Windows Server 2003/2008 Inapproprite Firewall rules (not RDP) Windows 7 "We've never had an incident." Default SNMP Write value Unpatched Exchange No MFA password spreadsheet No Security Awareness Training Adobe Flash No true network segmentation No DMZ Wireless PSK older than 2 years Individual permissions in shares Windows XP Guest SSID but no isolation closet spaghetti "We're as secure as we can be." Teamviewer / VNC Default admin credentials Plain text password discovered in share Computers not joined to Domain Whitelisted domains in email filter DNS logging not enabled No IR Plan Passwords never expire Unidentified PCI requirements External RDP Unlicensed hardware or software >50% passwords cracked Manual Backups "We update when there are problems" Stale Objects older than 1year No DR Plan No drive encryption Telnet No EDR No DKIM / DMARC "We just use Windows Defender" Users are local admins cracked admin password Shares with "Everyone, Full Control" Minimal Group Policy No SPF record No offsite backups Windows Server 2003/2008 Inapproprite Firewall rules (not RDP) Windows 7 "We've never had an incident." Default SNMP Write value Unpatched Exchange No MFA password spreadsheet No Security Awareness Training Adobe Flash No true network segmentation No DMZ Wireless PSK older than 2 years Individual permissions in shares Windows XP Guest SSID but no isolation closet spaghetti "We're as secure as we can be." Teamviewer / VNC Default admin credentials Plain text password discovered in share Computers not joined to Domain Whitelisted domains in email filter DNS logging not enabled No IR Plan Passwords never expire Unidentified PCI requirements External RDP Unlicensed hardware or software >50% passwords cracked Manual Backups "We update when there are problems" Stale Objects older than 1year No DR Plan No drive encryption Telnet No EDR No DKIM / DMARC "We just use Windows Defender" Users are local admins cracked admin password Shares with "Everyone, Full Control" Minimal Group Policy No SPF record No offsite backups
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Windows Server 2003/2008
Inapproprite Firewall rules (not RDP)
Windows 7
"We've never had an incident."
Default SNMP Write value
Unpatched Exchange
No MFA
password spreadsheet
No Security Awareness Training
Adobe Flash
No true network segmentation
No DMZ
Wireless PSK older than 2 years
Individual permissions in shares
Windows XP
Guest SSID but no isolation
closet spaghetti
"We're as secure as we can be."
Teamviewer / VNC
Default admin credentials
Plain text password discovered in share
Computers not joined to Domain
Whitelisted domains in email filter
DNS logging not enabled
No IR Plan
Passwords never expire
Unidentified PCI requirements
External RDP
Unlicensed hardware or software
>50% passwords cracked
Manual Backups
"We update when there are problems"
Stale Objects older than 1year
No DR Plan
No drive encryption
Telnet
No EDR
No DKIM / DMARC
"We just use Windows Defender"
Users are local admins
cracked admin password
Shares with "Everyone, Full Control"
Minimal Group Policy
No SPF record
No offsite backups