No driveencryptionDefaultadmincredentialspasswordspreadsheetNoSecurityAwarenessTrainingWhitelisteddomains inemail filterNo truenetworksegmentationPlain textpassworddiscoveredin shareInappropriteFirewallrules (notRDP)StaleObjectsolder than1year"We justuseWindowsDefender">50%passwordscrackedWirelessPSK olderthan 2yearsExternalRDPMinimalGroupPolicyWindowsServer2003/2008Unlicensedhardwareor softwarecrackedadminpasswordNo IRPlanUsersare localadminsNoMFATeamviewer/ VNCUnpatchedExchangeTelnetUnidentifiedPCIrequirementsPasswordsneverexpireShares with"Everyone,Full Control"NooffsitebackupsDefaultSNMPWritevalueGuestSSID butnoisolationNoSPFrecordWindowsXPNoDMZManualBackupsDNSloggingnotenabledComputersnot joinedto Domain"We updatewhen thereareproblems"AdobeFlashNoEDRclosetspaghettiNoDKIM /DMARC"We'venever hadanincident."No DRPlanIndividualpermissionsin shares"We're assecure aswe canbe."Windows7No driveencryptionDefaultadmincredentialspasswordspreadsheetNoSecurityAwarenessTrainingWhitelisteddomains inemail filterNo truenetworksegmentationPlain textpassworddiscoveredin shareInappropriteFirewallrules (notRDP)StaleObjectsolder than1year"We justuseWindowsDefender">50%passwordscrackedWirelessPSK olderthan 2yearsExternalRDPMinimalGroupPolicyWindowsServer2003/2008Unlicensedhardwareor softwarecrackedadminpasswordNo IRPlanUsersare localadminsNoMFATeamviewer/ VNCUnpatchedExchangeTelnetUnidentifiedPCIrequirementsPasswordsneverexpireShares with"Everyone,Full Control"NooffsitebackupsDefaultSNMPWritevalueGuestSSID butnoisolationNoSPFrecordWindowsXPNoDMZManualBackupsDNSloggingnotenabledComputersnot joinedto Domain"We updatewhen thereareproblems"AdobeFlashNoEDRclosetspaghettiNoDKIM /DMARC"We'venever hadanincident."No DRPlanIndividualpermissionsin shares"We're assecure aswe canbe."Windows7

Risk Assessment Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
  1. No drive encryption
  2. Default admin credentials
  3. password spreadsheet
  4. No Security Awareness Training
  5. Whitelisted domains in email filter
  6. No true network segmentation
  7. Plain text password discovered in share
  8. Inapproprite Firewall rules (not RDP)
  9. Stale Objects older than 1year
  10. "We just use Windows Defender"
  11. >50% passwords cracked
  12. Wireless PSK older than 2 years
  13. External RDP
  14. Minimal Group Policy
  15. Windows Server 2003/2008
  16. Unlicensed hardware or software
  17. cracked admin password
  18. No IR Plan
  19. Users are local admins
  20. No MFA
  21. Teamviewer / VNC
  22. Unpatched Exchange
  23. Telnet
  24. Unidentified PCI requirements
  25. Passwords never expire
  26. Shares with "Everyone, Full Control"
  27. No offsite backups
  28. Default SNMP Write value
  29. Guest SSID but no isolation
  30. No SPF record
  31. Windows XP
  32. No DMZ
  33. Manual Backups
  34. DNS logging not enabled
  35. Computers not joined to Domain
  36. "We update when there are problems"
  37. Adobe Flash
  38. No EDR
  39. closet spaghetti
  40. No DKIM / DMARC
  41. "We've never had an incident."
  42. No DR Plan
  43. Individual permissions in shares
  44. "We're as secure as we can be."
  45. Windows 7