NoSecurityAwarenessTrainingManualBackupsUnlicensedhardwareor softwareWindowsServer2003/2008NoDKIM /DMARCNoMFA>50%passwordscrackedDefaultSNMPWritevalueMinimalGroupPolicyTeamviewer/ VNCDefaultadmincredentialsWindows7Individualpermissionsin shares"We justuseWindowsDefender"NoDMZUnidentifiedPCIrequirementsUnpatchedExchangeNooffsitebackupsTelnet"We'venever hadanincident."No IRPlan"We updatewhen thereareproblems"WirelessPSK olderthan 2yearsNoSPFrecordStaleObjectsolder than1yearclosetspaghettiNo truenetworksegmentationExternalRDPNo DRPlanComputersnot joinedto DomainPasswordsneverexpireNoEDRDNSloggingnotenabledAdobeFlashpasswordspreadsheetWindowsXPUsersare localadminsShares with"Everyone,Full Control"No driveencryption"We're assecure aswe canbe."Whitelisteddomains inemail filterGuestSSID butnoisolationcrackedadminpasswordPlain textpassworddiscoveredin shareInappropriteFirewallrules (notRDP)NoSecurityAwarenessTrainingManualBackupsUnlicensedhardwareor softwareWindowsServer2003/2008NoDKIM /DMARCNoMFA>50%passwordscrackedDefaultSNMPWritevalueMinimalGroupPolicyTeamviewer/ VNCDefaultadmincredentialsWindows7Individualpermissionsin shares"We justuseWindowsDefender"NoDMZUnidentifiedPCIrequirementsUnpatchedExchangeNooffsitebackupsTelnet"We'venever hadanincident."No IRPlan"We updatewhen thereareproblems"WirelessPSK olderthan 2yearsNoSPFrecordStaleObjectsolder than1yearclosetspaghettiNo truenetworksegmentationExternalRDPNo DRPlanComputersnot joinedto DomainPasswordsneverexpireNoEDRDNSloggingnotenabledAdobeFlashpasswordspreadsheetWindowsXPUsersare localadminsShares with"Everyone,Full Control"No driveencryption"We're assecure aswe canbe."Whitelisteddomains inemail filterGuestSSID butnoisolationcrackedadminpasswordPlain textpassworddiscoveredin shareInappropriteFirewallrules (notRDP)

Risk Assessment Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
  1. No Security Awareness Training
  2. Manual Backups
  3. Unlicensed hardware or software
  4. Windows Server 2003/2008
  5. No DKIM / DMARC
  6. No MFA
  7. >50% passwords cracked
  8. Default SNMP Write value
  9. Minimal Group Policy
  10. Teamviewer / VNC
  11. Default admin credentials
  12. Windows 7
  13. Individual permissions in shares
  14. "We just use Windows Defender"
  15. No DMZ
  16. Unidentified PCI requirements
  17. Unpatched Exchange
  18. No offsite backups
  19. Telnet
  20. "We've never had an incident."
  21. No IR Plan
  22. "We update when there are problems"
  23. Wireless PSK older than 2 years
  24. No SPF record
  25. Stale Objects older than 1year
  26. closet spaghetti
  27. No true network segmentation
  28. External RDP
  29. No DR Plan
  30. Computers not joined to Domain
  31. Passwords never expire
  32. No EDR
  33. DNS logging not enabled
  34. Adobe Flash
  35. password spreadsheet
  36. Windows XP
  37. Users are local admins
  38. Shares with "Everyone, Full Control"
  39. No drive encryption
  40. "We're as secure as we can be."
  41. Whitelisted domains in email filter
  42. Guest SSID but no isolation
  43. cracked admin password
  44. Plain text password discovered in share
  45. Inapproprite Firewall rules (not RDP)