Guest SSID but no isolation closet spaghetti >50% passwords cracked Unidentified PCI requirements Whitelisted domains in email filter No SPF record Minimal Group Policy Manual Backups password spreadsheet No drive encryption No offsite backups Stale Objects older than 1year No MFA cracked admin password No DMZ Windows XP Default admin credentials Default SNMP Write value Shares with "Everyone, Full Control" Computers not joined to Domain "We've never had an incident." Adobe Flash Passwords never expire Plain text password discovered in share External RDP Telnet Inapproprite Firewall rules (not RDP) Windows 7 Users are local admins No DR Plan No IR Plan No EDR "We just use Windows Defender" Unpatched Exchange "We're as secure as we can be." Teamviewer / VNC Unlicensed hardware or software "We update when there are problems" Windows Server 2003/2008 No DKIM / DMARC DNS logging not enabled No true network segmentation Individual permissions in shares Wireless PSK older than 2 years No Security Awareness Training Guest SSID but no isolation closet spaghetti >50% passwords cracked Unidentified PCI requirements Whitelisted domains in email filter No SPF record Minimal Group Policy Manual Backups password spreadsheet No drive encryption No offsite backups Stale Objects older than 1year No MFA cracked admin password No DMZ Windows XP Default admin credentials Default SNMP Write value Shares with "Everyone, Full Control" Computers not joined to Domain "We've never had an incident." Adobe Flash Passwords never expire Plain text password discovered in share External RDP Telnet Inapproprite Firewall rules (not RDP) Windows 7 Users are local admins No DR Plan No IR Plan No EDR "We just use Windows Defender" Unpatched Exchange "We're as secure as we can be." Teamviewer / VNC Unlicensed hardware or software "We update when there are problems" Windows Server 2003/2008 No DKIM / DMARC DNS logging not enabled No true network segmentation Individual permissions in shares Wireless PSK older than 2 years No Security Awareness Training
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Guest SSID but no isolation
closet spaghetti
>50% passwords cracked
Unidentified PCI requirements
Whitelisted domains in email filter
No SPF record
Minimal Group Policy
Manual Backups
password spreadsheet
No drive encryption
No offsite backups
Stale Objects older than 1year
No MFA
cracked admin password
No DMZ
Windows XP
Default admin credentials
Default SNMP Write value
Shares with "Everyone, Full Control"
Computers not joined to Domain
"We've never had an incident."
Adobe Flash
Passwords never expire
Plain text password discovered in share
External RDP
Telnet
Inapproprite Firewall rules (not RDP)
Windows 7
Users are local admins
No DR Plan
No IR Plan
No EDR
"We just use Windows Defender"
Unpatched Exchange
"We're as secure as we can be."
Teamviewer / VNC
Unlicensed hardware or software
"We update when there are problems"
Windows Server 2003/2008
No DKIM / DMARC
DNS logging not enabled
No true network segmentation
Individual permissions in shares
Wireless PSK older than 2 years
No Security Awareness Training