criticallyout-of-datefirmwarecomplianceviolationNo DMZ(whereappropriate)GPO withinsecuresettingsLMHash onadminAdobeFlashGuestSSID butno guestisolationDNSloggingnotenabledVPN withweakencryption>20%phishclick rateUsersare localadminsuntrainedclickersPlain textpassworddiscoveredin shareTeamviewer/ VNCSMBsigningnotenabledWindows7WindowsServer2003/2008Unlicensedhardwareor softwareNo MFAon365AdmininsecurezonetransferspasswordcomplexitynotenforcedVMwithoutautostartApplicationwith > 1000vulnerabilitiesLLMNRenabledNoredundantISPBypassusersin DUOWirelessPSK olderthan 2yearsSegmentationwithout ACLsNIPSdisabled/unconfiguredNoGeo-IPblockingEnd userPasswordsthat neverexpireNobackupfailurealertsunauthenticatedmail relayroguedeviceNobotnetfiltercpasswordEDRMissingonendpointlegacyconfigurationnot removedInsecureshare withPII/PHI"DomainUsers" groupas localadministratorDefaultadmincredentialsUnpatchedExchangeTelnetunencryptedwebmanagementinterfaceNo driveencryptionpasswordspreadsheetWinlogoncachedefaultvalueWhitelisteddomains inemail filterNoDKIM /DMARCDefaultSNMPWritevalueStaleusersolder than1yearNoSPFrecordWindowsXPComputersnotjoined toAD (or AAD)PCIviolationInappropriteFirewallrules (notRDP)Individualuserpermissionsin sharesinappropriateunconstraineddelegation inActiveDirectoryminpasswordlength < 12charactersunencryptedbackupscriticallyout-of-datefirmwarecomplianceviolationNo DMZ(whereappropriate)GPO withinsecuresettingsLMHash onadminAdobeFlashGuestSSID butno guestisolationDNSloggingnotenabledVPN withweakencryption>20%phishclick rateUsersare localadminsuntrainedclickersPlain textpassworddiscoveredin shareTeamviewer/ VNCSMBsigningnotenabledWindows7WindowsServer2003/2008Unlicensedhardwareor softwareNo MFAon365AdmininsecurezonetransferspasswordcomplexitynotenforcedVMwithoutautostartApplicationwith > 1000vulnerabilitiesLLMNRenabledNoredundantISPBypassusersin DUOWirelessPSK olderthan 2yearsSegmentationwithout ACLsNIPSdisabled/unconfiguredNoGeo-IPblockingEnd userPasswordsthat neverexpireNobackupfailurealertsunauthenticatedmail relayroguedeviceNobotnetfiltercpasswordEDRMissingonendpointlegacyconfigurationnot removedInsecureshare withPII/PHI"DomainUsers" groupas localadministratorDefaultadmincredentialsUnpatchedExchangeTelnetunencryptedwebmanagementinterfaceNo driveencryptionpasswordspreadsheetWinlogoncachedefaultvalueWhitelisteddomains inemail filterNoDKIM /DMARCDefaultSNMPWritevalueStaleusersolder than1yearNoSPFrecordWindowsXPComputersnotjoined toAD (or AAD)PCIviolationInappropriteFirewallrules (notRDP)Individualuserpermissionsin sharesinappropriateunconstraineddelegation inActiveDirectoryminpasswordlength < 12charactersunencryptedbackups

Risk Assessment BINGO - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  1. critically out-of-date firmware
  2. compliance violation
  3. No DMZ (where appropriate)
  4. GPO with insecure settings
  5. LM Hash on admin
  6. Adobe Flash
  7. Guest SSID but no guest isolation
  8. DNS logging not enabled
  9. VPN with weak encryption
  10. >20% phish click rate
  11. Users are local admins
  12. untrained clickers
  13. Plain text password discovered in share
  14. Teamviewer / VNC
  15. SMB signing not enabled
  16. Windows 7
  17. Windows Server 2003/2008
  18. Unlicensed hardware or software
  19. No MFA on 365 Admin
  20. insecure zone transfers
  21. password complexity not enforced
  22. VM without autostart
  23. Application with > 1000 vulnerabilities
  24. LLMNR enabled
  25. No redundant ISP
  26. Bypass users in DUO
  27. Wireless PSK older than 2 years
  28. Segmentation without ACLs
  29. NIPS disabled /unconfigured
  30. No Geo-IP blocking
  31. End user Passwords that never expire
  32. No backup failure alerts
  33. unauthenticated mail relay
  34. rogue device
  35. No botnet filter
  36. cpassword
  37. EDR Missing on endpoint
  38. legacy configuration not removed
  39. Insecure share with PII/PHI
  40. "Domain Users" group as local administrator
  41. Default admin credentials
  42. Unpatched Exchange
  43. Telnet
  44. unencrypted web management interface
  45. No drive encryption
  46. password spreadsheet
  47. Winlogon cache default value
  48. Whitelisted domains in email filter
  49. No DKIM / DMARC
  50. Default SNMP Write value
  51. Stale users older than 1year
  52. No SPF record
  53. Windows XP
  54. Computers not joined to AD (or AAD)
  55. PCI violation
  56. Inapproprite Firewall rules (not RDP)
  57. Individual user permissions in shares
  58. inappropriate unconstrained delegation in Active Directory
  59. min password length < 12 characters
  60. unencrypted backups