NobackupfailurealertsUnlicensedhardwareor softwareinappropriateunconstraineddelegation inActiveDirectoryPCIviolationInsecureshare withPII/PHITelnetGuestSSID butno guestisolationSegmentationwithout ACLsNoGeo-IPblockingNoredundantISPminpasswordlength < 12charactersunencryptedwebmanagementinterfacecpasswordSMBsigningnotenabledNoDKIM /DMARCUnpatchedExchangeunauthenticatedmail relayWirelessPSK olderthan 2yearsApplicationwith > 1000vulnerabilitiescriticallyout-of-datefirmwareWhitelisteddomains inemail filterComputersnotjoined toAD (or AAD)"DomainUsers" groupas localadministratorcomplianceviolationLLMNRenabledlegacyconfigurationnot removedNIPSdisabled/unconfiguredNobotnetfilterunencryptedbackupsWindowsServer2003/2008DNSloggingnotenabledNo driveencryptionInappropriteFirewallrules (notRDP)AdobeFlashLMHash onadminroguedeviceNo DMZ(whereappropriate)VPN withweakencryption>20%phishclick rateStaleusersolder than1yearWinlogoncachedefaultvalueEnd userPasswordsthat neverexpireWindowsXPpasswordspreadsheetNoSPFrecordDefaultadmincredentialsEDRMissingonendpointpasswordcomplexitynotenforcedNo MFAon365AdminIndividualuserpermissionsin sharesVMwithoutautostartGPO withinsecuresettingsBypassusersin DUOuntrainedclickersUsersare localadminsPlain textpassworddiscoveredin shareTeamviewer/ VNCWindows7DefaultSNMPWritevalueinsecurezonetransfersNobackupfailurealertsUnlicensedhardwareor softwareinappropriateunconstraineddelegation inActiveDirectoryPCIviolationInsecureshare withPII/PHITelnetGuestSSID butno guestisolationSegmentationwithout ACLsNoGeo-IPblockingNoredundantISPminpasswordlength < 12charactersunencryptedwebmanagementinterfacecpasswordSMBsigningnotenabledNoDKIM /DMARCUnpatchedExchangeunauthenticatedmail relayWirelessPSK olderthan 2yearsApplicationwith > 1000vulnerabilitiescriticallyout-of-datefirmwareWhitelisteddomains inemail filterComputersnotjoined toAD (or AAD)"DomainUsers" groupas localadministratorcomplianceviolationLLMNRenabledlegacyconfigurationnot removedNIPSdisabled/unconfiguredNobotnetfilterunencryptedbackupsWindowsServer2003/2008DNSloggingnotenabledNo driveencryptionInappropriteFirewallrules (notRDP)AdobeFlashLMHash onadminroguedeviceNo DMZ(whereappropriate)VPN withweakencryption>20%phishclick rateStaleusersolder than1yearWinlogoncachedefaultvalueEnd userPasswordsthat neverexpireWindowsXPpasswordspreadsheetNoSPFrecordDefaultadmincredentialsEDRMissingonendpointpasswordcomplexitynotenforcedNo MFAon365AdminIndividualuserpermissionsin sharesVMwithoutautostartGPO withinsecuresettingsBypassusersin DUOuntrainedclickersUsersare localadminsPlain textpassworddiscoveredin shareTeamviewer/ VNCWindows7DefaultSNMPWritevalueinsecurezonetransfers

Risk Assessment BINGO - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  1. No backup failure alerts
  2. Unlicensed hardware or software
  3. inappropriate unconstrained delegation in Active Directory
  4. PCI violation
  5. Insecure share with PII/PHI
  6. Telnet
  7. Guest SSID but no guest isolation
  8. Segmentation without ACLs
  9. No Geo-IP blocking
  10. No redundant ISP
  11. min password length < 12 characters
  12. unencrypted web management interface
  13. cpassword
  14. SMB signing not enabled
  15. No DKIM / DMARC
  16. Unpatched Exchange
  17. unauthenticated mail relay
  18. Wireless PSK older than 2 years
  19. Application with > 1000 vulnerabilities
  20. critically out-of-date firmware
  21. Whitelisted domains in email filter
  22. Computers not joined to AD (or AAD)
  23. "Domain Users" group as local administrator
  24. compliance violation
  25. LLMNR enabled
  26. legacy configuration not removed
  27. NIPS disabled /unconfigured
  28. No botnet filter
  29. unencrypted backups
  30. Windows Server 2003/2008
  31. DNS logging not enabled
  32. No drive encryption
  33. Inapproprite Firewall rules (not RDP)
  34. Adobe Flash
  35. LM Hash on admin
  36. rogue device
  37. No DMZ (where appropriate)
  38. VPN with weak encryption
  39. >20% phish click rate
  40. Stale users older than 1year
  41. Winlogon cache default value
  42. End user Passwords that never expire
  43. Windows XP
  44. password spreadsheet
  45. No SPF record
  46. Default admin credentials
  47. EDR Missing on endpoint
  48. password complexity not enforced
  49. No MFA on 365 Admin
  50. Individual user permissions in shares
  51. VM without autostart
  52. GPO with insecure settings
  53. Bypass users in DUO
  54. untrained clickers
  55. Users are local admins
  56. Plain text password discovered in share
  57. Teamviewer / VNC
  58. Windows 7
  59. Default SNMP Write value
  60. insecure zone transfers