>20%phishclick rateminpasswordlength < 12characterspasswordcomplexitynotenforcedpasswordspreadsheetuntrainedclickersunencryptedwebmanagementinterfaceUnpatchedExchangeApplicationwith > 1000vulnerabilitiesDNSloggingnotenabledInsecureshare withPII/PHIWindowsXPinappropriateunconstraineddelegation inActiveDirectoryWindows7Computersnotjoined toAD (or AAD)roguedeviceNoSPFrecordLMHash onadmincomplianceviolationlegacyconfigurationnot removedSegmentationwithout ACLsinsecurezonetransfersWindowsServer2003/2008No DMZ(whereappropriate)unauthenticatedmail relayNoDKIM /DMARCGPO withinsecuresettingsLLMNRenabledcriticallyout-of-datefirmwareTelnetNoGeo-IPblockingWinlogoncachedefaultvalueBypassusersin DUOunencryptedbackupsEnd userPasswordsthat neverexpireNobotnetfilterVMwithoutautostartVPN withweakencryptionTeamviewer/ VNCGuestSSID butno guestisolationSMBsigningnotenabledPlain textpassworddiscoveredin shareEDRMissingonendpointNIPSdisabled/unconfiguredNoredundantISPIndividualuserpermissionsin sharesDefaultSNMPWritevalueNobackupfailurealertsAdobeFlashStaleusersolder than1yearUnlicensedhardwareor softwareWhitelisteddomains inemail filtercpasswordWirelessPSK olderthan 2years"DomainUsers" groupas localadministratorUsersare localadminsNo driveencryptionNo MFAon365AdminInappropriteFirewallrules (notRDP)DefaultadmincredentialsPCIviolation>20%phishclick rateminpasswordlength < 12characterspasswordcomplexitynotenforcedpasswordspreadsheetuntrainedclickersunencryptedwebmanagementinterfaceUnpatchedExchangeApplicationwith > 1000vulnerabilitiesDNSloggingnotenabledInsecureshare withPII/PHIWindowsXPinappropriateunconstraineddelegation inActiveDirectoryWindows7Computersnotjoined toAD (or AAD)roguedeviceNoSPFrecordLMHash onadmincomplianceviolationlegacyconfigurationnot removedSegmentationwithout ACLsinsecurezonetransfersWindowsServer2003/2008No DMZ(whereappropriate)unauthenticatedmail relayNoDKIM /DMARCGPO withinsecuresettingsLLMNRenabledcriticallyout-of-datefirmwareTelnetNoGeo-IPblockingWinlogoncachedefaultvalueBypassusersin DUOunencryptedbackupsEnd userPasswordsthat neverexpireNobotnetfilterVMwithoutautostartVPN withweakencryptionTeamviewer/ VNCGuestSSID butno guestisolationSMBsigningnotenabledPlain textpassworddiscoveredin shareEDRMissingonendpointNIPSdisabled/unconfiguredNoredundantISPIndividualuserpermissionsin sharesDefaultSNMPWritevalueNobackupfailurealertsAdobeFlashStaleusersolder than1yearUnlicensedhardwareor softwareWhitelisteddomains inemail filtercpasswordWirelessPSK olderthan 2years"DomainUsers" groupas localadministratorUsersare localadminsNo driveencryptionNo MFAon365AdminInappropriteFirewallrules (notRDP)DefaultadmincredentialsPCIviolation

Risk Assessment BINGO - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  1. >20% phish click rate
  2. min password length < 12 characters
  3. password complexity not enforced
  4. password spreadsheet
  5. untrained clickers
  6. unencrypted web management interface
  7. Unpatched Exchange
  8. Application with > 1000 vulnerabilities
  9. DNS logging not enabled
  10. Insecure share with PII/PHI
  11. Windows XP
  12. inappropriate unconstrained delegation in Active Directory
  13. Windows 7
  14. Computers not joined to AD (or AAD)
  15. rogue device
  16. No SPF record
  17. LM Hash on admin
  18. compliance violation
  19. legacy configuration not removed
  20. Segmentation without ACLs
  21. insecure zone transfers
  22. Windows Server 2003/2008
  23. No DMZ (where appropriate)
  24. unauthenticated mail relay
  25. No DKIM / DMARC
  26. GPO with insecure settings
  27. LLMNR enabled
  28. critically out-of-date firmware
  29. Telnet
  30. No Geo-IP blocking
  31. Winlogon cache default value
  32. Bypass users in DUO
  33. unencrypted backups
  34. End user Passwords that never expire
  35. No botnet filter
  36. VM without autostart
  37. VPN with weak encryption
  38. Teamviewer / VNC
  39. Guest SSID but no guest isolation
  40. SMB signing not enabled
  41. Plain text password discovered in share
  42. EDR Missing on endpoint
  43. NIPS disabled /unconfigured
  44. No redundant ISP
  45. Individual user permissions in shares
  46. Default SNMP Write value
  47. No backup failure alerts
  48. Adobe Flash
  49. Stale users older than 1year
  50. Unlicensed hardware or software
  51. Whitelisted domains in email filter
  52. cpassword
  53. Wireless PSK older than 2 years
  54. "Domain Users" group as local administrator
  55. Users are local admins
  56. No drive encryption
  57. No MFA on 365 Admin
  58. Inapproprite Firewall rules (not RDP)
  59. Default admin credentials
  60. PCI violation