NoredundantISPVPN withweakencryptionWinlogoncachedefaultvalueEDRMissingonendpointDNSloggingnotenabledunencryptedwebmanagementinterfaceEnd userPasswordsthat neverexpireSMBsigningnotenabledInsecureshare withPII/PHIUsersare localadminsWirelessPSK olderthan 2yearsWhitelisteddomains inemail filterNo driveencryptionIndividualuserpermissionsin sharesApplicationwith > 1000vulnerabilitiescomplianceviolationNIPSdisabled/unconfiguredinsecurezonetransfersAdobeFlashUnpatchedExchangeNoSPFrecorduntrainedclickersNo MFAon365AdminNoDKIM /DMARCVMwithoutautostartStaleusersolder than1yearGPO withinsecuresettings>20%phishclick rateComputersnotjoined toAD (or AAD)WindowsXPcriticallyout-of-datefirmwareTeamviewer/ VNC"DomainUsers" groupas localadministratorLLMNRenabledGuestSSID butno guestisolationSegmentationwithout ACLsNobotnetfilterNo DMZ(whereappropriate)cpasswordWindows7Plain textpassworddiscoveredin shareDefaultSNMPWritevalueminpasswordlength < 12charactersroguedeviceNobackupfailurealertsWindowsServer2003/2008TelnetBypassusersin DUOLMHash onadminNoGeo-IPblockingunencryptedbackupspasswordcomplexitynotenforcedlegacyconfigurationnot removedInappropriteFirewallrules (notRDP)inappropriateunconstraineddelegation inActiveDirectoryPCIviolationDefaultadmincredentialspasswordspreadsheetunauthenticatedmail relayUnlicensedhardwareor softwareNoredundantISPVPN withweakencryptionWinlogoncachedefaultvalueEDRMissingonendpointDNSloggingnotenabledunencryptedwebmanagementinterfaceEnd userPasswordsthat neverexpireSMBsigningnotenabledInsecureshare withPII/PHIUsersare localadminsWirelessPSK olderthan 2yearsWhitelisteddomains inemail filterNo driveencryptionIndividualuserpermissionsin sharesApplicationwith > 1000vulnerabilitiescomplianceviolationNIPSdisabled/unconfiguredinsecurezonetransfersAdobeFlashUnpatchedExchangeNoSPFrecorduntrainedclickersNo MFAon365AdminNoDKIM /DMARCVMwithoutautostartStaleusersolder than1yearGPO withinsecuresettings>20%phishclick rateComputersnotjoined toAD (or AAD)WindowsXPcriticallyout-of-datefirmwareTeamviewer/ VNC"DomainUsers" groupas localadministratorLLMNRenabledGuestSSID butno guestisolationSegmentationwithout ACLsNobotnetfilterNo DMZ(whereappropriate)cpasswordWindows7Plain textpassworddiscoveredin shareDefaultSNMPWritevalueminpasswordlength < 12charactersroguedeviceNobackupfailurealertsWindowsServer2003/2008TelnetBypassusersin DUOLMHash onadminNoGeo-IPblockingunencryptedbackupspasswordcomplexitynotenforcedlegacyconfigurationnot removedInappropriteFirewallrules (notRDP)inappropriateunconstraineddelegation inActiveDirectoryPCIviolationDefaultadmincredentialspasswordspreadsheetunauthenticatedmail relayUnlicensedhardwareor software

Risk Assessment BINGO - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  1. No redundant ISP
  2. VPN with weak encryption
  3. Winlogon cache default value
  4. EDR Missing on endpoint
  5. DNS logging not enabled
  6. unencrypted web management interface
  7. End user Passwords that never expire
  8. SMB signing not enabled
  9. Insecure share with PII/PHI
  10. Users are local admins
  11. Wireless PSK older than 2 years
  12. Whitelisted domains in email filter
  13. No drive encryption
  14. Individual user permissions in shares
  15. Application with > 1000 vulnerabilities
  16. compliance violation
  17. NIPS disabled /unconfigured
  18. insecure zone transfers
  19. Adobe Flash
  20. Unpatched Exchange
  21. No SPF record
  22. untrained clickers
  23. No MFA on 365 Admin
  24. No DKIM / DMARC
  25. VM without autostart
  26. Stale users older than 1year
  27. GPO with insecure settings
  28. >20% phish click rate
  29. Computers not joined to AD (or AAD)
  30. Windows XP
  31. critically out-of-date firmware
  32. Teamviewer / VNC
  33. "Domain Users" group as local administrator
  34. LLMNR enabled
  35. Guest SSID but no guest isolation
  36. Segmentation without ACLs
  37. No botnet filter
  38. No DMZ (where appropriate)
  39. cpassword
  40. Windows 7
  41. Plain text password discovered in share
  42. Default SNMP Write value
  43. min password length < 12 characters
  44. rogue device
  45. No backup failure alerts
  46. Windows Server 2003/2008
  47. Telnet
  48. Bypass users in DUO
  49. LM Hash on admin
  50. No Geo-IP blocking
  51. unencrypted backups
  52. password complexity not enforced
  53. legacy configuration not removed
  54. Inapproprite Firewall rules (not RDP)
  55. inappropriate unconstrained delegation in Active Directory
  56. PCI violation
  57. Default admin credentials
  58. password spreadsheet
  59. unauthenticated mail relay
  60. Unlicensed hardware or software