AdobeFlashcpasswordNo MFAon365AdminWinlogoncachedefaultvalueunencryptedwebmanagementinterfaceSegmentationwithout ACLsWirelessPSK olderthan 2years"DomainUsers" groupas localadministratorinsecurezonetransfersNIPSdisabled/unconfiguredStaleusersolder than1yearpasswordcomplexitynotenforcedNoGeo-IPblockingWindowsServer2003/2008Insecureshare withPII/PHIunauthenticatedmail relayinappropriateunconstraineddelegation inActiveDirectoryComputersnotjoined toAD (or AAD)End userPasswordsthat neverexpireGPO withinsecuresettingscriticallyout-of-datefirmwareWindows7SMBsigningnotenabledNobackupfailurealertsNoredundantISPLLMNRenabledPlain textpassworddiscoveredin shareDefaultSNMPWritevalueTelnetPCIviolation>20%phishclick rateIndividualuserpermissionsin sharesUnlicensedhardwareor softwareUnpatchedExchangeroguedeviceGuestSSID butno guestisolationWindowsXPNoSPFrecordDNSloggingnotenabledLMHash onadminInappropriteFirewallrules (notRDP)Teamviewer/ VNCNoDKIM /DMARCuntrainedclickersVMwithoutautostartApplicationwith > 1000vulnerabilitiesWhitelisteddomains inemail filterlegacyconfigurationnot removedNobotnetfilterDefaultadmincredentialsVPN withweakencryptionEDRMissingonendpointUsersare localadminsunencryptedbackupspasswordspreadsheetcomplianceviolationminpasswordlength < 12charactersNo driveencryptionBypassusersin DUONo DMZ(whereappropriate)AdobeFlashcpasswordNo MFAon365AdminWinlogoncachedefaultvalueunencryptedwebmanagementinterfaceSegmentationwithout ACLsWirelessPSK olderthan 2years"DomainUsers" groupas localadministratorinsecurezonetransfersNIPSdisabled/unconfiguredStaleusersolder than1yearpasswordcomplexitynotenforcedNoGeo-IPblockingWindowsServer2003/2008Insecureshare withPII/PHIunauthenticatedmail relayinappropriateunconstraineddelegation inActiveDirectoryComputersnotjoined toAD (or AAD)End userPasswordsthat neverexpireGPO withinsecuresettingscriticallyout-of-datefirmwareWindows7SMBsigningnotenabledNobackupfailurealertsNoredundantISPLLMNRenabledPlain textpassworddiscoveredin shareDefaultSNMPWritevalueTelnetPCIviolation>20%phishclick rateIndividualuserpermissionsin sharesUnlicensedhardwareor softwareUnpatchedExchangeroguedeviceGuestSSID butno guestisolationWindowsXPNoSPFrecordDNSloggingnotenabledLMHash onadminInappropriteFirewallrules (notRDP)Teamviewer/ VNCNoDKIM /DMARCuntrainedclickersVMwithoutautostartApplicationwith > 1000vulnerabilitiesWhitelisteddomains inemail filterlegacyconfigurationnot removedNobotnetfilterDefaultadmincredentialsVPN withweakencryptionEDRMissingonendpointUsersare localadminsunencryptedbackupspasswordspreadsheetcomplianceviolationminpasswordlength < 12charactersNo driveencryptionBypassusersin DUONo DMZ(whereappropriate)

Risk Assessment BINGO - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  1. Adobe Flash
  2. cpassword
  3. No MFA on 365 Admin
  4. Winlogon cache default value
  5. unencrypted web management interface
  6. Segmentation without ACLs
  7. Wireless PSK older than 2 years
  8. "Domain Users" group as local administrator
  9. insecure zone transfers
  10. NIPS disabled /unconfigured
  11. Stale users older than 1year
  12. password complexity not enforced
  13. No Geo-IP blocking
  14. Windows Server 2003/2008
  15. Insecure share with PII/PHI
  16. unauthenticated mail relay
  17. inappropriate unconstrained delegation in Active Directory
  18. Computers not joined to AD (or AAD)
  19. End user Passwords that never expire
  20. GPO with insecure settings
  21. critically out-of-date firmware
  22. Windows 7
  23. SMB signing not enabled
  24. No backup failure alerts
  25. No redundant ISP
  26. LLMNR enabled
  27. Plain text password discovered in share
  28. Default SNMP Write value
  29. Telnet
  30. PCI violation
  31. >20% phish click rate
  32. Individual user permissions in shares
  33. Unlicensed hardware or software
  34. Unpatched Exchange
  35. rogue device
  36. Guest SSID but no guest isolation
  37. Windows XP
  38. No SPF record
  39. DNS logging not enabled
  40. LM Hash on admin
  41. Inapproprite Firewall rules (not RDP)
  42. Teamviewer / VNC
  43. No DKIM / DMARC
  44. untrained clickers
  45. VM without autostart
  46. Application with > 1000 vulnerabilities
  47. Whitelisted domains in email filter
  48. legacy configuration not removed
  49. No botnet filter
  50. Default admin credentials
  51. VPN with weak encryption
  52. EDR Missing on endpoint
  53. Users are local admins
  54. unencrypted backups
  55. password spreadsheet
  56. compliance violation
  57. min password length < 12 characters
  58. No drive encryption
  59. Bypass users in DUO
  60. No DMZ (where appropriate)