Public cloudstoragemisconfigurationLack ofaccesscontrolsAPI keysin clientappLack ofAPILayerMetadataexposureUnsecureddatabaseSQLinjectionemotionalharmDataRetentionRisksMinimumsecurityrulesTrustlossLegacyInfrastructureUse ofFirebaseBackendinsiderthreatExposureof PIIUserNotificationStorage ofsensitiveinformartionIdentitytheftriskNo AuthControlsReputationalDamageNoregularauditsNoauthenticationon storagebucketExposureof privatemessagesIncidentResponsePublic cloudstoragemisconfigurationLack ofaccesscontrolsAPI keysin clientappLack ofAPILayerMetadataexposureUnsecureddatabaseSQLinjectionemotionalharmDataRetentionRisksMinimumsecurityrulesTrustlossLegacyInfrastructureUse ofFirebaseBackendinsiderthreatExposureof PIIUserNotificationStorage ofsensitiveinformartionIdentitytheftriskNo AuthControlsReputationalDamageNoregularauditsNoauthenticationon storagebucketExposureof privatemessagesIncidentResponse

Technical Risk Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Public cloud storage misconfiguration
  2. Lack of access controls
  3. API keys in client app
  4. Lack of API Layer
  5. Metadata exposure
  6. Unsecured database
  7. SQL injection
  8. emotional harm
  9. Data Retention Risks
  10. Minimum security rules
  11. Trust loss
  12. Legacy Infrastructure
  13. Use of Firebase Backend
  14. insider threat
  15. Exposure of PII
  16. User Notification
  17. Storage of sensitive informartion
  18. Identity theft risk
  19. No Auth Controls
  20. Reputational Damage
  21. No regular audits
  22. No authentication on storage bucket
  23. Exposure of private messages
  24. Incident Response