Recommended Starting Points
These are the fundamental guidance articles to start with - scroll down for more specific guidance and related content
Introductory Level
If implemented early enough, mitigations will be a necessary part of risk management when doing business with overseas parties.
Protected Procurement is guidance for businesses and organisations to help embed security across supply chains and to protect from supply chain attacks. Created in partnership with CIPS
Guidance for business who are also suppliers on how to develop and improve their security profile. This aims to encourage suppliers to see security as part of their competitive edge.
Consider security early when seeking investment to protect your company and help you prepare for the National Security and Investment Act
The consequences of failing to plan properly for new security projects or upgrades of existing security measures can be costly.
Guidance on how to take a security-minded approach to Digital Engineering, Technologies, Projects and Initiatives
It is important that you understand the risks associated with deploying these technologies, whether they relate to location sensitivities, data protection considerations or privacy concerns
This guidance is for early-stage investors in emerging technology companies.
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
Developing a risk based plan to doing business with overseas parties is essential to ensure success.
Guidance on a security-minded approach to securing underground asset data.
Being aware of government’s business screening requirements will allow you to be mindful of any national security threats.
Good governance and proactively considering security in business plans with overseas parties sets the tone of your risk appetite.
Guidance for those practitioners responsible for implementing supply chain security within organisations. Suitable for procurement professionals, commercial teams, security professionals, and others.
If taken in a timely manner, practical steps to manage risks will protect your reputation, prosperity and the national security of the UK.
Secure Business, an open approach to international business and engagement to protect your long-term profitability, reputation, and the UK's national security
Learn the fundamentals of insider risk management to get the most from NPSA advice
Get started here with an overview of security culture and why it’s important.
Intermediate Level
The guide helps risk owners, and their security advisors, to understand and manage the risk to building occupants, people outside the building and other assets resulting from damage to building facades caused by the blast effects of an external improvised explosive device (IED)
This document supplements the NPSA Standard by providing a method for testing external doors, non-glazed panels and non-loadbearing walls under blast loading from external IEDs and assessing the damage and hazard to people
NPSA recommends that products required to protect against a firearms attack are tested at an accredited test centre in accordance with the BS EN standards
This guidance note is to assist the building owner, security manager and facility manager in selecting a design threat and ensuring that suitable products are used to mitigate the threat
This guidance note is to assist the building owner, security manager and facility managers to ensure that suitable bullet resistant glass (BRG) is selected to mitigate the threat and that have been certified as meeting the required standard
This guidance note is to assist the building owner, security manager and facility managers to ensure that suitable bullet resistant glass is selected to mitigate the threat and that have been certified as meeting the required standard
Guidance note on measures to improve the blast resistance of glazing
A summary of the different types of curtain walling systems that exist and where these are typically used
This guidance presents an overview of the principles behind Vehicle As a Weapon (VAW) detection, the different technologies available & considerations regarding the environments in which they may operate
NCST are highly functional computers which are connected to a network and need to be suitably protected
This guidance supplements existing Security Minded Communications guidance and provides tailored advice for UK organisations which have remote or rural locations as part of their estate in the UK.
Assess your organisation’s personnel security maturity to build resilience
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems.
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems.
Protective security is important for a site’s own infrastructure which is crucial for it to function or could present hazards if attacked.
Data centres operators and their customers should both have individual risk management strategies designed to protect their critical assets and systems
Briefing templates for upskilling staff with search duties
Organisations may use search and screening measures to detect specific items and materials entering (or leaving) their buildings and sites
Advanced Level
HVAC systems may provide a viable, rudimentary means of dispersing chemical or biological agents. Measures to reduce this risk may need to be considered
Guidance to provide high level, practical advice to anyone looking to formulate a Site Security Plan, assisting in developing a proportionate plan which aims to mitigate Terrorist and State threats, whilst supporting in countering many other types of security or safety threats.
The planning process has a key role in making places – recommending how and where buildings should be built, what they should be used for and how they should fit into the local surroundings.
NPSA have developed this guidance as we often see security being considered too late in the design process where the physical security measures conflict with the design aspirations
Windows and glazed facades are important elements of a building that can be vulnerable to forced entry, ballistic, surreptitious and other attacks
All Levels
NPSA has created guidance for Emergency Services to ensure they can carry out their duties safely and effectively. This page lists relevant guidance products and how to access them.
Good general physical and personnel security measures will contribute towards resilience against CBRN incidents
Considerations for use of AI in protective security and guidance on defending against AI enabled threats
Supporting our customers in assessing and mitigating the security risks posed by uncrewed aerial systems (UAS), also known as UAV or drones
UK technology companies are at risk of being compromised by certain states for their technological, economic, political, and military gain. Secure your success
Being part of the UK's Critical National Infrastructure makes you, your colleagues, and your organisation highly attractive targets to certain states. Secure your success
Critical and emerging technology companies are at risk of being compromised by certain states for their technological, economic, political, and military gain. Secure your success
An effective security culture is an essential component of an organisation’s protective security regime. Learn more about security culture and how effective leadership can shape the security culture of your organisation.
Information on how open and shared data relates to a Security-Minded approach.
Guidance for data centre owners and users. You should use this guidance to inform your own risk management strategy that is unique to your organisation’s needs
On 24 November 2022 the Chancellor of the Duchy of Lancaster made a written ministerial statement to the House of Commons on the subject of visual surveillance systems used on the government estate
NPSA have published the following new guidance: Forced Entry Standards - A guide to forced entry protection standards for facades and other building elements used within the UK
Doors form an essential part of physical security and are often required to perform several functions
NPSA and NCSC have written guidance about Network Connected Security Technologies (NCST)
A key purpose of connected places, also known as smart cities, also known as is to join up specific vertical sectors across organisational boundaries into a whole-city approach for the creation, delivery and use of city spaces and services
Guidance on how to take a Security-Minded approach to Digital Engineering, Technologies, Projects and Initiatives
Guidance to aid those responsible for developing, designing, and delivering a new perimeter solution
Guidance on supply chain resilience or the security of supply. Aims to help businesses and organisations to anticipate, prepare and adaptively respond to prevent disruption to supply chains.


