Recommended Starting Points
These are the fundamental guidance articles to start with - scroll down for more specific guidance and related content
Introductory Level
This guidance is for users of shared workspaces and provides practical advice tailored to your workspace and activities
Get started here with an overview of security culture and why it’s important.
This webpage outlines five key principles underpinning NPSA advice and guidance
Access NPSA’s tools and resources that can support you as you look to improve your security culture
NPSA’s Passport to Good Security for Senior Executives sets out 20 principles for effective security management
Hostile actors can use international business and engagement as a way of gaining access and influence in order to harm your interests or the national security of the UK.
Physical and personnel security measures for major events require specific consideration due to their dynamic and complex character.
The Think before You Link campaign, on which the TBYL App is based, can help keep you, your colleagues, and the country safe from being targeted by malicious profiles online
If implemented early enough, mitigations will be a necessary part of risk management when doing business with overseas parties.
Protected Procurement is guidance for businesses and organisations to help embed security across supply chains and to protect from supply chain attacks. Created in partnership with CIPS
NPSA have released new election protective security guidance on protecting pedestrian queues
Consider security early when seeking investment to protect your company and help you prepare for the National Security and Investment Act
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
Developing a risk based plan to doing business with overseas parties is essential to ensure success.
Being aware of government’s business screening requirements will allow you to be mindful of any national security threats.
NPSA has developed innovative, immersive exercises to help you experience insider events in a safe space. This allows you to test your crisis communications response, using effective communication to break down organisational silos
Good governance and proactively considering security in business plans with overseas parties sets the tone of your risk appetite.
If taken in a timely manner, practical steps to manage risks will protect your reputation, prosperity and the national security of the UK.
Intermediate Level
Discover how to deter, detect and deny those seeking to cause harm
All organisations need to ensure they have the processes and procedures in place to deliver an effective, efficient and compliant security provision
Security-Mindedness is about encouraging business leaders, managers and practitioners to consider security across all areas of your organisations
This guidance is designed to help workspace providers provide the safety and collaboration that your users seek.
Guidance covering a wide range of topics that will help keep your public premises and events safe and secure, intended both for security managers and other managers whose responsibilities include security
Guidance for organisations’ senior leaders, highlighting the importance of senior leadership in achieving effective security
Guidance on providing security information during the first 12 months of the employee lifecycle.
Assess your organisation’s personnel security maturity to build resilience
The recommended approach to selecting personnel security metrics
What does good security behaviour look like in your organisation?
Data centres are a valuable target for threat actors seeking to steal data or disrupt operations and services. Data centre owners should assume that a cyber compromise is inevitable. We advise taking steps to detect intrusions and minimise their impact and preventative cyber security measures.
Advanced Level
Guidance to provide high level, practical advice to anyone looking to formulate a Site Security Plan, assisting in developing a proportionate plan which aims to mitigate Terrorist and State threats, whilst supporting in countering many other types of security or safety threats.
All Levels
The Insider Risk programme should be continuously reviewed to measure the effectiveness of any resources used and that it correctly reflects the current threats and vulnerabilities in your organisation.
Employment screening comprises the procedures involved in deciding an individual's suitability to hold employment in a given job role.
Effective education and training is necessary to ensure individuals know what policies, standards, guidelines and procedures are in place to maintain security.
Appropriate investigation and disciplinary practices are essential in ensuring that disproportionate actions are minimised and adherence to security policies and processes are reinforced.
Passport to Good Security - Security Pre-Screening: pre-screening of employees, contractors and service providers should be included as part of your overall organisation security strategy.
An insider risk programme should integrate effectively with the organisation’s overall communications’ strategy.
How will you embed the desired security behaviours and culture in your organisation?
Insider Threat Practitioners and Stakeholders will need to be engaged across business areas to provide specialist insight and ensure a successful implementation of a working Insider Threat Programme.
Understanding what security risks your organisation faces is essential for developing appropriate and proportionate security mitigation measures within the insider threat programme.
A programme of monitoring and review should be in place to enable potential security issues, or personal issues that may impact on an employee's work, to be recognised and dealt with effectively.
Passport to Good Security - Legality, Ethics and Transparency: employees should understand the role they can play in protecting the organisation from internal and external threat.
Passport to Good Security - Mitigate your Risks: plan the specific actions your organisation will take following completion of the risk assessment, focusing on the threats specific to your organisation’s critical assets.
Passport to Good Security - Good Governance: in your role as a manager with responsibility for security matters, you should aim to identify answers to key questions about the governance arrangements your organisation has (or may not have) in place for security risks.
Ensuring proportionate policies, standards, guidelines and procedures are in place that are understood and consistently enforced is critical in any insider risk programme.
A New set of guidance documents and video for SCA (Security Considerations Assessment) have been published to ensure security-related vulnerabilities are considered across a range of activities and processes within an organisation
Positive and visible Board level support for, and engagement with, protective security is vital to demonstrate to staff the value placed on security and the insider threat strategy.

