Introduction
Shared workspaces provide innovative and flexible environments for individuals and organisations to collaborate, innovate, and grow. From coworking spaces and private offices, to shared laboratories and innovation hubs, these spaces cater to a wide range of users, offering advanced resources and fostering partnerships without long-term commitments. However, such dynamic environments also present unique security challenges, with sensitive information, intellectual property, and equipment often at risk of theft, unauthorised access, or accidental exposure.
As a workspace provider, you play a critical role in establishing the foundation for security within these spaces. By implementing appropriate security measures, you not only protect your users, their property and privacy, but also safeguard your facility, assets and reputation. Effective security practices enhance user trust, support compliance with regulatory requirements, and create an environment where innovation can thrive.
This guidance is designed to help providers navigate these challenges, offering practical advice for creating secure shared workspaces. Whether you manage coworking spaces, high-tech labs, or private offices, this document outlines strategies for designing, retrofitting, and maintaining facilities that meet diverse user needs. By understanding the specific risks associated with different workspace types and applying proportionate security controls, providers can provide the safety and collaboration that your users seek.

Types of Shared Workspaces
Shared workspaces cater to a wide range of user needs and activities. From coworking spaces and private offices, to shared laboratories and innovation hubs, these environments support professionals, researchers, startups, and established organisations.
The categories below illustrate the variety of shared workspace types, helping you identify the spaces you offer and align them with user expectations.
- Coworking spaces - Flexible work environments with desks in an open area on a first-come, first-served basis ('hot desking') supported by communal facilities like meeting rooms.
- Shared laboratories - Shared labs provide cost-effective access to specialised lab equipment for researchers and startups. They often promote community and collaboration.
- Private offices in shared building - A private area within a coworking or other shared facility. Allows the users to manage their own space while still benefitting from shared resources.
- Catapults - Innovation hubs connecting businesses, engineers and researchers to turn ideas into market-ready solutions. They often include shared workspaces along with other benefits.
- University spaces - University-based hubs foster partnerships between academia and industry, and support research and real-world applications of innovative ideas.
- Incubators/Accelerators - Programmes for startups, offering mentorship, funding connections, and shared resources (including hot desking and private offices) to encourage growth.
Understanding your User's Risks
Shared workspaces can be attractive targets for those seeking to gain unauthorised access to sensitive information or systems. The same open, collaborative environments that make them appealing to users can also allow individuals with malicious intent to gain, or appear to have, legitimate access to your users’ confidential information. As a shared workspace provider, understanding the threat actors that might exploit these vulnerabilities is essential to safeguarding both your business and that of your users.
For the latest threat information, please refer to the NPSA, NCSC and MI5 websites and the ‘Secure Innovation’ and ‘Trusted Research’ campaign information.
May target users handling sensitive projects or research.
They exploit vulnerabilities to access user data, damaging your reputation and jeopardising the integrity of your users’ information and business.
Competitors may use shared spaces to gather information on users or operations.
They could pose as legitimate users, undermining user confidence and your workspace’s reputation.
Cybercriminals exploit digital systems like Wi-Fi or access controls.
Breaches disrupt services, expose data, and damage infrastructure, causing downtime and reputational harm.
Thieves can exploit opportunities in shared workspaces, such as unattended devices or information, and may seek to gain access by legitimate means. Once inside, thieves may take advantage of open environments to identify vulnerable targets.
Activists may target workspaces by way of disruption or vandalism. This could be based on issues relating to users’ business activities or supply chains.
Their actions harm reputation, impact profitability, and increase costs.
REMEMBER…
Any of these threat actors could present as legitimate shared workspace users, visitors, contractors, etc.
Proportionate Security Measures
We understand that shared workspace providers aim to deliver environments that maximise the benefits of collaboration while managing security risks. This is made more complex by the need to flexibly cater for users who require a range of different spaces at different times.
This guidance, therefore, categorises shared workspaces into three distinct groups (capturing different types of space, from hot desks and shared equipment, through to private spaces and dedicated confidential suites) and describes the security measures applicable to each category. These are: OPEN, PRIVATE and CONFIDENTIAL.
For example, a user in a PRIVATE office may occasionally use the OPEN flexible coworking area; all the time requiring an appropriate and proportionate level of security. Alternatively, a user may upgrade to a CONFIDENTIAL facility to meet client requirements, where higher security standards are warranted.
The measures recommended for OPEN workspaces focus primarily on awareness and basic provisions, whereas those for PRIVATE and CONFIDENTIAL spaces extend to cover more advanced measures and management practices. Importantly, none of these categories imply that a provider offers no security.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
Description |
Open environments designed for collaboration, shared equipment, and communal areas. Providers must prioritise accessibility and baseline security for diverse users. |
Enclosed spaces offering users greater control over their environment, allowing for more tailored security and privacy. These spaces are typically used by small businesses or teams requiring a dedicated workspace for focused work or sensitive discussions. |
Confidential workspaces cater to users handling sensitive information, where security is a priority. These spaces require providers to implement enhanced security measures aligned with industry best practices and third-party security standards. |
|
Examples |
|
|
|
Note: Providers of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
Security Culture
For shared workspace providers, fostering a strong security culture is not only part of your duty of care to users, but also a key differentiator in attracting and retaining clients. By promoting a proactive, security-conscious culture, providers can build trust, strengthen reputation, and better support their users as their security needs develop.
|
Workspace |
Focus |
Building Security Culture |
|---|---|---|
Open |
Awareness and reporting |
Encourage Reporting: Promote the reporting of suspicious behaviour through approachable staff, messaging and signage. Foster Engagement: Organise user meet-and-greet sessions where security policies and reporting procedures are introduced. Seek Feedback: Use feedback channels (e.g., surveys or suggestion boxes) to improve shared space security. |
Private |
Collaboration and accountability |
Collaborate with Users: Engage with users when developing security policies and procedures to ensure the needs of both provider and users are accommodated. Regular Check-Ins: Conduct quarterly or biannual review sessions with users to provide reassurance and review and address emerging security concerns. Training: Provide training for users on securing private spaces and handling visitor management effectively. |
Confidential |
Compliance and trust |
Tailored Workshops: Facilitate user workshops tailored to meeting confidentiality and compliance requirements specific to sensitive projects. Dedicated Support: Assign dedicated staff or liaisons for users of these spaces to ensure quick, effective communication on security-related needs. Build Trust: Build trust by demonstrating consistent application of security policies and practices, such as regular audits and visitor management processes, to protect sensitive information and operations. |
Design and Fit-Out of New Workspaces
When designing new shared workspaces, providers can embed security measures from the outset. An integrated, holistic approach to security at this stage of the process supports flexibility in operations and scalability of security controls.
|
Concepts |
Components |
Considerations |
|---|---|---|
Crime Prevention through Environmental Design (CPTED)1 |
Natural surveillanceNatural AccessControlTerritorial ReinforcementMaintenanceActivity Support |
|
Zoning and Layering |
Defining Space:OpenPrivateConfidential |
|
Security Systems |
Physical SecurityTechnical SecurityPerformance StandardsAdaptability/Scalability |
|
The NPSA overlay to the RIBA Plan of Work2 is for everyone involved in the safe and secure design, construction and operation of any building.
Adopt the process set out in the Overlay to help ensure new shared workspaces are safer for their occupants and that risks are appropriately mitigated.
Privacy
Ensuring user privacy is a core expectation for shared workspace providers. By tailoring privacy measures to workspace types, providers can balance security with the collaboration that users desire. This section outlines practical steps providers can take.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
Privacy Criteria |
Provide bookable meeting rooms and/or ‘call pods’ to support user privacy. |
Allow users to customise their spaces with privacy measures like blinds or additional locks. |
Support user-specific privacy needs for sensitive projects, such as excluding company names from public directories. |
|
Enhancements |
Install screens in communal areas to provide a basic degree of privacy for users. |
Fit blinds or privacy film on glazed partitions and windows3. Offer secure, lockable storage for user belongings. Provide a shredder and/or arrange a confidential waste disposal service. |
Provide high-quality locks recognised by the insurance industry or those that allow operation of the lock to be logged, giving users a record of who accessed their units. Provide advanced soundproofing for confidential spaces. |
|
Operational Practices |
Regularly remind users to use private areas, or privacy features, for sensitive discussions and to secure belongings when in shared spaces. |
Escort third parties and contractors when conducting work on your behalf, particularly when they require access to the interior of a user’s private or confidential workspace. |
|
|
Engage with users to identify their privacy needs during onboarding and support customisation requests where feasible. |
Support users in managing access for third parties and contractors by offering clear guidance on escorting protocols and providing necessary resources, such as temporary visitor passes or monitored access points. |
||
|
Governance |
Ensure clear communication channels for users to report any privacy concerns and put measures in place to address these issues promptly. |
Include user privacy requirements in service agreements, ensuring they are periodically reviewed and updated. |
Conduct regular reviews of privacy measures and ensure compliance with agreed user-specific standards. |
Note: Providers of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
Physical Security Systems
A secure environment helps users to work confidently in any space. Providers should implement measures that support deterring and preventing unauthorised access, monitoring of activity, and responding to incidents. This section outlines what providers can offer across Open, Private, and Confidential spaces to meet user security needs.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
System Criteria |
Ensure all workspace entrance and exit points, together with internal communal areas, are covered by video surveillance. |
Offer users the ability to introduce additional security measures like locks or video surveillance systems to private areas. |
Provide enhanced technologies such as biometric access5 and intrusion detection. |
|
Enhancements |
Provide barriers capable of resisting tailgating (e.g. speed gates) at the main entrance point, along with progressive access control (i.e., from one zone to another) within the space. |
Install automatic access control systems4, such as electronic locks and readers, to private offices and rooms. |
Fit tamper-resistant5 or security-rated doors to critical areas or rooms, supplemented by additional video surveillance. Provide enhanced walling systems to confidential spaces. |
|
Behaviours |
Train staff to monitor shared spaces and how to identify suspicious activity. | Regularly inspect all devices associated with the physical security systems and promptly address any user-reported issues. |
Introduce additional security protocols such as badge display policies and supervised entry for third-party personnel. |
|
Governance |
Operate and maintain a process for regularly reviewing and updating physical security systems based on user feedback. |
Conduct regular security audits of confidential zones to identify suspicious access patterns and ensure their operation meets user-specific and any applicable regulatory standards. |
|
Note: Users of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
Access Management and Visitor Control
Some shared workspaces have deliberately relaxed entry policies. However, it’s important to strike the right balance between openness and prevention of unauthorised access. It's important that you provide a workspace that manages access well to mitigate risks effectively and provide users with the reassurance they desire. The NPSA website has detailed advice on access control measures.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
System Criteria |
Select visitor management systems suitable for your busiest times and train reception staff on their use. |
Provide users with customisable access systems and clear visitor registration protocols. |
Support advanced visitor pre-approval systems and integrate identity verification solutions. |
|
Enhancements |
Provide staffed receptions in addition to physical security systems. | Deploy electronic access controls (e.g. fobs, keycards or other mobile credentials) for specific spaces. |
Use biometric or multifactor access controls for critical areas, ensuring tamper-resistant entry. |
|
Operational Practices |
Train staff to monitor visitor activity and to recognise suspicious behaviour. | Collaborate with users to ensure workspace visitor policies are followed, such as escorting in private areas and signing in guests. | Ensure visitors are pre-screened and escorted at all times after entering confidential zones. |
|
Governance |
Ensure visitor logs are retained securely and for a defined period and resolve access-related issues transparently. |
Regularly review access logs for user spaces and address non-compliance swiftly. |
Conduct routine audits of access logs and enforce strict policies for user adherence. Undertake root cause analysis of any identified non-compliances. |
Note: Providers of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
Operational Security and Incident Management
Operational security and incident management relates to the role that people, policies and procedures play in the everyday operation of a workspace, and the way in which security issues are handled and resolved. This is important to provide reassurance to users that security incidents are prevented, and that incidents which do occur have a minimal impact.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
Risk Awareness |
Identify potential risks in open environments, such as theft or misuse of shared resources. |
Support users in establishing risk assessment practices for their private spaces. |
Assess high-risk users or zones for targeted threats, such as espionage or sabotage. |
|
Emergency Preparedness |
Develop a range of basic emergency security procedures for staff to follow in the event of an incident at the workspace or nearby. | Work with users to define their space-specific emergency plans while ensuring alignment with workspace-wide arrangements. |
Implement tailored emergency plans, including secure evacuation routes and lockdown capabilities for critical areas and information assets. |
|
Incident Response |
Provide a central point of contact for reporting incidents and advertise this to all users. |
Ensure prompt containment measures for incidents involving sensitive material, coordinating directly with affected users, interested third parties and law enforcement as necessary. | |
|
Incident Learning |
Maintain an incident log and review patterns to make continual improvements to security arrangements. |
Conduct regular reviews of user feedback and audit incidents in detail to refine security measures. |
Hold post-incident reviews to identify lessons learned and collaborate with users to strengthen security arrangements. |
Note: Providers of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
Cyber Security
The security of digital systems and information within shared workspaces requires providers to play a proactive role. Cyber-attacks come in many forms, but the vast majority can be mitigated by implementing a few essential controls.
Cyber Essentials (CE) is the UK Government's baseline standard for cybersecurity for organisations of all sizes. It is designed to help protect against the most common cyber-attacks by implementing five key controls (Firewalls, Secure Configuration, Security update management, User access control and Malware protection). Cyber Essentials is assessed by an independently verified self-assessment whereas Cyber Essentials Plus (CE+) includes a technical audit to verify that the controls are in place. The Cyber Essentials readiness tool provides a series of questions to help organisations prepare for CE. The NCSC’s Cyber Advisor scheme offers cost effective security advice and support that focuses on implementing CE.
The National Cyber Security Centre (NCSC) offers a range of guidance to support organisations, including workspace providers, in protecting their digital infrastructure and minimising the impact of cyber incidents. Providers are encouraged to share the Top tips for staying secure online with users, which has advice that all users should follow to stay secure online and keep their devices safe.
|
|
OPEN |
PRIVATE |
CONFIDENTIAL |
|---|---|---|---|
|
Technical Controls |
Offer secure Wi-Fi. Wi-Fi should be protected with a strong password, ideally with separate networks for visitors and workspace users. |
Achieve relevant cybersecurity accreditations such as CE, CE+, or Information Security certifications such as ISO 27001, to reassure users of a secure information environment. Have a procedure in place for addressing cyber incidents, such as data breaches or network intrusions. |
Work collaboratively with users to support them to manage their cyber security risks using a recognised standard framework. |
Note: Providers of principally ‘Confidential’ workspaces should still consider the applicability of guidance for ‘Open’ and ‘Private’ workspaces. This is because workspaces catering for users with sensitive information often also include an element of open and enclosed workspaces for supplementary or occasional use.
References
IN-TEXT REFERENCES
- ISO 22341:2021, Security and Resilience – Protective Security - Guidelines for crime prevention through environmental design
- National Protective Security Authority (NPSA), Security Overlay to the RIBA Plan of Work
- National Protective Security Authority (NPSA), Windows & Glazed Facades
- National Protective Security Authority (NPSA), Automatic Access Control Systems
- National Protective Security Authority (NPSA), Tamper Indication
ADDITIONAL RESOURCES
- National Cyber Security Centre (NCSC), Cyber Essentials and Cyber Essentials Plus
- IASME and National Cyber Security Centre (NCSC), Get ready for Cyber Essentials
- National Cyber Security Centre (NCSC), Reports & advisories
- Security Service MI5, Threats and Advice
- National Protective Security Authority (NPSA), Threat Information
- National Protective Security Authority (NPSA), Secure Innovation
- National Protective Security Authority (NPSA), Trusted Research
- National Protective Security Authority (NPSA), Security Culture
- Icons obtained through: https://storyset.com/
- Images obtained through: https://unsplash.com

This document has been prepared by Toren Consulting in partnership with NPSA and the NCSC. Toren Consulting was founded on the belief that protecting our people and our belongings is one of the fundamental reasons that humans build. As built environment security design specialists, we aim to be respected professionals and valued members of property design teams. We emphasise a people-first approach, prioritising user experience and collaboration with stakeholders to deliver practical, buildable security solutions.