Recommended Starting Points
These are the fundamental guidance articles to start with - scroll down for more specific guidance and related content
Introductory Level
This guidance is for users of shared workspaces and provides practical advice tailored to your workspace and activities
Get started here with an overview of security culture and why it’s important.
This webpage outlines five key principles underpinning NPSA advice and guidance
Access NPSA’s tools and resources that can support you as you look to improve your security culture
NPSA’s Passport to Good Security for Senior Executives sets out 20 principles for effective security management
Hostile actors can use international business and engagement as a way of gaining access and influence in order to harm your interests or the national security of the UK.
NPSA have released new election protective security guidance on protecting pedestrian queues
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
Consider security early when seeking investment to protect your company and help you prepare for the National Security and Investment Act
Physical and personnel security measures for major events require specific consideration due to their dynamic and complex character.
Protected Procurement is guidance for businesses and organisations to help embed security across supply chains and to protect from supply chain attacks. Created in partnership with CIPS
The Think before You Link campaign, on which the TBYL App is based, can help keep you, your colleagues, and the country safe from being targeted by malicious profiles online
If implemented early enough, mitigations will be a necessary part of risk management when doing business with overseas parties.
Developing a risk based plan to doing business with overseas parties is essential to ensure success.
Being aware of government’s business screening requirements will allow you to be mindful of any national security threats.
NPSA has developed innovative, immersive exercises to help you experience insider events in a safe space. This allows you to test your crisis communications response, using effective communication to break down organisational silos
Good governance and proactively considering security in business plans with overseas parties sets the tone of your risk appetite.
Intermediate Level
All organisations need to ensure they have the processes and procedures in place to deliver an effective, efficient and compliant security provision
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Financial Sector
Protective Security Management Systems Case Study from the Transport sector
Discover how to deter, detect and deny those seeking to cause harm
Security-Mindedness is about encouraging business leaders, managers and practitioners to consider security across all areas of your organisations
This guidance is designed to help workspace providers provide the safety and collaboration that your users seek.
Guidance for organisations’ senior leaders, highlighting the importance of senior leadership in achieving effective security
Guidance covering a wide range of topics that will help keep your public premises and events safe and secure, intended both for security managers and other managers whose responsibilities include security
Guidance on providing security information during the first 12 months of the employee lifecycle.
Assess your organisation’s personnel security maturity to build resilience
The recommended approach to selecting personnel security metrics
What does good security behaviour look like in your organisation?
Data centres are a valuable target for threat actors seeking to steal data or disrupt operations and services. Data centre owners should assume that a cyber compromise is inevitable. We advise taking steps to detect intrusions and minimise their impact and preventative cyber security measures.
Advanced Level
Guidance to provide high level, practical advice to anyone looking to formulate a Site Security Plan, assisting in developing a proportionate plan which aims to mitigate Terrorist and State threats, whilst supporting in countering many other types of security or safety threats.
All Levels
The document comprises a Code of Practice (CoP) for security-informed safety in the rail sector and provides guidance on security issues for railway safety engineers and managers
Advice and recommendations for mitigating this type of insider behaviour
A Security Considerations Assessment (SCA) is a structured process for ensuring that potential security-related vulnerabilities are considered across a range of activities and processes
Information Management Clause, including requirements for a security-minded information management approach
Information Management Clause, including requirements for a security-minded information management approach
This guidance follows the NPSA protective security risk management (PSRM) approach, and demonstrates a systematic basis for an organisation to develop a proportionate and effective protective security strategy to manage security threats
This table can be completed by organisations to prepare a baseline assessment of their critical assets, adding additional lines if necessary
A programme of monitoring and review should be in place to enable potential security issues, or personal issues that may impact on an employee's work, to be recognised and dealt with effectively.
Passport to Good Security - Identify your Most Valuable Assets: understanding which assets are critical to your organisation’s existence and operation should be the starting point in your protective security planning process.
Passport to Good Security - Good Governance: in your role as a manager with responsibility for security matters, you should aim to identify answers to key questions about the governance arrangements your organisation has (or may not have) in place for security risks.
The Insider Risk programme should be continuously reviewed to measure the effectiveness of any resources used and that it correctly reflects the current threats and vulnerabilities in your organisation.
Employment screening comprises the procedures involved in deciding an individual's suitability to hold employment in a given job role.
Effective education and training is necessary to ensure individuals know what policies, standards, guidelines and procedures are in place to maintain security.
Appropriate investigation and disciplinary practices are essential in ensuring that disproportionate actions are minimised and adherence to security policies and processes are reinforced.
Passport to Good Security - Security Pre-Screening: pre-screening of employees, contractors and service providers should be included as part of your overall organisation security strategy.
An insider risk programme should integrate effectively with the organisation’s overall communications’ strategy.
How will you embed the desired security behaviours and culture in your organisation?

