Page 23 - CITS Theft Guide
P. 23
CITS Guide for Theft Prevention
- 23 -
7. Workforce Security Awareness and Vigilance
Physical and cyber controls are only as effective as the workforce that operates them. A workforce security
awareness and vigilance programme is central to this guide's approach, because it reduces the
complacency that most opportunistic and much organised theft depends on.
7.1. Building a Security Culture
Security culture refers to the shared values, attitudes, and behaviours that make good security practice
the normal, expected way of working on a site, rather than an imposed burden. NPSA's guidance on
embedding security behaviours (see Annex B) recommends working through five levers — Explain, Enable,
Encourage, Engage, and Evaluate — to move a workforce from passive compliance to active vigilance.
7.2. A Structured Process for Developing Security Culture
Proven practice for developing a security culture sets out a seven-step process for turning common-sense
behaviours into common practice on site (see Annex B). CITS recommends this process as a practical
companion to the Explain, Enable, Encourage, Engage, and Evaluate levers described above, because it
gives a repeatable sequence for turning an awareness ambition into a delivered, measurable campaign.
The seven-step security culture process
1. Identify Repeat Activities The routine tasks project team members carry out each day, and the
stakeholder groups who carry them out.
2. Re-Occurring Non-
Compliance
The things done incorrectly each day, and whether this stems from
unawareness of the rules, complacency, or malicious intent.
3. Review Adversarial Risk
Register
Checking whether known risks from the risk register (see Section 4.4) are
made more likely, or their impact amplified, by poor behaviour.
4. Identify Desired
Behaviours
The behaviours that would promote a security culture, and whether
existing rules need to change to mandate them.
5. Campaign Development
Defining what “good” looks like, developing key messages, securing
leadership and communications sign-off, allocating budget, and creating
communication tools.
6. Communicate to
Stakeholders
Selecting the stakeholder group for maximum impact, choosing
communication tools to reach them, and delivering and documenting
the messages.
7. Measure Impact of
Campaign
Gathering stakeholder feedback, monitoring the trend in non-compliant
events, conducting formal reviews, and capturing learning in a post-
campaign report.
When communicating to stakeholders at Step 6, good practice recommends keeping every message
Relevant, Important, and Personal (RIP) to its audience, delivered through storytelling and imagery rather
than dry policy statements, and using humour where appropriate to make messages memorable. This is a
useful reminder that most people on a project are, in practice, busy, social, and creatures of habit, so a
campaign has to work with those tendencies rather than against them if it is to change behaviour.
Adapted from Carpenter’s research on transformational security awareness, five further principles
underpin an effective programme:
(a) have a clear vision of what “good” looks like for the organisation;
(b) view awareness through the lens of the organisation’s existing culture, rather than importing
a generic template;

