Page 24 - CITS Theft Guide
P. 24
CITS Guide for Theft Prevention
- 24 -
(c) identify desired secure behaviours within everyday tasks and processes, rather than treating
security as a separate activity;
(d) leverage existing programmes and communication channels within the organisation, rather
than building new ones from scratch; and
(e) be realistic about short-term gains while aiming deliberately for long-term, sustained success.
7.3. Structuring a Multi-Campaign Awareness Programme
Processes that have previously been successful structure workforce awareness delivery as an annual
programme of four themed campaigns, one delivered per quarter, so that the workforce receives a steady
sequence of relevant, focused messaging rather than a single annual briefing (see Annex B). CITS
recommends this quarterly structure as a model that principal contractors can adapt to their own project
calendar and risk priorities.
Quarter Campaign theme
1st Quarter People and personnel security covering insider threat, vetting, and workforce
identity checks (see Section 6).
2nd Quarter Protecting property and theft
reduction
covering equipment marking, immobilisation, and
overnight security (see Section 5).
3rd Quarter Security reporting and response
capability
covering how and when to raise concerns, and the
incident response process (see Section 10).
4th Quarter Cyber security and information
assurance
covering good cyber hygiene and the protection of
BIM and sensitive data (see Section 8).
Each campaign should obtain executive endorsement and, where the organisation has one, sign-off from
its communications function; be built around a unique campaign identifier or logo that acts as a
memorable “flag” for the theme; and be delivered through a multi-media mix of tools suited to a
construction site environment — for example posters, mesh fence banners, portable pop-up banners,
ceiling hanging signs, campaign films featuring site leadership, and simple take-away items such as stickers
or pamphlets. Campaigns should be designed for repeat use in future years, refined each time using the
feedback gathered at Step 7 of the process described above, and, where relevant, coordinated with other
functions such as health and safety and human resources so that the workforce receives a single, joined-
up set of messages rather than competing campaigns.
Larger or higher-criticality organisations should also consider an annual demonstration exercise, run
across the whole programme, to retain an operating licence or satisfy a regulator; CITS notes that the aim
of a mature awareness programme is to spend more time educating the workforce and less time
investigating the consequences of not having done so.
7.4. Employee Education and Training
Employees should receive anti-theft training and regular refreshers, proportionate to the significant cost
that equipment theft represents to a business. Training should be conducted at least annually, should
focus on practical behaviours — key control, reporting suspicious activity, and challenging unfamiliar
visitors — and should conclude with a short assessment so that understanding, not just attendance, can
be confirmed. A nominated employee should act as the site's point of contact on equipment security, and

