Awareness as a Driver of Behavioural Change

Introduction

Awareness is a cornerstone of the Security Operations Management System (SOMS). Clause 7.4 of ISO 18788:2015 requires organizations to ensure that personnel are aware of their roles, responsibilities, and the importance of compliance with the security policy, objectives, and procedures.

But true awareness goes beyond distributing manuals or holding briefings. Effective awareness programs and campaigns must change behaviours and habits, creating a culture of responsibility, compliance, and professionalism across all levels of the organization.

Why Awareness Matters in Security Operations

  1. Human factor as the biggest risk – Most security breaches, whether physical or cyber, involve human error or negligence.
  2. Bridging the gap between knowledge and practice – Employees may know the rules but fail to apply them without reinforcement.
  3. Strengthening credibility – Clients and auditors require proof that awareness is not a once-off exercise but an ongoing cultural driver.
  4. Enhancing resilience – In high-risk environments, awareness helps ensure individuals react appropriately under stress.

Building an Awareness Methodology

Awareness in ISO 18788 must follow a structured cycle, aligned with the Plan–Do–Check–Act approach:

Step 1 – Identify Awareness Needs

  • Link awareness themes directly to:
    • Strategic Objectives (e.g., zero human rights violations, client trust).
    • Tactical Objectives (e.g., compliance audits, provincial readiness).
    • Operational Objectives (e.g., proper incident reporting, correct use of force, equipment handling).
  • Use risk registers, incident investigations, and skills audits to pinpoint where awareness is needed most.

Step 2 – Design Awareness Programs & Campaigns

  • Awareness is most effective when it is targeted, engaging, and repetitive.
  • Methods: posters, toolbox talks, e-learning modules, scenario videos, role-playing exercises, newsletters, SMS reminders, gamification challenges.
  • Campaign themes: “See it, Report it”, “Right Action Every Time”, “Respect is Security”, “Incidents are Evidence”.

Step 3 – Deliver Awareness Interventions

  • Integrate into daily operations (shift handovers, supervisor briefings).
  • Use multi-channel delivery (physical posters, digital reminders, workshops, mobile alerts).
  • Ensure leadership visibility: managers and supervisors must model the behaviour being promoted.

Step 4 – Measure Behavioural Change

  • Awareness is not just about participation; it must change behaviour:
    • Fewer repeated incidents of the same type.
    • Improved reporting timeliness and accuracy.
    • Better compliance scores in audits.
    • Demonstrable improvement in Internal Control Effectiveness (ICE) linked to human factors.
  • Use KPIs and surveys to measure before/after changes.

Step 5 – Reinforce & Improve

  • Habits form through repetition and reinforcement.
  • Awareness must be continuous, not campaign-based only.
  • Refresh messages quarterly; link awareness outcomes to Performance Management System (PMS) reviews.

Awareness Topics in a Security Environment

Typical awareness programs under ISO 18788 include:

  • Human Rights & Rules of Engagement – Ensuring proportionality, legality, respect for dignity.
  • Incident Reporting – Timely, factual, and complete documentation.
  • Use of Equipment & Technology – Body-worn cameras, radios, vehicles, surveillance systems.
  • Occupational Health & Safety – Safe patrols, PPE use, emergency drills.
  • Ethics & Anti-Corruption – Refusing bribes, declaring conflicts of interest.
  • Community Engagement – Cultural sensitivity, grievance mechanisms, communication skills.

Documentation and Audit of Awareness

As with competence and training, awareness programs must be documented for audit purposes:

  • Awareness plans and calendars (themes, frequency, target audiences).
  • Campaign materials (posters, presentations, newsletters, toolkits).
  • Attendance logs and participation records (toolbox talks, training sessions).
  • Surveys, test results, or quizzes to measure knowledge retention.
  • Behavioural metrics (incident trends, KPI improvements, ICE scores).
  • Management review minutes noting the impact of awareness programs.

Auditors will look for evidence that awareness is ongoing, relevant, and effective in changing behaviour.

Conclusion

Clause 7.4 of ISO 18788 makes awareness a critical enabler of security operations. In a high-risk environment, awareness programs must go beyond informing employees—they must shift behaviours, create habits, and embed culture.

By following a structured methodology—identifying needs, designing targeted campaigns, delivering engaging programs, measuring behavioural outcomes, and reinforcing messages—organizations ensure that awareness is not cosmetic but transformational.

This is how awareness contributes directly to achieving strategic, tactical, and operational objectives, while satisfying auditors that the SOMS is robust, auditable, and continuously improving.