Skip to main content

Recommendations for employee security screenings in companies

Thorough employee security screenings help reduce risk for roles that have access to sensitive data. The NCSC's recommendations explain what companies should consider when carrying out screenings, as well as how to interpret the results.

In today's workplace, the integrity and trustworthiness of employees is critical. By conducting thorough security screenings, organisations can minimise potential risks and ensure that only trusted individuals have access to sensitive data, financial resources or critical systems.

The purpose of carrying out security screenings is to confirm that a person does not pose a security risk. The screening should remove any doubts about the employee's integrity, reliability or trustworthiness, and confirm that they are not susceptible to blackmail or bribery because of their lifestyle or circumstances.

Companies should make it clear, both during recruitment and in the employment contract, when security screenings are required and what the consequences may be if concerns are identified. Compliance with the Federal Data Protection Act must also be ensured. The recommendations explain what companies should consider during the screening process and how to interpret the results. They are intended in particular for companies that are required to carry out security screenings for compliance reasons. This includes companies in the electricity and gas sectors, which must take the ICT minimum standard into account.