Protecting the Human Element: Why Personnel Security is Defence’s Front Line
Interviewee: Stuart Rainsford, Managing Director, CSO & CISO, WorkSec
Q1: To open our discussion, Stuart, could you explain life on the ground for SMEs in the defence sector right now and share how recent regulatory shifts, such as the AGSVA fee increases, have impacted your client base?
Stuart Rainsford: It has been extraordinarily busy. Beyond our standard operations, we recently had to navigate a sudden price increase introduced by AGSVA (Australian Government Security Vetting Agency) with virtually no advance notice – less than 24 hours. It’s a vivid illustration of the operational agility required to run a business within the defence supply chain today.
Q2: Unpacking your specialised focus at WorkSec – what exactly is Security Officer as a Service (SOaaS), and why is it so vital for businesses operating under the DISP framework?
Stuart Rainsford: SOaaS is effectively outsourcing or augmenting a company’s internal Security Officer (SO) function with specialised, external security professionals. Under the Defence Industry Security Program (DISP), member organisations are mandated to achieve and maintain compliance across four fundamental security domains:
| DISP Domain | Core Focus & Functional Scope | Typical Industry Approach |
| Governance | Overarching security policies, risk registers, annual security reporting, and executive oversight. | Often assigned to C-Suite as an extra duty; frequently under-resourced. |
| Personnel | Vetting, clearance sponsorship, travel briefings, change of circumstances, insider threat tracking. | WorkSec SOaaS Primary Focus: Managed actively to eliminate human vulnerabilities. |
| Cyber Security | System protection, Essential 8 compliance, access controls, network monitoring. | Highly saturated market with dedicated MSPs and cybersecurity vendors. |
| Physical Security | Facility access controls, secure storage, accredited physical zones (Secret/Top Secret). | Well-understood by defence contractors with dedicated facility footprints. |
While the market is flooded with technical cyber security providers, the personnel security and governance domains are severely neglected. In most Small to Medium Enterprises (SMEs), the designated Security Officer (SO) is an HR manager, while the Chief Security Officer (CSO) is a Director or C-suite executive. Neither has full-time capacity for security. WorkSec steps in to either execute these governance tasks on their behalf or guide their internal staff, delivering complete, audit-ready governance records for their DISP Annual Security Report.
Q3: What are the day-to-day responsibilities of a DISP Security Officer, and how does WorkSec operationalise these duties?
Stuart Rainsford: The Security Officer is responsible for developing, maintaining, and enforcing the organisation’s security policies and plans. Core responsibilities include:
- Maintaining the Security Register: Managing the Security Assessed Position (SAP) list, which details all staff clearance levels and their operational “need-to-know” justification.
- Incident and Travel Governance: Logically tracking security breaches, suspicious contact reports, overseas travel briefings, and security awareness training logs.
- Vetting Administration: Sponsoring individuals through AGSVA, initiating clearance applications, managing upgrades, downgrades, and revaluations.
- Active Briefings and Support: Serving as the primary point of contact when cleared staff encounter potential security risks, suspicious foreign inquiries, or changes in personal circumstances.
Q4: Why do you describe personnel as the true “front line” of a company’s cyber and security posture?
Stuart Rainsford: Technical cyber controls are essential, but human beings remain the easiest point of leverage for foreign intelligence or malicious threat actors. You can build a fortress-level firewall, but if an employee is vulnerable to coercion or social engineering, your system has an enormous gap. Cyber risk and personnel risk are intrinsically linked through compromised credentials, unmanaged contractors, poor offboarding, and trusted insider threats. Most cyber incidents stem from simple human or process failures rather than complex technical exploits.
Q5: Can you elaborate on how foreign intelligence entities extract information through social engineering, and how WorkSec trains staff to identify it?
Stuart Rainsford: To access classified information, an individual requires both the appropriate security clearance level (Baseline, NV1/Secret, or NV2/Top Secret) and a legitimate need-to-know. Malicious actors rarely ask outright for classified blueprints. Instead, they use subtle elicitation techniques—such as intentionally making a wrong statement to trigger a knowledgeable professional’s natural impulse to correct them.
“One of the most effective ways to extract classified detail is not to ask a question, but to make a deliberately incorrect statement. For example, an operative might casually say: ‘I heard the new Navy class frigates only achieve 25 knots.’ An untrained employee naturally wants to set the record straight: ‘Actually, no, with the upgraded propulsion unit we tested last month, it reaches…’ In five seconds, classified operational performance data is leaked.”
We train cleared personnel to evaluate every unusual interaction using the SOUP framework:
- S – Suspicious: Interactions that feel out of context or overly inquisitive regarding sensitive projects.
- O – Ongoing: Unsolicited contact attempts that repeat over time or across different platforms.
- U – Unusual: Requests or casual inquiries that fall completely outside standard business operations.
- P – Persistent: Pushing for details or continuing contact after being politely rebuffed.
Q6: How do life stressors alter a worker’s security risk profile over time, and what role does the Security Officer play in managing this?
Stuart Rainsford: A security clearance is not a static credential granted once and forgotten. A person’s vulnerability profile evolves as their life circumstances change. Divorce, severe financial stress, mental health struggles, or substance dependency create psychological pressure points that can be exploited for coercion or lead to negligent handling of sensitive data.
Furthermore, AGSVA frequently grants clearances with identified residual risks—such as historical debt, past drug use, or close family ties in non-allied nations. AGSVA notifies both the individual and the sponsor of these risks. As Security Officers, our job is not to penalise the worker, but to actively manage those residual risks alongside them, offering financial counselling, additional travel briefings, or psychosocial support to prevent that vulnerability from becoming a breach.
Q7: Looking ahead, what macro shifts in cyber standards and international frameworks should defence contractors be preparing for?
Stuart Rainsford: We are seeing a major evolution in standardisation. While DISP previously focused heavily on ASD’s Essential 8 Maturity Level 2, many SMEs found these technical controls extremely difficult to meet in cloud-native or hybrid environments. The assessors’ guides were originally written for legacy, on-premises infrastructure.
ASD is now transitioning towards a broader, principles-based framework known as ‘The Essentials’. Simultaneously, Australian suppliers entering the AUKUS supply chain must align with foreign standards such as the US CMMC (Cybersecurity Maturity Model Certification) and NIST frameworks. Defence security is a continuous journey—it requires constant evolution to stay ahead of the threat landscape.
Director Culture & Brand, author and strategist, shaping trusted leadership and thriving teams through transformation and growth.