Protecting the Human Element: Why Personnel Security is Defence’s Front Line

Discover how WorkSec's Security Officer as a Service (SOaaS) helps Australian defence contractors manage DISP personnel security, AGSVA clearances and insider threats.

Protecting the Human Element: Why Personnel Security is Defence’s Front Line

Interviewee:  Stuart Rainsford, Managing Director, CSO & CISO, WorkSec

Q1: To open our discussion, Stuart, could you explain life on the ground for SMEs in the defence sector right now and share how recent regulatory shifts, such as the AGSVA fee increases, have impacted your client base?

Stuart Rainsford: It has been extraordinarily busy. Beyond our standard operations, we recently had to navigate a sudden price increase introduced by AGSVA (Australian Government Security Vetting Agency) with virtually no advance notice – less than 24 hours. It’s a vivid illustration of the operational agility required to run a business within the defence supply chain today.

Q2: Unpacking your specialised focus at WorkSec – what exactly is Security Officer as a Service (SOaaS), and why is it so vital for businesses operating under the DISP framework?

Stuart Rainsford: SOaaS is effectively outsourcing or augmenting a company’s internal Security Officer (SO) function with specialised, external security professionals. Under the Defence Industry Security Program (DISP), member organisations are mandated to achieve and maintain compliance across four fundamental security domains:

DISP DomainCore Focus & Functional ScopeTypical Industry Approach
GovernanceOverarching security policies, risk registers, annual security reporting, and executive oversight.Often assigned to C-Suite as an extra duty; frequently under-resourced.
PersonnelVetting, clearance sponsorship, travel briefings, change of circumstances, insider threat tracking.WorkSec SOaaS Primary Focus: Managed actively to eliminate human vulnerabilities.
Cyber SecuritySystem protection, Essential 8 compliance, access controls, network monitoring.Highly saturated market with dedicated MSPs and cybersecurity vendors.
Physical SecurityFacility access controls, secure storage, accredited physical zones (Secret/Top Secret).Well-understood by defence contractors with dedicated facility footprints.

While the market is flooded with technical cyber security providers, the personnel security and governance domains are severely neglected. In most Small to Medium Enterprises (SMEs), the designated Security Officer (SO) is an HR manager, while the Chief Security Officer (CSO) is a Director or C-suite executive. Neither has full-time capacity for security. WorkSec steps in to either execute these governance tasks on their behalf or guide their internal staff, delivering complete, audit-ready governance records for their DISP Annual Security Report.

Q3: What are the day-to-day responsibilities of a DISP Security Officer, and how does WorkSec operationalise these duties?

Stuart Rainsford: The Security Officer is responsible for developing, maintaining, and enforcing the organisation’s security policies and plans. Core responsibilities include:

  • Maintaining the Security Register: Managing the Security Assessed Position (SAP) list, which details all staff clearance levels and their operational “need-to-know” justification.
  • Incident and Travel Governance: Logically tracking security breaches, suspicious contact reports, overseas travel briefings, and security awareness training logs.
  • Vetting Administration: Sponsoring individuals through AGSVA, initiating clearance applications, managing upgrades, downgrades, and revaluations.
  • Active Briefings and Support: Serving as the primary point of contact when cleared staff encounter potential security risks, suspicious foreign inquiries, or changes in personal circumstances.

Q4: Why do you describe personnel as the true “front line” of a company’s cyber and security posture?

Stuart Rainsford: Technical cyber controls are essential, but human beings remain the easiest point of leverage for foreign intelligence or malicious threat actors. You can build a fortress-level firewall, but if an employee is vulnerable to coercion or social engineering, your system has an enormous gap. Cyber risk and personnel risk are intrinsically linked through compromised credentials, unmanaged contractors, poor offboarding, and trusted insider threats. Most cyber incidents stem from simple human or process failures rather than complex technical exploits.

Q5: Can you elaborate on how foreign intelligence entities extract information through social engineering, and how WorkSec trains staff to identify it?

Stuart Rainsford: To access classified information, an individual requires both the appropriate security clearance level (Baseline, NV1/Secret, or NV2/Top Secret) and a legitimate need-to-know. Malicious actors rarely ask outright for classified blueprints. Instead, they use subtle elicitation techniques—such as intentionally making a wrong statement to trigger a knowledgeable professional’s natural impulse to correct them.

“One of the most effective ways to extract classified detail is not to ask a question, but to make a deliberately incorrect statement. For example, an operative might casually say: ‘I heard the new Navy class frigates only achieve 25 knots.’ An untrained employee naturally wants to set the record straight: ‘Actually, no, with the upgraded propulsion unit we tested last month, it reaches…’ In five seconds, classified operational performance data is leaked.”

We train cleared personnel to evaluate every unusual interaction using the SOUP framework:

  • S – Suspicious: Interactions that feel out of context or overly inquisitive regarding sensitive projects.
  • O – Ongoing: Unsolicited contact attempts that repeat over time or across different platforms.
  • U – Unusual: Requests or casual inquiries that fall completely outside standard business operations.
  • P – Persistent: Pushing for details or continuing contact after being politely rebuffed.

Q6: How do life stressors alter a worker’s security risk profile over time, and what role does the Security Officer play in managing this?

Stuart Rainsford: A security clearance is not a static credential granted once and forgotten. A person’s vulnerability profile evolves as their life circumstances change. Divorce, severe financial stress, mental health struggles, or substance dependency create psychological pressure points that can be exploited for coercion or lead to negligent handling of sensitive data.

Furthermore, AGSVA frequently grants clearances with identified residual risks—such as historical debt, past drug use, or close family ties in non-allied nations. AGSVA notifies both the individual and the sponsor of these risks. As Security Officers, our job is not to penalise the worker, but to actively manage those residual risks alongside them, offering financial counselling, additional travel briefings, or psychosocial support to prevent that vulnerability from becoming a breach.

Q7: Looking ahead, what macro shifts in cyber standards and international frameworks should defence contractors be preparing for?

Stuart Rainsford: We are seeing a major evolution in standardisation. While DISP previously focused heavily on ASD’s Essential 8 Maturity Level 2, many SMEs found these technical controls extremely difficult to meet in cloud-native or hybrid environments. The assessors’ guides were originally written for legacy, on-premises infrastructure.

ASD is now transitioning towards a broader, principles-based framework known as ‘The Essentials’. Simultaneously, Australian suppliers entering the AUKUS supply chain must align with foreign standards such as the US CMMC (Cybersecurity Maturity Model Certification) and NIST frameworks. Defence security is a continuous journey—it requires constant evolution to stay ahead of the threat landscape.

Sari Mustonen-Kirk
Sari Mustonen-Kirk

Director Culture & Brand, author and strategist, shaping trusted leadership and thriving teams through transformation and growth.

Share this article

More Insights

Read WorkSec insights and expert commentary on security clearances, defence industry trends, personnel security, compliance, and Australia’s evolving secure workforce.

Insights
Mon 13 Jul

Shifting the Compliance Paradigm: One Paddock, One Cow, and the Future of Australian Personnel Security

Australia’s PSPF Direction 003-2025 clamps down on advertising security clearances online, with Defence Industry and DISP entities expected to tighten policies, training and spot checks.

Insights
Tue 25 Nov

PSPF Direction 003-2025: Online Disclosure of Security Clearances

Australia’s PSPF Direction 003-2025 clamps down on advertising security clearances online, with Defence Industry and DISP entities expected to tighten policies, training and spot checks.

Insights
Sat 25 Oct

Cleared Careers Part 2: The Security Cleared Talent Pool

Competition for security-cleared talent in Australia’s defence and government sectors is surging, with WorkSec helping candidates navigate eligibility, suitability, and sponsorship to build trusted, cleared careers.

Insights
Sat 25 Oct

Cleared Careers Part 1: The Cleared Industry

Teaming and partnering in the defence sector help businesses meet DISP sponsorship and compliance needs with trusted, cleared workforces.

Insights
Fri 30 May

Defence Industry Leadership – The Business of Trust

Trust in defence industry supply chains is at the heart of bolstering our national security.

START YOUR PATH TO INDUSTRY-READY CAPABILITY

Whether you’re an individual seeking security clearance sponsorship or an organisation needing personnel security governance, reach out to WorkSec today to take the next step in securing your future.

Get Started Background

Sari Mustonen-Kirk

Director Culture & Brand
Sari Mustonen-Kirk

Sari is WorkSec’s Director Culture & Brand, a recognised thought leader in business transformation, growth, and trusted leadership. With more than thirty years’ experience building and leading Dream Teams across financial services, sales, technology, and personnel security, Sari brings a unique 360-degree approach that blends governance, risk and compliance with creativity, brand strategy, and cultural development. A twice-published author and best-selling podcast producer and host, she is widely respected for her ability to translate complex ideas into practical frameworks for people and businesses to thrive.

At WorkSec, Sari is responsible for refining the company’s brand identity, embedding a strong Employee Value Proposition, and collaborating with the executive team to build a Trusted Workforce culture with Trusted Leadership at its core. She is shaping and maturing WorkSec’s key service offerings, including the Security Officer as a Service (SOaaS) and Trusted Workforce Program for Individuals (TWPI), ensuring they deliver both compliance assurance and high-touch client value. Her focus also includes enhancing the Employment Suitability Check (ESC) framework and advancing WorkSec’s governance and reporting models to meet evolving DISP and AGSVA requirements.

Sari continues to research and anticipate shifts in Defence and Government legislation, DISP, and PSPF/DSPF frameworks, ensuring WorkSec remains a leader in personnel security governance. She is currently developing her third book, ‘Trusted – A Playbook for Leaders’, which will showcase her Trusted Leadership model and the lessons drawn from WorkSec’s own journey. Known for her vision, authenticity, and commitment to people, Sari is instrumental in strengthening WorkSec’s culture and positioning the business as a market leader.

Connect with Sari