
WORKPLACE SECURITY THREAT AND ACTIVE ATTACKER PREPAREDNESS GUIDE
Practical guidance for preparing workplaces for security incidents, violence, suspicious packages, bomb threats, civil unrest, and active attacker situations.
Purpose of this page
This page supports Disaster Guide 2026 users by providing high-level, practical preparedness content for man-made emergencies and workplace security threats. It is written for organizations that need to strengthen early reporting, internal notification, access control, lockdown and evacuation procedures, police coordination, and post-incident recovery.
Understanding man-made disasters and workplace security threats
Security-related emergencies may include threatening behaviour, workplace violence, unauthorized access, suspicious packages, bomb threats, civil unrest, intentional property damage, sabotage, active attacker events, or other human-caused threats. These incidents may develop gradually through concerning behaviour or messages, or they may occur suddenly. The organization’s goal is to encourage early reporting, responsible escalation, and practical protective action.
Prevention begins before the incident
Preparedness does not rely only on what staff do during a crisis. Organizations should maintain visitor management procedures, access control expectations, internal reporting channels, staff awareness training, documentation practices, and a clear process for escalating concerning behaviour or threats. Reception personnel, security staff, supervisors, managers, and public-facing employees should know how to preserve information, notify the right people, and avoid actions that could escalate a situation unnecessarily.
Build a clear reporting culture
Staff should know what to report, how to report it, and what will happen after they report. Reportable concerns may include threats, unusual messages, suspicious objects, unauthorized access attempts, aggressive behaviour, stalking or harassment concerns, property damage, or statements suggesting potential violence. The process should be simple enough to use under stress and should identify emergency contacts, supervisors, security personnel, building management, and police notification triggers.
Internal notification and decision-making
The emergency plan should identify who initiates the internal response, who contacts police, who notifies building management, who communicates with staff, who documents the incident, and who has authority to order protective actions. Depending on the situation, protective actions may include evacuation, lockdown, shelter-in-place, controlled access, relocation, suspension of operations, or waiting for police direction. Decisions should be based on available information, site procedures, building procedures, and official instructions.
Active attacker preparedness
Active attacker incidents are rare but high consequence. Training should remain high-level, practical, and focused on life safety. Staff should understand that the appropriate action may vary depending on their location, proximity to the threat, available exits, ability to secure an area, and instructions from police or emergency services. The organization should avoid overly complicated instructions and instead train practical principles that staff can remember and apply during stress.
Lockdown and shelter-in-place procedures
Lockdown procedures should explain how staff are notified, how doors or areas are secured when possible, how people move out of sight, how noise and movement are reduced, how emergency communications are managed, and how staff should respond when police arrive. Shelter-in-place may apply to external threats, civil unrest, police activity nearby, hazardous materials outside the building, or other conditions where remaining inside is safer than leaving.
Evacuation during security threats
Evacuation may be appropriate if there is a safe route away from danger and staff can leave without moving toward the threat. Procedures should identify exits, alternate routes, assembly or accountability expectations, and how staff report their status. Staff should be reminded not to re-enter until authorities or designated leadership confirm it is safe.
Bomb threats and suspicious packages
Personnel who receive calls, messages, mail, deliveries, or public contact should know how to respond calmly to suspicious circumstances. Staff should preserve information, record details where possible, avoid touching suspicious items, notify the internal emergency team, and ensure police and building management are involved in assessment and decision-making. A bomb threat checklist can support calm information gathering and documentation.
Post-incident recovery and support
After a security incident, the organization should account for staff, preserve records, cooperate with police, communicate carefully with employees and stakeholders, support affected personnel, and review the effectiveness of procedures. Recovery may include temporary closure, counselling support, repairs, access control changes, staff briefings, media management, corrective actions, and updates to the emergency response plan.
Suggested call to action
Need help developing workplace security threat procedures, active attacker awareness training, lockdown protocols, suspicious package response, or security tabletop exercises? KGICA can support organizations with practical, site-specific, non-sensationalized preparedness guidance focused on life safety and operational readiness.
PREPAREDNESS CHECKLIST
Threat reporting process
Ensure staff know how and when to report concerning behaviour, messages, calls, objects, or unauthorized access.
Visitor and access control
Maintain sign-in procedures, access restrictions, ID expectations, and controls appropriate to the site.
Evacuation and shelter options
Train staff to understand when evacuation, lockdown, or shelter-in-place may be required.
Police and building coordination
Align protective actions with building procedures, security personnel, and emergency services.
Escalation roles
Identify who contacts police, alerts building management, notifies leadership, and documents information.
Lockdown notification method
Provide a fast way to instruct staff during immediate security threats.
Bomb threat checklist
Support calm information gathering and preservation of details for police assessment.
Post-incident support plan
Align protective actions with building procedures, security personnel, and emergency services.


Should every workplace have lockdown procedures?
Any workplace exposed to public access, security threats, violence risk, nearby police activity, or external threats should consider documented lockdown or shelter-in-place procedures adapted to the site.
What should staff do if they see concerning behaviour?
They should report early using the organization’s reporting process. If there is immediate danger, staff should contact emergency services when safe to do so and follow site-specific procedures.
Is active attacker training the same for every workplace?
No. Training should be adapted to the building layout, exits, access control, occupancy, staff roles, public access, communications, and police or building procedures.
Who should be trained on bomb threats and suspicious packages?
Reception staff, security staff, mailroom personnel, public-facing employees, supervisors, and anyone likely to receive calls, messages, deliveries, or public contact should receive role-specific guidance.
What happens after a security incident?
The organization should account for people, cooperate with police, preserve records, communicate carefully, support affected staff, review procedures, and implement corrective actions.
