A reception team receives a report of an unattended item.
A venue manager hears that a staff member has noticed unusual behaviour near an entrance.
A duty manager must decide whether to stop an event, move people, call for support or gather more information.
These are not moments for finding a policy in a shared folder.
A guide to counter terrorism preparedness must begin with the people expected to make decisions when information is incomplete and time is limited.
The uncomfortable truth is that many organisations can demonstrate that they have a plan, training records and security equipment, yet cannot show that their people can recognise concern, communicate clearly or act with sound judgement. Preparedness is not a document state.
It is an operational capability.
Start with the environment, not the template
Counter terrorism preparedness should reflect the way an organisation actually operates.
A busy retail site, a construction project, a transport hub and a corporate office may face common protective security principles, but their exposure, routines, public access, staffing patterns and response options differ markedly.
A copied plan often fails because it assumes conditions that do not exist. It may name roles that are not staffed outside office hours, require communications channels that are unreliable, or set expectations that contractors have never been briefed on. The plan looks complete until a real decision is required.
Start by asking practical questions. Where do people enter, wait and congregate? Which areas are public, controlled or poorly supervised? What changes during deliveries, shift handovers, events, maintenance work or periods of reduced staffing? Who has authority to make immediate decisions, and who takes over if they are unavailable?
This is not an invitation to turn every site into a fortress.
Excessive controls can impede operations, frustrate staff and create a false sense of safety.
The aim is proportionate protection that reflects credible risks and can be maintained on an ordinary working day.
Treat threat, vulnerability and consequence separately
Preparedness becomes confused when organisations collapse three different questions into one.
Threat concerns the intent and capability that may affect the organisation.
Vulnerability concerns weaknesses in the physical environment, processes or behaviours.
Consequence concerns what may happen to people, operations, reputation and recovery if an incident occurs.
A site can have a low likelihood of a particular event and still need good arrangements because the potential consequences are severe.
Equally, an obvious vulnerability is not automatically a reason to install expensive equipment. It may be better addressed by changing supervision, improving access control discipline or giving staff a clearer reporting process.
The value of a proper assessment is not the report itself.
It is the quality of the decisions that follow. It should identify what matters most, where controls are weak in practice, and which improvements will make a measurable difference.
If every finding is marked urgent, none of them is being prioritised.
Build capability around decisions under pressure
Most private sector counter terrorism training tells people what suspicious activity can look like and where to report it. That baseline matters. It is not enough on its own.
People also need to understand what to do with uncertainty.
In real situations, a concern may be vague, a colleague may disagree, and senior support may not be immediately available. Staff need permission to report early, language to describe what they have seen, and confidence that raising a concern will be treated seriously rather than dismissed as an inconvenience.
Managers need a different level of competence.
They must assess information, protect people, coordinate with emergency services where necessary, manage business pressures and record decisions sensibly.
The operational risk is often not a lack of goodwill. It is hesitation, unclear authority or poor communication between teams.
This is where generic awareness sessions reach their limit.
A certificate confirms attendance. It does not demonstrate whether a supervisor can make an appropriate decision on a crowded Saturday afternoon, or whether an out of hours team knows how to escalate a concern.
Capability evaluation is useful because it exposes these gaps without waiting for a live incident. Scenario-based assessment can test whether individuals understand reporting, protective action, communication and their own limits of authority.
Immediate feedback also gives people a practical route to improve, rather than simply a pass or fail outcome.
Make reporting easy and response clear
A reporting process must work for the newest employee, the busiest contractor and the most experienced manager.
If it relies on people remembering a long chain of contacts or deciding whether a concern is sufficiently serious, reports will be delayed or lost.
Staff should know who to tell, how to contact them, what information is useful and what they should not do.
The reporting route should be reinforced through induction, briefings and normal supervision, not left in an annual training module.
Response arrangements need equal clarity.
There should be a shared understanding of who leads, how information is verified, how key people are contacted and how staff, visitors and partners receive instructions. This does not mean writing a script for every possible situation.
It means establishing decision principles that people can apply when the situation does not match the script.
For example, a duty manager may need to balance the need to avoid unnecessary disruption with the need to act promptly to protect people.
That judgement improves when managers have practised discussing uncertainty and consequences.
It deteriorates when the organisation treats any interruption to operations as failure.
Test the joins between teams
Security failures frequently occur at the joins, between security and facilities, operations and reception, landlord and tenant, permanent staff and contractors, or daytime and night-time teams.
Each group assumes another group owns the issue.
A sensible exercise will expose those joins. It should involve the people who would actually receive a report, make decisions, communicate with others and support recovery. Start with discussion-based scenarios, then move to practical testing where appropriate.
The purpose is learning, not catching people out.
Exercises should test ordinary complications. What if the designated lead is unavailable? What if the radio channel is congested? What if a contractor has information but does not know the site terminology? What if a manager receives conflicting accounts?
These are the details that determine whether a response is controlled or confused.
Afterwards, avoid the familiar exercise report that records a handful of observations and is never revisited. Assign owners, set realistic deadlines and test the changes.
If a weakness cannot be fixed quickly, make the residual risk visible to the person accountable for accepting it.
Prepare for Martyn’s Law as a capability issue
For UK organisations within scope, Martyn’s Law has increased attention on public protection, preparedness and organisational duties.
That is necessary, but there is a risk that some businesses will approach it as a procurement or paperwork exercise.
Compliance can establish a minimum standard. It cannot substitute for leadership, local judgement and a workforce that understands its role. A plan that satisfies a requirement but cannot be used by the people on shift is not a credible protective measure.
The better approach is to use legal and regulatory requirements as a prompt to examine actual readiness.
Are risk assessments current? Are roles realistic? Are procedures understood by the people expected to carry them out? Have arrangements been tested at the times and locations where the organisation is most exposed? The answers will often reveal more than a document review.
Use technology to support judgement, not replace it
CCTV, access control, visitor systems and mass notification tools can improve situational awareness and the speed of. communication.
They can also create dependency.
A system is only valuable if operators know what to look for, managers can act on the information, and there is a workable fallback when technology is unavailable.
Technical decisions should therefore follow the operational requirement. Buying equipment before defining the decision it needs to support is a common and expensive mistake.
Ask what information is needed, who needs it, how quickly they need it and what action it should enable.
The same principle applies to digital learning and assessment.
Used well, they offer consistent learning, diagnostic insight and a way to identify capability gaps across a dispersed workforce.
They should complement local briefing, leadership and exercises, not become a substitute for them.
Keep preparedness alive
Preparedness decays when organisations change.
New sites, new tenants, altered opening hours, temporary works, turnover, outsourcing and evolving threats all affect the assumptions made in a security plan.
A yearly review may be adequate for some risks, but it will not catch every operational change that matters.
Build preparedness into normal management.
Review it after significant changes, incidents, near misses and exercises. Ask frontline teams what makes procedures difficult to follow.
They usually know where the gap lies between policy and reality.
The strongest organisations do not claim to be fully prepared. They keep testing what their people can see, decide, communicate and do.
That honest discipline is what turns counter terrorism preparedness from a compliance task into a capability that protects people when it counts.
.
Useful Links:
.
