A venue manager asks for counter terrorism training.
A security team receives an anti terrorism policy. A board seeks assurance that the organisation is prepared for Martyn’s Law.
The language sounds interchangeable, but it can conceal a serious gap in responsibility and capability. Anti terrorism versus counter terrorism is not a semantic argument.
The distinction affects what an organisation should plan for, what its people need to practise, and where its role properly begins and ends.
For most private sector organisations, the practical question is not which label sounds stronger. It is whether people can recognise concern, make sound decisions, communicate clearly, protect life and sustain an effective response when conditions are confused and time is limited.
Why the language matters
Anti terrorism usually describes defensive measures intended to reduce opportunity, vulnerability and harm.
In the UK, the two phrases have been lumped into one over the last few years.
It is the protective security work that makes a site, event, service or organisation harder to exploit and better able to cope with an incident. Access arrangements, security culture, reporting routes, sensible physical security, staff awareness and emergency planning all sit comfortably within this space.
Counter terrorism is broader. In a UK context, it includes the national effort to prevent terrorism, pursue those involved, protect the public and prepare for consequences.
It involves intelligence, investigation, disruption and operational activity carried out by the appropriate authorities, alongside protective security and resilience.
The distinction matters because a business cannot, and should not, pretend to conduct counter terrorism in the way police, intelligence and specialist government bodies do. Its contribution is different but still important. A competent organisation can identify and report concerns, reduce avoidable vulnerabilities, support the emergency services and manage its own people, premises and operations.
Calling everything counter terrorism can create false confidence.
It may encourage leaders to believe that a briefing, a policy and a few signs of security activity amount to a meaningful capability. They do not. Equally, treating anti terrorism as merely guards, barriers and cameras misses the central issue, people make the decisions that determine whether those measures work.
Anti terrorism versus counter terrorism in practice
Think of anti terrorism as the organisation’s protective posture.
It asks practical questions. What is valuable or vulnerable here? Where could poor design, inconsistent routines or weak supervision create avoidable exposure? Do staff know what requires escalation? Can managers make proportionate decisions without creating panic or unnecessary disruption?
Counter terrorism includes that protective posture but extends beyond it. It brings in the wider system of threat assessment, intelligence-led investigation, intervention, disruption, emergency response and recovery. This is why the term is often used in corporate security, yet it should be used carefully.
A business may support the counter terrorism effort, but it is not the lead operational actor.
That boundary is not a limitation. It is a discipline. Security teams are most effective when they understand their authority, their reporting thresholds, their local knowledge and the decisions they own.
They become less effective when asked to behave like intelligence officers or when they collect information without a clear purpose, lawful basis or escalation route.
For a retail estate, anti terrorism might mean designing workable search and access processes, briefing staff on behavioural indicators of concern, ensuring contractors are managed consistently and testing communication arrangements. For an event organiser, it may mean integrating protective security with crowd management, stewarding, medical provision and incident command.
For a corporate office, it may centre on visitor management, mail handling, workplace reporting and leadership response.
The setting changes. The requirement for clear judgement does not.
The uncomfortable reality of protective security
Many organisations have security measures that look credible during a walkthrough but fail during a busy shift.
A reception procedure may be bypassed when queues build. A reporting process may exist, but staff may fear getting it wrong or troubling a manager. A crisis plan may name decision makers who are unavailable outside office hours.
These are not minor administrative defects.
They are indicators that the organisation has documented intent rather than tested capability. Terrorism preparedness is not proved by the presence of a policy.
It is demonstrated by how people notice, decide, communicate and act when normal routines are disrupted.
Where Martyn’s Law changes the conversation (In UK)
Martyn’s Law has rightly focused attention on preparedness in publicly accessible locations.
Yet the risk is that some organisations will approach it as a compliance project with a fixed list of documents, training records and physical measures. That approach may satisfy an early assurance conversation, but it does not necessarily prepare a workforce for an unfolding incident.
The stronger approach starts with an honest assessment of the operating environment. Who is present, at what times, and doing what? How does the site really function during peaks, deliveries, maintenance, staff shortages or competing incidents? What decisions would supervisors need to make before senior support arrives? Where are communications likely to fail?
This does not require every employee to become a security specialist.
It requires roles to be defined properly. Frontline staff need enough awareness to recognise and report. Supervisors need confidence to assess immediate priorities and direct people. Security practitioners need the technical and operational understanding to advise leaders, manage protective measures and work effectively with responding authorities. Senior leaders need to know what good looks like and how to test it.
A single annual presentation rarely achieves this.
Knowledge fades when it is not used, and people often overestimate their readiness until a scenario exposes hesitation.
Short, targeted learning reinforced through realistic discussion, assessment and exercising produces more useful evidence of competence than attendance alone.
Build capability around decisions, not just measures
Protective security is often purchased as equipment or written as process. Both have a place, but neither compensates for poor judgement.
A camera system does not decide whether an observation is meaningful. A procedure does not ensure a supervisor challenges unsafe practice. An emergency plan does not make a team communicate well under stress.
Start by identifying the decisions that matter in your environment.
These may include when to report a concern, who has authority to pause an operation, how to manage uncertain information, when to contact emergency services, and how to account for staff and visitors. Then examine whether the people expected to make those decisions have the knowledge, confidence and support to do so.
This is where capability diagnostics are valuable.
They reveal whether an individual can apply knowledge, rather than simply recognise familiar terminology. A practitioner who knows the names of security principles but cannot prioritise action in a realistic scenario has a development need. So does a manager who believes a plan is workable but has never tested it with the people who must use it.
Testing should be proportionate.
A small hospitality business does not need the same programme as a major transport operator or critical infrastructure site. But every organisation can ask staff to work through credible, non-sensitive scenarios, identify uncertainty and agree how decisions will be communicated.
The purpose is not to catch people out. It is to expose assumptions while there is time to correct them.
Avoid the false choice between prevention and response
Some teams focus heavily on preventing an incident, while others concentrate on response and recovery.
Both are necessary. Prevention without preparation leaves an organisation exposed when controls fail. Response planning without preventive thinking accepts vulnerabilities that could have been reduced earlier.
Anti terrorism measures should make harmful activity harder, increase the chance that concerns are noticed and improve the organisation’s ability to protect people.
Counter terrorism awareness should help personnel understand how their actions fit within a wider public safety system. Neither works in isolation from everyday operational discipline.
Good security is not theatre.
Excessively visible measures that staff cannot explain, apply consistently or maintain may create inconvenience without reducing risk. Conversely, quiet controls that are understood, rehearsed and supervised can be highly effective.
The right balance depends on the threat picture, the environment, the people using it and the consequences of getting it wrong.
A more useful standard for leaders
Senior decision makers should be wary of simple assurances.
Ask whether the organisation can show how its arrangements work on a difficult day, not merely where the documents are stored. Ask whether security, operations, facilities, HR and communications understand their respective roles. Ask whether contractors and temporary staff are included. Ask what recent testing has revealed and what has changed as a result.
The most useful answer is rarely perfect.
It is specific. It acknowledges where capability is strong, where it is unproven and what will be improved next. That is the difference between managing a security file and managing real risk.
Anti terrorism and counter terrorism are connected, but they are not interchangeable.
Organisations that understand the boundary can make a more credible contribution, protecting their people, supporting the wider response and building the judgement that matters when paperwork is no longer enough.
.
Useful Links:
.
