A concerning email, an escalating grievance, repeated boundary testing or a marked change in behaviour can create immediate pressure to act.
Yet most organisations are not short of people willing to raise concern. They are short of a reliable way to judge what the concern means. Behavioural threat assessment provides that discipline.
It is not a method for predicting who will cause harm, and it should never become a search for a particular type of person. It is a structured process for examining behaviour, communications, circumstances and known stressors so that an organisation can make proportionate decisions.
Done well, it turns uncertainty into an active management plan. Done badly, it becomes a speculative label that damages trust and misses the real issue.
What behavioural threat assessment is really for
The central question is not, Is this person dangerous?
That question encourages overconfidence and binary thinking. The more useful question is, What is happening, what is driving it, and what needs to change to reduce the risk?
A proper assessment looks for a pattern over time.
One angry comment may reflect a difficult day. The same person making specific, repeated statements, becoming fixated on a perceived injustice, ignoring clear boundaries and experiencing significant personal or professional pressure presents a different picture. Context matters. So does the direction of travel.
This approach is relevant well beyond counter terrorism.
It can support decisions involving workplace conflict, concerning communications, fixation on staff or premises, insider risk, safeguarding concerns, domestic abuse that may affect a workplace, and behaviour that indicates deteriorating judgement under pressure.
The exact response will depend on the setting, the available information and the duty of care owed to those involved.
The uncomfortable reality is that many organisations only begin thinking clearly once behaviour has become serious enough to force a response. By then, options may be narrower, relationships may have deteriorated and staff may already feel unsupported.
Early assessment is not about overreacting. It is about noticing change before the organisation is limited to crisis management.
Behavioural threat assessment is not profiling
Protective security can fall into a familiar trap, treating visible characteristics, strongly expressed opinions or an awkward manner as indicators of threat.
They are not. A person may be distressed, difficult or unpopular without presenting a credible risk to others.
Assessment must focus on observable behaviour and credible information. What has been said or done? Who observed it? Is there evidence of persistence, escalation, grievance, fixation, intimidation or an inability to accept boundaries? Are there identifiable targets, opportunities for harmful conduct, or signs that the individual is moving from expression towards action?
This distinction protects both people and organisations. It reduces the risk of discriminatory decision making, keeps the process defensible and directs attention to what can be managed. It also prevents security teams from being used to solve every employee relations problem simply because someone is uncomfortable to deal with.
That does not mean security should step away whenever human resources, safeguarding or line management are involved.
Behavioural risk often sits across functions. The right answer is usually coordinated judgement, not a handover between departments.
The quality of the process determines the quality of the decision
A credible process begins with a clear report and a disciplined record of facts.
Rumour, assumptions and second hand interpretation should be separated from verified information. Staff must know where to raise a concern, what to record and when an immediate response is required.
The assessment then needs the right people around the table. Depending on the case, that may include security, human resources, safeguarding, legal advisers, operational management and wellbeing professionals. Their roles are different, but the shared purpose should be clear: understand the behaviour, determine the level of concern and agree practical actions.
This is where many cases go wrong. Meetings can produce a great deal of discussion without a decision owner, a review date or an agreed standard for escalation. Notes are taken, an individual is described as a concern, and everyone assumes somebody else is managing it. That is not threat management. It is administrative drift.
Every assessment should lead to a proportionate plan.
That plan may involve supportive intervention, clearer workplace boundaries, changes to access arrangements, a welfare referral, improved supervision, engagement with external agencies where appropriate, or a defined escalation route if behaviour continues.
The action is not always restrictive. In some cases, timely support and direct communication reduce risk more effectively than security measures alone.
The plan also needs testing. Who will speak to the individual? What information needs to be shared, and with whom? What would indicate improvement, deterioration or a need to reassess?
Unless those questions have answers, the organisation has recorded a concern without building capability to manage it.
Look for movement, not just severity
A common mistake is to assess only the apparent seriousness of a single incident. Some low level behaviours deserve attention because they are becoming more frequent, more targeted or more determined.
Conversely, a dramatic isolated incident may be resolved quickly when context is understood and the person responds constructively to boundaries.
Movement is often more informative than volume. Is the grievance becoming more personal? Is communication becoming more persistent? Has the individual begun seeking contact with people who have asked not to be contacted? Are colleagues reporting a change in conduct? Has the person disengaged from normal support or oversight?
These questions do not create certainty. Behavioural threat assessment operates in uncertainty, which is why professional judgement matters. The objective is not to produce a score that removes responsibility.
It is to make the best available decision, explain why it was made and review it when circumstances change.
Capability matters more than the policy
Most organisations can produce a policy after an incident.
Far fewer can show that managers, security teams and decision makers know how to use it under pressure. A policy cannot identify a pattern, conduct a difficult conversation or decide whether a concern requires urgent escalation. People do that.
Training should therefore go beyond awareness. Staff need to understand the difference between concern and evidence, how to record factual observations, how to avoid exaggeration, and how to escalate without turning every report into an emergency. Managers need confidence to address behaviour early and respectfully.
Security professionals need to contribute risk judgement without straying into unsupported diagnosis.
Senior leaders have a separate responsibility. They set the conditions in which concerns are either raised early or suppressed. If staff believe reporting will be ignored, or that raising a concern will create trouble for them, warning signs stay hidden. If every report triggers an excessive response, staff stop using judgement and trust declines. The balance is not easy, but it is operationally essential.
For organisations preparing for Martyn’s Law, this is particularly relevant. Protective security arrangements are only as effective as the people operating them.
A venue may have procedures, communications systems and access controls, yet still fail to act on concerning behaviour because staff lack the confidence or authority to report, assess and escalate it.
Fairness is part of risk reduction
Threat assessment can affect livelihoods, reputations and wellbeing.
That is why information handling, confidentiality, documentation and review are not secondary matters. They are central to a fair process.
Information should be relevant, accurate and shared only with those who need it to make or implement a decision. Assessment language should describe behaviour and risk factors, not assign clinical labels or make claims the evidence cannot support. Where action affects an individual, organisations should consider how they will explain expectations, offer appropriate support and record the basis for their decisions.
Fairness does not mean avoiding difficult action. It means taking action that is proportionate, explainable and connected to the facts. This gives teams more confidence to intervene when they should, rather than hesitating because the process feels vague or legally exposed.
A behavioural threat assessment process earns its value in the ordinary cases, not only the exceptional ones. It gives people a way to deal with ambiguity before ambiguity becomes paralysis.
The most useful test is simple, if a manager received a concerning report tomorrow morning, would they know what to do, who to involve and what a good decision looks like? If not, that is the capability gap worth closing.
.
Useful Links:
.
