A control room receives an ambiguous report. A venue manager notices behaviour that does not fit the context. A project team discovers late changes to an access arrangement.

None of these moments is solved by a policy sitting in a shared folder.

They are solved by people who can recognise what matters, make proportionate decisions and act quickly without creating further risk.

That is the future of protective security. It is not a future defined by more technology, more documents or longer compliance checklists.

Those things have a place, but they are not capability. Modern threats expose old security thinking because the environment changes faster than many organisations can review, approve and distribute their procedures.

The organisations that will cope best are not necessarily those with the largest security budgets. They will be the ones that understand their exposure, build sound judgement at every relevant level and test whether their arrangements work under normal operational pressure.

The future of protective security is human and technical

Technology will continue to improve detection, visibility and response. Video analytics can help identify unusual patterns. Access control data can show where safeguards are being bypassed.

Digital reporting can give security teams a clearer picture of recurring concerns across a large estate. Used well, these tools reduce delay and help teams direct attention where it is needed.

But technology does not remove the need for judgement. It changes where judgement is required.

A system may flag an anomaly, but someone still has to decide whether it is relevant, who needs to know and what action is proportionate. A technical security system can record an event, but it cannot build trust with staff who are unsure whether reporting a concern will be taken seriously.

Nor can it resolve confusion between security, operations, facilities and senior management during a developing incident.

The mistake is to treat technical investment as a substitute for competent people. It is more accurate to see it as an amplifier. Good people using suitable systems become more effective. Poorly prepared teams can simply receive more alerts, more data and more opportunities to miss the point.

This matters especially in complex environments such as retail, transport, construction, hospitality and public venues. Security decisions are rarely made in isolation. They affect customer experience, staff workload, programme delivery, commercial priorities and safety.

The right answer depends on the threat, the vulnerability and the consequences, not on a generic rule applied without thought.

Documentation does not equal readiness

There is an uncomfortable truth in protective security, many organisations can demonstrate that they have completed an exercise without demonstrating that they can perform when it counts.

A risk assessment can identify weaknesses. A security plan can allocate responsibilities. Training can give people a common language. All are valuable. None proves that staff will recognise a developing problem, communicate clearly or make a defensible decision when information is incomplete.

This is particularly relevant as UK organisations prepare for Martyn’s Law. The direction of travel is clear. Protective security and preparedness will require greater attention from those responsible for publicly accessible locations. The sensible response is not to produce documents solely to satisfy a requirement. It is to use the requirement to address the gap between what the organisation says it can do and what its people can actually do.

A useful question for any security manager is simple, if an unfamiliar but credible concern was raised this afternoon, would the right people know how to assess it, escalate it and manage the consequences? If the answer is uncertain, the issue is not a lack of policy.

It is a capability gap.

Build capability before the incident

Capability is not one training course or one annual exercise. It is the combined ability of people, systems and leadership to operate effectively in the conditions they are likely to face.

That starts with a realistic understanding of the operating environment. Generic threat statements have limited value when they are not connected to a site, event, project or organisation.

Teams need to understand what is significant in their context: the people present, the physical layout, operational routines, dependencies, public interface and likely points of pressure.

Train judgement, not just recall

Many security training programmes are designed around information transfer.

Staff are told what a threat looks like, what policy says and who to contact. This establishes a baseline, but it is only the starting point.

People need opportunities to apply that knowledge. Short scenario based evaluation is often more revealing than a pass or fail course completion record. It shows whether an individual can distinguish between a routine issue and a concern requiring escalation. It also exposes uncertainty early, when it can be corrected without consequence.

The most useful learning is specific. A front of house team needs a different level of understanding from a security manager. A project manager responsible for temporary works, site access and contractors faces different decisions again.

Everyone does not need the same expertise, but everyone needs enough competence for their role.

Make reporting easier than staying silent

Protective security often succeeds or fails at the point of reporting.

Staff may notice something unusual but dismiss it because they lack confidence, assume someone else will deal with it or fear being seen as overreacting.

Organisations need clear reporting routes, but clarity alone is not enough. Leaders must show that proportionate reporting is valued. Feedback matters. If people repeatedly raise concerns and hear nothing further, they learn that reporting is performative. If they receive sensible feedback, including when a concern proves benign, they become better at identifying and communicating what is relevant.

This is behavioural risk management in practice.

It is about shaping the decisions people make when no manager is standing beside them.

Test the handovers between teams

The most significant failures are often found between functions rather than within them. Security may have a sound escalation process, while operations have a separate incident process. Facilities may manage contractors without seeing relevant security information.

Senior leaders may expect to be informed, but nobody has agreed what information they need or when.

Exercises should test these handovers. Not theatrical scenarios designed to impress observers, but credible situations that require people to share information, prioritise action and deal with uncertainty. The learning usually lies in the practical detail: contact information is out of date, authority is unclear, a key decision takes too long, or staff are unsure who owns the next step.

Finding those weaknesses is useful. Pretending they do not exist is expensive.

Security leaders will need broader operational judgement

The future protective security practitioner will need technical awareness, but technical knowledge alone will not be enough.

They will need to explain risk in language that boards, operational managers and frontline teams can act on. They will need to understand how commercial pressure can weaken controls and how poorly designed controls can damage normal operations.

That requires a shift in how security performance is assessed. Counting patrols, incidents logged or courses completed may provide management information, but it does not tell you whether capability has improved. Better measures examine the quality of decisions and the speed of effective action.

For example, can teams identify vulnerabilities before a change goes live? Do managers challenge poor assumptions during planning? Are reports sufficiently clear for the next person to act? Can the organisation account for what it learned from exercises, near misses and routine concerns?

These questions are harder than counting certificates. They are also far more useful.

Start with an honest capability diagnostic

Organisations do not need to rebuild everything at once.

The first step is to establish what is genuinely working and where confidence is being mistaken for evidence. A structured capability diagnostic can assess knowledge, decision making, reporting, leadership, planning and response arrangements across relevant roles.

The results should guide development. Some organisations will need a sharper threat, vulnerability and risk assessment. Others may have suitable plans but weak staff awareness. A security team may be technically capable while managers responsible for operations lack the confidence to make early, proportionate decisions. There is no universal fix because exposure and maturity differ.

The aim is not to create a perfect security posture. It is to build an organisation that can notice change, make sound decisions and improve continuously. That is a more realistic standard, and a more resilient one.

Protective security will always involve physical measures, technical systems, plans and procedures. The difference in the years ahead will be whether the people behind them can turn that preparation into effective action when the situation is unclear. Ask what your teams would do, not simply what your documents say.

The answer is where meaningful improvement begins.

.

Useful Links:

.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center