A security contract can look convincing on award day and still fail at the point that matters. The supplier has the right accreditations, the proposal is polished, and the price fits the budget. Yet the people on site may not understand the risk picture, supervisors may lack authority, and no one may test whether the service works under pressure. This guide to security procurement starts with a harder question: what capability must your organisation have when normal operations are disrupted?

Procurement is not an administrative exercise that follows a security decision. Done properly, it is part of the security decision itself. It determines the people, systems, standards, leadership and assurance arrangements available when an incident occurs. Get it wrong and an organisation buys a presence, a portal or a policy. Get it right and it builds a service that can recognise concern, make sound decisions and act.

Start Security Procurement With the Operating Reality

The first procurement mistake is writing a specification before understanding the problem. A standard requirement for a fixed number of officers, patrols, CCTV cameras or training hours may be easy to tender, but ease is not the same as effectiveness.

Begin with the environment in which the service must operate. A busy venue, construction project, retail estate, transport setting and corporate office each create different pressures. Consider the people using the site, the periods of highest demand, the consequences of disruption, existing controls and the decisions staff will have to make without immediate senior support.

A threat, vulnerability and risk assessment should inform this work, but it must be current and usable. A document written for a previous tenant, operating model or risk appetite is a poor foundation for buying a new service. The assessment should identify meaningful scenarios, not prescribe every action a supplier will take. Its purpose is to establish the outcomes required.

Those outcomes may include maintaining safe access during peak periods, improving the reporting and escalation of suspicious activity, managing disorder without unnecessary confrontation, protecting critical operations, or strengthening response coordination. For organisations preparing for Martyn’s Law, this is particularly relevant. Compliance activity should not obscure the central issue: can your people and arrangements perform when there is uncertainty, pressure and incomplete information?

Define the Capability, Not Just the Headcount

Headcount is measurable, which is why it dominates many security specifications. It is also an incomplete measure. Two officers with different experience, briefing quality, supervision and confidence may deliver very different results. The same applies to technology. A camera system has limited value if images are not monitored appropriately, incidents are not reviewed and findings do not change practice.

A useful specification explains the required operating capability. It should cover the expected standard of personnel, site induction, local knowledge, decision-making authority, supervisory presence, reporting quality, training, welfare, response arrangements and interface with the organisation’s own teams.

This does not mean dictating every process. Overly prescriptive specifications can lock buyers into an approach that is already outdated. Set the non-negotiable outcomes and controls, then ask suppliers to show how they will achieve them. Their answer reveals much more than a rate card.

Ask, for example, how they will identify that a new officer is not ready for a demanding location. Ask who will make the decision to remove or support that person. Ask how supervisors will detect declining standards between formal audits. These questions move the discussion from promises to management reality.

Build an Evaluation That Tests Reality

The lowest compliant bid is often a false economy. A supplier can reduce cost through lower pay rates, thin supervision, limited training, excessive reliance on relief staff or assumptions about client support. None of these choices will necessarily be obvious in a high-level proposal.

Price matters. Organisations have finite budgets and procurement teams have a duty to demonstrate value. But value should be assessed across the life of the contract, including service failure, staff turnover, poor incident management, disruption and the management time needed to correct persistent problems.

Evaluation criteria should reflect this. Technical quality needs enough weighting to influence the result, rather than acting as a gateway before a price-led decision. Evidence should carry more weight than assertion. A supplier saying it has excellent training tells you little. A supplier explaining how competence is assessed, how gaps are addressed, what supervisors observe, and how learning is carried into daily briefings gives you something to test.

Scenario-based evaluation is especially useful. Present a realistic but non-sensitive operational problem and ask bidders to explain their decision process, command arrangements, communications, welfare considerations and post-incident learning. The purpose is not to catch people out. It is to see whether the organisation has operational judgement or only a well-written bid team.

References should also be used properly. Do not simply confirm that a contract exists. Ask whether the supplier mobilised as promised, maintained staffing levels, dealt honestly with problems and improved the service over time. A long client list is not evidence of performance.

Examine the People Behind the Proposal

Security services are delivered through people, even where technology is central to the solution. The named contract manager, operations manager and supervisors deserve scrutiny. They will shape standards after the procurement team has moved on to its next priority.

Meet the people who will run the account. Test their understanding of your environment and ask what they would need from your organisation to succeed. This is not a test of presentation skills. It establishes whether there is a workable relationship and whether responsibilities are understood on both sides.

There is an uncomfortable truth here. Client behaviour can create the conditions for poor security delivery. Late changes, unclear authority, unrealistic staffing expectations and a refusal to address known site issues will undermine even a capable provider. Procurement should make these dependencies visible before contract award, not leave them to become grievances during mobilisation.

For technical systems, apply the same principle. Do not buy features because they appear on a brochure. Define the operational decision each system must support. Consider who will use it, who owns maintenance, how faults are managed, what information is retained, and how performance will be checked. Systems that are difficult to operate or poorly integrated often become expensive background furniture.

Treat Mobilisation as a Test of Credibility

A supplier’s first weeks reveal whether its stated model can survive contact with the site. Mobilisation should be planned as a controlled transition, with clear responsibilities, dates, decision points and escalation routes. It must cover recruitment or transfer arrangements, vetting, induction, local procedures, equipment, communications, stakeholder briefings and contingency staffing.

The client should not accept a mobilisation plan and assume the work is complete. Hold regular progress reviews and require evidence that critical actions have been completed. Visit the site. Speak to supervisors and frontline staff. Check whether they understand the environment, know who to contact and can describe the standards expected of them.

Early assurance should focus on readiness, not presentation. Uniforms issued and folders completed may be necessary, but they do not prove capability. The practical test is whether the team can operate coherently on the first difficult day.

Manage the Contract Through Useful Evidence

A monthly dashboard can create an illusion of control. Green indicators often record activity rather than effectiveness: patrols completed, training delivered, vacancies filled and reports submitted. These measures have a place, but they do not answer whether risk is being reduced.

Contract oversight needs both performance data and informed observation. Look at incident patterns, repeat concerns, staff turnover, sickness, supervisory visits, response times, training outcomes, customer feedback and audit findings. Then ask what the information means. A fall in reported incidents might show improvement, or it might show that staff have stopped reporting minor concerns because nothing happens afterwards.

Use governance meetings to make decisions. Review changes to the risk picture, agree corrective actions, set ownership and return to unresolved issues. If a supplier repeatedly misses standards, do not allow the contract to drift into an exchange of explanations. Establish whether the issue is resourcing, competence, management, client dependency or a specification that no longer matches the operating reality.

Mildot Group’s experience is that the strongest security arrangements are not those with the most documentation. They are the arrangements where people understand their role, leaders notice deterioration early and evidence leads to action.

The Procurement Question Worth Keeping

Before awarding any security contract, ask whether you are purchasing visible reassurance or proven capability. The difference may not be obvious in a tender response. It becomes obvious when the environment changes, information is unclear and someone has to make a decision that carries consequences.

Buy for that moment. It is where the real value of security procurement is decided.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center