A site can look secure right up to the point when normal conditions fail.

The access controls work, staff know where the incident folder is kept, and a plan has been signed off.

Then a member of the public raises a concern, a key supervisor is absent, communications become confused and someone has to make a judgement without waiting for permission.

That is where site resilience is exposed.

Knowing how to build site resilience means looking beyond physical measures and written procedures.

It means developing a site that can recognise disruption, make sound decisions and continue operating safely when people are under pressure. For organisations preparing for Martyn’s Law, this distinction matters.

Compliance may establish a baseline, but capability determines what happens when the situation does not follow the script.

Resilience is a capability, not a document

A resilient site is not one that claims it has considered every possible incident.

It is one where people can respond effectively to the incidents they are most likely to face, while adapting when circumstances change.

This is uncomfortable because many security programmes still measure activity rather than readiness.

They count completed training, approved policies, installed systems and exercises delivered. Those things have value, but none guarantees that a receptionist will report a concern clearly, that a duty manager will take control early enough, or that teams will share the right information when it matters.

Resilience is built from the relationship between people, procedures, physical design, technology and leadership.

A weakness in one area can undermine the others.

A well designed control room is of limited use if staff do not know what information should trigger escalation.

A strong incident plan will not help if it is inaccessible, overcomplicated or written for a level of staffing that does not exist at weekends.

The practical test is straightforward, can your site recognise a problem, communicate it, make decisions and recover without relying on a single exceptional individual?

If the answer is uncertain, the site is less resilient than its documentation suggests.

Start with the reality of the site

Generic risk assessments produce generic resilience.

A retail location, a hotel, a construction project and a transport hub may all manage public access, suspicious behaviour, evacuation and business disruption.

Their operational reality is very different.

Build from how the site actually functions. Consider its busiest periods, public facing areas, shift patterns, lone working, contractor activity, delivery arrangements, neighbouring premises and the people who make decisions when senior managers are unavailable. Look closely at routine pressure points.

These are often where resilience fails first.

For example, a venue may have a carefully planned response for a major incident but no reliable way for bar staff, agency personnel and security officers to share an early concern. A corporate office may have access control and visitor procedures, but its front of house team may feel unable to challenge an unfamiliar person who appears confident and legitimate.

A construction site may rely on a site manager whose absence leaves contractors unsure who can authorise a safety or security decision.

These are not minor operational details.

They are the conditions that shape behaviour.

Good resilience planning accounts for the site as it is run, not as it appears on a drawing or in a policy.

Identify critical functions and single points of failure

Every site has functions that must continue, be restored quickly or be shut down safely.

This could include managing access, communicating with staff and visitors, maintaining welfare, protecting sensitive areas, accounting for people or liaising with emergency services.

Then identify what each function depends on.

If one person holds the relevant knowledge, one radio channel carries all critical communications, or one supplier provides an essential service with no fallback, you have a single point of failure.

Not every dependency can be removed, but it should be recognised and managed.

The answer is rarely to create a large contingency document. It is usually to cross train people, clarify authority, provide simple alternatives and rehearse the handover between teams.

Resilience improves when more than one person can make the next sensible decision.

Build judgement before procedures

Procedures provide a common starting point.

They should not turn capable people into passive observers waiting for a precise instruction.

Staff need to understand what normal looks like in their environment, what may indicate a concern and how to report it in a useful way. This is particularly relevant in protective security, where individual observations can appear insignificant until they are placed in context.

Training that only asks people to recall definitions or select answers in a classroom does not build this judgement.

Give people realistic scenarios based on the site.

Ask what they notice, what information is missing, who needs to know and what action is proportionate. Discuss competing priorities. A manager may need to protect people, preserve business continuity and avoid causing unnecessary alarm at the same time.

Pretending these pressures do not exist creates brittle responses.

Good decision making is not about making every person a security specialist. It is about ensuring they recognise their role, understand their authority and have the confidence to act within it.

The most effective teams are not those that recite procedures word for word.

They are those that can explain why a procedure exists and adapt it without abandoning its purpose.

Design communication for the first ten minutes

The quality of early communication often decides whether an incident remains manageable or becomes confused.

Yet organisations commonly focus on who must be notified at senior level, rather than what frontline teams need to communicate immediately.

A useful initial report should establish what has happened, where it is happening, who is involved, what actions have been taken and what support is needed.

It does not need to be perfect. It needs to be clear enough for the next person to make a better decision.

Test your communication routes under ordinary constraints. Can staff contact the right person when the duty manager is in a meeting? Do agency workers know the reporting route? Is there an alternative if a radio, mobile network or internal system is unavailable? Can shift teams access current contact details without searching through shared folders?

Avoid assuming that a group messaging channel is an incident communication plan.

It may be useful, but it can also produce duplication, speculation and missed messages.

Resilient communication has clear roles, agreed language and a method for confirming that important information has been received.

Test the joins between teams

Most sites do not fail because one team has no plan.

They fail at the joins between teams, suppliers and functions. Security may identify a concern but lack authority over operations. Facilities may hold the information needed to isolate an area. Human resources may need to support staff after an event.

Communications may need accurate facts before addressing customers or stakeholders.

Exercises should therefore test coordination, not simply individual actions. A short, well facilitated scenario involving security, operations, front of house and senior decision makers can reveal more than a lengthy annual exercise built around a predictable script.

Do not make exercises theatrical.

The point is not to catch people out or create a dramatic display. It is to expose assumptions safely. Ask where decisions slowed down, what information was unclear and whether people understood who was leading.

Record actions, assign ownership and return to them.

An exercise that produces no change is performance, not preparedness.

Measure readiness, not attendance

Training records are necessary, but they are weak evidence of resilience on their own.

A completed course shows exposure to information.

It does not necessarily show whether a person can apply that information in context.

Use capability measures that reflect the work. This may include scenario based assessments, observations during exercises, quality of incident reports, response times, handover standards and staff confidence in their responsibilities.

Look for patterns rather than relying on one score. If several people hesitate at the same escalation point, the issue may be unclear authority or poor process design, not individual competence.

This is where practical diagnostic assessment adds value. It identifies where understanding is sound, where judgement is weak and where further development is needed.

It also prevents organisations from spending time retraining people on areas they already understand while ignoring the spaces that affect operational performance.

Keep resilience alive between incidents

Site resilience decays when it is treated as a project.

Staff move on, contractors change, layouts are altered, new technology is introduced and temporary arrangements quietly become permanent.

The plan may still exist, but the operating environment has changed around it.

Review resilience after meaningful change, not just on a calendar date. A refurbishment, a new visitor process, changes to opening hours, a revised staffing model or a new security provider can all affect the way a site responds.

Small changes often create the largest hidden voids because nobody considers them significant enough to test.

Make short resilience conversations part of routine management. Discuss recent concerns, lessons from near misses, changes to local conditions and whether reporting routes still work.

This is more valuable than rediscovering an obsolete plan during a serious event.

A resilient site is not one that promises certainty. It is one where people know their purpose, can make proportionate decisions and have practised working together when certainty disappears.

Ask your team one honest question, if something changed in the next ten minutes, would we know what to do first?

Their answer is a better starting point than any certificate on the wall.

.

Useful Links:

.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center