A Martyn’s Law compliance roadmap should not begin with a policy template. It should begin with an honest question: if a credible threat emerged at this site or event, would our people recognise it, make sound decisions and protect those in their care?

That question exposes the difference between documented compliance and operational readiness. Most organisations can produce a plan. Far fewer can show that staff understand it, supervisors can lead it and the response will still work when information is incomplete, communications are strained and normal routines have broken down.

Martyn’s Law places greater focus on preparedness for terrorism in publicly accessible locations. The right response is not to treat it as a paperwork exercise or a security project owned solely by one manager. It is a programme of practical risk reduction involving leadership, operations, people management, premises management and security.

Build a Martyn’s Law compliance roadmap around capability

The legal duties that apply will depend on the nature, capacity and use of a premises or event, alongside the requirements set out in current legislation and guidance. Do not guess at your category or assume that a familiar building presents a familiar risk. A hotel, retail unit, office reception, construction project, sports venue and temporary event may all face different operational challenges even where the underlying duty appears similar.

Start by establishing ownership. A named senior person should be accountable for the programme, with a clear operational lead who can bring together facilities, HR, security, operations and relevant third parties. This is not bureaucracy for its own sake. It prevents a common failure: each department assumes somebody else has considered the issue.

The accountable person needs accurate information about the site, its public access, normal operating patterns, peak periods, staffing profile, contractors, existing emergency arrangements and known vulnerabilities. They also need the authority to make changes. Assigning responsibility without control of budgets, staff time or operational decisions produces little more than a risk register.

Establish the real operating picture

A proportionate terrorism risk assessment is the foundation, but its value depends on the quality of observation behind it. Walk the site at different times. Watch how people arrive, queue, enter, move through the building and leave. Speak to front-of-house teams, cleaners, reception staff, maintenance personnel, event staff and security officers. They often understand practical weaknesses that do not appear on plans.

Look beyond the perimeter and access points. Consider crowded spaces, areas where people may become trapped or confused, shared entrances, delivery arrangements, unattended items procedures, contractor access and how visitors are managed when the site is busy. The point is not to create an exhaustive catalogue of scenarios. It is to identify where harm could be increased by poor layout, unclear responsibility, weak communication or slow decision making.

This work should also test assumptions. A controlled entrance is not necessarily controlled if staff routinely wave through familiar faces. A CCTV system is not a protective measure if nobody is responsible for monitoring it, escalating concerns or maintaining it. An evacuation plan is not credible if staff do not know who can authorise it or where they should direct people when the usual route is unsuitable.

A good assessment turns observations into decisions. It identifies what must change, who will make the change, when it will happen and how effectiveness will be checked. Generic wording such as ‘maintain vigilance’ gives staff no practical standard to work to.

Put proportionate measures into daily operations

Protective security works best when it supports the way a site actually operates. Measures imposed without considering customer flow, staffing levels or commercial pressures are often bypassed within weeks. The answer is not to remove them. It is to design them properly and explain their purpose.

For some organisations, the priority may be improving access management and visitor procedures. For others, it may be clarifying how suspicious behaviour or unattended items are reported, improving communication between security and operations, or ensuring that premises plans and emergency equipment are current. A large venue may require more formal command arrangements and coordination with multiple suppliers. A smaller premises may need simple, well-rehearsed actions that a limited team can carry out confidently.

The uncomfortable reality is that physical measures rarely compensate for uncertain people. A door, barrier or camera can support a security arrangement. It cannot interpret behaviour, challenge an anomaly, decide whether to pause an event or communicate calmly with a frightened crowd. Those responsibilities remain human.

That is why procedures must be written in clear operational language. Staff need to know what they are expected to notice, how to report it, who takes decisions and what happens next. They do not need a lengthy manual that remains unopened until an incident.

Train for judgement, not certificate collection

Awareness training is necessary, but awareness alone is not capability. Staff may complete a course and still be unable to describe their local reporting process, distinguish an immediate concern from a routine issue, or act when a manager is unavailable.

Training should reflect role and exposure. Reception and visitor-facing staff need confidence in observation, communication and escalation. Duty managers need decision-making practice and an understanding of their authority. Security personnel need to integrate protective security responsibilities with the wider operation rather than work in isolation. Senior leaders need to understand the consequences of delayed or unclear decisions.

Short, focused learning often works better than a single annual session. It gives organisations the chance to reinforce expected behaviours, address staff turnover and test whether knowledge has translated into practice. Digital learning and capability assessment can provide a useful baseline, particularly across dispersed teams, but they should inform practical development rather than replace it.

Ask staff questions that reveal understanding. Who do you contact if you identify a concern? What information would help the person receiving the report? What action can you take while waiting for instruction? What changes during a busy period, a shift handover or an event evacuation? If answers vary widely, the organisation has found a capability gap before an incident exposes it.

Test the plan where work happens

A plan is only a hypothesis until it is tested. Tabletop exercises are valuable because they expose confusion without disrupting operations, but they must be realistic enough to challenge routine assumptions. A discussion that follows the written plan perfectly tells you very little.

Use scenarios that reflect the site. Introduce uncertainty, conflicting information, absent staff, a crowded public area or a communication failure. Observe how teams share information, who leads, whether decisions are recorded and whether operational priorities conflict. The exercise should test coordination, not reward people for remembering the right words.

Where appropriate, progress to practical rehearsals. These need careful management to avoid unnecessary alarm, but they reveal issues that discussion cannot: a locked gate, poor signage, staff who cannot reach radios, a muster point that creates congestion, or a contractor who has never been briefed on emergency arrangements.

After every test, capture specific lessons. Avoid vague actions such as ‘improve communications’. State what will change, who owns it and the date by which it will be checked. Then test again. The aim is a cycle of improvement, not a one-off exercise performed for an audit file.

Manage the supply chain and changing conditions

Many public-facing organisations rely on contractors for cleaning, facilities, event delivery, guarding, catering or technical support. Their staff may be present at the point where an issue is first noticed, yet receive less briefing than permanent employees. That is a weakness worth addressing early.

Set clear expectations in contracts, inductions and site instructions. Contractors should understand relevant reporting arrangements, access controls and emergency actions. Equally, the organisation must ensure that its own team knows who is on site, what responsibilities they hold and how they can be contacted.

Review the roadmap when operations change. Refurbishment, new tenancy arrangements, altered opening hours, a change in customer profile, seasonal demand and new technology can all affect the risk picture. Compliance is not a date on a spreadsheet. It is the continuing ability to manage a changing environment.

Measure readiness, not activity

Senior leaders need evidence that the programme is working. Training completion rates, updated policies and risk assessments are useful management information, but they are inputs. They do not prove readiness.

More meaningful measures include staff confidence in reporting concerns, the quality and speed of escalation during exercises, closure of identified actions, consistency of contractor briefings and the ability of managers to explain their emergency roles. These indicators show whether security arrangements are being lived rather than merely held on file.

A practical Martyn’s Law compliance roadmap turns theory into action by making preparedness part of ordinary management. The final test is simple: when pressure rises, will your people wait for the document, or will they know what good action looks like?

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center