A completed risk assessment, a folder of procedures and a staff briefing do not make a premises ready.
They may satisfy part of the administrative requirement, but Martyn’s Law readiness depends on whether people can recognise concern, make sound decisions and act together when normal routines fail.
That distinction matters because the first few minutes of any serious security incident are rarely managed by a security policy.
They are managed by the people present, reception staff, duty managers, venue teams, facilities personnel, supervisors and security officers. Their judgement, communication and ability to follow a proportionate plan will shape the outcome.
Martyn’s Law should therefore be treated as a capability programme, not a compliance project.
Organisations that approach it as a document production exercise may have evidence of activity. They may not have the operational confidence the law is intended to encourage.
Note: All Martyn’s Law has established is that the UK private sector are 20 years behind the curve on 21st century security management systems. How do we rapidly change that situation?
What Martyn’s Law readiness should mean
The Terrorism (Protection of Premises) Act places a clearer expectation on responsible people to consider terrorist risk and prepare proportionate measures.
The detail will vary by premises type, capacity, activities and operating model. A small community venue does not need the same arrangements as a major arena, transport hub or multi site retail estate.
Proportionate does not mean minimal.
It means measures that genuinely reflect the environment, the people using it and the consequences of getting decisions wrong. A busy hotel, for example, has public access, contractors, guests, deliveries, events and staff working across shifts. Its risk picture changes through the day.
A generic plan written for a single, controlled entrance will not reflect that reality.
Readiness means knowing what your organisation would actually do. It means understanding who holds authority at different times, how staff raise concerns, what information they need, how they communicate under stress and when they call for emergency assistance.
It also means identifying where the plan relies on assumptions that have never been tested.
The uncomfortable truth is that many organisations only discover these voids during an incident, exercise or post event review.
By then, the issue is no longer theoretical.
Start with the operation, not the paperwork
A sensible Martyn’s Law readiness guide begins with how the premises works on an ordinary day.
Walk the site at opening, peak activity, shift change and closing. Observe rather than assume. Who enters? Who has access to sensitive areas? Where do queues form? What happens when a fire alarm activates, a delivery arrives late or a member of staff is absent?
This operational view often exposes weaknesses that a desktop assessment misses.
A rear entrance may be controlled on paper but regularly left unmanaged during a handover. A reception desk may be expected to receive security reports, yet staff may not know what information to record or who is on call after normal hours. A venue may have an evacuation plan, but no practical method to account for contractors or temporary event staff.
The purpose is not to create an ever longer list of risks. It is to identify decisions that matter and establish workable controls around them.
Good protective security is not built by adding friction everywhere.
It is built by applying attention where it reduces meaningful risk.
Identify the critical decisions
Most organisations do not need staff to become counter terrorism specialists.
They need them to make better decisions within their role. That requires clarity.
A front of house team should know how to report concerning behaviour without making unsupported accusations.
A duty manager should understand their authority to pause activity, restrict access or escalate an issue. Security staff should know how to preserve useful information, communicate clearly and avoid creating unnecessary confusion. Senior leaders should know who makes strategic decisions if an incident affects operations, people and reputation at the same time.
These responsibilities should be specific enough to guide action but not so rigid that they prevent judgement. Scripts can help during routine events.
They are less reliable when the situation is unfamiliar, incomplete or fast moving.
People need principles, rehearsal and confidence as well as instructions.
Assess capability, not attendance
Training records show who attended a session.
They do not show whether someone can apply learning under stress. This is where many readiness programmes become weak.
A short awareness course may improve baseline understanding. It will not, by itself, prove that a team can manage uncertainty, communicate across departments or make decisions when information is incomplete. That needs practical evaluation.
Use scenarios based on your own environment. They should test realistic pressures without drifting into unnecessary tactical detail. For a shopping centre, the challenge may be how centre management, tenants and contract security share a concern during a busy trading period. For a construction site, it may be how project leadership handles a credible report when access arrangements are changing daily. For a corporate office, it may be whether reception, facilities and remote decision makers can establish a common operating picture quickly.
Observe what people do, not just what they say they would do. Can they identify the decision maker? Do they know how to contact them? Is the communication channel available, understood and monitored? Are staff willing to challenge unusual activity appropriately, or do they assume somebody else will act?
Mildot Group’s experience of capability evaluation is clear on this point, immediate feedback is most useful when it identifies a specific void in knowledge, judgement or operational practice. A score alone is not improvement. It should direct the next intervention, whether that is focused learning, revised procedures, management coaching or a practical exercise.
Build a plan people can use
A security plan has value only when the right person can use it at the right time. Anything on paper is just theory.
Length is often mistaken for quality. In practice, an over engineered plan can leave staff searching for answers when they need to act.
Keep core response arrangements accessible and role based. Staff need to understand the immediate actions expected of them, how to escalate, how to communicate with colleagues and emergency services, and how to protect people without making the situation worse. Managers need clear thresholds for decision making and a way to record key actions as events develop.
This does not mean reducing every issue to a one page checklist. Some premises require detailed plans, particularly where operations are complex or multiple organisations share responsibility. But the detail must sit behind a usable front end.
A duty manager should not need to interpret a technical risk register before deciding who to call.
Plans also need to account for the people organisations routinely overlook: agency staff, contractors, cleaners, tenants, delivery personnel and night teams. If they work on site, they are part of the response environment.
If they do not receive proportionate information and instruction, the plan has a predictable blind spot.
Test the handovers and weak points
Security arrangements commonly fail at boundaries.
That includes the boundary between day and night shifts, landlord and tenant, security provider and client, head office and local management, or permanent staff and contractors.
Testing should concentrate on these seams. Ask whether a report raised by a cleaner reaches the duty manager. Check whether a contracted security officer has the same current contact information as the client team. Establish what happens if the nominated responsible person is unavailable. Confirm whether different sites use the same language for escalation and whether staff understand it.
Exercises do not need to be theatrical to be effective.
A structured discussion can reveal whether responsibilities are clear. A communications test can show whether contact arrangements work. A walk through can identify physical and procedural problems.
A more demanding exercise may be appropriate for higher risk or more complex premises, but it should have a defined purpose and lead to corrective action.
The key is to avoid rehearsing only the polished version of the plan.
Test the inconvenient conditions, reduced staffing, competing priorities, equipment failures, busy periods and unclear information.
Real incidents are rarely considerate enough to occur when the full team is available.
Create a cycle of improvement
Martyn’s Law readiness is not a one off implementation date.
Premises change. Staff leave. Contractors change. Refurbishment alters movement routes. A new event format changes footfall and access. Each change can affect the assumptions behind the security plan.
Review arrangements after exercises, incidents, significant operational changes and staff feedback. Keep the review practical. What worked? What caused delay? What was misunderstood? Who now owns the corrective action, and when will it be checked?
Senior leaders should ask a better question than, Are we compliant? Ask, Where would our people struggle tomorrow? That question directs attention towards real exposure, weak leadership cover, uncertain reporting routes, poor contractor integration, untested communications or teams that have never practised making decisions together.
A ready organisation is not one that claims certainty. It is one that has recognised its weak points, prepared its people and made improvement part of normal operations.
When pressure arrives, that is what turns a plan into protective action.
.
Useful Links:
.
