Martyn’s Law in Practice
Strategic Insight on Operationalising Current Guidance
Practical answers to the how, why and what next
.
By Anthony Gledhill | Updated August 2026
.
Purpose
This article bridges the space between compliance and capability.
Understanding Martyn’s Law is one thing. Making the required procedures and measures work during a fast moving hostile incident is another.
The focus here is practical.
What organisations need to consider, how responsibilities translate into working arrangements, where weaknesses are likely to emerge, and how leadership teams can build systems that protect people when information is incomplete and time is limited.
.
Introduction
If a serious hostile incident happened at one of your sites tomorrow, would your people act immediately or wait for someone to tell them what to do?
That question goes to the operational heart of the Terrorism (Protection of Premises) Act 2025, commonly known as Martyn’s Law.
The Act establishes requirements for certain premises and events to prepare for terrorist attacks. It identifies Responsible Persons, creates additional requirements for Enhanced Tier premises and qualifying events, and establishes the Security Industry Authority as regulator.
The legislation is not yet in force. Organisations are within the implementation period and are being encouraged to use this time to understand their responsibilities and prepare.
For Standard Tier premises, the central requirement is to ensure that appropriate public protection procedures are in place, so far as reasonably practicable.
Those procedures concern four areas:
• Evacuation
• Invacuation
• Lockdown
• Communication
For Enhanced Tier premises and qualifying events, the requirement goes further. Appropriate public protection measures must also be considered in relation to monitoring, movement, physical safety and security, and security of information.
On paper, that appears straightforward. Operationally, it is not.
A procedure has little value if the people expected to implement it do not know when to act, who has authority, how to communicate the decision, or what to do when events develop differently from the plan.
That is where operationalising Martyn’s Law begins.
What the Current Guidance Actually Requires
The Home Office statutory guidance provides the main framework for understanding what organisations need to do.
One distinction is particularly important.
The Act does not impose a general requirement for staff to complete a particular counter terrorism training course.
Instead, the Responsible Person must ensure appropriate public protection procedures are in place and, so far as reasonably practicable, capable of being enacted quickly and effectively.
That creates an obvious human requirement.
People with responsibilities within those procedures need to know what they are expected to do and have enough understanding, experience and access to the necessary tools to carry out those responsibilities.
Simply telling people that a procedure exists may not be enough. Briefings, induction, supervised practice, online learning, refresher activity and exercises can all contribute.
The method should fit the role.
The test is much simpler.
Can the person perform the action expected of them?
.
Start With the Four Public Protection Procedures
Every organisation preparing for Martyn’s Law should be able to explain how its four public protection procedures work at site level.
Not as definitions. As actions.
Evacuation
Where can people move safely?
Who can initiate evacuation?
What happens if the normal exit takes people towards the threat?
Are alternative routes understood?
Who directs people once movement begins?
Invacuation
Where can people be moved inside the premises?
Why are those areas safer?
How many people can they realistically accommodate?
How will people reach them?
Who controls the movement?
Lockdown
What can physically be secured?
Who has authority to initiate lockdown?
How do doors, shutters, barriers and access systems operate?
What happens to people immediately outside?
What happens if the threat is already inside?
Communication
Who initiates the warning?
What message will people receive?
Do different parts of the premises require different instructions?
What happens if the primary communication system fails?
Who contacts the emergency services?
Then consider how the procedures interact.
A hostile incident may require one area to evacuate while another invacuates or locks down.
Four individual procedures do not automatically create one effective response system.
They need to work together.
.
What an Attack Actually Looks Like
Hostile incidents rarely begin with clear information.
People may hear a bang, see others running, receive a fragmented radio message, observe suspicious behaviour or be told that something is happening elsewhere within the premises.
Someone has to interpret that – Someone has to decide – Someone has to communicate – People then have to act.
Examples:
The Manchester Arena Inquiry demonstrated how serious weaknesses in security, communication, command and information sharing can affect the response to an attack.
The London Bridge and Borough Market attack demonstrated something different. An incident can move rapidly across locations and organisational boundaries.
The lesson is not that future attacks will look the same.
The lesson is that uncertainty and change are normal.
Plans therefore need enough structure to provide direction, but enough flexibility to work when information is incomplete and circumstances change.
.
Leadership, Roles and Decision Making
The statutory guidance specifically asks organisations to consider key roles and responsibilities, who decides what action should be taken, and who has the authority to initiate a procedure.
That needs turning into clear site level answers:
- Who can order lockdown?
- Who can order evacuation?
- Can the duty manager make that decision without contacting head office?
- What happens if that person is absent?
- Who contacts the emergency services?
- Who provides them with information?
- Who coordinates staff activity?
- Who controls access?
- Who communicates with people inside the premises?
- Who responds when information changes?
These questions should be answered before the incident rather than discovered during it.
The Act does not prescribe operational titles such as Incident Lead, Crisis Manager or Emergency Services Liaison.
An organisation may still decide that clearly defined operational functions are necessary. The title is less important than the authority attached to it.
A simple test can reveal a great deal.
Ask the person running the premises today:
If something happens now, what decisions can you make without asking anyone else?
If the answer is unclear, the organisation has found a vulnerability.
.
The Responsible Person and Senior Individual
These roles should not be confused.
The Responsible Person is the person or organisation with control of qualifying premises for the relevant use, or control of premises for the purposes of a qualifying event.
Where the Responsible Person for Enhanced Tier premises or a qualifying event is an organisation rather than an individual, a Senior Individual must be designated.
That person must have sufficient seniority and influence to ensure the organisation meets its requirements.
Tasks can be delegated. Overall responsibility for ensuring compliance cannot simply disappear through delegation. This does not mean the Senior Individual automatically becomes personally liable whenever something goes wrong.
The statutory guidance makes clear that the Senior Individual is not personally liable merely because the Responsible Person fails to meet its requirements.
There are, however, criminal offences within the Act. Senior personnel may potentially face prosecution where an organisational offence has occurred and consent, connivance or neglect can be established.
The practical lesson for leadership is straightforward.
Know what is being done – Understand why decisions have been made – Know what weaknesses have been identified – Make sure action is taken where required.
.
Scope Is Not the Same as Exposure
The legislation uses defined criteria to determine whether premises and events fall within scope and which tier applies.
Those thresholds establish statutory responsibility. They do not provide a complete picture of security exposure. Crowd concentration changes throughout the operating day:
- People gather at entrances.
- Queues develop.
- Staff change shifts.
- Deliveries arrive.
- Events finish.
- Customers disperse.
- Shared areas become busy.
Vulnerability therefore changes with movement, timing and activity.
NPSA guidance on ingress and egress recognises the security challenges that can develop during these periods.
The practical response is simple:
- Walk the environment when it is busy.
- Observe where people naturally gather.
- Identify where queues form.
- Look at vehicle and pedestrian interaction.
- Consider shared entrances.
- Examine closing and dispersal periods.
- Identify areas outside your direct control that still affect your operation.
Then ask whether your procedures continue to work under those conditions.
The legal question is:
Are we in scope and what requirements apply?
The protective security question is:
Where could people be harmed and what can we reasonably do about it?
Both matter.
They answer different questions.
.
From Awareness to Capability
People do not need the same level of knowledge simply because they work in the same building.
A receptionist may need different information from a control room operator. A retail assistant has different responsibilities from a security officer.
A duty manager who may initiate lockdown requires a different level of understanding from someone whose role is to follow the instruction.
Start with the role:
- Identify the action required from that role.
- Explain the procedure.
- Practise the action.
- Test understanding.
- Correct weaknesses.
- Repeat where necessary.
- That sequence matters.
An attendance record demonstrates that someone attended training.
It does not demonstrate that they can perform the required action.
A simple scenario can provide far more useful information.
Ask:
There is a suspected attack outside the main entrance. What would you do?
Note: Do not initially provide options.
Listen to the answer.
You will quickly discover whether the individual understands the procedure, their own role, their authority and the communication route.
Then move beyond the individual and test the system:
- Talk through a scenario with managers.
- Include the staff responsible for key actions.
- Test communication.
- Test decisions.
Where appropriate and safe, test physical actions such as securing doors or moving towards designated areas.
Then review what happened:
- What decision was delayed?
- What message was misunderstood?
- Which door could not be secured?
- Which radio channel became congested?
- Who thought somebody else was responsible?
- What information did the emergency services need that was not immediately available?
Correct the weaknesses and test again.
Capability grows through use, not assumption.
.
The Emergency Services Response Gap
When seconds count, what will your staff do during the period before the emergency services arrive?
One of the most important operational periods begins before the emergency services can take effective control of the affected environment.
During those first moments, people already at the premises are making decisions. They may be deciding whether to move, stay inside, secure access, communicate a warning or contact emergency services.
Some decisions will be deliberate. Others will happen through hesitation, instinct or misunderstanding.
Be Clear – Organisations cannot remove that period.
They can prepare for it.
The objective is not to turn employees into emergency responders.
It is to give people enough clarity to take appropriate protective action until specialist help takes control. Staff should never be expected to take action that unnecessarily exposes them to danger.
Preparation should help people reduce harm, not place them in it.
.
Enhanced Tier Means More Than Procedures
Enhanced Tier premises and qualifying events have additional requirements. Public protection measures must be considered across four areas:
Monitoring: The ability to identify suspicious activity, items or indications of a potential attack.
Movement: How people enter, leave and move within the premises or event.
Physical safety and security: Measures that may deter, delay or reduce the impact of an attack.
Security of information: Protecting information about the premises, its operation, design, use and internal workings where that information could assist hostile planning.
The practical approach is to examine each area against the real environment:
- What can we see?
- What can we detect?
- What can we control?
- What could an attacker exploit?
- What information are we unnecessarily exposing?
- What protection already exists?
- What can reasonably be improved?
This requires assessment and judgement, not simply copying examples from guidance.
Reasonably Practicable
The words Reasonably Practicable sit at the centre of the legislation. (Along with evidencing, thats covered in another article)
They do not mean doing everything imaginable. They also do not mean doing nothing because the ideal solution is expensive.
The Home Office guidance describes a balance between reducing harm and factors such as cost, time and difficulty.
A practical decision process is:
Identify the problem.
Define the protective outcome required.
Consider the available options.
Assess likely effectiveness.
Consider cost, time and difficulty.
Look for reasonable alternatives.
Make the decision.
Record why.
Review it when circumstances change.
Example: Consider an entrance that may be vulnerable to hostile vehicle attack.
Permanent hostile vehicle mitigation may initially appear appropriate. It may also be physically difficult or financially disproportionate. That should not automatically end the assessment:
- Could vehicle access be changed?
- Could temporary measures be used at particular times?
- Could deliveries be rescheduled?
- Could queues be moved?
- Could existing street furniture provide useful separation?
- Could monitoring be improved?
- Could another entrance reduce exposure?
Reasonably practicable decision making is not simply about accepting or rejecting one expensive solution.
It is about finding an effective and proportionate way of reducing risk.
.
Coordination Matters
Modern premises rarely operate in isolation:
- Shopping centres contain tenants.
- Events involve contractors.
- Venues use security providers.
- Landlords and operators may control different systems.
- Shared areas may sit between organisations.
Where your procedure depends upon somebody else, speak to them before the emergency:
- Confirm who controls shared doors.
- Confirm how alarms are communicated.
- Confirm who can change access arrangements.
- Confirm how neighbouring premises communicate.
- Confirm where responsibility changes.
- Confirm what contractors are expected to do.
A plan containing assumptions about another organisation is not coordination.
.
Regulation, Assurance and Enforcement
The SIA will regulate Martyn’s Law.
Its published position indicates that compliance assessment will involve desk based work and onsite inspection using a risk based approach.
Authorised inspectors will have powers to inspect premises, observe activities, examine relevant documents and equipment, request explanations and obtain information.
Organisations should therefore avoid preparing solely for a document review.
Internal assurance should answer three questions:
What exists?
Do people understand it?
Can it realistically be implemented?
Test those questions before a regulator ever needs to.
.
The enforcement regime is significant
The Act provides the SIA with powers including compliance notices, restriction notices and financial penalties.
Maximum financial penalties for Standard Tier contraventions covered by the penalty regime can reach £10,000.
For Enhanced Tier premises and qualifying events, maximum penalties for relevant contraventions can reach £18 million or 5 per cent of qualifying worldwide revenue, whichever is higher.
Continuing breaches of compliance or restriction notices may also attract daily penalties. Certain serious forms of noncompliance can become criminal offences.
The leadership lesson is not to build a system around passing an inspection.
Build a capable system and retain enough evidence to demonstrate what has been done and why.
.
Documentation
Standard Tier premises are not required to provide the SIA with documentation demonstrating their public protection procedures – Note: This point may change over time.
That does not make documentation unnecessary.
A concise record of procedures, responsibilities, decisions and reviews can support consistency and provide useful evidence of how the organisation manages its responsibilities.
Enhanced Tier premises and qualifying events have additional documentation requirements.
They must document their public protection procedures and measures, explain how those arrangements are expected to reduce vulnerability or physical harm, keep the document updated and provide it to the SIA as required once the relevant provisions are in force.
The principle should remain simple. Document what the system actually does. Do not build a system simply to generate documents.
.
Avoiding False Assurance
One of the easiest mistakes under any new regulatory regime is confusing activity with capability.
A policy may have been written – Training may have been completed – A consultant may have produced a report – An exercise may have taken place.
None of those things independently proves that the system works.
Assurance should return to evidence:
- Can people implement the procedure?
- Can managers make the required decisions?
- Does the equipment work?
- Do communications reach the right people?
- Are dependencies understood?
- Were weaknesses identified during testing actually corrected?
If the answer is yes, documentation becomes evidence of a functioning system rather than a substitute for one.
.
What Leadership Teams Should Do Now
The implementation period provides something valuable.
Time.
Use it.
A practical sequence is:
Understand. Assign. Assess. Design. Communicate. Practise. Test. Improve.
Understand
Establish which premises and events are likely to fall within scope and what requirements are likely to apply.
Assign
Identify the Responsible Person.
For Enhanced Tier premises and qualifying events, identify who is likely to fulfil the Senior Individual role.
Define operational authority.
Assess
Examine the environment as it actually operates.
Look at busy periods, queues, entrances, exits, shared areas, movement, existing security measures and dependencies on other organisations.
Design
Develop workable evacuation, invacuation, lockdown and communication procedures.
For Enhanced Tier environments, also consider monitoring, movement, physical safety and security, and security of information.
Communicate
Make sure people know what is expected of them.
Keep the information relevant to their role.
Practise
Talk through realistic situations and allow people to make decisions.
Test
Check whether procedures, communications, equipment and decision making work in practice.
Improve
Record weaknesses, correct them and review arrangements when circumstances change.
This turns preparation into an operating capability rather than an administrative exercise.
Conclusion
Martyn’s Law establishes the legal requirement. Organisations still have to make it work.
During a hostile incident, people will not receive perfect information or be given time to consult a procedure.
They may face uncertainty, noise, movement, conflicting information and pressure:
- Someone still has to recognise what is happening.
- Someone still has to decide.
- Someone still has to communicate.
- People still have to act.
That is why preparation cannot stop at compliance.
Know what the law requires.
Then build the capability to deliver it.
.
Final Thought and Key Advice for Leadership Teams
During the first moments of a hostile incident, the organisation may not know whether it is dealing with terrorism, serious violence, criminal activity or something else.
That classification may come later.
The immediate requirement is recognition, decision making and proportionate action. This is why the practical benefits of strong public protection procedures extend beyond Martyn’s Law.
Clear authority, effective communication, sensible movement of people and practised decision making strengthen the response to a much wider range of rapidly developing incidents.
The focus should not be on identifying a legal category before people act. Prepare people to recognise danger, understand their responsibilities and make appropriate decisions with the information available.
Because in the first critical moments, people do not experience legislation.
They experience the incident.
.
Consultancy & Advisors
Private sector leadership should ask direct questions before appointing any counter terrorism consultancy:
All based around what private sector operational experience sits behind the advice.
Leadership should ask:
• What private sector environments have you actually delivered protective security or counter terrorism systems within?
• Have you operated in private sector organisations where decisions affect operations, reputation, liability, and business continuity?
• Have you delivered and managed security systems within a private sector organisation were the system was tested and proven?
• Can you demonstrate experience beyond guidance interpretation and compliance administration?
• How will your recommendations function operationally under pressure, not just during inspections or audits?
• How do you assess whether staff could actually perform during an incident rather than simply confirm training attendance?
• How do you test leadership, communication, and decision making?
• How do you apply the principle of reasonably practicable within operational reality, not theoretical discussion?
• If an incident happened tomorrow, how would your advice stand up under investigation, public inquiry, regulatory scrutiny, or in court?
Anyone can repeat guidance. If the first four questions can not be answered with experience and clean explanations, you will know your next move and the next five questions will not be required.
About the Author:
Anthony Gledhill
Over 20 years in private sector security, from frontline media operations through to designing and delivering capability development within government VIP protection units, and leading security systems across defence, construction, and oil & gas in benign, active insurgent, terrorist, and hybrid threat environments. Trained thousands of private sector security staff for armed and unarmed operations.
Useful Links:
.
References
Home Office (2026a) Terrorism (Protection of Premises) Act 2025: Statutory Guidance. London: Home Office.
Home Office (2026b) Terrorism (Protection of Premises) Act 2025: Supplementary Document A. London: Home Office.
Home Office (2026c) Terrorism (Protection of Premises) Act 2025: Supplementary Document B. London: Home Office.
Home Office (2026d) Terrorism (Protection of Premises) Act 2025: Supplementary Document C. London: Home Office.
Security Industry Authority (2026) Martyn’s Law: Section 12 Draft Guidance. London: Security Industry Authority.
National Protective Security Authority (2023a) Effective Command and Control. London: National Protective Security Authority.
National Protective Security Authority (2023b) Crisis Management Guidance. London: National Protective Security Authority.
ProtectUK (2021) Working with Emergency Services. London: National Counter Terrorism Security Office (NaCTSO).
Manchester Arena Inquiry (2021) The Manchester Arena Inquiry: Volume 1 – Security for the Arena. London: HM Government.
Home Office (2018) Lessons Learned Review of the Terrorist Attacks in London Bridge and Borough Market. London: Home Office.
.
Useful LInks:
.
