A security manager can produce a complete policy suite, close every audit action and ensure all mandatory learning is recorded. Then, at the moment somebody reports an unattended item, an aggressive confrontation or suspicious behaviour, staff hesitate, pass responsibility upwards or make a poor decision.

That is the real issue in security culture versus compliance. Compliance proves that certain controls exist. Culture determines whether people recognise risk, use those controls properly and act with sound judgement when the situation does not fit the procedure.

For organisations preparing for Martyn’s Law, or simply trying to manage protective security responsibly, this distinction matters. A compliant organisation may look prepared. A capable organisation can make decisions under pressure.

Compliance sets the floor, not the standard

Compliance has a legitimate purpose. Policies, risk assessments, training records, maintenance schedules and governance arrangements establish a baseline. They create consistency, assign accountability and provide evidence that an organisation has considered its duties.

The problem begins when that baseline is treated as the finish line.

A completed eLearning module does not show that a receptionist can identify behaviour that needs reporting. A signed security procedure does not show that a duty manager can coordinate a proportionate response during a confusing incident. A test certificate does not prove that staff know what to do when a system fails at the worst possible time.

This is not an argument against compliance. Organisations need it, particularly where public safety, legal obligations and assurance are involved. The issue is the assumption that documented compliance equals operational readiness. It does not.

Security failures often occur in the space between the written process and the real situation. Conditions are unclear. Information is incomplete. People are busy, tired or worried about getting it wrong. The correct response may require judgement rather than a simple instruction.

That is where culture shows itself.

What security culture looks like in practice

Security culture is not posters in a staff room or a senior leader stating that security matters. It is the shared standard of behaviour that appears when no one is checking.

In a healthy culture, people understand their role in protecting colleagues, visitors, assets and operations. They know what normal looks like in their environment, feel able to question what does not look right and have confidence that reporting concerns is worthwhile.

That confidence is easily lost. If reports disappear without feedback, staff learn that raising concerns is futile. If managers dismiss inconvenient observations because they disrupt operations, teams learn that production takes priority. If people are criticised for cautious, good-faith decisions, they learn to wait for permission.

The opposite is also true. When leaders ask sensible questions, explain decisions and treat near misses as learning opportunities, people become more willing to engage. They start to see security as part of their professional responsibility rather than an external demand imposed by policy.

This does not mean every employee becomes a security specialist. It means each person has a realistic understanding of what they may encounter, what action is expected and when to escalate. A retail colleague, venue steward, project manager and control room operator will each need different levels of knowledge. The principle remains the same: responsibility must match capability.

Why security culture versus compliance is a false choice

The phrase security culture versus compliance suggests an either-or decision. In reality, organisations need both, but they need them in the right order.

Compliance should support culture, not replace it. A procedure should make a competent person more effective. Training should improve recognition, decision making and communication. An exercise should test whether arrangements work in the environment, with the people and resources actually available.

When compliance becomes the dominant measure of performance, people naturally optimise for the evidence. They attend the course, tick the box, circulate the policy and file the record. That is understandable. It is also inadequate where the consequence of poor judgement could be serious.

Leaders should therefore ask a more difficult question: can our people apply what we say we expect of them?

The answer cannot be found in a learning management system alone. It requires observation, discussion, realistic evaluation and an honest look at how teams behave when pressure rises.

A facilities team may be fully briefed on access control, for example, yet routinely allow tailgating because challenging people feels socially awkward. The technical control exists. The policy is clear. The weakness is behavioural. Until managers address confidence, expectations and local supervision, further paperwork will achieve little.

The behaviours that expose a weak culture

Most organisations do not discover a culture problem through a headline incident. The warning signs are usually mundane and repeated.

Staff may report concerns inconsistently, or only when they are certain something is wrong. Contractors may receive a quick induction but little meaningful explanation of local risks. Managers may talk about security after an event, then allow familiar shortcuts to return. Exercises may be announced well in advance and assessed against a narrow script, producing reassurance rather than useful evidence.

Another common problem is upward dependency. Staff escalate every uncertain situation because they have not been given the authority or decision framework to act. Escalation is often appropriate, but a team that cannot take simple, proportionate action without senior approval will struggle during a fast-moving event.

Equally concerning is false confidence. A team may know the terminology, quote the procedure and perform well in a classroom discussion, yet be unable to prioritise competing demands in a live environment. Knowledge has value, but knowledge without practice is fragile.

Build capability around real decisions

A better approach starts with the decisions people must make, not with the documents the organisation needs to hold.

Consider the role, environment, likely pressures and consequences of delay. What might a front-of-house colleague notice? What must a supervisor decide before seeking support? What information does the incident lead need from others? What happens if communications are disrupted, key personnel are absent or a planned control cannot be used?

These questions turn broad security expectations into practical capability requirements.

Training then needs to do more than explain policy. It should help people recognise relevant indicators, communicate clearly, make proportionate decisions and understand the limits of their responsibility. Evaluation should test application, not recall alone. Immediate feedback is particularly valuable because it shows where confidence exceeds competence, or where a person has the right instinct but lacks a clear process.

Scenario work has a place here, provided it is credible. The aim is not theatrical drama or a pass-fail spectacle. It is to expose assumptions safely. A short discussion based on a realistic operational problem can reveal more than a heavily scripted annual exercise if it forces people to explain what they would do, why they would do it and who they would involve.

Mildot Group’s experience is that organisations make faster progress when they diagnose capability before prescribing more training. A gap may sit in awareness, leadership, communication, technical knowledge, planning or confidence. Treating every gap with the same generic module wastes time and can create a misleading sense of assurance.

Leadership decides what culture becomes

Security culture is shaped by leaders long before a crisis occurs. Staff watch what managers prioritise, tolerate and reward.

If senior decision makers only ask whether training is complete, that becomes the measure teams chase. If they ask what has been learned from reports, where people feel uncertain and whether plans have been tested against realistic constraints, they signal a different standard.

This does not require leaders to become security experts. It requires them to be curious, consistent and willing to hear uncomfortable information. A reported weakness is not necessarily a failure of the person raising it. Often, it is an opportunity to correct a condition before it becomes an incident.

Good leaders also avoid making security somebody else’s problem. The security function may provide expertise, standards and assurance, but operational managers control many of the daily conditions that affect behaviour. Staffing levels, handovers, supervision, time pressure, contractor management and local communication all influence whether protective measures work.

Measure what people can do

Organisations often measure attendance, completion and audit status because these are easy to count. They should be measured, but they are not enough.

Add measures that show operational capability. Examine the quality and timeliness of reporting. Look at whether teams can explain their response arrangements without reading from a document. Review how lessons from exercises and incidents are applied. Assess whether supervisors are making appropriate decisions within their authority.

The purpose is not to create another layer of administration. It is to establish whether the organisation is getting better at recognising, deciding and acting.

There will always be a place for policies, records and formal assurance. But people facing uncertainty do not respond from a folder. They respond from what they understand, what they have practised and what their organisation has taught them is expected. That is the standard worth building towards.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center