A venue can have cameras, access controls, evacuation plans and a folder full of policies, yet still be poorly prepared.
The failure usually appears at the point where a member of staff notices something unusual, is unsure whether it matters, and does nothing useful with the concern.
Terrorism mitigation is won or lost in those moments, not in the quality of the document stored on a shared drive.
That is an uncomfortable truth for organisations that have invested heavily in visible security measures. Physical measures matter, but they are only one part of the protective system.
Mitigation depends on people recognising concern, reporting it properly, assessing it with judgement and taking proportionate action early enough to make a difference.
The objective is not to turn every employee into a counter terrorism specialist. It is to build an organisation using 21st century security mindsets where people understand their role, know their limits and can contribute to a controlled response rather than adding confusion.
Terrorism mitigation is a capability problem
Too much private sector counter terrorism activity is being built around a compliance mindset in the UK. This is down to the majority of security practitioners involved and the government agencies delivering guidance have no experience in the topic.
A policy is issued, staff complete a course, a certificate is recorded and leaders assume the risk has been addressed. None of those things proves that a receptionist, duty manager, control room operator or project lead can make a sound decision when information is incomplete and time is limited.
Capability is different.
It means people can apply what they know in the setting where they work.
They can identify what is out of place without becoming distracted by every minor irregularity. They can communicate clearly. They understand who has authority to make decisions, when to escalate and how to keep their own actions proportionate.
This matters because suspicious activity rarely arrives as a neat, obvious problem. A concern may begin with behaviour that does not fit the environment, an unusual request, a pattern of information gathering or a colleague reporting something that feels wrong but is difficult to explain. Individual observations may be innocent.
The professional task is to ensure that concerns are neither dismissed through complacency nor inflated through fear.
The strongest organisations create a route between observation and decision. They do not demand certainty from the person making the report.
They ask for accurate information, then ensure a competent person assesses it in context.
Start with decisions, not paperwork
A useful security plan begins with the decisions people may need to make. What should a member of staff do if they identify a concern? Who receives the report? What information is needed to assess it? Who decides whether activity should change? How will staff, visitors and partners be informed if they need to take action?
When these questions are unanswered, the organisation does not have a plan. It has an intention.
The answers will differ between environments. A crowded event venue, a corporate office, a construction project and a transport setting each have different operating pressures, public access arrangements and lines of authority.
Copying a generic procedure often creates a false sense of readiness because it ignores how decisions are actually made on site.
That issue is alive and kicking right now in UK organisations. There are business selling template documents and the new level 3 awareness course on this topic is multiplying this issue.
Know what normal looks like
Situational awareness begins with an understanding of normal activity.
Staff who know their workplace can identify changes in behaviour, access patterns, deliveries, visitor conduct or information requests more effectively than someone given a vague instruction to remain vigilant.
This is not about encouraging suspicion of particular people or relying on personal instinct alone. It is about noticing observable behaviour and context. A report should describe what was seen, heard or requested, where and when it occurred, and why it appeared unusual in that environment. That gives the person assessing it something useful to work with.
Leaders should also recognise that frontline staff may avoid reporting concerns if previous reports were ignored, criticised or treated as an inconvenience.
Reporting culture is built by the response to the first report, not by a slogan on a staff noticeboard.
Design reporting that reaches a decision maker
A reporting process fails when it is unclear, slow or detached from operations.
Staff need a simple route that works during busy periods, outside normal office hours and when the usual manager is unavailable. The route should lead to somebody with the competence and authority to assess the information, not merely log it.
Good reporting also needs feedback. Where appropriate, the person who raised the concern should know it was received and handled. That reinforces the behaviour the organisation wants.
It also improves the quality of future reports, because staff learn what information is useful and why.
Prepare people for the first minutes
The Emergency Services Response Gap – The critical period of action.
Most serious failures in a developing incident are not caused by a lack of effort.
They are caused by uncertainty. People wait for permission, make assumptions about who is in charge, pass on incomplete information or focus on tasks that do not reduce immediate risk.
Preparation should therefore include the first decisions people may face. Staff should understand their immediate responsibilities, how to communicate concise facts, how to support emergency services and how to avoid creating additional hazards.
They do not need complex tactics.
They need clear priorities that have been practised in their own environment.
For organisations preparing for duties associated with Martyn’s Law, this distinction is especially relevant.
Demonstrating that training occurred will not be enough if staff cannot apply it.
The operational question is whether the organisation can recognise a concern, make decisions and protect people under stress.
Test the system where work happens
Tabletop exercises have value, particularly for testing leadership decisions and communications.
But they can also hide weaknesses. In a meeting room, people have time to think, access to every decision maker and a clear shared picture. Real operations are rarely that tidy.
Testing should reflect the actual workplace. Consider the shift pattern, language needs, contractor presence, lone workers, visitors, peak demand, communications coverage and the practical availability of key people. A response arrangement that depends on one security manager may look acceptable until that person is off site, on leave or managing another problem.
The test does not need to be dramatic. A short, controlled scenario can reveal whether staff know who to call, whether a control room can record and pass relevant information, whether managers understand their authority and whether the plan survives ordinary operational friction.
What matters is how the organisation responds to what it finds. A gap identified in an exercise is useful only if it produces a change in training, process, staffing, communications or security design.
Repeating the same exercise each year without correcting known weaknesses is performance, not preparedness.
Training should expose voids, not conceal them
Training is often judged by completion rates.
Completion is easy to measure, which is why it receives so much attention. It is not, however, a reliable measure of judgement, recall under pressure or decision making in a live environment.
Better development asks people to apply knowledge to realistic choices. It assesses whether they can identify relevant information, distinguish between observation and assumption, select an appropriate escalation route and explain their reasoning. Immediate feedback is valuable because it shows where confidence exceeds competence, or where a capable person has misunderstood a critical threshold.
This approach benefits both the individual and the organisation. Practitioners gain a clearer view of the areas they need to improve. Leaders gain evidence of wider capability gaps, rather than a spreadsheet showing that everyone attended the same session.
There is a trade off. Meaningful assessment can expose uncomfortable weaknesses and requires leaders to act on the results. That is precisely why it is more useful than training that reassures everyone while changing little.
Mildot Group’s capability evaluation approach is built around this principle, identify the void, explain the consequence and give people practical direction for improvement.
The questions leaders should be asking
Senior leaders do not need to know every operational detail, but they should be able to challenge assumptions.
Four questions are particularly revealing:
- Can our people report concerns quickly, clearly and without fear of getting it wrong?
- Does every shift know who can assess a report and make a decision?
- Have we tested our arrangements under normal operating constraints, rather than ideal conditions?
- Can we show improved capability, not simply completed training and approved documents?
If the answers are uncertain, the issue is not necessarily a lack of commitment. It may be that the organisation has focused on security artefacts rather than security performance.
Mitigation is not a state an organisation reaches and keeps. Threats, people, premises and operating conditions change.
Staff leave, contractors change, sites expand and familiarity can weaken alertness. The useful question is not whether your organisation has a terrorism prevention plan.
It is whether your people can make the right next decision when the plan is no longer enough.
.
Useful LInks:
.
