A UK security governance guide should not start with a policy template. It should start with a harder question: when a credible security concern reaches your organisation, who can make a decision, on what information, and how quickly?
That is governance in practice. It is the structure that turns security from a collection of systems, suppliers, assessments and documents into an accountable management activity. When it works, leaders understand their exposure, security teams know their authority, and operational staff can act without waiting for a committee meeting. When it does not, risk sits between departments until an incident exposes it.
What security governance is really for
Security governance sets the direction, authority and oversight for security activity. It establishes who owns risk, who approves investment, how assurance is gained, and what happens when controls fail.
Many organisations mistake governance for reporting upwards. Reporting matters, but a monthly dashboard is not governance if nobody can challenge poor performance, redirect resources or accept risk knowingly. Nor is a well-written security policy evidence that the organisation can manage a disruptive event.
The purpose is practical. Good governance helps an organisation make proportionate decisions before pressure, confusion and commercial priorities take over. It gives the security function sufficient access to decision makers, while keeping ownership of operational risk where it belongs: with the leaders responsible for the activity, site or service.
This matters particularly in environments such as retail, hospitality, events, transport, construction and critical infrastructure. A security decision can affect public safety, continuity, staff confidence, customer experience and contractual performance at the same time. Security cannot operate effectively as an isolated technical service.
Start with decision rights, not job titles
A common weakness is an impressive governance chart that says little about authority. It names a board sponsor, a security director and a risk committee, but does not explain who decides whether a site can continue operating with a known weakness, who can halt an unsafe activity, or who owns an overdue corrective action.
Define the decisions first. Typical examples include accepting a security risk beyond an agreed threshold, approving significant changes to security arrangements, appointing or changing a guarding supplier, responding to material incidents, and closing actions arising from assessments or exercises.
Each decision needs one accountable owner. Consultation is useful. Shared accountability is usually an evasion mechanism. If several people believe someone else owns the decision, the decision will either be delayed or made informally by whoever has the most influence on the day.
The level of authority should match the consequence. A local manager may own routine corrective actions. A decision to operate with a serious unresolved vulnerability should sit with a senior leader who understands the financial, legal, operational and reputational consequences. Security specialists advise, assess and challenge. They should not quietly inherit business risk because senior management is reluctant to make a visible choice.
Governance must reach the operating edge
Board oversight is necessary, but it is not enough. The people opening a venue, managing a contractor, responding to suspicious behaviour or supervising a crowded public space need clear boundaries and escalation routes.
If staff cannot explain what requires escalation, whom to contact, and what immediate action they are authorised to take, the governance model has not reached the point where risk is managed. It remains a senior-level design rather than an operational capability.
Build assurance around evidence of performance
Assurance is where security governance often loses credibility. Organisations can produce training completion figures, policy acknowledgements, meeting minutes and audit scores while remaining unable to demonstrate that people will perform under pressure.
Those measures have value, but they are inputs. They do not prove capability.
A better assurance approach combines several forms of evidence. Threat, vulnerability and risk assessments establish the basis for controls. Site inspections and technical reviews test whether those controls exist and are maintained. Exercises, scenario discussions and capability evaluations show whether people understand their role and can make decisions. Incident reports and near misses reveal how the system behaves in reality.
The distinction matters. A team may achieve full completion of counter terrorism training, yet have no confidence in recognising an escalating concern, making an early report or coordinating a proportionate response. The training record looks good. The operational picture is weak.
Security leaders should therefore ask for assurance that answers three questions: are the controls in place, are they used as intended, and would they work when conditions are imperfect? The third question is usually the one that exposes the gap.
Mildot Group’s experience is that immediate diagnostic feedback can be particularly useful here. It moves the discussion beyond whether people attended learning and towards what they can actually identify, judge and do. That creates a far more useful basis for development and management intervention.
Make risk appetite usable
Most organisations state that they have little or no appetite for security risk. It sounds reassuring, but it is rarely true or useful. Every organisation makes trade-offs. It may accept reduced coverage at a low-risk location, defer a technical improvement, or keep an operation open while a weakness is being addressed. The issue is not whether risk exists. It is whether it is understood, authorised and controlled.
A usable security risk appetite describes boundaries in operational terms. It should make clear which risks cannot be accepted locally, which require senior approval, and what compensating measures are expected while a permanent solution is developed.
For example, a failure in an access control system does not automatically require the same response in every setting. The appropriate response depends on the location, the activity, the people present, the duration of the failure and the available alternatives. Governance provides the decision framework. Competent people still need judgement.
Avoid turning appetite into a complicated scoring exercise that nobody outside the risk team understands. If a duty manager cannot use it during a difficult shift, it is not serving its purpose.
Treat suppliers as part of the control environment
Security delivery is often distributed across guarding providers, facilities teams, technology suppliers, landlords, event partners and contractors. Governance fails when an organisation assumes a contract transfers accountability.
A supplier may deliver a specified service. The organisation still owns the risk created if that service is inadequate, poorly supervised or no longer suited to the operating environment. Contract oversight should therefore examine performance, competence, supervision, incident quality, staffing resilience and whether reported activity is producing the intended security outcome.
This requires more than checking response times and attendance figures. A guarding presence may meet contractual numbers while staff lack local knowledge, escalation confidence or effective supervision. Technical systems may be operational but poorly configured, poorly monitored or disconnected from response arrangements.
Senior leaders should receive an honest view of these dependencies. Good news that cannot survive a site visit is not assurance.
Give governance a rhythm, then use it
Security governance needs a regular cadence, but meetings should not become a ritual. A site-level forum may deal with local actions, incidents and emerging concerns. A strategic forum should address significant risks, investment, assurance findings, supplier performance and unresolved decisions. The board or executive team needs a concise view of exposure, material changes and decisions requiring senior ownership.
The exact structure depends on the size and complexity of the organisation. A single venue does not need the same machinery as a national estate. What both need is a reliable route from the operating edge to the person able to decide.
Papers should be short and decision-focused. State the issue, the evidence, the consequence of delay, the options and the accountable recommendation. Do not conceal uncertainty. Security decisions are often made with incomplete information. Good governance records the basis for the decision and reviews it when circumstances change.
Test behaviour, not just plans
Plans are necessary, especially where organisations are strengthening preparedness for counter terrorism requirements and public protection duties. But a plan has no value until people have tested their understanding of it.
Use credible, proportionate scenarios to examine how managers communicate, how information moves, whether authority is clear and where assumptions fail. Keep the exercise focused on learning, not performance theatre. The most valuable finding may be that the escalation process is unclear, a contractor is not included, or a senior decision maker cannot be reached at the time they are needed.
These are governance findings, not minor administrative issues. They show where accountability and capability are disconnected.
The strongest security governance does not promise certainty. It creates disciplined decision making when certainty is unavailable. If your arrangements produce clear ownership, honest assurance and people who can act with sound judgement, they are doing the job. If they mainly produce papers, attendance and reassurance, the real test has not happened yet.