All insights
Security & Risk Management

Crowded Places Security: Building a Strategy That Goes Beyond Compliance

With the Terrorism Protection of Premises Act 2025 reshaping responsibilities for crowded places across the UK, organisations are being forced to re-examine how they protect public-facing sites. This article sets out how to move beyond minimum compliance and build a crowded places security strategy that is operationally credible and proportionate to the threat.

Oakwood Risk & Resilience9 min read

Crowded places security has been a recognised discipline within UK counter terrorism for more than two decades, but for much of that time it has been the responsibility of a relatively small group of specialists working with a relatively small group of high profile venues. The arrival of the Terrorism Protection of Premises Act 2025 has changed that. By the time the legislation reaches full implementation, tens of thousands of UK premises and events will be brought formally within scope, and many of them will be operated by organisations with little prior exposure to protective security thinking.

There is a real risk that this expansion produces a tick box culture, where organisations focus on the narrow letter of the legislation rather than the underlying intent. The intent is straightforward, namely that publicly accessible locations should reduce the risk of harm to the public from acts of terrorism. Meeting that intent in 2026 requires a strategic approach that goes well beyond compliance with secondary legislation.

Understanding the new landscape

The Act creates two tiers of duty, with standard duty premises subject to lighter requirements than enhanced duty premises and qualifying events. We have explored the practical preparation steps in our piece on preparing your organisation for the Terrorism Protection of Premises Act, and our explainer on Martyn's Law and your terrorism protection obligations sets out the legal framework in more detail. Rather than repeat that ground, this article focuses on the strategic questions that responsible persons should be asking once the basic compliance picture is clear.

The most important shift is that protective security is no longer something that can be delegated entirely to a security manager or a contracted guarding provider. Boards and senior leadership teams now have explicit accountability for the protective security posture of their premises and events. That accountability cannot be discharged by reading a policy document, and it requires senior leaders to develop a working understanding of the threats their sites face and the measures in place to mitigate those threats.

From compliance to operational credibility

The difference between a compliant site and an operationally credible one is striking when you walk through both. A compliant site has the documentation, the signage and the basic procedures in place. An operationally credible site has staff who can articulate what they would do in a series of plausible scenarios, security measures that have been tested under realistic conditions and a clear line of communication between front of house and senior leadership when something unusual occurs.

Operational credibility is built through three sustained activities. The first is meaningful staff training that goes beyond completing an online module. Front of house staff, security teams and operational managers need to understand the threats they might encounter, the indicators of hostile reconnaissance and the actions they should take in the early minutes of an incident. The second is regular exercising that puts those skills under pressure. Tabletop exercises remain the most accessible starting point, and our testing and exercises practice can help security and operational teams design realistic scenarios. The third is a process for capturing lessons from incidents and near misses across the wider sector and translating them into improvements at the site level.

Designing protective security around operations, not against them

One of the most common mistakes we see in crowded places security is the imposition of measures that work against the operational rhythm of the site rather than with it. Bag searches that create dangerous queues outside the security perimeter. Hostile vehicle mitigation that channels people into pinch points. Staff briefings that issue instructions but provide no context. Each of these failures usually reflects a security plan designed in isolation from the operational realities of the venue.

Good crowded places security is co-designed with the operational and customer experience teams. It accepts that the primary purpose of the site is to deliver an experience to its visitors, and it looks for measures that provide protection without undermining that purpose. This is not about diluting security in favour of commercial considerations. It is about recognising that security measures which create operational chaos are usually counterproductive, because they generate workarounds, undermine staff buy in and erode the wider security culture.

The defence in depth principle that we have written about in our piece on the principles of defence in depth for physical security is particularly useful here. By layering measures rather than relying on a single point of control, sites can absorb the inevitable operational compromises without losing their overall protective effect.

Threat intelligence and dynamic risk assessment

Static risk assessments age quickly in protective security. The threat picture in 2026 is shifting rapidly, with new attack methodologies, evolving target preferences and changing patterns of hostile reconnaissance. Sites that rely on a risk assessment completed eighteen months ago and not revisited since are exposed in ways their leadership rarely appreciates.

A credible crowded places security programme includes a process for receiving and acting on relevant threat intelligence. For most sites this means subscribing to the relevant national and sector specific advisories, building a relationship with the local counter terrorism security adviser and ensuring that intelligence reaches the people who can act on it within the organisation. Dynamic risk assessment then becomes the routine business of adjusting protective measures in response to changes in the intelligence picture, whether that means temporary uplift around a high profile event or sustained changes in response to a developing threat.

Investing in the right capabilities

The capability mix needed to deliver credible crowded places security in 2026 includes operational security expertise, behavioural detection skills, communications planning and incident management. Few organisations have all of these in house, and many will continue to rely on a combination of internal security teams and specialist external support.

For organisations that are building or rebuilding their internal capability, formal qualifications are increasingly important. The Certified Terrorism and Protective Security Practitioner certification is specifically designed for those responsible for protective security in publicly accessible locations. For broader security risk leadership, the CSRM® Certified Security Risk Manager certification provides the strategic grounding to integrate protective security into a wider security risk programme. We have written previously about how to become a certified protective security adviser in 2026 for those considering a career path in this discipline.

External support has a role too, particularly in the design and facilitation of complex exercises and in the periodic independent assessment of protective security arrangements. Our testing and exercises practice regularly supports crowded places operators with realistic scenario based exercising, and our security and resilience consulting team provides independent assessment and strategic advice on protective security programmes.

Where to start

Organisations that are early in their protective security journey often ask where to start. Our consistent answer is that the strategy should start with the question of harm, not the question of compliance. Who could be harmed at your site, in what plausible scenarios, and what would be the consequences for them, for the wider public and for your organisation. From that starting point, a proportionate and operationally credible programme tends to emerge naturally. Working backwards from a compliance checklist, by contrast, almost always produces a programme that satisfies the regulator on paper while leaving real gaps in the protection of the public.

The next two years will see the practical implementation of the Act tested against real incidents and real operational pressures. The organisations that treat 2026 as the year to build a strategic, intelligence led and operationally credible protective security programme will be in a much stronger position than those that wait for the secondary legislation to dictate the minimum and then do only that.

Talk to us

Want to discuss how this applies to your organisation?

Speak with us