For much of the last two years, organisations have been preparing for Martyn’s Law without knowing exactly what implementation would involve.Â
The Terrorism (Protection of Premises) Act 2025 established a new legal framework designed to improve public protection at publicly accessible premises, but until the Home Office published its statutory guidance there was still a degree of uncertainty. Most organisations understood the broad direction of travel, yet many were left asking the same questions. What would compliance actually look like? How much would need to change? Would existing arrangements be enough, or would significant investment be required?Â
The publication of the guidance provides those answers.Â
Perhaps the most reassuring message running throughout the document is that the legislation is intended to be proportionate. The expectation is not that every venue adopts the same security measures or invests heavily in new technology. Instead, organisations are expected to understand the risks associated with their premises and put in place measures that are appropriate, practical and reasonably practicable.Â
That distinction matters.Â
Over the last year we’ve seen plenty of speculation and no shortage of organisations offering quick fixes or suggesting extensive upgrades before the legislation has even come into force. The guidance paints a much more balanced picture. It encourages organisations to build on what they already have, review existing arrangements and make sensible improvements where they’re genuinely needed.Â
Start with what you already haveÂ
The implementation period gives organisations an opportunity to prepare properly rather than react under pressure. While there is no need to rush into major changes, there is every reason to start reviewing existing arrangements now.Â
One of the biggest mistakes organisations can make is assuming that Martyn’s Law starts with purchasing new equipment or commissioning new policies. In reality, the first step should be understanding what is already in place.Â
Most organisations responsible for publicly accessible premises have developed emergency arrangements over many years. Evacuation procedures, incident response plans, business continuity arrangements, crisis management structures and physical security measures rarely exist because of one piece of legislation. They exist because organisations have gradually responded to operational requirements, health and safety obligations, licensing conditions and previous incidents.Â
Martyn’s Law doesn’t replace that work. In many cases, it simply provides a framework for reviewing it.Â
Before making investment decisions, organisations should take stock of their current arrangements and compare them against the statutory guidance. That exercise often highlights that much of the required framework already exists. The task then becomes one of refinement rather than reinvention.Â
Review before you replaceÂ
The four public protection procedures identified within the Act, evacuation, invacuation, lockdown and communication, are already familiar concepts to many organisations.Â
Similarly, organisations likely to fall within the enhanced tier may already have monitoring arrangements, access controls, physical security measures and information management processes that support the public protection measures described within the guidance.Â
That does not mean an organisation can assume it is compliant. Equally, it should not assume that compliance requires starting again.Â
In our experience, organisations are often further ahead than they think. What we see more regularly is that good practice has developed across different parts of the business without ever being brought together. Security may own one element, facilities another, health and safety another and business continuity another still. Individually those arrangements may be perfectly sound. The challenge is understanding how they fit together and whether responsibilities are clearly defined.Â
Martyn’s Law presents a useful opportunity to take that broader view.Â
Rather than asking “What do we need to introduce?”, organisations should first ask “What do we already do well and where are the gaps?”Â
That conversation usually produces a far more proportionate outcome.Â
Spending money isn’t the same as improving securityÂ
Since Martyn’s Law was first proposed, the market has responded with a growing range of products and services claiming to help organisations achieve compliance.Â
Some of those services will undoubtedly add value.Â
Others risk encouraging organisations to spend money before they fully understand what they are trying to solve.Â
The statutory guidance is careful not to prescribe particular technologies or require organisations to purchase external products or services. Instead, it repeatedly refers to measures that are reasonably practicable.Â
That principle sits at the heart of the legislation.Â
A theatre with a capacity of 250 people faces different challenges from a major sports stadium. A museum has different operational requirements from a shopping centre. Even organisations of a similar size may require very different security arrangements depending on the nature of their activities, their location and the people who use the premises.Â
Good security has never been about applying identical solutions everywhere. We’ve already had conversations with organisations questioning whether they need additional CCTV, new access control systems or more visible security measures. Those are perfectly reasonable questions, but they’re often being asked too early.Â
Until you’ve reviewed your existing procedures and understood where genuine vulnerabilities exist, it’s difficult to know whether additional investment is necessary.Â
In many cases, the most effective improvements are not technological at all. Clearer procedures, better communication, stronger governance and regular exercising often deliver greater benefits than purchasing another security system.Â
Who actually owns compliance?Â
One area that deserves more attention is governance.Â
The Act requires every in-scope premises to identify a responsible person, but deciding who that should be is not always straightforward.Â
For smaller organisations, ownership may naturally sit with a single individual. For larger organisations, responsibility is often spread across several departments. Estates teams manage buildings, facilities oversee contractors, security manages physical controls, Business continuity looks after organisational resilience and senior leadership retains overall accountability.Â
Bringing those functions together is likely to be one of the biggest practical challenges many organisations face.Â
Physical security is relatively easy to see but governance is much harder.Â
- Who approves changes to procedures?Â
- Who ensures exercises take place?Â
- Who reviews lessons learned?Â
- Who reports progress to senior leadership?
- Who makes sure improvements are actually implemented?Â
These questions are just as important as any discussion around security measures because effective governance is what keeps procedures current long after implementation has been completed.Â
Organisations should also consider how they would demonstrate that oversight if asked. Policies alone are unlikely to tell the full story. Training records, exercise reports, management reviews and documented decisions all help demonstrate that arrangements are being actively maintained rather than simply filed away.Â
Plans should be exercised, not just writtenÂ
Most organisations already have emergency procedures.Â
One of the most common assumptions we encounter is that having a documented plan means an organisation is prepared. Unfortunately, experience shows that isn’t always the case.Â
Exercises have a habit of revealing things that documents cannot.Â
Whether that’s communication not flowing as expected or decision-making can take longer than anticipated or roles overlapping., Â
Simple practical issues that never appeared during the drafting process appear. Â
We’ve seen organisations make significant improvements after a relatively straightforward tabletop exercise without changing a single piece of technology. Simply bringing the right people into the room, walking through realistic scenarios and challenging existing assumptions often provides a much clearer picture of organisational preparedness than another policy review ever could.Â
Just as importantly, exercising builds confidence. People who have already worked through difficult scenarios are far more likely to respond effectively if they ever encounter one for real. That confidence is difficult to achieve through documentation alone.Â
Martyn’s Law should not sit in isolationÂ
One of the risks we see is organisations treating Martyn’s Law as a project in its own right.Â
While the legislation introduces specific legal duties, the response should not exist in isolation from everything else an organisation is already doing.Â
Most organisations already have arrangements for managing serious incidents. Crisis management teams, business continuity plans, emergency response procedures and communication strategies are all designed to help organisations respond when events don’t go according to plan.Â
Whether the incident is a terrorist attack, a major fire, flooding, severe weather, civil unrest or a significant cyber incident, many of the fundamentals remain the same. Leaders need reliable information, decisions need to be made quickly and clearly, people need to know what is expected of them and communication needs to reach the right audiences at the right time.Â
Rather than creating entirely separate procedures for Martyn’s Law, organisations should look at how the legislation strengthens the resilience arrangements they already have.Â
That approach avoids duplication and usually leads to a better outcome.Â
We’ve seen organisations with excellent business continuity arrangements but limited physical security planning and others with strong physical security measures but little consideration given to how senior leaders would coordinate their response during a fast-moving incident.Â
Martyn’s Law provides an opportunity to bring those disciplines together. It also encourages organisations to think more broadly about preparedness. If your crisis management arrangements only work for one type of incident, they probably need further development.Â
Compliance should be the outcome, not the objectiveÂ
It’s understandable that organisations are focused on compliance.Â
The legislation creates new legal duties and every responsible person will want confidence that those duties are being met.Â
However, there is a difference between complying with legislation and improving preparedness.Â
One of the most valuable aspects of the guidance is that it encourages organisations to think about outcomes rather than simply implementing controls.Â
If procedures exist but nobody understands them, they are unlikely to be effective.Â
If security measures have been introduced without considering how they affect operations, they may create new challenges rather than reducing risk.Â
If responsibilities are unclear, decision-making can quickly become fragmented during an emergency.Â
Good security is measured by how effectively people respond when something unexpected happens and we believe that is where organisations should be focusing their attention over the coming months.Â
What should organisations be doing now?Â
With the statutory guidance now available, organisations have a clear opportunity to review their position well before the legislation comes into force.Â
That review does not need to be complicated, but it should be structured.Â
A sensible starting point is to understand whether your premises or events fall within the scope of the legislation and if they do, identify who will act as the responsible person.Â
From there, organisations should review their existing emergency procedures, crisis management arrangements and security measures against the statutory guidance. In many cases this will confirm that much of the required framework is already in place. In others, it may highlight areas where responsibilities need to be clarified, procedures formalised or plans exercised more regularly.Â
The important point is that decisions should be informed by evidence rather than assumption.Â
There is little value in investing in new technology before understanding whether the real issue is governance, communication or training.Â
Similarly, there is little benefit in producing additional documentation if existing procedures have never been tested. A measured review now is likely to be far more effective than trying to implement multiple changes immediately before the legislation comes into force.Â
Taking a practical approachÂ
Every organisation will start from a different position. Some will already have mature security and resilience arrangements in place and simply want independent assurance that they align with the expectations of the legislation. Others may need support reviewing procedures, exercising plans or understanding where practical improvements can be made.Â
At Toro, we believe organisations should approach Martyn’s Law in the same way they approach every other security challenge: by understanding the risk first, making informed decisions and implementing measures that are proportionate to the environment they operate in.Â
Our role is not to recommend unnecessary products or create complexity where it doesn’t exist. It’s to help organisations understand where they are today, identify where improvements are genuinely needed and build confidence that their people, procedures and governance arrangements are ready long before the legislation comes into force.Â
Frequently Asked QuestionsÂ
Does Martyn’s Law mean we need to buy new security systems?Â
Not necessarily. The legislation does not require organisations to purchase specific products or technologies. The Home Office guidance makes it clear that measures should be proportionate and reasonably practicable. For many organisations, the first step should be reviewing existing arrangements rather than investing in new equipment.Â
How do I know if my organisation falls within the scope of Martyn’s Law?Â
The Act applies to publicly accessible premises and certain events that meet the relevant capacity thresholds. Standard tier premises are those where it is reasonable to expect between 200 and 799 people to be present at the same time. Enhanced tier premises and qualifying events are those where 800 or more people may be present. If you’re unsure whether your premises are in scope, it’s worth carrying out an initial assessment before making any changes.Â
What is a ‘responsible person’ under Martyn’s Law?Â
The responsible person is the individual or organisation with control of the premises or event and legal responsibility for meeting the requirements of the Act. Where that responsibility sits with an organisation, there should be clear ownership at a senior level to ensure procedures are maintained, reviewed and exercised.Â
Are existing emergency plans likely to be enough?Â
Many organisations already have strong emergency procedures in place. Evacuation plans, crisis management arrangements, lockdown procedures and communication plans often already exist. The important question is whether those arrangements align with the statutory guidance, whether responsibilities are clear and whether they have been tested in practice.Â
What is the difference between evacuation, invacuation and lockdown?Â
Evacuation involves moving people away from danger and out of the premises. Invacuation is the process of moving people to a safer location within the building when leaving may increase the risk. Lockdown involves securing the premises to restrict movement and prevent further access while an incident is taking place. Organisations should understand when each approach may be appropriate and ensure staff are familiar with the procedures.Â
Is Martyn’s Law only relevant to terrorism?Â
The legislation specifically addresses preparedness for terrorist incidents, but many of the arrangements it requires support wider organisational resilience. Crisis management, emergency communications, decision-making, exercising and business continuity are equally valuable during other serious incidents, including fires, severe weather, major accidents or acts of violence.Â
Should we wait until the legislation comes into force before taking action?Â
No. The implementation period gives organisations an opportunity to review their arrangements without unnecessary pressure. Starting now allows time to identify gaps, clarify responsibilities, exercise plans and make improvements in a measured and proportionate way rather than rushing to comply closer to the implementation date.Â
What should organisations do first?Â
Before introducing new measures, organisations should understand what they already have. Review existing emergency procedures, security arrangements and crisis management plans against the statutory guidance, identify any gaps and prioritise improvements based on risk. In many cases, organisations will find they already have many of the building blocks in place.Â
Â
