top of page
Security Risk Management Consultants UK

Protect:
Protective Security
Risk Management

Independent, risk-based security advice helping organisations protect people, assets, information and operations against credible threats.

Understand the threat. Expose vulnerabilities. Reduce risk.

We assess the threat environment, identify vulnerabilities and develop proportionate security measures aligned with your organisation's objectives, risk appetite and operating environment.

What We Do

Security Risk Assessments

Structured assessment of threats, vulnerabilities, consequences and existing controls.

​

Threat & Vulnerability Assessments

Understanding how credible threats could exploit weaknesses in people, premises, systems or operations.

​

Security Reviews

Independent review of existing security arrangements, policies, procedures and controls.

​

Protective Security Planning

Development or review of proportionate security measures aligned to the risk environment.

​

Critical Asset & Site Assessments

Identifying assets, locations and activities where disruption or compromise could have significant consequences.

​

Threat & Risk Updates

Keeping security risk under review as threats, operations and circumstances change.

Counter-Terrorism & Martyn's Law Preparedness

Protective security must reflect the threats an organisation actually faces.

Counter-terrorism preparedness is an important component of effective Protective Security Risk Management. State2 Security helps organisations understand credible terrorist and hostile threats, identify vulnerabilities and develop proportionate measures to reduce risk.

 

This includes supporting organisations in preparing for the Terrorism (Protection of Premises) Act 2025, commonly known as Martyn's Law, and understanding what the legislation may mean for their premises, people and operations.

​

Our approach considers existing protective security arrangements, vulnerabilities, preparedness and response capability, helping organisations identify practical priorities rather than simply treating security as a compliance exercise.

  • Threat and vulnerability assessment

  • Operational requirements

  • Protective security measures, including vehicle dynamic assessments and hostile vehicle mitigation schemes 

  • Protective security reviews

  • Counter-terrorism protective security & preparedness (learn More about CT-protective security & preparedness)

  • Consideration of the Terrorism (Protection of Premises) Act 2025

  • Preparedness and response requirements - Evacuation, Invacuation, Lockdown and Communication

From assessment to action

Our assessments are designed to support decision-making — providing leadership teams with a clear understanding of risk, prioritised recommendations and a practical route towards improvement.

Martyn's Law

The Terrorism (Protection of Premises) Act 2025 introduces requirements intended to improve preparedness for terrorist attacks at qualifying premises and events.

 

We can help organisations assess their current position, identify gaps and develop practical and proportionate measures to improve protective security and preparedness.

Clear findings

 

  • What matters and why

  • Prioritised risksWhere attention is required first

  • Practical recommendationsWhat can realistically be done

  • Executive-level reporting

  • Clear information for leadership and governance

  • Action planning

  • A structured route from assessment to improvement.

Protective security across complex environments

Security risks differ according to the organisation, environment and consequences of disruption. Our experience spans complex operational and public-facing environments including:

Infrastructure | Manufacturing | Construction | Life Sciences | Estates & Property | Visitor Attractions | Hospitality & Events | Private Estates

Independent advice. Operational experience

State2 Security is led by Charles Frank, a Chartered Security Professional and Principal Member of the Register of Security Engineers & Specialists, with more than 30 years' experience across protective security, law enforcement, defence, infrastructure, manufacturing and major projects.

Frequently Asked Questions

​Q1. What is Protective Security Risk Management?​

Protective Security Risk Management (PSRM) is a structured approach to identifying, assessing, and managing security risks to people, information, and physical assets. It helps organisations understand what threats they face, how vulnerable they are, and the potential consequences, so they can make informed decisions about security measures.

​

In summary, PSRM ensures an adaptive, proportionate, and sustainable risk-based framework, built on thorough and ongoing security risk assessment. This enables organisations to remain protected in a cost-effective manner that maintains operational continuity and supports business success.

​

Q2. What are the elements to Protective Security Risk Management?​

Identify Critical Assets and Systems – Determine what assets or systems, if lost or unavailable, would disrupt operations or significantly impact business objectives.

​

Categorise and Classify – Categorise the importance of assets and classify the sensitivity of information.

​

Identify Threats and Vulnerabilities – Understand who may wish to cause harm, what methods they might use, which assets they are targeting, and the potential impact.

​

Assess and Record Risk – Evaluate inherent and residual risks (after mitigation). Maintain security risk registers and critical asset registers, ensuring the senior risk officer is regularly briefed on significant changes.

​

Design and Implement Controls – Select and apply controls that are proportionate, cost-effective, and aligned with the organisation’s risk appetite, while avoiding unnecessary disruption to operations.

​

Assurance and Continuous Review – Maintain confidence in security measures through structured reviews, audits, and testing to identify and address gaps or failures.

​

Q3. What are the Principles of Protective Security Risk Management?​

  • Deter – Discourage or displace acts of crime / unauthorised activity.

  • Detect – Identify and verify criminality / unauthorised activity.

  • Delay – Slow down the progress of criminal acts / unauthorised activity reaching critical assets, including measures that obstruct crime in action.

  • Mitigate – Minimise the potential consequences of crime / unauthorised activity.

  • Respond – Take action to prevent criminal acts from succeeding, secure evidence ,and support the detention and prosecution of offenders.​
     

Further Reading:

AI, ChatGPT and Secure Working: What organisations need to understand
How organisations can use AI tools responsibly without compromising security, governance or professional judgement.

​

Understand Your Security Risk

Whether you need an independent assessment, a review of existing arrangements or advice on a specific threat or vulnerability, we can help you understand where your priorities lie.

Call 

01270 297 724

Email 

bottom of page