Protective Security Without the Fortress Mentality
- Martyn Ryan
- Aug 26
- 6 min read
Protective Security Without the Fortress Mentality: Proportionate Measures That Work
Good security doesn’t mean turning your premises into a fortress.
When people hear the words protective security, it’s easy to imagine barriers, security guards, locked doors, CCTV cameras and layers of restrictions.
Those measures can have their place.
But effective protective security isn’t about putting as many security measures as possible between your organisation and the outside world.
It’s about understanding what you’re protecting, what you’re protecting it from, and what measures are proportionate to the risk.
For most organisations, particularly public-facing businesses and community venues, the best security solution is rarely the most complicated one.
It’s the one that works.
What is protective security?
Protective security is the combination of measures an organisation uses to reduce the likelihood and potential impact of security incidents.
That can include:
Physical security
Access control
Staff awareness
Security procedures
Incident response
Emergency planning
Communication
Training
CCTV and other technology
Environmental design
Information and intelligence
Collaboration with emergency services and relevant partners
Importantly, protective security isn’t simply about preventing an incident.
It’s also about detecting, responding and recovering effectively.
A good security strategy therefore considers the whole picture.
The problem with the “fortress mentality”
There can be a temptation to respond to security concerns by adding more and more physical security.
More locks.
More barriers.
More restrictions.
More signs.
More technology.
More procedures.
But more security does not automatically mean better security.
A measure that is inappropriate, poorly implemented or routinely ignored may provide very little real protection.
Worse, excessive security can negatively affect the people who use a premises.
Imagine a busy community venue where visitors are confronted by unnecessary barriers, complicated access arrangements and an intimidating security presence.
The organisation may have technically increased its security measures.
But has it actually improved its security?
Not necessarily.
The challenge is to find the balance between security, usability and proportionate risk management.
Start with the risk — not the solution
One of the most important principles of effective protective security is simple:
Don’t start by asking, “What security equipment do we need?”
Start by asking:
“What could happen here, and how prepared are we to deal with it?”
That means considering factors such as:
The nature of the premises
The number and type of people who use it
How people enter and leave
Operating hours
Events and changes in occupancy
The surrounding environment
Previous incidents or concerns
The attractiveness of the location as a potential target
Staff capability and confidence
Existing emergency arrangements
Potential vulnerabilities
How quickly an incident could escalate
Once those factors are understood, appropriate measures can be identified.
This creates a much stronger security strategy than simply purchasing equipment and hoping it solves the problem.
Proportionate security is not “doing nothing”
There is sometimes a misconception that proportionate security means taking the cheapest or easiest option.
It doesn’t.
Proportionate does not mean minimal.
It means that the measures implemented are appropriate to the level and nature of the risk.
For one organisation, that might mean improved staff awareness, better procedures and clearer emergency arrangements.
For another, it could mean access control, improved lighting, CCTV or additional security personnel.
For a large venue hosting major events, considerably more sophisticated arrangements may be appropriate.
The key is that the security measures should have a clear purpose and a defensible rationale.
People are one of your most important security assets
Technology can be extremely valuable.
But your people are often the first line of defence.
A member of staff who recognises unusual behaviour, understands what to do and knows who to report it to can potentially identify a developing problem before it becomes an incident.
That doesn’t necessarily require everyone to become a security expert.
It requires people to understand the basics.
For example:
What does “normal” look like here?
What might be unusual?
Who should I tell if something concerns me?
What should I do if there is an immediate threat?
Where should I go for information during an incident?
Simple questions can make a significant difference.
Security awareness should therefore be embedded into normal organisational culture rather than treated as something that only matters when an incident occurs.
Security should support the customer experience
For many businesses and organisations, there is another important consideration:
Security has to work alongside the purpose of the premises.
A pub needs to remain welcoming.
A restaurant needs to provide a positive customer experience.
A sports club needs to welcome supporters.
A community centre needs to remain accessible.
A workplace needs to allow people to work effectively.
Security measures that unnecessarily interfere with those functions may ultimately become counterproductive.
The answer isn’t to ignore security.
It’s to design security measures around the way the organisation actually operates.
That is what proportionate security should look like.
Martyn’s Law and the importance of proportionate measures
The Terrorism (Protection of Premises) Act 2025, commonly referred to as Martyn’s Law, brings a greater focus on protective security and preparedness for qualifying premises and events.
For organisations within scope, the legislation isn’t simply about buying security equipment.
It is about taking appropriate steps to reduce vulnerability and improve preparedness.
That means understanding your premises, your activities, your people and the risks you may face.
It also reinforces an important principle:
Security should be considered as part of normal organisational management.
For smaller organisations in particular, this doesn’t necessarily mean creating a complicated security department or introducing disproportionate measures.
It means taking sensible, risk-based steps and being able to demonstrate that appropriate consideration has been given to protective security.
Five questions every organisation should ask
You don’t need a huge security budget to start improving your protective security.
Begin with five questions:
1. What are we protecting?
People, premises, information, operations, reputation or all of the above?
2. What are we realistically protecting them from?
Consider the threats relevant to your location, activities and environment.
3. Where are our vulnerabilities?
Look at entrances, exits, crowded areas, staff arrangements, procedures, communications and emergency response.
4. What measures do we already have?
Don’t overlook the controls that are already working.
5. What could we reasonably improve?
Prioritise improvements according to risk rather than simply implementing measures because they are available.
The best security measures are often the simplest
A good protective security strategy doesn’t necessarily require an expensive technology programme.
Sometimes the most effective improvements are straightforward:
Clear reporting arrangements.
Better staff awareness.
Improved communication.
Effective emergency procedures.
Controlled access to appropriate areas.
Good lighting.
Well-maintained CCTV.
Clear responsibilities.
Regular exercises and reviews.
Understanding what “normal” looks like.
None of these individually creates an impenetrable facility.
Together, however, they can create a significantly more resilient organisation.
Security should be dynamic
Threats change.
Organisations change.
Buildings change.
Events change.
Occupancy changes.
Staff change.
That means protective security shouldn’t be treated as a document that is written once and then placed in a drawer.
It should be reviewed periodically and particularly when there is a significant change to the organisation or the way the premises operates.
A change in opening hours, a major event, increased occupancy, a change to the physical layout or a significant change in local circumstances could all justify a review.
Good security evolves with the organisation.
A proportionate approach creates a defensible position
Perhaps one of the most valuable outcomes of a structured approach to protective security is that an organisation can explain why it has taken particular measures.
Instead of:
“We bought some CCTV because we thought we needed it.”
You can say:
“We assessed the risks associated with our premises and identified CCTV as an appropriate measure to improve monitoring and support incident response.”
That’s a much stronger position.
It demonstrates that security decisions are being made through a process of risk assessment, consideration and review.
Don’t build a fortress. Build resilience.
The ultimate objective of protective security isn’t to make a premises impossible to attack.
For most organisations, that simply isn’t realistic.
The objective is to:
Deter where possible.
Detect when something isn’t right.
Delay an attacker where appropriate.
Communicate effectively.
Respond quickly.
Protect people.
Recover effectively.
That is resilience.
And resilience doesn’t require a fortress.
It requires prepared people, sensible processes and proportionate security measures that work in the real world.
Meraxes Secure: Practical Protective Security
At Meraxes Secure Ltd, we believe protective security should be practical, proportionate and understandable.
Our approach is designed to help organisations understand their vulnerabilities, identify sensible improvements and develop security arrangements that work alongside their normal operations.
Whether you’re a small business, hospitality venue, sporting organisation, community facility or larger organisation, security should be appropriate to your risk — not driven by fear or unnecessary complexity.
If you’re unsure where to start, a structured security review can provide a clear starting point and help you develop a practical improvement plan.
Protecting People. Places. Purpose.
Need help understanding your security position?
Visit www.meraxessecure.co.uk or contact Meraxes Secure to discuss how we can help you take a practical, proportionate approach to protective security.

Comments