hotel_blog_1600

Do you know how secure your hotels are? Why hotel groups need a portfolio view of security risk

Ask the board of a hotel group how its hotels are performing and you will get an answer within minutes. Occupancy, rate, revenue per room and guest scores, all broken down by property and region. Now ask the same board about hotel security risk, site by site. In most cases, nobody can give an equivalent answer. That is the gap in risk insight for hotel leadership.

The information exists somewhere. It sits in audits, incident logs, training records and the heads of general managers. However, nobody brings it together in a form leadership can see and act on. This year has shown why that matters.

What 2026 has shown

In February, a court jailed a man for seven and a half years for sexually assaulting a woman in her room at a hotel in Maidenhead. He had talked his way into a key card at reception in the early hours by claiming to be her boyfriend. Afterwards, more than a hundred MPs signed a letter demanding a meeting with the chain’s chief executive.

Then, in August, a second woman spoke out. She described an attack at a London hotel in the same chain in October 2025. Her abuser told reception she was having a seizure, and staff gave him a key and directed him to her room. The company said staff had not followed its policy, which is never to confirm to a third party that a guest is staying.

In July, a guest at a hotel in Dundee entered another couple’s room while they slept. Once again, the company said staff had not followed its room access procedures correctly.

How the industry is responding

Since then, the chain has commissioned an independent review led by Paul Greaney KC. It now requires explicit guest permission before staff issue any additional key. It has also retrained 12,000 customer-facing colleagues, brought in independent audit and mystery shopping, and changed chief executive.

Meanwhile, UKHospitality is developing sector-wide Guest Security Principles and Good Practice guidance through a guest security working group.

I am not writing this to single out one company. Every large hotel group I have looked at faces the same underlying problem. This one has simply had it exposed in public.

One standard, hundreds of front desks

The detail that stays with me is this. In two of those three cases, the company says a policy existed but staff did not follow it. In the third, staff followed the procedure in place, and it still failed.

That is the portfolio problem in its simplest form. Head office writes the standard. Hundreds of front desks then apply it, often at three in the morning with one person on shift. Someone convincing is usually standing at the desk. As a result, leadership has very little sight of where the standard holds and where it does not. In most cases, it finds out after something has gone wrong.

Hotel security risk reaches beyond locks and cameras

These cases also show that hotel security risk, like all security risk, reaches well beyond physical protection. Talking a receptionist into handing over a key card is a deception aimed at a person, not an attack on a door. In fact, attackers used the same basic technique against the IT help desk at M&S in 2025. Locks and cameras matter, but they do little when someone hands over the key at the front desk.

When it goes wrong, the impact is plain to see. First, and most importantly, it falls on the guest, who had every reason to feel safe in their own room. After that, it falls on the brand. In this case, that meant national headlines, a letter from more than a hundred MPs, an independent review and a change of chief executive. For any hotel group, that is the real measure of security risk.

The wider threat picture for a hotel estate is broad. It includes room access and key control, violence against women and girls, and staff working alone at night. It also covers theft, large events and functions, guest data and booking systems, and at the far end, terrorism. None of it is new. What has changed is the level of scrutiny. Boards now need to show they have a grip on it.

Martyn’s Law adds a legal reason

From spring 2027, Martyn’s Law (the Terrorism (Protection of Premises) Act 2025) adds a compliance reason. Schedule 1 covers “Hotels etc”, and the Home Office guidance extends this to hostels and holiday parks.

The test is simple. Can you reasonably expect 200 or more people on site at the same time, at least occasionally? If so, you will need public protection procedures and must notify the regulator, the Security Industry Authority. At 800 or more, the heavier enhanced tier duties apply. Staff count towards both figures.

For a multi-site operator, the first challenge is knowing which sites are in scope. For example, a sixty-room country house hotel can sit well below the line on a weekday. On a wedding Saturday, however, it can clear it comfortably. Because the test looks at what you can expect occasionally, that hotel is in scope. Across an estate of hundreds of properties, many sites will sit close to the line.

The government intends that standard tier sites can comply without buying specialist services, and I think that is right. Even so, answering the scope question needs the same thing as answering the guest security question. You need a consistent, current picture of every property.

What a portfolio view of hotel security risk would look like

In practice, I think a useful portfolio view would do six things well:

  • Ask every site the same questions. Cover room access and key issue, escalation, night staffing, CCTV and access control, training and event capacity. The people who run each property can answer them, without a specialist on site.
  • Roll it up for leadership. Show one view across the estate, by brand, region and site, in language a board can act on.
  • Highlight the exceptions. The value lies in surfacing the twenty sites that need attention, not confirming the four hundred that are fine. Specialist time can then go to those sites first.
  • Look beyond the physical. Include procedures, people, guest data and systems as well as locks and cameras.
  • Track it over time. Policies change, staff move on and sites change use, so a one-off audit soon goes stale.
  • Answer the compliance questions too. Show which sites are in scope for Martyn’s Law, which tier, and on what evidence.

How HawkSight approaches it

We have built this kind of capability at HawkSight for other sectors. Our Gateway tool gathers structured site data from the people on the ground. Alongside it, HawkSight’s enhanced threat intelligence capability draws on more than 750 global news and intelligence sources. It assesses the adversarial threat at each individual site and maps it against the key assets the hotel depends on. It then sets out the controls needed to mitigate it.

Together, these give leadership both halves of the picture. First, what the threat is at each property. Second, whether the controls to meet it are actually in place.

Right now, I am exploring whether hotel operators want a version of this built for their estates. After all, guests trust a hotel with their safety, and shareholders trust leadership to protect the brand. Do you not owe both of them that picture?

I would like to hear from you

If you are responsible for security, safety or risk across a hotel portfolio, I would value your view. What would you want a single view of security risk across your properties to tell you? And what gets in the way of having one today?

truro_martyns_law_featured_1200x628

Martyn’s Law and Truro’s cancelled Bonfire Night: what it really tells us

Truro City Council has cancelled its Bonfire Night and fireworks display for the second year in a row, and Martyn’s Law sits at the centre of the decision.

With up to 5,000 people expected, the council treated the event as Enhanced Tier under Martyn’s Law. After a summer of planning around venue, road closures, ticketed entry and crowd management, it concluded it couldn’t stage the event safely within budget while keeping tickets affordable.

It’s a disappointing outcome for the community. I suspect it won’t be the last decision of its kind as councils and community groups plan their winter events.

So it’s worth slowing down and looking at what the law actually asks for, where the uncertainty sits, and how organisers can reach proportionate decisions rather than default ones.

Where Martyn’s Law stands today

The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025. It’s expected to come into force in spring 2027, with the Security Industry Authority (SIA) as regulator.

The Home Office published its statutory guidance in April 2026. The SIA has consulted on its own guidance covering how it will inspect and enforce, and the final version is still to come but rumoured to be this autumn.

Nobody is legally required to comply yet. The government is, however, encouraging organisers to prepare as if the law were already in force. That’s sensible advice, and it’s exactly what Truro tried to do.

Not every large event is in scope

This is the point I think gets lost most often. A crowd of 5,000 doesn’t automatically make an event a “qualifying event”.

For events not held at premises already in scope, two conditions matter. There must be a reasonable expectation of 800 or more people present at the same time. There must also be measures in place to check a condition of entry, such as a ticket, pass or payment. A suggested donation doesn’t count.

That creates a real tension. Organisers often introduce ticketed or controlled entry for good crowd safety reasons, to manage numbers and flow, and it’s also what can bring an event within the Act.

Organisers should understand that trade-off early and make the decision with their eyes open, rather than discover it halfway through planning.

What Martyn’s Law asks of enhanced tier events

Every in-scope premises and event needs public protection procedures: evacuation, invacuation, lockdown and communication. These cover what staff and volunteers do if an attack is happening or about to happen. Hotels are a good example of premises in scope, which I looked at in a recent post on hotel security risk.

Enhanced Tier premises and qualifying events go further. They need public protection measures, so far as reasonably practicable, to reduce both the vulnerability of the event and the risk of harm.

Where the responsible person is an organisation, it must appoint a designated senior individual. It must also prepare a document setting out its procedures and measures, including an assessment of how it expects those to reduce the risk.

One detail matters here. The statutory guidance is explicit that the Act assumes an attack could happen anywhere, so the requirements aren’t tied to how likely an attack is at a particular site.

That’s a different starting point from a traditional threat-led security risk assessment. The question is closer to this: if something happened here, how vulnerable would we be, and what reasonable steps would reduce the harm?

The threats Martyn’s Law is designed around

Martyn’s Law is specifically about terrorism, and it helps to be precise about the attack methods it targets. Recent history gives clear examples.

Vehicle as a weapon. In Nice in July 2016, an attacker drove a lorry through crowds on the Promenade des Anglais on Bastille Day. An attacker struck the Berlin Christmas market the same way that December. For outdoor events with road access, this is often the first vulnerability to consider.

Person-borne improvised explosive device. At Manchester Arena in May 2017, the attacker detonated his device in the foyer outside the ticketed area as the audience was leaving. Twenty-two people were killed, including Martyn Hett.

Marauding attacks with firearms or bladed weapons. Examples include the Bataclan in Paris in 2015, and London Bridge and Borough Market in 2017, where a knife attack followed a vehicle attack.

Hostile reconnaissance sits underneath all of these. Attackers plan, and visible, well-run security is a deterrent in its own right.

It does show how exposed a dense, celebrating crowd is to a vehicle, whatever the motive. Good event planning will address that regardless of what the law requires.

NPSA and ProtectUK already publish a great deal of free guidance on these threats, including hostile vehicle mitigation. I’d expect that material to sit closely alongside the SIA’s regulatory guidance.

The cost question

This is where Truro’s story will generate the most debate. The Home Office’s position is that compliance should be proportionate. Its impact assessment put average annual costs for the enhanced tier at around £5,200, mostly staff time rather than physical upgrades.

Many security professionals, me included, will find that difficult to square with an open-air event for thousands of people. That’s particularly true if the chosen answer involves vehicle mitigation, search regimes, extra stewarding and road closures.

But the Act doesn’t require every possible measure. It requires what is reasonably practicable, which the guidance equates with proportionate.

The risk is that, without clear examples of what proportionate looks like for a community event, organisers price in the maximum and conclude the event can’t happen.

The answer to that is evidence. You can’t protect what you don’t understand, and you can’t defend a decision you haven’t recorded.

An organiser who can show how they assessed their vulnerabilities, which measures they chose, which they considered and set aside, and why, is in a far stronger position than one who either gold-plates everything or does nothing.

Where support can help

Until the SIA publishes its final guidance, we’re all in something of a holding pattern on the detail. Anyone responsible for an event should watch for it and engage with it.

In the meantime, the people carrying this responsibility are often council officers and volunteers rather than security professionals. What they need is a simple, structured way to work through their vulnerabilities, set them against the current threat level and their local context, and record the reasoning behind the measures they choose.

That’s an area we’ve been exploring at HawkSight. That work includes how organisers could tailor templated procedures for evacuation, invacuation, lockdown, communication and crowd management to an event, rather than writing them from scratch.

It won’t replace the SIA’s guidance, or professional judgement where an event is genuinely complex. It could take a lot of the blank-page anxiety out of the process.

Keeping sight of why this matters

Figen Murray has spent years campaigning so that other families don’t go through what hers did. The law named after her son deserves to be taken seriously, and it deserves to work.

A community losing its Bonfire Night isn’t the outcome anyone wants.

If you’re with the SIA, NPSA, a local authority or an events team and I’ve got any of this wrong, or you can see how the final guidance will address it, I’d welcome the correction.

And if you’re planning an event now, what would help you most in reaching a proportionate answer?

Sources