hotel_blog_1600

Do you know how secure your hotels are? Why hotel groups need a portfolio view of security risk

Ask the board of a hotel group how its hotels are performing and you will get an answer within minutes. Occupancy, rate, revenue per room and guest scores, all broken down by property and region. Now ask the same board about hotel security risk, site by site. In most cases, nobody can give an equivalent answer. That is the gap in risk insight for hotel leadership.

The information exists somewhere. It sits in audits, incident logs, training records and the heads of general managers. However, nobody brings it together in a form leadership can see and act on. This year has shown why that matters.

What 2026 has shown

In February, a court jailed a man for seven and a half years for sexually assaulting a woman in her room at a hotel in Maidenhead. He had talked his way into a key card at reception in the early hours by claiming to be her boyfriend. Afterwards, more than a hundred MPs signed a letter demanding a meeting with the chain’s chief executive.

Then, in August, a second woman spoke out. She described an attack at a London hotel in the same chain in October 2025. Her abuser told reception she was having a seizure, and staff gave him a key and directed him to her room. The company said staff had not followed its policy, which is never to confirm to a third party that a guest is staying.

In July, a guest at a hotel in Dundee entered another couple’s room while they slept. Once again, the company said staff had not followed its room access procedures correctly.

How the industry is responding

Since then, the chain has commissioned an independent review led by Paul Greaney KC. It now requires explicit guest permission before staff issue any additional key. It has also retrained 12,000 customer-facing colleagues, brought in independent audit and mystery shopping, and changed chief executive.

Meanwhile, UKHospitality is developing sector-wide Guest Security Principles and Good Practice guidance through a guest security working group.

I am not writing this to single out one company. Every large hotel group I have looked at faces the same underlying problem. This one has simply had it exposed in public.

One standard, hundreds of front desks

The detail that stays with me is this. In two of those three cases, the company says a policy existed but staff did not follow it. In the third, staff followed the procedure in place, and it still failed.

That is the portfolio problem in its simplest form. Head office writes the standard. Hundreds of front desks then apply it, often at three in the morning with one person on shift. Someone convincing is usually standing at the desk. As a result, leadership has very little sight of where the standard holds and where it does not. In most cases, it finds out after something has gone wrong.

Hotel security risk reaches beyond locks and cameras

These cases also show that hotel security risk, like all security risk, reaches well beyond physical protection. Talking a receptionist into handing over a key card is a deception aimed at a person, not an attack on a door. In fact, attackers used the same basic technique against the IT help desk at M&S in 2025. Locks and cameras matter, but they do little when someone hands over the key at the front desk.

When it goes wrong, the impact is plain to see. First, and most importantly, it falls on the guest, who had every reason to feel safe in their own room. After that, it falls on the brand. In this case, that meant national headlines, a letter from more than a hundred MPs, an independent review and a change of chief executive. For any hotel group, that is the real measure of security risk.

The wider threat picture for a hotel estate is broad. It includes room access and key control, violence against women and girls, and staff working alone at night. It also covers theft, large events and functions, guest data and booking systems, and at the far end, terrorism. None of it is new. What has changed is the level of scrutiny. Boards now need to show they have a grip on it.

Martyn’s Law adds a legal reason

From spring 2027, Martyn’s Law (the Terrorism (Protection of Premises) Act 2025) adds a compliance reason. Schedule 1 covers “Hotels etc”, and the Home Office guidance extends this to hostels and holiday parks.

The test is simple. Can you reasonably expect 200 or more people on site at the same time, at least occasionally? If so, you will need public protection procedures and must notify the regulator, the Security Industry Authority. At 800 or more, the heavier enhanced tier duties apply. Staff count towards both figures.

For a multi-site operator, the first challenge is knowing which sites are in scope. For example, a sixty-room country house hotel can sit well below the line on a weekday. On a wedding Saturday, however, it can clear it comfortably. Because the test looks at what you can expect occasionally, that hotel is in scope. Across an estate of hundreds of properties, many sites will sit close to the line.

The government intends that standard tier sites can comply without buying specialist services, and I think that is right. Even so, answering the scope question needs the same thing as answering the guest security question. You need a consistent, current picture of every property.

What a portfolio view of hotel security risk would look like

In practice, I think a useful portfolio view would do six things well:

  • Ask every site the same questions. Cover room access and key issue, escalation, night staffing, CCTV and access control, training and event capacity. The people who run each property can answer them, without a specialist on site.
  • Roll it up for leadership. Show one view across the estate, by brand, region and site, in language a board can act on.
  • Highlight the exceptions. The value lies in surfacing the twenty sites that need attention, not confirming the four hundred that are fine. Specialist time can then go to those sites first.
  • Look beyond the physical. Include procedures, people, guest data and systems as well as locks and cameras.
  • Track it over time. Policies change, staff move on and sites change use, so a one-off audit soon goes stale.
  • Answer the compliance questions too. Show which sites are in scope for Martyn’s Law, which tier, and on what evidence.

How HawkSight approaches it

We have built this kind of capability at HawkSight for other sectors. Our Gateway tool gathers structured site data from the people on the ground. Alongside it, HawkSight’s enhanced threat intelligence capability draws on more than 750 global news and intelligence sources. It assesses the adversarial threat at each individual site and maps it against the key assets the hotel depends on. It then sets out the controls needed to mitigate it.

Together, these give leadership both halves of the picture. First, what the threat is at each property. Second, whether the controls to meet it are actually in place.

Right now, I am exploring whether hotel operators want a version of this built for their estates. After all, guests trust a hotel with their safety, and shareholders trust leadership to protect the brand. Do you not owe both of them that picture?

I would like to hear from you

If you are responsible for security, safety or risk across a hotel portfolio, I would value your view. What would you want a single view of security risk across your properties to tell you? And what gets in the way of having one today?

hybrid-conflict-blog-hero

War, crime or terrorism? Hostile state acts need a name, and a plan

When a hostile state acts on British soil, is it war, crime or terrorism? How we answer shapes how we prepare.

In the early hours of Sunday morning, police received a report of three suspicious vehicles heading towards RAF Fairford. One local resident has described finding the road blocked by three vans and a group of hooded, masked men, who ran when they saw her. Five men were arrested, first on suspicion of explosives offences and then on suspicion of preparing a terrorist act. Police evacuated around 85 households while Army bomb disposal teams examined the vehicles.

Fairford isn’t just any airfield. It hosts US heavy bombers, and the US has flown operations against Iran from it since February. In July, Iran’s Revolutionary Guard publicly warned Britain that any base used against Iranian territory was a legitimate target. ITV News reports that one line of inquiry is whether representatives of the Iranian regime paid others to carry out the plot on their behalf. At the time of writing, no connection has been confirmed. The five men remain in custody, and it’s right that we let investigators establish the facts.

But whatever they find, the incident exposes a problem I’ve been thinking about for some time. Judging by the discussion on my recent posts, it clearly resonates with many of you.

An academic argument with practical consequences

When I argued that we are, in effect, at war with states using hybrid methods against the UK, people rightly challenged me on the word “war”. War has a legal meaning, and using it loosely carries real risk, not least the risk of escalation with nuclear-armed states.

So let me come at it from a different direction.

What is the difference between a state-sponsored terrorist act and an act of war? The objective is often identical: to coerce another country into changing its behaviour. Clausewitz described war as the continuation of policy by other means, and a proxy with a van full of explosives is simply another means.

The real difference isn’t the implement. It’s the rulebook each one triggers.

An act of war falls under the laws of armed conflict and can justify a state-level response. We treat an act of terrorism as a crime, for the police and the courts to handle. The first can reach the state that ordered it. The second, in practice, reaches the people caught holding the tools.

That distinction can look academic, but it decides who can respond, and how.

Choosing the box you land in

Hostile states understand this better than we do. If you want to pressure the UK without paying a state-level price, you don’t send your own forces. You recruit criminals or sympathisers, often online and often for modest sums, and you make sure the act looks like arson, vandalism or terrorism. Once it lands in the criminal box, police arrest the proxy, the courts prosecute them, and the state that directed it pays nothing.

We’ve already seen this pattern. In 2025, men recruited on behalf of Russia’s Wagner Group were convicted over an arson attack on a London warehouse storing equipment bound for Ukraine. The organisers were the first people convicted under the National Security Act 2023. MI5’s Director General has said publicly that Iran, like the Russian services, makes extensive use of criminals as proxies. In 2025 he reported more than twenty potentially lethal Iran-backed plots in a single year. Different states, same method.

Put simply, we’ve built a system for catching the hand, not the head.

The National Security Act 2023 was a genuine step forward, creating offences for foreign-directed sabotage and interference. But it still works at the level of the individual. It punishes the proxy more effectively without changing the calculation for the state behind them.

A third category

This is where Kenneth Smart’s challenge changed my thinking. Framing these acts as war, within the current framework, does risk rapid escalation, and that’s a serious concern. But the answer can’t be to fall back on treating them as ordinary crime when a state is clearly directing them.

I think we need a third category: hostile state acts below the threshold of armed conflict, with rules of their own.

We already have the tools. Diplomatic expulsions, targeted sanctions, asset freezes, proportionate cyber operations and, under international law, lawful countermeasures against a state that has committed a wrongful act. What we lack is a framework that says when we’ll use them.

We already do this for threats we have defined. When the national terrorism threat level changes, nobody improvises. The government publishes the level, and organisations plan the protective measures that follow it in advance. Hostile state acts deserve the same treatment. Whatever we choose to call them, they need to become policy, with responses agreed before the next incident rather than after it.

Salisbury in 2018 shows it can be done. The government attributed the attack to Russia on a “highly likely” intelligence assessment, rather than waiting for a conviction. It then responded at state level alongside its allies. The problem is that the government built the response after the fact, and ad hoc responses deter very little.

A framework for hostile state acts

A proper framework would do three things.

First, define what a hostile state act is, so that incidents are assessed as part of a campaign rather than one at a time.

Second, set a published standard for attribution: a high-confidence assessment rather than proof beyond reasonable doubt. It should run alongside any criminal investigation instead of waiting for it.

Third, declare the kinds of proportionate, graduated response a state can expect when that threshold is met.

The honest counterargument is that publishing a threshold tells an adversary exactly where to stop. That’s a real risk. But I’d argue the current position is worse. Right now there is no threshold at all, and the fog of uncertainty is doing our adversaries’ work for them.

Why this matters beyond defence

Businesses are already on this battlefield. Critical infrastructure, defence supply chains and the companies around them are obvious targets, but anyone whose disruption creates pressure is in scope. Organisations can’t plan properly against a threat their own government hasn’t defined. A clear national framework would give security leaders something concrete to assess risk against and to explain to their boards. It is the same need for clear definitions that sits behind Martyn’s Law for terrorism at public venues.

I don’t claim to have all the answers, and I’d genuinely welcome challenge. Is a third category the right approach? And if it is, where would you set the threshold?


A note of thanks

I’d like to thank everyone who took the time to respond to my recent posts on this subject. The volume and quality of the discussion made it clear this is something that matters to many of us working in security, defence and resilience.

In particular, I’d like to thank Kenneth Smart. His thoughtful academic input on the challenges of framing these acts as war made me think harder about the problem. His challenge is a large part of why this piece explores a third category of conflict, rather than simply arguing that we are at war.

A note on how this was written

These are my own views, shaped by that discussion. I used AI to help research and draft this piece. Mainly, that let me get it out while the conversation is still live and people are still engaged with it. It has also helped me organise my thinking and put it across more clearly. The arguments, and any errors, are mine.

truro_martyns_law_featured_1200x628

Martyn’s Law and Truro’s cancelled Bonfire Night: what it really tells us

Truro City Council has cancelled its Bonfire Night and fireworks display for the second year in a row, and Martyn’s Law sits at the centre of the decision.

With up to 5,000 people expected, the council treated the event as Enhanced Tier under Martyn’s Law. After a summer of planning around venue, road closures, ticketed entry and crowd management, it concluded it couldn’t stage the event safely within budget while keeping tickets affordable.

It’s a disappointing outcome for the community. I suspect it won’t be the last decision of its kind as councils and community groups plan their winter events.

So it’s worth slowing down and looking at what the law actually asks for, where the uncertainty sits, and how organisers can reach proportionate decisions rather than default ones.

Where Martyn’s Law stands today

The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025. It’s expected to come into force in spring 2027, with the Security Industry Authority (SIA) as regulator.

The Home Office published its statutory guidance in April 2026. The SIA has consulted on its own guidance covering how it will inspect and enforce, and the final version is still to come but rumoured to be this autumn.

Nobody is legally required to comply yet. The government is, however, encouraging organisers to prepare as if the law were already in force. That’s sensible advice, and it’s exactly what Truro tried to do.

Not every large event is in scope

This is the point I think gets lost most often. A crowd of 5,000 doesn’t automatically make an event a “qualifying event”.

For events not held at premises already in scope, two conditions matter. There must be a reasonable expectation of 800 or more people present at the same time. There must also be measures in place to check a condition of entry, such as a ticket, pass or payment. A suggested donation doesn’t count.

That creates a real tension. Organisers often introduce ticketed or controlled entry for good crowd safety reasons, to manage numbers and flow, and it’s also what can bring an event within the Act.

Organisers should understand that trade-off early and make the decision with their eyes open, rather than discover it halfway through planning.

What Martyn’s Law asks of enhanced tier events

Every in-scope premises and event needs public protection procedures: evacuation, invacuation, lockdown and communication. These cover what staff and volunteers do if an attack is happening or about to happen. Hotels are a good example of premises in scope, which I looked at in a recent post on hotel security risk.

Enhanced Tier premises and qualifying events go further. They need public protection measures, so far as reasonably practicable, to reduce both the vulnerability of the event and the risk of harm.

Where the responsible person is an organisation, it must appoint a designated senior individual. It must also prepare a document setting out its procedures and measures, including an assessment of how it expects those to reduce the risk.

One detail matters here. The statutory guidance is explicit that the Act assumes an attack could happen anywhere, so the requirements aren’t tied to how likely an attack is at a particular site.

That’s a different starting point from a traditional threat-led security risk assessment. The question is closer to this: if something happened here, how vulnerable would we be, and what reasonable steps would reduce the harm?

The threats Martyn’s Law is designed around

Martyn’s Law is specifically about terrorism, and it helps to be precise about the attack methods it targets. Recent history gives clear examples.

Vehicle as a weapon. In Nice in July 2016, an attacker drove a lorry through crowds on the Promenade des Anglais on Bastille Day. An attacker struck the Berlin Christmas market the same way that December. For outdoor events with road access, this is often the first vulnerability to consider.

Person-borne improvised explosive device. At Manchester Arena in May 2017, the attacker detonated his device in the foyer outside the ticketed area as the audience was leaving. Twenty-two people were killed, including Martyn Hett.

Marauding attacks with firearms or bladed weapons. Examples include the Bataclan in Paris in 2015, and London Bridge and Borough Market in 2017, where a knife attack followed a vehicle attack.

Hostile reconnaissance sits underneath all of these. Attackers plan, and visible, well-run security is a deterrent in its own right.

It does show how exposed a dense, celebrating crowd is to a vehicle, whatever the motive. Good event planning will address that regardless of what the law requires.

NPSA and ProtectUK already publish a great deal of free guidance on these threats, including hostile vehicle mitigation. I’d expect that material to sit closely alongside the SIA’s regulatory guidance.

The cost question

This is where Truro’s story will generate the most debate. The Home Office’s position is that compliance should be proportionate. Its impact assessment put average annual costs for the enhanced tier at around £5,200, mostly staff time rather than physical upgrades.

Many security professionals, me included, will find that difficult to square with an open-air event for thousands of people. That’s particularly true if the chosen answer involves vehicle mitigation, search regimes, extra stewarding and road closures.

But the Act doesn’t require every possible measure. It requires what is reasonably practicable, which the guidance equates with proportionate.

The risk is that, without clear examples of what proportionate looks like for a community event, organisers price in the maximum and conclude the event can’t happen.

The answer to that is evidence. You can’t protect what you don’t understand, and you can’t defend a decision you haven’t recorded.

An organiser who can show how they assessed their vulnerabilities, which measures they chose, which they considered and set aside, and why, is in a far stronger position than one who either gold-plates everything or does nothing.

Where support can help

Until the SIA publishes its final guidance, we’re all in something of a holding pattern on the detail. Anyone responsible for an event should watch for it and engage with it.

In the meantime, the people carrying this responsibility are often council officers and volunteers rather than security professionals. What they need is a simple, structured way to work through their vulnerabilities, set them against the current threat level and their local context, and record the reasoning behind the measures they choose.

That’s an area we’ve been exploring at HawkSight. That work includes how organisers could tailor templated procedures for evacuation, invacuation, lockdown, communication and crowd management to an event, rather than writing them from scratch.

It won’t replace the SIA’s guidance, or professional judgement where an event is genuinely complex. It could take a lot of the blank-page anxiety out of the process.

Keeping sight of why this matters

Figen Murray has spent years campaigning so that other families don’t go through what hers did. The law named after her son deserves to be taken seriously, and it deserves to work.

A community losing its Bonfire Night isn’t the outcome anyone wants.

If you’re with the SIA, NPSA, a local authority or an events team and I’ve got any of this wrong, or you can see how the final guidance will address it, I’d welcome the correction.

And if you’re planning an event now, what would help you most in reaching a proportionate answer?

Sources