For the last few years, most conversations about security at Board level have understandably focused on cyber threats. However, across our NHS and public sector clients, we’re seeing a different conversation starting to emerge. Increasingly, the issues keeping executives awake at night are not just ransomware attacks and data breaches. They are concerns about staff safety, violence and aggression, lone workers, public access to buildings and preparedness for major incidents.

In many respects, physical security has drifted into the background over the past decade. It has often been viewed as an operational matter, something managed by facilities teams, security managers or contracted guarding providers. That approach is becoming increasingly difficult to justify.

Recent figures suggest NHS staff are experiencing hundreds of incidents of violence and aggression every day. Meanwhile, organisations continue to grapple with the practical implications of Martyn’s Law and what it means for their own premises, people and preparedness arrangements.

Staff Safety Cannot Be Taken for Granted

One of the strongest themes we encounter when speaking with healthcare and public sector leaders is concern about the treatment of frontline staff.

Most people would be surprised by the scale of violence and aggression now being reported across the NHS. Incidents that once might have been considered exceptional are becoming routine in some areas of the frontline workforce.

The repercussions extend far beyond the immediate incident as violence affects morale, wellbeing, recruitment and retention. It contributes to sickness absence and burnout. It can also have a profound effect on teams long after an incident has occurred.

Lone Worker Arrangements Need More Challenge

Lone working is another area that rarely receives significant Board attention until something goes wrong.

Many organisations have policies, monitoring systems and escalation procedures in place. The challenge is understanding whether those arrangements are genuinely operating as intended.

Community staff, social workers, housing officers and healthcare professionals often find themselves dealing with complex situations in unpredictable environments. Procedures that look robust on paper can prove much less effective when tested in reality.

From an assurance perspective, this is an area where we frequently see assumptions rather than evidence as a policy is not assurance and training records are not assurance. The real test is whether staff understand the arrangements, use them consistently and trust them to work when needed.

Martyn’s Law Is Prompting a Wider Conversation

The introduction of Martyn’s Law has understandably generated considerable attention across the public sector. Whilst much of the discussion has focused on compliance, we think that misses the bigger point.

The legislation reflects a changing expectation that organisations should actively consider how they would respond to a serious security incident rather than simply assuming it will never happen.

For many organisations, that raises important questions.

Would staff know what to do?

Have response arrangements been tested?

Could critical services continue to operate?

Who would take charge during a fast-moving incident?

The answers are not always as clear as organisations would like to believe.

Looking Beyond Guards and CCTV

One of the most common mistakes we see is equating physical security with visible security measures.

CCTV, access controls and security officers remain important. However, the strongest security environments are usually those where people take responsibility for security rather than assuming somebody else will deal with it.

That means creating a culture where:

  • incidents are reported;
  • concerns are escalated;
  • lessons are acted upon; and
  • security is recognised as everyone’s responsibility.

In our experience, organisational culture is often a far stronger predictor of resilience than the number of cameras on the wall.

A Good Time for Boards to Take Stock

Most public sector organisations have invested significant time and effort into strengthening cyber security over recent years.

We believe many would benefit from applying the same level of challenge to physical security.

Not because the risks are new, but because the environment is changing.

Higher levels of aggression towards staff, increasing expectations around preparedness and a growing focus on organisational resilience mean that physical security deserves a more prominent place on Board and Audit Committee agendas than it often receives today.

For many organisations, now would be a sensible time to step back and ask a simple question:

How confident are we that our arrangements would stand up to a serious security incident?

The answer may be more important than many Boards realise.

TIAA’s Security Advisory Services are here to help. Our experts can guide you through the practical, ethical, and operational aspects of deploying advanced surveillance solutions, ensuring compliance, resilience, and peace of mind. Contact us today to explore tailored strategies that protect your people, assets, and reputation.

Jonathan Gladwin,  Director – Security Advisory 

Carver Tedstone, Managing Consultant Security Advisory  

To view the previous blogs in the series please visit TIAA Blogs