Martyn’s Law for hotels, and what security teams need to prepare for

Martyn's law

Hotels are built around movement.

Guests arrive and leave. Staff change shifts. Contractors come and go. Deliveries enter through back-of-house areas. Bars, restaurants, meeting spaces and events can bring hundreds of people into the same property at different times.

That makes preparedness complicated.

Martyn’s Law, formally the Terrorism (Protection of Premises) Act 2025, is intended to improve how publicly accessible premises prepare for and respond to terrorist attacks. Hotels can fall within its scope, depending on factors including how many people can reasonably be expected to be present at the same time.

For hotel operators, though, the important question is not simply whether the legislation applies.

It is whether the procedures, responsibilities and evidence needed to respond effectively actually work in the reality of a 24-hour operation.

FREE Martyn's Law Download (PDF - no form)

 

What are the Martyn’s Law requirements?

Martyn’s Law introduces a tiered approach based largely on the number of people reasonably expected to be present at a premises at the same time.

Premises generally fall into the standard tier where between 200 and 799 people may reasonably be expected to be present. Enhanced-tier requirements apply to larger premises where 800 or more people may reasonably be expected to be present, subject to the other conditions in the Act.

The requirements are deliberately proportionate.

For standard-tier premises, the emphasis is on appropriate public protection procedures rather than installing extensive physical security measures. Those procedures are intended to reduce the risk of physical harm if an attack happens at the premises or nearby.

For enhanced-tier premises, there are additional requirements around public protection measures, reducing vulnerability, documenting arrangements and assigning responsibility.

 

Martyn’s Law standard tier and enhanced tier explained

For a hotel, the distinction matters because room count alone does not determine the answer.

A property may have bedrooms, restaurants, conference facilities, bars, leisure facilities and large numbers of employees on site at the same time.

It is the number of individuals reasonably expected to be present simultaneously that matters when considering the tier thresholds, alongside the other statutory tests.

Standard tier

Where a premises falls within the standard tier, the responsible person will need to notify the Security Industry Authority and ensure appropriate public protection procedures are in place, so far as reasonably practicable.

Those procedures can include how people would:

  • evacuate the premises
  • move to a safer place within it
  • secure the premises
  • and communicate information during an attack

There is no general requirement for standard-tier premises to install physical security measures simply because they fall within the Act.

Enhanced tier

Hotels that meet the enhanced-tier criteria face additional obligations.

Alongside appropriate procedures, the responsible person must consider reasonably practicable public protection measures designed to reduce vulnerability to an attack and reduce the risk of physical harm if one occurs.

Government guidance gives examples such as monitoring, access controls, searches and other protective measures where appropriate to the premises.

Enhanced-tier organisations also face additional requirements around documentation and responsibility.

 

What Martyn’s Law compliance means for hotel security operations

Legislation can look tidy on paper. Hotel security operations rarely do.

A procedure may say that staff should lock down a particular entrance, contact designated people or direct guests to a safe area.

The real question is whether the people on shift at 2:00am know that.

Can they find the correct procedure? Do they know who is responsible?

Can security communicate quickly with front of house, engineering, management and other teams?

Can somebody establish afterwards what happened and when?

This is where Martyn’s Law becomes an operational issue rather than simply a compliance one.

Preparedness has to survive shift changes, staff turnover and the everyday complexity of running a hotel.

 

Where hotel security processes can fall short

Many of the weaknesses exposed during an emergency are not dramatic failures. They are small operational gaps that already exist every day.

1. Incident reporting is fragmented

Security information may be spread across paper logs, emails, spreadsheets and different systems.

That can make it difficult to build an accurate picture quickly, particularly when several teams are involved.

The original Kinexio Martyn’s Law research identified manual incident reporting and inconsistent records as common security gaps because important information can be delayed, incomplete or difficult to distribute.

2. Staff know the policy exists but not what it says

Having a procedure somewhere on a shared drive is not the same as operational readiness.

Hotels employ large and diverse workforces, often across multiple shifts and departments.

Security procedures therefore need to be accessible, understood and usable by the people expected to act on them.

3. Communication breaks across departments

An incident rarely belongs to security alone.

Front of house may need to communicate with guests. Engineering may need to secure access points. Senior management may need updates. Contractors and third-party teams may also be involved.

The existing Kinexio briefing highlighted ineffective communication and poor coordination between teams as recurring vulnerabilities in emergency response.

4. Routine security activity is difficult to prove

A hotel may have defined patrols, checks and procedures.

But can it show that they happened?

That distinction matters because preparedness depends on more than having a written policy.

It depends on whether procedures are consistently carried out and whether there is evidence when something is missed.

5. The response can be reconstructed only after a lot of digging

After an incident, teams may need to establish:

Who was on duty? What checks had been completed? When was the incident reported? Who received the information? What actions were taken? How quickly was the situation resolved?

If that evidence sits across multiple systems and paper records, building the timeline becomes much harder than it needs to be.

 

Hotel security is an always-on problem

A hotel never really reaches a convenient moment for an emergency.

An incident could happen during breakfast, at a wedding reception, during a night shift or while contractors are working behind the scenes.

The people available to respond may be completely different depending on the hour.

That makes consistency particularly important.

A preparedness process should not depend on one experienced security manager being on site or somebody remembering where the emergency contact spreadsheet is stored.

The process needs to work regardless of the shift.

 

How hotels can prepare for Martyn’s Law

Martyn’s Law is expected to come into force in spring 2027. The SIA is currently preparing its regulatory systems and recommends that organisations begin by reviewing the Home Office statutory guidance.

That gives hotel operators an opportunity to look at their existing operation before the legislation takes effect.

Useful questions to ask now include:

  • Does Martyn’s Law apply to our property?
  • Which tier are we likely to fall within?
  • Is responsibility clearly assigned?
  • Are our public protection procedures documented and accessible?
  • Do employees understand what is expected of them?
  • Can teams communicate quickly during an emergency?
  • Can we verify that routine security checks and tasks have been completed?
  • Could we reconstruct a clear timeline after an incident?

The aim should not be to create more administration for the sake of compliance.

It should be to identify the points where the current operation relies too heavily on memory, manual processes or assumptions.

 

Martyn’s Law guidance for hotel teams

Understanding the legislation is only the starting point.

The harder part is translating it into an operation involving hundreds of people, multiple departments and continuous activity.

That is why we have created a hotel-specific Martyn’s Law briefing looking at the requirements through an operational security lens.

It explores the tier structure, common gaps in hotel security processes and practical ways teams can strengthen preparedness, communication and accountability.

Download the free Martyn’s Law for Hotels briefing

 

Leave a Comment