A quiet week for new rules, a useful one for risk thinking. Government published its own national risk assessment this week. If your site’s risk register hasn’t been touched in a while, it’s a good week to open it. Below: access control, and the one habit that undoes it.

🗞️ THIS WEEK IN UK SECURITY

National Risk Register 2026 published

The Cabinet Office published the National Risk Register 2026 on 14 July, its assessment of the most serious risks facing the UK. Seven new risks were added this edition, including cyberattacks on data and water infrastructure and a new “digital resilience failure” category, drawn from lessons after the 2024 CrowdStrike outage. Pandemic and water infrastructure failure remain the highest likelihood-and-impact risks. Operationally, that means if your site depends on third-party power, water or data infrastructure, that dependency is now a named national risk, not just a local one. Also this week: the SIA formally terminated recognition of training body BIIAB, escalating the training-standards action taken earlier this month.

Key takeaway: know your site’s dependencies before the register does.

📋 COMPLIANCE CORNER

Martyn’s Law notification deadlines confirmed

Martyn’s Law notification isn’t live yet, but the mechanics are now confirmed. Home Office guidance published 14 July sets out what responsible persons must tell the SIA, and when. Qualifying premises get three months from commencement to make first contact; after that, any change needs reporting within 28 days. Qualifying events run on a tighter 14-day clock, triggered from when the event is first publicised, not the event date. An auditor will want the responsible-person name, contact details and capacity calculation ready before commencement, not built after it lands.

Fix: build the notification pack now, not in spring 2027.

🔧 OPERATIONAL TIP

A familiar face is not a valid pass

A few years back, at a vehicle gate checking passes on every driver, two officers started waving through faces they recognised as regular staff. A peer manager flagged it. I explained access control checks authorisation, not faces: permissions change without gate staff knowing, and someone whose access was pulled can still talk their way past on familiarity.

Bottom line: no valid pass, no entry, whoever you think you know.

🔗 WORTH KNOWING

Being revised following the Manchester Arena Inquiry recommendations and the new Protect Duty legislation. Expected changes: more prominence for risk assessment, site-survey provisions where multiple contractors interact, and stronger counter-terror training content.

Thanks for reading. If you found this useful, forward it to one colleague who’d benefit. That’s how this grows.

Until next Tuesday.

Need paperwork that holds up on shift? SecureDocUK’s Visitor & Vehicle Log Book. It closes the exact access-control gap in this week’s Op Tip. Also worth a look: the Daily Occurrence Book. Browse the full library at SecureDocUK.

Andras

Control Room Supervisor & Deputy Security Operations Manager

The Control Room

Keep Reading