Staying Ahead of Risk: A Guide to Physical Security Intelligence

Physical security has always depended on information. The question is whether that information arrives in time to act on it, or only after something has already gone wrong.
For most organisations, the honest answer is the latter. Incident reports capture what happened. Security briefings describe yesterday’s environment. Risk assessments document threats that were assessed months ago. By the time the picture is complete, it is already out of date.
Threat intelligence changes that dynamic. It is the practice of gathering, verifying, and analysing information about risks before they materialise – and turning that analysis into decisions your teams can act on. Not just what has happened, but what is developing, what is likely, and what an appropriate response looks like.
This guide covers how threat intelligence works in physical security, what it means for security operations teams, commercial real estate portfolios, and retail, how location risk profiles build a structured picture of site-level risk, and how a maturing legislative environment is raising the bar for everyone who manages public-facing premises.
To learn more about Zinc’s Threat Intelligence module, click here.
What threat intelligence means in physical security
Threat intelligence in physical security is not a single feed or a data dashboard. It is a discipline: the structured process of collecting information from multiple sources, verifying its accuracy, contextualising it against your specific sites and operations, and producing guidance that supports faster, better decisions.
The distinction between data and intelligence matters. Data is raw: a crime report filed, a terrorism alert broadcast, a weather warning issued. Intelligence is processed: the same information filtered for relevance, verified for accuracy, and enriched with context so that a security manager in a specific building knows what it means for them, right now.
Unverified data creates noise. Teams that receive too many low-quality alerts quickly learn to disregard them, and miss the ones that matter. Analyst-verified intelligence, filtered by location relevance, is the standard that makes real-time response operationally credible.
Effective physical security intelligence draws on seven risk dimensions, each of which is covered in detail in the location risk profiling section below:
| Risk dimension | What it covers |
| Crime risk | Theft, assault, vandalism, anti-social behaviour, organised crime patterns |
| Terrorism risk | National threat level, proximity to high-value targets, extremist activity |
| Protest and civil unrest | Planned demonstrations, spontaneous gatherings, political activity near sites |
| Environmental hazards | Flood zones, severe weather, air quality alerts, infrastructure outages |
| Situational risk | Proximity to nearby locations that affect your exposure, access, and egress |
| Societal stability | Community dynamics and social factors that influence local security and civil order |
| Economic and demographic risk | Demographic composition and economic conditions that shape long-term resilience |
None of these dimensions tells the full story alone. A retail store with a low crime profile may sit adjacent to a protest flashpoint. A CRE building with a clean incident log may be in a flood risk zone with rising deprivation indicators. A venue with no prior incidents may be positioned near a high-value terrorism target. Intelligence is what connects those layers into a single, usable picture of risk.
How intelligence serves different operational needs
The same underlying intelligence – a spike in organised crime activity near a cluster of sites, a protest route confirmed two days out, a change in the national terrorism threat level – lands differently depending on who is looking at it and what they need to decide.

A frontline security manager needs to know what to do in the next few hours. A portfolio director needs to understand which assets carry elevated risk and how to evidence that to a board. A loss prevention team needs to see patterns across an estate and allocate resource accordingly. The intelligence is the same. The question it answers, and the decision it supports, is different for each.
That distinction matters for how a threat intelligence programme is designed. It is not about building separate systems for separate audiences. It is about making sure the same intelligence can be interrogated at different levels of granularity, surfaced in formats that suit different decision-makers, and connected to the operational actions each audience needs to take.
Security and FM service providers
For security teams, the most immediate need is situational awareness: knowing what is happening around each site right now. A developing protest two streets away, a surge in vehicle crime in the immediate area, a confirmed terrorism-related incident nearby – all of these change how a site should be managed in the next few hours. Real-time, verified alerts give teams the basis to act rather than react.
But intelligence also drives operational planning. Forward intelligence informs decisions that real-time feeds alone cannot support:
- Resource allocation across an estate ahead of elevated-risk periods
- Briefing cycles that reflect the current threat picture rather than last month’s
- Patrol intensity and access control posture calibrated to what is actually developing nearby
A security provider that can present a client with a data-informed case for additional resource, because the intelligence picture shows elevated risk, is delivering something qualitatively different from general awareness alone.
The verification standard matters enormously. Intelligence that arrives unverified erodes trust quickly. Teams that have been burned by false alerts learn to disregard them, and miss the ones that matter. Analyst-verified intelligence, consistently delivered with clear location relevance, is what builds the confidence that enables fast, decisive response.
For providers managing enhanced-duty premises under the Terrorism (Protection of Premises) Act 2025, intelligence also supports a growing compliance dimension. Clients in scope will need help building risk assessments, implementing documented procedures, and demonstrating ongoing review. We cover the specifics of Martyn’s Law obligations in the location risk profiling section below.
For more information on Martyn’s Law, read our latest article: Understanding Martyn’s Law: What It Means for UK Businesses
Commercial real estate portfolios
CRE portfolio managers are often working with the same intelligence picture as their security teams, but asking different questions of it. Not “what do we do right now?” but “which assets in this portfolio carry the most risk, how has that changed, and how do we evidence our response?”
Resource allocation applies here too, but at a different scale. Deciding which buildings need investment in physical security measures, which warrant a formal risk review ahead of lease renewal, or where to concentrate facilities management resource during a period of heightened civil unrest – these are estate-level decisions that require an aggregated intelligence view, not just a site-level one.
The compliance dimension is also sharper for CRE. Mixed-use assets with public-facing retail, food and beverage, or event spaces sit at the intersection of multiple regulatory obligations. Intelligence infrastructure supports that compliance in three ways:
- It produces the evidential base for risk assessments required under the Building Safety Act 2022 and, for in-scope premises, the Terrorism (Protection of Premises) Act 2025
- It generates the audit trail needed to demonstrate ongoing review rather than a one-time assessment
- It creates a documented link between risk identification and operational response – exactly what regulators and insurers expect to see
Retail and loss prevention

Retail security shares the estate allocation challenge with CRE, but the pace and granularity are different. A loss prevention team managing dozens of stores needs intelligence that works at both levels simultaneously: granular enough to be relevant to a specific store location, aggregated enough to surface patterns no individual view would reveal.
Crime intelligence is the primary driver, but the full intelligence picture for retail is broader than crime alone:
- Organised retail crime: gang activity, cross-store patterns, seasonal escalations, and local hotspots
- Protest activity near flagship stores or high-footfall locations
- Civil unrest in areas with high store concentration
- Weather events and environmental disruptions that affect operations
- Social media threats that have the potential to migrate into physical incidents
The resource allocation question in retail is particularly acute. Intelligence that shows store A has a rapidly rising crime profile while store B has been stable for two years should directly inform staffing and investment decisions. That is true whether the team managing those stores is a security provider, an in-house loss prevention function, or a central estates team. The intelligence is the same. The organisational context changes how it is acted on.
Retail operators in shopping centres and high-footfall formats also have a direct Martyn’s Law dimension; shopping centres appear explicitly in Schedule 1 of the Act. which we address in the sections below.
Building location risk profiles
A location risk profile (LRP) is a structured assessment of the threats and vulnerabilities associated with a specific site. It layers multiple data sources including crime, terrorism, environmental, societal context, economic indicators, and internal incident data, into a single, dynamic picture that can be compared across a portfolio and updated as conditions change.
The critical point is that an LRP is built by you, to reflect your situation. It is not a generic risk score applied uniformly from outside. You define which risk dimensions matter most for each site, what thresholds trigger a review, and how your own operational data feeds into the picture. The profile is shaped by the specific threats your organisation needs to monitor, and that specificity is what makes it actionable rather than informational. For example:
- A retail estate in a high-footfall urban centre will weight crime and protest risk more heavily than a CRE portfolio anchored in business parks
- A security provider managing critical infrastructure sites will configure terrorism proximity and environmental risk differently from one managing hotel contracts
- A mixed-use commercial estate with public-facing tenants will need to map situational risk and assess Martyn’s Law scope in ways that a single-occupier office building does not
The LRP is the operational expression of what good physical security intelligence looks like in practice. Rather than a static risk assessment produced once and filed, an effective LRP is a living tool: fed by live data, updated automatically as new intelligence emerges, and capable of evidencing not just current risk but how that risk has evolved over time.
The eight dimensions of a location risk profile
| Dimension | Data sources | Decision it supports |
| Crime risk | Police crime data, local authority records, internal incident history | Baseline security resource, target hardening, patrol prioritisation |
| Terrorism risk | National threat level, NPSA guidance, proximity analysis, venue tier designation | Protective measures planning, evacuation design, compliance obligations |
| Protest and civil unrest | Planned event notifications, protest routes, civil disorder intelligence | Operational planning, staffing uplift, route and access management |
| Environmental hazards | Flood risk mapping, severe weather alerts, utility disruption feeds | Business continuity planning, emergency response triggers |
| Situational risk | Proximity to high-footfall venues, transport hubs, critical infrastructure, event spaces, and other locations that affect access, exposure, and egress | Understanding how nearby locations increase or complicate your own risk – and how that changes your operational planning and protective measures |
| Societal stability | Community cohesion data, social tension monitoring, civil disorder indicators, local policing intelligence | Assessing the underlying community dynamics and social factors that influence local security conditions and civil order over time |
| Economic and demographic risk | Economic dimensions analysis: employment levels, deprivation indices, economic instability indicators. Demographic analysis: population composition, transience, age profile, and community behaviour patterns | Shaping long-term stability assessment, understanding how demographic and economic factors influence community resilience and the trajectory of security risk over time |
| Internal incident data | Your own incident records, patrol logs, case files, task completion data | Organisation-specific risk context not available from any external source |
Dynamic profiling versus one-time assessment
The most important distinction in location risk profiling is between a document produced once and a dynamic profile that updates as conditions change.
A one-time assessment captures a moment. It tells you what the risk picture looked like on the day it was written. By the time a significant event occurs – a surge in local crime, a protest movement gaining momentum near one of your sites, a change in the national terrorism threat level – that document may be months out of date.
A dynamic LRP tracks change. It surfaces trends that no single data point reveals. A profile showing a steady increase in anti-social behaviour incidents over six months, accompanied by a rising deprivation score for the surrounding area, is telling a story that a static assessment cannot tell. That story is what enables genuinely proactive decisions rather than reactive ones.
Dynamic profiling also matters for audit and governance. When an incident occurs, or when a regulator asks how a risk was identified and what was done about it, a timestamped, continuously updated LRP provides a clear, defensible record. A filed document from 18 months ago does not.
Portfolio benchmarking
Individual LRPs become significantly more valuable when compared across a portfolio. A CRE portfolio manager who can rank all 30 buildings by composite risk score, identify the five with the fastest-rising profiles, and drill into the specific dimensions driving each has the basis for a board-level conversation grounded in evidence rather than instinct.
The same logic applies to retail. Benchmarking crime risk scores across 60 stores, layered against internal incident data and local intelligence, produces a resource allocation framework that is both defensible and auditable. It also creates the kind of documented methodology that insurers increasingly want to see when assessing risk and setting coverage terms.
Location risk profiles and Martyn’s Law
The Terrorism (Protection of Premises) Act 2025, known as Martyn’s Law, received Royal Assent on 3 April 2025 with a minimum 24-month implementation period. When it comes into force, it will create legal duties for those responsible for publicly accessible premises where 200 or more people might reasonably be present.
Obligations are structured across two tiers:
| Standard duty: 200–799 people | Notify the Security Industry Authority (SIA) of duty-holder statusImplement public protection procedures: evacuation, lockdown, invacuation, and communication protocolsProcedures must be proportionate and aimed at reducing harm in the event of a terrorist attackNo requirement to introduce physical security infrastructure at this tier |
| Enhanced duty: 800+ people | All standard duty obligations, plus:Conduct detailed risk assessments of the premises and the surrounding environmentImplement physical protective measures: CCTV, access control, perimeter security where appropriateAppoint a designated senior individual accountable for complianceProduce and maintain documented security plans and evidence of their implementationReview and adapt assessments as the premises changes in use, capacity, or threat profile |
Schedule 1 of the Act lists premises types likely to be familiar to security and CRE professionals. Those explicitly in scope include:
- Shopping centres and large retail destinations
- Hotels, entertainment venues, theatres, cinemas, and sports grounds
- Restaurants and bars above the threshold
Offices are not listed. However, the threshold applies to any time at which 200 or more people might reasonably be present, including during peak hours or hosted events. Large commercial estates with public-facing uses at ground level, atrium events, or mixed-use occupancy should take legal advice on whether they qualify.
Scope note
The 200-person threshold applies not to building capacity, but to the number of people it is reasonable to expect to be present “from time to time”. Retail estates, mixed-use CRE assets, and commercial buildings that host public events may be in scope even if their primary use is not publicly accessible.Non-compliance can result in SIA compliance notices, monetary penalties, restriction notices on the use of venues, and criminal offences for persistent failures.
For in-scope premises, an LRP is not just useful; it is the foundation of a credible compliance process. The enhanced duty specifically requires ongoing risk assessment and the ability to demonstrate that assessments are reviewed and adapted as circumstances change. A dynamic, auditable LRP built from verified intelligence is what satisfies that obligation in practice. A document produced once does not.
For security and FM providers, this creates a clear service opportunity. Clients who need to demonstrate Martyn’s Law compliance will look to their security partners for support with risk assessment methodology, documentation, and ongoing review. Providers who can deliver intelligence-informed LRPs as part of their offer are better positioned to win and retain those contracts.
From intelligence to action: the operational chain
Intelligence without a clear pathway to action is just information. The value of a physical security intelligence programme depends entirely on its ability to change what people do, faster and more confidently than they would without it.
In practice, that connection works at three levels.
Real-time situational awareness
At the operational level, intelligence means knowing what is happening around your sites right now. That might be a developing protest two streets away, a confirmed terrorism-related incident in a nearby city that elevates the threat environment for similar venues, or a surge in vehicle crime in the immediate area. Real-time, verified alerts allow teams to respond in minutes, not hours.
The keyword is verified. Real-time data that has not been assessed for accuracy or relevance creates noise rather than clarity. The operational benefit of a live intelligence feed depends on the quality of what is being fed, which is why analyst verification is the standard worth investing in, not an optional premium.
Automated notification and escalation
When a relevant threat is detected, the response must move through the right channels without delay. Automated notification systems that route alerts by threat type, location proximity, and severity level ensure that the right people receive the right information at the right time, without manual triage creating lag or information loss.
For organisations with Martyn’s Law obligations, the notification configuration has direct compliance relevance. Enhanced-duty premises must have documented escalation paths for terrorist threats. Building those paths into an automated system, so that a high-severity alert triggers a defined sequence of communications to defined individuals, is both an operational capability and an evidenceable compliance action.
Strategic planning and resource allocation
At the strategic level, intelligence informs how resources are allocated across a portfolio over time. The questions it helps answer include:
- Which sites need additional security resource ahead of a planned protest or period of elevated civil risk?
- Which buildings require a formal risk review before lease renewal, given changes in the local threat environment?
- Which stores should increase loss prevention staffing during a period of elevated organised crime activity in the region?
These decisions, made with good intelligence, are faster, cheaper, and more defensible than decisions made on assumption. The audit trail that intelligence infrastructure creates supports post-incident review, board reporting, and regulatory demonstration, and is increasingly relevant as the compliance landscape for physical security continues to develop.

What good threat intelligence infrastructure looks like
Effective physical security intelligence is not a product you buy and deploy. It is a system with components that have to work together. The platform matters less than the architecture.
- Verified external intelligence: analyst-curated feeds across crime, terrorism, protest, environment, and societal risk – not unfiltered raw data
- Location-aware filtering: geographic parameters that ensure teams receive only intelligence relevant to their specific sites, not national noise
- Internal data integration: your own incident records, patrol logs, and operational history layered with external feeds to create a uniquely accurate picture
- Dynamic location risk profiles: a consistent framework that aggregates data into comparable, continuously updated site-level risk scores
- Automated alerts with clear escalation paths: configured notification routes that get intelligence to the right people, in the right format, based on threat type and severity
- Audit trail and reporting: a complete, timestamped record of intelligence received, decisions taken, and responses initiated
- Compliance documentation capability: the ability to produce evidence of risk assessment methodology, procedural documentation, and ongoing review for regulatory purposes
The platforms that deliver this most effectively do so within the same environment where teams manage incidents, tasks, and daily operations. Intelligence that sits in a separate tool requires manual transfer of information into operational systems – and that handover is where context gets lost, and response slows. Integration matters.
Common gaps in physical security intelligence programmes
Reactive incident data without forward intelligence
Internal incident logs are valuable. They record what has happened at your sites and are essential for identifying trends. But they do not tell you what is developing in the environment around those sites. Without external intelligence providing forward context, organisations are always responding to the past rather than preparing for what is likely next.
Unverified data sources
Social media monitoring and unverified news aggregation generate volume without reliability. A verified alert that a specific threat is approaching a specific site is operationally useful. A stream of unverified posts about general unrest in a city is not. The verification standard is worth specifying clearly when procuring intelligence services – not all providers apply the same one.
Siloed internal and external data
A series of minor incidents at a retail store, combined with external intelligence showing rising organised crime activity in the local area, together indicate a risk that neither source reveals in isolation. Integration, connecting your own operational data with verified external feeds, is what creates that picture. Most organisations have not yet built it, and most intelligence providers do not offer it.
One-time risk assessments
A location risk assessment produced once and filed is a document. It is not a risk management programme. Risk environments change: crime profiles shift, threat levels are revised, local demographics evolve. Treating LRPs as living, dynamic tools, rather than compliance artefacts produced for a single purpose, is the difference between a programme that genuinely reduces risk and one that generates false assurance.
No clear pathway from intelligence to action
Intelligence that arrives but is not acted on is a liability. If alerts go to the wrong people, arrive in the wrong format, or lack the context to trigger a decision, the system fails regardless of the quality of the underlying data. Building clear escalation paths, notification protocols, and decision frameworks is as important as the intelligence itself.
Key takeaways
Threat intelligence transforms physical security from reactive to proactive. It gives security teams, CRE portfolio managers, and retail operators the verified, contextualised information they need to act before incidents escalate. Location risk profiles are the foundation. They layer crime, terrorism, protest, environmental, societal, and internal data into a comparable, dynamic site-level picture that supports both operational decisions and regulatory evidencing.The Terrorism (Protection of Premises) Act 2025 raises the stakes for in-scope premises. Enhanced-duty holders must demonstrate ongoing risk assessment, documented procedures, and evidence of review, requirements that a dynamic LRP built from verified intelligence directly supports.Integration matters. The most valuable intelligence combines your own incident data with verified external feeds, and connects to the same systems where your teams manage daily operations.
- Threat intelligence is forward-looking – it anticipates risk rather than recording what has already happened
- Verified, location-filtered intelligence is the standard; unverified feeds generate noise that teams quickly learn to ignore
- Location risk profiles are most valuable when dynamic: continuously updated, comparable across a portfolio, and capable of evidencing change over time
- Martyn’s Law creates ongoing risk assessment and documentation obligations for in-scope premises – requirements that static assessments cannot satisfy
- Security and FM providers have a commercial opportunity in helping clients build intelligence-informed risk profiles as part of Martyn’s Law compliance support
- CRE operators should review mixed-use and high-footfall assets against the 200-person threshold; the scope may be wider than initially assumed
- Retail operators in shopping centres and high-footfall formats are very likely in scope and should begin capability-building now
- The audit trail that good intelligence infrastructure creates has value beyond operations: it supports board reporting, insurer conversations, and regulatory demonstration
To learn more about Zinc’s Threat Intelligence module, click here or contact our team today.





















+44 (0)20 3989 4859