Safety, Security & Resilience

Corporate Security

Your estate, your sites, your people — and your duty, wherever you operate, to keep the people who use your premises safe. Protective security that is proportionate, defensible and genuinely operational.

The offer

Led by our Experts

We have sourced the world’s best policing and emergency services SMEs. Corporate Security is led by Gary Ritchie KPM, Helen Clayton and Michael Phelan APM.

  • GCG Consortium Australia

    Gary Ritchie KPM

    GCG Managing Partner

    Managing Partner, and former Assistant Chief Constable of Police Scotland, retiring in 2025 after 34 years' policing service, with executive oversight of organisational change, partnerships and prevention, international policing development and operational support. He chaired the Scottish Resilience Partnership — advising the First Minister of Scotland on emergency and event preparedness — and held Gold Command during COP26 in Glasgow. He was awarded the King's Police Medal in 2025 and made an Honorary Professor of Edinburgh Napier University. He is now based in Sydney.

    Skills & focus

    • Strategic command
    • Resilience & emergency preparedness
    • Public health & harm reduction
    • Leadership development
    • Partnerships & prevention

    Years of service 34

    Full profile

  • GCG Consortium United Kingdom

    Helen Clayton

    Consortium member

    Founder and Director of Solstice Risk Advisory and former Head of Crime & Security at Sainsbury's, with more than 20 years' experience in retail crime and security. Security Woman of the Year 2021, a founding member of Operation Pegasus and a member of the Retail Crime Forum, she attended Downing Street in 2024 to help shape the Government's plans on retail crime. She is a serving magistrate in Nottinghamshire and a Board Director of Safer Business Network in London.

    Skills & focus

    • Retail crime & security
    • Corporate security risk
    • Threat monitoring & preparedness
    • Government & industry engagement
    • Executive protection

    Years of service 20+

    Full profile LinkedIn

  • GCG Consortium Australia

    Michael Phelan APM

    GCG Director of Global Intelligence Services

    Michael Phelan APM is the former Chief Executive Officer of the Australian Criminal Intelligence Commission and a former Deputy Commissioner of the Australian Federal Police, after more than 40 years in law enforcement. An Adjunct Professor at the University of Canberra, he holds an MBA and specialises in national security and organised crime.

    Skills & focus

    • Intelligence
    • National security
    • Organised crime
    • Agency leadership & governance
    • Financial crime & anti-corruption

    Years of service 40+

    Full profile

Delivered by our Experts 19 supporting members

Capability 01

Protective Security & Place Assurance

For corporate estates and premises, this is the security a regulator, an insurer or an inquiry would ask you to evidence. We work from strategic design down to the detail of a single site survey, and tell you which of your sites is furthest behind.

Protective Security Preparedness Pathways A staged route to stronger protective security maturity.

What it is

A structured route to stronger protective security maturity, including police-informed security design and practical support applying protective-security good practice and your legal and regulatory responsibilities, whatever country you operate in.

Why it matters

Protective security rarely improves by accident. In the UK, Martyn's Law makes keeping the people who use your premises safe a legal duty for qualifying sites. A staged pathway turns that duty into evidenced progress rather than a one-off exercise.

What you get

A clear, staged pathway, starting from an honest assessment of where you are today, through to specific, proportionate actions that build maturity over time, with police-informed design input and a direct route into the CT STEP platform for ongoing self-assessment and evidencing.

Security Design Integration Review Security as a design discipline, not a late add-on.

What it is

A review of how safety, security and resilience are currently embedded into your infrastructure, systems and operating models, assessing whether protective security is designed in from the start or added late, once decisions are already hard to reverse.

Why it matters

Security retrofitted after design and construction decisions are locked in costs more and does less than security designed in from the outset. The organisations that get this right treat security as a design discipline from day one.

What you get

An independent review of your current design and governance processes, identifying where security thinking is genuinely integrated and where it is fragmented or late-stage, with practical recommendations for embedding it earlier and more consistently across future projects.

Site Assessment & Technical Surveying Vulnerabilities a floor plan will never show you.

What it is

Assessment of physical vulnerabilities, perimeter issues, movement routes and operational pinch points at your sites, using drone-based assessment and other specialist technical methods where useful.

Why it matters

Vulnerabilities in a physical space, including sightlines, access points, crowd movement patterns and perimeter gaps, are often invisible from a desk review or a floor plan. They only become apparent through a proper site-level assessment by people who know what to look for.

What you get

A detailed, evidenced site assessment combining physical inspection with specialist technical methods, resulting in a clear picture of your site's vulnerabilities and practical, prioritised recommendations to address them.

↑ Back to all capabilities

Capability 02

CT STEP Services

For organisations that want to start with self-assessment before commissioning advisory work, CT STEP is a direct, practical entry point: the platform itself, mass-audience staff training, and specialist consultancy when you need deeper support.

CT STEP Platform A structured digital platform to evidence compliance, premises by premises.

What it is

Our structured digital platform gives Responsible Persons and Designated Senior Individuals a clear, repeatable way to evidence compliance — a four-step guided process (Understand, Evaluate, Plan, Activate) taking you from initial threat understanding through to activating procedures across every premises. Licensing includes a central governance dashboard and annual updates that keep pace with government guidance as it changes. Born from the UK’s response to Martyn’s Law, the platform has been adapted for organisations anywhere in the world.

Why it matters

Most organisations do not know where to start with terrorism preparedness, and commissioning a full external review before you have even understood your own exposure is slow and expensive. A guided, self-led starting point lets you understand your risk and build a first, evidenced plan in-house — most users complete one in about an hour.

What you get

A working account you can start using immediately; a date-stamped, shareable public protection plan; a central governance dashboard giving multi-site organisations a single view of readiness across every location; and annual updates that keep your evidence current as government guidance changes.

Consultancy & Implementation Working alongside Responsible Persons to turn legal duty into practical action.

What it is

We work alongside the Responsible Person and the Designated Senior Individual — the people the duty actually falls on. We scope which of your premises are in and at what tier, review your governance and procedures against the legal tests, and write the invacuation, evacuation and lockdown procedures where you do not have them. Once a year we come back, sample the evidence and report to your board.

Why it matters

Martyn’s Law places its duties on named individuals, not on organisations in the abstract. The people carrying that duty need confidence that their premises are correctly scoped, their procedures are proportionate and their governance would stand scrutiny — before a regulator, or an incident, tests it.

What you get

Practical, premises-specific support from counter-terrorism and protective security specialists: a clear picture of where you stand against the legal tests, a governance framework your board can rely on, procedures your staff can act on, and evidence-backed assurance reporting on an annual cycle.

Advisory, Speaking & Mentorship Ongoing and individual support for the people carrying legal responsibility.

What it is

The duty does not end when a project does. We brief boards and governing bodies so they can see what their premises are actually carrying. We speak on Martyn’s Law and what implementation is really like, at conferences and inside organisations. We mentor Responsible Persons and Designated Senior Individuals one to one, which is a different thing from putting them on a course. Where an organisation wants us on call rather than on a project, we hold a retained advisory arrangement.

Why it matters

A Responsible Person’s duties do not end when a project closes. The role carries personal accountability, and the confidence to discharge it well comes from continuing access to people who have carried comparable responsibility operationally.

What you get

Support shaped to the person as much as the organisation: briefings that give boards genuine oversight, speakers who bring operational reality to sector and leadership events, one-to-one mentoring for duty holders, and a retained relationship with senior practitioners for whenever questions arise.

Training & Exercising A dedicated learning pathway, from practitioner programmes to staff-wide awareness.

What it is

Training matched to what a person is actually responsible for. The Responsible Person Practitioner Programme is implementation training for Standard Tier premises; the Designated Senior Individual Practitioner Programme is governance and leadership training for Enhanced Tier premises. A technical workshop teaches your team to use the platform to evidence and maintain compliance. Exercises, from tabletop through to full operational tests, show whether the plans and the people work — and produce the evidence for your annual assurance. Terrorism Security Awareness Training is eLearning for everyone else on the payroll.

Why it matters

A public protection plan only works if the people expected to act on it know their role. Statutory duty holders need training matched to their tier of responsibility, and every member of staff needs the baseline awareness to recognise suspicious behaviour and respond appropriately.

What you get

A pathway matched to responsibility: practitioner programmes for Standard and Enhanced Tier duty holders, hands-on platform training, exercises that test the plans and generate your assurance evidence, and eLearning you can put in front of every member of staff.

↑ Back to all capabilities

Capability 03

Readiness & Resilience

Corporate resilience is built on ordinary systems: rostering, communications, suppliers, continuity. This capability tests whether your planning would hold in a live incident, under real strain, long after the annual review has been filed.

All Hazards Risk & Readiness Review Is your planning genuinely operational, or merely documentary?

What it is

A review of how your organisation understands and manages risk across safety, security, resilience and continuity. We test the threat and hazard assumptions your planning rests on, the governance above it, and who is meant to escalate what to whom. We pay particular attention to the dependencies between teams that plans usually assume away.

Why it matters

Most organisations have a plan. Fewer know whether that plan is genuinely operational and built on current, tested assumptions, or whether it has quietly become a documentary exercise, refreshed on a cycle rather than pressure-tested against how the organisation actually behaves under strain. That gap is usually invisible until the moment it matters most.

What you get

A review built on your documents, interviews with your senior team and a workshop with them in the room. You get a written assessment of where your risk and readiness planning would hold, where it would not, and the actions to close the gap in the order we would take them.

Organisational Readiness Assessment The everyday systems that decide crisis performance.

What it is

A structured qualitative assessment of the core systems that will determine your performance when pressure rises: command readiness, communications, supply chain resilience, workforce and wellbeing pressures, partner integration, business continuity, community and partner interfaces, and the strength of the everyday capabilities that crisis performance is built on.

Why it matters

Crisis performance is rarely about the crisis plan itself. It is about whether the ordinary, everyday systems underneath it, such as rostering, communications and supplier relationships, are strong enough to keep functioning when demand spikes. Weakness in those systems is often the first thing to fail, and the last thing anyone thought to test.

What you get

A practitioner-led assessment of the systems that matter most in your context. You get a written picture of where you stand and a sequenced set of actions you can start on the week we hand it over.

Adaptability & Resilience Assessment Can you sustain performance for weeks, not hours?

What it is

A focused assessment of your organisation's ability to absorb disruption, adapt to uncertainty and maintain performance during sustained operational strain, covering both structural resilience (systems, redundancy, supply chains) and behavioural resilience (how your people recognise weak signals, adjust pace, reprioritise, and hold up under fatigue).

Why it matters

A prolonged incident, an extended major event, a multi-month recovery: each tests an organisation differently to a single sharp shock. The organisations that struggle most are often those that performed well in a short exercise but had never tested whether they could sustain that performance for weeks, not hours.

What you get

A written assessment of structural and behavioural resilience, drawn from practitioner experience of sustained operations. It names the points where fatigue, rigidity or a fragile system is most likely to break first, and what to change before it does.

Training, Testing & Exercising Rehearsal turns a plan into a capability.

What it is

We design and run training, rehearsals, simulations and scenario tests for the way your organisation actually operates — a sequenced programme, not one tabletop exercise a year.

Why it matters

A plan that has never been tested is a hypothesis, not a capability. The gap between what people believe will happen and what actually happens under pressure only closes through realistic rehearsal, and organisations that exercise only once, late in the cycle, routinely discover their biggest gaps too late to fix them properly.

What you get

Training focused at the right levels of your organisation and planning systems, backed by a programme of exercises matched to your risk profile and timeline: from focused tabletop sessions through to full-scale, multi-agency simulations, each followed by a structured debrief and a clear record of lessons identified and actioned. The result is an evidence trail of improving readiness over time.

↑ Back to all capabilities

Capability 04

Programme & Infrastructure Assurance

If you run a complex estate or a capital programme with many contractors and suppliers, this capability gives you consistent oversight and challenge, so security and resilience standards hold across every package and site.

Programme Assurance & Governance An intelligent customer across every package.

What it is

An independent assurance and governance function for complex programmes involving multiple suppliers, contractors, delivery teams or partner agencies, helping you act as an intelligent, informed customer across every supplier and package.

Why it matters

On complex, multi-party programmes, the biggest risk is usually fragmentation: inconsistent assumptions, uneven standards between contractors, and gaps at the interfaces between packages that no single party is responsible for closing.

What you get

One set of assurance criteria that every contractor is held to, a written review of how each package measures up against them, and a standing route to escalate the gaps nobody owns — early, while they are still cheap to fix.

Testing, Commissioning & Operational Assurance From design intent to live operational confidence.

What it is

Support to move from planning and design into live operational confidence, including design-stage validation, commissioning readiness review, scenario testing and interface exercising with your delivery partners.

Why it matters

A system that passes design review on paper can still fail in live operation if the interfaces between design intent, construction delivery and day-to-day operations were never properly tested together before go-live.

What you get

An assurance programme running from design validation through commissioning to live operational testing, with a written sign-off at each stage. You know what has been tested, what has not, and what is still open before you rely on it.

International Benchmarking & Lessons Identified Learn from someone else's expensive lesson.

What it is

An evidence-based review of practice from comparable organisations, programmes and jurisdictions internationally, covering what has worked, what has failed, and what is genuinely transferable to your context.

Why it matters

Every major programme believes its challenges are unique, but most of the failure patterns have played out before, elsewhere. The organisations that benefit most are the ones willing to learn from someone else's expensive lesson.

What you get

A short written review of what comparable programmes did, what failed, and which of it applies to yours — with the implications for your next decisions on sequencing, design and governance set out in order.

Evidence-Based Practice & Strategic Insight Decisions based on what the evidence actually shows.

What it is

Turning research, operational experience and comparative evidence into practical action for senior decision-makers, delivered in partnership with GCG's Evidence-Based Practice domain.

Why it matters

Boards commit real money to preparedness on instinct and precedent, because nobody has put the evidence in front of them in a form they can decide from. That is a straightforward thing to fix.

What you get

A written evidence review of the decisions actually in front of you, and a practitioner in your planning and governance meetings while they are being taken — so investment and sequencing are argued from the evidence rather than from precedent.

↑ Back to all capabilities

Start the conversation

Start with an honest conversation about where you stand against your legal and regulatory responsibilities and good practice. If self-assessment is the right first step, we will point you to CT STEP instead.