Back to all articles
Martyn's Law (Protect Duty): How IT Underpins Your Compliance
Compliance
18 July 20265 min read

Martyn's Law (Protect Duty): How IT Underpins Your Compliance

RL

Rob Lloyd

Author

Martyn's Law: How IT Underpins Protect Duty Compliance

The Terrorism (Protection of Premises) Act 2025 became law on 3 April 2025. Commonly known as Martyn's Law—in honour of Martyn Hett, who was killed in the 2017 Manchester Arena attack—the legislation requires those responsible for certain premises to consider how they would respond to a terrorist attack.

While it is often viewed purely as a "physical security" issue, the reality is that modern physical security is entirely dependent on IT infrastructure.

The Tiered Approach & The "Special Consideration"

The legislation uses a tiered approach based on capacity. There is an implementation period of at least 24 months before the act comes into force, but proactive organizations are preparing now.

  • Standard Tier (Capacity 200-799): Focuses on low-cost, effective activities like training, information sharing, and having an emergency response plan.
  • Enhanced Tier (Capacity 800+): Requires a formal risk assessment, a designated senior individual, and the implementation of a comprehensive security plan.

How it affects Education

Early years, primary, secondary, and further education settings have a special consideration in place. This means they will remain in the Standard Tier, even if they expect 800 or more individuals to be present. DfE-funded independent training providers also fall under this special consideration.

Note: Higher Education establishments and privately owned independent training providers do NOT fall under this special consideration and will enter the Enhanced Tier if their capacity is 800+.

How it affects Business

Corporate offices, retail spaces, and entertainment venues must ensure they can adequately protect staff and the public. Unlike schools, businesses with a capacity of 800+ immediately fall into the Enhanced Tier, bringing significant regulatory and enforcement oversight from the Security Industry Authority (SIA).

What You Need To Do: The 4 Pillars

All settings within scope must have public protection procedures in place. These directly rely on your IT infrastructure:

  1. Evacuation (getting people out)
  2. Invacuation (moving people to a safe place)
  3. Lockdown (securing premises against attackers)
  4. Communication (alerting people to the danger)

The Role of IT in Protect Duty

Your premises team might buy the CCTV cameras and electronic door locks, but the IT department provides the nervous system that keeps them alive. To meet the 4 Pillars above, IT must ensure:

  • Mass Notification Systems: In an emergency, how do you instantly communicate a lockdown? IT manages the VoIP systems, digital signage, and SMS/Email broadcast tools. These must be highly available and resilient.
  • CCTV & Access Control Resilience: If the school or office network goes down, do the electronic doors fail open or closed? IT must provide resilient, segmented networks (VLANs) dedicated solely to physical security.
  • Active Testing: IT must be involved in lockdown drills to test the "failover" states of these communication and security systems.

Compliance with Martyn's Law requires a unified front between Facilities and IT. If your digital infrastructure isn't resilient, your physical security strategy will fail when you need it most.

Ready to simplify your school's IT compliance?

asitplan provides the unified dashboard and automated reporting you need to stay ahead of DfE standards and KCSIE updates.