6 min read

Understanding the SEVERE UK Threat Level: Implications for Businesses

Understanding the SEVERE UK Threat Level: Implications for Businesses
UK Threat Level Explained: What SEVERE Means for Businesses and Premises
10:48

The UK terrorism threat level is currently SEVERE, meaning a terrorist attack is considered highly likely.

The Joint Terrorism Analysis Centre raised the national threat level from SUBSTANTIAL to SEVERE on 30 April 2026. The current status and the definitions of all five levels are published by MI5.

But what does a SEVERE UK threat level actually mean for a business, workplace, venue or commercial premises? It does not mean every organisation is facing an immediate or specific threat. The national threat level is a broad assessment of the likelihood of terrorism across the UK.

For businesses, the practical response is to understand the context, review vulnerabilities and make sure security and emergency procedures remain appropriate for the people, property and activities at the premises.

What does the UK threat level SEVERE mean?

The UK uses five terrorism threat levels:

Threat level Meaning
LOW An attack is highly unlikely
MODERATE An attack is possible, but not likely
SUBSTANTIAL An attack is likely
SEVERE An attack is highly likely
CRITICAL An attack is highly likely in the near future

 

The level is set independently by the Joint Terrorism Analysis Centre, which is based within MI5. It is kept under regular review using available intelligence, terrorist capability and intentions, and the assessed timescale of potential activity.

A SEVERE national threat level does not predict that a particular organisation, building, sector or location will be targeted. It also does not automatically mean every business needs to introduce every possible security measure. Protective security should remain proportionate to the organisation's particular risks, vulnerabilities and operating environment.

️  Check Crime Levels in Your Area

Does a SEVERE threat level mean businesses must change their security?

Not necessarily. The national threat level does not prescribe one universal set of actions for every UK business.

A small office, warehouse, construction site, shopping centre, healthcare facility and event venue all have different access arrangements, levels of public contact, operating hours and potential consequences. The right response should therefore be risk-based rather than reactive.

Following the increase in the national threat level, ProtectUK advised organisations to review their protective security plans and consider whether existing arrangements remain appropriate.

The practical question is not simply, “What is the UK threat level?” It is, “If something happened at or near our premises, are our people, systems and procedures prepared?”

Seven areas businesses should review

A review does not always require major investment or dramatic changes to normal operations. It begins with checking whether the basics are clear, current and workable.

1. Review your security risk assessment

Start with the current risk assessment and ask whether it still reflects how the premises is used today.

  • Have staffing, occupancy or opening hours changed?

  • Are there new public areas, contractors or visitor arrangements?

  • Have deliveries or vehicle movements increased?

  • Are there new events, busy periods or temporary activities?

  • Have entrances, restricted areas or surrounding conditions changed?

  • Do emergency arrangements still match the building and its occupants?

A security assessment should establish what needs protecting, what could threaten it, where vulnerabilities exist and what the potential consequences could be. That evidence can then guide proportionate controls.

For a broader framework, read How Do I Reduce Business Risk? A Practical Guide for UK Organisations.

2. Review access control

Businesses should understand who can enter their premises, which areas they may access and how exceptions are handled. Depending on the site, the review could include:

  • visitor registration and identification;

  • staff passes and lost-pass procedures;

  • contractor authorisation;

  • delivery and collection arrangements;

  • doors, gates and reception controls;

  • restricted or sensitive areas;

  • out-of-hours access;

  • procedures for withdrawing access quickly.

Effective access control should support normal operations while reducing unauthorised entry and giving staff clear instructions when something does not match the expected plan.

3. Make sure employees understand the threat level

Employees do not need to become counter-terrorism specialists, but they should understand the security procedures relevant to their workplace.

Useful awareness can include:

  • what the current national threat level means;

  • how to report suspicious behaviour or activity;

  • who should be informed internally;

  • how warnings and emergency instructions will be communicated;

  • the individual's role during an incident;

  • when to call 999.

Frontline employees, reception staff, security officers, warehouse teams and supervisors may be especially important because they often notice unusual behaviour, access attempts or changes before senior management does.

️  Check Crime Levels in Your Area

4. Review emergency and incident response plans

During an emergency, employees should not be trying to understand the procedure for the first time.

Check whether the plan explains:

  • how an incident is reported and escalated;

  • who makes key decisions;

  • how staff, contractors and visitors receive instructions;

  • when evacuation, invacuation or lockdown may be appropriate;

  • how people requiring additional assistance will be supported;

  • how emergency services are contacted and briefed;

  • where essential information can be accessed;

  • how business continuity will be managed after the immediate incident.

The response must match the premises. Moving everybody outside may not always be the safest action. Organisations should plan for different circumstances and make sure the people responsible for decisions understand the available options.

5. Check CCTV, alarms and physical security

Technology should support the security plan rather than operate separately from it.

Businesses may want to confirm that CCTV, access control, intruder alarms, monitoring systems, intercoms, barriers and security lighting are functioning correctly and still cover the areas they were designed to protect.

Ask what happens after a system detects something. Who receives the alarm? Who assesses it? Who has authority to respond? Is the escalation list current outside office hours?

The objective is a connected process:

Detect → Assess → Communicate → Respond

Detection without a practical response procedure has limited value.

6. Review security roles and responsibilities

One of the most useful questions is also one of the simplest: Who owns security preparedness?

Responsibility can become unclear when operations, security, health and safety, HR, facilities teams and senior management each control part of the process. Establish who is responsible for:

  • maintaining the security risk assessment;

  • monitoring relevant threat information;

  • briefing employees;

  • managing physical security and contractors;

  • maintaining emergency procedures;

  • communicating during an incident;

  • testing plans and recording lessons.

Clear ownership makes protective measures more likely to work when they are needed.

7. Test the plan

A procedure that has never been tested is difficult to rely on. Testing does not always require a major live exercise. A short tabletop session can ask managers and key employees what they would actually do if a realistic incident happened today. This can quickly reveal gaps involving communication, access, evacuation, decision-making, emergency contacts and responsibilities. Record the findings, allocate actions and confirm when improvements have been completed.

Which organisations should pay particular attention?

All organisations should maintain proportionate security awareness, but the level and type of preparation will vary. Premises with significant numbers of employees, visitors or members of the public may have additional considerations. This can include retail and hospitality premises, shopping centres, logistics and distribution facilities, healthcare and education settings, public buildings, transport environments, major workplaces and event venues.

The aim is not to assume that a particular sector or site will be targeted. It is to consider the consequences, vulnerabilities and appropriate preparedness measures for each individual premises.

What is the difference between the UK threat level and a site risk assessment?

The UK threat level provides a broad national assessment of how likely a terrorist attack is considered to be. A site-specific security risk assessment examines an individual organisation, including its people, property, operations, vulnerabilities and potential consequences.

The national level can inform security planning, but it cannot replace an assessment of the site itself. Two organisations operating under the same SEVERE threat level may reasonably require very different controls.

Business manager completing a site security risk assessment using Circle UK Group's guided platform

Organisations that want a structured starting point can use Circle RiskCheck, the guided self-report risk assessment platform, to examine physical security, health and safety, compliance, governance and environmental management.

Does SEVERE mean businesses should be alarmed?

It means organisations should be aware and prepared, rather than making decisions based only on the word SEVERE.

Protective security works best when it is part of normal business risk management. Businesses should understand their environment, establish clear responsibilities, train people appropriately, maintain security systems and keep procedures practical as operations change.

The national threat level can change. Good security arrangements should not depend entirely on that change.

A simple business security checklist

Risk

  • Have we reviewed our current security risks and vulnerabilities?

  • Has anything changed at the premises since the last assessment?

People

  • Do employees know how to report suspicious activity?

  • Do managers understand their responsibilities during an incident?

Premises

  • Are access control, CCTV and alarm systems functioning correctly?

  • Are visitor, contractor and delivery procedures clear?

Response

  • Do we have an up-to-date incident response plan?

  • Can we communicate quickly with employees and visitors?

  • Have we tested the procedures?

Review

  • Who monitors relevant changes in threat information?

  • When will the security assessment next be reviewed?

If several of these questions are difficult to answer, the organisation may benefit from a wider security and preparedness review.

OVERWATCH

 

Frequently Asked Questions

Have Question? We are here to help

What is the current UK terrorism threat level?

As of September 2026, the national threat level from all forms of terrorism across England, Wales, Scotland and Northern Ireland is SEVERE, meaning an attack is considered highly likely.

When did the UK threat level become SEVERE?

The Joint Terrorism Analysis Centre raised the UK national threat level from SUBSTANTIAL to SEVERE on 30 April 2026.

Does SEVERE mean an attack is imminent?

No. CRITICAL is the level used when an attack is considered highly likely in the near future. SEVERE means an attack is considered highly likely.

What should businesses do during a SEVERE threat level?

There is no single response suitable for every organisation. Businesses should review their risk assessment, access controls, staff awareness, security systems, emergency procedures and response plans in line with their particular vulnerabilities.

 

Is your security plan ready for today's risks?

A changing threat environment is a sensible reason to check whether security arrangements still match your organisation, premises and people. Circle UK Group supports businesses with security risk assessments, protective security, security personnel, CCTV and monitoring, emergency planning and wider risk management.

Book a protective security and preparedness consultation with Circle UK Group. →

Alternatively, call 020 3988 2444 to discuss your security and preparedness requirements.

This article is provided for general information and awareness only. It does not constitute legal, counter-terrorism or specialist security advice. Organisations should assess their own risks and refer to current official guidance or seek appropriate professional advice where required.