The UK terrorism threat level is currently SEVERE, meaning a terrorist attack is considered highly likely.
The Joint Terrorism Analysis Centre raised the national threat level from SUBSTANTIAL to SEVERE on 30 April 2026. The current status and the definitions of all five levels are published by MI5.
But what does a SEVERE UK threat level actually mean for a business, workplace, venue or commercial premises? It does not mean every organisation is facing an immediate or specific threat. The national threat level is a broad assessment of the likelihood of terrorism across the UK.
For businesses, the practical response is to understand the context, review vulnerabilities and make sure security and emergency procedures remain appropriate for the people, property and activities at the premises.
The UK uses five terrorism threat levels:
| Threat level | Meaning |
|---|---|
| LOW | An attack is highly unlikely |
| MODERATE | An attack is possible, but not likely |
| SUBSTANTIAL | An attack is likely |
| SEVERE | An attack is highly likely |
| CRITICAL | An attack is highly likely in the near future |
The level is set independently by the Joint Terrorism Analysis Centre, which is based within MI5. It is kept under regular review using available intelligence, terrorist capability and intentions, and the assessed timescale of potential activity.
A SEVERE national threat level does not predict that a particular organisation, building, sector or location will be targeted. It also does not automatically mean every business needs to introduce every possible security measure. Protective security should remain proportionate to the organisation's particular risks, vulnerabilities and operating environment.
Not necessarily. The national threat level does not prescribe one universal set of actions for every UK business.
A small office, warehouse, construction site, shopping centre, healthcare facility and event venue all have different access arrangements, levels of public contact, operating hours and potential consequences. The right response should therefore be risk-based rather than reactive.
Following the increase in the national threat level, ProtectUK advised organisations to review their protective security plans and consider whether existing arrangements remain appropriate.
The practical question is not simply, “What is the UK threat level?” It is, “If something happened at or near our premises, are our people, systems and procedures prepared?”
A review does not always require major investment or dramatic changes to normal operations. It begins with checking whether the basics are clear, current and workable.
Start with the current risk assessment and ask whether it still reflects how the premises is used today.
Have staffing, occupancy or opening hours changed?
Are there new public areas, contractors or visitor arrangements?
Have deliveries or vehicle movements increased?
Are there new events, busy periods or temporary activities?
Have entrances, restricted areas or surrounding conditions changed?
Do emergency arrangements still match the building and its occupants?
A security assessment should establish what needs protecting, what could threaten it, where vulnerabilities exist and what the potential consequences could be. That evidence can then guide proportionate controls.
For a broader framework, read How Do I Reduce Business Risk? A Practical Guide for UK Organisations.
Businesses should understand who can enter their premises, which areas they may access and how exceptions are handled. Depending on the site, the review could include:
visitor registration and identification;
staff passes and lost-pass procedures;
contractor authorisation;
delivery and collection arrangements;
doors, gates and reception controls;
restricted or sensitive areas;
out-of-hours access;
procedures for withdrawing access quickly.
Effective access control should support normal operations while reducing unauthorised entry and giving staff clear instructions when something does not match the expected plan.
Employees do not need to become counter-terrorism specialists, but they should understand the security procedures relevant to their workplace.
Useful awareness can include:
what the current national threat level means;
how to report suspicious behaviour or activity;
who should be informed internally;
how warnings and emergency instructions will be communicated;
the individual's role during an incident;
when to call 999.
Frontline employees, reception staff, security officers, warehouse teams and supervisors may be especially important because they often notice unusual behaviour, access attempts or changes before senior management does.
During an emergency, employees should not be trying to understand the procedure for the first time.
Check whether the plan explains:
how an incident is reported and escalated;
who makes key decisions;
how staff, contractors and visitors receive instructions;
when evacuation, invacuation or lockdown may be appropriate;
how people requiring additional assistance will be supported;
how emergency services are contacted and briefed;
where essential information can be accessed;
how business continuity will be managed after the immediate incident.
The response must match the premises. Moving everybody outside may not always be the safest action. Organisations should plan for different circumstances and make sure the people responsible for decisions understand the available options.
Technology should support the security plan rather than operate separately from it.
Businesses may want to confirm that CCTV, access control, intruder alarms, monitoring systems, intercoms, barriers and security lighting are functioning correctly and still cover the areas they were designed to protect.
Ask what happens after a system detects something. Who receives the alarm? Who assesses it? Who has authority to respond? Is the escalation list current outside office hours?
The objective is a connected process:
Detect → Assess → Communicate → Respond
Detection without a practical response procedure has limited value.
One of the most useful questions is also one of the simplest: Who owns security preparedness?
Responsibility can become unclear when operations, security, health and safety, HR, facilities teams and senior management each control part of the process. Establish who is responsible for:
maintaining the security risk assessment;
monitoring relevant threat information;
briefing employees;
managing physical security and contractors;
maintaining emergency procedures;
communicating during an incident;
testing plans and recording lessons.
Clear ownership makes protective measures more likely to work when they are needed.
A procedure that has never been tested is difficult to rely on. Testing does not always require a major live exercise. A short tabletop session can ask managers and key employees what they would actually do if a realistic incident happened today. This can quickly reveal gaps involving communication, access, evacuation, decision-making, emergency contacts and responsibilities. Record the findings, allocate actions and confirm when improvements have been completed.
All organisations should maintain proportionate security awareness, but the level and type of preparation will vary. Premises with significant numbers of employees, visitors or members of the public may have additional considerations. This can include retail and hospitality premises, shopping centres, logistics and distribution facilities, healthcare and education settings, public buildings, transport environments, major workplaces and event venues.
The aim is not to assume that a particular sector or site will be targeted. It is to consider the consequences, vulnerabilities and appropriate preparedness measures for each individual premises.
The UK threat level provides a broad national assessment of how likely a terrorist attack is considered to be. A site-specific security risk assessment examines an individual organisation, including its people, property, operations, vulnerabilities and potential consequences.
The national level can inform security planning, but it cannot replace an assessment of the site itself. Two organisations operating under the same SEVERE threat level may reasonably require very different controls.
Organisations that want a structured starting point can use Circle RiskCheck, the guided self-report risk assessment platform, to examine physical security, health and safety, compliance, governance and environmental management.
It means organisations should be aware and prepared, rather than making decisions based only on the word SEVERE.
Protective security works best when it is part of normal business risk management. Businesses should understand their environment, establish clear responsibilities, train people appropriately, maintain security systems and keep procedures practical as operations change.
The national threat level can change. Good security arrangements should not depend entirely on that change.
Have we reviewed our current security risks and vulnerabilities?
Has anything changed at the premises since the last assessment?
Do employees know how to report suspicious activity?
Do managers understand their responsibilities during an incident?
Are access control, CCTV and alarm systems functioning correctly?
Are visitor, contractor and delivery procedures clear?
Response
Do we have an up-to-date incident response plan?
Can we communicate quickly with employees and visitors?
Have we tested the procedures?
Who monitors relevant changes in threat information?
When will the security assessment next be reviewed?
If several of these questions are difficult to answer, the organisation may benefit from a wider security and preparedness review.
A changing threat environment is a sensible reason to check whether security arrangements still match your organisation, premises and people. Circle UK Group supports businesses with security risk assessments, protective security, security personnel, CCTV and monitoring, emergency planning and wider risk management.
Alternatively, call 020 3988 2444 to discuss your security and preparedness requirements.
This article is provided for general information and awareness only. It does not constitute legal, counter-terrorism or specialist security advice. Organisations should assess their own risks and refer to current official guidance or seek appropriate professional advice where required.