Skip to content

PSeMS Case Study - Energy Terminal

  • Knowledge Level: Intermediate
  • Protection Stage: Operate & Detect
  • Time to read:

Protective Security Management Systems Case Study from the Energy sector

Last Updated: 27 August 2026
Share this article:

Applicable PSeMS components

  • This organisation has a broad range of challenges across all areas e.g. Plan, Do, Check, and Act (PDCA)
  • SeMS Components are broken down on the following pages for PDCA under ‘What was done’ and ‘Benefits’

Challenges

  • This facility identified the requirement for an effective and efficient PSeMS implementation. The principal challenge was how to create this and deliver a security provision that was deemed ‘mature’ with effective integration of all security and operational stakeholders, clear monthly reporting, Board level accountability, and processes for continual improvement and its monitoring and review. An ‘early adopter’ version of PSeMS was already established at this site.
  • Industrial and operational growth at this site also resulted in a need for the organisation to increase and integrate the security manpower. The organisation had two providers; one subsidiary provider managing site security only (perimeter security) and the other delivering a wider range of both site, maritime, and facilities security. It was decided to establish a single provider with all responsibilities passed to one security provider. The challenge was how to ensure integration was effective with no increase in security breaches.
    • The security team previously providing perimeter security only was identified as operating to a less effective standard than the main security team.
    • The principal challenge was to address how best to merge the two entities that are both operating under PSeMS guidance on the same facility. The!challenge to address was whether the more mature PSeMS entity would lead to the less mature entity increasing its standards or whether the less mature entity would adversely impact the more mature entity.

Applicable PSeMS components

  • Senior management endorse security policy
  • Clearly defined performance measures and objectives

What was done

  • At the start of each financial year the organisation prepared its corporate vision. The security function aligned itself with this by providing best value and evaluating how security could be better managed.!For example, if new security policies were introduced they would create an additional cost to the business and if so the security team would demonstrate a corresponding reduction in security risk. 
  • Safety and security related policies, procedures, and requirements were included in procurement documentation supplied to the organisation’s third-party suppliers.
  • Extensive metrics were put in place covering people, performance, and continuous improvement. Some notable elements from the organisation’s performance measures were a 100-day plan/security roadmap and a Success Register so that positive security news could be shared. Other tools used to engage with stakeholders for problem resolution were SIPOC (Supplier, Input, Process, Output and Customer).
  • Additional security performance metrics were implemented to cover the serviceability of the organisation’s physical security equipment. They used a red, amber, green approach to enable them to see the status of the security equipment on site, particularly the CCTV and provide an early indication that remedial measures to mitigate risk may be needed.

Benefits

  • The Head of Security is required to present to the organisation’s insurers every two years. Premiums have been reduced due to confidence in the security management system and oversight in place.

Applicable PSeMS components

  • Regular workforce engagement
  • Clear roles and responsibilities, training
  • Regular security risk and threat assessment

What was done

  • The organisation nurtured a strong security culture by placing confidence and trust in the security teams and focusing on developing effective relationships across the business.
  • The organisation ensured that security was seen as an enabler and not a barrier to business activities by providing valid examples and successes – such as the reduction in insurance premium.
  • All security activities, including those of the contract security team, were integrated into the organisation’s normal business activities to avoid ‘silo’ approaches.

Benefits

  • The organisation’s people-focused approach has helped create a positive security culture within their business, particularly with regard to security reporting.
  • Risk management processes are more robust with appropriate accountability in place.

Applicable PSeMS components

  • Established audit and assurance process for PSeMS
  • Corrective and preventive actions for security failures

What was done

  • A self-audit program was implemented and the organisation adhered to the International Ship and Port Facility code, a guiding document covering policy relating to tactical aspects of maritime security and response.
  • A zero tolerance approach was taken with contractors’ compliance breaches.
  • Contract security personnel were empowered to deal with incidents without needing authorisation from the organisation’s Security Management team who did not want to constrain their contractors to Assignment Instructions as there was a need for a flexible approach.

Benefits

  • The organisation’s positive organisational security culture, effective communications, robust response measures and embedded metrics helps them to routinely manage incidents and is a good example of ‘learn, review, and improve’. This helps support continuous improvement of the organisation’s PSeMS.
  • An example of the organisation’s security performance and oversight measures being used to good effect followed an incident involving an individual who gained unauthorised access to the site. The intruder was rapidly spotted by two non-security employees who immediately notified the security control room. Armed police officers and the contract security team were deployed to the scene and the intruder was subsequently arrested. Details of the event were recorded on the organisation’s Threat Calendar Log which forms part of their performance and excellence metrics, and a ‘3C’ form generated to show the Concern, Cause, and Countermeasures. An!immediate review of the incident revealed the cause of the event to be a failure in the CCTV patrol strategy. The frequency of patrols on vulnerable points was not sufficient and was increased, along with the full site patrols. The organisation provided a resolution to the event within 2 hours of it occurring. Security policies were updated with the lessons learned. The security metrics in place ensured a timely review and implementation of effective countermeasures.
Did you find this page useful?
helpfulness rating