
The European Commission’s new Guidelines on the resilience of critical entities, adopted on 10 July, provide an important opportunity for the private security sector. While non-binding, the Guidelines supplement Article 13 of the Critical Entities Resilience (CER) Directive and provide further detail on the measures critical entities can take to strengthen their resilience.
For private security companies (PSCs), one message stands out: resilience is an interconnected system, and security officers have an important operational role within it.
The Guidelines cover prevention, physical protection, response and mitigation, recovery, employee security management and awareness-raising. Across these areas, they create opportunities for PSCs to move beyond traditional guarding tasks towards becoming integrated resilience partners for critical entities.
This is particularly evident in crisis preparedness. The Guidelines emphasise clear responsibilities, tested communication channels, cooperation with relevant authorities and regular crisis exercises. PSCs operating at critical sites should therefore be appropriately integrated into preparedness plans, exercises and escalation procedures. Where relevant, this can also mean stronger cooperation between critical entities, private security and public authorities.
The Guidelines equally reinforce the importance of qualified and appropriately trained security personnel. Security officers protecting critical entities need to understand the essential services they are helping to protect, site-specific risks, escalation procedures and their expected role during an incident. This provides a strong basis for promoting the EN 17483 standard system as a practical framework supporting high-quality security services for critical infrastructure.
Opportunities also extend to recovery and resilience culture. PSCs can contribute through continuity of security services, surge capacity, access control and participation in lessons-learned exercises. Security officers, often among the first to observe unusual behaviour or respond to an incident, should be part of resilience exercises rather than simply informed afterwards.
The Guidelines create no direct new obligations for private security. They do, however, confirm something fundamental: effective resilience depends on trained people, tested procedures, trusted cooperation and clearly defined operational roles.
CoESS will present and discuss the Guidelines, their implications for the sector and the opportunities for national associations and private security companies during the CoESS General Assembly events in Malta on 15–16 October.