A Global Security Operations Centre, or GSOC, often looks most impressive before anything goes wrong. Screens show maps, video feeds, vehicle positions, access-control events, intelligence reports, and incoming alerts. Operators appear to have the world in view.
None of that, by itself, demonstrates operational control.
Control becomes visible when an event is ambiguous, time is short, and several organisations share responsibility. It is demonstrated when the GSOC can establish what is known, preserve what remains uncertain, identify who has authority, direct a proportionate response, confirm that actions were completed, and explain the reasoning afterwards. A control room that receives an alert but cannot show how the alert changed a decision is monitoring activity, not managing an incident.
For private security providers, this distinction matters commercially as well as operationally. The client is not simply buying observations. It is buying a managed service. After a serious incident, the central questions are likely to be exacting: What did the provider know? When did it know it? How reliable was the information? Who made the decision? Was the action within the provider’s authority? Were subcontractors working to the same standard? What happened to the people affected? What changed as a result?
An authoritative GSOC should be designed to answer those questions from its operational record, rather than reconstructing the answers when the client asks for a report.
The standards describe a management problem
The relevant standards do not treat good security as a collection of devices. ISO 18788 describes a security operations management system that must be established, operated, monitored, reviewed, maintained, and improved. Its stated purpose includes professional delivery against client needs, accountability to law, respect for human rights, and consistency with the organisation’s commitments.1 The important word is system. Technology, personnel, procedures, governance, and review must operate as a coherent whole.
The Security Industry Authority’s 2026 Approved Contractor Scheme material makes the same point in more operational language. The standard expects effective service-delivery processes, continuity arrangements, a response to customer requirements, consistent monitoring, and improvement against customer and consumer indicators. Its guidance says assignment instructions should be clear, accurate, current, and documented. It also expects key processes to be tested outside routine site inspections, and identifies changes made after incidents and complaints as evidence of good practice.2
The SIA scheme is UK-specific, but the underlying test travels well. A provider should be able to demonstrate not only that a procedure exists, but that people understand it, that it reflects the contract, that it works under pressure, and that experience changes it.
This has a direct implication for GSOC design. Evidence should be created as work is performed. If the operator must later search telephone logs, copy fragments from messaging applications, ask a supervisor to remember why a decision was made, and reconcile separate guard reports, the evidential chain was already weak during the incident. A polished post-incident document cannot repair missing command information.
Define the contract of command before the incident
Many response failures begin as failures of authority. The GSOC can see a problem, but the operator does not know whether the provider may act, must obtain client approval, or should defer to a site manager. The client assumes the provider is responding. The local guarding team assumes the GSOC is only observing. Each participant waits for somebody else.
An escalation matrix is useful, but it is not a complete command model. The contract of command should distinguish between actions the GSOC may take immediately, actions it must recommend, actions reserved to the client, and actions that pass to emergency services or another competent authority. It should also state how authority changes outside normal hours, when named decision-makers are unavailable, or when delay would expose somebody to avoidable harm.
This requires more precision than labels such as “low”, “medium”, and “high”. Two incidents with similar apparent severity may demand different decisions. A failed access-control reader during office hours may be an inconvenience. The same failure at a high-risk facility during a hostile approach may alter the site’s protective posture. A missed welfare check may be a communications problem, a procedural breach, or the first indication of a medical or security incident. Classification helps organise work, but context determines action.
The GSOC’s mandate should therefore connect triggers to decision rights. It should identify who can establish an incident, change its priority, issue a workforce instruction, direct a mobile response, authorise a route deviation, request police or medical assistance, notify the client, and close the event. Where the client retains a decision, the record should show the advice given, the information available, the time of referral, and the decision received.
The aim is not to centralise every choice. It is to remove avoidable doubt about who owns the next one.
A common operating picture must preserve uncertainty
Security incidents rarely arrive as verified narratives. They begin as fragments: an alarm, a guard’s call, a camera image, a traveller’s message, a vehicle stopping unexpectedly, an intelligence report, or silence when a response was expected. Those fragments may conflict.
A weak operational picture smooths the conflict away. An assumption becomes a map label, the label is repeated at handover, and by the third retelling it has become “confirmed”. A strong operational picture retains the distinction between observation and interpretation.
Every important entry should answer four different questions. What was observed? What does the team currently assess that observation to mean? What decision was made on that basis? What action followed? The source, time, confidence, and owner of the information should remain visible. When a fact is corrected, the earlier entry should not simply disappear. The record should show that the understanding changed and why.
This is consistent with the discipline used by the UK’s Joint Emergency Services Interoperability Principles. JESIP asks participating control rooms to build shared situational awareness, develop a joint understanding of risk, use plain English, and clarify what information and intelligence each agency holds. Its Joint Decision Model frames the assessment through the questions “what?”, “so what?”, and “what might?”.3 Private providers are not emergency services, and should not present themselves as such. However, the information discipline is highly relevant whenever a GSOC, a guarding supplier, a client team, and public responders must work from different sources.
Consider an access alarm followed by a report of an unknown person inside a perimeter. “Intruder on site” is not an observation. It is an assessment. The operational record might instead show that a door alarm was received at 21:14, that the camera view was obscured, that the lone officer reported an unidentified individual at 21:17, and that the GSOC instructed the officer to observe from a protected position while a second response resource and the client representative were contacted. If the person later proves to be an authorised engineer, the record still shows why the initial response was reasonable.
That degree of clarity protects the responder, the provider, the client, and the person who became the subject of the response.
Handover is a transfer of responsibility
A chronological log is not automatically a useful handover. Incoming staff may receive hundreds of entries but still be unable to state the current objective, the live risks, or the next decision point.
An effective handover compresses the record without distorting it. It identifies the present operational objective, the facts that have been confirmed, the assessment currently being used, the uncertainties that could change that assessment, the actions still outstanding, the authority under which the response is operating, and the time at which the situation will next be reviewed. It should also name the person accepting responsibility.
This matters during prolonged events, but it is equally important in ordinary security operations. An unresolved access issue, a repeatedly missed check-in, a temporary site instruction, or a deteriorating local situation can become hazardous when ownership dissolves at a shift boundary.
The handover should not merely say that the next operator has been “made aware”. Awareness is passive. Responsibility must be accepted, and outstanding actions must retain owners and deadlines. If a critical action does not survive the handover, the system has lost control even though the incident remains open on a screen.
Subcontracting widens the evidence chain
Private security delivery frequently crosses organisational boundaries. A prime contractor may use regional guarding companies, response partners, monitoring centres, transport providers, or temporary labour. The client may also operate its own security team alongside them.
Those boundaries do not make accountability disappear. The SIA’s rules normally require approved contractors to subcontract to other approved contractors unless specific permission is obtained. Its guidance requires customer agreement and defined quality-assurance arrangements for subcontracting.4 The International Code of Conduct for Private Security Service Providers goes further in a global context. It requires member and affiliate companies to apply the Code’s principles to personnel and subcontractors, to exercise due diligence in their selection and vetting, and to conduct ongoing performance review.5
The operational consequence is that a GSOC needs to know more than the name of the supplier. It needs an accurate picture of who is deployed, which assignment instructions apply, how the team can be contacted, what authority it holds, which competencies or equipment the task requires, how an incident is reported, and who is responsible for closing corrective action.
Information received from a subcontractor should retain its provenance. The prime contractor should not turn an unverified local report into a corporate fact merely by copying it into its own system. Equally, the subcontractor should not be excluded from the common operating picture when it is expected to act upon it. A controlled supply chain is one in which operational expectations and evidence can travel in both directions.
This also improves client assurance. A monthly report that aggregates all activity may conceal a recurring failure at one subcontracted site. A better assurance process can trace incidents, response times, missed actions, complaints, and procedural deviations to the part of the service where improvement is required.
Human rights and proportionality are operational constraints
Security providers operate where one party’s protection can affect another person’s rights. That is particularly clear when personnel monitor individuals, restrict movement, apprehend somebody, or use force. Human-rights commitments therefore belong inside the command process, not in a policy document detached from operations.
The International Code of Conduct requires reasonable steps to avoid force and says that any force used must be lawful, strictly necessary, proportionate to the threat, and appropriate to the situation. It also requires incident reports for events including weapons use, escalation of force, injury, attacks, criminal acts, traffic accidents, and incidents involving other security forces. The report is expected to address the time and location, the people involved, injuries or damage, the preceding circumstances, and the measures taken.6
This is not simply a reporting template. It implies a decision discipline. The GSOC should be able to show what alternatives were available, what the responder had been told, what changed the perceived risk, who authorised an escalation, and whether instructions remained consistent with the provider’s rules and the client mandate.
The same principle applies to location information and video. More visibility is not automatically better control. The provider should understand the operational purpose for collecting information, who may access it, when it may be disclosed, how long it should be retained, and how misuse or a complaint would be investigated. ICoCA’s Code requires fair and accessible grievance and whistleblowing procedures, protection against retaliation, effective remedies, and recommendations designed to prevent recurrence.7
A GSOC that can reconstruct an incident but cannot account for how people were treated has only solved part of the problem.
Client reporting should emerge from the operation
Clients need reports, but reporting can become detached from operational truth. A dashboard may show that ninety-five per cent of alarms were acknowledged within a target time while saying nothing about whether the acknowledgements led to the correct decisions. Fast closure may even improve a service-level figure while hiding repeated false alarms, unclear instructions, or unresolved causes.
Useful reporting should distinguish speed from effectiveness. Detection time, operator acknowledgement, verification, decision, dispatch, arrival, communication, resolution, and closure are different stages. Not every incident requires every stage, and the provider should not manufacture activity to fill a template. The purpose is to reveal where time was spent and whether the delay was justified.
A mature review also examines decision quality. Did the team act on the best information reasonably available? Were important uncertainties made explicit? Was the response within mandate? Did an action reduce risk, merely transfer it, or create a new exposure? Did the client or subcontractor receive the information required to fulfil its role? Did the same procedural weakness appear in an earlier event?
This produces a more valuable client conversation. Instead of presenting a volume of alerts as evidence of effort, the provider can show patterns in risk, explain changes to deployment or procedure, and demonstrate whether corrective action worked. The GSOC becomes a source of operational learning, not a remote archive of activity.
A practical assurance test
Leaders can test a GSOC without waiting for a major incident. Select a recent event and ask an operator to explain it using only the live operational record. Can they identify the first reliable observation, rather than the first interpretation? Can they show which procedure and client instruction applied? Is the decision-maker clear? Can they distinguish confirmed facts from the working assessment? Are the actions, owners, and completion evidence visible? If a subcontractor was involved, can the provider demonstrate what that party knew and was expected to do? Can the team produce a handover that another operator could safely accept? Can management show what was learned and whether the change was tested?
If those answers depend on the memory of one experienced supervisor, the organisation possesses expertise, but not yet a resilient management system. If they depend on assembling several uncontrolled records, the report may eventually be complete, but operational control was fragile.
Where technology fits
Technology cannot decide the provider’s mandate, create competent judgement, or make an unreasonable action defensible. It can make disciplined work easier to perform and harder to lose.
AtlasNXT can support the incident-management layer by bringing relevant people, location context, communications, and the developing event record into a shared operational view. It can help teams target safety messages, record acknowledgements, maintain an incident history, and preserve information for handover and review. It does not replace guarding procedures, emergency-service command, human-rights due diligence, or the client’s retained authority.
That distinction is important. The objective is not to promise that a platform will “manage risk” by itself. It is to give trained people a clearer environment in which to exercise control, and to leave an evidence trail that shows what they did.
The strongest GSOC is therefore not necessarily the one with the largest screen wall or the greatest number of data feeds. It is the one that can make a proportionate decision under uncertainty, carry that decision through organisational boundaries, protect the people affected, and demonstrate the integrity of the response afterwards.
Book an AtlasNXT demonstration to explore how a joined-up incident and communications record can support accountable security operations.
References
3. Joint Emergency Services Interoperability Principles, Joint Doctrine, Edition 3.1



