Active shooter preparedness for workplaces is a coordinated program that reduces violence risk, improves employee decision-making during an armed attack, and supports medical, organizational, and psychological recovery afterward. The program combines threat assessment, an Emergency Action Plan, physical security, role-based training, controlled exercises, and communication with first responders.
Key Facts at a Glance
The FBI defines an active shooter as “one or more individuals actively engaged in killing or attempting to kill people in a populated area.”
Run, Hide, Fight is a decision framework, not a rigid sequence that applies identically in every building.
A workplace Emergency Action Plan should address prevention, evacuation, sheltering, communications, medical aid, reunification, and recovery.
Announced, progressively designed exercises are safer than surprise simulations involving blanks, realistic weapons, or simulated gunfire.
Access-control testing, current floor plans, plain-language alerts, and responder coordination often matter more than expensive detection technology.
A typical small-business rollout takes 30-60 days, while a multi-building program commonly takes 90-180 days.
What Does Workplace Active Shooter Preparedness Include?
Workplace active shooter preparedness includes prevention, protection, response, and recovery measures that are assigned to specific people and tested in the actual work environment. A complete program connects human reporting, building controls, emergency communications, employee decisions, first-aid capability, and post-incident care.
The FBI definition describes an event already involving attempted or actual killings in a populated area. Workplace violence planning must therefore address a broader range of conduct before an incident reaches that threshold, including threats, stalking, domestic violence spillover, fights, weapon violations, and severe grievance escalation.
The program should be owned by a cross-functional team rather than delegated entirely to security. Human resources, facilities, information technology, legal counsel, disability and accessibility specialists, occupational health, communications, and local responders each control different parts of the risk.
Why Is a Fixed Incident Timeline Unsafe?
A 10-15 minute duration is a useful planning reference, not a guaranteed window. Some attacks end sooner, some continue longer, and police arrival times vary by location, access conditions, call quality, and the availability of responding units.
CISA and the FBI use rapid decision-making guidance because employees may need to act before law enforcement reaches the affected area. A plan should never tell employees to wait for an official instruction when they can safely escape, nor should it promise that a lockdown will end within a particular number of minutes.
A better design assumption is operational uncertainty: alerts may be delayed, exits may be blocked, phone service may fail, and responders may not immediately know who belongs in the building. Plans should provide options rather than false precision.
How Should a Workplace Build the Program?
A workplace should build its preparedness program through five controlled phases: assess vulnerabilities, write the Emergency Action Plan, install and test supporting controls, train employees by role, and evaluate the plan through safe exercises. A small office can establish the first version in 30-60 days; complex campuses require longer coordination.
Step 1: Assess People, Places, and Processes
Start with a site-specific risk assessment that examines how people enter, work, gather, leave, and communicate. Review the main entrance, loading areas, parking, reception, elevators, stairwells, production floors, childcare areas, conference rooms, isolated workstations, and spaces used after normal hours.
Assess these elements:
- Visitor screening and escort procedures
- Badge issuance, termination, and lost-card response
- Door locking, glazing, hinges, and room occupancy
- Emergency exits and accessible evacuation routes
- Camera coverage, retention, and monitoring responsibility
- Panic or duress alarms and their dispatch destination
- Public interaction, cash handling, and customer queues
- Domestic violence and restraining-order procedures
- Lone-worker, travel, remote-work, and shift-change risks
- Language, hearing, vision, mobility, and cognitive accessibility
Interview employees without asking them to diagnose coworkers. A behavior-based question such as “What conduct or process failure would make you hesitate to report a threat?” produces better information than asking who appears dangerous.
Success checkpoint: The assessment should produce a prioritized risk register with an owner, deadline, cost estimate, and verification method for every corrective action. A vague statement such as “improve security” is not an actionable finding.
Step 2: Write the Emergency Action Plan
The Emergency Action Plan should tell employees what to do, managers what to communicate, and responders what information they will receive. OSHA’s emergency planning principles support clear reporting procedures, escape routes, accountability methods, and assigned responsibilities, although exact legal requirements vary by jurisdiction and workplace type.
Include the following sections:
- Activation: Who can declare an emergency, and what evidence triggers the plan?
- Alerts: Which channels send the message, and what plain-language wording is used?
- Evacuation: Which exits, alternate routes, assembly areas, and accessibility aids are available?
- Sheltering: Which rooms lock, barricade, conceal occupants, and permit communication?
- Accountability: How are employees, contractors, visitors, and missing people tracked?
- Medical response: Where are trauma kits, AEDs, first-aid supplies, and trained responders?
- Law enforcement interface: Who provides floor plans, keys, camera access, and hazard information?
- Family assistance: Who manages reunification, emergency contacts, and privacy?
- Continuity: Which functions move, pause, or operate remotely after the site closes?
- Recovery: Who coordinates counseling, evidence preservation, repairs, return-to-work, and review?
Keep emergency instructions short enough to read under stress. A notification should state the hazard, location if confirmed, action required, routes or areas to avoid, and the source of the message. Avoid unverified descriptions that could cause employees to move toward a suspected attacker.
Step 3: Add Layered Physical and Digital Controls
Layered security uses multiple independent barriers, because any single camera, badge reader, alarm, or guard can fail. Controls should delay unauthorized access, increase useful information, support evacuation, and help responders without creating dangerous assumptions.
| Control | Typical specification | Verification interval | Main limitation |
|---|---|---|---|
| Badge access | Active permissions reviewed monthly | Monthly | A valid credential can still be misused |
| Door hardware | Self-closing and latching doors | Monthly functional test | Locked doors can obstruct evacuation |
| Mass notification | SMS, email, desktop, voice, and PA channels | Quarterly test | Personal devices may be unavailable |
| Camera system | 30-90 days of retention, site-specific coverage | Monthly spot check | Cameras do not stop an attacker |
| Duress alarm | Silent alert to a defined dispatch point | Monthly test | Staff must know its exact location |
| Trauma cabinet | Tourniquets, gauze, gloves, shears, instructions | Monthly inventory | Supplies require trained users |
| Floor plans | Current digital and printed responder copies | Quarterly update | Renovations can make maps obsolete |
Technology requires governance. An AI-enabled gun-detection camera may reduce detection time in a controlled field of view, but false alarms, occlusion, lighting, weapon ambiguity, network outages, and privacy rules affect performance. Technology should supplement human reporting and established emergency communications, not replace them.
Facilities teams should test whether doors actually latch, whether a lockdown command affects the correct zones, and whether notification messages reach people wearing hearing protection or working in noisy areas. An access system that functions in a software dashboard but fails at a physical door is not operationally ready.
Step 4: Train Employees by Role
Every worker needs basic awareness, but every role does not need identical instruction. Receptionists, supervisors, security officers, facilities staff, executives, first-aid responders, and remote employees encounter different decisions and information.
Core employee training should cover:
- Recognizing an emergency announcement and its authority
- Identifying at least two routes from the employee’s normal workspace
- Leaving belongings behind when evacuation is safer
- Locking, closing, and barricading a room when sheltering
- Silencing devices and reducing visibility
- Calling emergency services when safe, with location and description
- Avoiding elevators when evacuation conditions make them unsafe
- Keeping hands visible when law enforcement arrives
- Reporting threats without investigating or confronting a person
- Supporting coworkers with disabilities without creating unsafe dependency
CISA’s widely used public guidance summarizes the immediate response as “Run. Hide. Fight.” The phrase is memorable because it gives people options under stress, but training must explain that the safest choice depends on the attacker’s location, available exits, room construction, and current information.
Medical training deserves separate attention. The American College of Surgeons Stop the Bleed program teaches bleeding-control actions, while workplace first-aid requirements and local rules determine who may provide care. A trauma kit is useful only when supplies are accessible, marked, maintained, and matched with trained personnel.
Step 5: Exercise, Measure, and Correct the Plan
Begin with a 60-90 minute tabletop discussion, then conduct a communications test, a guided walk-through, and only afterward a limited functional exercise. Every exercise should be announced, accessible, psychologically considerate, and designed around learning objectives rather than fear.
Never use realistic weapons, blank ammunition, surprise gunfire, actors posing as victims, or unannounced confrontations without extraordinary safeguards and informed consent. Such methods can cause panic, injuries, emergency calls, and trauma while measuring theatrical realism instead of operational readiness.
Use these metrics:
- Alert delivery time to each communication channel
- Percentage of employees who can identify two exits
- Time required to provide current floor plans to responders
- Number of doors that fail to latch or lock as designed
- Percentage of badge permissions reviewed by deadline
- Percentage of trauma cabinets passing inventory checks
- Time required to account for visitors and contractors
- Number of corrective actions closed within 30 days
An after-action report should identify what happened, why it happened, who owns the correction, and when the organization will retest it. A drill that produces no assigned corrective action is an event, not a preparedness program.
Which Response Framework Should a Workplace Use?
Run, Hide, Fight is the best baseline framework for most workplaces because public agencies recognize it and employees can remember it quickly. ALICE can add more active information-sharing and evacuation options, while ALIVE offers another branded situational model, but neither should replace site-specific judgment or local responder coordination.
| Framework | Core actions | Training burden | Strongest use case | Important limitation |
|---|---|---|---|---|
| Run, Hide, Fight | Evacuate, shelter, resist as last resort | Low to moderate | General office, warehouse, nonprofit | Can be misunderstood as a fixed sequence |
| ALICE | Alert, Lockdown, Inform, Counter, Evacuate | Moderate to high | Large or complex facilities | Requires reliable information channels |
| ALIVE | Assess, Leave, Impede, Violence, Expose | Moderate | Situational-awareness instruction | Less standardized recognition among responders |
| Site-specific hybrid | Local exits, shelter rooms, alerts, responder terms | High design effort | Campuses, hospitals, manufacturing | Requires regular maintenance |
The AI Overview’s description of these as “accredited defense methodologies” is too broad. Run, Hide, Fight is public guidance associated with agencies including CISA and the FBI; ALICE is a private training model; ALIVE is a separate commercial framework. Employers should verify the provider, instructor qualifications, evidence base, insurance, and local law rather than treating every branded acronym as an official standard.
When Should Employees Run, Hide, or Fight?
Employees should run when a safe route away from the threat is available, hide when evacuation is unsafe or unknown, and physically resist only when confronted with an immediate threat and no safer option remains. The decision is dynamic and can change as new information arrives.
Run: Leave quickly, keep hands empty if possible, help others without delaying escape, and move away from the building. Do not gather at the nearest visible doorway if the threat may be there.
Hide: Select a room that can close and lock, barricade only if it does not expose occupants, turn off lights, silence devices, stay out of sight, and avoid opening the door for unverified instructions.
Fight: Physical resistance is a last-resort survival action when escape and concealment are unavailable. Training should focus on decisive collective action and immediate escape afterward, not on martial-arts techniques or pursuit.
What Does Preparedness Cost and How Long Does It Take?
Typical online awareness training costs $20-$75 per employee, while an onsite risk assessment and exercise commonly costs $2,000-$10,000 or more. Hardware, notification software, door repairs, security staffing, accessibility modifications, and medical supplies can exceed the training fee.
| Program component | Typical small-site cost | Typical time | Budget variable |
|---|---|---|---|
| Online awareness course | $20-$75 per seat | Same day to 1 week | Language, reporting, tracking |
| Tabletop exercise | $500-$3,000 | 2-4 weeks planning | Facilitator and participant count |
| Site risk assessment | $1,500-$7,500 | 1-3 weeks | Number of buildings and shifts |
| Functional exercise | $2,000-$10,000+ | 2-6 weeks planning | Responders, scope, accessibility |
| Mass notification platform | $1,000-$10,000 annually | 1-4 weeks setup | Users, channels, integrations |
| Trauma cabinet | $150-$500 each | 1-2 weeks procurement | Contents and cabinet type |
| Door or access repairs | $200-$5,000 per opening | 1 day to 8 weeks | Hardware, wiring, fire code |
A practical first-year budget for a 50-person office is often $3,000-$15,000 before major construction. A multi-building employer may need $25,000-$150,000 or more when it adds notification, access-control integration, consultants, responder exercises, and architectural changes.
Cost should follow risk. Repairing a door that does not latch may produce more immediate protection than purchasing a new analytics platform.
How Do Different Workplaces Adapt the Plan?
Workplace preparedness must reflect occupancy, public access, building design, staffing, and work hours. A retail store, hospital, factory, coworking suite, and remote technology company cannot share one operational plan without dangerous gaps.
| Workplace setting | Primary exposure | Priority controls | Training emphasis |
|---|---|---|---|
| Small office | Limited security staffing | Two exits, notification, door function, visitor log | Basic response and reporting |
| Retail or hospitality | Public access and transient occupants | Duress alarms, cash-area procedures, staff code words | De-escalation and customer movement |
| Manufacturing | Noise, machinery, shift work | PA redundancy, zone maps, supervisor radios | Evacuation around equipment |
| Healthcare | Vulnerable patients and controlled areas | Unit lockdown, patient movement, clinical command | Role-based shelter and continuity |
| Corporate campus | Multiple buildings and large population | Unified command, maps, interoperable alerts | Section-by-section exercises |
| Remote or hybrid team | Variable locations and connectivity | Location-aware alerts, travel policy, coworking procedures | Personal situational awareness |
Small and Remote-First Employers
Small businesses should appoint one program owner, create a one-page emergency card, verify two exits, establish a notification tree, and coordinate with the building manager. Remote-first teams should add procedures for coworking spaces, home offices, business travel, conferences, and employees who work alone.
A remote employee cannot rely on the company’s physical lockdown procedures. The employer should maintain current emergency contacts, location privacy controls, a way to send location-specific alerts, and guidance to contact local emergency services rather than waiting for corporate approval.
Public-Facing Workplaces
Retail, medical, and hospitality employers need procedures for people who do not know the building. Employees should know how to direct customers toward safe exits without creating a crowd, where staff-only refuge areas are located, and how to use silent alarms.
De-escalation training reduces some routine conflicts, but it cannot guarantee prevention of an armed attack. Staff should not be instructed to negotiate, pursue, physically search, or disarm a suspected attacker unless their professional role and training specifically require it.
Manufacturing and Large Campuses
Manufacturing sites should account for hearing protection, forklifts, hazardous materials, locked production zones, shift turnover, and multiple alarm systems. A voice announcement that cannot be heard over equipment is not a functioning alert.
Large campuses need a common map language. Use building names, floor numbers, entrances, stairwell labels, hazard locations, and assembly areas that employees and responders use consistently. Provide current copies to emergency services through an agreed secure process.
What Are the Most Common Program Failures?
The most common failures are stale access permissions, unclear authority to issue alerts, unrealistic drills, incomplete visitor accountability, and plans that assume every worker can move or communicate in the same way. Each failure is preventable when the organization assigns an owner and tests the physical result.
Failure 1: Treating Warning Signs as a Profile
Threat assessment should focus on observable conduct, credible threats, access attempts, leakage of violent intent, stalking, or fixation on a target, not appearance, diagnosis, religion, race, disability, or lawful beliefs. A multidisciplinary team should document facts, assess immediacy, protect privacy, and offer support where appropriate.
Failure 2: Assuming Lockdown Is Always Safest
A locked room may protect occupants in one location and trap them in another. The plan should explain how employees evaluate exits, concealment, door strength, attacker proximity, and new information without requiring a single universal command.
Failure 3: Buying Technology Before Fixing Basics
Organizations sometimes purchase cameras while failing to maintain doors, maps, radios, alarms, and employee contact records. The practitioner rule is simple: verify the basic control manually before adding an automated layer.
Failure 4: Ignoring Accessibility
An evacuation plan that depends on stairs, flashing alerts, hearing, vision, or rapid walking excludes people by design. Provide accessible alerts, evacuation chairs where appropriate, personal emergency evacuation plans, trained assistance procedures, and a choice that preserves the employee’s agency.
Failure 5: Forgetting Recovery
The incident continues operationally after the attacker is gone. Employers need a family-assistance process, protected leave and counseling pathways, evidence-preservation rules, communications approval, temporary work arrangements, and a staged return-to-work plan.
What Should Happen After an Incident?
After an active shooter incident, the employer should prioritize life safety, preserve the scene, support law enforcement, account for people, communicate verified information, and provide sustained medical and psychological care. Business continuity should begin only after responders release affected areas and leadership confirms that reopening will not create additional risk.
The recovery sequence commonly includes:
- Coordinate with law enforcement and emergency medical services.
- Establish a family assistance and reunification center away from the incident site.
- Protect employee privacy and prevent rumor-driven identification.
- Provide immediate medical evaluation and trauma-informed counseling.
- Offer paid time, leave, transportation, and practical support.
- Preserve relevant video, access logs, messages, and incident records.
- Assess structural damage, hazards, and temporary workplace locations.
- Conduct a multi-party after-action review when facts are sufficiently established.
- Update the plan, training, controls, and support resources.
- Continue check-ins because trauma reactions may emerge weeks or months later.
Employee Assistance Programs can help, but they should not be the only resource. Some employees need specialized trauma care, peer support, medical treatment, legal assistance, or culturally and linguistically appropriate services.
How Can an Employer Audit Readiness?
An employer can audit readiness by testing whether employees, systems, facilities, and responders complete defined tasks under realistic but safe conditions. The audit should produce evidence, not impressions.
Use this quarterly checklist:
- The Emergency Action Plan has a current revision date and owner.
- Every shift can receive an alert through at least two channels.
- Employees can identify two routes or one safe shelter option.
- Visitor and contractor records are available to authorized responders.
- Terminated employees lose access within the organization’s defined target.
- Critical doors latch, lock, and release according to fire and life-safety rules.
- Floor plans show current rooms, entrances, utilities, hazards, and stairwells.
- Trauma supplies are present, sealed, accessible, and in date.
- Supervisors understand their communication and accountability duties.
- Corrective actions from the previous exercise have evidence of closure.
A mature program tracks the age of unresolved findings. Any life-safety defect without an owner and target date should be escalated to executive leadership.
Frequently Asked Questions
Is active shooter training required for every workplace?
No single federal rule requires the same active shooter course for every U.S. workplace, but employers may have duties under OSHA’s General Duty Clause, state workplace-violence laws, industry rules, building codes, and contractual requirements. Legal counsel should review the plan, especially for healthcare, schools, government contractors, and public venues.
How often should a workplace conduct active shooter drills?
Most workplaces should provide awareness training during onboarding, refresh it annually, test communications at least quarterly, and conduct a tabletop exercise annually. A functional exercise may occur every 12-24 months, with higher-risk sites choosing a shorter interval after risk assessment and consultation with employees and responders.
Should a company tell employees about a threat assessment?
The company should share actionable safety information while protecting confidential personnel details and avoiding unsupported accusations. Employees need a trusted reporting channel, confirmation that reports are reviewed, and clear instructions for immediate threats. Threat assessment should never become informal surveillance based on stereotypes.
Do trauma kits replace first-aid training?
No. Trauma kits provide supplies, not judgment or skill. Employers should place kits where people can reach them, train designated responders through recognized bleeding-control instruction, inspect supplies monthly, and coordinate kit placement with AEDs, first-aid stations, emergency exits, and local medical response.
Can a workplace use Run, Hide, Fight for remote employees?
Run, Hide, Fight can provide a simple baseline for remote workers, but the employer must adapt it to homes, hotels, coworking sites, travel routes, and local emergency numbers. Remote employees also need location-specific alerts and a clear rule to contact local emergency services directly when danger is immediate.
What is the first preparedness action for a small business?
The first action is to walk the site with employees and identify two exits, lockable refuge rooms, notification gaps, visitor-control weaknesses, and the location of emergency supplies. The owner should then document five corrective actions with deadlines, rather than purchasing technology before understanding the building.
The Bottom Line
Active shooter preparedness for workplaces is a maintained management system, not an online course or a single lockdown button. Build it around a site-specific assessment, a concise Emergency Action Plan, reliable physical and communication controls, role-based training, safe exercises, medical readiness, responder coordination, and long-term recovery support.
Run, Hide, Fight is a practical baseline, but no acronym can predict every building or attack. The strongest program gives employees usable options, tests those options under safe conditions, corrects failures quickly, and preserves human judgment when information is incomplete.


