Technical surveillance risk,treated like a real risk
Covert devices, compromised rooms, intercepted conversations — most organisations have never assessed the risk, let alone controlled it. We help you assess it, govern it, and close it. A TSCM Partners service.
The questions this site answers
Written for the people who own the risk: heads of security, CISOs, general counsel and company secretaries.
How exposed are we?
What a TSCM risk assessment covers, what it delivers, and how it decides which rooms matter.
→What do regulations require?
NIS2, ISO 27001, the UK Corporate Governance Code, UK GDPR — mapped to surveillance risk, article by article.
→How do we run this as a control?
Policy, risk register wording, sweep frequency, trigger events, and board reporting — usable as written.
→What does it cost and who do we trust?
Honest pricing guidance and a vetting checklist for an unregulated market.
→Assess, govern, verify
Sweeps without an assessment are theatre. Assessment without a programme is a report on a shelf. The value is the loop.
01
Assess
A documented technical surveillance risk assessment: scoped spaces, threat sources, access routes, control gaps, and a cadence recommendation.
02
Govern
A one-page policy, a risk register entry with an owner, defined trigger events, and a standing line in the committee pack.
03
Verify
Professional inspections on the agreed cadence and triggers, with dated records that bound your exposure window and evidence the control.
Compliance, mapped
Where surveillance risk sits in the frameworks your auditors already use.
Run it as a programme
The governance layer, ready to adapt.
Writing a TSCM Policy
A TSCM policy turns occasional bug sweeps into a governed control: defined spaces, defined cadence, defined triggers, and records that stand up to auditors, regulators and courts. Here is the full structure, usable as written.
Technical Surveillance in the Risk Register
Most enterprise risk registers carry cyber intrusion in detail and say nothing about the interception of spoken information. Here is a complete, adaptable register entry: threat, vulnerability, impact, scoring, controls and owner.
How Often Should You Sweep?
Quarterly, semi-annual, or event-driven only? Sweep frequency is a risk decision, not a product tier. Here is how to set a cadence you can defend — to the board, to an auditor, and to yourself after an incident.
Trigger Events: When to Sweep Outside the Calendar
Most successful device placements exploit a moment: a fit-out, a departure, a deal. A calendar cadence alone misses them. These are the trigger events a serious programme defines in advance — and why each one earns its place.
Reporting Surveillance Risk to the Board
Surveillance risk reaches most boards either as silence or as alarmism after an incident. Neither serves governance. Here is a reporting pattern that keeps the control visible, evidenced, and proportionate — in three lines a quarter.
Who is behind this
TSCM Risk is a service of TSCM Partners Ltd, a UK limited company on Companies House. Engagements across the UK, Europe and the US are delivered by TSCM Partners and its vetted specialist network.
Evidence, not fear
We publish the frameworks, the checklists and the pricing logic openly. If your assessment concludes you need less than you feared, that conclusion is the deliverable.
A traceable entity
Registered company, named director, published address and phone. In an unregulated market, verify us the way we tell you to verify anyone.
Discretion by design
Mutual NDA before scoping, out-of-band contact routes, unbadged operators, and a deliberately small circle of knowledge.
Common questions
- What is TSCM risk?
- TSCM risk is the risk that information is lost through technical surveillance: covert listening devices, hidden cameras, compromised conference hardware, or interception of the spaces where sensitive matters are discussed. TSCM — technical surveillance counter-measures — is the professional discipline of assessing that exposure and detecting devices. Managing it well means treating it like any other enterprise risk: assessed, owned, controlled, and evidenced.
- Is a TSCM risk assessment the same as a bug sweep?
- No. A sweep is a point-in-time inspection that answers whether a space is clean today. A risk assessment is the analysis that decides which spaces matter, what the threat is, how often to inspect, and what the triggers are. The assessment designs the programme; sweeps operate it. Buying sweeps without the assessment usually means sweeping the wrong rooms on the wrong schedule.
- Who delivers the services behind this site?
- TSCM Risk is a service of TSCM Partners Ltd, a UK-registered company (Companies House 16842743). Assessment and inspection engagements across the UK, Europe and the US are delivered by TSCM Partners and its vetted specialist network.
- Does my organisation actually need this?
- Ask what is discussed aloud in your most sensitive rooms and what its loss would cost. Organisations doing material transactions, in litigation, handling regulated data, or facing determined competitors usually find the answer justifies at least a documented risk assessment and trigger-event coverage. Many will conclude a full calendar programme is unnecessary — that is a legitimate, defensible outcome of an assessment, and a far better position than never having asked.
Start with the assessment
One conversation to scope it. A written assessment you can put in front of the board. No obligation to buy sweeps from anyone, including us.