Technical Security
When is a TSCM sweep actually worth doing?
Organisations spend heavily protecting data at rest and in transit, then hold the actual decision in a conference room nobody has ever inspected. Here is how to decide when that matters.
Sweep when the value of a specific conversation goes up, or when trust in a space has changed. Those are the two conditions that justify the cost. "When we get around to it" is not a trigger, and a standing annual sweep on a room that was renovated in between is close to theatre.
Expect the physical inspection to find more than the spectrum work. A device that is not transmitting when you walk in is invisible to a receiver.
The economics changed, and not in your favour
Capable audio and video devices are now cheap, small, and available to anyone. That has shifted the realistic threat away from the exotic and toward the mundane: not a state service running a technical operation against you, but a competitor, a party to a dispute, a departing employee, or a contractor with a grievance and legitimate access.
Which points at the actual vector. In most cases it is not a specialist defeating your security. It is someone with a legitimate reason to be in the room leaving something behind — a vendor's technician, a cleaner, a maintenance contractor, a former employee whose badge worked for two weeks longer than anyone noticed.
And often it is not a planted device at all. It is a smart display, a conferencing system, a voice assistant, or a networked sensor doing precisely what it was designed to do, in a room where nobody consciously decided it should be doing it.
The triggers worth acting on
Before the conversation, not after
Ahead of a negotiation, a transaction, a board decision, a proposal, or a program milestone — while the sensitive discussion is still in front of you. This is the highest-value timing and the most commonly missed, because it requires anticipating rather than reacting.
When access changed
An insider departure or termination. A contractor with unsupervised access. A renovation or fit-out. A vendor service call in a sensitive space. Any of these resets what you actually know about the room.
When something is already off
Information appearing where it should not. A counterparty who seems to know your position. A live dispute, investigation, or litigation. A concrete reason to suspect eavesdropping — as distinct from a general unease.
On a cadence, for the spaces that earn it
Rooms where controlled or proprietary discussion is routine — program spaces, executive suites, engineering and integration areas, secure areas — justify recurring coverage. Set the interval by exposure, and re-sweep after any change to the space regardless of where you are in the cycle.
What an inspection actually covers
A credible sweep is layered, not a single instrument walked around a room:
- RF and spectrum analysis across the relevant bands, with attention to intermittent, burst, and store-and-forward behaviour rather than one pass at one moment
- Physical inspection — furniture, fixtures, wall and ceiling voids, power and data outlets, HVAC penetrations, and anything recently installed, moved, or serviced
- Telephony and conferencing — handsets, room systems, microphones and DSPs, and the signal paths in and out
- Audio-visual and networked devices — displays, cameras, assistants, sensors, and the appliances that belong to the building rather than to IT
- Infrastructure and building services — cabling, risers, conduit, adjacent spaces, and the plenum the room shares with its neighbours
- Acoustic exposure — what is simply audible through walls, doors, glass, ducts, and shared returns, with no device involved at all
That last item deserves emphasis because it is the one most often skipped and most often relevant. We have found more conversations leaking through a shared return air path or a poorly specified glass partition than we have found transmitters. It is unglamorous, it is fixable, and it is genuinely a technical security finding.
How to judge a provider
The market has a wide quality range and very little transparency. Reasonable questions:
- What is in the written deliverable? You want findings documented with location, method, and disposition — a record suitable for security files and for counsel. "We found nothing" on letterhead is not a product.
- What is the process on discovery? The right answer involves preserving in place and calling you before touching anything. Anyone whose instinct is to remove and hand you the device has just damaged your evidence.
- Does the scope include the acoustic and infrastructure layers, or only the spectrum? Spectrum-only is the cheap version and it misses the common cases.
- Will they say what falls outside their authority? In accredited environments, certain inspections must be performed by government-designated authorities, and TEMPEST matters rest with certified ones. A provider who will not acknowledge that boundary is selling you work that may not count.
- How do they handle discretion? After-hours access, cover for the building's occupants, and a distribution list of the smallest possible size should be defaults, not upgrades.
What a sweep does not do
It is a point-in-time answer. A room is clean as of the inspection, under the conditions inspected. That is genuinely valuable — it is the only way to answer "is this room what we think it is" — but it is not a control that persists. What persists is what you change afterwards: access discipline for the space, an owner for the networked devices in it, escort practice for vendors, and acoustic remediation where it was needed.
The sweep tells you where you stand. The programme is what keeps you there.
Questions
On sweeps
How often should a sensitive room be swept?
Will a sweep find something?
Can you sweep an accredited space?
What happens if a device is found?
How discreet is the process?
Next Step
If the room matters, test the assumption.
Describe the space and the concern in one paragraph. Keep specifics general in writing — details belong on a call.
Prefer to talk? 866.960.7475 · info@orbitalfederal.com