What the 2020 7NEWS report revealed about technical surveillance risk, why the issue remains relevant in 2026, and what sensitive organisations can learn from government protective-security practice.
AUTHOR: Claude Khoury, Chief Operating Officer, NSI Global
ORIGINAL PUBLICATION: 15 April 2020 REVISION COMPLETED: 21 September 2026 AEST
In April 2020, 7NEWS Sydney reported that counter-surveillance sweeps had begun across NSW ministerial offices in response to concerns about covert surveillance and foreign-intelligence collection. NSI Global founder and CEO Navid Sobbi was sought out by 7NEWS for expert commentary on Technical Surveillance Counter Measures (TSCM) and the vulnerability of sensitive conversations to covert collection by domestic or foreign actors.
Why Ministerial Offices Are High-Sensitivity Environments
Senior government offices can host discussions and records whose value is not limited to formally classified information. Depending on the function of the office, sensitive material can include policy development, regulatory decisions, procurement, infrastructure, legal advice, commercial negotiations, personnel matters, foreign-government engagement and information concerning law-enforcement or national-security activity.
That list describes categories of information that can make senior government environments attractive intelligence targets; it does not imply that any particular NSW ministerial office was compromised in 2020. Protective security is concerned with reducing the opportunity for compromise before there is proof that one has occurred.
ASIO’s public guidance similarly notes that foreign intelligence services seek information across government, defence, academia and business, and that information does not have to be highly classified to be valuable. Material that appears innocuous in isolation can be aggregated to fill intelligence gaps or assist future targeting.
What Does a Government Counter-Surveillance Sweep Actually Examine?
A professional TSCM engagement is a systematic technical and physical examination of the environment rather than a single pass with an RF detector. The Australian Government PSPF glossary identifies ASIO’s T4 Protective Security capability as providing technical surveillance countermeasures among its protective-security functions for Commonwealth, state and territory governments and business.
The appropriate methods depend on the threat model and the environment. A government or ministerial-office assessment may need to consider multiple classes of collection technology and vulnerability.
| Threat / Vulnerability | Why It Matters | TSCM Response |
| Active RF transmitters | Hidden microphones or cameras may transmit audio, video or data by radio. | Spectrum analysis, signal identification, direction finding and physical confirmation. |
| Cellular-connected devices | A covert device may communicate independently of the organisation’s Wi-Fi infrastructure. | Cellular-threat assessment, signal analysis and physical attribution. |
| Wi-Fi / Bluetooth surveillance | Malicious devices can use the same protocols as legitimate corporate technology. | Network/RF inventory, attribution and physical examination. |
| Passive recorders | A recorder may store audio or video locally and emit little or no useful RF signal. | Physical inspection, NLJD/electronic examination, thermal and optical methods where appropriate. |
| Hidden cameras | Cameras may be wired, wireless, networked or self-contained. | Optical/physical inspection, electronic analysis and RF/network assessment as relevant. |
| Concealed electronics | Surveillance components can be hidden inside legitimate fixtures or electronics. | Baseline comparison, nonlinear-junction detection and targeted physical examination. |
| External optical threats | Collection equipment may remain outside the room and use line-of-sight pathways. | Window, glazing and external-vantage assessment in addition to internal electronic testing. |
| Compromised endpoints | A phone, computer or conferencing system can expose sensitive discussions without a planted room bug. | Digital forensics, account review, COMSEC and endpoint assessment. |
For the technical methodology in more detail, see How to Detect Eavesdropping Devices: What a Professional TSCM Bug Sweep Checks.
Why RF Scanning Alone Is Not Enough
A transmitter-only sweep can miss surveillance equipment that is dormant, scheduled, remotely activated or recording locally. It can also generate false confidence in dense RF environments where legitimate Wi-Fi, Bluetooth, mobile, IoT and conferencing technologies create substantial background activity.
The practical question is not simply whether radio energy is present. The investigator must determine which signals and devices should exist, what is unexplained, whether suspicious electronics are physically present, whether there are non-transmitting threats and whether the room or communications environment contains vulnerabilities that could be exploited later.
Related NSI case study: Many Bugs Go Undetected by Standard Bug Sweeps.
Government TSCM Is About Vulnerabilities, Not Just Finding a Device
Finding a covert device is the clearest possible result, but a mature TSCM program is also designed to identify weaknesses that could make future surveillance easier. An engagement may reveal uncontrolled access, unexplained cabling, insecure meeting-room equipment, line-of-sight exposure, gaps in telecommunications security, unverified electronics or procedural weaknesses around sensitive meetings.
A technically competent report should therefore document what was examined, which methods were used, what was found, what could not be examined, any relevant limitations, vulnerabilities requiring remediation and the residual risk that remains after the inspection.
For high-sensitivity environments, TSCM can also be supplemented by live meeting monitoring or continuous remote monitoring so that protection does not end when the periodic sweep team leaves the site.
Related NSI capability: Live TSCM Meeting Monitoring.
Counter-Surveillance Also Requires Access and Insider-Risk Thinking
Technical surveillance normally requires a pathway: physical access, an insider, a contractor, altered equipment, compromised meeting technology, a remote communications path or an external vantage point. For that reason, TSCM works best when it is integrated with access control, personnel security, counterintelligence and incident reporting rather than treated as an isolated technical service.
Examples of access and process questions include:
- Who has unsupervised access to ministerial, executive or boardroom spaces outside normal hours?
- How are cleaners, maintenance personnel, fit-out contractors and audiovisual technicians controlled and recorded?
- Are new chargers, adapters, conferencing devices, power supplies or network components verified before introduction?
- Are sensitive meeting schedules unnecessarily visible to people who do not need to know?
- Are room changes, unexplained wiring, missing seals or altered fixtures investigated rather than normalised?
- Does the organisation have a defined escalation path when staff observe suspicious technical or access-related activity?
ASIO’s public foreign-interference guidance emphasises that hostile intelligence activity can involve attempts to penetrate government and business environments and that apparently low-value information can contribute to a larger intelligence picture. That is why technical and human security controls need to reinforce each other.
Why the 2020 Report Still Matters in 2026
The specific 7NEWS story is historical. It should not be used to imply that the same NSW Government sweep program is operating unchanged in 2026. The relevance lies in the enduring protective-security problem illustrated by the report.
ASIO’s 2025 Cost of Espionage report states that the threat posed by espionage is at extreme levels and is expected to worsen as technology develops and strategic competition increases. The report also records that espionage and foreign interference are expected to intensify and notes the growing role of technology in enabling those threats.
The Australian Government’s PSPF Release 2026 was issued on 1 July 2026 and updates information, personnel and physical-security controls, includes measures concerning emerging technologies, and includes training on countering foreign interference. The PSPF glossary continues to identify TSCM as part of ASIO T4’s protective-security capability.
A Six-Year Protective-Security Timeline
| Year | Development | Why It Matters to This Article |
| 2020 | 7NEWS Sydney reports counter-surveillance sweeps of NSW ministerial offices; Navid Sobbi is sought for expert TSCM commentary. | Establishes the original media event and NSI’s independent expert-media role. |
| 2025 | ASIO/AIC Cost of Espionage report describes espionage as an extreme-level threat and expects it to worsen. | Shows that the underlying espionage risk did not disappear with the 2020 news cycle. |
| 2026 | PSPF Release 2026 updates protective-security controls and includes counter-foreign-interference training. | Demonstrates continued Australian Government investment in protective-security policy for current and emerging threats. |
What Corporate Boards and Sensitive Organisations Can Learn From the Case
The lesson is not that every corporate boardroom should copy government security controls. The lesson is that organisations should calibrate protective security to the value of the information they hold, the consequences of compromise, the sophistication of plausible adversaries and the opportunities those adversaries have to gain access.
Law firms, critical infrastructure operators, defence-adjacent companies, resources and energy organisations, financial institutions, technology businesses and organisations involved in major transactions can face conversations and documents whose commercial or strategic value justifies a more mature TSCM posture.
Useful triggers for a professional TSCM review can include:
- A major transaction, tender, acquisition, litigation or regulatory matter involving highly sensitive information.
- Unexplained leakage of strategy or privileged discussions.
- A change in executive, contractor or facilities access around sensitive environments.
- Renovations, audiovisual upgrades, new conferencing equipment or third-party fit-out work.
- Foreign travel, visiting delegations or meetings involving high-value intellectual property or government-sensitive work.
- A suspicious device, signal, altered fixture or unexplained electronic component.
- A threat assessment indicating elevated espionage, insider or competitive-intelligence risk.
NSI Global Government and High-Sensitivity TSCM
NSI Global’s current TSCM service describes systematic visual, electronic and physical examination for covert surveillance across government, corporate and legal environments. Its Government Advanced TSCM service is specifically positioned for government departments, defence-adjacent organisations, parliamentary offices, secure facilities and other high-sensitivity environments.
NSI Global publicly states that its TSCM practice is led by founder Navid Sobbi, delivered in-house, and uses specialist ITAR export-controlled detection equipment. The value of that equipment depends on experienced interpretation, appropriate threat modelling, controlled access and clear reporting rather than the instrument alone.
Learn more: Government and Defence Technical Surveillance Counter Measures and NSI Global TSCM.
About Navid Sobbi’s 7NEWS Commentary
Navid Sobbi is the founder and CEO of NSI Global and has worked across digital forensics, TSCM and counterintelligence since the early 2000s. NSI Global’s current founder profile records his specialist work across TSCM and counterespionage. The 2020 7NEWS appearance is useful because it demonstrates that a mainstream Australian news organisation sought his subject-matter commentary when reporting on ministerial-office counter-surveillance.
Profile: Navid Sobbi – Founder and CEO, NSI Global.
Frequently Asked Questions
Why Do Governments Conduct Counter-Surveillance Sweeps?
Governments may use TSCM to reduce the risk that sensitive conversations, information or facilities are exposed through covert technical surveillance. The precise scope depends on the threat assessment, information sensitivity, physical environment and security requirements.
What Is TSCM?
Technical Surveillance Counter Measures is the specialist discipline used to detect, identify and mitigate covert technical surveillance and related vulnerabilities. It can combine RF/spectrum analysis, physical and electronic inspection, telecommunications assessment, nonlinear-junction detection, thermal or optical methods and other techniques appropriate to the environment.
Can an RF Sweep Detect Every Listening Device?
No. A device may record locally, remain dormant, transmit intermittently, use legitimate network infrastructure or operate through an optical or software-based pathway. Professional TSCM uses complementary methods because no single detector can rule out every threat.
Can a Surveillance Device Record Without Transmitting?
Yes. Audio recorders and cameras can store information locally for later retrieval. This is a primary reason that a transmitter-only sweep is insufficient.
How Often Should a Sensitive Office Be Swept?
There is no universal interval. Frequency should be based on the value of the information, threat profile, access history and trigger events such as sensitive transactions, renovations, unexplained leaks, visiting delegations or changes to personnel and contractors.
What Should Happen Before a Highly Confidential Meeting?
The answer depends on risk. Measures can include pre-meeting TSCM, access control, verification of meeting-room technology, device-management rules, secure communications, live RF monitoring and post-meeting review where warranted.
What Happens if a Suspicious Device Is Found?
The device may become evidence. Where safe and lawful, its position, connections and surrounding environment should be documented and the response coordinated with security, legal counsel, law enforcement or other authorised stakeholders before unnecessary handling or alteration.
Is TSCM Relevant Only to Government?
No. The same protective-security principles can be relevant to law firms, corporations, critical infrastructure, resources, defence-adjacent organisations and other entities whose sensitive discussions or information could justify the cost of technical surveillance.
Sources and Further Reading
- Australian Government Protective Security Policy Framework – Glossary – Defines ASIO T4 protective-security functions, including technical surveillance countermeasures.
- Australian Government – PSPF Release 2026 now available – Official summary of 2026 PSPF updates, including current/emerging-threat measures and counter-foreign-interference training.
- ASIO / Australian Institute of Criminology – The Cost of Espionage, July 2025 – Current public assessment of espionage and foreign-interference threat levels and expected intensification.
- ASIO NITRO – Recognising Hostile Intelligence Activity – Public guidance on hostile intelligence interest in government, defence, business and other Australian sectors.
- NSI Global – Technical Surveillance Counter Measures – Current NSI TSCM scope, methodology and client sectors.
- NSI Global – Government and Defence TSCM – NSI Global’s current government and high-sensitivity TSCM service positioning.
- NSI Global – Navid Sobbi – Current founder profile and TSCM/counterintelligence credentials.