By Navid Sobbi, Founder and CEO, NSI Global
Technical Surveillance Counter Measures—or TSCM—is the disciplined process of finding, assessing and reducing technical surveillance risks in places where sensitive information is discussed, displayed, stored or transmitted. It is often called a bug sweep, but a professional TSCM survey is broader than searching for a radio signal.
A capable survey examines the environment as a system. It considers physical access, unusual electronics, radio-frequency activity, non-transmitting devices, telephone and network infrastructure, acoustic or optical exposure, and the circumstances in which an adversary could obtain or retrieve information. The methods are selected for the site and threat; no single instrument can provide an “all clear.”
For organisations, the practical objective is not a theatrical search for gadgets. It is a documented assessment that identifies suspicious devices or anomalies, explains technical vulnerabilities, records the limits of the work and gives decision-makers a prioritised plan to reduce exposure.
What Is TSCM?
Technical Surveillance Counter Measures is a specialist branch of protective security concerned with covert technical surveillance. Depending on context, the work may be described as an electronic bug sweep, security sweep, electronic surveillance detection or technical security inspection.
The Australian Government’s Protective Security Policy Framework recognises technical surveillance countermeasures within the protective-security work performed by ASIO’s T4 capability. That does not mean every commercial inspection is a government survey. It does confirm that TSCM sits within protective security—not simply electronics repair or routine cyber security.
NSI Global’s TSCM services address physical, electronic and communications environments. A properly scoped engagement may examine offices, boardrooms, meeting venues, executive residences, vehicles, vessels, aircraft, telephone services and related infrastructure.
TSCM Is Not the Same as Cyber Security
Cyber security primarily protects digital systems, identities and networks. TSCM primarily addresses technical surveillance in physical and communications environments. The disciplines overlap when a device is network-connected, a conferencing system is compromised, a hardware implant is present or suspected spyware is part of the threat.
A room can have strong firewalls and still contain an audio recorder. Conversely, an RF sweep can be clear while an executive’s phone is compromised by malware. High-risk matters may therefore require TSCM, cyber investigation and forensic spyware or malware analysis under one coordinated plan.
How Covert Surveillance Devices Collect Information
Not every device behaves like a continuously transmitting “bug.” Understanding the collection method determines which inspection techniques are relevant.
| Threat behaviour | Examples | Detection implication |
| Transmit continuously | Covert microphones, cameras or cellular devices sending live data | RF analysis may identify activity if the signal is within the instrument’s coverage and observable during the survey |
| Transmit intermittently | Burst, scheduled or remotely activated transmitters | A short survey may not coincide with transmission; longer observation or monitoring may be justified |
| Store locally | Audio recorders or cameras using internal memory | No radio signal may be present; physical inspection, non-linear junction evaluation or thermal analysis may be more relevant |
| Use legitimate infrastructure | Compromised routers, phones, conferencing equipment or network devices | Baseline comparison, network and line analysis, configuration review and physical examination may be required |
| Track movement | Concealed GNSS/GPS or cellular trackers | Vehicle or asset inspection must account for concealment, power, placement and possible scheduled reporting |
Other risks include hidden optical cameras, keystroke-capture hardware, unauthorised wiring, telephone interception, modified charging or power equipment and surveillance functions concealed within otherwise legitimate electronics.
The key lesson is simple: the absence of an obvious RF transmission is not evidence that an environment is free from surveillance.
What a Professional TSCM Survey Actually Includes
The survey plan should be driven by a threat assessment, the site, the information at risk and the time available. Not every technique is required in every engagement, but the provider should be able to explain what is included, why it is included and what remains outside scope.
1. Secure Intake and Threat Definition
Planning begins before the team arrives. The provider should establish who may have had access, what information appears compromised, which rooms and systems matter, what building work or contractor activity has occurred, and whether a legal or safety issue is already active.
If active compromise is suspected, do not discuss the proposed sweep inside the affected space or through a device that may be involved. NSI Global advises clients to make initial contact from a secure location using a verified channel.
2. Environmental Baseline and Site Control
The team records the normal environment: approved devices, wireless services, room use, access points, cabling routes and surrounding RF activity. A baseline helps distinguish expected signals and equipment from anomalies, but it is only as reliable as the information available.
Operational security matters. The survey schedule, team arrival, access and internal communications should be restricted to those who need to know. A predictable or widely advertised sweep can give an insider time to remove or disable equipment.
3. Visual and Physical Examination
Technicians inspect furniture, fixtures, electronics, cable routes, ceiling or service voids, power supplies and items that appear altered, duplicated or out of place. The objective is not indiscriminate dismantling. It is a systematic comparison between what should be present and what is actually present.
This layer matters because a locally recording device may never emit a detectable signal. It also helps identify security weaknesses—uncontrolled keys, exposed cabling, unlogged contractor access or unapproved equipment—even where no covert device is located.
4. Radio-Frequency Spectrum Analysis
RF analysis examines the observable spectrum for signals that warrant identification or localisation. The operator must distinguish authorised services, neighbouring emitters, transient activity and possible surveillance transmissions.
Frequency range alone does not establish detection performance. Results also depend on sensitivity, antennas, bandwidth, dwell time, signal behaviour, the physical environment and the operator’s interpretation. A transmitter outside the receiver’s frequency coverage, inactive during observation or too weak at the measurement point will not be directly observed by that instrument.
5. Non-Linear Junction Evaluation
A non-linear junction detector can assist in locating semiconductor junctions associated with electronics, including devices that are switched off or not transmitting. It does not identify every response as a bug. Legitimate electronics, corrosion and building materials can also produce responses, so anomalies require interpretation and, where justified, closer examination.
6. Thermal and Optical Examination
Thermal imaging may reveal an unexpected heat pattern, concealed power source or electronic activity that deserves further inspection. Optical methods can assist with the search for camera lenses or unusual apertures. Neither method is conclusive alone. Thermal sensitivity, line of sight, surface materials, operating state and surrounding equipment all affect what can be seen.
7. Telephone, Cabling, Network and Power Analysis
Where the threat and authorisation justify it, the survey may include digital, analogue and VoIP services, network infrastructure, wiring and carrier-current paths. The objective is to identify unexplained connections, anomalies or security weaknesses—not to assume that every unusual reading is malicious.
This boundary should be agreed in writing. A room inspection does not automatically include cloud administration, endpoint forensics, the building’s entire data network or every telecommunications service.
8. Findings, Preservation and Reporting
If a suspicious device is located, the response changes from detection to evidence-aware handling. The team should document its position and condition, control access and coordinate with authorised management, counsel or law enforcement. Powering on, removing or dismantling it without a plan may change data, trigger a response or compromise the later investigation.
The final report should state the scope, dates, surveyed areas, methods, relevant observations, located devices or anomalies, identified vulnerabilities, actions taken, limitations and prioritised recommendations.
NSI Global’s Published Router-Camera Case
NSI Global first published this field example in 2018. A router in a CEO’s office appeared to operate normally and did not produce a suspicious result during the initial transmission, network and physical checks described in the account.
Thermal examination showed an unusual pattern inconsistent with the expected heat signature of that type of device. A subsequent controlled inspection located a self-contained high-definition pinhole video recorder inside the case, with a 128 GB micro-SD card. Its position provided a view toward the CEO’s working area, including the keyboard and screen.
The value of this example is not that thermal imaging always finds a hidden camera. It is that layered methods can expose an anomaly that a transmission-only approach may miss. The thermal result prompted inspection; the physical examination established what was present.
Read the original NSI Global case article: Many Bugs Go Undetected by Standard Bug Sweeps.
What a Negative TSCM Survey Means—and Why Scope Matters
A negative TSCM result is only meaningful when considered alongside the scope of the inspection. It means no covert device or reportable anomaly was identified within the areas examined, methods applied and observation period. It does not mean the entire premises are guaranteed free from surveillance.
The objective should be to commission a survey broad enough to address your organisation’s risk profile—not simply obtain a negative result from a limited inspection. A boardroom-only sweep, for example, cannot establish the security of executive offices, adjoining spaces or supporting infrastructure excluded from the work.
Before commissioning, the scope should account for:
- Where sensitive information is exposed: Include the relevant meeting rooms, executive workspaces, adjacent areas and infrastructure—not just the location where surveillance is first suspected.
- How surveillance could occur: Select complementary physical and technical examination methods appropriate to the credible threats. RF scanning alone does not cover every surveillance mechanism; some devices store recordings locally without transmitting. UK NACE technical guidance, recording-device guidance.
- When surveillance could operate: Consider whether the inspection period adequately addresses intermittent activity and whether sensitive meetings warrant live monitoring.
- What access is required: Resolve permissions for relevant rooms, ceiling voids, equipment and third-party infrastructure before the inspection. Inaccessible areas should remain explicit limitations.
- What happens afterwards: Assess whether contractor access, equipment changes or continuing exposure justify follow-up inspections, stronger access controls or targeted monitoring.
Broader scope does not mean inspecting everything indiscriminately. It means matching coverage to the sensitivity of your information, credible surveillance opportunities and the consequences of compromise.
NSI Global can help you establish those priorities before work begins. The resulting report should distinguish what was examined, what remains unresolved and which further measures are warranted—so a negative finding supports an informed security decision, rather than a false sense of assurance.
When Should an Organisation Commission TSCM?
There is no universal interval that suits every organisation. TSCM timing should reflect the value of the information, the credible adversary, access opportunities, environmental change and the consequence of compromise.
Common trigger events include:
- Unexplained leakage of commercial, legal, government or operational information
- M&A, capital raising, tender, litigation or major negotiation activity
- Sensitive board, executive, legal or government meetings
- Building work, tenancy changes or unescorted contractor access
- Executive appointment, departure or elevated insider-risk concern
- Visits by high-risk delegations or counterparties
- A suspicious object, signal, wiring change or unexplained device behaviour
- Threat intelligence indicating targeting of the organisation or sector
A baseline survey, risk-based recurring inspections and event-triggered work serve different purposes. Live meeting or continuous monitoring may supplement periodic inspections in selected environments, but monitoring does not replace physical inspection and cannot observe every form of surveillance.
NSI Global provides live TSCM meeting monitoring and continuous remote TSCM monitoring for appropriately scoped high-risk environments.
Environments That Require Different TSCM Plans
Corporate Offices, Boardrooms and Meeting Venues
Corporate surveys should consider boardrooms, executive offices, adjoining spaces, reception and contractor routes, communications equipment and rooms used for legal or transaction work. A device does not need to sit in the centre of the boardroom to collect information from it. Read more about corporate office and boardroom TSCM.
Executive Residences and Home Offices
Where senior personnel routinely handle corporate information at home, the residence may become part of the organisation’s information-security boundary. Any inspection must be lawfully authorised, sensitively scoped and proportionate to the business risk. NSI Global’s corporate residence TSCM page describes its executive home-office service. Separate residential or personal-safety matters follow NSI Global’s published referral requirements.
Vehicles, Vessels and Aircraft
Mobile environments combine many legitimate transmitters, complex wiring, power systems and restricted access spaces. The plan must distinguish expected platform emissions from anomalies and address both tracking and in-cabin collection. See NSI Global’s vehicle, vessel and aircraft TSCM service.
Government and Classified Environments
Australian Government entities operate within the Protective Security Policy Framework and other controlling requirements. The 2026 PSPF prescribes protective-security obligations across six domains for applicable Commonwealth entities. TSCM scope, personnel, equipment, information handling and reporting must align with the relevant authority, facility and classification.
“SCIF” should not be used as a generic name for any secure meeting room. A Sensitive Compartmented Information Facility is a specific term associated with accredited facilities and controlled information. Private organisations can build secure discussion facilities, but their design and description should be tied to the applicable threat model, standards and accreditation—not borrowed terminology. NSI Global provides government and advanced TSCM support for authorised engagements.
M&A and Supply-Chain Activity
TSCM can protect defined meetings, deal rooms, temporary venues and executive movements during a transaction. It does not replace cyber due diligence, personnel controls or supplier assurance. The security plan should identify who can access the environment, which equipment enters it and what changes between pre-transaction, signing and integration phases.
What to Do If You Suspect a Listening Device
Do not announce the suspicion in the affected room or use a device that may be involved to arrange the response. Move to a location and communication channel you have reason to trust.
Then:
- Restrict knowledge of the concern. Avoid alerting a suspected insider or device operator.
- Preserve the environment. Do not move, charge, activate, disconnect or dismantle a suspicious item unless immediate safety requires it.
- Record observations carefully. Note who found the item, when and under what conditions without repeatedly handling it.
- Engage authorised specialists. Coordinate TSCM, legal, security and, where appropriate, law-enforcement advice.
- Plan communications. Separate verified facts from assumptions before informing clients, staff, insurers or external parties.
Surveillance-device laws differ by jurisdiction and context. In NSW, the Surveillance Devices Act 2007 regulates listening, optical, tracking and data-surveillance devices, including their installation, use and communication of recordings. Obtain legal advice before taking investigative or evidentiary action.
Make TSCM Part of the Security System
TSCM is strongest when it connects to physical security, cyber security, personnel security and governance. A survey can locate a weakness, but the organisation must close it and keep it closed.
The wider programme should address:
- Access control, visitor management and contractor supervision
- Asset inventories and approval of electronics in sensitive rooms
- Secure meeting protocols and personal-device rules
- Change control after maintenance, fit-outs or equipment replacement
- Cyber monitoring and forensic escalation for connected devices
- Staff reporting routes for suspicious objects or information leakage
- Evidence and incident-response procedures if a device is found
- Risk-based inspection triggers and ownership at executive level
These controls can be incorporated into a broader Security Master Plan. The purpose is to reduce the opportunity to install surveillance, improve the chance of detecting change and ensure that findings lead to accountable remediation.
What to Require in the TSCM Report
A decision-useful report should contain more than an “all clear.” Ask for:
- The authorised scope and areas not accessed
- The inspection date, duration and relevant environmental conditions
- The methods used and the purpose of each method
- Approved devices, signals or systems used as the baseline
- Located items, anomalies and vulnerabilities, supported by photographs where appropriate
- Evidence-handling records if a suspicious device was preserved
- Technical limitations and residual risk
- Prioritised corrective actions, owners and recommended review points
Where litigation is possible, counsel should define the instruction and preservation pathway early. A TSCM report is not automatically admissible because it is detailed or technically sophisticated. Admissibility and weight are determined by the relevant court or tribunal. NSI Global’s Litigation Support practice can support appropriately instructed matters.
How to Choose a TSCM Provider
This guide is not intended to duplicate a full procurement assessment, but five questions quickly separate a defined professional service from an equipment demonstration:
- What threat and site information will you obtain before deciding the method?
- Which physical, RF, electronic, communications and network layers are included—and excluded?
- How will you deal with non-transmitting, intermittent or concealed devices?
- What happens if a suspicious device or anomaly is found?
- Will the report state coverage, limitations, residual risk and recommendations?
Personnel vetting and equipment access matter, particularly in government or classified environments, but neither replaces competence, a suitable methodology and controlled reporting. Equipment specifications should be matched to the threat rather than used as a guarantee.
How NSI Global Approaches TSCM
NSI Global’s public service pages describe an in-house TSCM practice led by founder Navid Sobbi, with more than two decades of counter-surveillance work in Australia and internationally. The published methodology covers visual, electronic and physical examination, with techniques such as RF spectrum analysis, non-linear junction evaluation, thermal analysis, telephone and network analysis, VoIP examination, covert-video inspection and carrier-current analysis selected according to scope.
The firm’s unique TSCM capabilities page provides additional detail on these layers. Capability does not mean every method is deployed on every site or that every device can be detected. The value lies in defining the threat, using complementary methods, documenting the work and explaining what the result does—and does not—establish.
If your organisation suspects active compromise, contact NSI Global from a secure location outside the affected environment. For planned protection, establish the threat, authorised scope and timing before discussing equipment or scheduling the inspection.
Frequently Asked Questions
Is TSCM Just Another Name for a Bug Sweep?
“Bug sweep” is the common term, but professional TSCM is broader. It may combine threat assessment, visual and physical search, RF analysis, non-linear junction evaluation, thermal examination, telephone or network analysis, evidence-aware handling and vulnerability reporting.
Can a TSCM Sweep Detect Every Listening Device?
No. Detection depends on the device, its operating state, concealment, frequency, power, timing, the environment, authorised access and the methods used. A professional report should state these limitations rather than promise a surveillance-free environment.
Can an RF Scan Find a Recorder That Stores Data Locally?
Not through its recording function if the device emits no observable RF signal. Other methods—physical inspection, non-linear junction evaluation, thermal or optical examination—may assist, depending on the device and environment.
How Often Should a Business Conduct a TSCM Survey?
There is no universal schedule. Frequency should reflect information value, credible threat, access and change, consequences and existing controls. Many organisations combine a baseline inspection with risk-based recurring and event-triggered work.
How Long Does a TSCM Sweep Take?
It may take hours or several days depending on the premises, number of rooms, equipment density, communications scope, operating constraints and required observation period. A provider should scope duration after understanding the environment.
Does TSCM Include Mobile-Phone Spyware Detection?
Not automatically. Device compromise is normally a digital-forensics or mobile-security workstream. If both physical surveillance and spyware are suspected, the two investigations should be coordinated without assuming that one replaces the other.
What Does an “All Clear” Mean After a Sweep?
It should mean only that no reportable device or anomaly was identified within the documented scope and conditions. It is not a guarantee about future placement, inaccessible areas, inactive devices or threats outside the methods used.
Should a Suspicious Device Be Removed Immediately?
Not without a safety and evidence plan. Handling or powering a device may change evidence or alert an operator. Restrict access, avoid discussing it nearby and obtain authorised technical, legal and, where appropriate, law-enforcement advice.
Sources and Further Reading
- Australian Government Protective Security Policy Framework—Release 2026
- Protective Security Policy Framework Glossary—T4 and TSCM
- NSW Surveillance Devices Act 2007
- UK National Protective Security Authority—Countering Espionage and Foreign Interference
- NSI Global—Technical Surveillance Counter Measures
- NSI Global—Many Bugs Go Undetected by Standard Bug Sweeps
This article provides general educational information. It is not legal advice, a substitute for an incident-specific threat assessment or a guarantee that a particular device will be detected. TSCM scope, legal authority, evidence handling and protective-security obligations depend on the environment, jurisdiction, threat and engagement terms.