TSCM audit vs bug sweep
The terms get used interchangeably, but they describe different levels of assurance. A bug sweep is a scan for active transmitters; a TSCM audit is a documented, multi-method inspection that also finds the devices a scan cannot see.
The short version
A bug sweep answers one question: is anything transmitting in this room right now? A TSCM audit answers the question you actually care about: is this space compromised — by anything, transmitting or not — and what should we do about it? Modern surveillance devices defeat simple sweeps by design: store-and-forward recorders transmit in bursts or not at all, GSM bugs sleep until called, and hard-wired microphones never emit RF in the first place.
Side by side
| Dimension | Bug sweep | TSCM audit |
|---|---|---|
| Goal | Find devices that are transmitting right now | Establish, with documentation, whether the space is compromised at all |
| Method | RF detection, often with handheld equipment | RF spectrum analysis, physical search, NLJD, thermal imaging, network checks |
| Dormant / switched-off devices | Missed | Detected via non-linear junction detection and physical inspection |
| Hard-wired microphones | Missed | Covered by physical inspection of cabling and infrastructure |
| Network compromise (rogue APs, IoT) | Usually out of scope | In scope via Wi-Fi and network checks |
| Output | A verbal all-clear | A written report: scope, findings, risk assessment, remediation |
| Use in legal / insurance processes | Weak — nothing documented | Strong — evidence preserved and findings documented |
When a sweep is enough
There is a legitimate role for the lighter engagement: a pre-meeting sweep of a room that was fully audited recently. If the baseline is clean and access has been controlled since, a targeted RF and physical check immediately before a sensitive meeting is a proportionate, cost-effective control. That is exactly how quarterly corporate audit programmes work: periodic full audits, with sweeps in between. For the lighter engagement, the dedicated TSCM sweep guide explains scope, method, limitations, and when a focused sweep is proportionate.
When only an audit will do
- First engagement on a site. Without a baseline, a sweep cannot tell you what belongs in the RF environment and what does not.
- A specific suspicion or suspected leak. You need dormant-device detection, evidence preservation, and a report — not a quick scan that tips off the operator.
- Legal, regulatory, or insurance context. Litigation support, GDPR or confidentiality obligations, and insurance claims all require documented findings.
- Sophisticated adversaries. If the plausible attacker is a competitor, a well-funded litigant, or a state-linked actor, assume devices designed to defeat RF-only detection.
For what a full engagement involves step by step, see what is a TSCM audit; for budgeting, the cost guide.