Skip to content
TSCM Audit

TSCM audit vs bug sweep

The terms get used interchangeably, but they describe different levels of assurance. A bug sweep is a scan for active transmitters; a TSCM audit is a documented, multi-method inspection that also finds the devices a scan cannot see.

The short version

A bug sweep answers one question: is anything transmitting in this room right now? A TSCM audit answers the question you actually care about: is this space compromised — by anything, transmitting or not — and what should we do about it? Modern surveillance devices defeat simple sweeps by design: store-and-forward recorders transmit in bursts or not at all, GSM bugs sleep until called, and hard-wired microphones never emit RF in the first place.

Side by side

DimensionBug sweepTSCM audit
GoalFind devices that are transmitting right nowEstablish, with documentation, whether the space is compromised at all
MethodRF detection, often with handheld equipmentRF spectrum analysis, physical search, NLJD, thermal imaging, network checks
Dormant / switched-off devicesMissedDetected via non-linear junction detection and physical inspection
Hard-wired microphonesMissedCovered by physical inspection of cabling and infrastructure
Network compromise (rogue APs, IoT)Usually out of scopeIn scope via Wi-Fi and network checks
OutputA verbal all-clearA written report: scope, findings, risk assessment, remediation
Use in legal / insurance processesWeak — nothing documentedStrong — evidence preserved and findings documented

When a sweep is enough

There is a legitimate role for the lighter engagement: a pre-meeting sweep of a room that was fully audited recently. If the baseline is clean and access has been controlled since, a targeted RF and physical check immediately before a sensitive meeting is a proportionate, cost-effective control. That is exactly how quarterly corporate audit programmes work: periodic full audits, with sweeps in between. For the lighter engagement, the dedicated TSCM sweep guide explains scope, method, limitations, and when a focused sweep is proportionate.

When only an audit will do

  • First engagement on a site. Without a baseline, a sweep cannot tell you what belongs in the RF environment and what does not.
  • A specific suspicion or suspected leak. You need dormant-device detection, evidence preservation, and a report — not a quick scan that tips off the operator.
  • Legal, regulatory, or insurance context. Litigation support, GDPR or confidentiality obligations, and insurance claims all require documented findings.
  • Sophisticated adversaries. If the plausible attacker is a competitor, a well-funded litigant, or a state-linked actor, assume devices designed to defeat RF-only detection.

For what a full engagement involves step by step, see what is a TSCM audit; for budgeting, the cost guide.

Ready to commission a TSCM audit?

Tell us about your site and concern. You will receive indicative pricing and a named follow-up from TSCM Partners, in confidence.