Skip to content
TSCM Audit

What is a TSCM audit?

TSCM stands for technical surveillance countermeasures. A TSCM audit is a professional, systematic inspection of a space — an office, home, vehicle, or network — to detect and document covert surveillance devices and the vulnerabilities that allow them.

The definition, in plain terms

Technical surveillance countermeasures (TSCM) is the discipline of detecting, locating, and neutralising illicit eavesdropping. A TSCM audit applies that discipline to your specific environment: trained specialists use professional equipment to search a defined area for covert listening devices, hidden cameras, GPS trackers, and compromised electronics, then report what they found and how to fix it.

The word audit matters. Unlike an informal “bug sweep”, an audit is methodical and documented: it has a defined scope, a repeatable method, and a written report you can act on — and, if necessary, put in front of a board, an insurer, or a court.

What the audit actually involves

A professional TSCM audit layers several detection methods, because no single technique finds every device:

  • RF spectrum analysis. A broadband survey of the radio spectrum identifies active transmitters: GSM and LTE bugs, Wi-Fi and Bluetooth implants, and burst transmitters that only key up occasionally.
  • Physical inspection. A hands-on search of furniture, fixtures, power sockets, cabling, ceiling and floor voids, and gifts or items introduced by third parties.
  • Non-linear junction detection (NLJD). Specialist equipment that finds semiconductor electronics even when the device is switched off, dormant, or out of battery — the threats a purely RF-based sweep cannot see.
  • Thermal imaging and lens detection. Thermal cameras reveal powered electronics behind surfaces; optical lens detectors find pinhole cameras.
  • Wi-Fi and network checks. Identification of rogue access points, unknown devices on the network, and cyber-adjacent weaknesses that let an attacker listen without planting hardware at all.
  • Documented reporting. A written record of what was inspected, what was found, the assessed risk, and prioritised remediation steps.

Who needs one

Demand comes from two directions. Organisations commission corporate TSCM audits to protect boardrooms, deal negotiations, intellectual property, and regulated information — increasingly as a standing quarterly programme rather than a one-off. Individuals commission private TSCM audits of homes, vehicles, and venues when they have concrete reason to believe their privacy is compromised — often during disputes, separations, or periods of public attention.

What a good audit is not

Be wary of providers who wave a handheld “bug detector” around for twenty minutes and declare the room clean. Consumer gadgets cannot detect dormant devices, hard-wired microphones, or network-level compromise, and a scan without a report leaves you with nothing actionable. A professional engagement uses laboratory-grade equipment — a serious TSCM kit represents an investment well into six figures — and always ends in documentation. We cover how to compare providers in TSCM audit vs bug sweep.

What it costs and how often to do it

Pricing scales with the size of the site and the complexity of its electronic environment — see the TSCM audit cost guide for current benchmarks. Frequency depends on risk: quarterly for boardrooms and other high-value rooms, annually as a baseline for general offices, and ad hoc before sensitive meetings or after suspicious events. The TSCM audit checklist helps you decide what to include in scope.

Ready to commission a TSCM audit?

Tell us about your site and concern. You will receive indicative pricing and a named follow-up from TSCM Partners, in confidence.