Why the risk is usually missing
Risk registers inherit their categories from IT security frameworks and insurance questionnaires, both of which are strong on networks and weak on rooms. The result is an organisation that models phishing in three variants but has never written down the risk that its quarterly results, deal terms or litigation strategy are intercepted where they are actually decided: out loud, in a known room, on a predictable schedule.
Writing the entry is not an academic exercise. An owned, scored risk is what unlocks budget, defines the control, and — under frameworks from NIS2 to ISO 27001 — is itself the first compliance artefact.
The entry, ready to adapt
Risk statement: unauthorised technical surveillance (audio, video, or data interception devices) of spaces where sensitive information is discussed, resulting in loss of confidential information, regulatory breach, litigation disadvantage, or market disadvantage.
Threat sources: competitors and their agents, insiders and departing employees, activist or criminal actors, state-linked collection where the sector attracts it, and opportunistic placement by third parties with premises access — contractors, cleaners, visitors, and fit-out crews. Vulnerability: sensitive discussions concentrated in known, predictable locations; premises access by third parties; conference and AV hardware with standing microphones; no current detection capability.
Impact should be anchored to your own information: what would leakage of a board pack, a deal price, or a settlement position cost? Likelihood is genuinely uncertain — detection data is scarce because unswept organisations cannot observe the event — so score it honestly as low-frequency, high-impact, and note that the absence of evidence is not evidence of absence when no detection control exists.
Controls and residual risk
Existing controls to record: physical access control, visitor management, clear desk policy, meeting hygiene. New control: a documented TSCM programme — periodic professional inspection of scoped spaces plus trigger-event sweeps, per the TSCM policy. Record the owner, the cadence, and the reporting line into the audit or risk committee.
Residual risk stays non-zero and should say so: detection is point-in-time, and the window between inspections is the accepted exposure. That honest framing is what makes the entry credible to auditors — and what justifies the cadence you chose.