Technical Surveillance in the Risk Register

Most enterprise risk registers carry cyber intrusion in detail and say nothing about the interception of spoken information. Here is a complete, adaptable register entry: threat, vulnerability, impact, scoring, controls and owner.

Last reviewed: 2026-09-03

Why the risk is usually missing

Risk registers inherit their categories from IT security frameworks and insurance questionnaires, both of which are strong on networks and weak on rooms. The result is an organisation that models phishing in three variants but has never written down the risk that its quarterly results, deal terms or litigation strategy are intercepted where they are actually decided: out loud, in a known room, on a predictable schedule.

Writing the entry is not an academic exercise. An owned, scored risk is what unlocks budget, defines the control, and — under frameworks from NIS2 to ISO 27001 — is itself the first compliance artefact.

The entry, ready to adapt

Risk statement: unauthorised technical surveillance (audio, video, or data interception devices) of spaces where sensitive information is discussed, resulting in loss of confidential information, regulatory breach, litigation disadvantage, or market disadvantage.

Threat sources: competitors and their agents, insiders and departing employees, activist or criminal actors, state-linked collection where the sector attracts it, and opportunistic placement by third parties with premises access — contractors, cleaners, visitors, and fit-out crews. Vulnerability: sensitive discussions concentrated in known, predictable locations; premises access by third parties; conference and AV hardware with standing microphones; no current detection capability.

Impact should be anchored to your own information: what would leakage of a board pack, a deal price, or a settlement position cost? Likelihood is genuinely uncertain — detection data is scarce because unswept organisations cannot observe the event — so score it honestly as low-frequency, high-impact, and note that the absence of evidence is not evidence of absence when no detection control exists.

Controls and residual risk

Existing controls to record: physical access control, visitor management, clear desk policy, meeting hygiene. New control: a documented TSCM programme — periodic professional inspection of scoped spaces plus trigger-event sweeps, per the TSCM policy. Record the owner, the cadence, and the reporting line into the audit or risk committee.

Residual risk stays non-zero and should say so: detection is point-in-time, and the window between inspections is the accepted exposure. That honest framing is what makes the entry credible to auditors — and what justifies the cadence you chose.

Register entry fields, in order

  1. 01Risk ID and title — technical surveillance / eavesdropping of sensitive spaces
  2. 02Risk statement — as drafted above, tuned to your information classes
  3. 03Threat sources — competitor, insider, criminal, state-linked, opportunistic
  4. 04Vulnerability — predictable rooms, third-party access, standing microphones, no detection
  5. 05Inherent impact — tied to named information: results, deals, disputes, IP
  6. 06Inherent likelihood — low-frequency, high-impact; note detection blindness
  7. 07Existing controls — access control, visitor management, meeting hygiene
  8. 08Treatment — TSCM programme: scoped spaces, cadence, trigger events, provider standard
  9. 09Owner and review date — named role, annual review minimum
  10. 10Residual risk — inter-sweep window explicitly accepted

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the UK, Europe and the US.

Speak to a specialist