TSCM Risk Assessment
A TSCM risk assessment is the structured evaluation of your exposure to technical surveillance — which spaces matter, who plausibly targets them, how devices get in, and what proportionate control looks like. It is the governance document the rest of the programme stands on.
What it is — and what it is not
An assessment is analysis, not inspection. It answers the questions that decide everything downstream: which rooms and vehicles carry information whose loss would genuinely hurt; which threat sources are plausible for your sector and situation; which access routes — contractors, visitors, fit-outs, leavers, hired venues — could introduce a device; and what inspection cadence and trigger events are proportionate to all of that.
A sweep, by contrast, is the point-in-time technical inspection the assessment prescribes. Organisations that buy sweeps without an assessment usually sweep the wrong spaces on the wrong schedule — and cannot show a regulator, auditor or court why the schedule was what it was.
What the assessment covers
- —Information mapping — what is discussed aloud, where, on what schedule, and what its loss costs
- —Space inventory — boardrooms, executive offices, deal and legal rooms, vehicles, and regular external venues
- —Threat analysis — competitor, insider, criminal, state-linked and opportunistic sources, weighted for your sector
- —Access route review — contractor and visitor flows, fit-out history, conferencing and AV estate, leaver exposure
- —Control gap analysis — what existing physical security does and does not cover
- —Cadence and trigger design — tiered inspection frequency with defined unscheduled triggers
- —Risk register entry and policy skeleton — governance artefacts ready to adopt
What you receive
A written report you can put in front of an audit committee: scope and rationale, threat assessment, prioritised findings, a tiered cadence recommendation with trigger events, a ready-to-adopt risk register entry, and — where commissioned — a baseline inspection result for the highest-priority spaces. The report is yours; nothing in it obliges you to buy inspections from us or anyone else.
Who commissions this
Boards preparing internal-control declarations, security leads building a NIS2 or ISO 27001 evidence base, general counsel protecting trade secret status and litigation posture, deal teams entering M&A processes, and organisations that have just had the unpleasant thought for the first time. Discretion is standard: mutual NDA before scoping, out-of-hours site work where needed.
Common questions
- What does a TSCM risk assessment deliver?
- A written report: the spaces in scope and why, the threat sources plausible for your sector, the routes by which devices could be introduced, the current control gaps, a recommended inspection cadence with trigger events, and a risk register entry ready to adopt. It is a governance document first — something you can put in front of an audit committee, a regulator, or a court.
- How long does an assessment take?
- For a single site with a defined set of sensitive spaces, typically a day on site plus reporting time. Multi-site and campus assessments scale with the number of distinct environments rather than headcount. The output is usually in your hands within two weeks of the site visit.
- Do you sweep during the assessment?
- The assessment can include a baseline inspection of the highest-priority spaces, and we usually recommend it — it converts the assessment's theoretical exposure window into a bounded one from day one. But the assessment is valuable without it, and combining or separating them is a scoping choice, not a requirement.
- Can the assessment be done discreetly?
- Yes, and it should be. Assessments are routinely conducted under cover of a facilities, insurance or compliance review, out of hours where needed, with a mutual NDA in place before any site detail is exchanged and the circle of knowledge limited to named individuals.
Scope an assessment
A short conversation establishes scope and a fixed price. Assessments run across the UK, Europe and the US.