Running a TSCM Program
The difference between buying sweeps and controlling a risk is governance: a policy, an owned register entry, a defensible cadence, defined triggers, and a line in the committee pack. Each guide below is usable as written.
Writing a TSCM Policy
A TSCM policy turns occasional bug sweeps into a governed control: defined spaces, defined cadence, defined triggers, and records that stand up to auditors, regulators and courts. Here is the full structure, usable as written.
→Technical Surveillance in the Risk Register
Most enterprise risk registers carry cyber intrusion in detail and say nothing about the interception of spoken information. Here is a complete, adaptable register entry: threat, vulnerability, impact, scoring, controls and owner.
→How Often Should You Sweep?
Quarterly, semi-annual, or event-driven only? Sweep frequency is a risk decision, not a product tier. Here is how to set a cadence you can defend — to the board, to an auditor, and to yourself after an incident.
→Trigger Events: When to Sweep Outside the Calendar
Most successful device placements exploit a moment: a fit-out, a departure, a deal. A calendar cadence alone misses them. These are the trigger events a serious programme defines in advance — and why each one earns its place.
→Reporting Surveillance Risk to the Board
Surveillance risk reaches most boards either as silence or as alarmism after an incident. Neither serves governance. Here is a reporting pattern that keeps the control visible, evidenced, and proportionate — in three lines a quarter.
→