The window of vulnerability is the unit of decision
A sweep is point-in-time assurance: it tells you the room was clean on the day. The period between sweeps is your accepted exposure window — a device placed the day after an inspection collects until the next one. Frequency-setting is therefore a single question: how long are you willing to let a successful placement run?
That question has different answers for different rooms, which is why mature programmes tier their spaces rather than applying one cadence to everything. It is also why re-inspection matters after any find or suspicion: it converts an unbounded exposure into a bounded one, which changes both the damage assessment and, where personal data is involved, the notification analysis.
A tiering model that survives contact with budgets
Tier one — the board room, the deal room, and executive offices in organisations facing live competitive, litigation or state-linked threat — commonly runs quarterly, supplemented by pre-meeting checks before the most sensitive sessions. Tier two — sensitive but lower-tempo spaces such as legal and HR rooms — commonly runs semi-annually. Tier three spaces are covered by trigger events only.
Event-driven sweeps do disproportionate work in every tier: before board and results meetings, during M&A activity, after renovations or office moves, and after contentious departures. An organisation that can afford only a small programme should buy trigger-event coverage of tier one before it buys calendar coverage of anything else.
Making the cadence defensible
Write the tiering and its rationale into the TSCM policy, and revisit it annually against the threat picture: new litigation, new competitors, new jurisdictions, new premises. Keep the dated record of every inspection. When an auditor, insurer or court later asks whether your protection was proportionate, the answer is the documented reasoning plus the operated schedule — not the size of the invoice.