How Often Should You Sweep?

Quarterly, semi-annual, or event-driven only? Sweep frequency is a risk decision, not a product tier. Here is how to set a cadence you can defend — to the board, to an auditor, and to yourself after an incident.

Last reviewed: 2026-09-03

The window of vulnerability is the unit of decision

A sweep is point-in-time assurance: it tells you the room was clean on the day. The period between sweeps is your accepted exposure window — a device placed the day after an inspection collects until the next one. Frequency-setting is therefore a single question: how long are you willing to let a successful placement run?

That question has different answers for different rooms, which is why mature programmes tier their spaces rather than applying one cadence to everything. It is also why re-inspection matters after any find or suspicion: it converts an unbounded exposure into a bounded one, which changes both the damage assessment and, where personal data is involved, the notification analysis.

A tiering model that survives contact with budgets

Tier one — the board room, the deal room, and executive offices in organisations facing live competitive, litigation or state-linked threat — commonly runs quarterly, supplemented by pre-meeting checks before the most sensitive sessions. Tier two — sensitive but lower-tempo spaces such as legal and HR rooms — commonly runs semi-annually. Tier three spaces are covered by trigger events only.

Event-driven sweeps do disproportionate work in every tier: before board and results meetings, during M&A activity, after renovations or office moves, and after contentious departures. An organisation that can afford only a small programme should buy trigger-event coverage of tier one before it buys calendar coverage of anything else.

Making the cadence defensible

Write the tiering and its rationale into the TSCM policy, and revisit it annually against the threat picture: new litigation, new competitors, new jurisdictions, new premises. Keep the dated record of every inspection. When an auditor, insurer or court later asks whether your protection was proportionate, the answer is the documented reasoning plus the operated schedule — not the size of the invoice.

Common questions

Is quarterly sweeping the standard?
Quarterly is a common cadence for the highest-risk spaces — boardrooms and deal rooms in organisations with live competitive or litigation exposure — because it bounds the exposure window at three months. It is not a universal standard. Lower-tempo sensitive spaces commonly run semi-annually, and some organisations legitimately run trigger-event coverage only. The defensible answer comes from your risk assessment, not from a vendor's subscription tier.
Are event-driven sweeps enough on their own?
For some risk profiles, yes — if the triggers are actually defined and wired into the processes where the events surface. The weakness of pure trigger coverage is the placement you never got a signal about; the strength is that it concentrates spend exactly where opportunity and value intersect. Most programmes mature into a hybrid: a thin periodic cadence for tier-one spaces plus rigorous triggers.
What does a sweep actually bound?
A clean professional inspection establishes that the space was free of detectable devices on that date. That bounds your exposure window in two directions: any later find has a known earliest-possible start, and any suspected leak before it has one eliminated vector. That bounded window is often the difference between a manageable disclosure analysis and an unbounded one.

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the US, UK and Europe.

Speak to a specialist