Why a policy, not just sweeps
An unwritten counter-surveillance practice fails in three predictable ways. It skips the periods of highest risk because no trigger events are defined. It produces no evidence, so it cannot support a compliance declaration, an insurance question, or a trade secret claim. And it dies when its informal owner changes role.
A one-page policy fixes all three. It is also what turns the spend into a control that regulators and auditors recognize: under NIST 800-53 RA-6, ISO 27001 and the SEC's Item 106 disclosure frame alike, the documented, operated control is what counts — not the activity.
Scope: name the spaces, not the building
The most common policy failure is scoping to "the premises". Sweep costs scale with area, so an unscoped policy becomes unaffordable and is quietly abandoned. Scope instead to the rooms where sensitive information is actually spoken or displayed: the board room, executive offices, the M&A or deal room, legal and HR meeting rooms, R&D discussion spaces, and vehicles used for sensitive calls.
For each listed space, record why it is in scope — the information class discussed there — so the list can be defended and revisited. Everything else in the building is covered by ordinary physical security, not by the TSCM programme.
Roles, confidentiality and handling a find
Name a single accountable owner — typically the head of security, the CISO, or in smaller organisations the general counsel or company secretary. Keep the circle of knowledge deliberately small: sweeps announced widely are sweeps defeated, and insider involvement in device placement is common enough that discretion is a design requirement, not paranoia.
The policy must say what happens on a find before a find happens. Typically: do not touch or discuss the device in the room; preserve the scene; notify the owner through an out-of-band channel; engage counsel early because interception is criminal conduct in most jurisdictions; decide deliberately between removal, monitoring, and law-enforcement referral; and assess notification duties — a device that captured personal data can trigger breach obligations, and one that captured material information can trigger disclosure analysis.