Detect · Defeat · Nullify™

Protecting the Spoken Word in Asia™ — Privacy Technical Audits, Bug Sweeping & Counter-Espionage since 1992.

Business counter-espionage sweeps, eavesdropping and hidden camera detection, digital investigations and Cyber TSCM, delivered from Hong Kong across Asia by professionals with over three decades of trusted service. What you say in private is your business; keeping it that way is ours.

The first confidential consultation carries no fee. If you do not need us, we will say so.

35+
Years of counter-espionage practice, pre-dating Risk3's 1992 founding
2
Court systems where we have given expert evidence: Hong Kong & Singapore
4
Home jurisdictions: Hong Kong · Singapore · Japan · Macau
100%
Independent: no hardware sales, no commissions
Strict Confidentiality Expert Witness Experience Fixed, Scoped Quotations Formally Trained TSCM Practitioners Independent Since 1992
Why Clients Call Us

An overheard conversation is never just a conversation.

It is a negotiating position surrendered, a privileged strategy exposed, a succession plan pre-empted. Clients retain Risk3 when the value of what is said in a room exceeds the cost of someone deciding to listen to it, and the devices that listen now cost less than a dinner for two.

One practice, four disciplines: if the sweep finds a device, digital investigations establish what it captured; Cyber TSCM closes the network paths around it; and internet investigations help establish who benefited. Discovery is the beginning. Resolution is the product.

  • A transaction is imminent. Deal terms, valuations and walk-away positions are worth the most in the weeks before signature.
  • Information has already moved. A counterparty, competitor or journalist knew something they could not have known honestly.
  • A dispute is under way. Litigation strategy, shareholder conflict or a contested departure has raised the stakes of every private meeting.
  • A pattern of coincidences. Lost tenders, pre-empted announcements, counterparties always one step ahead.
  • Duty of care. Boards and counsel formalising confidentiality assurance as part of governance, not as an afterthought.
Our Services

Thirteen services. One concern: your privacy.

Ten countermeasures disciplines, then the three investigative services that turn a discovery into an answer. Every engagement is scoped with the red-yellow-green floor plan and delivered by the principal, not a junior technician.

/ 01

Privacy Technical Audits

The full business counter-espionage bug sweep: RF spectrum examination reviewed against known device signatures, physical search of the fabric, conference and telephony systems inspected in place, delivered out of hours by practitioners with three decades of casework.

Explore bug sweeping
/ 05

Home Office & Estate Sweeps

Discreet sweeps of home offices, principal residences, apartments and estates. Executives take the most sensitive conversations home, where formal security is weakest — residential casework demands its own search discipline.

Explore residence sweeps
/ 09

Pre-Move-In Sweeps & Secure Fit-Out

A baseline sweep of new premises before your people and technology arrive: legacy cabling, abandoned equipment, the previous tenant's surprises. And while you build, fit-out consulting — acoustic isolation, cable routing, sound masking, construction-phase inspections — far cheaper designed in than retrofitted.

Explore pre-move-in & fit-out
/ 13

Cyber TSCM

The network security audit, reframed as counter-surveillance: an onsite examination of your infrastructure for rogue devices, compromised conference systems and every exposure that lets a network listen, reported with the risk level of each finding.

Explore Cyber TSCM
From the Casework

Four rooms. Four ways of being overheard.

A chief executive's office, the meeting room where privilege lives, the boardroom's own conference system and the whiteboard a desk clock was watching. Each case is a composite drawn from real engagements — identifying details changed or merged so that no client is identifiable; the device types, the instruments and the outcomes are real.

Thermal ImagerBug SweepingCEO Office

The wall socket that ran warm.

A sweep of a chief executive's office began, as Risk3 sweeps of powered fixtures do, before any panel was opened: a pass of the room with a thermal imager. A two-gang wall socket — with nothing plugged into it — showed a distinct hotspot on its centre-right side: the signature of electronics drawing power where no electronics should be. Behind the faceplate sat a GSM audio device, wired into the mains and transmitting on demand to anyone who dialled it.

Read the full case

Spectrum AnalyserRF Spectrum AnalysisIn-House Counsel

Consumer-grade hardware, professional-grade damage.

The meeting room used by a corporation's in-house legal team — the room where privilege lives — was swept as part of a first engagement. A countermeasures spectrum analyser capturing the full RF environment flagged a transmission that did not belong: a consumer-grade RF device, the kind sold openly online for the price of a taxi ride, radiating from within the room.

Read the full case

Spectrum Analyser + ThermalBoardroomConference System

The conference table that was always live.

The boardroom's own table microphones — legitimate, installed, invoiced — turned out to be the device. A countermeasures spectrum analyser identified a continuous wireless carrier leaving the room at a strength consistent with reception well beyond the building line, persisting when the conference system showed itself as off. The thermal imager agreed: the table's microphone modules were warm at rest, permanently energised and permanently transmitting whatever the room said.

Read the full case

Comet Lens DetectorHidden Camera DetectionProject Room

The desk clock that watched the whiteboard.

An unfamiliar digital clock had appeared in a restricted project room — helpful, unremarkable, and facing the whiteboard where the deal structure was drawn every morning. A Wi-Fi protocol analyser flagged the first thread: a previously unknown device on the air, associating with the office network; checks on the network side confirmed a session with an external cloud service that no inventory could explain.

Read the full case

Explore the full casework library

Fifteen cases, including the pen nobody claimed, the mirror that faced the wrong way and the rooms that leaked without a bug.

How Best to Retain Us

Bring a floor plan. Three colours do the rest.

Mark any floor plan in three colours before the first call. The colours become the quotation: fees concentrate where the risk concentrates, and travel is at cost. Send the marked plan by Signal, not the mail system you may be worried about, and always call away from the suspected area, on a device you trust.

Red — mandatory. Where a loss would be unrecoverable: the boardroom, the deal room, the principal's study. Swept every visit and priced first.

Yellow — second priority. The spaces that hear the red rooms: adjoining offices, service voids, reception and the conference systems in between.

Green — tertiary. Covered as time allows, or rotated across a scheduled programme so nothing goes permanently unexamined.

Secure First Contact

Scan to message us

Signal or WhatsApp · +852 9103 1852. The first confidential consultation is free, and if you do not require our services we will say so.

QR code: scan to message Risk3 Consulting on Signal

Signal

+852 9103 1852

Open chat
QR code: scan to message Risk3 Consulting on WhatsApp

WhatsApp

+852 9103 1852

Open chat

Prefer to write? Use the enquiry form

Why Risk3

An intelligence discipline, delivered as a professional service.

Risk3 Consulting Limited is an independent consultancy: we sell no equipment, install no systems and take no commissions. The person who answers your first call is the person who conducts the work, with over thirty years of continuous practice behind the instrumentation. Principal: Alan Jeffries, in Hong Kong since 1992; Japan and Singapore since 1993; Macau since the 1990s.

The Instrumentation We Deploy
Risk3 technology partners: REI, Audiotel International, JJN Digital, Shearwater, Selcom Security, FLIR, Fluke, Berkeley Varitronics, Electro-Metrics, Aaronia AG

We buy at market price and take nothing from any manufacturer.

Principal-led, every time

No junior technicians, no subcontractors. Continuity from first contact to final report.

Courtroom-proven

Expert witness reporting and oral evidence given to the courts of Hong Kong and Singapore.

Trained and current

Formally trained countermeasures practitioners, holding current certification in advanced technical surveillance countermeasures, using current-generation instrumentation under proven strategies.

Fixed, scoped fees

Quotations fixed against the red-yellow-green floor plan you provide: the agreed fee for the agreed scope does not change on site. If the premises materially differ from the plan, we re-quote before continuing.

Four disciplines, one practice

Sweep, network, device and open-source investigation under one engagement when a matter widens.

Discretion as standard

No published client lists, unmarked equipment, agreed cover stories, NDAs as standard.

What Our Clients Say

In their words.

“When you said it would take 8 hours I thought you were joking. I now know what a real TSCM inspection involves.”

Anonymous

“I really did not think you would find anything. Thank you so much.”

Hedge Fund · Managing Director

“I now realise that the last TSCM inspection we had done was a ‘Rain Dance’. Thank you for your integrity.”

Anonymous

Frequently Asked Questions

Direct answers to the questions clients ask first.

What does a Risk3 bug sweep (TSCM inspection) include?

The privacy technical audit in full: a radio-frequency spectrum examination, a physical search of the fabric of the room including fixtures, furniture, power and cabling, inspection of conference and telephony systems in place, and thermal and non-linear junction detection where the environment calls for it. The engagement ends with a written report of findings and practical recommendations, delivered only to you.

What is Cyber TSCM and how is it different from a penetration test?

Cyber TSCM is an onsite audit of your network infrastructure viewed as an eavesdropping surface: rogue access points, unauthorised devices on the LAN, compromised VoIP and video-conference systems, and misconfigurations that leak conversations rather than data. A penetration test asks whether an outsider can get in; Cyber TSCM asks whether anything inside is already listening.

What is the red-yellow-green floor plan?

It is how Risk3 scopes and prices every sweep. Mark any floor plan in three colours: red for spaces where a loss would be unrecoverable, swept every visit and priced first; yellow for the spaces that hear the red rooms; green for tertiary areas covered as time allows or rotated across a programme. The colours become the fixed quotation, so fees concentrate where the risk concentrates.

Can you sweep our offices outside business hours?

Yes. Most corporate sweeps are delivered overnight or at weekends so that staff, visitors and any watching party see nothing out of the ordinary. Where a cover story is needed for building management or facilities, we agree it with you in advance.

What happens if you find a device?

We stop, secure the area and brief you away from the room. Nothing is touched until you decide, with counsel where appropriate, whether to preserve the device evidentially, feed it controlled information, where lawful, to identify the operator, or remove it. Risk3 documents every find to a standard that supports later civil, employment or criminal action.

Do you work alongside our lawyers?

Routinely. Engagements can be structured under legal privilege from the first call, findings are reported in a form counsel can use, and the practice has given expert witness reporting and oral evidence to the courts of Hong Kong and Singapore.

How long does a privacy technical audit take?

Longer than most expect. A single boardroom done properly — spectrum, physical search, conference systems, cabling — typically takes four to eight hours. The red-yellow-green floor plan concentrates those hours where the risk concentrates; anything materially quicker for a comparable scope is unlikely to be a thorough inspection.

How often should we be swept?

Risk-based. Red rooms before every board cycle or transaction, quarterly for most clients with sustained exposure; yellow and green areas rotated across the programme. A one-off sweep answers today's question; a scheduled programme keeps the answer current.

What is a pre-move-in sweep?

A baseline inspection of new premises before your people, furniture and technology arrive: legacy cabling, abandoned equipment, the previous tenant's access points and anything the fit-out left behind. It is the cheapest sweep to do properly, because the rooms are empty — and every later inspection can be measured against a known-clean baseline.

Can you advise during an office fit-out or renovation?

Yes. Designing a boardroom to resist eavesdropping — acoustic isolation, cable routing, sound masking, access control and construction-phase inspections — costs a fraction of retrofitting the same protections after occupation. We work with your architects and contractors from drawings to handover, and sweep before the room goes live.

How much does a bug sweep cost?

It depends on the rooms, not the building. Fees are quoted fixed and in advance from your red-yellow-green floor plan: a single boardroom or executive office is a different engagement from a full floor, and the red rooms are priced first. The figure you accept is the figure you pay for the scope you accepted — travel at cost, no on-site revisions. If the rooms materially differ from the plan supplied, we tell you and re-quote before work continues. Be wary of any sweep priced cheap and by the hour with no defined scope; a proper quotation costs nothing. Send a marked floor plan by Signal and we will return a fixed fee.

I think my office or home is bugged. What should I do first?

Carry on as normal, and say nothing about your suspicion inside the space concerned. Do not search for the device yourself, and do not discuss a sweep on the phones, email or networks tied to that environment — if something is listening, it hears the plan to find it. Contact us from a different location, on a personal device, by telephone or Signal. The first confidential consultation carries no fee, and if a sweep is not the right answer we will say so.

The answers above are general guidance, not advice on any specific situation. If your concern involves your personal safety rather than commercial confidentiality, prioritise your safety and contact the Police. More practitioner answers throughout the common questions and is my office bugged? pages.

Contact

Request a confidential consultation.

Call away from the suspected area, on a device you trust. The first confidential consultation carries no fee, and if you do not require our services we will say so.

Enquiry Line

+(852) 9103 1852

Telephone · Signal · WhatsApp

Email

[email protected]

Risk3 Consulting Limited, registered in Hong Kong, CR No. 0781250. Principal Consultant: Alan Jeffries. If sending a floor plan for the red-yellow-green scoping, prefer Signal.

This site sets no cookies and runs no analytics or trackers. Your message is delivered to our consultation inbox by a third-party form service (Formspree Inc., USA); nothing is stored on this website. For fully secure communication, use Signal (not WhatsApp) or telephone.