Cyber TSCM — the network security audit, reframed as counter-surveillance
A penetration test asks whether an outsider can get into your network. Cyber TSCM asks a different question: whether anything already inside it is listening. It is an onsite network security audit conducted from the counter-surveillance point of view — your infrastructure and connected devices examined as an eavesdropping surface, not merely as an IT asset. It is the electronic counterpart to a physical bug sweep, and the two together give the complete picture of how a room can be heard.
What Cyber TSCM looks for
The audit concentrates on the ways a network — or a legitimate system quietly misused — can carry what is said in a room out of the building:
- Rogue and unauthorised wireless: unsanctioned Wi-Fi access points, personal hotspots and cellular (4G/5G) routers that open an unmonitored path in or out of a controlled space.
- Unknown and unmanaged devices on the network: hardware on the LAN that no inventory explains, and connected “smart” devices with microphones or cameras sitting in sensitive rooms.
- Conference and AV systems that can be made to listen: VoIP handsets, video-conference units and boardroom audio paths that can carry a live feed beyond the room — sometimes while appearing to be switched off.
- Misconfigurations that leak conversation rather than data: the settings, routes and forgotten connections that expose live audio and video instead of files.
These are not hypothetical. An unauthorised 4G router beneath a workstation, a smart speaker left active in a crisis-management room, a boardroom’s own microphones routed to an auditorium control booth — each is drawn from real casework, and each is a network exposure a firewall would never flag. Several are documented in our case studies.
How it fits the sweep
The physical sweep finds the device in the room; Cyber TSCM closes the network paths around it — the routes by which a planted device, or an ordinary system turned against you, moves the room’s conversation elsewhere. It is delivered onsite and scoped with the same red-yellow-green floor plan as every Risk3 engagement, so professional fees concentrate where the risk concentrates, and every finding is reported with its own risk level rather than as an undifferentiated list.
What Cyber TSCM is not
It is not a penetration test, and it does not replace enterprise cyber-security, your IT team or your managed service provider — it independently verifies what they maintain, from the narrow question of whether your environment can be listened to. Where an intrusion has already happened — ransomware, business email compromise, or a mailbox or device known to be compromised — that is incident response and digital forensics, which we handle as digital investigations rather than as a sweep. We recommend and sell no security hardware or software; the audit is diagnostic and independent.
Targeted device examination
Where a specific machine or device is suspected of carrying spyware or a keylogger, a targeted examination of that endpoint can be added to confirm or rule out compromise. This is scoped case by case for the device that matters — not a blanket software audit of every desktop — and is usually requested when an organisation needs a definite answer about one machine.
Why boards ask for this
Firewalls, intrusion-detection systems and other perimeter defences are often bought once and then assumed to be working. Without ongoing upkeep and independent verification they can drift out of date, and a gap is frequently noticed only after it has been used. Cyber TSCM is the independent check — a plainly reported view of whether the electronic environment around your most sensitive conversations is genuinely as closed as everyone assumes.
To discuss a Cyber TSCM audit, in complete confidence:
+852 9103 1852
Speak to us before you speak in that room
The first confidential consultation carries no fee, and scope is set with the red-yellow-green floor plan so professional fees concentrate where the risk concentrates. Call from a clean device, away from the suspected area.
