TSCM Explained: What an Embassy-Grade Electronic Sweep Actually Involves
What a real technical surveillance countermeasures sweep involves, why detection is elimination, and how to tell a genuine sweep from theatre.
Technical surveillance countermeasures is one of the few security disciplines where the customer usually cannot tell whether they received the service. A sweep that finds nothing looks identical to a sweep that was never really performed. That asymmetry has produced an industry with a wide quality range and very little public explanation of what competence actually looks like.
This is that explanation. I trained in this at sixteen with SAGEM France — explosive device detection, technical surveillance countermeasures, RF spectrum analysis, IED countermeasures, signal interception and jamming — and I have delivered it personally for two decades since. Nobody credible writes this down, in English or in Arabic, and the absence is not an accident: it is easier to sell a mystery.
What TSCM is, in one sentence
TSCM is the systematic elimination of every legitimate signal and physical anomaly in a defined space, until either nothing unexplained remains or something does.
Note what that sentence does not say. It does not say "finding bugs." Finding is the outcome in a minority of sweeps. The discipline is elimination, and that is the single most important thing to understand about it — including for judging whether the service you bought was real.
The method: detection is elimination
The instinct is to look for the anomaly. The method is the opposite: account for everything that should be there, and see what is left.
In a boardroom, that means the building's own Wi-Fi, the neighbour's Wi-Fi, the mobile network, DECT handsets, the projector's wireless link, the HVAC controller, the badge readers, the fire panel, the smart TV nobody remembers commissioning, the presentation clicker in a drawer, and the two Bluetooth devices in the pockets of the people standing in the room. Every one of those emits. Every one of them has to be identified, attributed and set aside.
What remains after that process is the finding. There is no shortcut, and the shortcut is exactly what distinguishes a real sweep from theatre: a technician who walks in with a handheld detector, waves it around, watches it light up on the building's own Wi-Fi, and declares the room either compromised or clean has performed a ritual, not a sweep.
The method scales beyond this discipline, which is why I keep returning to it. It is the same logic I apply to counter-drone detection — establish the baseline of what normally flies here, then treat the residue as signal — and the same logic that underpins confidence labelling in published intelligence. Account for the normal, and the abnormal declares itself.
What is actually being looked for
Four categories, and they fail differently.
Concealed listening devices. Audio capture, transmitted or stored. The transmitted ones are an RF problem. The stored ones are not — a recorder that never transmits has no RF signature at all, and is found physically or not at all.
Hidden cameras. Optical, and therefore findable by optical means regardless of whether they transmit — a lens reflects, and that reflection is a physical property that no amount of transmission discipline hides.
Wireless transmitters. The general category: anything moving data out of the room that should not be. This includes devices that are not "bugs" in any deliberate sense — a mis-configured conference system exfiltrating audio to a cloud service is the same operational problem with a different intent behind it.
Covert recorders. Local storage, no transmission, physically retrieved later. The hardest category, and the one that most cleanly separates a genuine sweep from an RF-only one.
Notice that two of the four categories are invisible to a purely RF approach. Any sweep sold as "we scan the frequencies" is addressing half the threat.
The equipment, and what each piece is actually for
I work with the following directly. Each one exists because the others cannot do its job.
Spectrum analyzers. The core RF instrument. It shows what is transmitting across the frequency range, at what power, with what modulation. Its value is not that it detects transmissions — a cheap detector does that. Its value is that it lets you characterise a transmission well enough to attribute it, which is what elimination requires.
Broadband RF detectors. Fast, portable, coarse. Useful for sweeping a large area quickly to find where to point the real instrument. Dangerous as a primary tool, because it produces a binary signal in an environment that is never binary.
Non-linear junction detectors. These find semiconductors, not transmissions. An NLJD illuminates a surface and looks for the harmonic response that electronic junctions produce. That means it finds a device that is switched off, that has no battery, and that has never transmitted. Nothing else in the kit does that, and its presence or absence in a service offering tells you a great deal.
Time-domain reflectometers. These inspect cabling — telephone, network, alarm, structured wiring — by sending a pulse and reading what comes back. An unexpected discontinuity is a tap, a splice, or an addition. Buildings are full of legacy cable, and cable is the most under-inspected attack surface in most facilities.
Thermal imaging. Electronics generate heat. A device concealed inside a wall cavity, a piece of furniture or a fixture has a thermal signature that the surrounding material does not, particularly after the room has been quiet and then occupied.
Physical inspection. Not equipment, and the most important item on the list. Furniture, fixtures, fittings, ceiling voids, floor boxes, power outlets, smoke detectors, picture frames, and every item that entered the room recently and cannot be accounted for.
The two hard problems
Frequency-hopping and burst transmission. A device that transmits for milliseconds, at intervals, across a hopping pattern is not going to appear on a casual spectral look. Detecting it requires dwelling long enough, across enough of the range, with enough resolution, to catch a signal that is deliberately designed to be brief. This is where sweep duration stops being a scheduling detail and becomes a technical parameter. A sweep sold by the hour, in a hurry, cannot solve this problem. It is not a matter of effort; it is a matter of observation time.
Devices that never transmit. The recorder in the drawer. No RF, no heat while dormant, no network activity. It is found by non-linear junction detection and by physical inspection, and by nothing else. Any provider whose method is entirely spectral cannot find it, and — this is the part that matters — cannot tell you they did not find it, because their method produces the same result either way.
Where it is done, and why the environment changes the method
Embassies and diplomatic missions have the widest threat surface and usually the most established internal procedures. The technical challenge is that the RF environment is dense and the building has decades of accumulated infrastructure. The elimination phase is long.
Executive offices and boardrooms are the highest-value-per-hour environments. A single meeting can be worth more than a year of general surveillance. These rooms also change constantly — new furniture, new devices, new visitors — which makes a single sweep a snapshot with a short shelf life.
Vehicles are the most commonly neglected. A vehicle is a small, enclosed, predictable space with a fixed occupant, its own power supply, and long unattended periods in semi-public places. It is close to an ideal target and it is almost never swept.
Permanently secured environments are a different discipline entirely — not a sweep but an architecture, where the goal is a space in which the introduction of a device is prevented rather than detected afterwards. That is counter-surveillance design, and it is what a client should ultimately want.
The honest limitation nobody sells
A sweep is a point-in-time result. It tells you the state of the room at the moment it was performed, and it starts expiring immediately.
That is not a caveat in the small print. It is the central operational fact, and it should drive how the service is bought. A single sweep before a specific sensitive meeting is a reasonable and well-targeted purchase. A single sweep as an annual box-tick is close to worthless, because the room is not the same room a week later.
What actually produces security is a combination: sweeps timed to events that matter, plus an architecture that reduces how easily the room's state can change between them. Access control on the space. Discipline about what enters it. Awareness of what was installed, by whom, and when.
Any provider who tells you a sweep makes a room permanently secure is either not thinking clearly or is not being straight with you.
How to tell a real sweep from theatre
Six questions. The answers are diagnostic.
Do you use a non-linear junction detector? If no, they cannot find a device that is off or has no battery. That is a whole threat category.
How long will you be in the room? If the answer is under an hour for a meaningful space, they cannot have dwelled long enough for burst and hopping transmitters.
Will you inspect cabling? If they have no TDR and no plan for the structured wiring, they are inspecting the air and not the building.
What will you tell me about the signals you found and dismissed? This is the best question of the six. A real sweep produces an inventory of everything identified and attributed. "We found nothing" without that inventory means they did not perform the elimination.
What is the deliverable? A one-line clearance certificate is not a deliverable. A written record of the environment, the method, the equipment used, what was identified, what was eliminated and what remains unexplained — that is a deliverable, and it is also the baseline that makes the next sweep faster and more sensitive.
Who is doing the work? For sensitive environments this matters more than it does elsewhere. The person you brief should be the person who performs it.
When to sweep
Timing is the decision that most determines whether the money was well spent, and it is almost never discussed.
Before a specific sensitive event. A board meeting where a transaction is decided, a negotiation, a legal consultation, a diplomatic exchange. This is the highest-value timing and the one clients most often skip, because it requires knowing in advance which conversations matter. The sweep should be as close to the event as scheduling allows, and the room should be access-controlled between the sweep and the meeting — a sweep followed by three days of open access has swept a different room.
After a change of state. New furniture, refurbishment, a contractor with unsupervised access, a departure on bad terms, a lost or replaced key. Each of those is a moment when the room's state changed, and each is a better trigger than the calendar.
After a specific concern. Information appearing where it should not, a competitor or counterparty demonstrating knowledge they should not have, a device found somewhere else in the building. In this case the sweep is part of an investigation and should be scoped as one — including the question of what else shares the same access path as the room in question.
On a routine cycle, as a baseline. The weakest justification on its own, and genuinely useful in combination with the others, because each sweep leaves a documented environment that makes the next one faster and more sensitive. The second sweep of a room is a better sweep than the first, and the fifth is better still — the eliminated-signal inventory is a cumulative asset.
What almost never makes sense is a single annual sweep with none of the above attached. It produces a certificate and very little security, and it is the format most commonly sold.
Why I write this down
Two reasons. The first is that the information asymmetry in this field is unusually harmful. A customer who cannot evaluate the service will buy on price, and in TSCM the cheap option and the ineffective option are frequently the same option — with the added problem that it produces a false clearance, which is worse than no sweep at all.
The second is that I would rather compete on method than on mystique. Everything above is the discipline. None of it is a trade secret, and the parts that genuinely should not be public — specific detection thresholds, particular device signatures, how a given environment is actually laid out — are not in this article and will not be.
What I bring that a vendor cannot: I trained on this equipment at sixteen and I still run the sweeps myself. The person you brief is the person in the room.
Carlos Kfoury is GM/CEO of CIS Security, which has delivered technical security work in Lebanon since 1990, and delivers TSCM sweeps and counter-surveillance architecture personally.
Related: What SAGEM Taught a 16-Year-Old · Counter-Drone Architecture for Critical Infrastructure · The CIS Lebanon Security Index · The operations platform behind the fieldwork: CIS Command
Carlos Kfoury is a Lebanese security entrepreneur, military strategist, and defense intelligence analyst — GM/CEO of CIS Security (operating since 1990), founder of the RAGE X intelligence ecosystem, and owner and manager of C.I.S. Services s.a.r.l. Full profile · Engage Carlos