What is Bugging? Surely It Doesn’t Really Happen

“What is bugging?” “What is bug sweeping?” or “What is TSCM?” are questions we are often asked, even by security professionals! It’s sad to see so many commercial organisations continuing to remain ignorant regarding the threat of technical surveillance. Many have never had any awareness instruction regarding technical surveillance risk management. We hear frequently, CEOs telling us that they think there is no need for Technical Surveillance Counter Measures (TSCM) surveys, because in their opinion technical surveillance attacks don’t happen “in the real world”!

We, at Verrimus, are definitely in “the real world” and we are seeing an increased demand for our operational services. Pharmaceutical companies, financial organisations, sporting professionals, legal professionals, energy industry organisations are just some of the sectors our recent clients have come from.

If you are a technical surveillance denier, ask yourself…If bugging or more accurately technical surveillance DOESN’T happen, why are we so busy? Our TSCM training services, TSCM operations and TSCM equipment services are all in high demand.

Maybe you need to learn what is bugging (technical surveillance) and what is TSCM (technical surveillance countermeasures?

Why do so many CEOs and other senior executives feel this way?

They certainly do not dismiss physical security threats to their organisation in the same manner. All organisations understand the threats posed to their physical security and they implement procedures and install a variety of door entry systems, alarms, CCTV systems, locks, etc, tailored to meet the risk appetites of their organisation and to keep their staff and physical sites safe.

Most companies do understand the threat to their critical information from cyber threats and so they invest in relevant and appropriate cyber security measures and experienced personnel.

You’d have serious concerns if a security professional within an organisation stated “we have no need for physical security process or cyber security process”. Yet, treating security in silos is exactly why technical surveillance fits neatly into the gap between those two security disciplines.

What is it about technical surveillance threats that lead CEOs to dramatically declare that they have no need for TSCM?

(Aside from those who ask us , what is TSCM? and who clearly have no knowledge of the risk.) Is it because some security professionals perceive technical surveillance as a black box under a boardroom table? Some CEOs who attend our Verrimus TSCM Awareness and Procurement courses admit that their only personal experience of TSCM is from watching TV and movies! Very few CEOs and other personnel responsible for mitigating threats to organisational privacy have ever viewed a professional TSCM operation, seen any technical surveillance attacks operating or have any idea of attack methodology and devices. Few have ever had a conversation with a specialist TSCM service provider, to discuss emerging and historical attack methodology.

Lack of Media Coverage

Perhaps this dismissal is also due to the fact that many technical surveillance attacks, when they are detected, identified and located are not reported in the media? Clients whom we work on behalf of have their own set of protocols and processes for dealing with any ‘finds’. (which we help them to develop). Very rarely do those protocols involve any publicity. The reputational (and financial) damage that can occur after a privacy breach is made public, can in some cases do more harm to an organisation than the original attack managed to do!

If you hold a position where you are responsible for your organisation’s privacy protection, do you know what the emerging technical surveillance threats and appropriate countermeasures are?

  • Does your current privacy protection strategy match your organisational risk appetite?
  • Do you think that your cybersec and physec mitigations cover technical surveillance too?
  • Do you know what is Technical Surveillance?
  • D you know what is TSCM?
  • Do you know how to procure TSCM services?
  • Do you know how to compare TSCM service providers when you issue an RFQ or tender proposal?
  • How do you currently appraise your TSCM service provision?
  • Is the provision your organisation currently has, fit for purpose?
  • Are all threat domains surveyed?

To conclude, technical surveillance attacks DO happen. You may not be aware of most of them, that doesn’t mean they don’t happen!

You need to learn what is technical surveillance and what is TSCM

We offer short, cost-effective, TSCM awareness and procurement (TSCM A&P) courses to assist organisations to understand the technical surveillance threat landscape.

We provide opportunities to get hands on with a live scenario and to understand the multi-layered, operational countermeasures procedures and analysis that is required to detect, identify and pin-point locate a technical surveillance attack.

If you would like to know more about our TSCM A&P coursesget in touch with info@verrimus.com

Get Trained in TSCM. Being Trained in TSCM is the beginning.

author avatar
Verrimus Verrimus Operational Team Member