Planning Prior to Commissioning a TSCM Survey

Verrimus TSCM operators are constantly surprised by the amount of clients whom admit to having performed NO planning, prior to commissioning an organisation to undertake a technical surveillance counter measures (#TSCM) survey on their behalf.

When it comes to TSCM some organisations (particularly those that have been Verrimus corporate clients for some time); understand the threat posed by technical surveillance attacks, they have risk assessed their working practices and physical spaces, they have understood the time and cost that is involved in surveying for existing attacks and mitigating for known threats, they have a privacy policy in place which is regularly reviewed and compliance is checked, they have discussed and detailed what process they will follow in the event that a technical surveillance attack is detected.

Unfortunately, we are still coming across organisations who have undertaken none or, perhaps, only some of the above steps. Let’s briefly explain why we feel the above steps represent a sensible and professional approach to mitigating the risk of technical surveillance.

Understanding Threat

This, we feel is key to any risk factor that threatens an organisation. Clients should be asking themselves the following questions; What is the threat? How are technical surveillance attacks mounted? By whom? What is it possible for a technical surveillance attack to do? How can the technical surveillance be used by an attacker?

Risk Assessed Practices and Spaces

Organisations should be routinely conducting risk assessments to identify and mitigate all known risks to their business and personnel. Failing to risk assess practices and physical spaces in relation to their vulnerability to a technical surveillance attack is negligent. To protect any organisation from any threat means that the first step, after understanding a threat exists, is to identify how to mitigate effectively and in accordance with the organisations risk appetite.

Time and Cost Analysis

As with all risk mitigations, there is a cost associated with them. Technical surveillance counter measures is a process that involves experienced operators using various measurement tools and searches to survey an area and detect, identify and pin point locate any technical surveillance attacks. Unfortunately, this process is not as depicted by Hollywood…it is not possible to survey all threat domains with one hand held device and then declare an area ‘clear’. It is also not possible to throw multiple personnel at an area of concern and conduct all of the measurements for all threat domains concurrently and not expect there to be technical conflict, which increases the risk of false positives or negatives resulting in missed attacks. It is also NOT best practice to conduct a thorough TSCM survey during operational hours. All Verrimus commercial TSCM surveys are conducted during nightshifts or weekends when occupancy levels are dramatically reduced or all personnel are not on site. Prior to commissioning a TSCM survey it’s important to be aware of this and have made plans for who will remain on site with the sweep team? Who will be the point of contact on site and off site. Do the personnel on site during the sweep need to know what is being surveyed, or would you rather they were unaware of the purpose of the activity? Is a cover story required?

Privacy Policy

When we at Verrimus refer to a need for a privacy policy we are referring specifically to that aspect of protecting an organisation’s (and the personnel whom work for that organisation) privacy. Clearly we all know that organisations must have a privacy policy in place to comply with GDPR responsibilities, but what about protecting your organisation’s critical information What about protecting the privacy of your personnel whilst they are on your premises? Have you issued clear instructions regarding remote working for example? Do you have minimum security and privacy requirements expected for your personnel to adhere to when they are working remotely? Do you ever check compliance? Do you know whether your employees whilst working from home have secure home WiFi networks for example? Setting standards and checking compliance are essential to ensure that you are mitigating risk to the lowest practicable level.

Find Process

When an organisation has commissioned a TSCM survey from Verrimus, one of our pre-deployment questions is ‘In the event of a find, what is your process for reporting and investigating?’ Unfortunately, some clients have no process or have given no thought to that stage of a TSCM survey. Many organisations are having a TSCM survey conducted, just as they have a routine fire alarm test, or a test for Legionnaire’s disease on their water taps. Not because there is currently a fire, but because they need to know that if there were to be a fire their alarm system is functioning and all personnel know what is expected of them in that situation. Or not because they know they have a case of Legionnaires disease, but they need to determine if they do and then they know step by step what they need to do to comply with H&S legislation and to remove the contamination. So, what if a routine TSCM survey finds an attack? What is your procedure? Where is the evidence sent? Who in the organisation must be informed immediately? Who will be responsible for the investigation? Will you immediately inform law enforcement? Will you leave the attack in situ and feed disinformation? Will you immediately remove the attack? – All questions you should have an answer for, so that a TSCM operational team know what your organisation’s process is.

We recommend that before organisations write their RFQ or tender documents, to find a suitable TSCM supplier, they need to consider and address all of the above points.

———–

If you need assistance with any of the above points, please feel free to reach out to Verrimus via info@verrimus.com.

author avatar
Verrimus Verrimus Operational Team Member