III The Method

The Room That Is Not Secure

Technical surveillance countermeasures answer a question most principals have never framed correctly.

The question a principal asks is whether the room is secure. It is the wrong question, and answering it as asked produces a document that is worse than useless because it is reassuring.

A sweep does not certify a room. It produces a statement about a particular space at a particular moment, and the moment ends when the team leaves. Nothing about the exercise makes the following Tuesday safe. Treating the output as a certificate — filing it, and proceeding as though the problem has been addressed — converts a genuine finding into a false one, and the falseness grows every day the document remains on file.

The right question is narrower and answerable: given what would have to be true for this space to be compromised, what should change about which conversations happen here.

What the discipline covers

The scope is broader than the popular image of a technician with a handheld device, and it is worth stating so that a principal knows what they are commissioning.

It includes radio-frequency and transmitter search; electronic examination of offices, boardrooms, residences and vehicles; physical examination of the premises themselves; testing of cable, wifi and telephone systems; and examination of phones, tablets and laptops for malware and spyware.

That list is deliberately a list of domains rather than of methods, and this piece contains no methodology, no equipment detail, no indicator and nothing about how any of it is done. Those belong in an engagement, not on a website, and a firm publishing them is advertising to the wrong audience.

Why a clean result is not the deliverable

Here is the part that inverts the usual expectation. A sweep that finds nothing and changes nothing has produced nothing.

The value is not in the finding. It is in what the exercise establishes about the environment and what that implies for behaviour — which spaces are appropriate for which categories of conversation, which are structurally unsuitable regardless of any result, and which routines have been assuming a protection that was never there. Most of the useful output of a properly conducted examination concerns the ordinary operation of the space rather than anything installed in it.

So the test of whether the work was worth commissioning is not whether something was found. It is whether anybody does anything differently afterwards. If the answer is no, either the work was superficial or its findings were not communicated to the people whose behaviour they concern — and the second failure is more common than the first.

The broader discipline it sits inside

Technical examination is one component of vulnerability detection, and isolating it is the characteristic error.

The wider assessment covers access control, surveillance coverage, staff protocols, emergency procedures and exposure to covert penetration. Those determine whether a compromise is feasible in the first place, and they are where most real exposure sits. A space can be technically clean and remain trivially penetrable by someone who can arrange to be inside it lawfully — as a contractor, a supplier, a member of staff, a guest — and no examination of the room addresses that, because the person is not an anomaly to be detected.

Which produces an ordering that clients frequently resist. The technical sweep is the visible, purchasable, satisfying intervention. It is rarely the highest-value one, and where the access position has not been assessed it is being performed on a space whose principal vulnerability is who is permitted to enter it.

What a principal should ask before commissioning

Three questions, none of which concerns technique, and all of which are answerable by a provider on a first call.

What is the scope, expressed as spaces and systems rather than as a duration? An engagement priced by the day rather than by what it covers is an engagement whose coverage is unspecified, and the gap will not be visible in the report.

Who receives the findings? A report addressed to the principal alone changes nothing about the behaviour of the people who use the space daily. A report whose distribution has not been decided in advance tends to reach nobody, because after the event every recipient is a new disclosure decision taken under discomfort.

What is the reporting position if something is found? This should be settled before rather than during. Whether a matter goes to police, to counsel, to insurers or nowhere is a decision with legal consequences, and taking it in the hour of discovery — with a device on the table and everyone present — is how people make choices they later regret.

A provider who has good answers to those three is describing a practice. One who redirects to equipment is selling an afternoon.

The counterintelligence frame

One further shift is worth making, and it changes what the work is for.

The relevant question is not only whether something is present. It is who would want it to be, and what that interest implies. Attention directed at a principal is itself information: it indicates that someone has assessed the value of what passes in that room, has resourced an attempt, and has made a judgement about the likelihood of detection. Each of those is a fact about an adversary rather than about a device.

This matters because the technical result, standing alone, is uninformative in both directions. Nothing found may mean nothing was attempted, or that an attempt succeeded in a way not reached, or that the interest is being pursued by means that put nothing in the room at all. Something found is not the end of an enquiry but the beginning of a different one — about capability, access and motive — and a provider whose engagement concludes at removal has stopped at the least interesting point.

The legal backdrop reinforces the framing. Unlawful interception of a communication is a criminal offence under the Investigatory Powers Act 2016, as is unauthorised access to computer material under the Computer Misuse Act 1990. Anyone conducting these activities against a principal is committing offences and knows it, which tells you something about their assessment of the reward and about their expectation of not being caught.

The reframe is from a state to a practice. Secure is not a condition a room can be placed in and left in; it is a set of decisions about what is said where, reviewed when circumstances change, informed by periodic examination rather than settled by it. A principal who has understood that will commission this work differently and will get more from it, which is the only useful thing that can be said about the subject in public.

Sources

  1. Investigatory Powers Act 2016, section 3 — offence of unlawful interception
  2. Computer Misuse Act 1990, section 1 — unauthorised access to computer material
  3. Counter Surveillance & TSCM — Privy Consul