Technical Surveillance Attacks (bugs) Remain a Significant Threat to Organisational Privacy

There is an abundance of very cheap and easily obtained technical surveillance attacks out there. You have been warned! Our latest test and training devices, small covert cameras, cost less than £30

Generally, people refer to technical surveillance attacks as ‘bugs’. Most competent TSCM operators dislike this over-simplified term. There are many examples portrayed in the media of these attacks being installed in everyday items such as; air fresheners, smoke alarms, alarm clocks, lamps, motion detectors, etc. However, a technical surveillance attack is not just a ‘bug’! Take a look at our NEWS page.

Cyber Security Spending

Organisations allocate and spend large budgets on cyber security strategies and actions. They equally allocate and spend large budgets on physical security measures. However, many organisations either wilfully ignore (or are ignorant of) the risks from these simple technical surveillance attacks and do not budget for or undertake technical surveillance counter measures (TSCM) surveys. Why is this? Is it simply a lack of knowledge? This addressing of corporate privacy in ‘silos’ of physical security and cyber security leads to a gap, which technical surveillance attacks squeeze right into!

For example, all of your cyber security spending will not detect a simple adaptation to the TV in the boardroom, allowing it to listen in to meetings. Cyber security mitigations won’t detect a camera hidden in the staff toilets. Your cyber security systems won’t detect a passive network tap or a keyboard logger. Standard cyber security processes won’t detect a phone line that is being monitored and covertly listened to.

It is worth reminding organisations that a motivated ‘privacy’ attacker (an individual or organisation who is intent on breaching the privacy of a corporate organisation) will not limit themselves to one method of attack. They may deploy several different attack methods often simultaneously (almost a scatter-gun approach) and see which get traction or results.

Cyber attacks and the mitigation of them is something that gets vast amounts of media coverage and publicity. Perhaps worth noting, whilst the reporting of cyber attacks happens, obviously there are those organisations that are able to prevent a data breach and then do not publicise this successful deterred attack.

Unreported Privacy Attacks

Equally, and possibly more frequently Verrimus note that when a technical surveillance attack is detected, identified and located most of our clients (and we therefore assume it’s a common occurrence) do not seek to publicise this fact. So, the actual volume of detected technical surveillance attacks is unknown, as is of course the actual volume of technical surveillance attacks that are successful. This lack of public acknowledgement, court cases and media reporting hides the actual number of instances that are occurring.

For technical surveillance awareness training, please contact Verrimus info@verrimus.com