Training in TSCM Isn’t Necessary – Technical Surveillance Doesn’t Happen – Really?
“Training in TSCM isn’t necessary because technical surveillance doesn’t happen” – Really? It’s sad to see so many commercial organisations continuing to remain ignorant regarding the threat of technical surveillance and have never been trained in TSCM, even from a procurement perspective. We hear frequently, CEOs tell us that they think there is no need for Technical Surveillance Counter Measures (TSCM) surveys, because in their opinion technical surveillance attacks don’t happen “in the real world”! We, at Verrimus, are definitely in “the real world” and we are seeing an increased demand for our operational services.
Why do so many CEOs and other senior executives feel this way? They certainly do not dismiss physical security threats to their organisation in the same manner. All organisations understand the threats posed to their physical security. They implement procedures and install a variety of door entry systems, alarms, CCTV systems, locks, etc, tailored to meet the risk appetites of their organisation. They do this to keep their staff and physical sites safe.
Most companies do understand the threat to their critical information from cyber threats. So they invest in relevant and appropriate cyber security measures and experienced personnel. What is it about technical surveillance threats that leads CEOs to dramatically declare that they have no need for TSCM?
Is it because they perceive technical surveillance as a black box under a boardroom table? Some CEOs who attend our Verrimus TSCM Awareness and Procurement courses admit that their only personal experience of TSCM is from watching TV and movies! Very few CEOs and other personnel responsible for mitigating threats to organisational privacy have ever viewed a TSCM operation. Even less have seen any technical surveillance attacks in practice or have any idea of attack methodology and devices. Few have ever had a conversation with a specialist TSCM service provider, to discuss emerging and historical attack methodology.
Lack of Media Coverage
Perhaps this dismissal is also due to the fact that many technical surveillance attacks, when they are detected, identified and located are not reported in the media? Clients whom we work on behalf of have their own set of protocols and processes for dealing with any ‘finds’. Very rarely do those protocols involve any publicity. The reputational (and financial) damage that can occur after a privacy breach is made public, can in some cases do more harm to an organisation than the original attack managed to do!
If you hold a position where you are responsible for your organisation’s privacy protection, do you know what the emerging technical surveillance threats and appropriate countermeasures are?
- Does your current privacy protection strategy match your organisational risk appetite?
- Do you know how to procure TSCM services?
- Do you know how to compare TSCM service providers when you issue an RFQ or tender proposal?
- How do you currently appraise your TSCM service provision?
- Is the provision your organisation currently has, fit for purpose?
- Are all threat domains surveyed?
To conclude, technical surveillance attacks DO happen. You may not be aware of most of them, that doesn’t mean they don’t happen!
Training In TSCM
We offer short, cost-effective, TSCM awareness and procurement (TSCM A&P) courses and online TSCM briefings, to assist organisations to understand the technical surveillance threat landscape.
We provide opportunities to get hands on with a live scenario and to understand the multi-layered, operational countermeasures procedures and analysis that is required to detect, identify and pin-point locate a technical surveillance attack.
If you would like to know more about our TSCM A&P courses, get in touch with info@verrimus.com
Get Trained in TSCM. Training in TSCM is the beginning.