Frequently Asked Questions

Straight answers on TSCM, bug sweeps and counter-espionage.

What boards, counsel and principals ask before engaging us. If your question is not answered here, a confidential consultation costs nothing and obliges you to nothing.

Fundamentals

TSCM is the professional discipline of detecting, locating and neutralising covert surveillance, audio devices, hidden cameras, RF transmitters, tracking devices and compromised infrastructure, and of hardening environments against future attack. It is commonly called a "bug sweep", though a credible engagement covers far more than devices: it addresses the environment, the infrastructure and the practices that let information escape.

A bug sweep is a point-in-time inspection for surveillance devices. An electronic privacy audit is broader: it examines every pathway by which sound, video and data can leave your sensitive spaces, conference systems, VoIP, smart-building infrastructure, personal devices, meeting practices, and delivers a prioritised remediation plan alongside the physical inspection. Most first-time clients discover their real exposure is wider than they assumed.

Corporate boards, CEOs, general counsel, family offices, investment funds, private equity firms and law firms, as well as high-net-worth individuals, government bodies, foreign consulates, professional athletes and public figures. Engagements are usually commissioned by the board, the GC's office or the principal directly.

You usually don't, modern devices give occupants no visible or audible indication, and folklore "signs" (clicks on phone lines, interference) are unreliable. The dependable indicators are informational: counterparties knowing your position, confidential matters surfacing externally, competitors moving pre-emptively, or details of private meetings repeated back to you. If information appears to be moving, that justifies an inspection regardless of whether anything looks wrong.

Yes. The region concentrates deal flow, contested corporate control, litigation and family wealth. These are the situations in which the value of overheard information spikes. Capable recording and transmitting devices are available online for less than the cost of a business lunch, and commercial investigators willing to deploy them operate throughout the region. The threat is not exotic; it is commercial, cheap and quiet.

Engagement & Process

In Hong Kong: typically within 24 hours, and same-day in genuine emergencies. Across the region: usually within 48–72 hours depending on jurisdiction and logistics. Standing clients on continuous monitoring programmes have pre-agreed response commitments.

No. Most inspections are conducted outside business hours, evenings, weekends or holidays, under a cover story if required (for example, "facilities works" or "IT upgrade"). Staff other than the engaging executives need never know an inspection took place, which also protects the integrity of any insider-related inquiry.

A single boardroom and adjacent support spaces: typically one evening. An executive floor: one to two nights. A large residence: a day to two days. Multi-site electronic privacy audits are phased over an agreed schedule. Duration is fixed at proposal stage. Credible TSCM cannot be rushed. Thoroughness is the entire product.

Scope drives cost: the size and complexity of the environment, urgency, and whether investigation or monitoring is included. Focused inspections begin in the tens of thousands of Hong Kong dollars; complex multi-site or investigative engagements are correspondingly larger. All work is quoted as a fixed, confidential proposal after an initial consultation.

For most listed companies and funds: quarterly, plus event-driven inspections immediately before board meetings, results announcements and transaction negotiations. High-threat environments, contested control situations, active litigation, hostile M&A, justify monthly cycles or in-place monitoring. We help clients set a cadence proportionate to actual exposure rather than selling a fixed package.

Yes, and in contentious matters we recommend it. Counsel-directed engagement can bring our work within legal professional privilege, protects the investigation from disclosure, and ensures findings are handled in a litigation-ready manner from the first hour. We work alongside disputes teams in Hong Kong, Singapore and across the region routinely.

Yes. Every engagement concludes with a written report: scope, methodology, findings, exposure assessment and prioritised recommendations, drafted for decision-makers, not technicians, and to a standard suitable for boards, audit committees, insurers and, where matters escalate, courts and arbitral tribunals.

Coverage & Capability

Hong Kong, Singapore, Macau, Mainland China, Japan, South Korea, Thailand, Malaysia, Indonesia, the Philippines and Australia. Multi-jurisdiction programmes are coordinated centrally from Hong Kong so standards, confidentiality and reporting remain consistent everywhere you operate.

Yes. Executive residences, holiday properties, vehicles, yachts and private aircraft interiors are core services, principals are most frequently targeted where formal security is weakest. See Executive Residence Inspection and Vehicle Inspection.

Yes. Pre-occupancy inspections of hotel suites, conference venues, arbitration hearing rooms and deal-signing locations are among our most requested services, particularly during executive travel, roadshows and off-site board meetings across Asia.

Yes. Device-level compromise assessment, covering commercial spyware and stalkerware on phones, laptops and tablets, is available as part of an electronic privacy audit or as a standalone digital forensics engagement. Mobile devices are now among the most common vectors for monitoring principals and their families.

Yes. Optical device detection, including non-transmitting, battery-powered and lens-based systems, is a standard component of every inspection, alongside RF, GSM/cellular, Wi-Fi/Bluetooth, carrier-current and wired attack vectors.

Professional-grade spectrum analysis, non-linear junction detection, thermal imaging, and physical and network inspection techniques, applied through a documented, repeatable methodology. We deliberately do not publish operational specifics, and we advise clients to be sceptical of providers who lead with equipment lists rather than method, reporting and evidential standards.

Yes. Transaction support includes pre-negotiation inspection of deal rooms and counterparties' proposed venues, in-meeting technical monitoring during sensitive sessions, and confidentiality assurance across the life of a transaction, from first approach to completion. See Private Equity & Investment Funds.

A discreet investigation into information loss attributable to personnel with legitimate access, combining technical findings, digital forensics, access analysis and, where appropriate, lawful interviews. These matters are coordinated with counsel and HR to manage employment law, privilege and evidential issues from the outset. See Corporate Espionage Response.

Discretion, Legality & Judgement Calls

Yes. Inspecting premises you own or control for surveillance devices is lawful in Hong Kong and across the jurisdictions we serve. Where matters involve discovered devices, evidence handling or cross-border work, we operate with counsel to ensure everything we do supports, rather than compromises, any later legal action. We do not conduct surveillance; we defeat it.

No. Discretion is absolute. We operate under NDAs as standard, use unmarked equipment cases, attend under agreed cover where necessary, and never reference client names or engagements, publicly or privately. Confidentiality applies equally to prospective clients who consult us and do not proceed.

We stop, secure the scene and brief you away from the room. Options include evidential preservation and forensic analysis, feeding controlled information to identify the operator, or removal. The decision is made with you and, where appropriate, your counsel, because a discovered device is evidence in a matter that has only just begun. Our digital forensics capability can then establish what the device captured and where it reported.

Do not touch it, do not discuss it in the room, and do not tell anyone who does not absolutely need to know. Leave the environment as it is and contact us from a different location on a personal device. Mishandling a discovered device destroys forensic value and alerts the operator. Our response line operates 24/7: +852 5808 1071.

In-house teams are essential partners, but TSCM is a specialist discipline requiring dedicated equipment, current threat knowledge and, critically, independence. If the concern involves an insider, internal teams may be inside the problem. An external, independent inspection also carries more weight with boards, insurers and courts.

Integrators profit from selling and installing equipment, which creates a structural incentive to find problems that equipment solves. Risk3 sells no hardware and takes no commissions. Our findings are driven solely by evidence, which is why boards, insurers and courts treat them as independent assurance rather than a sales instrument.

Still Have Questions?

Ask them in confidence.

A senior consultant will answer directly, no sales process, no obligation.

All enquiries handled under strict confidentiality

Call now Confidential enquiry