Most organisations meet counter-espionage the way they once met cybersecurity: an incident, a scramble, a one-off purchase, and a quiet return to hoping. The organisations that stopped losing information did the same thing cyber's leaders did. They replaced episodes with architecture.

Start from the crown jewels, not the calendar

A programme begins with an honest threat model, and a threat model begins with the information itself. What, if overheard, would move your share price, your litigation, your negotiation or your family's safety? Where does that information exist as conversation: which rooms, which people, which travel? Who benefits from collecting it, and what access could they plausibly obtain? These three questions, answered candidly, generate the programme's entire design: which environments get protected, how deeply, and how often. Skipping them produces the industry's most common failure: sweeping the impressive room quarterly while the real conversations happen somewhere else.

The four components

Baseline assurance: scheduled, independent technical inspection of the mapped environments, at a cadence set by exposure rather than budget cycle, with timing varied so the schedule itself stays unpredictable. Event coverage: automatic protection around the moments when exposure spikes: board meetings, results, transactions, disputes and sensitive travel. Protection is triggered by the corporate calendar, not by someone remembering to call. Response readiness: a pre-agreed plan for the two scenarios that will otherwise be improvised catastrophically: a discovered device, and evidence that information has moved. The plan settles who is told, who is not, and which specialist deploys under what authority. Governance: an owner (typically the GC or company secretary), a documented scope, and dated reporting into the audit committee or principal, so the programme survives personnel changes and produces evidence of diligence on the day something escapes anyway.

What "seriously" means to a board

Boards take a programme seriously when it speaks their language: exposure, likelihood, and cost against consequence. A well-run programme reports the way internal audit reports: findings, trends, remediation status. Not the way vendors sell. It is also honest about its limits: no programme makes surveillance impossible. It makes surveillance expensive, risky and short-lived, and it guarantees that when a compromise occurs the organisation discovers it first, on its own terms, with evidence in hand. That is the realistic promise of counter-espionage, and boards respect realism.

The alternative is the status quo: assurance purchased once, decaying quietly, remembered the morning a term sheet appears in a rival's hands. Architecture beats episodes.