Version 1.0 · Free to reproduce
The TSCM Buyer's Due Diligence Standard
Twenty questions to ask anyone who wants to sweep your boardroom, what a competent answer sounds like, and what should end the conversation.
Technical surveillance countermeasures is close to an unobservable service. Someone spends a few hours in your building with equipment you do not recognise, and hands you a document saying they found nothing. You cannot tell from the outside whether that was systematic work or a walk-through with a blinking box, and the invoice looks identical either way.
That information asymmetry is the central commercial fact of this industry, and it is why the field contains both serious practitioners and people who bought a detector on the internet last year. Buyers have almost no way to tell them apart, so they fall back on the two signals that are actually available to them: price, and how confident the person sounded.
Both of those signals are worthless here. This document is an attempt at a better one. It is the list of questions I would ask if I were buying this service rather than selling it, together with what a competent answer sounds like and what should end the meeting.
I have a commercial interest in this and you should read it knowing that. So here is the test of whether I have written it honestly: every good answer below is one that any competent independent provider can give. If you use this document to choose someone other than me, it has done its job.
Licence
Free to use, quote, forward and reproduce, including by competing providers, with attribution.
The company behind the person
Start here, because it is the cheapest part to check and the part most likely to be quietly wrong. All of it can be verified from your desk in under ten minutes.
“What is the legal entity I would be contracting with, and what is its company number?”
Why it matters. You need to know who carries the liability, and you need something you can look up. Trading names are not entities.
A good answer
A company name and number given immediately, matching the name on the quote and the bank details, which you then check on Companies House yourself.
A poor answer
A trading name only, a number that does not match the name on the invoice, or an entity registered last month with a name unrelated to the website.
“How long has that entity been trading, and has it filed accounts?”
Why it matters. Not because new is bad — everyone starts somewhere — but because you should know, and because how they tell you is informative.
A good answer
A direct answer, including if the answer is 'we are new and have not filed yet'. New companies run by experienced people are entirely normal.
A poor answer
Vagueness, or implying decades of corporate history that belongs to a different entity or to a previous employer.
“Are you registered with the ICO for data protection, and what is the reference?”
Why it matters. A TSCM provider walks around your premises recording what it finds, often including personal data. In the UK, processing that data means paying the annual fee and appearing on the ICO register.
A good answer
A registration reference you can find on the ICO's public register at ico.org.uk.
A poor answer
Not knowing what the ICO is. This is a security supplier that has not met a basic legal requirement of handling data, which tells you what to expect of its handling of yours.
“What insurance do you carry, and can I see the certificate?”
Why it matters. Professional indemnity for the advice and public liability for being on your premises. If something goes wrong you want this to exist.
A good answer
A certificate produced without friction, showing insurer, limit of indemnity and expiry.
A poor answer
'We're covered' with no document. Insurance is not publicly searchable, so a document is the only evidence there is.
“Do you hold Cyber Essentials or an equivalent?”
Why it matters. Your findings report is the single most sensitive document about your building, and it will live on their laptop. Ask how that laptop is run.
A good answer
A certificate number you can confirm on the IASME public directory. A badge on a website is not evidence; the directory is.
A poor answer
A badge image with no certificate number, or a certification that has lapsed. Both are checkable in about a minute.
The person who will actually be in the room
This industry sells on biography, and biography is the least verifiable thing about it. Be specific, and be aware that vagueness is usually a choice.
“Who specifically will be on site, and what is their background?”
Why it matters. The person who sells the engagement is often not the person who performs it. You are buying the performer.
A good answer
Named individuals, with backgrounds you can partially confirm, and a straight answer about who is subcontracted.
A poor answer
'One of our experienced operatives.' You are being sold an abstraction and quite possibly a subcontractor at short notice.
“What formal TSCM qualifications do they hold, and who awarded them?”
Why it matters. There is no single governing certification in TSCM. That means the word 'certified' is doing almost no work unless you ask who certified them.
A good answer
Named, checkable awards: a BTEC or TQUK-endorsed TSCM qualification, a named professional body membership, or a specific equipment certification, stated as exactly what it is.
A poor answer
'Certified TSCM expert' with no awarding body. Also: presenting a two-day vendor equipment course as a professional qualification. They are different things and a competent provider will say so unprompted.
“Where does your experience actually come from, and what does it not cover?”
Why it matters. Everyone in this field came from somewhere: military, police, engineering, IT, alarms. Every one of those origins has a blind spot. Someone who names theirs is more trustworthy than someone who implies they have none.
A good answer
A specific history, with an honest limit attached. 'I am strong on RF and physical search, I bring in a specialist for network forensics.'
A poor answer
Unfalsifiable claims of classified government work used to avoid the question, and mystique deployed where evidence should be. If it cannot be discussed it cannot be assessed, so it cannot be the basis of your decision.
“Have you been vetted, and to what level?”
Why it matters. Relevant if your environment warrants it. Also a fair question given you are about to give someone unsupervised access to your most sensitive rooms.
A good answer
A clear statement of what checks exist — DBS, BS 7858 screening, any clearance — and willingness to be checked again for your engagement.
A poor answer
Reluctance, or annoyance at being asked. You are about to hand over the keys to the boardroom.
The method
This is where competence and theatre separate most visibly, and where a buyer with a written method in hand has all the leverage.
“Can you give me your written methodology before I book?”
Why it matters. A serious provider has a documented process. If it only exists in their head, you cannot hold them to it and neither can they.
A good answer
A staged method covering scoping, physical search, RF analysis, electronic and infrastructure inspection, reporting, and re-inspection after remediation.
A poor answer
'Every job is different so we don't work to a fixed process.' Scope varies. Method should not.
“How much of the time on site is physical search rather than instrument work?”
Why it matters. Most finds in this field are physical finds. A provider who leads with equipment and treats the hand search as a formality has the ratio backwards.
A good answer
A substantial share, described concretely: fittings, voids, outlets, conferencing hardware, furniture, gifts and ornaments.
A poor answer
An answer that is entirely about equipment. The equipment is necessary and it is not sufficient.
“What equipment classes do you use, and what can each of them not detect?”
Why it matters. The second half is the real question. Every instrument has a defined blind spot, and knowing them is the difference between an operator and an owner of equipment.
A good answer
Spectrum analysis, non-linear junction detection, thermal imaging and line analysis described by function, each with its limits stated plainly — for example that a spectrum analyser will not see a device that is not transmitting during the sweep.
A poor answer
Brand names as a substitute for understanding, or any claim that one instrument detects everything. Nothing does.
“How do you handle devices that are not transmitting?”
Why it matters. This is the single best technical question a non-specialist can ask. A recording device that stores locally, or a transmitter that is dormant or bursts intermittently, is invisible to a simple RF sweep.
A good answer
Non-linear junction detection to find semiconductors whether powered or not, thermal imaging, physical search, and extended or out-of-hours monitoring where the environment justifies it.
A poor answer
Not understanding the question, or dismissing it. This is the failure mode that makes a clean report meaningless.
“When would you do this work, and how discreet is it?”
Why it matters. A sweep announced to the building is a sweep announced to whoever placed the device. RF baselines are also easier to read when the building is quiet.
A good answer
Out of hours where the environment allows, with a cover story agreed with you in advance and a named single point of contact on your side.
A poor answer
No consideration of who will see them, or an assumption that arriving in branded clothing during business hours is fine.
“What happens if you find something?”
Why it matters. The moment of a find is the moment amateur handling destroys your options — evidentially, legally, and in terms of what you can learn from it.
A good answer
A defined protocol: do not disturb, preserve evidence, establish who to notify, consider whether the device is live and what has already been compromised, and involve legal counsel before removal.
A poor answer
'We'd remove it and show you.' That may destroy forensic evidence and alert whoever placed it, in one action.
The report and the commercials
What you are actually buying is a document and the assurance behind it. Establish what that document contains before you agree a price.
“What exactly will the report contain? Can I see a redacted sample?”
Why it matters. The report is the deliverable. It is also the thing you will show your board, your insurer or your counsel.
A good answer
A redacted sample provided readily, recording scope, method, equipment classes used, areas covered, findings, and recommendations in priority order.
A poor answer
A one-page certificate saying 'no devices found'. That is not a report, and it will not survive a single informed question.
“What does a clean result actually mean, and what does it not mean?”
Why it matters. It means the scoped areas were clear, by the methods used, at that time. It does not mean the building is clear forever. A provider who does not volunteer this is overselling.
A good answer
Exactly that distinction, stated without being asked, including the point that a clean report's value is that it bounds an exposure window with a date.
A poor answer
Any implication that you are now permanently secure.
“How is the price built up, and what makes it change?”
Why it matters. Guarding against both the unexplained large number and the suspiciously small one.
A good answer
Fixed price against an agreed scope, with the drivers named: area, number of rooms, complexity, timing and travel. Changes to scope handled in writing.
A poor answer
A day rate with no scope, a price quoted before anyone has established what the spaces are, or an estimate that moves sharply once fear enters the conversation.
“How often do you think we should do this, and what should trigger an unscheduled one?”
Why it matters. Tests whether they are selling you a subscription or advising you. The honest answer depends on your risk, not on their revenue model.
A good answer
A frequency tied to your actual exposure, plus named event triggers: a deal, a dispute, a departure, building works, a leak with no obvious source.
A poor answer
A standard quarterly contract recommended before they know anything about your risk, or a suggestion that everyone needs monthly sweeps.
“What are you not able to help with?”
Why it matters. The closing question, and the most revealing one in the list. Everybody has a boundary. Only some people will tell you where theirs is.
A good answer
A clear boundary and, ideally, a referral: 'that is network forensics and I would bring in someone else' or 'physical penetration testing is not what I do'.
A poor answer
'We handle everything.' Nobody handles everything, and a provider who says so has just told you they will attempt work they are not competent at.
Signals that should end the conversation
Regardless of how the twenty questions go, any of these on its own is worth taking seriously.
- Fear-led selling: the pitch leads with how likely you are to be bugged rather than with method and scope. Prevalence in this industry is far lower than the marketing implies, and anyone whose case rests on your anxiety is managing you rather than assessing you.
- A free sweep, or a price far below every other quote. The commercial model is either an upsell after a discovery, or a walk-through that was never going to find anything.
- Unverifiable government or intelligence background used to shut down technical questions.
- A finding produced on the first visit with a great deal of drama and no evidentiary handling. It happens, and it is also the oldest trick in this trade.
- Refusal to put the method in writing, or to name who will be on site.
- Equipment brandished as credential. The instrument is not the competence; a spectrum analyser in untrained hands produces confident nonsense.
- No entity, no insurance, no ICO registration. Any one of these is a conversation. All three together is an answer.
How to use this
Send the twenty questions to every provider you are considering, at the same time, before any of them quotes.
Ask them in writing. You want the answers on record, and you want to see who takes the trouble to answer properly.
Check the four public registers yourself rather than accepting a claim: Companies House for the entity, the ICO register for data protection, the IASME directory for Cyber Essentials, and the awarding body for any qualification claimed.
Compare the answers rather than the prices. The spread of quality in this field is much wider than the spread of price, which is precisely why price is such a poor guide.
If a provider is annoyed by these questions, that is your answer. A competent one will be pleased somebody finally asked.
A note on my own interest in this
I sell this service, so you should read the document knowing that. The test I set myself was that every good answer above had to be one that any competent independent provider could give. None of it is written so that only my company passes. If you use it to hire someone else, it has done its job — and if you want to apply it to me, start with the Companies House officer search and the other public registers, and ask me anything they do not settle. A fuller verification register will be published on this site once outstanding company filings are current.