A clean report is not a certificate of safety
The most misunderstood deliverable in technical security is the sweep that finds nothing. It is worth a great deal, but not the thing most buyers think it is worth.
Most technical surveillance engagements find nothing. This surprises people who have absorbed the marketing of the industry, and it is the normal and expected outcome. The interesting question is what that result actually entitles you to believe.
What a clean result means
Stated precisely, a clean report means: the areas that were within scope were found to be clear, by the methods that were used, at the time the work was done. Every clause in that sentence is load-bearing, and dropping any of them turns a technical finding into a false reassurance.
- Within scope. The rooms that were searched. Not the rooms next door, not the corridor, not the executive's car or home unless those were scoped in.
- By the methods used. A radio-frequency sweep does not see a device that was not transmitting while you were there. Different methods have different blind spots, which is why serious engagements layer them.
- At the time. This is the clause that matters most and gets dropped most often. A building is clear at a moment, not in perpetuity.
The exposure window
The genuine value of a clean report is not that it makes you safe. It is that it puts a dated boundary on your uncertainty. Before the engagement, if you had asked how long a device could conceivably have been in your boardroom, the honest answer was: as long as the room has existed. After it, the answer is: since the date on the report.
That is a real and valuable thing to own, and it is what I mean when I say a clean report is an asset rather than a non-event. It converts unbounded uncertainty into a bounded interval. If something later goes wrong — a negotiating position appears to have leaked, a strategy is anticipated — you have a fixed point to reason from, and the set of possible explanations shrinks dramatically.
It also means the value decays. On the day of issue, your window is zero. A year later, your window is a year, and the document is telling you about a building that no longer exists in the same configuration: works have happened, furniture has moved, people have left, new equipment has arrived in meeting rooms.
Which is why frequency is a risk question
Providers who recommend a standard quarterly interval before knowing anything about your organisation are selling a subscription rather than giving advice. The right interval depends on what you discuss, who wants it, and how often your estate changes — and for many organisations the honest recommendation is less frequent than what they are usually quoted.
What matters at least as much as the interval is the trigger list: the events that should prompt an unscheduled inspection regardless of when the last one happened. A transaction entering a sensitive phase. A dispute heading toward litigation. A senior departure on bad terms. Building or refurbishment works, which are the single most common way something gets into a ceiling void legitimately. And the obvious one — information appearing somewhere it should not have.
If a provider hands you a clean report without explaining any of this, they have given you a document and withheld the part that makes it useful. Ask what it does not cover. A good practitioner will already be telling you.
Written by Marko Tuisk, director of TSCM Partners Ltd (company 16842743).