The shift toward remote and hybrid working has expanded the physical footprint over which an organisation’s confidential information is discussed, from a controlled, monitored office environment to a diverse and largely uncontrolled set of home offices, co-working spaces, and temporary workspaces, each with its own distinct and largely unmanaged TSCM risk profile. This article addresses the specific surveillance and confidentiality risks that remote working introduces and obstacles that our corporate investigators run into.
Home Office Bug Detection
A home office lacks the institutional security controls of a corporate premises — no controlled visitor access, no managed contractor vetting, no organisational oversight of the furniture, equipment, or smart devices present in the room. Where an employee or executive regularly conducts sensitive business from a home office, the same categories of device addressed throughout this series — concealed in power sockets, smart home devices, or everyday objects — remain a genuine risk, compounded by the home environment’s far greater exposure to visitors, deliveries, and household members whose own security awareness may not match corporate standards.
Executive Home Working
Senior executives who conduct board calls, M&A discussions, or other highly sensitive business from a home office present a particular concentration of risk, because the value of the information discussed is comparable to a boardroom but the physical security of the environment is, by default, considerably lower. We recommend that organisations with executives engaging in significant home-based confidential work consider extending TSCM coverage to the relevant home office, with the executive’s consent, as part of a broader executive protection programme.
Video Conference Risks
Video conferencing introduces a digital surveillance risk that sits alongside the physical TSCM concerns addressed elsewhere in this series: compromised conferencing accounts, unauthorised meeting access, and the camera and microphone on the user’s own device being a far more direct and centrally exploitable surveillance vector than any physically planted bug. Strong account security, verified meeting links, and awareness of what is visible in the camera’s background during a confidential call are practical mitigations that sit at the boundary between our TSCM and cyber security guidance.
Smart Devices
The proliferation of smart speakers, smart displays, connected doorbells, and other always-listening or always-recording consumer devices in domestic environments creates a TSCM consideration that has no real equivalent in a controlled corporate office, where such devices are typically restricted or absent entirely. An executive or employee discussing sensitive business within range of a smart speaker, regardless of the device manufacturer’s own data practices, has introduced an additional and largely uncontrolled potential listening point into the conversation. We recommend a clear policy on smart devices in any home environment used regularly for confidential business discussion.
Temporary Offices
Serviced offices, co-working spaces, and other temporary workspaces used by remote or hybrid staff share many of the risk characteristics addressed in our article on temporary office and event bug sweeps: limited visibility of who has previously occupied the space, shared infrastructure with other tenants, and no organisational control over the premises’ broader security practices. Where confidential work is regularly conducted from such a space, the same pre-use sweep principle applied to event venues is a sensible and proportionate precaution.
Building a Remote Working Security Policy
Organisations with a substantial remote or hybrid workforce engaging in confidential work should develop a specific policy addressing the risks set out in this article: guidance on smart devices in working areas, minimum standards for home office security where regular confidential work occurs, and a clear process for requesting a TSCM assessment of a specific home or temporary working environment where the seniority of the individual or the sensitivity of the work justifies it.
Concerned about remote working security risks in your organisation? Contact ARF Private Detectives for expert advice and TSCM support.

