The Risk3 Protocol
Every engagement, in every jurisdiction, follows the same five-stage methodology. It is documented, repeatable, and built for one test: would this finding survive cross-examination?
Why a named methodology matters
Anyone can buy detection equipment. What separates a professional countermeasures practice from a technician with a spectrum analyser is process: documented steps, contemporaneous records, evidential handling and reporting a board or a court can rely on. The Risk3 Protocol is that process, refined over thirty years of fieldwork in Asia.
Clients see the protocol in three places: in the proposal, where scope is defined against it; in the field, where each stage produces a record; and in the report, where findings are traceable to the stage and method that produced them.
The five stages
Threat model
What information, if overheard, would cause material damage? Where does it exist as conversation: which rooms, which people, which travel? Who benefits from collecting it, and what access could they plausibly obtain? The answers set inspection depth and cadence. The threat model is agreed with you before anything else happens.
Scope and conflict check
Every matter is conflict-checked before detail is taken. You then receive a fixed-fee written scope: environments, methods, schedule, deliverables and confidentiality undertakings. No hourly drift, no equipment upselling. There is nothing to upsell. We sell no equipment.
Layered detection
Fieldwork applies overlapping methods, each covering the blind spots of the others: wideband RF spectrum survey against baseline, non-linear junction detection for dormant electronics, thermal imaging, disciplined physical search, and optical device detection for cameras whether or not they transmit. We do not publish operational specifics.
Infrastructure examination
The most common findings are not planted devices but exploitable infrastructure: conference endpoints on auto-answer, unmanaged smart-building systems, recording features nobody disabled. The protocol treats your own systems as part of the attack surface and examines telephony, conferencing, cabling and network-connected building services accordingly.
Reporting and remediation
Engagements conclude with a written report: scope, methodology, findings, exposure assessment and prioritised remediation, in language a board can act on. Where devices are found, evidence is preserved with documented chain of custody. Where matters escalate, the same team supports counsel through to testimony.
Report standards
Every Risk3 report includes: the scope and limits of the inspection; the methods applied in each environment; findings with supporting technical detail; an assessment of residual exposure; prioritised recommendations; and the lead consultant's declaration. Reports are dated, version-controlled and suitable for audit committee records, insurers, courts and arbitral tribunals. A redacted sample report is available to qualified enquirers under confidentiality.
If something is found
The protocol's most important branch runs from discovery. The scene is secured and knowledge restricted immediately. Nothing is touched, removed or disclosed without your instruction. You are briefed away from the affected environment, on three options: preserve and analyse, exploit under control to identify the operator, or remove. Each option's legal and commercial consequences are set out before you choose, with counsel involved where appropriate. Discovery is the beginning of a matter, and the protocol treats it that way.
One protocol. Four ways to engage it.
Single inspections, electronic privacy audits, standing programmes and incident response. Scope and pricing are fixed in writing before work begins.
Detect · Defeat · Nullify