Every electronic device – a monitor, a keyboard, a printer, the cable between them – unintentionally radiates electromagnetic signals. With the right receiver, those emissions can be reconstructed into the information being processed: from tens or hundreds of metres away, from a neighbouring room, from a vehicle in the street, through walls. No malware is involved. No log ever records it. The target has no way of knowing it happened.
TEMPEST is the NATO term for protecting against this attack. In Sweden it is called RÖS – röjande signaler, compromising emanations. The two describe the same problem and are governed by parallel standards.
Why it is not an IT problem
Network security assumes an attacker has to get in. Emanation security starts from the opposite premise: the information is already leaving, continuously, through physics rather than through a connection.
That distinction matters because it changes what a defence looks like. A firewall, an air gap and a hardened operating system all address the network path. None of them touch the electromagnetic one. An air-gapped classified workstation with no network interface at all still radiates the contents of its screen.
The practical consequence is that emanation security cannot be added afterwards. It is a property of how a device is built – shielding, filtering, cable design, component placement – and it is why certified equipment is designed as certified equipment from the start.
What actually leaks
Three mechanisms carry information out of a device:
The device acts as an unintentional transmitter. Display signals are the classic case: the pixel clock produces a repeating pattern that can be captured and rendered back into a readable image. Keyboards, printers and video cables all radiate in characteristic ways.
Signals travel out along the mains cable, the earth conductor or any other wire leaving the protected area. A receiver connected further along the same electrical circuit – in the basement, in the next building – picks them up without ever entering the room.
A cable carrying classified traffic runs alongside one leaving the building, and induces a copy of its signal into it. This is why physical separation between red and black cabling is part of a certified installation, not an afterthought.
Certification levels
| NATO (SDIP-27) | Sweden | Protection |
|---|---|---|
| Level A | RÖS U1 | Highest – for the most exposed environments |
| Level B | RÖS U2 | High – for protected zones |
| Level C | RÖS U3 | Basic zone protection |
The levels correspond to how much inherent protection the surrounding environment provides. Level A assumes an adversary can get close – an embassy on a city street, a vehicle in the car park. Level C assumes a controlled perimeter has already pushed the attacker to a distance. Choosing a level is therefore a statement about the environment, not only about the information.
Certification is performed per product, in a specific configuration, by an accredited test laboratory. Two consequences follow, and both surprise people regularly:
- A certificate does not transfer. Modifying a certified unit – swapping a component, adding a card, replacing the enclosure – voids the approval. Commercial equipment cannot be certified after purchase.
- The chain is only as strong as its weakest device. A TEMPEST workplace holds only if every device in it meets the level: computer, monitor, keyboard, mouse, phone, speakers, printer, camera. One uncertified peripheral undoes the rest.
The certification levels are covered in more detail here, including how SDIP-27 relates to the Swedish RÖS levels in practice.
Who needs to care
Emanation security is not a general IT requirement. It becomes relevant when three things are true at once: the information is valuable enough for a capable actor to invest in collecting it, that actor can get physically close enough, and the consequence of disclosure is serious.
That combination describes defence and intelligence work, government handling of classified material, diplomatic missions, and increasingly critical infrastructure – control rooms for power, water and transport, where the operator is a plausible target for a state actor rather than an opportunist.
It also describes situations people do not always recognise: a conference room where a negotiation is held, a laboratory working on protected research, a bank’s dealing room. The question is not what sector you are in, but who would find the information worth the effort.
The threat has become cheaper
Two things have changed over the past decade. Software-defined radio has moved the cost of a capable receiver from specialist laboratory equipment into hardware that costs a few hundred euros. And the processing needed to reconstruct a signal – once the hard part – is now ordinary signal processing on an ordinary computer.
That does not mean interception is trivial. Reconstructing a usable image at a distance still requires skill, proximity and time. But the group of actors who can do it has grown well beyond state intelligence services, and it will keep growing. Today’s threat picture is covered separately.
What certified equipment looks like in practice
A TEMPEST-certified device is an ordinary device rebuilt to contain its own emissions. Enclosures are shielded and sealed; cables are filtered where they cross the boundary; internal layout separates signal paths that must not couple; and the fiber optic connection replaces copper wherever a wire would otherwise carry emissions out of the room. Fiber matters here for the same reason it matters elsewhere in secure design – it provides galvanic isolation and carries no electromagnetic signature.
The result looks like normal office equipment and is used like normal office equipment. That is the point: a protection that changes how people work is a protection that gets bypassed.
Fibersystem is a NATO-certified TEMPEST supplier and Sweden’s manufacturer of Level A and Level B equipment – complete computer workplaces, monitors, printers, IP phones, projectors and video conference systems, designed and built in Stockholm. Certification papers for a specific product are available on request.






