EMSEC – emission security – is the branch of information security that deals with what your equipment reveals without sending anything: the unintentional electromagnetic emanations every electronic device produces as it works.
It is the least familiar of the security disciplines, and the one most often assumed to be covered by something else. It is not.
The terminology map
The terms overlap and are routinely mixed up, including by people who should know better:
- EMSEC – the discipline: protecting against information leakage via emanations.
- TEMPEST – originally a US and NATO codename, now the common term for both the attack area and the certification standards (SDIP-27) that define protected equipment.
- RÖS – the Swedish term, röjande signaler (compromising emanations), with protection levels U1–U3.
- COMSEC – communication security: encryption, key management, protocol security. The sibling discipline.
In everyday use, “TEMPEST” is what people say when they mean EMSEC, and it is usually clear enough. Where precision matters – in a requirement specification, for instance – EMSEC is the discipline and TEMPEST names the standards you certify against.
Why encryption does not help
This is the single most important point, and the reason EMSEC exists as a separate discipline rather than a footnote to COMSEC.
Encryption protects data in transit and at rest. The emanation happens somewhere else entirely: at the keyboard as a key is pressed, at the display as a character is drawn, at the printer as a page is produced, on the internal bus as plaintext moves between components.
All of that occurs before encryption, on the plaintext. A perfectly encrypted link on a leaking workstation still leaks the plaintext – the encryption is doing its job correctly and is simply irrelevant to this channel.
The same logic applies to every logical control. Access control, endpoint protection, network segmentation and audit logging all govern what happens inside the system. Emanations are not inside the system; they are physics happening around it.
What leaks, concretely
The classic case, and still the most productive for an attacker. A display refreshes at a fixed rate, producing a repeating pattern that can be captured and rendered back into a readable image. What appears on the screen is, in the worst case, what appears on the attacker’s screen.
Each key produces a characteristic signal, both radiated and conducted along the cable. Reconstruction is harder than video but well documented.
Motors, print engines and paper handling produce emissions that correlate with what is being printed.
Data moving between processor, memory and peripherals radiates. This is why certification covers the whole device rather than its interfaces.
Emissions leave by two routes: radiated through the air, and conducted along power leads, earth conductors and signal cables. The conducted route is the one people forget – a receiver connected to the same electrical circuit, in the basement or the next building, never has to come near the room.
The threat has become ordinary
Capturing and reconstructing an emanation once required laboratory equipment and specialist expertise. Software-defined radio moved the receiver into hardware costing a few hundred euros, and the signal processing needed to make sense of the capture now runs on an ordinary computer.
This does not make interception easy – it still needs proximity, skill and time. But the population of actors capable of it has grown well past state intelligence services, and it keeps growing. Today’s threat level covers what that means in practice.
Meeting it
EMSEC protection is engineered into equipment and verified per product by accredited laboratories. It cannot be bolted on afterwards, for a reason worth stating plainly: the protection consists of shielding, filtering, internal layout and cable design, all of which are decisions made while the device is being built. There is no aftermarket product that makes a commercial monitor stop emitting.
In practice that means three things for a buyer:
- Certified equipment is bought as certified equipment, matched to a level that reflects how close an adversary can get. The levels are explained here.
- Every device in the zone counts. One uncertified peripheral on a certified desk is a working transmitter next to a protected screen.
- Installation is part of the protection. Filtered power, separated red and black cabling, and fiber wherever a conductor would otherwise cross the zone boundary. Galvanic isolation explains why the last point matters as much as the equipment itself.
Fibersystem manufactures EMSEC and TEMPEST-certified equipment – complete workplaces from computer to speakers, plus rugged variants for field use – as a NATO-certified TEMPEST supplier. Certification papers for a specific product are available on request.






