The unit as writtenunit scope
This is the official scope of the unit, kept here (folded) so its intended coverage is visible at a glance and my own notes can be placed against it. The notes below are mine; they follow this scope where it still holds and go past it where current practice has moved on. For this unit that happens often, because almost every number a small office network is built from has changed since the unit was written: the internet connection, the wireless standard, the cabling category, and the law that now applies to the devices sitting on it.
Unit: ICTSAS310 Install, configure and secure a small office or home office network. A national ICT unit in the systems administration and support sector, used here as an elective in the Certificate IV study. Release 1, first released with ICT Information and Communications Technology Training Package Version 6.0. It supersedes and is equivalent to ICTSAS307. No prerequisites, and no licensing, legislative or certification requirements apply to the unit itself at the time of publication, which is not the same thing as saying the work is unregulated; the cabling part of it is, and that is covered below. Nominal hours are 50, from the Victorian purchasing guide for the ICT training package.
What the unit describes: the skills and knowledge required to identify available network components and client requirements, and to install, configure and secure those components as part of a small office or home office (SOHO) network. It applies to people who work under a level of supervision and who have experience with analysis and problem solving when working with technologies.
The five elements and their performance criteria, as written:
Confirm client requirements and identify required network equipment. Identify and clarify client requirements for the SOHO network; identify, develop and document the SOHO network design according to client requirements; identify network materials according to the design; obtain vendor and service supplier specifications and the cost of identified components; and present the design to the client and secure sign-off.
Install and configure hardware and software. Develop installation plans according to organisational requirements; obtain approval for plans, security clearance and timing with the required people; confirm cables and connectors are installed to industry standards and requirements; install and configure hardware to the network design and industry standards; and install and configure software to the network design and industry standards.
Test network. Troubleshoot client-side connectivity using the required networking settings; test installed software and hardware to organisational procedures; test network settings to organisational procedures; and resolve identified problems to organisational procedures.
Secure network. Identify security features for the SOHO network; apply the identified security features to organisational procedures; and troubleshoot security intrusion symptoms and issues.
Finalise network installation and configuration. Finalise and document the network design, hardware, software and security features; document installation, boot up and configuration procedures to client requirements; and hand over and secure sign-off from the client.
Performance evidence: install, configure and secure a SOHO network on at least one occasion. In the course of that, install, configure and test hardware and software for the network, covering network technologies, devices, protocols, and network cables and connectors; install, configure and test the network according to client requirements and produce the required documentation; troubleshoot client-side connectivity and security system symptoms and issues; liaise with vendors and service suppliers to obtain specifications, availability and cost of identified components, and to develop installation plans that incorporate task prioritisation, contingency arrangements and minimum disruption to clients; and document the final network design, security features, and installation, boot up and configuration procedures.
Knowledge evidence: industry accepted hardware and software products, including those used for networks; building requirements that may be used in installing, configuring and securing an office; data and voice transmission technologies and protocols; hardware and software installation procedures; organisational procedures, including software and hardware testing methods, network setting testing methods, and problem resolution procedures; local area network capabilities and characteristics, including network types, internet protocol addressing, switch and hub operation, and both wired and wireless network connections; networking technologies, including network operating systems and cabling standards; network tools, set-up and configuration procedures; security implications and methods for a home office network; software packages supported by the organisation; industry standards applicable to small networks; and installation and configuration tools.
Foundation skills: reading, to interpret and critically evaluate technical texts and compare specifications against costs; writing, to record information in the required format for network plans, instructions and technical specifications; oral communication, to confirm requirements using effective technique and industry standard technical language; numeracy, to compare numerical information and forecast costs; planning and organising; problem solving, both intuitive in familiar situations and systematic for configuration and testing; self-management; and technology.
Assessment conditions: the skills must be demonstrated in a workplace or a simulated environment with conditions typical of a working environment, with access to industry standard software, hardware and networking technologies, server and workstation systems, internet connectivity, live networks, network components, networked devices, vendor hardware and software, and technical documentation.
Source: the application, elements, performance criteria and foundation skills are the training.gov.au record for ICTSAS310, read from the published unit descriptor PDF on 14 September 2026; the performance evidence, knowledge evidence and assessment conditions are from the companion assessment requirements document at the same source. Nominal hours are from the Victorian purchasing guide for the ICT training package.
What a small office network actually is, and why this unit is security work
A SOHO network is the whole computing environment of a business that has no IT department. That is the definition worth holding, because it explains every decision in the unit. There is no server room, no network engineer, no change advisory board and no help desk. There is one cabinet on a wall, a handful of devices, and a person who runs a business and has no interest in any of it beyond wanting it to work.
The unit is written as an installation unit, and it reads at first like a shopping and cabling exercise. It is not. Look at where the elements actually sit: one of the five is securing the network, another is testing it, and the knowledge evidence names security implications and methods for a home office network as a topic in its own right. The reason is that a small office is now a target in the same way a large one is, and it is a softer one. The Australian Signals Directorate's Annual Cyber Threat Report 2024-25, released on 14 October 2025, records over 84,700 cybercrime reports for the financial year, roughly one every six minutes, and puts the average self-reported cost of cybercrime to a small business at $56,600, up 14 per cent on the year before. That figure is an average per report from businesses that reported, not an average across all small businesses, which is a distinction worth keeping straight; but the direction is not in doubt. The report also cites an Australian Institute of Criminology finding that 22 per cent of small and medium enterprise owners reported cybercrime impacts in 2024.
So the technician who installs this network is the only person who will ever make a deliberate security decision about it. Whatever is configured on the day of installation is what the business runs for the next five years. A default password left in place, a flat network with no segmentation, a firmware version never updated again: these are not oversights that someone else will catch later, because there is no someone else. That is the frame for everything below.
Here is the shift worth understanding before anything else. The classic small office network was a perimeter: a router at the edge, everything inside it trusted, and security meaning "keep the outside out". That model assumed the work happened in the office, on the office's devices, over the office's connection. Almost none of that holds now. The staff have laptops that go home, the files are in a cloud service rather than on a server in the cupboard, the printer talks to a vendor's cloud, and half the devices on the network are appliances that nobody thinks of as computers. The perimeter is still worth building well, and this unit builds it, but it is no longer the whole of the job. The current answer is layered: a hardened edge, a segmented interior, identity and multi-factor authentication protecting the accounts that actually hold the data, and devices kept current. A page that taught only the edge would teach a real skill that is quietly doing less than it used to.
flowchart TD I[Internet] --> M[NBN connection device] M --> R["Router and firewall<br/>NAT, DHCP, DNS, VPN"] R --> SW["Managed switch<br/>VLANs, PoE"] SW --> AP1["Access point: staff SSID"] SW --> AP2["Access point: guest and IoT SSIDs"] SW --> W[Wired workstations and docks] SW --> P[Multifunction printers] AP1 --> L[Staff laptops] AP2 --> G[Guest devices] AP2 --> T[Smart devices, cameras, sensors] R -.-> C["Cloud services<br/>where the data actually lives"]
Starting with the client, and the questions that get you the requirements
The first element is a conversation, and it is the part of the unit most people underrate. Everything downstream, the design, the quote, the cabling, the security posture, is determined by what the client tells you in the first half hour, and clients do not describe networks. They describe problems and hopes: "the wifi drops out in the back room", "we want to be able to work from home", "the last person set it up and we don't know the password".
The technique is to translate business statements into technical requirements, and to keep asking until each one is specific enough to design against. A short structured list that gets most of the way there:
What to establish before designing anything
The people and the devices. How many staff, how many are on site at once, and what does each person use? Laptops, desktops, tablets, phones, docking stations. Who else connects: clients in a waiting area, contractors, cleaners, a point-of-sale terminal?
The premises. Floor area and shape, number of rooms, wall construction, ceiling type and height, where power is, whether the building is leased and what the landlord will allow you to do to it. Concrete, brick, foil-backed insulation and metal stud walls all attenuate wireless badly, and you cannot see any of that from a floor plan.
What the work actually needs. Cloud accounting and email is a light load; video conferencing all day, large file transfers, CAD, or video editing are not. Upload matters more than most clients expect, because video calls, cloud backup and file sync all push data out.
What already exists. The current internet service and who it is with, any existing cabling, the age and model of anything being kept, and whether there is a network cabinet or somewhere one could go.
Uptime and consequence. What happens to the business if the network is down for a day? A design that needs a backup connection is a different design and a different price.
Growth. How many staff in three years? Cabling outlives every other component in the room, so it is sized for the future rather than for today.
Budget, said out loud early. A design the client cannot afford is wasted work for both of you.
Two habits separate a competent requirements conversation from a poor one. The first is confirming in writing: after the meeting, send back a plain-language summary of what you understood and ask the client to confirm it. That document is the thing you design against, the thing you quote against, and the thing you point at when someone later remembers the conversation differently. The second is using language the client can actually follow. The foundation skills for this unit name this directly, and it is a real skill: explaining that the office needs two access points rather than one because the concrete wall between the front and back of the tenancy will not pass a wireless signal is a technical fact delivered in a sentence anyone can act on. Explaining that you need to address 5 GHz attenuation through a high-density medium is the same fact delivered uselessly.
The design then gets presented and signed off before work starts. That is performance criterion 1.5 and it is not bureaucracy; it is the point at which the client's expectation and your plan are made to match, in writing, while changing either is still cheap.
Getting to the premises: the internet connection
The wide area network connection is the one component the technician usually does not install and cannot fix, so knowing the types, their real performance and their current state matters for choosing and for setting expectations. This is also the part of the unit where old material is most reliably wrong, because the Australian access network has changed substantially since 2023.
Fibre to the premises runs optical fibre all the way into the building, terminating on a network termination device on the wall. It is the best of the fixed options: highest speeds, symmetric-capable, and unaffected by distance from the exchange in the way copper is.
Fibre to the node and fibre to the curb run fibre to a street cabinet or a pit and use the existing copper for the last stretch. Speed depends on the length and condition of that copper, which is why two neighbours can get different results. Both are being retired. NBN Co announced in January 2025 that it would upgrade the remaining roughly 622,000 fibre to the node premises, over 95 per cent of them to fibre to the premises, with completion expected by the end of 2030; in September 2025 it announced work commencing on the final stage, with more than 228,000 premises under construction and full fibre expected to reach approximately 11 million premises, about 94 per cent of the fixed line footprint, by 2030. NBN Co has not published a date for disconnecting the copper, so the honest position is that the upgrade has a schedule and the retirement does not.
Hybrid fibre coaxial uses a fibre backbone with coaxial cable for the final run into the premises, inherited from the old pay television networks.
Fixed wireless delivers the service by radio from an NBN tower to an antenna on the roof. This one has moved a long way: the $750 million upgrade programme completed in February 2025 across more than 2,300 towers, and the current tiers include Fixed Wireless Home Fast at peak wholesale 200 to 250 Mbps down, and Fixed Wireless Superfast at peak 400 Mbps down. Any material describing NBN fixed wireless as a congested 25/5 fallback is describing a service that no longer exists.
Mobile broadband uses the cellular networks, through a router with a SIM in it. It is the usual choice for a temporary office, a site office, or a backup link. The constraint that catches people is that Australia's 3G networks were switched off through 2024, with Telstra and Optus closing from 28 October 2024, and the shutdown affected not only 3G handsets but some 4G devices that fell back to 3G for voice and emergency calls. Anything cellular in a small office, a backup router, an alarm panel, an EFTPOS terminal, a lift phone, a medical alarm, must be 4G or better with voice over LTE.
Satellite is the remote option, and it is the one that has changed most. Geostationary satellite, which is what NBN Sky Muster is, sits far enough out that the round trip imposes latency no engineering can remove; the ACCC measured Sky Muster at an average 664.9 milliseconds in its first satellite performance report, published 5 December 2024. Low earth orbit constellations sit far closer, and the same ACCC report measured Starlink at 29.8 milliseconds average latency with 192 Mbps average download. That gap, roughly 665 milliseconds against 30, is the most useful number on this page for a remote client, because it is the difference between a connection that can carry a voice call, a video meeting or a remote desktop session and one that cannot. NBN Co announced on 27 August 2026 that it has partnered with Amazon Leo for an "nbn LEO" service, with eligible customers generally expected to begin transitioning from around mid-2027, progressively as capacity becomes available and subject to final testing, at initial wholesale speeds up to 50/10 and 100/20 Mbps. Sky Muster and Sky Muster Plus are generally expected to keep operating while customers move across. For the Northern Territory this is the single most consequential item in the unit, and it is still in progress, so it is worth restating the dates whenever it comes up.
On speed, the tier ladder itself changed on 14 September 2025, when NBN Co activated higher wholesale speeds on fibre to the premises and hybrid fibre coaxial at no extra wholesale cost. Home Fast moved from 100/20 to 500/50 Mbps, Home Superfast from 250/25 to 750/50, Home Ultrafast to approximately 1000/100, and a new Home Hyperfast tier arrived at 2000/200 on fibre. Around 9.8 million premises were eligible. Note that retail plan names differ from wholesale tier names and both differ from the marketing on a provider's website, so quote the speeds rather than the names. Note also that these are residential tiers; a small office that runs anything latency-sensitive or upload-heavy should at least be shown business grade fibre, where business nbn Enterprise Ethernet offers symmetric wholesale speeds up to nearly 10 Gbps, at a price that reflects it.
One design question follows from all of this and belongs in the requirements conversation: does the business need a second connection? A small office that cannot trade without the internet, which now includes anything using cloud accounting, cloud point of sale or voice over IP, is a business whose whole revenue depends on one service it does not control. A 4G or 5G failover in the router is inexpensive and is the single highest-value resilience decision available at this scale.
The local network: what each box actually does
The knowledge evidence asks for local area network capabilities and characteristics, and the honest way to teach that is one device at a time, because the small office market sells them fused into single units and that hides what is happening.
The modem, or network termination device, converts between the carrier's transmission method and Ethernet. On fibre to the premises this is the NBN-supplied box on the wall and you do not touch it. On fibre to the node it is a VDSL modem. On mobile broadband it is the cellular radio.
The router connects two different networks and decides where traffic goes. In a small office it does several jobs at once: it routes between the local network and the internet; it performs network address translation, which lets many devices share one public address; it runs a DHCP server handing out addresses; it usually forwards DNS queries; it enforces firewall rules; and it may terminate a virtual private network for remote workers. When people say "the router" in a small office they usually mean this box, and it is the most consequential single device on the network from a security point of view.
The switch connects devices on the same network and forwards traffic between them. This is where the unit's hub-versus-switch question lives, and it is worth being precise because the distinction explains why one of them no longer exists.
A hub is a repeater. Data arriving on one port is sent out every other port, with no inspection of where it is meant to go. Every device on the hub sees every frame, every device shares the available bandwidth, and two devices transmitting at once cause a collision that both have to back off from and retry. A switch reads the destination MAC address of each frame, looks it up in its MAC address table, which maps addresses to the ports they were learned on, and forwards the frame out only the port that reaches the destination. If the address is not in the table, it floods the frame out every port except the one it arrived on, and learns the answer from the reply. The practical consequences are that each switch port gets the full bandwidth rather than a share, that collisions are eliminated, and that a device cannot passively see traffic intended for its neighbours. That last point is why hubs are a security problem as well as a performance one, and why they disappeared from the market rather than merely falling out of fashion. Encountering one in the field today means encountering something old enough to be replaced on sight.
Switches divide further. An unmanaged switch is a plug-in box with no configuration. A managed switch supports VLANs, port security, quality of service, link aggregation, monitoring and remote management, and it is the one this unit's security element needs. A small office that wants segmented guest and internal traffic needs a managed switch; a small office that wants to power its access points and cameras over the network cable needs power over Ethernet, which is a switch feature and a budget item.
The wireless access point bridges wireless clients onto the wired network. In consumer equipment it is inside the router; in a properly designed small office it is one or more separate devices placed where the coverage is needed and connected back by cable.
The firewall inspects traffic against a rule set and permits or blocks it. Every small office router contains one. A dedicated firewall or unified threat management appliance adds intrusion prevention, content filtering, application awareness and often licensed threat intelligence feeds.
The server, where one exists, runs a network operating system: Windows Server, or a Linux distribution such as Ubuntu Server, Debian or Red Hat Enterprise Linux. The important current point about small office servers is how many have gone. Ten years ago a small office server held the files, the printing, the accounts database and the user accounts. Most of those roles have moved to cloud services, and the remaining on-premises boxes are usually network attached storage, a backup target, or a line-of-business application that will not run anywhere else. Knowing network operating systems remains part of the unit, and knowing why an office might not need one is now part of the design conversation.
Addressing a small network
Internet protocol addressing is named in the knowledge evidence, and the small office case is simple enough to hold entirely in your head, which makes it a good place to learn the concepts properly.
A device on the local network gets a private IPv4 address from one of three reserved ranges: 10.0.0.0 to 10.255.255.255, 172.16.0.0 to 172.31.255.255, or 192.168.0.0 to 192.168.255.255. These are not routable on the internet, which is the point; the router translates between them and its single public address on the way out. A typical small office uses something inside 192.168.x.0/24 or 10.x.x.0/24, giving 254 usable host addresses, which is ample.
The subnet mask says which part of the address identifies the network and which identifies the host. A /24, written as 255.255.255.0, means the first three octets are the network and the last is the host. The default gateway is the address of the router, the place a device sends anything not on its own subnet. DNS servers translate names to addresses, and in a small office they are usually either the router itself forwarding upstream, the internet provider's servers, or a deliberately chosen public resolver.
DHCP hands all of this out automatically: address, mask, gateway and DNS, on a lease that expires and renews. The design decision is which devices should not use it. Anything other devices need to find reliably should have a fixed address: the router, the switch, the access points, the printers, a network attached storage box, any camera recorder. There are two ways to fix an address, and confusing them causes a specific and common fault. A static address configured on the device itself is invisible to the DHCP server, so nothing stops the server handing the same address to something else later, producing an address conflict that appears weeks after the install. A DHCP reservation configured on the router ties an address to a device's MAC address, so the device still asks for an address by DHCP and always receives the same one, and the server knows the address is taken. Reservations are the better practice at this scale, and "someone set a static address by hand" is a fault worth learning to recognise, because the symptom is intermittent and the cause is not local to the device that fails.
IPv6 deserves a short, honest paragraph. The address space exhaustion that drove its creation is real, adoption has been climbing for two decades, and progress is genuinely uneven: some Australian providers enable it by default and others still do not, so the proportion of traffic carried over it drifts year to year rather than following a clean curve. For a small office in 2026 the practical position is that IPv4 with network address translation still carries the work, that the router probably supports IPv6 and may have it switched on without anyone noticing, and that a technician should know what a colon-separated address is, that a link-local address begins fe80::, and that IPv6 has no equivalent of network address translation because every device can have a globally routable address. That last point has a security consequence worth naming: on IPv4 the address translation incidentally hides internal devices, and people came to treat that as a firewall. It never was one, and on IPv6 the accident is gone, so the firewall rules have to be explicit.
Cabling, the part that outlives everything else
Cabling standards are named in the knowledge evidence, and the reason to take them seriously is economic rather than technical: every other component in a small office will be replaced two or three times before the cable in the walls is touched. Cabling is the only decision in the unit that is genuinely expensive to revisit, so it is the one place to specify above today's requirement.
The category question. Category 5e carries gigabit Ethernet to 100 metres and is still working in thousands of offices. Category 6 improves the margins. Category 6A is the current recommendation for new installations, and the argument for it is not headline bandwidth, which a small office will not use, but two practical drivers. The first is power over Ethernet heat: running power down a bundled cable raises its temperature, which degrades its performance, and the current TIA guidance for power over Ethernet applications is Category 6A or higher, with ambient temperature at or below 45 degrees Celsius, cable rated to at least 60 degrees, and no tight bundling. The second is access point uplinks, because a single Wi-Fi 6 or Wi-Fi 7 access point can exceed one gigabit and needs an uplink that can carry it.
The intermediate speeds are the useful part. 2.5GBASE-T and 5GBASE-T were standardised as IEEE 802.3bz-2016, since folded into the consolidated IEEE 802.3 base standard, and they exist precisely to solve the uplink problem without recabling: 2.5 gigabit runs over existing Category 5e to 100 metres, and 5 gigabit over Category 6 to 100 metres. So an office with installed Category 5e can carry a modern access point by replacing the switch rather than the cable. Material that presents the ladder as one gigabit then ten gigabit with nothing between is describing a market that no longer exists; multigigabit ports are now common on small business switches.
The standards themselves. The generic cabling standard is the ISO/IEC 11801 series; the current Part 1 is ISO/IEC 11801-1:2017, amended by Amendment 1, published late 2025. The Australian adoption is AS/NZS 11801.1:2019, reissued incorporating Amendment No. 1 on 9 December 2022, which supersedes AS/NZS 3080:2013; it still tracks the 2017 ISO edition and has not yet picked up the 2025 amendment, which is a normal lag rather than an error. The American equivalent, widely cited in vendor documentation, is the ANSI/TIA-568 series, and the current balanced twisted-pair document is ANSI/TIA-568.2-E, published with ANSI/TIA-568.5-1 and announced by TIA on 5 November 2024. Anything citing 568.2-D is one revision behind, and the revision matters more than usual because 568.2-E introduced new DC resistance unbalance specifications with the consequence that links certified to 568.2-D may not comply with the current requirements.
The Australian legal point, which is the one that catches people. In Australia, anyone who connects fixed or concealed cabling to a telecommunications network must be a registered cabler. This is not a professional courtesy; it is a regulatory requirement administered by the ACMA. The current instrument is the Telecommunications (Cabling Provider) Rules 2025, made 21 March 2025 and registered as F2025L00386, which remade the Telecommunications Cabling Provider Rules 2014. Any page, deck or assessment answer still citing the 2014 rules as current is now wrong, although the underlying obligation is unchanged in substance and the three registration types remain open, restricted and lift; the ACMA sets out what is involved in working as a registered cabler. The technical standards a cabler works to are AS/CA S009:2020 for installation requirements and AS/CA S008:2020 for cabling products, both published 20 August 2020, and are listed on the ACMA's Australian cabling standards page.
The practical effect on a small office job is that the cabling is normally subcontracted to a registered cabler, and the technician's part is specifying it, scheduling it, coordinating it and checking the result. That is why the unit asks you to confirm cables and connectors are installed to industry standards rather than to install them yourself, and why a small office quote almost always has a cabling subcontractor line on it.
Interference. The unit asks how to build a network in an area with significant electromagnetic or radio frequency interference, and the answer is either shielded twisted pair, where the shield is bonded and earthed properly or it does nothing, or fibre optic cable, which carries light and is immune to electrical interference entirely. The practical small office cases are a cable run near a lift motor room, near air conditioning plant, alongside a run of mains power, or through a workshop with welding or large motors. Separation from power cabling, correct earthing and route planning solve most of it before either of those products is needed.
Wireless: standards, spectrum and coverage
Wireless is where a small office network is judged, because it is the part the client experiences directly, and it is also where the delivered material dates fastest.
The standards, and their marketing names. The Wi-Fi Alliance's generation numbers map onto IEEE amendments: Wi-Fi 4 is 802.11n, Wi-Fi 5 is 802.11ac, Wi-Fi 6 is 802.11ax, and Wi-Fi 7 is 802.11be. Wi-Fi 6E is not a separate IEEE amendment at all; it is Wi-Fi 6 operating in the 6 GHz band, and the Alliance introduced that certification on 7 January 2021. Wi-Fi 6 is now folded into the base standard: IEEE Std 802.11-2024, the current base revision, was published 28 April 2025 and absorbs the earlier amendments. Wi-Fi 7 is both certified and ratified, with Wi-Fi CERTIFIED 7 launching on 8 January 2024 and IEEE Std 802.11be-2024 published on 22 July 2025, per the IEEE 802.11 working group's published standards list.
That sequence is worth pausing on, because it explains something about the industry that confuses people reading standards documents. Certification came eighteen months before publication. Vendors ship to draft amendments, the Alliance certifies interoperability against the draft, and the IEEE publishes later. It is normal, it works, and it means "is it ratified" is rarely the useful question; "is it Wi-Fi CERTIFIED" usually is.
Work on the next generation is under way. IEEE 802.11bn, which will become Wi-Fi 8, is in comment resolution on its first draft. Two other amendments in the 802.11 pipeline are new subject matter that has no equivalent in older material: 802.11bi is an enhanced privacy amendment responding to device tracking through MAC addresses and traffic analysis, and 802.11bt addresses post-quantum cryptography for Wi-Fi.
The bands, and the Australian regulatory position. 2.4 GHz travels furthest and penetrates walls best, but has only three non-overlapping channels and shares the band with Bluetooth, microwave ovens, cordless phones and every neighbour. 5 GHz has far more channels and far more capacity, at shorter range and with worse wall penetration. 6 GHz is the new spectrum that makes Wi-Fi 6E and Wi-Fi 7 worth having, and in Australia it is only partly open. The ACMA opened the lower 6 GHz band, 5925 to 6425 MHz, to radio local area networks in March 2022, in two device classes: low power indoor at a maximum 24 dBm EIRP, indoor use only, and very low power at a maximum 14 dBm EIRP in any location. The upper band, 6425 to 7125 MHz, was deferred. The ACMA published an outcomes paper on the future use of the upper band in December 2024 and ran a further consultation on automatic frequency coordination for standard-power 6 GHz Wi-Fi that opened 5 November 2025 and closed 6 February 2026, now marked under review. So as at September 2026 the position in Australia is that 6 GHz Wi-Fi is indoor low power only; there is no standard-power outdoor 6 GHz and automatic frequency coordination is not yet authorised. That is a live regulatory question, not a settled one, and it bears directly on whether a Wi-Fi 7 access point is worth its price in a given premises.
Designing coverage rather than buying a bigger box. The commonest small office wireless fault is one device trying to cover a floor plan it cannot reach. The right answer is more access points at lower power, placed by the shape of the building, rather than one at maximum power. Points that make the difference:
Wireless design at small office scale
Survey the building, not the floor plan. Wall construction decides everything. Solid concrete, double brick, foil-backed insulation, metal stud, mirrors and plasterboard with a wire mesh behind it all attenuate heavily. A concrete wall between the front and back of a tenancy usually means two access points, not one moved slightly.
Mount in the open, and mount high. Access points belong on a ceiling or a high wall in the space they serve, not inside the comms cabinet with the door shut, not behind a monitor, and not on the floor under a desk.
Plan the channels. In 2.4 GHz use only 1, 6 and 11, and use narrow channel width; anything wider makes the interference problem worse for everyone including you. In 5 GHz there is room to spread out, and it is worth checking which channels carry radar detection requirements in your area.
Cable each access point back. A wireless mesh link costs capacity because the radio carries both the client traffic and the backhaul. Mesh is a legitimate answer where cabling is impossible, particularly in a leased or heritage building, and a poor first choice where cabling is possible.
Separate the SSIDs by purpose, not by floor. One network name for staff, one for guests, one for smart devices. Roaming between access points on the same SSID is the behaviour you want; forcing users to pick a network by location is the behaviour you do not.
The management model has changed at the same time, and this is the part most likely to differ from older material. A small office today typically runs a cloud-managed controller with separate access points rather than a single consumer router, because that is what makes VLAN segmentation, per-SSID policy, centralised firmware updates and remote support practical for a business with no IT staff. Two vendor facts will make older reading lists wrong: Cisco Meraki Go was discontinued, with end of sale on 29 April 2025 and end of support scheduled for 30 July 2027, and Aruba Instant On was rebranded HPE Networking Instant On on 2 May 2024. Ubiquiti UniFi and TP-Link Omada keep their names. The lesson generalises beyond this unit: product names decay at the speed of the company that owns them, so a recommendation copied from a three-year-old document is checked before it is repeated.
Choosing and quoting the equipment
Performance criteria 1.3 and 1.4 ask you to identify the materials and to obtain vendor and supplier specifications and costs, and the thinking behind the shopping list is the part worth learning.
The first decision is architectural: one all-in-one device, or separate components. An all-in-one router with built-in wireless is cheap, simple and appropriate for a genuine home office of one or two people. Separate components, meaning a router or security gateway, a managed switch and one or more access points, cost more and are the right answer as soon as the office has multiple rooms, needs segmentation, or has anyone who will ever ask for a guest network. The deciding questions are coverage, segmentation and who will support it.
The second decision is where the management happens. Cloud-managed platforms put the configuration in a vendor portal, which means a technician can see and fix the network without driving to the site, and means the client is dependent on that vendor's service continuing to exist. Locally managed equipment has no such dependency and no remote visibility. For a business with no IT staff and an external support provider, remote manageability is usually worth more than the independence.
Then the components themselves get specified against the requirements: enough switch ports with headroom for growth, power over Ethernet if the access points or cameras need it, multigigabit ports if the access points warrant them, access points matched to the coverage plan and the band plan, a router sized for the connection speed and for any VPN load, an uninterruptible power supply for the cabinet, and the cabinet, patch panel and cabling subcontractor to install it. The quote carries all of it, plus labour, plus any software subscriptions the design depends on, which now routinely includes cloud printer management, endpoint protection and backup.
Two habits are worth building here. Get specifications from the vendor's own current documentation rather than from a reseller listing, because reseller pages lag and sometimes describe superseded models under the same name. And record where each figure came from, because a quote is a document that someone will question later, and being able to say which page on which date gave you the throughput number is the difference between a professional answer and a guess.
Planning the installation
The second element opens with planning, and the performance evidence names the three things a plan has to incorporate: task prioritisation, contingency arrangements and minimum disruption to clients. Those three are the whole of the discipline.
Task prioritisation means sequencing the work so that each step is possible when it starts. Cabling before hardware, because the hardware plugs into it. Power and cabinet before the equipment goes in. The internet service ordered early, because a carrier connection can take weeks and is the one item you cannot expedite. Configuration staged on the bench before the site visit wherever possible, so that time on site is spent installing rather than typing.
Contingency arrangements mean deciding in advance what happens when something does not arrive or does not work. The carrier connection is not ready on the day: what does the office use in the meantime? A device is dead out of the box: is there a spare, or does the cutover move? The cabling subcontractor finds the ceiling is inaccessible: what is the alternative route and what does it cost? Contingency planning is not pessimism; it is the difference between a delay and a crisis.
Minimum disruption means understanding the client's week before you choose a day. A cutover happens outside trading hours, or on the quietest day, or in stages so that the business is never entirely down. The client is told, in advance and in writing, what will be unavailable and for how long. Where the business cannot stop at all, the new network is built alongside the old one and devices are moved across in batches.
Performance criterion 2.2 adds the parts that involve other people: approval for the plan, security clearance, and timing agreed with the required personnel. In practice that means the client's written approval to proceed, arrangements for site access including keys, alarm codes and after-hours building access, notification to a building manager or landlord where the work touches the fabric of the building, and confirmed times with the cabling subcontractor and any other trades. On a leased tenancy, permission to penetrate walls or use the ceiling space often has to come from the landlord rather than the client, and finding that out on the day is a lost day.
A short written installation plan covering the sequence, the dates, the people, the contingencies and the disruption window is the deliverable. It is also the document that protects you, because it records what was agreed.
Installing and configuring the hardware and software
With the plan agreed, the install itself is methodical rather than difficult. The sequence that works:
Mount and power the cabinet, and terminate the cabling to the patch panel, which the registered cabler does. Test and certify the cabling before anything is plugged into it, because a marginal termination found later presents as an intermittent network fault and costs hours to trace.
Configure the router first, because everything else depends on it. That means the internet connection, the local address range, DHCP scope and reservations, DNS, firewall rules, and remote access if the design includes it. Change the administrator credentials before the device is ever reachable from the network, not afterwards.
Configure the switch: VLANs, port assignments, power over Ethernet where needed, management address, administrator credentials.
Mount and configure the access points: SSIDs mapped to VLANs, security mode, transmit power, channels, and the band steering and roaming behaviour.
Then the client devices and software. This is performance criterion 2.5 and it is easy to under-prepare. A typical small office build means joining machines to whatever identity system is in use, installing the applications on the supported list, setting file associations and default applications the way the client asked, connecting printers and installing their management software, configuring backup, and confirming endpoint protection is present, enabled and current. It is worth taking the client's software requirements as literally as the network requirements: "client computers open Office documents in LibreOffice by default" is a configuration decision with a right answer and a wrong one, and it will be noticed.
A habit worth forming: build a configuration record as you go rather than reconstructing one afterwards. Every address, every credential, every VLAN number, every SSID, every firmware version, written down at the moment it is set. That record becomes the handover documentation the fifth element asks for, and it is far more accurate than anything assembled from memory a week later.
Testing the network
The third element is testing, and the knowledge evidence asks specifically for organisational procedures covering software and hardware testing methods and network setting testing methods. The point of a test procedure is that it is written down before the work starts and produces a recorded result, so that "it works" becomes a statement someone can check.
The command line tools are the core of it and they repay being learned properly rather than pattern-matched:
The tools, and what each one actually tells you
ipconfig on Windows, ifconfig or ip addr on Linux and macOS. Shows the device's own address, mask, gateway and DNS servers. This is the first command, because it tells you whether the device got a sensible address at all. An address in 169.254.x.x means the device asked for DHCP and got no answer.
ping sends an ICMP echo request and reports whether a reply came back and how long it took. Ping the gateway to test the local network; ping a public address such as 8.8.8.8 to test routing and the internet connection; ping a name such as google.com to test DNS as well. The order matters, because it isolates the layer.
tracert on Windows, traceroute elsewhere. Shows each hop on the path and the latency to it, which tells you where a problem is rather than only that there is one.
nslookup or dig queries DNS directly, which separates a name resolution fault from a connectivity fault.
A speed test, run from a wired connection and then from wireless, at more than one location. Testing only over wireless conflates two different questions.
The switch and access point consoles, which report link speed and duplex, port errors, power over Ethernet draw, connected client counts and signal strength. Port error counters climbing is the classic signature of a marginal cable.
Device configuration is done either through a terminal emulator such as PuTTY over a console or SSH connection, or through a web interface in a browser, and knowing both matters because vendor tooling varies. Cisco equipment runs Cisco IOS, which is the network operating system answer for routers and switches in the unit's knowledge evidence; small business equipment more often presents a web interface or a cloud dashboard.
Testing the software and the client experience is the other half, and it is the half more likely to be skipped. Does each application launch and work? Does printing work from every machine to every printer, including scan to email or scan to folder? Does the backup actually run, and can a file be restored from it? Does a staff member's laptop get on the staff wireless and a visitor's phone get onto the guest wireless, and can the visitor's phone reach the internet but not the printer? That last test is the one that proves the segmentation, and it takes thirty seconds.
Troubleshooting as a method, not a list of fixes
Performance criteria 3.1 and 3.4 ask for troubleshooting and problem resolution, and the durable skill is the method rather than a memorised catalogue of faults. The method is to divide the problem in half and test the halves.
The layered approach is the standard version of that. Start at the bottom and work up: is there a physical link, meaning is the cable in, is the port lit, is the device powered? Then addressing: does the device have a correct address, mask and gateway? Then local connectivity: can it reach the gateway? Then routing: can it reach a public address? Then name resolution: can it resolve a name? Then the application: does the specific program work, and does it work for anyone else?
The other half of the method is scoping. Is it one device or all of them? One application or everything? One location or the whole office? Constant or intermittent? Did it ever work, or has it just stopped? Each answer eliminates a large class of causes. A fault affecting one device is not a router fault. A fault affecting everyone at once, that started this morning, is not a cabling fault.
Faults that recur often enough to recognise on sight: an address conflict from a hand-configured static address; a 169.254 address meaning DHCP did not answer; a duplex mismatch showing as a working but very slow link with rising error counters; a marginal or over-length cable run showing as intermittence under load; wireless dropping in one part of the building, which is a coverage problem rather than a device problem; a device that works wired and not wirelessly, which localises the fault immediately; and DNS failures, which present as "the internet is down" while ping to an address still works.
Performance criterion 4.3 extends this to security intrusion symptoms, which is a different diagnostic habit. What does a compromise look like on a small office network? Unfamiliar devices in the router's client list. Outbound traffic at odd hours or to unexpected destinations. Administrative settings changed that nobody changed. DNS servers on the router pointing somewhere that is not what you configured, which is a classic router compromise. Endpoint protection disabled or reporting detections. Staff reporting password prompts they did not trigger, or multi-factor prompts they did not request, which is the signature of someone trying stolen credentials. Certificate warnings appearing on sites that never produced them. The response at this scale is to isolate first, preserve what you can, change credentials from a known-clean device, and escalate; a small business will rarely have anyone to escalate to internally, which makes the technician's judgement about when to call in help part of the job.
Securing the network: the devices
The fourth element asks you to identify security features and apply them, and the honest way to teach it is in layers, because no single control carries the load. This first layer is the devices themselves.
Change every default credential, on every device, at install. Routers, switches, access points, printers, cameras, network storage. Default credentials for every consumer and small business device are published, searchable and used by automated scanners continuously. This is the single highest-value minute of the whole installation.
Keep firmware and software current. Router and access point firmware, switch firmware, printer firmware, operating systems and applications. Where the equipment supports automatic updates and the client has no change control, enable them; the risk of an unattended update is smaller than the risk of a device that is never updated again. Enabling automatic updates is also one of the ASD's small business baseline recommendations.
Run endpoint protection and keep its definitions current. On Windows that means Microsoft Defender Antivirus and Microsoft Defender Firewall, both of which are capable and both of which are sometimes found switched off. Out-of-date definitions and a disabled firewall are the two most common findings on a machine that has been running unattended, and both are checked as part of the install.
Use multi-factor authentication everywhere it is offered. This is the ASD's first recommendation to small business and it is the correct one, because the dominant attack on a small business is not an exploit against the network, it is someone signing in with a password. Multi-factor authentication defeats the great majority of that. The current preference, where it is available, is phishing-resistant authentication, meaning passkeys or hardware security keys rather than codes by SMS, because codes can be relayed by an attacker in real time and SMS is additionally exposed to SIM swapping and number porting.
Apply least privilege. Staff work in standard accounts rather than administrator accounts; the administrator account is separate and used deliberately. This one control stops a large share of malware from installing itself.
Enforce sensible passwords, which now means something different from what it used to. Length is what matters; composition rules and forced periodic rotation are no longer recommended practice, having been dropped from the current authoritative guidance because both push people towards predictable patterns. Long passphrases, unique per service, kept in a password manager, changed when there is reason to believe they have been exposed.
Back up, and test the restore. A backup that has never been restored from is a hope, not a control. The small office pattern that works is one copy in the cloud service the business already uses, one copy somewhere separate, and a restore tested at least once so that the client has seen it work.
Securing the network: the interior
The second layer is the network itself, and this is where the difference between a consumer install and a professional one is visible.
The firewall at the edge blocks unsolicited inbound traffic by default, and the discipline is to keep it that way. Port forwarding is the control most often loosened and least often tightened again; every forwarded port is a service published to the entire internet. Where a business needs remote access to something on the network, a VPN is the right answer rather than exposing the service. Remote management of the router from the internet is switched off unless there is a specific reason, and Universal Plug and Play, which lets any device on the network open a hole in the firewall by asking, is switched off as a matter of course.
Segmentation with VLANs is the control that has moved from enterprise practice into the reach of a small office, and it is the one worth arguing for in a quote. The principle is that devices which have no business talking to each other should not be able to. A workable small office scheme is a staff network carrying the computers, a guest network with internet access only and no reach into anything internal, and a device network for printers, cameras, smart devices and building systems, which can be reached from staff devices but cannot itself initiate connections inward. The value is containment: a compromised guest device or a compromised camera cannot see the accounting machine.
A VPN for remote workers, terminating on the router, so that access to anything on the office network happens through an authenticated encrypted tunnel rather than through a published port. The scope is worth thinking about: if the business's files are in a cloud service, remote staff may not need a VPN at all, and adding one is complexity without benefit.
DNS filtering blocks name lookups for known malicious and unwanted domains, which stops a fair proportion of phishing and malware before a connection is made. It is now a standard feature rather than an add-on, available on the router, through a public filtering resolver, or as a subscription service. Treat it as useful defence in depth rather than as a control that can be relied on alone.
Logging, and someone to read it. A small office rarely has anyone watching logs, and pretending otherwise is dishonest. What is achievable is that the equipment keeps logs, that they are retained somewhere that survives the device being wiped, and that alerting is configured for the few events that matter: an administrative login, a configuration change, a failed login burst, the connection dropping.
The idea underneath all of this has a name worth knowing, because the client will hear it and the industry has committed to it. Zero trust means that no network location is treated as inherently safe, so being "inside" the office network confers no automatic privilege; every request is evaluated on who the user is, whether their device is in a known good state, and what they are trying to reach. A small office will not implement zero trust as an architecture, but the direction explains why the advice has shifted from "build a strong perimeter" to "assume the perimeter will be crossed and limit what that gets you", which is exactly what segmentation and multi-factor authentication do.
Securing the wireless, and a control that has been overtaken
Wireless security deserves its own treatment, partly because it is the layer most exposed, and partly because this is the clearest example in the unit of advice that used to be right and is no longer.
WPA3 is the current standard, and it is not optional for certified equipment. The Wi-Fi Alliance states that WPA3 is mandatory for Wi-Fi CERTIFIED devices; the mandate took effect on 1 July 2020 for new certifications. WPA3-Personal replaces WPA2's pre-shared key handshake with Simultaneous Authentication of Equals, which removes the offline dictionary attack that made a captured WPA2 handshake worth cracking, and adds forward secrecy so that a later compromise of the passphrase does not decrypt traffic already recorded. WPA3-Enterprise is the version with 802.1X authentication behind it. WPA2 still works, is still on a very large installed base, and should be treated as what you find rather than what you configure.
The mixed-mode advice is where the ground has moved. For years the standard recommendation was to set the access point to WPA2/WPA3 transition mode, so that new devices negotiate WPA3 and older ones fall back to WPA2 on the same network name. On 6 GHz that advice no longer applies: Wi-Fi 7 mandates WPA3 in the 6 GHz band, and WPA3-Personal Transition Mode is not available there, with the further complication that legacy clients meeting an unfamiliar security element during association often fail to connect at all rather than failing gracefully. The industry's answer is a compatibility mode built on Robust Security Network Override, which lets an access point advertise WPA2 through the legacy element while capable clients negotiate WPA3, and client support for it is still uncommon as at September 2026. The practical consequence for a technician is concrete: an old device that cannot join the network is not necessarily broken, and the fix may be a separate 2.4 or 5 GHz SSID for legacy equipment rather than weakening the main one.
Separate SSIDs by trust level. A staff network with strong authentication, a guest network isolated from everything internal, and a device network for printers, cameras and smart devices. Client isolation, which stops wireless clients on the same SSID talking to each other, belongs on the guest network as a matter of course. Where the business is large enough to have staff turnover, 802.1X with a RADIUS server, so each person authenticates as themselves and can be removed individually, is better than a shared passphrase that has to be changed on every device when someone leaves.
Three controls that older material lists and current guidance does not. This is worth stating carefully rather than dismissively, because it is a good lesson in how to read a source.
Wi-Fi Protected Setup has a documented protocol flaw. The external registrar PIN can be brute-forced in roughly 11,000 attempts rather than the 100 million its eight digits suggest, because the protocol validates the halves separately; this was published by CERT as VU#723755 on 27 December 2011, with a CVSS base score of 9.3, and the recommended remedy is to disable the external registrar feature. Fifteen years later the Wi-Fi Alliance still lists Wi-Fi Protected Setup as a live certification programme, which is itself instructive about how slowly a convenience feature dies. Switch it off.
MAC address filtering and hiding the SSID are the other two. The technical objection to both is the same: MAC addresses and network names both travel in unencrypted management frames, so anyone who can listen to the air can read both, and a MAC address can be changed on most devices in a menu. So neither stops an attacker, while both add real administrative cost and generate support calls. The careful way to say this is not to claim a government source condemns them, because as far as I can establish none does. What can be said precisely is what current authoritative guidance actually recommends, and what it leaves out: the ASD's own advanced-steps personal cyber security guidance recommends WPA3 or WPA2 where WPA3 is unsupported, changing the default router credentials, changing the default network name so it does not reveal the router model, enabling the guest wireless feature, keeping router firmware updated, and disabling remote management and Universal Plug and Play. It does not mention MAC address filtering, hidden network names or Wi-Fi Protected Setup at all. An absence is weaker evidence than a statement, and it is the evidence that exists. The honest teaching position is that these are obscurity rather than security, that they may have a marginal place as a nuisance control, and that a technician who lists them as the network's security features has not secured the network.
Smart devices, and the law that now applies to them
The knowledge evidence asks for security implications and methods for a home office network, and the largest change in what that means has nothing to do with the network equipment. It is the number of other things now plugged into it.
A current small office holds far more than computers: multifunction printers with hard drives and web interfaces, security cameras and their recorders, door controllers, voice assistants, smart televisions in meeting rooms, environmental sensors, smart lighting and air conditioning controllers, and whatever the landlord's building management system has left on the network. Each is a computer running an operating system nobody patches, made by a company that may or may not still support it, often with a cloud service behind it that the business has never read the terms of. This is the operational technology and consumer device convergence that used to be an industrial topic and is now a small office one, and it is the single strongest argument for the segmentation described above.
As at March 2026 there is also law about it, which is new ground and is not in any pre-2025 material. The Cyber Security Act 2024 (Cth), registered as C2024A00098, was assented to on 29 November 2024. Its Part 2 creates security standards for relevant connectable products, and the standard itself is the Cyber Security (Security Standards for Smart Devices) Rules 2025, registered as F2025L00276, made on 4 March 2025 and commenced on 4 March 2026 after a twelve-month transition. Three obligations fall on manufacturers and suppliers:
What the smart device rules require
No universal default passwords. Each device must ship with a unique password, or require the user to set one that is not a factory default. This ends the practice that made whole categories of device trivially findable and controllable at scale.
A published way to report security issues, with status updates on resolution, so that a researcher or a customer who finds a flaw has somewhere to send it.
A published support period, including an end date for security updates, so a buyer can see how long the device will be maintained before they buy it.
The rules cover most smart devices manufactured on or from 4 March 2026 for personal, domestic or household use, and exclude desktop computers, laptops, smartphones and tablets among other exclusions. Devices manufactured before the commencement date are out of scope, so existing stock on the shelf and everything already installed is unaffected. Suppliers must provide products accompanied by a statement of compliance, and the Secretary of the Department of Home Affairs may issue compliance, stop and recall notices, conduct product testing, and publish the details of non-compliant entities where a recall notice is not followed. The Home Affairs policy page carries the detail, and its factsheet states the requirements follow the first three principles of the ETSI EN 303 645 standard and the United Kingdom's Product Security and Telecommunications Infrastructure Regulations 2023.
What this means for the technician is practical rather than legal. The published support period is now a specification you can ask for and compare, in the same way as a throughput figure, and it belongs in a quote when a client is choosing between two cameras. The unique-password requirement removes one class of problem from new devices while leaving it entirely intact on the installed base, which is where the work is. And the exclusions matter: a laptop is not covered by these rules, so the assumption that "there is a standard now" does not extend across the whole network.
What a small business has to report, and when
Two reporting obligations now bear on a business this size, and a technician who installs the network is often the only person who will ever mention them.
Ransomware payment reporting has been active since 30 May 2025 under Part 3 of the Cyber Security Act 2024. A reporting business entity must report within 72 hours of making a ransomware or cyber extortion payment, or of becoming aware that a payment was made on its behalf, to ASD through the reporting form at cyber.gov.au. The threshold is annual turnover of $3 million or more in the previous financial year, with a pro-rata formula for a business that operated for part of a year, and certain critical infrastructure entities are captured regardless of turnover. The first phase, from 30 May 2025 to 31 December 2025, was education-first; from 1 January 2026 ASD moved to active regulatory compliance. The Act also limits how a report can be used and disclosed, preserves legal professional privilege, and restricts the admissibility of reported information against the reporting entity, which is the design intent: encourage reporting by making it safe to report.
The number to notice is $3 million. That is not a large business. A great many small offices with a handful of staff are above it, and very few of them know this obligation exists.
Privacy obligations are the other half. The Privacy Act 1988 (Cth) exempts small businesses with an annual turnover of $3 million or less, so many small offices are outside it, and the OAIC's own guidance says so. The exemption has exceptions that catch more businesses than people expect: a small business is covered regardless of turnover if it provides a health service, trades in personal information, is a Commonwealth contractor, operates a residential tenancy database, does credit reporting, is a reporting entity under anti-money laundering legislation, is an employee association or protected action ballot agent, holds Consumer Data Right accreditation, or has opted in voluntarily. A medical practice, a physiotherapist, an allied health clinic and a childcare centre are all covered; so is any business that buys or sells contact lists. Where the Act does apply, the Notifiable Data Breaches scheme applies with it, and a breach likely to result in serious harm has to be assessed and notified.
Whether the small business exemption survives is a live question rather than a settled one. It has been on the reform agenda through successive stages of the Privacy Act review, and as at September 2026 the OAIC's small business guidance still describes the exemption as current. The practical advice to give a client does not actually depend on the answer: a business that holds customer records should handle them as though the Act applied, because the commercial and reputational consequences of losing them do not wait for legislation.
Artificial intelligence and the small office
Artificial intelligence enters this unit in two directions, and neither appears anywhere in the delivered material because neither existed in a form worth writing about when it was produced.
As an attacker capability, aimed squarely at businesses this size. The ASD's Annual Cyber Threat Report 2024-25 states that the prevalence of artificial intelligence "almost certainly enables malicious cyber actors to execute attacks on a larger scale and at a faster rate", and describes criminals using generative tools to automate the analysis of stolen datasets and identify valuable credentials, and to create high-quality video, fake voices, websites, know-your-customer records and spearphishing emails. The effect on a small business is specific. The tells that used to identify a fraudulent email, awkward phrasing, obvious translation errors, generic greetings, are gone, and the economics have changed: an attack that once had to be worth a criminal's personal time can now be run against thousands of small businesses at once. Business email compromise accounted for 15 per cent of self-reported cybercrime for businesses in that reporting period. In the ACCC's National Anti-Scam Centre figures for calendar year 2025, released 30 March 2026, total reported scam losses were $2.18 billion, down 29.7 per cent from the 2022 peak but up 7.8 per cent on 2024, with payment redirection, which is the closest proxy in that dataset for business email compromise, accounting for $166.8 million. ASIC reported removing 19,400 scams in the twelve months to August 2026, a 182 per cent increase year on year, with its chair attributing much of the growth to artificial intelligence making deceptive content more convincing.
What follows for the network build is not a product. It is that the controls which defeat this class of attack are identity controls and process controls rather than network controls: multi-factor authentication on email, a rule that bank account changes are verified by a phone call to a known number rather than a number in the email, and staff who have been told that a familiar voice on the phone is no longer proof of anything. A technician who installs a well-segmented network and leaves the client's email single-factor has secured the wrong thing.
As something now present inside the network. Network management platforms have begun adding assistants that answer questions about the network and suggest configuration changes; Cisco Meraki's AI Assistant, for instance, remained in public beta as at its documentation's last update of 19 August 2026 rather than general availability, which is a fair indicator of where this feature class sits generally. Treat these as useful for triage and not as a source of truth, for the plain reason that a suggestion about a client's network is a change to a client's network and needs the same verification as any other change. Meanwhile the devices themselves increasingly carry model-driven features, cameras that classify what they see, assistants that listen, printers that process documents in a vendor cloud, and each of those is a data flow leaving the premises that the client has probably not considered. Asking what a device sends, and to where, is becoming part of specifying it.
The broader governance picture is moving too, and honestly it is moving faster than the small business guidance is keeping up with. ASD's current Small Business Cyber Security Guide, the January 2025 edition, does not mention smart devices or artificial intelligence at all, which is a real gap in otherwise sound advice rather than a criticism of the advice it does give. The frameworks above it are also in flux: ASD opened a consultation on 15 June 2026, closing 12 July 2026, proposing to replace the Essential Eight Maturity Model with an ISM-grounded "Essentials" series beginning with enterprise IT and with further chapters foreshadowed for operational technology, cloud and potentially agentic AI. No retirement date has been published, and a senior ASD officer's indicative timeline given to the trade press points at roughly 2028. So the Essential Eight remains the current Australian baseline and is on notice, and anyone building a small office network today should apply it while watching what replaces it.
Documentation and handover
The fifth element is documentation, and it is where a professional job separates itself from a competent one. The test is simple: could a different technician, who has never seen this site, take this document and work on the network without guessing?
What the handover pack contains:
The handover pack
The network diagram. What is connected to what, with device names, model numbers, physical locations and the port each device is plugged into. Drawn, not described.
The address plan. The subnet, the DHCP range, every reserved and fixed address with the device it belongs to, the gateway, the DNS servers, and the VLAN numbering with what each VLAN is for.
The wireless configuration. SSIDs, which VLAN each maps to, security mode, access point locations, channel and power settings.
The device inventory. Every device: make, model, serial number, firmware version at handover, purchase date, warranty period, and where the vendor's support is.
Credentials, handled properly. Administrative credentials belong in the client's password manager, handed over to the business owner, not emailed and not written in the same document as everything else. The business must own its own credentials; a support provider that keeps them to itself has made the client a hostage rather than a customer.
The configuration and boot-up procedures. How the network is brought up from cold after a power failure, in what order, and what to check. This is performance criterion 5.2 and it is the page the client will actually use.
The security features applied, written plainly enough for a non-technical owner to understand what they have: what is segmented from what, what updates automatically, what the backup covers and how often, what multi-factor authentication is enabled on.
Test results. What was tested, with what result, on what date.
Support and escalation. Who to call, the internet provider's account and fault numbers, and warranty details.
The handover conversation matters as much as the pack. Walk the owner through what they now have, in their language, and be specific about the parts that need a human decision later: firmware that will need updating, warranties that will expire, the backup that needs testing again in six months, and the fact that adding a new device to the wrong network undoes some of the segmentation. Then get sign-off, which is performance criterion 5.3 and closes the job.
One habit that pays for itself: date the document and put a review date on it. A network document with no date is a network document nobody trusts, and an undated document that has been wrong for two years looks exactly like one that is right.
Sources used
The unit's application, elements, performance criteria, foundation skills, performance evidence, knowledge evidence and assessment conditions are from the published training.gov.au unit descriptor and assessment requirements documents for ICTSAS310, read 14 September 2026; nominal hours are from the Victorian purchasing guide for the ICT training package. Wireless standards and certification dates are from the Wi-Fi Alliance (the Wi-Fi CERTIFIED 7 announcement of 8 January 2024, the Wi-Fi CERTIFIED 6E announcement of 7 January 2021, and the undated security overview page) and the IEEE 802.11 working group's published standards list, with the Wi-Fi 7 6 GHz transition-mode problem from reporting dated 21 August 2026. Australian 6 GHz spectrum arrangements are from the ACMA's March 2022 outcomes paper on the low interference potential devices class licence and its consultation on automatic frequency coordination, which opened 5 November 2025 and closed 6 February 2026. NBN facts are from NBN Co media statements: the higher speed tiers (announced 5 September 2024, activated 14 September 2025), the fibre to the node upgrade programme (13 January 2025 and 5 September 2025), the completed fixed wireless upgrade (14 February 2025), and the nbn LEO partnership with Amazon Leo (27 August 2026); satellite performance figures are from the ACCC's first satellite measurement release of 5 December 2024. The 3G shutdown date is from Australian government and ABC reporting of 28 October 2024. Cabling standards are from ISO's record for ISO/IEC 11801-1:2017 and its 2025 amendment, the Australian adoption AS/NZS 11801.1:2019 as reissued 9 December 2022, and TIA's announcement of ANSI/TIA-568.2-E on 5 November 2024, with the power over Ethernet category guidance from Siemon's summary of 24 October 2024; multigigabit Ethernet is IEEE 802.3bz-2016 against the current base standard IEEE Std 802.3-2022. Australian cabling registration is the Telecommunications (Cabling Provider) Rules 2025, made 21 March 2025 and registered as F2025L00386, with the ACMA's cabling pages and the standards AS/CA S009:2020 and AS/CA S008:2020. Small business security guidance is the ASD Small Business Cyber Security Guide of January 2025 and the ASD personal cyber security advanced steps guide of 2023; the Wi-Fi Protected Setup flaw is CERT vulnerability note VU#723755, published 27 December 2011 and last revised 10 May 2012. Threat statistics are from the ASD Annual Cyber Threat Report 2024-25, released 14 October 2025 for the 2024-25 financial year, the ACCC National Anti-Scam Centre Targeting Scams report for 2025, released 30 March 2026, and ABC reporting of ASIC's scam removal figures dated 17 August 2026. The smart device law is the Cyber Security Act 2024 (C2024A00098) and the Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276, made 4 March 2025, commenced 4 March 2026), with the Department of Home Affairs policy page and factsheets; ransomware payment reporting detail is from the Home Affairs factsheet. Privacy exemption detail is from the OAIC's small business guidance page. Vendor product status is from Cisco's Meraki Go end-of-sale communication and HPE's Instant On rebranding announcement of 2 May 2024. The Essential Eight consultation is ASD's own announcement of 15 June 2026, with the indicative retirement timeline from iTnews reporting of 24 June 2026.