Cyber Town; training data next 100 miles

VU23220 Develop and carry out a cyber security industry project

VU23220100 nominal hoursIn progressUpdated 3 September 2026

The unit as writtenunit scope

This folded block is the official scope, kept out of the way of the notes. VU23220 is a core unit in 22603VIC Certificate IV in Cyber Security, the Victorian accredited course, with a nominal duration of 100 hours. It carries two prerequisites, VU23213 Utilise basic network concepts and protocols required in cyber security and VU23215 Test concepts and procedures for cyber security. At 100 hours it is the largest unit in the qualification, and it is the capstone: everything else in the course feeds it. Hours, core placement, prerequisites and assessment conditions are confirmed against the accredited course document for 22603VIC (V1, accreditation period 1 January 2023 to 31 December 2027, published by the Victorian Department of Education and Training, 2022), which also carries the elements and performance criteria set out below. The Victoria University unit page for VU23220 (vu.edu.au, no publication date shown, read 2 September 2026) agrees on hours, prerequisites and the unit description. A later version of the course document, V1.2, was posted in February 2026; it could not be opened during this build, so the wording below is V1.

What the unit is about. The accredited descriptor says the unit covers the performance outcomes, skills and knowledge to develop and undertake a project that simulates a real cyber security industry environment. The project may use a Cyber Security Operations Centre (CSOC) sandbox or an equivalent laboratory environment, so that the student can demonstrate configuring and testing firewalls, implementing intrusion detection and prevention systems, and evaluating and identifying traffic anomalies. Red and blue teaming exercises to identify security breaches and apply mitigation strategies are part of the project. The unit applies to individuals working as cyber security technicians within a team environment. No licensing or certification requirements apply.

Elements and performance criteria. Six elements, quoted in substance from the accredited course document.

Establish project team: select team members; determine individual responsibilities; establish team performance criteria; define the methodology of team performance measurement.

Determine context of business need or problem: determine scope and system boundaries together with the problem solving methodology; gather background information and prepare questions appropriate to the business problem; identify and document objectives and expected outcomes; identify key elements for project milestones; develop a work plan statement.

Support the project plan development: determine the process for identifying tasks and resources; prepare a schedule of project tasks with realistic timeframes and costs; allocate specific responsibilities to team members; develop a process to manage risks and unexpected events that may affect objectives or timelines.

Evaluate the suitability of the gathered resources: identify the key components required from the project; allocate resources; define the function and operation of the selected resources allocated to team members.

Implement the project design: select suitable systematic processes to implement the project; define and allocate subtasks; develop the subtasks; define a systematic testing procedure; plan and execute red and blue teaming exercises as part of the project; verify the functionality of the project in part or in full; generate documentation for the process such as meeting minutes, reports and emails.

Support project completion and handover: develop an implementation plan with minimal end user disruption; draft technical documentation including project timeframes, scope and cost; submit that documentation for approval; evaluate the developed project risk strategy; present a plan to train end users where required; obtain final project sign-off from the sponsor and key stakeholders; close the project and document experience gained and lessons learnt.

Foundation skills. Reading, to interpret the problem brief and related documentation. Writing, to prepare reports and related documentation. Oral communication, to deliver presentations to clients and to communicate and problem solve with team members. Technical, to install and use software packages.

Performance evidence. Participation in a team based cyber security project, contributing to the development, execution and evaluation of the project, in a real or simulated industry environment, demonstrating competency across all elements, performance criteria and foundation skills.

Knowledge evidence. Team work fundamentals; using project planning tools; creating, configuring and interconnecting virtualised devices; configuring basic features of firewalls; implementing tools to detect data anomalies, with intrusion detection and prevention systems, security information and event management tools, endpoint protection and Wireshark given as examples; models of cyber security for an organisation; components of a Cyber Security Operations Centre; and red and blue teaming exercises. The range of conditions notes that the listed tools are examples only and may be replaced or added to, which is the clause that lets a 2026 delivery teach current tooling rather than the tooling named in 2022.

Assessment conditions. The unit can be assessed in the workplace or in a simulated workplace environment, and where it is simulated the range of conditions must reflect a realistic workplace environment. Resources required: access to others to form a team, computer equipment, networking equipment, computer software and a virtualised testing environment, and relevant documentation. Assessors must satisfy the assessor requirements in the applicable vocational education and training legislation, frameworks and standards.

How CDU delivers it. The unit is clustered with ICTICT443 Work collaboratively in the ICT industry and assessed through a direct observation report, a structured activity project, a direct observation presentation and a structured activity role play. The project brief is a simulated tender for Top End Tours, a Northern Territory tour operator, carried forward from VU23217 and VU23221.

A note on how these notes treat the scope. The syllabus was accredited in 2023, and the taught material behind it dates from 2022. Almost every technical answer in it has moved: the SIEM market has consolidated, the endpoint categories have been renamed, the Essential Eight has been marked for retirement, Australia has passed its first standalone cyber security Act, and the free Palo Alto virtual firewall the material points at was withdrawn from sale in 2021. These notes teach the current version of each answer and say where the syllabus has been overtaken. Going past the syllabus is the intent here, not a detour.

What this unit is really about

Every other unit in this course hands you a bounded problem with a known answer. This one hands you an ambiguous document written by someone who does not fully understand what they are asking for, gives you a deadline that will not move, and asks you to produce a costed, defensible technical solution that a non-technical board will judge on how well you explain it. That is not a teaching contrivance. That is the job.

The vehicle is a tender response. Top End Tours is a fictional Darwin tour operator that has grown from three staff to more than twenty in eight years, runs a MySQL customer database of roughly twenty thousand records across a cloud server and a local backup, has five remote offices in the Northern Territory and Western Australia connected by consumer-grade DLink routers over base-level NBN, has policies last updated in 2018 that nobody follows, and has just been through a ransomware extortion attempt that a third-party investigator confirmed as a real breach. They declined to pay. They notified. They have brand damage, an owner who shouts in meetings, and a general manager who wants the problem to go away. They have released a tender for an IT and security infrastructure upgrade, and your company is bidding for it.

The scenario is doing more work than it looks. It gives you a real network to design, a real security architecture to justify, a real cost to defend, a real client relationship to manage, and a real set of legal obligations that a 2026 supplier cannot ignore. It also gives you an incumbent, IT 4 You, and an in-house IT person, Jonny Noc, both of whom have opinions about your solution and neither of whom will thank you for pointing out what they missed. If you have ever wondered why security consultants spend so much time on stakeholder management, that is the reason.

The technical weight of the unit sits in five places, and these notes are weighted accordingly: the network design and its redundancy, the firewall and segmentation architecture, the detection stack (intrusion detection, SIEM, endpoint), the red and blue team exercise that proves the detection stack works, and the lab you build to demonstrate all of it. The project process wraps around those, and it matters, but the process will not save a solution that does not stand up technically.

Did you know that most tender responses are lost on the response, not on the solution? Procurement panels score against published criteria. A technically superior bid that answers a different question to the one asked, misses an attachment, or lands after the deadline scores zero on the criteria it skipped, and there is no mechanism to fix it afterwards. That is why the writing and presentation sections of this unit are not padding.

Reading the brief: scope, boundaries and the questions nobody asked

The first technical act of the project is not technical. It is deciding what you are being asked to build, and then writing that decision down in a form the client can agree or dispute before you spend money on it.

The Top End Tours tender asks for five things: IT systems updated, security systems deployed, a video conferencing system installed, IP phones deployed, and physical security tightened. Read plainly, that is at least four separate projects with different suppliers, different lead times and different acceptance tests. The scope statement is where you turn that list into something deliverable.

A workable split for this brief puts computing endpoints and servers, networking infrastructure including the wide area network, security infrastructure, policy uplift, the training and implementation plan, and the two risk assessments in scope. It puts the cabling upgrade out of scope, on the ground that the Cat5E was recently installed and the tender does not ask for it. It puts new business software out of scope, because the tender does not ask for it and the finance system is not yours to touch. And it leaves two items genuinely debatable, remote access for staff and the website upgrade, because a reasonable reader could argue either way. Naming the debatable items is not a weakness in your scope statement. It is the thing that stops a scope dispute in month four.

The out-of-scope list is the more important half. In-scope items get costed and delivered. Out-of-scope items get argued about at handover unless somebody wrote them down. State the exclusion and state the reason, because "we did not include a cabling upgrade" reads as an oversight while "the existing Cat5E cabling was installed recently and is adequate for the proposed 1 Gbps access layer; recertification is offered as a priced option" reads as a decision.

Then there are the assumptions. A tender document written by a client who does not know what they need will always be vague in the places that cost the most money. Every assumption you make to fill a gap becomes a commercial risk if the client's actual intent was different, so assumptions belong in the response, listed, so that the client can correct them before contract rather than after. Typical gaps in this brief:

Are we designing for the two new offices in the business plan, and if so, where are they and when do they open? A design that scales to seven sites costs more than one that scales to five, and the difference is real money in WAN contracts and firewall licensing.

Have the existing policies ever been communicated to staff, and how are new policies distributed and acknowledged? A policy nobody has read is a different problem to a policy nobody agrees with, and the training plan changes accordingly.

Has the current NBN connection been adequate apart from outages, or is bandwidth itself the complaint? This changes whether you are proposing a link upgrade or a redundancy design.

When was the cabling installed, has it been certified, and are there records? Cat5E supports 1 Gbps but the installation quality determines whether it actually does.

Is event logging happening anywhere at all today, and can logs be extracted from the existing Windows machines? This is the question that determines whether you are building a detection capability or turning one on.

Is there an asset inventory? If not, your first deliverable is not a firewall, it is a list of what exists, and you should say so.

That last one is worth sitting with. You cannot secure what you have not counted, and asset inventory is the control that every framework puts first for exactly that reason. If Top End Tours cannot tell you how many endpoints they own, every number in your bid is an estimate, and honest bids say so.

The clarification meeting is where you ask these. Send the questions in advance, in writing, numbered, so the client can prepare. Minute the answers and circulate the minutes for confirmation. Those minutes become part of your evidence trail and, if the project ever goes wrong, part of the contractual record of what you were told.

Choosing how the project runs

Four development models turn up in the taught material for this unit: agile, PDBIO (plan, design and build, implement, operational), Cisco's PPDIOO (prepare, plan, design, implement, operate, optimise) and a linear "applied common sense" model that is waterfall in all but name. Any of them can be defended. The defence is what is assessed, not the choice.

The honest position in 2026 is that infrastructure projects are rarely purely one thing. A fixed-price tender with a fixed deadline and a physical equipment order has a waterfall shape imposed on it by procurement: you cannot iterate on a firewall you have not bought, and the client has signed for a defined scope at a defined price. Inside that shape, the design and configuration work benefits from short cycles, working increments and frequent client review, which is the agile contribution. The name for the result is a hybrid, and describing it accurately scores better than claiming a purity you will not practise.

Cisco's PPDIOO deserves a specific note. It is a network lifecycle model rather than a project management methodology, and it is genuinely useful for framing what happens after handover, because the operate and optimise phases are where a security solution either survives or decays. Its weakness is that it assumes an ongoing engagement. If your tender ends at handover with no managed service attached, you are proposing a model whose last two phases belong to somebody else, and you should say who.

Whichever you pick, the assessable content is the reasoning: what about this project, this client and this deadline makes this model fit. A tender response that says "we use agile" without connecting it to a fixed-date, fixed-scope infrastructure delivery is describing a preference, not a plan.

The testing methodology is a separate choice and it is the one students most often skip. Testing has to be defined before the build, because the definition of "working" is what you will be paid against. A workable structure for a project of this shape has four layers. Component testing checks that each device does what it should in isolation: the firewall passes and blocks the right traffic, the switch forwards on the right VLANs, the endpoint agent reports in. Integration testing checks that components work together: does traffic from a remote site reach the file server and get logged on the way. System testing checks the whole design against the requirement: can a user at Kununurra do their job, and does an attack from outside get seen. Acceptance testing is the client's test, run against criteria they agreed in advance, and it is the one that triggers payment.

The performance criterion about breaking a larger task into subtasks is asking for exactly this. Take "deploy the security infrastructure". Subtasks: build the firewall configuration in the lab; test the rule base against a traffic matrix; deploy to the main site in a maintenance window; verify against the same traffic matrix; deploy to remote sites; verify; enable logging to the SIEM; verify events arrive and parse correctly. Each subtask has an owner, a duration, a predecessor and a test that says it is done. That is what a work breakdown structure is for, and it is what makes a Gantt chart something other than decoration.

Designing the security operations centre

The centre of the technical solution is the security operations capability. The taught material offers five models, and they are still the right five, but what a small business actually buys in 2026 has shifted.

Dedicated SOC. On-site infrastructure, on-site staff, on-site processes. Full control, fastest response, and completely out of reach for a twenty-person tour company. Round-the-clock coverage needs somewhere between eight and twelve analysts once you account for shifts, leave and attrition, before you have bought a single tool. For Top End Tours this is the model you cost out in order to explain why you are not proposing it.

Multifunction SOC and NOC. Security operations and network operations share a facility and a team. It saves money and it means one team sees both a performance problem and an attack. The risk is well documented: when the same team owns uptime and security, uptime wins, because an outage is visible and an undetected intrusion is not.

Co-managed SOC. Some capability on site, some outsourced. In practice this is what most mid-sized Australian organisations run: local staff who know the business and own the response decisions, an external provider who watches the console overnight and escalates. It is the model that scales down furthest while keeping accountability inside the organisation.

Command SOC. A network of SOCs across multiple locations, coordinating. Relevant to national governments and global enterprises. Not relevant here.

SOC as a service. Monitoring and response delivered remotely as a subscription. No hardware, no hiring, predictable cost.

Update, current as at September 2026. The term the market now uses for the last of these is managed detection and response, and the shift is not just naming. Gartner's current definition of MDR is a service providing remotely delivered security operations centre functions enabling rapid detection, analysis, investigation and response through threat disruption and containment (gartner.com, page last updated 15 July 2026). The operative words are "response" and "containment". The older SOC-as-a-service pitch was monitoring and alerting, which left the customer holding every decision at three in the morning. MDR providers now take contracted response actions: isolating a host, disabling an account, killing a process. For an organisation with one IT person, that difference is the entire value proposition, and it is the difference you should be pricing.

Two consequences follow for a tender. First, if you propose MDR you have to specify the response authority precisely: which actions the provider may take without asking, which need approval, who can be reached out of hours, and what happens when nobody answers. A managed service with no pre-authorised containment is a paging service. Second, the vendor's platform choice becomes your platform choice, because most MDR is delivered on the provider's stack. Proposing MDR and separately proposing an unrelated SIEM is proposing to pay twice.

The components of a CSOC are conventionally described in three layers, and the layers are worth keeping distinct because a tender that only costs the third one is understating the project.

People: analysts, an incident manager, and someone who owns the detection content. The classic structure was tiered, with tier one triaging alerts, tier two investigating and tier three hunting. That structure is flattening, partly because automation absorbs the repetitive triage work and partly because tier one was where analyst burnout concentrated.

Process: the incident response plan, the playbooks, the escalation matrix, the on-call roster, the change process, and the post-incident review. Process is where most small deployments fail, because tooling can be bought in an afternoon and process cannot.

Technology: the collection layer (agents, sensors, log forwarders), the analysis layer (SIEM, detection rules, threat intelligence enrichment), the response layer (SOAR or manual runbooks) and the case management that keeps a record of what was decided and why.

flowchart LR
  subgraph Sources
    EP["Endpoints: EDR agent"]
    NET["Network: firewall, IDS, flow"]
    ID["Identity: sign-in and directory logs"]
    CLD["Cloud: SaaS and hosting audit logs"]
  end
  Sources --> COL["Collection: forwarders and connectors"]
  COL --> NORM["Parsing and normalisation"]
  NORM --> SIEM["SIEM: correlation and detection rules"]
  TI["Threat intelligence feeds"] --> SIEM
  SIEM --> ALERT["Alert queue"]
  ALERT --> TRIAGE["Analyst triage"]
  TRIAGE --> CASE["Case and evidence record"]
  TRIAGE --> RESP["Containment and response"]
  RESP --> REV["Post-incident review"]
  REV --> SIEM

The loop back from review to detection is the part that separates a working security operation from an expensive one. Every incident should change something: a rule, a policy, a configuration, a piece of training. If nothing changes, you have bought monitoring, not security.

Costing a physical CSOC space, as the taught material does, is instructive even when you are not proposing one. The equipment sits in the tens of thousands: servers, layer three switches, firewalls, a rack, red team field kits, dedicated internet. The room around it, with the build, power, cabling, air conditioning, lighting, cameras and video wall, runs several times that. That ratio is a useful thing to have seen once, because it explains why so many organisations that say they want a SOC end up buying a service instead.

The network underneath

Nothing in the security design works if the network beneath it is wrong, and the Top End Tours network is wrong in specific, diagnosable ways: a single consumer wireless router per site, a base-level NBN service with no second path, no separation between guest, staff and server traffic, and a cloud-hosted customer database reached over the same link as everything else.

The hierarchy. Campus design still resolves into access, distribution and core, and for a site of this size the distribution and core collapse into a single pair of layer three switches. The reason to keep the model in mind even when you collapse it is failure domains: the point of a hierarchy is that a problem at the access layer does not become a problem for the whole site. For the main site at Harvard Drive, a redundant pair of stacked or virtually chassised switches with layer three uplinks, and access switches dual-homed to that pair, is a defensible design at reasonable cost. For a remote office with a handful of staff, a single managed switch and a single firewall is defensible, and the redundancy conversation moves to the wide area link.

Segmentation. This is the highest-value, lowest-cost thing you can do for this client, and it will appear nowhere in the tender document because the client does not know to ask. The customer database is the asset that got them extorted. It should not be reachable from the guest network, from a tour guide's laptop, or from the reception PC that browses the web all day. A minimum sensible split for this business separates management, servers, staff workstations, voice, wireless guest access and the security tooling itself, with inter-VLAN traffic filtered rather than routed freely. Guest wireless in particular should egress straight to the internet and touch nothing internal, which is the answer to the tender's implied question about customer WAN access.

First hop redundancy. Where two routers or two layer three switches serve the same subnet, the hosts need one default gateway address that survives either device failing. HSRP is Cisco's protocol; VRRP is the IETF standard, defined in RFC 5798; GLBP adds load sharing. The assessment asks specifically for HSRP if the design includes a redundant connection, and it is worth knowing that HSRP is not a legacy curiosity. Cisco Press states directly that HSRP has not faded into history and that both HSRP and VRRP are supported across many Cisco product families (ciscopress.com, 5 August 2024). Where the design will be multi-vendor, VRRP is the safer choice for the same reason it exists.

The reasoning you need to be able to give is when redundancy is worth its cost. A remote sales office of three people can tolerate a half-day outage; a head office running a booking system that customers transact against cannot. Redundancy that costs more than the outage it prevents is a design error, and saying so in a tender demonstrates more competence than proposing dual everything.

The wide area network. This is where the taught material has aged most, and where the Northern Territory setting matters most.

The 2022 answer was a choice between traditional carrier links from Telstra, Optus or TPG with backup links, and SD-WAN with a VPN overlay. Both still exist, but the analyst framing has moved. SD-WAN is increasingly bought as part of a converged secure access service edge platform rather than as a standalone product: Gartner forecast in 2023 that by 2026 sixty per cent of new SD-WAN purchases would be part of a single-vendor SASE offering, up from fifteen per cent in 2022 (reported by Fierce Network, 10 October 2023). Whether that figure was reached is not something I could confirm, and the direction is clearer than the arrival. What is confirmable is that Gartner published a Magic Quadrant for SASE Platforms in July 2026, and that the most recent standalone SD-WAN Magic Quadrant I could locate is the 2024 edition.

The distinction worth being able to state: security service edge is the security half delivered from the cloud, covering secure web gateway, cloud access security broker, zero trust network access and firewall as a service. SASE is that converged with the network half, SD-WAN, under a single policy and management plane. Single-vendor SASE means both halves from one supplier, which buys simplicity and sells you lock-in.

Cisco's naming changed too. What the material calls vManage is now Cisco Catalyst SD-WAN Manager; Cisco's own product page carries the phrase "formerly vManage" (cisco.com, page dated 27 March 2026). The Viptela-era component names were rebranded across the board in 2023, so a 2026 tender that uses vEdge and vSmart terminology reads as dated.

What actually connects a Territory site. This is the part a Darwin bid has to get right, because a design that assumes metropolitan fibre everywhere will not survive a site visit.

NBN Enterprise Ethernet is a dedicated fibre service with symmetrical wholesale tiers up to nearly 10 Gbps, three classes of service with different traffic prioritisation, a carrier-grade network termination device with proactive monitoring, and a 99.95 per cent network availability target for service providers. Around 1.6 million business locations are eligible, and there are 322 Business Fibre Zones including 142 regional centres, where most eligible premises carry no up-front build cost (nbnco.com.au, page dated 14 July 2026). For a Darwin head office this is the sensible primary service. Whether it reaches a given address in Alice Springs or Tennant Creek is an address-level question, and the honest answer in a tender is that it will be checked before contract.

NBN Fixed Wireless completed a $750 million upgrade in February 2025, covering around 800,000 premises across roughly 345,000 square kilometres, upgrading more than 2,300 towers and quadrupling capacity. Speed tiers now reach 100/20 Mbps on Fixed Wireless Plus, 200 to 250 Mbps download on Home Fast in about ninety per cent of upgraded areas, and up to 400 Mbps on Superfast in about eighty per cent. More than 120,000 premises previously inside the Sky Muster satellite footprint moved onto Fixed Wireless for the first time (nbnco.com.au media statement, 14 February 2025).

Sky Muster Plus Premium is the satellite tier, with uncapped data for standard activities and wholesale maximums from 25/5 Mbps to 100/5 Mbps (nbnco.com.au, page last updated 25 August 2026). The number that matters for a business site is the 5 Mbps wholesale upstream maximum, combined with a fair use policy that shapes cloud uploads, system updates and unidentified traffic. That is precisely the traffic profile of a managed remote site sending logs to a SIEM and pulling patches, so a satellite-only remote office needs its monitoring and patching architecture designed around the constraint rather than fighting it.

Starlink is now the realistic high-bandwidth option for remote sites outside the fixed footprint. The business tiers are Local Priority and Global Priority, with prioritised data buckets of 50 GB, 500 GB, 1 TB and 2 TB, throttling to roughly 1 Mbps down after the bucket is exhausted, and reported speeds in the range of 135 to 310 Mbps down and 20 to 44 Mbps up, with network priority, public IP addressing and a stated 99.9 per cent availability commitment. Australian pricing reported in mid-2026 started around $108 per month for Local Priority with a $549 standard kit, rising steeply with the data bucket (WhistleOut, published 10 June 2026, last updated 2 September 2026). Those prices come from a comparison site rather than from Starlink, so a real bid re-checks them; the plan structure is consistent across sources.

For a redundant remote site, the pairing that makes design sense in the Territory is a terrestrial primary and a satellite secondary, because they fail independently. Two services from the same carrier do not.

The redundancy argument, made properly. The Optus outages are the case study that turns this from theory into a costed requirement.

On 8 November 2023 around 10.2 million Australians and 400,000 businesses lost Optus mobile and fixed services for roughly twelve to fourteen hours. Optus attributed it to routing information received from an international peering network after a routine software upgrade at about 4:05am, which exceeded preset safety levels on core routers that then self-isolated. Recovery required physical reconnection and reboots across multiple sites, which is why restoration was staged through the afternoon (ACS Information Age, 14 November 2023). The ACMA later found Optus failed to provide access to the emergency call service for 2,145 people and failed to conduct 369 welfare checks, and Optus subsidiaries paid over $12 million in penalties (ACMA media release, November 2024).

On 18 September 2025 a second outage, beginning around 2:17am and running most of the day, affected Western Australia, South Australia and parts of New South Wales. The stated cause was that established processes were not followed during a firewall upgrade. Failed Triple Zero calls were revised upward to more than 723 (ABC News timeline, 23 September 2025, updated 29 September 2025). On 30 July 2026 the ACMA commenced Federal Court proceedings alleging more than 1,000 contraventions, at a maximum of $250,000 each (ABC News, 30 July 2026). Reported outage duration and the associated death toll differ between the contemporaneous reporting and the later court action reporting, and those discrepancies have not been reconciled publicly.

Both were single-carrier, single-control-plane failures triggered by a change, not by a cut cable. The design conclusions follow directly. Diversity has to exist at the carrier and technology layer, not only at the link layer. Failover has to be tested against a control plane failure, where the link is up but routing is wrong, not only against an unplugged cable. And the change window is a risk in its own right, because in both cases a planned change took down production.

One further Territory-specific note, current as at September 2026. Telstra Satellite Messaging launched on 7 June 2025 using SpaceX Starlink Direct to Cell, and on 28 July 2026 extended beyond text to light data for selected navigation, weather and messaging applications (telstra.com.au, 7 June 2025 and 28 July 2026). It carries no voice and no Triple Zero access, so it is a communications fallback for field staff, not a life safety control. The Universal Outdoor Mobile Obligation Bill 2025, introduced on 27 November 2025, would require the national operators to provide baseline outdoor voice and SMS coverage with a stated implementation date of 1 December 2027; as at the last check it remained before the House and had not passed. For a tour company running vehicles into remote country, that is a live policy question rather than a settled fact, and it belongs in the risk section of a bid rather than the solution.

flowchart TB
  INT["Internet"]
  SAT["Satellite: independent path"]
  subgraph Main["Main site, Darwin"]
    FWA["Firewall A"]
    FWB["Firewall B"]
    CORE["Core switch pair, FHRP gateway"]
    DMZ["DMZ: public services"]
    SRV["Server VLAN: database, backup"]
    STAFF["Staff VLAN"]
    GUEST["Guest wireless, internet only"]
  end
  subgraph Remote["Remote site, typical of five"]
    RFW["Firewall or SD-WAN edge"]
    RSW["Access switch"]
  end
  INT --> FWA
  SAT --> FWB
  FWA --> CORE
  FWB --> CORE
  CORE --> DMZ
  CORE --> SRV
  CORE --> STAFF
  CORE --> GUEST
  RFW --> RSW
  RFW -. "encrypted overlay" .-> FWA
  RFW -. "backup path" .-> FWB
Firewalls: what you are actually configuring

The knowledge evidence asks for configuring basic features of firewalls, and the assessment asks you to identify a virtualised firewall and describe its operation. Behind that sits a set of ideas worth having straight.

A packet filter makes a decision on each packet in isolation, against source and destination address, protocol and port. A stateful firewall keeps a connection table, so that return traffic for a connection it allowed outbound is permitted without a separate inbound rule, and traffic that claims to be part of a connection that does not exist is dropped. Everything modern is stateful; the distinction still matters because it explains why an access control list on a router is not a firewall.

A next generation firewall adds identity and application awareness. Instead of "allow tcp/443 outbound", the policy becomes "allow the finance group to reach approved software as a service applications, block file sharing applications, inspect the rest". That requires the firewall to identify the application from traffic behaviour rather than port number, and usually to decrypt TLS in order to see inside it. Decryption is where next generation firewall projects meet reality: certificate pinning breaks it, privacy obligations constrain it, performance drops under it, and staff notice when it goes wrong. A tender that proposes full inspection without addressing the decryption policy is proposing something it has not thought through.

Zone-based policy is the structural idea worth carrying into the design. Rather than writing rules per interface, you define zones (untrusted, trusted, DMZ, guest, management) and write policy between zones. It scales, it is auditable, and it makes the intent readable to somebody who did not write it. The rule base should end in an explicit deny with logging, because an implicit deny that logs nothing gives you no evidence when something is blocked that should not have been.

The DMZ deserves a mention because the Top End Tours design needs one. Anything reachable from the internet, a web presence or a mail relay, sits in a zone that can be reached from outside and can reach nothing sensitive inside. The customer database does not belong there. If a public web application needs database access, it gets a filtered path to a specific service on a specific host, not a route into the server VLAN.

What to propose in 2026. The taught material names the Cisco ASA 5506-X, and this is the clearest example of the syllabus aging. The ASA 5500-X line has been superseded by Cisco Secure Firewall on Firepower Threat Defense; the 5506-X is long past end of sale. A current bid at this scale looks at the Cisco Secure Firewall 1000 series, a FortiGate entry-level model, a Palo Alto PA-400 series, or a Sophos or WatchGuard equivalent, and the sensible answer for a twenty-person company with five branches is usually driven by whoever can support it locally in Darwin rather than by feature comparison.

For Palo Alto specifically, the material's reference to a free academy VM-50 needs correcting. Palo Alto's own end-of-sale announcement gives an end-of-sale date of 31 July 2021 and an end-of-support date of 31 July 2024 for the fixed VM-Series models including VM-50, replaced by a credit-based Software NGFW licensing model where the smallest allocation is a two vCPU size (paloaltonetworks.com end-of-life announcements; community confirmation May 2024). What is available without cost today is a VM-Series trial, fifteen days on AWS and thirty days on Azure, Google Cloud, ESXi and KVM (paloaltonetworks.com, no date shown). The current PAN-OS line is 12.2, released 30 July 2026 (endoflife.date, a community-maintained aggregator, so worth cross-checking against Palo Alto's own release notes). A member institution should confirm current academy entitlements with Palo Alto directly rather than relying on a 2022 slide.

Detecting what the firewall let through

An intrusion detection system watches traffic and raises an alert. An intrusion prevention system sits inline and can drop the traffic. The difference is not just placement; it is a risk decision. An IPS that false-positives blocks legitimate business, so organisations commonly run new signatures in detection mode first and promote them to prevention once they have been observed. That staged approach is a good thing to describe in a tender, because it shows you have run one before.

Detection works two ways and both belong in a design. Signature-based detection matches known patterns and is precise, fast and blind to anything new. Anomaly-based detection models normal behaviour and flags deviation, and it catches novel activity at the cost of a much noisier alert stream during the period, usually weeks, while the baseline settles. Neither is sufficient alone.

Snort remains the reference open-source engine and is embedded in Cisco routers, which is the pitch the taught material makes. Suricata is the multi-threaded alternative and is what most modern open deployments run; Security Onion 2.4.211, released in March 2026, ships Suricata 8.0.3 alongside Zeek 8.0.6 and Elasticsearch 9.0.8 (docs.securityonion.net). Zeek is worth understanding as a different category: rather than matching signatures, it produces structured records of what happened on the network, connection by connection, which is the raw material for hunting and for after-the-fact investigation.

The problem this whole layer has is encryption. The overwhelming majority of traffic is now TLS, and a network sensor without decryption sees metadata, not content. That has pushed the value of network monitoring toward flow analysis, JA3 and JA4 style TLS fingerprinting, DNS analysis and beaconing detection, and it is a large part of why endpoint detection has taken over the ground intrusion detection used to hold. Network detection and response is the current name for the category that grew out of this: less about matching payload signatures, more about behavioural analysis of who talked to whom, when, how often and for how long.

Placement is the practical exam question. A sensor at the internet edge sees north-south traffic and misses everything internal. A sensor on a span port at the core sees east-west traffic and will drown you in volume. For Top End Tours, a sensor at the main site edge plus endpoint telemetry from every device is a defensible starting architecture, with an explicit note that lateral movement detection depends on the endpoint layer rather than the network layer.

Wireshark sits alongside all of this and is named in the knowledge evidence. It is not a monitoring tool; it is an investigation tool. You reach for it when you already know something is wrong and you need to see exactly what crossed the wire. The assessment asks for a Wireshark capture from the red and blue team exercise, and the useful skill is not opening Wireshark but knowing what to filter for and being able to narrate what the packets show: the scan, the exploit attempt, the callback, the exfiltration. A capture with no annotation proves you ran a tool. A capture with a walkthrough proves you understood the attack.

The SIEM, and what happened to the SIEM market

A security information and event management platform does four things: collects logs from everywhere, normalises them into a common schema, correlates events across sources to produce alerts, and retains the data so you can answer questions later. The third of those is the point. A failed login on a workstation is noise. A failed login on a workstation, followed by a successful login from a different country, followed by a new service installed and an outbound connection to an address nobody has ever contacted, is an incident. Only correlation across sources sees that.

Two design decisions dominate every SIEM deployment and both are commercial as much as technical.

What you send. Every log source costs money to ingest and adds noise if nobody uses it. The sources that earn their place first are identity (sign-ins, directory changes, privilege grants), endpoint detection telemetry, firewall and proxy logs, DNS, and cloud service audit logs. Verbose debug logs from applications nobody monitors are the classic budget sink.

How long you keep it. Detection needs days. Investigation needs months, because the median time between compromise and discovery is measured in weeks. Compliance may need years. The current market answer is tiering: a hot analytics tier for the data your rules run against, and a cheap long-term tier you can search when you need to.

Update, current as at September 2026. The market has consolidated hard since this material was written, and the specific product recommendations in the taught content need revisiting.

Cisco completed its acquisition of Splunk on 18 March 2024 for approximately $28 billion (cisco.com investor release, 18 March 2024). The direction since has been integration into Cisco's security platform: Talos threat intelligence shipped into Splunk products from August 2024, and Splunk Enterprise Security 8.6.1 reached general availability on 4 August 2026 carrying a set of AI agents for detection building, triage, malware reversing, phishing analysis and guided response, with menu navigation explicitly changed for consistency with Cisco products (Splunk documentation, page last updated 5 August 2026). Cisco's own security operations write-up describes Splunk feeding Cisco XDR as the analyst triage surface (blogs.cisco.com, 9 March 2026). That is an enterprise story. Splunk was never a small-business product and it is less so now.

Microsoft Sentinel has moved house. It is generally available in the Microsoft Defender portal, including for customers with no Defender XDR and no E5 licence, and the Azure portal experience is being retired, with the date extended to 31 March 2027 (learn.microsoft.com, January 2026 entry). Since 1 July 2025 new customers are onboarded to the Defender portal automatically. The Sentinel data lake became generally available on 30 September 2025, separating cheap long-term storage from the analytics tier and supporting both KQL and notebook access (techcommunity.microsoft.com, 30 September 2025). Commitment tiers run from 100 GB per day upward, and a 50 GB per day commitment tier is available at promotional pricing from 1 October 2025 to 31 December 2026, which is the first Microsoft entry point genuinely sized for a small organisation (microsoft.com pricing page, no date shown). Actual per-gigabyte rates should come from the Azure pricing calculator; the pricing page states its figures are estimates.

Google Security Operations, the former Chronicle, sells in three tiers, all on application, with Gemini in security operations at the Enterprise tier and applied Google Threat Intelligence from Mandiant and VirusTotal at Enterprise Plus (cloud.google.com, no date shown). Google completed its acquisition of Mandiant in September 2022 for $5.4 billion, and completed its $32 billion acquisition of Wiz on 11 March 2026 after United States clearance in November 2025 and European clearance in February 2026 (TechCrunch, 11 March 2026). Google publishes no prices, which makes it hard to bid.

The open-source options are the ones that make a Top End Tours-sized deployment plausible. Wazuh, which combines endpoint agents with SIEM functions, is on the 4.14 line with 4.14.7 released 29 July 2026 (documentation.wazuh.com). Elastic re-added AGPL v3 as a licence option alongside ELv2 and SSPL in August 2024, ending the period when the Elastic Stack was awkward for some deployments (elastic.co, 29 August 2024). Security Onion bundles Suricata, Zeek and Elasticsearch into a deployable network security monitoring platform. All three are free to acquire and expensive to run, because somebody has to build the detections, tune them, and stay awake. That trade, licence cost against staff cost, is the single most useful thing to be able to argue in a tender for a small client.

The number that explains the whole problem. Research published in 2026 surveying AI-driven alert screening in security operations centres notes that only around 0.01 per cent of daily alerts link to true attacks in modern deployments (Ndichu and others, "AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey", arXiv preprint, May 2026). That base rate is why headline accuracy figures mislead, why analysts burn out, and why the design goal for a small deployment should be a small number of high-quality detections rather than every rule the vendor ships turned on.

Endpoints: EPP, EDR, XDR and MDR

The taught material's distinction between endpoint protection platform and endpoint detection and response is still broadly right, and the terminology around it has shifted.

An endpoint protection platform prevents: anti-malware, exploit protection, device control, host firewall, application control. It stops known-bad and blocks common technique classes.

Endpoint detection and response records: it continuously collects process, file, registry and network telemetry from the endpoint, applies behavioural detection, and gives an investigator the ability to reconstruct what happened and to respond remotely, isolating the host or killing a process.

Extended detection and response widens the same idea beyond the endpoint, correlating endpoint, identity, email, network and cloud signals in one place. The distinction that matters commercially is native XDR, one vendor across all the signals, tighter integration and lock-in, against open XDR, multiple sources, more flexibility and more integration work.

Managed detection and response is not a product category at all. It is a service wrapped around one of the above.

Update, current as at September 2026. Gartner has retitled its endpoint market as "Endpoint Protection Platforms (Transitioning to Endpoint Protection)" and its 2026 Magic Quadrant, published 26 May 2026, is titled simply "Magic Quadrant for Endpoint Protection" (gartner.com; CrowdStrike investor release citing the report). So the term EPP is being retired by the analyst house whose usage popularised it. Both CrowdStrike and SentinelOne were named Leaders in that 2026 report.

Two forces have driven the architectural shift since 2022 and both are worth naming in a bid. Attackers systematically disable endpoint agents using vulnerable signed drivers, a technique adopted by more than ten named ransomware groups inside eighteen months. And identity-centric intrusions, of which the 2024 Snowflake campaign is the clearest example, can run their entire chain without touching a managed endpoint at all. An endpoint-only detection strategy has visible gaps on both sides.

For a Microsoft-centred client like Top End Tours, the licensing detail matters more than the product comparison. Microsoft Defender for Endpoint Plan 1 covers the preventive layer and comes with Microsoft 365 E3. Plan 2 adds endpoint detection and response, automated investigation and remediation, vulnerability management, threat analytics and the deep analysis sandbox, and comes with Microsoft 365 E5. Neither includes server licensing, which needs Defender for Servers or Defender for Endpoint Server separately, and that omission is a classic tender costing error. Defender for Business is the small and medium business SKU: it carries Plan 1's features plus an optimised endpoint detection and response capability, automated investigation and remediation, automatic attack disruption, and simplified antivirus and firewall configuration that the enterprise plans do not have, while lacking Plan 2's thirty-day advanced hunting and six-month retention (learn.microsoft.com). For a twenty-person company, Defender for Business is very likely the right answer and it is not the answer the 2022 material gives.

The CrowdStrike lesson. On 19 July 2024 a CrowdStrike Rapid Response Content update, Channel File 291, deployed at 04:09 UTC, contained an error that produced an out-of-bounds memory read and a bugcheck on Windows hosts running Falcon sensor 7.11 and above. A bug in the Content Validator had let the defective content pass. CrowdStrike reverted at 05:27 UTC, but reverting did not fix machines that had already crashed; recovery required manual intervention on each host, made far worse where BitLocker was in use. Approximately 8.5 million Windows devices were affected, which Microsoft assessed the following day as under one per cent of all Windows devices. Estimated costs to United States companies ran to around $5.4 billion with only a small fraction insured, and Delta alone reported $500 million by 31 July 2024 (CrowdStrike preliminary post-incident report, 24 July 2024; CISA alert, 19 July 2024).

This belongs in the risk register of any project proposing an endpoint agent, and CrowdStrike's own committed remediations are the teachable list: staggered deployment of rapid response content beginning with a canary group; customer control over update timing and deployment windows; enhanced monitoring during phased rollout; strengthened validator checks; fuzzing and fault injection testing; independent third-party review. Every one of those maps onto a question you should be able to answer about your proposed solution. Can the client control when content updates land. Is there a canary group. What is the recovery procedure if an agent bricks a fleet, and does it require physical access to each machine. Where are the BitLocker recovery keys and has anybody ever tested retrieving one.

Threat intelligence and the frameworks you map to

Threat intelligence is data collected, processed and analysed to understand a threat actor's motives, targets and behaviours, so that security decisions can be made on evidence rather than assumption. The practical distinction is between strategic intelligence, which tells a board which threats matter to their sector, and tactical or technical intelligence, which gives a SIEM indicators to match against.

Two frameworks structure how the industry talks about attacks, and the unit expects familiarity with both.

The Lockheed Martin Cyber Kill Chain breaks an attack into seven ordered stages: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. Its value is communicative. It gives a non-technical audience a mental model, and it supports the argument that defence should aim to break the chain at the earliest affordable point. Its weakness is the ordering: real intrusions loop, skip and revisit.

MITRE ATT&CK is a knowledge base of adversary tactics and techniques observed in the wild. Tactics are the adversary's goals; techniques are how those goals get achieved; sub-techniques are the specific variants. It is deliberately unordered, precisely because attackers do not proceed linearly, and it goes much deeper than the kill chain in describing method.

Update, current as at September 2026. ATT&CK is on v19.2, released 6 August 2026, which is the framework's first release under a narrower-scope "agile" model that publishes targeted updates to groups, software and campaigns outside the twice-yearly cadence when threat activity warrants (attack.mitre.org). The substantial release was v19, on 28 April 2026, and it carries a structural change that anyone with an existing mapping needs to know about: Enterprise Defense Evasion was split into two tactics, Stealth and Defense Impairment. Any detection catalogue, coverage matrix or mapping document built before April 2026 will not line up against the current framework. That release also added the first wave of eighteen ICS sub-techniques, extended detection strategies to Mobile ATT&CK, and added AI-related techniques including Query Public AI Services and Generate Content.

ATT&CK Evaluations are worth knowing about and worth reading carefully. The most recent round I could confirm is Enterprise 2025, published 10 December 2025, emulating Scattered Spider and Mustang Panda across eleven vendors (mitre.org, 10 December 2025). MITRE does not rank or score vendors, and the participant list in any round is short, so an evaluation is evidence about how a product behaved against two specific adversary emulations, not a market comparison. Vendors quote it as though it were the latter.

Australian threat reporting. The most recent ASD Annual Cyber Threat Report available as at September 2026 is the 2024 to 2025 edition, released 14 October 2025. ASD received over 84,700 cybercrime reports, an average of one every six minutes, and responded to more than 1,200 cyber security incidents, an eleven per cent increase on the previous year. The Australian Cyber Security Hotline took over 42,500 calls, around 116 a day. The average self-reported cost of cybercrime per report rose fourteen per cent to $56,600 for small business, and eight per cent to $33,000 for individuals (Minister for Defence media release, 14 October 2025). Contemporaneous reporting the same day added medium business at $97,200, large organisations at $202,700, identity fraud as the single most reported incident type, and ransomware at around eleven per cent of reported cybercrime (Cyber Daily, 14 October 2025); those figures come from secondary reporting rather than the ministerial release, and the report factsheet is the primary source to check.

The small business figure is the one to put in front of a client like Top End Tours, because $56,600 is the same order of magnitude as the annual cost of the solution you are proposing, and that comparison is the whole business case.

Open source intelligence and the exposure question. Shodan, which the supporting material covers, indexes internet-connected devices and their banners. It is the fastest way to answer the question a tender response should always answer: what does this client already look like from the outside. Running that check before you write the bid is legitimate reconnaissance of publicly available information, and finding an exposed management interface or an end-of-life device is the kind of specific, verifiable finding that separates a bid from a brochure. The line to stay on the right side of is authorisation: passive observation of public data is one thing, and probing, scanning or attempting access is another and needs written permission. That distinction is not a matter of etiquette; unauthorised access to a computer system is an offence under Part 10.7 of the Criminal Code Act 1995 regardless of intent.

The dark net material in the supporting decks sits in the same territory. Knowing how initial access brokers and ransomware leak sites operate is useful context for a client explaining why they were targeted. Browsing them is not a student activity and does not belong in a tender response.

Red team, blue team, and the part in between

The performance criterion is explicit: red and blue teaming exercises are planned and executed as part of the project. This is the single most technically substantial deliverable in the unit and the one most often reduced to a paragraph of description. It should be an exercise with a plan, an execution, evidence, and findings.

The roles. The red team plays the adversary, working to achieve defined objectives without being caught. The blue team defends, detects and responds. Purple team is not a third team; it is the mode where both work together in the open, red executing a technique and blue watching to see whether the detection fires, tuning it, and running the technique again. For a training exercise, purple is almost always more valuable than a covert red team engagement, because the point is to improve detection rather than to prove that a determined attacker can win. A determined attacker can win. That is not news.

Rules of engagement come first. Before anything runs, in writing: scope (which systems, which addresses, which accounts), timing (when the window opens and closes), prohibited actions (no denial of service, no data destruction, no touching production), the escalation path if something real is found during the exercise, evidence handling, and the authorisation itself, signed by somebody with the authority to give it. In a simulated project this is a document you produce; in a real engagement it is the difference between a penetration test and a criminal offence.

Designing the exercise. Pick objectives that map to threats this client actually faces. Top End Tours was extorted over customer data, so the scenario writes itself: an attacker obtains credentials through phishing, establishes access, moves toward the customer database, and attempts to stage and exfiltrate it. Map each step to ATT&CK techniques so that findings are expressed in language the industry shares, and so that the blue team's coverage can be stated as coverage of specific techniques rather than as a feeling.

A defensible exercise for this project runs through initial access by credential phishing, execution of a payload, persistence, credential access, discovery of the network and the database host, lateral movement to it, collection and staging, and an attempted exfiltration over an outbound channel. Each step is a hypothesis about detection: should this fire, did it fire, and if not, why not. Atomic Red Team and MITRE Caldera are the standard open tools for executing individual techniques repeatably, and repeatability is what makes the second run meaningful.

What the blue team produces. Not "we saw it". A detection record: the source that carried the signal, the rule or analytic that fired, the time between the action and the alert, what the analyst saw, what they did, and how long containment took. Where nothing fired, the gap is the finding, and the remediation is a new detection, a configuration change or a log source that was not being collected.

The Wireshark capture the assessment asks for belongs here, annotated: this is the scan, here is the exploit attempt, here is the callback to the command and control address, here is the outbound transfer. A screenshot of Wireshark showing traffic proves nothing on its own.

flowchart LR
  ROE["Rules of engagement, signed"] --> PLAN["Scenario mapped to ATT&CK"]
  PLAN --> EXEC["Red team executes technique"]
  EXEC --> OBS["Blue team observes: fired or missed"]
  OBS -->|"detected"| VAL["Validate: alert quality, time to detect"]
  OBS -->|"missed"| GAP["Gap: log source, rule or coverage"]
  GAP --> FIX["New detection or configuration change"]
  FIX --> RETEST["Re-run the same technique"]
  RETEST --> OBS
  VAL --> REPORT["Findings and mitigation report"]

Reporting. The output is a findings document that states what was attempted, what was detected, what was not, and what should change, with each recommendation costed or at least sized. A finding without a recommendation is a complaint. A recommendation without an owner and a date is a wish.

Building the lab

The knowledge evidence asks for creating, configuring and interconnecting virtualised devices, and the assessment asks for a Packet Tracer simulation of the network and a virtual environment for the incident response exercise. The lab is where most of the demonstrable technical work in this unit happens.

Network simulation and emulation are different things. Cisco Packet Tracer is a simulator: it runs Cisco's own reimplementation of device behaviour, so it can only model devices Cisco has coded into it, and it cannot boot a real vendor image. That is a real limitation and also the reason it runs on a laptop. It does include a simulated ASA 5506-X at software version 9.6(1) with a Security Plus licence, which is what makes the assessment's optional ASA firewall simulation possible, and the current line adds industrial equipment including a rugged switch and an ISA-3000 industrial firewall. The Packet Tracer version and release status could not be confirmed from a Cisco-owned page during this build, because netacad.com renders in JavaScript and could not be read.

An emulator runs the actual vendor image. That gives you real command syntax, real feature behaviour and real bugs, at the cost of memory, CPU and image licensing.

Cisco Modeling Labs is the option that solves the licensing problem legitimately. CML-Free is a no-cost single-user tier with a five-node limit, where unmanaged switches and external connectors do not count against the limit, and the reference platform includes IOL, IOL-L2 and ASAv images (developer.cisco.com, documenting CML 2.10.x, no date shown). That is the only route I could confirm to a properly licensed virtual ASA without sourcing an image yourself.

GNS3 and EVE-NG emulate more broadly but are bring-your-own-image for essentially everything. An independent comparison notes that manual image sourcing for both involves legal grey areas for most vendor images, whereas CML includes official Cisco images with licensing (netpilot.io, 21 April 2026, updated 1 September 2026). That is worth stating plainly in a study context: downloading vendor IOS or PAN-OS images from a forum to build a home lab is copyright infringement, however normalised it has become, and a cyber security professional arguing for licence compliance in a tender should not be running an unlicensed lab.

The security lab. The taught environment is a flat 192.168.1.0/24 segment with Kali as the attack platform, Metasploitable and an unpatched Windows XP host as targets, and Windows 7 and Windows 10 as more realistic endpoints. It works, and it is worth updating in two ways. Modern endpoints should be current Windows and a current Linux, because techniques that work against Windows XP demonstrate nothing about a 2026 environment. And a SIEM belongs in the lab, because the point of the exercise is detection: Wazuh, an Elastic stack or Security Onion, receiving logs from the endpoints and the firewall, closes the loop.

Three lab disciplines are worth building as habits. Isolate the lab from any production or home network, because a deliberately vulnerable host on a routable segment is a genuine risk to everyone on it. Snapshot before every exercise, so that a compromised machine can be reset in seconds rather than rebuilt. And document the build, because a lab you cannot rebuild is a lab you will lose.

The remote site simulation deserves a note on effort. The assessment says there is no need to simulate all five remote sites because they are identical, and that is correct: simulate the main site fully and one remote connection, and state the assumption that the remaining four are configured identically. Doing five is not more impressive; it is a use of time that would have been better spent on the firewall rule base.

Incident response as a deliverable

The tender asks for an incident response plan and a playbook. They are different documents and conflating them is a common error.

The plan is governance. It defines what counts as an incident, who declares one, the severity scale and what each level triggers, the roles and the people who fill them, the communication protocol including who talks to customers and regulators, the legal and reporting obligations, and the authority to take disruptive action such as disconnecting a site. It is short, it is approved at board or owner level, and it is reviewed annually.

The playbook is operational. It is a specific procedure for a specific incident type: ransomware, business email compromise, credential theft, data exfiltration. It says what to check, in what order, with which tool, and what to do at each decision point. It assumes the plan already answered the questions about who decides.

Both NIST and SANS describe the lifecycle in similar terms: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. The phase students consistently underweight is preparation, which is where the plan is written, the playbooks are drafted, the contacts are collected, the exercise is run and the backups are tested. Everything you did not prepare, you will improvise at three in the morning.

Two phases deserve specific attention for a client like this one.

Containment is a genuine trade-off, not a technical step. Isolating the compromised host stops the spread and destroys volatile evidence. Leaving it running preserves evidence and lets the intruder continue. There is no universally right answer, which is exactly why the decision authority belongs in the plan rather than in the moment.

Post-incident review is where the value is realised, and it is the phase that gets cancelled when everyone is tired. The output is a small number of specific changes with owners and dates.

Update, current as at September 2026. A 2026 incident response plan for an Australian business carries reporting clocks that the 2022 material predates, and they are covered in the legal section below. The short version for the plan itself: a ransomware payment must be reported within 72 hours by businesses over the turnover threshold; an eligible data breach must be assessed within 30 days and notified as soon as practicable; and the plan should name who is responsible for each clock, because "the IT provider will handle it" is not a defence.

For a client with one IT person, the plan should also be honest about capacity. A twenty-person company cannot run its own incident response at two in the morning. The realistic proposal is a documented plan, a rehearsed playbook, and a retainer with an incident response provider, priced, with a response time commitment. Naming NT Cyber Ops, who already investigated the breach in the scenario, is a reasonable move in a bid, because continuity of knowledge has value.

Risk: two registers, not one

The assessment asks for two risk assessments and they are genuinely different documents. The first covers the risk that your team fails to deliver the tender response by the deadline. The second covers the risk that, having won, you fail to deliver the project on time and on budget. Students routinely write one and duplicate it.

Delivery risk on the bid is about your team: a member unavailable through illness, leave or competing commitments; scope misunderstood because a clarification question went unanswered; a technical section that turns out to need more work than estimated; a costing that cannot be verified because a supplier will not quote in time; documents that do not merge cleanly the night before submission. The mitigations are unglamorous and effective: a team leader who collates continuously rather than at the end, an internal deadline earlier than the real one, each person's work reviewed by somebody else, and a named backup for every role.

Delivery risk on the project is about the client, the suppliers and the environment: equipment lead times, freight to remote Territory sites, availability of the client's staff for cutover, a remote site where the connection cannot be provisioned in the time assumed, weather, a change that breaks something, and the possibility that the client's undocumented environment contains a surprise. Freight and travel are real line items in the Territory and a bid that has not costed a technician's flights and accommodation to Kununurra is understating its price.

The mechanics are standard: identify the risk, rate likelihood and consequence, multiply to a severity, decide a treatment, assign an owner, and review. Treatments come in four kinds. Avoid, by changing the plan so the risk cannot occur. Reduce, by lowering the likelihood or the consequence. Transfer, by insurance or by a contractual term that puts the risk on a supplier. Accept, consciously and in writing, with a trigger for review. Accepting a risk is a legitimate decision; failing to notice one is not.

ISO 31000 is the reference methodology and the shape it gives is useful: establish the context, identify, analyse, evaluate, treat, then monitor and review, with communication and consultation running alongside the whole thing. The taught material's reference to the Victorian Occupational Health and Safety Act 2004 is a Victorian artefact of the syllabus; in the Territory the equivalent is the Work Health and Safety (National Uniform Legislation) Act 2011, and a bid written for an NT client should say so.

Two risks specific to 2026 belong on both registers and are the kind of thing that distinguishes a considered bid.

Supplier concentration. The CrowdStrike outage and the Optus outages are the same category of risk seen from two angles: a single supplier's change taking out your capability across every site simultaneously. The mitigation is not "use two endpoint vendors", which is usually unaffordable. It is knowing which single points of failure you have accepted, whether you control the update timing, and what the manual recovery procedure is.

Skills availability. The Territory ICT labour market is thin, and a solution that requires a specialist nobody can hire in Darwin has a support risk regardless of how good the design is. That is an argument for choosing platforms with local support presence over platforms with better feature sets, and it is an argument a Territory client will recognise immediately.

Costing the solution

The assessment asks for costs citing actual devices, and the sample figures in the assessor guide give a sense of the scale: a first-year cost in the region of $857,000 with an ongoing annual cost around $648,000 for a comparable scenario. Those are illustrative rather than benchmark figures, and the useful skill is not reproducing a number but building one that survives questioning.

A cost breakdown that stands up has these parts.

Hardware, itemised by model, quantity and unit price, with a source for the price. Firewalls, switches, routers or SD-WAN edges, servers, endpoints, the video conferencing equipment and the IP phones the tender asks for, plus the unglamorous items that get forgotten: optics, patch leads, rack hardware, uninterruptible power supplies.

Software and subscriptions, separated from hardware because they behave differently. Endpoint licensing per seat per year, firewall subscription bundles, SIEM ingestion, backup, the productivity suite if the design changes it. Subscription costs are where a first-year figure and an ongoing figure diverge sharply, and a bid that presents only one is hiding the other.

Services and labour: design, configuration, deployment, project management, testing, documentation, training delivery. Travel and accommodation for remote site work, priced honestly.

Ongoing costs: the managed service or monitoring subscription, connectivity, support hours, hardware maintenance and warranty extension, and licence renewals.

Contingency, stated as a percentage and justified. A bid with no contingency is either optimistic or already loss-making.

Three costing traps recur and all three are visible in the source material for this unit. Server licences are not included in endpoint plans and get missed. SIEM cost scales with data volume, so a design that sends everything to a per-gigabyte platform can quietly become the largest line item, which is the whole argument for tiering and for source selection. And whole-of-life cost is what the client actually pays: a cheaper firewall with a more expensive subscription bundle can cost more over three years, and showing a three-year or five-year total is both more honest and, usually, more persuasive.

Present costs at a summary level in the body of the response and put the detailed breakdown in an appendix. A board wants the number and the shape of the number; the finance manager wants the line items.

Tendering in Australia, and tendering in the Territory

The tender skills in this unit generalise, and the Territory specifics change the arithmetic enough to be worth knowing separately.

The Commonwealth picture. AusTender at tenders.gov.au is the central publication point for Australian Government procurement: annual procurement plans, approaches to market, multi-use lists, panel opportunities and contract notices. Suppliers register free, maintain a profile, subscribe to notifications by category so relevant opportunities arrive automatically, and lodge responses through the portal.

The Commonwealth Procurement Rules 2025 are the current version, registered 22 October 2025 and commencing 17 November 2025 (legislation.gov.au, F2025L01263). The procurement thresholds are $125,000 for non-corporate Commonwealth entities for non-construction procurement, raised from $80,000; $400,000 for prescribed corporate Commonwealth entities; and $7.5 million for construction. Above the relevant threshold, open tender is the default. Other features relevant to a supplier: below-threshold non-panel procurement by non-corporate entities must be limited to Australian businesses; there are SME participation targets of at least twenty-five per cent of contracts by value for procurements up to $1 billion and forty per cent by value for contracts up to $20 million; and paragraph 8.3 requires entities to consider and manage procurement security risk including cyber security risk consistent with the PSPF. That last paragraph is the hook that puts Essential Eight maturity claims, ISO 27001 certification and IRAP assessment into ICT tender criteria.

For hosting specifically, the Hosting Certification Framework run by the Digital Transformation Agency has applied to new contracts and extensions since 30 June 2022, with two levels: Certified Strategic, the highest assurance, available only to providers that let government specify ownership and control conditions; and Certified Assured, which safeguards against change of ownership or control through financial penalties (hostingcertification.gov.au).

The Territory picture, and why it changes your bid. Northern Territory Government tenders from Tier 3 upward are advertised on Quotations and Tenders Online at tendersonline.nt.gov.au. The framework sits under the Procurement Act 1995 and Procurement Regulations 1995, with mandatory directions in the Procurement Governance Policy, the Procurement Rules and Procurement Circulars (nt.gov.au, procurement framework page last updated 12 December 2025).

The tiers, from the Procurement Rules version 2.0 effective 1 October 2025: Tier 1 under $50,000, direct purchase or a minimum of one quote from a Territory business; Tier 2 from $50,000 to under $200,000, minimum three quotes with two from Territory businesses; Tier 3 from $200,000 to under $500,000, public tender through QTOL with a six business day advertising period; Tier 4 from $500,000 to under $5 million, public tender with six weeks; Tier 5 at $5 million and above, public tender with eight weeks.

The fact that changes how you write a Territory bid is this: the NT Procurement Rules require assessment criteria to include a minimum thirty per cent weighting for local content and a maximum of thirty per cent weighting for price. Price cannot be more than thirty per cent of the score, and local content must be at least thirty per cent. A cheaper bid from an interstate supplier can lose to a more expensive Territory bid, by design. Value for Territory assessment weighs price, local content, economic benefit to the Territory, capability development and training, innovation, risk, sustainability and whole-of-life costs, and the Aboriginal Procurement Policy sets targets for the share of contracts by number and value awarded to Aboriginal businesses and for Aboriginal employment on applicable contracts (nt.gov.au, procurement policies page last updated 15 December 2025). The old buylocal.nt.gov.au address now redirects there, so older citations need updating.

The practical consequence for a bid: local presence, local employment, local subcontracting and local training are not goodwill statements, they are scored, and evidence for them belongs in the response with the same rigour as the technical sections. A Darwin-based team offering local support, apprenticeships and Territory subcontractors is answering a criterion worth more than price.

One Territory-specific support measure worth knowing about for a client conversation: CyberNT runs the Cyber Invest Business Program, offering grants of up to $10,000 to small and medium Territory businesses to uplift cyber security and resilience, with Round 2 opening in October 2026. Registered service providers under that program must be a Territory enterprise with a valid ABN, hold current public liability or professional indemnity insurance, and hold relevant certifications with at least twelve months' prior experience (cyber.nt.gov.au, pages last updated August 2026). No specific standard such as the Essential Eight or ISO 27001 is named as a provider requirement.

Writing the response

Tender writing is a craft and some people make a career of it. The rules are unremarkable and almost universally broken.

Read the document completely before writing anything, and build a compliance matrix: every requirement, where in your response it is answered, and who owns that section. Panels score against criteria, and an answer they cannot find is an answer you did not give.

Use the format the client asked for. If they provided a template, use it; if they specified section order, follow it. Deviating to show a better structure is a reliable way to lose points from an evaluator who has thirty responses to score and is looking for section four.

Answer the criterion that was asked, in the language it was asked in. Evaluators score against the words in the document, and mapping your vocabulary onto theirs is not a stylistic choice.

Write plainly. Measured, factual language reads as more competent than superlatives; a solution described as "an issue we have addressed by segmenting the customer database" is more persuasive than one described as "a critical vulnerability we have comprehensively remediated". If the reader has to work to find the answer, the answer scores lower.

Answer with evidence. Reference letters, comparable projects, named certifications, named products and named prices. A claim of experience with no referee is a claim.

Manage the deadline as a project in its own right. The unit's assessment says there will be no extensions, as with real tenders, and that is accurate: a late submission is normally rejected without being read. Build an internal deadline days ahead of the real one, and have someone whose job is to assemble, proofread and lodge the whole thing rather than to write a section of it.

For this project the response body follows the structure the assessment sets out: background, about your company, the team, scope and boundaries, deliverables, the solution, timelines, implementation plan, cost summary, and a closing summary that says why the client should choose you. Appendices carry reference letters, policies, the training plan, roles and responsibilities, the Gantt chart, the simulations, service level agreements, the risk assessments, the equipment and cost breakdown, and the minutes and communications record.

The appendices are doing real work. The body is what the board reads; the appendices are what the technical evaluator checks. Both need to exist and neither can substitute for the other.

The presentation

The response wins you the shortlist. The presentation wins the work, or loses it.

The constraint in this project is sixteen minutes for a team of four, including handovers, which is four minutes each. Presentation time limits in real tenders are enforced, and going over costs marks. Four minutes is three to five slides, not eight to ten, and it is one idea explained properly rather than ten weeks of work summarised.

The single most common failure is slide density. Diagrams from your design document are not presentation slides. A network diagram that is legible on a laptop is illegible from the back of a boardroom, and putting it up anyway signals that you have not thought about the audience. Redraw for the room.

Know who is in the room and pitch accordingly. The Top End Tours board includes the owner, the general manager and the one IT person. Two of the three want to know whether this fixes the problem that embarrassed them and what it costs; the third wants to know whether it will work and whether he will be able to run it. A presentation that speaks only to the technical evaluator loses the room, and one that speaks only to the board loses the person who will veto it afterwards.

Speak to the audience, not to the slide, and speak about them rather than about yourself. "We can lower your incident rate, and here is a comparable client where we did" lands better than "our company has significant experience". Personalise: they are Top End Tours, not "the client".

Practicalities that decide more presentations than content does. Rehearse the handovers, because handovers are where teams lose thirty seconds each and run over. Check the equipment beforehand. If presenting remotely, show your faces, match audio levels and framing, agree a dress code, nominate one person to drive the slides so nobody says "next slide please", and rehearse the transitions. Every member presents, including the one whose topic is not the strongest selling point, and if their section is not the sell then give them a different one.

Implementation, acceptance and handover

Winning is where the project starts. The tender asks for an implementation plan that minimises disruption to the client's business, and the choice of model is assessable.

Turnkey, sometimes called big bang, replaces everything at once. It is fast, it delivers benefits immediately, and it concentrates all the risk into one window with no fallback. It suits simple solutions and confident suppliers.

Parallel runs the new alongside the old for a period, with selected trained users on the new system. It is the safest and the most expensive, because you are operating two environments and often paying for both.

Phased brings sections in over time. It reduces risk, spreads training, and lets each phase inform the next. It is the most common answer for infrastructure work of this shape, and it fits a business with five geographically separated offices particularly well: prove the design at the main site, then roll out.

The assessor guide's sample answer chooses big bang, and it is defensible if the reasoning is there. For a tour company in peak season with twenty thousand customer records and no in-house depth, a phased approach is easier to argue. Whichever you choose, the plan needs cutover windows that avoid the client's busy periods, a documented rollback for each phase, training before the change rather than after, and support presence on the first day of each phase.

Acceptance testing. A final acceptance test is what triggers payment, and it has four phases: define the acceptance criteria, develop the test plan, execute it, and reach an acceptance decision with sign-off. Who performs it is a live question, and the answers include the client, the supplier, a mixture, or an independent third party. A mixture is the usual answer, and the criteria must be agreed before the build rather than negotiated at the end.

For this solution the test list writes itself from the scope: workstations, network infrastructure, connectivity to remote sites and the internet, backup and restore, the security infrastructure including firewalls, intrusion prevention and the SIEM, the incident response process and its reporting, and a test of ordinary daily work. The last one matters most and gets skipped most: a system that passes every technical test and makes somebody's job harder has not been accepted by the person who has to use it.

Restore testing deserves calling out. A backup that has never been restored is a hypothesis. Testing a restore, to a stated recovery time objective and recovery point objective, belongs in the acceptance criteria.

The contract around it. A successful tender normally signs a contract before work starts, and it typically covers the agreed cost, the deliverables and the split between local and offsite resources, payment conditions and schedules often tied to the acceptance test, implementation and completion clauses possibly including penalties for late delivery, use of subcontractors, warranties and guarantees, contract term and retendering, exit clauses, performance clauses and security breach clauses. Reading a contract is not a technical skill, but noticing that the payment schedule is tied to an acceptance test you have not defined is.

Service level agreements are the ongoing half. An SLA that says "we will respond promptly" is unenforceable. One that specifies response and resolution targets by severity, the hours of coverage, the escalation path, the measurement method and the consequence of missing a target is a commitment. Warranties sit alongside: equipment vendor warranty terms, an installation warranty period, and whether initial on-site technical support is included or priced, which is a question the implementation model changes.

Handover and closure. The technical documentation package is a deliverable in its own right: as-built diagrams, IP addressing and VLAN documentation, configuration backups, credentials transferred through a proper mechanism rather than an email, the policy set, the incident response plan and playbooks, the training materials, and the licence and warranty register with renewal dates. A client who cannot operate the solution after you leave has not been handed over to.

Closure includes the parts that get skipped when everyone is ready to move on: formal sign-off from the sponsor, evaluation of whether the risk strategy actually worked, a lessons learnt discussion recorded somewhere it can be found, and feedback to the team leader if they are willing to receive it. Asking for a reference letter at the point of successful handover, while goodwill is high, is a practical habit worth forming; that letter is an appendix in your next bid.

Training and the human layer

The tender asks for a training plan, and the assessor guide's answer of a commercial awareness platform plus coverage of key policy items is a starting point rather than a plan.

The problem with security awareness training is well documented: annual compliance modules produce completion statistics and very little behaviour change. What does change behaviour is short, frequent, role-specific content, delivered close to the moment it is relevant, with simulated phishing that teaches rather than punishes.

That last point deserves care. Phishing simulation is standard practice and it has an ethical dimension that a bid should address. Simulations that use distressing lures, bonus announcements, redundancy notices, family emergencies, generate real anger and damage the security team's standing, which is the opposite of the goal. Simulations that name and shame individuals produce under-reporting, because staff learn that reporting is how you get identified. The design that works reports rates at team level, treats a click as a training trigger rather than a disciplinary event, and measures the reporting rate as the primary metric rather than the click rate. A person who clicks and reports within a minute is a better outcome than a person who neither clicks nor reports.

For Top End Tours specifically, the training plan has to work around a business where most staff are casual tour guides who are rarely in an office. That means short modules that work on a phone, scheduled around tour rosters rather than around a training calendar, delivered in language that is about their work rather than about information security. The content that earns its place: recognising and reporting a suspicious message, handling customer data including the financial records some returning customers have, using the new systems safely, and knowing who to call when something looks wrong.

Policy adoption is the other half and it is a change management problem, not a documentation problem. The existing policies are from 2018, describe practices nobody follows, and specify passwords of more than six characters, which is below any current guidance. Rewriting them is the easy part. Getting them used requires explaining why each rule exists, making the compliant path the easy path, providing a route for staff to say a rule does not work in practice, having management visibly follow the rules, and reviewing on a schedule with a named owner. A policy that makes the right behaviour harder than the wrong behaviour will be worked around, and the workaround will be more dangerous than the behaviour the policy banned.

Working as a team, and proving that you did

The unit is assessed partly on evidence that the team functioned, and it is clustered with ICTICT443 Work collaboratively in the ICT industry, so the collaboration evidence is doing double duty.

The roles the project defines are team leader, networking lead, security lead, policy and incident response lead, and training and risk assessment lead. The two that need to work most closely are networking and security, because the security architecture is constrained by the network design and vice versa; a firewall placed where the network does not route traffic through it protects nothing.

Team performance criteria and measurement are an explicit performance criterion, and the useful version is small and observable: are deadlines being met, is work arriving at usable quality, is communication happening, are members supporting each other, and is the client satisfied with dealing with the team. Metrics like gross profit margin belong to the commercial side of the project rather than to team function, and mixing them confuses both.

For a distributed team, and every team in the Territory is at least partly distributed, the practices that work are regular scheduled check-ins rather than ad hoc contact, clearly defined ownership so nobody is waiting on an ambiguity, early and explicit expectations, and deliberate effort to keep social contact alive. The failure modes are equally predictable: no face-to-face supervision, unclear expectations, poor communication, weak cohesion and isolation.

Conflict is normal and needs a decided mechanism before it is needed. A vote with the team leader holding the casting vote is a workable rule. What matters more is that the mechanism was agreed while everybody was calm.

The documentation requirement is not administrative padding; it is your evidence. Minutes of every meeting, internal, with the instructor and with the client, following a consistent template: date, purpose, location, attendees, absences and why, agenda items, outcomes, and who is doing what by when. All email correspondence retained. The team charter and code of conduct completed. In a real engagement this record is what protects you when a client says they asked for something you never heard, and in this unit it is what demonstrates the elements about generating documentation and about team function.

One current-practice note on collaboration tooling. The taught material points at Microsoft Project and Basecamp. Both still exist, and a team working inside a Microsoft tenancy in 2026 will usually find Planner and Project for the web, or Teams with a shared plan, less friction than a separate product. The choice matters far less than the discipline: one place for files, one place for tasks, one place for conversation, and everybody actually using them. Any collaboration platform also brings its own obligations, since electronic communication about a client's business must comply with the same privacy, records and telecommunications law as anything else, and sensitive client documents belong in the managed repository rather than in a chat attachment.

A note on AI in the security operations centre

This is not in the syllabus and it is unavoidable in a 2026 bid, because every vendor in the stack is selling it and a client will ask.

What is genuinely available. Microsoft Security Copilot reached general availability on 1 April 2024 as a capacity-based service priced in security compute units. In March 2025 Microsoft announced six of its own agents and five partner agents, including phishing triage in Defender, alert triage in Purview, conditional access optimisation in Entra and vulnerability remediation in Intune. The change that matters commercially came on 18 November 2025, when Security Copilot became included for Microsoft 365 E5 customers at 400 security compute units per month per thousand user licences, capped at 10,000 per month, with additional units available on demand (microsoft.com security blog, 18 November 2025). For any client already on E5, the AI layer stopped being a separate purchase.

Other vendors are in the same territory. CrowdStrike announced seven agents in September 2025, with language emphasising that they remain under human control and no published triage-volume or autonomy metrics. Palo Alto announced Cortex AgentiX in October 2025 with claims of up to ninety-eight per cent reduction in mean time to resolve and seventy-five per cent less manual work, built on 1.2 billion playbook executions; those are vendor claims with no published methodology. Splunk Enterprise Security 8.6 shipped its own agent set in August 2026.

What the independent evidence says. Gartner's 2026 Hype Cycle for Security Operations places AI SOC agents at the peak of inflated expectations, up from innovation trigger the previous year, with market penetration of only one to five per cent, and commentary to the effect that the market still has to prove agentic claims produce defensible outcomes; that is reported second-hand rather than read from the Gartner document. Cisco's own figure, reported at RSAC 2026, is that eighty-five per cent of enterprises have AI agent pilots and five per cent are in production (VentureBeat, 1 April 2026). The SANS 2026 AI Survey, released 20 July 2026 with 536 practitioners and 57 chief information security officers, found adoption of AI in security strategy rising from fifty to seventy-eight per cent year on year, seventy-eight per cent of organisations experiencing confirmed or suspected AI-enabled attacks, sixty-three per cent of practitioners reporting significant AI shortcomings in threat detection and response (up from forty-five per cent), and only twenty-seven per cent describing their production deployment as mature.

The academic picture is the most useful for a tender. The 2026 survey of AI-driven alert screening cited earlier synthesises 119 records and 87 core studies and concludes that the field produces technically sophisticated systems with comparatively little evidence that they remain effective under the temporal, organisational and data-distribution pressures of real security operations centres. Reported results range from over ninety per cent workload reduction under controlled conditions, to a six-month deployment achieving sixty-one per cent alert reduction at a 1.36 per cent false-negative rate. Its open challenges are cross-environment generalisation, adversarial evasion, label scarcity and drift, real-time performance at scale, accountability and automation governance, and the absence of benchmark standardisation.

How to write about this in a bid. Do not promise autonomous response. Do describe where AI assistance genuinely helps today: summarising an incident for a non-technical reader, drafting a query, enriching an alert with context, and reducing the time an analyst spends on repetitive triage. Do state that a human makes the containment decision. And do price it honestly, because for a client on E5 it may be included and for a client who is not it is a separate line item.

Sources used

The unit scope, elements, performance criteria, foundation skills, performance and knowledge evidence, range of conditions and assessment conditions are taken from the accredited course document for 22603VIC Certificate IV in Cyber Security, V1 (Victorian Department of Education and Training, 2022; accreditation period 1 January 2023 to 31 December 2027), read 2 September 2026, and cross-checked against the Victoria University unit page for VU23220 (no publication date shown). A later course document, V1.2, was posted in February 2026 and could not be opened during this build, so any change between V1 and V1.2 has not been checked. The training.gov.au record renders in JavaScript and could not be fetched. The delivery detail, the Top End Tours scenario and the assessment structure come from the CDU TAFE VU23220 Assessor Guide v4.4 (October 2024) and the VU23220 topic presentations held in the unit folder.

On security operations and tooling: Cisco's completion of the Splunk acquisition (18 March 2024); the Splunk Enterprise Security 8.6 release notes (page last updated 5 August 2026); Cisco's EMEA SOC write-up (9 March 2026); Microsoft's Sentinel in the Defender portal and unified security operations what's new; the Sentinel data lake general availability announcement (30 September 2025); the Microsoft Sentinel pricing page (no date shown, figures stated as estimates); Google Security Operations packaging (no date shown); TechCrunch on Google completing the Wiz acquisition (11 March 2026); SecurityWeek on Google completing the Mandiant acquisition (12 September 2022); the Wazuh 4.14.7 release notes (29 July 2026); Elastic's return to AGPL (29 August 2024); and the Security Onion release notes. Endpoint material draws on Microsoft's Defender for Endpoint requirements and Defender for Business overview, Gartner's endpoint protection market page and managed detection and response overview (last updated 15 July 2026), and, for the July 2024 outage, CrowdStrike's preliminary post-incident report (24 July 2024) and the CISA alert (19 July 2024).

Framework and threat material comes from the MITRE ATT&CK updates page and the April 2026 v19 release notes; MITRE's announcement of the 2025 ATT&CK Evaluations (10 December 2025); the Lockheed Martin Cyber Kill Chain; and, for Australian threat figures, the Minister for Defence's release on the Annual Cyber Threat Report 2024 to 2025 (14 October 2025) with additional figures from Cyber Daily (14 October 2025).

Network and lab material draws on nbn Enterprise Ethernet (page dated 14 July 2026), the nbn Fixed Wireless upgrade completion statement (14 February 2025), Sky Muster Plus Premium (last updated 25 August 2026), WhistleOut's Starlink priority plan comparison (published 10 June 2026, updated 2 September 2026), Telstra's satellite messaging announcements of 7 June 2025 and 28 July 2026, the Universal Outdoor Mobile Obligation Bill 2025 homepage, Cisco Catalyst SD-WAN Manager (page dated 27 March 2026), Cisco Press on HSRP and VRRP (5 August 2024), Cisco Modeling Labs free tier documentation, a comparison of GNS3, EVE-NG and containerlab (21 April 2026, updated 1 September 2026), and Palo Alto's end-of-sale announcements and VM-Series free trials page. The Optus outage material comes from ACS Information Age (14 November 2023), the ACMA penalty release (November 2024), the ABC timeline of the September 2025 outage (23 September 2025, updated 29 September 2025) and the ABC report of the ACMA Federal Court action (30 July 2026). Reported duration and death toll differ between the 2025 reporting and the 2026 court reporting and have not been publicly reconciled.

Legal and procurement material comes from the Cyber Security Act 2024, the Cyber Security (Ransomware Payment Reporting) Rules 2025, the Home Affairs Cyber Security Act page (last updated 19 February 2026), the Home Affairs ransomware payment reporting factsheet and smart device security standards page; the Privacy and Other Legislation Amendment Act 2024 with the OAIC's guidance on the statutory tort, the small business exemption (last updated 5 September 2024) and the Notifiable Data Breaches scheme (last updated 20 February 2025); the Cyber and Infrastructure Security Centre on the SOCI Act (last updated 27 August 2024) and the cyber security legislative reforms (last updated 4 September 2025); the Commonwealth Procurement Rules 2025 with the Finance PDF and the Finance announcement of the changes (22 October 2025); the Hosting Certification Framework; and, for the Territory, the NT Procurement Rules version 2.0 (effective 1 October 2025), the NT procurement framework page (last updated 12 December 2025), NT procurement policies and guidance (last updated 15 December 2025), Quotations and Tenders Online and the CyberNT Cyber Invest Business Program (last updated 21 August 2026). The Essential Eight retirement is reported by TechPartner News (23 June 2026) and Australian Cyber Security Magazine (24 June 2026); the ASD announcement page could not be reached during this build, and cyber.gov.au was unreachable throughout, so Essential Eight, ISM and PSPF detail rests on those secondary reports plus the ASD ISM OSCAL release history for release dates.

The AI in security operations section draws on Microsoft's Security Copilot general availability announcement (March 2024), the agents announcement (24 March 2025) and the inclusion in Microsoft 365 E5 (18 November 2025); CrowdStrike's agent announcement (16 September 2025); Palo Alto's Cortex AgentiX release (28 October 2025); VentureBeat's RSAC 2026 coverage (1 April 2026); analysis of the SANS 2026 AI Survey (July 2026); and Ndichu and others, "AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey" (arXiv preprint, 2026). The Gartner Hype Cycle placement of AI SOC agents is reported second-hand and the Gartner document itself was not read.