10/06/2026
That gap is not an IT problem. It is an unaudited attack surface.
The sites we work on tell a consistent story: cabling in the walls that nobody commissioned, nobody labelled, and nobody decommissioned.
It was there when the last tenant left. It will be there when the next one arrives. TIA-606 exists precisely to govern this. Compliance is voluntary. Most buildings treat it that way.
We found a live Cat6 port behind a blanking plate in a Wetherill Park plant room last year. Unlocked room. Carpark-level access. The port appeared on no drawing, no asset register, no CMDB. Network access control had no record of it. Three years of tenancy and nobody knew it existed.
Your SDN platform and your network automation tools are only as accurate as the physical topology underneath them. An undocumented run is a blind spot those tools cannot see and cannot protect.
An unmapped active port is not a documentation gap. It is a liability with no expiry date.
If your organisation is working toward ISO 27001 or Essential Eight compliance, does your physical layer documentation hold up to the same standard as your logical security controls?