Melbourne's independent cybersecurity advisor — helping Australian businesses strengthen their security posture, meet compliance obligations, and build lasting cyber resilience. Vendor-agnostic. Business-aligned. Locally based.
Melbourne-based · Serving Australian businesses across healthcare, finance, professional services, government, retail & manufacturing
Australian businesses face a perfect storm of escalating cyber threats, tightening regulation, and a global shortage of skilled security professionals. The question is no longer if you will be targeted — it's whether you'll be ready when it happens.
Privacy Act 1988 reforms (2024), the NDB scheme, SOCI Act, and the ACSC Essential Eight maturity model are raising the compliance bar. Non-compliance carries serious financial penalties and lasting reputational damage.
Every hour of undetected threat activity has a real business cost. Ransomware can halt operations for days. The ACSC reports cybercrime as an escalating national threat — and Australian businesses are firmly in the crosshairs.
Building a 24/7 SOC requires $1.5M+ in infrastructure, $2M–$3M annually in staffing, and $500K+ in licensing. Most Australian mid-market businesses simply cannot justify that investment — nor should they have to.
Insurers mandate MFA, EDR, incident response plans, and encryption. Without these controls, carriers can legally deny your breach claim — or triple your premium at renewal. Readiness is not optional.
Kamal Salwan works with your business to translate cybersecurity complexity into clear, actionable strategy — without trying to sell you unnecessary technology.
For most Australian mid-market businesses, a Managed Security Service Provider delivers superior coverage at a fraction of the cost.
| Factor | In-House SOC | MSSP (via Digital Enact) |
|---|---|---|
| Infrastructure & tools | $1.5M+ upfront | Included in subscription |
| Annual staffing | $2M–$3M/yr (6 analysts, 2 engineers, 1 CISO) | Included in subscription |
| Licensing & training | $500K+/yr | Included in subscription |
| Total approximate cost | $4M+ per year | $250K–$400K/yr |
| Coverage | Business hours + on-call gaps | 24/7/365 |
| Compliance reporting | Manual/internal | Built-in, audit-ready |
| Scalability | Requires additional headcount | Scales with subscription |
Cyber risk is not one-size-fits-all. Different industries face different threats, different regulatory obligations, and different consequences of a breach.
Privacy Act 1988, NDB scheme, My Health Records Act, ACSC Essential Eight
Ransomware targeting patient data, telehealth security, insider threats to electronic health records
“Protecting sensitive patient information while enabling digital health innovation”
Privacy Act 1988 (2024 reforms), APRA CPS 234, NDB scheme, ASD guidelines, SOCI Act
Insider threats, SOC gaps, real-time payment fraud, legacy infrastructure vulnerabilities
“Ensuring APRA CPS 234 compliance while protecting customer financial data”
Privacy Act 1988, NDB scheme, legal professional privilege, accounting data obligations
Phishing, business email compromise, client data breaches, supply chain attacks
“Protecting client confidentiality and firm reputation in a distributed work environment”
SOCI Act, Australian Government ISM, Essential Eight, ACSC guidelines, state privacy legislation
Ransomware on council systems, citizen data breaches, legacy infrastructure, inter-agency data sharing
“Aligning council cybersecurity with Essential Eight and SOCI obligations on limited budgets”
Privacy Act 1988, NDB scheme, PCI-DSS for payment processing
Payment data theft, supply chain attacks, distributed workforce, seasonal staff BYOD
“Securing payment systems and customer data across physical and digital channels”
SOCI Act (critical infrastructure), NDB scheme, ACSC Essential Eight, supply chain security
OT attacks, IoT vulnerabilities, ransomware halting production, IP theft
“Protecting operational technology while securing the digital supply chain”
When it comes to cybersecurity, you don't just need solutions — you need a trusted advisor who understands your business, your obligations, and your risk appetite.
You work directly with Kamal Salwan — not a rotating team of junior consultants. Single point of contact from assessment through to implementation guidance. The same person who understands your business strategy also understands your security needs.
Cyber outcomes are always tied to business goals: protecting revenue, reducing liability, meeting regulatory obligations. No unnecessary complexity or technology for technology's sake. Security is a business enabler, not just an IT function.
No vendor commissions or supplier incentives influencing recommendations. Genuinely independent advice on MSSPs, tools, and security architectures. Local to Melbourne — available for face-to-face engagement with Australian businesses.
Deep understanding of the Australian regulatory landscape: Privacy Act, NDB scheme, SOCI Act, Essential Eight, ASD guidelines, and the Cyber Security Strategy 2023–2030. Advice calibrated to your business size, industry, and risk context.

Founder & Principal Advisor, Digital Enact · Melbourne, Australia
Kamal is a digital transformation and cybersecurity strategist with deep experience helping Australian organisations navigate complex technology and regulatory landscapes. As a sole advisor, he provides the kind of direct, accountable, and genuinely independent advice that larger consultancies simply cannot offer. Every engagement is led personally by Kamal — from initial assessment through to implementation guidance.
Replace placeholder content below with real testimonials and client logos.
“Kamal helped us understand exactly where our security gaps were and gave us a clear, practical roadmap to address them. For the first time, our board had confidence in our cyber posture.”
“We were facing a cyber insurance renewal with a 60% premium increase. Kamal identified the missing controls, helped us implement them, and we renewed at a significantly lower rate.”
“The compliance advisory work Digital Enact provided saved us months of preparation. Kamal translated complex regulatory requirements into actions our team could actually execute.”
Clients & Partners
Book a free, no-obligation consultation with Kamal Salwan. In 30 minutes, you'll have a clearer picture of your current cyber risk and where to focus next.
No vendor agenda. No sales pressure. Just expert, independent advice tailored to your Australian business.
Prefer to get in touch directly?