# SALTT Technologies (full text for AI agents) > SALTT Technologies (SALTT Tech) is a 100% Australian-owned cybersecurity consultancy with offices in Sydney, Melbourne and Brisbane. It delivers five capability areas: penetration testing and technical assurance, AI cybersecurity, governance, risk and compliance (GRC), security architecture and engineering, and managed CyberOps. Engagements are led by senior practitioners and all data handling stays in Australia. Canonical site: https://www.saltt.tech Short index: https://www.saltt.tech/llms.txt Blog feed: https://www.saltt.tech/insights/rss.xml Last reviewed: 2026-09-06 ## Company facts - Legal entity: SALTT Technologies Pty Ltd. ABN 32 660 169 808. - Ownership: 100% Australian-owned. No offshore ownership and no overseas data handling. - Tagline: "Defending the digital future." Positioned as a sovereign Australian cybersecurity provider. - Offices: Sydney (headquarters), Melbourne, Brisbane. - Sydney: Level 4/1 James Place, North Sydney NSW 2060 - Melbourne: Suite 4423, 805/220 Collins Street, Melbourne VIC 3000 - Brisbane: Suite 4126, 29/97 Creek Street, Brisbane City QLD 4000 - Contact: hello@saltt.tech. Web form at https://www.saltt.tech/contact. Response within one business day. - LinkedIn: https://www.linkedin.com/company/saltt-technologies - Leadership: - Adrian Noblett, Chief Technology Officer. Cybersecurity practitioner and technical architect with deep expertise in security engineering and integration. Leads SALTT's technical capability and client delivery. - Malcolm Salameh, Managing Partner. Senior security executive and consulting leader with extensive experience across government, financial services and enterprise. Drives strategy, partnerships and commercial growth. - Sectors served: government, financial services, critical infrastructure, healthcare, enterprise. Clients range from ASX-listed enterprises to government agencies. Logos shown on the site include One Rail Australia, Makinson d'Apice, The Shepherd Centre, Tourism Australia, LifeFlight, Ticketek, NSW Government, ASX, helloworld, Youi, Waverley Council, Harris Farm Markets, Sydney Children's Hospitals Network, Guzman y Gomez, Nine Entertainment Co., Vittoria Coffee, TPG and NRL. - Frameworks and regulators referenced: ASD Essential 8, ISM, IRAP, CIS, NIST, OWASP, APRA CPS 234, ACSC advisories, Australian Government AI governance guidance. - Proprietary technology: Korrosiv.AI, SALTT's in-house AI-native penetration testing engine used to augment human-led testing. ## The SALTT name and values - S: Secure. Security is the foundation, not a feature. - A: Adaptable. We evolve with the threat landscape. - L: Leadership. We lead with expertise and accountability. - T: Trusted. Trust is earned through consistent delivery. - T: Teamwork. Great security is a collaborative endeavour. ## Why organisations choose SALTT - 100% Australian-owned: information stays in Australia and is worked on by Australian practitioners who understand local regulation. - Practitioners, not salespeople: every engagement is led by experienced practitioners, not account managers who hand off to juniors. - Outcomes, not just compliance: practical recommendations, usable deliverables and honest assessments rather than checkbox reports. - Sector experience across government, financial services, critical infrastructure, healthcare and enterprise. - Australian threat focus: ACSC advisories, ASD Essential 8, APRA CPS 234 and threat actors active in the region. - Collaborative by design: knowledge transfer and upskilling so clients are more capable after every engagement. ## Company story SALTT Tech was founded because too many Australian businesses were working with cybersecurity firms that overpromised, underdelivered and left them with reports they could not act on, treating compliance as the goal rather than security. SALTT works alongside client teams as a trusted partner rather than a vendor dropping off a PDF. --- # Services Overview page: https://www.saltt.tech/services ## Capability 01: Cybersecurity Architecture & Engineering URL: https://www.saltt.tech/services/security-architecture Security that is designed into your environment, not bolted on after the fact. Most security problems are architecture problems: controls added retrospectively create gaps, complexity and technical debt. SALTT works with technical teams to design security in, whether building something new, modernising infrastructure or moving to the cloud. Offerings: - Security Architecture Reviews: independent review of existing or proposed architecture against security principles and threat models. - Controls Design & Implementation: network segmentation, endpoint controls, logging, monitoring and data protection. - Zero Trust Architecture: design and phased roadmap from perimeter-based to identity-centric, least-privilege access. - Identity & Access Management: identity governance, privileged access management, MFA, SSO and lifecycle management across on-premises and cloud. - Cloud Security Architecture: AWS, Azure and GCP landing zones, network architecture, IAM structure, data protection and detective controls. - Security Framework Development: translating ISM, CIS and NIST into practical, measurable, owned controls. Outcomes: controls that fit the environment, reduced architecture risk, a clear zero trust path, securely built cloud environments, auditable least-privilege IAM, frameworks internal teams can operate. ## Capability 02: Penetration Testing & Technical Assurance URL: https://www.saltt.tech/services/penetration-testing Human-led adversarial testing augmented by Korrosiv.AI. Automated scanners find known problems; attackers find the rest. SALTT's offensive security services approach every engagement the way a motivated threat actor would, with business context, and every finding comes with a risk-rated remediation plan. Offerings: - External & Internal Penetration Testing: internet-facing and assumed-network-access perspectives. - Web Application Security Testing: manual OWASP-aligned assessment augmented by Korrosiv.AI, which analyses 100% of responses and adapts payloads in real time. - API Security Testing: REST and GraphQL, covering excessive data exposure, broken object-level authorisation and injection flaws. - Red Team Engagements: multi-stage adversary simulation that tests detection and response. - Cloud Configuration Reviews: AWS, Azure and GCP against best practice and CIS benchmarks. - Assumed Breach Exercises: lateral movement, escalation and exfiltration from an internal foothold. - Technical Security Assurance: independent review of controls and implementation quality before go-live. - Vulnerability Assessments: scoped, risk-rated assessments with prioritised remediation guidance. Outcomes: a clear risk-rated picture of exploitable vulnerabilities, remediation prioritised by business impact, evidence for board reporting, compliance and cyber insurance, validated detection and response, and a long-term testing partner. ## Capability 03: AI Cybersecurity URL: https://www.saltt.tech/services/ai-cybersecurity AI adoption is accelerating faster than security frameworks can keep up. Prompt injection, data leakage, model poisoning and insecure integrations are real attack vectors that most security programmes are not equipped to address. SALTT identifies where AI creates risk, designs proportionate controls and builds governance frameworks so organisations can adopt AI confidently. Offerings: - AI Cybersecurity Controls Design: model access, input validation, output filtering, integration security, adversarial monitoring. - LLM Threat Modelling: prompt injection surfaces, exfiltration vectors, insecure plugin integrations, misuse scenarios. - Data Governance Frameworks: training data handling, minimisation, access, retention and compliance for AI workloads. - LLM Risk Management: risk registers, acceptable use boundaries, residual risk documentation, escalation paths. - AI Policy & Standards: AI security policies, acceptable use standards and vendor assessment criteria aligned to Australian Government AI governance guidance. - Generative AI Risk Assessments: point-in-time assessment of existing deployments including shadow AI. Outcomes: visibility of AI risk, controls for AI-specific attack vectors, governance that enables adoption, data protection for AI workloads, demonstrable compliance posture as regulation evolves. ## Capability 04: Governance, Risk & Compliance URL: https://www.saltt.tech/services/grc Effective governance is the foundation that makes every other control work. Most organisations know they have gaps; few know which ones matter. SALTT starts from the actual risk environment rather than a generic checklist and builds governance frameworks the client team can own. Offerings: - Essential 8 Assessment & Remediation: independent maturity assessment against the ASD Essential 8 with a prioritised roadmap. - CISO as a Service (vCISO): strategy, stakeholder communication, board reporting and programme oversight on a flexible model. - Incident Response Planning: tested, usable plans built around the client's environment and threat profile. - Tabletop Simulations: facilitated breach scenarios for leadership teams. - 3rd Party Risk Management: supplier assessments, risk registers and ongoing monitoring. - Security Awareness & Phishing Simulations: targeted training and simulated phishing campaigns. Outcomes: a clear maturity picture, a board-ready roadmap, exercised incident response capability, owned governance frameworks, demonstrable Essential 8 progress, reduced supply chain exposure. ## Capability 05: CyberOps Management URL: https://www.saltt.tech/services/cyberops Security tools are only as good as the people maintaining them. Without ongoing configuration and tuning, EDR, SIEM, identity and cloud security platforms degrade. SALTT's CyberOps managed service maintains security tooling so it keeps delivering value. Offerings: - Security Tool Management: ongoing configuration, tuning and maintenance of security platforms. - Platform Optimisation: audit of the current stack, gap and misconfiguration remediation across endpoint, identity, cloud and network. - Vulnerability & Patch Management: structured identification, prioritisation and remediation. - Threat Intelligence: contextualised to sector, geography and technology stack. - Cyber Defence Programme Management: programme planning, maturity tracking, vendor management and board reporting. Outcomes: correctly configured tools, faster detection and containment, reduced vulnerability exposure, more coverage from existing platforms, measurable maturity, less burden on internal teams. --- # Insights (blog) Listing: https://www.saltt.tech/insights Feed: https://www.saltt.tech/insights/rss.xml Author page: https://www.saltt.tech/insights/author/saltt-tech - 2026-07-22. The First Agentic Breach Was an Accident. https://www.saltt.tech/insights/openai-hugging-face-agentic-breach-2026. In July 2026 two of the most capable AI models broke out of a locked-down test environment, reached the open internet and compromised a live technology company with no human directing the attack. - 2026-06-15. The Attacker's Marginal Cost Is Now Zero. https://www.saltt.tech/insights/ai-worms-self-replicating-malware-2026. Two research papers confirm self-replicating AI malware is no longer theoretical; what defenders should change. - 2026-05-12. Three Signals, One Problem: Speed Is Outrunning Australian Cyber Controls. https://www.saltt.tech/insights/three-signals-velocity-gap-australian-cyber. A pattern reading of three recent stories and what Australian security leaders should do this quarter. - 2026-05-05. Copy Fail: Nine-Year-Old Linux Kernel Flaw Gives Any User Root in 732 Bytes. https://www.saltt.tech/insights/copy-fail-cve-2026-31431-linux-kernel-vulnerability-analysis. Analysis of CVE-2026-31431, a logic flaw in the kernel's cryptographic subsystem. - 2026-04-24. Claude Mythos Vendor Breach: Implications for Enterprise Exposure Management. https://www.saltt.tech/insights/mythos-leak-find-your-gaps-first. Review of the reported Project Glasswing vendor breach and what it means outside the 40-partner consortium. - 2026-04-21. AI Security Tools Expand: What It Means for Aussie Defenders. https://www.saltt.tech/insights/weekly-cyber-brief-2026-04-20. OpenAI and Anthropic expanded security-focused AI capabilities; implications for Australian defensive programmes. - 2026-04-13. Russian GRU Router Campaign: What Australian Organisations Must Do. https://www.saltt.tech/insights/blog/weekly-cyber-brief-2026-04-13. - 2026-04-12. Korrosiv.AI Is Changing Penetration Testing. https://www.saltt.tech/insights/korrosiv-ai-changing-penetration-testing-australia. Typical web application assessments cover 20 to 40 percent of the real attack surface; how AI-native testing changes that. - 2026-04-12. AI-Driven Penetration Testing: What It Means for Your Program. https://www.saltt.tech/insights/ai-driven-penetration-testing-australia. - 2026-04-12. What a Penetration Test Actually Tells You. https://www.saltt.tech/insights/what-penetration-test-tells-you-results. How to interpret findings and translate them into risk reduction. - 2026-04-12. Essential 8 in 2026: What's Changed and Where to Focus First. https://www.saltt.tech/insights/essential-8-2026-whats-changed-where-to-focus. - Earlier. LastPass and Okta Breaches: Security Steps You Should Take Right Now. https://www.saltt.tech/insights/lastpass-and-okta-breaches-security-steps-you-should-take-right-now - Earlier. 91% of Cybersecurity Pros Experience AI-Driven Cyber Attacks. https://www.saltt.tech/insights/91-of-cybersecurity-pros-experience-ai-driven-cyber-attacks - Earlier. Defending against the escalating threat of Deepfakes. https://www.saltt.tech/insights/defending-against-the-escalating-threat-of-deepfakes - Earlier. Web Application and API protection needs to be cloud delivered. https://www.saltt.tech/insights/web-application-and-api-protection-needs-to-be-cloud-delivered - Earlier. BitUnlocker: a deep technical analysis of a full-volume encryption bypass and what it means for BitLocker threat models. https://www.saltt.tech/insights/bitunlocker-a-deep-technical-analysis-of-a-full-volume-encryption-bypass-and-what-it-means-for-bitlocker-threat-models - Earlier. Harness Your Inner Cyber Sleuth With KnowBe4's New 'Hack-A-Cat' Game on Roblox. https://www.saltt.tech/insights/harness-your-inner-cyber-sleuth-with-knowbe4-s-new-hack-a-cat-game-on-roblox --- # Frequently asked questions Q: Where is SALTT Technologies based? A: SALTT is headquartered in North Sydney with offices in Melbourne and Brisbane, and works with organisations across Australia. Q: Is SALTT Australian-owned? A: Yes. SALTT Technologies Pty Ltd is 100% Australian-owned, with no offshore ownership or overseas data handling. Q: What is Korrosiv.AI? A: Korrosiv.AI is SALTT's in-house AI-native penetration testing engine. It augments human testers by analysing every application response and adapting payloads in real time, increasing coverage on web application and API assessments. Q: Does SALTT help with the Essential 8? A: Yes. SALTT provides independent Essential 8 maturity assessments and prioritised remediation roadmaps as part of its GRC capability. Q: Does SALTT offer a virtual CISO? A: Yes. CISO as a Service (vCISO) is available on a flexible engagement model covering strategy, board reporting and programme oversight. Q: How do I contact SALTT? A: Email hello@saltt.tech or use the form at https://www.saltt.tech/contact. SALTT responds within one business day. --- # Legal - Privacy Policy: https://www.saltt.tech/privacy-policy - Product Supply Terms and Conditions: https://www.saltt.tech/products-terms - Voluntary Statement Against Modern Slavery (PDF): https://www.saltt.tech/voluntary-statement-against-modern-slavery