Technology decisions are business decisions, and increasingly policy decisions. Mohd Atasha works where the three meet.
He has negotiated inbound investment on a government’s behalf, carried operational responsibility for institutions across Asia and Europe, and contributes to Malaysia’s national technical standards for artificial intelligence. Founders and investors ask for his read as well. What a client gets is judgement that has to hold on all three sides at once.
What this has produced
- 11,000+
- Jobs created through investment he negotiated
- RM7bn+
- Foreign direct investment secured for Malaysia
- 20+
- Years across enterprise, government and emerging markets
Investment and employment figures reflect work with Fortune 500 and Forbes 2000 leadership between 2013 and 2015.
Three sides of the same decision
Advisors tend to come from one of these three. Having been accountable in each is less common, and it is usually why a conversation starts here.
- Technology
- Building and operating since 2001, from client work then to network isolation, artificial intelligence governance and cloud economics now. Long enough to know what can be delivered, and what only looks well on a slide.
- Business
- Institutional fund administration across Asia Pacific and Europe, two years with no financial loss. Regional director for a venture-backed cloud financial management platform. Chief Strategist at a research and development firm. He has carried commercial responsibility, not only advised on it.
- Policy
- He represented Malaysia in negotiations with international companies considering investment in the country, work associated with more than eleven thousand jobs and over seven billion ringgit, and afterwards contributed to policy design and implementation. He holds a seat on the national artificial intelligence technical standards task force, whose output is voluntary industry guidance rather than law. He has served as a consultant to the International Trade Centre in Geneva, advised a UNCTAD and Alibaba fellowship, and spoken at the United Nations.
In practice the three rarely stay apart. A regulator’s question about an artificial intelligence system arrives with a commercial deadline attached. An investment decision turns on whether the technology can in fact be delivered. Founders and investors tend to ask the same questions from the other direction.
What he is asked to do
Much of the work is strategy and commercial judgement, which does not reduce neatly to a list. The requests that arrive already shaped tend to concern risk, and those take four familiar forms.
Most organisations meet this as four separate budget lines: a security team worried about exposure, a compliance team asked how an artificial intelligence system decides, a finance team unable to explain a cloud bill, and a programme team mid-migration. They are usually treated as four problems, by four suppliers.
They are one event. A boundary that used to hold has dissolved, and the institution has taken on risk it cannot yet measure. Which is why they recur: fixing any one of them separately leaves the cause in place.
The air gap is eroding; networks built never to touch the internet now do. The datacentre perimeter dissolved into cloud and took cost visibility with it. The deterministic system gave way to models whose decisions resist the old kinds of audit. Transformation is the deliberate act of moving a boundary and hoping the consequences were understood.
Assessing that gap is the work. In one of the four it goes further: the air gap can be given back. Its value was never the wall but the silence behind it: a scan that found nothing, because nothing was listening. Arrange access so the protected machine reaches outward and never waits for a connection, and that silence returns without the isolation. That is air-gap zero trust network access, and it is the practical half of the first doctrine.
Doctrine
- From air gap to zero trustThe air gap was never really about separation. It was about there being nothing to reach. Connectivity did not have to cost you that; opening inbound ports did.
- Governing agentic systemsAn autonomous agent holding credentials is an access problem before it is a model problem. None of the major frameworks was written for this.
- Cloud spend is attack surfaceUnowned resources are unpatched resources. Cost management read as a control discipline rather than a procurement exercise.
Standing
AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force
Convened by the Malaysian Technical Standards Forum, the body designated by the Malaysian Communications and Multimedia Commission for communications and multimedia standards. The task force develops Malaysia’s national AI technical standards for that industry. These are voluntary industry codes rather than law: once registered by the commission, compliance with a code is a legal defence, not a legal obligation. A technical code on artificial intelligence cybersecurity architecture requirements is listed by the forum as under development. 2025 to present.
Partner Advisor, eFounders Fellowship
Appointed by Alibaba Group and the United Nations Conference on Trade and Development. Curriculum design for a programme delivered at Alibaba Business School, whose 2018 letter of invitation records him as an advisor of the course. 2018 to 2023.
Full list of frameworks, credentials and institutional standing
Assessment
That combination of empathy and execution is rare, and incredibly valuable.