The question is no longer what to decide: it’s who should.
Mohd Atasha helps chief executives decide where human judgement belongs as more decisions become automated by AI, across business, technology and policy. Done well, this creates growth, resilience and trust.
Talk through the decision you are facingOr read what fourteen people say about working with him
He sat on the government’s side of the table with chief executives at Fortune 500 companies, in investment talks associated with more than 11,000 jobs. He is part of the management team that took a venture-backed company from loss-making to profitable, now growing about fifty per cent a year. Both were decisions before they were results.

Which decisions are these ?
A machine can decide
The rule is clear, and a mistake is cheap and visible
- Reordering stock when inventory falls below a threshold
- Flagging an unusual line on an invoice for review
- Routing a routine request to the right queue
Contested: this is the work
It turns on business, technology and policy at once
- Connecting a network that was built never to touch the internet
- Moving to cloud, and losing the cost visibility the old perimeter gave
- Relying on a model whose decisions resist the old kinds of audit
- Moving a boundary deliberately, before the consequences are understood
A person must decide
Accountability cannot be delegated to anything
- Stopping work the organisation has committed to publicly
- Telling a board the plan has a gap in it
- Choosing which market to leave
The middle column is where this practice works. Those four are the same boundary problems set out below, and each one turns on business, technology and policy at once, which is what makes it hard to settle from inside any one of them.
Where are you stuck ?
Six situations that come up often. Choose the one that sounds like yours to see what it turns on, where he would start, and what you would have in hand afterwards.
These are the situations described elsewhere on this site, put in the words a reader would use. Nothing here describes a particular client.
Three kinds of expertise, in one person
A decision worth a second opinion usually sits between two of these rather than inside one, which is why it is hard to judge from the inside. Each entry says what he has been accountable for, and what tends to go wrong when that side is missing.
- Business
- He is part of the management team that turned Alphaus from a loss-making company into a profitable one now growing about fifty per cent year on year. Before that, institutional fund administration across Asia Pacific and Europe, two years with no financial loss, and Chief Strategist at a research and development firm. Without this, a decision is taken without the arithmetic of what it costs to serve each new customer, and margin quietly disappears.
- Technology
- Building and operating since 2001, from client work then to network isolation, artificial intelligence governance and cloud economics now. Long enough to tell what can be delivered from what only looks well on a slide. Without this, a plan commits to something the organisation cannot build, and the gap appears only once the deadline is close.
- Policy
- He negotiated on Malaysia’s behalf with chief executives at Fortune 500 and Forbes 2000 companies considering investment in the country, work associated with more than eleven thousand jobs and over seven billion ringgit, and afterwards moved to designing the policy rather than negotiating under it. He holds a seat on the national artificial intelligence technical standards task force. He has served as a consultant to the International Trade Centre in Geneva, advised a UNCTAD and Alibaba fellowship, and spoken at the United Nations. Without this, a regulator or an approval sets a timetable the commercial plan was never written for.
In practice they arrive together, which is what makes a stall hard to diagnose from inside. A regulator’s question arrives with a commercial deadline attached. An investment decision turns on whether the thing can in fact be delivered. A business model that worked at one size quietly stops working at the next. A sound plan still fails if nobody changes what they do. The useful question is not which department is at fault, but which of these the decision actually turns on.
The people who ask are usually chief executives, and heads of strategy, operations and growth. Chief technology and information officers ask too, often about the same problem from the other side. None of them needs to be technical to have the conversation, and nobody is answered in jargon.
What he is asked to do
Most of the work is strategy and commercial judgement, and that does not reduce neatly to a list. What does reduce to a list is the narrower kind of request that arrives already shaped, usually about risk. It is worth understanding because of what it costs a company in decisions deferred: these are the four things that most often stop a board from approving one, or stall it after approval.
Most organisations meet this as four separate budget lines: a security team worried about exposure, a compliance team asked how an artificial intelligence system decides, a finance team unable to explain a cloud bill, and a programme team mid-migration. They are usually treated as four problems, by four suppliers, which is four times the cost and none of the answer.
They are one event. A boundary that once held no longer does, and the institution has taken on risk it cannot yet measure. Which is why they recur: fixing any one of them separately leaves the cause in place.
The air gap is eroding; networks built never to touch the internet now do. The datacentre perimeter dissolved into cloud and took cost visibility with it. The deterministic system gave way to models whose decisions resist the old kinds of audit. Transformation is the deliberate act of moving a boundary and hoping the consequences were understood.
Assessing that gap is the work. In one of the four it goes further: the air gap can be given back. Its value was never the wall but the silence behind it: a scan that found nothing, because nothing was listening. Arrange access so the protected machine reaches outward and never waits for a connection, and that silence returns without the isolation. That is air-gap zero trust network access, and it is the practical half of the first doctrine.
None of this is a technology hobby. Unmeasured risk is what makes a board defer a decision, and a decision deferred for a year is a year of growth, or stability, or protection that the company does not get. Naming the exposure precisely is usually what lets the decision go ahead.
Doctrine
He publishes the reasoning behind the advice, so it can be read and argued with before any engagement begins. Two of the four are about technology; one is about cost, and one is about why sound decisions fail to take hold.
- From air gap to zero trustAn air gap removed the path by which anything inside could be discovered, reached or administered. Connectivity did not have to cost you that last part; opening inbound ports did.
- Governing agentic systemsAn autonomous agent holding credentials is an access problem before it is a model problem. None of the major frameworks was written for this.
- Cloud spend is attack surfaceUnowned resources are unpatched resources. Cost management read as a control discipline rather than a procurement exercise.
- The recommendation nobody acted onEvery argument here ends in an ask that requires somebody to be told they were wrong. Treating that as a communication problem is why sound work stalls.
Why you might believe any of this
Every figure and name below is published in full elsewhere on this site, and each line says where to check it.
- 11,000+
- Jobs created through investment he negotiated
- RM7bn+
- Foreign direct investment secured for Malaysia
- 20+
- Years across enterprise, government and emerging markets
- Assessed by leaders at
- Schlumberger Malaysia / Standard Chartered Global Business Services / Juris Technologies / Emerio, an NTT Ltd company / NTT Docomo Ventures / Bangsawan Group Singapore / Enterprise Singapore / Rally Students / The Fave Group / StoreHub / Otomate Me / Nettium / VentureTECH / 5Echo
- Currently holds
- AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force / Contributor, Artificial Intelligence Systems Cyber Security Framework (AISCF) Taskforce
That combination of empathy and execution is rare, and incredibly valuable.
Read all fourteen assessments, with names and organisations
More extensive list of frameworks, credentials and institutional standing
What happens if you make contact
Four stages. Most engagements do not run all of them, and the first exists partly to establish which are needed.
- Framing
- Assessment
- Architecture and decision support
- Handover