Frameworks and credentials
What this practice works to. Every entry links to its primary source; nothing is asserted that cannot be checked.
Operational technology and network architecture
- ISA/IEC 62443
- Zones and conduits; industrial automation and control systems security.
- NIST SP 800-82 Revision 3
- Guide to operational technology security.
- NIST SP 800-207
- Zero trust architecture.
- Adapting Zero Trust Principles to Operational Technology
- Joint guidance, April 2026.
Artificial intelligence
- ISO/IEC 42001:2023
- AI management systems. Certifiable, and increasingly requested in procurement due diligence.
- Regulation (EU) 2024/1689, the AI Act
- Applies extraterritorially where outputs are used in the Union.
Financial services and operational resilience
- Bank Negara Malaysia, Risk Management in Technology (RMiT)
- Policy document revised November 2025, effective 28 November 2025. The revision extends board accountability and adds explicit expectations on the governance of emerging technologies.
- Monetary Authority of Singapore, Technology Risk Management Guidelines
- Revised January 2021, with strengthened requirements on board oversight, secure development, emerging technology risk and cyber resilience.
Cloud financial management
Credentials held
- AWS Certified Cloud Practitioner
- Amazon Web Services: verifiable badge record
- AWS Certified AI Practitioner (Early Adopter)
- Amazon Web Services: verifiable badge record
- FinOps Certified Professional
- The Linux Foundation: verifiable badge record
- Certificate of Competence in Zero Trust (CCZT)
- Cloud Security Alliance: badge record to be added
- FinOps Certified Engineer
- FinOps Foundation
- PyTorch and Deep Learning for Decision Makers (LFS116)
- Linux Foundation
- Cybercrime Investigations
- Verification link pending
- BBA (Hons) International Business
- Universiti Teknologi MARA
- Diploma in Banking
- Universiti Teknologi MARA

Institutional standing
AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force
2025 to present. Convened by the Malaysian Technical Standards Forum, the body designated by the Malaysian Communications and Multimedia Commission for communications and multimedia standards. The task force develops Malaysia’s national AI technical standards for that industry. These are voluntary industry codes rather than law: once registered by the commission, compliance with a code is a legal defence, not a legal obligation. A technical code on artificial intelligence cybersecurity architecture requirements is listed by the forum as under development.
Task force announcement, MTSFB
What a technical code is, and why compliance is optional, MTSFB
Partner Advisor, eFounders Fellowship
2018 to 2023. Appointed by Alibaba Group and the United Nations Conference on Trade and Development. Curriculum design for a programme delivered at Alibaba Business School, whose 2018 letter of invitation records him as an advisor of the course.
Participant, UNCTAD Multi-year Expert Meeting on Investment, Innovation and Entrepreneurship
2020. Eighth session, held at the Palais des Nations, Geneva, on 21 September 2020. He appears on the official list of participants, United Nations document TD/B/C.II/MEM.4/INF.8.
International Consultant, International Trade Centre, Geneva
2019. Netherlands Trust Fund programme. The International Trade Centre is the joint agency of the World Trade Organization and the United Nations.
What an engagement looks like
Four stages. Most engagements do not run all of them, and the first exists partly to establish which are needed.
- Framing
- Duration is not fixed. One conversation before any scope is written, to establish what has already moved, what decision is waiting on it, and whether this is the right practice for the question at all.
- Assessment
- Two to four weeks. Establishing what has actually changed, what is now exposed, and what can be measured. Risk engagements open here rather than with an implementation plan, because an implementation plan written before this stage is a guess with a timeline attached.
- Architecture and decision support
- Duration is not fixed. Turning the assessment into something a board or an engineering team can act on: the options, what each will cost beyond the licence, and which parts should be decided rather than delegated.
- Handover
- Duration is not fixed. Implementation and managed service are not undertaken here, so the work ends with material a client’s own team or supplier can execute against, rather than with a dependency on the person who wrote it.
Fees are settled once scope is agreed and are not published here, because the stages above differ too much in scope for any single rate to be honest across all of them.
Not taken on
- Implementation or managed service delivery. Strategy, assessment and architecture only.
- Expert witness or litigation support work.
- Engagements where the conclusion has already been reached and an independent name is wanted for it.
- Introductions sold as a service. Where a relationship is useful to a client it is offered, not invoiced.
What the section above is, and is not.
One caution about this section, because the rest of this page is built on sources a reader can check and this part is not. The stages above are a statement of how the work is done, not a claim that can be verified from outside, and it would be wrong to present the two as the same kind of thing. What can be checked today is the writing the third stage produces: the doctrine documents are published in full, at version, with their sources listed and their unfinished sections declared.
Read the doctrine documents to judge that writing before commissioning any of it.