Frameworks and credentials

What this practice works to. Every entry links to its primary source; nothing is asserted that cannot be checked.

Last reviewed 2026-08-08. Links are checked weekly: see the evidence register for what each source returned.

Operational technology and network architecture

ISA/IEC 62443
Zones and conduits; industrial automation and control systems security.
NIST SP 800-82 Revision 3
Guide to operational technology security.
NIST SP 800-207
Zero trust architecture.

Artificial intelligence

ISO/IEC 42001:2023
AI management systems. Certifiable, and increasingly requested in procurement due diligence.
Regulation (EU) 2024/1689, the AI Act
Applies extraterritorially where outputs are used in the Union.

Financial services and operational resilience

Bank Negara Malaysia, Risk Management in Technology (RMiT)
Policy document revised November 2025, effective 28 November 2025. The revision extends board accountability and adds explicit expectations on the governance of emerging technologies.
Monetary Authority of Singapore, Technology Risk Management Guidelines
Revised January 2021, with strengthened requirements on board oversight, secure development, emerging technology risk and cyber resilience.

Cloud financial management

Credentials held

AWS Certified Cloud Practitioner
Amazon Web Services: verifiable badge record
AWS Certified AI Practitioner (Early Adopter)
Amazon Web Services: verifiable badge record
FinOps Certified Professional
The Linux Foundation: verifiable badge record
Certificate of Competence in Zero Trust (CCZT)
Cloud Security Alliance: badge record to be added
FinOps Certified Engineer
FinOps Foundation
Cybercrime Investigations
Verification link pending
BBA (Hons) International Business
Universiti Teknologi MARA
Diploma in Banking
Universiti Teknologi MARA
Mohd Atasha Alias standing in front of a display wall at the AWS Innovation Hub in Singapore, showing AWS Graviton processors and AWS AI chips alongside a screen headed “Deep dive into our AWS tech stack”.
At the AWS Innovation Hub in Singapore, May 2026. A visit, not a qualification: the badge records above are the part that can be verified. AWS describes the hub as a first-of-its-kind facility for Asia Pacific and Japan; it is not the only one of its kind worldwide, and this caption does not say so.

Institutional standing

AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force

2025 to present. Convened by the Malaysian Technical Standards Forum, the body designated by the Malaysian Communications and Multimedia Commission for communications and multimedia standards. The task force develops Malaysia’s national AI technical standards for that industry. These are voluntary industry codes rather than law: once registered by the commission, compliance with a code is a legal defence, not a legal obligation. A technical code on artificial intelligence cybersecurity architecture requirements is listed by the forum as under development.

Task force announcement, MTSFB

What a technical code is, and why compliance is optional, MTSFB

Partner Advisor, eFounders Fellowship

2018 to 2023. Appointed by Alibaba Group and the United Nations Conference on Trade and Development. Curriculum design for a programme delivered at Alibaba Business School, whose 2018 letter of invitation records him as an advisor of the course.

Advisor listing published by Alibaba Group

Participant, UNCTAD Multi-year Expert Meeting on Investment, Innovation and Entrepreneurship

2020. Eighth session, held at the Palais des Nations, Geneva, on 21 September 2020. He appears on the official list of participants, United Nations document TD/B/C.II/MEM.4/INF.8.

List of participants (TD/B/C.II/MEM.4/INF.8), UNCTAD

International Consultant, International Trade Centre, Geneva

2019. Netherlands Trust Fund programme. The International Trade Centre is the joint agency of the World Trade Organization and the United Nations.

International Trade Centre

What an engagement looks like

Four stages. Most engagements do not run all of them, and the first exists partly to establish which are needed.

Framing
Duration is not fixed. One conversation before any scope is written, to establish what has already moved, what decision is waiting on it, and whether this is the right practice for the question at all.
What you receive: A written statement of the question as he understands it, which is often the first time it has been written down in one place. Where the honest answer is that someone else is better placed, that is said rather than worked around.
Assessment
Two to four weeks. Establishing what has actually changed, what is now exposed, and what can be measured. Risk engagements open here rather than with an implementation plan, because an implementation plan written before this stage is a guess with a timeline attached.
What you receive: A written assessment: the findings, the evidence for each one, and an explicit list of what could not be established in the time. That last list is the part most often left out, and it is the part that tells a board how much weight the rest will bear.
Architecture and decision support
Duration is not fixed. Turning the assessment into something a board or an engineering team can act on: the options, what each will cost beyond the licence, and which parts should be decided rather than delegated.
What you receive: Written architecture or a decision paper, in the register the audience actually reads. The doctrine documents on this site are published specimens of that writing, so the standard can be judged before it is commissioned.
Handover
Duration is not fixed. Implementation and managed service are not undertaken here, so the work ends with material a client’s own team or supplier can execute against, rather than with a dependency on the person who wrote it.
What you receive: The documents, the reasoning behind them, and a named list of the assumptions that would have to be revisited if the situation changes. An engagement that cannot say what would falsify its own conclusions has not finished.

Fees are settled once scope is agreed and are not published here, because the stages above differ too much in scope for any single rate to be honest across all of them.

Shape set out 2026-08-09. The assessment duration above is the same figure published on the advisory enquiry page, not a second estimate.

Not taken on

  • Implementation or managed service delivery. Strategy, assessment and architecture only.
  • Expert witness or litigation support work.
  • Engagements where the conclusion has already been reached and an independent name is wanted for it.
  • Introductions sold as a service. Where a relationship is useful to a client it is offered, not invoiced.

What the section above is, and is not.

One caution about this section, because the rest of this page is built on sources a reader can check and this part is not. The stages above are a statement of how the work is done, not a claim that can be verified from outside, and it would be wrong to present the two as the same kind of thing. What can be checked today is the writing the third stage produces: the doctrine documents are published in full, at version, with their sources listed and their unfinished sections declared.

Read the doctrine documents to judge that writing before commissioning any of it.