Frameworks and credentials

What this practice works to. Every framework and credential entry links to its primary source.

Last reviewed 2026-08-13. Links are checked weekly: see the evidence register for what each source returned.

Operational technology and network architecture7 entries
ISA/IEC 62443
Zones and conduits; industrial automation and control systems security.
NIST SP 800-82 Revision 3
Guide to operational technology security.
NIST SP 800-207
Zero trust architecture.
Artificial intelligence6 entries
ISO/IEC 42001:2023
AI management systems. Certifiable, and increasingly requested in procurement due diligence.
Regulation (EU) 2024/1689, the AI Act
Applies extraterritorially where outputs are used in the Union.
Artificial Intelligence Systems Cyber Security Framework (AISCF)
Malaysia, National Cyber Security Agency, launched 9 July 2026. Secures AI data, AI models, and AI infrastructure and applications in layers across a seven-phase lifecycle. Addressed to any organisation that builds, supplies or uses AI systems. He contributed to the taskforce and is acknowledged on page 58. The full document is free to download from NACSA.
Gartner: over 40 per cent of agentic AI projects will be cancelled by end of 2027
A forecast rather than a measurement, listed for the three causes it names: escalating cost, unclear business value and inadequate risk controls.
Financial services and operational resilience4 entries
Bank Negara Malaysia, Risk Management in Technology (RMiT)
Policy document revised November 2025, effective 28 November 2025. The revision extends board accountability and adds explicit expectations on the governance of emerging technologies.
Monetary Authority of Singapore, Technology Risk Management Guidelines
Revised January 2021, with strengthened requirements on board oversight, secure development, emerging technology risk and cyber resilience.
Cloud financial management1 entry

Credentials held

AWS Certified Cloud Practitioner
Amazon Web Services: verifiable badge record
AWS Certified AI Practitioner (Early Adopter)
Amazon Web Services: verifiable badge record
FinOps Certified Professional
The Linux Foundation: verifiable badge record
FinOps Certified Instructor
The Linux Foundation: verifiable badge record
HRD Corp Accredited Trainer
Human Resource Development Corporation, Malaysia: verifiable trainer record, accredited 25 July 2024 to 25 July 2027
Certificate of Competence in Zero Trust (CCZT)
Cloud Security Alliance: badge record to be added
FinOps Certified Engineer
FinOps Foundation
Cybercrime Investigations
Maltego: subject area published by the vendor, not a record of completion
BBA (Hons) International Business
Universiti Teknologi MARA
Diploma in Banking
Universiti Teknologi MARA
Mohd Atasha Alias standing in front of a display wall at the AWS Innovation Hub in Singapore, showing AWS Graviton processors and AWS AI chips alongside a screen headed “Deep dive into our AWS tech stack”.
At the AWS Innovation Hub in Singapore, May 2026. A visit, not a qualification: the badge records above are the part that can be verified. AWS describes the hub as a first-of-its-kind facility for Asia Pacific and Japan.

Institutional standing

AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force

2025 to present. Convened by the Malaysian Technical Standards Forum, the body designated by the Malaysian Communications and Multimedia Commission for communications and multimedia standards. The task force develops Malaysia’s national AI technical standards for that industry. A technical code on artificial intelligence cybersecurity architecture requirements is listed by the forum as under development.

Task force announcement, MTSFB

What a technical code is, MTSFB

Contributor, Artificial Intelligence Systems Cyber Security Framework (AISCF) Taskforce

2025 to present. Published by the National Cyber Security Agency and launched by the Prime Minister at the National Cyber Security Summit in Putrajaya on 9 July 2026, together with the National Cryptography Policy. The AISCF sets out how to secure an AI system across its whole life, from inception and design through deployment, operation and retirement, and it protects three things in layers: AI data, AI models, and AI infrastructure and applications. It is addressed to any organisation that builds, supplies or uses AI systems, in the public sector or the private one, and it is aligned with the Cyber Security Act 2024. What it offers is a structure for deciding which controls a given AI system warrants.

Download the AISCF from NACSA. Contributors are acknowledged on page 58

Cyber Security Act 2024 (Act 854), Attorney General’s Chambers

Partner Advisor, eFounders Fellowship

2018 to 2023. Appointed by Alibaba Group and the United Nations Conference on Trade and Development. Curriculum design for a programme delivered at Alibaba Business School, whose 2018 letter of invitation records him as an advisor of the course.

Advisor listing published by Alibaba Group

Participant, UNCTAD Multi-year Expert Meeting on Investment, Innovation and Entrepreneurship

2020. Eighth session, held at the Palais des Nations, Geneva, on 21 September 2020. He appears on the official list of participants, United Nations document TD/B/C.II/MEM.4/INF.8.

List of participants (TD/B/C.II/MEM.4/INF.8), UNCTAD

International Consultant, International Trade Centre, Geneva

2019. Netherlands Trust Fund IV, the export sector competitiveness programme run by the International Trade Centre with the Dutch Centre for the Promotion of Imports, which ran from September 2017 to June 2021. The International Trade Centre is the joint agency of the World Trade Organization and the United Nations. The source below establishes the programme, its funder and its dates; it does not name him, because the centre does not publish the names of consultants engaged on a programme of this kind.

Netherlands Trust Fund IV programme, International Trade Centre

What an engagement looks like

Four stages. Most engagements do not run all of them, and the first exists partly to establish which are needed.

Framing
Duration is not fixed. One conversation before any scope is written, to establish what has already moved, what decision is waiting on it, and whether this is the right practice for the question at all. Part of that conversation is about the organisation rather than the estate: who would have to concede something for the likely recommendation to proceed, and whether that is currently a safe thing for them to do. A recommendation nobody can act on is a more common outcome than a wrong one.
What you receive: A written statement of the question as he understands it, which is often the first time it has been written down in one place. Where the honest answer is that someone else is better placed, that is said rather than worked around.
Assessment
Two to four weeks. Establishing what has actually changed, what is now exposed, and what can be measured. Risk engagements open here rather than with an implementation plan, because an implementation plan written before this stage is a guess with a timeline attached.
What you receive: A written assessment: the findings, the evidence for each one, and an explicit list of what could not be established in the time. That last list is the part most often left out, and it is the part that tells a board how much weight the rest will bear. Where an assessment returns a suspiciously short list of problems, that is reported as a finding about reporting rather than as a clean result.
Architecture and decision support
Duration is not fixed. Turning the assessment into something a board or an engineering team can act on: the options, what each will cost beyond the licence, and which parts should be decided rather than delegated.
What you receive: Written architecture or a decision paper, in the register the audience actually reads. The doctrine documents on this site are published specimens of that writing, so the standard can be judged before it is commissioned.
Handover
Duration is not fixed. Implementation and managed service are not undertaken here, so the work ends with material a client’s own team or supplier can execute against, rather than with a dependency on the person who wrote it.
What you receive: The documents, the reasoning behind them, and a named list of the assumptions that would have to be revisited if the situation changes. An engagement that cannot say what would falsify its own conclusions has not finished.

Fees are settled once scope is agreed and are not published here, because the stages above differ too much in scope for any single rate to be honest across all of them.

Shape set out 2026-08-09. The assessment duration above is the same figure published on the advisory enquiry page, not a second estimate.

Not taken on

  • Implementation or managed service delivery. Strategy, assessment and architecture only.
  • Expert witness or litigation support work.
  • Engagements where the conclusion has already been reached and an independent name is wanted for it.
  • Introductions sold as a service. Where a relationship is useful to a client it is offered, not invoiced.