Frameworks and credentials
What this practice works to. Every framework and credential entry links to its primary source.
Operational technology and network architecture7 entries
- ISA/IEC 62443
- Zones and conduits; industrial automation and control systems security.
- NIST SP 800-82 Revision 3
- Guide to operational technology security.
- NIST SP 800-207
- Zero trust architecture.
- Adapting Zero Trust Principles to Operational Technology
- Joint guidance, April 2026.
Artificial intelligence6 entries
- ISO/IEC 42001:2023
- AI management systems. Certifiable, and increasingly requested in procurement due diligence.
- Regulation (EU) 2024/1689, the AI Act
- Applies extraterritorially where outputs are used in the Union.
- Artificial Intelligence Systems Cyber Security Framework (AISCF)
- Malaysia, National Cyber Security Agency, launched 9 July 2026. Secures AI data, AI models, and AI infrastructure and applications in layers across a seven-phase lifecycle. Addressed to any organisation that builds, supplies or uses AI systems. He contributed to the taskforce and is acknowledged on page 58. The full document is free to download from NACSA.
- Gartner: over 40 per cent of agentic AI projects will be cancelled by end of 2027
- A forecast rather than a measurement, listed for the three causes it names: escalating cost, unclear business value and inadequate risk controls.
Financial services and operational resilience4 entries
- Bank Negara Malaysia, Risk Management in Technology (RMiT)
- Policy document revised November 2025, effective 28 November 2025. The revision extends board accountability and adds explicit expectations on the governance of emerging technologies.
- Monetary Authority of Singapore, Technology Risk Management Guidelines
- Revised January 2021, with strengthened requirements on board oversight, secure development, emerging technology risk and cyber resilience.
Cloud financial management1 entry
Credentials held
- AWS Certified Cloud Practitioner
- Amazon Web Services: verifiable badge record
- AWS Certified AI Practitioner (Early Adopter)
- Amazon Web Services: verifiable badge record
- FinOps Certified Professional
- The Linux Foundation: verifiable badge record
- FinOps Certified Instructor
- The Linux Foundation: verifiable badge record
- HRD Corp Accredited Trainer
- Human Resource Development Corporation, Malaysia: verifiable trainer record, accredited 25 July 2024 to 25 July 2027
- Certificate of Competence in Zero Trust (CCZT)
- Cloud Security Alliance: badge record to be added
- FinOps Certified Engineer
- FinOps Foundation
- PyTorch and Deep Learning for Decision Makers (LFS116)
- Linux Foundation
- Cybercrime Investigations
- Maltego: subject area published by the vendor, not a record of completion
- BBA (Hons) International Business
- Universiti Teknologi MARA
- Diploma in Banking
- Universiti Teknologi MARA

Institutional standing
AI Security and Resilience subgroup, Artificial Intelligence Standards Task Force
2025 to present. Convened by the Malaysian Technical Standards Forum, the body designated by the Malaysian Communications and Multimedia Commission for communications and multimedia standards. The task force develops Malaysia’s national AI technical standards for that industry. A technical code on artificial intelligence cybersecurity architecture requirements is listed by the forum as under development.
Contributor, Artificial Intelligence Systems Cyber Security Framework (AISCF) Taskforce
2025 to present. Published by the National Cyber Security Agency and launched by the Prime Minister at the National Cyber Security Summit in Putrajaya on 9 July 2026, together with the National Cryptography Policy. The AISCF sets out how to secure an AI system across its whole life, from inception and design through deployment, operation and retirement, and it protects three things in layers: AI data, AI models, and AI infrastructure and applications. It is addressed to any organisation that builds, supplies or uses AI systems, in the public sector or the private one, and it is aligned with the Cyber Security Act 2024. What it offers is a structure for deciding which controls a given AI system warrants.
Download the AISCF from NACSA. Contributors are acknowledged on page 58
Cyber Security Act 2024 (Act 854), Attorney General’s Chambers
Partner Advisor, eFounders Fellowship
2018 to 2023. Appointed by Alibaba Group and the United Nations Conference on Trade and Development. Curriculum design for a programme delivered at Alibaba Business School, whose 2018 letter of invitation records him as an advisor of the course.
Participant, UNCTAD Multi-year Expert Meeting on Investment, Innovation and Entrepreneurship
2020. Eighth session, held at the Palais des Nations, Geneva, on 21 September 2020. He appears on the official list of participants, United Nations document TD/B/C.II/MEM.4/INF.8.
International Consultant, International Trade Centre, Geneva
2019. Netherlands Trust Fund IV, the export sector competitiveness programme run by the International Trade Centre with the Dutch Centre for the Promotion of Imports, which ran from September 2017 to June 2021. The International Trade Centre is the joint agency of the World Trade Organization and the United Nations. The source below establishes the programme, its funder and its dates; it does not name him, because the centre does not publish the names of consultants engaged on a programme of this kind.
Netherlands Trust Fund IV programme, International Trade Centre
What an engagement looks like
Four stages. Most engagements do not run all of them, and the first exists partly to establish which are needed.
- Framing
- Duration is not fixed. One conversation before any scope is written, to establish what has already moved, what decision is waiting on it, and whether this is the right practice for the question at all. Part of that conversation is about the organisation rather than the estate: who would have to concede something for the likely recommendation to proceed, and whether that is currently a safe thing for them to do. A recommendation nobody can act on is a more common outcome than a wrong one.
- Assessment
- Two to four weeks. Establishing what has actually changed, what is now exposed, and what can be measured. Risk engagements open here rather than with an implementation plan, because an implementation plan written before this stage is a guess with a timeline attached.
- Architecture and decision support
- Duration is not fixed. Turning the assessment into something a board or an engineering team can act on: the options, what each will cost beyond the licence, and which parts should be decided rather than delegated.
- Handover
- Duration is not fixed. Implementation and managed service are not undertaken here, so the work ends with material a client’s own team or supplier can execute against, rather than with a dependency on the person who wrote it.
Fees are settled once scope is agreed and are not published here, because the stages above differ too much in scope for any single rate to be honest across all of them.
Not taken on
- Implementation or managed service delivery. Strategy, assessment and architecture only.
- Expert witness or litigation support work.
- Engagements where the conclusion has already been reached and an independent name is wanted for it.
- Introductions sold as a service. Where a relationship is useful to a client it is offered, not invoiced.