Your work spans investment, innovation strategy and cybersecurity across Asia. What convinced you that investment, innovation strategy, and cybersecurity across Asia should be treated as parts of the same strategic challenge rather than as separate disciplines?
My conviction came from working at the point where these disciplines repeatedly collide. I have reviewed more than 2,500 technology ventures, helped raise over US$40 million, advised companies entering Asian markets, and worked directly with cybersecurity firms, enterprises, investors, and public-sector stakeholders. Across those experiences, I kept seeing the same pattern. A company could possess excellent technology but fail to become investable because its governance, commercial model, or security posture was weak. Another company could be well funded but incapable of converting capital into defensible innovation. A third could grow quickly and then discover that one cyber incident had destroyed the trust on which its valuation and market access depended.
Investment determines which technologies receive the time and resources to scale. Innovation strategy determines whether those resources produce a relevant and differentiated business. Cybersecurity determines whether customers, regulators, partners, and investors can trust that business at scale. These are not adjacent concerns. They form one chain of value creation and risk. In digital industries, cybersecurity is not merely a protective function added after innovation. It is part of product quality, enterprise resilience, customer confidence, due diligence, and ultimately valuation.
This is especially true in Asia, where market entry is shaped by national regulation, industrial policy, local relationships, data sovereignty, procurement structures, and geopolitical considerations. The same product may face entirely different expectations in Japan, South Korea, Singapore, Indonesia, or Thailand. Capital without local strategy is easily wasted. Innovation without institutional understanding is difficult to commercialise. Cybersecurity without business context becomes a technical exercise that boards and customers struggle to value.
I therefore see the strategic challenge as one of alignment. Capital, technology, market access, governance, and security must reinforce one another. When they are separated, companies create hidden weaknesses. When they are integrated, innovation becomes more investable, more trusted, and more capable of crossing borders.
“Capital decides what can scale, innovation decides what deserves to scale, and cybersecurity decides whether it can be trusted at scale.”
Through Pygmalion Global, you support technology ventures seeking capital and international growth. What separates a company that is technically impressive from one that is genuinely ready to scale across borders?
Technical excellence is necessary, but it is only the beginning. A technically impressive company has built something difficult. A cross-border-ready company has built a repeatable system around that technology. It can explain the value clearly, deploy it reliably, support it locally, price it intelligently, satisfy procurement requirements, and allow customers and partners to use it without depending on the founder for every important conversation.
I usually test readiness through practical questions. Can a local salesperson explain the product in three minutes to a non-technical executive? Can a partner demonstrate it correctly without the engineering team present? Are the documentation, licensing, service levels, deployment options, and integration requirements clear? Does the company understand where its product fits within the customer’s existing architecture and budget? Can it produce credible references, respond to legal and security reviews, and support the customer after the contract is signed? If the answer to these questions is no, the company may have an invention, but it does not yet have an exportable business.
Cross-border scale also requires strategic humility. Too many firms assume that success in their home market proves that the same positioning, pricing, sales cycle, and channel structure will work elsewhere. It rarely does. Japan may demand extensive documentation and long internal consensus building. Southeast Asian markets may require stronger local relationships, flexible commercial models, and persistent on-the-ground engagement. Singapore may provide regional credibility, but it is not a substitute for localisation in other countries.
The decisive factor is whether the leadership team is willing to adapt without diluting the core value of the technology. Genuine scale comes from disciplined localisation, strong partner economics, operational consistency, and the ability to learn from each market. Technology opens the door. Organisational readiness determines whether the company can walk through it repeatedly.
“A product becomes scalable only when its value can be sold, delivered, supported, and trusted without constant intervention from headquarters.”
At NPCore, you contribute to international growth in the fields of APT and ransomware defence. When entering a new market, which matters most for a cybersecurity company: technical performance, local trust, or institutional partnerships, and why?
All three are essential, but local trust is usually the decisive factor once a product has met the minimum threshold of technical credibility. Cybersecurity differs from many other technology categories because the customer is not simply buying functionality. The customer may be granting access to sensitive systems, accepting a degree of operational dependency, and relying on the vendor during moments of crisis. A technically superior product can still fail if the buyer does not trust the company, its people, its support model, or its long-term commitment to the market.
Technical performance gets a company considered. Local trust allows it to survive scrutiny. Institutional partnerships allow that trust to scale. The sequence matters. Without performance, trust eventually collapses. Without trust, performance may never be tested. Without credible local institutions and partners, even a trusted vendor may remain confined to a small number of isolated opportunities.
In practice, trust is built through consistent local presence, transparent communication, realistic claims, credible references, and partners who understand both the technology and the customer environment. A local partner should not be treated merely as a commission-based reseller whose only role is to open doors. In cybersecurity, the partner often becomes part of the assurance model. Customers may depend on that partner for integration, incident response, training, regulatory interpretation, and executive communication.
I have been fortunate to work with more than ten cybersecurity companies, including NPCore in South Korea, P.O.TECH in Cyprus, and swIDch in the United Kingdom. Supporting their international growth has reinforced this view. Although these companies operate in different areas of cybersecurity, their expansion across Asian markets depends on the same fundamentals. Strong technology creates initial interest, but sustainable progress requires local partners who can communicate its value accurately, support customers after deployment, navigate institutional expectations, and demonstrate that the vendor is committed to the market beyond a single transaction.
Institutional relationships are particularly important in markets where government agencies, major conglomerates, regulated industries, and national cybersecurity bodies influence procurement standards and buying decisions. However, such relationships cannot compensate for an immature product or poor execution. My view is not that one factor replaces the others. Technical performance is the foundation, local trust is the decision mechanism, and institutional partnerships are the force multiplier.
“In cybersecurity, customers do not buy a tool alone. They buy confidence in who will stand beside them when the tool is tested by a real attack.”
Your work has taken you across more than 60 countries. What common assumption about Asian cybersecurity markets do foreign companies most often get wrong?
The most common mistake is treating Asia as a single market. It is a geographic label, not a unified commercial environment. The regulatory systems, procurement practices, risk perceptions, language requirements, channel structures, and decision-making cultures of Japan, South Korea, Singapore, Malaysia, Indonesia, Thailand, Vietnam, and the Philippines are materially different. A regional strategy built around one presentation, one price list, and one distributor model is usually a sign that the company has not yet understood the region.
A second mistake is assuming that visible cyber risk automatically creates an immediate budget. Foreign companies often arrive with strong threat statistics and expect customers to respond with urgency. But demand, budget, and procurement authority are three different things. A customer may recognise the risk but still lack a budget cycle, executive sponsor, approved architecture, or trusted implementation partner. This is why patient market development matters more than repeated demonstrations.
Companies also misunderstand the role of relationships. In many Asian markets, relationships are not a substitute for competence, nor are they an informal shortcut around procurement. They are part of the operating infrastructure of trust. Customers want evidence that the vendor will remain committed after the pilot, respond during an incident, adapt to local requirements, and protect the reputation of everyone involved. That confidence takes time to build.
Finally, foreign vendors often overestimate the value of global prestige and underestimate the importance of localisation. A strong international brand may secure the first meeting, but it will not answer questions about local-language reporting, data handling, integration, support, regulation, or customer references. The correct approach is country by country. A regional vision is useful, but execution must be local.
“Asia is not one market with many languages. It is many markets with different institutions, incentives, and definitions of trust.”
You have argued that cybersecurity has evolved from a specialist concern into a core business strategy. What must a board understand about cyber risk that cannot simply be delegated to its technical teams?
A board must understand that cyber risk is a question of enterprise survival, not merely system security. Technical teams can assess vulnerabilities, configure controls, monitor networks, and respond to incidents. They cannot determine the organisation’s risk appetite, decide which operations must continue under attack, approve major resilience investments, or balance cyber exposure against commercial ambition. Those are governance decisions and therefore board responsibilities.
The board must also understand that internal monitoring is only one part of cyber defence. An organisation may maintain strong internal controls and still be exposed through compromised suppliers, personal devices, infostealer malware, credential reuse, former employees, cloud platforms, contractors, or breaches that occurred years earlier. Once credentials, internal documents, customer records, source code, or operational information appear on dark web marketplaces or criminal Telegram channels, even in small quantities, they can become raw material for a much larger attack.
Old data should not automatically be treated as harmless data. A password from an earlier breach may still work on another system. An outdated employee directory may help attackers identify executives and administrators. A small collection of internal documents may reveal naming conventions, suppliers, technologies, email formats, and approval processes. Criminal groups can combine fragments from different breaches with publicly available information, social engineering, artificial intelligence, and newly discovered vulnerabilities. What appears to be an isolated leak can therefore become part of the foundation for ransomware, business email compromise, identity theft, supply chain intrusion, or a targeted attack against senior management.
This is why boards should expect visibility beyond the corporate network. They should ask whether the organisation is monitoring leaked credentials, impersonation, exposed infrastructure, fraudulent domains, criminal discussions, third-party breaches, and signs that company data is being traded or reused. External threat monitoring should not be treated as an optional intelligence function. It should inform identity controls, incident response, executive protection, supplier management, fraud prevention, and strategic risk decisions.
The board should know which assets and business processes are truly critical, how long the organisation can operate without them, and what would happen if the integrity of its data, identities, or decision systems could no longer be trusted. It should understand concentration risk in cloud services, suppliers, software platforms, and outsourced providers. It should also know whether backups can actually be restored, whether crisis authority is clear, and whether the company can communicate credibly with regulators, customers, employees, investors, and the public during a major incident.
Boards often ask whether the company is secure. That is the wrong question because no serious organisation can guarantee complete security. Better questions are whether the company can identify external warning signs, detect abnormal activity early, contain damage, operate in a degraded state, recover from a trusted baseline, and make difficult decisions quickly. The board should regularly test these questions through realistic exercises involving not only the CISO but also finance, legal, communications, operations, human resources, and business leadership.
Cyber risk cannot be delegated because accountability cannot be delegated. A major incident can affect revenue, safety, regulatory standing, M&A value, customer confidence, and executive credibility at the same time. The board does not need to manage firewalls, but it must understand that threats can develop both inside and outside the organisation. It must govern the consequences of failure and ensure that resilience is funded before a crisis makes the cost unavoidable.
“The board owns the business consequences of a cyber incident, including the risks developing beyond the organisation’s own network, even when the technical work is delegated.”
You have written about the role organisational culture plays in cybersecurity defence. Which management decision can most effectively turn cybersecurity from a compliance exercise into an everyday organisational practice?
The most effective management decision is to make every business leader accountable for the security of the processes, data, people, technology, and suppliers under their control, while giving employees clear authority to escalate and act quickly when a threat appears. As long as cybersecurity is measured only through the CISO’s budget, annual training completion, policy documents, or audit results, the rest of the organisation will continue to treat it as somebody else’s responsibility. Culture changes when operational ownership and decision-making authority change.
This is particularly important because cyber criminals and malicious hackers operate under a fundamentally different model from the organisations they attack. They are often aggressive innovators. They experiment constantly, exchange tools and techniques, automate their operations, learn from failed attacks, and change tactics without waiting for committee approval. They do not need to consult legal teams, procurement departments, executive boards, regulators, or multiple management layers before trying a new method.
Defenders, by contrast, work inside legitimate organisations that require governance, accountability, documentation, budget controls, legal review, and operational stability. These procedures are understandable and often necessary. However, excessive bureaucracy can become a serious security weakness when suspicious activity must pass through several reporting lines, approval committees, and departmental boundaries before anyone is authorised to act. An attacker may need only minutes to exploit a credential or move laterally, while the defending organisation may take hours or days to decide whether an incident is serious enough to contain.
Management must therefore design security governance for speed as well as control. Employees should know exactly where to report suspicious activity. Security teams should have preapproved authority to isolate devices, suspend accounts, block malicious infrastructure, preserve evidence, and initiate crisis procedures when defined thresholds are met. Business leaders should understand in advance which services may be temporarily interrupted to prevent a much larger loss. Rapid action should not depend on locating one senior executive during the first critical minutes of an attack.
Accountability should also be built into management scorecards and normal business reviews. A sales leader should be accountable for how customer data is collected, shared, and stored. A procurement leader should be accountable for supplier access and third-party exposure. A product leader should be accountable for secure design and remediation timelines. An operations leader should be accountable for recovery exercises and continuity procedures. Human resources should be accountable for access changes when employees join, change roles, or leave. The security team should provide expertise, challenge, intelligence, and oversight, but it should not be expected to carry responsibility for business decisions made elsewhere.
Management must also create an environment in which people report mistakes and suspicious activity immediately. Employees should not fear automatic punishment for admitting that they clicked a malicious link, shared information with the wrong recipient, or approved a suspicious request, provided they report it quickly and honestly. Concealment, deliberate policy violations, and repeated negligence should have consequences, but rapid reporting should be recognised as a contribution to organisational resilience. This is a management decision, not a technical control.
The objective is to make secure behaviour part of how work is designed, approved, measured, and corrected. Security should be present in product development, procurement, supplier onboarding, access decisions, performance reviews, executive meetings, and operational exercises. It should also include realistic scenarios in which normal approval channels are unavailable or too slow. Organisations need to practise making difficult decisions under pressure before an actual attacker forces them to do so.
Cybersecurity becomes an everyday organisational practice when managers accept that compliance proves only that procedures exist. It does not prove that the organisation can respond at the speed of an attacker. The strongest culture combines accountability, early reporting, decentralised awareness, and clearly defined authority for rapid action.
“Attackers innovate without permission. Defenders must preserve governance without allowing bureaucracy to become an attack surface.”
“Cybersecurity becomes cultural when responsibility follows operational authority instead of remaining concentrated in the security department.”
In your analysis of Europe’s automotive competition with China, you argue that innovation matters more than regulation. What does the European automotive industry need to change first if it wants to compete more effectively with Chinese manufacturers?
The first change must be the industry’s operating model, not simply its tariff strategy or product mix. Europe has often used regulation to protect consumers, industries, and strategic interests, and some protection may be justified when competition is distorted. But regulation can only create time. It cannot create competitive vehicles, faster software development, lower costs, stronger battery ecosystems, or better digital experiences. If Europe uses regulation to slow external competition without using that time to accelerate internal innovation, it will protect existing structures while falling further behind the main direction of the industry.
Chinese manufacturers are not competing only through cheaper electric vehicles. The strongest companies combine batteries, power electronics, software, data, advanced driver assistance, rapid product iteration, supply-chain control, and disciplined manufacturing economics. They often develop around a software-defined vehicle architecture rather than treating software as an additional feature attached to a traditional mechanical platform. This allows them to learn from customers faster, update products more frequently, and reduce development cycles.
European manufacturers therefore need to move beyond the narrow debate over internal combustion engines, hybrids, and battery-electric vehicles. Powertrain remains important, but the larger competition concerns the digital intelligence layer of the vehicle. Europe needs stronger in-house software and AI capability, more centralised electronic architectures, shorter decision cycles, deeper cooperation across batteries and semiconductors, and management systems that give engineering teams greater speed and accountability.
Europe should not copy China blindly. It has strengths in safety, engineering, premium brands, industrial quality, and regulation. But it must understand the scale and direction of the change. Strategic regulation should be paired with aggressive investment, experimentation, infrastructure, and industrial renewal. Otherwise, protection becomes a defensive pause rather than a competitive strategy.
“Regulation can buy Europe time, but only innovation, speed, and a new industrial operating model can convert that time into competitiveness.”
Your work places you at the intersection of technology, investment and institutional strategy. Looking towards 2030, which dimension of cyber resilience do governments and businesses still underestimate most?
The most underestimated dimension is the ability to continue operating and rebuild when digital trust itself has been compromised. Most organisations still concentrate on preventing intrusion and detecting malicious activity. Those capabilities remain essential, but by 2030 the more difficult problem will be determining what can still be trusted after an attack has moved across identity systems, cloud platforms, software supply chains, operational technology, AI services, and third-party providers.
An organisation may possess backups and still be unable to recover if privileged identities are compromised, software images are contaminated, configuration data is unreliable, or the same attacker remains inside the recovery environment. Governments may have sectoral response plans and still struggle when telecommunications, energy, finance, transport, health care, and public administration are disrupted at the same time through shared digital dependencies.
Resilience therefore requires more than redundant infrastructure. It requires known-good recovery environments, independent identity restoration, immutable and tested backups, manual operating procedures, segmented communications, trusted hardware and software baselines, and clear authority for making decisions under uncertainty. It also requires an honest map of dependency chains. Many organisations know their direct suppliers but not the cloud, software, data, and identity services on which those suppliers depend.
The strategic question for 2030 is not simply whether an attack can be stopped. It is whether essential functions can continue in a degraded state and whether institutions can restore trusted operations without amplifying the damage. Governments and boards should treat recovery coordination, cross-sector dependency, and trusted reconstruction as core national and corporate capabilities. Attackers are increasingly targeting the systems that organisations rely on to verify reality. Resilience must therefore include the capacity to re-establish trust, not merely restore machines.
“The defining resilience challenge of 2030 will be restoring trusted operations after identities, software, data, and dependencies have all become suspect.”

