From breaking systems to understanding how they fail
I studied Physics at the National University of Singapore as a Kent Ridge Scholar before moving into cybersecurity. My first professional lens on security was offensive: identify vulnerabilities, think like an attacker and explain how systems could be made more resilient.
Over time, that question moved upstream. Instead of asking only how a deployed system could be broken, I became increasingly interested in how teams could identify failure modes during design. That led my work into threat modeling, security architecture, cyber risk and, later, cyber policy.
That progression still shapes how I work today: connect attacker thinking with system design, and connect technical findings with decisions that engineers, defenders and leaders can act on.