Digital government and data governance
Public services should be easy to use and careful with people's data. I work right where those two meet.
My position
- People's personal data is held in trust, not mined as a resource. Every public system that collects data should answer three plain questions: what for, for how long, and who can see it.
- Digital transformation only lasts when governance comes with it. A convenient service portal without control standards (ISO/IEC 27001, Decree 13/2023 on personal-data protection), clear accountability and regular audit will eventually lose public trust.
- Transparency about incidents matters more than a perfect image. When something goes wrong, say what happened, who was affected and how it was fixed — that is the only way people keep using the service.
What I have done
- Five years of governance, risk and compliance consulting and auditing at FPT IS (2020–2025): assessing information-security management systems for organisations in financial services and other sectors, and helping them close gaps before certification.
- Certified ISO/IEC 27001:2022 Lead Auditor (Bureau Veritas, June 2024) — the international standard for information-security management that many Vietnamese agencies and companies adopt.
- Earlier, hands-on work in a security operations centre (SOC): detection and incident response. It is why, as an auditor, I can tell which controls hold up under pressure and which only look good on paper.
- Took part in Locked Shields 2025 — the world's largest live-fire cyber-defence exercise (NATO CCDCOE) — on Adelaide University's team, defending a fictional nation's critical infrastructure under sustained attack.
- Currently an intern at CyberLab, Adelaide University.
What is next
- Complete the MSc in Cyber Security at Adelaide University (2025–), focusing on data governance and critical-infrastructure protection — learning how another country solves the same problems, to bring back what fits.
- Write a series for non-specialists: how personal data is protected, what rights people have, and what to ask when a service requests their information.
- Share anonymised audit experience as practical lessons for organisations going through digital transformation.