Skip to content
An official website of Bach Ngo Gia
Bach Ngo

Interests

Digital government and data governance

Public services should be easy to use and careful with people's data. I work right where those two meet.

My position

  • People's personal data is held in trust, not mined as a resource. Every public system that collects data should answer three plain questions: what for, for how long, and who can see it.
  • Digital transformation only lasts when governance comes with it. A convenient service portal without control standards (ISO/IEC 27001, Decree 13/2023 on personal-data protection), clear accountability and regular audit will eventually lose public trust.
  • Transparency about incidents matters more than a perfect image. When something goes wrong, say what happened, who was affected and how it was fixed — that is the only way people keep using the service.

What I have done

  • Five years of governance, risk and compliance consulting and auditing at FPT IS (2020–2025): assessing information-security management systems for organisations in financial services and other sectors, and helping them close gaps before certification.
  • Certified ISO/IEC 27001:2022 Lead Auditor (Bureau Veritas, June 2024) — the international standard for information-security management that many Vietnamese agencies and companies adopt.
  • Earlier, hands-on work in a security operations centre (SOC): detection and incident response. It is why, as an auditor, I can tell which controls hold up under pressure and which only look good on paper.
  • Took part in Locked Shields 2025 — the world's largest live-fire cyber-defence exercise (NATO CCDCOE) — on Adelaide University's team, defending a fictional nation's critical infrastructure under sustained attack.
  • Currently an intern at CyberLab, Adelaide University.

What is next

  • Complete the MSc in Cyber Security at Adelaide University (2025–), focusing on data governance and critical-infrastructure protection — learning how another country solves the same problems, to bring back what fits.
  • Write a series for non-specialists: how personal data is protected, what rights people have, and what to ask when a service requests their information.
  • Share anonymised audit experience as practical lessons for organisations going through digital transformation.

Activities