About Ideally Us

Twenty years on the attacker’s side of the table. Now on yours.

Ideally Us is a boutique advisory firm founded in Hong Kong in December 2024. We help security, engineering and marketing leaders get ready for post‑quantum cryptography and AI agents, and we do not sell software. This is who you will be working with.

I spent seven years at Mandiant, the last of them inside Google after the acquisition, leading offensive security services across Asia Pacific and Japan. My teams broke into banks, insurers, governments and Fortune 500 companies on purpose, with the same tools and tradecraft as the attackers those organisations were worried about, so their people could see the attack land before it was real.

Before that I was a principal consultant at NTT, ran application security across seven Asian markets for AXA, designed the security of mobile payment systems at Gemalto in France, and spent my first years writing vulnerability signatures and doing research at Qualys, Trend Micro and Deloitte. That is twenty years of watching how organisations get breached, and what separates the ones that recover from the ones that do not.

I started Ideally Us because the two changes coming at my clients, post‑quantum cryptography and AI agents, are being sold to them by people with a product to move. Both deserve advice from someone who has run the attack, bought the tools, and has nothing to sell you except the answer.

Why me

I have run the attack you are worried about.

Ransomware, credential theft, supply chain, the quiet long‑term compromise. I have simulated all of them against real environments and watched what worked. Every recommendation I make has been tested against an adversary’s playbook, because for most of my career I was the adversary.

I have sat on every side of the vendor table.

I built detection at Qualys and Trend Micro, consulted at Deloitte, NTT and Mandiant, and bought security for AXA. I know how products are priced, how they demo and where the gaps are. Ideally Us sells no software, so when I tell you what to buy, that is all it is.

I lead people as well as projects.

A decade managing teams across Asia, plus training as a certified coach and psychological safety practitioner. Migrations and agent programmes fail on people long before they fail on technology. I know how to leave a team owning the outcome after we are gone.

I explain hard things to boards.

My work has been covered by Reuters, Forbes and SC Magazine, and I have spent years turning technical findings into decisions executives can make. You get one document your board can read and your engineers can act on.

The team

Ideally Us is not a one‑person shop. I work with a team of senior consultants across security, AI engineering and marketing, each with their own decade or more in the field, and more are joining soon. The people you meet on the first call are the people who do the work. There is no hand‑off to a junior bench after the contract is signed.

Book a 30‑minute call.

Tell us where you are. We will tell you honestly whether we can help, what it would take, and what we would do first. No pitch, no pressure.