Singapore-based practice led by Sid Thirumalai. Thirty years inside tier-1 banks, regulators, and complex multi-market delivery environments where the margin for ambiguity is zero.

30+
Years at the intersection of regulated technology delivery and governance
250+
Enterprise applications remediated in a single global obsolescence programme under MAS mandate
CISSP CCSP PMP CRISC CISA
Markets Singapore UK US China India
Sid Thirumalai, Programme Director and Founder of ThriveStep Pte. Ltd.
Sid Thirumalai
Distressed Programme Recovery
& Regulated Transformation
Credentials & Community
CISSP · CCSP · PMP · CRISC · CISA
Certified information security, cloud security, programme management, IT risk, and information systems audit professional
ISC2 Singapore Chapter
Events Director, Executive Committee
ISACA Singapore
SheLeadsTech Ambassador · Cyber Wellness Facilitator for secondary schools
Samaritans of Singapore
Crisis prevention facilitation: upstream awareness and early warning identification
Singapore Computer Society
Tech for Good programme contributor
AITP (NTUC-accredited)
Qualified to deliver Singapore government-funded ICT training under SkillsFuture

A practitioner who has been
inside the room when it matters.

01 The Positioning

Thirty years working at the intersection of regulated technology delivery and governance across Singapore, the UK, the US, China, and India. Not as a detached advisor. As the person responsible for making complex programmes land under regulatory scrutiny, across markets where the margin for ambiguity is zero.

Regulators like MAS and HKMA have been part of the landscape throughout. Not obstacles to manage around, but stakeholders to satisfy while protecting commercial agility. That is a different skill from programme management in unconstrained environments, and it is where ThriveStep operates.

30+
Years in regulated technology transformation
5
Markets: SG, UK, US, China, India
250+
Enterprise applications remediated under MAS mandate
4
Complex programmes recovered: 3 tier-1 banks, 1 SaaS MVNO
02 The Track Record

Large-scale technology transformations under MAS mandate. Global obsolescence remediation across 250+ enterprise applications. SaaS platform recoveries for commercial technology businesses serving LATAM markets. Digital banking programme turnarounds for international tier-1 banks. Wealth management platform recoveries. Telecom deployments rescued from commercial penalty.

The pattern across all of them: teams that knew the programme was in trouble but did not feel safe saying so early enough. Recovery work is never purely technical. It is always a governance and human factors problem wearing a technology mask.

03 Current Work

Beyond active client engagements, this practice invests in building governance frameworks that address gaps the large consultancies have not yet formalised.

HFGR Framework v0.4

The Human Factors Gate Review (HFGR) Framework maps cognitive risk assessment gates to existing compliance checkpoints in MAS TRM, NIST SP 800-61r3, and ISO 27035. It addresses the governance gap that every major regulatory framework for technology risk and incident response leaves: mandating human oversight of systems without governing the readiness of the teams executing it. The framework is shared selectively with risk leaders navigating this in their organisations. Connect directly to request a copy.

Human Firewall Series

A three-post LinkedIn series making the governance case for human cognitive risk management in regulated cybersecurity environments, grounded in peer-reviewed research, Singapore-specific regulatory data, and thirty years of practitioner observation at the sharp end of both programme failure and human crisis.

He took over a project with serious problems, when approximately 68% of scheduled time and budget had been consumed. Working closely with the client, he led the team to resolve the issues, regain client confidence, and deliver on time and above expectations, receiving a rating above 4 out of 5 from the client.

John Wilt Direct manager, 2007. The earliest of over two decades of documented programme recoveries.
Read all 17 LinkedIn recommendations

Where strategy
meets execution.

Every engagement is context-led. We do not offer one-size-fits-all advice. We conduct in-depth discovery before proposing a path forward.

"Helped Virtusa in turning around many projects that were in the Red. People with his kind of technical, functional and managerial skills are rare to find."

Rukmini M Director, Research, Sutherland Global Services, 2009

"Always willing to go the extra mile to deliver products against tight deadlines, both for client project work and regulatory deadlines."

Peter Francis FinTech Executive, 2011
Regulated Environments

Regulated Technology Transformation

Technology transformation under regulatory mandate (MAS, HKMA, FCA) where the stakes are too high for ambiguity and the margin for governance failure is zero. Embedded advisory across complex, multi-market delivery environments.

MAS TRM FSM-N05 HKMA NIST SP 800-53 GDPR
Governance

PMO Optimisation

Transforming project offices from administrative layers into strategic enablers. Portfolio prioritisation, governance design, reporting from delivery team to boardroom, and capability building, calibrated to your maturity, culture, and delivery complexity.

CMMi SAFe 6 OPM3 ITIL DORA
Training

Professional Training

AITP (NTUC-accredited) delivery of ICT and project management training for Singapore's technology sector. Methodology fluency, practical field insights, and career enrichment across PMBOK, PRINCE2, Agile, and SAFe, integrated with real-world regulatory and cross-cultural delivery experience.

PMBOK PRINCE2 Agile / SAFe SkillsFuture
Emerging Practice

Human Risk Intelligence Advisory

A structured governance methodology for assessing and managing human cognitive risk at the decision points where it intersects with existing security and delivery controls. Mapped to MAS TRM, NIST SP 800-61r3, and ISO 27035. Designed to overlay on governance structures organisations already have.

MAS TRM 2021 FSM-N05 NIST 800-61r3 ISO 27035

Four programmes.
Four different kinds
of hard.

Client identities are protected. The delivery details are real. All engagements were carried out by Sid Thirumalai in prior roles before founding ThriveStep.

Banking West Africa + 8 markets

African Digital Banking Programme

Programme Recovery Greenfield Transformation

A leading international bank's first fully digital banking programme: a greenfield transformation with no internal precedent. Six months into delivery, the programme was six months behind schedule. Scope had drifted, the digital channels team was misaligned, and stakeholder confidence was eroding.

Banking India

Wealth Management Platform

Programme Recovery RBI-Regulated Delivery

A major bank sought to introduce a fully new mutual funds offering for the Indian market, governed under Reserve Bank of India regulation, built on a completely modern technology stack, integrated within the existing mobile banking application. The programme was six months behind its target and had become siloed: product owners, development, production support, and operations working in parallel without genuine alignment.

Telecommunications Latin America

LATAM Telecommunications Platform

Distressed Recovery Full Platform Implementation

A full telecommunications platform implementation was in serious difficulty. Contractual penalties running into millions in lost revenue exposure were activating as the launch window approached and delivery was still not on track. The programme was highly visible, under intense commercial pressure, and the delivery team was stretched across scope, timeline, and stakeholder expectations simultaneously.

Technology / Banking / Government China

China Delivery Organisation

Capability Building Delivery Leadership Multi-sector

A technology services firm needed to establish a fully operational delivery organisation in China from zero: no team, no processes, no office, no pipeline. The brief was to build a functioning capability capable of executing high-stakes client programmes in a market requiring local recruitment, local language capability, and deep understanding of enterprise technology delivery within Chinese institutional and regulatory contexts.

Human Factors
Gate Review
Framework

HFGR v0.4 · June 2026 · Working Document

Every major regulatory framework governing technology risk and incident response mandates human oversight of systems. None of them govern the cognitive readiness of the teams executing that oversight.

The HFGR Framework addresses that governance gap directly. It maps human factors assessment gates to existing compliance checkpoints in MAS TRM, NIST SP 800-61r3, and ISO 27035. It is designed to overlay on governance structures organisations already have, not be built from scratch.

The Governance Gap
MAS Notice FSM-N05 Binding · May 2024

Requires banks to notify MAS within one hour of discovering a relevant incident. Executed by a senior management team under extreme time pressure, on incomplete information, while simultaneously activating containment, communications, and legal.

Silent on team readiness
NIST SP 800-61r3 CSF 2.0 · April 2025

Notes that adverse event volumes are "quite high" and that technical filtering reduces datasets to a subset suitable for human review. The human review layer is explicitly identified as a concentration point for analytical load.

Identifies the load. Does not govern it.
MAS TRM Guidelines 2021 Best Practice · In Force

Section 3.5 expects that FIs ensure personnel have the requisite competence to perform IT functions and manage technology risks. Silent on the conditions under which competence can actually be exercised under operational pressure.

Competence expected. Readiness ungoverned.
Three Domains. Fourteen Gates.
Incident Response
5 gates

Mapped to NIST SP 800-61r3 CSF 2.0 and MAS Notice FSM-N05. Gate IR-3 covers the FSM-N05 one-hour notification window: the highest-consequence human cognitive risk point in the framework.

NIST SP 800-61r3 · FSM-N05 · ISO 27035
Technology Risk Governance
5 gates

Mapped to MAS TRM 2021 best practice sections covering board oversight, SOC operations, cyber assessment, IT project management, and personnel competency. Distinguishes between binding Notices and best practice Guidelines throughout.

MAS TRM 2021 · FSM-N05
Programme Delivery
5 gates

Mapped to MAS TRM 2021 Section 5 and PMI Pulse of the Profession 2025. Gate PD-4 specifically addresses recovery under compounded cognitive load: the most frequently encountered pattern in distressed programme work.

MAS TRM 2021 S.5 · PMI Pulse 2025
Assessment Instruments
NASA-TLX
Six-dimension cognitive load assessment. Under 5 minutes to administer. Validated across aviation, military, and medical settings.
MBI-GS
Maslach Burnout Inventory, General Survey. Team-level aggregate scoring only. No individual attribution.
Edmondson PSS
Seven-item validated psychological safety survey. Predicts early escalation behaviour and error-catching capacity in teams.

The framework is a working document in active development. It is shared selectively with risk leaders, CISOs, and programme directors who are navigating this in their organisations. It is not publicly distributed.

If you are working through the governance gap between regulatory human oversight mandates and the cognitive readiness of the teams executing them, connect directly.

Request the framework

Shared via direct message after a brief conversation.

The right conversation
starts with
the right fit.

ThriveStep engagements are selective. Before any conversation about scope or timing, the right question is whether the problem you are facing matches what this practice is built to address.

Your programme is in difficulty

Schedule slipping, stakeholder confidence eroding, scope unclear. You need someone who has been in that room and knows how to recover it without further damage to team or client relationships.

You are navigating a regulated transformation

Technology delivery under MAS, HKMA, or equivalent mandate, where the margin for governance failure is zero and regulators are stakeholders to satisfy, not obstacles to manage.

You want to review the HFGR Framework

You are a risk leader, CISO, or programme director navigating the governance gap between regulatory human oversight mandates and the cognitive readiness of the teams executing them.

Sid Thirumalai
Founder, ThriveStep Pte. Ltd.
Email
contact@thrivestep.com.sg
LinkedIn
linkedin.com/in/siddharthtv
Book a call
cal.eu/thrivestep
Registered address
ThriveStep Pte. Ltd.
68 Circular Road, #02-01
Singapore 049422
Responses within one business day. All enquiries are treated in confidence.
CISSP CCSP PMP CRISC CISA