Goutama Bachtiar is the IT Advisory Director for Grant Thornton Indonesia, a UK-incorporated professional services firm. With a decade of experience at the company, he delivers a wide range of IT consulting, audit, and review services across the nation. His expertise covers IT GRC (governance, risk, and compliance), cybersecurity, data privacy, digital forensics, and business continuity management.
Follow The Ortus Club on LinkedIn to keep up-to-date on our conversations with today’s top IT leaders.
Here’s a glimpse of what you’ll learn:
- Why the most critical skill for modern IT leaders is shifting from insight to foresight, focusing on anticipating future trends and preparing the organisation for what’s next, rather than just reacting to the present.
- How the misalignment between business and IT objectives is the biggest mistake organisations make, leading to underinvestment in innovation, and why aligning these strategies is crucial for success.
- The importance of building systems that people can trust ethically and socially, not just technically, and why this question should be at the forefront of every IT leader’s mind in the age of Generative AI.
Could you please share your personal journey and how you got into the IT field?
My journey into IT was something of a blessing in disguise. I originally studied economics at university, with the dream of becoming a financial analyst. However, the 1998 Asian crisis prompted a significant career shift. I decided to pivot and enrolled in the Cisco Networking Academy programme here in Indonesia.
After graduating, I began my career as a system engineer and IT corporate trainer. From there, my path evolved through various roles, including networking consultant, software developer, network engineer, business analyst, and project manager. I later served as a country channel service delivery manager at Hewlett-Packard Indonesia before moving to a corporate angel investor firm, where I acted as an advisor sourcing deals and performing IT due diligence.
For the last ten years, I have been with Grant Thornton. Throughout my career, I’ve had the privilege of advising hundreds of organisations, including Fortune 500 companies across banking, fintech, and manufacturing. My path has been a fusion of development, governance, and leadership, all underpinned by a strong belief in ethical technology deployment.
What emerging technologies and innovation opportunities should businesses in the IT industry explore?
I believe AI, GRC (governance, risk, and compliance), and the secure-by-design approach—particularly the shift-left paradigm—are at the forefront. Digital identity solutions and technologies are also crucial. These are the key areas businesses should explore to gain maximum benefits.
Aside from that, there are significant opportunities in blockchain-based compliance mechanisms, quantum-resilient cryptography, and privacy-enhancing technologies. These are particularly relevant for financial services and other data-driven sectors.
In your experience, what is the biggest mistake companies make, and what practical steps can they take to avoid it?
The biggest mistake is the misalignment between business goals and IT objectives. This disconnect prevents business units from seeing the true value and benefits of IT investment. This often leads to underinvestment in innovation, IT infrastructure, talent development, and cybersecurity.
To avoid this, organisations must align their IT strategy with their overall business strategy. It is essential to integrate risk management into every stage of the digital journey to ensure technology serves the business’s core mission.
How do you envision the IT sector evolving in the next three to five years?
I believe we are going to witness a powerful convergence between AI, cybersecurity, and compliance at scale. The rise of autonomous systems, AI agents, and Retrieval-Augmented Generation (RAG) will push IT leaders to rethink their approach to oversight.
Regulations will inevitably catch up with technological innovation, and organisations will need integrated GRC-AI capabilities to keep pace. Furthermore, tech ethics and sustainability will move from niche concerns to becoming critical board-level conversations.
With the regulatory environment constantly changing, how should IT leaders navigate these shifts?
IT leaders should adopt what I call an agile compliance model, as conventional methods are no longer sufficient. This involves building a cross-functional task force that includes legal and risk counterparts.
This task force should actively accommodate the latest standards and frameworks, such as the NIST AI Risk Management Framework (RMF) and ISO 42001, along with global and regional privacy regulations. This proactive approach allows them to shape their governance structures effectively rather than just reacting to new rules.
What is the most critical skill that IT leaders should have today?
IT leaders need to shift their paradigm from insight to foresight. We already know about hindsight (looking back) and insight (understanding the present). It is now time for foresight, which combines both forward-looking and forward-thinking capabilities. While many leaders focus on the here and now, the most effective ones will be those who can anticipate future trends and prepare their organisations accordingly.
If there is one question IT leaders should be asking themselves today, what would it be?
The question is: “Are we building systems that people can trust, not just from a technical standpoint, but also ethically and socially?”
With the rise of Generative AI, this has become more important than ever. When organisations develop or use AI models, they must consider the ethical implications. The systems they build must be ethical, safe, responsible, accountable, and transparent. Trust is the ultimate currency.
How do you approach mentoring and developing the next generation of IT leaders within your team?
Within my team, I emphasise three core components: exposure, empowerment, and empathy.
I create opportunities for my team members to get involved in diverse projects to nurture their leadership skills and pair them with senior colleagues for guidance. Critically, I foster a psychologically safe environment that encourages curiosity and removes the fear of judgment. Leadership isn’t about authority; it’s about responsibility and influence. We must be responsible for our teams and influence them to become the leaders of tomorrow.
Reflecting on your experiences, what has been the most memorable insight or key takeaway that you have applied to your work?
A speaker at an event once said, “The absence of failure is not success; it’s often a sign of risk avoidance.“
This resonated deeply with me and reshaped how I assess resilience and agility in IT governance. It encouraged me to support implementations that involve well-planned and well-managed risks and controls. We can’t succeed if we’re too afraid to fail. Sometimes, avoiding risk holds us back from our greatest potential.
For someone attending a roundtable or masterclass, what advice would you give them to get the most value out of the experience?
Come with curiosity, not just a business card. The most valuable takeaways come from listening with intent, not just hearing.
Secondly, share authentically and without a hidden agenda. Finally, follow up when necessary. Treat the event as a learning circle, not a transaction. Be genuine when you meet new people. If a professional or business relationship develops, that’s great. If not, you can still build a friendship or at least a valuable connection. My principle is that if we cannot be business partners, at least we can be friends or, at the very least, someone we know.



