As the Chief Information Security and Technology Officer (CISTO) for the University of Tennessee System (www.tennessee.edu), Matt Williams leads cybersecurity strategy and IT governance across all campuses. A 2026 ORBIE Award winner, he’s known for his collaborative, people-first approach and his commitment to building trust and shared responsibility in higher education cybersecurity.
From PC Setup to Army Networks
When Matt got his first PC as a kid, he set it up for his mother, connecting all the components, installing the software, and setting up AOL and email accounts. “That experience really impacted me, and I knew I wanted to work with technology,” he recalls. Matt initially planned to become a computer engineer, but calculus convinced him otherwise. He pivoted to computer animation, unaware that those roles typically required degrees from specialized institutions.
Struggling to find freelance work and needing to pay off his loans, he joined the U.S. Army in a computer and networking role – a field he knew he would enjoy and excel in. “I ended up stationed on Osan Air Force Base in South Korea, on a small compound that we shared with another Army unit. I found that I really enjoyed working on the systems, and I was naturally good at it,” he shares.
From Sergeant to CISO: A Career Forged in Security
Knowing that he’d need a more appropriate degree to leave the Army, Matt’s wife, Kelli, encouraged him to earn a second bachelor’s degree after he earned his Security+ certificate. “Thanks to her encouragement, I earned a BS in Technical Management, a degree better aligned with my interests and career goals,” he says.
Matt’s mentor, Luke Houck, encouraged him to earn some professional certificates, specifically the CompTIA Security+, CompTIA A+, and the Cisco CCNA, to advance his career progression. Armed with the Security+ certification, Matt became the Information Security Assurance Officer for his unit. “It was wild because that position was typically held by an officer, and I was just a Sergeant. I was suddenly responsible for the entire information security program for the unit,” he recalls.
Those experiences solidified his interest in technology and security, but after leaving the military, Matt frequently moved between the two – taking on whatever role was needed to stabilize his teams. “Luckily for me, I landed in a role that combines both of my passions here at UT,” he remarks.
The milestone that most shaped Matt’s path to becoming CISTO was his role as Director of IT Infrastructure Services at the University of Akron. There, he gained visibility into the full technology infrastructure stack – beyond just networks – and learned what it truly meant to architect a secure environment.
At the University of Akron, he worked closely with the CISO and CIO, building relationships that gave him a broader view of IT leadership and deeper engagement with faculty, senior administrators, and the cabinet. He was later promoted to CISO and Associate CIO – a move he credits to the knowledge and trust he earned as Director of IT Infrastructure.
Building Trust to Beat Burnout
Matt credits his ability to integrate demanding responsibilities with personal life and well-being to an early career lesson in how destructive burnout can be. “It affected me professionally and personally, and caused significant strain on all my relationships. I realized that we spend more time at work than we do with our families throughout our lives, and vowed not to let burnout happen again,” he reflects.
He believes that the best path to balance is to build strong teams with great, trustworthy people and services. “Knowing that I can count on my teams and partners to step in for me if needed allows me to not stress over the constant barrage of tasks, risks, and threats. This also gives my teams opportunities to step up and show what they can do,” he shares.
Matt also covers when his subordinate leaders need him to, and he encourages them to build strong teams under them. “Having trusted third-party partners ready to step in if something goes badly is also a stress reducer for me,” he observes.
Collaboration as the Cornerstone of Security
For Matt, success in higher education cybersecurity means building a culture of shared responsibility through partnerships and trust, not mandates. He believes the only way to succeed is to work openly with faculty, researchers, and administrators – sharing risks, threats, and regulatory challenges – so that others are motivated to support and champion security initiatives.
“Higher education is a highly collaborative industry, and working with people collaboratively is the only way to build trust, so when I say we really need to do something, I have everyone’s support to do it. Trying to use directives to drive change with no trust or relationship is a much harder way to get anything done in higher education,” he observes.
Matt’s proudest career moment came in 2026, when he won the Tennessee CISO Large Enterprise ORBIE Award – an honor recognizing strategic vision, management effectiveness, and commitment to service, with finalists and winners selected by an independent peer review process. “Being selected as the winner out of the long list of nominees was completely unexpected, and all the amazing things my team at UT has done is the only reason I was selected,” he says humbly.
Learning Not to Take Decisions Personally
Matt recalls that the toughest challenge early in his leadership career came when he took an organizational decision personally. His team spent months evaluating vendors and building a business case for a network modernization project, only to be told the university would not move forward. He admits he took the rejection personally, and it negatively affected his attitude.
It took several months and guidance from a mentor for Matt to finally overcome his immaturity and see that the decision wasn’t about him at all – the university’s financial situation had shifted during their research, and there simply wasn’t funding to support the effort at that time. “That experience helped me better understand how and why business decisions are made. Now I can coach my own teams about the hows and whys so they can avoid my pitfalls,” he reflects.
Strategy, Consolidation, and Shared Services
In his role as the CISTO for the UT System, Matt is responsible for the cybersecurity strategy, policy, and IT governance, risk, and compliance (GRC) for all of the UT campuses and institutes, as well as owning the overarching technology infrastructure strategy for the UT System Administration office and UT Knoxville.
He looks at the technology and security landscape across the UT System and tries to find areas where they can consolidate technologies and tools, combine contracts with similar vendors to leverage their buying power at scale, and share resources like research computing efficiently.
The campuses own their respective information security programs, but they align with the UT System’s cybersecurity strategy. “We work closely to leverage shared services whenever possible so we aren’t duplicating effort and buying redundant solutions,” Matt explains.
Shaping the Next Generation of Cyber Leaders
Matt notes that working in higher education sets up the University of Tennessee System well to influence the next generation of cybersecurity leaders. They’re partnering with Dell Technologies, the Tickle College of Engineering, and the College of Emerging and Collaborative Studies to establish a student-run security operations center that gives a select group of students real-world, hands-on experience working in a SOC.
This partnership incorporates additional cybersecurity curriculum that Dell is developing with their colleges to provide students with certification training and certification vouchers, Dell executive guest speakers, and interview preparation. “This will allow our students to graduate with not only a degree, but professional certifications, real work experience, and preparation for interviewing and entering the workforce,” he observes.
Matt has also been invited to guest lecture in several courses to share with students what’s involved in establishing a cybersecurity program and leading a large team in a large complex organization. “I get to share what’s going on at the university, how we’re doing it, and most importantly, why we’re doing it. The engagement from the students is always high energy, and I spend more time just having a dialogue with them than I do covering prepared remarks. Several students in each of these classes engage with me via LinkedIn now,” he shares.
Build Relationships, Not Roadblocks
Matt encourages young cybersecurity professionals to build relationships across the organization, approach cybersecurity from a business perspective, and think about cybersecurity controls from a risk-based approach. He emphasizes the critical importance of building relationships, as leaders need allies and sounding boards when making difficult decisions.
“Don’t be a leader who says ‘no’ with no alternatives. Be a leader who says ‘no, but…’ or ‘how about this way instead?’ That’ll help build trust and secure the environment. Building trust is critical to being successful. You’ll find yourself having to make an unpopular decision, and you want people in your corner when that happens,” he advises.
Matt also underscores thinking about security from the business perspective and understanding the impact of strategy on the organizational mission. “We can’t implement every control, every time. There’ll be situations where a control could negatively impact the business, or the control is just too expensive,” he observes.
To evaluate a control, weigh the risks it mitigates against the cost of implementation – whether financial, capital, or political – relative to the value it delivers. “Cybersecurity leaders must make trade-offs. It’s critical to distinguish between what’s negotiable and what’s not. The key question is always: Is this problem worth the cost to fix it? Sometimes the answer is ‘no, but…’ – and that trade-off needs to be acknowledged,” he explains.
Fighting Smarter, Not Harder
Matt notes that the cybersecurity landscape didn’t change much until the recent emergence of AI. The threats are all still the same – bad guys using a vulnerability of some kind to steal, embarrass, or disrupt. The vectors of attack haven’t really changed, and are almost always a misconfiguration, unpatched vulnerability, or compromised account.
Other than AI, the social engineering tactics are the most noticeable change. Besides the old Nigerian Prince phishing messages, the emergence of smishing, vishing, whaling, and the automated use of account credentials and MFA tokens in real time as they’re harvested has caused a lot of heartache and headache.
AI has changed the sophistication of the attacks. Bad guys use AI to craft better messages, create better code to evade detection, and even use AI agents to do the bulk of the breach and lateral movement activities. “AI lets bad guys do it better, faster, smarter, and quieter. Meanwhile, those trying to defend against automated attacks are left with few data options,” he says.
What excites Matt about the future of cybersecurity is the emergence of defensive AI tools that can fight offensive AI, and agentic AI that make real-time decisions on telemetry that indicates malicious behavior. “This would help my team spend more time engineering solutions for the gaps in our operational security program. A strong cybersecurity foundation can stop up to 90% of attacks, but we struggle with implementing and maintaining that foundation. Defensive AI tools will be a game-changer for organizations, and I’m confident that we can do it without losing people,” he insists.
Matt acknowledges that fostering innovation while maintaining strong security is challenging, especially with rapidly evolving technologies. Controls that work today may be obsolete tomorrow. He encourages adopting a risk-based approach – and notes that many cybersecurity teams overlook the risk of stifling innovation. His team enables creativity by setting guardrails around data, not specific technologies, and collaborating with project owners early to work together rather than against them.
Breaking Silos, Building Baselines Together
Matt stresses the importance of collaboration across departments and institutions, particularly for shared security services. UT maintains a strong Security Community of Practice with subject matter experts from each campus to align on strategy, initiatives, and policy revisions.
Before 2024, each campus managed its own slice of its shared Microsoft tenant, leading to fragmented controls, duplicated effort, and frequent service disruptions from uncoordinated changes. That year, they partnered with Dell for a managed SOC and centralized how they operate within the tenant. Now, they implement tools and controls consistently, establishing a common security baseline across the board.
Collaboration is equally critical at UT Knoxville due to its decentralized IT structure, where many departments have their own IT staff outside central IT. Matt notes that working closely with these units helps them understand how new initiatives will affect each department – so they can move forward without sidelining anyone or disrupting faculty, staff, and researchers.
Conclusion
From soldier to CISO, Matt Williams has built a career defined by service, collaboration, and a relentless focus on people. He hopes to leave a legacy as a leader who was fun to work with, empowered people to own and innovate their domains, helped them grow personally and/or professionally, and always left a place or situation better than it was when he arrived. That, for him, is what true leadership in technology and education ultimately means.

