Skip to content
CISO Spotlights

Career profile

Monte Ratzlaff

Chief Information Security Officer (CISO), University of California

Status
Current role, per sources checked 20 November 2025
Appointed
23 April 2025
Published

Compiled 6 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

Monte Ratzlaff is the Chief Information Security Officer (CISO) of the University of California system, appointed to the permanent role in April 2025. He also serves as the UC Health Data Warehouse CISO at the Office of the President. In the role he reports to Van Williams, Vice President of Information Technology, with a dotted line to Rachael Nava, Executive Vice President and Chief Operating Officer.

Career path

Ratzlaff's path to security ran through IT and firewall work before he moved into the field full time. He held earlier roles in county government, at Blue Shield of California and at Golden 1 Credit Union, gaining information security experience in the banking and health care industries. He joined the University of California in 2010 as the first Chief Security Officer at UC Davis Health, where he managed the IT Security department. In 2016 he moved to the UC Office of the President to help build the systemwide Cyber Risk Program following a major incident at UC. He launched the UC Cyber-risk Coordination Center (C3) in 2015, which provides threat intelligence, monitoring and coordinated response across the system and has since become UC Digital Risk and Security. Ratzlaff served as interim CISO from 2021 to 2022 and again in the interim role beginning in 2023 before his April 2025 appointment to the permanent position. During that interim period he directed campus locations to submit cybersecurity investment plans and progress reports to his office.

Governance, collaboration and public remarks

Ratzlaff oversees UC's security program to protect institutional information and resources from threats such as ransomware and phishing. He has led efforts to mature UC's information security governance, including an overhaul of the systemwide IS-3 policy and modernization of the security contract appendix used with third parties. He founded the UC Tech Applied Intelligence Mentorship program, led the UC Tech Academy's Digital Risk Leadership program, and helped build the annual UC Cybersecurity Summit. In June 2025 he moderated a systemwide faculty panel on Endpoint Detection and Response technology hosted by Van Williams. Speaking at an October 2025 Information Technology Policy and Security Community of Interest fireside chat, Ratzlaff identified zero-day vulnerabilities, phishing targeting privileged accounts and cloud complexity among his ongoing concerns, saying, "It's the things we don't know that worry me." He holds the Certified Information Systems Security Professional (CISSP) and Certified Information Systems Auditor (CISA) credentials.

Sources

  1. 1.
    UC Tech Newsuctechnews.ucop.edu · undated page · checked 6 October 2026 · tier A
  2. 2.
    uctechnews.ucop.eduuctechnews.ucop.edu · undated page · checked 6 October 2026 · tier A
  3. 3.
    UC Tech Newsuctechnews.ucop.edu · published 20 November 2025 · checked 6 October 2026 · tier A
  4. 4.
    security.ucop.edusecurity.ucop.edu · undated page · checked 6 October 2026 · tier A
  5. 5.
    its.ucr.eduits.ucr.edu · undated page · checked 6 October 2026 · tier A
  6. 6.
    UCnetucnet.universityofcalifornia.edu · published 4 June 2025 · checked 6 October 2026 · tier A

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.