Subscribe
Security Statements and reactions
Cyber Frontlines: Greg Tkaczyk
Published 22 December 2025
In this edition of Cyber Frontlines, meet Greg Tkaczyk, Executive Consultant & Global CyberDefend CTO - Palo Alto Networks at IBM Security Services. Greg is a member of IBM Consulting’s Cybersecurity Global Center of Competency, specializing in the design, implementation and system integration of micro-segmentation and cloud security technologies. With over 20 years of global consulting experience, he holds credentials including IBM Master Inventor, IBM Certified Consultant Thought Leader, CISSP, CISA and Payment Card Industry Qualified Security Assessor (QSA). Greg proudly wears his Canadian iron ring as a computer engineer and has earned a Master’s degree in Information Security from Royal Holloway, University of London.
Stay up-to-date on Greg’s work on LinkedIn.
What do you do for IBM Security Services (CSS), and how long have you been with the team?
I have been with IBM for over 17 years, and in my current role, I wear three hats. First, I am a technical thought leader and innovator for offering development, working closely with product management, legal and marketing teams to define consulting delivery methods, system integration strategies, and AI-driven assets for emerging technologies. Secondly, I support pursuits as a subject matter expert and lead engagements or provide oversight, particularly for first-of-a-kind delivery. Finally, I deliver and coordinate global sales and practitioner enablement activities for our offerings, maintaining assets, demo environments and intellectual capital. My current focus is on our partnership with Palo Alto Networks and working with technologies such as Cortex Cloud.
What got you into the cybersecurity field?
As a computer engineering undergrad, I was considering a career in hardware design, but got an opportunity to join Compaq for a professional experience year with the information security team. This sparked my interest in cybersecurity, as this was a career I didn’t really know existed. Out of school, my first job was penetration testing (ethical hacking) at Deloitte, and after a successful SQL injection at a bank in the Cayman Islands, I was hooked!
What do you enjoy most about your work on your respective CSS project(s)?
I have been fortunate to deliver on projects around the world, working in at least 18 countries throughout the Americas, EMEA and APAC. I feel that this has given me a unique experience to work with many different clients and within many different cultures. The connections made with clients, colleagues and even locals have truly helped define me professionally and personally.
Now, I enjoy the opportunity to work with new technologies, developing first-of-a-kind approaches and mentoring the next generation of rock-star consultants!
Can you share a benefit of using or integrating generative AI in cybersecurity?
As a client-facing consultant for my entire career, I have seen my fair share of “grunt work”.
Generative AI, when properly used, provides a platform to accelerate our consulting services (assessments, design, implementation) and make our managed services more efficient. I am leaning into leveraging AI assets to make life easier for the consultants on the ground, while delivering value for our clients. Gen AI internal business-value assets and external client-value assets will act as a huge differentiator for us in the market.
Name one cybersecurity resource or person that all security professionals or leaders should follow, and why.
If I had to pick one, I would point to the SANS NewBites newsletter, which provides an excellent summary of the most important cybersecurity news twice a week.
As a bonus, I would suggest @LevelUpCoding, which rolled into my X feed one day. I like how they break down IT (and security!) concepts for things that you may need to know. What are the components of Kubernetes? How does SSH work? Agentic AI Concepts? They got you covered.
Do you have a favorite security conference to attend/follow, and why?
I have fond memories of Defcon (at the Alexis Park) and Blackhat over the years, but for top-notch training, I would point to SANS conferences.
What’s one recommendation you would give to help organizations protect their people, data or infrastructure?
Those who know me will have heard me say this before. I believe that cybersecurity boils down to three things: visibility, consistency and control.
Visibility: You must have visibility into your assets, applications, users and data. Lack of visibility across hybrid and multi-cloud environments creates blind spots that could be leveraged by an attacker. Visibility identifies dependencies, both technical and operational, that can influence your design of security controls. Ultimately, it is impossible to architect security controls if you don’t have a clear understanding of what it is you are trying to protect.
Consistency: Fragmented and inconsistent security controls create complexity, risk and cost. It is key to identify solutions that allow you to implement consistent security across heterogeneous environments: Within data centers and across hybrid and multi-cloud; on bare-metal, virtualized platforms and containerized environments; across various operating systems and hypervisors; and on any underlying network infrastructure.
Control: The controls we implement need to reduce risk while aligning with business timelines and objectives. In security, perfection can be your enemy if it slows you down from “taking risk off the table”. Allow for granular enough policy enforcement so that different parts of the business can mature at different rates. Some parts of the business may want to initially alert, while others may want to actively block or automatically remediate security issues. All improvements are good and a step forward!
What advice do you have for starting a career in cybersecurity?
First and foremost, the combination of technical skills and the ability to speak confidently in front of a client is rare. If you can master this, you will be successful in whatever part of cybersecurity you focus on.
Secondly, details matter. Anything that you put in front of a client needs to be crisp, clear and professional. My mentees know that my pet peeves include inconsistent formatting and slide footers!
Finally, learn to think like an attacker. Undoubtedly, my personal experience of starting with penetration testing and learning how to break applications, networks and systems laid the foundation for the rest of my career. This doesn’t mean that you have to be a pen-tester, but you must understand the threats being defended against!
Within your scope of work on CSS, what security trends are you watching in 2025 and beyond?
Security for AI is just getting started. There are many niche players, and the market is starting to consolidate—just like the early days of CSPM (cloud security posture management), CWP (cloud workload protection) and application security into CNAPPs (Cloud Native Application Protection Platforms). This will be an interesting space to work in!
The other trend on my radar is Policy as Code, especially for the enforcement of security, compliance and architecture requirements. Although this isn’t a brand-new concept, as coding becomes more accessible to everyone through AI agents and assistants, I think we will see innovation in the way that we embed different security stakeholder requirements into infrastructure provisioning.
Meet the rest of the team on the Cyber Frontlines. Up next: Brenden Glynn
Would your team catch the next zero-day in time?
Join security leaders who rely on the Think Newsletter for curated news on AI, cybersecurity, data and automation. Learn fast from expert tutorials and explainers—delivered directly to your inbox twice weekly. See the IBM Privacy Statement.
First name*
Last name*
Business email*
Your subscription will be delivered in English. You will find an unsubscribe link in every newsletter. Refer to our IBM Privacy Statement for more information.
Submit
Webinar On-demand
Achieve continuous compliance in a hybrid data world with IBM Guardium Data Protection
Register for this webinar to learn how AI governance helps organizations manage risk, meet evolving regulations and build trusted, responsible AI at scale.
Register now
More on the Cyber Frontlines
Meet Brenden Glynn
Schedule a discovery session with X-Force®
Resources
NEW
Smarter AI governance and security solutions
Learn how to turn governance and security into drivers of resilience, smarter decision-making and confident growth with practical strategies from this buyer’s guide.
Get the guide
TII report
IBM X-Force Threat Intelligence Index 2026
Gain insights to prepare and respond to cyberattacks with greater speed and effectiveness with the IBM X-Force® Threat Intelligence Index.
Read the report
Cybersecurity guide
Cybersecurity in the era of generative AI
Learn how today’s security landscape is changing and how to navigate the challenges and tap into the resilience of generative AI.
Read the guide
KuppingerCole report
See why KuppingerCole ranks IBM as a leader
The KuppingerCole data security platforms report offers guidance and recommendations to find sensitive data protection and governance products that best meet clients’ needs.
Read the report
TEI report
The total economic impact (TEI) of Guardium Data Protection
Discover the benefits and ROI of IBM Guardium® Data Protection in this Forrester TEI study.
Read the report
On-demand webinars
Guardium® webinars
Learn how to protect your data across its lifecycle from our webinars.
Explore on-demand webinars
Gartner Market Guide
Gartner® Market Guide for AI TRiSM
Access this Gartner guide to learn how to manage the complete AI inventory and secure your AI workloads with guardrails. It also shows how to reduce risk and manage the governance process to achieve AI trust for all AI use cases in your organization.
Read the guide
Security tutorials
Expand your skills with free security tutorials
Follow clear steps to complete tasks and learn how to effectively use technologies in your projects.
Explore tutorials
IAM explainer
What is identity and access management (IAM)?
Identity and access management (IAM) is a cybersecurity discipline that deals with user access and resource permissions.
Read the article
IBM Guardium®
Protect your most critical data—discover, monitor and secure sensitive information across environments while automating compliance and reducing risk.
Explore IBM Guardium
Enterprise security solutions
Transform your security program with solutions from the largest enterprise security provider.
Explore IBM security solutions
Security services
Transform your business and manage risk with cybersecurity consulting, cloud and managed security services.
Explore IBM security services
Take the next step
Automate data protection, threat detection and compliance to secure your enterprise across cloud and on‑premises environments.
Explore IBM Guardium®
Discover IBM security solutions
Products
Consulting services
Industries
Case studies
Financing
Research
LinkedIn
X
Instagram
YouTube
Podcasts
Business partners
Documentation
Events
Newsletters
Support
TechXchange community
Overview
Careers
Investor relations
Leadership
Newsroom
Security, privacy and trust
Contact IBM
Privacy
Terms of use
Accessibility
ibm.com, ibm.org, ibm-zcouncil.com, insights-on-business.com, jazz.net, mobilebusinessinsights.com, promontory.com, proveit.com, ptech.org, s81c.com, securityintelligence.com, skillsbuild.org, softlayer.com, storagecommunity.org, think-exchange.com, thoughtsoncloud.com, alphaevents.webcasts.com, ibm-cloud.github.io, ibmbigdatahub.com, bluemix.net, mybluemix.net, ibm.net, ibmcloud.com, galasa.dev, blueworkslive.com, swiss-quantum.ch, blueworkslive.com, cloudant.com, ibm.ie, ibm.fr, ibm.com.br, ibm.co, ibm.ca, community.watsonanalytics.com, datapower.com, skills.yourlearning.ibm.com, bluewolf.com, carbondesignsystem.com, openliberty.io