One Executive, Two Hats: Carl Froggett on Running Security and IT at Deep Instinct
The former Citi CISO talks about what happens when security leadership and infrastructure ownership collapse into a single role.

Carl Froggett holds both the CISO and CIO titles at Deep Instinct simultaneously. That combination is still uncommon enough to warrant attention. Most organizations keep those functions separate, often deliberately, to preserve a check-and-balance between the team building systems and the team responsible for defending them.
Froggett spent nearly 17 years as CISO at Citi before moving to Deep Instinct. That's a long tenure by any measure, and Citi is not a small operational environment. Financial sector threat surface. Regulatory scrutiny. Nation-state interest in the sector is well-documented — groups tracked by CrowdStrike as LABYRINTH CHOLLIMA and by Mandiant as APT38 have historically targeted financial institutions for both espionage and destructive capability. Whether Froggett's tenure intersected with any of those campaigns is not public.
What is notable is the institutional knowledge someone accumulates running security for a major bank across 17 years. The threat model shifts. The adversary matures. Tooling cycles through generations. Most CISOs don't stay long enough to watch a full cycle complete.
The dual-role structure at Deep Instinct raises questions worth sitting with. Merging CISO and CIO functions concentrates accountability. That can accelerate decisions — fewer handoffs between security requirements and infrastructure execution. It can also create blind spots. The person approving a technical architecture is now also the person auditing its risk posture. That tension doesn't disappear just because one person holds both titles.
Deep Instinct is an AI-native security vendor. Its core product uses deep learning for threat prevention, which means Froggett is simultaneously a practitioner and a customer of the technology his company sells. That's an unusual feedback loop — and potentially a valuable one for product direction.
The broader trend here is worth tracking. Security and IT leadership structures are shifting at a number of organizations, particularly at smaller, faster-moving companies where headcount constraints make consolidated roles more common. Whether that model scales or introduces governance risk depends heavily on the individual and the board's appetite for that concentration of authority.
Froggett's background suggests the former. His institutional depth is hard to dismiss.



