One Executive, Two Hats: Carl Froggett on Running Security and IT at Deep Instinct
The former Citi CISO talks about what happens when security leadership and infrastructure ownership collapse into a single role.

Key points
- Carl Froggett holds both the CISO and CIO titles simultaneously at Deep Instinct.
- He spent nearly 17 years as CISO at Citi before joining the company.
- The combined role concentrates accountability in ways that can speed decisions but also compress the check between building systems and auditing their risk.
- Deep Instinct's core product uses deep learning for threat prevention, making Froggett both practitioner and customer of the technology his company sells.
- Whether the model scales depends on the individual and the board's appetite for that concentration of authority.
Does combining CISO and CIO actually work?
Most organizations keep those functions separate, often deliberately. The logic is a check-and-balance: the team building systems and the team defending them stay at arm's length. Froggett's arrangement collapses that distance into one job.
Merging the roles concentrates accountability. Fewer handoffs between security requirements and infrastructure execution can accelerate decisions. It can also create blind spots. The person approving a technical architecture is now the same person auditing its risk posture. That tension doesn't disappear because one person holds both titles.
Should you worry about the governance risk?
At scale, that compression is harder to justify. At a vendor like Deep Instinct, where headcount is smaller and speed matters, the tradeoff looks different. Froggett's nearly 17 years at Citi, a large financial institution with a broad threat surface and sustained regulatory scrutiny, represents institutional depth that's genuinely hard to dismiss. Most CISOs don't stay long enough to watch a full adversary cycle complete.
Our June coverage of executive-level targeting is a reminder of what that threat surface actually looks like for senior leaders at financial firms: patient, quiet, and routed through consumer infrastructure.
Deep Instinct's product relies on deep learning, a form of AI, for threat prevention. That puts Froggett in an unusual feedback loop: he's a practitioner stress-testing the same technology his company is selling. That could be genuinely valuable for product direction, or it could be a conflict worth watching.
What to watch next
The consolidated CISO-CIO model is appearing at other smaller, faster-moving companies where headcount constraints push toward combined roles. Whether it produces better security outcomes or just faster ones is the real question. Governance risk in this structure doesn't announce itself. It accumulates.
Froggett's background is the strongest argument for why this particular arrangement might hold. His institutional depth is the thing most people trying to replicate this model won't have.



