# CISO-CIO Convergence: Why Enterprise Security and Technology Leadership Are Merging at the Top


Carl Froggett's career trajectory mirrors a quiet but significant shift in how organizations approach cybersecurity and technology governance. After nearly two decades as Chief Information Security Officer at Citigroup—one of the world's largest financial institutions—Froggett has taken on a dual role as both CISO and CIO at Deep Instinct, a cybersecurity-focused technology company. His move raises a critical question: is the traditional separation between security and IT leadership becoming obsolete?


## The Case for Convergence


The argument for combining CISO and CIO roles is straightforward: the two positions pursue identical outcomes through different lenses. Both executives exist to support the business. The CIO owns technology strategy, infrastructure, and digital transformation. The CISO owns risk management, compliance, and security posture. Neither can succeed without the other.


"Both CISO and CIO ultimately do the same thing," Froggett explains. "They both support the business. The CIO is responsible for the technology strategy—the software, the infrastructure, the cloud strategy—while the CISO is responsible for ensuring it is secured."


In practical terms, this means a CIO without security awareness will build systems that create risk. A CISO without technology authority will struggle to enforce controls that business leaders view as obstacles to innovation. Separated, these roles can drift into friction—CIOs pushing for speed and capability; CISOs demanding caution and compliance. Combined, that tension collapses into a single decision-maker who must balance both imperatives simultaneously.


## Scale Matters More Than Philosophy


However, Froggett is candid about the critical constraint: this model only works at specific organizational scales. Citigroup employs over 200,000 people across hundreds of business units, thousands of applications, and geographic complexity. Deep Instinct operates with fewer than 200 employees, a single product focus, and tighter operational cohesion.


"Combining CISO and CIO would be too much for one person at Citi, but works well at Deep Instinct," he notes.


At enterprise scale, the CISO and CIO roles already demand more than 40 hours per week of focused attention. A 200,000-person organization generates security incidents, compliance audits, and technology incidents simultaneously and continuously. Asking one person to direct both functions would create an impossible backlog and increase organizational risk. Mid-market and smaller organizations, by contrast, often lack the budget to hire separate executives—and the reduced complexity of smaller IT estates makes a combined role operationally feasible.


The implication is important: role consolidation is not a universal best practice. It's a pragmatic adjustment to organizational maturity and size.


## The Impartiality Trap


Combining roles solves one problem but creates another: loss of independent perspective. A separate CIO and CISO naturally challenge each other's recommendations. That friction, while occasionally frustrating, drives better decisions because both viewpoints are represented in final choices.


When one person holds both titles, that built-in check disappears. Froggett acknowledges this explicitly: "What you lose, and I'm very aware of this every time I make a decision, is the impartiality and alternative view."


His mitigation strategy is deliberately structural. He has cultivated a culture where IT team members are expected—and psychologically safe—to challenge his decisions. "The culture is: 'if you need to, speak up,'" he says. "The main issue with combining the roles is you can get tunnel vision if you don't have the alternative view; and that can lead to bad decisions."


This requires exceptional leadership discipline. A CISO-CIO who surrounds themselves with yes-men or lacks the humility to invite dissent will make worse decisions than separate CISOs and CIOs who naturally challenge each other. The role combination amplifies both the quality of leadership and the risks of poor leadership.


## From Networks to Security: A Career Arc


Froggett's path into this position reflects the broader professionalization of cybersecurity. He holds a BSc in Computer Science from Loughborough University and began work as a contract engineer before joining Salomon Brothers in 2004 as a network engineer. When Salomon merged into Citigroup in 1998, he transitioned from pure infrastructure roles into security.


The timing was not coincidental. The early 2000s marked the moment when corporate communication shifted from physical infrastructure to internet-connected systems, and that shift created an entirely new category of risk. "Because of my experience in a wide range of technologies, I was asked if I could look at the security and exposure of these new communication technologies," Froggett recalls. He pivoted from IT engineering into security and has spent more than 20 years in the field.


His trajectory highlights an important industry reality: many senior security leaders came through infrastructure and engineering first. That grounding in how systems actually work—not just theoretical security frameworks—remains a distinguishing characteristic of effective CISOs. Froggett's CIO background is not a liability; it's foundational to his credibility in both roles.


## The Business Reality: Zero Risk Is Unworkable


A recurring theme in Froggett's perspective is pragmatism about risk. "There is no such thing as zero risk unless you want to turn everything off and go home," he states flatly.


This is not a dismissal of security. Rather, it reflects a mature understanding that security exists to enable business, not replace it. Every control has friction. Every delay imposed by security review is opportunity cost. The CISO's job is not to minimize risk to zero—it's to keep risk within acceptable bounds while allowing the business to function and compete.


Organizations that separate CISOs from CIOs sometimes develop imbalanced risk tolerance. CISOs may over-index on security at the expense of speed; CIOs may under-estimate emerging threats in pursuit of innovation velocity. A combined executive must make explicit trade-offs rather than having each function operate with conflicting incentives.


## HackWire Analysis


The consolidation of CISO and CIO roles reflects a maturing understanding of how security and technology are inseparable in the modern enterprise. Froggett's move to Deep Instinct arrives at a pivotal moment: as organizations grapple with AI-driven threats, rapid cloud adoption, and the need for security to be embedded in architecture rather than bolted on afterward, the notion that security and technology can operate as separate functions becomes increasingly untenable.


However, this trend carries a subtle risk. The CISO role exists partly because history shows that placing security authority under technology leaders weakens it. IT leaders, measured on uptime and feature delivery, will consistently optimize for speed over caution. The CISO as an independent function creates essential friction—a voice that says "not yet" or "not that way." Losing that voice through role consolidation requires exceptional leadership character and organizational culture to replace.


The real lesson is not that all organizations should combine these roles, but that they should stop pretending the roles are entirely separate. Security must be embedded into technology strategy from inception, not layered on afterward. Whether that happens through combined leadership or through exceptionally strong collaboration between separate CISOs and CIOs is less important than ensuring technology and security leaders have equal standing, aligned incentives, and mutual accountability.


The risk is consolidation without cultural maturity—creating a CISO-CIO role where the CIO title dominates and security becomes subordinate once again. For organizations that pursue this path, Froggett's emphasis on psychological safety, dissent culture, and deliberate perspective-seeking becomes not a nice-to-have, but essential infrastructure.


— HackWire Editorial


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)