/
사이버 복원력

5 Cybersecurity Leadership Lessons from Former Citi CISO Carl Froggett’s 30+ Year Career

A headshot of Carl Froggett, CISO at Deep Instinct
Carl Froggett, former CISO at Citi and current CISO at Deep Instinct

Some episodes of The Segment hit closer to home than others. This one is personal.

More than 21 years ago, Carl Froggett interviewed me for a job on the 10th floor of Citigroup in London. I doubt either of us imagined that two decades later, we’d be sitting on opposite sides of the microphone, reflecting on his remarkable career.

Carl was at Citi for nearly 25 years, and today, he’s the Chief Information Officer at Deep Instinct, the first company to apply end-to-end deep learning to cybersecurity. His journey from pulling cables under data center floors to leading global infrastructure defense at Citi and now driving AI innovation is a masterclass in reinvention.  

Every chapter of Carl’s journey shows how listening, learning, and leading through change can transform a career and an entire organization’s mindset.

Here are five takeaways from his incredible career that stood out to me from our discussion on the recent episode of The Segment podcast.

1. Cybersecurity should power the business, not block it

Carl’s early days in tech were far from glamorous.

After graduating from Loughborough University where he captained the university’s pool team, he landed his first major job at investment bank Salomon Brothers.  

“I remember being in a suit and tie, crawling under data center floors, pulling cables,” he said. “I thought, ‘I did a computer science degree for this?’”

But those early career experiences shaped his approach when cybersecurity was still viewed as an inconvenience.  

He said that when he first started in cyber, his team didn’t hardly have a budget because it was seen as a necessary evil: “Security existed because auditors required it,” he said.

That mindset forced him to communicate in business terms. He connected with business leaders on the fact that banks take risks every day.  

“Cybersecurity has to support that risk model, not obstruct it,” he explained. “You can’t rely on scare tactics. You have to bring clarity. If you don’t, you might lose your ability to trade.”

It’s a lesson that still holds true for CISOs today: cybersecurity must enable business, not block it.

I remember being in a suit and tie, crawling under data center floors, pulling cables. I thought, "I did a computer science degree for this?"

2. Cybersecurity innovation starts with listening

From introducing CheckPoint firewalls to evaluating Palo Alto Networks in its early days, Carl’s track record of spotting transformative technology wasn’t about chasing hype. He simply wanted to solve security problems that mattered.

He recalled how a vendor’s original pitch didn’t resonate until he reframed it for the operations team: fewer false positives meant greater efficiency.

“They didn’t care about the specs,” Carl said. “They cared about what it solved for them.”

That insight guided his work at Deep Instinct, where he realized traders valued reliability as much as protection. “Low latency was the differentiator,” he said. “It wasn’t about zero-day protection. It was about performance you could trust.”

That mindset became Carl’s superpower — translating technical innovation into real-world value. By listening first, he uncovered what people actually needed, not just what technology could do.  

It’s a reminder that true innovation doesn’t always start with invention but with empathy.

3. A strong company culture is the ultimate enabler

Carl credits much of his growth to the culture built at Citi.  

“If you were honest and prepared, failure was okay as long as you had a plan,” he said. That culture of failing fast let people take smart risks, learn quickly, and move with agility.

It also fostered cross-functional collaboration across what could have been silos.  

“We didn’t all report into the same line, but we were aligned,” he said. “We agreed on the right problems to solve, and we solved them together.”

That sense of trust and shared purpose became the foundation of Citi’s security success. The best ideas came from anywhere in the organization, not just management.

“Our job as leaders was to listen and clear the path.”

4. The AI era demands cyber reinvention

Carl’s move to Deep Instinct came from a conviction that traditional approaches were no longer enough.

He said that generative AI has changed everything. Today, nation-state-level threats can be created in seconds by anyone with a subscription.

Carl and his team often demonstrate this in live sessions, using publicly available large language models (LLMs) that can generate ransomware on demand.  

“We’re in a new era,” he said. “Everything is unique now. Machine learning can’t keep up.”

Deep Instinct’s deep learning model, trained once or twice a year, represents what Carl calls a “fundamental reset.”

“Machine learning constantly retrains on what it’s already seen,” he said. “But deep learning understands what’s never been seen before.”

It’s that shift from reactive to predictive that Carl believes will define the next generation of cybersecurity.

We’re in a new era. Everything is unique now. Machine learning can’t keep up.

5. Leading means learning to let go

Carl’s most personal lesson came from having to step back and be less hands-on as he took on more leadership-focused roles in his career.

“It was hard,” he admitted. “I loved being hands-on. But I had to shift my mindset from delivering firewalls to delivering services.”

The transition from doing to enabling allowed him to scale his influence and align his team’s work with the broader business. For Carl, leadership is never about control. “It’s about creating space for others to succeed,” he said.  

What Carl’s career teaches us about cybersecurity leadership

What stands out about Carl’s story isn’t luck or timing. He’s always been ahead of the curve because he listens before he leads.

From crawling under trading floors to pioneering AI-driven security, his career has been one long lesson in solving the problems that actually matter.

That’s what makes his perspective urgent now. The world Carl predicted — where anyone can weaponize AI to launch sophisticated attacks — is already here. The old tools can’t keep up.

The path forward is clear: listen first, move fast, and tie every security decision to real business impact.

Cybersecurity will keep evolving, but Carl’s story proves that true leaders don’t just keep pace but set it.

Listen to the full episode of The Segment: A Zero Trust Leadership Podcast on Apple 팟캐스트, Spotify또는 당사 웹사이트.

관련 주제

관련 문서

보안 태세를 강화하는 방법
사이버 복원력

보안 태세를 강화하는 방법

조직은 제로 트러스트 보안 전략을 빠르게 채택하여 이미 침해된 것처럼 운영하고 악의적인 공격자가 네트워크 전체에 확산되는 것을 억제하는 조치를 취하고 있습니다.

사이버 회복탄력성의 기준은 무엇인가요?
사이버 복원력

사이버 회복탄력성의 기준은 무엇인가요?

마이크로세그멘테이션에 기반한 제로 트러스트 전략이 사이버 사고 발생 시와 그 이후에 조직의 복원력을 강화하는 방법을 알아보세요.

의료 서비스 랜섬웨어 복원력을 위한 4가지 필수 요소
사이버 복원력

의료 서비스 랜섬웨어 복원력을 위한 4가지 필수 요소

제로 트러스트 세분화를 통해 의료 기관에서 랜섬웨어의 확산을 차단하는 방법에 대해 Illumio와 AWS 보안 전문가에게 알아보세요.

스포캔 교사 신용 조합의 5명으로 구성된 보안 팀이 제로 트러스트에서 큰 성공을 거둔 방법
사이버 복원력

스포캔 교사 신용 조합의 5명으로 구성된 보안 팀이 제로 트러스트에서 큰 성공을 거둔 방법

스포캔 교사 신용 조합의 린 5인 팀이 현명한 전략, 팀워크, 리더십의 동의를 통해 제로 트러스트 성공을 달성한 방법을 알아보세요.

미래 매핑 사이버 보안 가시성이 가장 큰 장점인 이유
사이버 복원력

미래 매핑 사이버 보안 가시성이 가장 큰 장점인 이유

클라우드 보안, AI 위험 및 시스템 위협을 마스터하기 위해 CISO가 지도 제작자처럼 생각해야 하는 이유를 알아보세요.

제로 트러스트가 성장했습니다. 창립자들이 말하는 다음 단계는 다음과 같습니다.
세분화

제로 트러스트가 성장했습니다. 창립자들이 말하는 다음 단계는 다음과 같습니다.

보안 그래프, 공격자의 사고방식, 스마트한 우선순위 지정이 제로 트러스트의 성공을 위한 핵심 요소인 이유를 알아보세요.

위반 가정.
영향 최소화.
복원력 향상.

제로 트러스트 세분화에 대해 자세히 알아볼 준비가 되셨나요?