
From Check-the-Box to Continuous Assurance: TrustCloud’s Vision for AI-Powered GRC and TPRM
August 19, 2026From Flying by Instinct to a Modern Cybersecurity Flight Deck: Trellix’s Vision for Public-Sector Resilience

Imagine boarding an airplane and watching the pilot cover the altitude gauges, radar and navigation screens. Then the pilot tells you not to worry—after 20 years of flying, instinct is good enough.
Would you stay on the plane?
That was the scenario Christie Karrels, Public Sector Technical Director at Trellix, posed to attendees at the FRC Erie Summit on July 29, 2026. Watch the full session here. And it set up the central premise of her presentation: too many organizations are still operating cybersecurity programs as though they can safely “fly by instinct.”

As Christie explained, security teams often have plenty of instruments. The problem is that the instruments may not communicate with one another, the people monitoring them are stretched thin, and the threat environment is moving faster than humans can reasonably process.
For state and local government and education organizations, that challenge is particularly acute. Small teams may be responsible for aging infrastructure, numerous disconnected security tools, expanding mandates and mission-critical services—all within budgets that aren’t necessarily growing to match the responsibility. Christie’s question for public-sector leaders was therefore less about adding another security product and more about this: How do you build a cybersecurity flight deck you can actually trust?
Borrowing the Flight Plan from the Federal Government
Christie brought a valuable perspective to the discussion: years of experience working across defense, intelligence, federal civilian, state and local government organizations. Rather than asking resource-constrained public-sector organizations to invent an entirely new cybersecurity model, she suggested learning from lessons already developed in high-threat federal environments.
Her Federal Flight Deck boils those lessons down to five principles:
- Protect the cargo. Data—not the traditional network perimeter—is the mission. Whether the organization is a government agency, school system or healthcare organization, the most important question is ultimately how well it protects its most strategic information assets.
- Turn on the radar. Visibility is foundational. Endpoint, network, cloud, identity, operational technology and other sources of telemetry become more valuable when organizations can understand them together.
- Verify the pilot. Identity is the new perimeter. Organizations need to continuously understand who—or what—is requesting access and whether that access makes sense.
- Consolidate the dashboard. Public-sector organizations rarely have the luxury of ripping out their existing investments and starting again. Christie emphasized meeting organizations where they are and making better use of the security technologies they already own. And finally: use the autopilot. Automation is no longer a luxury. There is simply too much information moving too quickly for security teams to handle every repetitive task manuallyTraditional GRC and TPRM processes can make that difficult.
- And finally: use the autopilot. Automation is no longer a luxury. There is simply too much information moving too quickly for security teams to handle every repetitive task manually.

The Resilience Gap: When Attackers Move at Machine Speed
The need for that final principle—automation—becomes clearer in the second half of Christie’s presentation.
She describes a growing “Resilience Gap” between the speed and volume of modern threats and the capacity of human security teams. Attackers are increasingly using automation and AI to scale their activity, while defenders are still constrained by the number of alerts an analyst can realistically investigate during a shift.
Hiring more people alone can’t close that gap. There aren’t enough experienced cybersecurity professionals available, and public-sector organizations cannot simply double staff every time threat volume increases.
Christie takes that argument a step further with an important distinction: the answer isn’t merely giving analysts an AI chatbot that helps them work a little faster. The larger opportunity is automating more of the cognitive work of an investigation itself.
That is where Trellix WISE enters the story.

From More Alerts to Better Answers
Christie described Trellix WISE as an agentic AI approach designed to help security teams investigate at machine speed while preserving human oversight.
Rather than requiring an analyst to manually move between disconnected systems and assemble context, WISE is designed to draw information from across the security ecosystem—endpoint, network, identity, email, SIEM and other sources—to develop a more complete picture of an alert.
That multi-vendor approach is particularly relevant to FRC customers. Christie made a point of emphasizing that organizations don’t have to replace everything they already own to participate in the investigation. The more useful context available from existing technologies and partners, the better-informed the security decision can become. Trellix’s presentation explicitly positions partner technologies as contributors to the investigation rather than information trapped in separate consoles.
And automation does not mean removing people from the process. Christie emphasized maintaining human control over consequential response decisions—using machines to perform more of the collection, correlation and investigative work while allowing security professionals to focus on the decisions that require judgment.
For public-sector organizations trying to do more with limited teams, that distinction matters.

A Different Way to Measure Security Operations
One of Christie’s most thought-provoking ideas comes later in the session, when she challenges the metrics security teams traditionally use.
Alerts triaged. Cases closed. Rules tuned. Dashboards built.
Those numbers tell you how much activity occurred. But do they tell you whether the organization would actually detect the attack that matters?
Christie proposed confidence as a more meaningful metric—confidence based on the visibility and context available to an investigation. As network, endpoint, identity and other sources fill in gaps, confidence can improve. When important telemetry is missing, the system should make that limitation visible rather than pretending to know more than it does.
It’s a compelling idea regardless of which technology an organization ultimately chooses: measure the security program by how well it can understand and respond to risk, not simply by how busy the SOC is.
There’s much more in Christie’s full session, including data residency, Zero Trust, security operations, using AI without unnecessarily moving sensitive data, and how organizations can preserve institutional knowledge when experienced analysts leave.
And throughout the presentation, the flight metaphor keeps returning to the same fundamental point:
Modern cybersecurity requires more than additional instruments. It requires a flight deck that can bring the right information together, make sense of it quickly and help the people responsible for the mission make better decisions. For FRC, that is one of the reasons our partnership with Trellix is so relevant to public-sector customers. Trellix brings deep experience across federal and state and local environments, while FRC helps customers evaluate how technologies such as WISE can fit into their existing security architecture, investments and mission requirements.

Watch the Full Session
Watch the full session to hear Christie Karrels’ complete presentation from the FRC Erie Summit and learn how lessons from the federal cybersecurity journey can help public-sector organizations build a more visible, automated, and resilient security operation.
To learn more about Trellix, Trellix WISE, and how FRC can help your organization modernize its cybersecurity operations, contact your FRC representative.



