cd /news/artificial-intelligence/gtt-bets-that-the-network-not-the-lo… · home › topics › artificial-intelligence › article
[ARTICLE · art-145925] src=networkworld.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

GTT bets that the network, not the log file, is where AI-era security gets won

GTT Communications launched GTT Defense Halo, an AI-native network defense platform running on its own AI factory embedded in its global Tier 1 backbone, with dedicated single-tenant instances per customer and connections in New York, Dallas, London, and Prague. GTT vice president of strategy and technology adoption Chris Bonavita said the platform's value came from correlating identity, host, user, and syslog data with network traffic in real time rather than from packet capture and software-defined networking data, and that embedding the AI factory in GTT's network lets it operate at network speed. The platform comprises three components — Defense Halo Recon for firewall and device configuration analysis and CVE-to-asset exposure mapping, Defense Halo Detect for behavioral baselining and anomaly detection, and Defense Halo Response for agentic runbook-driven responses — built on Nvidia GPUs, Morpheus, and NIM inference microservices that GTT extended with patent-pending work.

read6 min views1 publishedOct 6, 2026

Security teams face a time problem, and AI is making it worse. Attackers use AI to find flaws and write exploits faster than any human-staffed security operations center can respond, while most defensive tools still collect telemetry, ship it somewhere, normalize it, and only then analyze it. Each step adds delay, and in security, delay is exposure.

GTT Communications believes the answer is to stop moving data and place intelligence where network traffic already is. The company recently launched GTT Defense Halo, an AI-native network defense platform that runs on its AI factory, embedded in GTT’s global Tier 1 backbone. The factory connects to New York, Dallas, London, and Prague, and each customer receives a dedicated, single-tenant instance rather than a slice of a shared cloud environment.

I received a pre-launch briefing and demo from Chris Bonavita, GTT’s vice president of strategy and technology adoption. Some of it is genuinely differentiated, while some still needs to be proven in customer environments.

The platform has three components. GTT Defense Halo Recon provides ongoing analysis of firewall and device configurations, comparing them against known security frameworks to identify compliance violations and security exposures. It also prioritizes exposure management by mapping all known CVEs to the customer’s monitored assets and quantifying exposure risk.

Defense Halo Detect establishes a baseline of normal behavior for a specific customer’s network and performs continuous threat analysis, detecting anomalies that go beyond known CVEs and indicators of compromise. Defense Halo Response feeds findings through an agentic runbook into an existing security service and handles approved responses across managed environments.

What makes it interesting is the data correlation. Bonavita said GTT first expected packet capture and software-defined networking data to be the most valuable inputs. They weren’t. The real value came from correlating identity, host, user, and syslog data with network traffic, all at once and in real time. That’s the right conclusion. Breaches rarely appear in a single data source. They appear in the gaps between sources, where siloed tools are weakest.

The demo’s strength was a real-time “galaxy” model of every host-to-host conversation. Click a node to see everything it’s communicating with, then move through time to trace where an event started and how it spread. Threat hunting that can take weeks becomes a matter of minutes.

The industry has settled on “machine speed” as the benchmark for AI defense, and GTT is embracing it. Because the AI factory is built into its own network, data ingestion and analysis occur on net rather than over the top, eliminating egress charges and connectivity limits on telemetry ingestion.

“Most AI operators now talk about machine speed. You need machine speed to combat machine speed,” Bonavita told me. “Since we’ve embedded this into our network, we can operate at network speed.” This is where GTT’s history as a network operator becomes an advantage rather than a legacy to explain away. Owning the transport and the AI infrastructure removes costs and latency that software-only security vendors can’t. The single-tenant design matters too, since each customer is measured against its own baseline and data residency is easier to prove.

I asked whether the Nvidia partnership was more about branding than engineering. Bonavita said the value came from combining Nvidia GPUs, Morpheus, an AI application framework, and Nvidia’s NIM inference microservice model, which GTT extended with its own patent-pending work.

The use case that’s most important to early customers is a familiar struggle: real-time analysis of firewall configurations against known security frameworks and building a single policy across multiple vendors. Bonavita described an enterprise customer with 110 sites moving from cloud-managed Palo Alto Networks firewalls to on-premises Fortinet gear. Done manually, the conversion took about three and a half weeks. GTT Defense Halo completed it in roughly three and a half hours, with human review. Once the changes were approved, a rerun took 11 minutes.

With AI-assisted bug hunting driving CVE volumes sharply higher, knowing which vulnerability matters on which device, in the context of actual traffic, is far more valuable than another prioritized list. This drove another use case for Defense Halo: CVE correlation. GTT analyzed 145,000 devices across its managed firewall estate, spanning Cisco, Check Point, Palo Alto, HP, and Fortinet, in two hours and 15 minutes.

GTT has optimized its security stack by deploying Defense Halo across its enterprise estate, reducing licensing costs and saving more than $1 million after accounting for integration work and manual correlation labor. Bonavita went further, saying for GTT’s use case, Defense Halo could now handle about 98% of what its SIEM had previously done. That’s a bold claim, and he was careful to limit it to GTT. I’d treat it as a sign of direction, not a reason to rip out a SIEM next quarter.

One of the more interesting aspects of the briefing was hearing a vendor argue for less automation. GTT uses automated response internally as the first customer. “Our own experience over the last six months shows that most folks are going a little too fast,” Bonavita said. He pointed out that a poorly executed automated response strategy can create new attack surfaces, competing bots, and insecure cloud-based data exchanges.

GTT’s model draws a line at the work done. Humans make decisions, and AI carries out actions once a decision has been made. “We learned from experience in our own internal development, and that is why we’re committed to human oversight,” he said.

That’s the correct call. The rush to autonomous security operations agents is outpacing the governance needed to keep them safe. Showing operators the raw data alongside the AI’s reasoning will build the trust GTT will need when customers are ready for more automation.

GTT is positioning GTT Defense Halo to unify network and security operations. The logic holds, since an anomaly might be operational or malicious, and the same data should address both. But I’m not convinced large enterprises are ready to merge their network and security operations centers. The org charts and budgets are deeply entrenched. Bonavita acknowledged that GTT’s sweet spot is mid-to-large, distributed enterprises, where convergence may be easier.

The go-to-market is sensible: Start with existing managed firewall and network customers and extend the platform through technology advisors. The real test is how it performs on networks messier than GTT’s own, against well-funded security platforms that are moving toward network-level correlation.

GTT Defense Halo marks a step in the company’s evolution from connectivity provider to security player. It also signals where network security is heading. The combination of on-net AI infrastructure, single-tenant analysis, and real-time correlation of identity, host, and traffic data targets a real weakness in how most organizations defend themselves today: too many tools, too much data movement, and too little context. The firewall policy and CVE correlation use cases give GTT a practical entry point and solve a problem network and security teams face now, not in the future.

The bigger story is philosophical. At a time when much of the industry is racing toward fully autonomous security operations, GTT is betting that speed and governance can coexist and that customers will trust AI more when they can see how it reaches its conclusions. Whether Defense Halo can hold up in complex customer environments and against larger security platforms remains to be seen. But the architecture is sound, early results are promising, and the underlying idea that the network itself should be the first line of AI-era defense is one that CIOs and CISOs should take seriously.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @gtt communications 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/gtt-bets-that-the-ne…] indexed:0 read:6min 2026-10-06 · —