Network operator and service provider GTT Communications is embedding real-time AI security directly into its Tier 1 network backbone to deliver faster threat defense, simpler multi-vendor firewall management, and safer human-guided automation.
endif; ?>
Security teams face a time problem, and AI is making it worse. Attackers use AI to find flaws and write exploits faster than any human-staffed security operations center can respond, while most defensive tools still collect telemetry, ship it somewhere, normalize it, and only then analyze it. Each step adds delay, and in security, delay is exposure.
GTT Communications believes the answer is to stop moving data and place intelligence where network traffic already is. The company recently launched GTT Defense Halo, an AI-native network defense platform that runs on its AI factory, embedded in GTT’s global Tier 1 backbone. The factory connects to New York, Dallas, London, and Prague, and each customer receives a dedicated, single-tenant instance rather than a slice of a shared cloud environment.
I received a pre-launch briefing and demo from Chris Bonavita, GTT’s vice president of strategy and technology adoption. Some of it is genuinely differentiated, while some still needs to be proven in customer environments.
What GTT Defense Halo does
The platform has three components. GTT Defense Halo Recon provides ongoing analysis of firewall and device configurations, comparing them against known security frameworks to identify compliance violations and security exposures. It also prioritizes exposure management by mapping all known CVEs to the customer’s monitored assets and quantifying exposure risk.
Defense Halo Detect establishes a baseline of normal behavior for a specific customer’s network and performs continuous threat analysis, detecting anomalies that go beyond known CVEs and indicators of compromise. Defense Halo Response feeds findings through an agentic runbook into an existing security service and handles approved responses across managed environments.
What makes it interesting is the data correlation. Bonavita said GTT first expected packet capture and software-defined networking data to be the most valuable inputs. They weren’t. The real value came from correlating identity, host, user, and syslog data with network traffic, all at once and in real time. That’s the right conclusion. Breaches rarely appear in a single data source. They appear in the gaps between sources, where siloed tools are weakest.
The demo’s strength was a real-time “galaxy” model of every host-to-host conversation. Click a node to see everything it’s communicating with, then move through time to trace where an event started and how it spread. Threat hunting that can take weeks becomes a matter of minutes.
The case for network speed
The industry has settled on “machine speed” as the benchmark for AI defense, and GTT is embracing it. Because the AI factory is built into its own network, data ingestion and analysis occur on net rather than over the top, eliminating egress charges and connectivity limits on telemetry ingestion.
“Most AI operators now talk about machine speed. You need machine speed to combat machine speed,” Bonavita told me. “Since we’ve embedded this into our network, we can operate at network speed.” This is where GTT’s history as a network operator becomes an advantage rather than a legacy to explain away. Owning the transport and the AI infrastructure removes costs and latency that software-only security vendors can’t. The single-tenant design matters too, since each customer is measured against its own baseline and data residency is easier to prove.
I asked whether the Nvidia partnership was more about branding than engineering. Bonavita said the value came from combining Nvidia GPUs, Morpheus, an AI application framework, and Nvidia’s NIM inference microservice model, which GTT extended with its own patent-pending work.
Combatting firewall sprawl is the near-term win
The use case that’s most important to early customers is a familiar struggle: real-time analysis of firewall configurations against known security frameworks and building a single policy across multiple vendors. Bonavita described an enterprise customer with 110 sites moving from cloud-managed Palo Alto Networks firewalls to on-premises Fortinet gear. Done manually, the conversion took about three and a half weeks. GTT Defense Halo completed it in roughly three and a half hours, with human review. Once the changes were approved, a rerun took 11 minutes.
With AI-assisted bug hunting driving CVE volumes sharply higher, knowing which vulnerability matters on which device, in the context of actual traffic, is far more valuable than another prioritized list. This drove another use case for Defense Halo: CVE correlation. GTT analyzed 145,000 devices across its managed firewall estate, spanning Cisco, Check Point, Palo Alto, HP, and Fortinet, in two hours and 15 minutes.
GTT has optimized its security stack by deploying Defense Halo across its enterprise estate, reducing licensing costs and saving more than $1 million after accounting for integration work and manual correlation labor. Bonavita went further, saying for GTT’s use case, Defense Halo could now handle about 98% of what its SIEM had previously done. That’s a bold claim, and he was careful to limit it to GTT. I’d treat it as a sign of direction, not a reason to rip out a SIEM next quarter.
The most important decision is what GTT held back
One of the more interesting aspects of the briefing was hearing a vendor argue for less automation. GTT uses automated response internally as the first customer. “Our own experience over the last six months shows that most folks are going a little too fast,” Bonavita said. He pointed out that a poorly executed automated response strategy can create new attack surfaces, competing bots, and insecure cloud-based data exchanges.
GTT’s model draws a line at the work done. Humans make decisions, and AI carries out actions once a decision has been made. “We learned from experience in our own internal development, and that is why we’re committed to human oversight,” he said.
That’s the correct call. The rush to autonomous security operations agents is outpacing the governance needed to keep them safe. Showing operators the raw data alongside the AI’s reasoning will build the trust GTT will need when customers are ready for more automation.
Where the questions remain
GTT is positioning GTT Defense Halo to unify network and security operations. The logic holds, since an anomaly might be operational or malicious, and the same data should address both. But I’m not convinced large enterprises are ready to merge their network and security operations centers. The org charts and budgets are deeply entrenched. Bonavita acknowledged that GTT’s sweet spot is mid-to-large, distributed enterprises, where convergence may be easier.
The go-to-market is sensible: Start with existing managed firewall and network customers and extend the platform through technology advisors. The real test is how it performs on networks messier than GTT’s own, against well-funded security platforms that are moving toward network-level correlation.
Recommendations for IT and security pros
- Audit your data movement costs. Know what shipping telemetry to external analytics platforms costs in terms of egress, latency, and blind spots. That’s your baseline for judging on-net alternatives.
- Start with firewall policy hygiene. If you run firewalls from multiple vendors, cross-brand policy analysis and CVE correlation are low-risk, high-return places to test AI-driven security. Ask for a proof of concept on a real portion of your estate.
- Insist on isolation. In regulated industries, make customer-isolated models and in-region processing requirements.
- Separate decisions from actions. Whatever AI security platform you use, set policy on what AI can recommend, what it can execute, and what always requires human sign-off. Be skeptical of vendors that can’t show you their reasoning alongside the raw data.
- Converge the data before the teams. Give network and security operations staff a shared, correlated view first, and let organizational changes follow the results.
- Pressure-test consolidation claims. Model licensing, integration, and headcount savings using your own numbers, not the vendor’s case study.
Final thoughts
GTT Defense Halo marks a step in the company’s evolution from connectivity provider to security player. It also signals where network security is heading. The combination of on-net AI infrastructure, single-tenant analysis, and real-time correlation of identity, host, and traffic data targets a real weakness in how most organizations defend themselves today: too many tools, too much data movement, and too little context. The firewall policy and CVE correlation use cases give GTT a practical entry point and solve a problem network and security teams face now, not in the future.
The bigger story is philosophical. At a time when much of the industry is racing toward fully autonomous security operations, GTT is betting that speed and governance can coexist and that customers will trust AI more when they can see how it reaches its conclusions. Whether Defense Halo can hold up in complex customer environments and against larger security platforms remains to be seen. But the architecture is sound, early results are promising, and the underlying idea that the network itself should be the first line of AI-era defense is one that CIOs and CISOs should take seriously.




