# GTT bets that the network, not the log file, is where AI-era security gets won

DevFeed: [GTT bets that the network, not the log file, is where AI-era security gets won](<https://devfeed.tech/articles/gtt-bets-that-the-network-not-the-log-file-is-where-ai-era-security-gets-won-65467.md>)

Original publisher: [Read original article](<https://www.networkworld.com/article/4230845/gtt-bets-that-the-network-not-the-log-file-is-where-ai-era-security-gets-won.html>)

Author: Zeus Kerravala

Published: 2026-10-06T09:00:00Z

Content type: article

Language: en

Sources: [Network World](<https://devfeed.tech/sources/network-world.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [trust](<https://devfeed.tech/topics/trust.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [networking-telecommunications](<https://devfeed.tech/tags/networking-telecommunications.md>), [security](<https://devfeed.tech/tags/security.md>), [telecommunications](<https://devfeed.tech/tags/telecommunications.md>)

## AI overview

GTT Defense Halo is an AI-native network defense platform that analyzes firewall and device configurations, correlates network, identity, host, and user data, and supports approved security responses with human oversight. The article describes reported firewall-policy and vulnerability-correlation results while noting that the platform's performance in complex customer environments remains to be proven.

## Source excerpt

Security teams face a time problem, and AI is making it worse. Attackers use AI to find flaws and write exploits faster than any human-staffed security operations center can respond, while most defensive tools still collect telemetry, ship it somewhere, normalize it, and only then analyze it. Each step adds delay, and in security, delay is exposure. GTT Communications believes the answer is to stop moving data and place intelligence where network traffic already is. The company recently launched GTT Defense Halo, an AI-native network defense platform that runs on its AI factory, embedded in GTT's global Tier 1 backbone. The factory connects to New York, Dallas, London, and Prague, and each customer receives a dedicated, single-tenant instance rather than a slice of a shared cloud environment. I received a pre-launch briefing and demo from Chris Bonavita, GTT's vice president of strategy and technology adoption. Some of it is genuinely differentiated, while some still needs to be proven in customer environments. What GTT Defense Halo does The platform has three components. GTT Defense Halo Recon provides ongoing analysis of firewall and device configurations, comparing them against known security frameworks to identify compliance violations and security exposures. It also prioritizes exposure management by mapping all known CVEs to the customer's monitored assets and quantifying exposure risk. Defense Halo Detect establishes a baseline of normal behavior for a specific customer's network and performs continuous threat analysis, detecting anomalies that go beyond known CVEs and indicators of compromise. Defense Halo Response feeds findings through an agentic runbook into an existing security service and handles approved responses across managed environments. What makes it interesting is the data correlation. Bonavita said GTT first expected packet capture and software-defined networking data to be the most valuable inputs. They weren't. The real value came from correl