Skip to content

Product1 publisher3 min readPublished

Each firewall change triggers a framework check in GTT's new Defense Halo service

GTT launched Defense Halo, which re-checks firewall and device configs whenever they change and ranks known vulnerabilities by the assets a customer runs. For the team rolling it out, catching a bad config sooner only pays off if someone can also ship the fix sooner.

The Product Desk · Product desk

Illustration accompanying Each firewall change triggers a framework check in GTT's new Defense Halo service

What happened

  • GTT tied the launch to a late-August open letter, organized by OpenAI and signed by more than 100 companies, warning that AI-enabled attacks would spread widely within months.
  • Threat detection starts from a behavioral baseline built from each customer's own logs and traffic flows, and anomalies are checked in real time.
  • GTT runs the software on compute built into its Tier 1 backbone, hosted in the U.S., the U.K. and the EU to meet data sovereignty requirements.
  • Defense Halo is available now, and GTT said select customers are already running it.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision A buyer has to judge whether its change process can keep pace with real-time remediation plans, because a plan waiting in a queue leaves the gap open as long as before.
  • constraint Automated containment covers only devices GTT deems compatible, so a mixed fleet gets network-speed response on part of the estate and human-speed response on the rest.
  • capability Firms bound by U.S., U.K. or EU data residency rules can use AI-driven network detection without sending their traffic analysis out of region.

A network engineer opens a firewall port so a vendor can reach a server, then closes the ticket. Defense Halo is built for that edit. Its first vulnerability module tests the new configuration against security frameworks at the moment it changes [6].

Fletcher Keister, GTT's chief product and technology officer, said every security leader he speaks with is "fighting the same battle against the clock" [4]. A vulnerability gets riskier the longer it goes undetected, according to Keister [5]. The product is aimed at shrinking the time vulnerabilities and threats go unnoticed on corporate networks [2].

Under the AI framing, the vulnerability side does jobs a buyer can test directly. A second module maps known vulnerabilities to the specific assets a customer runs and ranks them by priority [7]. A live model of the network shows every host-to-host connection. When a new vulnerability surfaces, that model feeds the platform's exposure assessments [11].

Here's what teams tell themselves happens next: an AI-generated remediation plan comes back in real time [8] and the gap closes. Here's what the description supports. Automated action is described for confirmed threats, which GTT says can be contained through runbooks on compatible devices [10]. For a loose firewall rule or an unpatched server, what arrives is a plan. The exposure lasts until someone on the customer's team approves the plan and ships it.

The architectural case comes from Amy DeCarlo, principal analyst for security and data center services at GlobalData. She said most security products analyze traffic only after it has been collected and normalized, a step she said adds latency, cost and blind spots [14]. She called GTT's choice to run AI inference inside its own network "architecturally different" [15]. Endpoint-centric and log-centric platforms, she said, "are not positioned to match" [17].

I think the clearest buyer is a company whose security team is small next to the network it defends, since GTT runs the stack and each customer gets its own isolated instance [13]. GTT did not disclose pricing or say who the early customers are [16].

Two figures from a team's own change log sort the decision: how often firewall and device configs change, and how long a flagged fix takes to clear change control. Frequent changes with fast fixes is the strongest case, because on-change checks and a ranked list match how the team already works. Frequent changes with slow fixes means findings arrive faster than the team closes them, so a trial mostly measures the change process. Rare changes with fast fixes puts the value on detection and containment, and that depends on how much of the fleet counts as compatible [10]. Rare changes with slow fixes is the hardest case to justify. In every quadrant, the trial metric is median time from a flag to a shipped fix.

What to watch

  • GTT publishing a price for Defense Halo or naming the select customers already running it.
  • A published list of which firewalls and network devices count as compatible for automated containment runbooks.
  • Whether customers must carry traffic on GTT's backbone to get the in-network inference DeCarlo credits.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories