AI News Feed
Market watch
Cybersecurity

GTT launches Defense Halo as Rig Security debuts with $12M for AI agent oversight

GTT launched Defense Halo for AI threat hunting; Rig Security raised $12M to track AI agents under employee accounts.

GTT Defense Halo is designed to reduce the time vulnerabilities and threats go unnoticed on enterprise networks. The company tied the launch to an open letter signed in late August by more than 100 technology, cybersecurity and financial services companies. Organized by OpenAI Group PBC, the letter warned that AI-enabled attacks would become far more widespread within months. GTT Chief Product and Technology Officer Fletcher Keister said every security leader he speaks with is “fighting the same battle against the clock,” and AI-powered threats make it harder. According to Keister, a vulnerability gets riskier the longer it goes undetected, and Defense Halo was built so customers could find and act on such weaknesses much sooner.

On the vulnerability side, one Defense Halo module checks firewall and device configurations against security frameworks whenever they change. A second module maps known vulnerabilities to the specific assets a customer runs and ranks them by priority. Remediation plans generated by AI come back in real time, with the aim of closing gaps before attackers discover them. Detection is tuned to each customer’s own network. The software builds a behavioral baseline from logs and traffic flows, and any anomaly that strays from it gets checked in real time to decide whether it amounts to a genuine threat. GTT said confirmed threats can then be contained at network speed through automated runbooks on compatible devices.

The platform also keeps a live, stateful model of the customer’s network showing every host-to-host connection. Threat hunters can work from that picture in real time, and the same model feeds the platform’s exposure assessments when a new vulnerability surfaces. GTT runs the software on what it calls its AI factory, compute capacity built into its global Tier 1 backbone and hosted in the U.S., the U.K. and the European Union to meet data sovereignty requirements. Each customer gets a dedicated, isolated instance of the patent-pending system.

Amy DeCarlo, principal analyst for security and data center services at GlobalData plc, said most security products only analyze traffic once it has been collected and normalized, which adds latency, cost and blind spots. She described GTT’s decision to run AI inference inside its own network as “architecturally different.” Paired with isolated customer models and in-region data residency, DeCarlo said, the result is something endpoint-centric and log-centric platforms “are not positioned to match.” Defense Halo is available now, and GTT said select customers are already running it.

Rig Security’s platform addresses a different identity problem. Coding assistants and autonomous agents seldom sign in under an identity of their own, and whatever they do is logged against the developer or service account that launched them. A production database wiped by an agent looks, in the audit log, like the engineer’s own work. Founder and Chief Executive Guy Kozliner said AI agents are now the most active identities in an enterprise “and they are acting under human names.” Security teams can see when an account does something dangerous, but Kozliner said they cannot tell whether a person or an agent was behind it, and there is no way to stop the agent without also blocking the employee.

The company’s answer starts with the Rig Identity Correlation Engine, where machine learning models match a single identity as it shows up across identity providers, cloud infrastructure and on-premises systems. Rig said the matching is better than 96% accurate. Results feed a live graph of which people, service accounts and agents hold access to what. The same platform also handles posture management and threat detection. Enforcement happens on the endpoint. A lightweight sensor separates an agent’s session from the user’s own and can stop a risky action before it leaves the machine, without interrupting the employee whose identity the agent borrowed. The rest of the platform needs no installed software, and Rig said customers can roll out sensors once it is running.

Fortune 200 companies in financial services, insurance and health care already run Rig in production. The 20-person company said its software now analyzes hundreds of millions of identity events and access signals every month. Mortgage lender New American Funding LLC is one customer. Bill Harper, its assistant vice president of digital identity, said agents write code and investigate issues across the company, and that traditional identity tools cannot reliably tell their activity apart from the employee’s. Rig shows which agents are running and whose access they are using, and gives the lender control over them “without getting in the employee’s way,” he said.

Kozliner started Rig after working on Wiz Inc. co-founder Ami Luttwak’s team. Chief Technology Officer Nokky Goren was the first engineer at Axis Security Ltd., a network security startup that Hewlett Packard Enterprise Co. bought in 2023. Head of Product Michal Haikov is a veteran of Israel’s Unit 8200 and of Flow Security Inc., now part of CrowdStrike Holdings Inc. Ten Eleven Ventures and Brightmind Partners co-led the seed round. CrowdStrike took part as a strategic investor, and Luttwak was among a group of cybersecurity founders and executives who also put money in. Mark Hatfield, co-founder and partner at Ten Eleven Ventures, said most identity tools only point out what is wrong. Rig connects what it finds to enforcement in real time, he said, so that security teams “can actually act on identity risk, including risk created by AI agents.” Rig is available now through the AWS Marketplace and the CrowdStrike Marketplace.