ARMOR In Action with Gigamon: Deep Observability as the Intelligence Foundation for Secure AI
In this article
As AI evolves from pilot projects into business-critical systems, organizations are entering what Gigamon describes as the Intelligence Era, where success will increasingly depend not simply on how much data organizations collect, but on the quality of intelligence behind human and AI-driven decisions.
At the same time, AI is becoming more distributed. Organizations are increasingly adopting Hybrid AI architectures that span public and private models, applications, agents, data, and infrastructure. Every new interaction creates additional communications, dependencies, and data in motion that organizations must understand, secure, and govern.
Security therefore becomes a defining factor in successful AI deployments. To help organizations address this challenge, WWT developed ARMOR (AI Readiness Model for Operational Resilience), a vendor-agnostic AI security framework. Built through collaboration with NVIDIA and strengthened by real-world engagement with the Texas A&M University System, ARMOR provides security leaders with a practical framework for assessing and managing AI risk. It organizes AI security into seven domains: Governance, Risk and Compliance, Model Protection, Secure AI Operations, Infrastructure Security, Identity Security, Data Protection, and Secure Software Development Lifecycle. Together, these domains help organizations build cyber-resilient AI environments.
ARMOR's seven domains focus on key elements of securing AI systems and related processes, helping organizations understand security control points inside and between these systems, and their interactions with the surrounding environment. That becomes increasingly important as Hybrid AI spans models, agents, applications, workloads, and data across a wider range of infrastructure and creates more relationships that security teams must continuously understand and validate. This is key to understanding how AI security mechanisms mesh with traditional security solutions and is vital to identifying present gaps. ARMOR also accommodates organizations at different maturity levels. ARMOR is a real-world-tested AI security framework that was shaped through two-way collaboration with a lighthouse customer, Texas A&M University, who served as the first testing ground.
Gigamon brings a distinctive perspective to the ARMOR framework. Rather than adding another enforcement point, the Gigamon Deep Observability Pipeline transforms network traffic into trusted network-derived telemetry, including packets, flows, and application metadata across data centers, public cloud, containers, and AI infrastructure.
This independent context from data in motion complements metrics, events, logs, and traces (MELT), helping security, observability, and AI platforms generate higher-quality intelligence. The security value is therefore delivered not as another control plane, but by strengthening the SIEM, NDR, SOAR, DSPM, and guardrail systems that detect, investigate, and act on what is happening across the environments.
In the sections ahead, we'll show how Gigamon maps to the ARMOR domains, with particular strength in Infrastructure Security, Secure AI Operations, and network-based discovery of shadow AI.
Mapping the Gigamon portfolio to ARMOR domains
The Gigamon Deep Observability Pipeline provides a layered approach to accessing, optimizing, enriching, and delivering network-derived telemetry: traffic access through TAPs and cloud-native visibility, aggregation and brokering through GigaVUE appliances and Cloud Suite, and intelligence through capabilities including Application Metadata Intelligence, AI Traffic Intelligence, and Gigamon Insights. Coverage of Model Protection, the Secure Software Development Lifecycle and Data Security is enabling in nature, providing detection and evidence rather than enforcement, and Identity Security is not addressed by the current portfolio.
Across the seven ARMOR domains, Gigamon alignment can be summarized as follows:
With the portfolio mapped, the following sections describe how each Gigamon solution contributes to the ARMOR domains it primarily supports and the domains it secondarily reinforces.
GigaVUE Appliances & Cloud Suite
ARMOR Domains: Infrastructure Security (Primary); Secure AI Operations, Secure Software Development Lifecycle (Overlap)
Hybrid AI is distributing AI workloads across increasingly diverse infrastructure, from accelerated computing platforms and private AI infrastructure to public cloud and containerized services.
These architectures create growing volumes of north-south and east-west communications, along with new dependencies among applications, models, services, and data.
AI workloads run on accelerated computing platforms spanning compute, high-performance networking, network-attached storage, and hybrid cloud interconnects. ARMOR requires comprehensive visibility into north-south, east-west, and scale-across traffic spanning cloud and container environments, including encrypted communications.
GigaVUE appliances and Cloud Suite, including Universal Cloud Tap, provide packet access, aggregation, and brokering of that traffic to the security and performance tools used by SOC and NOC teams.
This is the foundational fabric for ARMOR's Infrastructure Security domain: visibility that lets teams implement and validate segmentation and protection policies rather than assume them. Notable capabilities include:
- Lossless traffic access: TAPs at critical data center, core and AI interconnect links plus cloud-native visibility, avoiding reliance solely on SPANs and per-tool agents.
- Segmentation and boundary validation: Detection of suspicious traffic and anomalies, signs of lateral movement between systems and data exfiltration, providing confidence that infrastructure security policies are configured and operating correctly.
- Tool brokering: Centralizes AI and non-AI traffic feeds for SIEM, NDR, IDS/IPS, packet capture and performance tools, letting NetOps and SecOps provision access for any tool without constant SPAN reconfiguration.
- SDLC traffic monitoring: Visibility into CI/CD pipelines touching AI services, test versus production AI traffic, and workloads on any platform (on-premises, cloud, microservices, serverless).
Application Metadata Intelligence (AMI)
ARMOR Domains: Secure AI Operations (Primary); Governance, Risk and Compliance, Data Security (Overlap)
ARMOR emphasizes continuous monitoring and adaptive defense, but Hybrid AI increases both the volume of data in motion and the number of application, workload, and AI interactions security teams must understand. Simply sending more raw traffic to more tools does not solve that challenge.
AMI extracts rich application context from network traffic while de-duplication, filtering, and slicing help optimize the telemetry delivered to downstream tools. This provides security and operations platforms with higher-quality, context-rich intelligence while helping organizations manage the cost and complexity of processing rapidly growing traffic volumes. Gigamon cites an expected 30-50 percent reduction in traffic sent to tools, deferring one to two years of sensor and license expansion while adding richer context to SIEM analytics and dashboards. Notable capabilities include:
- Optimized telemetry: Application-level filtering, metadata extraction, and de-duplication deliver richer context to SecOps and NetOps teams while reducing unnecessary traffic sent to downstream tools and helping reduce visibility gaps across AI workloads.
- SIEM, NDR, and SOAR enrichment: High-fidelity network telemetry feeding existing SOC workflows, supporting real-time incident response for AI workloads and reducing incident volume and false positives.
- Audit-grade evidence: Comprehensive network traffic visibility as the source of truth, enriched with application-aware metadata, supporting regulatory audits and incident investigations.
Security Intelligence (Decryption)
ARMOR Domains: Data Security (Primary); Governance, Risk and Compliance, Secure AI Operations (Overlap)
Hybrid AI spreads models, applications, and data across private infrastructure, public cloud, and specialized AI services. As a result, sensitive training data, inference traffic and other information increasingly move between environments, often over encrypted connections. Gigamon decryption and traffic intelligence selectively decrypt relevant flows for inspection, extending visibility from data at rest to data in motion.
Enforcement remains with the customer's DLP and DSPM stack; Gigamon supplies the in-motion visibility those tools lack. Notable capabilities include:
Selective decryption: Decrypts only the flows that require inspection, reducing encrypted blind spots in AI-related traffic.
Sensitive-flow detection: Identifies unexpected data movement, clear-text data exposure, and data-policy violations across on-premises and public cloud environments.
Policy validation: Verifiable checks such as 'no AI data leaves this region,' supporting compliance and data-residency requirements.
DSPM and DLP enhancement: Adds data-in-motion discovery and classification of data used in AI workloads to existing DSPM and DLP tools.
AI Traffic Intelligence
ARMOR Domains: Governance, Risk and Compliance (Primary); Model Protection, Secure AI Operations, Data Security (Overlap)
As organizations adopt Hybrid AI, AI usage becomes increasingly distributed across sanctioned and unsanctioned applications, public AI services, privately deployed models, and emerging agentic workflows. That makes basic governance questions harder to answer: What AI services are being used? Where are models running? Which users and applications are interacting with them? And where could sensitive data be exposed?
AI Traffic Intelligence uses network-derived telemetry to help identify AI usage across distributed environments, giving security teams independent context for AI governance and shadow AI discovery. This strengthens the visibility behind the ARMOR GRC domain and provides context to posture-management and guardrail systems responsible for policy and enforcement.
Its Model Protection role is observational: it watches model access paths and feeds posture-management and guardrail systems rather than enforcing controls itself. Notable capabilities include:
- Shadow AI discovery: Identifies unsanctioned AI usage and associated data risks, helping organizations reduce visibility gaps into user access to AI services.
- AI engine and model detection: Provides network-based visibility into supported AI engines and models operating across the environment, helping security teams understand AI usage and associated traffic patterns.
- Model access-path monitoring: Safeguards against potential data extraction, unauthorized access via API calls to AI endpoints, prompt-injection patterns, and abuse of model hosting infrastructure, and observes abnormal request volumes or access patterns.
- Guardrail and AI-SPM context: Provides network visibility context to systems implementing AI guardrails and augments AI Security Posture Management.
Gigamon Insights
ARMOR Domains: Secure AI Operations (Primary)
As telemetry volumes grow, security and operations teams face increasing pressure to turn that data into actionable answers more quickly.
Gigamon Insights applies GenAI to network and security use cases through a conversational, natural-language interface over network telemetry. Analysts can ask security, application, performance, and compliance questions directly, helping them turn complex telemetry into actionable intelligence more efficiently. It remains an analyst assistant rather than an autonomous SOC capability, and WWT's AI Security and Operations expertise supports its deployment.
- Conversational telemetry analysis: Natural-language questions and answers over large volumes of network security data.
- Operational efficiency: Leverages AI for SecOps and NetOps efficiency in addition to security outcomes.
AI Traffic Intelligence Enhancements
ARMOR Domains: Model Protection, Infrastructure Security, Secure AI Operations (Overlap; roadmap)
As Hybrid AI continues to evolve across private models, agentic workflows, and AI infrastructure, the Gigamon product roadmap is intended to extend AI Traffic Intelligence into additional areas, including private LLMs, agentic AI, and AI HPC visibility. These remain future items on the Gigamon product roadmap rather than currently shipping capabilities and should be validated with Gigamon product management before inclusion in any customer commitment. Notable roadmap items include:
- Private LLM and agentic AI visibility: Planned extension of AI Traffic Intelligence (Future).
- AI HPC visibility: Planned deeper visibility into AI HPC platforms (Future).
- AI-based enrichment and NVIDIA integrations: Planned joint-solution integrations (Future; contact Gigamon PLM for details).
Ready to get started?
At WWT, we're helping organizations operationalize ARMOR with partners that can address the security requirements of emerging Hybrid AI environments. As AI becomes distributed across models, applications, agents, data, and infrastructure, organizations need trusted intelligence to understand how those systems interact and to validate that security controls are operating as intended. As Hybrid AI expands across models, applications, agents, data and infrastructure, the ability to observe and validate those interactions will become increasingly important.
Whether you're building a new AI environment or strengthening the security posture of an existing one, the path forward starts with understanding what is happening across the environment and ensuring that the intelligence behind security decisions can be trusted. WWT ARMOR provides the framework for building resilient AI security, while the Gigamon Deep Observability Pipeline provides trusted network-derived telemetry that strengthens the tools and controls responsible for securing it.