Visa has announced updates to its cybersecurity portfolio, including the release of the Visa Vulnerability Agentic Harness and expanded consulting services. The developments aim to help organisations reduce vulnerability resolution times amid a growing AI-driven threat landscape.

Global digital payments leader Visa has announced enhancements to its cybersecurity portfolio, introducing new tools and advisory services designed to help organisations identify and address security vulnerabilities more efficiently.

The company unveiled the next evolution of the Visa Vulnerability Agentic Harness (VVAH), an open-source, model-agnostic framework. The updated release moves AI-powered cyber risk management from discovery to validated remediation. According to Visa, the framework aims to reduce the Mean Time to Adapt (MTTA)—the time elapsed between the discovery and resolution of attack paths—with certain resolutions shrinking from weeks to hours.

Originally developed following Visa's participation in Anthropic's frontier AI cybersecurity initiative, Project Glasswing, VVAH initially focused on helping security teams uncover vulnerabilities, assess exploitability, and generate structured findings. The latest iteration extends this workflow to include remediation and validation within a single structured process.

In tandem with the framework update, Visa Consulting & Analytics (VCA) has expanded its Cybersecurity Advisory Practice. VCA is introducing three new advisory services intended to help clients assess risk, prioritize remediation efforts, and strengthen operational resilience.

Prateek Sanghi, Head of Visa Consulting & Analytics for Asia Pacific, noted that AI is accelerating both the scale of cyber threats and the speed of vulnerability exploitation. He emphasized that the primary challenge for organisations is no longer just identifying vulnerabilities, but determining which risks require immediate attention and resolving them before bad actors can act.

Over the past year, the VCA Cybersecurity Advisory Practice has engaged with various clients to evaluate security maturity and operational resilience. For instance, CAIXA Cartões utilized the advisory services to support its cybersecurity maturity assessment and prioritize risk management initiatives.

Lessandro Thomaz, Executive Director at CAIXA Cartões, stated that the partnership helped broaden the institution's strategic perspective on cybersecurity by providing structured assessments and supporting the prioritization of risk management processes.

Since its open-source release in June 2026, VVAH has been downloaded by tens of thousands of developers globally. Additionally, Visa has joined broader industry initiatives to support secure open-source development, contributing VVAH to NVIDIA's Open Secure AI Alliance and collaborating on IBM and Red Hat's Project Lightwell initiative.

"As artificial intelligence reshapes the threat landscape, enterprises must transition their security metrics from simple threat detection speed to actual remediation speed. Visa's integration of AI frameworks into open-source communities highlights a practical industry shift toward collaborative, automated defense mechanisms. For businesses and financial institutions navigating digital transformation, prioritizing risk management and operational resilience is no longer optional—it is a core requirement for maintaining customer trust and business continuity." — Dr. Shishir Gupta, Founder & CEO, StartupLanes