Global digital payments company Visa has announced enhancements to its cybersecurity offerings aimed at helping organisations identify and resolve system vulnerabilities more efficiently. The latest update introduces the Visa Vulnerability Agentic Harness (VVAH), an open-source, model-agnostic framework designed to shift AI-powered cyber risk management from mere discovery to validated remediation.
According to Visa, the framework helps organizations reduce the Mean Time to Adapt (MTTA)—the duration between discovering and resolving attack paths—potentially shrinking resolution windows from weeks to hours. The VVAH framework enables security teams to discover, triage, remediate, and validate vulnerabilities within a single structured workflow.
Alongside the VVAH update, Visa announced the expansion of its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice. The practice is introducing three new advisory services intended to help clients assess risk, prioritize remediation efforts, and enhance operational resilience. Prateek Sanghi, Head of Visa Consulting & Analytics for Asia Pacific, noted that the primary challenge in the current threat environment is determining which risks require immediate attention rather than simply accumulating identified vulnerabilities.
Visa's advisory services have previously supported financial institutions such as CAIXA Cartões. Lessandro Thomaz, Executive Director at CAIXA Cartões, stated that the partnership assisted the institution in evaluating its cybersecurity maturity and prioritizing risk management initiatives.
Since its open-source release in June 2026, VVAH has seen tens of thousands of downloads globally. Visa has also joined broader industry initiatives, contributing VVAH to NVIDIA's Open Secure AI Alliance and collaborating on IBM and Red Hat's Project Lightwell to support open-source software security.
"As businesses increasingly adopt artificial intelligence, cybersecurity frameworks must evolve from simple threat detection to rapid, automated remediation. Visa's approach highlights a crucial shift in enterprise security: reducing the time it takes to adapt and resolve vulnerabilities is now more valuable than simply generating larger lists of potential risks. For fintechs and digital enterprises, integrating structured risk management and open-source collaboration tools is essential to maintaining operational resilience and customer trust." — Dr. Shishir Gupta, Founder & CEO, StartupLanes