Visa has announced enhancements to its cybersecurity offerings, including updates to its open-source Visa Vulnerability Agentic Harness and new advisory services from Visa Consulting & Analytics. The developments aim to help organizations reduce Mean Time to Adapt in threat management.

Global digital payments company Visa has announced upgrades to its cybersecurity portfolio, aimed at helping organizations identify, prioritize, and resolve security vulnerabilities using artificial intelligence. The updates include the latest release of the Visa Vulnerability Agentic Harness (VVAH), an open-source, model-agnostic framework designed to streamline cyber risk management.

According to Visa, the updated framework moves AI-powered cyber risk management from mere discovery to validated remediation. The system helps organizations reduce the Mean Time to Adapt (MTTA)—the duration between the initial discovery of an attack path and its resolution. The company notes that some resolutions have dropped from weeks to hours under the framework.

Originally introduced following Visa's participation in Anthropic's frontier AI cybersecurity initiative, Project Glasswing, VVAH was designed to help security teams uncover vulnerabilities, evaluate exploitability, and generate structured findings. The latest release extends this functionality to include remediation and validation within a single structured workflow.

To support organizations in operationalizing these insights, Visa Consulting & Analytics (VCA) has introduced three new cybersecurity advisory services. These services are intended to help clients assess risk, prioritize remediation efforts, and strengthen operational resilience.

Prateek Sanghi, Head of Visa Consulting & Analytics for Asia Pacific, noted that the speed at which cyber threats scale in the region makes traditional vulnerability identification insufficient. He emphasized that shifting focus to the Mean Time to Adapt is critical for managing risks effectively.

Over the past year, the VCA Cybersecurity Advisory Practice has worked with various clients globally to evaluate cybersecurity maturity and resilience. Among them is CAIXA Cartões, which utilized the advisory services to support its risk management initiatives. Lessandro Thomaz, Executive Director at CAIXA Cartões, stated that the partnership helped broaden the institution's strategic perspective on cybersecurity and prioritized its operational resilience framework.

Since its open-source release in June 2026, VVAH has seen tens of thousands of downloads globally by developers. Additionally, Visa has joined industry initiatives such as NVIDIA's Open Secure AI Alliance—contributing VVAH as a model-agnostic framework—and IBM and Red Hat's Project Lightwell initiative to collaborate on securing open-source software.

"As businesses increasingly adopt artificial intelligence, the complexity of managing digital security scales proportionally. Visa's approach of moving from vulnerability discovery to automated remediation highlights a critical shift in enterprise risk management. For technology organizations and fintechs, reducing the time required to resolve vulnerabilities is essential for maintaining customer trust and operational stability in a rapidly changing threat landscape." — Dr. Shishir Gupta, Founder & CEO, StartupLanes