Visa has announced enhancements to its cybersecurity offerings, including the next evolution of its Visa Vulnerability Agentic Harness and new advisory services from Visa Consulting & Analytics. The developments aim to help organizations accelerate vulnerability remediation in an evolving threat landscape.

Global digital payments leader Visa has announced updates to its cybersecurity portfolio, introducing new tools and advisory services designed to help organizations identify, triage, remediate, and validate security vulnerabilities more effectively.

The announcement features the latest release of the Visa Vulnerability Agentic Harness (VVAH), an open-source, model-agnostic framework initially stemming from Visa's participation in Anthropic's Project Glasswing initiative. According to Visa, the updated framework extends its capabilities from vulnerability discovery to validated remediation. The system is designed to help organizations reduce Mean Time to Adapt (MTTA), which measures the time between the discovery and resolution of an attack path. Visa stated that certain resolutions have seen timelines drop from weeks to hours.

Alongside the VVAH update, Visa Consulting & Analytics (VCA) has introduced three new cybersecurity advisory services. These services are intended to help clients assess risk, prioritize remediation efforts, and build operational resilience. The advisory practice has previously supported financial institutions such as CAIXA Cartões with cybersecurity maturity assessments and risk management prioritization.

Since its open-source release in June 2026, VVAH has accumulated tens of thousands of global downloads by developers. Additionally, Visa has joined broader industry security initiatives, contributing VVAH to NVIDIA's Open Secure AI Alliance as a model-agnostic framework and collaborating through IBM and Red Hat's Project Lightwell to secure open-source software.

Prateek Sanghi, Head of Visa Consulting & Analytics for Asia Pacific, noted that the speed of vulnerability exploitation makes rapid remediation crucial. He stated that shifting the focus from the total number of identified vulnerabilities to reducing the Mean Time to Adapt is critical for managing modern cyber risks.

Lessandro Thomaz, Executive Director at CAIXA Cartões, highlighted that the institution's collaboration with Visa provided structured assessments of its process maturity, supporting its ongoing operational resilience initiatives.

"As digital infrastructure expands across the financial ecosystem, managing cybersecurity effectively requires moving beyond simple vulnerability detection to rapid, validated remediation. Frameworks like Visa's open-source agentic harness demonstrate how automated, model-agnostic tools can help organizations cut down resolution times significantly. For businesses and fintech startups alike, integrating structured risk assessment and prioritizing actionable responses will remain essential to maintaining operational resilience and customer trust in an increasingly complex threat environment." — Dr. Shishir Gupta, Founder & CEO, StartupLanes