Global digital payments company Visa has announced enhancements to its cybersecurity portfolio, aimed at helping organizations identify and resolve vulnerabilities more effectively. The updates include the next evolution of the Visa Vulnerability Agentic Harness (VVAH), an open-source, model-agnostic framework.
According to the company, the latest VVAH release is designed to move AI-powered cyber risk management from mere discovery to validated remediation. The framework aims to help organizations reduce the Mean Time to Adapt (MTTA)—the time elapsed between the discovery and resolution of attack paths—with some resolutions reportedly decreasing from weeks to hours.
Originally introduced following Visa's participation in Anthropic's frontier AI cybersecurity initiative, Project Glasswing, VVAH initially focused on uncovering vulnerabilities, assessing exploitability, and generating structured findings. The updated release extends this workflow to encompass discovery, triage, remediation, and validation within a single structured framework.
In conjunction with the framework update, Visa Consulting & Analytics (VCA) has introduced three new cybersecurity advisory services. These services are designed to help clients assess risk, prioritize remediation efforts, and strengthen operational resilience in a changing threat environment.
Prateek Sanghi, Head of Visa Consulting & Analytics for Asia Pacific, noted that the scale of cyber threats and the speed of vulnerability exploitation are increasing. He stated that identifying vulnerabilities is no longer the primary differentiator, and that determining which risks matter most and remediating them quickly is critical.
Over the past year, the VCA Cybersecurity Advisory Practice has engaged with clients across various sectors to evaluate cybersecurity maturity and operational resilience. For instance, CAIXA Cartões worked with Visa to support its cybersecurity maturity assessment and prioritize risk management initiatives.
Lessandro Thomaz, Executive Director at CAIXA Cartões, noted that the partnership helped broaden the institution's strategic perspective on cybersecurity by providing structured assessments and supporting the prioritization of risk management initiatives.
Since its open-source release in June 2026, VVAH has been downloaded by tens of thousands of developers globally. Additionally, Visa has joined industry initiatives related to AI and cybersecurity, including NVIDIA's Open Secure AI Alliance—where Visa is contributing VVAH—and IBM and Red Hat's Project Lightwell initiative focused on securing open-source software.
"As artificial intelligence accelerates the speed at which cyber threats evolve, businesses must shift their focus from merely identifying vulnerabilities to reducing their Mean Time to Adapt. Visa's integration of AI frameworks into remediation workflows highlights a practical approach to managing operational risk in the digital economy. For organizations navigating complex threat landscapes, adopting structured, model-agnostic security frameworks and leveraging specialized advisory services will be critical to maintaining customer trust and ensuring long-term business resilience." — Dr. Shishir Gupta, Founder & CEO, StartupLanes