Visa expands cybersecurity tools with new advisory services
Fri, 28th Aug 2026 (Today)
Visa has expanded its cybersecurity portfolio with updates to its Visa Vulnerability Agentic Harness and new advisory services aimed at helping organisations identify and fix vulnerabilities more quickly.
The latest version of the Visa Vulnerability Agentic Harness, or VVAH, extends the framework from vulnerability discovery into remediation and validation. Visa has also expanded its Visa Consulting & Analytics Cybersecurity Advisory Practise with three new services focused on risk assessment, remediation prioritisation and resilience planning.
According to Visa, the revised framework is designed to shorten the time between identifying attack paths and resolving them, with some remediation timelines reduced from weeks to hours.
VVAH is an open-source, model-agnostic framework. The new release adds closed-loop remediation, allowing teams to refine fixes that fail validation without restarting the process. It also broadens model choice and offers optional real-time progress views for long-running scans and remediation workflows.
Organisations can deploy approved Anthropic and OpenAI models, as well as other AI models, through configuration changes rather than code changes. The framework is designed to handle discovery, triage, remediation and validation in a single workflow.
Visa linked the changes to a broader shift in cyber defence as artificial intelligence shortens the window between a vulnerability being found and exploited. That pressure is pushing companies to validate and act on findings faster rather than simply generate more alerts.
"AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action," said Rajat Taneja, president of technology at Visa.
"By advancing VVAH and expanding our cybersecurity advisory capabilities, we're helping organisations move from insight to validated remediation while strengthening resilience in an increasingly AI-driven threat landscape," Taneja said.
New services
The advisory expansion introduces three new offerings through Visa Consulting & Analytics. One is AI Cyber Leadership Education, which includes executive workshops, training and Visa University certification courses led by Visa's AI and cybersecurity specialists.
A second service, the VVAH-Informed Cybersecurity Maturity Assessment, is designed to help organisations use the VVAH framework to identify and assess vulnerabilities, understand areas of risk and prioritise remediation work. The third, VVAH Cyber Risk Prioritisation and Roadmap, is intended to help clients evaluate findings and build a longer-term cyber risk management plan.
These services build on a broader Cybersecurity Advisory Practise that has worked with clients over the past year on cybersecurity maturity reviews, risk assessments and operational resilience priorities. Visa said the new structure draws on its own AI-based cybersecurity work and payments experience.
"Finding vulnerabilities is no longer the hardest part. Speed to remediation is the new battleground. When AI-enabled attackers move faster and probe at scale, companies need AI-powered defenses," said Carl Rutstein, global head of Visa Consulting & Analytics.
"Our enhanced cybersecurity advisory services combine insights from implementing frontier AI models for cybersecurity, VVAH and decades of payments expertise to help clients prioritise risk areas, act quickly and build sustainable cyber resilience," Rutstein said.
Client example
Visa cited its work with CAIXA Cartões as an example of how its advisory practice has been used. The financial services group worked with Visa on a cybersecurity maturity assessment and on prioritising risk management and operational resilience initiatives.
"At CAIXA, we understand that cybersecurity is a fundamental pillar for customer trust and business sustainability in an increasingly complex digital environment," said Lessandro Thomaz, executive director at CAIXA Cartões.
"Our partnership with Visa has helped broaden our strategic perspective on cybersecurity by providing a structured assessment of the maturity of our processes and supporting the prioritisation of initiatives focused on risk management and operational resilience. Projects like this reinforce the importance of collaboration between financial institutions and strategic partners to anticipate challenges, strengthen capabilities and deliver increasingly secure and reliable solutions to our customers," Thomaz said.
Wider uptake
VVAH was first released after Visa's participation in Anthropic's Project Glasswing, a cybersecurity initiative focused on frontier AI. Since its open-source release in June 2026, the framework has been downloaded by tens of thousands of developers worldwide, signalling growing interest in AI tools that support vulnerability management workflows.
Visa has also joined industry efforts around AI security and open-source software. It is contributing VVAH to NVIDIA's Open Secure AI Alliance and working with other organisations through IBM and Red Hat's Project Lightwell initiative to secure open-source software.
Those moves place Visa among a broader group of large technology and financial companies seeking to shape how AI is used in cyber defence, particularly as businesses face pressure to test, fix and validate weaknesses faster. The latest expansion shows the company pushing further into security software and advisory work alongside its core payments business.
VVAH is designed to help organisations discover, triage, remediate and validate vulnerabilities within a single structured workflow.