📊 Key Data
  • Mean Time to Adapt (MTTA): Visa's VVAH framework reduces remediation time from weeks to hours.
  • Adoption: VVAH open-source framework downloaded by tens of thousands of developers since June 2026.
  • Collaboration: Visa partners with NVIDIA, IBM, and Red Hat to secure open-source software.
🎯 Expert Consensus

Experts would likely conclude that Visa's shift to AI-driven adaptation in cybersecurity represents a critical evolution in defending against rapidly advancing threats, emphasizing speed and collaboration over traditional detection methods.

about 23 hours ago
The New Arms Race: Visa Shifts Cyber Defense from Detection to Adaptation

The New Arms Race: Visa Shifts Cyber Defense from Detection to Adaptation

SINGAPORE – August 28, 2026 – For years, the cybersecurity mantra has been about building higher walls and better watchtowers. The focus was on detection: finding the vulnerabilities before the adversary could. But in the new era of artificial intelligence, that playbook is becoming dangerously obsolete. AI is not just a tool for defenders; it’s a force multiplier for attackers, compressing the timeline from vulnerability discovery to exploitation from months to mere hours. In this high-speed threat landscape, simply knowing your weaknesses is no longer enough.

This is the reality that prompted payments giant Visa to announce a significant expansion of its cybersecurity portfolio. Unveiling the next evolution of its AI-powered framework, the Visa Vulnerability Agentic Harness (VVAH), and new advisory services, the company is making a bold statement: the battle is no longer about who has the longest list of vulnerabilities. It’s about who can adapt the fastest.

The New Battleground: Mean Time to Adapt

The central challenge of modern cybersecurity is no longer discovery, but remediation. AI-powered scanners can unearth thousands of potential flaws in a company’s codebase, creating a deluge of alerts that overwhelm human security teams. The real bottleneck has shifted from finding problems to fixing and validating them. This is where Visa is planting its flag, championing a new metric: Mean Time to Adapt (MTTA).

MTTA measures the time elapsed from the moment an AI discovers an exploitable vulnerability to when a validated fix is deployed in production. It’s a metric of agility and resilience. According to Visa, its VVAH framework can shrink this window from weeks to hours.

“Across Asia Pacific, AI is accelerating both the scale of cyber threats and the speed at which vulnerabilities can be exploited,” said Prateek Sanghi, Head of Visa Consulting & Analytics, Asia Pacific. “The real challenge is determining which risks matter most and remediating them before they can be leveraged by attackers. In essence, shifting focus from 'number of vulnerabilities identified' to 'Mean Time to Adapt' has become more critical than ever.”

This sentiment is echoed by senior technology executives, who increasingly see MTTA as the most strategically important metric in the field. The logic is simple: in an environment where breaches are inevitable, the speed and reliability of the response become the primary determinants of security.

Under the Hood: VVAH's Agentic Approach

At the heart of Visa's strategy is the VVAH, an open-source, model-agnostic framework that moves beyond simple scanning. Born from Visa’s participation in Anthropic’s frontier AI initiative, Project Glasswing, VVAH operates as an “agentic pipeline”—a coordinated team of AI agents designed to discover, remediate, and validate vulnerabilities in a single, structured workflow.

The latest enhancements push this concept further. The framework now features “closed-loop remediation,” allowing it to learn from fixes that fail validation without requiring a human to restart the entire process. It’s also model-agnostic, giving organizations the flexibility to use models from Anthropic, OpenAI, or any other provider, avoiding vendor lock-in.

Since its open-source release in June 2026, VVAH has been downloaded by tens of thousands of developers, with its GitHub repository showing thousands of stars—a clear indicator of strong community interest. While the framework automates much of the grunt work, Visa emphasizes that human oversight remains integral. Humans initiate the scans, review the AI-generated patches, and approve the final merge, ensuring a “human-in-the-loop” governance model that balances speed with safety.

From Framework to Action: Consulting and Collaboration

An open-source tool, no matter how powerful, is only effective if organizations know how to implement it. To bridge this gap, Visa is expanding its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice with three new services designed to help clients operationalize the insights from VVAH.

These services range from executive education on the AI cyber threat landscape to hands-on maturity assessments using the VVAH framework and strategic guidance on prioritizing risks. This combination of a free, open-source tool with paid, expert-led consulting allows Visa to both contribute to the public good and build a commercial strategy around its expertise.

One early example is CAIXA Cartões, a Brazilian card issuer. “Our partnership with Visa has helped broaden our strategic perspective on cybersecurity by providing a structured assessment of the maturity of our processes and supporting the prioritization of initiatives focused on risk management and operational resilience,” said Lessandro Thomaz, Executive Director at CAIXA Cartões. This highlights the practical application of Visa’s advisory services in helping organizations navigate the complexities of the new threat environment.

A Strategic Pivot Beyond Payments

Visa’s deepening foray into cybersecurity represents more than just a new product line; it’s a strategic pivot. A company whose entire brand is built on trust and security in the financial world is now leveraging that expertise to become a major player in enterprise cybersecurity. This move acknowledges that the security of the entire digital ecosystem is intrinsically linked to the security of its own network.

Further underscoring this commitment is Visa’s active participation in industry-wide collaborations. The company is contributing VVAH to NVIDIA's Open Secure AI Alliance and working with IBM and Red Hat's Project Lightwell to help secure open-source software. These are not the actions of a company simply selling a product; they are the actions of an organization seeking to shape industry standards and foster collective defense.

In an age where digital threats evolve at machine speed, the idea of a single organization standing alone against the tide is a fantasy. By open-sourcing its tools, sharing its expertise, and collaborating with peers and competitors, Visa is championing a new model of shared responsibility, betting that a more secure ecosystem is ultimately better for everyone.

Topics & Related

Event:
Product Launch
Theme:
Agentic AI
Threat Landscape
Sector:
Payments
Cybersecurity
Product:
AI & Software Platforms

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 49027