Enhancing Security: Visa’s Updates to VVAH and Cybersecurity Advisory Services
Visa has taken significant steps to improve the landscape of cybersecurity by enhancing its open-source vulnerability tool, VVAH (Vulnerability Validation and Assessment Helper). These updates include not just fixes for vulnerabilities but also features aimed at remediation, validation, and model selection—crucial components for modern security teams.
Speeding Up Remediation Efforts
One of the standout features of Visa’s updates is the focus on reducing the “Mean Time to Adapt” (MTTA)—the time taken from discovering a vulnerability to effectively addressing it. According to Visa, some remediation efforts have dramatically shifted from weeks down to hours, allowing organizations to respond to threats more swiftly. Rajat Taneja, President of Technology at Visa, emphasizes the importance of this speed, especially in a world where artificial intelligence (AI) tools are capable of exploiting vulnerabilities at an alarming rate. Taneja states, “AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action.”
From Discovery to Remediation: A Complete Workflow
VVAH originated as part of Project Glasswing, aimed at using AI to assist security teams in identifying vulnerabilities and assessing their exploitability. The latest iteration of VVAH pushes past mere discovery into a more comprehensive remediation workflow. This includes several key enhancements:
-
Closed-loop Remediation: This feature allows security teams to receive structured feedback on fixes that fail validation, enabling them to refine their approaches without having to restart the entire process. This iterative capability is intended to streamline problem-solving and bolster efficiency.
-
Configurable AI Model Selection: Users can now swap or add AI models within the VVAH framework without delving into code changes. This means that as new AI models emerge—whether from Anthropic, OpenAI, or other sources—teams can easily test and implement them without the hassle of rebuilding their workflows.
-
Real-time Progress Monitoring: Optional views allow security teams to keep track of ongoing scans and remediation tasks. This visibility can enhance communication and management during long-running processes, simplifying the workflow from discovery through validation.
Expanding Cybersecurity Advisory Services
In tandem with improving VVAH, Visa has broadened its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice. The new services aim to transform vulnerability findings into actionable strategies, equipping organizations with the tools they need to prioritize risk and strengthen their defenses.
-
AI Cyber Leadership Education: This initiative provides executives with workshops, training, and certification courses centered around insights drawn from Visa’s AI and cybersecurity initiatives.
-
VVAH-Informed Cybersecurity Maturity Assessment: This service utilizes the VVAH framework to help organizations pinpoint vulnerabilities, understand associated risks, and assign remediation priorities effectively.
-
Cyber Risk Prioritization and Roadmap: This guidance assists organizations in evaluating their cybersecurity findings, enabling them to develop long-term risk management plans that foster resilience.
Carl Rutstein, Global Head of Visa Consulting & Analytics, highlights the shift from vulnerability discovery to rapid remediation as a decisive battleground in cybersecurity. He asserts that as AI-enabled threats escalate, companies must equip themselves with AI-driven defenses.
Collaboration and Industry Alliances
Visa’s cybersecurity advisory practice has already collaborated with various clients to bolster their security infrastructure. Notably, CAIXA Cartões benefitted from Visa’s services in evaluating their cybersecurity maturity and setting risk management priorities. According to Lessandro Thomaz, Executive Director at CAIXA Cartões, the partnership has broadened their strategic outlook on cybersecurity, emphasizing the need for structured assessments and prioritized initiatives in a complex digital landscape.
In terms of broader industry engagement, Visa has integrated VVAH into two significant collaborative initiatives. It is contributing to NVIDIA’s Open Secure AI Alliance, promoting VVAH as a model-agnostic framework for AI security, and participating in IBM and Red Hat’s Project Lightwell, which focuses on securing open-source software. As Thomaz succinctly puts it, these collaborative projects highlight the essential partnerships between financial institutions and strategic allies in creating robust security solutions.
Growing Adoption and Impact
Since its open-source launch in June 2026, VVAH has reportedly been downloaded by tens of thousands of developers worldwide, underlining the increasing interest in AI-powered vulnerability management. This surge in adoption reflects a collective need for effective, efficient tools that empower organizations to address their cybersecurity challenges head-on.
With these innovations and collaborations, Visa is effectively helping organizations navigate the increasingly complex cybersecurity landscape, facilitating speed, reliability, and resilience in their defense mechanisms amidst evolving threats.