Mumbai: Visa is shifting from periodic cybersecurity checks to continuous, AI-driven defence as cyber threats increasingly operate at machine speed, with India seeing a sharp rise in cyber fraud.Visa said it has moved from schedule-based vulnerability management to continuous detection, testing, remediation and validation. Its open-source Visa Vulnerability Agentic Harness (VVAH) uses multiple AI agents to discover vulnerabilities, test them, develop fixes and validate those fixes before production. Visa also uses Mean Time to Adapt (MTTA), rather than detection or patch counts, to measure how quickly it can close exploitable paths.The approach was tested through Anthropic’s Project Glasswing, where frontier AI models were used against Visa’s internet-facing and critical infrastructure. Visa said its zero-trust architecture and network segmentation prevented identified vulnerabilities from becoming successful attack chains.“As AI becomes more powerful, the cybersecurity challenge is no longer just finding vulnerabilities, it is fixing them faster than they can be exploited. India’s digital payments ecosystem has demonstrated what innovation at population scale can achieve, but sustaining trust will require the same pace of innovation in security and resilience,” said Suresh Sethi, group country manager, Visa during the launch of a whitepaper on Project Glasswing during the Global Fintech Fest in Mumbai.Project Glasswing is a defensive cybersecurity initiative in which Visa worked with Anthropic to test frontier AI models against its internet-facing services, core platforms and critical infrastructure. The exercise exposed complex vulnerabilities but also showed that Visa’s zero-trust architecture, network segmentation and other safeguards could break the attack chain before vulnerabilities were successfully exploited.Visa has also developed an agentic control plane governing AI agents’ identities, permissions and operating boundaries, while its Payment Threats Lab tests fraud and AI attacks against payment rules and configurations.
Share your thoughts in the comments
Be respectful · TOI community guidelines
It is working with IBM and Red Hat on Project Lightwell to secure open-source software and has tightened supplier requirements around continuous vulnerability testing and software bills of materials.The urgency is particularly high in India. Cyber fraud cases rose 24% year-on-year to 2.81 million in 2025, while losses from investment scams reached Rs 22,495 crore and digital-arrest scams accounted for 9% of losses. The 1930 cyber-fraud helpline logged 32.4 million calls during the year, roughly one every second.








Leave a Reply