Skip to content
Artwork for AI Security Podcast
AI Security Podcast · October 2 · 55 min

How Visa Secures Trillions Using AI Agents & Open-Source Harnesses

How does a global financial engine moving trillions annually manage cyber risk in the age of AI? In this episode, Ashish sits down with Subra Kumaraswamy, CISO of Visa. Subra discusses Visa's journey as part of Anthropic's Glasswing Project testing the Mythos model, revealing why a majority of Mythos-discovered vulnerabilities were non-exploitable due to robust zero-trust architecture and micro-segmentation. Subra explains why Visa open-sourced VVAH (Visa Vulnerability Agentic Harness) to help security teams scale vulnerability discovery, prioritization, and remediation across any model. He also breaks down how Visa triages 98% of Level 1 SOC incidents with AI agents, why "Mean Time to Adapt" (MTTA) is replacing legacy patch timelines, and how cross-functional AI governance enables innovation while maintaining strict production controls (00:00) Introduction: Securing $18 Trillion in Global Transactions(01:50) Subra Kumaraswamy’s 30-Year Career: Netscape, Sun, and Visa(04:30) Improving Visa’s Cyber Maturity Score from 3.2 to 4.9(07:30) Inside Project Glasswing and Testing Anthropic’s Mythos(09:30) Why Visa Open-Sourced VVAH (Visa Vulnerability Agentic Harness)(13:30) Mythos vs. Zero Trust: Why Only 0.03% of Vulns Were Exploitable(16:30) Defining MTTA: Mean Time to Adapt at Machine Speed(19:00) The Threat of Multi-Service Vulnerability Chaining(24:00) Prioritizing Exploits and Automating PRs with Developer Agents(28:30) Moving to Autonomous Defense in High-Stakes Environments(33:00) AI Governance: Balancing Vibe-Coding with Production Gates(36:00) Collapsing Silos: Unifying Endpoint, Identity, and AppSec Signals(39:00) Building Custom Control Planes with Agent Harnesses(45:30) Triaging 98% of Level 1 Incidents with AI Agents(48:30) Hiring for CQ (Curiosity Quotient) & Developer Mindsets(53:00) The "You Laugh, You Lose" Cybersecurity Joke Challenge Resources spoken about during the episode: VVAH - Visa Vulnerability Agentic Harness

0:00-55:24

transcript

No transcript — this publisher did not publish one.

show notes

How does a global financial engine moving trillions annually manage cyber risk in the age of AI?

In this episode, Ashish sits down with Subra Kumaraswamy, CISO of Visa. Subra discusses Visa's journey as part of Anthropic's Glasswing Project testing the Mythos model, revealing why  a majority  of Mythos-discovered vulnerabilities were non-exploitable due to robust zero-trust architecture and micro-segmentation.

Subra explains why Visa open-sourced VVAH (Visa Vulnerability Agentic Harness) to help security teams scale vulnerability discovery, prioritization, and remediation across any model. He also breaks down how Visa triages 98% of Level 1 SOC incidents with AI agents, why "Mean Time to Adapt" (MTTA) is replacing legacy patch timelines, and how cross-functional AI governance enables innovation while maintaining strict production controls



(00:00) Introduction: Securing $18 Trillion in Global Transactions(01:50) Subra Kumaraswamy’s 30-Year Career: Netscape, Sun, and Visa(04:30) Improving Visa’s Cyber Maturity Score from 3.2 to 4.9(07:30) Inside Project Glasswing and Testing Anthropic’s Mythos(09:30) Why Visa Open-Sourced VVAH (Visa Vulnerability Agentic Harness)(13:30) Mythos vs. Zero Trust: Why Only 0.03% of Vulns Were Exploitable(16:30) Defining MTTA: Mean Time to Adapt at Machine Speed(19:00) The Threat of Multi-Service Vulnerability Chaining(24:00) Prioritizing Exploits and Automating PRs with Developer Agents(28:30) Moving to Autonomous Defense in High-Stakes Environments(33:00) AI Governance: Balancing Vibe-Coding with Production Gates(36:00) Collapsing Silos: Unifying Endpoint, Identity, and AppSec Signals(39:00) Building Custom Control Planes with Agent Harnesses(45:30) Triaging 98% of Level 1 Incidents with AI Agents(48:30) Hiring for CQ (Curiosity Quotient) & Developer Mindsets(53:00) The "You Laugh, You Lose" Cybersecurity Joke Challenge


Resources spoken about during the episode:

VVAH - Visa Vulnerability Agentic Harness

links3