AI & ML

Equifax Enhances Cybersecurity with AI-Driven Strategies

Equifax is harnessing AI to improve its cybersecurity efforts, automating processes and enhancing threat detection while managing new challenges presented by AI.

Aug 25, 2026 3 min read
Sign in to save

Equifax is navigating the complexities of cybersecurity after experiencing one of the most significant breaches in U.S. history, incurring cleanup costs exceeding $1.4 billion. This dark chapter arose from a series of mistakes, ranging from a poorly managed patching process to a lapsed public-key certificate. In its recovery efforts, Equifax engaged experts like Mandiant, now part of Google Cloud, to come up with effective solutions.

Fast forward to today, in the face of rapidly evolving threats, particularly those facilitated by artificial intelligence, Equifax finds itself adapting to a landscape where attackers can exploit vulnerabilities at an unprecedented pace. The company's EVP and CISO, Jeremy Koppen, a veteran of Mandiant with over a decade of experience, leads this vital initiative. Since joining Equifax in May 2025, he’s been tackling the ramifications of AI-enhanced attacks, which have reportedly surged by about 30% due to automation.

Koppen emphasizes the urgency of managing vulnerabilities: “The mean time for exploiting a vulnerability is shrinking,” he remarks. This narrowing window for action highlights the necessity for businesses to rapidly adapt their strategies against both traditional threats and AI-driven risks. To strengthen its defenses, Equifax is not only reinforcing basic cybersecurity hygiene but has also begun deploying AI technologies strategically across its operations.

Expanding Passwordless Security

An essential aspect of Equifax's cybersecurity strategy is the expansion of its passwordless authentication initiative, encompassing all 22,000 employees and contractors, as well as its business partners. Koppen states that eliminating the risks associated with password usage has significantly improved security. “This has been a major implementation for our team, minimizing the social engineering aspect,” he adds.

Another critical innovation is the introduction of a risk assessment tool that evaluates both risk and business data to identify vulnerabilities within the organization. This initiative aligns with Equifax's objective of mitigating the impact of emerging threats by prioritizing risk management based on the nature of assets and the layers of defense in place.

Leveraging AI for Incident Response

With security alerts reaching an astounding 19.8 million daily, Equifax is leveraging AI to streamline its response processes. Currently, half of the incident tickets in the security operations center are handled through automation, allowing human analysts to focus on high-priority issues. This integration of AI doesn’t replace human expertise; instead, it provides vital context to enhance decision-making in real-time.

To address previous issues, such as the certificate mishaps that contributed to the 2017 breach, Equifax has implemented a certificate management tool that automates the renewal and testing of TLS certificates, minimizing the risk of similar oversights. “Automation is a game-changer in various security domains,” Koppen notes.

Koppen also oversees the security of Equifax's software development processes, which are also evolving due to AI advancements. In today’s threat landscape, the speed at which attackers can analyze code for vulnerabilities has intensified. By utilizing AI in the code review phase, Equifax has reduced the time required from 46 days to just 18, without sacrificing the verification needed for security guardrails.

Proactive Vulnerability Management

Equifax's annual security report reveals impressive metrics, such as a 61% reduction in security consultation times, with AI agents capable of analyzing container vulnerabilities and automatically generating code fixes. This proactive approach allows the company to handle over 213,000 threat findings each year without impeding delivery timelines.

However, the rise of AI has also introduced new attack vectors. The company’s security team identified a tactic where adversaries could embed hidden prompts within AI models to execute malicious tasks. In response, Equifax has developed preventative controls to detect and eliminate these covert commands before they can cause harm.

Mitigating the Risks of Rogue AI

While using AI agents to identify and address security vulnerabilities shows promise, there are inherent risks. Agencies capable of uncovering weaknesses in a system might also exploit flaws in their defensive structures. Koppen stresses the importance of ensuring that any AI agents deployed are tightly controlled and monitored to prevent unauthorized data access or misuse.

“We need to ensure that we lock down what the agent can access,” he explains, advocating for identity-based controls as a fundamental protective measure. This practice reinforces the need for organizations to continually refine their security posture to thwart potential data exfiltration.

Manual controls have transitioned to a more automated and policy-driven approach, where new agents undergo thorough testing prior to deployment. Because of continuous monitoring, Equifax can promptly halt any AI model exhibiting unpredictable behavior, further underscoring the importance of safeguards.

Koppen keeps a vigilant eye on developments in the AI security landscape, particularly concerning autonomous agents escaping from their designed parameters. He appreciates the community’s collaborative spirit around these challenges, recognizing the value of shared knowledge in fortifying defenses against emerging threats.

The steps Equifax is taking reflect a broader trend in the industry: as AI capabilities evolve, so too must the strategies and practices of cybersecurity professionals. By embedding AI into their systems and processes thoughtfully, Equifax is positioning itself at the forefront of proactive cybersecurity management.

Source: Richard Smith · www.csoonline.com

Comments

Sign in to join the discussion.