{"id":9220,"date":"2026-08-25T08:25:00","date_gmt":"2026-08-25T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9220"},"modified":"2026-08-25T08:25:00","modified_gmt":"2026-08-25T08:25:00","slug":"how-equifax-is-using-ai-to-elevate-its-cybersecurity","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9220","title":{"rendered":"How Equifax is using AI to elevate its cybersecurity"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">For nearly a decade, Equifax has been dealing with the aftermath of <a href=\"https:\/\/www.csoonline.com\/article\/567833\/equifax-data-breach-faq-what-happened-who-was-affected-what-was-the-impact.html\">one of the worst cybersecurity breaches<\/a> in US history, racking up $1.4 billion on cleanup costs.<\/p>\n<p class=\"wp-block-paragraph\">Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certificate, and poor governance. One company Equifax brought in to help was Mandiant, now part of Google Cloud.<\/p>\n<p class=\"wp-block-paragraph\">Today, Equifax, like all enterprises, is facing a different monumental cybersecurity challenge, one that sees AI facilitating attacks at a scale never seen before, altering companies\u2019 security postures with its rapid internal adoption, and, now, with the latest advanced models, showing its potential to <a href=\"https:\/\/www.csoonline.com\/article\/4206116\/meta-joins-openai-anthropic-in-latest-ai-test-breach.html\">escape controls and attack other companies<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The person leading Equifax\u2019s response to this challenge is EVP and CISO <a href=\"https:\/\/www.linkedin.com\/in\/jeremy-koppen-506ba733\/\">Jeremy Koppen<\/a>, who spent 13 years at Mandiant.<\/p>\n<p class=\"wp-block-paragraph\">Koppen came on board in May 2025, just in time for the AI threat to start getting real.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWith the increase of AI capabilities, we\u2019ve seen an increase in external attacks,\u201d he tells CSO. \u201cI was just looking through the numbers, and we\u2019ve had about a 30% volume spike driven by automation.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Meanwhile, if there\u2019s a known vulnerability out there, companies have <a href=\"https:\/\/www.csoonline.com\/article\/4156005\/patch-windows-collapse-as-time-to-exploit-accelerates.html\">less time than ever to patch it<\/a>, Koppen notes. \u201cThe mean time for an exploitation of a vulnerability is shrinking with the rise of new technology,\u201d he says. \u201cSo that\u2019s top of mind.\u201d<\/p>\n<p class=\"wp-block-paragraph\">To deal with the growth of AI-related risks and threats, as well as all the traditional threats still out there, Equifax is <a href=\"https:\/\/www.csoonline.com\/article\/4204101\/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html\">doubling down on basic cybersecurity hygiene<\/a> and using AI itself.<\/p>\n<p class=\"wp-block-paragraph\">For example, Equifax is expanding has its passwordless strategy, which covers all 22,000 employees and contractors, to its business partners as well. \u201cThat\u2019s been a critical piece, where we know we don\u2019t have that social engineering aspect,\u201d Koppen says. \u201cDefinitely having passwordless has been a big implementation for our team.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Also this year, Equifax has rolled out a map of business exposure, which uses a quantitative risk engine to examine risk data and business data to figure out where the problems are and how they could impact the business.<\/p>\n<p class=\"wp-block-paragraph\">That includes addressing the shrinking patching window, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe can make sure we\u2019re prioritizing and reducing that risk,\u201d he says. \u201cMaybe an asset is externally facing and that would increase the risk. But if it\u2019s shielded by multiple layers of defense in depth and controls, then you get additional levers in what you can do.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Putting AI to work<\/h2>\n<p class=\"wp-block-paragraph\">To help its security teams contend with the rising number of alerts and scans, which now number 19.8 million per day, Koppen says, Equifax is turning to AI.<\/p>\n<p class=\"wp-block-paragraph\">Today, 50% of security operations center (SOC) incident tickets are handled automatically, enabling human analysts to focus on the most critical ones. AI also provides knowledge and context to help analysts hit the ground running and reduce the time it takes to process them.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe can use AI to help remediate,\u201d Koppen says, \u201cbut it\u2019s not replacing that human in the loop. You still need that verification to ensure that you know this is correct. And if we fix this piece, what are the additional impacts it may have.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Automation is also used to help other areas of security. For example, that certificate problem that contributed to the 2017 breach? According to the <a href=\"https:\/\/investor.equifax.com\/news-events\/press-releases\/detail\/1399\/equifax-releases-2025-security-annual-report\">company\u2019s annual security report<\/a>, released in March, Equifax has launched a certificate management tool to automatically renew and test TLS certificates.<\/p>\n<p class=\"wp-block-paragraph\">Koppen is also responsible for the security of the software Equifax produces, an area that\u2019s also being transformed by AI.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn a standard process, you\u2019d have a design diagram of how things would work and there\u2019s integration with security, and you go back and forth,\u201d he says. But with AI accelerating the pace at which attackers can probe code for vulnerabilities, there\u2019s less time to address code security issues, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe can use AI in that process as well,\u201d Koppen says, noting how AI has helped Equifax perform code review earlier in the design process, ensuring adequate guardrails are built in and reducing the time that process takes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt used to be 46 days and now we\u2019re down to 18,\u201d Koppen says. \u201cIt\u2019s great to be able to save that time but have a result that we\u2019ve verified with a human in the loop and with the security guardrails.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Overall, according to the company\u2019s annual security report, security consult times are down by 61%, and Equifax\u2019s AI agents analyze container vulnerabilities and automatically write the code fixes. The system is now handling more than 213,000 findings annually without slowing down delivery.<\/p>\n<p class=\"wp-block-paragraph\">The report also mentions a new attack vector related to AI. The company\u2019s attack simulation team discovered that adversaries could embed invisible text prompts to trick AI models into delivering malware. Equifax built a live prevention control to strip out these hidden commands before they can do any damage.<\/p>\n<h2 class=\"wp-block-heading\">Watching out for rogue AI<\/h2>\n<p class=\"wp-block-paragraph\">Then there\u2019s the flip side of AI. Having an AI agent that can discover new security vulnerabilities is all well and good when it\u2019s working as expected.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe want to be able to do that review on our own environments, to make sure we\u2019re identifying any potential vulnerabilities before they\u2019re announced to the public,\u201d Koppen says. \u201cBecause we know attackers are going to be doing that.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Unfortunately, as frontier labs have found out, an agent that\u2019s good enough to find a weakness in your environment might also be able to find a weakness in its own guardrails and controls.<\/p>\n<p class=\"wp-block-paragraph\">But there are techniques that companies can use to protect themselves, Koppen says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen we\u2019re using agents, we want to make sure we lock down what the agent can get to,\u201d he explains, referring to identity-based control, which is not new. \u201cThat\u2019s key from 20 years ago. I think it\u2019s just more imperative now to have those be implemented.\u201d<\/p>\n<p class=\"wp-block-paragraph\">And companies have long had to have protections in place to make sure that data wasn\u2019t being exfiltrated \u2014 or that the company\u2019s infrastructure wasn\u2019t being used as a staging ground for attacks against third parties.<\/p>\n<p class=\"wp-block-paragraph\">Today, of course, there\u2019s a new AI twist to it.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI think about it from a network perspective,\u201d Koppen says. \u201cThat\u2019s key, that\u2019s the first control we have, making sure that we\u2019re locking down the agent so it can\u2019t escape outside of that zone.\u201d<\/p>\n<p class=\"wp-block-paragraph\">According to the company\u2019s security report, manual gatekeeping has been replaced with policy-as-code, with every new agent automatically tested before production, with human-in-the-loop approvals for high-stakes use cases. In addition, there\u2019s continuous monitoring to stop a model if it begins to drift or behave unpredictably, and <a href=\"https:\/\/www.csoonline.com\/article\/4205348\/why-you-need-a-reliable-ai-agent-kill-switch.html\">automated kill switches<\/a> with instant rollback capabilities.<\/p>\n<p class=\"wp-block-paragraph\">Koppen says he\u2019s been watching the situation with the escaping agents from OpenAI and Anthropic. Any sources of information about how to protect the environment is good, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou know, that\u2019s been an exciting thing, with the community very open and communicating and sharing,\u201d he says. \u201cIt\u2019s been a really refreshing thing, just seeing that collaboration.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>For nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.4 billion on cleanup costs. Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certificate, and poor governance. One company Equifax brought in to help [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9221,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9220"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9220"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9221"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}