Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Equifax Reinforces Cybersecurity Using AI: Strategies and Innovations

Equifax is transforming its cybersecurity approach by harnessing AI technology to tackle emerging threats and optimize its defenses.

Aug 25, 2026 | 3 min read
Sign in to save

Equifax has spent nearly a decade managing the fallout from one of the most significant cybersecurity breaches in US history, incurring cleanup costs of $1.4 billion. The breach, attributed to a series of operational failures, including a poorly managed patching process and an expired public-key certificate, has left a lasting impact on the company's approach to security.

As Equifax navigates the current cybersecurity landscape, it's now grappling with the evolving challenges posed by AI. With the rapid adoption of AI tools in security breaches, the stakes are higher than ever. Jeremy Koppen, the Executive Vice President and Chief Information Security Officer at Equifax, is at the forefront of this evolving challenge, having joined the company in May 2025. "With the increase of AI capabilities, we’ve seen an increase in external attacks," he notes, revealing a disturbing 30% surge in attack volumes attributed to automated processes.

Time is of the essence when it comes to addressing vulnerabilities, as the window for patching continues to shrink. "The mean time for an exploitation of a vulnerability is shrinking with the rise of new technology," Koppen adds, emphasizing the urgency of their proactive measures.

Enhancing Cyber Hygiene

In response to the increase in AI-related threats, Equifax is reinforcing its fundamental cybersecurity hygiene while also embracing AI technologies. A key initiative is the expansion of its passwordless authentication strategy to include business partners in addition to its 22,000 employees and contractors. Koppen attributes significant risk reduction to this implementation, minimizing susceptibility to social engineering attacks.

This year, the company also introduced a quantitative risk engine that maps business exposures based on risk and operational data, allowing them to prioritize vulnerabilities effectively. "We can make sure we’re prioritizing and reducing that risk," Koppen explains, detailing a layered defense strategy that helps minimize potential threats.

Leveraging AI in Operations

Equifax is increasingly relying on AI to manage the overwhelming number of daily security alerts, currently reaching 19.8 million. Approximately 50% of incident tickets in their security operations center are now processed automatically, freeing up human analysts to tackle more complex issues. "We still need that verification to ensure accuracy," Koppen insists, highlighting the importance of human oversight alongside AI-driven processes.

Automation is also pivotal in enhancing other security protocols. Following the certificate-related failure from the 2017 security breach, Equifax has established a certificate management tool designed to automate the renewal and verification of TLS certificates, thereby mitigating similar risks in the future.

Furthermore, Koppen oversees the security of Equifax's software development, an area markedly transformed by AI advancements. The integration of AI into early code review processes has cut the review timeline from 46 days down to just 18. This acceleration aligns with their focus on building secure frameworks from the outset. "It’s great to be able to save that time but have a result that we’ve verified with a human in the loop," he remarks.

According to Equifax's recent security report, they've also significantly decreased security consult times by 61%. Their AI tools now evaluate container vulnerabilities and can autonomously generate code fixes, effectively managing over 213,000 findings each year without triggering delays in delivery.

Mitigating AI-Driven Threats

While AI can identify new vulnerabilities effectively, it also introduces a new set of risks. "We want to be able to do that review on our own environments, to make sure we’re identifying any potential vulnerabilities before they’re announced to the public," Koppen clarifies, pointing out the necessity of preemptive strategies in the battle against increasingly sophisticated adversaries.

There remains the undeniable risk that AI agents capable of detecting vulnerabilities might also find weaknesses within their own security measures. To combat this, Equifax is implementing robust controls to restrict the activities and access of AI agents, applying identity-based access controls that have been crucial for years. “That’s key from 20 years ago," Koppen states, underscoring its renewed importance in today’s landscape.

Manual processes have evolved into policy-as-code systems that automatically test new agents before they enter production, ensuring a layered defense with human approval for high-stakes applications. Continuous monitoring mechanisms are also in place to identify and halt any AI model showing unpredictable behavior, supplemented by automated kill switches for rapid response.

Koppen is attentive to developments surrounding AI agents, mentioning the risks posed by escaping models from organizations such as OpenAI and Anthropic. He appreciates the collaborative atmosphere within the tech community regarding shared information on protective measures, calling it refreshing and vital in the fight against evolving AI threats.

The proactive steps taken by Equifax provide a blueprint for organizations facing similar cybersecurity challenges, leveraging AI not just as a tool for defense but as a strategic asset in safeguarding their infrastructure.

Source: Robert Brown · www.csoonline.com
Sign in to join the discussion.