Equifax Harnesses AI to Strengthen Cybersecurity Measures and Mitigate Threats

Aug 25, 2026 859 views

Equifax continues to navigate the implications of a massive cybersecurity breach that marred its reputation and cost over $1.4 billion in remediation efforts. The fallout from the incident, which was exacerbated by a flawed patch management process and inadequate governance, remains a cautionary tale in the industry. To bolster its defenses, the company enlisted Mandiant, a security firm now integrated into Google Cloud, to improve its cybersecurity posture.

Fast forward to today, and Equifax is grappling with a new breed of threats fueled by artificial intelligence. The pace of these attacks has escalated, transforming the cybersecurity landscape as adversaries exploit vulnerabilities with unprecedented speed. Jeremy Koppen, Equifax's Executive Vice President and Chief Information Security Officer (CISO), is at the forefront, implementing strategic responses to these emerging challenges.

Koppen, who previously spent 13 years at Mandiant, observed a staggering 30% increase in external attacks attributed to automation. As the time window for patching vulnerabilities shrinks, organizations must act swiftly. "The mean time for an exploitation of a vulnerability is shrinking with the rise of new technology," he notes, underscoring the urgency of effective vulnerability management.

Strengthening Cyber Hygiene with AI

In response to the growing volume and sophistication of threats, Equifax is prioritizing basic cybersecurity hygiene while incorporating AI technologies into its operations. This includes expanding a passwordless strategy that now extends to 22,000 employees and contractors, thus reducing the risks associated with social engineering attacks.

Equifax has also introduced an innovative tool known as the business exposure map, which employs a quantitative risk engine to assess potential business impacts based on risk data. This tool aids in mitigating the challenges posed by the diminishing timeframe for implementing patches and other security measures.

"We can make sure we’re prioritizing and reducing that risk," Koppen explains. The system allows the organization to evaluate the risk based on the nature of the asset and the controls in place, effectively strengthening their defense mechanisms.

Leveraging AI for Operational Efficiency

To enhance the productivity of its security operations center (SOC), Equifax deploys AI to sift through an astonishing 19.8 million alerts and scans daily. Currently, AI handles 50% of incident ticketing on its own, freeing human analysts to concentrate on higher-priority concerns. This not only streamlines the workflow but also enriches the context of alerts, allowing for quicker response times.

Koppen emphasizes the importance of human oversight, stating, "We can use AI to help remediate, but it’s not replacing that human in the loop." This ensures all fixes are verified for security compliance while addressing potential ramifications.

Furthermore, automating tasks in other facets of security management has paid dividends. Equifax has implemented a certificate management tool to tackle issues that previously contributed to security lapses, such as the expired certificate that facilitated the infamous breach in 2017.

Under Koppen's leadership, the software development lifecycle has also witnessed enhancements due to AI integration. The timeline for conducting security code reviews has drastically reduced from 46 days to just 18, thanks to AI's capability to perform early examinations of code in the design phase. "It’s great to be able to save that time but have a result that we’ve verified with a human in the loop," he adds.

Overall, Equifax's annual security report reveals a significant reduction in consultation times by 61%. The company’s AI agents are now proficient at analyzing container vulnerabilities and generating code fixes autonomously, handling over 213,000 findings each year without impeding delivery timelines.

Guarding Against Malicious AI

While AI offers avenues for improved security, it also presents new challenges. Equifax’s security team discovered that adversaries might embed covert prompts to manipulate AI models for malicious purposes. In response, the company has developed proactive measures to intercept these hidden commands before they can cause harm.

Koppen stresses the need for vigilance, indicating that while AI can discover new vulnerabilities, it can similarly find weaknesses in its own controls. Accordingly, securing these AI environments is paramount. "When we’re using agents, we want to make sure we lock down what the agent can get to," he asserts, reflecting on the necessity of identity-based controls.

Equifax has transitioned from manual safety measures to a policy-as-code approach, ensuring that every new AI agent undergoes rigorous testing prior to production. This includes real-time monitoring to halt any errant behaviors, along with automated kill switches to revert to previous states when necessary.

The shift in strategy doesn't come without challenges. However, there’s been an encouraging trend towards collaboration within the tech community to share insights on safeguarding against rogue AI behavior. “It’s been really refreshing, just seeing that collaboration,” says Koppen, highlighting the value of communal knowledge as industries collectively tackle these new frontiers in cybersecurity.

Source: Robert Miller · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

How Equifax is using AI to elevate its cybersecurity