Equifax Leverages AI to Strengthen Cybersecurity Measures
Equifax's CISO Jeremy Koppen, who joined in May 2025, says AI now handles half the company's daily security workload. Here's what that looks like in practice.

Key points
- Equifax processes 19.8 million security alerts daily as of 2025.
- AI resolves 50% of security operations center tickets without human intervention.
- Security consult times have fallen 61% since AI was introduced.
- A 30% spike in external attacks, driven by automation, prompted the acceleration.
How is Equifax using AI to improve cybersecurity?
AI now closes half the incident tickets in Equifax's security operations center before a human analyst sees them, giving those analysts room to focus on cases that actually need judgement. The system also surfaces context so analysts aren't starting cold. Koppen told CSO Online the goal isn't replacement: "It's not replacing that human in the loop. You still need that verification."
The numbers behind the shift are worth sitting with. Equifax's attack-surface is 19.8 million alerts a day, security consult times are down 61%, and AI agents now handle more than 213,000 container-vulnerability findings a year. Code-security review time dropped from 46 days to 18.
The passwordless rollout covering all 22,000 employees and contractors has now extended to business partners, cutting the social-engineering surface that password-based auth leaves open.
What lessons has Equifax learned from past breaches?
The 2017 breach, which cost $1.4 billion to clean up, traced partly to an expired public-key certificate and a broken patching process. Equifax's response to the certificate problem is now automated: a certificate management tool renews and tests TLS certificates without manual input.
Koppen joined in May 2025 after 13 years at Mandiant, which Equifax had brought in after the breach. He's also introduced a quantitative risk engine that maps business exposure, letting the team weigh whether an externally facing asset is protected by enough layers to lower its priority. The patching window matters here: "The mean time for an exploitation of a vulnerability is shrinking," Koppen told CSO Online.
How is Equifax adapting to emerging AI threats?
AI threats cut two ways. Externally, Equifax's attack simulation team found that adversaries can embed invisible text prompts to manipulate AI models into delivering malware. The company built a live control to strip those hidden commands before they execute. We covered a related capability in Zhipu's GLM-5.3 model on 17 August, which demonstrated how the same technique works offensively.
Internally, the risk is an AI agent that's capable enough to probe its own guardrails. Koppen's answer is network-level containment: lock the agent to a defined zone so it can't reach outside it. Policy-as-code enforces that automatically, every new agent is tested before production, high-stakes actions require human approval, and automated kill switches with instant rollback handle anything that starts to drift.
Common questions
What steps is Equifax taking to prevent AI-based threats?
Equifax uses network-level containment to restrict what AI agents can access, policy-as-code to enforce security rules automatically, and a live control that strips invisible prompt-injection commands before they reach a model.
How has AI improved Equifax's incident response times?
Security consult times are down 61%, and code-security review dropped from 46 days to 18 days.
What measures are in place to handle rogue AI models?
Continuous monitoring watches for behavioural drift, and automated kill switches with instant rollback can shut a model down without waiting for a human to notice.



