Leader profile2015 – present10 sources

Jamil Farshchi

CISO, later CTO (Home Depot, Equifax)

Roles and dates

Compiled from the sources listed at the foot of this page. Where a date is unconfirmed in the public record, the entry says so.

  • Deputy chief information assurance officerNASAbefore 2015
  • Chief Information Security OfficerLos Alamos National Laboratorybefore 2015
  • Vice president, global information securityVisabefore 2015
  • First global Chief Information Security OfficerTime Warnerbefore 2015
  • Chief Information Security OfficerThe Home DepotMarch 2015 – February 2018
  • Chief Information Security Officer (reporting to the CEO)EquifaxFebruary 2018 – 2024
  • Executive Vice President and Chief Technology Officer (initially retaining the CISO remit)Equifax1 March 2024 –

Situation and mandate

FACT Farshchi joined The Home Depot as CISO in March 2015, roughly six months after the 2014 breach of 56 million payment cards [10]. He left in February 2018 to become CISO of Equifax, announced on 12 February 2018, about five months after Equifax disclosed the breach of 2017 [6]. On 1 March 2024 he became Equifax's Executive Vice President and Chief Technology Officer, initially retaining the CISO remit [4][10]. In 2025 Equifax appointed a separate Chief Information Security Officer, Jeremy Koppen [8][9]; Equifax's corporate leadership page now lists Farshchi as "EVP, Chief Technology Officer" and Koppen as "EVP, Chief Information Security Officer" [7].

This is the course's cleanest documented case of the post-crisis mandate, taken twice. In both companies the reporting line, the budget, the board's attention and the internal information environment had already been reset by a public failure before he arrived. He said so himself, in May 2018: "Before a breach, your success is dependent on convincing people about the value of security. I don't have to do that" — and described his resources as "basically an open checkbook" [5].

INTERPRETATION That quotation is the most useful sentence in this profile, and not a flattering one. It says that the variable which usually constrains a CISO — the standing to be believed — was supplied by an event, not earned in the job. Everything below should be read as what a well-resourced post-breach security chair can build, not as what security leadership generally can achieve.

Documented decisions

1. He took two consecutive post-breach rebuilds rather than a clean estate. Home Depot in 2015, Equifax in 2018 [6][10]. INTERPRETATION Choosing the burning building twice is a fit decision: it selects for the conditions under which this leader's settings work, and it is the single most transferable observation in the profile — for the learner as well as the board.

2. The reporting line was made structural, not personal. CEO Mark Begor's Senate testimony of 7 March 2019 records that Equifax's CISO reports directly to the CEO [1]; Axios reported in May 2018 that the role carried a direct line to the CEO and the board [5]. This is a governance change made at hire, before any program existed.

3. An incremental $1.25 billion of security and technology spending was committed for 2018–2020. Recorded in the same testimony, along with "nearly 1,000" IT and security professionals added during 2018 [1]. The figure is the company's, stated to Congress.

4. Company-wide security goals were attached to the bonuses of 3,900 employees. Also on the congressional record [1]. INTERPRETATION This is the most copied and least examined mechanism in the case: it converts a security objective into a compensation term for people who do not work in security, and it is a compliance lever rather than a values lever.

5. A "Board Cyber Audit Framework" of programmatic and operational metrics was developed by the CISO. Begor's testimony attributes the framework to the CISO and describes it as the instrument by which the board evaluates the program [1]. INTERPRETATION A named, repeatable reporting format that the board adopts is the mechanism by which a post-crisis mandate outlives the crisis.

6. The program was published externally, annually, from 2020. Equifax has issued a Security Annual Report every year since 2020 [2][10]. Voluntary external disclosure of a security program's metrics is unusual, and it is a decision with two edges: it creates an outside record, and it creates an incentive for the record to look good.

7. Passwordless authentication was deployed across the workforce, with a stated threat rationale. In the release for the 2024 report (27 March 2025), Farshchi — titled Chief Technology Officer and Chief Information Security Officer — said the company "modernized our defenses, accelerated Equifax Cloud adoption, and pushed the boundaries to future-proof the organization against AI impersonation tactics like voice cloning with the deployment of passwordless technology" [2]. Nearly 22,000 employees and contractors were moved to passwordless authentication [2].

8. He moved from the security chair to the technology chair, and the security chair was then separated. EVP and CTO from 1 March 2024, initially with the CISO remit [4][10]; a dedicated CISO appointed in 2025 [8][9]. FACT, not interpretation: no public source explains the sequence. It is recorded here because the shape of it — the post-breach CISO becoming the CTO, and the CISO role then being refilled as a standalone executive job — is a structural pattern worth studying, not because anyone has said why.

Reported results

Every figure in this section is company-reported. Security "maturity" and "posture" scores are produced by benchmarking tools, not by independent audit, and Equifax selects what to publish.

From the 2024 Security Annual Report release, 27 March 2025 [2]: Equifax states it "outperformed all major industry benchmarks related to its security maturity score" for a fifth consecutive year and maintained "a security posture score that exceeded Technology and Financial Services industry averages"; mean time to detect under one minute; nearly 22,000 employees and contractors on passwordless authentication; an average of 15 million cyber threats defended against daily (about 175 hostile attempts per second), a 25% increase on 2023; more than 210,000 phishing simulations with a 2.9% click rate.

From the 2025 Security Annual Report release, 18 March 2026 [3] — issued after a separate CISO was in post, so it describes the company, not this executive: a security posture score exceeding Technology and Financial Services industry averages for a sixth consecutive year; a NIST Cybersecurity Framework score of 4.4; mean time to detect kept below one minute; an average of 19.8 million threats defended against daily, up 30% year on year; an AI triage agent auto-resolving nearly half of security operations centre tickets; security consult times down 61%. CEO Mark Begor states in the same release that the "$3 billion global security and technology transformation and the creation of the Equifax Cloud" is "principally complete" [3].

INTERPRETATION Read these as evidence of what a company chose to measure and publish, which is itself informative — a CISO who can get the board to adopt a metric set has changed the governance, whatever the numbers say. Read none of them as evidence that the program prevented anything. Detection time under one minute is a statement about telemetry, not about outcomes.

What is contested or thinly documented

No legal action or disputed incident handling attributed to him personally appears in the sources reviewed [10]. Five flags.

Outcome evidence is entirely company-reported. There is no independent measurement of Equifax's security posture in the public record, and the benchmark scores come from vendor tooling [2][3][10].

Attribution is loose. Begor's testimony records decisions made by Equifax around the CISO hire [1]. The $1.25 billion, the 1,000 hires and the bonus linkage were board and CEO decisions as much as CISO decisions; only the Board Cyber Audit Framework is attributed to the CISO in that document.

The open checkbook limits generalization. The record shows what an extremely well-resourced post-breach CISO can build. It shows nothing about a resource-constrained one, which is the condition of most of this course's learners [10].

Visibility. He is a high-profile personal brand, which is one reason he is documentable and one reason this profile exists. That is the course's selection-bias lesson applied to the course's own reading list [10].

The role transition is unexplained. Nothing public states why the combined CTO/CISO remit was split, and learners should resist the temptation to read a story into it in either direction [7][8][9].

What it teaches

Trait Dial (INTERPRETATION, inferred from the decisions above)

INTERPRETATION— inferred from documented decisions and mechanisms only.

Centralization ↔ decentralization: toward centralization. A single board metrics framework owned by the CISO (decision 5) and enterprise-wide identity change (decision 7) are centralizing moves.

Aggression ↔ caution: toward aggression on investment. A $1.25 billion incremental commitment and 1,000 hires in a year is a spend posture, not a caution posture (decision 3).

Decisiveness ↔ inquiry: toward decisiveness. The mechanisms were installed early and structurally — reporting line, bonus linkage, board framework — rather than after a discovery period (decisions 2, 4, 5).

Urgency ↔ patience: toward urgency, moderated by the multi-year shape of the spend and the annual reporting cadence (decisions 3, 6).

Overlays. Control ↔ Enablement: toward control, appropriately, for a season — the post-breach mandate is a control mandate. Prevention ↔ Resilience: the published metrics are detection-weighted (mean time to detect, threats defended), which is a prevention-and-detection posture; recovery metrics are not published.

Maturity Model

FRAMEWORK The record illustrates Level 4 — Fit more than any other level, and specifically the turnaround fit. The mandate, the reporting line, the budget and the information environment were all set to the settings this leader's decisions require, by an event, before arrival. On Player → Coach → Architect, the Equifax work is Architect: governance, portfolio, board reporting, an enterprise identity programme.

The Level 3 — Maturity question the case poses is the one the profile cannot answer from outside: what happens when the crisis fades. Post-breach settings — centralization, urgency, decisiveness, a control posture — are correct for a season and become a bottleneck afterwards. The published record shows the settings; it does not show whether they were re-calibrated.

Fit

Reporting line. CEO-direct, with board access, from the first day (decision 2). This is the structural counterpart to the profile's whole argument: the discretion was designed into the job before the person occupied it.

Regulator. Consumer-data and credit reporting, under intense legislative and regulatory attention after 2017; a CEO testifying to a Senate subcommittee about the security program is itself a description of the governance environment [1].

Stage. Post-breach turnaround, then a long second phase — the harder one — in which attention decays and the program has to survive on governance rather than on alarm. The Security Annual Report (decision 6) is best read as a mechanism against that decay.

Information environment

A post-breach information environment is unusual in a specific way: bad news is cheap to deliver upward, because everyone above you already believes the worst. That is the condition Farshchi describes in the "I don't have to do that" quotation [5]. The failure mode is the mirror image of the ordinary one — not silence, but attention that outruns judgment, and a board that will fund anything labelled security for about two years. The Board Cyber Audit Framework and the annual report are both mechanisms for converting temporary attention into permanent format.

Two-Sentence Test and the Risk Corollary

"We're going to do this" is the easy sentence in a post-breach company; the open checkbook says it for you. The hard sentence is the second one, and the hardest version of it here is organizational: the crisis is over, and the settings that got us here are now costing more than they buy. Nothing in the public record shows that sentence being said, which is not evidence that it was not. The Risk Corollary is the test of the second phase: a post-breach CISO who can only say "No — this is what the breach taught us" has converted an event into an identity, and the board will eventually stop listening.

Discussion questions

  1. The "open checkbook" quotation describes discretion supplied by an event. Which of your own current mechanisms would survive if the discretion supplying them disappeared next quarter?
  2. Bonus linkage for 3,900 employees is the most copied mechanism in this case. What behaviour would it actually produce in your organization — and how would you tell the difference between compliance and adoption?
  3. Equifax publishes an annual security report. Write the first page of yours. Which number would you least want to publish, and what does your reluctance tell you?
  4. "Mean time to detect under one minute" is a company-reported figure. What would you need to see to treat it as evidence, and what does that requirement tell you about the metrics you currently give your own board?
  5. If you were on the Equifax board in 2022, what question would you have asked to find out whether the post-breach settings were still correct?

Sources

  1. Testimony of Mark W. Begor, Chief Executive Officer, Equifax Inc., US Senate Permanent Subcommittee on Investigations, 7 March 2019 (PDF) — https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/Begor%20Testimony.pdf (primary, congressional record; reporting line, $1.25B, ~1,000 hires, 3,900 bonus linkage, Board Cyber Audit Framework)
  2. Equifax, "Equifax Releases 2024 Security Annual Report," 27 March 2025 — https://investor.equifax.com/news-events/press-releases/detail/1348/equifax-releases-2024-security-annual-report (primary, company; verified 2026)
  3. Equifax, "Equifax Releases 2025 Security Annual Report," 18 March 2026 — https://investor.equifax.com/news-events/press-releases/detail/1399/equifax-releases-2025-security-annual-report (primary, company; verified 2026)
  4. Equifax official biography, Jamil Farshchi (PDF) — https://assets.equifax.com/marketing/US/assets/jamil-Farshchi-Web-Bio.pdf (primary, company)
  5. Axios, "Equifax's new head of cyber enjoys direct line to CEO, board," 22 May 2018 — https://www.axios.com/2018/05/22/equifax-chief-information-security-officer-ceo-board ("open checkbook"; "I don't have to do that")
  6. SecurityWeek, "Equifax Hires Former Home Depot Security Chief Jamil Farshchi as CISO," 12 February 2018 — https://www.securityweek.com/equifax-hires-former-home-depot-security-chief-jamil-farshchi-ciso/
  7. Equifax, "Corporate Leadership" — https://www.equifax.com/about-equifax/leadership/ (primary, company; current titles verified 2026)
  8. Equifax, "Equifax Appoints New Chief Information Security Officer to Lead its Best-in-Class Security Program" — https://www.equifax.com/newsroom/all-news/-/story/equifax-appoints-new-chief-information-security-officer-to-lead-its-best-in-class-security-program/ (primary, company)
  9. CDO Magazine, "Equifax Appoints Jeremy Koppen as Chief Information Security Officer," updated 13 June 2025 — https://www.cdomagazine.tech/leadership-moves/equifax-appoints-jeremy-koppen-as-chief-information-security-officer
  10. research/leaders-shortlist.md, §2.2 (compiled role history; earlier roles at NASA, Los Alamos, Visa, Time Warner; the flags on company-reported outcomes, visibility and generalization) — internal research document

Numbered references match the bracketed markers in the text above. Links open the primary source where one exists; internal research files are named as such.

Related

Dials illustrated
centralization ↔ decentralizationaggression ↔ cautiondecisiveness ↔ inquiryurgency ↔ patienceinnovation ↔ operational discipline
Sectors
consumer data / credit reportingretailpaymentsgovernment / national laboratory