From BNSF’s CISO Alex Levy: "The security advice I actually give my family”

Highlighting our commitment to safety, service, innovation, people, communities and our heritage.

Date
Oct 05, 2026

Read Time
6 mins.






By ALEX LEVY

Alex Levy is Chief Information Security Officer at BNSF Railway, where he is leading the charge on enterprise resilience in the face of increasing threats to businesses’ cybersecurity. In September, Levy was named the inaugural TIME + Commvault CISO of the Year for exemplifying the next generation of cybersecurity leadership.

October is Cybersecurity Awareness Month, and each year around this time, the same posters go up: “Think before you click.” True, but useless. Nobody ever decided to click recklessly. What people need is a short list of things that actually move the needle, in the order that matters, explained without jargon.

Here’s the list I give to friends, to my parents and to my own kids. You do not need to be technically savvy to follow it or do all of it this week. If you do the first three things you will have eliminated the majority of ways ordinary people open themselves up to vulnerabilities online.

First, the honest threat model

You are almost certainly not being targeted by a nation-state. What is actually coming for you is much less dramatic, and much more common:

  1. Credential stuffing: A company you signed up with years ago gets breached. Your email and password are now on a list. Criminals automatically try that same pair on hundreds of other sites to see what opens.

  2. Phishing: A message that looks like it comes from your bank, your boss, your child’s school or a delivery company, designed to get you to type a password or approve a login.

  3. Account takeover of your email or phone number: These two are the master keys to everything else you own.

  4. Scams that target humans, not computers: Fake invoices, romance scams, “grandparent” calls, fraudulent job offers, crypto “opportunities.”

Almost none of this requires anyone to hack anything like you see in the movies. It requires you to reuse a password, approve a prompt or believe a message. That is good news, because it means the defenses are within your reach.

The three things that matter most

If you stop reading after this section, you will still have done the important part.

1. Never reuse a password, use a password manager to make that possible

Password reuse is the single biggest self-inflicted wound in personal security. One breach anywhere becomes a breach everywhere.

Humans cannot remember 100 unique passwords, so don’t try. Use a password manager. The well-known ones (1Password, Bitwarden, Proton Pass, and the managers built into Apple, Google and Microsoft accounts all generate long random passwords, encrypt them before storing and fill them in for you. Bitwarden has a solid free tier if cost is a concern.

A few practical notes:

Let it generate the passwords. The point is they are random and unique. You will never type them, so it does not matter that they look like k9!vTz#2qLpW, for example.

Your master password is the exception. Make it a passphrase: four or five unrelated words strung together, like “copper-lantern-mango-drift.” Long and memorable beats, short and cryptic.

Password managers also spot reuse. Most will audit your saved logins and tell you which passwords are weak, duplicated or known to be in a breach. Work on changing the passwords on that list, over a few sittings if needed. 

“But what if the password manager gets breached?” It is a fair question, and the answer is that the alternative is worse. Your vault is encrypted with a key derived from your master password, which the vendor does not have. Reusing Summer2024! across 40 sites is a certainty of harm; a password manager is a small, well-defended risk.

Check whether your email address shows up in known breaches at haveibeenpwned.com. It’s free, legitimate and run by a well-respected researcher. Expect to find something. Everyone does.

2. Turn on multi-factor authentication, use good factors

Multi-factor authentication (MFA) means a stolen password alone is not enough. Not all factors are equal, so here they are from best to worst:

Passkeys (best). A passkey replaces the password entirely with a cryptographic key stored on your phone, laptop or security key, unlocked by your face or fingerprint. Passkeys cannot be phished, because there’s nothing to type and nothing to hand over. Where a site offers a passkey, take it. Support is now broad: Google, Apple, Microsoft, Amazon, PayPal and many banks offer it.

Hardware security keys (also best): These are physical keys like YubiKey and worth it for your primary email and financial accounts if you want the strongest option

Authenticator apps (good): These are six-digit codes from an app such as Google Authenticator, Microsoft Authenticator, Authy or your password manager. Technically still phishable if you are tricked into typing the code into a fake site, but it’s a large improvement over nothing.

Push approvals (good, with a caveat): “Approve this sign-in?” prompts are convenient, but attackers spam them hoping you tap “yes” out of annoyance. Rule for the whole family: if a prompt appears and you did not just try to log in, deny it and change that password.

SMS codes (better than nothing). Vulnerable to SIM swapping, where someone convinces your carrier to move your number to their device. Use SMS only when nothing else is offered.

3. Fortify your email and your phone number first

Everything else resets through these two. If someone owns your email, they can request password resets across your whole digital life. If someone owns your phone number, they can intercept the reset codes.

For your primary email account: use the strongest available MFA, a unique password and a look through the account’s recovery settings to make sure the backup email and phone on file are still yours and current. While there, check for forwarding rules or “connected apps” you do not recognize; attackers love to set up silent forwarding.

For your phone number: call your mobile carrier and ask for a port-out PIN or number lock on the account. It takes five minutes and it defeats the most common SIM swap. Set a device passcode of six digits or more, not four, and never a birthday.

The next tier: solid, unglamorous habits

Keep things updated. Turn on automatic updates for your phone, computer and browser. Most successful attacks exploit flaws that were patched months earlier. When a device stops receiving security updates, that is its real end of life, regardless of whether it still turns on.

Lock down your money separately. Freeze your credit at all three bureaus (Equifax, Experian and TransUnion). It’s free, takes about 15 minutes online, and you can thaw it temporarily when you need your credit run. Freeze your children’s credit too, because child identity theft often goes unnoticed for a decade. Turn on transaction alerts at your bank and card issuers so you see charges in real time.

Adopt a verification rule and never break it. Any request involving money, credentials or urgency gets verified through a channel you chose, not one they gave you. Hang up and call the number on the back of your card. Text your daughter on the number you already have. This one rule defeats fake invoices, romance scams and the AI voice-cloning calls that are now genuinely convincing. 

Agree on a family code word. Cloning a voice takes seconds of audio from social media, so pick a word or phrase that  a caller in distress would know and a scammer would not. 

Back up your important things. Photos, documents, tax records, etc. The simple solution: one copy in a reputable cloud service with MFA turned on and one copy on an external drive that is not always plugged in. Ransomware cannot affect a drive sitting in a drawer.

Tidy your home network. Change the router’s admin password away from the default, turn on automatic firmware updates if offered and use WPA3 or WPA2 (the latest WiFi security protocols) with a long passphrase. Put smart TVs, cameras, doorbells and other gadgets on the guest network so a compromised device cannot reach your laptop. Replace routers that no longer receive updates.

Reduce your exposure. Delete accounts you no longer use. Review app permissions on your phone once or twice a year and revoke location, microphone, contacts and photo access that are not needed. Consider opting out of the larger data broker sites or paying a service to do it for you if the manual process is too tedious.

Be skeptical of search results and sponsored links. A growing share of scams starts with someone searching “Netflix customer support” and calling the number in a paid ad. Navigate to companies by typing the address or using a saved bookmark.

Talking to kids about cyber hygiene

Technical controls matter less here than the relationship does. Filters and parental controls are a speed bump, not a wall, and every kid eventually finds a way around them. What protects children is knowing that they can come to you.

Set the tone early and explicitly. Tell them, in these words: You will never be in trouble for telling me something went wrong online. Not ever. I will help you fix it. Repeat it periodically. The entire criminal model of online exploitation depends on a child believing they cannot tell a parent.

Teach a few rules that generalize. People online are not always who they say they are. Anything you send can be saved and shared, no matter what the app promises. Free things in games are usually a way to get your account or your parents’ card. Nobody legitimate asks a child to keep a secret from their parents.

Beware of common, organized crime aimed at teenagers, especially boys. The pattern is a friendly stranger, a rapid move to a private app, a request for an image and then threats to send it to everyone the child knows unless they pay. If it happens: do not pay, do not delete the messages, do not let the child handle it alone and instead report it to the platform and to the FBI or the NCMEC CyberTipline. Paying does not stop it. Telling someone does.

Match the controls to the age. Screen time limits, app store approvals and content filters make sense for younger children. As they get older, shift from surveillance to conversation; a teenager who understands “why” is more protected than one who is merely blocked.

Give them their own good habits. Their own password manager entry, unique passwords for game and social accounts and MFA on anything with a payment method attached. Game account theft is often an unfortunate rite of passage. 

Helping older relatives

Older adults lose far more money per incident than any other group, mostly to phone and message scams rather than technical compromise.

Set their devices up for them with automatic updates, MFA on email and banking, and a password manager that you help them maintain. Next, focus on the social side: stress the importance of never acting on an urgent financial request without calling you first, and make clear that you will never be annoyed by that call. Normalize hanging up. Legitimate institutions do not mind being called back; scammers cannot survive it.

BNSF’s Alex Levy is the Commvault + TIME Chief Information Security Officer of the Year.
BNSF’s Alex Levy is the Commvault + TIME Chief Information Security Officer of the Year.

If something goes wrong

Speed matters more than perfection.

1. Change the password on the affected account from a device you trust and sign out all other sessions.

2. Change the password on your email if there is any chance it was involved.

3. Turn on or reset MFA and check for unfamiliar recovery addresses, phone numbers or forwarding rules.

4. Call your bank directly if money is involved and ask about reversing transactions; some windows are measured in hours.

5. Report it. In the United States, that is reportfraud.ftc.gov for fraud, identitytheft.gov for identity theft and ic3.gov for internet crime.

6. Tell people who might be targeted next. Attackers use a compromised account to reach the contacts inside it.

Do not spend the first hour being embarrassed. Even well-trained professionals get caught by good phishing; it is a designed experience, not a character flaw.

A realistic plan

This weekend (about two hours): Install a password manager, fix the passwords on your email, banking and your primary social accounts, turn on the strongest MFA those accounts offer and set a port-out PIN with your mobile carrier.

This month: Freeze your credit and your children’s, turn on bank alerts, enable automatic updates everywhere, secure the router and work through the password manager’s list of reused passwords.

This quarter: Set up backups, prune old accounts and app permissions, add passkeys wherever they are offered and have a family conversation about code words and the never-in-trouble rule.

Ongoing: Verify anything urgent through a channel you chose.

That is the whole program. None of it is exotic, all of it compounds. The goal is not to be unhackable; it is to be a harder target and to have already decided what you will do on the day something slips through.

 

Picture Perfect: 2026 BNSF Summer Photo Contest winners

Read More

BNSF railroaders create place of peace for Gold Star Aberdeen, South Dakota, families

Read More

Freeze frame: Photos capture BNSF trains in winter wonderlands

Read More