What's Happening?
Alex Levy, Chief Information Security Officer at BNSF Railway and the inaugural TIME + Commvault CISO of the Year, has provided essential cybersecurity advice for families. This guidance comes during Cybersecurity Awareness Month, aiming to offer practical
and jargon-free steps to enhance personal online security. Levy emphasizes that most threats to individuals are not sophisticated nation-state attacks but rather common vulnerabilities like credential stuffing, phishing, account takeovers of email or phone numbers, and human-targeted scams. He highlights that these attacks often succeed due to password reuse, approving prompts without verification, or believing deceptive messages. The core of his advice focuses on three critical actions: never reusing passwords by utilizing a password manager, enabling multi-factor authentication (MFA) with strong factors like passkeys or hardware security keys, and fortifying email and phone numbers as they are master keys to other online accounts. Levy also provides advice for helping older relatives and teaching children about cyber hygiene, stressing the importance of open communication and verification rules for financial requests.
Why It's Important?
The widespread adoption of digital services for banking, communication, and personal data storage makes individuals and families increasingly vulnerable to cyber threats. Alex Levy's advice is crucial because it demystifies cybersecurity, making it accessible and actionable for the average American household. By focusing on practical steps like password managers and MFA, it empowers individuals to protect their financial assets, personal information, and digital identities. The emphasis on securing email and phone numbers is particularly significant, as these are often the entry points for attackers to gain control over an individual's entire digital life. Furthermore, the guidance for older adults, who are disproportionately targeted by financial scams, and for children, who are susceptible to online exploitation, addresses critical demographic vulnerabilities. Implementing these measures can significantly reduce the success rate of common cyberattacks, thereby safeguarding personal finances, preventing identity theft, and maintaining digital privacy for millions of Americans.
What's Next?
Individuals and families are encouraged to implement Levy's recommendations immediately. This includes dedicating time to install a password manager, update passwords for critical accounts (email, banking, social media), and activate the strongest available MFA. Within the month, further steps involve freezing credit reports for adults and children, enabling bank transaction alerts, and securing home routers. Quarterly actions include setting up data backups, reviewing app permissions, and adopting passkeys where offered. Ongoing vigilance requires verifying any urgent requests through pre-established, trusted channels. These continuous efforts aim to create a more resilient digital environment for families, making them harder targets for cybercriminals. The advice also suggests reporting incidents to relevant authorities like reportfraud.ftc.gov, identitytheft.gov, and ic3.gov, and informing contacts who might also be targeted after an account compromise.
Beyond the Headlines
Levy's advice transcends mere technical fixes, delving into the behavioral and social aspects of cybersecurity. His emphasis on normalizing hanging up on suspicious calls and establishing family code words for verification highlights the human element in preventing scams, especially those leveraging AI voice cloning. The guidance for parents to foster an environment where children feel safe reporting online issues, rather than fearing punishment, addresses the psychological manipulation tactics used by online predators. This approach recognizes that technology alone cannot solve all security problems; human awareness, critical thinking, and established communication protocols are equally vital. The long-term implication is a shift towards a more proactive and integrated approach to digital safety, where cybersecurity is not just an IT department's responsibility but a shared family value and a fundamental life skill in the digital age. This fosters a culture of continuous learning and adaptation to evolving cyber threats.













