Alex Levy, chief information security officer at BNSF Railway, has been named the inaugural TIME + Commvault CISO of the Year. The award launched in March 2026 and drew more than 200 nominees, according to Progressive Railroading. It recognizes the expanding role of security chiefs as they face new risks from AI, cyber threats and increasingly complex technology.
The numbers behind the recognition are modest but specific. One award, launched in March. More than 200 nominees. One winner, selected by Commvault and a panel of industry experts. For a sector that rarely appears in security award coverage, the result puts a freight railroad's security leadership at the top of a broad field.
Levy leads a team of cybersecurity, AI and software engineers through bnsf | tech, a division of BNSF. The railroad describes itself as a critical infrastructure provider, and Levy's own statement made the same framing: protecting BNSF's systems and data, he said, is essential to economic resilience and national security. This connects to our earlier piece, How to read a data breach notification without panicking.
Why the award exists
TIME and Commvault created the CISO of the Year award in March 2026. The stated purpose is to recognize how the job has changed. According to Progressive Railroading, the award cites new risks presented by AI, cyber threats and increasingly complex technology.
Bill O'Connell, chief security officer at Commvault, framed the pressure in the press release announcing the result. "Today's CISOs are balancing the rapid adoption of AI with a surge in sophisticated, AI-driven automated threats, underscoring the need to operationalize resilience and recovery," he said. He called the recognition a testament to Levy's "vision for an active, unified approach that enables BNSF to protect and recover at machine speed."
That language matters for readers outside the vendor world. The award's sponsors are pointing at a specific shift: security teams are no longer judged only on prevention. Recovery speed, and the ability to restore operations after an incident, is now part of the measured job.
What the record establishes, and what it does not
The documented record is narrow, and it is worth stating plainly.
- Levy holds the CISO role at BNSF Railway and leads security, AI and software engineering through the bnsf | tech division.
- He was selected by Commvault and a panel of industry experts from among more than 200 nominees.
- The award is the first of its kind; there is no prior winner to compare him against.
What the record does not establish: the selection criteria in detail, the identity of other nominees or finalists, or any independent assessment of BNSF's security posture. The sourcing is a press release relayed by trade press. That is a normal way for an award to reach the public, but it means the claim rests on the sponsors' own account. Readers should read it as a vendor-and-panel judgment, not an audit.
No security incident at BNSF is referenced in the record, in either direction. The award is a leadership recognition, not a statement that the railroad has faced, or avoided, any specific attack.
Why it matters beyond one railroad
Freight rail is critical infrastructure, and BNSF says as much in its own statement. Levy called BNSF "a vital role" in powering the U.S. economy and the supply chains that communities and businesses depend on. Whether that framing holds up as policy is a question for another record. What is documented is that a major railroad's top security officer has now been publicly recognized by a national magazine and a data-management vendor for work that spans AI adoption and recovery from AI-driven threats.
The practical takeaway for security teams in any sector is the emphasis on recovery. The award's sponsors highlighted resilience and recovery at machine speed alongside protection. Teams reviewing their own posture can apply the same lens: prevention is half the job, and tested recovery is the other half. Our 3-2-1 backup guide covers the small-team version of that discipline.
For readers tracking how security leadership is being measured across industries, this is a data point worth noting: a new award, a large nominee pool, and a critical-infrastructure winner in its first year. Follow future coverage in our cybersecurity news section and our broader security coverage. For related coverage, see The monthly personal security checklist: 20 minutes, first Saturday.

