Texas handed you a legal shield against data breaches, but you have to earn it first

By Don Oxman

Picture the worst Tuesday of your business life.

An employee clicks a link that looked like an invoice. By the time anyone notices, an attacker has been inside your network for a week, and the customer records you were trusted to protect are for sale online.

The cleanup is brutal. But the part that can actually end a business comes later, in a courtroom, when a plaintiff’s attorney argues you were careless and asks a jury to punish you for it.

That last part is where most small business owners are dangerously exposed, and where Texas just changed the rules.

Most owners in Tarrant County treat a data breach as an IT problem.

It isn’t. It’s a legal and financial one, and the bills don’t stop when the systems come back online.

For years, that was the trap. A breach hit, customer data spilled, and the lawsuits followed. Even when a business had done reasonable things to protect itself, it could still be on the hook for punitive damages, the kind of award designed to punish rather than to make a customer whole.

Those awards aren’t tied to your actual losses, which means they can dwarf them. For a company with fewer than 250 employees, that exposure could be the difference between recovering and closing the doors.

Texas changed that math on September 1, 2025.

Senate Bill 2610, now part of Chapter 542 of the Texas Business and Commerce Code, created a cybersecurity “safe harbor.” In plain terms: if your business is sued after a data breach and you had a qualifying cybersecurity program in place before the incident, a court cannot award punitive damages against you.

That’s a meaningful shield. But read it carefully, because of what it doesn’t do.

Safe harbor is not immunity. It doesn’t erase your actual damages, the real costs of cleaning up a breach, notifying customers, and rebuilding. It doesn’t stop a regulator. It doesn’t make you breach-proof. What it does is take the most punishing category of legal exposure off the table for the businesses that took security seriously before anything went wrong.

And that last part is the whole game.

The protection isn’t automatic, and it isn’t one-size-fits-all. The law scales with your size.

If you have fewer than 20 employees, the bar is reasonably basic: written password policies, employee training, the fundamentals.

Between 20 and 99 employees, you’re expected to meet something like the CIS Controls Implementation Group 1, a defined starter set of safeguards.

From 100 to 249, the law looks for a full program built on a recognized framework, such as NIST CSF or ISO 27001.

Notice the common thread: every tier points back to a recognized framework. Texas didn’t invent a new standard. It pointed to the ones security professionals already use—NIST, CIS, ISO—and said, in effect, adopt one, document it and maintain it.

So what does a “program” actually mean? It’s broader than software. The law expects administrative safeguards (the policies and training that govern how your people handle data), technical safeguards (the tools: multi-factor authentication, encryption, monitoring, backups), and physical safeguards (who can walk up to the server or the unlocked laptop).

Most businesses already own pieces of all three. What they don’t have is the part the statute cares about most: proof. A program you can’t document is, for legal purposes, a program you don’t have.

Here’s why this should land for every owner reading this. SB 2610 is voluntary. Nobody is going to fine you for ignoring it. But the businesses that act on it are quietly converting cybersecurity from a grudge expense into something with a measurable legal payoff. They aren’t just lowering the odds of a breach, they’re capping what a breach can cost them in court. In a market where everyone is fighting for margin, that’s a competitive advantage hiding inside a compliance task.

It pairs with your other protections, too. If you carry cyber liability insurance, your carrier is already asking whether you have these controls in place and pricing your premium on the answer. The same documentation that satisfies an underwriter is the documentation that supports a safe harbor defense. You’re often being asked to do the work twice and getting credit for it once.

The mistake I see most is treating this as a someday project. Safe harbor only counts if the program existed before the incident. You cannot stand one up after you’ve been breached and claim the protection. The court looks at what you had on the day it happened, not what you scrambled to assemble afterward. Cybersecurity is one of the few areas of running a business where the deadline is set by an attacker you’ll never meet.

It’s also worth saying what SB 2610 is not. It is not the Texas Data Privacy and Security Act. Those are two different laws with different requirements, and meeting one does not satisfy the other.

SB 2610 is the carrot, a reason to do the work, not a penalty for skipping it. Treat it that way.

So the question isn’t whether SB 2610 applies to you. If you’re a Texas business under 250 employees holding customers’ personal information, it does. The question is whether you’ll have something to point to when it matters.

Start where it’s concrete. Figure out which tier you fall in based on headcount. Pick a recognized framework that fits that tier. Then take an honest inventory: do you have a written program, or just a drawer full of tools nobody has ever mapped to a standard? Where you find gaps, close them, and write down what you did. The documentation isn’t busy work. It’s the evidence.

Reputation, revenue and legal exposure all run through the same place. In 2026, security isn’t the cost of doing business in Texas. It’s part of how you stay in it.

You can’t buy your way to safe harbor. You have to build it.

Don Oxman is the founder of Total 360 Security, a Texas-based virtual CISO and cybersecurity firm that helps small and mid-size businesses meet recognized frameworks and earn safe harbor protection. Learn more at total360security.com

More Articles