Texas businesses can face security obligations from more than one direction at the same time: state law, industry rules, contracts, cyber insurance and customer requirements. We find it is much easier to manage when the legal requirement, the technical control and the evidence supporting it are kept together.
What we look for
The cleanest compliance programs tie three things together: the requirement, the technical control and the evidence. Legal counsel should determine what a law requires; the technology team should be able to show how the control is configured and tested.
Texas businesses can be subject to cybersecurity, privacy, breach-notification and industry-specific requirements based on the data they hold, the services they provide and the contracts they sign.
This guide is an operational overview, not legal advice. Organizations should consult qualified legal counsel regarding how specific laws apply to them.
Texas Data Breach Notification
The Texas Attorney General states that businesses and organizations experiencing a breach of system security affecting 250 or more Texans must report the breach to the Office of the Attorney General as soon as practicably possible and no later than 30 days after discovery.
Texas law also requires notice to affected individuals. The Texas Attorney General's Identity Theft Enforcement and Protection Act guidance states that notice to affected individuals must generally be provided as quickly as possible and no later than 60 days after determining the breach occurred, subject to applicable exceptions.
Organizations should establish an incident-response process before a breach occurs so legal, insurance and notification decisions can be made quickly.
Texas Data Privacy and Security Act
The Texas Data Privacy and Security Act became effective July 1, 2024.
Businesses within the law's scope should understand obligations involving personal data, consumer rights, privacy notices, data protection assessments and processor/controller relationships.
Applicability depends on the organization's activities and statutory exceptions. Legal counsel should determine whether and how the law applies.
Security Controls and Reasonable Cybersecurity
Texas businesses frequently have cybersecurity obligations that arise from several sources:
- State privacy and breach laws
- Federal regulations
- Customer contracts
- Cyber-insurance requirements
- Payment-card requirements
- Industry rules
- Professional standards
- Vendor agreements
A structured cybersecurity framework helps organizations document how security is managed.
CIS Critical Security Controls
The CIS Critical Security Controls are a prioritized set of cybersecurity safeguards.
CIS uses three Implementation Groups to help organizations prioritize controls according to risk profile and resources.
IG1 is intended as foundational cyber hygiene.
IG2 adds safeguards for organizations with greater complexity, sensitive information or increased operational requirements.
IG3 adds further safeguards for organizations facing higher risks or sophisticated threats.
The correct Implementation Group should be based on risk rather than employee count alone.
Core Cybersecurity Capabilities
A Texas business cybersecurity program should consider:
- Asset inventory
- Software inventory
- Data protection
- Secure configuration
- Account management
- Access control
- Vulnerability management
- Audit logs
- Email and browser protections
- Malware defenses
- Data recovery
- Network infrastructure management
- Network monitoring and defense
- Security awareness
- Service provider management
- Application software security
- Incident response
- Penetration testing where appropriate
These areas correspond to the 18 CIS Critical Security Controls.
Incident Response
An incident response plan should document:
- Internal decision makers
- Cyber-insurance contact information
- Legal counsel
- IT and cybersecurity contacts
- Critical systems
- Isolation procedures
- Credential-reset procedures
- Evidence preservation
- Communications responsibilities
- Regulatory review
- Restoration priorities
- Post-incident review
Cyber Insurance
Cyber-insurance policies frequently contain technical and procedural requirements.
Businesses should ensure that representations on insurance applications accurately reflect the controls actually in place.
Technical controls commonly requested by insurers can include multi-factor authentication, endpoint protection, backups, email security and privileged-access management. Requirements vary by carrier and policy.
Contractual Requirements
A company may need to follow cybersecurity requirements because a customer contract requires them even when a specific regulation does not.
Examples include NIST requirements, CMMC obligations for certain defense contractors, security questionnaires, vendor-risk programs and minimum insurance requirements.
Build an Evidence File
Businesses should retain evidence that cybersecurity controls are operating.
Evidence can include:
- Policies
- Asset inventories
- User-access reviews
- Security training records
- Backup test results
- Vulnerability reports
- Patch reports
- Security alerts
- Incident-response exercises
- Vendor reviews
- Risk assessments
Common questions
Does every Texas business have the same cybersecurity requirements?
No. Requirements depend on the organization's industry, data, customers, contracts and other factors.
Does Texas require breach reporting?
Yes. The Texas Attorney General states that a breach affecting 250 or more Texans must be reported to the OAG no later than 30 days after discovery.
Is CIS a law?
The CIS Critical Security Controls are a cybersecurity framework, not a general law that automatically applies to every business. Organizations may choose to use CIS or be required to follow it through contracts, policy or another program.
Does compliance guarantee cybersecurity?
No. Compliance establishes requirements, but threats and technology change continuously. Organizations still need ongoing risk management.
Where Huff Data fits
Huff Data Systems can help businesses assess technical controls, improve cybersecurity, document technology processes and build a prioritized roadmap.
Legal conclusions and interpretations should be made with qualified counsel.
Sources and further reading
This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.
