CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
      • IT Help Desk
      • 24/7 Emergency Support
      • Co-Managed IT
    • Cybersecurity
      • Network Security
      • Managed Firewall
      • Email Security
      • Phishing Protection
      • Security Awareness Training
      • Dark Web Monitoring
      • Penetration Testing
    • Business Continuity & Disaster Recovery (BCDR)
      • Backup & Disaster Recovery
      • Microsoft 365 Backup
      • Cloud Disaster Recovery
      • Backup & DR Audit
    • Cloud Services
      • Microsoft 365
      • Microsoft Azure
      • Cloud Migration
      • SharePoint
      • Virtual Desktop
    • Compliance
      • SOC 2
      • HIPAA
      • CMMC
      • NIST CSF
      • PCI DSS
      • FTC Safeguards
      • CIS Controls
      • Cyber Insurance
      • Compliance Audit
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Virtual CTO & CIO Services
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Texas Breach Notice Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Outline of Texas with a clock face and sealed envelopes flying outward, illustrating the Texas breach notification deadlines
Shane Stevens
Shane Stevens October 4th, 2026

10 Things to Do After a Breach When Texas Gives You 60 Days to Notify

Texas Data Breach Notification Law: What To Do And When – How The 250-Resident Threshold Works In Texas

Breach Response Checklist
Texas Data Breach Notification: 10 Things to Do Before Day 30 and Day 60.

A Houston business has 60 days to tell affected people and 30 to tell the Attorney General. Here is the order.

TL;DR
Texas gives a business 60 days to notify affected people and 30 days to notify the Attorney General when 250 or more Texans are involved. Both clocks start the day the breach is determined. The Attorney General publishes each report, including whether customers were told.
⏱️ Start the Clock 🔢 Build the Count 👁️ What Becomes Public ✉️ Notify and Close 🚀 How CinchOps Helps

The Texas data breach notification law gives a business 60 days to notify every affected person, and 30 days to notify the Texas Attorney General when at least 250 Texas residents are involved. Both deadlines sit in Texas Business and Commerce Code Section 521.053, and both start on the same day.

Picture the moment. The incident is contained, the systems are back, and someone mentions that Texas law puts a clock on telling people. 60 days sounds like plenty until you are counting them. The tempting options are to notify everyone today, to wait for the forensics, or to hope the count stays under 250. Each one skips work that the law and the Attorney General's form both expect to be finished first.

CinchOps handles breach response and evidence scoping specifically for Houston-area businesses with 10 to 200 employees, with 24/7 threat monitoring and help desk requests answered in under 15 minutes. CinchOps is not a law firm. This checklist puts the technical and administrative work in order and cites the statute for every deadline. Confirm how each rule applies to your business with your attorney.

The short version: Plan to day 30, because the Attorney General's form asks how many Texans were affected and how many you have already told. For the full list of who else gets a call, read who to report a ransomware attack or data breach to in Texas, and get breach response involved before anyone files.
AFTER A BREACH IN TEXAS10 Things to Do, in OrderCounted from the day the breach is determined 12345678910 Write down the date the breach was determinedPreserve the evidence and test the definitionCall the insurer and put counsel on the calendarMap what data lived on the affected systemsCount affected people and Texas residentsTell the owner if the records are not yoursDraft the notices before you fileFile the Attorney General report (250+ Texans)Send notice to every affected personUpdate the report and close the gap DAY 0DAY 0DAY 0BEFORE DAY 30BEFORE DAY 30IMMEDIATELYBEFORE DAY 30BY DAY 30BY DAY 60AFTER FILING Day 30 and day 60 are outer limits in Tex. Bus. & Com. Code Sec. 521.053. Confirm with counsel. CinchOps · cinchops.com

Both Texas Clocks Start the Day You Determine the Breach

Steps 1, 2 and 3: fix the starting date, protect the evidence, and get the 2 people with their own deadlines on the phone.

Texas Business and Commerce Code Section 521.053 counts both notification deadlines from the date a business determines that a breach occurred. Affected individuals must be told without unreasonable delay and no later than the 60th day. The Texas Attorney General must be told no later than the 30th day when at least 250 Texas residents are involved.

TWO TEXAS DEADLINESOne Starting Date, Two Finish LinesOuter limits in Tex. Bus. & Com. Code Sec. 521.053 Day 0Day 30Day 60 Texas Attorney GeneralAffected individuals 250 or more TexansAny count No later than day 30Without unreasonable delay, no later than day 60 Both clocks start the day the business determines the breach occurred. CinchOps · cinchops.com

1. Write down the date, so both deadlines have a starting line you can prove

Every later step is measured from one date, and 3 weeks from now nobody will remember it the same way. The statute counts from the day the business determines the breach occurred. The Attorney General's reporting page describes the deadline as 30 days after discovery of the breach. Those can be different days, and the gap is a question for your attorney.

  • Record who found the problem, what they saw, and the date and time.
  • Record the date someone concluded that data was taken, and what that conclusion was based on.
  • Give both dates and both wordings to counsel. CinchOps plans its technical work to the earlier date.

2. Preserve the evidence, so you can show what was and was not taken

The Texas duty depends on a definition. Section 521.053(a) defines a breach of system security as unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of sensitive personal information. Encrypted data counts if the person who took it has the key. Whether data was acquired is a forensic finding, and the proof lives on the machines you are tempted to wipe.

  • Keep affected machines isolated and intact until someone qualified has imaged or examined them.
  • Save firewall logs, Microsoft 365 or Google Workspace sign-in records, and backup snapshots from before and after the incident.
  • Ask counsel whether the facts meet the statute's definition. Section 521.002 covers an unencrypted name combined with a Social Security number, a driver's license or government ID number, or an account or card number with its access code, plus information that identifies a person and relates to their health or health care.

3. Call your insurer and your attorney, so the calendar has an owner

2 outside parties change what you are allowed to do next. A cyber insurance policy carries its own notice clause, and the policy sets that deadline, so read it before you spend money on response. Your attorney decides how the Texas wording applies to your facts. Neither call should wait for the forensics to finish.

  • Mark day 30 and day 60 on a shared calendar, counted from the date in step 1.
  • Ask counsel whether a law enforcement agency has asked you to hold notice. Section 521.053(d) allows a delay when notice would impede a criminal investigation.
  • Name one person inside the business who owns the notification file from here to the end.
Key insight: Always consult your attorney or legal counsel and your cyber insurance provider when a breach happens. This checklist covers the technical and administrative work. How Texas law applies to your facts is a question for counsel.

How Many Texans Were Affected Decides Which Deadline Applies

Steps 4, 5 and 6: find the data, count the people, and check whether the records were yours to begin with.

The count of affected Texas residents decides whether the 30-day Attorney General deadline applies. Section 521.053(i) requires the Attorney General notice when a breach involves at least 250 residents of Texas. Notice to individuals has no minimum count: one affected person is enough to start the 60-day clock for a Houston business.

THE 250 QUESTIONHow Many Texas Residents Were Affected?The count decides whether the 30-day deadline applies FEWER THAN 250 Notify every affected personAttorney General report Without unreasonable delay, by day 60Not required by Section 521.053(i) 250 OR MORE Notify every affected personAttorney General report Without unreasonable delay, by day 60Required, no later than day 30 Records belong to another business?Notify the owner immediately after discovering the breach, under Section 521.053(c). CinchOps · cinchops.com

4. Map what data lived on the affected systems, so the count is built on facts

You cannot count people until you know which files, mailboxes and databases the intruder could reach. This is the step that stalls. The pattern CinchOps sees in onboarding audits is that a business can name its servers and cannot say where the Social Security numbers and bank details are stored. A CPA practice in Sugar Land or a law firm in Katy holds exactly the records the Texas definition describes.

  • List every account the intruder used and every mailbox, file share and application those accounts could open.
  • Search those locations for the data types in Section 521.002: Social Security numbers, license and ID numbers, account and card numbers, and health information.
  • Note where the evidence shows data left the network, and where it only shows access.

5. Count affected people and separate the Texas residents, so you know if 250 applies

The Attorney General's form asks for 2 numbers as of the day you file: how many Texas residents were affected, and how many have already been sent a disclosure by mail or another direct method. Letters to individuals have until day 60. The count behind them has to exist by day 30, which makes day 30 the real planning date.

  • Build one list of affected people with a name, a last known address and a state for each.
  • Total the Texas residents. At 250 or more, the Attorney General notice is required.
  • For residents of other states, Section 521.053(b-1) allows notice under that state's law or under the Texas rule. Ask counsel which applies.

6. Tell the owner of the data immediately if the records are not yours

Some businesses hold sensitive records that belong to someone else. A bookkeeping firm that stores a client's payroll files is one example, and so is an IT or software vendor hosting customer data. Section 521.053(c) puts a faster duty on that business: notify the owner or license holder of the information immediately after discovering the breach.

  • Sort the affected records into data you own or license and data you maintain for another business.
  • Notify each owner right away, and check the contract between you for its own notice terms.
  • Agree in writing on who sends the notices to individuals and who files with the Attorney General.

What Becomes Public When You File a Texas Breach Report

Steps 7 and 8: the Attorney General publishes a listing of the reports it receives, so prepare the notices first and file from a finished worksheet.

A Texas Attorney General breach report is published. Section 521.053(j) requires the Attorney General to post a listing of the notifications it receives on its public website, and to update that listing no later than the 30th day after a new notification arrives. The listing shows the business name, its address, the number of Texans affected, and whether consumers were notified.

The listing lives on the Attorney General's Data Security Breach Reports page. It has a search box, and it showed 652 entries when CinchOps opened it on October 3, 2026. The statute keeps sensitive personal information, details that could compromise a system's security, and information made confidential by law out of the listing. This table lists the 10 fields the public listing shows for each report and what a reader learns from each one.

Field on the public listingWhat anyone reading it learns
Entity or individual nameWhich business reported a breach
Address, city, state and ZIP code (4 fields)Where the business is, down to the street and ZIP code
Types of information affectedWhat kind of data was involved
Number of Texans affectedHow large the breach was in Texas
Notice provided to consumers (Y/N)Whether the business had told the affected people
Methods of notice to consumersHow the business told them
Date published at the Attorney General's websiteWhen the report became public

For an owner, that means customers, competitors, journalists and insurers can all see the business name, how many people were affected, what kind of data it was, and whether the business had told its customers yet. Because the listing carries city and ZIP code, a report about a Katy or Cypress business is easy for a neighbor or a local reporter to find. The page carries one note from the Attorney General: "Details including number of affected Texans and whether notice was provided to them may change after a report is listed here."

THE PUBLIC LISTING10 Fields Anyone Can ReadOne row per report on the Texas Attorney General's website Entity orindividual nameStreet addressCityStateZIP codeTypes ofinformation affectedNumber ofTexans affectedMethods of noticeto consumersNotice providedto consumers (Y/N)Date publishedat OAG website Orange fields are the ones a customer, competitor or insurer reads first. Fields observed October 3, 2026. CinchOps · cinchops.com

7. Draft the notices before you file, so the public record shows you told people

The "notice provided to consumers" field is public. A business that files on day 29 with no letters sent is reporting that fact on a page its customers can search. Section 521.053 sets the 30-day and 60-day limits separately, so the order is yours to choose with counsel. Having the notices drafted, approved and ready to mail when you file protects how the listing reads.

  • Have counsel draft the notice letter while the count in step 5 is being finished.
  • Pick the delivery method. Section 521.053(e) allows written notice to the last known address or electronic notice that meets 15 U.S.C. Section 7001.
  • Check substitute notice only if it applies. Section 521.053(f) allows email, a conspicuous website posting, or statewide media when notice would cost more than $250,000, more than 500,000 people are affected, or contact information is insufficient.

8. File the Attorney General report by day 30 from a finished worksheet

The report is filed electronically through the Attorney General's website, and the Attorney General's page states that the system cannot save a report in progress. It has to be completed in one sitting by an authorized agent of the business, usually an owner, manager, officer or attorney. The page also warns that a completed report is potentially an open record.

  • Preview the form first, and write the answers in a separate document before opening the live version.
  • Prepare the 6 items Section 521.053(i) requires: the nature and circumstances of the breach, the number of Texas residents affected, the number already sent a disclosure, the measures taken, the measures planned, and whether law enforcement is investigating.
  • Keep the confirmation email and the record number the Attorney General sends after submission.

Send the Notices by Day 60 and Keep the Report Current

Steps 9 and 10: get notice to every affected person, update the Attorney General when the numbers change, and fix what let the intruder in.

Texas requires notice to each affected individual without unreasonable delay and no later than the 60th day after the business determines the breach occurred. Section 521.151 adds a civil penalty of up to $100 per individual for each consecutive day a business fails to take reasonable action on that notice, capped at $250,000 for a single breach.

HOW NOTICE IS GIVEN3 Ways Texas Lets You NotifySection 521.053(e) and (f) Written notice Sent to the last knownaddress of the individual Electronic notice Allowed when it meets15 U.S.C. Section 7001 Substitute notice Email, website posting orstatewide media, only above$250,000 in cost, 500,000people, or missing contact info Notifying more than 10,000 people at one time? Also notify each nationwide consumer reporting agency. CinchOps · cinchops.com

9. Send notice to every affected person, so day 60 passes with nothing outstanding

60 days is an outer limit. The statute's first instruction is "without unreasonable delay," and the only exceptions it names are a law enforcement request and the time necessary to determine the scope of the breach and restore the integrity of the system. A business that waits until day 59 by habit is leaning on the limit and ignoring the instruction.

  • Mail or send the notices as soon as the list and the letter are final, and keep proof of the send date.
  • If you are notifying more than 10,000 people at one time, Section 521.053(h) also requires notice to each nationwide consumer reporting agency without unreasonable delay.
  • Brief whoever answers the phone. Affected customers will call the main number.

10. Update the report and close the gap, so the listing reflects your finished work

Counts change as an investigation finishes. The Attorney General's page asks a business filing supplemental information to report the total number of affected and notified consumers to date and every type of personal information identified. Under Section 521.053(j), a notification comes off the public listing no later than its first anniversary if the business has reported no additional breaches in that period.

  • File an updated report when the affected count or the notified count changes, so the public listing shows the current numbers.
  • Fix the route the intruder used. A stolen password points to multi-factor authentication. Lost data points to backups you have restored from.
  • Store the timeline, the count worksheet, the notices and the confirmation email together. Section 521.151 sets $2,000 to $50,000 per violation of the chapter, and that file is your record of what you did and when.
When you file with the Texas Attorney General, the public listing shows your name, your city, how many Texans were affected, and a yes or no on whether you've told them. Have the letters ready before you file. You want that column to say yes.
Shane Stevens, CEO, CinchOps - LinkedIn

The Count Is a Technical Finding, and It Is Due in 30 Days

CinchOps scopes what an intruder reached, preserves the evidence, and gives your attorney the list the Texas notices are built from. See how Breach Response for Houston Businesses works, or call 281-269-6506.

See Breach Response

How CinchOps Can Help a Houston Business Meet Both Texas Deadlines

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

  • Breach Response contains the incident, preserves evidence and scopes what was accessed, which produces the count behind steps 4 and 5.
  • Cybersecurity with 24/7 threat monitoring shortens the time between an intrusion and the day you determine it happened.
  • Multi-Factor Authentication Deployment closes the stolen-password route into mailboxes and file shares.
  • Backup and Disaster Recovery keeps immutable, offsite copies for clients on the top-tier plan, so recovery can run while the investigation continues.
  • Cyber Insurance Readiness puts the policy, its notice clause and the claims contact in one place before an incident.
  • Local coverage through managed IT in Houston and managed IT in Katy, with industry depth for law firms and CPA firms.

A Texas breach report is a public statement about your business, and the numbers on it come from your own systems. The owners who file calmly on day 30 already knew where their sensitive records were stored before anything went wrong. Build that data map now, while nothing is on fire, and talk to CinchOps if you want help putting it together.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

How long does a Texas business have to notify people after a data breach?

Texas Business and Commerce Code Section 521.053(b) requires notice to each affected individual without unreasonable delay and no later than the 60th day after the business determines the breach occurred. When at least 250 Texas residents are involved, the Texas Attorney General must also be notified no later than the 30th day.

What does the Texas Attorney General publish about a breach report?

The Texas Attorney General posts a public listing of breach reports. On October 3, 2026 it showed the entity name, street address, city, state, ZIP code, types of information affected, number of Texans affected, whether notice was provided to consumers, the methods of notice, and the date published. Section 521.053(j) excludes sensitive personal information.

Do I have to report a breach to the Texas Attorney General if fewer than 250 Texans were affected?

Section 521.053(i) requires the Attorney General notice when a breach involves at least 250 residents of Texas. Below that number, the statute does not require the Attorney General report. Notice to each affected individual is still required at any count, within the same 60-day limit. Ask your attorney to confirm the count and the conclusion.

What should a Houston business do after a ransomware attack or data breach?

A Houston business should record the date the breach was determined, preserve evidence, and call its cyber insurer and attorney. Then it maps what data was reached, counts affected people and Texas residents, files the Attorney General report by day 30 if 250 or more Texans are involved, and notifies every affected individual by day 60.

Can a Texas business delay breach notification?

Section 521.053 names 2 situations. A law enforcement agency can ask a business to delay notice that would impede a criminal investigation, and notice then goes out once the agency clears it. The 60-day limit also yields as necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

How long does a breach report stay on the Texas Attorney General's public listing?

Section 521.053(j) directs the Attorney General to remove a notification from the public listing no later than the first anniversary of the date it was added, if the business has not notified the Attorney General of any additional breaches during that period. The listing itself notes that details may change after a report is posted.

What does breach notification cost in Houston?

Breach notification cost in Houston depends on forensic scope, attorney fees and how many notices are mailed, and a cyber insurance policy may cover part of it. For the ongoing IT and security work that produces the data map and the count, the published CinchOps rate is $100 to $250 per user per month, with no long-term contract.

Discover More

Does a Small Business Really Need an Incident Response Plan? (2026 Guide)
9 Things to Do After Your Cyber Insurance Renewal Questionnaire Arrives
Texas SB 2610: The Cybersecurity Safe Harbor Every Houston SMB Should Know About
Texas Privacy Implementation Changes: New Requirements Now in Effect for Houston Businesses
Are You Really Ready? Testing Your Cybersecurity Incident Response Through Tabletop Exercises
Backup Testing for Houston Businesses: The Restore Test

Resource

Infographic: after a breach in Texas, the Attorney General report is due by day 30 at 250 or more Texans and notices to affected individuals by day 60, with the 10 steps, what the public listing shows and the civil penalties
After a Breach in Texas: 30 Days for the Attorney General, 60 Days for Your Customers Open Full Size

Sources

  • Texas Business and Commerce Code, Chapter 521 - Sections 521.002, 521.053 and 521.151, Texas Legislature Online, read October 3, 2026
  • Data Breach Reporting - Office of the Texas Attorney General, read October 3, 2026
  • Data Security Breach Reports - Office of the Texas Attorney General, public listing, fields and entry count observed October 3, 2026
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 17th, 2026
AI Phishing
Hoxhunt 2026 Phishing Trends Report: A 14x AI Phishing Surge Hit Over the Holidays

50 Million Data Points Reveal How Phishing Training Reduces Organizational Risk – Calendar Invites Are The New Phishing Trap With 4x Higher Click Rates

September 17th, 2026
Glowing blue digital umbrella with particles representing cyber insurance protection.
9 Things to Do After Your Cyber Insurance Renewal Questionnaire Arrives

Building And Keeping A Cyber Insurance Answer Pack – What Houston Businesses Should Add To The Backup Answer

June 5th, 2026
Business Email Compromise Houston
Gift Card Email From Your Boss? The Two Scams Houston Businesses Need To Know

Business Email Compromise, Explained For Houston Small Businesses – Gift Card Fraud Skips Your Firewall And Targets Your People

June 25th, 2025
Managed Service Provider Houston Cybersecurity
Hackers Mess With TxTag System to Harvest Credit Card Data via Phishing Campaign

Cybercriminals Exploit Government Email Systems in Sophisticated TxTag Toll Scam – How a $6.69 Fake Toll Notice Became a Major Security Threat

June 13th, 2025
Managed Service Provider Houston Cybersecurity
Texas Takes the Lead: Establishing America’s Largest State Cyber Command Center

Texas Launches America’s Largest State Cybersecurity Command Center – Creates Dedicated Cyber Defense Department in San Antonio

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Compliance
  • Virtual CTO & CIO
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy