Data Breach Reporting Checklist for Texas Small Businesses
Who to Report a Ransomware Attack or Data Breach to in Texas, and By When
A Houston small business has 2 Texas deadlines, 1 insurance clause and 3 federal doors. Here is the map.
To report a ransomware attack in Texas, a small business has 2 legal duties and several smart calls. Texas Business and Commerce Code Section 521.053 requires notice to every affected individual within 60 days, and to the Texas Attorney General within 30 days once at least 250 Texas residents are involved.
Everything else on the list is a contract duty or a choice. Your cyber insurance policy carries its own notice clause. The FBI Houston field office, the Internet Crime Complaint Center (IC3) and CISA all take reports from private businesses, and for most Houston small businesses those reports are voluntary. Health data and card data bring their own clocks.
CinchOps provides breach response specifically for small and mid-sized businesses in the Houston metro area, with 24/7 threat monitoring and help desk response in under 15 minutes. CinchOps is not a law firm. This page maps who gets told and when, with the primary source behind every deadline. Confirm how each rule applies to your business with your attorney.
Know Who a Texas Business Must Notify and Who It Should
10 parties, sorted by whether the report is required by law, required by contract, or recommended.
A Texas small business hit by ransomware or a data breach must notify affected individuals, and must notify the Texas Attorney General when at least 250 Texas residents are involved. Reports to FBI Houston, IC3 and CISA are voluntary for most private small businesses. Insurers, HHS and card brands come in with a policy, health data or card data.
The table below compares each party a Houston business may need to report a ransomware attack or data breach to, with the legal status of the report, the trigger, the deadline, the filing route and the information each party asks for.
| Who to notify | Required or recommended | Trigger or threshold | Deadline | How to file | What they ask for |
|---|---|---|---|---|---|
| Affected individuals | Required by Texas law, Section 521.053(b) | Sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. No minimum count. | Without unreasonable delay, and no later than the 60th day after the business determines the breach occurred | Written notice to the last known address, or electronic notice. Substitute notice is allowed above $250,000 in cost or 500,000 people. Statute text | The statute sets the method and the deadline. Counsel drafts the letter. |
| Texas Attorney General | Required by Texas law, Section 521.053(i) | The breach involves at least 250 Texas residents | As soon as practicable, and no later than the 30th day after the business determines the breach occurred | Electronic Data Breach Report on the Attorney General's site. Reporting page | Nature and circumstances of the breach, number of Texas residents affected, number already sent notice, measures taken, measures planned, and whether law enforcement is investigating |
| The business that owns the data, when you only hold it for them | Required by Texas law, Section 521.053(c) | You maintain sensitive personal information you do not own, and it was or is reasonably believed to have been acquired | Immediately after discovering the breach | Direct notice to the owner or license holder of the information | Not specified in the statute. Check the contract between the two businesses. |
| Nationwide consumer reporting agencies | Required by Texas law, Section 521.053(h) | You must notify more than 10,000 persons at one time | Without unreasonable delay | Direct notice to each nationwide agency | The timing, distribution and content of the notices to individuals |
| Cyber insurer | Required by contract if you plan to claim | Set by the policy | Set by the notice clause in the policy. No public source sets a number. | The claims contact named in the policy | Set by the policy. Read the notice clause before you need it. |
| FBI Houston field office | Recommended. No source reviewed for this page requires it of a private small business. | Ransomware, business email compromise or other cyber crime | None published. The office takes reports 24/7. | (713) 693-5000 or tips.fbi.gov. 1 Justice Park Drive, Houston, TX 77092. FBI Houston | Not listed on the field office page |
| FBI Internet Crime Complaint Center (IC3) | Recommended | Ransomware, business email compromise, cyber-enabled fraud | None published. If money moved, the FBI says to contact your bank immediately. | Online complaint at ic3.gov | An online complaint about the incident. IC3 states it cannot respond directly to every submission, so keep your own copy. |
| CISA | Voluntary today. Mandatory reporting under CIRCIA is not in effect until CISA issues a final rule. | Any cyber incident. The pending rule is aimed at covered critical infrastructure entities. | None today. The law directs a 72-hour window for covered entities once the rule takes effect. | Incident Reporting System at cisa.gov/report | Details of the incident. CISA asks you not to paste malicious code or include personal data unless it is needed. |
| HHS, for HIPAA covered entities | Required by the HIPAA Breach Notification Rule | Breach of unsecured protected health information | Individuals: no later than 60 days after discovery. HHS: no later than 60 days for 500 or more individuals; for fewer than 500, within 60 days after the end of the calendar year. | Breach report form on the HHS site. Media notice is also required above 500 residents of a state. | A description of the breach, the types of information involved, steps individuals should take, what the entity is doing, and contact information |
| Acquiring bank and Visa, for card data | Required by card brand rules | Suspected or confirmed unauthorized access to Visa payment account data | Notify the acquiring bank immediately. The event must reach Visa within 3 calendar days of reasonable suspicion or confirmation. | Through your acquiring bank or payment processor. Visa procedures | An incident report. If Visa requires a forensic investigation, a PCI forensic investigator must be under contract within 5 business days. |
Every deadline in the table comes from a primary source opened on October 3, 2026. Other card brands publish their own procedures, and those were not reviewed for this page. Your acquiring bank is the right first call for any card data question.
Count Both Texas Deadlines From the Day You Determine the Breach
Section 521.053 sets 2 clocks with the same starting line and different finish lines.
Texas sets a 60-day outer limit for notifying affected individuals and a 30-day outer limit for notifying the Texas Attorney General. Both run from the date the business determines the breach occurred. The Attorney General notice applies when the breach involves at least 250 Texas residents, and it must be filed electronically through the Attorney General's website.
The current text reflects a 2023 amendment, Senate Bill 768, effective September 1, 2023. The Attorney General's reporting page dates the electronic-form requirement to the same day. A third-party page that gives a single 60-day deadline for everything does not match the text on the Texas Legislature's site as of October 3, 2026.
What starts the clock. A breach of system security is defined in Section 521.053(a) as unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of sensitive personal information. Encrypted data still counts if the person who took it has the key. The test is whether data was acquired. Ransomware that locks files in place and ransomware crews that copy files out first are different situations under that wording, and telling them apart is a forensic job.
What counts as sensitive personal information. Section 521.002 covers an unencrypted name combined with a Social Security number, a driver's license or government ID number, or an account or card number with the code that opens the account. It also covers information that identifies a person and relates to their health, their health care, or payment for it. That health branch carries no HIPAA condition in the definition, so a Houston business outside health care that stores such records should ask counsel whether it is covered.
The 30-day deadline sets the pace. The Attorney General's form asks for the number of Texas residents affected and the number already sent notice, as of the day you file. Letters to individuals have until day 60, yet the count behind them has to exist by day 30. The Attorney General's page tells a business that files an update to report the total affected and notified to date, so a first filing can be corrected as the investigation finishes.
One wording gap to hand to counsel. The statute counts from the date the business determines that the breach occurred. The Attorney General's page describes the deadline as 30 days after discovery of the breach. Those dates can differ. CinchOps plans its technical work to the earlier date and leaves the legal reading to the client's attorney.
Section 521.053 allows 2 delays: a law enforcement agency can ask a business to hold notice that would impede a criminal investigation, and the 60-day limit yields as necessary to determine the scope of the breach and restore the integrity of the system. Section 521.151 sets the penalty side. A violation of the chapter carries $2,000 to $50,000, and failing to take reasonable action on individual notice adds up to $100 per individual per day, capped at $250,000 for a single breach.
2 more facts shape the decision. The Attorney General posts a public listing of the breach reports it receives, and its page warns that a completed report is potentially an open record. A report filed in Austin about a Katy or Sugar Land business should be assumed readable by customers and competitors.
Make the Reports in This Order During the First 24 Hours
Contain first, call the people with contract deadlines second, report to law enforcement the same day, and leave the state filing for when the scope is known.
In the first 24 hours after ransomware or a hacked mailbox, a Houston business contains the incident, calls its cyber insurer and attorney, calls the bank if money moved, and reports to the FBI through the Houston field office or IC3. The Texas Attorney General report and the notices to individuals come later, once the scope is known.
- 1. Isolate, and write down the time. Disconnect affected machines from the network and leave them powered on, because shutting down destroys evidence held in memory. Record who found what and when. That record is what later fixes the date the breach was determined.
- 2. Call your IT provider or a breach response team. Containment and evidence preservation start here, before staff-wide emails that an intruder with mailbox access could read.
- 3. Call your cyber insurer and your attorney. The policy sets the insurer's notice deadline, and it may name the forensic and legal firms you are expected to use. Find the notice clause before you spend money on response.
- 4. If money moved, call your bank now. The FBI's guidance on business email compromise is to contact your financial institution immediately and ask it to contact the institution that received the transfer.
- 5. Report to the FBI the same day. Call FBI Houston at (713) 693-5000 or file a complaint at ic3.gov. The FBI states that it does not support paying a ransom, and that payment does not guarantee you get data back.
- 6. Consider a CISA report. The CISA Incident Reporting System at cisa.gov/report accepts voluntary reports from any organization.
- 7. If card data is involved, call your acquiring bank. Visa's procedures require immediate notice to the acquiring bank and a report to Visa within 3 calendar days of reasonable suspicion.
- 8. Hold the Texas filings until you have a count. The Attorney General's form cannot be saved and has to be completed in one sitting by an authorized representative, so it is filled in from a finished worksheet, days into the response.
The early calls change what the later reports say. An insurer that learns about the incident on day 1 can put counsel in place before the first written statement leaves the building. The FBI's advice on a diverted payment comes down to one word: immediately.
Is There an Incident Open Right Now?
CinchOps responds to active cyber incidents at Houston-area small and mid-sized businesses with containment, recovery support and clear next steps.
Talk to CinchOpsGive Your IT Provider 3 Jobs Before Anyone Files a Report
Evidence, scope and a count of affected people are technical findings, and every report in this guide depends on them.
An IT provider's work during a breach produces the facts every report depends on. The provider preserves evidence, determines what the intruder accessed or copied, and turns that finding into a list of affected people. That list decides whether the 250-resident Attorney General threshold is met and how many notices go out.
Preserve the evidence. Isolated machines, firewall logs, Microsoft 365 or Google Workspace sign-in records and backup snapshots are the raw material for the description of the breach that the Attorney General's form asks for. Wiping and rebuilding on day 1 feels productive and erases the proof of what was, and was not, taken.
Scope what was accessed. The Texas duty turns on whether sensitive personal information was acquired, or is reasonably believed to have been. Answering that means tracing which accounts the intruder used, which mailboxes and file shares those accounts could reach, and whether data left the network.
Build the count. Once the affected systems are known, someone has to open them and list the people whose records fit the Texas definition, then separate Texas residents from everyone else. A CPA practice in Sugar Land or a law firm in Katy holds exactly the name-plus-Social-Security-number and name-plus-account records that definition describes. In 35+ years of IT work, Shane Stevens has seen the same thing stall this step: the business cannot say what data lived on the machine that was hit.
The same team documents the measures taken and the measures planned, which are 2 of the 6 items Section 521.053(i) requires in the Attorney General report. Recovery runs in parallel. CinchOps keeps immutable, offsite backup copies for clients on its top-tier plan, so restoring systems does not depend on the intruder's cooperation.
The Texas Attorney General's form asks for 2 numbers: how many Texans were affected, and how many you've already told. Your logs and your file inventory produce those numbers. Check both before the ransom note shows up, because day 30 comes fast.
An Active Incident Needs a Phone Call Before a Form
CinchOps takes active incident calls from Houston-area businesses, scopes by phone and starts containment remotely. See how Breach Response for Houston Businesses works, and call 281-269-6506.
See Breach ResponseHow CinchOps Can Help a Houston Business Report a Breach on Time
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- Breach Response contains an active incident, preserves evidence and scopes what was accessed, which gives your attorney the facts for the Texas notices.
- Backup and Disaster Recovery keeps immutable, offsite copies so recovery can start while the investigation is still running.
- Multi-Factor Authentication Deployment closes the stolen-password route into a mailbox. The FBI's own business email compromise guidance tells businesses to turn it on and never disable it.
- Cybersecurity with 24/7 threat monitoring shortens the gap between an intrusion and the day you determine it happened.
- Cyber Insurance Readiness gets the policy, the notice clause and the claims contact into one place before an incident.
- Local coverage through managed IT in Houston and managed IT in Katy, with industry depth for law firms and CPA firms.
A reporting map is only useful if the facts behind it exist. The businesses that meet the 30-day Attorney General deadline without panic are the ones that already know where their sensitive records live and who their insurer's claims contact is. Build that list this quarter, keep it with your incident plan, and talk to CinchOps if you want a second set of eyes on it.
Frequently Asked Questions
My Houston small business got ransomware. What do I do, and who do I report it to?
Disconnect affected machines without powering them off, then call your IT provider, your cyber insurer and your attorney. Report to FBI Houston at (713) 693-5000 or at ic3.gov. If sensitive personal information was taken, Texas law requires notice to affected individuals within 60 days and to the Attorney General within 30 days at 250 or more Texans.
My Houston business email was hacked. Who can help, and who do I tell?
An IT provider with breach response experience can lock the account, review sign-in logs and check what the intruder read or sent. If a payment was redirected, call your bank immediately and file a complaint at ic3.gov. Texas notice duties apply if sensitive personal information in the mailbox was acquired.
How long does a Texas business have to report a data breach to the Attorney General?
Texas Business and Commerce Code Section 521.053(i) requires notice to the Texas Attorney General as soon as practicable and no later than the 30th day after the business determines the breach occurred. The duty applies when the breach involves at least 250 Texas residents. The report is filed electronically on the Attorney General's website.
Is a Texas small business required to report ransomware to the FBI or CISA?
No source reviewed for this guide requires a private small business to report ransomware to the FBI, and the FBI asks victims to contact a field office or IC3. CISA reporting is voluntary today. Mandatory federal reporting under CIRCIA applies to covered critical infrastructure entities only after CISA's final rule takes effect.
Does ransomware count as a data breach under Texas law?
It depends on whether data was acquired. Section 521.053 defines a breach of system security as unauthorized acquisition of computerized data that compromises sensitive personal information. Ransomware that copied files containing that information before encrypting them meets the wording. Whether that happened is a forensic finding, and how the law applies is a question for counsel.
What is the penalty for late breach notification in Texas?
Section 521.151 sets a civil penalty of $2,000 to $50,000 for each violation of the chapter. Failing to take reasonable action to notify individuals adds up to $100 per individual for each consecutive day, capped at $250,000 for a single breach. The Texas Attorney General brings the action and can recover its costs.
What does breach response cost in Houston?
Breach response cost in Houston depends on forensic scope, legal fees and how many notices are mailed, and a cyber insurance policy may cover part of it. For the ongoing protection side, the published CinchOps rate is a flat $100 to $250 per user per month, with no long-term contract, no hidden fees and no cancellation penalty.
Discover More
Resource
Sources
- Texas Business and Commerce Code, Chapter 521 - Sections 521.002, 521.053 and 521.151, Texas Legislature Online, read October 3, 2026
- Data Breach Reporting - Office of the Texas Attorney General
- FBI Houston Field Office - Federal Bureau of Investigation
- Ransomware and Business Email Compromise - Federal Bureau of Investigation
- Internet Crime Complaint Center (IC3) - Federal Bureau of Investigation
- CISA Incident Reporting System and Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) - Cybersecurity and Infrastructure Security Agency
- Breach Notification Rule - U.S. Department of Health and Human Services
- What To Do If Compromised: Visa Supplemental Requirements, Version 10.0 - Visa, effective June 25, 2026