CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
      • IT Help Desk
      • 24/7 Emergency Support
      • Co-Managed IT
      • Remote IT Support
      • Onsite IT Support
      • Proactive Monitoring
      • Patch Management
      • Network Monitoring
      • Mobile Device Management
      • IT Procurement
      • IT Documentation
      • Server Management
      • Mac Support
      • Employee Onboarding & Offboarding
    • Cybersecurity
      • Endpoint Security
      • Network Security
      • Managed Firewall
      • Email Security
      • Phishing Protection
      • Security Awareness Training
      • Dark Web Monitoring
      • Penetration Testing
      • Multi-Factor Authentication
      • Zero Trust
      • Vulnerability Scanning
      • SIEM Services
      • Managed SOC
      • Virtual CISO (vCISO)
      • Password Management
      • Managed Detection & Response
    • Business Continuity & Disaster Recovery (BCDR)
      • Backup & Disaster Recovery
      • Microsoft 365 Backup
      • Cloud Disaster Recovery
      • Backup & DR Audit
      • Backup as a Service
      • Tabletop Exercises
    • Cloud Services
      • Microsoft 365
      • Microsoft Azure
      • Cloud Migration
      • SharePoint
      • Virtual Desktop
      • Azure Managed Services
      • Cloud Monitoring & Management
      • Microsoft Entra ID
      • Microsoft Teams
      • Microsoft Exchange
      • OneDrive for Business
      • Amazon Web Services (AWS)
    • AI Services
      • AI Policy & Governance
      • AI Security & Risk
      • AI Readiness Assessment
      • AI Strategy
      • AI Assistant Platforms
      • AI Training & Adoption
      • AI Workflow Automation
      • AI Development
      • Agentic AI
      • Business Intelligence
      • Business Process Automation
      • Data Analytics
    • Compliance
      • SOC 2
      • HIPAA
      • CMMC
      • NIST CSF
      • PCI DSS
      • FTC Safeguards
      • CIS Controls
      • Cyber Insurance
      • Compliance Audit
    • Network, Voice & Strategy
      • Software Defined Wide Area Networks (SD-WAN)
      • Voice Over IP (VoIP)
      • Virtual CTO & CIO Services
      • Teams Phones & Conferencing
      • Network Assessment
      • IT Consulting
      • IT Cost Assessment
      • Digital Transformation Strategy
      • Legacy System Assessment
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise
    • Architecture
    • Banking & Credit Unions
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Healthcare
    • Law Firms
    • Manufacturing
    • Non-Profit
    • Oil & Gas Services
    • Real Estate & Property Management
    • Transportation & Logistics
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Texas Breach Notice Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Reviews
  • Contact
I Need IT Support Now
SB2610 Shield
Shane Stevens
Shane Stevens October 5th, 2026

What Does Texas SB 2610 Require for the Cybersecurity Safe Harbor?

What Texas SB 2610 Requires For The Cybersecurity Safe Harbor – The Three Tiers In Texas SB 2610 Explained

Texas Law Explained
Texas SB 2610 Safe Harbor: What Does a Houston Business Need in Place to Qualify? The Answer Depends on How Many People You Employ.

The 3 tiers in the law, what the protection covers and leaves open, and the records a Houston business needs to show it qualified.

TL;DR
Texas SB 2610 bars exemplary damages after a data breach for a business with fewer than 250 employees that had a conforming cybersecurity program in place. The required program scales in 3 tiers by headcount, and the business carries the burden of proving it.
📊 The 3 Tiers ⚖️ What It Protects 📝 Proving You Qualified 🚀 How CinchOps Helps

The Texas SB 2610 safe harbor protects a business with fewer than 250 employees from exemplary damages in a data breach lawsuit, provided the business can show it had a conforming cybersecurity program in place when the breach happened. What counts as conforming depends on headcount.

The question usually arrives sideways. An insurance broker mentions a Texas safe harbor at renewal, or an attorney raises it while reviewing a client contract, and a Houston owner wants to know what the business has to have in place. The law took effect September 1, 2025 as Chapter 542 of the Texas Business and Commerce Code. It passed the Texas Senate 31 to 0 and the House 109 to 27.

CinchOps builds and documents SB 2610 cybersecurity programs specifically for small and mid-sized businesses in the Houston metro, mapped to the tier for each headcount: fewer than 20, 20 to 99, or 100 to 249 employees.

THE LAW IN THREE FACTSTexas SB 2610 at a GlanceUnder 250employees: the size ofbusiness the law coversSept 1, 2025the date the lawtook effect3 tiersof requirements,set by headcountCinchOps · cinchops.com
The short version: SB 2610 does not order a business to do anything. It rewards one that already had a written, maintained security program before the breach. CinchOps is an IT provider and not a law firm, so confirm how the law applies to your business with an attorney.

What Does Texas SB 2610 Require at Each Business Size?

The law sets 3 tiers. Headcount decides which one applies.

Texas SB 2610 requires password policies and employee cybersecurity training for a business with fewer than 20 employees, the CIS Controls Implementation Group 1 for a business with 20 to 99 employees, and conformance to a recognized framework such as NIST or ISO/IEC 27000 for a business with 100 to 249 employees.

The table compares the 3 SB 2610 tiers by employee count, the wording in Section 542.004 of the law, and the records CinchOps recommends a business in that tier keep on file.

EmployeesWhat Section 542.004 saysRecords to keep on file (CinchOps recommendation)
Fewer than 20"Simplified requirements, including password policies and appropriate employee cybersecurity training"A written password policy, proof it is enforced, and dated training records for each employee
20 to 99"Moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1"A dated assessment against each Implementation Group 1 safeguard, with the gaps found and the date each was closed
100 to 249Conformance to an industry-recognized cybersecurity framework named in the lawThe framework name and version, a dated assessment against it, and a plan for the open items

A 12-person CPA practice in Katy and a 60-person engineering firm in The Woodlands sit in different tiers and owe different amounts of work. Both tiers use the word "including," which sets a floor and stops short of a complete list. Every tier also has to meet the base test in the law: administrative, technical and physical safeguards that protect personal identifying information and sensitive personal information.

THREE TIERSWhat SB 2610 Asks For at Each SizeFewer than 20employeesSIMPLIFIEDPassword policies andemployee security training20 to 99employeesMODERATECIS ControlsImplementation Group 1100 to 249employeesRECOGNIZED FRAMEWORKNIST, ISO/IEC 27000 oranother framework in the lawCinchOps · cinchops.com

The frameworks SB 2610 names include the NIST Cybersecurity Framework, NIST Special Publications 800-171 and 800-53, the CIS Critical Security Controls, the ISO/IEC 27000 series, HITRUST, SOC 2 and FedRAMP, plus "other similar frameworks." A business already subject to HIPAA, the Gramm-Leach-Bliley Act or PCI DSS has to conform to the current version of those as well. CinchOps explains two of the options in CIS Controls for Houston businesses and the NIST Cybersecurity Framework for small and mid-size businesses.

The law covers a business entity in Texas that has fewer than 250 employees and owns or licenses computerized data that includes sensitive personal information. Texas defines that as an unencrypted name combined with a Social Security number, a driver's license or government ID number, or an account or card number with its access code, along with identifying health information. The bill text does not say how to count part-time staff or contractors, so a business near 20, 100 or 250 should ask an attorney which side of the line it is on.

What Does the SB 2610 Safe Harbor Protect, and What Does It Leave Open?

The protection is narrower than the name suggests.

The SB 2610 safe harbor removes one thing: exemplary damages in a lawsuit arising from a breach of system security. The lawsuit can still be filed, compensatory damages are still available, and Section 542.005 says the law does not change any common law or statutory duty a business already has.

THE LIMITSWhat the Safe Harbor Does and Leaves OpenWHAT IT DOESBars exemplary damagesin a breach of system security lawsuitfiled against a qualifying businessWHAT IT LEAVES OPENThe lawsuit itselfCompensatory damagesBreach notice and other existing dutiesCinchOps · cinchops.com

Exemplary damages are defined in Texas law as "any damages awarded as a penalty or by way of punishment but not for compensatory purposes," and the definition includes punitive damages. They are the part of a verdict meant to punish. Compensatory damages, the part that repays what people lost, are outside the safe harbor.

Existing duties stay in force. A Texas business that suffers a breach of system security still has to notify affected individuals no later than the 60th day after it determines the breach occurred, and has to notify the Texas Attorney General no later than the 30th day when at least 250 Texas residents are involved. CinchOps walks through that sequence in the data breach reporting checklist for Texas small businesses.

Two limits in the text catch owners out. The protection applies only to a cause of action that accrues on or after September 1, 2025. And the business has to demonstrate that the program was implemented and maintained "at the time of the breach," so the burden sits with the business and the program cannot be built afterward.

How Does a Houston Business Prove It Qualified for the SB 2610 Safe Harbor?

The law says "demonstrates." In practice that means paper with dates on it.

A Houston business proves it qualified for the SB 2610 safe harbor with dated records created before the breach. The law requires the business to demonstrate that it implemented and maintained the program, so it needs a named framework, a dated assessment against it, training records and a log showing the program was kept up.

In 35+ years doing this, the gap I see most often is missing dates. The firewall is configured, the staff sat through training and the backups run, and nobody can show when any of it was last checked. A program that exists only in people's heads is hard to demonstrate to anyone.

THE EVIDENCE FILEFive Records That Show a Maintained ProgramHeadcount and tierThe employee count and which of the 3 tiers appliesNamed frameworkThe framework and the version the program followsDated assessmentThe program checked against that framework, with a datePolicy and training recordsWho was trained, on what, and whenReview logDated entries showing the program was kept upA CinchOps working list, not wording from the law and not legal advice.CinchOps · cinchops.com

The local numbers suggest how much work is ahead. The CinchOps Houston Area Security Index scored 4,393 Houston-area businesses on external security signals, and 49.6% earned a D or an F. An outside score does not decide whether a business qualifies under SB 2610, because the Index cannot see internal policies or training. It does show that about half the businesses measured would have visible problems to fix before they could make the case.

Frameworks change, and the law allows for it. When a named standard is updated, a program keeps qualifying if the business updates it by the later of 2 dates: the implementation date published in the new standard, or the first anniversary of its publication. A dated network security audit each year is the simplest way to show the program kept pace.

The safe harbor is the one part of a breach lawsuit a business gets to prepare for in advance. If you were going to secure the company anyway, the extra cost is writing it down and keeping the dates.
Shane Stevens, CEO, CinchOps - LinkedIn

Find Out Which SB 2610 Tier You Are In and What Is Missing

For a business with 20 to 99 employees, the law points to CIS Controls Implementation Group 1. CinchOps assesses Houston businesses against it through its CIS Controls service.

See CIS Controls for Houston businesses →

How Can CinchOps Help a Houston Business Meet the SB 2610 Requirements?

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

HOW CINCHOPS HELPSTier, Gaps, Evidence1Find the tierHeadcount mapped tothe SB 2610 requirement2Close the gapsMissing controls fixed,each change dated3Keep the evidenceAssessment and reviewlog kept currentCinchOps · cinchops.com
  • The CIS Controls service assesses a business against Implementation Group 1 and records each gap and the date it was closed.
  • An IT security audit produces the dated, written assessment the evidence file is built around.
  • Through cybersecurity services, CinchOps closes the gaps an assessment finds and runs 24/7 threat monitoring between reviews.
  • Under managed IT support, help desk requests are answered in under 15 minutes.
  • CinchOps works with businesses across the Houston area, including CPA firms, law firms and engineering firms.

SB 2610 pays the business that did the work before anything went wrong and can show when it did it. The Houston businesses CinchOps assesses usually have part of a program in place and little of the paperwork. Find your tier, get the assessment dated, and talk to CinchOps if you want it built and kept current.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the Texas SB 2610 safe harbor?

The Texas SB 2610 safe harbor is a protection in Chapter 542 of the Texas Business and Commerce Code. It bars exemplary damages in a data breach lawsuit against a business with fewer than 250 employees that had a conforming cybersecurity program in place at the time of the breach.

Does Texas SB 2610 require my business to do anything?

No. SB 2610 is voluntary. It creates no new duty and no new right to sue, and a business that ignores it breaks no rule. What the business gives up is the protection from exemplary damages, which is available only to one that built and maintained a conforming program before a breach.

What does SB 2610 require for a business with 20 to 99 employees?

A business with at least 20 and fewer than 100 employees must meet what the law calls moderate requirements, including the Center for Internet Security Controls Implementation Group 1. The practical step is a dated assessment that lists each Implementation Group 1 safeguard, whether the business meets it, and when any gap was closed.

Can a business qualify for the SB 2610 safe harbor after a breach?

No. The law protects a business that demonstrates it implemented and maintained the program at the time of the breach. A program assembled after the incident does not meet that test, which is why the dated records created beforehand matter more than the security tools themselves.

What does an SB 2610 cybersecurity program cost in Houston?

CinchOps prices managed IT and security at a flat monthly rate of $100 to $250 per user per month, with no long-term contracts, no hidden fees and no cancellation penalties. The tier sets the amount of work, so a 15-person office needs far less than a 150-person one. Ask for a written scope.

Discover More

Which Compliance Rules Apply to a Houston Small Business?
Network Security Audit in Houston: What It Covers
Making Sense of the NIST Cybersecurity Framework for Houston Small & Mid-size Businesses
9 Things to Do After Your Cyber Insurance Renewal Questionnaire Arrives
How To Run A Cybersecurity Tabletop Exercise At A Houston Business
Why Security Awareness Training Matters Most for Houston SMBs

Sources

  • Texas Legislature, SB 2610, enrolled text (89th Regular Session), adding Chapter 542 to the Business and Commerce Code
  • Texas Business and Commerce Code, Chapter 521, Sections 521.002 and 521.053 (definitions and breach notification)
  • Texas Civil Practice and Remedies Code, Section 41.001 (definition of exemplary damages)
  • Spencer Fane, Texas Cybersecurity Safe Harbor for Small and Mid-Sized Businesses, October 29, 2025
  • CinchOps, Houston Area Security Index 2026
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

August 10th, 2026
AI Cybersecurity Houston
AI Security Roadmap for Houston Businesses: The Four-Phase Guide

A Four-Phase AI Security Roadmap For Houston Businesses – How Houston Businesses Can Secure AI Without Slowing Down

May 27th, 2026
Managed IT Houston
Intelligence Is Now Manufactured, and AI Tokens Are the New Industrial Commodity

Token Consumption Patterns For Houston Businesses – Why Token Economics Belong On The CFO Dashboard

March 11th, 2026
Network Segmentation
Network Segmentation for Small Businesses: Isolate Threats Before They Spread

Segmentation Strategies That Fit Small Business Budgets – Build Boundaries That Attackers Can’t Cross Silently

June 9th, 2025
Managed Services Provider Cybersecurity
Industrial Ransomware Surge: Dragos Q1 2025 Analysis Reveals Critical Threats to Manufacturing and Infrastructure

Q1 2025 Ransomware Data Analysis for Manufacturing and Infrastructure Organizations – Industrial Ransomware Attacks Surge 18% in Q1 2025

February 2nd, 2026
Cybersecurity Houston
Role of Remote Work Security for Houston SMBs

Your Team Works Remote Make Sure Your Security Does Too – Practical Security For Houston’s Remote Teams

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Compliance
  • Virtual CTO & CIO
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy