Think you're being hit by ransomware right now? Don't panic — start here →
Already a safemode IT client? Call our 24/7 Security Operations Center immediately: 512-761-7652, Option 1
SAFE HARBOR LAWS

Good security can now be legal protection, not just good practice.

Texas now gives businesses a legal shield if they've adopted a recognized cybersecurity framework and still get breached anyway. This is general information, not legal advice — but it's worth understanding what's on the table.

TEXAS · EFFECTIVE SEPTEMBER 1, 2025

Texas SB 2610: the new safe harbor for Texas small businesses

Senate Bill 2610 shields qualifying businesses with fewer than 250 employees from exemplary (punitive) damages in a data breach lawsuit — provided they maintain a cybersecurity program scaled to their size. It doesn't eliminate liability entirely, but it takes the largest damages exposure off the table.

Your employee countWhat you need to qualify
Fewer than 20 employeesA written password policy and cybersecurity training for staff
20–99 employeesCIS Critical Security Controls, Implementation Group 1
100–249 employeesNIST Cybersecurity Framework or the HITRUST Common Security Framework
Any size, already compliantExisting HIPAA, GLBA, or PCI-DSS compliance also satisfies the law

Want the deeper dive? Read safemode IT's full breakdown: Texas SB 2610: The New Cybersecurity Safe Harbor Law Every Business Owner Must Know.

This is general information, not legal advice

Safe harbor laws are specific and evolving. Talk to a licensed attorney about how SB 2610 applies to your specific business before relying on it.

WANT TO KNOW WHERE YOU STAND AGAINST SB 2610?

Get a free look at your safe harbor readiness.

We'll help you see which tier of SB 2610 applies to your business and what's left to put in place.