Good security can now be legal protection, not just good practice.
Texas now gives businesses a legal shield if they've adopted a recognized cybersecurity framework and still get breached anyway. This is general information, not legal advice — but it's worth understanding what's on the table.
Texas SB 2610: the new safe harbor for Texas small businesses
Senate Bill 2610 shields qualifying businesses with fewer than 250 employees from exemplary (punitive) damages in a data breach lawsuit — provided they maintain a cybersecurity program scaled to their size. It doesn't eliminate liability entirely, but it takes the largest damages exposure off the table.
| Your employee count | What you need to qualify |
|---|---|
| Fewer than 20 employees | A written password policy and cybersecurity training for staff |
| 20–99 employees | CIS Critical Security Controls, Implementation Group 1 |
| 100–249 employees | NIST Cybersecurity Framework or the HITRUST Common Security Framework |
| Any size, already compliant | Existing HIPAA, GLBA, or PCI-DSS compliance also satisfies the law |
Want the deeper dive? Read safemode IT's full breakdown: Texas SB 2610: The New Cybersecurity Safe Harbor Law Every Business Owner Must Know.
This is general information, not legal advice
Safe harbor laws are specific and evolving. Talk to a licensed attorney about how SB 2610 applies to your specific business before relying on it.
Get a free look at your safe harbor readiness.
We'll help you see which tier of SB 2610 applies to your business and what's left to put in place.