Austin Buonasera
 • 
September 3, 2025
 • 
6
 Minute read

Texas SB 2610: The Cybersecurity Safe Harbor That Can Cap Your Breach Liability

Texas SB 2610 shields businesses under 250 employees from punitive damages after a breach, if they run a compliant security program. What the law requires, by size.

Quick Summary

  • Texas SB 2610, the state's Cybersecurity Safe Harbor law, took effect September 1, 2025. It's in force now.
  • It bars punitive (exemplary) damages in a breach lawsuit if your business maintained a compliant written cybersecurity program. It doesn't stop the suit or ordinary damages — it caps the part that can multiply into a business-ending number.
  • It applies to Texas businesses with fewer than 250 employees, with requirements that scale by headcount.
  • Under 20 employees: password policies and training. 20–99: CIS Controls IG1. 100–249: a recognized framework like NIST CSF or ISO 27001.
  • If you already comply with HIPAA, GLBA, PCI DSS, or ISO 27001, you're treated as meeting the standard.
Sunset over foggy mountains with dark silhouettes and a cloudy sky.

If you run a business in Texas, a law that took effect on September 1, 2025 changed the math on a data breach — and most small businesses still haven't heard of it. It's Senate Bill 2610, the Texas Cybersecurity Safe Harbor law, and for once it's a cybersecurity rule that works in your favor.

The short version: if your business gets breached and gets sued, SB 2610 can block the most dangerous kind of damages — as long as you did the security work ahead of time.

What the safe harbor actually does

SB 2610 adds a new chapter to the Texas Business & Commerce Code that bars a court from awarding exemplary damages — punitive damages — against a business in a lawsuit arising from a data breach, if that business maintained a compliant written cybersecurity program before the breach.

That distinction is the whole point. The law doesn't stop someone from suing you, and it doesn't erase your responsibility for actual, compensatory damages. What it removes is the punitive multiplier — the part of a judgment meant to punish, which stacks on top of real damages and can turn a survivable incident into a business-ending one. For a small or mid-sized business, that multiplier is often the difference between recovering and closing the doors.

Think of it as an affirmative defense you build in advance. You can only raise it if the program was already in place.

Who it covers, and what's required

The safe harbor applies to Texas businesses with fewer than 250 employees that handle sensitive personal information. What you have to do scales with your size — the law doesn't ask a fifteen-person shop to run an enterprise security program.

  • Fewer than 20 employees. The simplified tier: documented password policies and ongoing cybersecurity training for your staff.
  • 20 to 99 employees. Adopt the CIS Controls Implementation Group 1 (IG1) — a defined set of basic safeguards widely treated as cyber hygiene.
  • 100 to 249 employees. Implement a recognized framework, such as the NIST Cybersecurity Framework, NIST SP 800-171 or 800-53, the CIS Controls, or the ISO/IEC 27000 series.

There's also a shortcut for regulated businesses. If you already comply with HIPAA, the Gramm-Leach-Bliley Act, PCI DSS, or ISO/IEC 27001, you're treated as meeting the framework requirement. For a CPA firm, a medical practice, or any business already under one of those regimes, much of the work is done — it just has to be real, documented, and maintained.

One catch worth stating plainly: the scale of your program has to fit your business, and it has to actually be in place and maintained. A policy in a drawer that nobody follows is not a compliant program, and it won't hold up as a defense.

Why this matters for small businesses specifically

Attackers target small and mid-sized businesses because they tend to hold valuable data behind lighter defenses. That's not a scare line; it's why SMBs show up in the breach reports year after year. SB 2610 changes part of that equation. For the first time, the security work you do isn't only risk reduction — it's a documented legal shield if the worst happens.

Texas is now the fifth state to offer this kind of safe harbor, and the pattern is spreading. The businesses that treat it as an opportunity, rather than one more thing to ignore, come out ahead on both security and liability.

How we help you qualify

Qualifying for the safe harbor isn't about buying a product. It's about building and maintaining a program that maps to one of the recognized standards, and being able to prove it. That's the core of our managed cybersecurity work:

  • Assess where you stand today against the framework that fits your size.
  • Close the gaps — MFA, endpoint detection, email security, access controls, and backups.
  • Write and maintain the policies and documentation that prove the program exists.
  • Keep it current, because a safe harbor only protects you if the program was real and maintained when the breach happened.

If you're a Texas business under 250 employees, the practical first step is finding out which tier you fall into and how far your current setup is from it.

See where you stand. A few questions will show you which SB 2610 tier applies and where your gaps are. About three minutes.

Check your exposure · Book a consultation

This article is general information, not legal advice. For how SB 2610 applies to your specific situation, consult qualified counsel.

Cards showing CPA firms scored 3/8 on client-data protection risks with notes on regulatory penalties and breaches.
3 minutes or less

Not sure what's exposed? Start here.

Answer a short set of questions about email, devices, vendors, backups, and access. No passwords, no system details — just the questions an attacker has already answered about you.
Get Your Risk Assessment