Guide · Security Baseline, Documentation & Vendors

What Texas SB 2610 actually asks of a 40-person company

A Texas company with fewer than 250 employees that is sued after a data breach can, since September 1, 2025, raise a defense against exemplary damages if it shows it had a cybersecurity program in place that conformed to a recognized framework. That sentence is the whole law. What it asks of a company of forty people is more specific than the summaries suggest, and less expensive than the fear suggests. What follows is how the statute reads, not legal advice; the baseline we write is meant for your lawyer's desk as much as for your server room.

Published 8 September 2026 · From the enterprise IT practice in Houston, Texas. Business hours, US Central; an engineer replies within one business day.

What the law does, and what it does not

Senate Bill 2610 added Chapter 542 to the Business and Commerce Code. It applies to a business that owns or licenses computerized data containing sensitive personal information and has fewer than 250 employees. If such a business is sued in tort after a breach, it is entitled to an affirmative defense against exemplary damages, the punitive part of a judgment, if it can show it implemented and maintained a cybersecurity program that met the statute's requirements at the time of the breach.

It does not shield the business from actual damages, from the Attorney General, or from the duty to notify. The clocks in Business and Commerce Code §521.053 keep running: affected Texans have to be told within 60 days of the breach being determined, and the Attorney General within 30 days if 250 or more Texans are affected; those reports are published by the Attorney General, so the second clock is a public one.

The three tiers, and where forty people lands

The statute scales the expected program to headcount, as the text reads:

  • Fewer than 20 employees: a program with reasonable cybersecurity measures, such as password policies and employee awareness training
  • 20 to 99 employees: a program that conforms at least to the Center for Internet Security's Critical Security Controls at Implementation Group 1
  • 100 to 249 employees: a program that conforms to a recognized framework, among them the NIST Cybersecurity Framework, NIST SP 800-53 or 800-171, the CIS Controls, ISO/IEC 27001, or the federal cloud baseline

A company of forty is in the middle tier, so the question is a specific one: does its program conform to CIS Controls Implementation Group 1? The statute also expects a program to keep up when the framework it follows is revised, within a reasonable period, which is a way of saying the document has a review date on it.

What Implementation Group 1 is in practice

IG1 is the 56 foundational safeguards of the 18 CIS Controls, chosen to be achievable by a small company with limited IT staff. Grouped the way we build them:

  • Know what you have: an inventory of every device and every piece of software, with the unauthorized ones removed
  • Know where the data is: what sensitive data exists, where it lives, who can reach it, and when it is disposed of
  • Standard configurations: laptops, servers, and the firewall built from a baseline rather than from defaults, with unused accounts and services off
  • Accounts and access: unique accounts per person, multi-factor authentication on remote access and on every administrator account, access removed when it is no longer needed
  • Patching: operating systems and applications updated on a written schedule, with a vulnerability scan that tells you what was missed
  • Logs: kept, with time synchronized, for the systems that matter
  • Email and browsers: DNS filtering and mail protections in place
  • Malware defenses: on every device, updating on their own
  • Recovery: backups automated, protected, kept off-site, and restored from on a schedule to prove they work
  • The network: infrastructure kept current and managed
  • People: security awareness training at hire and yearly, including phishing and password handling
  • Vendors: a list of the service providers that hold your data
  • Incidents: a named person to handle an incident, and a way for staff to report one

'Implemented and maintained' means evidence

The defense is only available for a program that existed at the time of the breach, so a program written afterwards is worth nothing, and a program that existed only as a policy nobody followed is worth very little. What a court, an insurer, or a customer's questionnaire will want to see is artifacts: the asset inventory with a date on it, the report showing multi-factor authentication is on for every administrator, the patch report for last month, the log of the last restore test, the training records, the vendor list, and a review date on the program itself.

That is a folder, kept current, with an owner. Most of its contents are things a well-run IT function produces anyway, which is why the gap at a 40-person company is usually documentation and three or four controls rather than a program from scratch.

What this costs a 40-person company in effort

No figure, because it depends on the estate, but the shape is consistent. A company that already has managed endpoints, a real firewall, tested backups, and multi-factor authentication is a documentation exercise away from IG1. A company running Windows 10 on the floor, a server under a desk, and shared admin passwords has the same list of projects it needed anyway, now with a reason to schedule them. The write-up is the same document either way, and it also answers most of what a cyber-insurance application asks.

This is not a certification. Nobody certifies a company against IG1 or the NIST framework, and a provider that says it will is selling a stamp. What we produce is the security baseline and documentation described on our Enterprise IT services page, written against the statute and the framework, with the artifacts above in it, and reviewed on a date.

Reading the statute yourself

The text is short and worth reading: Business and Commerce Code Chapter 542 for the safe harbor, and §521.053 for the notification clocks. None of this page is legal advice; what the statute means for your company is a question for your counsel, and the baseline document is written so it can be handed to them.

Sources, so you can check the summary against the original: Business and Commerce Code, Chapter 542 (Texas Legislature Online); Business and Commerce Code, §521.053 (Texas Legislature Online); CIS Critical Security Controls, Implementation Group 1 (Center for Internet Security).

Where this sits on the IT page

One row of our Enterprise IT services page does this work: Security Baseline, Documentation & Vendors. The page covers the eight layers together, on-site across Greater Houston and remote across Texas, and starts every engagement with an inventory of what you have.

More guides

Other tickets this page gets

Printers, Scanners & Peripherals

Why a network printer keeps going offline in the office, and the four settings that fix it

Usually addressing, not hardware: a reserved address, a standard TCP/IP port, one driver from one place, and power settings that leave the network interface awake.

Read the guide →
Servers, Virtualization & Backup

Windows Server 2012 R2 gets its last updates on October 13, 2026 and 2016 on January 12, 2027: the per-server decision

Two deadlines four months apart, and a decision that is made one server at a time: in place, rebuilt beside the old one, or retired with the share that moved.

Read the guide →
Active Directory & Entra ID

Your only IT person quit. What to lock down in the first 48 hours

Nothing needs rebuilding today. The order of work for two days: the accounts that own everything, the leaver's own access, what would break next, and what to write down.

Read the guide →
Get in touch

Send your headcount and what is already in place.

Roughly how many people, whether laptops are managed, where backups go, and whether administrators use multi-factor authentication. You get back where you sit against Implementation Group 1 and which of the 56 safeguards are the real gaps.

Prefer to talk?

Call 832-598-8234 or email msco@stoneagesoftware.com. Houston, Texas — serving Houston, The Woodlands, Conroe, Sugar Land, Katy, Pearland, and the Greater Houston metro.

What happens next

We read your message, an engineer replies with questions or a straight answer, and if it's worth a call we book one. No drip campaign, no handoff to sales.

No obligation — we reply within one business day. This form sends your details to Stone Age Software LLC so we can respond to you. See our privacy policy for how we handle them. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.