Texas New “Safe Harbor” Law

Texas SB 2610: The Cybersecurity Safe Harbor Every Small Business Owner Needs to Understand

Published September 2025 by AegisPro CyberShield TX

TL;DR

Texas Senate Bill 2610, effective September 1, 2025, gives small and mid-sized Texas businesses a legal safe harbor from punitive damages in data breach lawsuits, but only if a documented cybersecurity program is in place before an incident occurs.

▪ Applies to Texas businesses with fewer than 250 employees that handle sensitive personal information
▪ Requirements scale by employee count, from basic policies for the smallest businesses to full framework compliance for larger ones
▪ Shields against punitive damages only, not compensatory damages, class actions, or regulatory action
▪ Protection is not retroactive, so waiting until after a breach means losing the safe harbor entirely
▪ Businesses must be able to document and prove their program was active at the time of the incident

Bottom line: SB 2610 rewards proactive cybersecurity with real legal protection. If you have not built your program yet, now is the time.

____________________________________________________________________________________________________________________________________________________________________________

If you own a small or mid-sized business in Texas, there is a law on the books that could quite literally save your business from financial ruin after a cyberattack. It is called Senate Bill 2610, and most small business owners have never even heard of it.

That is a problem, because SB 2610 is one of the most business friendly cybersecurity laws Texas has ever passed. It rewards businesses that take security seriously with real legal protection when the worst happens.

Why SB 2610 Matters to You

The reality of running a small business in 2026 is that cyberattacks are no longer a question of if but when. According to the 2025 Verizon Data Breach Investigations Report, small and mid-sized businesses report nearly four times the number of cybersecurity incidents compared with large organizations.

Historically, a single data breach could bankrupt a small business through a combination of remediation costs, regulatory fines, and civil lawsuits. That is where SB 2610 steps in.

Signed by Governor Greg Abbott on June 20, 2025 and effective September 1, 2025, the law establishes a legal safe harbor for Texas businesses that adopt recognized cybersecurity frameworks. In practical terms, if your business is sued after a breach and you can prove you had a real cybersecurity program in place beforehand, the court cannot award punitive damages against you.

For a small business, that is a massive shield against what has historically been the most financially devastating outcome of a breach lawsuit.

Who Qualifies for the Safe Harbor

SB 2610 was written specifically with small and mid-sized businesses in mind. To qualify, your business must:

▪ Operate in Texas and be subject to Texas jurisdiction
▪ Have fewer than 250 employees
▪ Own or license computerized data containing sensitive personal information
▪ Have a documented cybersecurity program in place before a breach occurs

That last point is critical. The law is explicit that your cybersecurity program must be implemented and maintained before an incident. Post-breach implementation does not qualify for safe harbor protection retroactively. Waiting until after an incident means you lose the protection entirely.

Requirements Scale With Business Size

One of the strongest features of SB 2610 is that it does not treat a 10 person business the same as a 200 person business. The law scales its requirements based on employee count:

Fewer than 20 employees: Basic measures such as password policies and employee training
20 to 99 employees: CIS Controls Implementation Group 1, covering foundational cyber hygiene
100 to 249 employees: Full compliance with a recognized framework such as NIST CSF, NIST SP 800-53/171, CIS Controls, ISO/IEC 27001, or FedRAMP

If your business already complies with HIPAA, Gramm-Leach-Bliley, or PCI-DSS, you likely already meet SB 2610 requirements as well.

What SB 2610 Does Not Cover

Understanding the limits of this law is just as important as understanding its protections. SB 2610 shields you from punitive damages only. It does not protect you from:

▪ Compensatory or actual damages resulting from a breach
▪ Class action lawsuits
▪ Regulatory investigations and enforcement actions
▪ Breach notification obligations under other Texas laws

Think of SB 2610 as a legal seatbelt. It will not prevent every consequence of a crash, but it can absolutely keep your business from being totaled.

What Compliance Actually Looks Like

At AegisPro CyberShield TX, we have been helping Texas businesses prepare for and align with SB 2610 since the law took effect. True compliance is more than checking a box. It requires:

▪ A written cybersecurity program aligned to a recognized framework
▪ Documented administrative, technical, and physical safeguards
▪ Ongoing employee security awareness training
▪ Evidence of active monitoring, patching, and incident response
▪ Dated policies, deployment records, and training logs to prove your program was active at the time of a breach

That last piece matters more than most business owners realize. SB 2610 operates as an affirmative defense, which means your legal team must be able to demonstrate with evidence that your cybersecurity program was in place before the breach. Verbal claims and good intentions do not qualify. Documentation does.

Our Advice: Get Compliant Before You Need To

The businesses that will benefit most from SB 2610 are the ones that act early. Waiting until after an incident eliminates the protection entirely, and reactive cybersecurity is always more expensive than proactive.

Whether you are running a retail shop in Fort Worth, a medical practice in Dallas, or a professional services firm across the DFW area, now is the time to build or formalize your cybersecurity program.

▪ Start with a Cybersecurity Risk Assessment
▪ Choose a framework appropriate for your business size
▪ Document your policies, controls, and training programs
▪ Maintain evidence of active security practices year round

Final Thoughts

SB 2610 represents a fundamental shift in how Texas treats small business cybersecurity. Rather than punishing businesses after a breach, the state is rewarding those that invest in real protection. That is a rare and powerful opportunity, but only for the businesses prepared to take advantage of it.

The safe harbor is there. The question is whether your business will be ready to use it.

Need help preparing for SB 2610 compliance?

Schedule a Free Risk Assessment or call us at (817) 993-9427.

AegisPro CyberShield TX
Cybersecurity Built for Texas Small Businesses™

Next
Next

Texas SB3 Veto