Texas SB 2610 Compliance for small and mid-size businesses
We build, run, and document the cybersecurity program Texas SB 2610 describes, so you have a clear record when it matters.
A cybersecurity program built for the Texas safe harbor
Texas SB 2610 gives qualifying businesses with fewer than 250 employees a defense against exemplary (punitive) damages in a lawsuit after a data breach, when a qualifying cybersecurity program was in place at the time. ALCON DTS helps you build that program, run it every day, and keep the evidence that shows it was working.
Your attorney advises on how the law applies to you. We handle the controls, the documentation, and the regular reviews that keep the program current.
Who it helps
- Texas businesses with fewer than 250 employees
- Organizations that hold employee, patient, client, or customer records with sensitive personal information
- Firms growing past 20 or 100 employees, where the program requirements step up
- Businesses that want a written program to show insurers and customers
What you get
Readiness review
We compare your current controls with the SB 2610 tier that matches your headcount.
Framework alignment
We align your program to a recognized framework, such as CIS Controls IG1 or the NIST Cybersecurity Framework, based on your size.
Written program and policies
Administrative, technical, and physical safeguards, written down and kept current.
Controls we run
Multifactor authentication, device protection, email security, tested backups, and security training, managed for you.
Evidence file
An organized record of policies, training completion, restore tests, and reviews.
Program reviews
Regular reviews keep the program aligned with the current framework version.
How it works
Assess
We confirm your size tier and review your current controls.
Build
We close the gaps and write the program down.
Run
We operate the controls and collect evidence as the work happens.
Review
We review the program on a schedule and update it when frameworks change.
Which SB 2610 tier fits you? Ten quick questions show how SB 2610 likely applies to your organization, including your tier, plus other security rules to know.
Learn more about the law
Our plain-language guide explains who qualifies, what the program looks like at each size, and which frameworks the law names. The readiness checklist helps you see where your organization stands today.
Related services
SB 2610 programs draw on these services:
Start with a cybersecurity assessment
We compare your current controls with the SB 2610 tier that fits your headcount, show you what is already in place, and give you a clear plan for the gaps.
Request a cybersecurity assessment
This page is general information about Texas law. Your attorney advises on how it applies to your organization.
Build your SB 2610 program with ALCON DTS.
Controls, documentation, and reviews in one ongoing service.

