A year ago this month, Texas quietly passed one of the more useful pieces of legislation a business owner will read about all year.
Senate Bill 2610, sometimes called the Cybersecurity Safe Harbor Act, took effect on September 1, 2025. It applies to Texas businesses with fewer than 250 employees that handle sensitive personal information, which describes the overwhelming majority of CPA firms, law practices, medical and dental offices, insurance agencies, and title companies in this state. The idea behind it is simple. If your business is sued after a data breach, and you can show that a genuine, documented cybersecurity program was already in place before the breach happened, the law shields you from punitive damages.
It does not shield you from everything. Compensatory damages, regulatory investigations, and class actions are all still on the table. What SB 2610 removes is the additional, often much larger, punitive exposure, and it does so as a reward for having done the work in advance rather than after the fact.
A year in, the lesson many businesses have learned the hard way is that the protection is conditional. It only applies if the program was documented and actually maintained before an incident, not assembled afterward to look good in front of a judge. Legislators in Ohio and Utah passed similar safe harbor laws years earlier, and both states saw a measurable rise in cybersecurity investment once businesses understood the protection was real but earned, not automatic.
What counts as a qualifying program
The law asks for administrative, technical, and physical safeguards scaled to the size of the business, generally aligned with a recognized framework such as NIST, CIS Controls, or SOC 2. There is no single certificate to obtain. What matters is whether the safeguards were genuinely in place and can be demonstrated after the fact.
Why this matters beyond the legal upside
The businesses treating SB 2610 seriously are not doing it purely for the liability protection. They are discovering, often for the first time, an honest picture of their own network, their own vendors, and their own employees’ use of AI tools, because that is what building a real program requires. The legal incentive turns out to be a reason to finally do the security work most owners already suspected they needed.
Where to start
A qualifying program begins with an honest assessment of where your business actually stands today. That is precisely what AstraLink Connect’s Verify assessment is built to provide: a plain English look at your network, your devices, and your AI tool usage, documented in a way that supports exactly the kind of program SB 2610 is asking for.
This is general information, not legal advice. Please confirm your specific obligations under SB 2610 with your attorney or compliance advisor.
See where your business stands today. Request a Verify assessment from AstraLink Connect.