
For Texas law firms, cybersecurity is increasingly a business-risk, client-data, and governance issue, not simply an IT responsibility.
A Texas law that took effect September 1, 2025 gives qualifying businesses another reason to approach cybersecurity as a structured, documented program.
Texas Senate Bill 2610 created a cybersecurity safe harbor that can limit the recovery of exemplary damages following certain data breaches when a qualifying business can demonstrate that it implemented and maintained a cybersecurity program that meets the law’s requirements.
That does not mean SB 2610 prevents a lawsuit after a breach. It does not eliminate every form of liability. And it does not create a new cybersecurity mandate specifically for law firms.
What it does is make the maturity of an organization's cybersecurity program potentially significant after an incident.
For Texas law firms that hold sensitive client, employee, financial, health, or personally identifying information, that deserves attention.
What Is Texas SB 2610?
Texas SB 2610 added Chapter 542 to the Texas Business & Commerce Code.
The law applies only to a Texas business entity that:
- Has fewer than 250 employees; and
- Owns or licenses computerized data containing sensitive personal information.
When a qualifying business is involved in an action arising from a breach of system security, the law prohibits recovery of exemplary damages if the business can demonstrate that, at the time of the breach, it had implemented and maintained a cybersecurity program meeting the requirements of the statute.
That last phrase matters.
SB 2610 is not simply about purchasing cybersecurity products or writing a security policy.
The statute focuses on an implemented and maintained cybersecurity program.
Does SB 2610 Apply to Texas Law Firms?
Potentially.
SB 2610 is not written specifically for the legal industry. It applies to qualifying Texas business entities with fewer than 250 employees that own or license computerized data containing sensitive personal information.
Many law firms routinely maintain information that could fall within protected or sensitive categories, including information associated with employees, clients, financial matters, litigation, transactions, healthcare matters, identification records, and other confidential business activities.
Whether a particular law firm meets the statutory requirements should be evaluated with legal counsel.
From a cybersecurity perspective, however, SB 2610 raises a useful question for firm leadership:
Could your firm demonstrate that it has implemented and maintained a cybersecurity program rather than simply accumulated cybersecurity tools?
That is a very different standard.
What Does a Cybersecurity Program Need to Include Under SB 2610?
SB 2610 says a qualifying cybersecurity program must contain administrative, technical, and physical safeguards designed to protect personal identifying information and sensitive personal information.
The program must also be designed to protect against threats to the integrity of that information and against unauthorized access or acquisition that could create a material risk of identity theft or other fraud.
The law further connects the cybersecurity program to recognized cybersecurity frameworks.
Those include, among others:
- The NIST Cybersecurity Framework
- NIST Special Publication 800-171
- NIST 800-53 and 800-53A
- CIS Critical Security Controls
- ISO/IEC 27000-series standards
- Secure Controls Framework
- SOC 2
- Other similar cybersecurity industry frameworks or standards
The statute also recognizes certain regulatory or industry standards when they apply to the business, including HIPAA, Gramm-Leach-Bliley Act requirements, and PCI DSS.
The practical takeaway is important:
SB 2610 connects cybersecurity risk management to established frameworks rather than leaving “reasonable cybersecurity” completely undefined.
For law firms, that creates an opportunity to move from informal security practices toward a program that can be assessed, documented, maintained, and improved.
SB 2610 Scales Cybersecurity Expectations by Business Size
One particularly relevant feature of SB 2610 is that it recognizes that a 15-person business and a 200-person business do not operate with the same resources or complexity.
The law includes size-based requirements.
Businesses With Fewer Than 20 Employees
The statute describes simplified requirements, including password policies and appropriate employee cybersecurity training.
Businesses With 20 to 99 Employees
The statute calls for moderate requirements, including the requirements of CIS Controls Implementation Group 1.
CIS describes IG1 as a foundational set of safeguards intended to provide essential cyber hygiene.
Businesses With 100 to 249 Employees
The statute requires compliance with the broader framework requirements identified in SB 2610.
These distinctions make the legislation particularly relevant to small and midsize organizations.
For law-firm leadership, the lesson is not that every firm needs an enterprise security operation.
It is that the cybersecurity program should be appropriate to the firm's size, information, risk, and responsibilities while still being structured enough to demonstrate what is actually in place.
What Does SB 2610 Not Do?
Understanding what SB 2610 does not do is just as important as understanding what it does.
It does not provide blanket immunity after a breach.
The safe harbor specifically addresses exemplary damages. It should not be interpreted as preventing all litigation or eliminating every potential form of liability following a cybersecurity incident.
It does not create a new private cause of action.
The statute expressly states that Chapter 542 may not be construed to create a private cause of action or change an existing common-law or statutory duty.
It does not replace existing breach-notification requirements.
Texas already has breach-notification requirements under Texas Business & Commerce Code §521.053.
Among other provisions, the law addresses notification following a breach of system security involving sensitive personal information.
It does not mean that having cybersecurity software is enough.
A firewall, endpoint-security platform, backup system, or MFA solution may be part of a cybersecurity program.
But the statute speaks more broadly about administrative, technical, and physical safeguards and an implemented and maintained cybersecurity program aligned with recognized standards.
Technology is part of the program.
It is not the entire program.
Why Documentation Matters Under SB 2610
One of the most important phrases in SB 2610 is that an organization must be able to demonstrate that it implemented and maintained its cybersecurity program.
That shifts the conversation from:
“Do we have cybersecurity?”
to questions such as:
- Which cybersecurity framework are we using?
- What controls have we implemented?
- Where are our known gaps?
- Who owns remediation?
- Are policies being reviewed and followed?
- Are users receiving cybersecurity training?
- Are access controls actually enforced?
- Are backups being tested?
- Is the incident response plan current?
- Can we produce evidence showing that these activities occur?
A policy document stored in a folder is different from an operating cybersecurity program.
The same is true of technical controls. Multi-factor authentication may be enabled, for example, but leadership should still understand where it applies, whether exceptions exist, and how the organization verifies that the control remains effective.
This is where a structured cybersecurity risk-management and vCISO program can help organizations move from isolated controls to documented priorities, remediation plans, policies, governance, and ongoing oversight.
That type of documentation can also support broader risk-management needs, including client security reviews, cyber-insurance applications, vendor assessments, audits, and leadership oversight.
Cybersecurity Frameworks Are Not One-and-Done Checklists
SB 2610 also accounts for an important reality: cybersecurity frameworks change.
When certain recognized standards listed in the statute are updated, a business has time to bring its cybersecurity program into alignment. The statute generally allows until the later of the updated standard's published implementation date or the first anniversary of the standard's publication.
That reinforces a broader cybersecurity principle:
A cybersecurity program has to be maintained, not merely completed.
Risks change.
Technology changes.
Employees change.
Vendors change.
Frameworks change.
A security assessment performed several years ago does not automatically describe the environment that exists today.
For example, the current NIST Cybersecurity Framework 2.0 places explicit emphasis on cybersecurity governance alongside identifying, protecting, detecting, responding to, and recovering from cybersecurity risk.
SB 2610 and AI Governance Are Separate Issues, but They Intersect
Artificial intelligence is not the central subject of SB 2610.
But AI governance has become increasingly relevant to cybersecurity and information protection inside law firms.
Texas Professional Ethics Committee Opinion 705, issued in February 2025, addresses ethical considerations surrounding lawyers' use of generative AI.
The opinion discusses issues including technological competence, confidentiality, verification of AI-generated output, supervision, and understanding the potential risks of using generative AI in connection with client work.
That creates a related risk-management question for law firms:
Do you know what information attorneys and staff are putting into AI systems?
A firm may have strong endpoint protection, MFA, email security, and backups while still allowing employees to enter confidential information into an AI platform that has never been reviewed.
Cybersecurity and AI governance therefore should not operate as completely separate conversations.
A practical AI governance program should address questions such as:
- Which AI tools are approved for firm use?
- What client or firm information may be entered into them?
- What information is prohibited?
- How are AI vendors evaluated?
- Who approves new AI tools?
- When must AI-generated information be independently verified?
- What safeguards exist around confidential information?
- How will the firm review and update its AI policy as tools change?
AvTek's AI Governance services address this broader process through AI risk assessments, acceptable-use policies, approved-tool standards, data-protection guidance, defined roles and responsibilities, and ongoing governance.
For leadership teams still trying to determine where AI fits into the organization's broader risk strategy, AvTek's article 7 Questions Every Business Should Answer Before Expanding Its Use of AI provides a useful starting point.
What Should Texas Law Firms Do About SB 2610?
SB 2610 should not be approached as a reason to buy more cybersecurity technology.
A better first step is understanding the cybersecurity program your firm already has.
1. Determine Whether SB 2610 May Apply to the Firm
Review the firm's employee count and the types of computerized sensitive personal information it owns or licenses.
Legal counsel should determine how the statute applies to the firm's specific circumstances.
2. Identify the Cybersecurity Framework Being Used
If leadership cannot answer the question, “What framework is our cybersecurity program based on?” that is a useful place to start.
For many organizations, frameworks such as NIST CSF 2.0 or the CIS Controls can provide structured ways to evaluate cybersecurity risk.
3. Assess the Current Environment Against That Framework
Identify what controls are already working, what is only partially implemented, and where meaningful gaps remain.
A risk assessment should lead to priorities, not simply produce another report.
AvTek's vCISO services include risk-management guidance, control and documentation review, remediation prioritization, governance, and cybersecurity strategy.
4. Document the Cybersecurity Program
Policies, risk assessments, training, access controls, incident-response procedures, backup testing, remediation decisions, and other evidence help demonstrate that cybersecurity is being actively managed.
Documentation should show not merely what the organization intends to do, but how the program is actually being maintained.
5. Create a Remediation Plan
Not every gap can or should be fixed at once.
Leadership should prioritize remediation according to business risk, sensitive information, operational impact, applicable requirements, and available resources.
The purpose is to build a manageable improvement process rather than treat cybersecurity as a one-time project.
6. Review AI as Part of the Broader Risk Program
Opinion 705 makes clear that lawyers using generative AI need to understand the technology and protect client confidential information.
AI use should therefore be visible to leadership rather than occurring outside the firm's governance processes.
An AI governance program can help establish which tools are allowed, what data may be shared, who approves new AI applications, and how AI-related risks are reviewed over time.
7. Reassess Regularly
SB 2610 focuses on a cybersecurity program that is implemented and maintained.
That makes ongoing review important.
Changes to employees, systems, vendors, cloud services, AI applications, client requirements, threats, and cybersecurity frameworks can all change the firm's risk profile.
The Bigger Question for Texas Law Firm Leaders
The most useful question raised by SB 2610 may not be:
“Are we compliant with SB 2610?”
It may be:
“Could we demonstrate how our firm manages cybersecurity risk today?”
Could leadership identify the framework the firm follows?
Could the firm explain how sensitive information is protected?
Could it produce its current policies?
Could it show that cybersecurity training takes place?
Could it demonstrate which risks have been identified and what is being done about them?
Could it explain how AI tools are reviewed before confidential information is exposed to them?
Those questions matter beyond SB 2610.
They affect the firm's ability to manage risk, respond to clients, evaluate vendors, obtain cyber insurance, prepare for incidents, and make informed technology decisions.
What Texas Law Firms Should Take Away From SB 2610
Texas SB 2610 does not guarantee that a law firm will avoid litigation after a breach.
It does not eliminate every type of potential damages.
And it does not replace the firm's other legal, ethical, contractual, or regulatory responsibilities.
What it does provide is a clearer incentive for qualifying Texas businesses to build and maintain a cybersecurity program around recognized standards.
For law firms, that means cybersecurity maturity increasingly looks less like a collection of tools and more like a repeatable process:
Assess risk.
Choose a framework.
Implement appropriate controls.
Document what is being done.
Address gaps.
Review the program as risks change.
That is good risk management regardless of whether a firm ever needs to rely on SB 2610's safe harbor.
And if the firm does experience a breach, being able to demonstrate what was implemented and maintained before the incident may matter far more than trying to reconstruct the cybersecurity program afterward.
Frequently Asked Questions About SB 2610 and Texas Law Firms
What is Texas SB 2610?
Texas SB 2610 is a law that created a cybersecurity safe harbor for qualifying Texas businesses. In an action arising from a breach of system security, a qualifying business may be protected from exemplary damages if it demonstrates that it implemented and maintained a cybersecurity program that meets the statute's requirements. The law took effect September 1, 2025.
Does SB 2610 apply to Texas law firms?
The law is not specific to law firms. It applies to qualifying Texas business entities with fewer than 250 employees that own or license computerized data containing sensitive personal information.
A law firm should consult legal counsel to determine how the statute applies to its particular circumstances.
Does SB 2610 prevent someone from suing a law firm after a data breach?
No.
The law does not provide blanket immunity. Its safe harbor specifically limits recovery of exemplary damages when the statutory requirements are met. It also expressly states that the chapter does not create a private cause of action or change existing common-law or statutory duties.
What cybersecurity frameworks does SB 2610 recognize?
The statute identifies several frameworks and standards, including the NIST Cybersecurity Framework, NIST 800-171, NIST 800-53 and 800-53A, CIS Controls, ISO/IEC 27000-series standards, Secure Controls Framework, SOC 2, and similar industry standards.
It also recognizes certain regulatory or industry standards when they apply to the business.
What does SB 2610 require for businesses with 20 to 99 employees?
For businesses with at least 20 but fewer than 100 employees, SB 2610 describes moderate requirements that include the requirements of CIS Controls Implementation Group 1.
Is having MFA, antivirus, and backups enough to qualify?
Those controls may be components of a cybersecurity program, but SB 2610 describes something broader.
The statute calls for administrative, technical, and physical safeguards and conformity with recognized cybersecurity standards.
Organizations should therefore think in terms of a maintained cybersecurity program rather than a collection of individual security products.
Does SB 2610 regulate law firms' use of artificial intelligence?
SB 2610 is focused on cybersecurity programs and breach-related liability, not specifically on AI use.
Texas lawyers should separately consider Professional Ethics Committee Opinion 705, which addresses ethical issues involving generative AI.
What should a Texas law firm do first?
Start by understanding what cybersecurity program already exists.
Identify the framework being followed, assess current controls, identify gaps, organize supporting documentation, establish remediation priorities, and determine who is responsible for maintaining the program.
Cybersecurity does not need to begin with more tools.
It begins with understanding risk and being able to demonstrate how that risk is being managed.
If your firm needs help turning that assessment into an ongoing cybersecurity or AI governance program, contact AvTek to discuss where your current controls, documentation, and governance processes stand.

