Legal Tech • February 2026

Avoiding Punitive Damages After a Data Breach

What Texas SB 2610 means for businesses and law firms.

Written by Majo Castro

Robert Tobey

When Texas Senate Bill 2610 Took Effect On September 1, 2025,1 it reshaped how Texas businesses think about cybersecurity risk and legal exposure following a data breach. The law establishes a cybersecurity safe harbor that can limit a business’ exposure to punitive damages if a qualifying security program was implemented and maintained before an incident occurred.

For small and midsize businesses, including law firms, the challenge is no longer whether cybersecurity matters, but how to turn a legal standard into practical, defensible action. Most organizations handle highly sensitive client and consumer information as a core part of their operations yet lack the compliance infrastructure and security resources of larger enterprises. So, SB 2610 meets businesses where they are by offering a scaled, framework-based road map. It basically connects reasonable, achievable cybersecurity safeguards to meaningful legal protection if a security incident occurs.

Rising Expectations
For small and midsize businesses, this represents a meaningful shift. Cybersecurity moves from being viewed solely as a cost of doing business to a form of risk management with real legal consequences. SB 2610 does not replace other obligations, but it provides a clear and scalable road map for adopting reasonable security practices and limiting exposure to significant punitive damages following a cyber incident.

What This Means for Law Firms
A data breach now carries not only operational and reputational for professional services firms—but also the risk of significant civil liability. SB 2610 is not simply another compliance obligation. It offers businesses a structured way to manage the financial exposure associated with a cybersecurity incident.

SB 2610 as an Affirmative Defense
SB 2610 operates as an affirmative defense to punitive damages—it’s not immunity from all liability, only punitive damages, and requiresdocumented compliance with recognized frameworks at the time of the incident. So, if a business/firm is sued following a data breach, the protection is not automatic. The firm must be prepared to demonstrate that it had implemented and maintained a qualifying cybersecurity program at the time of the incident.

When a firm can show that its cybersecurity program met the statute’s tier-specific requirements based on employee headcount, SB 2610 limits exposure to punitive damages. These damages often far exceed the direct costs associated with responding to a breach.

Professional Responsibility Considerations
For Texas attorneys, SB 2610 also fits naturally alongside the duty of technological competence under Rule 1.01, Comment 8 of the Texas Disciplinary Rules of Professional Conduct. While SB 2610 does not create ethical obligations, aligning a firm’s cybersecurity practices with a recognized framework can help demonstrate that the firm has taken reasonable steps to understand and mitigate the risks associated with modern technology and client data.

Five Steps to Prepare Your Organization Under SB 2610
SB 2610 applies to Texas businesses with fewer than 250 employees2 that handle sensitive personal information, such as Social Security numbers, driver’s license data, or health records. Qualification for the statute’s safe harbor depends on employee headcount and implementation of an appropriate cybersecurity program.

Step 1: Confirm Your Employee Headcount. Your official employee count determines which security tier applies and which cybersecurity framework must be implemented to qualify for the safe harbor.

Step 2: Identify Your Applicable Security Tier.

a. Fewer than 20 employees:

a. Implement basic password policies.

b. Provide appropriate employee cybersecurity training.

c. Document security procedures.

d. Perform regular software updates.

e. Outline an incident response plan.

b. 20 to 99 employees: Implement the CIS Controls Implementation Group 1 (IG1), commonly referred to as “essential cyber hygiene.”

c. 100 to 249 employees: Implement and maintain a cybersecurity program aligned with at least one recognized framework listed in the statute.

Step 3: Implement Required Safeguards to Qualify for the Safe Harbor.
A qualifying cybersecurity program must address all three safeguard categories required by the statute:

a. Administrative safeguards, including responsibility for security oversight and documented policies.

b. Technical safeguards, such as access controls and system protections appropriate to the selected framework.

c. Physical safeguards, addressing the security of offices, devices, and other hardware

Step 4: Document and Maintain the Program. The cybersecurity program must be implemented and maintained before any security incident occurs. Written policies, procedures, and records of implementation are critical to demonstrating compliance if the safe harbor is later asserted.

Step 5: Review and Update as Frameworks Evolve. If the cybersecurity framework your organization relies on is updated, SB 2610 allows a limited window to bring internal policies and controls into alignment. Regular review helps ensure continued eligibility for the safe harbor.

Beyond Compliance
Compliance with SB 2610 is only one part of the equation. While the law provides the legal mechanism to avoid punitive damages, the real value lies in the competitive advantage it creates. For any business, a strong, documented security posture signals more than just legal adherence, it shows professionalism, reliability, and ethical leadership. In a moment in time where corporate clients and vendors are increasingly auditing their business data practices, being able to demonstrate alignment with the SB 2610 Safe Harbor and related standards becomes a powerful market differentiator.

Notes

  1. S.B. 2610, 89th Leg., R.S. (Tex. 2025), https:// capitol.texas.gov/tlodocs/89R/billtext/pdf/SB02610F. pdf#navpanes=0.

  2. Texas Legislation (SB 2610)—Cybersecurity Safe Harbor for Small Businesses—What you need to know and steps to prepare, Palindrome Technologies (July 2, 2025), https://palindrometech.com/governance-risk-management-compliance-resources/ texas-legislation-sb-2610-cybersecurity-safe-harbor-for-small-businesses-what-you-need-to-know-and-steps-to-prepare; see also Shawn Tuma, Texas Cybersecurity Safe Harbor for Small and Mid-SizedBusinesses, Spencer Fane (Oct. 29, 2025), https://www.spencerfane.com/insight/texas-cybersecurity-safe-harbor-for-small-and-mid-sized-businesses/.


MAJO CASTROMAJO CASTRO is the founder and managing attorney of CastroLand Legal, a Texas-based firm specializing in cybersecurity, privacy, and regulatory compliance. Castro advises startups, MSPs, and mid-sized companies on developing effective compliance programs that balance legal precision with business practicality.