Legal Tech • February 2026
Avoiding Punitive Damages After a Data Breach
What Texas SB 2610 means for businesses and law firms.
Written by Majo Castro

When Texas Senate Bill 2610 Took Effect On September 1, 2025,1 it reshaped how Texas businesses think about cybersecurity risk and legal exposure following a data breach. The law establishes a cybersecurity safe harbor that can limit a business’ exposure to punitive damages if a qualifying security program was implemented and maintained before an incident occurred.
For small and midsize businesses, including law firms, the challenge is no longer whether cybersecurity matters, but how to turn a legal standard into practical, defensible action. Most organizations handle highly sensitive client and consumer information as a core part of their operations yet lack the compliance infrastructure and security resources of larger enterprises. So, SB 2610 meets businesses where they are by offering a scaled, framework-based road map. It basically connects reasonable, achievable cybersecurity safeguards to meaningful legal protection if a security incident occurs.
Rising
Expectations
For small and midsize businesses, this represents a meaningful shift.
Cybersecurity moves from being viewed solely as a cost of doing
business to a form of risk management with real legal consequences. SB
2610 does not replace other obligations, but it provides a clear and
scalable road map for adopting reasonable security practices and
limiting exposure to significant punitive damages following a cyber
incident.
What This Means for Law Firms
A data breach now carries not only operational and reputational for
professional services firms—but also the risk of significant civil
liability. SB 2610 is not simply another compliance obligation. It
offers businesses a structured way to manage the financial exposure
associated with a cybersecurity incident.
SB 2610 as an Affirmative Defense
SB 2610 operates as an affirmative defense to punitive
damages—it’s not immunity from all liability, only punitive
damages, and requiresdocumented compliance with recognized
frameworks at the time of the incident. So, if a business/firm is sued
following a data breach, the protection is not automatic. The firm must
be prepared
to demonstrate that it had implemented and maintained a qualifying
cybersecurity program at the time of the incident.
When a firm can show that its cybersecurity program met the statute’s tier-specific requirements based on employee headcount, SB 2610 limits exposure to punitive damages. These damages often far exceed the direct costs associated with responding to a breach.
Professional Responsibility Considerations
For Texas attorneys, SB 2610 also fits naturally alongside the duty of
technological competence under Rule 1.01, Comment 8 of the Texas
Disciplinary Rules of Professional Conduct. While SB 2610 does not
create ethical obligations, aligning a firm’s cybersecurity
practices with a recognized framework can help demonstrate that the
firm has taken reasonable steps to understand and mitigate the risks
associated with modern technology and client data.
Five Steps to Prepare Your Organization Under SB 2610
SB 2610 applies to Texas businesses with fewer than 250
employees2 that handle sensitive personal information, such
as Social Security numbers, driver’s license data, or health
records. Qualification for the statute’s safe harbor depends on
employee headcount and implementation of an appropriate cybersecurity
program.
Step 1: Confirm Your Employee Headcount. Your official employee count determines which security tier applies and which cybersecurity framework must be implemented to qualify for the safe harbor.
Step 2: Identify Your Applicable Security Tier.
a. Fewer than 20 employees:
a. Implement basic password policies.
b. Provide appropriate employee cybersecurity training.
c. Document security procedures.
d. Perform regular software updates.
e. Outline an incident response plan.
b. 20 to 99 employees: Implement the CIS Controls Implementation Group 1 (IG1), commonly referred to as “essential cyber hygiene.”
c. 100 to 249 employees: Implement and maintain a cybersecurity program aligned with at least one recognized framework listed in the statute.
Step 3: Implement Required Safeguards to Qualify for the Safe
Harbor.
A qualifying cybersecurity program must address all three
safeguard categories required by the statute:
a. Administrative safeguards, including responsibility for security oversight and documented policies.
b. Technical safeguards, such as access controls and system protections appropriate to the selected framework.
c. Physical safeguards, addressing the security of offices, devices, and other hardware
Step 4: Document and Maintain the Program. The cybersecurity program must be implemented and maintained before any security incident occurs. Written policies, procedures, and records of implementation are critical to demonstrating compliance if the safe harbor is later asserted.
Step 5: Review and Update as Frameworks Evolve. If the cybersecurity framework your organization relies on is updated, SB 2610 allows a limited window to bring internal policies and controls into alignment. Regular review helps ensure continued eligibility for the safe harbor.
Beyond Compliance
Compliance with SB 2610 is only one part of the equation. While the
law provides the legal mechanism to avoid punitive damages, the real
value lies in the competitive advantage it creates.
For any business, a strong, documented security posture signals more
than just legal adherence, it shows professionalism, reliability, and
ethical leadership. In a moment in time where corporate clients and
vendors are increasingly auditing their business data practices, being
able to demonstrate alignment with the SB 2610 Safe Harbor and related
standards becomes a powerful market differentiator.
MAJO CASTRO is the
founder and managing attorney of CastroLand Legal, a Texas-based firm
specializing in cybersecurity, privacy, and regulatory compliance.
Castro advises startups, MSPs, and mid-sized companies on
developing effective compliance programs that balance legal precision
with business practicality.