Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Safe Harbor topic
No spam. Unsubscribe anytime.
Committee hears bill to create cybersecurity "safe harbor" for small businesses; NFIB and SMBs testify, bill left pending
Summary
A committee substitute for Senate Bill 2610 would create a three-tiered cybersecurity safe-harbor framework to shield small and medium-sized businesses from exemplary damages in data-breach litigation if they maintain cybersecurity programs aligned with recognized industry standards.
Get email alerts on the Cybersecurity Safe Harbor topic
No spam. Unsubscribe anytime.
Senator King introduced a committee substitute for Senate Bill 2610, which would create a cybersecurity safe-harbor for small and medium-sized businesses that maintain compliant cybersecurity programs aligned with recognized industry standards.
The sponsor and presenters said the substitute removes a drafting error that had created new liability, adds a three-tier compliance framework keyed to business size, and removes the Department of Public Safety from a role of determining industry standards (DPS had asked to be removed because the industry standards listed in the bill were deemed sufficient). Senator Blanco was identified as the author of the underlying bill and Senator King presented the substitute on her behalf.
Witnesses supporting the bill included Sarah Horn, assistant state director for NFIB Texas, who told the committee that the proposal provides voluntary incentives—safe harbor from punitive damages—for businesses that maintain programs aligned with recognized industry standards such as NIST. Horn said the measure encourages voluntary adoption of best practices without imposing burdensome mandates.
Eduardo Contreras, owner of Alcon DTS, a Texas-based managed IT and cybersecurity firm, also testified in favor. Contreras cited statistics and examples from other states (Ohio, Utah) where similar laws increased SMB adoption of cybersecurity controls and reduced breach-related lawsuits. He told the committee the bill would encourage small and medium businesses to implement multi-factor authentication and risk assessments.
Committee members asked about firm-size thresholds included in the committee substitute. One exchange noted the bill text as circulated said “under 100 employees,” but witnesses said the intent for the committee substitute was 250 employees; senators indicated they expected to amend or clarify that threshold. The committee took testimony from NFIB and private-sector witnesses, then left SB 2610 pending for further work and to consider the committee substitute.
