The breaches that hit companies like yours are almost never exotic. We start where the damage actually comes from and work outward.
Attackers are already using AI to write better phishing messages and research their targets. It has also removed a lot of the bad grammar and awkward wording people used to rely on when spotting a fake.
So the old advice about spotting the typos is finished. What still works is a second channel: anything that moves money or changes bank details gets confirmed by voice, on a number you already had.
We choose the tools underneath all this on merit and we buy them ourselves. You aren't being sold a product line, and nobody pays us a commission to recommend anything.
Since September 2025 there has been a law on the books in Texas that almost nobody has mentioned to you. If your business has fewer than 250 employees and you hold sensitive personal information about people, and you get breached, someone suing you can be barred from collecting punitive damages, provided you can show that at the time of the breach you had a real security program implemented and maintained.
That is Chapter 542 of the Business and Commerce Code. It is a narrow shield and not a shortcut. It does nothing about what someone can recover for actual harm, nothing about a regulator, and it does not create any new claim or change a duty you already had. What it can take off the table is the extra pile on top.
The shape is the same at every size: administrative, technical and physical safeguards, and a program that conforms to a recognized security framework. The law names about a dozen that qualify, so nobody is steering you toward one product. What changes with headcount is the scale and scope of the program. Under twenty people the requirements are simplified, and the statute points at a password policy and real staff training. Twenty to ninety-nine requires moderate measures, including the CIS Controls Implementation Group 1 baseline. The framework-conformance requirement applies to every qualifying program, not just the larger bands. If a standard on the statute's framework list gets revised, you get a window to update to it rather than falling out overnight, so long as you actually do the updating inside that window.
Two words in the statute do most of the work: implemented and maintained. A policy written once and filed is not a program. It has to have actually been running on the day it went wrong, which is the argument for starting before you need it rather than after.
We can build it, run it, and write down what it does, which is the same work we would be telling you to do anyway. Whether your business and your program actually qualify is a call for your attorney, not for us.
The whole thing, in detail: what the statute asks for and what we build →
Not a scan report with four hundred findings. The two or three things that would really let somebody in.
Start a Conversation