
“We think someone got into the system. We’re not sure when, and we’re not sure what they took.” That sentence, said out loud in a conference room off the Katy Freeway, is the moment a legal clock you couldn’t see starts ticking — and you’re already behind.
Here’s the uncomfortable truth most Houston business owners never hear until it’s too late: the law doesn’t wait for you to be ready. The day you determine a breach occurred, deadlines kick in. Miss them and you’ve added a second crisis — a regulatory one — on top of the first. And the cruel part? Most small businesses can’t even tell if or when a breach happened. You can’t start a clock you can’t see.
The Clocks That Start the Day You Find Out
Texas has its own breach notification law — the Texas Identity Theft Enforcement and Protection Act, tucked into Chapter 521 of the Texas Business & Commerce Code. In plain English, here’s what it requires when a business suffers a breach of sensitive personal information:
- Notify the affected individuals. You must tell the people whose data was exposed without unreasonable delay and no later than 60 days after you determine a breach occurred.
- Notify the Texas Attorney General. If at least 250 Texas residents are affected, you also have to notify the Texas AG — and that notice is required within a short window, generally described as within 30 days.
That’s the Texas piece. It is almost never the whole picture.
Other Clocks May Be Running at the Same Time
- HIPAA. If you handle protected health information — a medical practice, a dental office, a billing company — the HIPAA Breach Notification Rule carries its own, separate deadlines that don’t care what Texas says.
- PCI and card brands. If you take credit cards, your payment processor and card-brand contracts can impose their own notification and forensic requirements, often on a much tighter timeline.
- Contracts. Your client agreements, your vendor agreements, and your cyber-insurance policy frequently bury notification obligations in the fine print — sometimes measured in hours, not days.
- Other states. If even one of your affected customers lives in California, Florida, or anywhere else, that state’s breach law can apply too. A small Houston business can suddenly owe notice under a dozen different statutes at once.
None of this is legal advice, and we are not your lawyers. This is what we see in the field. In a real breach, your first two calls should be to your attorney and your cyber-insurance carrier — immediately, before you notify anyone else or touch the evidence. They will tell you which clocks apply to your specific situation. We make sure you can actually answer their questions.
The Real Problem: You Have to Know a Breach Happened
Read that 60-day deadline again. It starts when you determine a breach occurred. That little phrase quietly assumes something most small businesses simply don’t have: the ability to detect a breach and figure out how bad it is.
Here’s how it plays out in real life. A business gets a tip — a customer complaint, a strange bank alert, a ransom note on a screen. The owner asks the obvious questions:
- When did the attacker get in?
- What did they actually access or copy?
- Whose information was exposed — and how many people?
- Are they still inside right now?
And the answer, far too often, is a shrug. No logging. No monitoring. No endpoint detection. No record of who logged in, from where, or what they touched. The business has no way to reconstruct what happened because nothing was ever watching.
You Can’t Prove What Didn’t Get Taken
This is the trap that turns a manageable incident into an expensive one. When you have no evidence, you cannot demonstrate that the damage was limited. And when you can’t prove only ten records were touched, you may be forced to assume all of them were — and notify everyone.
That difference is enormous. Notifying 40 customers is a bad week. Notifying 4,000 — with the AG notice, the credit-monitoring offers, the call center, the press inquiries — is a different category of event entirely. Good detection and logging don’t just help you respond faster; they let you scope the breach down to what really happened, which can dramatically shrink who you have to notify and what it costs.
The Cascade When You Get It Wrong
Missing a notification deadline — or botching the response — doesn’t stay contained. It cascades:
- Regulatory exposure. The Texas AG and other regulators can pursue businesses that fail to notify properly or on time. Industry regulators (think health care) have their own enforcement on top of that.
- Lawsuits. Affected customers and class-action attorneys pay close attention to how a breach was handled. “They knew and sat on it” is the kind of story that fuels litigation.
- Reputational damage. In a referral-driven Houston market, the headline isn’t the breach — it’s how you handled it. Customers forgive companies that were honest and fast. They walk from companies that were sloppy and slow.
- Hard costs. Forensics, legal fees, printing and mailing notices, credit-monitoring services, and call-center support add up quickly — and the broader your notification list, the bigger the bill.
How Readiness Changes the Whole Outcome
The businesses that come through a breach intact almost never got lucky. They were ready. Readiness is the difference between a contained incident and a catastrophe, and it comes down to four things you put in place before anything goes wrong.
1. Detection, logging, and monitoring
You can’t respond to what you can’t see. Endpoint detection, centralized logging, and active monitoring are what let you answer “when, what, and whose” — the exact questions that determine the size of your notification obligation. This is the core of our network security work: building the visibility that lets you detect a breach early and scope it accurately, plus an incident-response capability for when something does slip through.
2. An incident response plan you’ve actually rehearsed
A plan in a drawer that nobody has read is not a plan. The first hour of a breach is chaos; a rehearsed playbook — who calls the attorney, who calls the insurer, who isolates the machines, who talks to customers — keeps that chaos from becoming a second disaster.
3. Tested backups so you can recover
Especially with ransomware, recovery is half the battle. Backups you’ve never restored are a guess, not a safety net. Our data backup and recovery approach is built around backups that are isolated, verified, and actually tested — so “restore from backup” is a real option, not a prayer.
4. A security partner you already know
The worst time to meet your IT and security team is the morning of a breach. The businesses that fare best already have a relationship, already have the controls documented, and already know who to call. That readiness — the technical controls plus the documentation that proves they exist — is the heart of our compliance work and a natural extension of managed IT services.
This is the whole thesis of this series in one example: you can be compliant on paper — a privacy policy on the website, a checkbox marked “yes, we have a breach plan” — and still be completely exposed in reality, because when the moment comes, you can’t see the clock, can’t scope the damage, and can’t recover.
If You’re in a Breach Right Now
To be absolutely clear: if you believe you’re being breached as you read this, stop and call your attorney and your cyber-insurance carrier first. They direct the legal response and your policy may require it. Then get your security team engaged to contain and investigate. The order matters — and acting fast, in the right order, is what protects you.
Let’s Make Sure You Can See the Clock
You don’t want to be discovering your blind spots during a breach. Start with a free 15-minute discovery call at /discoverycall/ — we’ll talk through where you stand on detection, logging, backups, and incident readiness, and where the real gaps are. To see how we make compliance real instead of a checkbox, visit /compliance/. The discovery call is the only thing we offer for free — the readiness work itself is professional engineering at professional rates, and it’s a fraction of what an unscoped breach will cost you. We’re a phone call you want to have now, not at 2 a.m. when the clock is already running.
Aspendora Technologies provides cybersecurity, managed IT, and expert on-premise & open-source solutions to Houston-area small businesses since 2010.
