A Texas breach plan is three jobs on a clock. Contain the damage in 4 hours, get counsel and the facts by hour 24, and know whose data was touched by hour 72. After that, 2 legal deadlines take over, 30 days for the Attorney General and 60 days for individuals, and both run from the day you decide a breach occurred, which is a date you should write down on purpose. Print this. It sits beside our cybersecurity services in San Antonio.
A Texas data breach response plan is a written sequence that tells your team who does what from the first alert. Contain in 4 hours. Call counsel by hour 24. List the affected Texans by hour 72.
I run service delivery at Uprite, so I think of a breach as a phone call. Somebody finds something wrong. Somebody has to decide what happens in the next hour. If nobody knows who that is, the hour is gone.
A plan fixes that. It isn’t a binder on a shelf. It’s a set of decisions made on a calm afternoon, so they don’t get made at midnight by whoever happens to be awake. Prevention comes first, and our cybersecurity services in Texas page covers the controls that stop most of this.
Here’s the route. The first 72 hours in 3 blocks. A table of who owns each call. The Texas deadlines, checked against the statute text. One honest limit too. I’m not a lawyer, and counsel decides whether you owe anyone a notice.
What is a data breach response plan?
A data breach response plan is a written playbook that names who contains an incident, who investigates it, who decides whether notification is owed, and who speaks to customers and regulators. It lists contacts, evidence to keep and deadlines, so decisions take minutes instead of days.
NIST published Revision 3 of its incident response guide, SP 800-61, in April 2025. It ties response to the same risk management you already run under the NIST Cybersecurity Framework 2.0. Response isn’t a side project. The FTC’s data breach response guide for business says it more briefly. Secure your systems, fix the cause, then notify the right people.
What counts as a breach under Texas law?
Texas Business and Commerce Code Section 521.053 defines a “breach of system security” as unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of sensitive personal information that the business maintains. Encrypted data still counts if the person who took it also has the key.
Sensitive personal information has its own definition in Section 521.002. It means a person’s name combined with an unencrypted Social Security number, a driver’s license or government ID number, or a financial account number with its access code, but not information the government already makes public. Health information counts too. Names and email addresses alone do not.
That definition is why the first 72 hours are a fact hunt. A stolen laptop with an encrypted drive may not be a notifiable breach, while a mailbox an attacker read for 6 weeks very well may be, depending on what it held and whether anyone could read it. The facts decide. Facts take work.

Hours 0 to 4, stop the damage and start the log
Your goals are simple. Limit the damage. Keep the evidence. Everything else waits, because the urge to fix things is strong and usually wrong.
Start with one incident lead, named in advance, with a backup. That person doesn’t fix anything. They make sure someone does, and they keep the log.
- Take affected computers off the network but leave them powered on, since shutting them down can erase evidence, as the FTC guide advises, and leave them that way until forensic experts can image them.
- Disable accounts that look compromised, and force a reset on any admin account that touched them.
- Stop scheduled jobs that could overwrite good copies of your data.
- Move the response team to phones and a channel outside the affected systems.
- Write down the time, who noticed and what they saw.
Five moves. No heroics.
The log is the most underrated item there. Treat it like evidence. It becomes the record for your insurer, your counsel and, if it comes to that, the Attorney General. A date written at hour 2 beats a memory at day 20.
CISA’s #StopRansomware Guide carries a response checklist that fits any intrusion, not only ransomware. It treats evidence preservation as part of containment. So should you.
Monitoring earns its fee here. EDR can contain a device automatically the moment something anomalous runs, and our average first response across clients is about 5 minutes. A plan that waits for someone to notice at 9 a.m. has already lost 8 hours.
Hours 4 to 24, scope it and call the right people
By hour 4 the bleeding should have slowed. Now you ask what happened, in the right order. One question at a time.
Call counsel before you decide anything legal
Whether this is a “breach of system security” is a legal conclusion. Your IT team can tell you what was accessed. They can’t tell you what you owe. Get a lawyer who handles data incidents on the phone early, and run the investigation through that lawyer so the work stays protected wherever the law allows, and ask them how your team should document findings.
Call your insurer on their clock
Read the policy’s notice window today, not during the incident. Check yours tonight. Many policies set one. Many also name the forensic and law firms you must use, and the carrier may refuse to cover vendors you picked first, which is an expensive way to learn the rules at hour 10.
Decide who else to call
The FTC guide recommends calling local law enforcement promptly. You can also report to CISA at cisa.gov/report or file with the FBI’s Internet Crime Complaint Center. Police can ask you to hold notice if it would hurt an investigation, and the statute allows that delay. Ask counsel first.
Work out how they got in
Until you know, you can’t call the door shut. Look for the quiet signs. Check for mailbox forwarding rules, new admin accounts, remote access tools nobody installed, and sign-ins from places you don’t operate.
Somewhere in this window you’ll form a view that sensitive data was taken. Write that moment down. In Texas the 60-day clock runs from the date you determine a breach occurred, so record the date, the time, who decided and what they knew, because that single date anchors everything that follows. Counsel will ask.
Hours 24 to 72, find out whose data it was
Most plans skip this block, and it decides your notice list. You can’t notify people you can’t identify. So identify them.
Work from the data, not the systems. Which files, mailboxes or databases were reached, what did they hold, and which records carried Social Security numbers, ID numbers, account numbers or health details, and was any of it readable by whoever took it? Then count how many of those people live in Texas.
That Texas count matters twice. At 250 Texas residents the Attorney General gets a report. At more than 10,000 people notified at one time, the nationwide consumer reporting agencies get one as well.
Restoring service runs in parallel under a different team. For ransomware, our guide to ransomware recovery in Texas covers the restore order, and disaster recovery in San Antonio shows what a tested restore looks like, but neither one replaces the evidence work in this block. Don’t let a restore overwrite the evidence your scoping needs.
By hour 72 you want 4 things in writing. A short description of what happened. The data types involved. A first count of affected people by state. And the date you determined a breach occurred, if counsel agrees you have one. That’s the handoff.

Who decides what in the first 72 hours?
Most plans fail on ownership, not technique. Two people each assume the other made the call. This table gives every decision to one role. Names beat departments.
| Decision | Who decides | Who to call | What to preserve |
|---|---|---|---|
| Is this an incident | Incident lead | IT provider or SOC | Alerts, timestamps, screenshots |
| Isolate which systems | IT provider with the incident lead | Help desk, EDR console | Running machines, memory, logs |
| Notify the insurer | Owner or CFO | Carrier hotline | The policy and the notice date |
| Hire counsel and forensics | Owner | Your attorney, panel vendors | Engagement letters |
| Is it a notifiable breach | Counsel | Counsel, forensic firm | Facts, data inventory, decision date |
| Involve law enforcement | Owner with counsel | Local police, FBI, CISA | Reports, case numbers |
| Notify individuals and the AG | Owner on counsel’s advice | Mail house, AG online form | Notice drafts, mailing proof |
| What goes public | Owner | Counsel, PR if retained | The approved statement only |
One honest note. In a small company the owner holds half those rows. That’s fine. Not knowing it ahead of time is the problem.
What are the Texas notification deadlines?
Texas runs 2 main clocks, and both start when you determine a breach occurred. Individuals get notice without unreasonable delay and no later than the 60th day, while the Attorney General gets notice no later than the 30th day if the breach involves at least 250 Texas residents.
The 30-day figure is newer than many guides admit. Senate Bill 768 shortened it from 60 days effective September 1, 2023. Plenty of older checklists still print the old number. Check yours.
| Who gets notice | Deadline | Trigger |
|---|---|---|
| Affected individuals | Without unreasonable delay, no later than the 60th day | You determine a breach of sensitive personal information occurred |
| Texas Attorney General | As soon as practicable, no later than the 30th day | At least 250 Texas residents affected |
| Nationwide consumer reporting agencies | Without unreasonable delay | More than 10,000 people notified at one time |
| The data’s owner | Immediately after discovery | You hold data you don’t own, such as a vendor or IT provider |
Three details matter.
First, the AG’s own data breach reporting page words the 30 days as running from discovery of the breach, while the statute says the date you determine the breach occurred, and those are not always the same day. Plan for the earlier one and you never have to argue the point.
Second, the 60 days can stretch only for a law enforcement request or when needed to determine the scope of the breach and restore the reasonable integrity of the data system. It isn’t a general extension.
Third, the AG report goes through an electronic form. It asks for a description of the breach, the number of Texans affected, how many have been notified, what you’ve done and plan to do, and whether law enforcement is involved. The AG warns that a submitted report is potentially an open record. Write it as if a reporter will read it. Keep it factual.
Penalties are real. Section 521.151 sets civil penalties of $2,000 to $50,000 per violation, and failing to notify individuals adds up to $100 per person per day, capped at $250,000 per breach, and the Attorney General enforces all of it. Don’t test that.
Do federal rules add anything?
Only if you work in a regulated lane. Most Texas small businesses don’t, but check.
Healthcare is the common one. Under 45 CFR 164.404, a HIPAA covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. A business associate has the same 60-day outer limit to tell the covered entity. Breaches of 500 or more people also go to HHS at the same time as individual notice.
Public companies face a faster rule. The SEC’s 2023 cybersecurity disclosure rule requires an 8-K under Item 1.05 within 4 business days of deciding an incident is material, as the SEC’s announcement of the rule explains, though it covers only companies that file with the SEC.
What are the steps of a data breach response plan?
Here’s the plan on one page. Print it and tape it inside the incident binder.
- Name the incident lead and write down the time you learned of the problem.
- Isolate affected systems without powering them off.
- Disable compromised accounts and reset admin credentials.
- Call counsel and your insurer within the first 24 hours.
- Preserve logs, images, emails and the incident log.
- Work out which data was reached and whose it was.
- Have counsel decide whether it’s a notifiable breach, and record that date.
- Notify the Attorney General by day 30 if 250 or more Texans are involved, and individuals by day 60.
- Fix the cause, then review what the plan missed.
What does the Texas Attorney General’s breach list actually show?
I wanted to test the plan against real filings, so I pulled the AG’s public breach list on September 27, 2026. It held 640 notices published between April 2025 and September 2026.
Small breaches are common. Here’s the proof. Of the 640, 253 involved fewer than 1,000 Texans, and the median was 1,645. A company doesn’t need to be large to land on that list.
Sensitive data is the norm. 530 of the 640 notices, or 82.8%, listed Social Security numbers. And 406, about 63%, used U.S. mail alone to notify people, so line up a mailing vendor before you need one. Mail still rules.
One number surprised me. Across the 535 notices that gave both dates, the median gap between a breach starting and the company finding it was 72 days. That’s the honest limit of every “first 72 hours” guide, this one included. The attacker has often been inside for 10 weeks before your clock starts. That’s a long visit.
The cost side agrees. IBM’s Cost of a Data Breach 2026 report puts the global average at $4.99 million and the average time to identify and contain a breach at 247 days, the first rise after 5 straight years of decline. A plan can’t undo dwell time. Monitoring can shrink it.

What should be in place before an incident?
The plan only works if the people in it have met. Five things make the difference.
A one-page contact sheet with phone numbers that work when email doesn’t. An incident lead and a backup. Counsel and a forensic firm your insurer has already approved. A copy of the cyber policy with the notice window highlighted. And a mailing vendor who can print and send notices in days.
Then rehearse. Our San Antonio security program includes an annual tabletop exercise, where the team walks a fake incident from alert to notice. It takes a morning. It finds the missing phone number every time. Do it yearly.
Lessons from San Antonio ransomware attacks show what happens when a continuity document has never been run, and how ransomware crews pick San Antonio companies explains why to drill before the call. If you’re budgeting for monitoring, what cybersecurity costs in San Antonio lays out the price tiers.
Texas also rewards preparation in court. Senate Bill 2610 protects businesses with fewer than 250 employees from exemplary damages if they ran a recognized cybersecurity program before the breach, though it doesn’t block penalties or regulators. Our HIPAA vs Texas SB 2610 guide walks through the tiers.
Where Uprite fits, and where it doesn’t
We’re a managed IT and security provider. We aren’t a law firm, and we aren’t a forensic investigation firm. Counsel decides what you owe, and in a serious case a forensic specialist, often one your insurer names, images the evidence, so read your carrier’s panel list well before you need it. That’s the honest line.
We do cover the technical side of the plan. That means 24/7 monitoring, EDR with automated containment, incident response, and immutable backups with scheduled restore tests. Our teams work from offices in Houston, San Antonio, Dallas and Katy, so someone can reach the rack when isolation has to happen by hand, which matters when a firewall or a server has to be unplugged rather than disabled.
See how that looks locally on our pages for cybersecurity services in Houston and cybersecurity services in Dallas.
Questions Texas owners ask about breach response
How long do I have to notify people after a data breach in Texas?
No later than the 60th day after you determine a breach occurred, and sooner if you reasonably can. If at least 250 Texans are affected, the Attorney General must hear within 30 days. Counsel should confirm how both clocks apply to your facts. Do not guess.
Do I have to tell the Texas Attorney General about a small breach?
Only when at least 250 Texas residents are affected. Below that, no AG report is required, but individual notice still is when sensitive personal information was acquired. About 4 in 10 notices on the AG’s list involved fewer than 1,000 Texans.
What counts as sensitive personal information in Texas?
A person’s name together with an unencrypted Social Security number, driver’s license or ID number, or financial account number with its access code. Health information that identifies a person also qualifies. Encrypted data falls outside the definition unless the key was taken too.
Should I call the police or the FBI?
Usually yes, with counsel’s input. The FTC recommends contacting local law enforcement promptly, and you can report to CISA or the FBI’s IC3. Police can also ask you to hold notice while they investigate, and Texas law lets you delay for that reason until the agency says notice will no longer compromise the case.
If my software vendor is breached, is that my problem?
Often it is. Here is why. A company that holds data it doesn’t own must tell the owner immediately after discovering a breach. The owner, meaning you, still has the duty to notify affected individuals. Your vendor contract should spell out who pays for it.
What if I’m not sure any data was actually taken?
The statute covers data that was, or is reasonably believed to have been, acquired by an unauthorized person. Unsure doesn’t mean exempt. Preserve the logs, document your reasoning, and let counsel decide whether you reach the notice threshold.
Find out how your first 72 hours would really go. We’ll walk your team through an incident-readiness review covering your contacts, your insurer’s notice window, your data inventory and your Texas notification path, then hand you a written plan that’s yours to keep either way.
Get an Incident-Readiness Assessment








