Most business leaders understand the need for cybersecurity.
They have firewalls. They use endpoint protection. Employees have multi-factor authentication. Backups are running. Many organizations also pay a managed IT or cybersecurity provider to monitor their systems and respond when something goes wrong.
But there’s another question businesses increasingly need to answer:
Can you prove what you’re doing?
That distinction has become especially important for Texas businesses following the passage of S.B. 2610.
Effective September 1, 2025, Texas Business & Commerce Code Chapter 542 established a cybersecurity program Safe Harbor for certain qualifying businesses. The law applies to Texas business entities with fewer than 250 employees that own or license computerized data containing sensitive personal information. In certain actions arising from a breach of system security, exemplary damages may not be recovered from a qualifying business if it can demonstrate that, at the time of the breach, it implemented and maintained a cybersecurity program that satisfies the law’s requirements. (Texas Business & Commerce Code Chapter 542, 2025)
That makes cybersecurity documentation much more than administrative paperwork.
It can become evidence.
And the same work businesses do to become audit-ready may have another financial benefit: helping them demonstrate a stronger cybersecurity risk profile when applying for or renewing cyber insurance.
For CEOs and CFOs, that changes the cybersecurity conversation. Audit readiness has a cost, but failing to demonstrate a mature cybersecurity program can potentially cost much more.
What S.B. 2610 Actually Does for Texas Businesses
S.B. 2610 is designed to encourage qualifying Texas businesses to proactively implement recognized cybersecurity practices.
The law does not create blanket immunity after a data breach.
Instead, Chapter 542 establishes a specific limitation involving exemplary damages. A qualifying business must demonstrate that it had implemented and maintained a compliant cybersecurity program at the time of the breach. (Texas Business & Commerce Code §542.003, 2025)
The statute also identifies requirements for what constitutes an appropriate cybersecurity program, including alignment with recognized cybersecurity frameworks or applicable regulatory standards. (Texas Business & Commerce Code §542.004, 2025)
That distinction is critical.
The law isn’t simply asking:
Did you buy cybersecurity technology?
The more important question is:
Did you implement and maintain an appropriate cybersecurity program?
Those are very different standards.
Cybersecurity Tools Are Not a Cybersecurity Program
Imagine a business with:
- Multi-factor authentication
- Endpoint detection and response
- Email security
- Managed backups
- Security monitoring
- Patch management
- Employee security training
From a technical standpoint, that organization may be doing many things correctly.
But suppose its written information security policy hasn’t been reviewed in three years.
Its incident response plan names employees who no longer work there.
Its asset inventory doesn’t include newer cloud applications.
Nobody can locate records showing when employees completed cybersecurity training.
Its disaster recovery plan was written before the company migrated several critical systems.
Now the picture looks different.
The technology may be current.
The evidence isn’t.
That’s the gap audit readiness is designed to uncover.
Why Documentation Matters Under S.B. 2610
The words “implemented and maintained” are particularly important in Chapter 542.
A cybersecurity program cannot simply exist on paper.
At the same time, a business needs to be able to demonstrate that its program actually existed and was being maintained when a breach occurred.
Documentation helps connect those two sides.
Depending on the organization’s cybersecurity program and applicable framework, that evidence could include:
- Information security policies
- Risk assessments
- Incident response plans
- Employee security awareness records
- Access-control policies
- Backup and recovery procedures
- Asset inventories
- Vendor management procedures
- Vulnerability and patch-management records
- Business continuity plans
- Evidence of periodic reviews and updates
The specific requirements will depend on the organization and the framework or standard it follows.
But the principle is straightforward:
If your organization can’t produce evidence of its cybersecurity program, proving that the program was implemented and maintained becomes more difficult.
“Our Cybersecurity Provider Handles It” May Not Be Enough
This is where businesses can develop a false sense of security.
An organization may have worked with the same managed IT or cybersecurity provider for years. Leadership assumes that because security systems are being monitored, everything associated with cybersecurity is current.
That assumption is worth testing.
A managed cybersecurity provider may be doing an excellent job protecting endpoints, monitoring threats, installing patches, and maintaining backups.
That does not automatically mean someone is maintaining every document associated with the organization’s cybersecurity program.
Cybersecurity operations and cybersecurity governance overlap, but they are not necessarily the same responsibility.
The problem often comes down to ownership.
Leadership assumes IT owns the documentation.
IT assumes the managed service provider owns it.
The managed provider assumes internal leadership or a compliance consultant owns it.
Everyone believes someone else is responsible.
Then an insurer, auditor, attorney, customer, or executive asks for the documentation.
That’s when the gaps become visible.
Documentation Has to Match the Business You Operate Today
Cybersecurity documentation isn’t something a business should create once and store in a folder indefinitely.
Businesses change too quickly.
Employees leave.
New executives arrive.
Vendors change.
Companies migrate to cloud platforms.
New applications are deployed.
Offices open and close.
Cybersecurity tools are replaced.
New threats emerge.
Every significant change can create distance between the cybersecurity program described in your documentation and the one actually operating inside your business.
Consider an incident response plan.
If the plan instructs employees to contact a CIO who left two years ago, does it accurately represent your current response process?
Or consider an asset inventory that doesn’t include a cloud application storing sensitive customer information.
Technically, the business has documentation.
Operationally, that documentation is outdated.
Audit readiness is about closing that gap before somebody else discovers it.
The Cyber Insurance Connection
S.B. 2610 creates one business case for better cybersecurity documentation.
Cyber insurance creates another.
Cyber insurers need to understand the risk they’re agreeing to cover. The U.S. Government Accountability Office has documented how increasing cyberattack frequency and severity have led insurers to become more selective, tighten terms, adjust coverage limits, and increase premiums for higher-risk organizations. (U.S. Government Accountability Office, 2021–2022)
Insurers may evaluate controls such as:
- Multi-factor authentication
- Endpoint security
- Backup practices
- Incident response
- Employee training
- Access management
- Vulnerability management
- Security monitoring
Documentation can help demonstrate that these aren’t merely boxes checked on an application.
They are part of an active cybersecurity program.
Cyber insurance pricing varies significantly between carriers, industries, coverage levels, claims histories, and individual organizations. No cybersecurity provider can guarantee that becoming audit-ready will automatically reduce a company’s premium.
But insurers use information about cybersecurity controls and practices when evaluating risk, and stronger risk management can potentially contribute to more favorable underwriting outcomes.
That creates an important financial argument for audit readiness.
The Cost of Audit Readiness vs. the Cost of Remaining Unprepared
For leadership, cybersecurity investments eventually come down to risk and return.
Becoming audit-ready takes work.
Policies may need to be rewritten.
Risk assessments may need to be performed.
Old documentation may need to be updated.
Responsibilities may need to be clarified.
Training records may need to be centralized.
Incident response and recovery plans may need to be tested.
There is a cost associated with that work.
But look at what the investment can support.
A well-documented cybersecurity program can help an organization:
- Prepare to demonstrate S.B. 2610 Safe Harbor eligibility
- Potentially reduce exposure to exemplary damages following a qualifying breach
- Present a stronger cybersecurity posture during insurance underwriting
- Identify weaknesses before attackers find them
- Improve incident response
- Strengthen business continuity
- Respond more effectively to customer security questionnaires
- Prepare for audits and compliance assessments
- Give leadership greater visibility into organizational risk
Suddenly, audit readiness stops looking like a compliance expense.
It becomes risk management.
Cyber Insurance and Safe Harbor Share a Common Goal
Cyber insurance and S.B. 2610 serve different purposes.
Insurance transfers certain financial risks to an insurer according to the terms of a policy.
S.B. 2610 establishes a statutory Safe Harbor involving exemplary damages for qualifying businesses that meet its requirements.
But both reward a similar underlying behavior:
Taking cybersecurity risk seriously before a breach occurs.
That’s why the same cybersecurity improvements can create value in multiple areas.
A documented risk assessment can help leadership identify weaknesses while providing evidence of cybersecurity governance.
An updated incident response plan can improve recovery while demonstrating preparedness.
Documented employee training can reduce phishing risk while providing evidence that cybersecurity practices are actively maintained.
Tested backups can improve ransomware resilience while supporting insurance conversations.
The organization isn’t creating separate cybersecurity programs for insurance, Safe Harbor, audits, and business continuity.
It is building one defensible cybersecurity program that supports all of them.
Five Questions Every CEO Should Ask
Business leaders don’t need to become cybersecurity engineers.
But they should know whether their organization can answer five questions.
1. What cybersecurity framework are we following?
S.B. 2610 recognizes specific approaches to cybersecurity programs. Leadership should understand which framework or applicable standard the organization follows and why it is appropriate for the business.
2. When was our cybersecurity documentation last reviewed?
Don’t ask whether policies exist.
Ask when they were last updated.
3. Can we prove the controls we say we have?
If the company says employees receive security training, can you produce training records?
If backups are tested, can you demonstrate the testing?
If access is periodically reviewed, where is that review documented?
4. Who owns cybersecurity governance?
Someone needs clear responsibility for keeping policies, risk assessments, response plans, and other evidence current.
5. What could we produce tomorrow?
This may be the most revealing question.
If an insurer, auditor, attorney, or customer requested evidence of your cybersecurity program tomorrow morning, what could your organization actually produce?
If the answer is unclear, there’s work to do.
Audit Readiness Should Be Continuous
Waiting until an insurance renewal, customer audit, or cyber incident to organize cybersecurity documentation creates unnecessary pressure.
A stronger approach is continuous readiness.
When technology changes, update the documentation.
When responsibilities change, update the incident response plan.
When employees complete training, retain the evidence.
When risks change, revisit the assessment.
When recovery procedures are tested, document the results.
This creates a cybersecurity program that evolves alongside the business.
More importantly, it helps establish that cybersecurity isn’t something the organization implemented once.
It is something the organization maintains.
For S.B. 2610, that distinction matters.
Frequently Asked Questions
What is Texas S.B. 2610?
S.B. 2610 added Chapter 542 to the Texas Business & Commerce Code. Effective September 1, 2025, it establishes a cybersecurity program Safe Harbor involving exemplary damages for certain qualifying Texas businesses that can demonstrate they implemented and maintained a compliant cybersecurity program at the time of a breach.
Which businesses can potentially qualify?
Chapter 542 applies to a Texas business entity with fewer than 250 employees that owns or licenses computerized data containing sensitive personal information. Additional requirements apply to the cybersecurity program itself.
Does S.B. 2610 prevent a business from being sued after a data breach?
No. It should not be described as blanket immunity from lawsuits or all damages. The statute specifically addresses recovery of exemplary damages in certain actions arising from a breach when the qualifying business demonstrates compliance with Chapter 542.
Does having an MSP automatically make a business compliant?
No. Managed IT and cybersecurity services can provide important technical controls, but businesses should verify whether their cybersecurity program, policies, procedures, risk assessments, training records, and other supporting documentation are current.
Can audit readiness lower cyber insurance premiums?
Potentially, but it isn’t guaranteed. Cyber insurers evaluate many factors when determining eligibility, coverage, deductibles, and pricing. Strong cybersecurity controls and supporting documentation can help demonstrate a company’s risk-management maturity, which may contribute to more favorable underwriting outcomes depending on the carrier.
How often should cybersecurity documentation be reviewed?
Documentation should be reviewed regularly and whenever significant changes occur to personnel, technology, vendors, operations, or applicable requirements. A document should reflect the organization as it operates today, not the organization that existed when the policy was originally written.
Don’t Just Have Cybersecurity. Be Able to Prove It.
The cybersecurity conversation is changing.
For Texas businesses, S.B. 2610 creates a compelling reason to implement and maintain an appropriate cybersecurity program. Cyber insurers are also evaluating how organizations manage cyber risk when making underwriting decisions.
Both conversations lead back to the same issue:
Evidence matters.
At TruePoint Systems, we help businesses move beyond simply having cybersecurity tools to building a cybersecurity program they can understand, maintain, and demonstrate. By bringing managed IT, cybersecurity, strategic technology guidance, and audit readiness together under one accountable partner, we help leadership identify gaps before those gaps become expensive surprises.
The goal isn’t more paperwork.
It’s a cybersecurity program that can stand up to scrutiny when an insurer, auditor, customer, attorney, or business leader asks the question that matters:
Can you prove you were prepared?
Managed Technology. Zero Surprises.

