When people ask what a data breach costs, they want one number. There is not one number, and anyone who hands you a national average per record is selling something. What there is, if you run a business in Texas, is a predictable sequence of events with predictable expenses attached, and legal deadlines that start running the moment you figure out what happened.

So let us do the local math instead. What Texas law expects, who has to be told, what the invoices look like, and what the whole thing costs in time nobody budgets. Before we start: this article is general information, not legal or tax advice. Breach response is a legal process with real deadlines, and a qualified attorney, your CPA, and your insurance carrier should confirm what applies to your situation.

What Texas Law Says About Telling People

The relevant statute is Texas Business and Commerce Code Section 521.053. It applies to a person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information. That is broad language. It does not say large company, and it does not carve out businesses that keep records in a cloud service instead of a server closet.

Two deadlines matter most, and both start from the same moment.

  • Individuals get notice without unreasonable delay. The statute requires disclosure without unreasonable delay and in each case not later than the 60th day after the date the person determines the breach occurred.
  • The Attorney General gets notice at 250 Texas residents. Under the statute, if the breach involves at least 250 residents of this state, notice must go to the Texas Attorney General not later than the 30th day after the date the person determines the breach occurred.

Read those together and notice something uncomfortable. The clock is tied to determining a breach occurred, not to finishing your investigation. The expensive part of breach response, figuring out exactly what happened, happens under a deadline you do not control. It also means the state gets told before most of your customers do.

The Attorney General Report, and Why It Is Public

Section 521.053 spells out what the notice to the Attorney General must contain: a description of the nature and circumstances of the breach, the number of Texas residents affected at the time of notification, the number who received prior disclosure, the measures taken, any measures intended after the notification, and whether law enforcement is investigating.

The Texas Attorney General’s office says businesses and organizations must report breaches affecting 250 or more Texans, that reports must be submitted as soon as practicably possible and no later than 30 days after discovery of the breach, and that as of September 1, 2023 all reports must be filed electronically using its Data Breach Report form. The office also notes that a completed report is potentially an open record, meaning members of the general public may request a copy, and that it maintains a required public listing of the breach reports it receives on its website.

That last part is what small businesses do not expect. Your incident does not stay between you and your customers. It becomes a searchable entry competitors, reporters, and prospective clients can find. Reputation cost is not a soft concept here. It has a URL.

The Direct Costs: The Invoices That Show Up

These are the line items that arrive with someone’s letterhead on them. Amounts vary enormously by size and complexity, which is why we are not going to invent a figure. What we can tell you is the shape of the bill.

  • Forensics. Somebody has to determine what was accessed, when, and by whom, to a standard your lawyer can rely on. It is specialized work billed by the hour, and guessing is not an option because your notification obligations depend on the answer.
  • Legal counsel. Breach counsel decides whether the statute is triggered, drafts the notices, handles the Attorney General filing, and manages regulator or contract questions. If you do business outside Texas, other states have their own rules, and the analysis gets complicated fast.
  • Notification itself. Printing, postage, address verification, a phone line for questions, and staff to answer it. Cost scales with how many records you kept, which is a good argument for keeping fewer.
  • Credit monitoring and identity services. Frequently offered to affected people. Whether it is required depends on the facts and your contracts, which is a question for counsel, but it is commonly expected.
  • Penalties and contractual exposure. Texas law provides for civil penalties enforceable by the Attorney General, and we are deliberately not quoting a figure, because the amount and how it is calculated are exactly what you want an attorney to confirm for your circumstances. Separately, your card processor, your clients, and your insurance policy may impose their own obligations.

The Indirect Costs Nobody Budgets For

The invoices are the visible part. The costs that actually hurt a smaller company never appear on a single statement.

  • Downtime. If systems come offline, so does revenue. A service business that cannot dispatch, quote, or invoice for a week loses that week permanently, and the backlog afterward costs overtime.
  • Owner and staff hours. Breach response consumes your best people. The owner, the office manager, and whoever knows how the systems fit together spend weeks on this instead of their actual jobs.
  • Client attrition and slower sales. Some clients leave. More common is that a few quietly do not renew, and new prospects start asking security questions you have to answer honestly.
  • New requirements from partners. Larger customers often add security questionnaires, audit rights, and insurance minimums to contracts afterward. Meeting them costs money you had not planned to spend.
  • Morale. If an employee’s mistake was part of the chain, how leadership responds shapes whether anyone reports the next suspicious email quickly. Blame is expensive. We saw this play out publicly in what the Stryker cyberattack tells us about the threats facing every business.

The Cheapest Hour in the Whole Event

Here is the honest math. An hour spent before an incident is worth many hours spent during one, because beforehand you work at your own pace with your normal staff, and during it you are buying emergency help against a statutory deadline while the business is not running normally.

The preparation that pays for itself is not exotic. Know what sensitive personal information you hold and where it lives, because you cannot notify people accurately if you cannot answer that. Delete what you no longer need, since data you do not have cannot be breached. Turn on multi-factor authentication everywhere, keep backups you have actually tested restoring, and write down who to call in what order, including counsel and your insurance carrier, stored somewhere that does not require your network to be up. Then read your cyber policy before you need it, while you still have time to comply with what it requires. This is the same argument we made in why cybersecurity is no longer optional for mid-sized businesses, with the invoice attached.

The Bottom Line

A breach in Texas is not one bill. It is a statutory clock, a public filing, several professional invoices, and a long tail of lost time and lost trust. The parts you can control are upstream: how much sensitive data you keep, how quickly you can tell what happened, and whether the people who need to act know their roles. None of that requires a large budget. It requires deciding in advance.

Once more, plainly: this is general information, not legal or tax advice, and the specifics of any incident change the analysis. Have a licensed Texas attorney, your CPA, and your insurance carrier confirm your obligations and coverage before you need them.

If you are not sure where your sensitive data lives or what your first three phone calls would be, that is a solvable problem and a short conversation. We help Denton County businesses get it written down before it matters. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).