Austin, Texas · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week
Austin moves fast. We make sure the money and the data arrive where you sent them.
A brokerage in Cedar Park with three closings on the board, a startup at the Domain answering its first enterprise questionnaire, a specialty practice in Round Rock, a supplier in Pflugerville with a Samsung drawing on the server: Central Texas grows faster than its security does. We close that gap and watch it around the clock, with an engineer who answers, so Mopac at 5:30 is the worst part of your day.
Chicago-based, serving Central TexasEngineer on site for practicesPublic pricingStaff training included
Serving Downtown and Rainey Street, the Domain, South Congress, Round Rock, Cedar Park, Pflugerville, Georgetown and Bee Cave. Remote first, on site when it matters.
A Austin story
The Tuesday the down payment went somewhere else
the broker-owner of a 40-agent residential brokerage in Cedar Park
It is a Tuesday in June, already 98 on Parmer Lane, and the broker-owner of a Cedar Park brokerage has three closings on the board. The biggest is a first-time buyer in Leander, $212,000 due to the title company by 10 a.m. Her agent on that deal is good, fast, and runs her whole business from her phone.
The agent's email is a free account with a password she also used for a furniture site that was breached in 2024. Since April somebody has read her mail from another country each night. They have watched this closing from the first showing. On Monday evening they sent the buyer an email, from her name, with updated wiring instructions and the title company's logo.
The buyer is careful. He wires first thing Tuesday so he will not be late. The instructions look exactly like the ones from the week before, except for a different bank and a different account number.
At 9:40 a.m. the buyer texts the agent a photo of the wire confirmation, and the account number on it is not the title company's.
What changes the ending
Multi-factor authentication and a company mailbox for each agent, so a password reused on a furniture site does not open a $212,000 closing (CIS 6 Access Control Management)
Domain protection and mail filtering that catches lookalike senders and flags any message containing wiring instructions (CIS 9 Email and Web Browser Protections)
Buyers, agents and staff trained on one rule, that wiring instructions are confirmed by phone at a known number before a dollar moves (CIS 14 Security Awareness and Skills Training)
What price are you willing to pay to let ten years of building go away because someone overseas tricked one person on your team into clicking a link? Texas ranks second in the nation for losses reported to the FBI, and the closing wire is the one they watch for. We would rather you take the week at Port Aransas you earned, and drive back up 35 to find payroll still there.
Sam Khan, founder. The Cyber Expert in times of peace.
Texas, by the numbers
What the FBI, the state and the researchers counted, not what a vendor guessed.
$1,825.6M
lost by Texas victims across 97,922 complaints to the FBI in one year, second in the nation on both counts
Source: FBI IC3 2025 Annual Report, Texas state page (2026)
$304.3M
lost to business email compromise in Texas across 2,253 complaints, the fraud that reroutes closing wires and payroll
Source: FBI IC3 2025 Annual Report, Texas state page (2026)
40%
higher click rate on lures delivered to phones than to email inboxes, which is where agents and owners now read their mail
Source: Verizon 2026 Data Breach Investigations Report
The law and its clock
Texas data breach notification law (Tex. Bus. & Com. Code 521.053)
Notify affected individuals without unreasonable delay and no later than the 60th day after determining a breach. If 250 or more Texas residents are affected, notify the Attorney General through the online form as soon as practicable and no later than 30 days.
In force since July 1, 2024. Small businesses as defined by the SBA are exempt, except that they must obtain consent before selling sensitive personal data. Attorney General enforcement only, $7,500 per violation, 30-day cure.
In force since January 1, 2026. Sets duties for developers and deployers of AI systems, with the Attorney General as exclusive enforcer and a complaint form on the AG's homepage. Separately, SB 2610, effective September 1, 2025, limits civil liability for businesses after a breach of system security; confirm the operative conditions against the enrolled text before relying on them.
The regulator has the final say. We help interpret, scope and get you ready; we do not certify.
It happened here
The Ascension ransomware attack forced Ascension Seton hospitals in Austin onto paper charts for nearly a month; the system later reported 5.6 million people affected.
HCA Healthcare, parent of St. David's HealthCare in Austin, disclosed that a patient list of about 27 million rows was posted online, affecting about 11 million patients across its system.
The Texas Health and Human Services Commission found that its own employees had improperly accessed the personal information of at least 61,000 Medicaid, CHIP, TANF and SNAP recipients; the employees were fired.
We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.
Who we protect in Austin
Same controls, told from where it hurts for your business.
Medical, dental and specialty practices
Ascension Seton went to paper for a month. My practice in Round Rock could not bill for a week. What is different about us?
The EHR server and each workstation watched around the clock, backups that restore, and a HIPAA risk analysis done on site that also covers Texas HB 300 training and the state's own medical privacy rules.
Education and health services employ 172,100 people in the metro (BLS, July 2026), with fast growth of specialty practices in Cedar Park, Round Rock and Bee Cave; Texas has 16,692 active dentists (KFF, 2024).
Our first enterprise customer sent a 200-question security questionnaire, and TRAIGA just took effect. Do we need SOC 2, an AI policy, or both?
The controls SOC 2 expects, in place and producing evidence, plus a written AI governance program sized to the company, so the questionnaire is answered from a console and the audit, when you choose it, is a formality.
Professional and business services is the metro's largest private sector at 294,600 jobs, growing 3.2% a year (BLS, July 2026); Austin carries the strongest SOC 2 demand of the Texas cities, and TRAIGA took effect January 1, 2026.
A buyer wired $212,000 to an account that was not the title company's because the email looked like our agent's. Who is liable?
Company mailboxes with multi-factor authentication for each agent, lookalike domains flagged, and the wire-verification habit trained into agents, staff and clients before closing day.
Texas businesses lost $304.3 million to business email compromise in 2025 (FBI IC3, 2026), and construction employment in the metro grew 5.5% in a year (BLS, July 2026).
We sell to a state agency and to a Fort Cavazos supplier. DIR wants one security assessment and the prime wants NIST 800-171. Is that two programs?
One control set that answers the Texas Cybersecurity Framework and NIST 800-171 at the same time, with the evidence produced once and the controls kept running between assessments.
The state is the biggest local buyer, with the Capitol, DIR and each agency headquarters in Austin (research desk, 2026); Texas military installations contribute $148.8 billion in economic output and support more than 628,000 jobs (Texas Comptroller, 2026).
Semiconductor and advanced-manufacturing suppliers
Samsung and Applied Materials audit our security before they share process data. What do they expect from a 45-person shop in Pflugerville?
Customer data in one controlled place with access by role, the plant network separated from the office, internet-facing systems patched, and an engineer watching around the clock.
Samsung, NXP, Applied Materials and Infineon anchor a supplier base across Round Rock, Pflugerville and Taylor (research desk, 2026), and the 2026 DBIR found 61% of manufacturing breaches involve a third party.
In Austin an AccuSights cybersecurity engineer comes to the practice, from Round Rock to Bee Cave, and sets up the critical controls and the protection agent the same week.
The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.
Defense suppliers: Camp Mabry, the Army's transformation and innovation commands in Austin, Fort Cavazos an hour north and Joint Base San Antonio an hour south, with BAE Systems' electronics facility and a growing dual-use startup scene around Capital Factory, create a supplier base that handles CUI. We get a supplier to a true NIST 800-171 score and a system security plan, and keep the controls running, because the DoD paused the assessment mandate in July 2026 but the primes did not pause their questionnaires.
Your staff, trained and scored
It is fine to skip the new Nigerian prince's email. Next time, press the report button too.
Your agents in Cedar Park and your engineers at the Domain get the same short monthly training, built around the lures hitting Texas inboxes and phones this month, including the wire-change email, and each person is scored so you know who needs a hand. The report button sits in the mail client and on the phone; one press protects the whole company. We do not charge per module or per test.
Short monthly training tied to the threats we are seeing this month, not a yearly video.
Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
Phishing tests that teach the report habit; one report protects the whole company.
Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.
What we do for a Austin business
Assess it, keep it compliant, protect it around the clock.
Assess
Cybersecurity and Data Protection Assessment (CDPA)
Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.
HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.
24/7 protection for every employee, endpoint, server and website
An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.
The discipline the largest institutions run, sized for a business that cannot hire a department for it.
Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.
Governance
Who owns security, which policies are real, and what the owner signs. One page, not a binder.
Risk
What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.
Compliance
The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.
A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.
Questions Austin owners ask
What people in Austin search for, answered straight.
How much does SOC 2 cost for an Austin startup, and how long does it take?→
Our pricing is public on the site, and a 30-minute demo scopes it to your stack and headcount. The controls, not the audit, set the pace: a startup with access reviews, tested backups and monitoring in place can be audit-ready in weeks. We build the controls first, then the report follows.
What does Texas law require after a data breach?→
Tex. Bus. & Com. Code 521.053 gives you 60 days from determining a breach to notify affected individuals, and if 250 or more Texans are affected the Attorney General gets a notice through the online form within 30 days. Practices and business associates also carry HIPAA's own clock and the Texas Medical Records Privacy Act.
Does the Texas Data Privacy and Security Act apply to my small business?→
If you are a small business under the SBA definition, you are exempt from most of it, with one exception: you must get consent before selling sensitive personal data. Larger companies carry the full set of duties, enforced by the Attorney General at $7,500 per violation with a 30-day cure. We tell you plainly which side of the line you are on.
What is the Texas cybersecurity safe harbor?→
SB 2610, effective September 1, 2025, limits civil liability for business entities in connection with a breach of system security when a recognized cybersecurity program is in place. The operative conditions live in the enrolled text and should be confirmed before you rely on them, but the direction is clear: documented, running controls are now a legal shield in Texas as well as a defense.
Does my practice in Round Rock or Cedar Park need a HIPAA risk analysis?→
Yes. The HIPAA Security Rule requires a documented risk analysis for any practice that holds electronic patient records, and Texas HB 300 adds workforce privacy training within 90 days of hire. We do the analysis on site, alongside the controls, so it reflects the practice as it runs.
We sell software to a Texas state agency. What security evidence does DIR expect?→
State agencies assess vendors against the Texas Cybersecurity Framework, and contractors with access to state systems complete the annual certified cybersecurity training under HB 3834. We map your controls to that framework once, so the same evidence answers DIR, a SOC 2 auditor and an enterprise customer.
Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.
Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Austin practice replies within one business day.