AccuSights
PartnersBlogAbout
Book my 30-minute demo

Dallas, Texas · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

Dallas-Fort Worth builds what the country flies. We keep the drawings in the shop.

A machine shop in Grand Prairie that supplies a Fort Worth prime, a dental group in Plano, an RIA in Southlake with a questionnaire due Friday. You built it on the Tollway and 635. Someone overseas is working tonight on a login that looks like yours. We work the other side of that, around the clock.

Chicago-based, serving Dallas-Fort WorthEngineer on site for practicesPublic pricingStaff training included

Serving Uptown and Downtown Dallas, Las Colinas and Irving, Plano and Legacy West, Frisco, Richardson, Southlake and Westlake, Fort Worth and Arlington and Grand Prairie. Remote first, on site when it matters.

A Dallas story

The Tuesday the machine shop almost lost the prime

the second-generation owner of a 48-person machine shop in Grand Prairie that supplies a Fort Worth prime

It is a Tuesday in April and the prime's supplier security questionnaire is due Friday. The owner took over the shop from his father in 2014, 48 people now, and the titanium bracket order on the floor is worth $3.1 million over three years. The drawings for it are controlled unclassified information. They live in one folder.

On Monday the estimator got an email from the prime's supplier portal asking him to re-verify his login before the questionnaire deadline. It looked like every other portal email. He typed his password into a page that was not the portal. He did what the email asked, and the email was good.

At 1:14 on Tuesday morning someone in another time zone tries that password on the shop's cloud account.

The login never gets past the prompt. The engineer watching the console sees the attempt from a country the shop has never shipped to, resets the password before the first shift, and writes it up. On Wednesday the owner answers the questionnaire's question about detecting unauthorized access with Tuesday's log. The prime reads it, and the bracket order stays in Grand Prairie.

The password works, and the only thing between a stranger and the drawings that keep the contract alive is a second factor the estimator has on his phone.

What changes the ending

  1. MFA on every account that can reach the drawings, so a password from a fake portal is useless at 1 a.m. (CIS 6 Access Control Management).
  2. CUI in one enclave with access by name, not a shared drive the whole shop can open, which is what NIST SP 800-171 asks for anyway (CIS 3 Data Protection).
  3. A named engineer watching logins around the clock, so the prime hears about the attempt from you, with evidence, not the other way around (CIS 13 Network Monitoring and Defense).

What price are you willing to pay to let two generations of building in this city go away because someone overseas tricked one person on your team into clicking a link? The prime will not wait while you rebuild. We would rather you take the vacation you earned and land at DFW to find payroll still there and the contract still yours.

Sam Khan, founder. The Cyber Expert in times of peace.

Texas, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$1.826B
lost to internet crime by Texas victims in 2025, across 97,922 complaints, second only to California on both
Source: FBI IC3 2025 Annual Report, Texas state page, 2026
$8.5M
the recovery budget the Dallas City Council approved after ransomware got in with stolen credentials and took down 911 dispatch and the courts
Source: The Dallas Morning News, 2023
61%
of manufacturing breaches involve a third party, the highest of any major sector
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

Texas breach notification, Business and Commerce Code 521.053

Notify affected individuals without unreasonable delay and no later than 60 days after determining a breach occurred. If 250 or more Texans are affected, notify the Attorney General through the AG web form within 30 days.

Regulator: Texas Attorney General · source

Texas Data Privacy and Security Act

In force since July 1, 2024. SBA-defined small businesses are exempt except that they must get consent before selling sensitive data. Attorney General enforcement, $7,500 per violation, 30-day cure period.

Regulator: Texas Attorney General · source

Texas SB 2610 cybersecurity safe harbor

Signed June 20, 2025, effective September 1, 2025. A business that keeps a written cybersecurity program aligned to a recognized framework such as the CIS Controls can limit exemplary damages after a breach. Read the enrolled text for the exact conditions.

Regulator: Texas courts · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

Royal ransomware hit the City of Dallas after attackers used stolen credentials to reach a city server and take almost 1.2 TB of data, disrupting 911 dispatch, courts and city websites; the council approved an $8.5 million recovery budget.

May 2023 · The Dallas Morning News

Dallas County notified more than 200,000 people that Social Security numbers, medical and health-insurance information had been exposed in a ransomware attack the previous October.

July 2024 · The Dallas Morning News

A ransomware attack took the Tarrant Appraisal District in Fort Worth offline; the district confirmed a $700,000 ransom demand and later said some taxpayer data was posted online.

March 2024 · Fort Worth Report

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Dallas

Same controls, told from where it hurts for your business.

Medical and dental practices

What if the Plano office manager's inbox is the one that pays the vendors and holds the patient schedule?

Every workstation and the practice server watched around the clock, offline backups that restore charts in hours, MFA on every login, the HB 300 training record kept, and a HIPAA risk analysis your license can stand on.

Education and health services employ 530,600 people in Dallas-Fort Worth (BLS, July 2026), with the heaviest independent-practice density in Plano, Frisco, Southlake and Arlington; Texas has 16,692 active dentists (KFF).

Defense suppliers and machine shops

What if the prime asks for our NIST 800-171 score on Friday and the drawings live on a shared drive everyone can open?

CUI in one controlled enclave, the 110 NIST SP 800-171 practices assessed and scored, a System Security Plan you can hand to the prime, and an engineer watching logins so the prime hears about an attempt from you.

The F-35 line, the tiltrotor plant and the missile plant in Grand Prairie make DFW the densest DoD subcontractor base in Texas, and Texas installations support more than 628,000 jobs statewide (Texas Comptroller, July 2026).

RIAs, broker-dealers and insurance agencies

What if the custodian's questionnaire asks how we detect an intrusion and the honest answer is that we do not?

The questionnaire answered from evidence the agent collects, client data encrypted behind access by name, MFA everywhere, and a written program that satisfies the FTC Safeguards Rule and the SB 2610 safe harbor at the same time.

Financial activities employ 389,400 people in DFW (BLS, July 2026), fed by the back-office campuses in Plano and Westlake, and the financial sector is the most attacked by raw incident count (Verizon 2026 DBIR).

Law firms

What if the wire instructions in the thread are real, but the thread has had a stranger in it since March?

Lookalike-domain filtering, a callback rule your paralegals practice, MFA on partner mailboxes, and an engineer who sees the login from the wrong country before the money moves.

Business email compromise cost Texas $304.3 million across 2,253 complaints in 2025 (FBI IC3), and Uptown, Las Colinas and Legacy West hold the firms that move the money.

Software and telecom companies

What if the enterprise customer wants SOC 2 and the evidence is a folder of screenshots from last year?

A control set mapped once to SOC 2 and the questionnaire, evidence collected continuously by the agent, and a named engineer who answers question 14 with a log, not a paragraph.

The Richardson Telecom Corridor and Frisco's corporate belt sit inside DFW's 805,200 professional and business services jobs, up 3.0% a year (BLS, July 2026).

Medical, dental and other healthcare practices

In Dallas an AccuSights cybersecurity engineer comes to the practice, from Uptown to Plano, Frisco and Fort Worth, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: NAS Joint Reserve Base Fort Worth, the F-35 final assembly line, the tiltrotor plant and the missile plant in Grand Prairie make Dallas-Fort Worth the densest DoD subcontractor base in Texas. The July 2026 pause of the C3PAO mandate is not a pardon: NIST SP 800-171 stays in the contract, and we score you against its 110 practices before the prime asks.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your Plano front desk and your Grand Prairie estimators get the same short, scored training every month, built around what we see in DFW inboxes and on DFW phones that month, including the fake supplier-portal emails aimed at defense suppliers. Phishing tests teach one habit above all: press the report button, and an engineer sees it. No per-module charges and no shaming for a click.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a Dallas business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions Dallas owners ask

What people in Dallas search for, answered straight.

What is the new HIPAA rule in 2026?
The proposed Security Rule update published in January 2025 would remove the "addressable" loophole and require MFA, encryption, an asset inventory, network segmentation and yearly testing. Check the final text before you rely on it, but those are the controls we put in now, because they are what stops ransomware whether or not the rule changes.
How much does HIPAA compliance cost in Dallas?
Our pricing is public: the risk analysis and the on-site setup are a fixed fee, and protection is priced per employee. A 30-minute demo scopes it for your practice, from Plano to Fort Worth, and the engineer who does the visit is the one you talk to afterward.
We are a Fort Worth subcontractor. What CMMC level do we need?
If you handle controlled unclassified information, drawings, specifications, test data, you are a Level 2 supplier and NIST SP 800-171 has been in your contract since 2017. The July 2026 pause of the C3PAO mandate does not change that. We assess the 110 practices, score you, write the System Security Plan and fix the gaps before the prime asks.
Is there a HIPAA-compliant AI chatbot?
No tool is HIPAA compliant on its own. What matters is a signed business associate agreement and controls around what staff paste in. The consumer version signs no BAA, so patient data cannot go in it. Some enterprise offerings do sign one. We set up a sanctioned tool and a data-loss policy that watches AI destinations, because employee AI use tripled in a year (Verizon 2026 DBIR).
What does Texas law require after a data breach?
Notify affected individuals within 60 days of determining a breach occurred, and notify the Attorney General within 30 days if 250 or more Texans are affected. HIPAA runs its own 60-day clock for patient data. SB 2610 can limit exemplary damages if you kept a written program aligned to a recognized framework, which is what our assessment is scored against.
Does the Texas Data Privacy and Security Act apply to my small business?
SBA-defined small businesses are exempt from most of it, but they still need consent before selling sensitive data, and the Attorney General enforces at $7,500 per violation after a 30-day cure period. HIPAA, the FTC Safeguards Rule and your customers' contracts usually reach you first. We tell you in the first 30 minutes which of these actually applies.

Sources: FBI IC3 2025 Annual Report, Texas · Texas Business and Commerce Code 521.053 · Texas Attorney General, TDPSA · Texas SB 2610 bill history · Texas Comptroller, military installation economic impact, 2026 · BLS, Dallas-Fort Worth-Arlington Economy at a Glance · KFF, professionally active dentists · The Dallas Morning News, City of Dallas ransomware · City of Dallas after-action report · The Dallas Morning News, Dallas County · Fort Worth Report, Tarrant Appraisal District · FBI Dallas Field Office · CISA Region 6 · Verizon 2026 DBIR

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Dallas practice replies within one business day.

3-min test