AccuSights
PartnersBlogAbout
Book my 30-minute demo

Houston, Texas · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

Houston does not shut down for weather. It should not shut down for a link either.

A two-chair dental practice on Mason Road in Katy, an engineering firm in the Energy Corridor, a Clear Lake supplier with NASA drawings on a shared drive. You built it through Harvey, Beryl and the derecho. Someone overseas is working tonight on the outage no generator fixes. We watch the other side of that, around the clock.

Chicago-based, serving Greater HoustonEngineer on site for practicesPublic pricingStaff training included

Serving the Texas Medical Center, the Energy Corridor, the Galleria and Uptown, The Heights and Montrose, Katy, Sugar Land, The Woodlands and Clear Lake and League City. Remote first, on site when it matters.

A Houston story

The Tuesday a Katy dental practice got its nineteen years back by lunch

the owner-dentist of a two-chair practice on Mason Road in Katy

It is 7:05 on a Tuesday in August, already 84 degrees, and the first patient is a crown prep at 7:30. The owner-dentist opened on Mason Road nineteen years ago with one chair and a loan. Nineteen years of charts, X-rays and ledgers live on the server in the closet behind the sterilization room.

The remote-access tool on that server had a flaw the vendor fixed in June. Nobody installed the fix, because nobody knew there was one. At 3:40 that morning someone in another time zone found the open door, walked in, and started encrypting.

The hygienist logs in at 7:12 and the schedule will not load.

The agent on the server had already cut the encryption off at 3:41 and woken an engineer, not the dentist. By 7:20 the engineer is on the phone. The offline backup from midnight restores the database by 11:15. The crown prep runs late. The 1:00 patient never knows. The breach analysis shows the copying was stopped before a single record left the building.

The screen shows a note instead of the day's schedule, and nineteen years of patient records are on the other side of it.

What changes the ending

  1. An offline, tested backup of the practice-management database that restores in hours, not the weeks a rebuild takes (CIS 11 Data Recovery).
  2. Patching the remote-access tool and the server the week the fix ships, because unpatched flaws are now the number one way in (CIS 7 Continuous Vulnerability Management).
  3. A protection agent on the server that stops encryption at 3:41 a.m. and wakes an engineer, not the dentist (CIS 10 Malware Defenses).

What price are you willing to pay to let nineteen years of building in this city go away because someone overseas tricked one person on your team into clicking a link? You got through Harvey and Beryl. We would rather you take the vacation you earned and land at Hobby to find payroll still there and every chart where you left it.

Sam Khan, founder. The Cyber Expert in times of peace.

Texas, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$1.826B
lost to internet crime by Texas victims in 2025, across 97,922 complaints, second only to California on both
Source: FBI IC3 2025 Annual Report, Texas state page, 2026
$304.3M
of that was business email compromise, the changed invoice and the changed wire, across 2,253 Texas complaints
Source: FBI IC3 2025 Annual Report, Texas state page, 2026
99%
of healthcare breaches are the work of financially motivated criminals; 20% begin with an exploited flaw
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

Texas breach notification, Business and Commerce Code 521.053

Notify affected individuals without unreasonable delay and no later than 60 days after determining a breach occurred. If 250 or more Texans are affected, notify the Attorney General through the AG web form within 30 days.

Regulator: Texas Attorney General · source

Texas Medical Records Privacy Act (HB 300, Health and Safety Code Chapter 181)

A broader "covered entity" definition than HIPAA. Workforce privacy training within 90 days of hire and at least every two years, with penalties up to $1.5 million per year.

Regulator: Texas Attorney General and the licensing boards · source

Texas Data Privacy and Security Act

In force since July 1, 2024. SBA-defined small businesses are exempt except that they must get consent before selling sensitive data. Attorney General enforcement, $7,500 per violation, 30-day cure period.

Regulator: Texas Attorney General · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

A suspected ransomware attack on The Harris Center for Mental Health and IDD, Harris County's public mental-health authority, encrypted employee files, limited access to patient records and delayed treatment.

November 2023 · Houston Public Media

A ransomware attack on Fort Bend County Libraries took down the website, catalog and patron accounts for roughly six months, at a reported cost to taxpayers above $5 million.

February 2025 · ABC13

The PowerSchool student-information-system breach exposed data of more than 880,000 Texas students and teachers, including Houston-area districts, and the Texas Attorney General sued the vendor.

September 2025 · KPRC 2

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Houston

Same controls, told from where it hurts for your business.

Medical and dental practices

What if the server in the closet behind sterilization is the only copy of nineteen years of charts?

Offline backups tested on a schedule, the server and every workstation patched and watched around the clock, MFA on every login, the HB 300 training record kept, and a HIPAA risk analysis your license can stand on.

Texas has 503 community hospitals, the most of any state, 75,335 active physicians and 16,692 active dentists (KFF), and Houston's independent practices spread from the Medical Center to Katy, Sugar Land and The Woodlands.

Energy services, fabrication and engineering firms

What if the operator's vendor questionnaire asks how we detect an intrusion and nobody here is watching?

Every endpoint and server watched around the clock, the questionnaire answered from evidence the agent collects, vendor connections into your network mapped and locked down, and backups that survive a bad Tuesday.

Houston has 240,100 manufacturing jobs and 73,400 in mining and logging (BLS, July 2026), and 61% of manufacturing breaches involve a third party (Verizon 2026 DBIR).

NASA and defense suppliers in Clear Lake

What if the prime asks for our NIST 800-171 score on Friday and the drawings live on a shared drive?

CUI in one controlled enclave, the 110 NIST SP 800-171 practices assessed and scored, a System Security Plan you can hand over, and an engineer watching logins so the prime hears about an attempt from you.

Johnson Space Center and Ellington Field anchor the Clear Lake contractor cluster, and Texas military installations support more than 628,000 jobs statewide (Texas Comptroller, July 2026).

Law firms and title companies

What if the payoff instructions in the thread are real, but the thread has had a stranger in it since June?

Lookalike-domain filtering, a callback rule your closers practice, MFA on every mailbox, and alerts on new inbox rules and logins from the wrong country, read by a human the same morning.

Business email compromise cost Texas $304.3 million across 2,253 complaints in 2025 (FBI IC3), and Houston's no-zoning sprawl means closings happen in every strip center from Cypress to Pearland.

CPA and bookkeeping firms

What if the office manager's inbox is the one that pays the vendors, and it is also the one that opens every client's W-2?

MFA on every account, client data encrypted behind access by name, a data-loss policy that stops files leaving, application control so a "support tool" from a phone call cannot run, and the FTC Safeguards Rule written plan.

Professional and business services is Houston's fastest-growing large sector at 582,900 jobs, up 3.1% a year (BLS, July 2026), and every one of those firms holds someone else's bank details.

Medical, dental and other healthcare practices

In Houston an AccuSights cybersecurity engineer comes to the practice, from the Medical Center to Katy, Sugar Land and The Woodlands, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: Johnson Space Center, Ellington Field and the Clear Lake contractor cluster make Houston a NASA and defense supplier town, and the state's 14 installations contribute an estimated $148.8 billion in economic output (Texas Comptroller, July 2026). The July 2026 pause of the C3PAO mandate is not a pardon: NIST SP 800-171 stays in the contract, and we score you against its 110 practices before the prime asks.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your Katy front desk and your Energy Corridor engineers get the same short, scored training every month, built around what we see in Houston inboxes and on Houston phones that month. It also satisfies the HB 300 training record Texas expects. Phishing tests teach one habit above all: press the report button, and an engineer sees it. No per-module charges and no shaming for a click.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a Houston business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions Houston owners ask

What people in Houston search for, answered straight.

How much does it cost to get HIPAA compliant in Houston?
Our pricing is public: the risk analysis and the on-site setup are a fixed fee, and protection is priced per employee. A 30-minute demo scopes it for your practice, from the Medical Center to The Woodlands, and the engineer who does the visit is the one you talk to afterward.
What is Texas HB 300 and how is it different from HIPAA?
HB 300 is the Texas Medical Records Privacy Act. It covers more businesses than HIPAA does, requires privacy training within 90 days of hire and every two years after, and carries penalties up to $1.5 million a year. Our monthly training keeps the record HB 300 asks for, and the risk analysis covers both laws at once.
What is the Texas 60-day breach rule?
Under Business and Commerce Code 521.053 you must notify affected individuals no later than 60 days after determining a breach occurred, and if 250 or more Texans are affected you notify the Attorney General within 30 days through the AG web form. HIPAA runs its own 60-day clock for patient data. The clock only matters if something leaves, which is the part we work on.
Does the Texas cybersecurity safe harbor protect my business?
SB 2610, signed June 20, 2025 and effective September 1, 2025, limits exemplary damages after a breach for a business that keeps a written cybersecurity program aligned to a recognized framework such as the CIS Controls. Read the enrolled text for the exact conditions. Our assessment is scored against the CIS Controls, which is the kind of program the statute is describing.
What does a cybersecurity company in Houston do for an energy services firm with 40 people?
An assessment that finds where the money, the drawings and the vendor connections live and the ten fixes that matter first. The operator's questionnaire answered from evidence. And 24/7 protection: an agent on every device and a named engineer watching it, so a login from the wrong country at 3 a.m. meets a human at 3:03.
Do you come on site in Katy, Sugar Land and The Woodlands?
Yes. Our engineers work on site across Greater Houston, inside the Loop and out to the Grand Parkway, and remotely for the rest. The critical controls and the protection agent go in the same week as the risk analysis.

Sources: FBI IC3 2025 Annual Report, Texas · Texas Business and Commerce Code 521.053 · Texas Attorney General, TDPSA · Texas Health and Safety Code Chapter 181 · Texas SB 2610 bill history · Texas Comptroller, military installation economic impact, 2026 · BLS, Houston-Pasadena-The Woodlands Economy at a Glance · KFF, community hospitals · KFF, professionally active physicians · KFF, professionally active dentists · Houston Public Media, The Harris Center · ABC13, Fort Bend County Libraries · KPRC 2, PowerSchool suit · FBI Houston Field Office · CISA Region 6 · Verizon 2026 DBIR

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Houston practice replies within one business day.

3-min test