Your duty to protect client confidences, your state safe-harbor protection, and your firm’s cybersecurity are no longer three separate problems — they’re one. Briggs IT helps Texas law firms understand what the rules require and build the written proof that they’ve met it.
For years, protecting client information was a matter of professional courtesy and good practice. That’s over. Texas attorneys are now held to a duty of technological competence — the State Bar’s ethics opinions have made clear that a lawyer must take reasonable steps to safeguard client confidences against foreseeable unauthorized access, including across email, cloud services, and AI tools. The duty is no longer aspirational. It’s an expectation you’re measured against.
At the same time, Texas Senate Bill 2610 (SB 2610) created something new: an affirmative safe harbor against punitive damages for a firm that has implemented and documented a qualifying cybersecurity program. Here’s what that means in plain terms — in the event of a breach, your firm is either able to show, in writing, that it qualified, or it isn’t. That single distinction can be what stands between a manageable incident and your partners’ personal exposure. The program isn’t paperwork for its own sake. It’s the documentation that protects the people who own the firm.
A qualifying program isn’t one thing — it’s a set of pieces that work together and, just as important, the written evidence that each one exists. A complete program includes:
We’re the subject-matter experts — not your IT department, and not the authority (that’s the regulators). Our recurring engagement is maintenance, and you can’t maintain a program that isn’t built yet. So the sequence is deliberate: we review where you stand, get the gaps fixed and documented to a clean baseline, and only then does recurring begin.
Most firms do — and a good IT provider is worth keeping. But keeping the lights on and building a defensible compliance program are different jobs. A compliance program means someone who can produce a Written Information Security Program that lines up with the State Bar’s ethics expectations, stand up a documented incident response plan, and assemble the evidence an examiner — or a plaintiff’s attorney — will ask to see. That’s a different discipline from break-fix or help-desk work, and it’s not a knock on them.
Compliance is the only thing we do — it’s our whole practice, not a sideline. If you have IT, we tell you and them exactly what the rules require and verify it gets done. If you don’t, we build the program in a scoped, defined, and billable remediation and implementation phase. Your IT keeps doing their job; we make sure the compliance side is real, documented, and holds up when someone asks.
Small firms get hit precisely because they’re small. Attackers don’t pick a firm and study it — they run automated campaigns against tens of thousands of targets at once and take whoever’s unprotected. A small firm with thin defenses is easier to breach than a large one with a security team, and no one ever had to know your name to find you.
And a law firm is a rich target at any size. You hold wire instructions, settlement funds, real-estate closings, and client confidences — exactly what ransomware and business-email-compromise crews are after. Being small doesn’t make you less valuable to them; it usually just makes you easier. Size isn’t cover. Preparation is.