National cyber insurance · A division of Thrive Risk Management CA License #6012320
Texas · AG-first enforcement

Texas cyber insurance, built for the Texas AG era.

Cyber insurance built for the state that enforces privacy through raw prosecutorial muscle — a comprehensive privacy law with $7,500-per-violation penalties, a 60-day breach-notification statute with a public Attorney General breach list, and the first state AG in America to sue under a comprehensive privacy law.

Structured for TDPSA compliance & AG investigations
Built for the 60-day notice rule and the public AG breach list
Markets that write Texas cyber risk at every revenue size

Request a Texas cyber Quote

Tell us about your business. A licensed advisor responds — no spam, no call center.

By submitting you consent to be contacted by Thrive Risk Management Insurance Solutions regarding your quote. No obligation.

HomeTexas cyber Insurance
Texas cyber, in plain terms

Texas gives consumers no private right of action for privacy violations — and then hands all of that leverage to one office. The Texas Data Privacy and Security Act took effect July 1, 2024 with the broadest applicability of any state privacy law, the breach statute puts every sizable incident on a public Attorney General list, and the AG has built what his office calls the largest privacy-enforcement team of any state — filing the first-in-the-nation lawsuit under a comprehensive state privacy law in January 2025. Here is what an AG-first regime means for how your cyber policy should be structured.

The TDPSA: the broadest reach of any state privacy law

Texas’s comprehensive privacy statute is the Texas Data Privacy and Security Act (TDPSA), Business & Commerce Code Chapter 541, effective July 1, 2024. Unlike California or Colorado, it has no revenue or record-count threshold: it applies to essentially any entity that conducts business in Texas or serves Texans and processes or sells personal data, exempting only businesses that meet the federal SBA small-business definition — and even those must obtain consent before selling sensitive data. It requires clear privacy notices, consent for processing sensitive data such as precise geolocation, health, and biometric information, data-protection assessments for higher-risk processing, and binding contracts with processors.

Enforcement is the Attorney General’s alone — there is no private right of action — with civil penalties of up to $7,500 per violation after a 30-day cure period. And Texas has staffed for it: in June 2024 the AG launched a dedicated data privacy and security enforcement initiative, billed as the largest privacy-enforcement team of any state attorney general in the country. Within months it had secured a record $1.4 billion biometric-privacy settlement with Meta and, in January 2025, sued Allstate and its subsidiary Arity for allegedly collecting and selling driving data from 45 million consumers through embedded mobile-app software — the first enforcement lawsuit ever filed under a state comprehensive privacy law.

Breach notification: 60 days, 30 days, and a public list

Texas’s breach-notification regime lives in the Identity Theft Enforcement and Protection Act, Business & Commerce Code Chapter 521, and it has three teeth worth knowing:

  • Two clocks: affected individuals must be notified within 60 days of determining a breach occurred, and when a breach affects 250 or more Texans, the Attorney General must be notified electronically within 30 days of discovery via the AG’s data breach reporting portal.
  • A public breach list: the AG is required to publish reported breaches on a public website listing — meaning every reportable Texas breach becomes a searchable public record that customers, competitors, and plaintiff attorneys can browse. The reputational event is statutory, not optional.
  • Escalating penalties: violations of Chapter 521 carry civil penalties of $2,000 to $50,000 per violation, and a failure to notify can cost up to $100 per individual per day of delay, capped at $250,000 per breach — a penalty structure that turns slow incident response directly into money.

How your cyber insurance should be structured in Texas

Because Texas concentrates enforcement in the Attorney General rather than in private lawsuits, the center of gravity of a Texas cyber policy shifts. Regulatory-defense coverage is the headline third-party grant: a TDPSA inquiry or Chapter 521 investigation arrives as a civil investigative demand from a well-staffed unit that has already shown it will litigate, and defense costs accrue whether or not a penalty ever lands. First-party breach-response coverage should be sized for the 60-day and 30-day clocks — forensics, breach counsel, notification, and call-center costs are exactly what the statute forces you to spend — and because the AG list makes every reportable breach public, crisis-communications and reputational-harm coverage stop being luxuries. Two cautions: the SBA small-business exemption under the TDPSA does not exempt anyone from the breach statute, so small Texas firms carry real notification exposure; and no privacy statute limits ransomware or funds-transfer fraud, which remain the loss drivers for most Texas businesses. We structure the policy around all of it — enforcement exposure, statutory response costs, and the crime perils the headlines forget.

Texas cyber — Frequently Asked

Questions Texas operators ask.

Do I have to notify anyone after a data breach in Texas?
Yes, on two tracks with two different deadlines. Under Business & Commerce Code §521.053, you must notify each affected individual within 60 days of determining that a breach of system security occurred, and if the breach involves 250 or more Texas residents you must also report it electronically to the Attorney General within 30 days of discovery using the form on the AG’s website. The AG then publishes the breach on a public list that anyone can search — so the notification is also, in effect, a press release. Miss the deadlines and the statute bites: failure to notify can draw penalties of up to $100 per affected individual for each day of delay, capped at $250,000 per breach, on top of Chapter 521 civil penalties that range from $2,000 to $50,000 per violation. This is precisely the sequence a cyber policy’s breach-response coverage is built to fund — forensics to scope the incident fast enough to make the 30-day AG clock, breach counsel to draft compliant notices, and mailing and call-center costs for the 60-day consumer notice. When we place Texas cyber, we confirm those first-party limits reflect your actual record count, because the statute, not your budget, sets the timetable.
Texas has no private right of action for privacy violations — do I still need cyber insurance?
Yes, and arguably the structure matters more here, not less. What Texas removed in private lawsuits it concentrated in the Attorney General, whose privacy-enforcement unit — launched in June 2024 and billed as the largest of any state AG — has already produced a $1.4 billion biometric settlement with Meta and the first-ever state lawsuit under a comprehensive privacy law, against Allstate and Arity, seeking up to $7,500 per TDPSA violation. Multiply $7,500 by a database of affected Texans and the exposure rivals any class action, and the defense costs of answering a civil investigative demand accrue even when you ultimately cure within the TDPSA’s 30-day window. Meanwhile, the perils that actually bankrupt small businesses — ransomware, business-email compromise, funds-transfer fraud — have nothing to do with privacy statutes and hit Texas firms daily. And common-law negligence and contract-based breach suits still exist in Texas courts even without a statutory cause of action. A well-built Texas policy therefore pairs strong first-party coverage for ransomware and cybercrime with regulatory-defense coverage for the AG, plus notification-cost coverage sized to Chapter 521’s clocks. The absence of a private right of action changes where the lawsuits come from — not whether you can afford the incident.
Doesn’t my general liability policy cover cyber attacks?
No — and this is the most expensive assumption in small-business insurance. General liability responds to bodily injury and physical damage to tangible property, and courts have generally held that electronic data is not tangible property. On top of that, standard GL policies now carry explicit exclusions for access to or disclosure of confidential or personal information, added across the market after early data-breach lawsuits. Commercial property policies have the same problem: they cover the server hardware, not the data on it or the income lost while your systems are locked. Cyber insurance exists as a separate line precisely because it covers what those policies deliberately carve out — breach response, ransomware, data restoration, and privacy lawsuits. If a client contract requires “cyber liability,” a GL certificate will not satisfy it.
What does a cyber insurance policy actually cover?
A modern policy has two sides. First-party coverage pays your own costs after an incident: forensics to determine what happened, breach counsel, the notification letters state law requires you to send, credit monitoring for affected people, ransomware and extortion response, business income lost during an outage, and the cost of restoring data. Third-party coverage defends and pays when others come after you: lawsuits from customers or employees whose data was exposed, claims that malware spread from your systems, regulatory investigations, and PCI assessments from the card brands. Most policies add crime-style endorsements for social engineering and funds-transfer fraud, where many real-world losses now occur. The Federal Trade Commission’s Data Breach Response guide shows how many moving parts a breach involves — a good cyber policy funds and coordinates essentially all of them.
Other States

cyber insurance in other states.

Need Texas cyber coverage that clears your contracts?

Tell us about your operation and your loss history — we’ll confirm we can write Texas and structure the limits to match.

Get a Texas Quote Call (818) 356-8150