Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Houston startup lands $10M to power up electrician staffing platform

money moves

Houston-based Buildforce, which provides a tech-enabled staff platform geared toward electricians and electrical contractors, has raised a $10 million Series A round led by Houston’s Saepio Capital.

Other investors in the round include Blue Heron Capital, Revolution’s Rise of the Rest Seed Fund, S3 Ventures and Chicago Ventures.

Buildforce says the funding will help fuel its national expansion and further development of its technology.

The startup, founded in 2019, connects electricians with electrical contractors for commercial and industrial construction projects. Buildforce’s mobile app helps electricians find and carry out work, and a web app helps electrical contractors find and manage electricians.

“This financing is a major milestone in furthering our mission to help people dedicated to a career in the construction trades lead more secure and fulfilling lives,” co-founder and CEO Moody Heard said in a news release.

Buildforce focuses solely on the electrical trade within the construction sector.

Nick Graziano, principal at Blue Heron, says the shortage of electricians is intensifying as demand for electricians accelerates, driven by data center construction, infrastructure development and energy transition initiatives.

The U.S. Bureau of Labor Statistics estimates the U.S. will need to hire about 80,000 new electricians per year through 2032 to catch up with demand. According to the National Electrical Contractors Association, the U.S. is grappling with a current shortage of 50,000 electricians.

A 2026 economic report from asset manager BlackRock says the electrical trade is expected to be the single fastest-growing employment category in the U.S. labor market over the next 10 years.

“Buildforce is capitalizing on a clear opportunity in America’s generational infrastructure buildout. We believe their mission to use technology to improve lives in the construction space will allow them to make a positive long-term impact on a large and important labor market,” added Jaan Bains, managing partner at Saepio Capital.

Venus Aerospace adds government, C-suite leaders following $91M raise​

new leaders

Fresh off its $91 million Series B, Houston-based Venus Aerospace has made several key additions and promotions to its leadership team.

The company says its expanded team will help it deploy its high-thrust rotating detonation rocket engine (RDRE), which completed its first U.S. flight test last summer.

"We flew the world's first high-thrust RDRE in just over four years on $80 million. We believe that makes it the fastest, most capital-efficient rocket engine program in history," Sassie Duggleby, co-founder and CEO of Venus Aerospace, said in a news release. "Adding this talent to our leadership team is how we bring that same discipline to the company itself, as we scale to meet the technical needs of defense and space customers who need range and speed legacy systems can't deliver."

The key hires include:

Lane Bodian, Vice President of Public Policy

Bodian previously served as the Principal Deputy Assistant Secretary of Defense for Legislative Affairs at the Pentagon.

Dan Rebnord, Director of Federal Government Relations

Rebnord most recently served as Senior Policy Advisor to a member of the Senate Armed Services Committee and previously worked in the Office of Legislative Affairs at the Department of Defense and as Staff Director for a national security subcommittee in the House of Representatives. Rebnord and Bodian will lead Venus' work with government stakeholders.

Tom Barron, Chief Operating Officer

Barron was promoted from his role as vice president of operations for Venus Aerospace. Before his time at Venus, he served as Special Assistant to the Secretary of Defense and consulted aerospace clients at McKinsey & Company. He also served as a U.S. Army Infantry and Special Forces officer.

Nick Cardwell, Chief Product Officer

Cardwell was promoted from his role as vice president of research and development. He previously held product and technology leadership roles at VC-backed tech companies in the San Francisco Bay Area and Austin.

Venus also named Cameron Taylor as its new vice president of operations, Sarah Boland Heine as its head of communications, Matt Stohr as its head of business development, and Sheila Menz as general counsel.

The company also announced a joint technology development agreement to advance the RDRE with defense giant Lockheed Martin last week. Through the partnership, Venus and Lockheed will focus on evaluating the RDRE's propulsion architecture in defense systems, specifically for precision fires applications where weapons are designed to accurately strike targets at long distances.

Lockheed Martin Ventures, the investment arm of the aerospace and defense contractor, is an investor in Venus Aerospace.

"Lockheed Martin is focused on rapidly delivering advanced capabilities that strengthen deterrence and provide decisive advantages for the warfighter," Tim Cahill, president, Lockheed Martin Missiles and Fire Control, said in a news release. "Our collaboration with Venus Aerospace allows us to evaluate a promising propulsion technology and determine how it can be integrated into future precision fires solutions. Efforts like this help accelerate innovation, reduce risk and shorten the path from emerging technology to operational capability."

Venus' RDRE is expected to enable vehicles to travel four to six times the speed of sound from a conventional runway and is about 15 percent more efficient than traditional alternatives, according to the company.

Venus says the reusable, affordable and scalable RDRE is designed with a "common propulsion architecture" that can work for multiple industries and mission types. The company has previously estimated that the hypersonic market is projected to surpass $12 billion by 2030.