Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Houston researchers develop dissolvable implant for targeted cancer drug delivery

cancer research

Researchers at Houston Methodist have developed a biodegradable implant that can be used to safely and consistently deliver drug treatments to tumors and then dissolve without the need for further surgery.

The implant is only the size of a grain of rice, but its potential is staggering. The biodegradable nanofibrous drug-eluting seed (b-NDES) works as a reservoir parked inside a soft tumor, where it can slowly release immune-stimulating drugs over time. This overcomes a consistent problem with drugs such as immune checkpoint inhibitors. Normal systemic administration sees comparatively little of the drug making its way to the tumor, with most of it circulating throughout the body. The b-NDES is like deploying a small guerrilla fighting force embedded in enemy territory, doing maximum damage to the entrenched tumor.

"To improve cancer treatment, we're trying to start a fire inside the tumor itself," Corrine Chua, associate professor in the Center for BioNanoengineering at Houston Methodist Research Institute, said in a news release. "By activating immune cells directly within the tumor microenvironment, those cells can then travel throughout the body and seek out cancer wherever it exists. The b-NDES platform was developed to help keep therapeutic drugs concentrated inside tumors while minimizing exposure to healthy tissues.”

Chua co-led the study with Alessandro Grattoni, chair and director of the Center for BioNanoengineering at Houston Methodist Research Institute.

The study included support from the Nancy Owens Breast Cancer Foundation and the National Institutes of Health/National Cancer Institute.

Chau and Grattoni used preclinical models of triple-negative breast cancer, an aggressive form of cancer that is estrogen receptor-negative, progesterone receptor-negative and HER2-negative. Because of the receptor negativity, some popular treatments like tamoxifen and trastuzumab are ineffective. Chemotherapy has been shown to be the best course of action.

The b-NDES implant is deployed alongside radiation drugs. It keeps the drugs focused on the tumor, reducing the amount of harmful side effects typically seen when drugs are circulated more widely in the body. In 60 percent of the models, tumors were eliminated and did not cause side effects beyond the tumor site. Once the drugs have been deployed, the implant breaks down naturally.

While promising, more research will have to be done to expand use to other tumor types.

"Although the study focused on triple-negative breast cancer models, the approach could have broader applications for solid tumors," Grattoni added in the release. "It could potentially be used in cancers where there is a tumor lesion accessible for placement, including pancreatic or lung cancers."

New Houston platform Same Day Reels launches for on-demand content creation

In The Moment

If an event doesn't happen on Instagram, did it even really happen? In today's social media-driven age of branding and audience engagement, the answer increasingly is no.

Houston entrepreneur Karen De Amat is looking to fill the online content creation needs of companies with her new venture, Same Day Reels, which launched in early August. It will serve as a platform to connect companies and brands with talent that can help turn an event into a viral moment as it is happening.

"Events move quickly, and social media moves even faster,” said De Amat. “Same Day Reels was built to help brands capture the moment while it still matters. We are creating a more efficient way for businesses and creators to work together. Brands need content faster, and creators need more opportunities to turn their talent into real work. Same Day Reels brings those needs together.”

The company is focused on adding livestreams and concurrent short video content to "activations, launches, fundraisers, grand openings, conferences, hospitality experiences, and private celebrations." Such content can significantly increase the visibility of a product or brand according to digital marketing brands like Wyzowl, whose data found 63 percent of people in 2026 prefer to learn about new products via short video.

Packages offered by Same Day Reels will include filming, editing, and publishing content within hours of the targeted event.

De Amat says that her content creation platform will be a way to preserve the excitement of events and launches by enshrining them with immediate social media-driven memories.

“Event content is no longer just something you post after the fact,” De Amat said. “It is part of how people experience, remember and share the moment.”

Previously, De Amat is also the founder and CEO of Social Behavior, an influencer marketing company she launched from her home in 2014. It quickly garnered an array of clients and thrust De Amat into the spotlight, including numerous appearances on Fox 26's The Isiah Factor. Influencer Marketing Hub named her one of the top CEOs of influencer marketing companies in Houston in 2025.

---

This article originally appeared on CultureMap.com.

Bristol Myers Squibb to build $2.3B Houston pharma manufacturing campus

coming soon

New Jersey-based pharmaceutical giant Bristol Myers Squibb Co. has officially named Houston as the home of its new state-of-the-art manufacturing site.

The 60,000-square-foot facility represents a $2.3 billion investment, according to a news release. It is expected to create 500 skilled jobs and will be located in Houston's Generation Park.

BMS first announced that it was considering Houston among 16 other cities for the facility in May. The new hub will manufacture small molecule, biologic and antibody-drug conjugates and is part of a $40 billion commitment to invest in the United States over five years. Construction is slated to begin next year, with the facility coming online in 2030.

"We're building the domestic manufacturing capabilities needed to deliver the next generation of medicines and support future scientific breakthroughs. Houston and the state of Texas offer the talent, infrastructure, and partnership needed to help bring that vision to life," Christopher Boerner, CEO and board chair of BMS, said in the release.

The new facility will feature a modular, multi-modal design, which will allow the company to reconfigure and add to its manufacturing capabilities over time. BMS says it expects the facility to "(grow) in scale and capability well beyond its opening configuration."

"Our decision to build this state-of-the-art manufacturing campus in Houston, Texas, reflects our confidence in the region’s ability to support a world-class, digitally advanced supply operation,” Karin Shanahan, EVP and chief supply chain and operations officer of BMS, added in the release. “This facility is designed to deliver the speed, quality, and reliability that patients depend on, combining flexible, modular manufacturing with advanced digital capabilities to ensure consistent supply across multiple modalities. It strengthens our ability to operate with resilience and positions us to reliably deliver medicines to patients today while adapting future demands.”

Texas Gov. Greg Abbott shared that the state has granted BMS a $4.89 million Texas Enterprise Fund (TEF) grant for the project. TEF grants, administered by the Texas Economic Development & Tourism Office, support business relocation or expansion projects that create "new, good-paying jobs in the community and attract significant new capital investment to the state." The development is also a qualified project under the Texas Jobs, Energy, Technology, and Innovation (JETI) program.

“Texas is a global hub for life sciences, where today’s innovations shape the future of healthcare,” Abbott said in a news release. “This $2.3 billion investment by Bristol Myers Squibb in the dynamic biotech ecosystem in Houston is a testament to the depth of our skilled workforce and the pipeline of talent coming through our nation-leading technical colleges and research universities. With lower operating costs and easy access to markets across the U.S. and the world, Texas drives affordability for consumers.”

"Bristol Myers Squibb’s announcement is a tremendous win for Texas and the Houston region, further reinforcing our position as a premier destination for life sciences and advanced manufacturing,” added Greater Houston Partnership President and CEO Steve Kean.

Last fall, Eli Lilly and Co. selected Generation Park, a 4,300-acre, master-planned commercial district near Lake Houston, for its $6.5 billion manufacturing plant. More than 300 locations in the U.S. competed for the factory. Read more here.