Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Houston brain health co. secures $6.5M for rare disease study

neuro funding

Houston-based Goldenrod Therapeutics, part of Fannin Partners' portfolio, has announced the initial close of a $6.5 million series seed preferred stock round.

The round was led by Ataxia Ventures and an affiliate of Fannin, according to a news release.

Goldenrod Therapeutics plans to use the funding to support manufacturing, formulation optimization, IND-enabling studies and a Phase I study of its drug to treat brain inflammation, known as 11h.

The study will consider how 11h, which blocks the enzyme PDE4, could treat Friedreich’s ataxia (FA), a rare genetic disease that affects movement, speech and balance. To date, other PDE4 inhibitors have proven to regulate neuroinflammation and neuronal signaling, but have had adverse gastrointestinal side effects or have not reached enough of the central nervous system, according to Goldenrod.

The company says its 11h is expected to have "broad applicability" with limited emetric side effects.

“Our 11h program is a next-generation, orally bioavailable, brain-penetrant PDE4 inhibitor, where researchers overcame longstanding limitations associated with earlier PDE4 inhibitors," Dr. Dev Chatterjee, CEO of Goldenrod, said in the news release. "We believe this creates the potential for a best-in-class therapy for Friedreich’s Ataxia and a potential foundation for development across multiple neurodegenerative and neuroinflammatory disorders.”

11h was first developed at the University of Nebraska Medical Center (UNeMed). Houston-based Fannin Partners in-licensed the product 2020 and landed SBIR Phase I funding to support its initial development for opioid use disorder soon after.

Goldenrod has also received funding to study 11h's effectiveness for multiple sclerosis, methamphetamine addiction and cocaine addiction.

Goldenrod says it is developing 11h to target a variety of neurological and inflammatory conditions, including Alzheimer's disease, multiple sclerosis, ALS, substance use disorders, Batten disease, pain and traumatic brain injury.

27 Houston companies make Fortune 500 for 2026, led by energy giants

Houston HQs

Editor's note: This article has been updated to correct the number of companies based in the Dallas-Fort Worth area.

Houston is a giant among U.S. hubs for corporate headquarters.

The 2026 Fortune 500 lists 27 companies based in the Houston area, with many energy companies claiming top spots. Houston ties with Chicago for the second-most Fortune 500 headquarters, preceded only by New York City (53). Dallas-Fort Worth is home to 24 Fortune 500 headquarters.

Texas leads the nation for Fortune 500 headquarters (57), with California in the No. 2 spot and New York at No. 3.

“Texas is the undisputed headquarters of headquarters,” Gov. Greg Abbott said in a news release. “The world’s leading businesses invest with confidence in Texas because of our welcoming business climate, predictable regulatory environment, and skilled and growing workforce. People and businesses are choosing Texas because Texas works.”

The 2026 Fortune 500 ranks the largest U.S. corporations based on revenue in fiscal year 2025.

Here’s a rundown of the 27 Fortune 500 companies based in the Houston area.

  • No. 9 ExxonMobil
  • No. 21 Chevron
  • No. 29 Phillips 66
  • No.55 Sysco
  • No. 75 ConocoPhillips
  • No. 89 Enterprise Products Partners
  • No. 103 Plains GP Holdings
  • No. 133 Hewlett Packard Enterprise
  • No. 149 NRG Energy
  • No. 157 Quanta Services
  • No. 164 Baker Hughes
  • No. 173 Occidental Petroleum
  • No. 179 Waste Management
  • No. 201 EOG Resources
  • No. 204 Group 1 Automotive
  • No. 207 Halliburton
  • No. 223 Cheniere Energy
  • No. 236 Corebridge Financial
  • No. 262 Targa Resources
  • No. 266 Kinder Morgan
  • No. 388 Westlake
  • No. 435 CenterPoint Energy
  • No. 438 APA
  • No. 440 Comfort Systems USA
  • No. 455 NOV
  • No. 488 KBR
  • No. 496 Coterra Energy. Oklahoma City, Oklahoma-based Devon Energy and Houston-based Coterra Energy merged in early May, with the combined company retaining the Devon Energy name and the Houston headquarters.

The Greater Houston Partnership notes the Houston area soon will welcome its 28th Fortune 500 company. Expand Energy (formerly Chesapeake Energy), appearing at No. 362 on the 2026 list, says it’s moving its headquarters from Oklahoma City to Spring this year.

As the natural gas producer prepares to relocate to Texas, it’s hunting for a new leader. Nick Dell’Osso stepped down as president and CEO earlier this year. Board Chairman Michael Wichterich is interim president and CEO.

Dell’Osso became president and CEO of Oklahoma City-based Gulfport Energy effective May 28.

---

This article first appeared on EnergyCapitalHTX.com.