Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Who are Houston's top innovators? Nominate now for 2026 Houston Innovation Awards

Calling All Innovators

Calling all Houston innovators: The 2026 Houston Innovation Awards, presented by InnovationMap, return this fall to celebrate the best and brightest in the Houston innovation ecosystem right now.

We're asking you to nominate Houston's top innovators and startups for this year's awards. Nominations are open now through August 27 and can be made on behalf of yourself, your organization, and other influential leaders in the local innovation scene.

The annual awards program recognizes the most innovative individuals and companies in Houston across 10 prestigious categories.

This year's awards will honor the following categories:

  • Minority-founded Business, honoring an innovative startup founded or co-founded by BIPOC or LGBTQ+ representation.
  • Female-founded Business, honoring an innovative startup founded or co-founded by a woman.
  • Energy Transition Business, honoring an innovative startup providing a solution within renewables, climatetech, clean energy, alternative materials, circular economy, and beyond.
  • Health Tech Business, honoring an innovative startup within the health and medical technology sectors.
  • Deep Tech Business, honoring an innovative startup providing technology solutions based on substantial scientific or engineering challenges, including those in the AI, robotics, and space sectors.
  • Startup of the Year (People's Choice), honoring a startup celebrating a recent milestone or success. The winner will be selected by the community via an interactive voting experience.
  • Scaleup of the Year, honoring an innovative later-stage startup that's recently reached a significant milestone in company growth.
  • Incubator/Accelerator of the Year, honoring a local incubator or accelerator that is championing and fueling the growth of Houston startups.
  • Mentor of the Year, honoring an individual who dedicates their time and expertise to guide and support budding entrepreneurs.
  • Trailblazer, honoring an innovator who's made a lasting impact on the Houston innovation community.

You have three weeks to submit nominees, so don't delay — nominate today at this link or fill out the form below. Qualified nominees will receive a formal application to complete, which will be reviewed by our esteemed panel of judges to determine the finalists and winners.

More announcements about the 2026 Houston Innovation Awards are coming soon, including an introduction to this year's panel of judges. Interested in sponsoring the 2026 Houston Innovation Awards? Please contact sales@innovationmap.com.

KBR unveils name, branding for new government services spinoff

new identity

Houston-based KBR Inc.'s new Mission Technology Solutions unit officially has a name.

The previously announced government services spinoff, which until now has been nicknamed SpinCo, will now be known as Trinzic. The company said in a news release that the name was inspired by the word intrinsic, "reflecting essential, built-in capabilities and deep expertise operating in some of the world’s most complex and mission-critical environments."

New York-based firm Siegel + Gale developed the company's new brand. In addition to the new name, the company shares that its new logo will feature a stylized letter N, with brand colors in orange and gray.

“Trinzic represents who KBR Mission Tech has always been at our core: an essential partner bringing innovation and trusted execution to the missions that matter most,” Stuart Bradie, KBR President and CEO, said in the release. “The new Trinzic brand represents both our strong heritage and the tremendous opportunity ahead. Our teams aim to deliver solutions that address some of the world’s most critical national priorities every day, and this new identity captures the purpose-driven culture and mission focus that we expect to continue to define the company moving forward.”

KBR expects the spin-off to be completed in January 2027. At that time, Trinzic will operate as an independent, publicly traded company that will focus on technology and engineering services for the space and national security sectors.

KBR will remain a separate publicly traded company that will focus on sustainable technology and services to support the energy transition. KBR first announced the spinoff plans in October 2025.

Last month, KBR announced two C-suite hires for Trinzic, or what was then known as SpinCo.

Michael LaRouche will serve as Trinzic's inaugural president and CEO. LaRouche is currently CEO of Serco North America, a Virginia-based government services contractor. Nicholas Veasey, current CFO of Virginia-based MAG Aerospace, was named Trinzic's CFO. Bradie will remain chairman, president and CEO of KBR.

Rice lands $19 million grant to build AI-driven quantum materials lab

Quantum Boost

Rice University has received a $19.9 million award from the National Science Foundation to increase the production of quantum and electronic materials by using a combination of artificial intelligence, cloud-based labs and robotics.

The four-year project will create a remote and automated research platform that aims to accelerate discovery and the testing process, according to Rice. The aptly titled project, "Revolutionizing AI-Driven Autonomous Experimentation for Next-Generation Semiconductor Synthesis” (READINESS), will be led by Rice materials scientist Jun Lou, who serves as principal investigator. SUNY Polytechnic Institute and the University of Texas at Austin will collaborate with Rice on the project.

At first, READINESS will focus on two-dimensional materials, oxide semiconductors and diamond thin films that can support emerging technologies, like quantum devices.

READINESS is one of 20 projects selected for the NSF's Programmable Cloud Laboratories Test Bed initiative, which aims to provide more U.S. researchers with access to automated scientific tools.

Additionally, the project aligns with the Department of Energy’s Genesis Mission, which recently selected four projects from Houston universities and companies, including two from Rice. The national initiative aims to unite government, industry, academia and philanthropy to lead to breakthroughs in energy, scientific discovery and national security.

READINESS will offer more advanced lab systems remotely via a cloud interface to assist startups, other research groups, and companies that don’t have the resources, staffing or equipment to produce quantum materials and advanced electronics. READINESS will also allow researchers to simulate experiments via virtual experiments or digital twins before they conduct the physical experiment.

Rice says this will be particularly useful in quantum materials research, which is often met with barriers— like the adjustments of chemical composition, gas flow, pressure, and temperature—that can change the properties of a material.

“This project will give researchers access to capabilities that have traditionally been available only in a handful of laboratories,” David Sholl, executive vice president for research at Rice, said in a news release. “By lowering those barriers, READINESS can accelerate discovery and expand who can participate in cutting-edge materials research.”

Additionally, the project’s AI aspect will offer recommendations for new tests, recognize safety limits and analyze results to assist researchers.

“Responsible AI should complement researchers’ capabilities rather than replace their judgment,” Luay Nakhleh, Dean of Rice’s George R. Brown School of Engineering and Computing, added in the release. “READINESS embodies this principle by combining automated systems with transparency, safeguards and human oversight at critical decision points.”

READINESS’ lab will be based out of Rice’s Ralph S. O’Connor Building for Engineering and Science. Partner sites will also contribute equipment, expertise and workforce development programs, according to Rice.

Ultimately, READINESS aims to elevate the speed, reliability and reproducibility of experiments, and to promote access to automated scientific tools for U.S. researchers.

“Our goal is to create a laboratory that researchers from across the country can use to produce advanced electronic and quantum materials on demand,” Lou added in the release. “By integrating robotics, AI and digital twins, we aim to learn from every experiment and shorten the pathway from scientific discovery to practical technology.”