Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

7+ can't-miss Houston business and innovation events in June 2026

where to be

Editor's note: The FIFA World Cup comes to Houston this month, joined by major energy conferences and a lineup of fan-favorite, recurring events. Here’s what not to miss and how to register. Please note: this article may be updated to add more events.


June 1-4 — CLEANPOWER 2026 Conference and Exhibition

CLEANPOWER unites policymakers, experts, and corporate leaders to solve the challenges that none can solve alone. This must-attend, four-day conference is packed with cutting-edge discussions about wind, solar, storage, and transmission; dealmaking; networking; and fun.

This event begins June 1 at the George R. Brown Convention Center. Register here.

June 2 — Humans of Healthcare

Houston Methodist Center for Innovation will present its quarterly speaker series, Humans of Healthcare. The series will feature a panel of experts who will share about their career paths and discuss the nuances of the health care industry. This month's session will focus on today’s nursing landscape, the industry’s expectations of nurses and what career paths are possible in the field.

The event is Tuesday, June 2, from 5-6:30 p.m. at the Ion. Register here.

June 9 — Greentown Go Make Kickoff

Head to the Ion to celebrate the Greentown Go Make 2026 cohort. The open-innovation program with Shell Catalysts & Technologies and Technip Energies focuses on catalytic solutions for industrial decarbonization and the energy transition. Hear pitches from the founders and network with a select group of startups while enjoying food and drink.

This event is Tuesday, June 9, from 5:30-8 p.m. Register here.

June 9-10 — Texas Brain Economy Summit

The Center for Houston’s Future and UTMB are bringing the Texas Brain Economy Summit back to Houston this summer to continue to position the region as a global leader in brain health. Expect to hear from leaders of global institutions, including the World Economic Forum, U.S. Chamber of Commerce, McKinsey Health Institute, Global Brain Economy Initiative, Davos Alzheimer’s Collaborative, Business Collaborative for Brain Health (UsAgainstAlzheimer’s), Rice University, Memorial Hermann, MD Anderson and many others. Read InnovationMap's full preview of the event here.

This event begins Tuesday, June 9. Purchase tickets here.

June 10 — MIT Future of Healthcare Technology Forum

The MIT Club of South Texas will host an in-person forum to explore how innovation, government and policy are changing the healthcare industry. The event will feature MIT alumni and Houston healthcare leaders, including Dr. Tim Boone, dean of the Texas A&M School of Engineering Medicine; Cynthia Reinhart-King, chair of bioengineering at Rice University; Dr. Tony Lin, CEO and chairman emeritus of Kelsey-Seybold Clinic; and others.

This event is Wednesday, June 10, from 5:15-8:30 p.m. at the TAMU EnMed Building. Register here.

June 11 — Goals & Gigawatts: Houston Energy & Climate Week The Power of & Kickoff Party

Come watch the Mexico City FIFA opening match while celebrating energy and innovation at the Goals & Gigawatts Kickoff Party. The event will feature food, drinks, and a showcase on Houston Energy & Climate Week. Learn what to expect and how to get involved in HECW before closing the night with a DJ and karaoke.

This event is Thursday, June 11, from 1:30-6:30 p.m. Find more information here.

June 16-17 — Energy Projects Conference & Expo

The Energy Projects Conference & Expo (EPC Show) is the largest event in North America for professionals working at the heart of major energy projects. The essential event for engineering, construction, commissioning, operations and maintenance across multiple energy sectors brings together five leading conferences under one roof. Conference subjects span LNG exporting, hydrogen and ammonia, midstream, petrochem and refining, and sustainable aviation fuels.

This event begins June 16 at George R. Brown Convention Center. Register here.

June 25 – NASA Tech Talk

Every fourth Thursday of the month, NASA experts, including longtime engineer Montgomery Goforth, present on technology development challenges NASA’s Johnson Space Center and the larger aerospace community are facing, and how they can be leveraged by Houston’s innovation community. Stick around after for drinks and networking at Second Draught.

This event is Thursday, June 25, from 6-7 p.m. at the Ion. Register here.

Houston researchers report promising first in-human trial for implantable cancer therapy

cancer breakthrough

When it comes to cancer remedies, the treatment can be as challenging for the body as its cause. But what if immunotherapy could be localized? That’s precisely what a Houston team may soon make a reality.

Rice University researchers, in partnership with MD Anderson Cancer Center, recently published their findings from the first in-human trial of an implantable cancer-fighting treatment in the journal Clinical Cancer Research. The paper details testing of AVB-001, encapsulated cells engineered to release interleukin-2 (IL-2)—a naturally occurring signaling protein that boosts immunity—in the peritoneal cavities of 14 patients. The goal is to avoid the toxicity usually experienced with less targeted treatments, as well as find a solution to IL-2s’ abbreviated half-lives.

“Traditional IL-2 therapy has shown potent antitumor activity, but its clinical use has been limited by severe side effects and delivery challenges,” Omid Veiseh, director of the Rice Biotech Launch Pad, professor of bioengineering at Rice and a senior author on the study, said in a press release. “This platform allows us to localize and sustain cytokine exposure directly where tumors reside while minimizing systemic toxicity.”

Serous ovarian carcinoma is especially well-suited to the use of AVB-001 because it tends to spread throughout the abdomen. After a minimally invasive laparoscopic procedure, patients implanted with the cells were noted to tolerate the treatment well. Half of the enrolled patients’ cancer was stabilized, with several among them reporting extended signs of benefit. No maximum tolerated dose was reached and there were no life-threatening events tied to the study.

If that sounds like less-than-earth-shaking results, this is only the beginning. The capsules were implanted for about one week because IL-2 activity drops off after that. The researchers now know that further testing should include either higher levels, repeated doses, or a combination thereof, in order to create stronger advances.

The team has already made early headway on this next step. Preclinical studies in nonhuman primates were not only tolerated well, but without added toxicity, the apes had consistent pharmacological effects.

“This is a foundational step,” Veiseh explained. “We now have evidence that the platform is safe, biologically active and potentially scalable. The next phase is optimizing dosing and exploring combination therapies to unlock its full clinical potential.”

The combination would also include a checkpoint inhibitor, which might improve AVB-001’s tumor-fighting power. “What is exciting is that we are not just delivering a drug, we are programming a microenvironment,” added Dr. Amir Jazaeri, professor of gynecologic oncology at MD Anderson, member of the Rice Biotech Launch Pad’s clinical advisory board and a senior author on the study. “This opens the door to combination strategies that could amplify immune responses in ways that have not been feasible before.”