Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

UH lands $4M NIH grant to study early signs of autoimmune disease

NIH funding

The University of Houston recently received a $4 million National Institutes of Health grant to support a 10-year longitudinal study to identify the earliest biological markers of autoimmune disease.

Led by Chandra Mohan, the Hugh Roy and Lillie Cranz Cullen Endowed Professor of Biomedical Engineering, the study aims to examine what causes Systemic Autoimmune Rheumatic Diseases (SARDs) and to identify targets for future treatments. The study will be carried out in collaboration with Dr. Karen Costenbader at Harvard Medical School, Boston.

SARDs include conditions like rheumatoid arthritis, systemic lupus erythematosus, Sjögren’s syndrome and systemic sclerosis—all are considered chronic diseases currently without a cure. Autoimmune diseases affect over 30 million people globally, according to UH.

SARDs occur when the body’s immune system attacks healthy, non-threatening tissues and organs. According to UH, in these diseases, the body often attacks nuclear antigens, creating anti-nuclear autoantibodies, which can be early detection signs for SARDs in more than 50 percent of patients, Mohan says.

Researchers will study blood samples and environmental exposure over the 10 years to better understand anti-nuclear autoantibodies.

“Collectively, these studies will help identify the genetic, environmental and cellular factors that are operative at the two steps of SARD development, namely the emergence of anti-nuclear autoantibodies and disease onset,” Mohan said in a news release. “ More importantly, these studies will highlight functional molecular pathways and mechanisms that may be operative at each step."

Mohan predicts that looking at SARDs’ shared characteristics, rather than each disease individually, could help identify more treatment methods.

“Individual SARDs have been examined in silos without an attempt to discern shared underlying features at the molecular level,” he added in the release. “Current understanding of the initial (and likely shared) origins of SARDs is only rudimentary but urgently needed to develop means for prevention and treatment.”

Earlier this year, UH also received an $11 million NIH grant to conduct a first-of-its-kind study of early language development in children ages 18 to 24 months. Read more here.

New Texas Stock Exchange officially begins trading in Dallas

Welcome to Y'all Street

Two-step aside, New York Stock Exchange and Nasdaq. The Dallas-based Texas Stock Exchange, nicknamed Y’all Street, just kicked off live trading with five stocks — and lots of Lone Star ambition.

“The Texas Stock Exchange aims to revitalize competition for [stock] issuers, establish the premier venue for listings, and create a world-class trading platform for all market participants,” the exchange says in a fact sheet.

The exchange — whose Texas-influenced nickname is a nod to New York City’s Wall Street — has collected at least $275 million in investments. The roughly 90 financial backers of TXSE include Bank of America, BlackRock, Charles Schwab, Citadel Securities, Dell Family Office, Fortress, Goldman Sachs, and JPMorgan Chase.

Representatives of TXSE couldn’t be reached for comment. On its website, the exchange calls itself “the most well-capitalized equities exchange to ever be approved” by the U.S. Securities and Exchange Commission (SEC).

Not to be outdone, NYSE has launched Dallas-based NYSE Texas and Nasdaq has expanded its presence in Dallas.

Y’all Street adds to Dallas-Fort Worth’s rising status as a major hub for financial services, with The Wall Street Journal naming North Texas the country’s second biggest financial hub after New York City.

“A homegrown national exchange means more jobs, more investment, and more growth opportunities for businesses and communities across the Lone Star State,” Gabriela von zur Muehlen, senior vice president and chief policy officer at the Texas Association of Business, told The Texas Tribune.

Bulent Temel, an associate professor of practice in economics at the University of Texas at San Antonio, told Texas Standard that TXSE “is going to boost the credibility of the Texas economy.”

Texas’ estimated gross domestic product (GDP), a yardstick for the size of an economy, climbed to a record-setting $2.9 trillion in 2025, making it the state with the second highest GDP after California. DFW’s estimated GDP in 2023 stood at $744.6 billion, eclipsing the GDP of many countries.

“The center of gravity for American capitalism is now headquartered in the Boom Belt,” Abbott proclaimed in April, referring to an 11-state region (including Texas) in the South and Southeast that’s seeing tremendous economic and population growth. “The Texas Stock Exchange is the natural extension of that capitalism. It ensures that capital markets will reflect the quadrant that is driving American growth.”

---

This article originally appeared on CultureMap.com.

Orion vehicle manager reflects on Artemis II, looks to 2028 moon mission

Q&A

Humanity is finally headed back to the moon after more than half a century. This year's launch of the Artemis II mission in the Orion spacecraft put four crew members in lunar orbit and tested the new ship developed by Lockheed Martin.

Everything went smoothly, safely returning astronauts home, but there is always room to improve. InnovationMap chatted via email with Orion vehicle manager Branelle Rodriguez, shortly after a talk at The Ion, for insight on how Orion might perform in the future as the next lunar landing approaches in early 2028.

InnovationMap: How satisfied are you with the way Orion operated on this past mission?

Branelle Rodriguez: Orion performed exceptionally well during Artemis II, successfully demonstrating critical spacecraft capabilities, including life support systems, displays and controls, and executing manual piloting operations. Artemis II brought humans back to the moon, achieving key exploration and scientific imagery, while validating systems essential for future Artemis missions.

IM: What is the most important thing you learned about improving Orion for the next mission?

BR: The Artemis II mission provided invaluable insights into crew operations and spacecraft performance in a deep-space environment. With every mission, NASA applies lessons learned to continuously improve Orion’s operations, validate design and ensure mission readiness. Artemis II offered our first opportunity to evaluate several new systems and gain a deeper understanding of what it is like for astronauts to live and work inside the spacecraft. The operational, technical and human factors data collected are being integrated across the program to refine future missions, reduce risk and enhance overall mission success.

IM: How has Orion helped the mission to explore space?

BR: Orion is one of NASA’s foundational elements for human deep space exploration—not only supporting the mission but serving as a core component of it. It is currently the only spacecraft capable of carrying crew on deep space missions and returning them safely to Earth from the high speeds required from the vicinity of the moon. No other spacecraft has the technology to endure the extremes that come with human deep-space travel, such as advanced environmental and life support, navigation, communications, radiation shielding, and the world’s largest ablative heat shield to protect the astronauts during reentry into Earth’s atmosphere. Orion has already taken astronauts to explore space farther than ever before—252,756 miles from Earth— and will carry crews to the moon on future missions to explore the lunar South Pole region. The astronauts’ observations, samples, and data collected on these future missions will expand our understanding of our solar system and home planet.

---

This conversation has been edited for brevity and clarity.