CIS Controls IG1: A Plain-English Guide for Texas SMBs

A straightforward breakdown of CIS Controls IG1 for Texas companies with 20-99 employees, including why SB 2610 makes this list worth your attention now.
A Round Rock distributor, a lawsuit, and a list of 56 items
A manufacturer outside Round Rock got hit with a business email compromise last spring. Wire fraud, six figures, the whole mess. When the lawsuit came from a customer whose data got dragged into the breach, the first question from opposing counsel wasn't about firewalls or antivirus. It was: "What security controls did you have in place?" The company had a password policy and a firewall from 2016. That was it. That gap is exactly what CIS Controls IG1 is built to close, and it's also exactly what Texas law now cares about.
What CIS Controls IG1 actually is
The Center for Internet Security publishes a list of 18 control families, broken into three implementation groups based on how much resource a company has. IG1 is the entry tier — 56 specific safeguards considered the minimum baseline for any organization handling sensitive data. It's not theoretical. It's a checklist: encrypt laptops, log who accesses what, patch known vulnerabilities, train people to spot phishing, back up data in a way that survives ransomware. None of it requires a six-figure security budget or a dedicated security team.
If your company has somewhere between 20 and 99 employees, you're squarely in the group CIS designed IG1 for. You've got enough data and enough attack surface to be a real target, but you probably don't have in-house security staff reviewing SIEM alerts all day. IG1 assumes that and scopes accordingly.
The safeguards that actually move the needle
Not every item on the list carries equal weight. A few categories do most of the work:
- Asset and software inventory — you can't protect what you don't know you have. Half the companies we walk into don't have an accurate list of devices touching their network.
- Access control management — who has admin rights, and why. This ties directly into privileged access management, which is where a lot of breaches actually start.
- Secure configuration — turning off default settings, disabling unused services, enforcing multi-factor authentication everywhere it's available.
- Data recovery — backups that are tested, isolated from the production network, and actually restorable. Not just "we have backups" but "we ran a restore test last quarter."
- Security awareness training — teaching staff to recognize the phishing email before it becomes the wire fraud call.
Credential abuse shows up in some form in 39% of breaches, according to the Verizon 2026 DBIR, which is why the access control and MFA pieces of IG1 matter more than most of the flashier controls further down the list.
Why this isn't just a nice-to-do anymore
Texas SB 2610, effective September 1, 2025, gives companies with 20 to 99 employees a real legal incentive here. If you implement CIS Controls IG1 — all 56 safeguards — you're shielded from exemplary damages in a data breach lawsuit. It doesn't create a new way for someone to sue you, and it doesn't block compensatory damages, but it caps the punitive exposure that tends to be the scariest number in these cases. Source: Texas SB 2610 (as of 2026-08-20).
That's a meaningful shift. Most compliance frameworks ask you to spend money with no direct legal payoff. This one has a specific, named benefit attached to a specific, named list of controls. If you're already working toward HIPAA or the FTC Safeguards Rule, a lot of IG1 overlaps with what you're already doing — it's not a separate project bolted onto your existing compliance work.
What skipping this actually costs
The math on doing nothing isn't abstract anymore. Median ransomware recovery cost, not counting any ransom paid, sits at $375,000, with the mean pulled up to $1.7M by a handful of catastrophic cases. Source: Sophos State of Ransomware 2026 (as of 2026-08-20). Paying the ransom doesn't even get you out of that cost — 69% of victims didn't pay at all, up from 65% the year before, and still had to cover remediation. Same source.
On the patching side, the median time to fully remediate a known-exploited vulnerability sits at 43 days from detection, up from 32 the previous year, per the Verizon 2026 DBIR (Fig. 13). IG1's vulnerability management safeguards exist specifically to shrink that window, because attackers aren't waiting six weeks to use a public exploit.
How a 20-99 person company actually implements this
You don't need to hire a CISO. Most companies this size handle IG1 through a combination of internal process changes and outsourced technical execution. The practical path looks like this:
- Run an honest gap assessment against the 56 safeguards — not a vendor pitch disguised as an assessment, an actual gap list.
- Fix the cheap, high-impact items first: MFA everywhere, admin account cleanup, backup testing.
- Bring in continuous monitoring for the stuff humans can't watch all day — endpoint detection, log review, alerting.
- Document what you did. SB 2610's protection depends on being able to show the controls were implemented, not just that you meant to.
This is the kind of work a managed IT services partner handles as part of normal operations rather than a one-time project. If your current provider has never mentioned CIS Controls or SB 2610 to you, that's worth a conversation — our guide on switching IT providers walks through how to evaluate whether it's time to make a change. Companies working with a cybersecurity partner already covering network segmentation, cloud configuration review through cloud services, and network infrastructure hardening are usually most of the way to IG1 without realizing it.
Frequently Asked Questions
Does IG1 apply even if my company isn't in a regulated industry like healthcare or finance?
Yes. IG1 isn't tied to HIPAA or financial regulation specifically. It's a general baseline, and SB 2610's protection applies to any Texas company in the 20-99 employee range, regardless of industry.
How long does it take a company our size to get through all 56 safeguards?
It varies with how much existing infrastructure you have, but most companies see the bulk of the gap closed within a few months when the work is prioritized correctly — high-impact items like MFA and backup testing first, documentation and policy work running in parallel.
Does Microsoft 365 Copilot create new security risk under IG1?
Copilot only surfaces files and data a user already has at least view permission to — it exposes existing oversharing rather than creating new exposure. Source: Microsoft Learn (as of 2026-08-20). That said, IG1's access control safeguards are exactly what prevents that oversharing from existing in the first place, which is part of what we review when setting up Microsoft 365 managed services.
Can I implement IG1 myself without an outside vendor?
Technically yes, if you have staff with the bandwidth and expertise. In practice, most companies this size don't have anyone whose full-time job is security, so the documentation and ongoing monitoring pieces tend to slip. That's the part most often outsourced.
If you want to know exactly where your company stands against these 56 safeguards, start with a free IT assessment or contact our team to talk through what SB 2610 means for your specific risk exposure.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.


