Compliance Resources

maps. Guides. Readiness.

Compliance decoded for Texas organizations — audit deadlines, policy area breakdowns, and remediation roadmaps. No fluff.

Available Guides
Most Popular Interactive Calculator · IBM 2024 · Verizon DBIR · FBI IC3
Breach Cost Calculator

Enter your industry, endpoint count, and record volume. Get an IBM 2024-benchmarked breach cost estimate (low/expected/high), Texas-specific penalty exposure (TDPSA $7,500/violation, HIPAA, CMMC contract loss), the 207-day dwell-time gap cost, and a side-by-side comparison: cost of one breach vs. 12 months of CoreRecon Fortress. Instant results. No demo required.

Calculate My Breach Exposure →
New Interactive Quiz · Texas Law · Tex. Bus. & Com. Code Ch. 541
Texas TDPSA Readiness Quiz 2026

21 questions. All major TDPSA obligations — consumer rights (access, correction, deletion, portability, opt-out), universal opt-out / GPC recognition (eff. Jan 1 2025), privacy notice contents, sensitive data consent, Data Protection Assessments, controller-processor contracts, data minimization, reasonable security, appeal process, and AG enforcement readiness. Industry selector for SaaS/tech, fintech, healthcare, marketing, retail/e-commerce. Email-gated 30/60/90 gap roadmap PDF.

Take the TDPSA Quiz →
New Interactive Quiz · FTC Safeguards Rule · 16 CFR Part 314
FTC Safeguards Rule Readiness Quiz 2026

20 questions. All 9 required elements — Qualified Individual, written risk assessment, MFA, data inventory, encryption, change management, continuous monitoring, secure disposal, service provider oversight, IR plan, board report, and 30-day breach notification. Industry selector for auto dealers, title companies, accounting firms, mortgage brokers. Email-gated gap roadmap PDF. Enforcement: Drizly, Chegg, CafePress, Cuachi.

Take the Quiz →
Live · Updates Every 60 Minutes NEW
Texas Threat Intelligence — Live Feed

CISA KEV catalog, ICS advisories, HC3 healthcare alerts, FBI IC3, MS-ISAC municipal intel — aggregated, TX-relevance scored, and refreshed automatically. The intelligence your SOC runs on, visible to you in real time.

View Live Feed →
Live Resource
Texas Breach Tracker 2023–2026

Every confirmed Texas cybersecurity incident — 25+ entries, CoreRecon technical analysis on each. Filter by sector, attack type, and threat actor. The intelligence asset journalists cite and buyers bookmark.

View Tracker →
⏱ Live Countdowns
Compliance Deadline Tracker 2026–2027

Every Texas-relevant cyber compliance deadline — CMMC, CJIS, TSA Pipeline, HB 300, NCUA, FFIEC, ABA Rule 1.6. Live countdowns, penalty exposure, and how CoreRecon closes each gap.

View Deadlines →
Healthcare Intelligence — June 2026
Texas Healthcare Cyber Threat Brief 2026

12 verified TX incidents, 207-day dwell, $9.8M avg cost. BlackCat, Qilin, Rhysida, INC Ransom profiles. HIPAA + TX HB 300 double-jeopardy analysis. 7 actionable recommendations.

Read the Brief →
New Oil & Gas Intelligence — June 2026
Texas Oil & Gas Cyber Threat Brief 2026

935% ransomware surge targeting TX O&G (Zscaler). 15 documented incidents, 5 threat actor profiles (VOLTZITE, RansomHub, BlackCat/ALPHV, CyberAv3ngers IRGC, Sandworm), 7-framework regulatory map (TSA SD02F, SEC Item 1.05, CIRCIA, NERC CIP, TX RRC, OSHA PSM), OT/ICS controls roadmap.

Read the Brief →
📊 Q4 2026 Report
Q4 2026 Texas Cyber Threat Brief

22 municipalities, 935% O&G surge, CJIS v6.0 deadline, CMMC L2 gate, 200+ legal incidents. Full sector-by-sector breakdown and MITRE ATT&CK mappings.

Download Brief →
Defense Intelligence — June 2026
Texas Defense Contractor Threat Brief 2026

10 verified DIB incidents. $23M+ FCA settlements. VOLT TYPHOON/APT40 MITRE ATT&CK profiles. CMMC Phase 2 countdown. InterConnect Wiring profile — F-16 wiring harness cascade risk.

Read the Brief →
New Agriculture Intelligence — June 2026
Texas Agriculture Cyber Threat Brief 2026

212 ransomware attacks on food/ag 2024. JBS Foods ($11M), Schreiber Foods ($2.5M), Dole ($10.5M). TDPSA + FSMA 204 + USDA cybersecurity mandates. 8 OT/ICS controls. 35+ verified sources. Email-gated PDF.

Download Brief →
PDF Brief Electric Cooperative Intelligence · NERC CIP + ERCOT + RUS · V37
TX Electric Cooperatives Cyber Threat Brief 2026

Brazos Electric $2.1B Chapter 11. DMEA Colorado billing offline 1+ month from cyberattack — ICS bricked. NERC CIP-003-9 vendor MFA enforcement live April 2026. ERCOT QSE credential compromise: simultaneous physical + financial risk. 8 co-op controls, 30/60/90 roadmap. 62 verified sources. Email-gated PDF.

Download Brief →
Vertical Page + PDF Brief Dental Healthcare Intelligence · HIPAA + TDPSA + TSBDE · V39
TX Dental Practices & DSOs — Cyber Threat Brief 2026

MCNA Dental (8.9M records, LockBit). Henry Schein BlackCat supply-chain (1M+). Change Healthcare 192M. West Texas Oral Facial Surgery (Lubbock, INC Ransom June 2025). Pecan Tree Dental (Grand Prairie, Sinobi Jan 2026). Central TX Pediatric Orthopedics (140K patients). 30K+ active TX dentists. Dentrix/Eaglesoft/Open Dental/Carestream/Dexis attack surface. HIPAA + TDPSA + TX HB 300 + TSBDE 22 TAC §108.7 four-layer compliance stack. 49 verified sources. Free assessment + gated PDF threat brief.

View Dental Practices Page →
Interactive Tool DFARS 252.204-7019/7020 · CMMC 2.0 Level 2 Gate · 110 Controls
SPRS Score Calculator — NIST SP 800-171 Self-Assessment

Score all 110 NIST 800-171 Rev 2 controls across 14 families. Live SPRS number, color-coded risk tier, prioritized 30/60/90-day gap roadmap, and DoD PIEE submission walkthrough. Free executive PDF report gated by email. Know your score before DoD does.

Calculate My SPRS Score →
Interactive Tool CJIS SP v6.0 · 13 Policy Areas · Oct 2027 Deadline · TX DPS Audits Active
CJIS v6.0 Audit Readiness Checklist

Select your gaps across all 13 CJIS policy areas. Get plain-language requirements, remediation steps, evidence checklists, effort estimates, and target dates. Export an auditor-ready PDF to hand your CSA before TX DPS arrives. Free, no demo, no sales call.

Build My Audit Checklist →
Critical Infrastructure · CISA AA24-038B
Volt Typhoon — Texas Infrastructure Threat Brief

China MSS Volt Typhoon pre-positioned inside TX energy, water, and pipeline OT since mid-2022. LOLBin evasion tradecraft evades every signature-based tool. Sabotage, not ransomware. Full actor profile, TX exposure, and defensive playbook.

Read the Brief →
New Tech Sector Intelligence — June 2026
Texas Tech Sector Cyber Threat Brief 2026

49M Dell records, 14 TX tech incidents, 4 threat actor profiles (Scattered Spider, LAPSUS$, IntelBroker, Volt Typhoon). SOC 2, FedRAMP, TX-RAMP, CMMC L2 compliance crosswalk. 6 tech-specific threat vectors. 24-item 30/60/90 hardening roadmap for Austin/Plano/Dallas/Houston tech.

Read the Brief →
New Municipal Intelligence — June 2026
Texas Municipalities Cyber Threat Brief 2026

22 TX municipalities hit in Q4 2025 coordinated wave. FBI CJIS v6.0 auditing active. 5 threat actor profiles (Royal, LockBit 3.0, BlackCat, REvil, Volt Typhoon). 13 CJIS policy area crosswalk. 21-item 30/60/90 hardening roadmap. $8.5M Dallas recovery cost documented.

Read the Brief →
New Defense Intelligence — June 2026
Texas Defense Contractors Cyber Threat Brief 2026

9 documented incidents. $26M+ FCA settlements. CMMC Phase 2: November 10, 2026. 4 threat actor profiles (APT41, Volt Typhoon, Lazarus, LockBit). 110-control SPRS breakdown. IBM breach cost analysis. SDVOSB flow-through competitive advantage for Texas primes.

Read the Brief →
Credit Union Intelligence — June 2026
2026 Texas Credit Union Cyber Threat Brief

NCUA Part 748 72-hr reporting, GLBA Safeguards 2023, FFIEC CAT 2.0 maturity model, 11-incident TX CU database (MeridianLink, Patelco, TX Dow, Energy Capital CU), and 3-tier coverage model for under-$1B CUs. FFIEC CAT maturity bands mapped to CoreRecon tiers.

Read the Brief →
New Legal Intelligence — June 2026
Texas Law Firms Cyber Threat Brief 2026

45 ransomware attacks on law firms in 2024 (record). $2.77B BEC losses, 12% attorney impersonation rate. 15 incident database, 5 actor profiles (ALPHV/BlackCat, LockBit, Cl0p, Silent Ransom Group, INC Ransom). ABA Rule 1.6(c) + TX TDRPC Rule 1.05 compliance crosswalk. Vendor supply chain risk (Clio/Cleo, DocketWise, iManage).

Read the Brief →
Manufacturing Intelligence — June 2026
Texas Manufacturing Cyber Threat Brief 2026

Manufacturing #1 most attacked sector globally (27.7% IBM X-Force 2026). $45K–$50K/hour ransomware downtime. CMMC L2 Nov 2026. Oracle Cloud Austin 140K tenant breach. OT/ICS risk, 9-incident TX database, 4 threat actor profiles.

Read the Brief →
Anchor Post 3,200 Words · 70 Citations · 8 Verticals · June 2026
State of Texas Cyber Threats 2026

The cross-vertical intelligence anchor: 207-day dwell time problem, three attack patterns, eight sector summaries, five-framework compliance overlay, and what 30-minute response means per vertical. The piece everything else links to.

Read the Anchor Post →
New Title & Escrow Intelligence — June 2026
Texas Title & Escrow Cyber Threat Brief 2026

Wire fraud losses surged to $275.1M in 2025 on 12,368 FBI complaints. BEC attack chain: credential theft → compromised email → wire fraud. First American Financial and Fidelity National Financial both hit in late 2024. ALTA Best Practices Pillar 3 compliance, TX Insurance Code Ch. 651, and 30-min SLA SOC coverage.

Read the Brief →
New K-12 Education Intelligence — June 2026
Texas K-12 School District Cyber Threat Brief 2026

PowerSchool breach (Dec 2024): millions of student records exfiltrated, follow-on attacks against TX districts now using stolen data. Canvas LMS breach (Jan 2025): 3.65TB, 8,000 institutions, TX universities during finals. TTUHSC 1.4M records via Interlock. FERPA, HB 18/SCOPE Act, CJIS v6.0, SB 820 compliance.

Read the Brief →
New Higher Education Intelligence — June 2026
Texas Higher Education Cyber Threat Brief 2026

35 verified sources. 207-day dwell analysis. TTUHSC 1.4M records. FERPA + GLBA Safeguards Rule + HIPAA + CMMC L2 + TX SB 820 + PCI DSS crosswalk. Nation-state research IP theft, FAFSA ghost student fraud, and BEC wire fraud vectors. 12-item 30/60/90 action plan.

Read the Brief →
New
Defense

CMMC L2 Nov 2026 Implementation Guide

Phase 2 is live. C3PAO third-party assessment now required. All 110 NIST 800-171 controls mapped by 14 domains with 90-day implementation roadmap and email-gated PDF checklist.

Now Available
Law Enforcement

CJIS v6.0 Compliance Guide

FBI CJIS v6.0 auditing is live. Full compliance deadline: October 1, 2027. Map all 13 CJIS security policy areas to your security posture.

Now Available
Defense

CMMC Level 2 Compliance Guide

CMMC Level 2 enforcement begins November 10, 2026. Defense contractors need Level 2 certification to win contracts above $10M.

Now Available
Healthcare

HIPAA Security Compliance Guide

Healthcare organizations handling PHI need HIPAA Security Rule compliance. OCR enforcement and breach notification requirements.