Texas Vertical Intelligence

One entry point.
Eight Texas sectors.

Choose the operating environment you need to protect. Each vertical hub connects the landing page, live threat intelligence, and the gated PDF brief built for that sector.

Published TX Verticals

Find your sector.
Follow the full funnel.

Start with the security page, read the latest CoreRecon analysis, or request the gated brief for a deeper operating-environment assessment.

Utilities

TX Utilities Cybersecurity 2026

Texas multi-utility operators (gas + electric + water combined MUDs, special utility districts, gas LDCs, multi-utility OES firms) face NERC CIP-002 through CIP-014 (CIP-008 IR plan tri-clock + CIP-014 physical security + CIP-013 supply-chain), AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan on 5-yr cycle, TSA SD-Pipeline-2021-01D (top 100+ gas LDCs + LNG), 49 CFR Part 192/195 (gas distribution + transmission), EPA RRAN-aligned RRA/ERP, AWWA G430/J100/DWFR, RRC 16 TAC §3.70 pipeline damage prevention, TX PUC Substantive Rule §25.367 (96-hr electric cyber-incident clock to PUCT — concurrent with CIRCIA 72-hr for NERC-registered entities), TDPSA §541 (utility customer billing + usage data enumeration), Volt Typhoon IT/OT pre-positioning in U.S. energy + water since 2021 (CISA/NSA AA24-038A), Muleshoe TX water-tank overflow (Jan 2024, CyberArmyofRussia/Unitronics PLC), Halliburton TX $35M RansomHub (Aug 2024), Brazos Electric $2.1B Ch.11 (2021 aftermath), City of Dumas TX SCADA ransomware (Nov 2024). Shared-MSP / vendor-IT / AMI headend / SCADA recloser / GIS / customer-portal BEC attack surface. CoreRecon tri-clock parallel-narrative SOC deliverable at $89–$129/endpoint + $2,500+/mo Command tier with AWIA RRA/ERP authorship + CIP-014 audit support + CIP-013 supply-chain plan + TDPSA enumeration coverage. SDVOSB-certified, 30-min CIP-008 SLA, TX-resident analysts, federal-grant procurement eligible (DWSRF/BRIC/RUS/DOE OE-000).

96-hr + 72-hr
TX PUC §25.367 + CIRCIA concurrent clocks — TX electric utility tri-narrative reports in parallel after every CIP-008 IR event
UtilitiesNERC CIPAWIA
Dental Practices

TX Dental-TX Cybersecurity 2026

V54 Dental-TX anchor brief: MCNA Dental 8.9M records (TX Medicaid/CHIP dental administrator, 2023). Henry Schein BlackCat/ALPHV supply-chain (2023) — 1M+ records across Dentrix customer network, including TX practices. Change Healthcare 192M (Feb 2024). West Texas Oral Facial Surgery INC Ransom (Jun 2025). Pecan Tree Dental Grand Prairie TX — Sinobi variant confirmed Jan 2026. Professional Dental Alliance 170K+ via vendor phishing. Texas dental practices & DSOs face HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record-retention four-layer compliance. DMS-attack surface: Dentrix / Eaglesoft / Open Dental / Curve Dental PMS credential paths, DSO multi-location shared-AD exposure, Weave / Demandforce patient-comms SaaS hijacking, DEXIS Imaging / Patterson file-server ACL gaps. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V54 launch framing and the V54 Dental-TX gated-PDF CTA at /resources/threat-briefs/dental-practices.

8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
DentalRansomwareHIPAA
Senior Living

TX Senior-Living-TX Cybersecurity 2026

V55 Senior-Living-TX anchor brief: Avamere Group 380,000+ records (ALPHV/BlackCat, 2023–2024, multi-state senior-living & SNF operator). Prospect Medical Holdings 1.3M records (Rhysida, 2023 — Texas-affiliated senior-care operations). Deer Oaks TX verified $225K ransom (2024, family-portal BEC pattern). Texas HHSC Medicaid breach (TX state-agency exposure path, 2024). Acuity Health 2.5M senior-care EHR supply-chain exposure (2024). Lifepoint Health TX senior-care multi-state breach (2024). Texas assisted-living facilities (ALFs), memory-care operators, and skilled-nursing facility (SNF) groups face five-layer compliance: HIPAA Security Rule + TX HSC §242 + TX HSC §247 (HHSC) + CMS Conditions of Participation (42 CFR §483) + TDPSA §541. Attack surface: MatrixCare / PointClickCare / American HealthTech credential paths, multi-facility shared-EHR-tenant segmentation gaps, family-portal BEC, MDS 3.0 eHR submission chain (CMS QIES ASAP), RUG score manipulation Medicare PDPM integrity, memory-care medication-management IoT devices. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V55 launch framing and the V36 Senior-Living gated-PDF CTA at /resources/threat-briefs/senior-living.

380K records
Avamere Group — 380K records ALPHV/BlackCat (2023–2024, largest senior-living breach in U.S. history)
Senior LivingRansomwareHIPAA
Municipalities

TX Municipalities — CJIS v6.0 & SCADA

V56 Municipalities-TX anchor brief: City of Dallas Royal ransomware ($8.5M cost-recover, 2023 — CJI exposure triggering FBI notification). City of Mission / Borger / San Angelo Q4 2025 coordinated wave. Borger TX REvil-affiliate (2025, public works + utility systems). 22 municipalities hit by coordinated Q4 2025 ransomware campaign (collective $2.5M demand). Akbar 911-PSAP ransomware precedent (county 911 ComEx / CAD encryption). Muleshoe TX Unitronics PLC utility SCADA overflow (Jan 2024) re-applicable — most TX cities also run their own water/wastewater SCADA. Full four-track compliance pinch: FBI CJIS Security Policy v6.0 (auditing live Oct 2025; LEA audit enforcement Oct 1, 2027 deadline; 13 policy areas) + Tex. Gov't Code Ch. 552 (Texas Public Information Act breach liability + §552.136 PII exception) + Texas Business & Commerce Code §521.053 (TDPSA breach notification, 60-day clock) + federal CIRCIA 72-hr CISA reporting (where utility SCADA in scope). Attack surface: CJI admin plane (RMS/CAD/NCIC/III terminals), 911 CAD egress, city water/wastewater SCADA (DNP3/Modbus/Unitronics PLC), public-records-portal credential stuffing, citizen-payment BEC (utility billing / municipal court fines), SaaS scheduling platforms (the Mission TX 2025 vector). CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident analysts, CJIS-mapped SOC + offline CJI continuity playbook + TxDIR cooperative contracting posture. CTA at /v/municipalities-tx landing page.

22 municipalities
hit by coordinated Q4 2025 ransomware wave — CJIS v6.0 auditing live Oct 2025
MunicipalitiesCJISRansomware
Defense Contractors

TX Defense Contractors — ITAR & CMMC

Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since 2021 — Texas hosts the #2 US DIB and ~3,000 active TX defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026. TX DIB ITAR §120–130 shop-floor angle: ITAR-tagged geometry on Solidworks / AutoCAD / Siemens NX / CATIA / Pro-E file servers represents the most frequent Volt Typhoon collection target — cyber exfiltration treated as a 22 CFR §127 unauthorized-export predicate. DFARS 252.204-7012 72-hr DIBNet clock from discovery (not detection) runs in parallel with a DDTC voluntary disclosure. DFARS 252.204-7021 makes CMMC certification a condition of award. DFARS 252.204-7019/7020 SPRS scoring ≤110 with 3-year refresh; DFARS 252.204-7020 sub-tier flow-down attaches prime CMMC + 22 CFR §127 exposure to Tier 2/3 ITAR incidents. NIST SP 800-171 Rev 2 — 110 controls across 14 families. False Claims Act qui tam exposure under 31 USC §§3729–3733 on unencrypted CUI per recent DoD cyber-fraud enforcement actions ($1.2M–$70M+ settlement range, 15–30% relator share). SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, ITAR §120–130 DLP tagging on CAD/CAM file servers + DFARS 7012 72-hr disclosure workflow + DDTC voluntary disclosure workflow + sub-tier DFARS 7020 flow-down audit. CTA at /v/defense-contractors-tx landing page.

CMMC L2 Nov 2026
CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins — DoD will not award contracts if SPRS shows a gap
DefenseCMMCDFARS
Oil & Gas

TX Oil & Gas OT/ICS Cybersecurity 2026

V51 Oil-Gas-TX anchor brief: 935% YoY ransomware surge against oil & gas (Zscaler 2025). Halliburton TX $35M direct loss (RansomHub, Aug 2024 — SEC 8-K confirmed). Colonial Pipeline (Houston-origin) DarkSide attack — entire East Coast fuel shut down for the first time ever (May 2021). Newpark Resources Woodlands TX ransomware (Oct 2024). ENGlobal Corp Houston TX 6-week business outage (Nov 2024 – Jan 2025 SEC update). HSE/SCADA death-pile: Muleshoe TX Jan 2024 Unitronics PLC tank-overflow template applies 1:1 to pipeline SCADA valves; Hanna UT Pump Station TX PLC ransomware proof-point; Volt Typhoon IT/OT pre-positioning in U.S. energy targets (Dragos VOLTZITE tracking — 2024-2025). Downtime cost framing: Halliburton Aug 2024 invoice/PO processing offline = multi-million-dollar per-day crew & vendor idle cost. Regulatory stack: TSA SD-Pipeline-2021-01 series + TSA SD-02F (effective May 3, 2025) + SEC Item 1.05 4-business-day cyber-incident disclosure + CIRCIA 72-hr + TDPSA §541 + TCEQ air-permit + RRC 16 TAC §3.71. OT/IT convergence attack surface: Modbus / DNP3 / OPC-UA / EtherNet-IP engineering workstation exposure, cellular RTU/SCADA gateways (VOLTZITE vector), VPN-credential reuse (Colonial trigger), PI historian exfil, Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix vendor remote-access. CoreRecon SCADA-aware SOC at $89–$129/endpoint + $2,500+/mo Command tier with pre-authorized SCADA isolation playbook + 30-min IR SLA beating TSA 12-hr CISA clock + SD-02F Cybersecurity Implementation Plan authorship + OT-aware threat hunts. CTA at /v/oil-gas-tx landing page.

$35M loss
Halliburton — RansomHub ransomware, Aug 2024 (SEC 8-K Item 1.05 confirmed direct charges)
Oil & GasOT/ICSSCADA
Community Banks

TX Community Banks — FFIEC CAT Sunsetting

FFIEC CAT retired Aug 31, 2025 — replacement is FFIEC CAT → NIST CSF 2.0 mapping per FIL-21-2025. Heartland Tri-State Bank $47.1M CEO-fraud collapse (Jul 2023 — social engineering + wire-authority escalation = total bank failure). Evolve Bank $185M LockBit demand / 7.6M records exfiltrated (2024 – public 2025; correspondent-banking / Pathward-Kemba impact). Texas Capital Bank class action filed Jul 2026 — 86,067 Texans affected by May 2026 breach. GLBA 16 CFR 314.4 nine-element Safeguards Rule (effective Jun 9, 2023; Qualified Individual required) + FDIC 12 CFR Part 304 36-hour computer-security-incident notification (effective May 1, 2022) + Texas Department of Banking SB 1961 cyber-incident reporting (effective Sep 1, 2025) + TDPSA §541 (60-day breach notice + 30-day cure + $50K flex-cap) + NIST CSF 2.0 (FFIEC replacement per FIL-21-2025) + FFIEC IT Examination Handbook InTRAC / CyFER. Pathward-Kemba / Kemba-Pathward fourth-party custodian / capital-stack / correspondent-channel vendor risk (voluntary receivership + waiver-of-successor-liability precedent). CDC CAL IC3 24k co $7 total community-bank-SEC top. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, bank-aware 9-element GLBA artifact library + 36-hr FDIC notification workspace + correspondent-banking / core-processor / Pathward-Kemba fourth-party mapping + 14-day FFIEC-to-NIST CSF 2.0 posture delivery. V59 launch at /v/community-banks-tx → /verticals/tx-community-banks-tx.

$47.1M
Heartland Tri-State Bank CEO-fraud collapse — social engineering + wire-authority escalation = total bank failure
Community BanksFFIECGLBA
Law Firms

TX Law Firms — ABA 1.6(c) & IOLTA Wire Fraud

State Bar of TX hit by INC Ransom (Jan 2025) — 1.4M records. Orrick $8M OCR class-action settlement (2023). Mossing & Navarre Toledo ransomware. Bryan Cave Leighton Paisner CCG breach. ABA Model Rule 1.6(c) duty to make reasonable efforts + TX DR 1.05 + ABA Formal Opinion 483 (cyber incident response) + TDPSA §541 + IOLTA wire fraud kill chain (TX IOLTA §171.101–§171.203). Case management attack surface: Clio / MyCase / PracticePanther / iManage / NetDocuments credential paths. Ransomware targeting active case files, settlement escrow timing, and client trust accounts. 8 law-firm-specific controls. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC. CTA at /verticals/tx-law-firms-tx.

$8M settlement
Orrick Herrington — OCR class action settlement (2023), new professional-liability data-security standard
Law FirmsABA 1.6(c)IOLTA