Briggs I.T. Services

Briggs I.T. Services Texas SMB Compliance & Cybersecurity for Law Firms, RIAs, CPA Firms and Tax Preparation Practices | The Woodlands, TX | CIS Controls Supporter

Attorneys — a quick word on AI, and it's not the warning you're expecting.The real risk isn't that the AI makes mistakes...
08/28/2026

Attorneys — a quick word on AI, and it's not the warning you're expecting.

The real risk isn't that the AI makes mistakes. Everyone knows it does. The risk is what happens in your head when it hands you something polished and confident.

NIST studies this. In its Generative AI Profile, risk 2.7 — Human-AI Configuration — describes how humans over-rely on G*I systems or may unjustifiably perceive G*I content to be of higher quality than that produced by other sources. NIST's term for it is automation bias: excessive deference to automated systems.

It's a well-documented human tendency, not a personal failing. A tool that's right most of the time trains you to stop checking — and that's exactly when it slips in a fabricated case cite or a subtly wrong statement of law, formatted so cleanly it looks verified. NIST notes automation bias can make the AI's other failure modes worse, confabulation among them.

For a lawyer, the fix is simple to state and easy to skip: the fluency of the output is not evidence of its accuracy. You verify AI work the same way you'd verify a new associate's — because your name goes on it, not the tool's.

And to be fair to the technology, NIST names the opposite error too: being so wary of AI you lose its genuine benefits. The goal is calibrated trust, not none.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

Tax preparers — if you have a WISP, here's a quick way to tell whether it's finished or just started.The IRS's WISP temp...
08/28/2026

Tax preparers — if you have a WISP, here's a quick way to tell whether it's finished or just started.

The IRS's WISP template, Publication 5708, walks you through it in steps. The early ones are scaffolding — define your objectives, name a coordinator, assess your risks, inventory your hardware. Important, but scaffolding.

Step V is where a WISP becomes real: "Document Safety Measures in place." The IRS describes it as the section that sets the policies and business procedures the firm undertakes to secure all the PII in its custody.

And it doesn't leave "policies" vague. It lists what to write down:

• Data collection and retention
• Data disclosure
• Network protection
• User access
• Electronic data exchange, Wi-Fi, and remote access
• Connected devices
• Reportable incidents

Plus a written Employee Code of Conduct.

Here's the test. Open your WISP and look for those policies, by name, actually written out. If they're there, you have a real plan. If your document sets up a coordinator and a risk assessment but never lists the actual policies, it stopped at Step IV — and Step V is the part that would matter most if anyone ever looked.

The template is free and it's specific. It tells you exactly what belongs in the plan.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

RIAs — Texas's cybersecurity safe harbor doesn't ask the same thing of every firm. It scales with your headcount, and 20...
08/28/2026

RIAs — Texas's cybersecurity safe harbor doesn't ask the same thing of every firm. It scales with your headcount, and 20 employees is the line that matters.

SB 2610 (now Chapter 542 of the Business & Commerce Code) gives firms a liability shield if they run a conforming cybersecurity program. What counts as "conforming" depends on your size — §542.004(a)(4) sets three tiers:

• Under 20 employees: simplified requirements — password policies and employee cybersecurity training
• 20 to 99 employees: moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1
• 100 to 249 employees: full conformance to a recognized framework

Here's the part worth planning around. Below 20, the statute describes the bar in plain terms you already understand — passwords, training. The moment you hit 20 employees, it names a specific outside standard, CIS IG1, as your Tier 2 requirement.

That's a real step up, and it doesn't announce itself. A growing advisory firm can cross 20 employees without anyone noticing that the safe-harbor bar just rose. If the shield matters to you — and for a firm holding client financial data, it should — the headcount that changes your obligation is worth watching.

The statute names the standard. Going and meeting it is the work.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

RIAs — your compliance manual probably says you'll "respond appropriately" to a security incident. The SEC rule wants mo...
08/27/2026

RIAs — your compliance manual probably says you'll "respond appropriately" to a security incident. The SEC rule wants more than that.

Regulation S-P applies to you: §248.30(d)(3) defines a covered institution to include any investment adviser registered with the Commission. And §248.30(a)(1) requires written policies and procedures to protect customer information.

The part people gloss over is §248.30(a)(3) — the response program. Your written policies have to include a program reasonably designed to detect, respond to, and recover from unauthorized access to customer information.

And the rule doesn't leave "recover" vague. The program must include procedures to:

• Assess the nature and scope of the incident, and identify which systems and what customer information may have been accessed
• Take appropriate steps to contain and control the incident to prevent further access
• Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed

Read that as a sequence you write down once, calmly, so that during an actual incident you're following a plan instead of guessing. A firm that has these three steps on paper recovers in a different league than one figuring them out live.

The rule is telling you the structure. The value is having it ready before you need it.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

Tax preparers — a breach is chaos, and "who am I supposed to notify?" is the question you don't want to be researching i...
08/27/2026

Tax preparers — a breach is chaos, and "who am I supposed to notify?" is the question you don't want to be researching in the moment.

IRS Publication 4557 has a short list for it. In the event of a breach, it says to consider notifying consumers, law enforcement, and businesses — and it spells out each one:

• Notify consumers if their information is subject to a breach that poses a significant risk of identity theft or related harm
• Notify law enforcement if the breach may involve criminal activity
• Notify the credit bureaus and other businesses that may be affected

Now the important nuance. The IRS frames these as things to "consider" — it's guidance, a checklist to work from, not a set of hard federal deadlines.

The binding part is one line down: "check to see if breach notification is required under applicable state law."

That's where the actual obligation lives. The IRS list tells you who to think about telling. Your state's breach-notification law tells you who you're required to tell, and how fast. For a Texas firm, that's a separate statute with a real deadline attached — worth knowing before you're counting days.

The IRS also suggests contacting the IRS and the states after a data loss, so they can help watch for fraudulent returns filed with the stolen information.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

Heads up to every Houston firm with cameras in the lobby and a phone on the desk.Ubiquiti — the company behind UniFi, th...
08/27/2026

Heads up to every Houston firm with cameras in the lobby and a phone on the desk.

Ubiquiti — the company behind UniFi, the network gear in a lot of small professional offices — published a security bulletin on August 26. It lists 22 issues. Three of them scored 10 out of 10, the highest there is, and Ubiquiti says each one could be used by someone with access to the network holding no credentials at all.

The three are the video camera application, the phone system application, and the gateway hardware itself — the Dream Machines, Cloud Keys, Cloud Gateways and recorders. Updates are available for all of them.

Here is the part worth sitting with. Nobody thinks of the camera box as a computer. It got installed, it works, and then it stops being anybody's job. Meanwhile it sits on the same network as your client files.

No firm has been reported as affected and we are not suggesting yours has been. This is simply the kind of thing that is easy to handle this week and awkward to explain later.

If you are not sure who looks after your network equipment, email [email protected] and we will help you find out. Our plain-English Texas compliance guide is at briggssocial.com/guide

Heads up to anyone at a Houston firm who has been pasting work into an AI assistant and then deleting the chat afterward...
08/27/2026

Heads up to anyone at a Houston firm who has been pasting work into an AI assistant and then deleting the chat afterward.

Anthropic updated Claude's memory this week. Two things in its own help documentation are worth knowing. First, Claude now saves memory as individual topics while you are still typing, rather than summarizing the conversation after it ends, and the same memory carries between Claude chat and Claude Cowork when Cowork runs in the cloud.

Second, and this is the one: when a conversation is deleted, the memory entries made from it are not removed. Deleting the chat and removing what was learned from it are two separate actions.

Anthropic describes what gets saved as your role, your projects and professional context, the people and places in your work and life, your working style, and ongoing project details. In a professional firm that reads as the client, the matter, and the people around it.

The plan side is backwards from what most people would guess. Memory is on by default on Free, Pro and Max — the individual seats a small firm tends to buy — and off by default on Team and Enterprise until an owner turns it on.

Nothing was breached here and no notification duty has been triggered. It is a default that was set for you, and it takes about ten minutes to look at: Settings, then Memory, then read what is listed under Topics.

If you would rather have this written down as one page your staff can follow instead of a policy nobody reads, email me at [email protected] — happy to help. The Texas Compliance Landscape guide is at https://briggssocial.com/guide if you want the wider picture first.

08/27/2026

Most Texas firms don't have a compliance problem. They have a which-rules-apply problem.

A twenty-attorney firm, an RIA with a dozen people, and a CPA practice that also prepares returns are answering to overlapping sets of obligations written by different regulators at different times, with no one coordinating them. Some reach you. Some don't. Knowing which is which is the first real piece of work.

So we wrote it down. The Texas Compliance Landscape is a plain-English reference to the eleven obligations most likely to reach a Texas legal, advisory, or tax firm - the FTC Safeguards Rule, IRS Pub 4557 and the WISP, IRC Section 7216, SEC Regulation S-P, Texas SB 2610 and its cybersecurity safe harbor, TITEPA breach notification, TRAIGA, the TDPSA, State Bar ethics rules, and the rules of the Texas State Securities Board and the Texas State Board of Public Accountancy.

Each one gets what it actually requires, who it reaches, and the clocks that start when something goes wrong. Where an exemption is likely to apply, it says so.

No form, no email gate. It's a PDF:
briggssocial.com/guide

[email protected] | 832-304-1850

For the RIAs — the NIST framework starts somewhere surprising. Not with a firewall. With your mission.NIST CSF 2.0 has s...
08/26/2026

For the RIAs — the NIST framework starts somewhere surprising. Not with a firewall. With your mission.

NIST CSF 2.0 has six functions, and the one it lists first is GOVERN — before PROTECT, before DETECT, before any actual control. Texas names the framework in its safe harbor statute, so how it's ordered is worth knowing.

The first subcategory under GOVERN is GV.OC-01: "The organizational mission is understood and informs cybersecurity risk management."

In plain terms: your security choices should come from what your firm exists to do.

For an advisory practice, that's the fiduciary duty — the client's interest comes first. And that duty is supposed to drive the security calls, not sit in a separate lane from them. When you're deciding whether a tool, a workflow, or a shortcut is acceptable, "is this consistent with our duty to the client whose money is involved?" is the question GV.OC-01 wants you asking first.

Here's why it matters for a small firm specifically. You don't have a governance department. You — the principal — are it. Which means the mission and the security decisions already live in the same head. GV.OC-01 is just asking you to connect them on purpose instead of by accident.

It costs nothing. It's a way of thinking, not a purchase.

Guide: briggssocial.com/guide
Or email [email protected]

https://briggssocial.com/guide

Address

The Woodlands, TX

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm

Telephone

+1 832-304-1850

Alerts

Be the first to know and let us send you an email when Briggs I.T. Services posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Briggs I.T. Services:

Shortcuts

Share