Solutions / Texas coverage
Microsoft security consulting for Texas organisations, statewide.
Texas concentrates more distinct regulator overlays on Microsoft 365 than any other state: HIPAA and Texas HB 300 for healthcare, TAC 202 and DIR standards for state agencies, TSA and API 1164 for energy, CMMC for defense contractors, and NYDFS Part 500 for financial services with a New York touch. Identra works with Texas customers statewide to configure the tenant for the specific regulator or auditor in front of them.
- Service area
- Texas statewide (Austin, DFW, Houston, San Antonio, El Paso, Corpus Christi)
- Delivery mode
- Remote-first, on-site available
- License footprint
- M365 E3 / E5 / GCC / GCC High
- Delivery
- Fixed scope, fixed price
01 / What we configure
Five verticals covered statewide.
- 01
Healthcare (HIPAA + HB 300)
Texas healthcare organisations face HIPAA at the federal level and Texas HB 300 at the state level. HB 300 adds broader Covered Entity definition, biennial training obligation, and stricter breach notification. Identra configures both overlays on the same tenant.
HIPAATexas HB 300Biennial training - 02
State agencies (TAC 202 / DIR)
Texas state agencies and public higher-education institutions run Microsoft 365 in GCC or commercial cloud under Texas Administrative Code Title 1 Chapter 202 and DIR security control standards. Annual DIR security assessment support.
TAC 202DIR standardsAnnual assessment - 03
Energy (TSA SD-02, API 1164)
Texas is home to the largest concentration of upstream, midstream, and downstream energy operators in the US. Identra configures OT-adjacent workstation isolation, vendor Global Secure Access, and Sentinel workbooks for TSA SD-02 pipeline security compliance.
TSA SD-02API 1164OT boundary - 04
Defense contractors (CMMC Level 2)
Fort Worth and San Antonio host major defense manufacturing operations. Identra stands up CUI enclaves in GCC High and prepares tenants for CMMC Level 2 C3PAO assessment against NIST 800-171 Rev 3.
CMMC Level 2GCC HighNIST 800-171 - 05
Financial services (SOX, FFIEC, NYDFS)
Texas-headquartered financial services firms face SOX 404 IT General Controls, FFIEC IT Handbook, and (for NY-licensed firms) NYDFS Part 500. Identra configures PIM, Communications Compliance, and per-regulator evidence packs.
SOXFFIECNYDFS Part 500
02 / What it looks like
Three Texas engagements from different corners of the state.
Statewide coverage across different sectors and regulator overlays.
CIO at a San Antonio-based hospital system
Situation. Multi-hospital system with staff across three cities. HIPAA audit combined with HB 300 review scheduled for the next quarter. Existing tenant configuration inconsistent between hospitals following a recent merger.
Outcome. Unified HIPAA baseline applied across the merged tenant. HB 300 add-on evidence (training records, breach notification workflow) integrated with the base HIPAA evidence pack. Both audits closed with no material findings.
CISO at an El Paso-based state agency office
Situation. State agency office serving the border region. DIR annual security assessment approaching. Existing configuration inherited from a predecessor with no documented TAC 202 mapping.
Outcome. Tenant assessed against TAC 202 and DIR standards. Gaps closed in configuration. Evidence pack matched the DIR template. Annual assessment accepted on first submission.
IT Director at a Corpus Christi refining operator
Situation. Downstream refining operator with mixed OT and corporate Microsoft 365 environment. Cyber insurance renewal required demonstration of specific cybersecurity controls including MFA, EDR, and DLP.
Outcome. MFA rolled out on all privileged access via FIDO2 keys. Defender for Endpoint deployed on all corporate workstations. Purview DLP with custom sensitive-info types for process design files. Insurance renewal completed at improved rate.
03 / Frequently asked
What buyers ask first.
- Do you cover all of Texas or specific metros?
- Identra covers Texas statewide, remote-first. Most engagements are delivered fully remote regardless of customer location within the state. On-site presence is available for kickoff workshops, executive readouts, or complex walkthroughs and is scheduled based on customer preference rather than geography.
- What Texas-specific regulations should we know about?
- Beyond federal regulations, Texas-specific items to know: TAC Title 1 Chapter 202 (state agency information security), DIR security control standards (implementation guidance for TAC 202), Texas HB 300 (HIPAA add-on for healthcare), Texas Data Privacy and Security Act (2024, business-wide privacy law taking effect in phases), and Texas SB 8 (specific breach notification requirements). Identra scoping covers the applicable set for each customer.
- What is the Texas Data Privacy and Security Act?
- Texas SB 8 (2023) took effect 1 July 2024 and creates a general business privacy framework similar to Virginia CDPA and Colorado CPA. Businesses that process personal data of 100,000 or more Texas residents (or process personal data of 25,000+ where more than 50% of gross revenue comes from selling personal data) are in scope. Purview data classification and DLP configurations satisfying GDPR-style privacy also satisfy TDPSA.
- Do you provide managed services after implementation?
- Identra engagements are consultative: configure, document, hand over. We do not provide 24/7 managed detection or continuous SOC operations. Customers who need ongoing managed services typically pair Identra implementation with a Texas-local MSSP for ongoing operations. We can refer to trusted Texas-local MSSP partners.
- What is the typical Texas engagement size?
- Range depends on sector and regulator scope. Healthcare and state agency engagements run 10 to 16 weeks. Energy sector runs 12 to 18 weeks. CMMC Level 2 runs 16 to 24 weeks. Financial services runs 12 to 16 weeks. Fixed scope, fixed price, no hourly bill-outs.
04 / Related
Where this fits.
Location
Austin
Microsoft 365 security consulting in Austin, Texas.
Location
Round Rock
Hospitals, semiconductor suppliers and Williamson County employers.
Location
Cedar Park
CMMC Level 2 and CUI for the defence and aerospace corridor.
Location
Pflugerville
The SH 130 manufacturing and distribution corridor.
Location
Dallas / Fort Worth
Microsoft 365 security consulting across the DFW Metroplex.
Location
Houston
Microsoft 365 security consulting in Houston, Texas.