An official website of the State of Texas
Cybersecurity Transition: House Bill 150 (89R) transferred Department of Information Resource's (DIR's) cybersecurity functions to the Texas Cyber Command (TXCC). Learn more
Incident Reporting & Response

Report a cybersecurity incident

If your organization is experiencing a cybersecurity incident, the Texas Cyber Command is your point of contact. Our teams help state agencies and organizations across Texas prepare for, respond to, and recover from cyber threats.

Report now

Report an Incident

State agencies, institutions of higher education, and local governments: report a confirmed or suspected cybersecurity incident through the established statewide channels below. You can also prepare with our response resources.

Required: 48 hours Reporting within 48 hours of discovery is required by law, but report as soon as you can: within 24 hours is strongly encouraged, and calling the hotline satisfies the requirement. See all reporting deadlines

Incident Response Hotline
(877) 347-2476
State Agencies & Higher Education

Report through the SPECTRIM portal.

Access SPECTRIM (opens in new tab) Reporting requirements
Local Governments

Submit the Local Incident Reporting Form via Archer Engage. School districts and charter schools report under Texas Education Code Section 11.175 through the same form.

Access Archer Engage (opens in new tab) Reporting requirements
Other ways to report

Suspicious email or a cyber threat

These paths are open to anyone and do not require a reporting portal.

Report a phishing email

Forward suspected phishing emails as an attachment to phishing@txcc.texas.gov. Analysts at the Network Security Operations Center (NSOC) review the message for malicious files and URLs and act to block confirmed malicious sites at the state network perimeter.

Report a cyber threat

If you've identified a cyber threat, such as suspicious activity, indicators, or intelligence that could affect other organizations, you can submit it for research and information sharing through the Texas Information Sharing and Analysis Organization (TX-ISAO).

Report via TX-ISAO (opens in new tab)
Your obligations

Reporting deadlines

The same statutory deadlines apply to state agencies, institutions of higher education, local governments, school districts, and charter schools.

Recommended: 24 hours
Tell us as soon as you can

The sooner the Command knows, the sooner it can help you contain the incident and warn others. Reporting within 24 hours of discovery is strongly encouraged, well ahead of the statutory deadline.

Required: 48 hours
Report the incident

Reporting a security incident within 48 hours of discovery is required by law. Calling the incident response hotline satisfies this requirement.

Submit the follow-up analysis

After eradication, closure, and recovery, submit the details of the incident and an analysis of its cause through the appropriate portal below.

Reporting is required for incidents assessed to propagate to other systems, result in criminal violations that must be reported to law enforcement, or involve the unauthorized disclosure or modification of confidential information, such as sensitive personal information.

Response & preparedness

Incident response and preparedness resources

The Texas Cyber Command provides organizations with incident response support, guidance, and resources before, during, and after a cybersecurity incident. The guides, templates, and resources below help organizations build a robust incident management and response program.