The code you have shown is fine, and not just in terms of speed - it will be safer than the alternatives too (as the values from the textboxes are treated as values, rather than potentially being treated as part of the SQL code by mistake).