Articles Tagged with risk management

7E0DCD95-4E0B-48C5-8518-44DD2E8595CE-300x200A doughnut chain, a mortgage servicer, and a payroll processing company have almost nothing in common as businesses. Different industries, different customers, different sizes. But all three ended up in the same place over the past two years: paying millions of dollars to settle lawsuits after hackers got into systems holding ordinary personal information. If you think your business is too small, too unremarkable, or too far outside the tech world to end up in the same position, these three cases say otherwise.

Krispy Kreme: Employee Data, Not Just Customer Data

Krispy Kreme discovered a data breach in November 2024 that exposed the personal information of 161,676 current and former employees, including Social Security numbers, dates of birth, and financial account access details. The lawsuits that followed alleged the company failed to comply with basic data security obligations under the FTC Act and industry standards, and specifically claimed the sensitive information was never encrypted or redacted. Krispy Kreme agreed to pay roughly 1.6 million dollars to resolve the claims.

CA23A19B-E0C3-45CF-AA7E-F3D7CCBF3917-300x200Every contract you sign has one section that gets less attention than almost anything else in the document, and it is usually the section that ends up costing business owners the most. It is not the payment terms. It is not the termination clause. It is the indemnification clause, and most business owners either skim past it or assume it is standard boilerplate that does not need a second look.

It is not boilerplate. It is one of the most consequential paragraphs in the entire agreement, and by the time most business owners understand what it actually does, they are already the ones paying for someone else’s mistake.

What an Indemnification Clause Actually Does

Contact Information