“Always-on” customer experience has become shorthand for availability: 24/7 support, globally distributed channels, elastic cloud infrastructure, and aggressive service-level agreements (SLAs).
But the last few years have exposed that when customers can’t get through, access accounts, or trust what they’re seeing, it’s more often a security issue than a data center failure.
Major outages make headlines, but many of the longest and most damaging CX disruptions are security-driven. Credential stuffing that triggers emergency lockouts, fraud spikes that swamp contact centers, or breach containment actions that force companies to temporarily shut down self-service portals bring home the reality.
More than keeping systems up and running, resilience involves keeping customer journeys safe and usable under attack at a time when customer expectations are higher than ever.
According to data compiled by Zendesk, 56 percent of CX leaders confirm that their organization experienced a data breach or cyber attack targeting customer data in the past year. And 70 percent of consumers will avoid purchasing from a company they view as having inadequate security.
Designing Always-on CX With Attack Scenarios in Mind
Resilient CX leaders are reframing “always on” around the idea of assuming that a security breach will happen, and then designing experiences that degrade safely instead of collapsing.
As Johan Edholm, Security Engineer and Co-Founder at Detectify, told CX Today:
“If you want customers to always be able to reach you, you have to assume there will be moments when attackers try to exploit that access.”
“Threats like stolen credentials, account takeovers, and fraud spikes should be built into resilience planning from the start. The aim is not just continuous service, but a customer experience that remains safe and dependable during an incident.”
Edholm added that the most fragile points in the customer journey are when a business has to make a quick trust decision, such as around customer login and password reset, account recovery, checkout, or any action involving money or sensitive account changes.
“These are the flows attackers target first, because speed and confusion work in their favor. If the organization has not decided in advance how those flows should behave when something looks wrong, teams end up improvising. That is when both security and customer experience start to degrade.”
Resilient CX Assumes Failure
Most resilience programs were built on infrastructure logic around redundancy, failover, and recovery time objectives. That is important, but it can overlook how modern attacks take customer interactions offline even when systems are technically “up.”
The organizations that recover fastest plan for impact and keep customers moving through safe alternatives when something breaks.
In a containment scenario, a company may be able to keep web and mobile experiences running, but if the integrity of customer accounts is in question, the responsible move might be to limit their access while investigating their legitimacy.
“Controlled degradation means you do not keep everything working normally just for the sake of convenience when something suspicious is happening,” Edholm said. “If the signals you rely on to judge whether a user is legitimate start to look unreliable, the system should limit what people can do rather than continue on as if everything is fine.”
That could involve temporarily restricting password resets and other sensitive actions, adding extra identity checks before users can make account changes, slowing down higher-risk activity, or sending some cases for human review. As Edholm explained:
“For CRM and customer data systems, the priority must be to ensure you have confidence that the person on the other end is really who they say they are.”
“Once that confidence starts to weaken, every action tied to that identity becomes harder to trust.”
Designing for safe degradation means asking what happens next when a control fails, and whether a customer can still complete a meaningful journey without exposure to unacceptable risk.
For example, if password resets are frozen while the company investigates a security incident, can customers still access read-only account views with step-up verification? If confidence in a digital identity drops, is there a low-friction way to confirm identity without sending customers to overwhelmed contact centers? And if a channel is under attack, can customers be dynamically routed to verified alternatives such as authenticated in-app messaging rather than email?
This kind of resilience requires tight coordination between security, IT, and CX. It also demands that frontline tools and policies are designed for variability.
A resilient system allows an enterprise to continue operating while limiting access to the most sensitive actions, until trust can be restored.
Securing Omnichannel CX Across Customer Touchpoints
Consumer journeys now tend to span multiple touchpoints, often starting in a mobile app, continuing via chat, and ending on a phone call. And any break in context during the shift in channels tends to frustrate them, Avaya noted in its recent Connected Consumer Research report. The survey found that “a striking 96% of consumers say it is at least somewhat important to switch channels without repeating themselves—with 71% saying it’s very or extremely important.”
That demand for always-on continuity means that organizations need to measure more than uptime. A channel can be online and still failing if fraud gets through, or trust in user identity breaks down.




