Are You Doing Enough to Protect Your Contact Centre Data?

Contact centres holding customer records should audit current data protection practices as breach risks and regulatory expectations continue to rise.

A dispatch from Call Centre Helper

Contact Centre Security Advice Is Increasingly Written by the People Selling You the Fix

On 27 August 2026, Call Centre Helper published "Are You Doing Enough to Protect Your Contact Centre Data?", a roundup in which it put that question to a panel of vendor consultants rather than independent security researchers. Contributors named include Dan Brown, Director of Cloud Ops at Enghouse Interactive; Ben Willmott, Principal Solution Consultant at Route 101; and Lewis Gallagher on the rise of "Shadow AI". Other companies credited in the piece include Content Guru, Netcall, ScorebuddyCX, UJET, Zoom and SequenceShift, alongside named contributors Ben Neo, Derek Corcoran and Martin Taylor. No breach statistics, survey sample sizes or audit findings are cited anywhere in the piece — it's advice, not evidence.

Who is actually behind this advice?

Every tip comes from a solution consultant at a company that sells contact centre software, not from an independent auditor or regulator.

That doesn't make the advice wrong — Dan Brown's point that breaches usually start with "an account that should have been disabled" or a patch delayed a few weeks is a fair description of how real incidents unfold. But a roundup structured as vendor-contributed columns is closer to content marketing dressed as a checklist than a diagnostic tool. If you're benchmarking your own contact centre against it, treat each tip as a sales pitch's opening line, not a finding.

Does "Shadow AI" actually change your risk model?

Yes — agentic bots now hold the same system access staff do, so they need the same monitoring, not just new policy documents.

Ben Willmott's framing is the sharpest thing in the piece: agentic service "by definition" requires bots to reach internal systems, which means those bots are now a phishing and social-engineering surface in their own right, not just a channel for handling one. Lewis Gallagher's "Shadow AI" point — staff quietly using personal AI tools because sanctioned ones are slower or missing features — is the same Shadow IT problem contact centres have run for a decade, just with higher-stakes data leaving the building.

What should you actually ask your own vendor?

Ask for the evidence behind any security claim: who tested it, when, against what standard, and what failed.

Given this site's earlier point that "when every vendor sounds excellent, polish stops being evidence," the same test applies here. Before accepting a vendor's security messaging, ask for their most recent penetration test date, their patch SLA in writing, and — specifically — whether their AI agents are logged and access-reviewed on the same cycle as human agents. If a vendor can't answer that last one concretely, their agentic roadmap is ahead of their security operations.

Where does this fit with what's already been said about CX security and AI?

It reinforces, rather than contradicts, this site's running warning that AI ambition is outpacing operational governance in contact centres.

Paired with recent coverage of CX vendors splitting over AI strategy, the message for buyers is consistent: the industry agrees agentic AI raises the stakes, but nobody outside the vendors themselves is yet measuring whether governance is keeping up.

Frequently asked questions

Is this Call Centre Helper piece based on a survey or independent audit?

No. It's a panel of named vendor consultants each contributing a tip; no methodology, sample size or breach data is included.

What's the one operational habit the piece says matters most?

Enghouse Interactive's Dan Brown argues daily operational discipline — access reviews, monitoring, patching — protects more than periodic compliance audits alone.

Do AI agents need separate security treatment from human agents?

Route 101's Ben Willmott says yes: agentic bots need the same phishing training and access monitoring as staff, because they hold comparable system access.

Source: Call Centre Helper, "Are You Doing Enough to Protect Your Contact Centre Data?", published 27 August 2026.

Find out how to strengthen contact centre data security, reduce risks, protect sensitive information, and prepare your teams for emerging threats.
- Call Centre Helper, Megan Jones
Read the full story at Call Centre Helper