About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Customer Experience · 23 September 2026

MAG Breach Shows Peripheral Data Systems Weaken CRM Security

A cyberattack on Manchester Airports Group exposed how ancillary services like parking, Wi-Fi and Fast Track lanes can create security blind spots outside core CRM oversight.

Newsdesk
Curated briefing · 2 min read

What happened

A cyberattack on Manchester Airports Group (MAG) has exposed how customer data collected through peripheral services — car parking, airport Wi-Fi and Fast Track lanes — can become a significant security and governance liability when it sits outside an organisation's core CRM systems. The incident, reported by CX Today, illustrates that data gathered through convenience-oriented touchpoints is often stored, managed and protected less rigorously than data held in primary customer platforms.

According to the report, the breach did not originate in MAG's central customer database but in the wider ecosystem of ancillary services that airports and similar operators use to enhance the passenger journey. This fragmented data footprint — built up over years as new services are bolted on — created blind spots that attackers were able to exploit.

Why it matters

For organisations investing heavily in customer experience, the MAG incident is a reminder that experience-enhancing data collection carries a parallel governance obligation. Every new touchpoint — a loyalty perk, a convenience service, a personalisation feature — expands the attack surface, and that surface often grows faster than the security architecture designed to protect it.

The lesson extends well beyond airports. Any business layering multiple third-party or auxiliary systems onto a core CRM — retailers with loyalty apps, hotels with concierge platforms, banks with partner offers — faces the same structural risk: data proliferation without centralised oversight. As experience ecosystems become more distributed, security and CX leaders will need to treat data governance as a design requirement for every new service, not an afterthought bolted on after launch.

The Renascence take

Most organisations audit their CRM for security rigorously while treating adjacent services — the ones that actually shape day-to-day customer perception — as low-risk conveniences. That assumption is precisely what this incident challenges.

The uncomfortable truth is that customer trust is only as strong as the least-governed system touching customer data — and that system is rarely the CRM leadership scrutinises most closely. Every "small" service added to delight customers, from Wi-Fi sign-ups to fast-track queues, quietly inherits the same duty of care as the core platform, whether or not it receives the same investment. A genuinely customer-obsessed operator maps its entire data footprint end to end, treats every ancillary touchpoint as a governance node rather than a convenience feature, and assumes attackers will look exactly where oversight is thinnest.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

According to CX Today's reporting, the breach originated not in MAG's core customer database but in peripheral services such as car parking, airport Wi-Fi and Fast Track lanes, which sit outside the main CRM's security oversight.

These ancillary touchpoints were added over time to enhance the passenger experience, but they were often stored, managed and protected less rigorously than data in the core CRM, creating governance blind spots attackers could exploit.

Any business layering third-party or auxiliary systems onto a core CRM — such as retailers with loyalty apps, hotels with concierge platforms, or banks with partner offers — faces the same structural risk of data proliferation without centralised oversight.

It suggests that data governance should be treated as a design requirement for every new customer touchpoint from the outset, rather than an afterthought added after a service already delights customers.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.