One possible idea would be to have your inbound/outbound mail routes through a secure hosted machine elsewhere (outside the ISP).

Ensure that mail in and out only goes via that host, and is encrypted in both directions. That machine can then act as an "MX" record for the customer's domains.

Some hosted email security services already provide such a system; I work for a company which does just this.

If you're using this, even if the ISP's routers were compromised, your email is still safe.

Slarty