Security isn’t optional anymore
For creative and digital agencies, trust is everything. Clients don’t just hand over briefs and brand guidelines — they share commercially sensitive data, customer information, access credentials and long-term plans.
At Oxygen, information security isn’t an afterthought or a marketing badge. It’s been embedded in how we work for well over 15 years.
That’s why we’re proud to have been recertified to Cyber Essentials Plus in 2026 for the second year running, alongside holding ISO 27001 continuously since 2008.
Why security matters specifically for agencies
Agencies sit at a crossroads of risk:
- Multiple clients, often across regulated sectors.
- Shared access to systems, analytics, CMSs and platforms.
- Remote and hybrid working.
- Third-party tools and integrations.
- Tight deadlines that can tempt shortcuts
A single weak link can expose far more than one organisation.
For clients, this raises a reasonable question: “How confident are we that our data is safe?”
“A government impact evaluation found that 79% of Cyber Essentials certified organisations believe the scheme has a positive impact on the confidence of their own clients and customers, underscoring how certification builds trust in an organisation’s cyber security posture.”
What Cyber Essentials Plus actually means (in plain English)
Cyber Essentials Plus is not a self-assessment. It’s an independent, hands-on technical audit of our systems.
It verifies that we have strong protections in place against the most common cyber attacks, including:
- secure configuration of devices and servers
- proper access control and user permissions
- malware protection
- patch management and updates
- firewall and boundary security.
The “Plus” level means our defences were tested by an external assessor, not just declared by us.
In short: it demonstrates that our day-to-day setup is genuinely secure, not just well-intentioned.

ISO 27001: Security as a management system, not a one-off
If Cyber Essentials Plus proves our technical controls, ISO 27001 proves our culture and processes.
We’ve maintained ISO 27001 certification since 2008, which means:
- information security is built into how we operate, not bolted on
- risks are formally identified, reviewed and managed
- staff are trained and accountable
- suppliers and tools are assessed for security impact
- policies, incident response and business continuity are documented and tested.
Crucially, ISO 27001 requires continuous improvement — not a one-time pass.
Why this is reassuring for our clients
For our clients, these certifications mean several things:
- Lower risk when sharing sensitive information.
- Confidence that access is controlled and auditable.
- Reassurance when compliance or procurement teams ask hard questions.
- Alignment with their own security and governance standards.
- Reduced likelihood of disruption caused by cyber incidents.
It also makes working with us easier for organisations in regulated or security-conscious sectors, where supplier assurance is essential.
“Organisations report saving even more time on cyber diligence when a supplier has Cyber Essentials Plus — 59% compared with 48% for standard Cyber Essentials.” UK Government
Security without slowing creativity
Strong security shouldn’t get in the way of great work.
Our approach is about enabling collaboration safely, not locking everything down to the point of frustration. These certifications help us strike that balance — protecting client data while keeping teams productive and responsive.
A long-term commitment, not a tick-box exercise
Anyone can talk about security. Maintaining independent certifications year after year is harder.
Cyber Essentials Plus and ISO 27001 are part of a broader commitment to professionalism, resilience and trust — the same qualities our clients expect in the work we deliver. If you’d like to know mor then please get in touch.