Unusual Group today issued a stark warning to the marketing industry in response to the UK Government’s Cyber Security and Resilience Bill 2025, due to be enforced in 2026.
Luke Tobin, CEO, Unusual Group, said,
“The legislation will separate the agencies that can be trusted from those that can’t. Security is now a growth lever, not a cost, agencies that adapt will win more trust and bigger clients. The ones that don’t? They’ll be left behind.”
Unusual Group believes the Bill will force a long-overdue clean-up across the sector.
Tobin added “When that ecosystem is vulnerable, so is every campaign, every client relationship and every brand we’re entrusted to protect.”
Cyber Security and Resilience Bill Core Priorities for Marketing Agencies
“For agencies, this Bill isn’t just about compliance — it’s about credibility,” said Ali Newton-Temperley, COO of Unusual Group.
Unusual Group sees the Bill driving five major improvements in the sector:
- Stronger data protection across campaigns and martech ecosystems
- Faster breach reporting and response, reducing reputational damage for clients
- Greater resilience in agency supply chains, from freelancers to SaaS tools
- Clearer accountability, giving CMOs and agency leaders confidence in governance
- Higher trust in digital experiences, improving brand loyalty and customer confidence
Marketing agencies are increasingly handling PII, first-party data, AI-driven insights, CDPs, CRM access, and live advertising environments. The Unusual Group advocates that the bill can raise the bar on security, without slowing creativity or innovation when it is embraced with the right processes.



