IT support statistics UK 2026: costs, response times and what SMEs actually pay
By the Helios team
Most of the IT support statistics UK writers quote are laundered marketing: a vendor surveys its own customers, a blog rounds the result, another blog quotes the first, and within a year the number has no source at all. This page is the opposite. Every figure below comes from a named public source with a link, the ones that get misquoted are flagged, and where no reliable UK figure exists we say so instead of inventing one. Cite it, check it, steal it.
The UK IT support statistics worth citing
Start with the numbers that survive scrutiny. Each row links to a primary source you can check yourself.
| Statistic | Figure | Source |
|---|---|---|
| UK businesses identifying a cyber attack or breach in the past 12 months | 43 per cent (2025 edition), down from 50 per cent in 2024 | DSIT Cyber Security Breaches Survey |
| Most common attack type among affected businesses | Phishing, reported by over four fifths of businesses that identified an attack | Cyber Security Breaches Survey |
| UK businesses reporting a ransomware incident | Roughly doubled year on year, to about 1 per cent of all businesses | Cyber Security Breaches Survey |
| SME share of the UK business population | 99.9 per cent of roughly 5.5 million private sector businesses | DBT Business Population Estimates |
| Patching deadline required by Cyber Essentials | 14 days for critical and high-severity updates | NCSC Cyber Essentials |
| Average time from vulnerability disclosure to exploitation | About five days, in Mandiant's analysis of 2023 vulnerabilities | Mandiant, Google Cloud |
Two things to notice before you quote any of them. The survey year matters, because the breach figure moved seven points between editions. And the denominator matters even more, which we will come back to.
Cyber incidents: what the official survey actually says
The Cyber Security Breaches Survey, run annually for the UK government, is the single best source in this space: large sample, published methodology, free, and updated every spring. It is also the most misquoted. The headline figure, 43 per cent of businesses identifying an attack, includes every phishing email a member of staff noticed and deleted. That is not 43 per cent of businesses suffering harm. It is 43 per cent noticing an attempt.
This is why the survey's cost estimates look strangely low, averaging in the low thousands of pounds for the most disruptive breach. Most identified attacks are phishing emails that went nowhere. The businesses that lose real money are a small subset, and averages flatten them into invisibility. The ransomware figure is the one worth watching: still only around 1 per cent of businesses, but roughly double the previous year, and ransomware is the incident type where a five-figure or six-figure loss is plausible for a 30-person firm.
For a second official signal, the ICO publishes quarterly data security incident trends: every reported incident, categorised by cause and sector. Phishing and ransomware sit consistently near the top. It is reporting data rather than survey data, so it undercounts anything nobody was obliged to report, but it is free, quarterly and citable. Insurer reports such as the Hiscox Cyber Readiness Report add a UK-inclusive commercial view, though remember the sample skews towards firms already thinking about insurance.
Rule of thumb: a statistic with no named source, a suspiciously round number and no date is not a statistic. It is a guess wearing a spreadsheet's clothes.
What UK SMEs actually pay for IT support
Here is the honest gap: there is no official UK statistical series on what SMEs pay for IT support. The ONS does not measure it. Gartner publishes IT spend as a percentage of revenue by industry, but its benchmarks are built from organisations far larger than a 25-seat accountancy practice, so quoting them for SMEs is borrowing enterprise clothing.
What can be said, hedged openly: UK managed service pricing commonly quoted in the market sits roughly between £40 and £100 per user per month for fully managed support, with per-device arrangements typically lower, and the spread driven by what is bundled: security tooling, backup, Microsoft 365 management, on-site time. Any article giving you a single precise national average is averaging things that should not be averaged. If you want to understand why the ranges vary so much, the structure of the charging model explains most of it, which we have covered in MSP pricing models: per-device, per-user or flat fee.
Whether the machines belong to clients or to your own company, the more useful exercise is arithmetic you can do yourself. Take your headcount, multiply by a market rate, and compare it against the fully loaded cost of an in-house hire plus tooling. For most firms under about 50 staff, the comparison is not close, which is why the SME market outsources.
Patching timelines: the 14-day rule meets the 5-day reality
Two numbers define UK patching expectations, and they point in awkward directions. Cyber Essentials, the government-backed baseline certification, requires critical and high-severity updates applied within 14 days of release. Mandiant's analysis of 2023 vulnerabilities put the average time from disclosure to exploitation at about five days, down from weeks in earlier years.
The arithmetic: the UK's baseline standard gives you 14 days to patch. Attackers, on average, need about five. Compliance and safety are not the same deadline.
This gap is the single most useful patching statistic for anyone writing about SME security, because it reframes the question from "are we compliant" to "are we exposed for nine days at a time". We have argued the operational side of this in how fast should you patch: for most SME estates, deployment rings sized for enterprises add delay without adding safety.
Downtime costs: mostly folklore
Downtime cost figures are where IT statistics go to misbehave. The famous per-minute numbers trace back to enterprise surveys: the Uptime Institute's annual outage analysis, for instance, consistently finds a majority of significant outages costing over 100,000 dollars, but its respondents run data centres, not 20-seat law firms. Quoting those figures for UK SMEs is wrong by orders of magnitude.
Do the sum for a real business instead. A 20-person firm with fully loaded staff costs of roughly £20 an hour, losing half its productivity for one working day, loses about £1,600 in wasted wages alone: 20 people, £20, 8 hours, times a half. Add lost revenue, missed deadlines and recovery time on top. That is a defensible, checkable number, and it is usually more persuasive to a business owner than any headline statistic, because it is their payroll.
How to cite these numbers without embarrassing yourself
- Prefer the primary source. Link the government survey, not a blog quoting a blog quoting it. Skip this and your number will be two editions out of date within a year.
- Date every figure. The breach rate moved seven points between 2024 and 2025. An undated statistic is already wrong.
- Watch the denominator. "Per cent of businesses", "per cent of breached businesses" and "per cent of incidents" are three different claims. Most misquotes are denominator swaps, not fabrications.
- Distrust averages of skewed things. Breach costs and downtime costs are dominated by a small number of severe cases. Medians tell you more, when the source publishes them.
- Say when no number exists. There is no official UK figure for SME IT support spend. Saying so is more credible than inventing one, and it is also true.
The best statistic is one your reader can recalculate. Everything else is an appeal to authority.
Where this fits with Helios
Helios is a flat-rate RMM and PSA built by a working MSP, and this page exists because we got tired of seeing unsourced numbers repeated at us in sales decks. The platform will not fix a statistic, but it does generate the ones that matter locally: your patch latency, your ticket response times, your backup success rate, evidence rather than industry averages. Most of what this article argues for is scepticism, not tooling, and no product supplies that.
Helios merges RMM, PSA and an AI agent into one flat monthly price: £99, £199 or £399, every feature on every plan, monthly billing, cancel any time. 14-day trial, no card, no feature gating. Start free.