IT support statistics UK 2026: costs, response times and what SMEs actually pay
The IT support statistics UK readers can trust are few: 43 per cent of UK businesses identified a cyber attack or breach in 2025, Cyber Essentials requires critical patches within 14 days, and fully managed support is commonly quoted at £40 to £100 per user per month, though no official series tracks what SMEs pay. Every figure below comes from a named public source with a link, misquoted ones are flagged, and where no reliable UK figure exists we say so. Cite it, check it, steal it.
The UK IT support statistics worth citing
Start with the numbers that survive scrutiny. Each row links to a primary source you can check yourself.
| Statistic | Figure | Source |
|---|---|---|
| UK businesses identifying a cyber attack or breach in the past 12 months | 43 per cent (2025 edition), down from 50 per cent in 2024 | DSIT Cyber Security Breaches Survey |
| Most common attack type among affected businesses | Phishing, reported by over four fifths of businesses that identified an attack | Cyber Security Breaches Survey |
| UK businesses reporting a ransomware incident | Roughly doubled year on year, to about 1 per cent of all businesses | Cyber Security Breaches Survey |
| SME share of the UK business population | 99.9 per cent of roughly 5.5 million private sector businesses | DBT Business Population Estimates |
| Patching deadline required by Cyber Essentials | 14 days for critical and high-severity updates | NCSC Cyber Essentials |
| Average time from vulnerability disclosure to exploitation | About five days, in Mandiant's analysis of 2023 vulnerabilities | Mandiant, Google Cloud |
Two things to notice before you quote any of them. The survey year matters, because the breach figure moved seven points between editions. And the denominator matters even more, which we will come back to.
Cyber incidents: what the official survey actually says
The Cyber Security Breaches Survey, run annually for the UK government, is the single best source in this space: large sample, published methodology, free, and updated every spring. It is also the most misquoted. The headline figure, 43 per cent of businesses identifying an attack, includes every phishing email a member of staff noticed and deleted. That is not 43 per cent of businesses suffering harm. It is 43 per cent noticing an attempt.
This is why the survey's cost estimates look strangely low, averaging in the low thousands of pounds for the most disruptive breach. Most identified attacks are phishing emails that went nowhere. The businesses that lose real money are a small subset, and averages flatten them into invisibility. The ransomware figure is the one worth watching: still only around 1 per cent of businesses, but roughly double the previous year, and ransomware is the incident type where a five-figure or six-figure loss is plausible for a 30-person firm.
For a second official signal, the ICO publishes quarterly data security incident trends: every reported incident, categorised by cause and sector. Phishing and ransomware sit consistently near the top. It is reporting data rather than survey data, so it undercounts anything nobody was obliged to report, but it is free, quarterly and citable. Insurer reports such as the Hiscox Cyber Readiness Report add a UK-inclusive commercial view, though remember the sample skews towards firms already thinking about insurance.
Rule of thumb: a statistic with no named source, a suspiciously round number and no date is not a statistic. It is a guess wearing a spreadsheet's clothes.
What UK SMEs actually pay for IT support
Here is the honest gap: there is no official UK statistical series on what SMEs pay for IT support. The ONS does not measure it. Gartner publishes IT spend as a percentage of revenue by industry, but its benchmarks are built from organisations far larger than a 25-seat accountancy practice, so quoting them for SMEs is borrowing enterprise clothing.
What can be said, hedged openly: UK managed service pricing commonly quoted in the market sits roughly between £40 and £100 per user per month for fully managed support, with per-device arrangements typically lower, and the spread driven by what is bundled: security tooling, backup, Microsoft 365 management, on-site time. Any article giving you a single precise national average is averaging things that should not be averaged. If you want to understand why the ranges vary so much, the structure of the charging model explains most of it, which we have covered in MSP pricing models: per-device, per-user or flat fee.
Whether the machines belong to clients or to your own company, the more useful exercise is arithmetic you can do yourself. Take your headcount, multiply by a market rate, and compare it against the fully loaded cost of an in-house hire plus tooling. For most firms under about 50 staff, the comparison is not close, which is why the SME market outsources.
Patching timelines: the 14-day rule meets the 5-day reality
Two numbers define UK patching expectations, and they point in awkward directions. Cyber Essentials, the government-backed baseline certification, requires critical and high-severity updates applied within 14 days of release. Mandiant's analysis of 2023 vulnerabilities put the average time from disclosure to exploitation at about five days, down from weeks in earlier years.
The arithmetic: the UK's baseline standard gives you 14 days to patch. Attackers, on average, need about five. Compliance and safety are not the same deadline.
This gap is the single most useful patching statistic for anyone writing about SME security, because it reframes the question from "are we compliant" to "are we exposed for nine days at a time". We have argued the operational side of this in how fast should you patch: for most SME estates, deployment rings sized for enterprises add delay without adding safety.
Downtime costs: mostly folklore
Downtime cost figures are where IT statistics go to misbehave. The famous per-minute numbers trace back to enterprise surveys: the Uptime Institute's annual outage analysis, for instance, consistently finds a majority of significant outages costing over 100,000 dollars, but its respondents run data centres, not 20-seat law firms. Quoting those figures for UK SMEs is wrong by orders of magnitude.
Do the sum for a real business instead. A 20-person firm with fully loaded staff costs of roughly £20 an hour, losing half its productivity for one working day, loses about £1,600 in wasted wages alone: 20 people, £20, 8 hours, times a half. Add lost revenue, missed deadlines and recovery time on top. That is a defensible, checkable number, and it is usually more persuasive to a business owner than any headline statistic, because it is their payroll.
How to cite these numbers without embarrassing yourself
- Prefer the primary source. Link the government survey, not a blog quoting a blog quoting it. Skip this and your number will be two editions out of date within a year.
- Date every figure. The breach rate moved seven points between 2024 and 2025. An undated statistic is already wrong.
- Watch the denominator. "Per cent of businesses", "per cent of breached businesses" and "per cent of incidents" are three different claims. Most misquotes are denominator swaps, not fabrications.
- Distrust averages of skewed things. Breach costs and downtime costs are dominated by a small number of severe cases. Medians tell you more, when the source publishes them.
- Say when no number exists. There is no official UK figure for SME IT support spend. Saying so is more credible than inventing one, and it is also true.
The best statistic is one your reader can recalculate. Everything else is an appeal to authority.
Where this fits with Helios
Helios is a flat-rate RMM and PSA built by a working MSP, and this page exists because we got tired of seeing unsourced numbers repeated at us in sales decks. The platform will not fix a statistic, but it does generate the ones that matter locally: your patch latency, your ticket response times, your backup success rate, evidence rather than industry averages. Most of what this article argues for is scepticism, not tooling, and no product supplies that.
Helios merges RMM, PSA and an AI agent into one flat monthly price: £99, £199 or £399, every feature on every plan, monthly billing, cancel any time. 14-day trial, no card, no feature gating. Start free.
Read next
Why MSPs choose Helios
One platform that does the work, at a price that stays put
Helio fixes, not just flags
When an alert fires, Helio, the AI technician built into Helios, investigates it, writes the fix and runs it once you approve. It keeps what works, so the next one is quicker.
Everything in one product
RMM, a service desk with SLAs, patching including third-party apps, remote access, Microsoft 365 and Defender checks, backup monitoring, a client portal and billing into Xero or QuickBooks.
Priced by fleet, not by people
£4 a device on Launch up to 25 devices, from £20 a month, then £99, £199 or £399 a month by fleet size, with any number of technicians and every feature on every plan.
A price that stays put
Your price is locked for as long as you stay subscribed, and that is written into our terms. Monthly billing, cancel any time.
Bring your clients across
Import your clients and machines from another RMM's CSV export, then roll the Helios agent out at your own pace, with a count of how many have arrived.
14 days free, no card
The full platform from the first minute, on your own machines. No sales call, no feature held back for the trial.
See it on your own fleet
Helios is the AI-native platform for MSPs: monitoring, patching, security, Microsoft 365, backup monitoring, remote access, client billing and an AI service desk in one product, at one flat price per MSP. Contracts and logged time become invoices in Xero or QuickBooks without leaving the platform. Every feature is on every plan. 14-day free trial, card-free, set up in minutes, cancel any time.
Start freeResearched and written with Helio SEO, our AI writer for business blogs.