Site navigation

What IT Trends Will Shape UK SMEs in 2025?

Graham Turner

,

SME trends 2025
UK SMEs face mounting cybersecurity threats, rapid AI adoption, and IT sprawl. JumpCloud’s latest report reveals key trends, from shadow IT to the growing role of MSPs, as businesses navigate competing priorities of security, simplicity, and innovation.

Managing IT today means navigating fragmented ecosystems, ever-evolving security threats, and a minefield of rising costs – the catalyst for which was a significant tax burden that will significantly impact small to medium-sized enterprises (SMEs).

At the same time, UK IT admins within SMEs are under constant pressure to juggle complex device environments, shadow IT risks, and the rapid advance of AI – all while delivering a simple and seamless user experience.

The pace of change can feel relentless. According JumpCloud’s  2025 SME IT Trends report, nearly 90% of UK IT admins are worried about unauthorised apps and devices expanding their attack surface, while 60% are concerned that AI’s rapid rise outpaces their ability to secure against AI-driven threats.

Despite this, nearly half of UK SMEs are worried that implementing stronger security controls may result in poor user experiences.

With IT sprawl overwhelming many teams, 83% of UK IT admins are calling for a unified platform to manage devices, identities, and access, simplifying their increasingly fragmented environments.

Below, we’ll take a look at some of the reports key findings and insights.

UK SMEs Are Under Siege

For the fourth consecutive iteration of JumpCloud’s SME IT Trends report, 61% of UK organisations cite security as the biggest business challenge. The latest report reveals that the number of UK SMEs that have suffered a cybersecurity attack has remained consistent, with 45% experiencing an attack in Q1 2025, compared to 44% in Q3 2024.

In Q1 2025, phishing accounted for 53% of cybersecurity attacks suffered by UK SMEs – once again the most prevalent threat vector when compared to Q3 2024. Over a third (37%) of cybersecurity attacks were due to stolen or lost credentials, whilst 30% were due to too many permissions.

These are reflected in the three biggest security concerns that UK SMEs identify – software vulnerability exploits (36%); network attacks (36%); and stolen/shared user credentials (26%).

Continually grappling with security threats is why UK SMEs are prioritising investment in cybersecurity tools and services (52%) – more than anything else – in the next six months.

Is User Experience Sabotaging Cybersecurity?

Robust security measures must always be balanced with ease of use and accessibility to business applications. However, with security such a prominent business concern amongst UK organisations, it’s concerning to see that the pendulum has swung in the wrong direction.

Nearly half of UK SMEs (48%) say they are not implementing stronger security measures across their IT stack because these measures generally result in a poorer experience for users.

Ironically, 42% of UK SMEs are not implementing stronger security measures because they already manage too many tools in their IT stack. This is an illustration of the snowball effect that increased tool sprawl across an organisation’s IT team can have on securing businesses and their data.

AI: The Emerging Saviour or a Ticking Time Bomb?

While UK organisations continue to approach AI’s implementation with caution, it is increasingly being recognised as a force for good. The appetite to implement AI initiatives in UK SMEs continues to grow, with 75% looking to implement AI over the next 12 months, an increase on the 66% who had plans to do this in Q3 2024.

Indeed, AI adoption continues to accelerate, with 39% of UK respondents planning to implement AI in the next six months compared to 34% in the Q3 2024 survey and 19% in the survey prior to this. The proportion of UK respondents who said they had no plans to implement AI dropped to 6% in these latest findings from 9% in the previous survey.

This all points to a clear acceleration in AI adoption and organisations recognising its potential.

Indeed, when asked if their opinion of AI had changed in the last six months, 34% said that the impact of AI is even greater than they thought it would be, while 32% said the potential impact is the same but moving slower than they thought, a positive drop on the 37% who said this in the last survey.

Employees Are Using AI – But Who’s in Control?

In terms of how organisations are using AI, nearly half (49%) encourage their employees to use genAI tools like ChatGPT and others.

In fact, 48% have developed a policy to help guide employees around AI use, which is encouraging as they try to establish the appropriate guardrails around usage. However, 38% only allow employees limited access to AI applications and 23% have controls that prevent employees from accessing AI applications.

This is because concerns around AI and its power to outpace UK SMEs’ ability to protect against threats remain an issue, however, this view has softened slightly.

The survey found this percentage has decreased to 60% in Q1 2025 versus 64% in Q3 2024.

But in Q1 2025, 29% of cybersecurity attacks were attributed to AI, which was a slight increase from the 25% in Q3 2024.

Shadow IT & Tool Sprawl

Shadow IT continues to pose a problem. In Q3 2024, UK SMEs said they didn’t have the visibility or ability to discover all shadow IT applications used by employees – or that this wasn’t a business priority for them. In Q1 2025, 55% of UK SMEs have discovered employees using applications outside of those officially managed by IT.

An alarming 83% of UK SMEs estimate that employees are using between one and 20 unsanctioned applications. As a result, concern about shadow IT remains high, with 87% of UK SMEs very concerned or somewhat concerned about its use.

Beyond shadow IT problems, tool sprawl continues to remain high amongst UK organisations.

The number using between 11-15 tools to manage the employee lifecycle and all resources has slightly increased since Q3 2024, now standing at 19%. The number of UK SMEs using between five to 10 tools has also increased from 46% in Q3 2024 to 51% in Q1 2025.

Unsurprisingly, 83% of UK SMEs are still calling for a single platform that consolidates multiple solutions into one to enable better-centralised management, security, and control of tools and applications.

Additionally, the number of passwords being used by employees to log in to IT resources continues to increase. 41% of UK SMEs have employees using between six-15 passwords which is an increase from 31% in Q3 2024.

As a result, nine out of 10 businesses say that biometric capability is a key security requirement when purchasing new devices. 85% either agree or strongly agree that their organisation’s security posture would be stronger if they required biometric authentication.

To this point, 62% say that the best tool, application, or process for keeping their organisation secure is biometrics, closely followed by MFA (43%).

SME Security Spending and Staffing Levels

IT budgets are booming, but will it be enough to beat cybersecurity threats?

In the second half of 2024, 68% of UK SMEs expected IT budgets to increase. Interestingly, when looking at 2025, this has shot up to 80% of UK SMEs expecting IT budgets to rise.

Likewise, 76% of UK SMEs expect cybersecurity budgets to increase in the next 12 months and over half (52%) of UK SMEs are planning to invest in cybersecurity tools and services in the next six months. This was higher than any other investment being planned.

This increased investment is reflected in the confidence of UK respondents to deal with and financially recover from a cybersecurity attack, which has increased from 73% in Q3 2024 to 77% in Q1 2025.

Despite the current business uncertainty and the change of government, this hasn’t resulted in more anticipated redundancies. In Q3 2024, over two-thirds (69%) of UK SMEs had either experienced layoffs, or anticipated there would be layoffs at their company in the next six months. In Q1 2025, this remained steady at 66%.

MSP Adoption Skyrockets

Planned MSP investment in the next 12 months has gone up since the previous SME IT Trends report, from 67% in Q3 2024 to 79% in Q1 2025.

In Q1 2025, more UK SMEs (31%) are using MSPs to completely manage their IT programme, including technology, process, and support, compared to 24% in Q3 2024.


Recommended reading


Consequently, fewer UK SMEs use MSPs to support internal IT teams (44% in Q1 2025 versus 51% in Q3 2024).

Once again, system security is the primary reason for UK SMEs to use MSPs (53% in Q1 2025 and 52% in Q3 2024). As a result, the majority of UK SMEs (61%) said that cybersecurity is the one aspect they would like their MSPs to manage that they do not manage today.

Consequently, fewer UK organisations use MSPs to support internal IT teams (44% in Q1 2025 versus 51% in Q3 2024). For those UK SMEs not using MSPs, nearly half (43%) say that they do not do so because they prefer to handle IT themselves. 42% of UK SMEs have concerns about how MSPs manage security; a slight increase from Q3 2024 (37%).

Overall, the report finds that UK SMEs are at a crossroads: security, innovation, and control in the age of uncertainty.

As UK SMEs navigate an increasingly complex landscape, three clear themes emerge: security threats continue to escalate, AI adoption is accelerating, and reliance on MSPs is growing.

The need for robust cybersecurity has never been more urgent – yet businesses are torn between securing their IT and maintaining a seamless user experience.

While AI promises transformative potential, the risks it poses demand careful management and oversight. Meanwhile, the surge in MSP usage reflects a shift towards outsourcing IT management, but concerns over control and security remain a significant hurdle.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data