• Skip to primary navigation
  • Skip to main content
  • Skip to footer
CACTUS IT

CACTUS IT

  • Services
    • Consulting
    • Hardware
    • Software
    • Managed IT services
    • Backup/Recovery
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666711

admin

What a cyber incident actually costs a small business (and why the honest answer is more useful than the scary one)

August 17, 2026 by admin

cost of a cyber incident UK small business

Someone clicks the wrong link, or a laptop shows a message it shouldn’t, and every business owner braces for the same thing: a number. Something enormous, something that sounds like the end of the business as you know it.

Most cyber security content is happy to hand you that number, usually an eye-watering average, quoted with total confidence and little explanation of where it came from. Here’s what UK data actually shows about the cost of a cyber incident, and it’s a different, more useful story.

What the data says about the cost of a cyber incident

The UK government’s own Cyber Security Breaches Survey asks businesses directly what their most disruptive breach cost them. For most, the answer is close to nothing, the median reported cost was £0 (DSIT, Cyber Security Breaches Survey 2025/2026). Most incidents turn out to be a manageable nuisance: a password reset, an awkward hour, then everyone moves on. That’s genuinely good news, and it doesn’t match the fear most business owners carry.

The part that still matters

The honest caveat: among the worst outcomes, the top 5% of cases, costs climbed to £4,000 for micro and small businesses, and £10,000 for medium and large ones. A small proportion of businesses get a genuinely serious hit, often at the worst possible moment for cash flow, and there’s no way to know in advance who that’ll be. That’s really what protection buys you: not immunity from the average outcome, but a buffer against the one you can’t predict.

The two costs the survey doesn’t ask about

The financial figure is only part of the picture, and often not the part that hurts most.

The first is reputational. Very few unhappy customers complain formally. Far more common is quiet erosion, a client who doesn’t renew, a contact who stops sending referrals, a supplier who asks a sharper question at the next review. None of it shows up in a survey or comes with an invoice, but for a business built on relationships, it can matter more than the technical clean-up.

The second is human. Somebody usually carries an incident personally, the employee who clicked the link and spends the week feeling responsible, or the office manager who’s quietly held “cyber security” as an unofficial part of their job for years, and now feels it’s landed on them by name. That stress is real, rarely talked about, and tends to outlast the technical fix.

Neither shows up as a number. Both are usually more disruptive, day to day, than the bill.

What this means practically

This isn’t an argument for doing nothing because most incidents are minor. It’s an argument for being clear-eyed about what you’re actually protecting, which is broader than a bank balance. A modest, predictable spend on proper protection is easier to justify once you frame it as protecting relationships and people, not just accounts.

A more useful question than “how much would this cost us” is: if something happened tomorrow, would our customers still trust us, and would whoever was involved feel supported rather than blamed?

If you’d like to talk through where your business actually stands, on the technical side or the human side, get in touch. We’re happy to just listen first and see where the conversation goes.


Source: Department for Science, Innovation and Technology (DSIT), Cyber Security Breaches Survey 2025/2026, GOV.UK.

Filed Under: News

Why switching IT providers is less disruptive than businesses expect

August 10, 2026 by admin

switching IT providers transition process

You’ve had the thought more than once. Things aren’t right with your current IT provider. But then comes the other thought, right behind it: switching sounds like a nightmare. New passwords, new systems, weeks of confusion, staff complaining. So you put it off, again, and go back to living with a provider you don’t fully trust.

That fear is doing a lot of work it doesn’t deserve to do. IT touches everything in a business, which makes the idea of changing hands feel disproportionately risky. In practice, a well-run switch is far less dramatic than most people picture, and the businesses who struggle most with it are usually the ones who waited until something had already gone wrong before starting to look.

What actually happens when you switch

A proper handover follows a fairly predictable shape, regardless of which provider you’re moving to.

  • A full audit comes first. Before anything changes hands, a new provider should map out exactly what’s currently in place: hardware, software, licences, security tools, and anything that’s overdue for attention. This isn’t just paperwork, it’s the foundation for everything that follows, and it often surfaces things the business itself had forgotten about.
  • Documentation and access get gathered. The new provider works to collect passwords, configurations and account details, either directly from the outgoing provider or, where that relationship has broken down, by working around them using what the business itself has access to.
  • A migration plan gets built around your business, not a generic template. Critical systems get prioritised. Anything genuinely disruptive to move, if there is anything, gets scheduled outside working hours wherever possible.
  • Staff experience is usually limited to very little. A short window of introductions, maybe a new number to call or a new ticketing portal to bookmark, and that’s typically the extent of what day-to-day staff notice.

Where the real risk actually sits

The genuine risk in switching providers isn’t the switch itself. It’s the gap while nothing’s been decided. Businesses that delay because they’re worried about disruption often end up staying with underperforming support for months or years longer than they’d like, absorbing the slow cost of poor service the whole time. Compare that ongoing, low-grade frustration to a well-planned transition lasting a few weeks, and the maths usually favours moving sooner rather than later.

The other real risk is doing it in a rush, under pressure, after something’s already gone badly wrong. A provider who’s just lost your trust through a serious failure isn’t always cooperative during a handover, and a business scrambling to find someone new in a crisis has far less room to properly vet who they’re choosing. Planning a move on your own terms, while your current setup is merely frustrating rather than actively broken, is a much stronger position to switch from.

A realistic timeline

For a typical small business, a full transition from initial audit to a new provider being fully embedded usually takes somewhere between two and six weeks, depending on the complexity of the systems involved and how much documentation the outgoing provider is willing to hand over promptly. None of that time needs to feel disruptive if it’s planned properly. Most of the work happens behind the scenes, between the two providers and the business owner, well before staff notice anything has changed.

If it’s been on your mind

If you’ve been circling this decision for a while, turning it over without acting on it, that hesitation is worth naming honestly: it’s very rarely about the practicalities. It’s about the fear of the unknown, which tends to shrink considerably once you actually talk to someone about what a move would involve for your specific setup.

If you’ve been putting off a conversation about switching, we’re happy to talk it through with no pressure and no obligation.

Filed Under: News

What good IT support actually feels like day to day

July 31, 2026 by admin

proactive IT support monitoring dashboard

Tuesday morning, nothing happens. Everyone logs in, everything works, the day starts on time. Nobody notices, because there’s nothing to notice. That’s not luck. Somewhere in the background, someone caught a problem before it became your problem: a hard drive throwing early warning signs, a security patch installed overnight, a licence renewed before it lapsed.

That’s the strange thing about good proactive IT support. When it’s working properly, it’s almost invisible. You mostly notice it by its absence, which is exactly why so many businesses don’t realise their current support is falling short. If the only version of IT support you’ve ever known is reactive, waiting for the phone to ring, then fixing whatever’s wrong, it’s easy to assume that’s just what IT support is.

It isn’t. There’s a real, practical difference between reactive support and proactive support, and it shows up in different places than you might expect.

Reactive support looks like this:

  • Something breaks, you notice, you call
  • The fix happens after the disruption, not before it
  • You find out about a problem the moment it stops you working
  • Every interaction starts with something already having gone wrong
  • Maintenance happens if and when someone remembers to ask for it

Proactive IT support looks like this:

  • Systems are monitored so problems are spotted before they cause downtime
  • Patches and security updates happen quietly, on a schedule, without you having to ask
  • You get a heads-up about a licence, a certificate, or a piece of aging hardware before it becomes urgent
  • Most conversations are about planning ahead, not putting out fires
  • The good weeks vastly outnumber the bad ones, and the bad ones are rarer and smaller than they used to be

None of this is about response time in a crisis, though that matters too. It’s about how much never becomes a crisis in the first place. A provider who answers the phone in thirty seconds but never prevents anything is still running a reactive operation, just a fast one.

Why this gets missed

The trouble is that proactive support is genuinely hard to spot from the outside, because success looks like nothing happening. A business that’s never experienced the alternative has no real point of comparison. It’s a bit like a car that’s been well maintained: you don’t notice the servicing, you just notice that it starts every morning. The businesses that do notice the difference are almost always the ones who’ve switched from a reactive provider to a proactive one, and been surprised by how much quieter things got.

There’s a simple test worth applying to your own experience. Think back over the last few months. How many of your interactions with your IT provider started with something already broken, versus something being flagged before it caused a problem? If it’s overwhelmingly the former, that’s not a reflection of bad luck with technology. It’s a reflection of the support model underneath it.

What this means in practice

Proactive support isn’t a marketing phrase, it’s a specific way of working: remote monitoring that actually gets looked at, patches applied on a defined schedule rather than an ad hoc one, regular reviews of what’s aging or at risk, and a provider who tells you about a problem before you tell them. None of it is complicated. Most of it just requires someone to be doing the unglamorous, unnoticed work in the background, consistently, rather than only showing up when things go wrong.

If you’ve read this and realised every call to your current provider starts with a problem you found first, that’s worth paying attention to. It’s not how it has to be.

Curious what proactive support would actually look like for your business? Get in touch and we’ll walk you through it, no obligation.

Filed Under: News

Five reasons Yorkshire businesses are switching IT provider this year

July 22, 2026 by admin

Tickets that used to get picked up within the hour now take a day. “Someone will call you back” turns into silence until you chase it yourself. Nothing dramatic has happened. It’s just quietly stopped feeling like support.


Nobody switches provider over one dramatic failure. It’s always a slow accumulation of small things nobody quite got round to complaining about, until enough of them stack up. These are the five reasons we hear most from businesses looking to switch IT support provider.

1. Response times that have quietly got worse

Every provider is fast to answer the phone when they’re trying to win your business. The real test is what happens eighteen months in. A ticket that used to get picked up within the hour starts taking a day. “Someone will call you back” turns into silence until you chase it yourself. It happens gradually enough that you barely notice, right up until you compare notes with another business owner and realise your “normal” isn’t.

2. Communication that leaves you guessing

Not the same thing as speed. This is about whether anyone tells you what’s happening while you wait. Has the ticket been picked up? Is it stuck on a part, a password, or a decision from you? A provider who updates you without being chased is doing something most don’t bother with. Its absence is the single most common complaint we hear from businesses looking to leave.

3. A provider who only ever reacts

Reactive support waits for something to break, then fixes it. Proactive support catches the failing hard drive, the licence about to lapse, the patch that’s overdue, before any of it becomes your problem. If every conversation with your current provider starts with something already having gone wrong, they’re running break-fix and calling it managed support.

4. A friendly voice on the phone, but not much security expertise behind it

Plenty of smaller IT providers are genuinely good at keeping day-to-day systems ticking over, but haven’t kept pace with how much cyber security now matters. That gap stays invisible until it’s tested, usually by an actual incident, or by a client, insurer or supplier asking a direct question your provider can’t answer with any confidence.

5. Bills that don’t match what was promised at the start

Nothing burns trust faster. A low headline rate that turns out to exclude “extras” that come up constantly in practice, like onsite visits, or anything beyond a narrow definition of “basic troubleshooting,” leaves a business feeling misled even when nothing was technically hidden in the contract. Once that trust goes, it doesn’t come back.

None of these five are dramatic on their own. That’s the point. It’s the combination of two or three that finally tips a business owner from “this is just how IT support is” to “we need something better.” If you read that list and nodded more than once, that’s not something to shrug off.


It’s also a far more common move than people think. Most businesses your size already have external IT support: 64% of businesses with 10 to 49 employees, and 70% of those with 50 to 249, already outsource it (DSIT, Cyber Security Breaches Survey 2025/2026). So the real question was never whether to have support. It’s whether the one you’ve got is actually any good, and switching provider is far less disruptive than most people expect, more on that in a future post.

Ready to switch IT support provider?

If more than one of these sounds familiar, get in touch for a straightforward chat about what’s not working and what good support should look like instead. No pressure, no obligation, just an honest conversation.

Source: Department for Science, Innovation and Technology (DSIT), Cyber Security Breaches Survey 2025/2026, GOV.UK.

Filed Under: News

Microsoft 365: What’s actually changing in the July 2026 price increase?

June 9, 2026 by admin

No fluff, just the facts on the upcoming price and feature shifts:

  • Price Changes Business Basic is up 16%. Business Standard is up 12%. Business Premium stays the same.
  • The Mailbox Win Every mailbox (Basic, Standard, and Premium) doubles from 50GB to 100GB.
  • The Security Shift Basic and Standard get basic URL link scanning — but they do NOT get the full Defender Plan 1 suite.
  • Copilot Improvements to Copilot Chat are included for teams actively using it.

Our take The mailbox increase is a real benefit — but a price rise is still a price rise. If you want the best value with full security included, Business Premium is increasingly the standout choice.

When will you actually see the increase on your bill?

The new pricing officially takes effect 1 July 2026, but the date it hits your bill depends on your subscription terms:

Annual commitments — You’ll continue at your current rate until your renewal date after July.

Monthly commitments — You’ll likely see the change on your first billing cycle after 1 July.

Worth checking your renewal date now so there are no surprises.

Filed Under: News

How to spot a Phishing email – With examples from UK businesses

August 12, 2025 by admin


how to spot a phishing email


Phishing emails are one of the biggest threats to UK businesses — and they’re getting harder to spot. As an IT support company in Yorkshire, we see examples every week from local businesses who almost fall victim.

The good news? With a few quick checks, you can spot most phishing attempts before they do any damage.

An example from a local business

One of our customers, a small manufacturing company in West Yorkshire, recently received an email that looked like it came from their bank. The logo was spot-on, the sender’s name matched their bank manager, and the message warned of “urgent account verification” to prevent suspension.

The giveaway? When the recipient hovered over the “Verify Now” link, it pointed to a completely unrelated website — a random domain ending in .xyz, not the bank’s own domain. We stopped it in time, but it’s a perfect reminder:

Always hover over links before clicking. If the web address looks odd or doesn’t match the organisation’s real site, it’s likely a scam.


Key signs of a Phishing email

  1. Check the sender’s address, not just the name
    Scammers can fake the display name (“NatWest Bank”), but the actual email might come from natwest-support@randomdomain.com. If the domain after the @ doesn’t match the real company, be suspicious.
  2. Poor spelling, grammar, or formatting
    Many phishing emails still contain typos or awkward phrasing. For example, we’ve seen “Your account will be suspended” — not something a professional UK business would send.
  3. Unexpected attachments
    If you weren’t expecting a file from someone, don’t open it — especially if it’s a Word document, Excel sheet, or zip file. These can hide malicious software.
  4. Urgency or threats
    Phrases like “Act now or your account will be closed” are designed to make you panic. Take a breath, and verify through official channels before clicking anything.
  5. Generic greetings
    Legitimate companies you work with usually use your name. “Dear customer” or “Dear user” should raise suspicion.

What you should do if you’re not sure

  • Don’t click links or open attachments until you’ve verified the sender.
  • Call the organisation directly using a trusted number (not the one in the email).
  • Report the email to your IT team or forward it to report@phishing.gov.uk (run by the National Cyber Security Centre).
  • For Cactus IT support customers please contact us at the helpdesk on 01943666711 or by email on support@cactus-it.co.uk and we will check the email for you

Why it matters for local businesses

We’ve seen phishing emails that successfully trick staff into giving away passwords, bank details, or making fraudulent payments. For businesses in Yorkshire, even a single incident can cause financial loss, downtime, and damage to reputation.

Training your team to spot these red flags is one of the cheapest and most effective cyber defences you can have.


Final tip: Phishing emails rely on you acting quickly without thinking. Slow down, check carefully, and when in doubt — don’t click.

For further advice and information on IT support for your business, please contact us on 01943666711 or by email on info@cactus-it.co.uk

Filed Under: News

  • Page 1
  • Page 2
  • Go to Next Page »
  • Services
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666 711

Footer

67b East Parade, Ilkley, West Yorkshire LS29 8JP
VAT: GB104229944 United Kingdom

INFO@CACTUS-IT.CO.UK

01943 666 711

  • Services
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666 711
INFO@CACTUS-IT.CO.UK
01943 666 711
  • Privacy Policy
  • Terms and conditions
  • Cookie policy
  • IT support Ilkley
  • Technology partners

CACTUS BACKUP LIMITED - TRADING AS 'CACTUS IT' - © 2026
Design by Supafrank