Business & Technology
UK online retail spending rises 10.5% in March
UK online retail spending rose 10.5% year on year in March as overall retail sales remained firm, according to figures cited by Parcelhero.
The delivery and retail analysis company said online sales values rose 2.4% from February, while total retail sales volumes increased 0.7% month on month. Over the first quarter, retail sales volumes were up 1.6% from the previous quarter.
The figures suggest a resilient consumer market at a time when there were concerns conflict involving Iran could weigh on household confidence and demand. The latest Office for National Statistics retail sales bulletin showed spending held up better than expected.
Some store-based categories also performed well. Textile, clothing and footwear retailers recorded a 1.2% rise in sales volumes as spring ranges reached shops.
David Jinks, head of consumer research at Parcelhero, said some of March’s strength was driven by fuel buying rather than broader discretionary spending.
“While there were understandable concerns that the Iran conflict, which started at the end of February, would impact consumer spending, ironically it helped drive up March’s result due to people stockpiling petrol. With automotive fuel sales stripped from the figures, March’s sales volumes were actually only 0.2% up overall.”
“What is in no doubt is that eCommerce did well. In terms of sales volumes, non-store retailers, the ONS category that is predominantly online sellers, reported volumes up 1.4% in March and 3.7% in Q1. March non-store sales volumes reached their highest level since February 2022.”
“The most spectacular results of all were for eCommerce sales values, the amount spent online. Online sales values rose by 2.4% in March over February and by 10.5% year on year, comparing March 2026 with March 2025.”
“Of course, monthly retail figures are notoriously volatile, which is why the ONS is increasingly concentrating on three-month figures. Q1 online sales values rose 2.5% compared with the previous quarter and, saving the best figures till last, 11.7% year on year against Q1 2025.”
“We’ll end with a snapshot of retail’s overall health. Total spend, the sum of in-store and online sales, rose 1.8% in March and online sales claimed 28.7% of the entire retail market. It will be fascinating to see if this surprisingly strong set of retail results holds up in April as the Iran conflict drags on.”
“Ultimately, however fickle or strong key retail periods of the year prove to be, stores with both a High Street and online offering are the most protected against unexpected events. Parcelhero’s new report, ‘2030: The High Street Fights Back?’, has just been launched as the sequel to its 2016 publication, ‘2030: The Death of the High Street’. The update examines the impact of eCommerce and events such as the pandemic on the High Street. It concludes that the High Street may not have reached a dead end by 2030 but, in this new age of retail, it will have arrived at its biggest crossroads,” Jinks said.
Online share
Beyond the monthly rise, the quarterly numbers suggest internet shopping continued to take a larger share of household spending. Online sales accounted for 28.7% of the total retail market in March.
That matters for retailers balancing store estates with digital operations. The data suggests consumers continued to direct a substantial share of spending online even as physical categories such as clothing improved.
The non-store category, used by the ONS to capture predominantly online sellers, reported sales volumes up 1.4% in March and 3.7% across the first quarter. March marked the highest level for non-store sales volumes since February 2022.
Mixed picture
The broader retail picture was less dramatic once fuel was excluded. Underlying sales volumes would have shown only a 0.2% monthly rise without the boost from automotive fuel purchases.
That highlights the tension within the numbers. Headline retail growth remained positive, but part of the increase appears to have come from precautionary buying linked to geopolitical uncertainty rather than a broad-based surge in discretionary consumer demand.
Even so, online spending values outpaced the rest of the market. First-quarter online sales values rose 2.5% from the previous quarter and were 11.7% higher than the same period a year earlier.
The contrast between sales values and sales volumes is also notable. Higher values can reflect consumers buying more items, spending more per purchase, or changes in product mix, while volume figures track the amount bought more directly.
For retailers, the data suggests digital channels remained a source of growth during a period of external uncertainty. It also underlines the uneven nature of consumer spending, with some sectors benefiting from seasonal demand and others from short-term reactions to international events.
March’s results combined several themes at once: a resilient headline retail market, a stronger showing for online spending, and a more modest underlying picture once fuel effects are removed. Online sales claimed 28.7% of the retail market.
Business & Technology
Work phones fuel illegal streaming cyber risk study
BeStreamWise has published research on the use of work phones for illegal streaming in the UK. It found that 68% of people who stream content illegally use a company smartphone for that activity.
The findings highlight a workplace cybersecurity issue linked to unofficial streaming sites and apps. Among illegal streamers aged 18 to 24, 71% said they had used a work smartphone to access sport, films or television from unofficial sources, compared with 62% of those aged 45 to 54.
More than half of illegal streamers using work smartphones, 56%, said their device had been infected with malware in the past 12 months. That compares with a national average of 18%, according to the research.
Some respondents also reported repeated problems. More than a quarter, 27%, said they had experienced malware infections multiple times during the past year.
Phishing was another risk highlighted in the study. One in five illegal streamers who use work devices, 20%, said they had received phishing attempts involving requests for passwords and account login data, compared with 8% of illegal streamers overall.
The survey also suggested that awareness of those risks remains low among some workers. Only 34% of respondents who use work devices for illegal streaming said they knew illegal streaming sites can infect devices with malware, compared with 42% of the public overall.
BeStreamWise is backed by government bodies and media and sports organisations including the Premier League, BBC, ITV, Sky and FACT. It describes itself as a cross-industry initiative focused on raising awareness of the risks linked to illegal streaming.
Business exposure
The figures add to a broader picture of cyber threats facing employers. Government data cited alongside the study shows phishing attacks are the most common type of cyber breach reported by UK businesses, affecting 38% of companies.
The same official figures put the average cost of a significant cyber attack at £195,000 for each affected business. That gives fresh relevance to employee behaviour on corporate devices, particularly when those devices are used to access unauthorised services outside normal company controls.
Illegal streaming has often been treated as a consumer issue linked to broadcasting rights and lost subscription revenue. The new data reframes it by focusing on the risks to company systems, internal networks and commercial information when workers use employer-issued phones to visit unofficial services.
Younger workers appeared more likely than older groups to use work devices in this way, though the practice was not limited to one age bracket. The gap between respondents aged 18 to 24 and those aged 45 to 54 was narrower than might be expected, suggesting the behaviour is spread across the workforce rather than confined to the youngest employees.
That pattern may complicate any response from employers. Companies that rely on staff policies alone may struggle if workers do not associate illegal streaming with cyber risk, especially when the activity takes place on smartphones that move in and out of corporate environments more easily than office-based desktop systems.
Expert warning
The research was accompanied by comment from independent cybersecurity expert James Bore.
“These findings will be a huge concern for business leaders looking to keep their networks and data safe. Illegal streaming sites and apps sit outside the security checks that legitimate platforms go through, so the risk of encountering malware is much higher. Installing unauthorised software on work devices carries the same risks as on personal devices, particularly if companies do not have up-to-date antivirus software installed. Malware can be an entry point into company networks where sensitive commercial and financial information is stored,” said James Bore, Independent Cybersecurity Expert.
The research was based on a survey of 2,000 people in the UK. Its central finding is that a large share of people who already access pirated content are doing so on employer-provided smartphones, creating a route by which malware and phishing attacks can reach business systems.
For employers, the issue goes beyond viewing habits to basic cyber hygiene. The data suggests that personal choices made on work devices can expose wider company infrastructure to threats that begin with a film, match or television stream.
Business & Technology
Phoenix Software staff win Broadcom VCF Knight status
JOSEPH GABRIEL LAGONSIN
News Editor
Phoenix Software has announced that two employees have achieved Broadcom VCF Knight status, Broadcom’s highest recognition for partner professionals.
Infrastructure Practise Lead Richard Worth and Senior Technical Consultant Robert Dent both received the Broadcom VCF Knight – Storage certification, recognising expertise in VMware Cloud Foundation-related storage.
The achievement strengthens Phoenix’s position within Broadcom’s partner network, where it holds UK Pinnacle and Expert Advantage status. It also reflects continued investment by the York-based business in technical staff with specialist VMware expertise.
Broadcom’s Knight programme identifies partner specialists with experience in the architecture, design, implementation and support of Broadcom technologies. In this case, the focus was on VMware Cloud Foundation and related storage work.
The process involves several stages rather than a single exam. Candidates must pass multiple advanced technical tests, submit evidence of customer designs, deliver a live technical demonstration to a Broadcom sponsor, and then undergo nomination and review by a Broadcom panel.
The certification typically takes several months to complete and requires periodic renewal, making it a relatively rare qualification within the VMware and Broadcom partner ecosystem.
Worth has worked in IT for more than 25 years, including nine at Phoenix, where he leads the infrastructure practice. His background spans networking, storage and virtualisation, all closely tied to the technologies covered by VMware Cloud Foundation.
Dent has worked with VMware technologies for more than 20 years, beginning during an early IT apprenticeship and later implementing virtualisation environments at the University of Hull. His experience also includes servers, storage, NetApp and vSAN, and he gained his first VMware certification while working at the university.
Technical route
The certifications come as many customers reassess their VMware environments following Broadcom’s acquisition of the software business. That has increased scrutiny on partners able to demonstrate deep product knowledge and delivery experience.
Both men completed the same rigorous process to secure the designation, which Phoenix described as evidence of its ability to support organisations running complex virtualised infrastructure.
Worth said: “The difference with the Knight programme is that it recognises not just what you know, but what you’ve actually delivered. It reflects real-world experience – designing, implementing, and solving problems for customers. For me, VCF brings together everything we do across networking, storage, and virtualisation into one cohesive platform.”
Dent linked the certification to customer expectations around complex infrastructure projects.
Dent said: “This is one of the highest standards a consultant can achieve. It’s exactly the level of expertise customers expect when they’re investing in complex platforms like VMware Cloud Foundation. For me, it’s also about continuing to learn and building environments where the wider team can develop their skills.”
Phoenix operates across software licensing, hardware, software asset management and managed IT services, and has been in the market for more than 30 years. It works with public and private sector customers on IT strategy, infrastructure design, deployment and software management.
The latest certifications suggest the company is seeking to deepen specialist skills in core infrastructure areas as customers continue to assess how they manage virtualisation, storage and networking in consolidated cloud environments.
Business & Technology
Connected building systems pose growing cyber risk
Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.
The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.
Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.
David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.
“Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease. As today’s digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network,” Robinson said.
Attack surface
Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.
In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.
He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.
Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.
Remote access
Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.
Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.
The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.
Network separation
Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.
This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.
Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.
Strategic priority
Robinson’s final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation’s wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.
That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation’s connected estate and can affect both physical security and business continuity if disrupted.
Restore Information Management is one of the UK’s larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. “Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset,” Robinson said.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
