IT Infrastructure is the hidden carbon culprit in the office and SMEs must change

Data centre with server racks and green icons representing a move to sustainability

Supply chain pressure, upcoming ESG regulation, and energy price volatility are forcing SMEs to prioritise IT sustainability, whether they’re ready or not. 

Sustainability is no longer a ‘nice to have’, it’s a business-critical necessity. From supply chain expectations to upcoming ESG reporting requirements, IT infrastructure is fast becoming a business-critical issue, yet many smaller organisations remain unprepared.  

With the UK legally committed to hitting net zero by 2050, initiatives like the SME Climate Hub are calling on smaller businesses to halve emissions by 2030 and report progress annually. The British Business Bank has already supported over £12.5 billion in funding to help smaller firms adopt greener technologies and improve energy efficiency, creating a clear expectation that businesses will need to demonstrate measurable emissions reductions. 

“There’s a misconception that sustainability in IT is only relevant to large businesses but SMEs are now facing increasing pressure, whether that’s by clients, regulators, partners, or their own energy bills, to green their IT operations.” said Richard Puckey, Head of Compliance at Espria

“Pressure is coming from all sides; supply chain partners are demanding more transparency, and regulatory frameworks like the UK’s Sustainability Reporting Standards and the EU’s Corporate Sustainability Reporting Directive are beginning to filter through, setting new expectations for smaller businesses. 

“Even energy price volatility is forcing SMEs to look at how their IT choices effect costs and carbon footprint. IT infrastructure is often the silent carbon culprit in the office, and it’s time we started treating it as such.” 

By managing hardware lifecycles and choosing remanufactured devices, Puckey believes that SMEs have practical options that can reduce emissions without compromising their IT operations. 

“One of the most overlooked issues is the environmental footprint of hardware refresh cycles. Regular upgrades and poor disposal practices are driving up e-waste, with SMEs having little visibility into the lifecycle footprint of their devices. 

“When it’s time to part ways with your IT equipment, businesses need to ensure that it’s disposed of in an environmentally responsible way. Recycling end-of-life devices minimises e-waste especially where hardware can be re-purposed thus contributing to saving carbon emissions and reducing landfill waste. 

“Beyond recycling, SMEs should consider opting for refurbished or remanufactured IT hardware options instead of always buying new. Compared to manufacturing new units, high-quality remanufactured devices from certified providers not only costs less, but also dramatically reduces emissions since the materials from the original manufacturing process are reused. For SMEs with tight budgets, refurbished IT can meet spend and performance requirements while supporting sustainability goals.” 

The same principle of avoiding waste in hardware also applies to software and infrastructure, where inefficiencies can quietly drive up both energy use and costs. 

“Physical servers can be a source of inefficiency for many SMEs, taking up space, requiring energy-intensive cooling, and often running below capacity. This results in wasted disk space, higher operating costs, and unnecessary emissions. By migrating to the cloud, businesses can store and access data in an eco-friendlier and more cost-effective way that suits businesses whether they work on premises or across hybrid work settings. 

“But it’s not just hardware, software renewals and licensing can also contribute to carbon footprints. Many SMEs don’t realise they are paying for unused or under-used licenses and software. This “shelfware” still requires maintenance, updates and backups which only contribute to unnecessary energy usage. 

“Conducting regular audits, negotiating contracts, and terminating auto-renewals can deliver savings and reduce environmental impact. This is increasingly important as expectations grow around carbon disclosure and Scope 3 emissions. 

Puckey concludes, “In today’s market, IT infrastructure is the silent carbon culprit in the office, and it’s time we started treating it as such. For SMEs, every decision around hardware, software and infrastructure has an environmental impact that can be reduced and mitigated. From opting for remanufactured devices to auditing software usage and moving servers to the cloud, IT leaders can save money and make an immediate positive impact on the environment.” 

What’s in this article

    You may be interested in

    Office printer connected to a business network, highlighting the cybersecurity risks of unsecured printers and potential access points for cybercriminals.

    Is Your Office Printer a Way In for Cybercriminals?

    Most small businesses think of cyber security as a laptop problem, a server problem, or an email problem. The office printer rarely gets a mention, yet it is connected to your network, holds a hard drive, and processes some of the most sensitive documents in the business, from invoices to HR letters and client contracts. However, it is important to realise that office printer vulnerabilities can be exploited by cybercriminals, potentially leading to cyber attacks. A modern multifunction printer is a computer. It has an operating system, a network connection, often Wi-Fi, and increasingly a…

    Read the article

    cyber resilience act

    The Cyber Resilience Act: what it means for your business

    By Stephen Cook From 11th September 2026, a new EU regulation starts changing how connected products and software are built, sold and supported – and UK businesses trading into Europe are firmly in scope [1] [2]. Here is what the Cyber Resilience Act actually requires, why it matters beyond the compliance paperwork, and how Espria helps clients meet it.  What is the Cyber Resilience Act?  The Cyber Resilience Act (CRA) is an EU regulation – Regulation (EU) 2024/2847 – that sets mandatory cybersecurity requirements for “products with digital elements.” In practice, this covers hardware and software that can connect to a device or network: IoT devices,…

    Read the article

    The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste

    Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…

    Read the article

    Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer

    Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough. The Gap Between Confidence and Reality Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident. The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services…

    Read the article

    Integration of Sophos and Microsoft for enhanced threat intelligence

    Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations

    For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…

    Read the article

    Checklist marked passed next to cracked cyber shield over network, illustrating compliance vs cyber resilience.

    Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan

    Moving from box‑ticking compliance to real‑world cyber readiness  Written by Richard Puckey  Cyber security has a confidence problem  For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure.  The problem? Cyber threats don’t operate on an annual cycle.  The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…

    Read the article