One morning, Sophie B. opens an invoice from a supplier she has worked with for years. The logo is right, the tone is familiar, but the account number has changed — "new bank," the email explains. In a trustee firm that handles the banking details of hundreds of clients every day, a detail like that can shape a whole day, and sometimes far more.
The good news: there aren't fifty threats to master, just a small handful that keep coming back. Understanding them is already how you take back control.
Why an SME concentrates so many cyber threats
We tend to picture cyber threats targeting large corporations. It's the opposite. A Swiss SME is a target precisely because it is reachable: little or no in-house IT, tight budgets, and above all short decision chains where colleagues trust one another. For an attacker, that's an excellent effort-to-reward ratio — they don't need to crack a vault, just to exploit a moment of inattention.
A service business such as a trustee firm is especially exposed for a simple reason: it doesn't just hold its own money, it holds the financial and banking data of its clients. What makes it valuable also makes up its attack surface. An attacker who gets into its mailbox doesn't reach a single account, but a whole portfolio of potential payments and months of correspondence they can imitate perfectly.
Another aggravating factor is the belief, widespread in small companies, of "not being an interesting target." That very drop in vigilance is what makes SMEs valuable to attackers — they cast a wide net and automate, without picking victims one by one. In practice, an SME's cyber threats boil down to four families, described here without drama.
Phishing: the fake invoice almost paid
Phishing is receiving a message that imitates a trusted contact — a bank, a supplier, a public service — to push you into clicking, paying or handing over a password. Sophie B.'s message is a textbook example: nothing looks wrong, you're simply asked to do what you already do every day, but toward the wrong recipient.
By far the most common way in, it doesn't target a software flaw but a human reflex: routine and trust. You don't fend it off with a miracle tool, but with a habit — checking before you act.
CEO fraud: "the boss" asking for an urgent transfer
CEO fraud is a targeted variant of phishing: a message poses as a manager or a partner and demands an urgent, confidential transfer, "to be settled before tonight." In a small organisation where you personally know whoever signs the payments, social pressure does the rest: who wants to contradict their partner over a pressing deal?
The whole trap lies in the sense of urgency. A request that forbids checking — "don't tell anyone," "this is confidential," "it's for today" — should be exactly what triggers a check.
Ransomware: the Monday when everything is encrypted
Ransomware is malicious software that encrypts your files — makes them unreadable — then demands a ransom to give the access back. It often gets in through an attachment opened without a second thought, then spreads quietly before locking everything at once, usually at the worst moment.
For an SME, the stakes aren't only the ransom: it's the shutdown. No accounting, no email, no client files for days, right in the middle of a closing period. Real protection isn't paying — nothing guarantees you get your files back — but being able to restart from recent backups, provided they truly exist and have already been tested.
Data leaks: when a client file slips out
A data leak is the unwanted release of confidential information: a file sent to the wrong recipient, a hacked mailbox, a USB stick lost on a train. No sophisticated hacker required — one misdirected click is enough.
In Switzerland, this risk has a legal dimension. The nFADP, the federal data protection act in force since 2023, expects an SME to take "appropriate" security measures and to notify the federal authority (the FDPIC) of breaches likely to harm the people concerned. For a trustee firm bound by professional secrecy, losing a client's trust often weighs more than the incident itself.
Key takeaways
Three ideas beat a long list of fears.
First, most cyber threats don't target your machines but your habits: a click, a moment of trust, a rush. That's good news, because habits change without an IT budget.
Second, these threats overlap. The same verification reflex blocks the fake invoice, CEO fraud and a good share of password-theft attempts. So you make fast progress by acting on a few well-chosen points.
Third, in Switzerland, data protection isn't a comfort option: the nFADP makes it a leadership responsibility, on a par with keeping the books. No one expects an SME to become a fortress — only to take reasonable measures and be able to explain what it does with the trust placed in it.
Habits to put in place this week
1. Verify every money request through a known channel
Any change of bank details, any unusual or pressing transfer request, is checked by calling the person back on a number you already know — never the one in the message. This single reflex neutralises both the fake invoice and CEO fraud. Above an amount you set, require two approvals.
2. Turn on two-factor authentication wherever you can
Two-factor authentication (MFA) adds, on top of the password, a second proof — for example a code on your phone. Even if a password leaks, the account stays shut. Enable it first on email and on your business software: it's free and it's the measure with the biggest payoff.
3. Know where your data lives and check your backups
Take ten minutes to list where your sensitive information lives (email, accounting software, shared drives) and make sure a recent backup exists. Above all, check that it has already been restored at least once: an untested backup is an assumption, not a protection. The federal cybersecurity office (NCSC) publishes practical guidance for this.
Where do you really stand?
These habits sharply reduce an SME's exposure, but they don't tell you where, precisely, your weak points are. That's where a structured self-assessment helps: reviewing your real cyber threats question by question rather than acting on gut feeling.
Cyber Passport certifies nothing and won't declare you "secure." It shows you, area by area, where your organisation is solid and where it still rests on trust or habit — so you can then decide, with clear eyes, where to start.



