Cybersecurity: your SME's business continuity is manageable

Published on May 4, 20269 min read
A small accountancy office keeps running during a minor IT outage, the manager working on a backup laptop

One Monday morning, Sophie B. arrives at the accounting firm and the bookkeeping software refuses to open. One client's payroll has to go out that afternoon; another is waiting on a VAT filing. During that hour of waiting, she puts words to something obvious for the first time: the whole firm rests on a handful of tools that have to work — and on the trust of clients who hand her their most sensitive figures.

That morning it was only a botched update. But the question it leaves behind is the right one: for a small business, what happens on the day the tools stop responding? Cybersecurity is not, first and foremost, a technical matter. It is a matter of business continuity and trust. And, contrary to what people often assume, it is a subject you can tackle in small steps.

Cybersecurity is first a question of business continuity

Let's be plain. Business continuity is simply your ability to keep working — or to bounce back quickly — when something breaks: an outage, a lockout, a human error, a security incident. It is not an IT concept. It answers a very concrete question: "If that tool stops tomorrow morning, can I still serve my clients this afternoon?"

For an accounting firm the answer is vital, because the firm does not sell a product you can remake later. It sells two things: reliability and confidentiality. A client hands you their payroll, their accounts, their tax data, because they trust that you will deliver on time and that their figures will not end up in the wild. The day a system locks up — or worse, data leaks — it is not merely a technical nuisance: it is the promise made to the client that cracks.

The point that is often missed is that most interruptions are nothing dramatic. It is not necessarily a movie-style attack. It is a workstation encrypted by malicious software (what's called ransomware — a program that locks your files and demands a ransom), a mailbox broken into because a password was lying around, a backup everyone believed was fine that then fails to restore. In other words: ordinary situations that only turn serious when a few simple habits have not been put in place.

Many SME owners assume that "IT is something the provider handles." Providers often do good work on what they are asked to do — but they act on request; they are not there to decide, in your place, what matters to your business. Continuity remains an owner's decision: you are the one who knows that the payroll on the 25th cannot wait.

There is a second, quieter dimension that is just as decisive: trust. A client who learns their firm lost access to its files for three days does not remember the technical cause — they remember that they could not count on you. And a client who doubts the security of their data does not always say so: they simply leave at renewal, without a word. Conversely, a small business able to answer calmly to "what happens if an incident occurs?" reassures and stands out. Seen this way, cybersecurity is not a defensive cost: it is a mark of seriousness.

What to take away

Three ideas are enough to change how you see the subject.

Cyber is not an IT topic, it is a topic of continuity and trust. The real question is not "am I at the cutting edge of technology?" but "does my business hold up if a tool goes down, and can my clients keep trusting me?". Framed this way, the subject becomes yours again, not a specialist's.

Most risks shrink with simple habits. We picture heavy budgets and big projects. In practice, the measures that best protect a small business are inexpensive and mostly a matter of habit: knowing what your activity depends on, protecting your access, checking your backups. It is manageable, and it does not require being an IT expert.

In Switzerland, the law expects proportionate, not perfect. The nFADP — the revised Swiss Federal Act on Data Protection, in force since September 2023 — requires any organisation holding personal data to take "appropriate" security measures. The word matters: appropriate to your size and your means. No one expects a small firm to run a bank's setup. What is expected is solid basics and conscious choices.

Habits to put in place this week

Here is where to start, with no special budget and no technical skill. Three habits, doable in a few hours spread across the week.

1. Know what your business depends on

Take a sheet of paper and list what the firm cannot run without: the bookkeeping software, email, access to client files, the payroll system. For each, note two things: where the data lives (on a Swiss server? with a vendor? on a workstation?) and who to call if it goes down. This list fits on one page. It is worth its weight in gold on the day of an incident, because it turns panic into a sequence of known steps. It is also the foundation of everything that follows: you only protect well what you have first made visible.

2. Protect your access with two-factor authentication

Two-factor authentication (often called MFA) means requiring, on top of the password, a second proof — usually a code or a confirmation on your phone. In practice, even if a password is guessed or stolen, the door stays shut. Turn it on first for your email and your business software, where client data flows. Most professional services such as Microsoft 365 offer it at no extra cost: it is a matter of a setting, not an investment. Ask your provider this week, and make it the rule for everyone, partners included.

3. Check that you could actually restart

"We have backups" is a reassuring sentence — and not enough. A backup is only worth something if it restores. The concrete habit: ask for a real restore test, meaning that a recent file is actually recovered from the backup, to confirm it comes back and comes back complete. Write down the date of the test. If no one can tell you when the last restore was attempted, you have just identified your most important weak spot — and the easiest to fix.

Where do you really stand?

These three habits get you moving, but they do not answer the deeper question: across your whole business, where are you solid, and where are you still relying on luck or on interpersonal trust? That is exactly what a Cyber Passport self-assessment does. It certifies nothing and promises no compliance: it shows you, question by question, the real state of your business continuity and your data protection, then helps you set priorities. You end up with a clear picture you can also share with a client or an auditor who asks "how do you protect my data?".

Getting started does not mean fixing everything at once. It means knowing where you stand, and moving in the right order. It is manageable — here is the starting point.

Topics

  • business continuity
  • SME
  • Switzerland
  • client trust
  • cyber resilience

Read next

A workshop manager facing a halted production line, a rising cost meter beside a laptop
Product & methodApr 27, 20267 min read

What a cyberattack really costs a manufacturing SME

Production downtime, recovery, customers who start to doubt: the real cost items of a cyberattack in a manufacturing SME, and where to begin without being a specialist.