One Monday morning, Sophie B. receives a message from a "supplier" casually announcing a change of bank details for the next invoice. The logo looks right, the tone is polite, the request seems ordinary. That day, it wasn't a firewall that protected her accountancy firm: it was a colleague who picked up the phone to check with the real contact. In an SME, cybersecurity is everyone's business long before it is a matter of IT.
Why cybersecurity is everyone's business first
We tend to picture security as a technical wall: a firewall, antivirus software, an outside provider who "handles the IT". Those tools matter, but they protect something attackers almost never target first — the machines. What they target is a person, a moment of inattention, a habit.
Most attacks that hit a Swiss SME start with a perfectly ordinary human action: clicking a link, opening an attachment, approving a payment, replying to an urgent request. This is what we call social engineering: instead of forcing a technical door, the attacker manipulates trust, urgency or routine to get what they want. Its most common form is phishing — a message posing as a legitimate contact (a supplier, a bank, a colleague, the boss) to make you act quickly and without thinking.
In an accountancy firm, this reality is especially sensitive. The data flowing through every day — bookkeeping, payroll, tax and banking details for dozens of clients — is priceless to a fraudster. And it doesn't pass only through the IT person's computer: it passes through the front desk's inbox, the accountant's shared spreadsheet, the partner's phone as they approve a payment between two meetings. Every role handles sensitive information, so every role is part of the defence.
The best tool in the world does not replace that human reflex. A well-written phishing message slips past the filters if no one, at the end of the chain, takes a second to doubt. Conversely, a team that knows when to hesitate catches what technology lets through. That is why security rests first on two very untechnical things: everyone's day-to-day behaviour, and governance — the simple decisions leadership makes to organise who does what, and under which rules.
This shift in perspective changes everything for a small organisation. As long as you see security as an IT problem, you delegate it to a provider and forget about it — until the day something goes wrong. As soon as you see it as an organisational problem, it enters the space a management team knows how to handle: setting rules, talking to the team, deciding who approves what. An SME doesn't need an in-house expert to make progress; it needs a few good habits to become the shared norm. That is reassuring, because it puts security within everyone's reach — no jargon, no heavy investment.
Key takeaways
Technology is necessary, but not enough. A firewall and antivirus do their part, but they don't decide on behalf of a colleague in a hurry. An SME's real security plays out in a series of small human decisions, every day, at every level.
Responsibility is shared — and that's good news. If security were solely the provider's job, an SME with no internal IT team would be helpless. It isn't: the most effective measures (check, talk, report) require neither budget nor technical skill. They require a collective habit, driven by leadership.
In Switzerland, the law expects exactly this. The nFADP — the Federal Act on Data Protection, in force since September 2023 — requires any company holding personal data to take "appropriate" security measures. These are as much organisational (clear rules, aware staff) as technical. In other words, the law itself treats cybersecurity as a matter of governance, not IT alone. On the practical side, the National Cyber Security Centre (NCSC) regularly publishes advice for SMEs — and it, too, is as much about human reflexes as technical settings.
Habits to put in place this week
None of these actions requires a budget, software or a provider's help. They require a management decision and a conversation with the team.
1. Name a point of contact and say it out loud
Appoint someone — not necessarily the most technical person — as the "security" point of contact. Their role isn't to know everything, but to be the one people turn to when in doubt: a strange message, a call that feels fake, a USB stick found in the car park. Announce it to the whole team. Simply knowing who to ask turns an isolated doubt into a collective reflex. It's the first act of governance, and it's free.
2. Set the rule "I verify on another channel"
Any sensitive request received in writing — a change of bank details, an unusual transfer, an urgent request to send a confidential document — is verified through a second channel that you choose, not the sender. You hang up and call the known number; you don't reply to the email, you phone. This rule fits in one sentence, applies to everyone, and defuses most fraud that relies on urgency. It's exactly the reflex that saved Sophie B.'s firm.
3. Make reporting a reflex, never a fault
Security's worst enemy isn't the mistake: it's the silence that follows it. A colleague who clicked a bad link and says so within the minute lets you react; one who fears being blamed lets the problem grow all weekend. Say clearly, once, that reporting a mistake is a good move and not a blunder to hide. That sentence, spoken by leadership, is worth more than many tools. To anchor it, agree on a simple channel — a quick word, a message to the point of contact — and always thank whoever reports, even when the alert turns out to be harmless. That's how a reflex takes hold: by making it comfortable.
Where do you really stand?
These three habits belong to awareness and governance — two areas where you often don't know where you stand until you've asked the right questions. That is exactly what the Cyber Passport self-assessment offers: it certifies nothing and issues no label; it shows you, question by question, where your organisation is solid and where it still rests on nothing but everyone's goodwill.
Because cybersecurity will always be everyone's business, the real starting point isn't buying one more tool, but making your blind spots visible. To go further and build a concrete awareness plan suited to a Swiss SME, our dedicated blueprint gives you the step-by-step path.



