SME cybersecurity: the 3 foundations too often neglected

Published on February 2, 20267 min read
Illustration: a small-business owner facing a security wall whose foundations are still to be laid

Sophie B. runs a small accounting firm in French-speaking Switzerland. Last month her IT provider offered her a shiny new security tool, four-figure quote in hand, and she signed, feeling reassured. Then one evening a doubt caught up with her: does she even know which data she is protecting, and where it actually lives?

Why cybersecurity foundations matter more than tools

Many SME owners dodge that question. You buy a firewall, an antivirus, sometimes a monitoring service, and you tell yourself you have “done cybersecurity”. It feels reassuring, it is tangible, it fits into a budget. But without a few foundations laid first, those tools protect a house whose front door will not lock.

And an accounting firm does not handle trivial data. Bookkeeping, payroll, tax filings, the bank details of dozens of client SMEs: this is the heart of professional confidentiality, and the first thing an attacker looks to sell or hold hostage. Against that, the most common mistake is not the lack of a sophisticated tool — it is failing to lay the foundations that give the tool any meaning.

In plain terms: a powerful security product bolted onto an organisation that shares passwords, never tests its backups and has never taken stock of its data is a top-of-the-range alarm on a door left wide open. Camille, our cyber adviser, puts it this way: “Technology amplifies what is already there. When the foundations are missing, mostly it amplifies the mess.”

The nFADP — Switzerland's revised Federal Act on Data Protection, in force since September 2023 — does not, in fact, require you to buy any particular product. It expects any company holding personal data to provide “appropriate” security: proportionate to the risk, thought through, and explainable. In other words, a process, not an invoice. The Swiss National Cyber Security Centre (NCSC) points the same way: its advice to SMEs always starts with basic hygiene, never with a miracle tool.

These foundations rest on three pillars, almost always neglected in the same order: know what you are protecting, keep the basics up over time, and bring your people on board. None of the three needs a big budget. All three call for something technology cannot supply: clarity about your own organisation.

What to remember

  • A tool never makes up for a missing foundation. Investing in advanced monitoring before securing access and backups is putting the cart before the horse — and often paying twice: for the tool, then for the damage it did not prevent.
  • The “appropriate” security the nFADP expects is a process, not a purchase. It is built with simple, repeated actions and a clear view of what you hold. A small, well-organised firm is better protected than a large, poorly kept one.
  • The decisive link is still human. The vast majority of incidents start with a click, a reused password or an attachment opened too fast — not with an exotic flaw only an expert could exploit. That is good news: what depends on everyday habits can be fixed without heavy investment.

The steps to put in place this week

Three steps, one per foundation. They do not replace a full roadmap, but they move your SME from “we hope it holds” to “we know where we stand”.

1. Take stock of your data

Before protecting, you have to know what to protect. Take an hour to list, in black and white, the most sensitive data you hold (payroll, tax data, your clients' bank details), where it really lives (your accounting software, your mailbox, a shared drive, an employee's USB stick?) and who has access. This simple inventory almost always surfaces the awkward obvious: sensitive files sitting where no one watches them any more, and former staff who may still have an active account. It is the first step of any serious approach — and, concretely, the starting point of a self-assessment. Until you know what you hold and where, you can neither protect it nor prove to a client that you protect it properly.

2. Keep the basics up over time

Three habits are enough to cover the essentials, provided you maintain them:

  • Two-factor authentication (called MFA or 2FA). On top of the password, a second proof — usually a code on your phone — blocks the vast majority of account thefts, even when the password has leaked. Turn it on everywhere you can, starting with your work mailbox, which is the key to everything else.
  • Updates. Software you do not update is a door the vendor took care to close but that you leave open. Enable automatic updates on computers, phones and business applications.
  • Tested backups. Having a backup is useless if you have never checked that you can restore it. Once a quarter, ask to recover yesterday's file: the day an incident strikes, you will know whether your safety net truly exists or only exists on paper.

These are basics, not a detailed plan. Rolling them out properly — exact scope, exceptions, break-glass accounts, cadence — belongs to a dedicated roadmap. But these three actions alone already change an SME's exposure radically.

3. Make your people the first line

The best tool in the world will not save a rushed employee who clicks a fake invoice on a Friday at 5 pm. Phishing — those fraudulent emails that imitate a supplier, a bank or a client to extract a password or trigger a payment — remains the number-one way in for SMEs.

The good news: you do not train your teams with a one-hour meeting once a year, forgotten the next day. You install the reflex in small touches — a two-minute reminder in a team meeting, a real trap email discussed together, a simple rule everyone knows (“the slightest doubt about a payment and you do not reply: you pick up the phone and call the number you already know”). Repeated over a few weeks, that reflex becomes a culture, and that culture is worth more than any licence. In an accounting firm, where everyone handles client data every day, it is probably the foundation that pays off most for the least effort.

Where do you really stand?

These three foundations — know your data, keep the basics, bring your people on board — cost almost nothing. What is usually missing is not budget: it is an honest view of where you are solid and where you still rely on trust and habit.

That is exactly what a Cyber Passport self-assessment structures. It certifies nothing and sells you no extra tool: question by question, it shows you which foundations are genuinely in place and which still rest on sand — so that your next investment finally reinforces something solid, rather than decorating an open door.

Topics

  • foundations
  • SME
  • Switzerland
  • nFADP
  • self-assessment

Read next