Cybersecurity myths (5/5): being compliant is not being safe

Published on August 3, 20267 min read
Illustration: the head of an accounting firm reviews a file, between a "compliant" stamp and a switched-off alarm

Sophie B. runs an accounting firm in French-speaking Switzerland. Last month a client asked her, almost in passing: "You're compliant with data protection rules, right?" She said yes, relieved that she had updated her records register the year before. Then a quiet doubt caught up with her: what if "compliant" didn't mean "safe"? To close this series on cybersecurity myths, here are the last two false beliefs — the most reassuring on the surface, and therefore the riskiest.

Why these two cybersecurity myths are so expensive

The first eight myths in the series all circled the same reflex: "it only happens to other people." The last two are subtler, because they lean on something true — a step already taken — to justify stopping there.

The first is believing that being in order with the law equals being protected. In Switzerland, the nFADP — the revised Federal Act on Data Protection, in force since September 2023 — requires an SME that holds personal data to take "appropriate" security measures and to notify the federal authority (the FDPIC, Federal Data Protection and Information Commissioner) of a breach as soon as possible. If your clients operate in the European Union, the GDPR adds its own 72-hour notification deadline.

But a law describes a framework, not your technical posture on a given day. An up-to-date register and a well-written privacy policy do not block a booby-trapped email, do not switch on two-factor authentication (MFA — on top of the password, a second proof of identity, such as a code on your phone), and do not test your backups. Compliance and security are neighbouring but distinct efforts: one answers "are we meeting our obligations?", the other "what actually protects us if someone tries tonight?". You can tick every legal box and still be exposed because of software that was never updated, a shared password, or a colleague who was never trained. And compliance is a snapshot: it describes a situation on a date, while the threats keep evolving every week.

A telling example: an accounting firm can have a flawless processing register and, on the very same day, let several colleagues share one password to reach the accounting software. On paper, everything is neat; in practice, a single leaked login is enough to open the door to every client file. The legal document was never meant to prevent that — that is the job of concrete measures, the ones you don't write in a binder but switch on in the tools.

The second myth is even quieter: "we'll deal with it if it happens." That is betting that improvisation will do on the day. Yet improvisation is exactly what costs the most during an incident. For Sophie B., a client file locked by ransomware — malicious software that encrypts your files and demands a ransom — on a Friday evening is a cascade of questions with no prepared answer: who do we call first? Do we have a usable backup? Who tells the affected clients, and in what words? Do we have to notify the FDPIC, and within what deadline? Every minute spent working out who decides is a minute in which the problem grows and trust erodes. Incident response — the organised way of reacting when something goes wrong — is only worth anything if it is decided before the incident, not during it.

In plain terms, as Camille, our adviser, puts it: compliance and security answer to two different judges. The first reports to a regulator, on paper, on a given date. The second reports to an attacker, in real conditions, every day. A composed SME works on both at once, without believing that one excuses the other. It is also, increasingly, what your own clients look at: a partner who entrusts you with their data no longer only asks "are you compliant?", but "what have you actually put in place?".

What to take away

  • Being in order and being protected are not the same thing. The nFADP sets obligations; security is the concrete set of measures that hold when you are attacked. One does not buy the other.
  • Compliance is a photo, security is a film. An audit describes a moment; the threats do not stop the next day. What was "in order" in January may have a hole by June.
  • "We'll cope" is not a plan. What makes the difference on the day of an incident is not a talent for improvisation, but what was written down and tested calmly beforehand: who does what, who calls whom, which backup we restore.

Moves to put in place this week

1. Split "obligations" and "protections" on a single page

Take a sheet with two columns. On the left, what you do for the law: processing register, client information, contracts with your providers. On the right, what actually protects you: two-factor authentication switched on, backups tested, devices up to date, staff made aware. The exercise takes an hour and almost always reveals a shorter right-hand column than expected. That is where the real risk sits — not in the legal binder.

2. Write your incident "first half-hour"

Not a full crisis plan — just a one-page card, posted up and known to everyone. Three questions, three answers: who do we alert internally first (a named person, a number)? Who do we call outside (your IT provider, possibly your insurer)? And what must we not do in a panic (pay a ransom, switch machines off at random, wipe traces)? That prepared half-hour is worth more than any tool bought after the fact.

3. Run a restore test, just once

Having backups means nothing until you have checked that they actually restore. Pick an unimportant folder, ask your provider to recover it from the backup, and time it. If no one knows how, or if it takes two days, you have just learned something essential in calm conditions rather than under pressure on a Monday morning.

Where do you really stand?

These last two cybersecurity myths share one trait: they give the feeling that the necessary has been done, while a blind spot remains. The good news is that closing it does not require a big budget — especially in a structure like Sophie B.'s, with no in-house IT person: it requires an honest look at where you actually stand.

That is exactly what the Cyber Passport self-assessment is for. It certifies nothing and never declares you "compliant": it shows you, question by question, what belongs to your obligations, what belongs to your real protections, and where your organisation still relies on luck or habit. A clear starting point you can share with your clients and auditors. And to turn "we'll cope" into an actual plan, the "Incident response" blueprint lays out the steps, one by one.

Topics

  • cybersecurity myths
  • compliance
  • incident response
  • SME
  • Switzerland

Read next