One Tuesday morning, Sophie B. receives an email that looks like it comes from a regular supplier: new bank details, to be applied before the next payment. Nothing alarming — a busy colleague could have approved it without a second thought. In her accounting firm, as in many Swiss SMEs, two reassuring convictions stand in for a security policy: “my staff know how to pay attention” and “we have backups.” These are exactly the two cybersecurity myths that leave the door ajar.
Two cybersecurity myths that show up in every SME
Sophie B. runs an accounting firm: bookkeeping, payroll and tax data for dozens of clients pass through her team’s inboxes every day. Like many owners, she reassures herself with two common-sense ideas. The first: “my people are serious, they’ll spot a scam.” The second: “we run a backup, we’re covered.”
The problem isn’t that these statements are false. It’s that they describe an intention, not a system. An intention holds up neither against a well-crafted trap email on a closing-day deadline, nor against a drive that fails on a Friday evening. Let’s look at these two beliefs closely, without dramatising: the point isn’t to scare you, but to turn two wishes into two habits that actually hold.
“My team knows how to pay attention”
Let’s clear up a misunderstanding first: getting caught isn’t a matter of intelligence. Phishing attacks (an email, text or call that imitates a trusted third party to make you click, pay or hand over a password) don’t target the gullible. They target context. And an accounting firm offers the ideal context: invoices arriving non-stop, tax deadlines, changes of bank details that are part of the daily routine.
The most conscientious employee clicks because the message lands at the right moment, in the right tone, on the right file. “Paying attention” assumes you’re alert all the time, in the same way, for everyone. That’s not a process, it’s a state of mind — and a state of mind gets tired, distracted, goes on holiday.
For an accounting firm the stakes are specific: what flows through those inboxes are the accounts, payroll and tax records of clients who trust you. A hijacked account doesn’t just hit your organisation — it breaks the confidentiality your clients handed you. Sophie B.’s real fear isn’t the IT outage; it’s the phone call where she has to tell a client their data has leaked.
Awareness still matters: a team that knows what a fraud attempt looks like spots more of them. But it wears off if you never revisit it, and above all it shouldn’t be the only line of defence. Behind the human, you need a technical safety net: decent spam filtering, and multi-factor authentication (“MFA” — on top of the password, a second proof, such as a code on your phone) on sensitive accounts. The Swiss National Cyber Security Centre (NCSC) — the reference authority on the matter — precisely recommends combining behaviour with technical measures rather than resting everything on each person’s vigilance.
“A monthly backup is enough”
The second myth is more insidious, because it sounds responsible. “We run backups”: good. But two questions hide behind that sentence, and they’re the ones that count.
First, how often? A backup (a copy of your data kept separately) made once a month means an incident can set you back four weeks. For an accounting firm mid-closing, that’s a month of entries, payroll and filings to re-enter — in the best case.
Second, is that copy actually recoverable? A backup you’ve never tested through a restore (the operation of bringing the data back into service from the copy) is a backup you don’t know works. And if it stays permanently connected to the network, ransomware (software that encrypts your files and demands a ransom to make them readable again) will encrypt it along with everything else. You think you have a parachute; it’s inside the burning plane.
So the right question isn’t “do we back up?” but “how much work can I afford to lose, and have I ever tried to bring it all back?” The nFADP (Switzerland’s data protection act) expects an SME holding client data to maintain “appropriate” security — which includes the ability to recover that data after an incident.
What to remember
- Security is a process, not an intention. “Paying attention” and “having backups” only protect you if they translate into repeatable, verified habits.
- The human is one layer among several, not the only wall. You back up your team’s vigilance with a technical net — filtering, multi-factor authentication — so a second of inattention doesn’t cost everything.
- A backup only counts if it’s recent, tested and out of reach. A copy never restored, or permanently wired to the network, is a false sense of security.
Steps to put in place this week
1. Turn “paying attention” into a shared reflex
Set one simple rule everyone knows: any change of bank details or any unusual payment request is verified by calling back a number already on file — never the contact given in the message. Remind the team of it in five minutes at a team check-in. It’s free, and it lifts the decision off the shoulders of a single rushed person.
2. Check your backups really exist — and test a restore
Ask three questions: is my data copied at least daily, is one copy kept offline (disconnected from the network), and have I ever managed to restore a file? Run the test this week on a single document: if it comes back intact, you know the net holds. If it doesn’t, you’ve just avoided a very bad surprise.
3. Add a technical net: multi-factor authentication on sensitive accounts
Turn on multi-factor authentication (MFA) for mailboxes and for access to the tools holding client data. On an office suite like Microsoft 365, this can be done without a provider and without budget. A stolen password is then no longer enough to open the door.
Where do you really stand?
These three steps touch on awareness and basic hygiene — two areas the Cyber Passport self-assessment reviews. It certifies nothing: question by question, it shows you where your organisation is solid and where it still rests on trust and “we’ve always done it this way.” It’s often while answering these questions that these cybersecurity myths become visible — and therefore fixable.
This article is the second step in a five-part series. To go further on the first of these two angles, our “Team awareness” blueprint lays out the full plan: short formats, an annual rhythm, progress measurement and onboarding for newcomers.



