Cybersecurity myths: two beliefs that expose your SME (1/5)

Published on July 6, 20267 min read
Illustration: a Swiss SME facing common cybersecurity myths, caught between a false sense of security and real threats.

"Honestly, who would go after a firm like ours?" Sophie B., managing partner of an accounting firm in French-speaking Switzerland, genuinely believed it — until the morning a client simply asked her how she protected their data. That day, two cybersecurity myths were still doing the job of a security strategy in her office.

You hear these beliefs in almost every Swiss SME. They are not a sign of negligence: they simply sound like common sense, and that is exactly what makes them effective. This five-part series reviews ten myths that weaken the security of smaller companies. This first part debunks two of them — the most widespread, and probably the most expensive.

Two cybersecurity myths that expose SMEs

A small business does not get hacked because it is famous. It gets caught because a door was left open. Here are the two lines of reasoning that most often leave that door ajar.

"We're too small to interest a hacker"

This is the most reassuring idea — and the most misleading. It rests on an outdated picture of the attacker: someone who patiently picks a target and only goes after large groups. Reality is more mundane. Most attacks today are automated: programs constantly scan the internet for known weaknesses, without caring about the size or sector of the company behind them. A poorly updated piece of software, a badly configured access point, and the program slips in — usually without any human ever having "chosen" you.

Call it the illusion of invisibility: believing that being low-profile in the market means being invisible online. But in cyberspace, anything connected is visible. Staying under the radar protects you from nothing; it merely delays the moment you discover you were exposed.

For an accounting firm, this myth is all the more risky because the office concentrates exactly what has value: salaries, tax records, banking details of dozens of client SMEs. It is not Sophie B.'s reputation that interests an attacker — it is that data, and the leverage it represents. Ransomware (software that encrypts your files and demands a ransom to make them readable again) does not need to know who you are to paralyse your business on a Monday morning. And for a firm whose entire trade is trust, a leak does not only cost francs: it costs clients.

There is also a distinctly Swiss dimension. This data falls under the nFADP, the revised Federal Act on Data Protection. In the event of a leak, the firm's responsibility — and the possible obligation to report the breach to the federal authority (NCSC, the National Cyber Security Centre) — depends not on its size, but on the sensitivity of the data involved.

"Our antivirus protects us"

The second reassuring reflex: "our IT provider installed an antivirus, so we're covered." Antivirus is still useful — but it only watches one door among many. Historically, it recognises known threats by their "signature," a bit like a doorman with a photo of the usual troublemakers. The problem: today's attacks are designed not to appear in the photo.

The best example is phishing (an email or message that impersonates a trusted party — bank, supplier, authority — to push you into clicking, paying or handing over a password). No antivirus stops a busy employee from opening a fake invoice from a familiar supplier and then entering their credentials on a page that looks exactly like their bank's. The weakness here is not the software: it is a perfectly human moment of inattention.

Relying on antivirus alone is locking the front door while leaving the windows open. Real protection is made of several simple layers that complement each other: a second proof of identity to log in, software kept up to date, backups you know how to restore, and a team able to spot a trap. None of these layers costs a fortune; it is their absence that ends up being expensive.

In plain terms, as Camille — the adviser who supports SMEs like Sophie B.'s — often puts it: a good antivirus is the seatbelt. Useful, essential even — but nobody drives with their eyes closed just because it is fastened.

What to remember

  • Size is no protection. The most frequent attacks are automatic and opportunistic: they target weaknesses, not reputations. A small structure holding sensitive data is a perfectly profitable target.
  • One tool is not enough. Antivirus is a layer, not a shield. The most effective traps go through people — an email, a phone call — where no software decides for you.
  • In Switzerland, responsibility is the same for everyone. The nFADP expects an SME to take security measures "appropriate" to the sensitivity of the data it holds, not to its turnover.

Steps to take this week

1. Turn on two-factor authentication where it counts

Two-factor authentication (MFA: on top of the password, a second proof — for example a code on your phone) offers the best protection for the least effort. Turn it on first for email, the accounting software and online banking. Even if a password leaks, the door stays shut.

2. Check that everything updates on its own

Most automated attacks exploit weaknesses the vendor has already fixed… but which were never installed. Take ten minutes to confirm that automatic updates are switched on for computers, browsers and business software. It is not a cost: it is a box to tick.

3. Run a real-life test with your team

Gather the team for fifteen minutes and look together at two or three genuine fake emails: an odd sender address, artificial urgency, a link that does not lead where it claims. The goal is not to catch anyone out, but to build the reflex: when in doubt, verify through another channel before clicking or paying. This is precisely the layer no antivirus will ever replace.

Where do you really stand?

These cybersecurity myths share one trait: they create the impression of being protected without anything ever being checked. The first step is not to buy one more tool, but to take an honest inventory — question by question, without jargon.

That is exactly what the Cyber Passport self-assessment offers. It certifies nothing and promises no compliance: it shows you, area by area, where your organisation is solid and where it still rests on a belief. Enough to turn "I think we're covered" into "I know where I stand," and then to prioritise what really matters instead of stacking up tools at random.

Part 2 of this series will tackle two more equally stubborn myths. In the meantime, if you take away just one thing: an SME's security is not decided by a piece of software, but by a few simple habits, kept up over time.

Topics

  • myths
  • SME
  • Switzerland
  • awareness
  • antivirus

Read next