On a Friday evening, Sophie B. rereads a request from a supplier asking to update their bank details. Nothing looks off at first glance: the email is polished, the logo is right. As usual, she reassures herself with a quick "anyway, IT is the provider's job." Two cybersecurity myths hide inside that very human reflex — and they are precisely the ones that cost Swiss SMEs the most.
Two cybersecurity myths that expose your SME
A trustee firm handles a company's most sensitive material: accounting, payroll, tax and banking data for dozens of clients. Yet security there often rests on two comfortable beliefs that, put end to end, leave the door ajar. Let's look at them honestly, without dramatizing.
"The provider handles security"
Many SMEs with no in-house IT hand their infrastructure to an external provider and conclude they no longer have to worry about it. That mixes up two different things: delegating a task is not transferring a responsibility.
Under the nFADP — Switzerland's data protection act, in force since September 2023 — you, as the company that decides how your clients' data is used, remain the "controller." In other words, if your data leaks, the responsibility is still yours, even when the systems were run by someone else. The provider is a "processor" in the eyes of the law: they execute, but they do not carry your duty to protect.
The nFADP does not stop there: it expects security that is "appropriate" to the risks, and provides that a data breach may have to be reported to the Federal Data Protection Commissioner. In practice, an aggrieved client will not ask "who ran the server?" but "did you take reasonable measures?" Relying entirely on a third party, without ever checking what they do, is not a reasonable measure: it is an assumption. And an assumption protects neither your clients nor your liability.
The second blind spot is more concrete. A poorly framed provider creates false security. Large organizations have been breached not through a flaw of their own, but through the access of a poorly protected supplier, used as a way into the main network. For an SME the logic is the same on a smaller scale: your provider holds broad access to your systems. If that access is badly managed, it becomes your weak point — without you ever having decided so.
The problem is not having a provider: that is perfectly reasonable, and often the best option. The problem is not knowing what they actually cover. Who checks that backups work? Who installs security updates, and how often? Who do you call, on a Sunday night, if something goes wrong? As long as those answers live in an "I thought that was handled," no one owns them.
"An attack would be obvious right away"
The second myth is even more stubborn: we picture a cyberattack as a red screen, a computer that refuses to boot, an unmistakable alarm. In reality, the most costly attacks are silent.
An intruder who manages to steal a password breaks nothing. They log in like a normal user, read emails, observe who talks to whom, learn the payment habits. Specialists call "dwell time" the period during which an attacker stays inside a system before being spotted. It is often measured in weeks, sometimes months.
In plain terms, as our cyber adviser Camille puts it: silence is not proof that all is well. Very often it is the signature of a well-run attack. The moment when "you can see it" — a payment gone out, files encrypted, a client flagging an odd email from your address — comes at the end of the story, not the beginning.
For a trustee firm, that invisible delay is especially dangerous: it is enough for an attacker to understand your billing flows to slip in, at the right moment, a fake bank-detail change that surprises no one. Discretion is not a technical detail: it is the core of the fraudster's business model.
What to take away
- You cannot outsource responsibility for your data. You may hand over the technical operation, but the duty to protect stays with you. A provider is a partner to frame, not a legal umbrella.
- Silence is not proof that all is well. Effective attacks are designed to stay invisible as long as possible. Not seeing an incident does not mean there isn't one.
- These two blind spots add up. Believing "the provider handles it" and assuming "we'd see an attack" means watching neither the door nor what happens once it has been crossed.
Habits to put in place this week
1. Map out who does what with your provider
Take one page. Write down in black and white, together with your provider, what they cover and what they don't: backups and restore tests, security updates, connection monitoring, and above all the number to call in an incident. Three questions are enough to start: "What exactly do you back up, and have you ever tested it?", "Who has access to our systems, and since when?", "What do we do, concretely, if I call you on a Sunday?" Switzerland's federal cybersecurity office (NCSC) recommends framing in writing exactly what a provider does.
2. Make silent attacks less silent
You probably already use Microsoft 365: it can flag an unusual sign-in (a distant country, an improbable hour). Ask for those alerts to be switched on and, crucially, name who watches them. Also turn on multi-factor authentication (MFA) — beyond the password, a second proof such as a code on your phone: this is what stops a stolen password from being enough. Access that no longer relies on the password alone, and alerts that someone actually reads, sharply cut the time an intruder can go unnoticed.
3. Build a verification reflex for money
Any unusual request touching a payment — a change of bank details, an urgent transfer — is checked on a known channel: you call the supplier back on the number already in your records, never the one given in the email. Add a five-minute quarterly review: "who has access to what, here and at our providers?" These two reflexes cost nothing and close the door that the two myths left open.
Where do you really stand?
Unpacking these cybersecurity myths is already progress — but a reassuring belief is no substitute for a clear-eyed assessment. The honest question is not "am I protected?" but "what, in my organization, still rests on an assumption I have never checked?"
That is exactly what the Cyber Passport self-assessment structures. It certifies nothing and does not declare you "compliant": question by question, it shows you where your organization stands firm and where it rests on an "I thought that was handled." Enough to turn two myths into a clear plan.



