One morning, Sophie B. opens an email from one of her largest clients. It is not an accounting question: it is a request for assurances about how her firm protects the data entrusted to it, before renewing the engagement. For the first time, IT security stops being a distant technical topic — it becomes a condition for keeping revenue.
Sophie runs an accounting firm. Her business, in the end, comes down to one word: trust. Her clients hand her their most sensitive material — salaries, accounts, tax and banking data. The day that trust cracks, she does not lose servers, she loses engagements.
Why cybersecurity has a direct impact on your revenue
Cybersecurity is often framed as an expense: a technical cost, a box to tick, one more constraint. That reading misses the point. For a service-based SME, data security is not next to your revenue — it is inside it.
The mechanism is simple. Your clients entrust you with information because they trust you. An incident — a fake invoice paid, a hijacked mailbox, a payroll file leaked — does not only cost time and money to fix. It damages that trust. And a client who doubts the security of their data does not always say so: they leave at the next renewal, quietly.
The other half of the mechanism is more recent, and more interesting. Increasingly, clients themselves ask the question before signing. A reasonably structured buyer sends what is called a supplier security questionnaire: a list of questions about your practices — who has access to what, how you back up, how you react to an incident. They are not trying to trap you; they are covering their own risk. Because if they hand you their data and you lose it, they are the ones who will have to explain themselves to their own clients.
In Switzerland, this reflex is reinforced by law. The nFADP (the new Federal Act on Data Protection, in force since September 2023) expects any company handling personal data to take "appropriate" security measures, and to report serious breaches to the competent federal authority (the FDPIC). An SME unable to say how it protects its clients' data is therefore not only technically fragile: it becomes the weak link that partners start to avoid.
A trap lurks here for SMEs like Sophie B.'s: believing that "it's handled." Many accounting firms have no in-house IT and rely on an external provider, called when something breaks. That provider is responsive but rarely proactive on security: they repair, they do not anticipate. As a result, the owner assumes the topic is covered, when in fact no one has truly taken charge of it. The day a client asks their questions, that illusion evaporates at once — and that is the worst moment to find out. Knowing what your provider does (and does not do) is part of the commercial answer.
Reputation works in the same direction, more quietly. A badly handled incident does not always end in a headline; it first travels by word of mouth, between business owners in the same region who recommend their providers to each other. In a fabric of Swiss SMEs where many engagements come through networks, that reputation is worth its weight in gold — and a leak that gets around can dry up a source of clients far more surely than a fine. Conversely, a reputation for taking data seriously becomes a reason to be recommended.
Turn the logic around, and the argument becomes positive. A company that can calmly show where it stands on security reassures. It turns a constraint into a commercial edge. Faced with two equivalent providers, a client picks the one who answers "here is how we protect your data" rather than the one who fumbles. Cybersecurity, well explained, is no longer a defensive expense: it is a sales argument.
What to remember
Security protects your revenue, it does not nibble at it. Every engagement rests on trust; every incident chips away at it. Thinking in terms of "the cost of an attack" hides the real stake: the cost of clients who do not come back.
Your clients are already auditing you, or soon will. The supplier security questionnaire is trickling down from large groups to their subcontractors and providers. Being able to answer it becomes a condition of access to the good contracts, not a luxury.
You do not need to be perfect — you need to know where you stand. A serious client does not ask for perfection; they ask for clarity and a direction of travel. An SME that knows its weak spots and its plan inspires more confidence than one claiming to have no problems at all.
Steps to put in place this week
1. Write down, in one page, how you protect client data
Not a technical document: one readable page, in plain language, that a client could read. Where the data is stored, who has access, how you back up, who to call if there is a problem. The exercise has two virtues: it prepares you to answer a client, and it reveals your own gaps. Sophie B. spent an hour writing hers — and realised while doing so that three former staff members still had active accounts.
2. Lock down access to your most sensitive data
Turn on multi-factor authentication (MFA) — on top of the password, a second proof, such as a code on your phone — for your mailbox and your business software. It is the step with the best effort-to-protection ratio, and exactly the kind of measure a client likes to hear about: concrete, verifiable, jargon-free.
3. Prepare your answer to "how do you protect my data?"
Do not discover it the day a big client asks. Decide who, in the firm, answers that question, and with what. A calm, honest answer — "here is what we do, here is what we are improving" — beats an empty promise. Keep the one-page document from the first step at hand: it serves as the backbone for all your answers. And there is no need to improvise: a client treated well on this ground feels respected, not inspected. That is often where, quietly, the difference is decided between an engagement you keep and a contract that slips away for sheer lack of preparation.
Where do you really stand?
These three steps open the door, but they do not replace an overall view. A leader's real question is not "am I under attack?" but "can I show a client, or an auditor, that I take this seriously?".
That is exactly what a Cyber Passport self-assessment structures: a stocktake, question by question, of where your organisation is solid and where it still rests on trust and habit. The result is a clear report, shareable with a client or an auditor. Cyber Passport certifies nothing and promises no compliance — it gives you the clarity and the language to turn your security into an asset rather than a blind spot. And turning that blind spot into an argument acts directly on your revenue.



