A long-standing client sends Sophie B. a very simple question: "Concretely, who protects our data at your firm?" The managing partner of the accounting practice rereads the message twice. She knows her IT provider "handles the computers" — but is that the same thing as security? And if it isn't quite him, then who should she turn to? Behind that hesitation lies a question many business owners carry without daring to say it out loud: what exactly are the cybersecurity roles, and which one concerns me?
What cybersecurity roles really cover
First misunderstanding to clear up: cybersecurity is not one job, it is a family of jobs. In a large company, several people share the work — one watches, another tests, a third sets the rules. In a fifteen-person firm, no one holds any of these titles. And that is precisely where the blind spots hide.
Sophie B.'s reflex — "the provider handles it" — is the classic trap. An IT provider keeps the tools running: they set up the workstations, fix problems, apply updates, configure the mailboxes. That is useful and necessary. But keeping the tools running is not the same as watching for an attack, stress-testing your own defences, or deciding on a strategy. You can have IT that works perfectly and security that, in reality, is left to no one.
The simplest way to make sense of it is to picture security as a team, with clearly distinct positions. Some watch, some build, some decide. Here are the main ones, in plain language — not so you hire them all, but so you know what people mean when these words come up in a conversation, a quote or a questionnaire from your client.
The cybersecurity analyst (or SOC analyst). The SOC (Security Operations Center) is an organisation's monitoring room. The analyst is the sentinel: they watch alerts, connections and abnormal behaviour, and react when something is off — a login from abroad at three in the morning, a file that starts encrypting the others. This is the job of day-to-day detection and response.
The penetration tester ("pentester"). You pay them to attack you — legally. A penetration test (pentest) means putting yourself in a burglar's shoes to try every door before a real criminal finds the weak lock. They break nothing: they reveal the flaws so you can fix them. In an SME this is usually a one-off engagement, not a position.
The security engineer or architect. This is the builder of the defences. They design and configure what protects you: the firewall (the filter between your network and the internet), multi-factor authentication (MFA — beyond the password, a second proof, for example a code on your phone), the separation of access rights. Where the analyst watches and the pentester tests, the engineer builds.
The CISO (Chief Information Security Officer). This is not a technician, it is a conductor. They set the rules, weigh the risks, decide what gets protected first, and connect security to the company's decisions and to the law. In an SME this strategic role is almost always vacant — or held by the owner without them realising it. Yet it is the role that governs all the others.
The cyber consultant or auditor. An outside eye who assesses your situation, points out the gaps and recommends priorities, without you having to hire permanently. They do not replace your provider: they steer them, and they translate for you what needs to be done. For an accounting firm with no in-house IT, this is often the most realistic entry point: you bring in the expertise when you need it, leave with a plan, and keep control of the decisions.
The data protection officer (DPO). Their field is not technical but legal: they make sure the nFADP (Switzerland's data protection act) is respected and that personal data is properly handled. IT security and data protection overlap, but are not the same — two concerns, two reflexes.
No SME employs all of these profiles. Most are outsourced, shared, or simply dormant. The point, then, is not to recruit them all: it is to know which function is actually covered, by whom, and which one is nobody's job.
What to remember
Cybersecurity is not "IT". Your provider may keep the machines running without watching for attacks or steering a strategy. Believing "it's handled" because a maintenance contract exists is like mistaking servicing the car for actually watching the road.
You do not need to hire each of these roles. You need to know which function is covered, by whom, and which one is left orphaned. An honest map beats a rushed recruitment: it tells you where to put the next franc, and when a one-off consultant is enough rather than a full-time hire.
The most strategic role — the CISO, governance — is the great absentee in SMEs. Yet it is the one that decides everything else. The costliest gap is not technical: it is the absence of someone whose job is to ask "who is taking care of this?".
The steps to put in place this week
1. Draw the "who does what" map of your firm
On a single page, list the main functions: monitor, update, back up, decide the rules, respond to an incident. Next to each, a name — even if that name is "no one". The blank boxes are not a failure: they are your priorities, finally visible.
2. Put the security question to your provider in writing
Three questions are enough: is security in our contract, or only troubleshooting? Who notices a suspicious login at night? Who checks that a backup actually restores? A written answer clarifies the scope and avoids the "I thought that was included".
3. Appoint an internal security lead (not a technician)
Choose the person whose role will be to ask the right questions and relay the decisions — the seed of a CISO. They do not need to be an expert; they need to own the subject, so it stops being everyone's job, which means no one's.
Where do you really stand?
Putting names to cybersecurity roles is already a way of seeing where your organisation stands on solid ground and where it rests on a misunderstanding. That is exactly what the Cyber Passport self-assessment structures: it certifies nothing and sells you no position. Question by question, it turns these roles into concrete responsibilities, shows you which ones are covered in your firm and which remain a blind spot — so that, next time a client writes to you, you know who to turn to.



