An important client writes to Sophie B.: before renewing his mandate, he'd like to understand "how you protect my data". As managing partner of a Swiss accounting firm, Sophie knows her files are sensitive — salaries, tax returns, the bank details of dozens of client SMEs — yet she realises she would struggle to answer. Until now, IT has been "something the provider takes care of". Where do you start when you're neither an IT specialist nor a large company?
SME cybersecurity is about your data, not your size
The first idea to let go of is the one Sophie repeated to herself for years: "we're too small for anyone to bother with". It's wrong — and for a reassuring reason. The vast majority of attacks target no one in particular. They are automated campaigns that sweep the internet and stop wherever a door is left ajar. The attacker doesn't know your company's name: they know the value of what they find.
An accounting firm concentrates exactly what can be turned into money: bank details, salaries, identities, access to third-party accounts. It isn't your revenue that makes you interesting, it's your book of data. And that value is the same whether you are fourteen people or four hundred.
The second reflex to correct is believing that security lives somewhere else, "with the provider". An external provider keeps the machines running; they have no mandate to decide who on your team may access which file, nor to check every month that your backups hold. Security isn't a service you buy once: it's a posture you maintain. As long as it explicitly belongs to no one, it belongs to no one.
Two words come up often and deserve plain definitions. Phishing is an email or text message that imitates a trusted sender — a bank, a supplier, a colleague — to make you click, pay, or hand over a password. Ransomware is a program that encrypts your files and demands a ransom to make them readable again; it usually gets in through a single click. These two threats account for most of what actually hits SMEs, and neither requires you to be a designated target.
Finally, there's a framework worth knowing — not to be frightened by it, but to place yourself. Since September 2023, Switzerland's new Federal Act on Data Protection (nFADP) expects any organisation handling personal data to take "appropriate" security measures and to report a serious breach to the Federal Data Protection and Information Commissioner (FDPIC). The nFADP doesn't impose a specific piece of software; it makes you responsible for having thought and acted in proportion to how sensitive your data is. For Sophie, whose files touch on her clients' business confidentiality, that's a useful nudge: getting started already answers that expectation.
The good news: you aren't alone with these questions. The Swiss National Cyber Security Centre (NCSC) publishes concrete recommendations designed for Swiss SMEs — free and regularly updated. It's the first official resource to turn to when a technical doubt comes up, rather than the first article you find. Placing yourself also means knowing where to find trustworthy information.
What to take away
Three ideas are enough to shift your posture, even before the first technical measure.
- You're a target because of what you hold, not your size. A service SME's data can be monetised immediately, and attacks don't sort by headcount.
- Security is a habit, not a purchase. A few well-kept habits cover the largest share of everyday risk. It's not about armour-plating everything at once, but about closing the most-used doors first.
- You start with no budget and no IT specialist. The very first steps are organisational: knowing what you protect, and who accesses it. That's free, and it's the foundation for everything else.
In other words, "where do you start" isn't a question of means. It's a question of order: doing the right things in the right sequence, beginning with the simplest and most rewarding.
The steps to put in place this week
Three actions, doable with no technical skill and no spending. They don't solve everything — which is precisely why they are the starting point of a roadmap.
1. Take stock of what really matters
You only protect well what you've named. Take a sheet of paper and list, with no tools, the three or four things whose loss or leak would be most serious: the accounting software, the mailbox, the client files, the online banking access. For each, note a single fact: who on the team can access it today? This one-hour exercise almost always reveals surprises — a shared account everyone uses, an access left open for someone who has left, a sensitive folder sitting in a space visible to all. You're not fixing anything yet: you're making visible what was blurry. It's the map without which nothing that follows makes sense.
2. Turn on multi-factor authentication (MFA)
Multi-factor authentication (MFA) adds a second proof to the password — usually a code on your phone or an approval in an app. In practice, even if someone guesses or steals your password, they can't get in without your phone. At almost no effort, it's the measure that blocks the greatest number of intrusions. Start with the most exposed account: the work mailbox, the gateway to almost everything else. Most services enable it in a few minutes in the security settings, with nothing else to install. Then extend it, one account at a time, to your sensitive access points.
3. Ask the right question about your backups
"We have backups" is a sentence Sophie has heard a thousand times, without ever seeing proof that they work. This week's step isn't to reconfigure everything, it's to ask your provider three questions — and get the answer in writing. Where are my backups? When was the last restore actually tested? How long would it take to recover my files if everything were lost tomorrow morning? A backup you've never managed to restore isn't a backup, it's an assumption. That simple conversation will tell you where you really stand, without you touching a single setting.
Where do you really stand?
These three steps are a beginning, not a plan. They close the most frequent doors, but Sophie's real question — in what order to handle the rest over the coming months, and how far to go — calls for a roadmap. That's exactly what an article doesn't contain: the detailed "how", step by step, with priorities and checkpoints, lives in the dedicated blueprint.
Before you get there, you need to know where you stand. The Cyber Passport self-assessment shows you, question by question, where your organisation is solid and where it rests on trust or habit. It certifies nothing and declares you compliant with nothing: it structures an honest snapshot that you can share with a client or auditor who asks you, as they asked Sophie, "how do you protect my data?". Starting SME cybersecurity isn't about solving everything in a week — it's about giving yourself a map, then moving forward in the right order.



