One Monday morning, an employee at Sophie B.'s firm can no longer open her accounting files: the names have turned into a string of unreadable characters. At the practice, no one is tasked with watching security alerts — everyone is busy doing their own job. The real question, then, is not how to stop every attack, but how to detect and respond to one before it spreads across the whole firm.
Detect and respond: why an SME with no SOC is concerned
Large companies run a SOC — a Security Operations Center, meaning a security team that monitors alerts continuously, often around the clock. A service business like Sophie B.'s obviously has none, and never will: it is neither its trade nor its budget. Many owners conclude, wrongly, that protecting themselves "for real" is out of reach.
That is a mistake, because modern attacks do not work the way we picture them. An attacker rarely breaks the door down. More often, they slip in quietly — with a password stolen through a booby-trapped email, for instance — and then stay unnoticed for days, sometimes weeks. They watch, they map out where the sensitive data sits, and only at the end of that window do they strike: files encrypted, a payment diverted, client records exfiltrated.
That window — the time during which the attacker is already inside without anyone knowing — is the real danger. The longer it lasts, the deeper the damage: backups contaminated in turn, client data copied, access rights multiplying. Conversely, an intrusion spotted the same day usually stays a minor incident. Everything comes down to how quickly you notice something, not to how high the wall is.
Prevention — good passwords, multi-factor authentication (MFA: on top of the password, a second proof, such as a code on your phone) — sharply reduces the risk of entry. But no barrier is perfect, and a service SME is an all the more attractive target because it holds sensitive data belonging to many third parties. That is why you cannot stop at "preventing." You also need to detect — spot the signs that something abnormal is happening — and respond — know what to do within the hour, calmly, without improvising. Neither reflex requires a SOC. What they require, above all, is organisation — and that is good news for a small structure: organisation cannot be bought, it is decided.
What to remember
Prevention alone is a losing bet. Assume that one day, despite your precautions, something will get through. A robust organisation is not one that is never attacked — it is one that notices quickly and knows what to do. That is exactly the posture that frameworks such as NIST CSF 2.0 lay out, distinguishing the functions identify, protect, detect, respond, recover: half the work happens after the intrusion.
Detecting does not start with a purchase. We imagine you need expensive software to see an attack. In reality, the first detection tool is knowing what a normal day looks like — and therefore spotting what is not normal. Most of the tools you already use (your work email, for one) raise alerts that no one reads. Turning them on and naming who receives them costs zero francs.
Responding fast is also an obligation, not just a good idea. In Switzerland, the nFADP — the Federal Act on Data Protection, in force since September 2023 — expects a business to take "appropriate" measures and to report a data breach to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible where the risk to the people concerned is high. If you also handle data of clients or contacts based in the European Union, the GDPR adds its own deadlines. For an accounting firm holding the data of hundreds of clients, knowing how to respond is therefore not a luxury: it is a responsibility, and a good response always starts with fast detection.
Moves to put in place this week
1. Write down your five warning signs
For a small structure, detecting starts with a single sheet of paper. Gather the people who touch the IT tools and list, together, five signs that should raise the alarm immediately. For example: a file that becomes unreadable or renames itself; a mailbox login from a country where no one works; a colleague flagging a genuinely strange email received in a partner's name; software running abnormally slowly on several machines on the same day; a client telling you they received a message you never sent.
The goal is not to be exhaustive, but to turn a vague feeling ("that's weird") into a shared reflex ("that's a signal, I report it straight away"). Post the list and make it clear whom it goes to.
2. Turn on the alerts — and the multi-factor authentication — you already have
Most SMEs work on an online office suite that already knows how to flag suspicious behaviour: a login from an unusual place, the creation of a rule that automatically forwards your emails outside the company, several failed login attempts. These alerts often exist without anyone receiving them. Ask your IT provider to switch them on and to route them to a named person — not to a generic inbox no one checks.
In the same move, roll out multi-factor authentication (MFA) across sensitive access, starting with email. It is the measure that cuts off the largest number of intrusions at the root, and it costs nothing more than a few minutes per person.
3. Write down your first-hours reflex
The worst moment to work out whom to call is in the middle of a crisis. So prepare, in calm times, a one-page sheet that answers three simple questions: who does what in the first hours (who isolates the affected machine by unplugging it from the network and Wi-Fi, who informs management, who keeps a record of what is observed); whom you call (your IT provider, and the contact point of the National Cyber Security Centre — the NCSC — which receives incident reports); and what you must absolutely not do (pay a ransom without advice, or shut machines down abruptly and risk erasing useful traces).
This sheet does not replace a full crisis plan, but it buys you the most precious hours: the ones where a calm response makes the difference between a contained incident and a disaster.
Where do you really stand?
These three moves take you from a waiting posture to an active one: you accept that an attack may happen, and you organise yourself to detect and respond. The honest follow-up question is this: on these topics — detection, logging, incident response, nFADP obligations — where are you solid, and where are you mostly relying on luck?
That is exactly what the Cyber Passport self-assessment lays bare. It certifies nothing and does not declare you "secure": it shows you, question by question, your real maturity and what deserves to be strengthened first. To go further and turn these moves into a genuine detection-and-response capability, our dedicated blueprint walks through the full plan, step by step.



