One morning, Sophie B. agrees to spend an hour on a self-run security assessment. As a partner in a small accounting firm in French-speaking Switzerland, she expects nothing unusual: "we're careful, it should be fine." An hour later, she has written down three things she never saw coming — a password shared by the whole team, a backup no one has ever tried to restore, and the account of a colleague who left months ago that still works. Nothing dramatic. But nothing that can really wait, either.
Why a security assessment tells you more than you'd think
A security assessment — meaning a structured questionnaire that methodically reviews your practices, one area at a time — isn't looking for the spectacular breach. It asks the simple questions no one asks in the daily rush. And that is exactly where an SME's real blind spots hide.
Because a firm like Sophie B.'s almost never gets caught by a sophisticated attack from the other side of the world. It stumbles on ordinary details that no one keeps an eye on. Three of them come up in nearly every assessment.
The first is the shared account. A single login for the accounting software, used by the whole team "because it's simpler." The day a client file is changed by mistake, there's no way to tell who did what. And when someone leaves the company, you can't remove their access without locking out everyone else.
The second is the backup that has never been tested. "We have backups" is a reassuring sentence — until the day you actually need to recover a file and discover that the copy is incomplete, corrupted, or three weeks old. A backup you have never restored isn't a backup: it's an assumption.
The third is the access that outlives the person who used it. Last summer's intern, the bookkeeper who moved to a competitor, the contractor you no longer call: their accounts often still exist, with the same rights as on day one. No one closed them, because closing an access is never a Monday-morning priority.
These three blind spots share the same root: they come from an organisational gap, not from carelessness. In a structure where no one is officially in charge of security — no in-house IT person, no dedicated lead — these small convenience decisions pile up without anyone going back over them. Each one, on its own, seemed reasonable the day it was made. It's their accumulation, year after year, that opens the gap between what an SME believes about its security and what it actually is. An assessment plays exactly the review role that daily life never allows.
For an accounting firm, none of this is trivial. It holds the bookkeeping, payroll and tax data of many client SMEs — a de facto professional secret. The nFADP, Switzerland's revised data protection law that came into force in 2023, expects precisely that a company handling this kind of information takes "appropriate" measures to protect it. A shared account and an untested backup are not technical details: they are questions Sophie B. will need to be able to face if a client — or the authority — ever raises them.
Switzerland's Federal Office for Cybersecurity (the NCSC) publishes practical recommendations for SMEs that point in exactly this direction: start with basic hygiene — who has access to what, where the backups are, who can do what — rather than with advanced tools. An assessment is nothing more than that basic hygiene, written down in black and white.
Key takeaways
An assessment isn't meant to scare you, it's meant to help you see. Most SME leaders discover they are neither "hopeless" nor "exposed," but somewhere in between: a few solid foundations, and a few gaping holes they had simply never looked at.
- Blind spots aren't faults, they're things nobody thought about. No one decided to share a password in order to weaken the company — it happened out of convenience, on a day when it helped. An assessment puts those small arrangements back under the light.
- What isn't tested doesn't really exist. A backup, a procedure, an emergency access: until you've tried them at least once, you don't know whether they work. The assessment turns "I think so" into "I know so."
- An SME's security rests mostly on organisational moves. Not on expensive tools. Removing an account, assigning a personal login, testing a restore: none of that requires an IT budget, only half a day of attention.
Moves to put in place this week
You don't need a full audit or an outside provider to get started. Here are three moves Sophie B. was able to launch herself the very next day.
1. List the shared accounts
Write down the logins used by more than one person — the business software, the generic mailbox, the online banking access. For each one, ask a single question: "if someone left tomorrow, could I remove this access without disrupting the others?" Every "no" is an account to turn, over time, into a personal login — one identifier per person. Start with the most sensitive one.
2. Test a single restore
Don't check that the backup "runs": check that you can pull a file out of it. Pick a document, ask for it to be restored, and watch how long it takes and whether the recovered version is up to date. Note who managed to do it, and how long it took: those two pieces of information are worth their weight in gold on the day of a real incident. If no one knows how to proceed, you've just learned something useful — before needing it under pressure.
3. Clean up access rights
Take the list of people who have access to your tools — email, accounting software, file sharing. Compare it with the list of those who actually work with you today. Any difference is an access to close. It's the quickest move on the list, and often the most revealing: it's not unusual to find one or two active accounts no one remembers. While you're at it, note who holds the broadest rights — those are the ones to watch first.
Where do you really stand?
These three moves don't close every blind spot — mostly, they show how much a simple security assessment changes the way you look at your own organisation. You move from "I think we're more or less protected" to a clear, question-by-question picture of what holds and what rests only on trust and habit.
That is exactly what the Cyber Passport self-assessment offers: a structured path that reviews your practices and hands you a readable status report, ready to share with your clients or your auditors. It certifies nothing and never declares you "compliant" — it shows you where you really stand, and where to start. And to go further than these three moves and build a prioritised remediation plan, the matching blueprint takes over.



