One morning, an employee of Sophie B. opens an ordinary-looking email: a supplier invoice to pay, with a link to “update the bank details.” The tone is urgent, the amount believable. She hesitates, senses something is off, and asks before clicking. That reflex — pausing and asking — is worth more than any security software. It is exactly what security awareness is for: turning every person into a line of defence, not a culprit.
Security awareness, or why people are your first line of defence
Sophie B. runs an accounting firm: the bookkeeping, payroll and tax data of hundreds of small clients pass through mailboxes and a few business applications every day. There is no in-house IT specialist — an external provider steps in on request. Attackers know this profile by heart. They don't try to break through a technical fortress: they write an email.
That is the principle of phishing: a message that imitates a trusted sender — a supplier, a bank, a colleague, the boss — to push you into clicking, paying or handing over a password. No spam filter catches every one of these messages, because the best ones are clean, well written and arrive at just the right moment. In the end, a person decides: they click, or they stop.
Yet we keep repeating that “people are the weakest link.” The phrase is comfortable — it names a ready-made culprit — but it is wrong and, above all, counterproductive. Someone who has been shown what a trap looks like, and who feels allowed to say “wait, let me check,” intercepts the attack where no tool would have seen it. The human factor isn't the hole in the hull: it's the lookout.
Put plainly, as Camille would say: an SME's security isn't a single wall, it's a series of small nets. The antivirus is one, the spam filter another, the backup a third. An employee's attention is the net that catches what the others let through — often the last one before a payment or a leak. And strengthening it costs almost nothing: time, conversation and a little method, not another licence.
How do you spot an attempt? Rarely by a glaring spelling mistake — today's traps are polished. More by a cluster of small signals: urgency at an awkward moment, a request that steps outside the usual channel (“pay this invoice today, off-process”), bank details “to be updated,” a sender address that's almost right. None of these clues proves anything on its own; together, they warrant a pause. Learning to sense that climate, without turning paranoid, is already most of the work — and it's learned as a team, not from a manual.
This shift in perspective is anything but theoretical. In a team of a dozen people, closeness is a strength: everyone knows each other, trust flows, decisions move fast. That is also what makes an attack effective — nobody wants to ask a colleague they pass every morning for a second confirmation. Security awareness isn't about installing suspicion; it's about making it normal to verify, without it feeling like a lack of trust.
Plainly put: blaming produces the opposite of what you want. The person who clicked by mistake and dreads the telling-off does something very human — they stay quiet and hope nothing happens. But in cybersecurity, silence is expensive: the longer a compromise stays invisible, the further it spreads, from the infected computer to the mailbox, then to the payments. The nFADP (the revised Swiss Federal Act on Data Protection, in force since September 2023) expects “appropriate” security and the reporting of serious breaches — and you can only report what people dare to flag. The Swiss federal cybersecurity office (NCSC), the national reference, ranks employee awareness among the most effective basic measures, and among the least expensive.
What to remember
Technology filters some of the threats; it will never filter all of them. The final decision — open the attachment or not, pay or not, reply or not — always comes down to a person. Better make sure they're equipped to decide well, rather than left alone with a well-crafted email at 5 p.m. on a Friday.
Blaming drives silence; empowering drives reporting. A team where saying “I'm not sure about this” is valued is worth, in practice, more than one more piece of security software. It's a cultural shift, not a purchase — and that's exactly why it's within reach of an SME on a tight budget: it plays out in behaviour, not in invoices.
Awareness isn't one big annual course forgotten within three weeks. It's a team habit kept alive in small doses — and it's within reach of any SME, even without a dedicated budget or in-house IT. The nFADP, moreover, places responsibility for data security on the company itself, not on its provider: in practice, that responsibility comes down to people who know how to react.
Habits to set up this week
1. Make doubt legitimate
Say it to your team once and clearly: nobody will be scolded for checking a request, or even for clicking a dubious link and reporting it straight away. Name a simple point of contact — a person, or a “when in doubt” address — where an alert can be raised in ten seconds. The real risk to your business isn't that someone makes a mistake: it's that they keep it to themselves.
2. Short, regular reminders
Five minutes in a team meeting, every other week, beats a three-hour training forgotten the following month. Take a real, recent example — an actual suspicious email the firm received — and pull it apart together: what was off? The sender's address? The manufactured urgency? The link that doesn't go where it claims? Repeated, this small ritual turns abstract knowledge into a shared reflex.
3. Lead by example from the top
When Sophie B. tells the story herself of the fraud she nearly fell for, the message changes in nature. It's no longer “you, be careful,” it's “this happens to all of us, here's how we react.” Awareness travels badly when it comes from the top without the top living by it too. Leadership that flags its own doubts gives the whole team permission, without another word, to do the same. It's also the best antidote to shame: if the person who decides admits to being caught out, no one else has any reason to hide a mistake.
Where do you really stand?
These three habits are about governance and culture — two things you can't buy, but that you can structure. That's where Cyber Passport comes in: the self-assessment certifies nothing and never declares you “compliant.” It shows you, question by question, where your security awareness already holds up and where it still rests on the vigilance of a single person on a busy day. It's the honest starting point for turning your employees into a lasting first line of defence — and for preparing, when you decide to, a real awareness programme.



