One Friday evening, a client calls Sophie B. back just before hanging up: "By the way, how do you actually know your defences are working?" She replies that she has "antivirus and an IT provider who handles it," then goes quiet. She has just realised she has no number at all to steer her cybersecurity — nothing to reassure that client, and nothing to reassure herself.
Steering your cybersecurity starts with measuring it
In an accounting firm, IT security often looks like a black box: you pay an external provider, cross your fingers, and assume "it's handled." The trouble is, an assumption cannot be steered. You have no idea whether things are improving, standing still or getting worse — and the day a client, an auditor or your insurer asks the question, you have nothing to show.
Steering does not mean becoming an IT specialist. It means tracking a few metrics — often called KPIs, meaning a simple number that answers a precise question: "is this working?" A good metric fits on one line, can be read at a glance and leads to a decision. You do not need a thirty-column dashboard: for a small business, three or four well-chosen figures say more than a report nobody reads.
An accounting firm is especially concerned, for three very concrete reasons. First, it handles some of the most sensitive data there is: bookkeeping, payroll, and the tax and banking affairs of dozens of clients. Second, it usually has no in-house IT specialist — security is delegated, and therefore barely visible to the person who nonetheless carries the responsibility towards clients. Third, it is precisely those clients who are starting to ask for guarantees before entrusting their files. In that context, "I trust my provider" is no longer enough: you need to be able to show something tangible.
In plain terms. A useful metric is a number that makes you do something. If watching it move changes none of your decisions, it is worthless: drop it and keep one that truly matters.
Take an example that speaks to a firm like Sophie B.'s. The question "does everyone use two-factor authentication?" — two-factor authentication (MFA) means asking, on top of the password, for a second proof, such as a code on your phone — becomes a metric the moment you turn it into a percentage: "8 out of 14 accounts are protected by two-factor authentication." You move from a vague impression to a figure. And a figure can be tracked, given a target, and shown.
Be careful, though: not all numbers are equal. "Number of emails blocked by the antivirus last month" looks impressive in a report, but makes you decide nothing — that is what we call a vanity metric. By contrast, "share of accounts protected by two-factor authentication" or "have we tested a backup restore this quarter" point to a clear action when the answer is not to your liking. Before adopting a metric, ask one question: "if this number is bad, will I know what to do?" If yes, keep it. If not, leave it aside.
What to remember
A few metrics are enough. The classic mistake is to try to measure everything at once, then give up after two months. Three simple metrics tracked over time beat fifteen measured once and forgotten in a spreadsheet. Start small: you will add more once the first ones have become an effortless habit. Regularity matters more than completeness — a modest figure you look at every quarter carries more weight than a perfect dashboard consulted only once.
A metric is only worth something if it drives a decision. Knowing that half the team still lacks two-factor authentication only matters if it triggers an action: raising it with the provider, scheduling the rollout, checking again the following month. The number is a starting point, not an end in itself.
Measuring is also what you will be asked for. The nFADP — Switzerland's revised Federal Act on Data Protection — expects an SME holding sensitive data (and an accounting firm holds a great deal) to take "appropriate" security measures. Without a few metrics, you cannot demonstrate that you are actually steering anything. More and more clients and principals ask the question before entrusting their files, sometimes in the form of a security questionnaire to complete. The day that document arrives, it is better to already have a few figures on hand than to have to reconstruct everything under pressure.
Moves to put in place this week
1. Pick three metrics that speak to your business
You do not need the full list — save it for later. This week, choose three figures that are easy to obtain and meaningful for an accounting firm. For example: the percentage of accounts protected by two-factor authentication; the "yes / no" answer to "have we tested a backup restore in the last three months?"; the share of staff who completed a short awareness session this year. Three concrete metrics you understand without being a specialist.
2. Set a starting figure and a target
For each metric, note today's value — even if it is uncomfortable. It is your reference point, and no one will judge you on that starting line. Then set a simple, dated target: "go from 8 protected accounts out of 14 to 14 out of 14 within three months." A target turns an observation into a heading. Without it, a metric is just a snapshot; with it, it is a direction — and progress you will see concretely at the next review.
3. Look at these figures on a fixed date
A metric you never look at is useless. Block thirty minutes per quarter in the calendar — alone, or with your provider — to review your three figures. Have they moved in the right direction? If not, why, and what small action do we decide on? Write the decision in one line, and quarter after quarter you will build a record of your progress: precisely what you can show a client or an auditor. It is this regular appointment, more than any tool, that makes the difference between enduring your security and steering it. The National Cyber Security Centre (NCSC) also publishes practical recommendations for SMEs, useful for choosing the right moves behind each figure.
Where do you really stand?
Choosing the right metrics, knowing which ones truly matter for a Swiss SME facing the nFADP and its clients' questions, is exactly what a structured self-assessment lays bare. Cyber Passport certifies nothing and does not declare you "compliant": it shows you, question by question, where your organisation is solid and where it still rests on trust and habit. You get a picture of your maturity, free of jargon and judgement — and, precisely, a few clear metrics to steer your cybersecurity and share with confidence with a client or an auditor. The "Cyber metrics" blueprint then hands you the full set of metrics to track, with recommended targets, alert thresholds and a ready-to-use tracking table for your next quarterly review.



