Daniel A. runs a precision machining workshop. For years he assumed his company was too quiet to interest anyone: "We're not a bank." Then, one Monday morning, Marc K., his part-time IT lead, shows him a list: hundreds of login attempts on the company mailbox, all launched overnight. No one had singled Daniel out in particular — and that is exactly where the misunderstanding lies.
Why hackers target SMEs, really
The idea of being "targeted" is misleading. We picture a hacker in a hoodie who studies their prey, picks a company and prepares the strike. That image is reassuring — because we tell ourselves we're too small to be worth the effort. The reality is more ordinary, and a little more unsettling: most attacks target no one in particular.
Automated programs — software bots — sweep the internet continuously, day and night, looking for doors left open: a weak password, a piece of software that was never updated, an email address lying around. When a door gives way, the attack triggers on its own. Often the goal is to drop ransomware — software that encrypts (scrambles) all your files, then demands a ransom to give you back access. For whoever runs these bots, trying a small firm in the Jura or a global group costs roughly the same: almost nothing. So they try it on everyone.
That's the first reversal: your SME isn't "too small." It's simply within reach of the same net, cast at random across millions of addresses at once. Size doesn't protect you; your level of protection does.
Camille, our cyber advisor, often puts it this way: "Picture a street where a prowler tries every door handle, one by one, without knowing in advance what's behind them. They have nothing against you personally — they'll simply walk in wherever it's open. In cyber, that prowler doesn't even need to walk: a program tries thousands of handles a second. The only thing that matters is whether yours is locked." There's good news buried in that image: you can't stop the prowler from passing by, but you can decide that your handle, at least, won't turn.
The weak link in a chain
There's a second reason, and this one is more deliberate. A workshop like Daniel A.'s doesn't operate alone: it subcontracts for larger clients, in watchmaking or medical devices. An attacker who can't get into the big, well-protected group looks for another way in. That way in is often a smaller supplier, connected to the client through emails, shared files, sometimes a shared login to a platform.
This is called a supply chain attack: you don't storm the fortress head-on, you go through the supplier who holds a key. The SME becomes the entry point to bigger targets. This isn't an abstraction: it's precisely why more and more large clients now send their subcontractors a security questionnaire before renewing a contract. Being "the weak link" is no longer only a technical risk — it has become a commercial one.
Data that's worth something
Finally, contrary to what people assume, an industrial SME holds coveted things: technical drawings, machining specifications, its clients' intellectual property, its order book. A lot of value, often behind lighter protection than a large group's. For an attacker, that's the best ratio between effort and reward. The Swiss National Cyber Security Centre (NCSC) — the public reference in Switzerland — regularly publishes recommendations aimed specifically at SMEs, not out of excess zeal, but because they are genuinely concerned.
What to remember
- You're not targeted personally, but you are within reach. Attacks are automated and cast a wide net: the question isn't "am I an interesting target?" but "did a door stay open at my place?".
- Being small doesn't protect you — quite the opposite. Light protection makes you both an easy target and a convenient way in toward your clients and larger customers.
- The responsibility is yours. The nFADP (Switzerland's data protection act) expects a company to take security measures "appropriate" to the sensitivity of what it holds. This isn't a matter reserved for the big players; it's an expectation that applies to you too.
Habits to put in place this week
Here's the good news: the measures that block the vast majority of these automated attacks are simple, and most require neither a budget nor an in-house IT department. Three habits are enough to step out of the crowd of "open doors."
1. Turn on two-factor authentication, starting with email
Two-factor authentication (MFA) adds, on top of the password, a second proof of identity: usually a code or an approval on your phone. Even if a bot guesses your password, it stays locked out without that second factor. Start with the company mailbox — it's the most attacked door, and the one that opens the way to everything else. The feature already exists in most of the tools you use; you just have to switch it on.
2. List your access and your connections
Take thirty minutes to answer two very plain questions: who has access to what inside your company, and who are you connected to on the outside? Look in particular for former employees' accounts still active, shared logins no one watches anymore, and the digital links with your clients and suppliers. You can only protect well what you've first made visible.
3. Check that your backup really exists — and that it's kept apart
"We have backups" isn't enough. The real question is: if all your files were encrypted tomorrow morning, could you restart from a recent, intact copy kept separate from the rest? Check that a backup is actually running, that it isn't permanently connected to the network (otherwise ransomware reaches it too), and that a restore has been tested at least once. It's your safety net the day everything else gives way — and, for a workshop whose activity depends on drawings and orders, it's also the difference between a few hours of downtime and several lost production days.
Where do you really stand?
These three habits noticeably reduce your exposure. But they don't answer the underlying question Daniel A. and Marc K. are asking: across our whole organisation, where are our real weaknesses, and where should we start? Understanding why hackers target SMEs is a first step; knowing precisely where you stand is another.
Cyber Passport certifies nothing and won't declare you "compliant": it helps you carry out a structured, honest self-assessment that you can share with a client or an auditor who asks for it. You finally see your posture clearly, priority by priority, instead of a vague feeling of insecurity.
To turn that awareness into a concrete action plan, discover our blueprint dedicated to the cyber posture of SMEs.



