Swiss SMEs are attacked with commodity techniques, not bespoke ones. The intrusions we review almost never involve a novel exploit. They involve a password that was reused, an account that was never disabled, a backup that was reachable from the same network it was supposed to protect, or an invoice email that looked right.

That is good news, because commodity attacks have commodity defences. The problem is that security spending rarely follows the attack pattern — it follows the vendor conversation.

The five, in priority order

1. Multi-factor authentication on everything external. Email, VPN, remote desktop, the ERP, the finance system. Not "on admin accounts" — on everything reachable from outside. This single control removes the largest category of intrusion, and it costs licence configuration rather than money.

2. A leaver process that actually revokes. Accounts belonging to people who left are a standing finding in almost every assessment. Tie deprovisioning to the HR event, not to a helpdesk ticket somebody remembers to raise.

3. Backups that an attacker cannot reach. A backup on the same domain, with the same credentials, on the same network, is not a backup — it is a second copy waiting to be encrypted. Offline or immutable, and restored in a test at least twice a year. An untested backup is a hypothesis.

4. Payment change verification out of band. Business email compromise does not break encryption; it asks accounts payable to update bank details. One phone call to a number you already had, every time, no exceptions for urgency. Urgency is the attack.

5. Patching with a deadline. Not a patching policy — a deadline, with an owner, and a report that shows what missed it.

Everything after these five is refinement.

What does the revised FADP require of an SME?

It requires you to be able to demonstrate what personal data you hold, where it is, who can reach it, and on what legal basis — plus notification of breaches likely to result in high risk to the people affected. It does not prescribe specific technical controls, and it does not require data to stay in Switzerland.

The practical consequence is that the data inventory is the compliance artefact that matters most, and it is also the thing that makes the five controls above implementable. We cover the detail in what Swiss companies actually have to do under the revised FADP.

What should an SME actually spend?

ItemTypical annual costPriority
MFA rollout and enforcementLicence config, mostly timeImmediate
Endpoint detection and responseCHF 40–90 per seatHigh
Immutable or offline backupCHF 3,000–15,000Immediate
Security awareness with phishing simulationCHF 20–50 per personHigh
External penetration testCHF 12,000–35,000After the five
24/7 managed detectionCHF 30,000+Only with a response plan

Ranges are typical observations from the Swiss market and vary with estate size. Buying the bottom row before fixing the top rows is the most common misallocation we see: continuous monitoring produces alerts, and alerts without a response process produce a subscription.

Do we need a penetration test?

Not until the five controls are in place. A penetration test against an estate with no MFA and an unrevoked leaver account will report exactly that, at considerable expense, and you will have paid a specialist to tell you something an inventory would have shown for free.

Test once the obvious is closed. Then it is genuinely informative.

Operational technology is a different problem

If you run production equipment, the assumption that you can patch on a schedule is usually wrong, and the assumption that OT is air-gapped is almost always wrong too. Segment first, monitor the boundary, and treat vendor remote-access channels as the primary risk — they typically bypass everything else you have built. Our cybersecurity practice starts OT engagements with a connectivity map rather than a control framework, because the map usually changes the framework.

Where to start this month

Run one query: list every external-facing service and whether MFA is enforced on it. Not policy — enforcement. That list, on one page, will tell you more about your real exposure than any framework assessment, and it takes an afternoon.

Guidance for Swiss organisations is published by the National Cyber Security Centre, which is worth reading before any vendor conversation.

Working on this right now?

Tell us where you are in two questions. A consulting partner reviews every enquiry within 2 business days.