Podcast
The article takes the floor. A conversation generated by artificial intelligence.
An SME cannot secure everything at once. It can instead protect, as a priority, the access, data and services its activity depends on. Here is a pragmatic plan for investing in the right order. The good news: well-chosen priorities remain accessible, even on a tight budget.
Why Swiss SMEs think they’re too small to be attacked
Picture a Monday morning: your accounting is encrypted, your mail blocked, your teams at a standstill, and a laconic message demands a ransom. The targeted company has only 25 staff, no IT department, and thought hackers only went after large groups. In reality, attackers automate their campaigns and target the least-protected structures first.
A risk perception completely off
In reality, the gfs-zürich study run with la Mobilière shows only 46% of SMEs have implemented password creation rules, and only 40% genuinely raise staff awareness of cyber risks. The result is a gap between the real threat and the measures actually deployed.
Leaders underestimate the risk, treat cybersecurity as a luxury, and defer decisions, directly exposing cash, reputation, and contracts.
“We don’t have anything interesting”: the costly argument
Many executives tell themselves they don’t store strategic data. In practice, attackers are interested in anything that can be quickly monetised: mail access for payment fraud, server encryption to demand a ransom, theft of HR or customer files for extortion.
It isn’t top-secret data being targeted, but the company’s ability to keep functioning.
The false equation: security = big budget
Another brake: the idea that protecting yourself immediately implies a 24/7 security operations centre (SOC), complex solutions, and five-figure invoices. Result: many SMEs do… nothing.
Yet a large share of incidents still stem from basic flaws: weak password, no multi-factor authentication (MFA), missing updates, untested backups. An effective priority plan starts by fixing these points cheaply. More advanced investments come later, gradually.
Prioritise real risks without blowing the budget
You can’t secure everything 100% right away. But you can decide what you refuse to lose: invoicing, email, customer files, ERP, production files. The point isn’t to buy the best solution; it’s to limit business impact as much as possible.
Map the scenarios that would really hurt
Start with a simple question: If this system goes down for three days, what concretely happens? Take your key functions: accounting, production, sales, support, HR. For each:
- identify the necessary applications and data (ERP, CRM, shared files, email);
- assess the impact of an extended outage (cash, contracts, image, legal obligations);
- note external dependencies (host, cloud provider, IT partner).
You get a short list of high-pain crisis scenarios: ransomware blocking the file server, impersonation of your email to defraud your customers, theft of bank-account access, loss of a poorly backed-up cloud. These should drive your spending.
Rate risks: probability × impact
Next, give each scenario an estimate of probability (low, medium, high) and impact (low, medium, high). A targeted attack by a highly sophisticated group remains unlikely for a small structure.
On the other hand, ransomware spread massively via a booby-trapped attachment has a real probability, especially when only 40% of staff are aware of digital risks. Concentrate your efforts on medium/high-probability + high-impact risks: email, account access, the servers or cloud services that carry your operations, backups.
The near-zero-cost cybersecurity baseline for any SME
Before buying tools, lock down the basics. This baseline often only requires time, a bit of method, and occasional external support to move faster.
Standardise access: passwords, MFA, shared accounts
If only 46% of SMEs have password rules, your competitive advantage starts there. Decide on simple, non-negotiable rules: minimum length, ban on reused passwords, recommended password manager, rotation in case of suspicion.
Enable MFA wherever possible: email, cloud tools, VPN. Remove generic shared accounts (e.g. info@ used by everyone for everything) or, at minimum, immediately change their passwords on a departure. A provider like Avepto can fold these measures into a global identity and access management approach to avoid recurring human flaws.
Tidy up workstations and updates
Many attacks succeed because workstations are behind on updates. Set a simple internal rule: automatic updates enabled on all systems, with a monthly check.
Uninstall obsolete or unused software, which expands your attack surface for no benefit. Block rogue installs: no new software without validation, no unknown USB key plugged into a workstation. Install a proper antivirus on every endpoint: even a basic, well-managed solution beats a misconfigured sophisticated one.
Train quickly without organising a seminar
Since only 40% of SMEs raise team awareness of cyber risks, you can sharply reduce your exposure with a one-hour focused action. Goal: teach teams to spot a fraudulent email, verify an urgent payment request, report an incident without fear of sanction, and protect customer data.
A simple internal kit (ten slides, three concrete examples, clear procedures) is enough to start. Add a quarterly reminder with two or three new examples to maintain reflexes. To structure that awareness work over time, see our article on phishing training that actually works.
Which paid solutions to choose when every franc counts
Most companies plan to raise their cybersecurity budget. If your budget remains limited, the goal is to invest in what truly reduces potential losses, not in what shines most on a flyer.
Cyber insurance and local aid: an underused lever
Cyber insurance generally offers two pillars: incident assistance (specialists, lawyers, communication) and coverage of certain damages (business interruption, data restoration, response costs). Before subscribing, check the prerequisites: backups, antivirus, MFA, password policy.
Several cantons and economic-support bodies can occasionally fund security audits or upgrade projects. These aids evolve, but the logic is the same: encourage SMEs to set up a minimal security baseline. A discussion with your chamber of commerce or a local provider helps identify what you can claim.
Choose your security building blocks without scattering
With a limited budget, focus your investments on four axes: endpoint protection (managed antivirus/EDR), email security, professional backup, supervision by a provider. A managed EDR solution helps detect suspicious behaviours on endpoints faster.
Advanced email filtering massively reduces phishing attempts. A managed external backup lets you recover your critical data. Finally, a managed-services contract gives you a single point of contact for any security or availability issue. The point is to assemble these building blocks coherently rather than stack isolated products.
To go further, a partner like Avepto can combine cybersecurity solutions, backup, and managed services into one offering designed for SMEs.
Your 30-day cybersecurity action plan with limited resources
You don’t have time to launch a big cybersecurity project. But you can transform your security posture in 30 days, in 30- to 60-minute blocks, following a clear roadmap.
Days 1–10: stabilise the visible foundations
In the first ten days, focus on three workstreams. First, list your critical systems: email, servers, cloud solutions, ERP, shared files, invoicing tools. Document who accesses them and how.
Next, enforce your new password rules and enable MFA on services that allow it. Finally, run a micro-awareness session for your teams: 30 minutes, three recent attack examples, and a clear rule for reporting any doubt.
Days 11–20: lock down data and backups
Second phase: reduce the probability of data loss or encryption. Start by checking your backups: location, frequency, retention, recent restore test. If you can’t restore a file or full system in real conditions, treat the backup as nonexistent.
Then put in place minimal segmentation: limit access rights to only those who need them. Use the moment to disable the accounts of former staff still active. Where it makes sense, consider a managed professional backup solution, like those offered by IT specialists through SME secure-data-backup services.
Days 21–30: organise the response and delegate what must be delegated
Final step: prepare for the day something goes wrong. Write a simple escalation procedure: who to alert first, which machines to disconnect immediately, who is allowed to speak externally (clients, press, authorities), how to contact your insurer and your IT provider.
Make sure critical contact numbers are accessible offline. Then identify everything you can’t handle in-house: continuous system supervision, advanced alert handling, technical responses to an attack. Delegate these to a provider capable of supplying managed services and security monitoring sized for your scale.
In thirty days an SME can clarify its priorities, fix several common weaknesses and have a first response procedure in place. Lasting control then takes regular follow-up. To turn this roadmap into an execution plan suited to your reality, schedule an exchange with Avepto and get an action-oriented cyber diagnosis.


