[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"mdc--2fg4uz-key":3},{"data":4,"body":5},{},{"type":6,"children":7},"root",[8,16,23,28,35,51,56,62,67,72,78,83,88,94,99,105,118,138,143,149,154,159,165,170,176,181,202,208,213,226,232,237,250,256,261,267,272,277,283,288,293,306,312,317,323,328,333,339,344,364,370,383,388],{"type":9,"tag":10,"props":11,"children":12},"element","p",{},[13],{"type":14,"value":15},"text","An SME cannot secure everything at once. It can instead protect, as a priority, the access, data and services its activity depends on. Here is a pragmatic plan for investing in the right order. The good news: well-chosen priorities remain accessible, even on a tight budget.",{"type":9,"tag":17,"props":18,"children":20},"h2",{"id":19},"why-swiss-smes-think-theyre-too-small-to-be-attacked",[21],{"type":14,"value":22},"Why Swiss SMEs think they’re too small to be attacked",{"type":9,"tag":10,"props":24,"children":25},{},[26],{"type":14,"value":27},"Picture a Monday morning: your accounting is encrypted, your mail blocked, your teams at a standstill, and a laconic message demands a ransom. The targeted company has only 25 staff, no IT department, and thought hackers only went after large groups. In reality, attackers automate their campaigns and target the least-protected structures first.",{"type":9,"tag":29,"props":30,"children":32},"h3",{"id":31},"a-badly-skewed-perception-of-risk",[33],{"type":14,"value":34},"A badly skewed perception of risk",{"type":9,"tag":10,"props":36,"children":37},{},[38,40,49],{"type":14,"value":39},"In fact, ",{"type":9,"tag":41,"props":42,"children":46},"a",{"href":43,"rel":44},"https:\u002F\u002Fwww.mobiliere.ch\u002Fetude\u002Fteletravail-cybersecurite-pme-suisse",[45],"nofollow",[47],{"type":14,"value":48},"the gfs-zürich study run with la Mobilière",{"type":14,"value":50}," shows only 46% of SMEs have implemented password creation rules, and only 40% genuinely raise staff awareness of cyber risks. The result is a gap between the real threat and the measures actually deployed.",{"type":9,"tag":10,"props":52,"children":53},{},[54],{"type":14,"value":55},"Leaders underestimate the risk, treat cybersecurity as a luxury, and defer decisions, directly exposing cash, reputation, and contracts.",{"type":9,"tag":29,"props":57,"children":59},{"id":58},"we-dont-have-anything-interesting-the-costly-argument",[60],{"type":14,"value":61},"“We don’t have anything interesting”: the costly argument",{"type":9,"tag":10,"props":63,"children":64},{},[65],{"type":14,"value":66},"Many executives tell themselves they don’t store strategic data. In practice, attackers are interested in anything that can be quickly monetised: mail access for payment fraud, server encryption to demand a ransom, theft of HR or customer files for extortion.",{"type":9,"tag":10,"props":68,"children":69},{},[70],{"type":14,"value":71},"It isn’t top-secret data being targeted, but the company’s ability to keep functioning.",{"type":9,"tag":29,"props":73,"children":75},{"id":74},"the-false-equation-security-big-budget",[76],{"type":14,"value":77},"The false equation: security = big budget",{"type":9,"tag":10,"props":79,"children":80},{},[81],{"type":14,"value":82},"Another obstacle: the idea that protecting yourself immediately implies a 24\u002F7 security operations centre (SOC), complex solutions, and five-figure invoices. Result: many SMEs do… nothing.",{"type":9,"tag":10,"props":84,"children":85},{},[86],{"type":14,"value":87},"Yet a large share of incidents still stem from basic flaws: weak password, no multi-factor authentication (MFA), missing updates, untested backups. An effective priority plan starts by fixing these points cheaply. More advanced investments come later, gradually.",{"type":9,"tag":17,"props":89,"children":91},{"id":90},"prioritise-real-risks-without-blowing-the-budget",[92],{"type":14,"value":93},"Prioritise real risks without blowing the budget",{"type":9,"tag":10,"props":95,"children":96},{},[97],{"type":14,"value":98},"You can’t secure everything 100% right away. But you can decide what you refuse to lose: invoicing, email, customer files, ERP, production files. The point isn’t to buy the best solution; it’s to limit business impact as much as possible.",{"type":9,"tag":29,"props":100,"children":102},{"id":101},"map-the-scenarios-that-would-really-hurt",[103],{"type":14,"value":104},"Map the scenarios that would really hurt",{"type":9,"tag":10,"props":106,"children":107},{},[108,110,116],{"type":14,"value":109},"Start with a simple question: ",{"type":9,"tag":111,"props":112,"children":113},"em",{},[114],{"type":14,"value":115},"If this system goes down for three days, what concretely happens?",{"type":14,"value":117}," Take your key functions: accounting, production, sales, support, HR. For each:",{"type":9,"tag":119,"props":120,"children":121},"ul",{},[122,128,133],{"type":9,"tag":123,"props":124,"children":125},"li",{},[126],{"type":14,"value":127},"identify the necessary applications and data (ERP, CRM, shared files, email);",{"type":9,"tag":123,"props":129,"children":130},{},[131],{"type":14,"value":132},"assess the impact of an extended outage (cash, contracts, image, legal obligations);",{"type":9,"tag":123,"props":134,"children":135},{},[136],{"type":14,"value":137},"note external dependencies (host, cloud provider, IT partner).",{"type":9,"tag":10,"props":139,"children":140},{},[141],{"type":14,"value":142},"You end up with a short list of the crisis scenarios that would hurt most: ransomware blocking the file server, impersonation of your email to defraud your customers, theft of bank-account access, loss of a poorly backed-up cloud. These should drive your spending.",{"type":9,"tag":29,"props":144,"children":146},{"id":145},"rate-risks-probability-impact",[147],{"type":14,"value":148},"Rate risks: probability × impact",{"type":9,"tag":10,"props":150,"children":151},{},[152],{"type":14,"value":153},"Next, give each scenario an estimate of probability (low, medium, high) and impact (low, medium, high). A targeted attack by a highly sophisticated group remains unlikely for a small structure.",{"type":9,"tag":10,"props":155,"children":156},{},[157],{"type":14,"value":158},"On the other hand, ransomware sent at scale through a malicious attachment is a real possibility. It deserves priority treatment, especially as only 40% of the SMEs surveyed say they train their staff on digital risks. Concentrate your efforts on medium\u002Fhigh-probability + high-impact risks: email, account access, the servers or cloud services that carry your operations, backups.",{"type":9,"tag":17,"props":160,"children":162},{"id":161},"a-low-cost-cybersecurity-baseline-for-any-sme",[163],{"type":14,"value":164},"A low-cost cybersecurity baseline for any SME",{"type":9,"tag":10,"props":166,"children":167},{},[168],{"type":14,"value":169},"Before buying tools, lock down the basics. This baseline often only requires time, a bit of method, and occasional external support to move faster.",{"type":9,"tag":29,"props":171,"children":173},{"id":172},"standardise-access-passwords-mfa-shared-accounts",[174],{"type":14,"value":175},"Standardise access: passwords, MFA, shared accounts",{"type":9,"tag":10,"props":177,"children":178},{},[179],{"type":14,"value":180},"If only 46% of SMEs have password rules, your competitive advantage starts there. Decide on simple, non-negotiable rules: minimum length, ban on reused passwords, recommended password manager, rotation in case of suspicion.",{"type":9,"tag":10,"props":182,"children":183},{},[184,186,192,194,200],{"type":14,"value":185},"Enable MFA wherever possible: email, cloud tools, ",{"type":9,"tag":41,"props":187,"children":189},{"href":188},"\u002Fen\u002Fproductivity\u002Fvpn",[190],{"type":14,"value":191},"VPN",{"type":14,"value":193},". Remove generic shared accounts (e.g. info@ used by everyone for everything) or, at minimum, immediately change their passwords on a departure. A provider like Avepto can fold these measures into a global ",{"type":9,"tag":41,"props":195,"children":197},{"href":196},"\u002Fen\u002Fcybersecurity\u002Fidentity",[198],{"type":14,"value":199},"identity and access management",{"type":14,"value":201}," approach to avoid recurring human flaws.",{"type":9,"tag":29,"props":203,"children":205},{"id":204},"tidy-up-workstations-and-updates",[206],{"type":14,"value":207},"Tidy up workstations and updates",{"type":9,"tag":10,"props":209,"children":210},{},[211],{"type":14,"value":212},"Many attacks succeed because workstations are behind on updates. Set a simple internal rule: automatic updates enabled on all systems, with a monthly check.",{"type":9,"tag":10,"props":214,"children":215},{},[216,218,224],{"type":14,"value":217},"Uninstall obsolete or unused software, which expands your attack surface for no benefit. Block rogue installs: no new software without validation, no unknown USB key plugged into a workstation. Deploy ",{"type":9,"tag":41,"props":219,"children":221},{"href":220},"\u002Fen\u002Fcybersecurity\u002Fantivirus",[222],{"type":14,"value":223},"properly configured, managed endpoint protection",{"type":14,"value":225}," on every device: a basic, well-maintained solution beats a sophisticated one left misconfigured.",{"type":9,"tag":29,"props":227,"children":229},{"id":228},"train-quickly-without-organising-a-seminar",[230],{"type":14,"value":231},"Train quickly without organising a seminar",{"type":9,"tag":10,"props":233,"children":234},{},[235],{"type":14,"value":236},"Since only 40% of SMEs raise team awareness of cyber risks, you can sharply reduce your exposure with a focused one-hour session. Goal: teach teams to spot a fraudulent email, verify an urgent payment request, report an incident without fear of sanction, and protect customer data.",{"type":9,"tag":10,"props":238,"children":239},{},[240,242,248],{"type":14,"value":241},"A simple internal kit (ten slides, three concrete examples, clear procedures) is enough to start. Add a quarterly reminder with two or three new examples to keep the habits alive. To structure that awareness work over time, see our article on ",{"type":9,"tag":41,"props":243,"children":245},{"href":244},"\u002Fen\u002Farticles\u002Fphishing-training-employees",[246],{"type":14,"value":247},"phishing training that actually works",{"type":14,"value":249},".",{"type":9,"tag":17,"props":251,"children":253},{"id":252},"which-paid-solutions-to-choose-when-every-franc-counts",[254],{"type":14,"value":255},"Which paid solutions to choose when every franc counts",{"type":9,"tag":10,"props":257,"children":258},{},[259],{"type":14,"value":260},"With a limited budget, the goal is to invest in what truly reduces potential losses, not in what shines most on a flyer.",{"type":9,"tag":29,"props":262,"children":264},{"id":263},"cyber-insurance-and-local-aid-an-underused-lever",[265],{"type":14,"value":266},"Cyber insurance and local aid: an underused lever",{"type":9,"tag":10,"props":268,"children":269},{},[270],{"type":14,"value":271},"Cyber insurance generally offers two pillars: incident assistance (specialists, lawyers, communication) and coverage of certain damages (business interruption, data restoration, response costs). Before subscribing, check the prerequisites: backups, antivirus, MFA, password policy.",{"type":9,"tag":10,"props":273,"children":274},{},[275],{"type":14,"value":276},"Several cantons and economic-support bodies can occasionally fund security audits or upgrade projects. These aids evolve, but the logic is the same: encourage SMEs to set up a minimal security baseline. A discussion with your chamber of commerce or a local provider helps identify what you can claim.",{"type":9,"tag":29,"props":278,"children":280},{"id":279},"choose-your-security-building-blocks-with-focus",[281],{"type":14,"value":282},"Choose your security building blocks with focus",{"type":9,"tag":10,"props":284,"children":285},{},[286],{"type":14,"value":287},"With a limited budget, focus your investments on four axes: endpoint protection (managed antivirus\u002FEDR), email security, professional backup, supervision by a provider. A managed EDR solution helps detect suspicious behaviours on endpoints faster.",{"type":9,"tag":10,"props":289,"children":290},{},[291],{"type":14,"value":292},"Advanced email filtering stops a large share of fraudulent messages before they reach the inbox. A managed external backup lets you recover your critical data. Finally, a managed-services contract gives you a single point of contact for any security or availability issue. The point is to assemble these building blocks coherently rather than stack isolated products.",{"type":9,"tag":10,"props":294,"children":295},{},[296,298,304],{"type":14,"value":297},"To go further, a partner like Avepto can combine ",{"type":9,"tag":41,"props":299,"children":301},{"href":300},"\u002Fen\u002Fcybersecurity",[302],{"type":14,"value":303},"cybersecurity solutions",{"type":14,"value":305},", backup, and managed services into one offering designed for SMEs.",{"type":9,"tag":17,"props":307,"children":309},{"id":308},"your-30-day-cybersecurity-action-plan-with-limited-resources",[310],{"type":14,"value":311},"Your 30-day cybersecurity action plan with limited resources",{"type":9,"tag":10,"props":313,"children":314},{},[315],{"type":14,"value":316},"You don’t have time to launch a big cybersecurity project. But you can transform your security posture in 30 days, in 30- to 60-minute blocks, following a clear roadmap.",{"type":9,"tag":29,"props":318,"children":320},{"id":319},"days-110-stabilise-the-visible-foundations",[321],{"type":14,"value":322},"Days 1–10: stabilise the visible foundations",{"type":9,"tag":10,"props":324,"children":325},{},[326],{"type":14,"value":327},"In the first ten days, focus on three workstreams. First, list your critical systems: email, servers, cloud solutions, ERP, shared files, invoicing tools. Document who accesses them and how.",{"type":9,"tag":10,"props":329,"children":330},{},[331],{"type":14,"value":332},"Next, enforce your new password rules and enable MFA on services that allow it. Finally, run a micro-awareness session for your teams: 30 minutes, three recent attack examples, and a clear rule for reporting any doubt.",{"type":9,"tag":29,"props":334,"children":336},{"id":335},"days-1120-lock-down-data-and-backups",[337],{"type":14,"value":338},"Days 11–20: lock down data and backups",{"type":9,"tag":10,"props":340,"children":341},{},[342],{"type":14,"value":343},"Second phase: reduce the probability of data loss or encryption. Start by checking your backups: location, frequency, retention, recent restore test. Until restoring a file or a full system has been tested in real conditions, you cannot know whether it will work on the day you need it.",{"type":9,"tag":10,"props":345,"children":346},{},[347,349,355,357,363],{"type":14,"value":348},"Then put in place ",{"type":9,"tag":41,"props":350,"children":352},{"href":351},"\u002Fen\u002Fcybersecurity\u002Fnetworks",[353],{"type":14,"value":354},"minimal segmentation",{"type":14,"value":356},": limit access rights to only those who need them. Use the moment to disable the accounts of former staff still active. Where it makes sense, consider a managed professional backup solution, such as our ",{"type":9,"tag":41,"props":358,"children":360},{"href":359},"\u002Fen\u002Fmanaged-it\u002Fbackups",[361],{"type":14,"value":362},"managed backup services for SMEs",{"type":14,"value":249},{"type":9,"tag":29,"props":365,"children":367},{"id":366},"days-2130-organise-the-response-and-delegate-what-must-be-delegated",[368],{"type":14,"value":369},"Days 21–30: organise the response and delegate what must be delegated",{"type":9,"tag":10,"props":371,"children":372},{},[373,375,381],{"type":14,"value":374},"Final step: prepare for the day something goes wrong. Write a simple ",{"type":9,"tag":41,"props":376,"children":378},{"href":377},"\u002Fen\u002Fcybersecurity\u002Fdisaster-recovery",[379],{"type":14,"value":380},"escalation and recovery procedure",{"type":14,"value":382},": who to alert first, which machines to disconnect immediately, who is allowed to speak externally (clients, press, authorities), how to contact your insurer and your IT provider.",{"type":9,"tag":10,"props":384,"children":385},{},[386],{"type":14,"value":387},"Make sure critical contact numbers are accessible offline. Then identify everything you can’t handle in-house: continuous system supervision, advanced alert handling, technical responses to an attack. Delegate these to a provider capable of supplying managed services and security monitoring sized for your scale.",{"type":9,"tag":10,"props":389,"children":390},{},[391,393,399],{"type":14,"value":392},"In thirty days an SME can clarify its priorities, fix several common weaknesses and have a first response procedure in place. Lasting control then takes regular follow-up. To turn this roadmap into an execution plan suited to your reality, ",{"type":9,"tag":41,"props":394,"children":396},{"href":395},"\u002Fen\u002Fcontact",[397],{"type":14,"value":398},"schedule an exchange with Avepto",{"type":14,"value":400}," and get an action-oriented cyber diagnosis."]