Podcast
The article takes the floor. A conversation generated by artificial intelligence.
IT security is no longer something you deal with now and then: it is part of how an SME runs every day, in Switzerland in particular. Yet many SMEs still rely on practices that have not kept pace with their tools, their working habits and the threats.
Far from being a domain reserved for large groups, cybersecurity has now imposed itself as a pillar of resilience for small structures. Incidents do not come only from sophisticated attacks, but also from incomplete protection, ageing configurations or procedures that are still informal.
A more exposed environment, with protection that is still uneven
Digital threats have become more frequent, more accessible, and harder to detect. Attacks no longer require advanced technical skills: ready-made kits make it possible to run phishing campaigns or automated scans.
Despite this trivialisation of risk, many Swiss SMEs still operate without a clearly defined security strategy. Few have a formalised plan for incident management, data protection, or staff awareness. As a result: some attacks succeed without any particularly complex technique, by exploiting missing protection, an access right that is too broad, or a procedure that was never formalised.
Data losses, ransomware, and identity-fraud cases remain frequent, even in small structures. And these aren’t exceptional cases: most cybersecurity providers in Switzerland note a regular increase in these incidents in the local economic fabric.
When the search for simplicity creates blind spots
One of today’s biggest paradoxes? Danger often comes from the search for simplicity. Staff still use their personal computer without encryption, store passwords in their inbox, or leave the accounts of long-departed employees active.
These practices, often kept in place to save time, create access paths and dependencies that are hard to control when an incident occurs.
The IT-security fundamentals you can no longer ignore
You don’t need a complex infrastructure to be secure. What counts is adopting good practices: simple but unavoidable.
Here are the main pillars every SME should master today:
- Strict access control: no shared accounts, rights limited to each role.
- Automatic backups (local and cloud), regularly tested.
- Continuous updates on all software, OS, and antivirus.
- Regular team awareness, with attack simulations (phishing, social engineering…).
These baseline measures sharply reduce exposure to the most common incidents we encounter. For the detailed action plan on a tight budget, see our cybersecurity priorities on a controlled budget.
Two incidents that could have been avoided
Two typical examples, representative of incidents we regularly see in French-speaking Switzerland.
In Lausanne, a fiduciary lost access to its customer files for four days because of a Word document containing a booby-trapped macro. Blocking macros and endpoint protection (EDR) would have been enough to protect it.
In Neuchâtel, an energy SME suffered a CHF 18,000 fraud after a transfer to a fake IBAN. A systematic manual check of transfers and better mailbox protection would have avoided the loss.
These Swiss examples are neither rare nor isolated.
Avepto: a partner for SMEs that no longer want to be victims
At Avepto, we support Swiss SMEs in setting up concrete IT-security solutions. No needless jargon, no over-engineered complexity: we favour effective tools, simple to maintain and tailored to your size.
Our approach rests on:
- An analysis of your existing risks.
- Setting up backup, supervision, filtering, and network access control solutions.
- Integration of secure cloud services (Microsoft 365, Infomaniak’s kDrive…).
- And above all: human support, with continuous follow-up and a real ability to intervene quickly.
To conclude: prepared rather than perfect
Good IT security is not about removing every risk. It is about knowing which systems the business cannot run without, protecting the accesses that matter and preparing the response to an incident.
A large share of attacks is opportunistic and automated. Others target a specific organisation, a specific role or a specific commercial relationship. An SME can be exposed in both cases, without that meaning it has been negligent.
The fundamentals remain within reach: appropriate access rights, tested backups, up-to-date systems, staff who know what to watch for, and clearly defined responsibilities.
Read about our approach to cybersecurity for SMEs.


