Cybersecurity is a bit like taking out insurance: you don’t always think about it until the day it’s too late. Swiss SMEs are not spared from cyberattacks.
On the contrary, they are often prime targets precisely because they are seen as less well protected than large companies. However, defending against common risks starts with raising awareness about everyday practices. Of course, this does not prevent turning to specialized solutions to better protect your IT system.
1. Passwords: not to be taken lightly
Do you remember that password you’ve been using everywhere since 2014? Yes, the one you chose because it’s easy to remember. Bad idea. Passwords are often the first line of defense against intrusions. And unfortunately, “admin123” or “Jean1975” don’t stand up to automated attacks for long.
Best practice
Use long passwords (at least 12 characters), complex ones (mix letters, numbers, and symbols), and above all, make sure each account has a unique password. Yes, for every account.
The simple solution
Install a password manager. It generates and securely stores your passwords for you. No more having to invent and remember them all!
2. Updates are not a 'later' thing
Are you postponing updates on your computer because you’re “in the middle of work”? We understand. But know that these updates fix well-known security vulnerabilities. And if you don’t install them, you’re leaving your front door wide open.
Best practice
Enable automatic updates on your systems, software, and applications. Whether it’s Windows, macOS, Android, iOS, your antivirus, or your accounting software, everything must be up to date.
Bonus for SMEs
Ask your IT provider to implement a centralized update policy to ensure everyone is protected.
3. Beware of suspicious emails (even if they come from 'your boss')
Phishing is when a hacker sends you an email that appears to come from someone or a company you know, trying to get you to click on a link or open an attachment. These attacks are becoming more and more sophisticated, so sometimes only a small detail—like the sender’s email address—can tip you off. But it’s not always obvious, and with AI spreading everywhere, the risk of falling for these traps is increasing.
Best practice
Always be suspicious of unexpected emails, especially if they ask you to act quickly (pay an invoice, make a transfer, send a password, click a link).
A simple reflex
If in doubt, call the person who supposedly sent you the email (using their real number, not the one in the email).
4. Backing up is like breathing
Your computer breaks down, or worse, ransomware locks all your data. What happens if you don’t have a backup? … You lose everything: photos, documents, memories, work.
Best practice
Set up automatic and regular backups of your important data. Store these backups in a location physically separate from your main system (for example, on an external drive kept in another building or in a secure safe).
And above all
Regularly test that your backups work!
5. Don’t stay alone: find a trusted partner
You don’t have the time or resources to do everything yourself? That’s normal. Just like with accounting or HR, in many cases, it’s important to surround yourself with specialists.
Best practice: Find a trusted partner who can advise you, monitor your infrastructure, and respond quickly in case of an incident.

Praethorus by ELCA supports Swiss SMEs in their cybersecurity efforts. We don’t come with expert jargon, but with concrete solutions tailored to your real needs. Audit, raising your team’s awareness, implementing protections, incident response: we are by your side.
Cybersecurity can seem abstract or too technical, especially for an SME focused on its core business. But the threats are very real, and the consequences of an attack can be serious: data loss, business interruption, damage to your reputation…
By applying these 5 reflexes, you already cover a very large part of common risks.
Take one step towards cybersecurity, and we will take the other 99 with you. Click here to learn more about Praethorus.

