Getting started
Cyberattacks affect micro-enterprises, too. Five essential measures can significantly improve your cybersecurity levels: multi-factor authentication, daily backups, updates, caution when opening emails, and secure passwords.
Many micro-enterprises assume that they are of no interest to cybercriminals. However, the reality is very different. Hackers use automated programs that scan the internet for vulnerabilities. It doesn’t matter whether you are a global corporation or a local trade business with a handful of employees: a single successful attack can bring your company to a standstill, prevent you from paying your bills or expose your customers’ data online. This means that IT security is not just a matter of business continuity but of safeguarding your company’s very existence.
The essential checklist: five steps that offer vital protection
To make it as easy as possible for you to get started with cybersecurity, you should focus on the following points when protecting your systems. These measures often take very little time, but significantly increase your protection level:
- Use multi-factor authentication (MFA)
Enable MFA wherever possible (email, banking, cloud, etc.). A password alone no longer offers enough protection. - Back up your data regularly
Back up your data to an external storage device or secure cloud on a regular basis. It is important that the backup is not permanently connected to your computer, so that it remains safe from attacks. - Install updates regularly
Install security updates for all hardware and software components, your smartphone and your tablet as soon as they are available. These updates close known vulnerabilities that could be exploited by attackers. - Be wary of unusual emails
Be wary of unexpected attachments or links, even if you think you know the sender. A quick phone call can protect you from an expensive scam. Do not use the phone number provided in the email when making the call. Look up the number on the sender’s website instead. - Use secure passwords
Choose different passwords for each service, ensuring they always consist of at least 12 characters. A password manager can help you to keep track of them all without having to remember everything yourself.
The new Swiss Data Protection Act (FADP): what you need to know
The revised Data Protection Act (FADP) came into force on 1 September 2023. The Act includes IT security requirements that also apply to micro-enterprises: for example, you must protect your customer data using appropriate technical and organisational measures.
A key aspect of the FADP is the transparency requirement: you must inform your customers what data you collect and why. If data is stolen or lost, you may also be required to report this to the Federal Data Protection and Information Commissioner (FDPIC). By introducing the basic technical measures outlined above, you will already be meeting many of the legal data security requirements, as well as minimising the risk of legal implications or reputational damage.
Cloud applications: who is actually responsible?
The switch to cloud services such as Microsoft 365 and Google Workspace offers benefits for micro-enterprises in terms of flexibility and collaboration. However, it is a common misconception that subscribing to a cloud service transfers all responsibility for security to the provider. Experts in this field use the term "shared responsibility model". While Microsoft is responsible for the physical security of its data centres and for ensuring its infrastructure is available, you as the business owner are responsible for who has access to your data and how this access is configured.
Cloud accounts without MFA are currently one of the biggest gateways for identity theft. You should also bear in mind that, due to the standard data retention periods, the cloud cannot replace a proper backup strategy. If you haven’t implemented independent backups via a third-party provider, any accidentally deleted documents or cloud storage encrypted by ransomware may be lost. The cloud protects you against hardware failures, but not against user error or targeted attacks on your login credentials.
IT service providers as strategic partners
For micro-enterprises without their own IT department, working with a competent IT service provider is the best solution. A good service provider is much more than just an emergency contact in case your printer breaks down. Instead, it acts as your proactive security adviser. Behind the scenes, it ensures that your firewall is configured correctly, antivirus software is running on all your devices, the cloud backups mentioned above are actually working, and any available hardware and software updates are installed promptly
Although delegating IT to experts doesn’t free you from ultimate responsibility as the business owner, it does give you the assurance that your systems are being monitored in accordance with current standards. This kind of partnership is particularly valuable in relation to the Swiss Data Protection Act (FADP), as your service provider can help you to implement and document the necessary technical and organisational measures. When choosing your partner, look for clear service level agreements (SLAs) and ensure that you explicitly discuss the issue of security, instead of focusing solely on device functionality.
Conclusion: Getting started is more important than perfection
You don’t have to be an IT expert to make your company more secure. The most important step is to stop avoiding the issue. Begin by backing up your critical accounts and data. IT security is an ongoing process that starts with small but consistent steps. That way, your focus stays where it should be: on your core business and customers.
Strong cybersecurity foundations for businesses and public authorities
Further information
ITSec4KMU (German and French)
German Federal Office for Information Security (BSI) – Cybersecurity for SMEs (German)
