Security

SME cybersecurity: the 2026 guide

A practical guide to cybersecurity for Swiss SMEs in 2026: data protection obligations, common threats, priority measures and realistic costs.

David Cunha

David Cunha

Published on February 10, 2026 9 min read
SECURITY

Cybersecurity is no longer the preserve of large companies. Swiss SMEs are now prime targets precisely because they process sensitive data while having limited defences. This guide sets out what you need to know and do concretely in 2026.

CHF 50,000+
frequent total cost of a ransomware incident for a 20-person SME
CHF 250,000
maximum FADP fine for the responsible individuals
CHF 400–750/mo
realistic budget to properly secure 20 workstations

The threat landscape in 2026

Ransomware remains the most costly threat

Ransomware encrypts all your data and demands a ransom to decrypt it. Targeted companies are often paralysed for several days or weeks. The total cost of a ransomware incident. ransom, restoration time, lost revenue, crisis communication. frequently exceeds CHF 50,000 for an SME of 20 people, even without paying the ransom.

In 2024, the Swiss National Cyber Security Centre (NCSC) recorded a significant increase in ransomware reports affecting SMEs. The most affected sectors: trust and fiduciary services, healthcare, industry and retail.

Phishing has become professionalised

The phishing emails of 2026 no longer resemble the clumsy attempts of the 2010s. They perfectly imitate your bank, your cloud provider or a colleague. They use public information (LinkedIn, website) to personalise the message. The click rate is markedly higher than that observed on generic campaigns.

"Business email compromise" (impersonating an executive to request an urgent transfer) is the most costly variant. and one of the hardest to detect without team training.

Insecure access. the most common intrusion vector

Most intrusions do not come through a sophisticated technical flaw. They come through:

  • Weak or reused passwords (the same ones for personal and work accounts)
  • The absence of multi-factor authentication on remote access
  • Network equipment (routers, firewalls) never updated since installation
  • Former employees' accounts never deactivated

What the Swiss Data Protection Act requires

The revised Swiss Data Protection Act (FADP), in force since 1 September 2023, imposes several security obligations on Swiss companies:

  • Privacy by design and by default: data protection must be built into your systems and processes from the design stage, not added afterwards
  • Breach notification: any data breach presenting a high risk to the individuals concerned must be reported to the FDPIC "as soon as possible"
  • Record of processing activities: mandatory for companies processing sensitive data or carrying out large-scale profiling
  • Appropriate security measures: an obligation to implement technical and organisational measures suited to the risks

The priority measures. in order

1. Multi-factor authentication (MFA) everywhere

This is the measure with the best cost/effectiveness ratio. Enabling MFA on your email, your VPN and your Microsoft 365 or Google Workspace takes half a day and blocks the vast majority of intrusion attempts using stolen credentials.

2. Verified and off-site backups

A backup that has never been tested is not a backup. It may be corrupted, incomplete or inaccessible at the moment you need it. The 3-2-1 rule remains the standard: 3 copies, on 2 different media, 1 of which is off-site.

"Off-site" means physically separated from your main infrastructure, not a hard drive in the same office. In the event of ransomware or fire, your local backups are useless.

3. EDR on all workstations and servers

Traditional signature-based antivirus does not detect modern threats. An EDR (Endpoint Detection & Response) monitors process behaviour in real time and can automatically isolate a compromised workstation before the infection spreads.

Indicative cost: CHF 5 to 15 per workstation per month depending on the solution. For an SME with 20 workstations, that's CHF 100 to 300/month. far lower than the cost of an incident.

4. Updating network equipment

Check when your firewall and network switches last received a firmware update. If you don't know, that's already a problem. Vulnerabilities in network equipment are exploited actively and quickly after their public disclosure.

5. Staff training

An annual 1- to 2-hour session on recognising phishing, password management and the right reflexes in the event of a suspicious incident. No need for a certification course. you need concrete content, real examples, and clear procedures ("if you receive a suspicious email, here's what to do").

What it costs

For an SME of 20 people, properly securing its infrastructure represents:

  • EDR for 20 workstations: CHF 200 to 300/month
  • Managed firewall: CHF 150 to 300/month (depending on the hardware)
  • Off-site cloud backup: CHF 50 to 150/month depending on volume
  • Annual training: CHF 500 to 1,500 for the full session
  • Annual security audit: CHF 1,500 to 4,000 depending on depth

Total: CHF 400 to 750/month in running costs, plus a one-off investment in audits and training. That's significant, but it should be put in perspective against the cost of a single serious incident.

Where to start

If you have nothing in place, start with MFA and verified backups. these are the two most effective short-term measures. Then, have an SME cybersecurity audit carried out by an independent provider to identify your real gaps, not the ones you assume.

A full cybersecurity audit for an SME of 20 to 50 people generally spans one to two weeks depending on the scope, and produces a report with prioritised recommendations. It's the best starting point for building a realistic action plan. To maintain these measures over time (EDR, tested backups, MFA, updates), managed IT such as AlpenCare includes them in a monthly fee.

David Cunha

Written by

David Cunha

Co-founder · Technical director, AlpenData

A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.

More about AlpenData →

First IT recommendations

Want to know where your SME is exposed?

Request a 30-minute conversation with an AlpenData engineer. You walk away with first recommendations on your security, your backups and your IT priorities, with no commitment.