Cybersecurity is no longer the preserve of large companies. Swiss SMEs are now prime targets precisely because they process sensitive data while having limited defences. This guide sets out what you need to know and do concretely in 2026.
The threat landscape in 2026
Ransomware remains the most costly threat
Ransomware encrypts all your data and demands a ransom to decrypt it. Targeted companies are often paralysed for several days or weeks. The total cost of a ransomware incident. ransom, restoration time, lost revenue, crisis communication. frequently exceeds CHF 50,000 for an SME of 20 people, even without paying the ransom.
In 2024, the Swiss National Cyber Security Centre (NCSC) recorded a significant increase in ransomware reports affecting SMEs. The most affected sectors: trust and fiduciary services, healthcare, industry and retail.
Phishing has become professionalised
The phishing emails of 2026 no longer resemble the clumsy attempts of the 2010s. They perfectly imitate your bank, your cloud provider or a colleague. They use public information (LinkedIn, website) to personalise the message. The click rate is markedly higher than that observed on generic campaigns.
"Business email compromise" (impersonating an executive to request an urgent transfer) is the most costly variant. and one of the hardest to detect without team training.
Insecure access. the most common intrusion vector
Most intrusions do not come through a sophisticated technical flaw. They come through:
- Weak or reused passwords (the same ones for personal and work accounts)
- The absence of multi-factor authentication on remote access
- Network equipment (routers, firewalls) never updated since installation
- Former employees' accounts never deactivated
What the Swiss Data Protection Act requires
The revised Swiss Data Protection Act (FADP), in force since 1 September 2023, imposes several security obligations on Swiss companies:
- Privacy by design and by default: data protection must be built into your systems and processes from the design stage, not added afterwards
- Breach notification: any data breach presenting a high risk to the individuals concerned must be reported to the FDPIC "as soon as possible"
- Record of processing activities: mandatory for companies processing sensitive data or carrying out large-scale profiling
- Appropriate security measures: an obligation to implement technical and organisational measures suited to the risks
The priority measures. in order
1. Multi-factor authentication (MFA) everywhere
This is the measure with the best cost/effectiveness ratio. Enabling MFA on your email, your VPN and your Microsoft 365 or Google Workspace takes half a day and blocks the vast majority of intrusion attempts using stolen credentials.
2. Verified and off-site backups
A backup that has never been tested is not a backup. It may be corrupted, incomplete or inaccessible at the moment you need it. The 3-2-1 rule remains the standard: 3 copies, on 2 different media, 1 of which is off-site.
"Off-site" means physically separated from your main infrastructure, not a hard drive in the same office. In the event of ransomware or fire, your local backups are useless.
3. EDR on all workstations and servers
Traditional signature-based antivirus does not detect modern threats. An EDR (Endpoint Detection & Response) monitors process behaviour in real time and can automatically isolate a compromised workstation before the infection spreads.
Indicative cost: CHF 5 to 15 per workstation per month depending on the solution. For an SME with 20 workstations, that's CHF 100 to 300/month. far lower than the cost of an incident.
4. Updating network equipment
Check when your firewall and network switches last received a firmware update. If you don't know, that's already a problem. Vulnerabilities in network equipment are exploited actively and quickly after their public disclosure.
5. Staff training
An annual 1- to 2-hour session on recognising phishing, password management and the right reflexes in the event of a suspicious incident. No need for a certification course. you need concrete content, real examples, and clear procedures ("if you receive a suspicious email, here's what to do").
What it costs
For an SME of 20 people, properly securing its infrastructure represents:
- EDR for 20 workstations: CHF 200 to 300/month
- Managed firewall: CHF 150 to 300/month (depending on the hardware)
- Off-site cloud backup: CHF 50 to 150/month depending on volume
- Annual training: CHF 500 to 1,500 for the full session
- Annual security audit: CHF 1,500 to 4,000 depending on depth
Total: CHF 400 to 750/month in running costs, plus a one-off investment in audits and training. That's significant, but it should be put in perspective against the cost of a single serious incident.
Where to start
If you have nothing in place, start with MFA and verified backups. these are the two most effective short-term measures. Then, have an SME cybersecurity audit carried out by an independent provider to identify your real gaps, not the ones you assume.
A full cybersecurity audit for an SME of 20 to 50 people generally spans one to two weeks depending on the scope, and produces a report with prioritised recommendations. It's the best starting point for building a realistic action plan. To maintain these measures over time (EDR, tested backups, MFA, updates), managed IT such as AlpenCare includes them in a monthly fee.
Written by
David Cunha
Co-founder · Technical director, AlpenData
A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.
More about AlpenData →