Who can reach what, and what do you do on Monday morning if everything is encrypted?
Access review, backups that are actually tested, a one-page response plan, Swiss data law without the jargon.
The situation
In 2025 the Swiss Federal Office for Cybersecurity received some 65,000 reports and notes that attackers now aim at SMEs, medical practices and any organisation holding sensitive data. Phishing attempts rose 17% in a year. In the organisations we review, the problem is almost never a missing antivirus: it is the former employee who still has access, the backup nobody has ever restored, and the password shared since 2019.
What we do
- Access review: the list of who reaches what, ghost accounts, suppliers, open shares. Two-factor authentication wherever possible, a company password manager, a written joiner and leaver procedure.
- Resilience: backups on the 3-2-1 rule, with a real restore test, not a ticked box. A one-page response plan: "Monday morning, everything is encrypted: who calls whom, what gets unplugged, where we restore from".
- Awareness: thirty minutes per team, twice a year, on the phishing actually circulating in Geneva, with your own examples.
- Pragmatic Swiss data law (nLPD/FADP): a record of processing, contracts with your processors, a privacy policy and a breach procedure. What a director needs to have at hand, without turning the company into a law firm.
What it is not
It is not a penetration test or a 24/7 monitoring centre. When those services are useful, we help you buy them at the right price from a specialist. And it is not legal advice: for contracts and disputes, we work with your lawyer.
Price
Frequently asked questions
Our IT provider says everything is in order.
That may be true. The review checks it with facts: the account list, the date of the last restore test, the state of two-factor authentication. A good provider has nothing to fear from a review; they often come out of it with a clearer brief.
Are we "compliant" with Swiss data law after your visit?
We issue no certificate and nobody can guarantee compliance. We put you in a position to meet the law's obligations: know what you process, have it written down, have contracts with your processors and know what to do in case of a breach. For a legal opinion, your lawyer remains the reference.
How much of the team's time does it take?
Half a day for the person who manages the tools, one hour for you, thirty minutes per employee for the awareness session. The rest we do outside your busy hours.