Let's talk about security

Access our cybersecurity articles to discover essential practices such as least privilege, MFA and Zero-Trust, tailored to the needs of Swiss SMEs.

Articles

Can you recover your data after a ransomware attack without paying the ransom? Often yes, because ransomware encrypts files, it does not erase them: they stay on the disk, unreadable without the key. This guide explains what ransomware really does, why the direct decryption of a recent strain is out of reach, and above all what a recovery laboratory can still save without ever contacting the criminals: deleted but not overwritten RAIDs, snapshots (Shadow Copies), partially encrypted files, forgotten backups. You will find the steps to take in an attack (shut down, isolate, overwrite nothing), an honest decision on whether to pay, the shift toward blackmail by disclosure, your legal obligations in Switzerland (FOCS, nFADP) and the only real safeguard: an offline, immutable and off-site backup.
  • February 19, 2026, Peter Senn

Quishing: Behind Every QR Code Lies a Decision

Malicious QR codes bypass all your anti-spam filters. Discover how quishing targets your employees and the 5 essential steps to protect your Swiss SME from this rapidly growing threat.

Shadow IT refers to the unauthorized use of digital tools within a company — and its variant, Shadow AI, is now one of the main sources of data leaks for Swiss SMEs. Every time an employee copies customer data into ChatGPT or stores files on their personal Dropbox, your sensitive data escapes all control. Discover the concrete risks associated with the revised Federal Act on Data Protection (nLPD) and the American Cloud Act, and the sovereign solutions to regain control without hindering the productivity of your teams.

Complete Shadow IT / Shadow AI guide for Swiss SMEs: nLPD risks, Cloud Act, sovereign solutions (Euria, kDrive, Proton Drive, SwissTransfer) and practical governance.

1 in 6 Swiss SMEs has experienced a cyberattack — and 94% of passwords are reused. These 7 digital hygiene practices protect your organization without requiring technical skills.

The guide that transforms cybersecurity into 9 concrete actions for Swiss SMEs 10-250, with a 30/60/90-day plan adapted for both managers and IT teams (two reading paths).

  • December 15, 2025, Peter Senn

Why Swiss SMEs Need to Enable Automatic Updates

Automatic updates are the simplest and most effective cybersecurity measure to protect your Swiss SME: a one-time setup of just a few minutes is enough to block cyberattacks that exploit known vulnerabilities. According to the National Cyber Security Centre (NCSC), 60% of cyber incidents affecting Swiss SMEs exploit unpatched software flaws. Discover how to configure this essential protection without disrupting your daily operations, with solutions tailored to the realities of Swiss SMEs and the requirements of the revised Federal Act on Data Protection (nLPD).

Do your SME employees use their personal smartphones, tablets, and computers for work? This practice, called BYOD (Bring Your Own Device), offers flexibility and cost savings, but it exposes your company to significant security risks: data loss, nLPD violations, or cyberattacks. This practical guide explains how to effectively manage BYOD with measures accessible to Swiss SMEs: define a clear policy, protect devices, separate professional and personal data, raise awareness among your teams, and prepare a contingency plan. Concrete advice, without technical jargon, to protect your business without overcomplicating things.

A weak password exposes your accounts, identity, and finances to cyberattacks in seconds. This practical guide explains exactly how to create memorable and unbreakable passwords, enable two-factor authentication, and adopt sustainable digital hygiene — without being a computer expert.

Public WiFi exposes Swiss SMEs to cyberattacks that are invisible but very real. Discover 5 concrete measures to protect your business data on the go and maintain business continuity.

A backup security plan is a set of documented procedures that ensures the availability, integrity, and rapid restoration of an SME's critical data in the event of an incident. According to the Veeam Data Protection Trends 2024 report, 76% of companies experienced at least one major data-related outage in the past 12 months — and those without a tested backup plan took an average of 3 times longer to resume operations.

For an SME, adopting such a policy protects the company's reputation, ensures regulatory compliance (GDPR, Swiss nLPD which came into force in September 2023), and maintains customer trust. It's a measurable strategic choice: according to Gartner (2023), the average cost of unplanned downtime reaches CHF 8,500 per hour — a risk that a structured plan helps to avoid.

Discover how bexxo can secure your business. Don't hesitate to contact us for a personalized consultation today!