Answers to your questions

Quickly find answers to your questions about cybersecurity, CVE Find, standards, vulnerabilities and Bexxo services in our comprehensive FAQ.

FAQ

What are the obligations of the nFADP for Swiss SMEs?
The nFADP requires maintaining a record of processing activities, reporting breaches within 72 hours, conducting impact analyses and implementing appropriate technical measures. Fines can reach CHF 250,000.
  • Tags:  
What are the obligations under the nFADP in the event of a data breach?
The nFADP requires notification to the FDPIC within 72 hours, informing affected individuals if the risk is high, and documenting the incident. Fines can reach CHF 250,000 for the responsible persons.
  • Tags:  
What are the risks associated with a lack of awareness?

A lack of awareness exposes the company to very real risks: opening fraudulent emails, installing malware, data leaks, or even bad practices such as using unencrypted media or sharing passwords. These errors can lead to costly cyberattacks or even business interruptions.

In addition, untrained personnel can become the unintentional entry point for ransomware, data theft, or industrial espionage. In a context of increasing digitization, ignoring this aspect amounts to leaving a permanent flaw in the company's defense.

  • Tags:  
What areas does the cybersecurity analysis cover?

The analysis covers 5 priority areas for SMEs:

  • Network: firewall configuration, remote access (VPN), segmentation.
  • Website: SSL/TLS, security headers, common vulnerabilities (OWASP Top 10).
  • Authentication: password policy, MFA, administrator access management.
  • Training: level of team awareness on phishing (91% of cyberattacks start with an email — Proofpoint 2024).
  • Data: classification of sensitive data, nFADP compliance.

Depending on your needs, the analysis can focus on one or more specific areas.

  • Tags:  
What benefits do companies gain from a network audit?

Optimized performance, reduced vulnerabilities, and service continuity. You'll have a network that is both reliable and scalable.

  • Tags:  
What certifications guarantee Bexxo's reliability?
Bexxo / Tesweb SA holds three key certifications: the CyberSafe Label, recognising companies committed to a proactive cybersecurity approach; the Swiss Label, a certification from the Swiss Union of Arts and Crafts (sgv) guaranteeing 100% Swiss anchoring of products and services (founded in 1917, centenary celebrated in 2017); and a federal clearance allowing intervention in classified environments — the highest level of rigour in confidentiality.
  • Tags:  
What cybersecurity services does Bexxo offer?
Bexxo offers web and network security audits, penetration testing (pentest), cybersecurity consulting, anti-phishing training with PhishTrainer, and continuous vulnerability monitoring via CVE Find.
  • Tags:  
What deliverables can I expect from a cybersecurity consultation?

You will receive a detailed action plan with customized recommendations and an implementation timeline. Bexxo also provides follow-up to measure progress and adjust the strategy as needed.

  • Tags:  
What do you receive at the end of the analysis?

At the end of the exchange with the Bexxo expert, you receive by email a personalized PDF report including: (1) a summary of the risks identified by area, classified by criticality (high/medium/low); (2) a prioritized action plan with the measures to implement first; (3) recommendations adapted to the size and sector of your company. You can view an example report via the link below. This report can be used as a basis for your internal audits or presented in the event of an nFADP inspection.

  • Tags:  
What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a unique identifier assigned to a known security flaw (e.g. CVE-2024-12345). This system, maintained by the MITRE Corporation, allows security professionals to reference the same vulnerability universally. In 2025, more than 48,000 new CVEs were published (+20% vs 2024).
  • Tags:  
What is a network audit?

It is a diagnostic assessment of the architecture and configurations of your infrastructure (routers, firewalls, switches, etc.) to identify potential security vulnerabilities or bottlenecks.

  • Tags:  
What is a network security audit?

A network security audit is a systematic assessment of a company's IT infrastructure: device mapping, traffic analysis, verification of firewall rules, remote access (VPN) and network segmentation. It is carried out in accordance with ISO 27002 and NIST CSF standards and produces a vulnerability report classified by criticality with a prioritised action plan. At Bexxo, our audits cover 10 to 20 control points depending on the chosen package.

  • Tags:  
What is a network security audit?
A network security audit is a systematic assessment of a company's IT infrastructure: active equipment (routers, switches, firewalls), segmentation, communication protocols, access management and encryption levels. At Bexxo, our audits reveal on average 3 to 5 critical vulnerabilities per SME infrastructure.
  • Tags:  
What is a penetration test (pentest)?

A penetration test, or pentest, is a security assessment that involves simulating a real attack on a computer system, network, or application in order to identify exploitable vulnerabilities. The goal is to detect weaknesses before an attacker discovers them, and to provide concrete recommendations to strengthen security.

Unlike purely documentary audits, a pentest relies on offensive techniques similar to those used by hackers. It may include exploiting software flaws, compromising accounts, or traversing firewalls. It is often performed in addition to an automated scan to assess not only the presence of vulnerabilities, but also their actual exploitability in the target context.

  • Tags:  
What is a web cybersecurity audit?

A web audit involves an in-depth analysis of the vulnerabilities of a website or online application: penetration testing, source code review, server configurations, etc.

  • Tags: