FAQ
What is a web security audit?
A web security audit is a methodical assessment of a website designed to identify exploitable vulnerabilities (SQL injections, XSS, CSRF, misconfigurations) and verify compliance with ISO 27001 and NIST CSF standards. At Bexxo, our audits cover 10 to 20 control points depending on the chosen package.
What is a website security audit?
A website security audit is a methodical examination of a website's vulnerabilities: application flaws (OWASP Top 10), SSL/TLS configuration, HTTP security headers, access management and compliance with ISO 27002 and NIST CSF standards. It produces a report with a list of flaws classified by criticality and a prioritised action plan. At Bexxo, our audits cover 10 to 20 control points depending on the chosen package.
What is Bexxo Academy?
Bexxo Academy (academy.bexxo.ch) is Bexxo's cybersecurity training platform, dedicated to Swiss SMEs, their employees and the general public. It offers interactive modules, phishing simulators, quizzes, videos and educational games, accessible 24/7 from any device. It is complemented by in-person sessions at Bexxo's premises in Ins (BE), for up to 20 people.
What is Bexxo?
Bexxo is the cybersecurity division of Tesweb SA, a Swiss company founded in 2006 in Ins (canton of Berne). Launched as a distinct and protected brand in 2023, Bexxo supports SMEs in French-speaking Switzerland with security audits, penetration tests, anti-phishing training and vulnerability monitoring. Certified with the Swiss Label and CyberSafe Label, we guarantee 100% Swiss services.
What is Bexxo's free cybersecurity analysis?
Bexxo's free cybersecurity analysis is a personalized assessment of your company's security posture, carried out free of charge and without commitment by a Bexxo expert. In a 30-minute exchange, we assess your risks across 5 areas: network infrastructure, website, access management (MFA authentication), team awareness on phishing, and classification of sensitive data. You then receive a written PDF report with the identified vulnerabilities and a prioritized action plan — identical to the report given to our paying clients.
What is CVE Find?
CVE Find is a Swiss vulnerability monitoring platform, developed and maintained by Bexxo (tesweb SA). It covers the entire MITRE CVE database with real-time updates, email and SMS alerts, and integrated scoring to prioritise patches. The interface is available in French, English and German.
What is cybersecurity consulting?
Cybersecurity consulting is a strategic support service provided by external experts designed to assess an organisation's risks, define an appropriate security policy and oversee its implementation. At Bexxo, our consultants draw on the ISO 27002:2022 standard and the NIST CSF framework to structure each engagement.
What is cybersecurity training in the workplace?
Cybersecurity training in the workplace is a structured programme that teaches employees to recognise and avoid everyday cyber threats: phishing, social engineering, weak passwords, risky behaviours. Unlike purely technical solutions, it addresses the main vulnerability of organisations: the human factor. At Bexxo, training combines real simulation via PhishTrainer (fake phishing email campaigns) and interactive learning via Bexxo Academy (modules, quizzes, videos). 68% of data breaches involve human error (Verizon DBIR 2024).
What is EBIOS Risk Manager?
EBIOS Risk Manager is the ANSSI risk analysis method, structured in 5 workshops: scoping, risk sources, strategic scenarios, operational scenarios and treatment. Adopted by French government bodies and many French-speaking companies, it identifies the most realistic threats and prioritises security investments.
What is phishing?
Phishing is an online fraud technique that involves sending emails, SMS, or messages that imitate legitimate communications (bank, government agency, employer) to trick the victim into revealing confidential information — passwords, banking details, professional credentials. Phishing is the most widely used attack vector: 91% of cyberattacks start with a fraudulent email (Proofpoint 2024).
What is PhishTrainer?
PhishTrainer is a Swiss phishing simulation software developed by Bexxo. It sends real simulated fraudulent email campaigns to a company's employees — with no real risk — to test their vigilance, identify vulnerable profiles, and measure the effectiveness of training. Data remains hosted in Switzerland, in accordance with the nFADP. PhishTrainer works in synergy with Bexxo Academy, Bexxo's e-learning platform.
What is ransomware recovery?
Ransomware recovery is an emergency intervention process designed to restore access to data and systems encrypted by an attack, without yielding to cybercriminals' demands. It includes forensic analysis of the malware, searching for decryption tools, restoration from backups and, if necessary, data extraction directly from physical media.
What is spear phishing and why is it more dangerous?
Spear phishing is a targeted variant of classic phishing: instead of sending millions of generic emails, attackers personalize the attack using real information about the victim (manager's name, ongoing project, supplier name). This targeting makes the email far more credible. Spear phishing accounts for 66% of confirmed data breaches (Verizon DBIR 2024). With AI, attackers can now generate these personalized emails at scale — the cost of a targeted attack has dropped considerably.
What is the company's responsibility in the event of an incident caused by a poorly informed employee?
If a security incident occurs due to risky behavior by a poorly informed employee, the company remains largely responsible. The law, including the nLPD in Switzerland and the GDPR in Europe, requires organizations to take the necessary measures to protect data and reduce risks. This includes training and awareness for staff.
In the event of a dispute or investigation, a company unable to demonstrate that it has implemented preventive actions (such as regular training, awareness campaigns, or reminders of best practices) could be deemed negligent. This can lead to fines, damage to reputation, and a loss of trust from customers and partners.
What is the difference between a black box, gray box, and white box pentest?
The main difference between black box, gray box, and white box testing lies in the level of information provided to the tester before starting the simulated attack.
- In black box, the attacker has no prior knowledge of the system. They act as an external hacker and attempt to access resources without any assistance. This type of test is realistic for simulating an external attack, but it is often limited to what can be guessed or discovered from the outside.
- In gray box, the tester has some technical information or partial access (such as a user account). This reflects a scenario where the attacker has already infiltrated part of the system or possesses internal knowledge, such as a former employee.
- In white box, all information is provided: source code, technical documentation, administrator access. This type of test provides a complete view and allows for the identification of deep vulnerabilities, often invisible from the outside.
Each approach has its advantages, and the choice depends on the objectives of the test and the level of risk to be covered.