Independent guide for Swiss SMEs
Understand and improve the cybersecurity of your Swiss SME
The legal obligations, the real threats, and the measures that actually protect you. Explained simply, without jargon, with official Swiss sources and concrete examples.
Free, no sign-up. Your score appears immediately.
The state of the threat in Switzerland
voluntary cyber-incident reports received by the NCSC in 2025, up from 62,954 in 2024
NCSC, semi-annual report 2025/II (2026)
of Swiss SMEs consider their protection sufficient, down from 55% a year earlier
SME Cybersecurity 2025 study
maximum fine under the Federal Act on Data Protection, imposed on the responsible individual
Art. 60–63 FADP
An SME is not targeted because it is interesting, but because it is accessible. Most attacks are automated and target no one in particular. That is also why simple measures are enough to remove most of the risk.
Where to start
Six domains covering the essentials
Each domain groups explanatory articles, independent of one another. You can start with whichever one matches the question on your mind today.
Threats
Phishing, ransomware, CEO fraud: understand concretely what happens to Swiss companies, and why SMEs have become prime targets.
ExploreRegulations
FADP, Cyber Resilience Act, EN 18031: which laws apply to your company, from when, and what you actually risk.
ExploreBest practices
The measures that make a difference, ranked by effort versus protection. What to do first when you have little time and little budget.
ExploreResponding to an attack
The right reflexes for the first hours, who to contact in Switzerland, your legal obligations, and the mistakes that make things worse.
ExploreTraining your teams
Your employees are your best defence, not your weak link. Build an awareness programme that genuinely changes behaviour.
ExploreTools
Cyber check-up, FADP test, cost simulator: free, instant tools to gauge your company and know where to start.
ExploreFree tool
Where does your company really stand?
Twelve concrete questions about your backups, access rights, updates and procedures. At the end, a score out of 100 and the three actions that would make the biggest difference for you.
- Three minutes, no technical knowledge required
- Instant result, no e-mail address required
- Recommendations linked to the relevant articles
Who writes this site
A site published by a Swiss compliance firm
This site is published by Säfeli, a certification and regulatory compliance consultancy based in Granges-Paccot, in the canton of Fribourg. We support Swiss SMEs and manufacturers daily on cybersecurity requirements.
The content is free and will stay that way. Every claim links to its official source, and articles show their update date. When a topic goes beyond what one article can cover, we say so rather than oversimplifying.
Learn more about us- Official sources cited NCSC, FDPIC, Fedlex, European Commission
- Dated, up-to-date content Regulation moves, the articles keep pace
- Written for non-technical readers Every technical term is explained the first time it appears
The blog
Swiss cyber news, decoded
What's changing in threats and regulations, and what it concretely means for your SME. With official sources.
NIS2: why this European directive also concerns Swiss SMEs
Think European cyber regulation doesn't concern you because you're in Switzerland? NIS2 travels down the supply chain, and many Swiss SMEs will find out through their clients.
ReadThe NCSC report: what the second half of 2025 tells us about the threats
The NCSC's semi-annual report, published at the end of March 2026, paints a picture of the threats seen in the second half of 2025. Ransomware, voice phishing and new techniques all feature prominently.
ReadFADP: what the FDPIC's latest report reveals for SMEs
The Federal Data Protection and Information Commissioner has published its activity report. Behind the figures lies a useful reminder: in Switzerland, it is individuals, not the company, who risk the criminal fine.
Read