When people talk about data theft, they picture a hacker forcing their way into a remote server. That image exists, but it is misleading. In the real life of an SME, a leak much more often begins with an ordinary act: a file sent to the wrong recipient, a laptop forgotten on a train, an account that was never closed after someone left.

The result is nevertheless the same. Information concerning your customers, your employees, or your partners ends up outside your control. And from that moment on, you must answer three questions: what has gone out, who can do what with it, and what are you required to do.

A leak is not necessarily a hack

The Swiss legal concept is deliberately broad. A data security breach is any breach that accidentally or unlawfully leads to the loss of personal data, its alteration, erasure, destruction, or its disclosure to unauthorised persons. The key word is “accidentally”. Error counts just as much as attack.

CauseWhat it looks like in practiceWhat makes it likely
HackingIntrusion into a server or mailbox, files exfiltrated before encryptionWeak password, unprotected remote access, unpatched vulnerability
Human errorAttachment sent to the wrong recipient, a customer list visibly copied in, a shared folder open to everyoneNo proofreading, poorly configured cloud sharing, time pressure
Lost or stolen equipmentLaptop, phone, or USB stick lost, with unencrypted dataNo disk encryption, no lock code
Compromised providerThe payroll software, the trustee, or the host suffers an attack, and your data goes with itContract with no security clause, no visibility into the processor
Former employeeCopy of the customer file taken away, account still active months after leavingNo offboarding procedure, shared accounts, access never reviewed

None of these five rows is marginal. The three in the middle require no technical skill from anyone, and they are enough to expose your entire customer database.

The account that stays open after someone leaves

This is the most mundane and the most persistent flaw. An employee leaves the company, their badge is returned, their computer too, but their access to e-mail, the CRM, or file sharing remains active. Sometimes for years. On the day someone leaves, revoking access must be on the same list as returning the keys.

What are your data worth to an attacker?

Many business owners think their files interest no one. “I sell windows, not state secrets.” This is a misjudgement about the nature of the market. Data is not resold for its content, but for what it allows someone to do.

Identity theft and fraud. A name, a date of birth, an address, and an AHV number are enough to open accounts or order on credit in someone else’s name. Your personnel files contain exactly that.

Targeted payment fraud. Your e-mail exchanges and your accounts reveal who pays what, to whom, and on what schedule. An attacker who knows this can send a perfectly credible fake request to change banking details, at exactly the right moment.

A springboard to your customers. Your contacts are a way in. A message arriving from a known supplier, with the right tone and the right references, gets opened without hesitation. The damage then spreads beyond your company and affects your partners.

Blackmail through publication. This is the model used by today’s ransomware groups: data is first stolen, then encrypted, and its publication serves as extra leverage. This is called double extortion. In the second half of 2025, 57 ransomware-related incidents were reported to the National Cyber Security Centre. The full mechanics of these attacks are detailed in our article on ransomware.

Over the whole of 2025, the NCSC received 64,733 voluntary reports of cyber incidents, compared with 62,954 in 2024. These reports are voluntary: they indicate a trend, not an exhaustive count.

What are your obligations once a leak has been identified?

This is where many Swiss SMEs, in good faith, apply rules that are not their own.

No, Swiss law does not say 72 hours

The 72-hour deadline comes from the European regulation, not from Swiss law. The Federal Act on Data Protection requires a report "as soon as possible", with no figure attached. And above all, reporting to the FDPIC is only required if the breach is likely to result in a high risk to the personality or fundamental rights of the people concerned. Not every leak needs to be reported.

Remember three principles, generally applicable.

The threshold is high risk. A professional contact address mistakenly sent internally is not on the same level as a salary table, a medical file, or a list of banking details disclosed externally. It is up to you to assess this, and above all to document your assessment, including when you conclude that no report is needed.

Reporting does not expose you criminally. The law expressly provides that a report made to the FDPIC cannot be used in criminal proceedings against the person reporting it, without their consent. This point is important to know, because the fear of self-incrimination holds many business owners back.

If you are a processor, the threshold does not apply to you. A processor must report any breach to its principal, with no high-risk condition. If you host or process a customer’s data, transparency is owed in all cases.

On top of this come obligations that do not come from the law. Your commercial contracts often include confidentiality clauses and information deadlines in the event of an incident. Your customers can hold you accountable on this basis well before any authority does. The full procedure is detailed in your FADP obligations and in our article dedicated to reporting a breach.

The real consequences for an SME

The administrative penalty is not the first problem. What costs you is what comes after.

The loss of trust is immediate and lasting. A customer who learns that their banking details have circulated does not think in terms of compliance. They simply ask themselves whether to keep working with you. What is at stake then depends heavily on how you found out and who told them: our article on communicating during a cyberattack details what to say, to whom, and through which channel.

Contractual liability follows. If your contract commits you to protecting the data entrusted to you, a leak can open the door to a claim for damages, independently of any official proceedings.

Finally, the internal cost is widely underestimated. Identifying what has gone out takes time, often that of an external expert. You then need to inform people, answer questions, and rebuild procedures. During this time, the business is not producing.

Prevention, in order of effectiveness

Three measures cover the vast majority of the scenarios in the table.

Limit access. Each person accesses only what they need, and nothing else. No shared accounts, a rights review at least once a year, and an offboarding procedure that revokes everything on the last day. This topic is developed in access management.

Encrypt devices. Disk encryption is built into Windows and macOS, and it takes a few minutes to turn on. An encrypted and locked laptop that disappears remains a hardware problem, not a data leak. This point matters all the more as devices leave the office: the corresponding measures are gathered in our article on remote work and mobile devices.

Know where your data is. Make a list of what you hold, where, and who has access to it, including at your service providers. Without this inventory, you can neither assess a risk nor answer the question that matters on the day of an incident: what exactly has gone out?

The two-minute reflex

Most leaks caused by human error come down to a single send. Before sending a file outside the company, check three things: the recipient, the attachment, and the hidden tabs of the spreadsheet. An Excel file sent for its monthly figures sometimes contains, in a second tab, the entire staff list with salaries.

These measures are complemented by your backups, which protect the availability of your data, and by vigilance regarding your suppliers, through whom a growing share of incidents arrives.

What should you do starting today?

A 2025 study found that 42% of Swiss SMEs consider their protection sufficient, compared with 55% a year earlier. Confidence is declining, which is rather healthy: clear-sightedness precedes action.

Start with the simplest step. List the active accounts in your tools and compare this list against your actual headcount. Many business owners discover access that should never have survived this long. Then decide who, in your company, is notified first if a leak is identified, and what they do within the following hour. The steps of the response are described in your legal obligations after an incident.

To gauge your overall level of protection, the cyber check-up devotes several questions to access and data confidentiality. The other risks an SME is exposed to are gathered in the Threats pillar.

For specific situations, particularly a dispute with a former employee or doubt about the high-risk threshold, the advice of a specialised lawyer remains essential.