Security that protects your business, not a binder on a shelf.
We assess your real exposure, harden what matters — access, backups, MFA — and prepare your team for the day something goes wrong.
Cybersecurity for an SME means reducing the most likely risks — phishing, ransomware, account takeover — with proportionate measures: multi-factor authentication, tested backups, controlled access and trained teams. MAWT assesses your exposure, hardens the essentials and prepares a concrete incident response plan, backed by a network of proven senior security experts under a single point of contact.
For Swiss SMEs and growing companies without a dedicated security team — fiduciaries, medical practices, law firms, manufacturers, service firms — that handle client data or professional secrets and want a serious posture without an enterprise budget.
Cybersecurity for an SME is not about buying the tools large enterprises use. It is about knowing your real exposure and closing the gaps that attackers actually exploit: weak authentication, untested backups, over-broad access, and teams that have never seen a convincing phishing attempt.
MAWT runs these engagements with a network of proven senior security experts, under a single point of contact. We assess, we harden the essentials, we prepare your incident response — and we document everything in plain language, so your security posture is something you can explain to a client, an insurer or a regulator.
Most SME incidents are preventable
The attacks that actually hit Swiss SMEs are rarely sophisticated. A convincing phishing email, a reused password, an invoice with a changed IBAN, a laptop that was never encrypted. Ransomware groups run automated campaigns: they do not care whether you are a bank or a ten-person fiduciary.
The good news is that a handful of well-executed measures stops most of it. Multi-factor authentication on every account that matters, backups you have actually restored once, access rights that match reality, and teams that recognize a fraud attempt. None of this requires an enterprise security budget — it requires doing the basics properly.
Our approach: assess, harden, prepare
We start with an assessment of your real situation: which data matters, who can access what, what happens if a given system disappears for three days. The result is a short document in plain language, prioritized by business impact — not a hundred-page audit nobody reads.
Then we harden the essentials with you: MFA deployment, access reviews, backup verification, sensible email and endpoint settings. Finally we prepare the day it goes wrong anyway: a written incident response plan with clear roles, contact points and first steps, rehearsed at least once so it works under stress.
- Assessment of your exposure, prioritized by business impact
- MFA rolled out on email, cloud tools and remote access
- Backups tested with an actual restore, not just a green checkbox
- Access rights reviewed, with a clean offboarding checklist
- Awareness session built on real fraud examples, not slides
- Incident response plan rehearsed with your key people
A network of senior experts, one point of contact
MAWT operates security engagements with a network of proven senior security specialists — people who have handled real incidents and hardened real infrastructures. You do not manage a roster of consultants: you have one interlocutor at MAWT who scopes the work, brings in the right expertise and stays accountable for the result.
We are deliberately careful with claims. We do not promise absolute protection — nobody honestly can. We reduce risk where it counts, document what was done, and make sure you can keep operating if something slips through. Continuity of your business is the goal, not a perfect score.
Security that fits Swiss obligations
The Swiss nLPD requires you to protect personal data with measures appropriate to the risk, and to notify serious breaches. Professional secrecy adds obligations for lawyers, doctors and fiduciaries. We translate these duties into concrete technical and organizational measures — and document them, so you can show your work to a client, an insurer or the authorities.
Where relevant, we connect security to the rest of your stack: the same engagement often surfaces quick wins in your business applications, automations or hosting choices, which our development teams can address directly.
- •Risk assessment focused on your actual exposure
- •Account hardening: MFA, access rights, offboarding
- •Backup strategy verified with real restore tests
- •Phishing and fraud awareness sessions for your teams
- •Written incident response plan, rehearsed once with you
- •One point of contact, senior security experts behind it
- •A risk assessment in plain language, prioritized by business impact
- •Hardened access: MFA deployed, rights reviewed, offboarding checklist
- •A backup strategy verified by an actual restore test
- •An incident response plan your team has rehearsed once
- •A pragmatic twelve-month roadmap, sized for an SME
Most SME incidents start with phishing or a weak password.
MFA, tested backups and access control stop the majority of attacks.
An incident plan nobody has rehearsed is not a plan.
Proportionate measures beat expensive tools you never operate.
One contact at MAWT, proven senior security experts behind it.
Compliance Services
nLPD and GDPR compliance for Swiss SMEs: processing registers, data protection documentation, ISO 27001 preparation and solid answers to client security questionnaires.
Penetration Testing
Targeted penetration tests for Swiss SMEs: web applications, APIs and infrastructure, with a clear contractual scope, a prioritized report and a re-test after fixes.