Skip to content
MAWT Logo
Security

Security that protects your business, not a binder on a shelf.

Overview

We assess your real exposure, harden what matters — access, backups, MFA — and prepare your team for the day something goes wrong.

Cybersecurity for an SME means reducing the most likely risks — phishing, ransomware, account takeover — with proportionate measures: multi-factor authentication, tested backups, controlled access and trained teams. MAWT assesses your exposure, hardens the essentials and prepares a concrete incident response plan, backed by a network of proven senior security experts under a single point of contact.

Target

For Swiss SMEs and growing companies without a dedicated security team — fiduciaries, medical practices, law firms, manufacturers, service firms — that handle client data or professional secrets and want a serious posture without an enterprise budget.

Details

Cybersecurity for an SME is not about buying the tools large enterprises use. It is about knowing your real exposure and closing the gaps that attackers actually exploit: weak authentication, untested backups, over-broad access, and teams that have never seen a convincing phishing attempt.

MAWT runs these engagements with a network of proven senior security experts, under a single point of contact. We assess, we harden the essentials, we prepare your incident response — and we document everything in plain language, so your security posture is something you can explain to a client, an insurer or a regulator.

Most SME incidents are preventable

The attacks that actually hit Swiss SMEs are rarely sophisticated. A convincing phishing email, a reused password, an invoice with a changed IBAN, a laptop that was never encrypted. Ransomware groups run automated campaigns: they do not care whether you are a bank or a ten-person fiduciary.

The good news is that a handful of well-executed measures stops most of it. Multi-factor authentication on every account that matters, backups you have actually restored once, access rights that match reality, and teams that recognize a fraud attempt. None of this requires an enterprise security budget — it requires doing the basics properly.

Our approach: assess, harden, prepare

We start with an assessment of your real situation: which data matters, who can access what, what happens if a given system disappears for three days. The result is a short document in plain language, prioritized by business impact — not a hundred-page audit nobody reads.

Then we harden the essentials with you: MFA deployment, access reviews, backup verification, sensible email and endpoint settings. Finally we prepare the day it goes wrong anyway: a written incident response plan with clear roles, contact points and first steps, rehearsed at least once so it works under stress.

  • Assessment of your exposure, prioritized by business impact
  • MFA rolled out on email, cloud tools and remote access
  • Backups tested with an actual restore, not just a green checkbox
  • Access rights reviewed, with a clean offboarding checklist
  • Awareness session built on real fraud examples, not slides
  • Incident response plan rehearsed with your key people

A network of senior experts, one point of contact

MAWT operates security engagements with a network of proven senior security specialists — people who have handled real incidents and hardened real infrastructures. You do not manage a roster of consultants: you have one interlocutor at MAWT who scopes the work, brings in the right expertise and stays accountable for the result.

We are deliberately careful with claims. We do not promise absolute protection — nobody honestly can. We reduce risk where it counts, document what was done, and make sure you can keep operating if something slips through. Continuity of your business is the goal, not a perfect score.

Security that fits Swiss obligations

The Swiss nLPD requires you to protect personal data with measures appropriate to the risk, and to notify serious breaches. Professional secrecy adds obligations for lawyers, doctors and fiduciaries. We translate these duties into concrete technical and organizational measures — and document them, so you can show your work to a client, an insurer or the authorities.

Where relevant, we connect security to the rest of your stack: the same engagement often surfaces quick wins in your business applications, automations or hosting choices, which our development teams can address directly.

What it includes
  • Risk assessment focused on your actual exposure
  • Account hardening: MFA, access rights, offboarding
  • Backup strategy verified with real restore tests
  • Phishing and fraud awareness sessions for your teams
  • Written incident response plan, rehearsed once with you
  • One point of contact, senior security experts behind it
Deliverables
  • A risk assessment in plain language, prioritized by business impact
  • Hardened access: MFA deployed, rights reviewed, offboarding checklist
  • A backup strategy verified by an actual restore test
  • An incident response plan your team has rehearsed once
  • A pragmatic twelve-month roadmap, sized for an SME
Takeaways
  • Most SME incidents start with phishing or a weak password.

  • MFA, tested backups and access control stop the majority of attacks.

  • An incident plan nobody has rehearsed is not a plan.

  • Proportionate measures beat expensive tools you never operate.

  • One contact at MAWT, proven senior security experts behind it.

You might also need

Compliance Services

nLPD and GDPR compliance for Swiss SMEs: processing registers, data protection documentation, ISO 27001 preparation and solid answers to client security questionnaires.

Penetration Testing

Targeted penetration tests for Swiss SMEs: web applications, APIs and infrastructure, with a clear contractual scope, a prioritized report and a re-test after fixes.

Frequent questions

Are we too small to be a target?

No. Most attacks on SMEs are automated: phishing campaigns and ransomware scan for weak points regardless of company size. Attackers often prefer smaller companies precisely because defenses are lighter and payment pressure — losing access to client files — is high.

Where should an SME start with cybersecurity?

Three things deliver the most protection per franc: multi-factor authentication on email and cloud accounts, backups you have actually tested by restoring, and a review of who can access what. We usually address these in the first weeks of an engagement, before anything more sophisticated.

How much does cybersecurity cost for a Swiss SME?

It depends on your size and exposure, which is why we start with an assessment rather than a product. Hardening the essentials is measured in days of work, not months. We prioritize by impact so the budget goes where it reduces real risk, and we tell you plainly when a measure is not worth its cost.

Do we need a full-time security officer?

At typical SME size, rarely. What you need is the essentials done well, someone accountable for keeping them that way, and access to senior expertise when a question or incident arises. That is the model we operate: a single point of contact at MAWT, backed by a network of senior security experts.

What does the Swiss nLPD require from us?

In short: protect personal data with technical and organizational measures appropriate to the risk, be able to explain what you process and why, and notify the authorities of serious breaches. The law does not prescribe specific tools — it expects a defensible, documented posture, which is exactly what we help you build.

Does cyber insurance replace security measures?

No — it complements them. Insurers increasingly require the basics (MFA, backups, patching) before covering you, and may reduce payouts if they were missing. A solid posture makes you insurable at better terms; insurance then covers the residual risk that no measure can eliminate.
Next steps

Know where you stand before an incident tells you.