Security should support your business, not police it. For small and medium-sized companies that means: the measures that matter, explained in plain language, at predictable cost. No enterprise budget required, no fear-based selling.
A single incident, ransomware, a data breach or an extended outage, can threaten an SME's existence. Meanwhile requirements keep rising through the Swiss FADP and NIS2. Prevention costs a fraction of the cleanup. All packages come with fixed scope and a fixed price after an intro call.
An honest baseline instead of security theater: an automated scan with a logo on it is not an audit. You get an analysis with clear priorities and explanations that make sense without an IT degree.
When something happens: one number, one point of contact. Containment, recovery and a final report your insurer will accept. Optionally available as a retainer with a defined response time.
The basics that actually matter: backups, MFA, updates, an emergency plan and staff awareness. Properly documented, so FADP obligations are met and cyber insurers offer you good terms.
Less dependence on single vendors: an assessment of your cloud and software dependencies and, where it makes sense, migration to open alternatives. Pragmatic and without ideology.
A real case, anonymised. This is what an SME engagement looks like in practice.
A Swiss online retailer reports on a weekday: the shop is unreachable, orders are going nowhere, the cause is unclear. An attack cannot be ruled out.
Within 45 minutes the cause was identified: not an attacker, but a faulty update of a pricing plugin that sent the shop into an infinite loop. The plugin was isolated and the shop was back online. Concrete recommendations followed: an update process with a staging environment, monitoring, and a review of the backups.
An intro call costs nothing and gives you a first honest assessment. By email or directly by phone.