awsmtech.ch

Articles Blog EN

Articles Blog EN

Cybersecurity in Business: The 5 False Certainties That Expose Sensitive Sectors

Cybersecurity in Business: The 5 False Certainties That Expose Sensitive Sectors Cybersecurity in Business: The 5 False Certainties That Expose Sensitive Sectors   Law firms, fiduciaries, private clinics, private banks, international NGOs: in the sectors we support every day in French-speaking Switzerland, data is not just a simple IT asset. It is professional secrecy, a patient file, a client mandate, sensitive financial information. Yet a recent analysis published by Swisscom on IT security among SMEs highlights a reality we also observe in the field, audit after audit: most organizations that suffer a security incident were convinced, until the day of the attack, that they were properly protected. This gap between the feeling of security and the actual level of protection is the real blind spot in business cybersecurity. It is almost never a matter of unwillingness, but rather a lack of verification, poorly defined responsibilities between the company and its IT provider, and assumptions that are never challenged. Here are the five most common false certainties, and how we address them at AWSMTECH for clients who, by the very nature of their activity, cannot afford mistakes. 1. “Our data is backed up” This is the most widespread certainty, and also the most dangerous. A backup exists in almost every organization we encounter. But a backup only has value if it has been tested under real restoration conditions, if it is isolated from the main network to withstand ransomware that could also encrypt the backups, and if the restoration time is compatible with the reality of the business. For a law firm or a notary office, losing access to files for three days is not merely inconvenient: it can engage professional liability toward clients and legal deadlines. For a private clinic, it can directly affect continuity of care. What we systematically verify: backup frequency, isolation, actual restoration time tested under real conditions, as well as coverage of all critical systems — not only files, but also email systems, business databases and server configurations. 2. “Our passwords are strong” A complex password is still useless if it is stolen through phishing, reused on a compromised third-party service, or intercepted on an infected workstation. Password strength does not protect against credential theft. Only multi-factor authentication can effectively strengthen this protection. In highly confidential sectors — wealth management, private banking, fiduciary services — access to email or document management tools is often the most direct entry point into the entire information system. What we deploy: mandatory multi-factor authentication across all critical access points, a strict privileged access management policy, and real-time detection of suspicious logins. 3. “Access rights protect our data” Many organizations apply generic access rights inherited from the company’s history rather than from a genuine security logic. As a result, an employee may have access to client files, HR data or financial information that is unrelated to their role. If a single workstation is compromised, the entire scope of data accessible to that employee may potentially be exposed. For an NGO or an international organization operating in several countries, with remote teams and sometimes high staff turnover, this issue becomes central. Our approach: applying the principle of least privilege, periodically reviewing access rights, and strictly separating sensitive environments — finance, HR, client files — through an architecture designed from the initial IT assessment. 4. “We update regularly” The word “regularly” often hides a very uneven reality: some workstations are up to date, others are forgotten, business software is never patched for fear of incompatibility, and network equipment sometimes runs for years without firmware updates. Known vulnerabilities are exploited by automated attackers only a few days after publication. The issue is therefore not only to perform updates, but to know exactly what needs to be corrected, within what timeframe, and with what level of priority. What we implement: a complete inventory of the IT environment, automated and supervised patch management, as well as monitoring of critical vulnerabilities with contractually defined correction deadlines — not left to individual goodwill. 5. “We have a firewall” A firewall effectively protects a clearly defined network perimeter, typically an office. But hybrid work, business travel and the use of mobile devices have largely dissolved this perimeter. A notary accessing files from home, a wealth manager travelling, or an NGO team spread across several continents: in all these cases, the office firewall alone no longer protects very much. Our response: security designed around identity and devices, not only the local network, through our secure workstation and managed mobility solutions. The real problem is almost never technical What these five points have in common is that they are almost never caused by a lack of tools, but by a lack of clarity about who is responsible for what. Many companies mistakenly believe that signing a contract with an IT provider automatically transfers responsibility for compliance. This is not the case. Under the nLPD, as well as under the GDPR for organizations processing data from European residents, responsibility for data protection remains with the company’s management, regardless of the level of operational delegation to an IT partner. A provider can execute, secure and document. But governance remains with the client. This is precisely why we built our approach around three pillars: cybersecurity and compliance, IT assessment and audit, and outsourced CTO / CISO services. These three dimensions make it possible to technically secure the infrastructure, objectively measure the real level of protection, and steer security with a clear strategic vision. Five questions to ask your IT partner today You do not need to be a technical expert to assess your real exposure. A few simple questions are often enough to open the discussion and identify areas of uncertainty. When was our backup last tested — not simply saved, but actually restored? Is multi-factor authentication enabled on 100% of our critical access points? Who exactly has access to what within our organization — and has this list been reviewed in the past 12 months? Is there a complete inventory of our

Articles Blog EN

Hostpoint accelerates file transfer with File Express, between sovereignty and security

Hostpoint accelerates file transfer with File Express, between sovereignty and security Hostpoint accelerates file transfer with File Express, between sovereignty and security In a digital landscape where data exchanges are exploding, file transfer is becoming a strategic service, far beyond its purely functional role. It is in this context that the Swiss hosting provider Hostpoint is unveiling File Express, a new platform designed to simplify the sending of large files while strengthening guarantees around security and sovereignty. This initiative illustrates the evolution of a rapidly maturing market, where user expectations, both individual and professional, are changing quickly. A response to a now universal use case Long limited to occasional use, file transfer is now at the heart of everyday digital workflows: project deliveries, confidential document exchanges, and the sharing of large multimedia content. Yet traditional solutions, such as email attachments or general-purpose cloud services, quickly show their limits when file volumes increase. This is precisely where File Express positions itself. Accessible directly from a browser, the solution allows users to send and receive files without installation, following a simplicity-first approach comparable to market standards. Without registration, users can already transfer files up to 5 GB, while registered users benefit from advanced features such as transfer management and password protection. A Swiss market already structured… but undergoing change Hostpoint is not entering an empty market. The Swiss file transfer market is already shaped by several well-established players, starting with SwissTransfer by Infomaniak, which allows users to send up to 50 GB for free without creating an account. Alongside this, there are solutions offered by Swisscom, as well as international platforms such as WeTransfer, widely adopted for their simplicity. However, these tools are increasingly being challenged on issues that go beyond user experience: data location, compliance, and control over exchanges. With File Express, Hostpoint is therefore enriching the existing offering by focusing on a differentiated value proposition centered on security and control. Security as a central argument Beyond functionality, the competition is now being played out on the ground of digital trust. Hostpoint highlights the full hosting of data on infrastructure located in Switzerland, a factor that has become decisive for many organizations concerned about regulatory compliance. The paid plans go further, integrating features such as end-to-end encryption, geoblocking, and detailed transfer tracking. These elements reflect the premiumization of the service: file transfer is no longer only a question of volume, but also of controlling data flows and protecting sensitive information. From a technological component to a strategic product Unlike some solutions developed from scratch, File Express is based on technology from Swiss Cyber Gate, a Hostpoint subsidiary specializing in secure transfer solutions. This repositioning, transforming a technical solution into an accessible and enhanced web application, is part of a broader strategy: offering a complete ecosystem of digital services, from hosting to collaborative tools. In this logic, the launch of File Express appears to be a natural step, designed to strengthen the coherence and value of the provider’s overall offering. Segmentation designed for professional use cases The business model of File Express also reflects this dual ambition, between accessibility and increased capability. A free version allows immediate adoption, while subscriptions progressively introduce greater capacities: larger transfer volumes, extended storage space, and advanced security features. The highest plans notably allow transfers of up to 500 GB and storage capacities of several terabytes, combined with enhanced encryption. This structure reflects a clear positioning: capturing both simple use cases and the more demanding needs of businesses. Towards a redefinition of file transfer tools The emergence of solutions such as File Express confirms a broader trend: file transfer is no longer an isolated tool, but an integrated component of companies’ digital strategy. As requirements around confidentiality, compliance, and data governance intensify, selection criteria are also evolving. Ease of use, once the dominant factor, is no longer enough; it must now be accompanied by strong guarantees around security and data location. In this context, Swiss players with local infrastructure appear well positioned to stand out. A dynamic driven by digital sovereignty With File Express, Hostpoint is not simply adding another feature to its catalogue: it is positioning itself within a broader movement where data sovereignty is becoming a central commercial argument. For Swiss companies, and particularly SMEs, this evolution marks a turning point. Choosing a file transfer tool is no longer simply a technical matter; it is becoming a strategic issue at the crossroads of cybersecurity, compliance, and operational performance. In this race for trust, local solutions may well gain a decisive advantage.

Articles Blog EN

“Don’t Touch That”: Why Legacy Debt Is One of the Biggest Risks in Your Server Room

“Don’t Touch That”: Why Legacy Debt Is One of the Biggest Risks in Your Server Room “Don’t Touch That”: Why Legacy Debt Is One of the Biggest Risks in Your Server Room The most dangerous phrase in a server room is often, “Don’t touch that.” It’s usually said half as a joke, half with a grimace. It refers to the old box that still works, runs something critical, and has survived so many fixes and workarounds that nobody feels confident changing it anymore. Here at AWSMTECH (Switzerland) LTD, we hear this exact phrase from small and mid-sized businesses in Geneva all the time. And it almost always points to the same underlying issue: legacy debt. Legacy debt isn’t just old technology. It’s old technology that has quietly become a dependency. The kind that accumulates risk silently, until it suddenly turns into downtime, a security incident, or an emergency upgrade at the worst possible moment. A legacy debt audit is the fastest way to bring that hidden risk back into the light. What Legacy Debt Really Looks Like Legacy debt is not just “old gear.” It’s old gear that has become normal. It’s the server that runs a business-critical application, the edge device no one remembers purchasing, or the workaround that evolved into a permanent dependency. Over time, this debt stacks up quietly in many Geneva-based infrastructures. As Infinite Lambda describes it, legacy debt “happens even to the best systems,” silently accumulating cost and constraint until it becomes too expensive, or too risky, to ignore. That’s why a legacy debt audit is not theoretical. At AWSMTECH (Switzerland) LTD, we treat it as a visibility exercise: identifying the oldest, highest-leverage risks that should still be actively managed, but often are not. The security problem usually appears when “old” becomes “unpatchable.” UK NCSC guidance on obsolete products is blunt: once technology is out of date, it ideally should not be used, and the only fully effective mitigation is to stop using it altogether. If a system cannot be updated, its weaknesses do not fade with time. They wait for the wrong day. Legacy debt also becomes visible when basic server hygiene starts to slip. NIST SP 800-123 describes secure server operations as an ongoing discipline, including regular patching and upgrades, log monitoring, backups, and removal of unnecessary services and protocols. When these fundamentals become inconsistent, legacy debt stops being just a security issue and turns into a reliability and incident-response problem. Finally, legacy debt frequently hides at the edge. End-of-support, internet-facing devices represent outsized risk in the most exposed part of your environment. The 3 Oldest Risks to Identify First In most legacy debt audits we run for Geneva-based organisations, 3 categories consistently create the highest risk. They combine age with leverage: they sit at the front door, can no longer be fixed, or have quietly drifted away from a safe baseline. Risk #1: End-of-Support Edge Devices If you want to find high-impact legacy debt quickly, start at the edge. Firewalls, VPN gateways, routers, and other internet-facing devices are the front door to your environment. Once they reach end-of-support (EOS), security updates stop, and defending them becomes increasingly difficult. What to check in your audit: List every edge device, including firewalls, VPNs, and routers, and confirm support status. Identify which devices are internet-facing and which services are exposed. Flag devices that cannot run current firmware or no longer receive updates. For small businesses in Geneva, unsupported edge devices often represent the single highest-leverage technical risk. Risk #2: Obsolete Products That Can’t Be Fixed Anymore Obsolete systems are the purest form of legacy debt. They still run, but they no longer receive security updates. That means every newly discovered vulnerability becomes permanent. There is no clever workaround that makes unsupported software safe, only temporary risk reduction until replacement. What to check in your audit: Identify all systems past support: server operating systems, appliances, hypervisors, and business-critical applications. Flag systems that require security exceptions, such as old protocols, weak authentication, or special firewall rules. Identify “business-critical but unsupported” systems. At AWSMTECH (Switzerland) LTD, this category is often where the hardest, but most necessary, decisions begin. Risk #3: “It Still Works” Servers With Neglected Basics This is the most deceptive risk, because everything appears normal. The server is supported. The hardware runs. No one is complaining. But over time, the fundamentals drift: patching becomes irregular, unnecessary services remain enabled, and backups have not been tested under real conditions. NIST SP 800-123 frames secure server operations around unglamorous but essential practices: patching, monitoring logs, controlling services, and validating backups. These basics are what prevent small issues from escalating into long outages. What to check in your audit: Patch reality: current patch levels and frequency of delays. Service sprawl: services running that are no longer required. Admin and service accounts: shared credentials and excessive permissions. Backup confidence: date and outcome of the last restore test. Change control: who can make changes and how they are tracked. For Suisse romande SMEs, this category often represents hidden operational fragility rather than obvious security flaws. Stop Carrying Silent Risk Legacy debt rarely announces itself. It sits quietly in the background, until it suddenly becomes downtime, exposure, or an emergency upgrade you did not plan for. A legacy debt audit gives you control back. It turns “we should really deal with that someday” into a short, prioritised list you can act on. Start with the highest-leverage risks: End-of-support edge devices. Obsolete, unpatchable systems. Servers where the basics have quietly drifted. Then assign owners, set timelines, and move one item at a time from “too risky to touch” to “handled.” Here at AWSMTECH (Switzerland) LTD, we help small and mid-sized organisations across Geneva and Suisse romande run pragmatic, risk-focused legacy debt audits that lead to real action. Contact us to get support with your next legacy debt audit.

Articles Blog EN

MFA Is a Strong Lock — But It’s Not the Whole Door​

MFA Is a Strong Lock — But It’s Not the Whole Door​ MFA Is a Strong Lock — But It’s Not the Whole Door Multi-factor authentication (MFA) is a strong front-door lock. But it’s not the only thing that determines whether someone can get in. Here at AWSMTECH (Switzerland) LTD, we regularly explain to small businesses in Geneva that what happens after login is just as important as the login itself. Once you sign in, your browser keeps you authenticated using a session token—often stored as a cookie. Think of it as a wristband at an event. Once security checks you in, the wristband proves you belong. If an attacker steals that wristband, they may not need to challenge MFA at all. That is the core idea behind session cookie hijacking. The attacker isn’t breaking MFA. They’re skipping it by replaying your already authenticated session. This is not a reason to stop using MFA. It’s a reason to stop treating MFA as the finish line. For businesses across Suisse romande, the practical defence shifts toward layered controls: phishing-resistant authentication, healthy and managed devices, tighter session policies, and monitoring that detects suspicious access early. Why MFA Isn’t a “Game Over” Control MFA remains one of the most effective security improvements most organisations can make, and AWSMTECH (Switzerland) LTD strongly recommends it to every client in Geneva. However, MFA alone does not end an attack. The reason is simple: attackers don’t always try to defeat the login itself. They often go around it. Cloudflare notes that “attackers are finding new ways to circumvent MFA” and that modern incidents rarely rely on a single technique. Instead, they are part of chained attacks, where one method leads into another. MFA blocks a large proportion of credential theft. What it does not automatically protect is what happens after a successful sign-in. That is precisely where session cookie hijacking applies. Microsoft has described adversary-in-the-middle phishing campaigns in which attackers use reverse-proxy sites to intercept both the user’s credentials and the session cookie that proves an authenticated session exists. This is not a weakness in MFA. The attacker isn’t defeating MFA—they are reusing the session after MFA has already been completed. What a Session Cookie Is — and Why Attackers Want It When you sign in to a web application, the service needs a way to remember that you have already proven your identity. That temporary authenticated state is called a session. Session identifiers are commonly stored as cookies. Kaspersky explains that session hijacking is often referred to as “cookie hijacking” for exactly this reason. Attackers target session cookies because they are the shortcut. Proofpoint describes session tokens as digital “keys” that allow users to stay authenticated. If those keys are stolen, attackers can impersonate legitimate users and potentially bypass authentication controls such as MFA. That is what makes session cookie hijacking so effective. If an attacker can capture the cookie representing your active session, they don’t need to break the login process. They simply reuse what you have already completed and gain access to the same applications and data—exactly as if they were sitting at your keyboard. How Session Cookie Hijacking Actually Happens Many teams imagine “account takeover” as password guessing or MFA fatigue attacks. Session hijacking works differently. The attacker’s goal is not to log in as you—it is to take over the proof that you are already logged in and reuse it, often without triggering another authentication challenge. 1) Adversary-in-the-Middle (AiTM) phishing AiTM phishing is a classic proxy-login trap. You believe you are signing in to a legitimate site, but instead you are interacting with a look-alike page controlled by the attacker. That page relays the login in real time to the real service, so everything appears normal—including MFA. Attackers use this technique to intercept the username, password, and session cookie that proves authentication. Again, this is not MFA being broken. MFA succeeds—and the session is stolen immediately afterward. One known campaign attempted to target more than 10,000 organisations, demonstrating how scalable and effective this technique has become. 2) Browser-in-the-Middle (BitM) session stealing Browser-in-the-middle attacks take this a step further. Instead of just proxying the login, the attacker maintains control over the user’s browsing session itself. Google’s threat intelligence team states that stealing a session token is effectively the same as stealing the authenticated session—and once obtained, the attacker no longer needs to perform an MFA challenge. In this scenario, the attacker is not trying to authenticate instead of the user. They are riding along after authentication has already occurred. 3) Cookie theft from the endpoint Not all session hijacking involves sophisticated phishing infrastructure. In some cases, attackers steal session data directly from a compromised device. If malware gains access to an endpoint, it can extract session cookies and reuse them elsewhere. Session tokens behave like digital keys. If they are taken from an infected device, they can allow attackers to impersonate legitimate users and access sensitive systems without ever touching the login page. MFA Is a Baseline — Not the Finish Line MFA remains essential. It blocks a huge category of credential-based attacks and significantly raises the bar for attackers. But session cookie hijacking is a reminder that not every attack focuses on the login step. For Geneva-based SMEs, the practical response is layered and realistic, not alarmist: Make phishing harder through phishing-resistant sign-ins Treat device health and patching as part of identity security Tighten session behaviour on high-risk applications Monitor for suspicious access patterns that indicate session replay When these controls work together, MFA stops being a comforting checkbox and becomes what it was always meant to be: a strong baseline, supported by protections around the session itself. Here at AWSMTECH (Switzerland) LTD, we help small and mid-sized businesses across Geneva and Suisse romande design identity protections that reflect how modern attacks actually work. Contact us today if you would like help protecting your login sessions from hijacking.

Articles Blog EN

Clean Desk 2.0: Why Physical Habits Are Still a Cybersecurity Issue in 2026

Clean Desk 2.0: Why Physical Habits Are Still a Cybersecurity Issue in 2026 Clean Desk 2.0: Why Physical Habits Are Still a Cybersecurity Issue in 2026 In the traditional office, a Clean Desk policy was a simple discipline: shred sensitive documents, lock them away, and never leave passwords in plain sight. Here at AWSMTECH (Switzerland) LTD, we often remind our clients in Geneva that the principle itself hasn’t changed, but the environment has. In 2026, the “desk” is no longer just a physical surface. For many teams across Suisse romande, the home office has become the default workspace. That means physical access can very quickly turn into digital access. An unlocked screen, a shared device, or a laptop left in the wrong place can expose the same business-critical systems your organisation relies on every day. Clean Desk 2.0 is not about appearances. It’s about securing the physical-to-digital bridge. If a houseguest, a delivery person, or even a passer-by can sit down at your workstation, they don’t need advanced technical skills to cause damage. They only need a few unattended minutes and an open session. Why an Unlocked Screen Is a Data Breach Most small business owners treat multi-factor authentication (MFA) as the ultimate safeguard. And it is an important one. But as we regularly explain to small businesses in Geneva, once you’re already logged in, MFA is no longer the control that protects you. When you sign into a cloud application, your browser creates a session token, often stored as a cookie, so you don’t have to authenticate on every action. Security vendors like Kaspersky describe session hijacking as “cookie hijacking”, while Proofpoint compares session tokens to digital keys. If those keys are stolen, attackers can impersonate users and bypass controls such as MFA. This is where physical access changes everything. If someone can sit at your desk while you step away for a coffee, they don’t need to crack passwords. They can reuse your already authenticated session and gain access to the same cloud platforms, CRM data, and financial tools you were just using, without triggering any MFA prompt. That’s why, at AWSMTECH (Switzerland) LTD, we insist that Clean Desk 2.0 must include a strong auto-lock culture: Use short screen-lock timers Lock your screen manually every time you leave your desk Treat an unlocked session like a set of master keys left in the door Hardware “Legacy Debt” on Your Desk Most people keep old technology for one simple reason: it still works. But “still works” is not the same as “still secure.” The same legacy debt we see in server rooms also exists in home offices across Geneva, often in places that matter most: routers, VPN gateways, Wi-Fi access points, or the “backup” laptop that hasn’t been updated in months. The critical issue is end-of-support (EOS). Once a device reaches EOS, security updates stop. Official guidance is clear: once a product is obsolete, the only fully effective mitigation is to stop using it. You cannot patch your way out of a device that no longer receives patches. This is particularly dangerous for edge devices, anything internet-facing that sits between your home network and the outside world. A key Clean Desk 2.0 habit we recommend to businesses in Suisse romande is to audit the home-office edge exactly like a server room: Identify all internet-facing devices Confirm they are supported and regularly patched Retire or replace anything that is not Your Digital Employee Needs a Locked Door As AI becomes embedded into everyday business tools, workstations are no longer just where work happens. They’re where automated actions are executed. An AI agent might update your CRM, draft client communications, schedule appointments, or move workflows forward with minimal human input once initiated. For SMEs in Geneva, this brings efficiency, but also a new physical risk. Unattended sessions and automation do not mix. If an AI-driven process is running while you are away from your desk, an unlocked screen effectively becomes an open control panel. Someone doesn’t need to be technical to interfere. A few clicks can approve an action, redirect payments, alter data, or disrupt an active workflow. The solution isn’t to avoid automation. At AWSMTECH (Switzerland) LTD, we advise treating AI-driven workflows like any other powerful business system: with clear boundaries and approvals. Decide in advance: Which decisions an AI agent can make without human presence Which actions require explicit approval Spending limits and escalation rules Which systems and data the agent may access, and which are forbidden Physical Efficiency and Cloud Waste A Clean Desk 2.0 mindset is not only about security. It is also about operational discipline: knowing what you use, why you use it, and what should be turned off when it is no longer needed. Cloud waste is the digital equivalent of leaving the lights on in an empty building. Among Geneva-based SMEs, it typically appears as underused servers, forgotten test environments, or ever-growing storage that no one actively manages. Nothing seems dramatic day to day. Costs simply rise quietly, month after month. The habit that fixes this is the same one that keeps a physical workspace under control: visibility and ownership. Assign owners to environments and major cloud resources, review what is actually being used, and schedule non-production workloads to shut down outside business hours. These routine “tidy-up” practices reduce costs, lower exposure, and make your environment significantly easier to manage when something goes wrong. Building a Clean Desk 2.0 Foundation Securing a home office against physical data leaks is not about paranoia. It is about professionalism. In 2026, the home workspace is no longer secondary. It is part of your business perimeter. Clean Desk 2.0 is a set of modern defaults: locked screens, supported devices, clear ownership, and safe automation. When these basics are consistent, small home-office lapses stop escalating into larger business incidents. Here at AWSMTECH (Switzerland) LTD, we support small and mid-sized businesses throughout Geneva and Suisse romande in turning these principles into simple, enforceable baselines. If you would like help

Articles Blog EN

Why Your SaaS Exit Strategy Matters More Than Ever in 2026

Why Your SaaS Exit Strategy Matters More Than Ever in 2026 Why Your SaaS Exit Strategy Matters More Than Ever in 2026 When you first sign up for a software-as-a-service (SaaS) platform, everything is designed to feel effortless. Here at AWSMTECH (Switzerland) LTD, we see this every day with small and mid-sized organisations across Geneva and the surrounding Lake Geneva region. The problem is that the first real test of a SaaS relationship isn’t the onboarding. It’s the exit. For many small businesses in Geneva, the front door is wide open, but the emergency exit is bolted shut: exports are incomplete, critical business data sits in proprietary formats, and leaving a platform often requires expensive and time-consuming vendor support. That’s more than inconvenient. It’s a material business risk. As organisations in Suisse romande move toward a workforce blended with humans and Agentic AI by 2026, the real competitive advantage will come from data you can move, reuse, and trust. At AWSMTECH (Switzerland) LTD, we believe that if your data cannot leave a vendor cleanly, you do not fully control your processes. Instead, your options, timelines, and costs are decided for you. Why This Gets Worse in 2026 The question of a “backup exit strategy” is becoming more urgent in 2026 because SaaS sprawl and third-party dependency are now the norm for SMEs in Geneva. Your business data no longer lives in a single system. It is distributed across cloud platforms, integrations, plug-ins, and automation tools. When one vendor changes pricing, terms, features, or risk posture, you don’t simply “switch tools.” You either move your data cleanly—or you remain stuck. The security environment raises the stakes even further. Verizon’s 2025 DBIR Executive Summary analysed 22,052 security incidents and 12,195 confirmed breaches, calling it the highest number of breaches ever reviewed in a single report, across 139 countries. For businesses in Geneva’s finance, legal, and regulated sectors, this matters because exits and migrations often happen under pressure—after a breach, during an audit, or following a regulatory concern. As we regularly advise clients at AWSMTECH (Switzerland) LTD, a solid exit strategy is what prevents “we need to move” from becoming “we can’t move.” Attackers are also increasingly focused on credentials and data pathways—the same pathways you rely on during exports and migrations. Microsoft’s Digital Defense Report 2025 highlights that credential and access-key theft attempts increased by 23%, while attempts to extract sensitive data from storage accounts and databases rose by 58%. Microsoft also reports that data collection was present in 80% of reactive engagements, reinforcing a critical point: getting the data is now a primary objective of modern attacks. If you cannot export your data safely and predictably, you are effectively trapped. You can’t rotate away from a risky platform quickly, and you can’t migrate without introducing new exposure. Finally, being stuck is expensive—even before vendor fees enter the equation. IBM’s 2025 Cost of a Data Breach Report puts the global average cost of a breach at USD 4.4 million. While not a “lock-in” metric, it is a powerful reminder for Geneva-based SMEs: data incidents carry real financial consequences, and poor exit readiness can multiply those costs at the worst possible moment. In 2026, the real question isn’t if you’ll need to move your data—it’s whether you’ll be able to do it cleanly, independently, and on your own timeline. The Financial Cost of the “Proprietary Trap” A weak exit plan doesn’t just slow down innovation. It quietly inflates operating costs. At AWSMTECH (Switzerland) LTD, we frequently see organisations in Geneva paying for overlapping tools or overpriced platforms simply because switching feels too complex. When data is locked inside proprietary systems, spending becomes sticky: you can’t right-size quickly, consolidate tooling, or move workloads to a better-fit solution without turning it into a major project. That’s how inefficiency lingers. The real cost isn’t the monthly invoice—it’s the loss of choice. When your data can’t move, every renewal, pricing change, or product shift becomes a forced decision instead of a strategic one. A true backup exit strategy reverses that dynamic. It allows businesses across Suisse romande to migrate on their own terms, reduce duplicated tooling, and make decisions based on value rather than inertia. In practical terms, it turns “we can’t leave” into “we can compare, choose, and move when it makes sense.” Securing the Move Once a decision is made to move data, the migration itself becomes a high-risk moment—not because migrations are inherently unsafe, but because they concentrate exactly what attackers are looking for: High-privilege access Multiple simultaneous admin sessions Large volumes of data in motion During migrations, teams are often signed into several privileged tools at the same time. This is where session cookie hijacking becomes relevant. An attacker doesn’t need to steal a password if they can capture a session token that proves you are already authenticated. Microsoft has documented adversary-in-the-middle phishing attacks that intercept session cookies, allowing attackers to bypass MFA entirely. Cloudflare has also highlighted how MFA circumvention is now part of broader attack chains—confirming what we consistently recommend at AWSMTECH (Switzerland) LTD: security during migrations must be layered, not single-control reliant. To secure a backup exit migration, we advise Geneva-based organisations to: Use phishing-resistant authentication for admin and migration accounts Enforce shorter session lifetimes for privileged access Run migrations from managed, patched, and protected devices Actively monitor for suspicious access during the migration window Ownership Is a Discipline The organisations that thrive over the next few years—especially in competitive markets like Geneva—won’t just adopt new tools. They’ll remain flexible as those tools evolve or are replaced. In a world of SaaS sprawl and AI-driven workflows, that flexibility comes from clean data ownership, well-defined processes, and the ability to move when necessary. Here at AWSMTECH (Switzerland) LTD, we believe that control over your data is not a one-time decision—it’s an ongoing discipline. If you would like help building an exit-ready baseline across your SaaS and vendor stack, our team supports small and mid-sized businesses throughout Geneva and Suisse romande

Articles Blog EN

Green IT for SMEs: Combining Digital Performance and Environmental Sustainability

Green IT for SMEs: Combining Digital Performance and Environmental Sustainability Green IT for SMEs: Combining Digital Performance and Environmental Sustainability Digital transformation has become an essential step for all companies, including small and medium-sized enterprises (SMEs). It optimizes processes, facilitates collaboration, and stimulates innovation. However, this digital boom comes with a sharp increase in energy and resource consumption, often invisible at first glance. For example, data centers are estimated to represent around 1% of global electricity consumption, equivalent to the annual consumption of several million households. In Switzerland, data centers already account for nearly 4% of national electricity consumption, as much as all the country’s trains combined. With the rapid rise of cloud computing and artificial intelligence, this digital footprint continues to grow. In this context, the Green IT approach (or sustainable IT) aims to reverse the trend: it brings together a set of practices designed to reduce the environmental footprint of digital technologies while preserving performance. In other words, the objective is to adopt eco-responsible technologies and more sustainable usage patterns in order to reconcile digital transformation with environmental sustainability. What is Green IT? Green IT (short for Green Information Technology) refers to all strategies and best practices aimed at minimizing the environmental impact of digital technologies throughout their lifecycle. This includes the eco-responsible design of hardware and software, their energy-efficient daily use, and the end-of-life management of equipment with proper recycling of electronic waste. Beyond technical solutions, Green IT involves a comprehensive organizational approach: it means rethinking digital usage and integrating digital sobriety into company practices to align digital transformation with sustainable development goals. Why does Green IT matter for SMEs? Several factors are encouraging SMEs to take a closer interest in sustainable IT practices: Rising energy costs: IT represents a growing share of electricity expenses and operational costs for SMEs. Between servers running 24/7, office equipment, and massive online data storage, the energy bill related to digital technologies is increasing rapidly. Optimizing the consumption of these systems is therefore an immediate lever to reduce costs. Pressure from customers and partners: More and more clients, consumers, and business partners expect companies to adopt sustainable practices. Committing to a Green IT approach sends a strong signal: the company reduces its carbon footprint and demonstrates environmental responsibility, thereby strengthening its brand image and competitiveness in the market. Increasing regulatory requirements: Public authorities – in Switzerland, in Europe, and elsewhere – are multiplying environmental standards and incentives for digital sobriety. For example, Switzerland encourages improvements in the energy efficiency of data centers, and the European Union is progressively imposing directives on electronic waste management and the energy consumption of devices. Adopting Green IT enables SMEs to stay ahead of regulatory compliance, avoid potential fines, and benefit from available incentives for responsible companies. Performance and innovation: Contrary to common belief, improving the environmental efficiency of IT can go hand in hand with enhanced performance. For example, rationalizing stored data or modernizing an obsolete server can accelerate applications while consuming less energy. Likewise, migrating to high-performance cloud tools can strengthen business agility while reducing its carbon footprint. Thus, digital performance and sustainability can progress together, offering SMEs a dual competitive advantage. Key Green IT practices (and their benefits) Fortunately, SMEs can deploy Green IT step by step, depending on their resources and priorities. Below are some fundamental Green IT practices and the concrete benefits they bring to small businesses: Green IT Practice Potential Benefits for SMEs Efficient IT infrastructures (cloud & virtualization) Reduce energy consumption by optimizing server and storage usage (fewer active machines, reduced cooling systems). Lower electricity bills and maintenance costs, while potentially improving application reliability and performance. Sustainable and eco-designed hardware Energy-efficient IT equipment (Energy Star certified and equivalent) consumes less electricity and lasts longer. By prioritizing modular, repairable, or refurbished equipment, companies reduce replacement costs and limit electronic waste production. Responsible e-waste management Recycling and reuse policies for end-of-life equipment reduce electronic waste and prevent pollution associated with landfill disposal. Recycling recovers valuable materials, and refurbishing used devices can generate savings or additional revenue. Sustainable digital usage Measures such as automatic sleep mode for computers, switching off equipment outside office hours, reducing paper printing, and disabling unnecessary digital services immediately decrease electricity consumption and waste. These simple actions lower recurring costs and demonstrate the company’s environmental commitment, strengthening its image among stakeholders. Awareness and green corporate culture Integrating Green IT into company culture ensures the sustainability of efforts. Training employees in digital eco-friendly practices (e.g., managing emails properly, limiting HD streaming, unplugging unused devices) and including environmental objectives in IT strategy strengthens staff engagement and coherence of actions. Challenges and opportunities of Green IT for SMEs Despite its many advantages, implementing Green IT can present specific challenges for small organizations. A lack of financial and technical resources is often cited as a barrier: investing in more energy-efficient equipment or newer software represents an immediate cost that can be difficult to bear for an SME with a tight budget. In addition, a lack of expertise in digital sustainability can leave managers feeling overwhelmed by the range of possible solutions, and resistance to changing habits within teams can slow down the green transition. These obstacles are real but can be transformed into growth and innovation opportunities. For example, improvements in energy efficiency ultimately generate substantial long-term savings, largely offsetting the initial investment. Likewise, the need to train in responsible digital practices can become an opportunity to build skills and innovate, strengthening the company’s competitiveness. By overcoming internal resistance through awareness and employee involvement, the SME develops a more agile and responsible corporate culture, fostering internal cohesion. Finally, by voluntarily adopting Green IT practices, an SME positions itself as a pioneer in its sector. It can gain a competitive advantage by responding to growing demand for environmentally friendly products and services. It will also be better prepared for future regulatory changes or fluctuations in energy costs, thereby strengthening its resilience. Practical tips to start Green IT SMEs do not need significant

Articles Blog EN

Cybersecurity Switzerland 2026: anticipate NIS2, DORA and FINMA. Understand the key requirements and strengthen your company’s resilience.

Cybersecurity Switzerland 2026: anticipate NIS2, DORA and FINMA. Understand the key requirements and strengthen your company’s resilience. Cybersecurity Switzerland 2026: Are you ready for NIS2, DORA and FINMA? Cybersecurity Switzerland 2026: Are you ready for NIS2, DORA and FINMA? By 2026, regulated companies in Switzerland will have to face an unprecedented convergence of regulations in cybersecurity and operational resilience. On one side, the European regulations NIS2 and DORA impose strict standards on companies operating within the European Union. On the other, FINMA and the National Cyber Security Centre (NCSC) are strengthening local requirements. Objective of this article: help you understand the implications of these regulations, identify the risks of non-compliance, and adopt best practices to ensure the security of your information systems and the continuity of your critical activities. Why NIS2 and DORA compliance also concerns Swiss companies Even though Switzerland is not a member of the EU, it does not escape the influence of European regulations. The NIS2 Directive and the DORA Regulation apply indirectly to Swiss companies through their cross-border activities, their partners or their subsidiaries in the EU. Switzerland has chosen to align its national strategy with NIS2 through the KRITIS-G law, which will enter into force in January 2027. Likewise, Swiss ICT providers delivering services to financial entities in the EU must comply with DORA as of January 2025. DORA: What Swiss ICT providers need to know The DORA Regulation requires financial institutions and their ICT providers to implement: An ICT risk management framework Resilience testing (TLPT, BCP) Rigorous third-party supplier management Incident notifications within strict deadlines Sanctions of up to 2% of global annual turnover Even though DORA is a European regulation, it applies to Swiss providers operating for financial entities in the EU. It is therefore crucial to anticipate these obligations now. FINMA 2023/1: A new era for banking operational resilience FINMA Circular 2023/1, in force since January 2024, requires Swiss banks to implement: Strengthened operational risk governance Identification of critical functions Business continuity management (BCM) plans Rapid notification obligations in case of a cyber incident It aligns with international best practices and complements DORA requirements for Swiss financial institutions. Comparative table: NIS2 vs DORA vs FINMA – What are the differences? Requirement NIS2 (EU) DORA (EU) FINMA 2023/1 (Switzerland) Sectors concerned 18 critical sectors Financial sector + providers Banks and insurers Incident notification Max 24h Strict deadlines As soon as possible Sanctions Up to 10% of global turnover Up to 2% of global turnover Periodic penalty payments, withdrawal of authorization Governance required Yes Yes Yes Supplier management Mandatory Very detailed Requirements via Circ. 2018/3 Non-compliance risks: What you really risk Financial fines (up to 10% of turnover) Loss of contracts with European partners Damaged reputation (publication of breaches) Withdrawal of authorization by FINMA Exclusion from public tenders Increase in cyber insurance premiums Synergies and divergences between Swiss and European frameworks Synergies: Common objectives: strengthening cyber resilience Risk-based approach and reinforced governance Compatibility between technical requirements (ISO 27001, NCSC ICT Minimum Standard) Divergences: Different definitions of critical functions Varying notification deadlines Stricter contractual requirements under DORA 6 best practices to anticipate 2026 without stress Conduct a NIS2 / DORA / FINMA compliance audit Implement a cybersecurity framework based on ISO 27001 Integrate regulatory requirements into supplier contracts Train teams on incident management Involve the Board of Directors in the cyber strategy Use the NCSC ICT Standard as a technical baseline Turning compliance into a competitive advantage The convergence of NIS2, DORA and FINMA regulations is not just a regulatory challenge. It is a strategic opportunity for Swiss companies to: Strengthen their cybersecurity posture Earn the trust of clients and partners Position themselves as a reliable player in the European market Reduce operational and legal risks By anticipating now, you turn compliance into a growth lever.

Articles Blog EN

Discover why SMS codes are no longer sufficient for MFA and which modern, secure, and phishing-resistant authentication solutions to adopt in Switzerland.

Discover why SMS codes are no longer sufficient for MFA and which modern, secure, and phishing-resistant authentication solutions to adopt in Switzerland. MFA Security: Why SMS Codes Are No Longer Enough in 2026 (and What to Adopt in Switzerland)  For many years, enabling multi-factor authentication (MFA) has been a cornerstone of account and device security. MFA remains essential, but the threat landscape has evolved, making some traditional methods less effective. The most common form of MFA – four- or six-digit codes sent via SMS – is convenient and familiar, and certainly an improvement over passwords alone. However, SMS relies on aging technology, and cybercriminals now have reliable techniques to bypass it. For organizations handling sensitive data, SMS-based MFA is no longer sufficient. It is time to adopt modern, phishing-resistant MFA to stay ahead of current attacks. SMS was never designed as a secure authentication channel. Its dependence on mobile networks exposes it to significant vulnerabilities, particularly within telecom protocols such as Signaling System No. 7 (SS7), which is used for communication between networks. Attackers know that many companies still rely on SMS for MFA, making it an attractive target. For example, SS7 vulnerabilities can be exploited to intercept SMS messages without even accessing your phone. Eavesdropping, message redirection, or injection can occur directly within the operator’s network or during transmission. SMS codes are also vulnerable to phishing. If a user enters their username, password, and SMS code on a fraudulent website, attackers can capture all three elements in real time and immediately access the legitimate account.  Understanding SIM Swapping Attacks One of the most serious threats associated with SMS is SIM swapping. In this type of attack, a criminal contacts your mobile carrier while impersonating you and claims to have lost their phone. They then request that your number be transferred to a new SIM card in their possession. If successful, your phone loses service while the attacker receives all your calls and SMS messages, including MFA codes for your banking or email services. Even without knowing your password, they can reset your credentials and take full control of your accounts. This type of attack does not require advanced technical skills. It primarily relies on social engineering targeting carrier customer support, making it simple yet potentially devastating. Why Phishing-Resistant MFA Is Becoming the New Standard To counter these threats, it is essential to minimize human intervention by adopting phishing-resistant MFA. This approach relies on cryptographic protocols that bind each login attempt to a specific domain. One of the most widely adopted standards is FIDO2, which uses cryptographic keys tied to both a device and a domain. Even if a user clicks on a phishing link, the authentication application will not release credentials if the domain does not match. This technology is also passwordless, eliminating the risk of phishing-based theft of passwords or one-time passcodes (OTPs). Attackers are forced to target the device itself, which is far more difficult than deceiving a user. Using Hardware Security Keys Hardware security keys are among the most robust phishing-resistant solutions available. These are small physical devices, similar to a USB key, that are inserted into a computer or tapped against a smartphone. To log in, the user simply inserts or taps the key, which then performs a cryptographic verification with the service. This approach is extremely secure because there is no code to enter, and attackers cannot steal the key remotely. They would need to physically obtain it, which is significantly more difficult. Authenticator Apps and Push Notifications If physical keys are not feasible, authenticator apps such as Microsoft Authenticator or Google Authenticator are a clear improvement over SMS. Codes are generated locally on the device, eliminating the risks associated with SIM swapping or SMS interception. Push notifications do carry some risk. Attackers can send multiple approval requests, leading to MFA fatigue, where a user eventually taps “approve” simply to stop the alerts. Modern applications now integrate number matching. The user must enter in the app the number displayed on their login screen, ensuring they are physically present at their device. Passkeys: The Future of Authentication As passwords are regularly compromised, modern systems are adopting passkeys – credentials stored on the device and protected by biometrics such as fingerprint or facial recognition. Passkeys are phishing-resistant and can be synchronized through services like iCloud Keychain or Google Password Manager. They offer the security of a hardware key with the convenience of a device the user already owns. They also reduce the burden on IT teams, as there are no passwords to store or reset. Finding the Balance Between Security and User Experience Moving away from SMS-based MFA requires a cultural shift. Because users are accustomed to the simplicity of SMS, introducing hardware keys or authenticator apps may initially meet resistance. It is crucial to explain the reasons for the change, particularly the risks of SIM swapping and the value of the data being protected. When users understand the stakes, they are more likely to embrace stronger measures. A phased rollout can help for general internal users, but phishing-resistant MFA should be mandatory for privileged accounts – administrators, executives, and leadership. The Cost of Inaction Continuing to rely on outdated MFA methods creates a false sense of security. Even if such methods satisfy certain compliance requirements, they leave systems exposed to costly attacks and breaches, both financially and reputationally. Modernizing authentication methods offers one of the strongest returns on investment in cybersecurity. The cost of hardware keys or identity management solutions remains modest compared to the expenses associated with a security incident, incident response, or data recovery. Is Your Company Ready to Move Beyond Passwords and SMS Codes? We specialize in deploying modern identity solutions that are secure and easy to use. Contact us to implement a robust authentication strategy tailored to your organization.

Articles Blog EN

Strengthen your cloud security in 15 minutes a day. Discover best practices to prevent vulnerabilities and protect your data in Switzerland.

Strengthen your cloud security in 15 minutes a day. Discover best practices to prevent vulnerabilities and protect your data in Switzerland. Moving to the Cloud…  Migrating to the cloud offers great flexibility and speed, but it also brings new responsibilities for your team. Cloud security is not something you configure once and forget: small mistakes can quickly turn into serious vulnerabilities if they are ignored. You do not need to spend hours on it every day. In most cases, a short, regular check is enough to spot issues before they escalate. Establishing a routine is the most effective way to protect yourself against cyberthreats and to maintain an organized and secure environment. Think of daily cloud security checks like a morning hygiene routine for your infrastructure. Fifteen minutes a day can prevent major incidents. A proactive approach is essential to ensure business continuity and should include the following best practices: 1. Review access and identity logsThe first step is to check who has logged in and confirm that all access attempts are legitimate. Identify logins from unusual locations or at odd hours: these are often the first signs of a compromised account. Also pay close attention to failed login attempts. A sudden increase may indicate a brute-force or dictionary attack. Quickly investigate these anomalies to prevent an intruder from moving further into your environment. Finally, proper identity management requires strict monitoring of user accounts. Make sure former employees no longer have access and immediately disable any account that should no longer exist. Keeping a clean user list is a fundamental pillar of security. 2. Check storage permissionsData leaks often result from the accidental exposure of a folder or file. Misconfigured permissions can make an item public with a single click. Review your buckets or storage spaces daily and ensure that private data remains private. Look for any container configured with “public” access. If a file does not need to be publicly visible, lock it down. This simple check prevents sensitive data leaks and protects both your reputation and legal compliance. Misconfigurations remain one of the leading causes of breaches. Even though cloud providers offer automated detection tools, a manual review by your cloud administrators is recommended to maintain a clear view of your environment. 3. Monitor unusual usage spikesSudden changes in consumption can reveal a security incident. A compromised server may be used for cryptocurrency mining or integrated into a botnet attacking other systems. Common indicators include a CPU running at 100% or an unexpected increase in cloud costs. Check your cloud dashboard daily to spot abnormal resource spikes and compare the day’s data with your usual baseline. If something looks suspicious, inspect the affected machine or container and trace the root cause: this can prevent a much larger issue. Resource spikes may also indicate a DDoS attack. Identifying them quickly allows you to mitigate traffic and keep your services online. 4. Review security alerts and notificationsYour cloud provider likely sends security alerts, but they are often ignored or end up in spam. Make it a habit to review them daily: they sometimes contain critical information. These notifications may flag outdated systems or unencrypted databases. Addressing them quickly significantly reduces the risk of leaks. Integrate the following checks into your daily routine: Review priority alerts from the cloud security center Check for any new compliance violations Ensure backups completed successfully Confirm that antivirus definitions are up to date on servers Responding to alerts strengthens your security posture and demonstrates due diligence in protecting company assets. 5. Verify backup integrityBackups are your safety net, but only if they are complete and usable. Every morning, check the status of overnight backups. If a job failed, rerun it immediately. Losing a day of data can be costly; maintaining reliable backups is essential to business resilience. It is also recommended to regularly test restores to ensure everything works as expected. Knowing your data is secure allows you to focus on the rest, without fearing the impact of ransomware or other attacks. 6. Keep software up to dateCloud servers require updates just like physical servers. Your daily check should include verifying the status of your patch management system. Unpatched servers are prime targets. With new vulnerabilities discovered every day, reducing the exposure window is critical. Apply patches as soon as they are available, especially critical ones, without waiting for the next maintenance window. This responsiveness prevents many incidents. Building a security routineSecurity does not require heroic daily efforts. It requires consistency, discipline, and a solid routine. A daily 15-minute cloud check is a small investment with a high return, as it protects your data and ensures the smooth operation of your systems. By adopting this proactive approach, you significantly reduce risks, strengthen trust in your IT operations, and simplify the management of your cloud environment. Need help setting up an effective routine? Our managed cloud services monitor your infrastructure 24/7 so you can focus on your core business. Contact us to protect your cloud environment.

Scroll to Top