Law firm, trust company, private clinic, private bank, international NGO: in the professions we support every day in French-speaking Switzerland, data is not a simple IT asset. It is professional secrecy, a patient file, a client mandate, sensitive financial information. Yet a recent analysis published by Swisscom on IT security for SMEs highlights a finding we ourselves observe in the field, audit after audit: most organisations that suffer a security incident were convinced, right up until the day of the attack, that they were properly protected.
This gap between the feeling of security and the actual level of protection is the true blind spot of corporate cybersecurity. It is almost never a matter of lacking good intentions, but rather of a lack of verification, responsibilities poorly split between the company and its IT provider, and assumptions that are never questioned.
Here are the five most common false certainties, and how we address them at AWSMTECH for clients who, given the nature of their activity, cannot afford to get it wrong.
1. "Our data is backed up"
This is the most widespread — and most dangerous — certainty. A backup exists in almost all of the organisations we meet. But a backup only has value if it has been tested under real restoration conditions, if it is isolated from the main network so it can withstand ransomware that would also encrypt the backups, and if the restoration time is compatible with the reality of the business.
For a law firm or a notary's office, losing access to case files for three days is not just inconvenient: it can trigger professional liability toward clients and statutory deadlines. For a private clinic, it can directly affect continuity of care.
What we systematically check: the frequency of backups, their isolation, the actual restoration time tested under real conditions, as well as coverage of all critical systems — not just files, but also mailboxes, business databases and server configurations.
2. "Our passwords are strong"
A complex password remains useless if it is stolen through phishing, reused on a compromised third-party service, or intercepted on an infected workstation. Password strength does not protect against credential theft. Only multi-factor authentication can effectively reinforce this protection.
In highly confidential sectors — wealth management, private banking, trust companies — access to email or document management tools is often the most direct gateway into the entire information system.
What we deploy: mandatory multi-factor authentication on all critical access points, a strict privileged access management policy, as well as real-time detection of suspicious logins.
3. "Access rights protect our data"
Many organisations apply generic access rights, inherited from the company's history rather than from a security rationale. As a result, an employee may have access to client files, HR data or financial information that has nothing to do with their role.
If a single workstation is compromised, the entire scope that employee has access to potentially becomes exposed. For an NGO or an international organisation operating in several countries, with remote teams and sometimes significant staff turnover, this question becomes central.
Our approach: application of the least-privilege principle, periodic review of access rights, and strict separation of sensitive environments — finance, HR, client files — through an architecture designed from the initial IT assessment onward.
4. "We update regularly"
The word "regularly" often hides a patchy reality: some workstations are up to date, others forgotten, business software is never patched for fear of incompatibility, and network equipment sometimes runs for years without a firmware update.
Yet known vulnerabilities are exploited by automated attackers within just a few days of being disclosed. The issue is therefore not only about applying updates, but about knowing precisely what needs to be fixed, within what timeframe, and with what level of priority.
What we put in place: a comprehensive inventory of the fleet, automated and supervised patch management, as well as tracking of critical vulnerabilities with contractually defined remediation deadlines — not left to everyone's goodwill.
5. "We have a firewall"
A firewall effectively protects a well-defined network perimeter, typically an office. But hybrid work, business travel and the use of mobile devices have largely dissolved that perimeter.
A notary consulting files from home, a wealth manager travelling, or an NGO team spread across several continents: in all these cases, the office firewall on its own no longer protects much.
Our response: security designed at the level of identity and device, no longer just the local network, through our secure workstation and managed mobility solutions.
The real problem is almost never technical
What these five points have in common is that they almost never stem from a lack of tools, but from a lack of clarity about who is responsible for what. Many companies wrongly believe that signing a contract with an IT provider automatically transfers responsibility for compliance.
This is not the case. Under the nFADP, as under the GDPR for organisations processing data of European residents, responsibility for data protection remains in the hands of company management, regardless of the level of operational delegation to an IT partner.
A provider can execute, secure and document. But governance remains with the client.
It is precisely to close this gap that we built our approach around three pillars: cybersecurity and compliance, IT assessment and audit, and outsourced CTO / CISO.
These three dimensions make it possible to technically secure the infrastructure, objectively measure the actual level of protection, and steer security with a clear strategic vision.
Five questions to ask your IT partner today
You don't need to be a technical expert to assess your actual exposure. A few simple questions are often enough to open the conversation and identify areas of uncertainty.
When was our backup last tested — not simply saved, but actually restored?
Is multi-factor authentication enabled on 100% of our critical access points?
Who, precisely, has access to what within our organisation — and has that list been reviewed in the past 12 months?
Is there a complete inventory of our equipment and software, with formal tracking of updates?
Does our security protect the user and the device, wherever they are — or only the office?
If any of these questions remains without a clear and immediate answer, that is the signal that an audit is needed.
Our conviction at AWSMTECH
The organisations we support — law firms, notary offices, trust companies, private clinics and healthcare providers, private banks and wealth managers, NGOs and international organisations — share one thing in common: they cannot afford to get it wrong.
A data leak, a service interruption or a case of non-compliance are not mere technical incidents. They are reputational, legal and sometimes human risks.
That is why our role is not limited to installing tools. We clarify responsibilities, we document what is in place, we test what is supposed to work, and we give our clients real — not assumed — visibility into their level of protection.
Want to know where your blind spots really are? Our experts can carry out an audit of your infrastructure and your nFADP/GDPR compliance, then provide you with a clear action plan, prioritised according to the actual risks of your business.
Need IT support?
AWSMTECH (Switzerland) LTD supports SMEs in Geneva and French-speaking Switzerland with pragmatic, risk-oriented audits.
Contact us
