Why this site exists

Try to find a clear answer to a cybersecurity question while running an SME in French-speaking Switzerland, and you will see the problem. Good-quality information in French is scarce. It is scattered across the sites of the Confederation, cantons, associations and service providers. And when you do find it, it is often written for IT specialists.

The rest is in English, or designed for large companies with a dedicated team and a budget that bears no resemblance to that of a twelve-person company.

The result: many managers know they should deal with it, but do not know where to start, or what really matters in their case. This site exists to fill that gap. It translates technical and legal topics into concrete decisions, for companies with 1 to 100 employees.

Who writes this site

The articles are written by Elio S., for Säfeli Sàrl.

Säfeli Sàrl is a certification and regulatory compliance consultancy based in Granges-Paccot, in the canton of Fribourg. Its business is bringing products and organisations into compliance with applicable standards and regulations.

Company website: www.safeli.ch.

Our editorial method

Cybersecurity is a field where a lot of impressive figures circulate that no one can ever trace back to a source. We chose the opposite approach. Four rules apply to every article.

  • Every claim links to its official source. Sources appear at the bottom of each article, with a direct link. You can verify what we write, and we think you should.
  • No statistic without a source and a year. A figure we cite states where it comes from and what period it refers to. We favour official Swiss publications. A figure we cannot source is not published.
  • Articles are dated. Each page shows its last update date. In cybersecurity as in law, information accurate last year can be wrong today. The date is part of the information.
  • We say what we don't know. When a point is uncertain, debated, or depends on a company's specific situation, we write that rather than deciding just to look good.

The tone follows the same logic. We do not sell fear. Illustrative scenarios are labelled as such, never presented as documented real cases. And we do not make a manager feel guilty for discovering the topic: starting somewhere is infinitely better than doing nothing.

Our business model, stated plainly

Better to write it clearly than to let you guess.

This site is free and will stay that way. There is no advertising, no sponsored content, no article paid for by a software vendor. No tool asks for your e-mail address in exchange for a result. We do not collect addresses to resell them: we do not collect addresses at all, as explained in the privacy policy.

It is funded by Säfeli Sàrl, for which it also serves as a showcase. That is the trade-off, and we own it: we invest time in this content because some of the companies that read it will later turn to our services. Online training courses are also being considered.

The dual role, exposed rather than hidden

We write about a field in which we sell services. That is a potential conflict of interest, and we prefer to expose it rather than hide it. Our safeguard is simple: the articles must remain useful to someone who never contacts us. If a piece of content only helps you if you call us, it is poorly written. You are the best judge: the sources are there so you can prove us wrong.

What this site can do, and what it cannot

This is the most important point on this page, and the easiest to gloss over. Two ideas, which do not contradict each other.

You can already do a lot yourself. The measures described here are within reach of an SME, without an oversized budget. Two-factor authentication, tested backups, applied updates, aware employees: applied seriously, these measures rule out the vast majority of automated attacks, the ones that strike at random and target no one in particular. Do not leave here thinking the topic is beyond you.

And it is not enough. Applying a list of best practices is a first line of defence, not protection. Three reasons for this.

  • A checked box is not a measure that works. The backup that has been silently failing for six months remains the textbook example: it is on the list, it will restore nothing.
  • The costliest risks are specific to each business. They depend on your workflows, your service providers, your sensitive data, and appear on no generic list.
  • A configuration degrades over time. An access right someone forgot to close, a service opened as a quick fix and never closed again: what was correct two years ago is not necessarily correct today.

In other words: this site gives you the basic keys to understand and act. It does not replace an analysis of your situation, or a review by someone who knows where to look. Knowing what really matters at your company requires looking at your company.

Where to start

If you are new to the site, here are three entry points depending on your question.

  • The cyber check-up: twelve questions, a score, and the three actions that would make the biggest difference for you. It is the best starting point.
  • The 10 essential measures: what to put in place first when you have little time and little budget.
  • The FADP: if your question is primarily legal, start with what Swiss law actually expects from you.

Write to us

An error to report, a topic you would like to see covered, a question about an article: use Säfeli's contact form.

www.safeli.ch/contact

Säfeli Sàrl, Route d'Englisberg 3, 1763 Granges-Paccot, Switzerland.

A comment, a correction, a question?
E-mail: [email protected]
Phone: 079 737 37 93

A reported factual error is corrected and the article's update date is changed accordingly.

Legal information appears in the legal notice.