Most cybersecurity advice is written for a company that does not exist: one with an in-house IT person, a dedicated budget and some spare time. A company of four people has none of that, and a company of sixty does not face the same problems either.
Here are three distinct paths, based on your headcount. Each one sets out what to do, in what order, and over what timeframe. Follow the one that matches your situation, and ignore the other two until they become relevant to you.
What does size actually change?
It is not the number of employees that matters, it is what that number implies.
Below ten people, there is usually no one whose job is IT. The owner decides, carries it out and forgets, because they have other things to do. The measures that stick are the ones that keep working on their own once switched on.
Between ten and fifty, a threshold is crossed: you no longer know by heart who has access to what. Employees join, leave, change roles. An IT provider steps in, without its limits always being clear. The subject stops being technical and becomes organisational.
Beyond fifty, the problem is no longer putting the measures in place, but guaranteeing that they hold up over time. Without a designated person in charge or a written record, a correct configuration degrades within eighteen months without anyone noticing.
Path 1: 1 to 9 people
Your constraint is time, not budget. Everything below can be done yourself, mostly with tools you already have.
| Deadline | Action | Effort |
|---|---|---|
| First month | Two-factor authentication on e-mail, online banking and business tools | 2 to 3 hours |
| First month | An offline backup, disconnected between copies | 3 to 4 hours |
| First month | Automatic updates enabled on all computers and phones | 1 hour |
| First quarter | Password manager for you and your employees | 3 hours, then 15 min per person |
| First quarter | Written inventory of accounts and tools in use | 2 hours |
| First year | A real backup restoration test | Half a day |
| First year | A clear rule on unusual payment requests | 1 hour |
The first three lines are non-negotiable. They cover the scenarios that genuinely destroy a small business: the ransomware that encrypts everything, the stolen e-mail account, the known vulnerability left open for months. The details of the backup are explained in our article on the 3-2-1 rule.
The last line deserves a word. In a small business, an urgent transfer request from an address resembling the boss’s own goes through easily, because no one dares to check. A simple rule, known to everyone, is enough to break this mechanism: any change of bank details is confirmed by phone, on a number known in advance. This is the core of CEO fraud.
Path 2: 10 to 49 people
At this size, the measures from the first path remain the foundation. They are no longer enough, because the risk has shifted towards people and processes.
| Deadline | Action | Effort |
|---|---|---|
| First month | Check the three foundations of path 1, without assuming they are in place | Half a day |
| First month | An up-to-date list of all active accounts, by person and by tool | A day |
| First quarter | Arrival and departure procedure, with access closed the same day | Half a day of drafting |
| First quarter | Removal of administrator rights from workstations | 1 to 2 days, with your provider |
| First quarter | A one-page crisis sheet: who to call, in what order, with which numbers | 2 to 3 hours |
| First year | Team awareness training, short and repeated rather than long and one-off | 1 hour per session, 2 to 3 times a year |
| First year | Written review with your provider on what is covered and what is not | Half a day |
| First year | A complete, timed restoration test | A day |
Two points deserve further explanation.
Departures. This is the most common blind spot at this size. An employee who left eight months ago whose e-mail still works, whose access to the file server has stayed open, whose account still appears in the management tool. It is almost never malicious, it is simply that no one was responsible for closing it. A one-page procedure solves the problem for good.
The provider. Many owners think their outside IT person takes care of security. Often, their contract covers keeping things running, not protection. The point is not to question them, but to know precisely where the boundary lies, and who takes care of the rest. The risks tied to this dependency are detailed in our article on supply chain attacks.
Path 3: 50 people or more
You probably already have most of the technical measures in place. The work now consists of making them durable and demonstrable.
| Deadline | Action | Effort |
|---|---|---|
| First month | Appoint a named person responsible for information security | Management decision |
| First quarter | Register of personal data processing activities | 2 to 4 days |
| First quarter | IT charter handed out and signed by every employee | 1 to 2 days |
| First quarter | Data breach notification procedure, tested through a dry run | A day |
| First year | Formalised access review, twice a year | A day per review |
| First year | Documented risk analysis, reviewed annually | Several days |
| First year | Independent audit of the measures in place | Varies |
At this size, compliance becomes a subject in its own right. The Federal Act on Data Protection requires appropriate measures without listing them, and requires notifying the Federal Data Protection and Information Commissioner (FDPIC) of breaches that pose a high risk to the people concerned. Swiss law does not set a numerical deadline, it requires acting as soon as possible, which means knowing in advance who decides and who drafts the notification. The details are covered in our article on reporting a data breach.
The periodic review is the most underestimated measure in this path. A policy written in January and never revisited becomes a work of fiction within two years. What protects you is not the document, it is the date of the next check written into a calendar.
The limit of any plan based on size
It is worth being honest about what these three tables are actually worth.
A plan based on headcount gives a reasonable trajectory, and following the one that matches you will put you ahead of many comparable companies. But this plan knows nothing of your line of work, the nature of the data you handle, the flows between your tools, the providers you depend on without being able to replace them, or what would hurt you the most if it stopped working tomorrow morning.
An architecture firm whose entire value lies in ongoing drawings must first worry about backups and availability. A medical practice of the same size processes sensitive data: its priority is access control and encryption. Both companies have the same headcount, the same theoretical path, and yet it is not the same measure that needs to come first.
These plans also share the weakness of any checklist: a ticked box is not a measure that actually works. A backup that has been silently failing for six months still appears as done in the table. A former employee’s account forgotten in a secondary tool does not appear in any box. And what you do not know about never appears in a checklist you fill in yourself.
This foundation is therefore a solid starting point, not a finished protection. Turning it into real protection requires two things: an analysis of what actually matters in your business, and a check by someone who knows where to look. This holds true for all three paths, including the first.
Where to start this week?
If you only remember one thing: open the path that matches your headcount, take the first line, and set a date for it. One measure carried out is worth more than three measures planned.
Then, take thirty minutes to answer the three questions that size alone cannot settle: what data should never leave this building, which outage would cost you the most, and on whom do you depend with no alternative. Compare your answers to the order in the table, and reorganise if necessary.
To assess your current level before choosing, the cyber check-up covers the same topics in a few minutes and points out your main gaps. If you are looking for the detail of the measures themselves rather than their order, they are described one by one in the 10 essential measures. The other articles in the Best practices pillar complete each step.