Most cybersecurity advice is written for a company that does not exist: one with an in-house IT person, a dedicated budget and some spare time. A company of four people has none of that, and a company of sixty does not face the same problems either.

Here are three distinct paths, based on your headcount. Each one sets out what to do, in what order, and over what timeframe. Follow the one that matches your situation, and ignore the other two until they become relevant to you.

What does size actually change?

It is not the number of employees that matters, it is what that number implies.

Below ten people, there is usually no one whose job is IT. The owner decides, carries it out and forgets, because they have other things to do. The measures that stick are the ones that keep working on their own once switched on.

Between ten and fifty, a threshold is crossed: you no longer know by heart who has access to what. Employees join, leave, change roles. An IT provider steps in, without its limits always being clear. The subject stops being technical and becomes organisational.

Beyond fifty, the problem is no longer putting the measures in place, but guaranteeing that they hold up over time. Without a designated person in charge or a written record, a correct configuration degrades within eighteen months without anyone noticing.

Path 1: 1 to 9 people

Your constraint is time, not budget. Everything below can be done yourself, mostly with tools you already have.

DeadlineActionEffort
First monthTwo-factor authentication on e-mail, online banking and business tools2 to 3 hours
First monthAn offline backup, disconnected between copies3 to 4 hours
First monthAutomatic updates enabled on all computers and phones1 hour
First quarterPassword manager for you and your employees3 hours, then 15 min per person
First quarterWritten inventory of accounts and tools in use2 hours
First yearA real backup restoration testHalf a day
First yearA clear rule on unusual payment requests1 hour

The first three lines are non-negotiable. They cover the scenarios that genuinely destroy a small business: the ransomware that encrypts everything, the stolen e-mail account, the known vulnerability left open for months. The details of the backup are explained in our article on the 3-2-1 rule.

The last line deserves a word. In a small business, an urgent transfer request from an address resembling the boss’s own goes through easily, because no one dares to check. A simple rule, known to everyone, is enough to break this mechanism: any change of bank details is confirmed by phone, on a number known in advance. This is the core of CEO fraud.

Path 2: 10 to 49 people

At this size, the measures from the first path remain the foundation. They are no longer enough, because the risk has shifted towards people and processes.

DeadlineActionEffort
First monthCheck the three foundations of path 1, without assuming they are in placeHalf a day
First monthAn up-to-date list of all active accounts, by person and by toolA day
First quarterArrival and departure procedure, with access closed the same dayHalf a day of drafting
First quarterRemoval of administrator rights from workstations1 to 2 days, with your provider
First quarterA one-page crisis sheet: who to call, in what order, with which numbers2 to 3 hours
First yearTeam awareness training, short and repeated rather than long and one-off1 hour per session, 2 to 3 times a year
First yearWritten review with your provider on what is covered and what is notHalf a day
First yearA complete, timed restoration testA day

Two points deserve further explanation.

Departures. This is the most common blind spot at this size. An employee who left eight months ago whose e-mail still works, whose access to the file server has stayed open, whose account still appears in the management tool. It is almost never malicious, it is simply that no one was responsible for closing it. A one-page procedure solves the problem for good.

The provider. Many owners think their outside IT person takes care of security. Often, their contract covers keeping things running, not protection. The point is not to question them, but to know precisely where the boundary lies, and who takes care of the rest. The risks tied to this dependency are detailed in our article on supply chain attacks.

Path 3: 50 people or more

You probably already have most of the technical measures in place. The work now consists of making them durable and demonstrable.

DeadlineActionEffort
First monthAppoint a named person responsible for information securityManagement decision
First quarterRegister of personal data processing activities2 to 4 days
First quarterIT charter handed out and signed by every employee1 to 2 days
First quarterData breach notification procedure, tested through a dry runA day
First yearFormalised access review, twice a yearA day per review
First yearDocumented risk analysis, reviewed annuallySeveral days
First yearIndependent audit of the measures in placeVaries

At this size, compliance becomes a subject in its own right. The Federal Act on Data Protection requires appropriate measures without listing them, and requires notifying the Federal Data Protection and Information Commissioner (FDPIC) of breaches that pose a high risk to the people concerned. Swiss law does not set a numerical deadline, it requires acting as soon as possible, which means knowing in advance who decides and who drafts the notification. The details are covered in our article on reporting a data breach.

The periodic review is the most underestimated measure in this path. A policy written in January and never revisited becomes a work of fiction within two years. What protects you is not the document, it is the date of the next check written into a calendar.

The limit of any plan based on size

It is worth being honest about what these three tables are actually worth.

A plan based on headcount gives a reasonable trajectory, and following the one that matches you will put you ahead of many comparable companies. But this plan knows nothing of your line of work, the nature of the data you handle, the flows between your tools, the providers you depend on without being able to replace them, or what would hurt you the most if it stopped working tomorrow morning.

Two companies of twenty people, two opposite priorities

An architecture firm whose entire value lies in ongoing drawings must first worry about backups and availability. A medical practice of the same size processes sensitive data: its priority is access control and encryption. Both companies have the same headcount, the same theoretical path, and yet it is not the same measure that needs to come first.

These plans also share the weakness of any checklist: a ticked box is not a measure that actually works. A backup that has been silently failing for six months still appears as done in the table. A former employee’s account forgotten in a secondary tool does not appear in any box. And what you do not know about never appears in a checklist you fill in yourself.

This foundation is therefore a solid starting point, not a finished protection. Turning it into real protection requires two things: an analysis of what actually matters in your business, and a check by someone who knows where to look. This holds true for all three paths, including the first.

Where to start this week?

If you only remember one thing: open the path that matches your headcount, take the first line, and set a date for it. One measure carried out is worth more than three measures planned.

Then, take thirty minutes to answer the three questions that size alone cannot settle: what data should never leave this building, which outage would cost you the most, and on whom do you depend with no alternative. Compare your answers to the order in the table, and reorganise if necessary.

To assess your current level before choosing, the cyber check-up covers the same topics in a few minutes and points out your main gaps. If you are looking for the detail of the measures themselves rather than their order, they are described one by one in the 10 essential measures. The other articles in the Best practices pillar complete each step.