In most SMEs, cybersecurity awareness follows the same path: employees are trained, guidelines are posted, and leadership attends the first quarter of an hour before leaving for a meeting.

That is exactly the wrong way round. Not because executives are more careless than anyone else, but because they hold the most interesting position for an attacker, and the only one that sets an example for the whole company.

Seen from an attacker’s side, you are the best target

An attacker does not pick victims in a company at random. They look for the account that pays off the most for the effort invested. On that measure, leadership wins every time, for four very concrete reasons.

Your access is the broadest. An executive generally has access to contracts, financial data, personnel files, client correspondence, and often management tools. Compromising this account means obtaining in one go what would otherwise have to be patiently assembled elsewhere.

You approve payments. In an SME, the boss’s signature or a verbal agreement is often enough to release a transfer. An attacker who controls your mailbox no longer needs to force anything: all they need to do is write.

Your identity is worth money, even without any hacking. CEO fraud consists precisely of impersonating an executive to obtain an urgent transfer. Swiss companies reported 605 cases of this type to the National Cyber Security Centre in the first half of 2025, and 366 in the second half. The attacker does not even need to get into your systems; all they need is your name, your position, and your way of writing.

Your calendar is public. Website, trade register, professional networks, local press articles, conferences: the information needed to target you is available to everyone. An attacker often knows when you are travelling, which makes an urgent request perfectly credible to your accountant.

Typical scenario: the trade fair

An SME announces on its website that its director is attending a trade fair abroad from the 12th to the 15th of the month. On the 13th, the accountant receives a message signed by the director: he is in a meeting, he cannot take calls, a deposit of 24,000 francs must go out today to secure a contract. The tone is right, the signature too. No system was hacked. The attacker simply read the company's website.

The paradox of exemptions

In many companies, security rules stop at the door of leadership. The pattern is almost always the same, and there is nothing malicious about it: it comes from a lack of time.

Two-factor authentication, that extra code requested at login, is imposed on everyone except the executive, because it is tedious when you log in twenty times a day. Administrator rights, which allow installing and changing anything on a machine, stay permanently enabled on their computer to avoid having to call someone. And work e-mails also arrive on the personal phone, the family one, which is protected by nothing in particular.

Each of these exceptions makes sense on its own. Added together, they produce an absurd result: the company’s most coveted account is also its least protected.

Risk concentrates where it costs the most

Exempting leadership does not reduce the company's overall risk, it shifts it. And it shifts towards the account that gives access to the most things, that triggers payments, and whose impersonation is the most credible. It is the only exemption that multiplies the consequences instead of diluting them.

The remedy is simple to state: leadership applies the same rules as everyone else, and sometimes stricter ones. Two-factor authentication on the mailbox and an administrator account separate from the day-to-day work account are the minimum.

A team follows what it sees, not what it reads

You can circulate the best IT policy in the world. If your employees see you bypass a rule, that rule is dead.

The team’s reasoning is perfectly rational. If the constraint really mattered, the boss would follow it too. Since he does not, it is an administrative formality, and it will be treated as such: bypassed quietly as soon as it gets in the way.

The reverse works just as well, and that is good news. An executive who explains in a meeting that they too have activated two-factor authentication, that they too nearly clicked on a fake delivery message, and that they reported it, achieves in five minutes what a written procedure never achieves.

This point is decisive for a culture of reporting. An employee who has made a mistake will only report it quickly if they are certain not to be humiliated. That certainty is not established in a document, it is demonstrated by leadership’s behaviour.

What do you need to understand, without becoming a technician?

There is no question of turning you into a specialist. No one expects an executive to know how to configure a firewall, any more than they are expected to keep the books line by line. What is expected is the ability to read a balance sheet. It is exactly the same level of expectation here.

Four skills are enough, and none of them is technical.

Judging a budget. Knowing what you are buying when presented with a security quote, what that spending actually covers, and what it leaves out.

Knowing what to ask your provider. This is probably the most worthwhile point. An executive who asks three good questions gets more than an executive who accepts everything.

Deciding in a crisis. Under pressure, with incomplete information and a phone that keeps ringing.

Knowing your legal responsibilities. So as not to discover them the day they materialise.

Here are the questions that separate a serious answer from a reassuring one.

The question to askWhat a good answer containsWhat should alert you
When did you last test a full restore?A date, a measured duration, a report”The backups run every day”
Who holds administrator rights in our company, and why?An up-to-date, named listA vague or postponed answer
What actually happens if a machine is encrypted tomorrow morning?A step-by-step process, with timelines”We have antivirus”
What access do former employees and providers still have?A documented removal procedure”Normally, everything is cut off”

You do not need to understand the technical content of the answer. You need to spot whether it is precise or vague. That is an executive’s skill, not an IT specialist’s.

What are your personal responsibilities?

Swiss data protection law contains a feature that often surprises executives: the fine, which can reach CHF 250,000, targets the responsible individual, not the company.

Its scope needs to be clarified immediately, because this point circulates in a highly exaggerated form. Only intentional violations are punishable: negligence, even regrettable negligence, does not fall within scope. Prosecution is generally triggered by a complaint; it does not start automatically. And Article 64 paragraph 2 allows the company to be convicted instead of the individual when the fine considered does not exceed CHF 50,000.

In other words, this is not a sword hanging over your head every day. It is, however, a responsibility that exists, that cannot be delegated to the IT department, and that deserves to be known rather than discovered. The concrete obligations that follow from it, in particular reporting a data breach, are detailed in our article on the FADP for SMEs. For a specific situation, legal advice remains essential.

Which decisions are yours alone?

During an incident, most of the work is technical and falls to specialists. But three decisions can be made by no one other than leadership, and they all arrive within the first few hours.

Whether to pay a ransom. This is a trade-off between the company’s survival, the absence of any guarantee of recovering anything, and funding a criminal activity. The subject is covered in detail in our article on whether to pay a ransom or not.

Whether to communicate, to whom, and when. Your clients, your partners, your employees, possibly the local press. Silence rarely protects, but improvised communication causes lasting damage.

Whether to halt production. Shutting down limits the spread and costs money immediately. Waiting preserves activity and can turn a contained incident into a full-scale disaster.

None of these decisions can be made properly cold, at three in the morning, without ever having thought about it beforehand. That is exactly what preparation provides: not the right answer in advance, but the fact of having already thought through the question. The reflexes for the first hours are described in what to do in the first hours.

What can you do this week?

Three actions, achievable with no budget and no provider.

Activate two-factor authentication on your own mailbox, before asking it of anyone else. Give up your permanent administrator rights in favour of a separate account, used only when necessary. And take twenty minutes to write, in one page, which scenario would genuinely put your company in difficulty.

The most effective signal is the most visible one

Announce in a meeting that you are now applying the same rules as everyone else, and say why. This sentence has more effect on behaviour than any procedure circulated by e-mail. A team imitates its leadership, it does not obey a document.

These actions form a foundation; they do not replace an analysis of your own situation. Knowing your actual risks requires looking at your financial flows, your providers and your data, something no generic list can do in your place. And verifying that what is in place actually works requires a check by someone who knows where to look.

This is precisely where support is most useful to an executive. It is not about turning you into an expert, but about giving you the questions to ask and the criteria to judge the answers. The cyber check-up lets you situate your company within a few minutes, and the other articles in the Training your teams pillar take this reflection further towards your employees.