Most SME managers picture a cyberattack as an event aimed at them. Someone chooses their company, looks for a flaw, gets in.

In reality, many companies are affected without ever having been targeted. They simply happened to be on the client list of a provider that got hacked. This is the principle behind supply chain attacks, and it is the most common blind spot in Swiss SME security.

Targeting a supplier to reach its clients

Attacking a single SME pays little. Attacking the IT provider that administers fifty SMEs pays fifty times more, for the same effort.

Attackers made this calculation long ago. Rather than forcing fifty doors, they force a single one: that of the supplier who already holds the keys to all the others. Your IT provider generally has remote access to your servers, administrator rights, and sometimes your passwords. Your business software vendor pushes updates that your machines install without question. Your accounting firm holds your bookkeeping and your payroll data.

Each of these links is legitimate and necessary. Each is also an entry path that bypasses all your defences, because it comes from inside the circle of trust.

Your defences see nothing unusual

When an attacker uses your provider's access, they force no door: they connect as the provider would, with the provider's credentials, from the provider's usual tools, often outside office hours. No firewall flags an authorised connection. This is what makes these attacks so difficult to detect, and so effective.

The most frequent effect is ransomware deployed simultaneously across all of a single provider’s clients. Overnight, several unrelated companies discover the same morning that their servers are encrypted. This is also why off-site backup matters so much here: it must remain out of reach, including from your provider’s own access, as explained in the 3-2-1 backup rule.

Now turn the perspective around. Your SME is itself someone’s supplier. You deliver parts to a manufacturer, you develop a module for a group, you handle payroll for companies larger than yours.

For an attacker targeting that large client, you are a far more accessible target than the client itself. The group has a security team, detection systems, procedures. You do not. But you have access to its supplier portal, an account on its extranet, a recognised billing channel, or simply an email relationship that no one questions.

This reasoning, not an excess of bureaucracy, explains the shift observed in recent years: large clients no longer just expect their suppliers to be secure, they require it by contract. Security questionnaires, incident notification clauses, audit rights, strong authentication requirements. Many French-speaking Swiss SMEs discover these documents when renewing an important contract.

Security is becoming an award criterion

A poorly completed security questionnaire, or an inability to answer, can today cost you a tender. Conversely, an SME able to document its measures in a few pages immediately stands out from its competitors. Security is no longer just a cost: it has become a sales argument.

Knowing what to answer on the day this document arrives changes a great deal, and we devote an entire article to it: how to respond to a client security questionnaire.

What questions should you ask your IT provider?

You do not need technical skills to conduct this conversation. You need the right questions, and to know what a good answer looks like.

Question to askWhat you want to knowGood answer
What access do you have exactly on our systems?The real extent of the rights held by a third partyA precise list, limited to what is necessary
Is this access protected by two-factor authentication?Whether a stolen password is enough to get inYes, without exception, including for remote access
Does each technician have their own account?Whether a shared, untraceable account existsNamed accounts, and a record of who does what
What happens if you yourselves are the victim of an attack?Whether a plan exists, and your place in itA written plan, with a client notification deadline
Within what timeframe do you notify us of an incident affecting you?Your ability to react in timeA specific deadline, ideally 24 to 48 hours
Where are our data and our backups hosted?The country, and the separation of copiesA clear answer, backups outside your network
Do you subcontract any part of our services?The chain beyond the first linkThe list of subcontractors, and their countries
How would we recover our data if we changed provider?Your real dependencyAn exportable, usable format, without obstruction

A methodological note: the goal is not to trap your provider. A competent partner will generally welcome these questions, because they let it justify investments it may have been proposing to you for years. The warning sign is not an imperfect answer, it is a refusal to answer.

What contractual clauses are useful?

A contract stops no attack. It determines what happens next, and that is already a great deal. Four points deserve to be included, whatever the size of the provider.

Incident notification. The provider commits to informing you without delay if it suffers an incident that could affect you, with a specific deadline. Without this clause, you may learn of it far too late, or even from your own clients.

Governing subcontracting. Your provider must inform you if it entrusts part of the service to a third party, and that third party must be held to the same obligations. A chain is only as strong as its weakest link, and you often know only the first one.

Minimum security measures. Two-factor authentication on access to your systems, named accounts, encrypted backups, connection logging. These requirements can be formulated in a few lines.

Data return and deletion. At the end of the contract, your data is returned to you in a usable format, then deleted by the provider. This point is systematically forgotten, and it comes at a high price when the time comes to change partners.

These clauses are best reviewed by a lawyer, especially if the contract concerns sensitive data or a significant volume of business.

Data protection and the NIS2 ripple effect

Two regulatory frameworks touch directly on this subject, and it is worth not confusing them.

Under Swiss law, the Federal Act on Data Protection leaves you responsible. If you entrust personal data to a provider, you remain the data controller: the fact that the leak originates with the provider does not stop it from being your problem. The law in fact penalises entrusting processing to a subcontractor without having ensured that it guarantees data security (art. 61 FADP). In practice, this means checking before entrusting, and documenting it. The detail of these obligations is covered in our article on your FADP obligations.

On the European side, the NIS2 directive (EU directive 2022/2555) does not apply directly in Switzerland. A company established here is generally not subject to it as such. But it reaches you indirectly, and that is precisely its intention: the European companies concerned must secure their supply chain, including their foreign suppliers. They therefore pass these requirements on by contract. A French-speaking Swiss SME supplying clients in Germany or France thus experiences NIS2 without being subject to it. The subject is explored further in our dedicated article on NIS2, and manufacturers of connected products will find a related framework in the Cyber Resilience Act.

In both cases, the same caution applies: the exact qualification of your situation depends on your activity, your clients and the data processed. If in doubt about a contractual commitment, seek professional support.

Where to start, in practice

The subject seems vast. It actually comes down to an inventory and a few decisions.

Start by listing your digital suppliers, on a single page: IT provider, software vendors, hosting provider, accounting firm, payroll provider, point-of-sale solution, messaging platform. For each one, note two things: what data it holds, and what access it has to your systems. This one page is enough to reveal the two or three dependencies that are truly critical.

Then deal with those two or three as a priority, using the questions in the table above. The rest can wait.

The three-question test

For each important supplier, ask yourself: what happens to my company if it is unavailable for three days, if it loses my data, or if an attacker takes control of its access? If you cannot answer, you have just identified your priority. Three questions, ten minutes per supplier.

Two figures to close. The general climate is not improving: the National Cyber Security Centre received 64,733 voluntary cyber-incident reports in 2025, against 62,954 the year before. And business confidence is declining: according to the SME Cybersecurity 2025 study, 42% of Swiss SMEs consider their protection sufficient, against 55% a year earlier. This decline is not necessarily bad news. It mostly reflects new-found clear-sightedness.

Controlling access granted to third parties connects directly to the broader subject of access management, and the consequences of a compromise via a supplier are those described in our articles on ransomware and on data theft.

To assess your overall exposure in a few minutes, the cyber check-up includes several questions devoted to providers and external access. The other risks facing an SME are grouped in the Threats pillar.