Home · Blog

Security leadership for Swiss SMEs

Practical knowledge on security leadership in an SME: security management and operations, GRC, ISMS and ISO 27001. How a fractional CISO works, and what you can take on yourself. No jargon, no scare tactics.

Cover image: Security budget in an SME: how much, for what
Basics

Security budget in an SME: how much, for what

A security budget in an SME is rarely too small, usually invisible. Why the percentage question fails, which three pots matter and what the board needs.

Read more →
Cover image: Data classification in an SME: three levels are enough
ISMS

Data classification in an SME: three levels are enough

Data classification rarely fails on the scheme. Why three levels are enough, which data sets matter and who in the business has to stand behind them.

Read more →
Cover image: IT risk management in an SME: who carries the risk
GRC

IT risk management in an SME: who carries the risk

An IT risk register changes nothing until somebody signs. How to spot one that holds up, and who is actually allowed to accept a risk in an SME.

Read more →
Cover image: Customer security questionnaires: answering without guessing
Customer Audits

Customer security questionnaires: answering without guessing

A customer security questionnaire rarely fails on missing controls. Why it delays deals and what makes an honest no stronger than a polished yes.

Read more →
Cover image: Security roadmap for SMEs: what is realistic in twelve months
Security Operations

Security roadmap for SMEs: what is realistic in twelve months

A security roadmap rarely fails on the list, it fails on capacity. How an SME orders the work, how much fits into a quarter and what it costs to run.

Read more →
Cover image: When does an SME need a CISO? Four triggers from practice
Basics

When does an SME need a CISO? Four triggers from practice

Headcount does not decide whether an SME needs a CISO. Decisions without an owner do. Four triggers that show when the moment has already arrived.

Read more →
Cover image: Supplier risk in an SME: which suppliers can stop your business
GRC

Supplier risk in an SME: which suppliers can stop your business

You do not manage supplier risk with questionnaires for everyone. Which suppliers can stop your business, what you can demand and what the rest get.

Read more →
Cover image: ISO 27001 vs SOC 2: which proof for which customer
ISMS

ISO 27001 vs SOC 2: which proof for which customer

ISO 27001 or SOC 2? Which proof convinces which customers, why the answer sits in sales rather than security, and when it pays to hold both.

Read more →
Cover image: An incident response plan for your SME: decisions before the incident
Security Operations

An incident response plan for your SME: decisions before the incident

An incident response plan settles decisions before the incident forces them: what belongs in it, who must report and why one exercise beats twenty pages.

Read more →
Cover image: Security assessment: what taking stock delivers
Basics

Security assessment: what taking stock delivers

A security assessment shows where your SME stands on security: what taking stock delivers, when it pays off and how you recognise a good one.

Read more →
Cover image: NIS2 and Swiss SMEs: how the EU rule arrives through the contract
GRC

NIS2 and Swiss SMEs: how the EU rule arrives through the contract

NIS2 does not bind Swiss SMEs directly, it arrives through customer contracts. How the clause appears, what the 24-hour deadline means and how it fits the ISG.

Read more →
Cover image: External CISO: models, providers and how to choose
Basics

External CISO: models, providers and how to choose

External CISO is an umbrella term for five different models. Which one fits when, and the one question in a selection call that reveals more than any price list.

Read more →
Cover image: A living ISMS instead of paperwork: how you tell the difference
ISMS

A living ISMS instead of paperwork: how you tell the difference

A certified ISMS can still be dead. How to recognise a living ISMS, why paper ISMS happen and what makes the difference in a customer audit.

Read more →
Cover image: The ISG ISMS obligation by the end of 2026: what still counts
GRC

The ISG ISMS obligation by the end of 2026: what still counts

By 31.12.2026 the ISG requires a working ISMS. Who is affected, how the deadline reaches SMEs through their customers and what is realistic in four months.

Read more →
Cover image: Security KPI reporting: the numbers your management team and board need
Security Operations

Security KPI reporting: the numbers your management team and board need

Patch levels impress no board. Which security KPIs management and the board need, how often to report and why fewer numbers build more trust.

Read more →
Cover image: What does a CISO cost in Switzerland? The honest calculation
Basics

What does a CISO cost in Switzerland? The honest calculation

A full-time CISO in Switzerland costs CHF 150'000 to 250'000 per year. What a mandate costs, what the budget overlooks and which sum adds up in an SME.

Read more →
Cover image: IT compliance in Switzerland: deliver it, do not just get it advised
GRC

IT compliance in Switzerland: deliver it, do not just get it advised

IT compliance in Switzerland means nDSG, ISG and customer audits at once. Why another consulting report solves nothing and what actually holds up.

Read more →
ISMS

ISO 27001 in an SME: effort, duration and cost

ISO 27001 in an SME: what building an ISMS really costs in effort, time and money, when certification pays off and how to start without wasting budget.

Read more →
Security Operations

Consolidating security tools: more protection with fewer licences

Too many security tools cost money and overview instead of protection. How an SME consolidates tools, cuts duplicate licences and still gets safer.

Read more →
Basics

What is a fractional CISO? Role, duties and cost for SMEs

A fractional CISO leads security on a part-time mandate. What the role covers, when it pays off for an SME and what it costs in Switzerland.

Read more →
GRC

AI governance in an SME: who leads the artificial intelligence?

AI governance means deciding which AI an SME uses, who is accountable and how the risks are controlled. And what the EU AI Act has to do with it.

Read more →

Quick answers

What is a fractional CISO?
An experienced security leader who runs a company's security on a part-time mandate: the same responsibility as an employed CISO, a defined share of time, no fixed headcount cost. Read the article
What does a CISO cost in Switzerland?
A full-time CISO costs CHF 150,000 to 250,000 per year, plus social contributions and recruiting. A CISO retainer on a mandate starts at CHF 4,900 per month. See the numbers
By when does the ISG require an ISMS?
Affected organisations must be able to demonstrate a working ISMS by 31 December 2026. The ISG asks for lived practice, not a certificate. See the deadline