
Picture a manufacturing company with 80 people. The costing for the biggest quote of the year sits in an Excel file on the sales manager's laptop. Over the weekend he sent a copy to his private address so he could keep working on it at home. The payroll list is printed out in a binder, and the cabinet it sits in is not locked. And exactly one person knows how to restart the line in Hall 2 after a power outage. She retires in November.
Ask this company how things stand on security and you get an honest answer: the firewall is up to date, the updates run, and so does the backup. That is probably even true, but none of the three gaps above has anything to do with the IT infrastructure. This is where IT security and information security part ways, and for an SME that has very practical consequences.
What is information security?
Information security protects the information that matters to a company, wherever it lives: in systems, on paper, in conversations or in the knowledge of individual people. The goal is that only authorised people see it, that it stays correct, and that it is available when the business needs it.
In technical terms these three goals are confidentiality, integrity and availability. For personal data, the Swiss Data Protection Ordinance adds traceability, meaning who did what with the data and when (Art. 2 DPO).
In everyday terms this translates quickly. The quote costing should not end up with a competitor, the IBAN on the supplier invoice has to be the right one, and on the Monday after an incident accounting wants to be able to send invoices again.
What is the difference between information security and IT security?
IT security protects systems, networks and devices. Information security protects the information itself and therefore also covers paper, processes, people and suppliers. IT security is part of information security, but not all of it. A company can be technically well set up and still lose information.
In practice the difference shows up where no firewall helps. Accounting releases a payment because the call sounded like the boss. We described how that works with faked voices in our article on deepfake fraud in companies. The machine supplier has had remote access for years and nobody remembers it. One employee is the only person who knows how the year-end closing works.
To be honest, another tool helps with none of these problems. What helps is a clear rule or a second person who knows. That is why information security starts with the management team.
What is the difference between information security and data protection?
Data protection protects the people whose personal data you process. Information security protects all of the company's important information, including information with no personal reference, such as recipes, design drawings or quotes. The two overlap on data security: personal data has to be protected by technical and organisational measures.
Swiss data protection law requires exactly that. Under Art. 8 FADP, companies that process personal data and their processors must ensure data security appropriate to the risk. Anyone who intentionally fails to meet the minimum requirements for it can, on complaint, be fined up to CHF 250,000 under Art. 61 FADP, as a private individual, not as a company. What that means for management in practice is covered in our article on nDSG liability for managing directors.
For an SME the overlap is convenient: if you know and protect your most important information, you have covered most of the data security the FADP asks for. It does not work the other way round. A clean data protection concept does not protect your design drawings.
Who is responsible for information security in an SME?
Management is responsible, and in a Swiss stock corporation ultimately the board of directors. Implementation can be handed to IT, a service provider or an external CISO. Responsibility for which risks the company carries stays with the leadership.
The Swiss Code of Obligations lists the overall management of the company and the setting of its organisation among the duties the board cannot hand off (Art. 716a CO). Deciding which information carries the business and how much risk to accept along the way is a leadership question of that kind. That is not a law that regulates information security in detail for every SME. But anyone who has to explain after an incident why nobody ever asked the question is in a weak position.
In our experience it is rarely a lack of will. More often each side assumes the other one decides, and in the end nobody has decided. We broke down how to split the tasks cleanly, even without your own security team, in IT security without a security team.
Which information security requirements apply in Switzerland?
There is no general law that obliges every Swiss SME to run an information security management system. Requirements become binding through data protection law, through sector rules such as those of FINMA, through the Information Security Act for organisations that support the federal government, and increasingly through customer contracts.
The Information Security Act causes the most confusion. It binds a clearly defined group, and most mid-sized companies are not part of it. Who it applies to and where it reaches you anyway is covered in our article on the ISG ISMS obligation by 2026.
In practice the strongest driver is the market anyway. Larger customers send questionnaires before they sign and ask about responsibilities, access rules and incident handling. Whether a law binds you matters little to them.
If you want guidance without buying a standard right away, the federal ICT minimum standard is a good place to look. It was written for critical infrastructure operators, but any company can use it free of charge. The Federal Office for Cyber Security (BACS) has been responsible for it since March 2024.
Five questions to start with
Information security does not start with a project but with a few honest answers. The management team can work through these five questions in one meeting, and none of them needs technical background.
- Which information carries our business? Not all data matters equally. It is usually a handful: customer data, costings, design drawings, payment data, knowledge about critical processes. Which of it must never leak, be altered or go missing?
- Where does it live? On which systems, in which cloud services, on which laptops, in which binders and with which suppliers? Without this list you are protecting blind. Why the inventory is the foundation is explained in our article on the asset inventory.
- Who can get to it? Who has access, who really needs it, and who still has it although they left the company long ago? That applies to accounts just as much as to keys to the filing cabinet.
- What happens if it is gone? How long can the business operate without this information, and has anyone ever tried a restore? A backup nobody has ever restored from is an assumption.
- Who decides in an emergency? Who gets called, who may take systems offline, who informs customers? Settling these questions on the first day of an incident costs exactly the time you will be short of.
The answers do not have to be perfect. But they should be written down, with a date and names. With that you have already done the most important part: a gut feeling turns into a picture you can make decisions on.
Does an SME need an ISMS?
An information security management system, ISMS for short, makes sure these questions are answered regularly rather than once: with responsibilities, rules and a yearly review. An SME almost always needs this structure, and a certificate for it only when customers or regulations ask for one.
The ISO 27001 standard describes how such a system is built. For many companies it is a good framework, even without certification. We broke down where the costs really are in How much does ISO 27001 cost?, and what a setup that fits the business looks like in our article on the pragmatic ISMS.
The most common mistake is the order. Companies first buy a tool or start a certification project and only then work out what actually needs protecting. The other way round is cheaper and more effective: first the five questions, then the gaps, then the measures that fit the risk. We think this is the cheapest route, and it often leads to less effort than management feared.
The binder in the cabinet
Back to the company from the start. None of the three gaps needs a budget. The costing belongs on a company drive with controlled access, the cabinet gets a lock, and the employee who is retiring writes down the restart procedure together with a colleague. At the start, information security in an SME is rarely much more than that, which is exactly why it gets overlooked so often.
If you want to know how far your company is on these questions and whether an ISMS makes sense for you, we support you with building an ISMS and ISO 27001, sized to fit your business. The first step is a no-obligation conversation.
Which piece of information in your company sits somewhere today that IT knows nothing about?
Frequently asked questions
What does information security include?
Information security covers every measure that keeps important information confidential, correct and available. That includes technical protection, but also access rules, clear responsibilities, how paper and mobile devices are handled, requirements for suppliers, staff training and a plan for emergencies. IT is an important part of it, but not the only one.
Is information security mandatory for Swiss SMEs?
Switzerland has no general law that obliges every SME to run an information security management system. Data protection law does require data security appropriate to the risk for personal data. On top of that come sector rules such as FINMA's, the Information Security Act for companies that support the federal government, and requirements from customer contracts.
Where should an SME start with information security?
The starting point is an overview, not software. Clarify in the management team which information carries the business, where it lives, who can access it, how long the business can run without it and who decides in an emergency. Write the answers down. The gaps and the measures worth taking follow from there.




