You Don't Treat Your Own Toothache – So Why Treat Your Own Cyber Risk?
Sick → doctor. Taxes → accountant. Cyber → "our IT guy handles that."
When something serious breaks in your company, you call a specialist. Sick → doctor. Taxes → accountant. Contract dispute → lawyer. Machine down → technician. You don't do this because you're incapable. You do it because you know what you handle yourself – and what you're better off handing to someone who does nothing else.
And then there's this one area where, somehow, that logic stops applying. Cybersecurity → "our IT guy handles that."
Would you let your IT guy do your taxes? Represent you in court? Then why is he your last line of defence against an attack that can take your business off the air in a week?
This isn't a vote of no-confidence in your IT. It's a category mix-up.
Outsourcing to specialists is exactly what good owners do. The problem isn't your judgement. The problem is that, somewhere along the line, cybersecurity quietly got filed under "IT topics" – instead of under "specialist discipline with its own specialists."
A good IT provider keeps things running: servers, printers, Microsoft 365, new laptops. That's a different job from: anticipating attacks, hardening the environment, containing an incident in the first 24 hours, and talking to the regulator, the insurer and the lawyer at the same time.
Both matter. They are not the same job.
What's actually on the table
Picture Monday morning. Nobody can get to their email. The order system doesn't answer. Every screen shows the same message: a bitcoin amount and a 72-hour deadline. Your backups are encrypted too.
This isn't a worst-case scenario from a sales deck. This is the most common shape of a ransomware incident at a Swiss SME, as the Federal Office for Cybersecurity (BACS) documents on a regular basis. What follows:
- A week of downtime – realistically three.
- Notification to the EDÖB within 72 hours if personal data is involved (Art. 24 FADP).
- Notification to BACS within 24 hours if you are critical infrastructure (Art. 74a ISA, in force since 1 January 2025).
- Customers whose data turns up on the dark web.
- Personal liability for the managing director under Art. 754 CO for breach of duty of care.
The question isn't whether this can happen. The question is who's sitting next to you on Tuesday at 06:30.
Family doctor and surgeon – both doctors, not the same job
The simplest analogy is also the most honest one.
- Your IT provider is the family doctor. Keeps the business healthy day to day. Knows your systems. Solves the everyday problems. Indispensable.
- A security specialist is the surgeon. Anticipates what can go wrong. Hardens things before someone pushes on them. When it's serious, they're at the table from hour one – with forensics, a communications plan and the right phone numbers for the regulator already in their pocket.
Asking your family doctor to operate on you isn't disrespectful. It's just the wrong question.
What you get – in plain terms
We're deliberately not going to say SIEM, EDR, zero-trust or SOC here. Those belong in the toolbox, not in a management conversation. What you, as an owner or managing director, actually get fits in four lines:
- You keep working. Even when others can't.
- Your data stays yours. Not on the dark web, not at a competitor, not in the press.
- You sleep at night. Because somebody is on the hook to fix it at 02:00 without calling you first.
- You're covered when the regulator asks. EDÖB, BACS, your insurer, FINMA – the documentation exists before anyone demands it.
You don't have to replace your IT. You just have to let someone look.
A common reflex: "So we'd have to tear everything out." No. The first step isn't a big project, a new contract, or switching providers.
The first step is an assessment: one or two half-days where we sit down with your IT, look at what's actually in place, where the few genuinely important gaps are, and the five things you should do in the next 90 days. That's it. You decide afterwards whether anything comes of it.
Your IT stays your IT. We don't step on their toes – we give them a second pair of eyes for the area they don't work in every day anyway.
"We thought our IT had it covered"
It's the line we hear most often – usually after the incident, sometimes before. A few excerpts from conversations with clients in the 30–250 employee range:
- "We had a firewall and a backup. We figured that was enough. After the ransomware hit, both were useless – the backup was on the same network." – Managing director, manufacturing, Aargau.
- "Our IT partner was great at what they did. But when the incident came, they'd never seen one either. We lost six days before someone with experience was at the table." – Owner, trust office, Zurich.
- "In hindsight, the assessment was the cheapest audit we've ever done. It surfaced three things that would have cost us the business inside six months." – CEO, hospital, central Switzerland.
A concrete first step
SIDD is a Swiss institute for cybersecurity and data protection. We work with SMEs, hospitals, municipalities and financial services firms – and with their existing IT providers, not against them.
If you just want to know where you stand today without it turning into a project: 15 minutes on the phone, free, no obligation. We walk through three or four questions with you and tell you honestly whether an assessment makes sense for you – or doesn't.
Request a risk check · Get in touch
More on how we work: CISO/ISO as a service, ISMS to ISO 27001, Penetration testing, IT security workshop for SMEs.
