The Swiss National Cyber Security Centre’s emergency-planning guidance for small and medium-sized organisations addresses a problem that technology alone cannot solve: during a cyber incident, people lose time deciding who may act. A concise plan turns the first hour from improvisation into a sequence of safe decisions. For Swiss SMEs facing phishing, ransomware or business-email compromise, this is a resilience control, not paperwork.
The plan should be written for the organisation that exists on a difficult day. It must work when the managing director is travelling, the IT provider is unavailable and normal email cannot be trusted. It should also reflect Swiss reporting obligations and the contractual duties that arise when an SME supplies a bank, hospital or larger manufacturer.
Keep the first version deliberately narrow. A ten-page manual that nobody has read is less useful than a two-page action sheet supported by appendices. Put the first decisions, contacts and authority limits on the front page, then keep technical recovery details and supplier information behind it. Review the document whenever staff, providers, banking arrangements or critical systems change.
Start with the first 60 minutes
The opening page should answer five questions: who declares an incident, who isolates systems, who contacts the external IT provider, who preserves evidence and who communicates with staff and customers? Names should be backed by alternates and current phone numbers. Keep an offline copy because the attacker may control the company’s mailboxes or file shares.
Early actions should be conservative. Do not wipe a compromised endpoint, negotiate with an attacker from a normal account or broadcast unverified claims. Isolate affected devices, protect backups and move crisis coordination to a trusted channel. A small organisation can make these steps executable with a laminated contact card and a pre-agreed call tree.
◆ Key Takeaway
The best SME emergency plan is short enough to use under pressure and specific enough to prevent harmful improvisation. Rehearsal matters more than document length.
Preserve evidence while restoring control
Recovery pressure often leads teams to destroy the evidence needed to understand the intrusion. Before rebuilding, record affected hosts, timestamps, suspicious messages, ransom notes, account activity and relevant logs. Ask the IT provider what will be retained and for how long. If personal data or regulated services are involved, notify the responsible privacy and compliance contacts early.
Backups should be treated as evidence and recovery infrastructure. Verify that at least one copy is offline or logically separated, that restoration credentials are independent of the production domain, and that the business knows which services can be restored first. A backup that has never been restored is an assumption, not a recovery plan.
Evidence preservation does not require a forensic laboratory. It requires discipline: note the time zone, avoid editing original files, export relevant logs before retention periods expire and write down every containment action. If an external investigator is later engaged, this chronology gives them a reliable starting point and helps management explain decisions to insurers, customers or authorities.
Make continuity decisions explicit
An SME does not need to restore everything at once. Define minimum viable operations for invoicing, payroll, customer support, production and safety. For each function, record a manual workaround, an owner and the maximum tolerable outage. These decisions help management resist unsafe pressure to reconnect systems before the root cause is understood.
Supplier dependencies deserve equal attention. A compromised mailbox can redirect payments even when internal systems are clean. Confirm changes to bank details by a second channel, require dual approval for urgent transfers and give key suppliers a number they can use to verify unusual requests.
Communication should be proportionate and useful. Staff need to know what systems to stop using and where to report suspicious activity. Customers need a verified status, an operational workaround and a next update time. A pre-approved holding statement reduces the temptation to disclose unverified technical details while the incident is still being contained.
Rehearse the plan, then improve it
- Print an offline incident card with primary and backup contacts, including the NCSC reporting route.
- Run a 45-minute tabletop exercise for ransomware and a separate exercise for payment-fraud email compromise.
- Test restoration of one critical service from an isolated backup and record the elapsed time.
- Pre-authorise endpoint isolation, domain lock-down and emergency procurement with management.
- Document evidence-preservation responsibilities for staff, the IT provider and any forensic partner.
- Review customer, insurer and supplier notification clauses before an incident creates conflicting deadlines.
A Swiss SME cannot eliminate every cyber incident, but it can eliminate avoidable confusion. The NCSC approach is valuable because it connects technical containment with contacts, continuity and communication. A plan reviewed after every exercise will become part of how the business operates, rather than a file discovered only after the damage begins.