What Cyber Security Costs a Swiss SME
The check above gives a range. This text explains where it comes from, what it means and where the money takes effect first — so that the number does not hang in the air but becomes a decision.
In short: Swiss companies spend on average around 11 percent of their IT budget on security. Depending on industry, size, data sensitivity and regulation, the sensible share lies between 5 and 15 percent. For a services SME with 25 employees that is roughly 15,000 to 25,000 francs per year — spread across ten control areas, of which managed detection and identity protection are the largest.
Why there is no fixed number
The question “What does cyber security cost?” has the same answer as “What does a car cost?”: it depends what for. Five drivers determine the amount:
- Industry. A bank or a hospital processes data whose loss is existential, and is subject to supervision. A trade business is not. The share of the IT budget therefore ranges from 5 percent in the public sector to 15 percent for financial service providers.
- Size. More employees means more accounts, more devices, more attack surface — but also more economies of scale. A security budget grows with the organisation, only more slowly.
- Exposure. Whoever does business online, runs many interfaces or gives customers access to systems is more visible than a business whose IT does the bookkeeping behind a firewall.
- Regulation. ISO 27001, nDSG, FINMA circulars or the demands of NIS2 customers require evidence — and evidence costs time.
- Maturity. Whoever starts from zero needs more in the first two years: basics like MFA, backup and EDR are one-off investments with ongoing costs afterwards.
The check above asks exactly these five things. That is not a scientific method, but an honest one: the range is deliberately wide, because a single number would feign a precision that does not exist.
Guide values: the share of the IT budget
The most common yardstick is the share of security spending in the total IT budget. Publicly documented benchmarks — such as the annual surveys of large consultancies and analysts — have landed for years at around 10 to 12 percent as the average across all industries. The check uses 11 percent as the reference line and the following ranges per industry:
| Industry | Share of IT budget | Typical IT spend per head |
|---|---|---|
| Financial services | 10–15 % | CHF 25,000 |
| Healthcare | 8–12 % | CHF 12,000 |
| IT / software | 9–13 % | CHF 20,000 |
| Industry / manufacturing | 6–9 % | CHF 8,000 |
| Retail / e-commerce | 6–9 % | CHF 7,000 |
| Public sector | 5–8 % | CHF 9,000 |
| Services / SME | 6–10 % | CHF 10,000 |
The IT spend per head figures are orders of magnitude for estimating a missing IT budget. Whoever knows their budget enters it directly in the check — the result then becomes considerably more accurate. On top of the ranges come surcharges for high data sensitivity, formal compliance requirements and high exposure, plus a premium if the maturity level is still at the basics.
Three worked examples
- Fiduciary office, 25 employees, Microsoft 365, no formal requirements: IT budget roughly 250,000 francs, share 6 to 10 percent → 15,000 to 25,000 francs per year.
- Machine builder, 100 employees, own servers, customers demand ISO 27001: IT budget roughly 800,000 francs, share 6 to 9 percent plus compliance surcharge → around 55,000 to 85,000 francs.
- Software company, 50 employees, online business critical, health data: IT budget roughly 1 million, share 9 to 13 percent plus surcharges for data and exposure → 100,000 to 150,000 francs.
Striking: the amount per employee lies between 600 and 3,000 francs per year in all three cases. Whoever is well below that should know why.
Where the money takes effect first
A budget is only as good as its distribution. The check splits the amount across ten control areas, weighted by size — in small companies bought-in monitoring dominates, in large ones your own staff. For an SME with 10 to 50 employees the distribution looks roughly like this:
- Managed detection (MDR/SOC), around a fifth. Someone has to look at the alerts at night. An SME has no team of its own for that; an external service costs a fraction of one.
- Security staff and know-how, around 15 percent. Usually a part-time share of one person who keeps the overview, plus training.
- Identity & access, around 12 percent. MFA, Conditional Access, rights management. With Microsoft 365 most of this is included in Business Premium — how to use it is shown in Hardening Microsoft 365: 12 settings.
- Endpoint & EDR, around 12 percent. The protection on every device that still works when the email has got through.
- Network, around 8 percent. Firewall, segmentation, VPN.
- Backup & resilience, around 8 percent. Tested backups kept offline — the measure that takes the leverage out of extortion.
- Awareness & phishing training, around 8 percent. The cheapest measure with the broadest effect; the phishing simulation shows what it is about.
- SIEM & logging, around 5 percent. Switch logs on, retain them, make them searchable.
- GRC, audits & pentests, around 5 percent. Evidence, risk register, one test per year.
- IR retainer & reserve, around 5 percent. A contract with an incident response team before you need it, and a reserve for the emergency.
The order is not a ranking of importance but of cost. The most important measure is often the cheapest: MFA for everyone costs nothing with most licences and stops the largest part of account takeovers. What an assessment in Microsoft 365 typically finds is in M365 Assessment: Where Tenants Are Really Vulnerable.
Regulation drives the budget
The compliance surcharge in the check is not an end in itself. Three developments are raising the evidence effort for Swiss companies at the same time:
- NIS2 via the supply chain. EU customers pass their obligations on by contract — questionnaires, audit rights, security annexes. What that means in concrete terms is in NIS2 and Switzerland.
- ISG and the reporting duty. Since April 2025 operators of critical infrastructure must report cyberattacks to the BACS within 24 hours. Only those who detect can report — that is an argument for detection, not just for paper.
- nDSG. The revised Data Protection Act demands appropriate measures and makes data security breaches reportable.
Whoever wants to answer all of that with a certificate finds effort, costs and a roadmap in ISO 27001 for Swiss SMEs. The costs for that lie in the GRC share of the budget — and in the first year usually above it.
Evidence and maturity
The maturity score in the check is deliberately coarse: basic, solid, advanced, corrected for compliance requirements and risk. It is meant to answer one question: do we know where we stand? A company that knows its risks, documents its measures and has proof for them is not automatically more secure — but it can set priorities and answer questions. That needs no expensive tool: CISO Assistant is open source and covers assessments, risk register and evidence; whoever wants to see alternatives finds them in the comparison of open-source GRC tools.
What an attack costs
The other side of the calculation is the damage. It rarely consists of the ransom — mostly of standstill. A simple back-of-the-envelope calculation for your own company: daily revenue times the number of days on which no work is possible without IT, plus recovery costs, plus what customer trust is worth. For a business with 5 million in revenue and ten days of downtime that quickly comes to 200,000 francs before a single franc of ransom is paid. The Federal Office for Cybersecurity (BACS) documents in its semi-annual reports that ransomware and fraud via account takeover are the most frequently reported incidents at companies — not the spectacular cases from the headlines.
How such a compromise unfolds step by step and at which five points it can be stopped is shown in Anatomy of an attack. Each of these points corresponds to a control area from the list above.
Budget by maturity: the first three years
A security budget is not a constant. Whoever starts with the basics spends more in the first two years than later — and should plan for that instead of being startled anew every year.
- Year 1 — basics. MFA for everyone, legacy protocols gone, tested backups, EDR on all devices, a password manager, the first training sessions. The premium in the check (“basic”) reflects exactly this year: one-off projects come on top of the running costs.
- Year 2 — visibility. Collect logs centrally, buy in an MDR service, define alerts, a first penetration test. Now the part of the budget that recurs takes shape.
- Year 3 — evidence and routine. Risk register, plan of measures, internal audits, perhaps ISO 27001. The budget settles at the industry value; the maturity score should now be at “established” or above.
Whoever knows this trajectory can show management a curve instead of a number — and that is usually the more convincing argument.
Typical budgeting mistakes
- Counting only products. Licences are the visible part. The time to configure and monitor them properly is the larger one — and is missing from most budgets.
- One-off instead of ongoing. Buying a firewall and not touching it for three years is not security but a snapshot.
- Forgetting awareness. The cheapest item is cut most often — yet almost every attack begins with a message to a human being.
- No reserve. An incident never arrives on budget day. Five percent reserve prevents the wrong decisions being made for cost reasons in an emergency.
- Buying past the maturity level. A SIEM without someone who reads it is an expensive store. First basics, then visibility, then automation.
How the check calculates
Transparency is part of it: the check takes the range per industry as the basis, estimates the IT budget from industry and headcount if not given, adds surcharges in percentage points for data sensitivity, compliance requirements and exposure, subtracts half a point if the programme is already advanced, and adds a point if it is still at the basics. The maturity score starts at 35, 60 or 82 points depending on self-assessment and is corrected by a compliance bonus and a risk penalty. The distribution across the ten areas follows a table per size class. All values are guide values from publicly documented benchmarks — not advice, but a start for a conversation with management.
Frequently asked questions
Is 3 percent of the IT budget enough?
For a business without sensitive data, without online business and without requirements, perhaps. For everyone else that is well below any benchmark — and usually exactly the things that stop an attack are then missing: monitoring, tested backups, training.
Is Microsoft 365 Business Premium already “security”?
A large part of it, yes: MFA, Conditional Access, Defender for endpoints and email are included. But included is not switched on. The licence is the basis, the configuration and the monitoring are the budget.
Should an SME build its own SOC?
Below a few hundred employees practically never. An external MDR service delivers round-the-clock monitoring for a fraction of the cost of a single full-time position — which is why it is the largest item in the check for small companies.
How often should the budget be reviewed?
Annually with the IT budget, and additionally after every event that changes the drivers: new customers with requirements, new sites, an incident, a move to the cloud.