You know you should "do something" about cybersecurity. You might have even had it on a to-do list somewhere for a while now.
But between antivirus software, backups, firewalls, and the ten different providers promising you peace of mind, you don't know where to start. And as long as you don't know where to start with cybersecurity as an SME, you don't start at all. It’s human nature, and it’s exactly the trap.
When the issue becomes urgent—a competitor gets hacked, a client asks for a security questionnaire, or a scam attempt is narrowly avoided—the first instinct is often to buy. A new tool, a subscription, a piece of hardware. It feels reassuring: you’ve "done something."
Except that spending before understanding is like buying an alarm without knowing which door is left wide open. You might be protecting something that wasn't at risk anyway, while the real vulnerability remains exposed.
Effective cybersecurity doesn't start with a product. It starts with a simple question: what do I have to lose, and what could cause me to lose it?
The right way in has a slightly technical name, but the principle is crystal clear: risk analysis. It involves answering three questions, in order.
What is truly important to my business? Your customer data, your accounting, your blueprints, your email, your website that takes orders. Not everything has the same value.
What could happen to them? Ransomware that encrypts your files, an employee who leaves with their access still active, a doctored invoice paid to a scammer, or a crash with no backup.
And if it did happen, how serious would it be? It’s the intersection of the two: a risk that is both likely and serious takes priority over one that is rare and minor. You end up with a list of priorities, and therefore, a plan.

This logic is the heart of the international standard ISO/IEC 27005 and the NIST Cybersecurity Framework, which summarizes everything in five verbs: identify, protect, detect, respond, recover. In Switzerland, theFederal Office for Cybersecurity (NCSC) also publishes recommendations along the same lines for SMEs.
This is where a resource worth knowing comes in: MEHARI. It is a risk analysis and management method made available for free by CLUSIF, the leading French association for information security. It is open, well-documented, and compatible with the ISO 27005 standard.
In practical terms, MEHARI provides a framework, a knowledge base, and structured questions that guide you through the process: which assets, which threats, which vulnerabilities, and what level of severity. You don't need to be an expert to get started.
Once a risk has been assessed, the process clearly outlines your options: reduceit,avoidit, transfer it (insurance, service provider), oraccept it with full knowledge of the facts. It is this decision-making logic, rather than buying a tool, that builds a genuine security strategy.
Let's be honest about its limitations. MEHARI remains a comprehensive method, originally designed for organizations of a certain size. But as a free, structured, and serious starting point, it does the job very well.
You spend more effectively. Instead of spending on tools that just provide peace of mind, you invest in what actually protects you. Often, the first measures identified cost almost nothing: deactivating accounts for departed employees, enabling two-factor authentication, verifying that backups can actually be restored, or test your email anti-spoofing protection (SPF, DKIM, and DMARC) for free.
Take back control. A priority list turns a stressful cloud of uncertainty into a clear action plan.
You are ready when called upon. More and more clients, insurers, and partners are demanding proof of cyber maturity. In Switzerland, the FADP has also strengthened obligations regarding personal data.
Let's take an engineering firm of 30 people with no internal IT staff. Following a MEHARI-style approach, two assets stand out: client project plans and email, through which invoices are processed. The scenarios: ransomware that encrypts the plan server, and email spoofing fraud.
Result: before buying anything, three priorities emerge. A tested, offline backup for the plans. Serious email protection, including two-factor authentication. A simple procedure for verifying changes to bank details.
Start small, but start. An initial analysis, even if imperfect, is infinitely better than a perfect plan that is never launched.
Use an existing method rather than improvising. MEHARI or an equivalent framework prevents you from overlooking entire aspects of the subject.
Make it a living document. A review once a year is sufficient for most SMEs.
Distinguish between analysis and support. That is precisely where a partner adds value.
Cybersecurity doesn't start with an expense; it starts with a question: what do I have to lose, and what could cause me to lose it? A free method like MEHARI is enough to turn that question into an action plan.