Frequently Asked Questions
Quickly find answers to your cybersecurity questions.
Yes, if your website collects personal data, processes payments or is accessible from the internet. 73% of websites have at least one critical vulnerability (source: Bexxo, internal data). The nFADP (Swiss Data Protection Act) requires companies to document their security measures — an audit provides this proof. In the event of a data breach, the absence of diligence can result in fines of up to CHF 250,000.
No — the audit covers identification, classification and the action plan. Fixing the vulnerabilities is a separate service, which can be carried out by your internal teams based on the report, or by Bexxo on a quoted basis. This separation guarantees the objectivity of the audit: the auditor cannot have an interest in finding more vulnerabilities than actually exist. All our packages include assistance in understanding the report and taking the first corrective measures.
The duration depends on the package and the size of the infrastructure:
- Essentiel: 1 to 2 working days for a network of fewer than 50 devices.
- Avancé: 3 to 5 working days depending on topology complexity.
- Premium: 1 to 2 weeks for a multi-site infrastructure or complex architecture (VPN, hybrid cloud, OT/IT).
The report is delivered within this timeframe, with a presentation session included for the Premium package.
The duration varies depending on the package and the complexity of the site:
- Essentiel: 1 to 2 working days.
- Avancé: 3 to 5 working days.
- Premium: 1 to 2 weeks depending on the size of the site and scope (APIs, database, third-party applications).
The report is delivered within this timeframe, followed by a presentation session (Premium package) or an email exchange.
The nFADP (Swiss Federal Act on Data Protection, in force since September 2023) requires companies to implement proportionate technical and organisational measures to protect personal data. Although it does not explicitly require an annual network audit, documentation of security measures is mandatory. In the event of a data breach, the absence of demonstrated diligence can result in fines of up to CHF 250,000 for data controllers. An audit report constitutes this proof of diligence with the Federal Data Protection and Information Commissioner (FDPIC).
Yes, unconditionally. The initial analysis is offered by Bexxo as part of our cybersecurity awareness initiative for Swiss SMEs. No credit card is required, no contract is signed. At the end of the analysis, if you are interested in additional services (in-depth audit, package, training), you will receive a detailed quote — which you are free to accept or decline. 68% of Swiss SMEs have never had a cybersecurity review (NCSC): this analysis is designed to remove that barrier.