Frequently Asked Questions
Quickly find answers to your cybersecurity questions.
For an SME with 20 to 50 employees, the typical programme runs over 3 to 6 months:
- Week 1: set up PhishTrainer, send the first baseline phishing campaign.
- Months 1-2: Bexxo Academy access for all employees, introductory modules (30 to 45 min per module).
- Months 3-6: monthly phishing campaigns, targeted reminders for at-risk employees, progress report.
The setup is handled by Bexxo — no internal technical skills required. Monthly administration time is less than 2 hours for the HR or IT manager.
Our CVE Find service allows you to filter and sort vulnerabilities according to several key criteria: CVSS score, EPSS score, membership in the KEV list, severity level, publication date, etc. These combined indicators allow you to quickly identify the most serious and most likely to be exploited vulnerabilities.
Once the filters are applied, the user can subscribe to alerts or export the data for integration into internal tools. This makes it possible to maintain active monitoring, focused on genuinely dangerous vulnerabilities, while avoiding the noise of irrelevant information.
When you are facing a conflict (for example, with a supplier) or ransomware demanding a ransom payment. The negotiation service allows you to explore legal and operational options.
Yes, our CVE Find service is accessible free of charge online. All users can consult CVE records, apply filters, and access enriched information (scores, exploitation status, KEV/EPSS data). The objective of the site is to democratize access to vulnerability information, without financial barriers.
Advanced functionalities (e.g., API integration, automatic export, personalized alerts) are offered as options or premium services, but the basic functionality remains open to all.
The nFADP (Swiss Federal Act on Data Protection, in force since September 2023) requires companies to implement proportionate technical and organisational measures to protect personal data. Although it does not explicitly require an annual network audit, documentation of security measures is mandatory. In the event of a data breach, the absence of demonstrated diligence can result in fines of up to CHF 250,000 for data controllers. An audit report constitutes this proof of diligence with the Federal Data Protection and Information Commissioner (FDPIC).