Security awareness training topics for Swiss SMEs
Security awareness training topics
Security awareness training topics for a Swiss SME should cover how attacks reach your inbox and phone, how payments and credentials get stolen, how to report something suspicious, and what your own rules say about passwords and working from home. The list is shorter than a certification course because people remember a few habits, not fifty slides.
This page is for owners, HR and finance leads in companies with about 20 to 250 staff who need to brief a provider or plan an internal session. Choosing a provider and pricing are covered in other articles. Whether simulations are lawful in Switzerland is covered in phishing simulations allowed in Switzerland.
Share of small firms with regular cyber training, against 82% of medium-sized firms (both under 250 staff), in Deloitte’s 2026 study of Swiss companies. Not our survey.
Core topics almost every Swiss SME needs
Phishing and social engineering by email. Show real patterns: fake Post or parcel messages, Microsoft sign-in prompts, invoice changes, and urgent payment requests. BACS singles out finance teams when it describes business email compromise. Mention AI-generated text when your staff already see flawless German or English with no typos.
Smishing and vishing. SMS parcel scams and fake IT support calls hit reception and back office as often as they hit specialists. Mention CEO-style voice fraud too: reported CEO fraud rose from 719 cases in 2024 to 971 in 2025, according to BACS weekly reporting.
Passwords and multi-factor authentication. Focus on your approved tools, not a product comparison. Explain why shared inbox passwords are risky and what MFA fatigue looks like in daily work.
Reporting inside the company. People need one address, one form, or one person, and a promise that reporting early is welcome. Without this part, the other topics rarely stick.
Your payment and data rules. Never accept IBAN changes by e-mail alone, use four-eyes for transfers, and say what may not go into WhatsApp or private mail.
- Phishing, smishing and vishing with Swiss examples
- Passwords and MFA as you actually use them
- Internal reporting path everyone knows
- Payment and invoice verification steps
- Remote work and visitor rules if they apply
- Brief line on what separates an IT incident from a personal-data breach (without a privacy law deep dive)
Topics to add by role
- Finance: invoice fraud, CEO fraud and callback verification on known numbers.
- HR: hiring scams and safe handling of applicant data.
- Reception: visitor badges, unknown USB sticks and phone impersonation.
- Production or logistics: supplier mail and fake delivery notices, if that matches your postbag.
You do not need three separate courses on day one. One live session can use role-specific examples and still keep a shared core. Before the date, note which two roles had the most near-misses in the last twelve months and give them five extra minutes.
What to leave out of a first session
Full malware analysis, penetration test results, and long legal lectures lose the room. ISO control numbers belong in an appendix for auditors, not on slide one. Do not turn the session into a blame review of last month’s clicks.
Simulations and e-learning platforms are tools, not topics. If you use them, make clear they are practice, not punishment. The legal limits are in phishing simulations allowed in Switzerland.
What this is not
This is not a privacy course. Processing personal data under the revised FADP belongs in privacy awareness. Nor is it technical hardening, because patch policies stay with IT, and it is no guarantee that no incident will happen.
The FADP requires appropriate technical and organisational measures (Art. 8 FADP). Training is a common organisational measure, but it does not replace documented processes. This is practical orientation, not legal advice.
A live session does not make the company certified. Mapping to ISO/IEC 27001:2022 control A 6.3 or NIST SP 800-50 can be documented on request after training; auditors still ask for attendance and content evidence.
Fits security awareness
- Phishing, fraud, reporting paths, password habits
- Behaviour in mail, on the phone and at payments
Fits privacy awareness
- Applications, customer data, retention, breach duties
- What staff may do with personal data day to day
A made-up example: tailoring a session list
A made-up example: a fiduciary with 22 staff, mostly client mail and payment runs. The owner lists topics with the external IT partner: phishing with fake tax and bank mail, CEO payment requests, internal reporting to the office lead, password manager for shared tools, and a five-minute rule on verifying IBAN changes by calling a known number. Reception adds visitor tailgating and fake courier calls. The live session runs 90 minutes in German, with ten minutes for questions on eTax-themed mail they saw last month.
Nothing on the list requires a simulation first. The firm schedules a follow-up conversation six weeks later to see whether reporting improved.
Limits and who can skip parts
Companies with almost no client money movement can shorten payment fraud but should keep reporting and phishing. Firms that never take phone orders might shorten vishing slightly but should still cover CEO voice fraud because finance answers the main line.
If everyone works in one room and shares one mailbox, keep the session short and repeat it when headcount grows past fifteen. Remote teams without customer data on laptops can emphasise device lock and separate accounts instead of visitor rules.
Frequency, duty and proof (short)
The law sets no fixed syllabus. Insurers and customers often ask for «awareness» or «staff training». Copy the wording from the form and cover the core topics. For the minimum content a particular insurer requires, check that insurer’s documents.
In practice that means reporting paths at onboarding, a refresher at least once a year, and a repeat soon after a real incident. A full annual plan is a separate topic.
For auditors, attendance, a one-page summary and the trainer name usually suffice. Keep ISO A 6.3 mapping separate from the attendance list.
Records and working with IT
Most SMEs train with an external speaker, while IT owns mail rules and MFA. Agree who sends reminders, who collects attendance and who answers reporting mail after the session. Without an owner, the annual slot becomes an HR calendar entry that IT never sees.
Fraud made up 52% of reports in the BACS H2 2025 report, someone else’s measurement. Payment and CEO-style requests belong in every annual slot. The cyberattack reporting duty applies to critical infrastructure, not to most SMEs, so do not scare staff with 24-hour rules unless you are clearly in scope.
Is e-learning enough for every topic?
E-learning suits repetition and proof of attendance. Payment fraud and reporting paths often benefit from live questions. Agree with your provider which topics stay in the room.
Do new hires need training immediately?
They should hear reporting paths and password rules at onboarding, even if the next company-wide session is months away. Onboarding checklists complement the annual slot.
Do we need phishing simulations in the first session?
No. Simulations are an optional tool after prior notice, not a substitute for content. Legal limits: phishing simulations allowed in Switzerland.
First step before you book
Write down your top three incident types from the last two years, even near-misses, and match the topics to those stories. Send the list to whoever will deliver the session so examples fit your tools, and reserve ten minutes for audience questions.
If the office already uses material from the national «SUPER, oder?» campaign on AI-generated phishing (BACS, spring 2026), use it as a hook, then connect it to your reporting path and payment rules so the lesson stays local.
For a live format with prep and follow-up, see Security Awareness Training. It runs one to two hours, remote or on site in Switzerland, in German or English.
Written by
Aurum Avis Labs
Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.
Related Articles
You might also be interested in these articles