Small businesses no longer run one office network with a server in the cupboard. They run a collection of cloud services: Microsoft 365 or Google Workspace, accounting software, a CRM, payroll, file storage, project management, e-commerce, electronic signatures and dozens of specialist applications. The old IT-support promise—“call us when a computer stops working”—does not cover that environment.
When a SaaS-based business fails, the cause is often not a broken laptop. A former employee still has access. The only administrator account belongs to an outside consultant. Customer data is exported into an unmanaged spreadsheet. A payment to a critical vendor fails. Nobody knows whether deleted cloud files can be restored. Each application works, yet the system formed by those applications is fragile.
The right question is therefore not whether an IT provider “understands the cloud.” It is whether the provider can help the company control identity, data, suppliers and recovery across the whole SaaS estate. This guide explains what that looks like for a Swiss SME and how to buy support without outsourcing management responsibility.
Your SaaS stack is an operating system
Founders usually acquire SaaS one tool at a time. Marketing adds an email platform. Sales chooses a CRM. Finance connects expense software. A contractor installs analytics. Each decision may be reasonable in isolation, but the connections create shared risk.
An identity provider may control access to fifteen applications. The CRM may feed the billing platform. The billing platform may update accounting. A single automation account may hold broad privileges in all three. If nobody maps those dependencies, an apparently minor change can interrupt revenue or expose data.
The SaaS dependency stack
Employees, contractors, laptops and phones
Single sign-on, MFA, administrator roles and recovery
Email, files, CRM, finance, payroll and commerce
APIs, exports, automations and audit logs
Backups, incident plan, contracts and ownership
The narrowing shape is intentional. Many companies have plenty of applications but weak governance underneath them. Good support strengthens the lower layers rather than merely adding another security product.
Management still owns the risk
Switzerland’s National Cyber Security Centre makes an important point in its information-security guidance for SMEs: management is responsible for classifying information, deciding which risks to accept and providing resources for controls. IT staff and suppliers advise and implement; they do not become the owner of business risk.
A support provider should therefore make decisions understandable. It should explain which data and processes are critical, what could interrupt them, which controls exist, which gaps remain and what each improvement costs. A monthly report listing closed tickets is not enough if management still cannot answer whether payroll can run after an account compromise.
Start with an application and owner register
Create one inventory covering every paid and important free service. Record the business owner, technical administrator, billing owner, contract term, renewal date, number of users, data category, integration dependencies, authentication method, export capability and termination process.
“Business owner” is not the same as IT administrator. The head of finance may own the accounting process while an IT provider administers access. The business owner decides how critical the service is and approves changes; the administrator implements them.
| Inventory field | Why it matters | Warning sign |
|---|---|---|
| Business owner | Someone can approve access and assess operational impact. | “IT owns it” even though IT cannot judge the data or process. |
| Administrator accounts | The company knows who can change security and export data. | Only a consultant’s personal account has full control. |
| Renewal and billing | A failed card or missed cancellation cannot surprise the business. | Subscription is tied to a former employee’s card. |
| Data and location | Privacy, retention and recovery decisions become possible. | Nobody knows whether customer or employee data leave Switzerland. |
| Dependencies | Changes can be tested against upstream and downstream systems. | An integration fails and invoices silently stop. |
The first inventory will be incomplete. That is useful: every unknown reveals a control gap. Review expense claims, browser extensions, single-sign-on logs and finance records to find applications that were never formally approved.
Identity is the new network perimeter
In a cloud-first company, a valid login can reach data from anywhere. Identity configuration deserves more attention than office Wi-Fi. Use multi-factor authentication, preferably phishing-resistant methods for administrators and other high-risk roles. Separate daily accounts from privileged administrator accounts. Avoid shared logins, because they destroy accountability and make offboarding unreliable.
Centralised single sign-on can reduce passwords and accelerate removal of access, but only if applications are actually connected and emergency recovery is designed. Protect the identity provider’s administrators rigorously. Keep tested break-glass accounts with credentials stored securely and monitored for use.
Access should reflect the job. A marketing contractor does not need payroll exports; a bookkeeper does not need source-code administration. Review privileged access regularly and after role changes. The biggest access failure is often not a hacker gaining entry but a legitimate account retaining permissions long after the business need ended.
Joining, moving and leaving must be one workflow
A new starter needs the right equipment and access on time. A role change needs old access removed as well as new access added. A departure needs sessions revoked, tokens disabled, company devices returned, data transferred and shared secrets rotated where necessary.
HR, the manager and IT support should use one checklist with clear timing. For an involuntary termination, coordinate access removal with the meeting. For a normal departure, preserve business records without retaining the person’s private information unnecessarily.
Do not delete an account immediately if it contains business mail or owns shared resources. Suspend access, preserve required records and transfer ownership according to a documented retention process. Automatic forwarding of all former-employee mail can create privacy problems; use a limited, transparent alternative.
Cloud availability is not your backup strategy
SaaS providers build resilient infrastructure, but service availability does not answer every recovery question. A user may delete data, ransomware may synchronise encrypted files, an administrator may misconfigure retention, or the provider may close an account after a billing or policy dispute.
For each critical application, define a recovery objective in business language. How much data can the company afford to lose? How long can the process remain unavailable? Who can initiate recovery? Has the company restored a sample successfully?
| Service | Recovery question | Practical test |
|---|---|---|
| Email and files | Can deleted or encrypted content be restored beyond native retention? | Restore a folder and mailbox item to a separate location. |
| CRM | Can accounts, notes, attachments and relationships be reconstructed? | Export and re-import a controlled record set. |
| Accounting | Can statutory records be accessed if the application is unavailable? | Produce a complete period export with documents and audit trail. |
| E-commerce | Can orders be fulfilled and customers contacted during an outage? | Run a tabletop outage during a busy sales day. |
A backup that has never been restored is an assumption. Include recovery tests in the support agreement and record the outcome, time taken and gaps.
Integrations create invisible privileged users
Automation tools and API connections often hold broad access without appearing on the employee list. A simple workflow may read every CRM contact and write to the accounting system. If its token leaks, the attacker inherits those privileges.
Inventory service accounts, API keys, OAuth grants and webhooks. Give each a named owner and minimum permissions. Store secrets in an appropriate vault rather than a shared document. Rotate them when a supplier or employee with access leaves. Monitor failed and unusual automation activity so a broken flow does not remain invisible for weeks.
Support must include supplier management
For SaaS, the IT provider often cannot repair the underlying product. Its value lies in diagnosis, escalation, configuration and continuity. The support agreement should state who contacts each vendor, which support tier the business buys, how incidents are escalated and what workaround exists.
Before adopting a critical service, review authentication, administrator controls, logging, data export, backup or retention, incident notification, subcontractors, data locations, deletion and termination assistance. The Swiss data-protection framework leaves the customer responsible when processing is outsourced. A reputable logo does not remove the need to understand the contract.
Define service levels around business impact
A promise to “respond within four hours” can mean an automatic email, not progress. Define severity using business consequences. A complete inability to take customer orders is different from one user’s printer issue. State coverage hours, response, update frequency, restoration target, escalation contact and exclusions.
| Severity | Business example | Expected behaviour |
|---|---|---|
| Critical | Revenue process unavailable, active compromise or widespread data exposure | Immediate human coordination, containment, frequent updates and executive escalation |
| High | Important team cannot work and no reasonable workaround exists | Rapid diagnosis, vendor escalation and agreed update interval |
| Normal | Single-user issue or non-critical function with workaround | Tracked resolution during support hours |
| Request | New account, permission or planned configuration | Approval and scheduled fulfilment under standard process |
Measure recurring incidents, time to contain, restoration success, stale privileged accounts, unsupported devices and completion of access reviews. Ticket volume alone can reward a provider for repeatedly fixing symptoms.
Know what happens during a cyberincident
The National Cyber Security Centre advises companies to act quickly and provides guidance for ransomware, data leaks, hacked websites, business-email compromise and other events. Your company still needs a short internal plan: who leads, who can disable accounts, who contacts the insurer and authorities, who preserves evidence, who informs customers and who approves communications.
Keep the plan available outside the normal SaaS environment. If identity or email is compromised, a document stored only in that environment may be inaccessible. Maintain verified emergency contacts for the IT provider, critical vendors, bank, insurer, legal adviser and management.
Run a tabletop exercise once a year. A realistic scenario—such as the finance account being taken over during payroll—reveals unclear authority and missing phone numbers without harming production.
Data protection must match the configuration
A privacy statement cannot compensate for unknown data flows. Map which applications process customer, employee and supplier data; for what purpose; in which country; for how long; and through which subprocessors. Configure retention and access to match the stated purpose.
When a support provider can access personal data, the agreement should address instructions, confidentiality, security, subprocessors, assistance with rights requests, breach notification, deletion and return. The company remains accountable for selecting and overseeing the processor.
A technically convenient setting may have legal consequences. Enabling call recording, employee analytics, AI transcription or broad support access should trigger a privacy and employment review before activation.
A better way to select an IT support provider
Give candidates a real scenario rather than a feature checklist. Ask how they would onboard the company, discover unapproved SaaS, secure administrator access, recover deleted CRM data, remove a departing founder and coordinate a payment-platform outage. Good answers will include people, evidence and decisions, not only products.
Ask who owns documentation and configurations when the relationship ends. The company should control its domains, tenants, administrator accounts, backups and vendor contracts. The provider should supply current documentation and assist transition under clear exit terms.
Check whether the provider understands the business model. A medical practice, manufacturer and online retailer have different critical systems and tolerance for downtime. Certifications can support trust, but they do not replace a service design fitted to the client.
The first 30 days
In week one, inventory applications, administrators, devices and critical processes. Fix any service controlled solely through a private or supplier account. In week two, enforce multi-factor authentication, define privileged roles and connect joiner–mover–leaver workflows.
In week three, document backups, exports, incident contacts and supplier escalation. Restore sample data from the most important systems. In week four, agree service priorities, reporting and a twelve-month improvement plan. Present residual risks to management in plain language and record which ones the company accepts.
The strongest SaaS support relationship does not make the provider indispensable. It makes the business understandable, recoverable and transferable. When identities, suppliers, data and decisions are documented, the SME can change staff, tools or providers without losing control of its own company.
Technical controls are strongest when they support clear business promises. Align them with ethical data and supplier practices, verify the public interface against the essential website feature set, and decide when professional web-design help is worth the cost.
Official sources
- National Cyber Security Centre: information-security checklist for SMEs
- National Cyber Security Centre: information and incident guidance for companies
- National Cyber Security Centre: cloud computing and cybersecurity
- Federal Data Protection and Information Commissioner: outsourcing personal-data processing
Official guidance checked on 27 July 2026. Security controls should reflect the company’s data, sector, contractual duties and tolerance for interruption.



