Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
16.06.2026

Never again break a sweat over cybersecurity

Das Wichtigste in Kürze

  • Holiday season increases cyber risks.
  • MFA, Passkeys, and Conditional Access effectively protect against attacks.
  • Vigilance against phishing and secure behavior remain crucial.
  • During holidays, attention tends to wane. A refresher security training right before departure is beneficial, especially if your laptop and work phone are also packed. Those who diligently check their security now can relax on the beach with peace of mind. With little effort, basic security can be achieved, preventing many attacks or, in the worst case, ensuring a manageable outage.

    Security Tips for Admins

    Access must be securely managed: Multi-factor authentication (MFA) and Conditional Access are mandatory for all roles, without exception – this way, attackers won't find any loopholes. Furthermore, now is the right time to switch to passkeys. The Microsoft ecosystem supports this passwordless technology, which renders phishing attempts ineffective.

    Conditional Access is the method of choice when employees are frequently on the go. This allows precise control over where access to company services is permitted. Not from holiday countries, for instance. Risk-based access blocks requests if they do not comply with the defined policy.

    Generally, administrators should take this opportunity to review user accounts and restrict permissions. Less is more secure. You should conduct such access reviews every few months. So-called "break-glass" accounts are intended only for emergencies. They are highly protected and monitored. Privileged Identity Management ensures time-limited access according to roles and their security clearance – and pulls the imaginary plug on too many Global Admin accounts.

    Consult the specialists at Baggenstos to adapt your M365 security settings to your organization.

    "Security is also a matter of business processes and productivity," says Sven Heeb from Baggenstos. "It requires an optimal balance: We know the necessary settings from SME practice."

    Security Tips for Users

    It's becoming increasingly difficult to spot phishing emails. They are often deceptively created by AI and orchestrated in waves. Technically, employees are well-protected with a properly configured M365 environment. It's human nature to skim emails and react to trigger words like: "Act immediately," "Refund," or "Criminal complaint." The rule still applies: Read, Think, Click. If the email creates pressure, appeals to emotions, or contains threats, it is certainly a phishing email. Requests that you did not initiate yourself should be ignored or reported to your supervisor. And of course: Do not open unknown attachments or links in emails.

    Companies that manage their data protection with Microsoft Purview are well-protected against the accidental leakage of important data. This also includes sharing data only according to strict rules – preferably not as an open link and without inviting others to edit.

    In holiday mode – on foreign networks – it's even more crucial to keep risks to a minimum. Do not process sensitive data on public Wi-Fi; use your company's VPN software. If you absolutely must work: Disconnect your mobile data connection and only enable it under secure conditions. If the device is stolen or lost, the loss must be reported to the IT department first. They will remotely wipe the device and lock all accounts. When you return to work afterwards, you will have internalized the most important security rule for holidays: Switch off all digital devices and relax.

    SME Security Toolkit

    - Implement MFA and passkeys as standard for all accounts

    - Avoid global admin accounts: Set up and rigorously secure break-glass accounts

    - Actively use Conditional Access and minimize risks: Block Legacy Auth, block risky sign-ins

    - Phishing best practices for operations: "Read, Think, Click"; consistently report suspicious emails, never confirm MFA pushes that you did not initiate yourself

    - Properly classify and share data: OneDrive/SharePoint links only to authorized personnel, set an expiration date, allow editing only when necessary

    - Pre-holiday emergency routine: clear device loss process (contact, lock, remote wipe), annual test

    No items found.

    Share article

    Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
    Check your safety before the holidays?

    Gaining Security for SMEs

    Leverage Baggenstos's expertise and pack your bags worry-free!