Identity and Security
Who has access to what, from where, and with what credentials. Our articles on identity, authentication, and the measures that really work in a business setting.
-
01Identity and Security
Cyber Insurance Questionnaire: Measures an SME Agrees to Follow
The application form for Helvetia’s Special SME Cyber Insurance, dated July 1, 2026, poses the question in a single line: “Do you comply with the requirements?”, followed by “(See our cybersecurity brochure, page 4 and…
Reading time: 13 min
Read the article -
02Identity and Security
Requirement to Report Cyberattacks: Who Is Affected in Switzerland—and Who Is Not?
As of April 1, 2025, operators of critical infrastructure are required to report cyberattacks to the Federal Office for Cybersecurity (FOCS) within 24 hours of their detection. The two sections that set forth the penalty, 74g and 74h of the…
Reading time: 14 min
Read the article -
03Identity and Security
Switching IT Service Providers: An Inventory of Access Rights and Contracts
An IT service provider has access to your environment: this is necessary for them to do their job. Some of these access rights are set up in their name, others in yours, and the distribution is established over the years, folder by folder, s…
Reading time: 11 min
Read the article -
04Exchange
Microsoft 365 and Entra ID : Deadlines to Meet Before April 2027
Between August 31, 2026, and April 1, 2027, five mechanisms found in most tenants Microsoft 365 will no longer function according to their current rules: EWS access by applications to Exchange Online, calendar sharing with a partner tenant…
Reading time: 11 min
Read the article -
05Copilot
Governance of Microsoft AI Agents: What Agent 365 Changes, and What Decisions Need to Be Made
As of May 1, 2026, Microsoft Agent 365 is generally available for the commercial market, billed per user. Microsoft Entra Agent ID is available as of the same date. Together, they elevate AI agents from tools to objects of interest…
Reading time: 8 min
Read the article -
06Copilot
GDPR, the AI Act, and Sovereignty: Choosing an AI Solution Without Asking the Wrong Questions
The choice of an AI solution is often presented as a matter of product compliance. The reality is more complex: regulatory obligations fall largely on the user company, and no supplier contract covers them…
Reading time: 6 min
Read the article -
07Copilot
Shadow AI: Managing the Use of AI That Your Employees Have Already Adopted
In most organizations, the question isn’t whether employees are using AI tools that management hasn’t selected, but to what extent and with what data. The term “shadow AI” refers to this parallel use: u…
Reading time: 5 min
Read the article -
08Copilot
AI and Privacy: What Really Protects Your Critical Data
The question that executives ask is almost always the same: Does what our employees write in the tool leave our company? The answer depends on a boundary that is rarely explained—the one that separates what your service agreement covers from…
Reading time: 5 min
Read the article -
09
Reading time: 1 min
Read the article

