# NeoGuard > Compare VPN, antivirus, and password manager solutions for Swiss businesses and individuals. Buyer's guides and nFADP compliance resources. Last updated: 2026-06-15 NeoGuard is operated by Greulich Digital Labs, Romanshorn, Switzerland. ## Main Pages - [Home](https://neoguard.ch/): Overview of NeoGuard services and value proposition - [Products](https://neoguard.ch/products/): Vetted VPN, antivirus, and password manager solutions - [Comparisons](https://neoguard.ch/compare/): Side-by-side product analysis for Swiss businesses - [Glossary](https://neoguard.ch/glossary/): Privacy and security terms explained (nFADP, DSGVO, etc.) - [Blog](https://neoguard.ch/blog/): Practical guides on privacy, security, and Swiss compliance - [Proton Meet and Proton Workspace](https://neoguard.ch/blog/proton-meet-workspace-swiss-business/): What Proton's encrypted video calls and workspace suite mean for businesses in Switzerland - [Proton Pass for Business](https://neoguard.ch/products/protonpass/): Swiss password manager with built-in Hide My Email aliases, dark web monitoring, and Sentinel high-security mode for SMEs - [Bitwarden](https://neoguard.ch/products/bitwarden/): Open-source, US-based password manager for businesses and individuals in Switzerland. Zero-knowledge AES-256, a strong free tier, self-hosting, plus what the US CLOUD Act means for an nDSG/GDPR assessment. FAQ on master-password recovery, bitwarden.com vs bitwarden.eu, and Vaultwarden. - [DPAs of cloud and email providers used in Switzerland](https://neoguard.ch/blog/dpa-switzerland/): Plain-English read-through of the published Data Processing Agreements of Microsoft 365, Google Workspace, Dropbox, Infomaniak, Tresorit, and Proton. Covers access, breach notification, sub-processor change notice, and deletion timelines. - [Password Managers for SMEs in Switzerland Compared](https://neoguard.ch/blog/password-manager-sme-comparison/): Side-by-side comparison of NordPass, 1Password, Bitwarden, and Proton Pass for SMEs in Switzerland. Covers admin features (SAML SSO, SCIM), server location, encryption architecture, DPA availability under nFADP Art. 9, and a decision guide by team profile. - [Best VPNs for Switzerland Compared](https://neoguard.ch/blog/best-vpn-switzerland/): Side-by-side comparison of Proton VPN, NordVPN, Surfshark, and Mullvad for individuals, freelancers, and SMEs in Switzerland (DE version at /de/blog/bester-vpn-schweiz/). Ranks providers by headquarters and jurisdiction (Switzerland, Panama, Netherlands/9 Eyes, Sweden/14 Eyes), independently audited no-logs policies (Securitum, Deloitte, SecuRing, Cure53/X41), RAM-only servers, Swiss server presence, anonymous signup and payment (Mullvad's no-email account plus cash or Monero), and the free-tier picture. Flags that NordVPN and Surfshark share an owner (Nord Security). Decision guide by user profile. - [Credential Stuffing: One Reused Password, Many Compromised Accounts](https://neoguard.ch/blog/credential-stuffing-password-reuse/): Deep-dive on credential stuffing and password spray. Covers the mental-model gap behind password reuse, the distinction between credential stuffing and password spray attacks (with the Microsoft Midnight Blizzard 2024 case), why pattern passwords like `Summer2026!` don't help, how generative AI lowers the cost of personalized credential cracking, and the four-measure defense (password manager, passkeys where available, 2FA, breach monitoring). Cites Cybernews May 2025 (94% reuse), Verizon DBIR 2025 (19% of daily SSO authentication attempts are credential stuffing), and BACS S-U-P-E-R campaign April 2026. - [Supply Chain Attack on Bitwarden: What It Means for the Password Manager](https://neoguard.ch/blog/bitwarden-cli-supply-chain-incident/): News-pegged explainer of the 22 April 2026 Bitwarden CLI supply chain incident. Covers the 90-minute compromise window of `@bitwarden/cli@2026.4.0` on npm via a tampered Checkmarx GitHub Action, Bitwarden's confirmation that vault data and production systems were not affected (only ~334 developer machines pulled the tainted package), the secrets the embedded `bw1.js` payload harvested (npm tokens, GitHub PATs, SSH keys, AWS/Azure/GCP credentials), the remediation runbook (upgrade to 2026.4.1, clear npm cache, rotate every reachable secret, audit GitHub activity), placement in the Shai-Hulud npm supply chain wave tracked by Palo Alto Unit 42, and what the incident means for SMEs in Switzerland under the nFADP reporting obligation. Sources: Bitwarden community statement, Endor Labs technical write-up, BleepingComputer, Palo Alto Unit 42, The Hacker News. - [Verizon DBIR 2026: Three Numbers Every SME Should Know](https://neoguard.ch/blog/verizon-dbir-2026-sme/): Analysis of the Verizon Data Breach Investigations Report 2026 for SMEs in Switzerland and the wider DACH region (DE version at /de/blog/verizon-dbir-2026-kmu/). Three numbers stand out from the 22,000+ incidents and 12,000+ confirmed breaches analysed: 48% of breaches globally and 54% in EMEA involve third parties (up from 15% in 2024 and 30% in 2025); 96% of ransomware victims in the DBIR dataset are SMEs, with compromised credentials (38%) and unpatched edge devices (29%) the two recurring entry vectors; 45% of employees now regularly use generative AI on corporate devices (tripled from 15% in the 2025 report), 67% via personal non-corporate accounts, with source code the data type most often uploaded. Corroborated with IBM Cost of a Data Breach Report 2025: 20% of studied breaches traced back to a Shadow AI incident, organisations with heavy Shadow AI use saw USD 670,000 higher breach costs, and 63% of breached organisations either had no AI governance policy or were still developing one. Closes with the three effective measures: 2FA on accounts, an up-to-date supplier list, and clear rules for AI use in the business. - [Proton Pass: Can the new AI Access Tokens make AI agents safer?](https://neoguard.ch/blog/proton-pass-ai-agents-sme/): Analysis of Proton's 22 May 2026 AI Access Tokens launch for SMEs running AI agents (DE version at /de/blog/proton-pass-ki-agenten-kmu/). Covers the three published properties (scoped vault binding, configurable lifespan from one hour to one year, audit log with reasons), two concrete SME scenarios (AI agent for accounting, sales/customer-success agent), and four practical limits (bearer credential semantics, no substitute for 2FA, no protection against prompt injection or goal hijacking, no help on a compromised device). Comparison with peer approaches: 1Password and Keeper use "access without exposure" (secrets injected at runtime without entering the LLM context); Bitwarden's Agent Access SDK is explicitly positioned against giving agents "the keys to everything"; Proton picks a pragmatic middle ground but is missing native SIEM integration (Splunk/Sentinel/Datadog/syslog) that 1Password, Bitwarden and Keeper already offer. Cites OWASP "Excessive Agency" as the underlying threat pattern. - [Click, Fix, Malware? How Fake CAPTCHAs Fuel ClickFix Attacks](https://neoguard.ch/blog/clickfix-fake-captcha/): Explainer on the ClickFix social-engineering technique (DE version at /de/blog/clickfix-gefaelschte-captcha/). A fake "I'm not a robot" CAPTCHA or browser-error page poisons the clipboard and instructs the visitor to run the command themselves via Win+R then Ctrl+V, executing an infostealer with no exploit and no downloaded file. Covers the attack chain (clipboard hijacking, mshta/PowerShell living-off-the-land binaries), the prevalence range across sources (Verizon DBIR 2026 ~2.7% of browser-blocked attacks vs Microsoft Digital Defense Report 2025 ~47% of observed initial access, ahead of phishing at 35%), the Swiss/DACH angle (BACS weekly reviews Feb 2026 and Nov 2024, BSI March 2025, a Microsoft-documented campaign that hit organizations in Switzerland), and defenses (never paste website commands into PowerShell/Terminal/Run, restrict the Run dialog and PowerShell/mshta via app allowlisting). Cites Microsoft, ESET, Verizon DBIR, BuiltWith, Checkmarx, Malwarebytes, NCSC.ch. - [CLOUD Act Exposure Scanner](https://neoguard.ch/cloud-act-exposure-scanner/): Free interactive checker (DE version at /de/cloud-act-exposure-scanner/). Enter the SaaS tools your team uses and see which ones have a US parent company and therefore fall under the US CLOUD Act (18 U.S.C. § 2713), where each vendor stores data, and whether a Swiss or EU alternative exists. Asserts parent-entity facts only and distinguishes encrypted content from metadata; it does not claim blanket immunity for non-US tools running on US hyperscalers. - [FAQ](https://neoguard.ch/faq/): Common questions about NeoGuard and privacy tools - [About Us](https://neoguard.ch/about/): About Malte Greulich (PhD in information security) and how NeoGuard is run as a personal project. Affiliate disclosure and AI-assistance disclosure included. - [Deals](https://neoguard.ch/deals/): Curated catalog of active affiliate offers on the security software covered on NeoGuard (NordVPN, Proton, 1Password, Tresorit, CrowdStrike, Surfshark, NordPass, Passpack). CHF prices verified manually against vendor pages. Filterable by category and brand, with NeoGuard's editorial picks across VPN, password manager, encrypted mail, encrypted storage, and endpoint protection. ## German Version - [Startseite](https://neoguard.ch/de/): Deutsche Version der Website - [Produkte](https://neoguard.ch/de/produkte/) - [Vergleich](https://neoguard.ch/de/vergleich/) - [Glossar](https://neoguard.ch/de/glossar/) - [Blog](https://neoguard.ch/de/blog/) - [FAQ](https://neoguard.ch/de/faq/) - [Über uns](https://neoguard.ch/de/ueber-uns/) - [CLOUD-Act-Check](https://neoguard.ch/de/cloud-act-exposure-scanner/): Prüft in zwei Minuten, welche deiner SaaS-Tools zu einem US-Konzern gehören und damit unter den US CLOUD Act fallen, wo deine Daten liegen und welche Schweizer oder EU-Alternative es gibt. Kostenlos und ohne Konto. - [Deals](https://neoguard.ch/de/deals/) ## Topics Covered - Swiss data protection law (nFADP) compliance for businesses - VPN solutions for Swiss and DACH remote teams - Antivirus and endpoint protection for SMBs - Password management for teams (5-50 seats) - Privacy tool bundles with CHF pricing - DSGVO/GDPR compliance in the DACH region - Deepfakes and AI-enabled fraud (CEO fraud, voice cloning) - Identity theft prevention and response - NIS2 directive and which Swiss companies it affects - Data protection officer (DPO): duties and when one is mandatory