For law firms

Client confidentiality is only one email away from a breach.

You are personally liable for confidentiality, even if someone at the front desk clicks. Law firms hold files that interest opponents and blackmailers, and money in client trust accounts that attracts fraudsters. I train partners, lawyers and staff to recognise that one fake email: no IT project, no jargon, in about 45 minutes per person.

Example scene for Law firms
“I am liable for confidentiality, even if the trainee clicks.”
“Twelve people, deadline emails with attachments every day, and nobody is in charge of IT security.”
“I read about AI phishing and don’t know whether my firm would spot it.”
Add your team See prices
€49 per person, one-off

Training, phishing test, six months of refreshers and proof of training. No subscription. Twelve people: €588 net. A partnership with 30 people: €1,470 net.

45 min per person

Online, can be paused at any time, between two appointments or on a Friday afternoon. Your own effort: enter your team, done.

PDF Proof of training with timestamp

Who was trained when, plus the team rate. The document for the data protection authority, your insurer and the firm’s own records.

1 week to proof of training

Enter your team on Monday, and by Friday the proof is in the Cockpit. No IT service provider, no installation; beA and your practice management software stay untouched.

What happens after the click

What criminals do with client files – and what it costs you.

You can hardly put a figure on the value of your files; the attackers can. Client data isn’t “stolen”, it is copied: you still have it, and now someone else does too.

Clients are blackmailed directly

With divorce files, criminal proceedings or M&A contracts in hand, the attackers write to your clients themselves: pay, or it gets published. The New York firm Grubman Shire Meiselas & Sacks went through this in 2020, with high-profile clients and a demand for 42 million dollars.

Publication on the dark web

If nobody pays, pleadings, powers of attorney and copies of ID documents end up openly online, where opponents, the press and identity thieves can find them. There is no getting them back; confidentiality is broken for good.

Money from the client trust account

A settlement amount or a purchase price payout goes to the “new account number” of the other side or of the client. The money is gone, the client claims it from you, and your professional indemnity insurer checks whether you were negligent.

The firm stands still, the deadlines keep running

Encrypted systems mean no access to files, the deadline calendar or beA, often for days. A missed deadline is a liability case, and recovery, forensics and legal advice usually cost more than any ransom.

And this is what you then have to do

72 hours

Notification to the state data protection authority as soon as a risk to the people affected cannot be ruled out (Art. 33 GDPR). Professional secrecy does not exempt you from this.

without undue delay

Informing every affected client if the risk is high (Art. 34 GDPR), plus notifying your professional indemnity insurer and, depending on the case, filing a criminal complaint.

permanently

Professional responsibility (§ 43a BRAO, § 203 StGB), possible fines and damages. A law firm’s reputation cannot be insured.

Almost every one of these cases starts with an email that one person took to be genuine. That one moment of recognition is what I train.

Typical attacks

This is how your sector is being attacked right now.

I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.

Fake beA notification

“New message in your beA – please confirm your mailbox” leads to a copied login page. (beA is the special electronic mailbox every German lawyer must use.)

Cease-and-desist letter or pleading with attachment

A supposed pleading from the opposing side, or a cease-and-desist letter with deadline pressure, brings malware into the firm.

Changed account number

Shortly before the payout, the client or opposing counsel reports a “new bank account” for the settlement amount.

Voice message from the partner

Supposedly the name partner, by email or AI-generated voice message: an urgent, confidential transfer from the client trust account.

Your obligations

What you have to do – and what this lets you tick off.

For law firms, what counts is professional law (BRAO, BORA (German Rules of Professional Practice for Lawyers), § 203 StGB), the GDPR and, with cyber policies, the insurer’s obligations. Unlike medical practices, lawyers have no specific training regulation, but if something goes wrong, the authorities and insurers will ask what you did on the organisational side.

✓ covered by the programme

The programme covers your team’s awareness training and documents it with a timestamp: what the data protection authority, professional indemnity insurers and cyber insurers mean by “organisational measures”.

– stays with you

What stays with you: the formal confidentiality undertaking of your staff, the four-eyes principle for payments from the client trust account, and the technology – encryption, backups and updates, handled by your IT service provider.

All obligations in detail, with legal reference and attack scenario
◐ partly
Instruct staff to maintain confidentiality and raise their awareness regularly. · § 43a para. 2 BRAO, § 2 BORA
↳ covers: beA, pleading

The course makes your team aware of social engineering and of how to handle client data; the formal confidentiality undertaking of your staff is something you do yourself. The proof of training shows that you have raised awareness.

◐ partly
The duty of confidentiality also applies to the firm’s assistants. · § 203 para. 1 and 4 StGB
↳ covers: Client impersonation

Assistants, trainee lawyers and apprentices take the same course as the lawyers and afterwards know which requests they must not answer.

◐ partly
Technical and organisational measures to protect client data. · Art. 32 GDPR
↳ covers: Changed account number

Trained staff are the organisational part and are documented with a timestamp. Your IT service provider adds encryption, backups and access control.

✓ covered
Secure use of the special electronic lawyers’ mailbox (beA). · § 31a BRAO, § 20 RAVPV
↳ covers: beA

Phishing simulations with beA-style motifs train staff to recognise fake notifications; the access card stays with you.

◐ partly
Reporting a data breach within 72 hours, informing clients. · Art. 33 and 34 GDPR
↳ covers: all four attacks

The course practises the internal reporting path: who calls whom, what gets written down, what is left out. You or your data protection officer make the notification itself and keep the record.

◐ partly
Cyber insurance obligations: staff training, four-eyes principle for payments. · Policy terms, risk questionnaire
↳ covers: Changed account number, voice message

Training with proof is exactly what insurers ask about in the questionnaire. The call-back rule before transfers has its own chapter; you set up the four-eyes principle internally.

– your IT
Technical safeguards: encryption, backups, updates, access control. · Art. 32 GDPR, state of the art

Not part of awareness training – this lies with you or your IT service provider.

The proof of training is your answer to that question. What it is not: recognised continuing legal education under § 43a para. 6 BRAO. The training trains your team, not your lawyers in substantive law.

Examples

This is what it looks like in practice.

Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

All example views

How I work with you

This is how my training works.

In a law firm, diligence, discretion and reputation matter, including when it comes to security. That is why I enable first instead of testing: partners, lawyers and staff all start with the same level of knowledge before any simulated attack arrives.

Two ways – you choose what suits you.

1 In person, by me

I train your team in person – on site or online, in conversation and with examples from your everyday work.

2 Everyone online on their own

Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.

My recommendation

Train first, then test – deliberately in that order.

  1. Initial training

    First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.

  2. Phishing test as a self-check

    Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.

  3. A security culture, refreshed when needed

    Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.

📊

Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.

No subscription, as and when you need it, and always with my personal support.

Who is behind it

One contact person from southern Baden, not a hotline.

Patrick Ihle, founder of secureIT

I am Patrick Ihle, founder of secureIT. Professionally I work in information security, and alongside that I have been a trainer and lecturer for over 20 years. secureIT is my own business in Ballrechten-Dottingen near Freiburg. If you book with me, you get a name and a phone number, not a hotline. I am happy to visit law firms in southern Baden on site; everyone else I support online.

More about me
AI in everyday work

Client confidentiality and AI only go together with clear rules.

Drafting pleadings, summarising files, researching case law: for law firms, AI is tempting and risky at the same time. Client data in a freely available chatbot can breach confidentiality, and courts have already reprimanded lawyers for invented citations. Since February 2025, the AI literacy obligation under the EU AI Act also applies to your whole team.

  • Confidentiality under § 43a BRAO (German Federal Lawyers’ Act) and § 203 StGB (German Criminal Code) also applies when using AI
  • Spot invented judgments and citations before they end up in a pleading
  • AI course with a certificate for each person, plus a template AI policy for the firm
See the AI course with certificate Sample AI policy (PDF)
FAQ

Frequently asked questions

Can I see which colleague clicked on the test email?
No, and that’s intentional. In the Cockpit you see the rate for the firm and for each team, but no names. Anyone who clicks lands on a learning page and knows it themselves. That way the test stays an exercise and doesn’t become a personnel issue between partners, employees and trainee lawyers.
Does the simulation touch beA, our practice management software or the mail server?
No. The simulation consists of normal emails to your employees’ addresses. I don’t access anything in your firm, install nothing and need no logins. beA (the German special electronic mailbox for lawyers) is not involved. Your IT service provider doesn’t need to set anything up; if you like, I’ll tell them in advance which sender domain the test emails come from, so the spam filter lets them through.
Does this meet the obligations of my cyber insurance?
Most insurers ask in their risk questionnaire about regular employee training on phishing and about a four-eyes principle for payments. The programme covers the training part and proves it with a timestamp. You handle the four-eyes principle internally; the call-back rule before bank transfers is part of the course. If in doubt, show the proof of training to your broker – I have a dedicated page for insurance brokers.
What happens to my employees’ data?
What is stored: name, email address, course completion and the result of the phishing test, on IONOS servers in Germany. Client data is never involved. The data processing agreement (DPA) is concluded on registration and is available as a PDF for your data protection records.
How much time does this really take my firm?
Around 45 min per person for the course, online, and it can be paused and resumed in stages – so it also fits between two client appointments. The phishing test afterwards takes no time; it happens in the inbox. Your own effort: add the team, unlock the course, download the proof of training later. That’s done in an hour, and you can also hand it over to your office management.
Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Partners, lawyers and assistants trained in one week.

Enter your team, activate the course, done. Afterwards, the proof for authorities and insurers sits in the firm’s records. The account is free; you only pay when you start.

Enter your team Test it yourself first

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first