Client confidentiality is only one email away from a breach.
You are personally liable for confidentiality, even if someone at the front desk clicks. Law firms hold files that interest opponents and blackmailers, and money in client trust accounts that attracts fraudsters. I train partners, lawyers and staff to recognise that one fake email: no IT project, no jargon, in about 45 minutes per person.
Training, phishing test, six months of refreshers and proof of training. No subscription. Twelve people: €588 net. A partnership with 30 people: €1,470 net.
Online, can be paused at any time, between two appointments or on a Friday afternoon. Your own effort: enter your team, done.
Who was trained when, plus the team rate. The document for the data protection authority, your insurer and the firm’s own records.
Enter your team on Monday, and by Friday the proof is in the Cockpit. No IT service provider, no installation; beA and your practice management software stay untouched.
What criminals do with client files – and what it costs you.
You can hardly put a figure on the value of your files; the attackers can. Client data isn’t “stolen”, it is copied: you still have it, and now someone else does too.
With divorce files, criminal proceedings or M&A contracts in hand, the attackers write to your clients themselves: pay, or it gets published. The New York firm Grubman Shire Meiselas & Sacks went through this in 2020, with high-profile clients and a demand for 42 million dollars.
If nobody pays, pleadings, powers of attorney and copies of ID documents end up openly online, where opponents, the press and identity thieves can find them. There is no getting them back; confidentiality is broken for good.
A settlement amount or a purchase price payout goes to the “new account number” of the other side or of the client. The money is gone, the client claims it from you, and your professional indemnity insurer checks whether you were negligent.
Encrypted systems mean no access to files, the deadline calendar or beA, often for days. A missed deadline is a liability case, and recovery, forensics and legal advice usually cost more than any ransom.
And this is what you then have to do
Notification to the state data protection authority as soon as a risk to the people affected cannot be ruled out (Art. 33 GDPR). Professional secrecy does not exempt you from this.
Informing every affected client if the risk is high (Art. 34 GDPR), plus notifying your professional indemnity insurer and, depending on the case, filing a criminal complaint.
Professional responsibility (§ 43a BRAO, § 203 StGB), possible fines and damages. A law firm’s reputation cannot be insured.
Almost every one of these cases starts with an email that one person took to be genuine. That one moment of recognition is what I train.
This is how your sector is being attacked right now.
I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.
“New message in your beA – please confirm your mailbox” leads to a copied login page. (beA is the special electronic mailbox every German lawyer must use.)
A supposed pleading from the opposing side, or a cease-and-desist letter with deadline pressure, brings malware into the firm.
Shortly before the payout, the client or opposing counsel reports a “new bank account” for the settlement amount.
Supposedly the name partner, by email or AI-generated voice message: an urgent, confidential transfer from the client trust account.
What you have to do – and what this lets you tick off.
For law firms, what counts is professional law (BRAO, BORA (German Rules of Professional Practice for Lawyers), § 203 StGB), the GDPR and, with cyber policies, the insurer’s obligations. Unlike medical practices, lawyers have no specific training regulation, but if something goes wrong, the authorities and insurers will ask what you did on the organisational side.
The programme covers your team’s awareness training and documents it with a timestamp: what the data protection authority, professional indemnity insurers and cyber insurers mean by “organisational measures”.
What stays with you: the formal confidentiality undertaking of your staff, the four-eyes principle for payments from the client trust account, and the technology – encryption, backups and updates, handled by your IT service provider.
All obligations in detail, with legal reference and attack scenario
The course makes your team aware of social engineering and of how to handle client data; the formal confidentiality undertaking of your staff is something you do yourself. The proof of training shows that you have raised awareness.
Assistants, trainee lawyers and apprentices take the same course as the lawyers and afterwards know which requests they must not answer.
Trained staff are the organisational part and are documented with a timestamp. Your IT service provider adds encryption, backups and access control.
Phishing simulations with beA-style motifs train staff to recognise fake notifications; the access card stays with you.
The course practises the internal reporting path: who calls whom, what gets written down, what is left out. You or your data protection officer make the notification itself and keep the record.
Training with proof is exactly what insurers ask about in the questionnaire. The call-back rule before transfers has its own chapter; you set up the four-eyes principle internally.
Not part of awareness training – this lies with you or your IT service provider.
The proof of training is your answer to that question. What it is not: recognised continuing legal education under § 43a para. 6 BRAO. The training trains your team, not your lawyers in substantive law.
This is what you have in hand after the programme.
You don’t write any of it yourself. Once the last person on the team has finished, everything is in the Cockpit; you download it and file it in the firm’s records.
One page: starting point, costs for 12, 25 and 40 people, effort, what it is and what it isn’t, proposed resolution. To print out for your next meeting.
📋 Proof of training with timestampWho was trained when, the team rate in the phishing test, timestamp. Under Examples you can see a sample with fictitious data, exactly as your broker receives it.
🔎 Certificate per person, verifiableEach person receives a certificate of participation whose authenticity anyone can verify online.
🔒 Data processing agreement (DPA)I process the names and email addresses of your staff, on servers in Germany. The agreement is concluded when you register, as a PDF for your data protection records.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
In a law firm, diligence, discretion and reputation matter, including when it comes to security. That is why I enable first instead of testing: partners, lawyers and staff all start with the same level of knowledge before any simulated attack arrives.
Two ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
No subscription, as and when you need it, and always with my personal support.
One contact person from southern Baden, not a hotline.
I am Patrick Ihle, founder of secureIT. Professionally I work in information security, and alongside that I have been a trainer and lecturer for over 20 years. secureIT is my own business in Ballrechten-Dottingen near Freiburg. If you book with me, you get a name and a phone number, not a hotline. I am happy to visit law firms in southern Baden on site; everyone else I support online.
More about meClient confidentiality and AI only go together with clear rules.
Drafting pleadings, summarising files, researching case law: for law firms, AI is tempting and risky at the same time. Client data in a freely available chatbot can breach confidentiality, and courts have already reprimanded lawyers for invented citations. Since February 2025, the AI literacy obligation under the EU AI Act also applies to your whole team.
- Confidentiality under § 43a BRAO (German Federal Lawyers’ Act) and § 203 StGB (German Criminal Code) also applies when using AI
- Spot invented judgments and citations before they end up in a pleading
- AI course with a certificate for each person, plus a template AI policy for the firm
For your firm.
The full comparison with the GDPR, cyber insurance and ISO 27001, in case your insurer or a major client asks for more.
Free self-test →Three simulated phishing emails to your own address. That way you can see in advance what the test will look like for your team.
Proof for cyber insurance →What the insurer asks in the questionnaire and what the proof looks like, to forward to your broker.
Frequently asked questions
Can I see which colleague clicked on the test email?
Does the simulation touch beA, our practice management software or the mail server?
Does this meet the obligations of my cyber insurance?
What happens to my employees’ data?
How much time does this really take my firm?
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
Partners, lawyers and assistants trained in one week.
Enter your team, activate the course, done. Afterwards, the proof for authorities and insurers sits in the firm’s records. The account is free; you only pay when you start.