You talk to every owner every quarter. Two lines are enough.
Your clients with 10 to 50 employees have no IT department, but they do have an insurer, a major customer or a data protection officer asking for proof of training. You do not have to explain or sell anything. One paragraph in your newsletter with your link, and I handle the rest.
Looking for training for your own practice? This way to the page for tax practices.
The attacks that land in your clients’ accounts departments.
These are exactly the cases the training covers. Otherwise, each of them ends up in your practice as a query, a reversal or a damage report.
Familiar supplier, new bank details, accounts pays. The classic in businesses without a four-eyes principle.
“I’m in a meeting, please make an urgent transfer …” sent to the person with account authority.
Supposed refund or payment reminder with a link to a copied login page, often with the name of the tax practice in the subject line.
Someone poses as your practice and asks the client for documents or login details.
The paragraph you simply paste in.
Neutral wording, no marketing speak, with your partner link. Fits into any quarterly newsletter between tax deadlines and notices.
IT security: proof of training for insurers and clients Cyber insurers, larger clients and the NIS2 supply chain are increasingly asking for proof that employees have been trained on phishing. For businesses without their own IT department, there is a lean way to do this: online training, phishing test and verifiable certificate in one run, €49 per person one-off, no subscription, set up in ten minutes. Information and sign-up at YOUR-PARTNER-LINK. If you wish, we will be happy to put you in touch.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
You register once as a partner, put your link in the newsletter and you are done. The client buys directly at the list price, and I take care of training, test and proof. The commission is credited when payment is received, including for the repeat in the following year.
Three ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
You run the training yourself: I provide the ready-made materials and you pass them on in-house – at your own pace.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
New team members can be added later with one click: they immediately receive the online training materials and a first self-test – and join the next joint session or training with the same prior knowledge.
The reverse order – and why I advise against it.
From a management perspective, it often seems logical to assess the situation with a test first and only then decide whether training is needed. Technically that works – I can set it up for you.
A client who just wants to “test” whether their people click gets a click rate, but no proof. For insurers and clients, what counts is training with evidence. That is why: training first, then testing. A test without prior training only measures the starting point at zero. My approach turns this around: equip first, then check.
No subscription, as and when you need it, and always with my personal support.
Client and payroll data stay out, even if AI would be faster.
AI saves time in a tax practice, as long as no client or payroll data ends up in a chatbot. Since February 2025, you also have to train your team in AI literacy and document it.
- Confidentiality under § 57 StBerG (German Tax Advisers Act) and § 203 StGB (German Criminal Code) also applies towards AI providers
- Training obligation under Art. 4 EU AI Act, with proof for each person
- Template AI policy and template works agreement free of charge
For your practice.
20 % on the first and follow-up purchases, credited when payment is received, offset or paid out.
For your own practice →Payroll data, balance sheets, DATEV access: your inbox is a target too. The page for your own team, with a decision paper for the partners’ meeting.
Proof page for clients →What the insurer asks and what the proof looks like, ready to forward.
Frequently asked questions
Am I giving IT advice I don’t want to be liable for?
How do I get the commission without writing invoices?
May I change the text snippet?
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
Register once, add it to the newsletter once, done.
No advisory obligation, no effort for your practice. The client clicks, I deliver.