You hold the data of a hundred businesses. One email is enough.
Payroll records with IBANs and social security numbers, annual accounts, financing documents, access to DATEV (the German accounting and tax software cooperative) and ELSTER (the German tax authorities’ online portal): your firm holds what criminals would otherwise have to hunt for client by client. You are liable for confidentiality, even if someone at reception clicks. I train licensed advisors, tax assistants and apprentices to recognise that one fake email: no IT project, no jargon, about 45 minutes per person.
Training, phishing test, six months of refreshers and proof of training. No subscription. Twelve people: €588 net. A partnership with 30 people: €1,470 net.
Online, can be paused at any time, between two client appointments or in the quiet week after the 10th (the monthly filing deadline). Your own effort: add your team, done.
Who was trained and when, plus the team rate. The document for the data protection authority, professional indemnity insurer, cyber insurer and your own firm records.
Add your team on Monday, and by Friday the proof of training is in your Cockpit. No IT service provider, no installation, DATEV and your firm software stay untouched.
What criminals do with your client data – and what it costs you.
You can hardly put a figure on the value of your data. The attackers can. Client data isn’t “stolen”, it’s copied: you still have it, and now someone else does too. And unlike the shop next door, the damage doesn’t hit one business, it hits all your clients at once.
Whoever has your payroll records knows the name, IBAN and salary of every employee of your clients. That turns into the email to the employer: “My bank details have changed.” Whoever has your bookkeeping knows suppliers, invoice cycles and amounts, and forges the next invoice to fit perfectly. Both happen at the client’s end, but with your knowledge, and the client wonders where the criminals got it from.
ELSTER authorisations, DATEV access and bank data from DATEV Unternehmen online open a direct path to the money: changed refund accounts, manipulated VAT returns, payments from the client’s account. The tax authorities get in touch when it is too late.
A client is about to sell, raise finance or file for insolvency, and their figures are in the attacker’s hands. The client is blackmailed first, then you. If nobody pays, annual accounts, salary lists and ID copies end up openly on the internet. There is no getting them back, and confidentiality is broken for good.
Encrypted systems mean: no payroll, no VAT return, no extension requested in time, often for days. Late-filing penalties for all clients at once, and every single one of them calls. Recovery, forensics and legal advice usually cost more than any ransom.
And this is what you then have to do
Notify the state data protection authority as soon as a risk to the people concerned cannot be ruled out (Art. 33 GDPR). Professional confidentiality does not exempt you from this.
Inform every affected client if the risk is high (Art. 34 GDPR), and with payroll data that includes their employees. Also notify your professional indemnity insurer and, depending on the case, file a criminal complaint.
Professional responsibility (§ 57 StBerG, § 203 StGB), possible fines and damages claims from clients. Clients who leave after an incident don’t come back.
Almost every one of these cases starts with an email that one person believed was genuine. That one moment of recognition is what I train.
This is how your sector is being attacked right now.
I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.
“New document in the portal – please log in” or “Your certificate is expiring” leads to a cloned login page.
An alleged enforcement notice or refund notification with a link or attachment, often with the name of a real client in the subject line.
A client sends “the missing invoices for the VAT return”. The client’s account is real, just taken over, and the attachment brings the malware into the firm.
Shortly before the payroll run, an “employee” of the client reports her new bank details, or the partner asks by AI voice message for an urgent, confidential transfer.
What you have to do – and what this lets you tick off.
For tax firms, what counts is professional law (StBerG, BOStB – the professional code for tax advisors, § 203 StGB), the GDPR and, with cyber policies, the insurer’s obligations. Unlike for medical practices, there is no specific training regulation for tax advisors, but after an incident the supervisory authority, liability insurer and cyber insurer will ask what you did organisationally.
The programme covers raising your team’s awareness and documents it with a timestamp: what the data protection authority, professional indemnity insurers and cyber insurers mean by “organisational measures”.
What stays with you: formally binding your staff to confidentiality under § 62 StBerG, the four-eyes principle for payments, and the technology: encryption, backups and updates through your IT service provider or your DATEV support partner.
All obligations in detail, with legal reference and attack scenario
The course makes your team aware of social engineering and how to handle client data. The proof of training shows that you raised that awareness.
You carry out the formal commitment yourself. The course provides what is missing afterwards: tax assistants, apprentices and payroll staff know which requests they must not answer and how to recognise them.
Everyone takes the same course as the licensed advisors, from the partner to the temp entering receipts.
Trained staff are the organisational part and are documented with a timestamp. Your IT service provider adds encryption, backups and access control.
The course practises the internal reporting path: who calls whom, what gets written down, what is left alone. You or your data protection officer handle the notification itself and the records.
Training with proof of training is exactly what insurers ask about in the questionnaire. The call-back rule before transfers has its own chapter; you set up the four-eyes principle internally.
Not part of awareness training – this stays with you or your IT service provider or your DATEV support partner.
The proof of training is your answer to that question. What it is not: continuing education in tax law. The training teaches your whole firm to recognise attacks, it does not train your advisors in their field.
This is what you have in hand after the programme.
You don’t write any of it yourself. Once the last person on the team has finished, everything is in the Cockpit: you download it and file it in your firm records. Your data protection officer can review the data processing agreement in advance, it is publicly available.
One page: starting point, costs for 12, 25 and 40 people, effort, what it is and what it isn’t, proposed resolution. To print out for your next meeting.
📋 Proof of training with timestampWho was trained and when, the team rate in the phishing test, timestamp. Under Examples you can see a sample with fictitious data, just as your broker receives it.
🔎 Certificate for each person, verifiableEach person receives a certificate of participation whose authenticity anyone can verify online.
🔒 Data processing agreement (DPA)I process the names and email addresses of your employees, on servers in Germany. I never touch client data. The agreement is concluded when you register, as a PDF for your data protection files.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
In a tax firm, diligence, discretion and client trust matter, security included. That is why I enable first instead of testing: licensed advisors, tax assistants and apprentices start with the same knowledge before any simulated attack arrives.
Two ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
No subscription, as and when you need it, and always with my personal support.
One contact person from southern Baden, not a hotline.
I am Patrick Ihle, founder of secureIT. Professionally, I work in information security, and alongside that I have been a trainer and lecturer for more than 20 years. secureIT is my own business in Ballrechten-Dottingen near Freiburg. If you book with me, you get a name and a phone number, not a hotline. I am happy to visit firms in southern Baden in person, and I support everyone else online.
More about meClient and payroll data stay out, even if AI would be faster.
Sorting receipts, answering client emails, building a formula for the payroll report: AI saves a tax firm time. With real client or payroll data, it becomes a disclosure to a third party that touches your duty of confidentiality. Since February 2025, the EU AI Act has required you to train your team in AI literacy.
- Confidentiality under § 57 StBerG (German Tax Advisory Act) and § 203 StGB (German Criminal Code) also applies to AI providers
- Asking AI to explain a formula: yes. Uploading client spreadsheets: no
- AI course with a certificate for each person, plus a model AI policy for the firm
For your firm.
Three simulated phishing emails to your own address. That way you can see in advance what the test for your team looks like.
Proof of training for cyber insurance →What the insurer asks in the questionnaire and what the proof of training looks like, to forward to your broker.
For your clients →Two lines in your client newsletter, and your clients get the same proof of training. With partner commission.
Frequently asked questions
Can I see which colleague clicked on the test email?
Does the simulation touch DATEV, our practice management software or the mail server?
How do I convince my fellow partners at the partners’ meeting?
Does this meet the obligations of my professional liability and cyber insurance?
What happens to my employees’ data, and can my data protection officer review it in advance?
How much time does this really take my firm?
Can I also recommend this to my clients?
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
Partners, tax assistants and apprentices trained in one week.
Add your team, unlock the course, done. Afterwards, the proof of training for the authority, liability insurer and cyber insurer is in your firm records. The account is free, you only pay when you start.