For tax advisors and their firms

You hold the data of a hundred businesses. One email is enough.

Payroll records with IBANs and social security numbers, annual accounts, financing documents, access to DATEV (the German accounting and tax software cooperative) and ELSTER (the German tax authorities’ online portal): your firm holds what criminals would otherwise have to hunt for client by client. You are liable for confidentiality, even if someone at reception clicks. I train licensed advisors, tax assistants and apprentices to recognise that one fake email: no IT project, no jargon, about 45 minutes per person.

Example scene for Tax firms
“I am liable for confidentiality, even if the apprentice clicks.”
“Twenty-five people, receipts and invoices arriving as attachments every day, and nobody responsible for IT security.”
“I keep reading about AI phishing and don’t know whether my firm would spot it.”
Add your team See prices
€49 per person, one-off

Training, phishing test, six months of refreshers and proof of training. No subscription. Twelve people: €588 net. A partnership with 30 people: €1,470 net.

45 min per person

Online, can be paused at any time, between two client appointments or in the quiet week after the 10th (the monthly filing deadline). Your own effort: add your team, done.

PDF proof of training with timestamp

Who was trained and when, plus the team rate. The document for the data protection authority, professional indemnity insurer, cyber insurer and your own firm records.

1 week to proof of training

Add your team on Monday, and by Friday the proof of training is in your Cockpit. No IT service provider, no installation, DATEV and your firm software stay untouched.

What happens after the click

What criminals do with your client data – and what it costs you.

You can hardly put a figure on the value of your data. The attackers can. Client data isn’t “stolen”, it’s copied: you still have it, and now someone else does too. And unlike the shop next door, the damage doesn’t hit one business, it hits all your clients at once.

Salaries and invoices are redirected

Whoever has your payroll records knows the name, IBAN and salary of every employee of your clients. That turns into the email to the employer: “My bank details have changed.” Whoever has your bookkeeping knows suppliers, invoice cycles and amounts, and forges the next invoice to fit perfectly. Both happen at the client’s end, but with your knowledge, and the client wonders where the criminals got it from.

Refunds and access

ELSTER authorisations, DATEV access and bank data from DATEV Unternehmen online open a direct path to the money: changed refund accounts, manipulated VAT returns, payments from the client’s account. The tax authorities get in touch when it is too late.

Extortion with balance sheets

A client is about to sell, raise finance or file for insolvency, and their figures are in the attacker’s hands. The client is blackmailed first, then you. If nobody pays, annual accounts, salary lists and ID copies end up openly on the internet. There is no getting them back, and confidentiality is broken for good.

The firm grinds to a halt, the 10th comes anyway

Encrypted systems mean: no payroll, no VAT return, no extension requested in time, often for days. Late-filing penalties for all clients at once, and every single one of them calls. Recovery, forensics and legal advice usually cost more than any ransom.

And this is what you then have to do

72 hours

Notify the state data protection authority as soon as a risk to the people concerned cannot be ruled out (Art. 33 GDPR). Professional confidentiality does not exempt you from this.

without delay

Inform every affected client if the risk is high (Art. 34 GDPR), and with payroll data that includes their employees. Also notify your professional indemnity insurer and, depending on the case, file a criminal complaint.

permanently

Professional responsibility (§ 57 StBerG, § 203 StGB), possible fines and damages claims from clients. Clients who leave after an incident don’t come back.

Almost every one of these cases starts with an email that one person believed was genuine. That one moment of recognition is what I train.

Typical attacks

This is how your sector is being attacked right now.

I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.

Fake DATEV or ELSTER message

“New document in the portal – please log in” or “Your certificate is expiring” leads to a cloned login page.

“Tax office” with a reminder and a deadline

An alleged enforcement notice or refund notification with a link or attachment, often with the name of a real client in the subject line.

Receipts from a client with a malicious file

A client sends “the missing invoices for the VAT return”. The client’s account is real, just taken over, and the attachment brings the malware into the firm.

Changed bank details just before the salary transfer

Shortly before the payroll run, an “employee” of the client reports her new bank details, or the partner asks by AI voice message for an urgent, confidential transfer.

Your obligations

What you have to do – and what this lets you tick off.

For tax firms, what counts is professional law (StBerG, BOStB – the professional code for tax advisors, § 203 StGB), the GDPR and, with cyber policies, the insurer’s obligations. Unlike for medical practices, there is no specific training regulation for tax advisors, but after an incident the supervisory authority, liability insurer and cyber insurer will ask what you did organisationally.

✓ covered by the programme

The programme covers raising your team’s awareness and documents it with a timestamp: what the data protection authority, professional indemnity insurers and cyber insurers mean by “organisational measures”.

– stays with you

What stays with you: formally binding your staff to confidentiality under § 62 StBerG, the four-eyes principle for payments, and the technology: encryption, backups and updates through your IT service provider or your DATEV support partner.

All obligations in detail, with legal reference and attack scenario
◐ partly
Confidentiality about everything that becomes known in the course of professional practice. · § 57 para. 1 StBerG, § 5 BOStB
↳ covers: DATEV/ELSTER, tax office

The course makes your team aware of social engineering and how to handle client data. The proof of training shows that you raised that awareness.

◐ partly
Bind employees to confidentiality. · § 62 StBerG
↳ covers: Client impersonation

You carry out the formal commitment yourself. The course provides what is missing afterwards: tax assistants, apprentices and payroll staff know which requests they must not answer and how to recognise them.

◐ partly
The duty of confidentiality also applies to the firm’s assistants. · § 203 para. 1 No. 3 and para. 4 StGB
↳ covers: Receipts from a client

Everyone takes the same course as the licensed advisors, from the partner to the temp entering receipts.

◐ partly
Technical and organisational measures to protect client data. · Art. 32 GDPR
↳ covers: Changed bank details

Trained staff are the organisational part and are documented with a timestamp. Your IT service provider adds encryption, backups and access control.

◐ partly
Report a data breach within 72 hours, inform clients. · Art. 33 and 34 GDPR
↳ covers: all four attacks

The course practises the internal reporting path: who calls whom, what gets written down, what is left alone. You or your data protection officer handle the notification itself and the records.

◐ partly
Obligations under professional indemnity and cyber insurance: staff training, four-eyes principle for payments. · § 67 StBerG, policy terms, risk questionnaire
↳ covers: Changed bank details, voice message

Training with proof of training is exactly what insurers ask about in the questionnaire. The call-back rule before transfers has its own chapter; you set up the four-eyes principle internally.

– your IT
Technical safeguards: encryption, backups, updates, access control. · Art. 32 GDPR, state of the art

Not part of awareness training – this stays with you or your IT service provider or your DATEV support partner.

The proof of training is your answer to that question. What it is not: continuing education in tax law. The training teaches your whole firm to recognise attacks, it does not train your advisors in their field.

Examples

This is what it looks like in practice.

Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

All example views

How I work with you

This is how my training works.

In a tax firm, diligence, discretion and client trust matter, security included. That is why I enable first instead of testing: licensed advisors, tax assistants and apprentices start with the same knowledge before any simulated attack arrives.

Two ways – you choose what suits you.

1 In person, by me

I train your team in person – on site or online, in conversation and with examples from your everyday work.

2 Everyone online on their own

Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.

My recommendation

Train first, then test – deliberately in that order.

  1. Initial training

    First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.

  2. Phishing test as a self-check

    Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.

  3. A security culture, refreshed when needed

    Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.

📊

Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.

No subscription, as and when you need it, and always with my personal support.

Who is behind it

One contact person from southern Baden, not a hotline.

Patrick Ihle, founder of secureIT

I am Patrick Ihle, founder of secureIT. Professionally, I work in information security, and alongside that I have been a trainer and lecturer for more than 20 years. secureIT is my own business in Ballrechten-Dottingen near Freiburg. If you book with me, you get a name and a phone number, not a hotline. I am happy to visit firms in southern Baden in person, and I support everyone else online.

More about me
AI in everyday work

Client and payroll data stay out, even if AI would be faster.

Sorting receipts, answering client emails, building a formula for the payroll report: AI saves a tax firm time. With real client or payroll data, it becomes a disclosure to a third party that touches your duty of confidentiality. Since February 2025, the EU AI Act has required you to train your team in AI literacy.

  • Confidentiality under § 57 StBerG (German Tax Advisory Act) and § 203 StGB (German Criminal Code) also applies to AI providers
  • Asking AI to explain a formula: yes. Uploading client spreadsheets: no
  • AI course with a certificate for each person, plus a model AI policy for the firm
See the AI course with certificate Sample AI policy (PDF)
FAQ

Frequently asked questions

Can I see which colleague clicked on the test email?
No, and that’s intentional. In the Cockpit you see the rate for the firm and for each team, but no names. Anyone who clicks lands on a learning page and knows it themselves. That way the test stays an exercise and doesn’t become a personnel issue between partners, tax clerks and trainees.
Does the simulation touch DATEV, our practice management software or the mail server?
No. The simulation consists of normal emails to your employees’ addresses. I don’t access anything in your firm, install nothing and need no logins. Your IT service provider or DATEV support doesn’t need to set anything up; if you like, I’ll say in advance which sender domain the test emails come from, so the spam filter lets them through.
How do I convince my fellow partners at the partners’ meeting?
With the decision paper available for download above: one page covering the starting point, costs for 12, 25 and 40 people, effort per person, what the programme covers and what it doesn’t, and a draft resolution. Plus the free self-test, which lets every partner see in advance what a test email looks like. If it helps, I can also explain the approach in twenty minutes by video call during your meeting.
Does this meet the obligations of my professional liability and cyber insurance?
Most insurers ask in their risk questionnaire about regular employee training on phishing and about a four-eyes principle for payments. The programme covers the training part and proves it with a timestamp. You handle the four-eyes principle internally; the call-back rule before bank transfers is part of the course. If in doubt, show the proof of training to your broker – I have a dedicated page for insurance brokers.
What happens to my employees’ data, and can my data protection officer review it in advance?
What is stored: name, email address, course completion and the result of the phishing test, on IONOS servers in Germany. Client data is never involved. The data processing agreement (DPA) is openly available on the data processing page, so your data protection officer can read it before registration; it is concluded on registration and is available as a PDF for your data protection records.
How much time does this really take my firm?
Around 45 min per person for the course, online, and it can be paused and resumed in stages – so it also fits between two client appointments or into the quieter week after the 10th. The phishing test afterwards takes no time; it happens in the inbox. Your own effort: add the team, unlock the course, download the proof of training later. That’s done in an hour, and you can also hand it over to your office management.
Can I also recommend this to my clients?
Yes. As a partner, you add two lines with your link to your client newsletter; your clients book themselves and receive the same proof of training for their insurer. You receive 20% commission or offset it against places for your own firm. Details on the page for tax advisors as referrers.
Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Partners, tax assistants and apprentices trained in one week.

Add your team, unlock the course, done. Afterwards, the proof of training for the authority, liability insurer and cyber insurer is in your firm records. The account is free, you only pay when you start.

Add your team Test it yourself first

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first