What is behind secureIT?
My name is Patrick Ihle. I founded secureIT in 2023, and I am the one who prepares your quote, stands in front of your team and answers the phone. That is not a shortcoming but a standard of quality.
secureIT is not a team and not an agency. I built the platform, the offer and the support for schools and associations to give as many people as possible access to cybersecurity and so help secure a piece of our future. Where I cannot provide personal support for lack of time, the platform takes over, so that training based on my approach is available to your teams even without me.
For me, awareness means genuinely training participants and their businesses and clearing up uncertainty. It is about security. Security in everyday actions.
Profile
Information security · governance, risk & compliance · AI and data strategy · health IT
- Founder and managing director of secureIT UG (haftungsbeschränkt), a German limited liability company
- Main occupation: information security, governance and management systems
- Responsible for developing an information security management system (ISMS)
- Graduate engineer (Dipl.-Ing.) in information technology, specialising in network and software engineering (DHBW Lörrach)
- In software development since 2003: developer, product manager, software architect, team and project lead
- Part-time trainer, lecturer and examiner
I train people, not security appliances.
The most common sentence after an incident is: “The employee clicked.” I think that sentence is wrong. Someone who opens job applications, invoices and meeting requests all day is doing exactly what they are there for. Attacks are built to fit precisely into that working day.
Every business needs the technical defences, and they belong in the hands of the IT department: firewall, spam filter, access rights, backup. My subject is what they cannot prevent: the attack that takes the official route, with valid credentials and a request that sounds plausible in everyday work.
So it is not about slotting people into a row of technical safeguards. Nobody becomes a piece of technology here. It is about training people and enabling them to recognise and stop an attack. And about letting them do safely, day to day, what they are supposed and allowed to do anyway: use the intended doors, get to information by the secure route, and know what to do if something does happen. That is a skill in demand everywhere today, at work and at home.
That is also why nobody is singled out with me. The business only sees anonymised results; the personal result goes only to the person concerned. Anyone who fears the evaluation will not report the real incident later, and that is exactly the moment that matters.
In person at your premises, or the same content entirely online.
Both are the same thing in different forms. You decide what suits your business: a session with me on site, or the online version you run without me.
In person, based on an individual quote
I come to your business, practice, law firm or workshop and train your team directly. No death by PowerPoint, but live demos: how a sender is forged, what a remotely loaded image reveals about the recipient, how quickly a stolen password turns up somewhere else.
- Content tailored to your sector and your actual processes
- Questions answered in the room, not in a ticket system
- Date, scope and price based on an individual quote
- Optionally followed by the phishing simulation as a practical test
Online, in a personal video format
If a joint session doesn’t work, because of shifts, several sites or simply short notice, you run the same training online. In the videos I explain things exactly as I would in the room; it is not an anonymous learning platform but my training in another form.
- Everyone sets their own pace, based on prior knowledge rather than group
- Active rather than passive: quiz questions, examples to work through, repetition
- No appointment needed, pause and resume at any time
- Simulated phishing attacks afterwards, including proof for each person
For schools there is a third format: ready-made lesson series that the teacher runs at the board while the class joins in on their phones. This is free of charge for schools and non-profit organisations.
First building, then securing
I wrote my first program in 1996. The enthusiasm has stayed with me, even after twenty years of professional life. I still develop software myself today, including this platform.
I started my career in healthcare in 2003: first as a developer, later as a product manager, software architect and team and project lead. Over those years I built teams, designed software architectures and brought products to market. Responsibility for software solutions is still part of my daily work.
Alongside that, I trained further in IT security, from both sides: strategically, by helping to shape and monitor security policies, and practically, by working on the vulnerabilities of real infrastructure. If you have built software, you know better where it breaks.
What I do today
In my main job I work in information security, supporting senior management on strategic, operational and governance matters. My focus is where corporate management, information security and compliance meet.
Specifically, I am responsible for developing the information security management system and the integrated management system, I coordinate the key governance, risk and compliance topics and I steer the resulting measures. On top of that come strategic initiatives around AI governance, data strategy and secure software development: projects in which security, regulatory requirements, innovation and economic feasibility have to be brought together.
For you this means two things. First: when you ask me about NIS2, the GDPR or proof of training, you get an answer from someone who has not just read these requirements but has to implement them in his own organisation. Second: I know what it feels like when security rules meet a working day that still has to function. That is why you won’t get a list of measures from me that nobody can keep up.
Why I teach
Passing on knowledge is, for me, the rewarding part of the work. Over twenty years I have supported hundreds of students, trained apprentices and onboarded new colleagues. Alongside my main job I still work as a trainer, lecturer and examiner, at adult education centres as well as in front of school classes seeing for the first time what a Wi-Fi attack really looks like.
That shapes how I train: no slides full of jargon, but live demos. I show how a sender can be forged, what a remotely loaded image reveals about you, how quickly a stolen password is reused. Once you have seen it, you can’t explain it away.
The technology was there. People clicked anyway.
The businesses I have seen had invested a lot: firewalls, virus scanners, access control systems, clean network segmentation. And still the successful attack came through an email that someone opened because it looked plausible and because it was Friday afternoon.
Email is an insecure channel. It was when the protocol was designed, and that hasn’t changed. Senders can be forged, messages are mostly unencrypted, attachments can carry malicious code. There are technical solutions to each of these problems, but they are never all in place everywhere at the same time. Ransomware almost always arrives by email. In the end, what decides is how consciously the person at the screen handles it, and whether anyone has shown them what to look for.
I founded the company in 2023, at a time when the pandemic and war had accelerated digitalisation in Europe, and the attacks along with it. My goal is not a modest one: easily accessible solutions for protecting people and data that work in everyday life. Not just for corporations with their own security department, but for businesses, practices, law firms, schools and private individuals. Knowledge about attacks must not stay with specialists. Digitalisation, yes, but securely.
What you can hold me to
- Nobody is singled out. The business only receives anonymised results; the personal result goes only to the person concerned.
- No plain-text passwords. In simulated attacks I never store an entered password, only the fact that one was entered.
- No data passed to third parties. Servers in Germany, no sharing, deletion on request.
- Honest about scale. Up to 200 employees, you don’t need to talk to me. Just book directly in the Cockpit.
- Reachable like a human being. Phone, WhatsApp, email. You get the same person on the line every time.
Let’s have a quick chat.
If you are wondering whether this fits your business: call me or book an appointment. A conversation costs nothing and usually settles within fifteen minutes whether we are a good match.