NIS2 checkContact

References

References are available on request

We publish no client names, logos, quotes or results without explicit written permission. There are therefore no general client stories and no anonymised success claims on this page. We do describe the kinds of engagement we carry out. When you are seriously considering working with us, we can on request introduce you to an existing client in a comparable sector or situation.

Why there are no logos here

Your security is confidential and in safe hands with us

Information about security suppliers, the technology in use and internal working methods can be sensitive. We therefore publish nothing about a client without permission for that specific item.

Naming the company that runs your security tells anyone who is interested which stack you are on, and gives a caller a plausible name to use on your service desk. Our clients treat that as operational information.

A client can give separate permission for the use of a name, a logo, a quote or a result. Without that permission, the client stays off the website.

We also do not publish anonymous success stories that a reader cannot verify. Instead, we describe four kinds of engagement below and offer, where possible, a direct reference conversation.

Four patterns

Security against cyber risks

The examples below do not describe individual clients. They show the situations organisations come to us with, what we then do, and the lead time that fits.

An international group without a named CISO

The situation: an organisation consists of several legal entities in different countries. Responsibility for security is spread across IT, finance, external advisers and the board. Nobody oversees the whole. What we do: a named CISO works two blocks of eight hours a month for the organisation, with a named deputy who sits in the same meetings. The first step is an overview per legal entity and country: which law applies, who is responsible, and through which route incidents have to be reported. A monthly review of risks and incidents and periodic reporting to the board follow.

The overview of entities and countries takes four to six weeks. The CISO service then continues on a monthly basis.

Managed CISO

NIS2 obligations in several countries

The situation: an organisation operates in several European countries and has treated NIS2 as one uniform arrangement. In practice each country has its own national law, supervisor, registration and reporting route. What we do: we carry out a classification scan per country and per legal entity, separating missing controls from controls that exist but cannot yet be evidenced. We can then prepare the registrations, implement the missing controls and record the reporting procedures per country.

The classification and first assessment take two to three weeks per country. The delivery can take several months, depending on which controls are missing.

Country programme

A supplier receiving security questions from a major customer

The situation: the organisation is probably not directly in scope for NIS2, but receives an extensive security questionnaire from a major customer. The response is tied to a contract renewal or a tender. It asks for an ISMS, an incident procedure, multi-factor authentication everywhere, and evidence that a backup has actually been restored. What we do: we first complete the questionnaire factually on the basis of the existing situation. Items for which no control or evidence is available are marked as open. We then draw up a delivery plan based on the weight the customer gives each item. The evidence built up can afterwards be used for other customers as well.

The first factual response can be completed within a few days. Making the improvements usually takes weeks and depends on what is missing.

Supply chain

A cyber incident at an organisation that is not yet a client

The situation: files are encrypted, an account is being misused, or other behaviour points to an active incident. The organisation has no agreement with us yet. What we do: we start the assessment during the first phone call. The first work is aimed at limiting the damage, preserving information and recording the timeline: isolating machines without powering them down, establishing what was reached, and opening the incident record. Where a reporting duty may apply, we collect the information for the first notification and the reports that follow. After the incident, part of the security required can be set up as a managed service.

Response starts on the call. For a reportable NIS2 incident, reporting moments then apply at 24 hours, 72 hours and one month.

Incident

These descriptions are examples of kinds of engagement and not accounts of individual clients. Detail about a specific organisation, how the engagement ran and the parts that went less well is discussed only in a reference conversation and with that client's permission.

What all four have in common

From assessment to day-to-day management

Depending on the existing situation, an engagement can consist of five stages, with one organisation accountable across all of them, including the step where a report and a roadmap normally change hands.

The five stages of a Think Smart Europe engagement, and who owns each one afterwards
StageWhat happensWhat you getWho owns it afterwards
AssessWe establish per entity and per country which obligations apply, and test the existing controls and evidence against the ten Article 21(2) measures.A classification per country and a delivery plan with priorities.Think Smart Europe can carry out the plan.
RemediateMissing controls are put in place: multi-factor authentication, privileged account management, immutable backup, logging and patch management.Working controls with recorded responsibilities.Think Smart Europe or your existing team, according to the agreed division of work.
ImplementThe required platforms and integrations are rolled out in your estate: endpoint and EDR, SIEM, identity, network, backup and recovery.A configured technical solution and the accompanying documentation.Think Smart Europe or your own operations organisation.
OperateRecurring work is carried out: service desk, endpoints, updates, account management and restore tests.One agreed way of working, one SLA and one report.The party named as owner in the agreement.
MonitorThe SOC assesses security alerts and the delivery is reported on periodically.Information for the board, audits, insurers, customers and supervisors.Think Smart Europe carries out the agreed monitoring. Your board remains responsible for formal decisions, because Article 20 does not let it delegate that.

Not every organisation needs all five stages. Existing controls that work well are assessed and recorded instead of rebuilt, and where an incumbent provider runs something well we will say so.

References

A conversation rather than a logo

A written client story is selected and edited by the supplier. It usually tells you little about delays, setbacks or the difference between the estimate and the final cost.

A written case study
  • Approved by two marketing departments before anyone published it
  • A percentage with no baseline underneath it
  • The parts that went wrong removed, because nobody publishes those
  • No way for you to check that the organisation in it exists

Cheap to produce, and read as evidence by almost nobody.

A reference conversation
  • A named person at an organisation in your sector, on a call you run
  • Any question you like, including what we got wrong and what it cost
  • We are not on the call and we do not ask for a summary afterwards
  • Arranged in about two weeks, because we have to ask them first

Slower, and the only version we would believe ourselves.

How to ask

Requesting a reference

In a reference conversation you speak directly to a client in a comparable situation. You decide which questions you ask. Arranging such a call takes about two weeks, because the client concerned has to agree first.

01

Describe what you want to assess

Give your sector, the rough size of your organisation and the subject you want to discuss with an existing client. That could be the cooperation between Amsterdam and Bulgaria, the use of the Managed CISO or how incident response ran. A general request produces a general call.

02

We ask a suitable client for permission

We approach one or two organisations that fit your situation. We tell them who is asking and why. The client can decline. Where no suitable client is available or nobody wants to take part, we say so. We do not offer a less relevant reference as a substitute.

03

You speak to the client directly

The introduction goes out by email. Think Smart Europe does not take part in the call and does not ask for a report afterwards.

04

You ask your own questions

You can ask what went less well, what caused delay, how the final invoice compared with the estimate and whether the client would choose the same service again. Any of those points can be put to us afterwards.

We arrange reference conversations for organisations that are genuinely assessing our service. That limits the demand on clients who give up their time for the call voluntarily.

Frequently asked

Frequently asked questions

Why is there no client list here?

We do not have general permission to publish client names and logos. Without specific written permission we do not do so.

Our clients treat their choice of security supplier as operational information. That is a reasonable position, and we do not talk them out of it for a logo wall.

Named references are available on request and with the permission of the client concerned.

Who carried out the work described here?

Both halves, and it is worth being precise about which half does what.

Think Smart Europe is a joint venture of Dutch founders and Think Smart in Bulgaria. The Bulgarian organisation was registered on 19 December 2019, employs around forty people, holds the ISO certifications and the vendor partnerships, and provides the engineering and monitoring capacity.

The Dutch organisation provides the CISO work, the compliance advisory, the agreement and accountability for the engagement.

Where is the work carried out?

In Amsterdam and in Bulgaria.

The client team, the CISO and the agreement sit at Vijzelstraat 68 in Amsterdam. Engineering, the service desk and the 24-hour monitoring are carried out from Sofia, Varna and Stara Zagora. All locations are inside the European Union, under one GDPR regime and the certified management systems of our parent organisation.

Put that question to a reference directly as well.

Can our current IT supplier stay involved?

Yes. Three of the four kinds of engagement commonly start that way.

A Managed CISO, an assessment across several countries or support with customer questions can be set up alongside an existing IT provider. Work that is already being done well does not have to be replaced.

Responsibility for the missing controls and evidence does have to be recorded clearly. The question that matters is who produces the evidence when a supervisor, an insurer or a customer asks for it. Have that conversation before anyone asks.

Will we be named as a client later?

Only with written permission for the specific use. Permission for a name, a logo, a quote and a result is handled separately and can be withdrawn.

Without permission your organisation stays out of our public communication. That is the default, and nobody asks you a second time.

Can we receive a written example in advance?

Yes. We can send a short description of a comparable engagement, without identifying detail, which is useful when a business case needs a paragraph.

That document is background information rather than independent proof of our performance. We do not publish it.

Speak to one of our clients

Tell us your sector, the rough size of your organisation and the question you want to discuss. Where we have a suitable client who agrees, we will introduce you directly. Where no suitable reference is available, we will say so.

Cyber Incident