NIS2 checkContact

IT managed services

Your service desk should not depend on who is on holiday

We run the day-to-day work so that your own people are not the only ones who can. Service desk, laptops and mobile devices, firewalls and switches, servers, Microsoft 365 and cloud workloads, and the identity setup underneath all of it. This is the least interesting part of the contract and the part that decides whether the rest of it holds.

The scope

Most IT problems come from one of these five places

Below is what a full managed service covers. You can take part of it, endpoints only, or cloud only, and plenty of organisations start that way. Where the boundary sits gets written into the contract, because an unwritten boundary is where work quietly stops.

Service desk and end-user support

One point of contact for every user, in every country you operate in. Phone, mail and portal arrive in the same queue, so the same problem raised three ways is still one ticket with one owner.

Endpoint management

Imaging, enrolment, configuration baselines, patching and software distribution for laptops, desktops and mobile devices. Devices that fall outside the baseline are reported rather than quietly tolerated.

Network and firewall

Firewalls, switches, routers and wireless across offices, branches and production sites. Rule changes, firmware, configuration backups, and a record of who asked for a change and who approved it.

Servers and cloud

On-premises servers, Microsoft 365 and public cloud workloads. Capacity, patching, licence hygiene, backup and, the part that counts, restores that have actually been tested.

Identity and access

We manage multi-factor authentication, conditional access, privileged accounts and the technical steps around joining, changing role and leaving. Those changes are made on the basis of timely and approved information from HR and line managers.

Security monitoring and incident response fall under Managed Security and SOC. That service can be set up on top of our day-to-day management, but equally on top of an IT estate run by your own team or another supplier.

The service desk

One service desk for your users

Users reach one service desk, whichever country they sit in. English is the standard working language. Other languages are offered only where that is set out in the agreement.

Calls, emails and portal tickets all land in the same queue. Every ticket gets a priority, an owner and a next action.

First line handles standard questions and faults. More complex tickets are passed to second or third line inside the same organisation.

The monthly report shows how many tickets came in, how long they took to handle and which problems keep coming back.

One way of working across several countriesEvery site uses the same priorities, the same records and the same reporting. Local arrangements and languages are set out separately in the contract.
Clear escalationFirst, second and third line work within the same delivery organisation. Every escalation keeps one owner and a recorded next action.

Compliance

Management with evidence

Day-to-day IT management supports several of the NIS2 measures. Among other things it produces records of updates, restore tests, account changes, approved changes and completed checks.

Several of the ten measures in Article 21(2) of the NIS2 directive are delivered mostly by ordinary IT operations rather than by security tooling.

  • (c) Business continuity, backup, restore and a tested recovery of a workload, with an agreed RTO and RPO per system.
  • (e) System lifecycle, acquisition, development and maintenance, which in daily practice means patching, vulnerability handling and hardened baselines applied on a schedule.
  • (g) Cyber hygiene and training, the ordinary discipline of current systems, tidied-up accounts and managed software.
  • (i) HR security and access control, joiner, mover and leaver handled as one process, with accounts holding elevated rights reviewed rather than assumed.
  • (j) Authentication and secured communications, multi-factor authentication enforced across users and administrators, with every exception named and owned.

Run as a managed service, each of these leaves evidence behind as a by-product: patch age per device, restore tests with dates on them, accounts closed against the leaving date HR recorded. That is the difference between believing your patching is current and being able to show it on the day somebody asks.

This information can be used for audits, supplier assessments, insurance questions and supervision. A managed IT contract does not, however, make you compliant with the Cyberbeveiligingswet. Matters such as classification, board responsibility, incident reporting and supplier risk have to be assessed separately.

Included

What the service covers

The middle column describes the work. The right-hand column describes what comes back in your monthly report.

IT managed services, scope and service measures
ServiceWhat is includedWhat is measured
Service deskSingle point of contact by phone, mail and portal. Incident and request handling, first line resolution, escalation to second and third line.Response and resolution against the agreed priority levels, ticket volume, backlog age, and the faults that keep recurring.
Endpoint managementImaging, enrolment, configuration baselines, patching and software distribution for laptops, desktops and mobile devices.Patch coverage and patch age per device, devices outside the baseline, and every exception with a reason and an owner.
Network and firewallFirewalls, switches, routers and wireless across all sites. Rule changes, firmware maintenance and configuration backups.Availability per site, firmware currency, and a change record showing who requested and who approved each rule.
Servers and cloudOn-premises servers, Microsoft 365 and public cloud workloads. Capacity, patching, licence hygiene, backup and restore.Backup success rate, restore tests actually performed, and the agreed RTO and RPO per workload.
Identity and accessMulti-factor authentication, conditional access, privileged access management, and the joiner-mover-leaver process.Accounts created and closed against the dates HR supplied, privileged accounts in use, and access reviews completed on schedule.
Reporting and reviewA monthly service report and a review with your named service lead.Trends rather than totals, the changes made, the risks accepted, and the decisions we need from you.

Service hours, priority levels, response times, languages and on-site work are set per agreement.

What changes for your own team

Your team and Think Smart Europe

We take over the agreed day-to-day work, such as the service desk, patching, technical checks, account management and restore tests. Your organisation stays responsible for architecture choices, budgets, business priorities, supplier contracts and decisions with a major impact on operations. The exact split of tasks is recorded in writing at the start.

What moves to us
  • Password resets, account changes and the daily ticket queue
  • The patch cycle across devices, servers and network equipment
  • Holiday, sickness and out-of-hours cover for the routine work
  • Backup monitoring and the restore tests nobody gets round to
  • First line for every site, including the small ones

The work that has to happen every week whether or not anyone has time for it.

What stays with you
  • Architecture, standards and what the estate should look like
  • The vendor and licence relationships, and the budget
  • Which projects happen, in what order, and what they are worth
  • Approval of changes that affect the business, not only the system
  • The relationship with your own users and your own board

You keep the decisions on architecture, budget and priorities.

Transition

Moving to our service

The transition runs in five steps. The plan assumes an incumbent supplier who does not cooperate, so that the transition also holds when that cooperation does not materialise.

01

Discovery

In the first two to three weeks we map the systems, users, suppliers, access rights, open problems and existing documentation. Where your incumbent supplier cooperates, this goes faster.

02

Documentation and access

We check that the technical documentation, administrator rights, contracts and escalation details needed are available and usable. Anything that exists only in one head gets written down at this stage.

03

Tooling

We set up our management and reporting tooling alongside the existing environment and test the important access paths before taking work over. Administrator accounts get multi-factor authentication before they are used for anything.

04

Parallel running

For an agreed period we work alongside the existing team or the current supplier. Missing information and exceptions can be dealt with in that time.

05

Handover and review

After the handover we go through all open points and responsibilities. About thirty days later there is a first review based on the first service report.

For a single-country organisation with a few hundred users a full transition usually takes six to ten weeks. We set a firm plan after discovery.

Frequently asked

Questions and answers

Do we have to replace our current IT supplier?

Not always. We can take over a defined part of the management, or work alongside the existing supplier.

The split of duties and the escalation then have to be recorded clearly, including who holds the administrator accounts and who is called outside office hours. Where a split arrangement goes wrong, nobody owned the space between two contracts.

Where is the work carried out?

The client relationship, your service lead, the reviews, the escalations and the contract are handled from Amsterdam. The service desk and engineering work from our delivery centers in Sofia, Varna and Stara Zagora.

That is inside the European Union, under the same GDPR regime, and delivered under the certified management systems of our parent organisation. On-site work is carried out where that is included in the agreement.

Think Smart Europe is new. Why would we hand it our IT?

Because the Dutch company is new and the engineering organisation behind it is not. Think Smart Europe was formed as a joint venture between its Dutch founders and Think Smart in Bulgaria, which has been registered since December 2019, runs managed services today, and holds the ISO management systems and the vendor partnerships.

So you contract with a Dutch company, and the delivery capacity is not being built from scratch while you wait. Ask us for references in the intake call.

Is security monitoring included?

Not as standard. Managed Security and SOC is a separate service that can be taken alongside day-to-day IT management.

Where the same team handles both the management and the monitoring, the evidence lines up. Where those sit with two parties, the contract has to record who is responsible for the handover between them.

What are the service hours, and which languages do you support?

Service hours, supported languages, response times and arrangements for on-site support are set per agreement.

Infrastructure monitoring runs around the clock. User support outside office hours and attendance on site are quoted separately.

Discuss which management tasks you want to hand over

We map the current service, the responsibilities and the main problem areas. You then receive a proposal covering the scope, the transition approach and the management costs.

Cyber Incident