Discovery
In the first two to three weeks we map the systems, users, suppliers, access rights, open problems and existing documentation. Where your incumbent supplier cooperates, this goes faster.
One directive, twenty-seven national laws, and what they ask of you.
Five levels, from the basics in order to group-wide defence.
Every required measure, and the service that delivers it.
Detection and response from our European SOC.
Devices, cloud and support, run as one service.
NIS2, DORA and GDPR in one assessment.
Vendor platforms, rolled out and then run.
One named CISO, two days a month.
Direct help, and your report filed on time.
You leave the call with a prioritised list of your gaps and a price indication for closing them. Free and without obligation.
Plan the callWho we are and how we are set up.
Amsterdam, Sofia, Varna and Stara Zagora.
The platforms we implement and operate.
What the work looks like in practice.
The client team in Amsterdam, the engineering in Bulgaria, everything inside the EU. One contract, under Dutch law.
How we deliverIT managed services
We run the day-to-day work so that your own people are not the only ones who can. Service desk, laptops and mobile devices, firewalls and switches, servers, Microsoft 365 and cloud workloads, and the identity setup underneath all of it. This is the least interesting part of the contract and the part that decides whether the rest of it holds.
The scope
Below is what a full managed service covers. You can take part of it, endpoints only, or cloud only, and plenty of organisations start that way. Where the boundary sits gets written into the contract, because an unwritten boundary is where work quietly stops.
One point of contact for every user, in every country you operate in. Phone, mail and portal arrive in the same queue, so the same problem raised three ways is still one ticket with one owner.
Imaging, enrolment, configuration baselines, patching and software distribution for laptops, desktops and mobile devices. Devices that fall outside the baseline are reported rather than quietly tolerated.
Firewalls, switches, routers and wireless across offices, branches and production sites. Rule changes, firmware, configuration backups, and a record of who asked for a change and who approved it.
On-premises servers, Microsoft 365 and public cloud workloads. Capacity, patching, licence hygiene, backup and, the part that counts, restores that have actually been tested.
We manage multi-factor authentication, conditional access, privileged accounts and the technical steps around joining, changing role and leaving. Those changes are made on the basis of timely and approved information from HR and line managers.
Security monitoring and incident response fall under Managed Security and SOC. That service can be set up on top of our day-to-day management, but equally on top of an IT estate run by your own team or another supplier.
The service desk
Users reach one service desk, whichever country they sit in. English is the standard working language. Other languages are offered only where that is set out in the agreement.
Calls, emails and portal tickets all land in the same queue. Every ticket gets a priority, an owner and a next action.
First line handles standard questions and faults. More complex tickets are passed to second or third line inside the same organisation.
The monthly report shows how many tickets came in, how long they took to handle and which problems keep coming back.
Compliance
Day-to-day IT management supports several of the NIS2 measures. Among other things it produces records of updates, restore tests, account changes, approved changes and completed checks.
Several of the ten measures in Article 21(2) of the NIS2 directive are delivered mostly by ordinary IT operations rather than by security tooling.
Run as a managed service, each of these leaves evidence behind as a by-product: patch age per device, restore tests with dates on them, accounts closed against the leaving date HR recorded. That is the difference between believing your patching is current and being able to show it on the day somebody asks.
This information can be used for audits, supplier assessments, insurance questions and supervision. A managed IT contract does not, however, make you compliant with the Cyberbeveiligingswet. Matters such as classification, board responsibility, incident reporting and supplier risk have to be assessed separately.
Included
The middle column describes the work. The right-hand column describes what comes back in your monthly report.
| Service | What is included | What is measured |
|---|---|---|
| Service desk | Single point of contact by phone, mail and portal. Incident and request handling, first line resolution, escalation to second and third line. | Response and resolution against the agreed priority levels, ticket volume, backlog age, and the faults that keep recurring. |
| Endpoint management | Imaging, enrolment, configuration baselines, patching and software distribution for laptops, desktops and mobile devices. | Patch coverage and patch age per device, devices outside the baseline, and every exception with a reason and an owner. |
| Network and firewall | Firewalls, switches, routers and wireless across all sites. Rule changes, firmware maintenance and configuration backups. | Availability per site, firmware currency, and a change record showing who requested and who approved each rule. |
| Servers and cloud | On-premises servers, Microsoft 365 and public cloud workloads. Capacity, patching, licence hygiene, backup and restore. | Backup success rate, restore tests actually performed, and the agreed RTO and RPO per workload. |
| Identity and access | Multi-factor authentication, conditional access, privileged access management, and the joiner-mover-leaver process. | Accounts created and closed against the dates HR supplied, privileged accounts in use, and access reviews completed on schedule. |
| Reporting and review | A monthly service report and a review with your named service lead. | Trends rather than totals, the changes made, the risks accepted, and the decisions we need from you. |
Service hours, priority levels, response times, languages and on-site work are set per agreement.
What changes for your own team
We take over the agreed day-to-day work, such as the service desk, patching, technical checks, account management and restore tests. Your organisation stays responsible for architecture choices, budgets, business priorities, supplier contracts and decisions with a major impact on operations. The exact split of tasks is recorded in writing at the start.
The work that has to happen every week whether or not anyone has time for it.
You keep the decisions on architecture, budget and priorities.
Transition
The transition runs in five steps. The plan assumes an incumbent supplier who does not cooperate, so that the transition also holds when that cooperation does not materialise.
In the first two to three weeks we map the systems, users, suppliers, access rights, open problems and existing documentation. Where your incumbent supplier cooperates, this goes faster.
We check that the technical documentation, administrator rights, contracts and escalation details needed are available and usable. Anything that exists only in one head gets written down at this stage.
We set up our management and reporting tooling alongside the existing environment and test the important access paths before taking work over. Administrator accounts get multi-factor authentication before they are used for anything.
For an agreed period we work alongside the existing team or the current supplier. Missing information and exceptions can be dealt with in that time.
After the handover we go through all open points and responsibilities. About thirty days later there is a first review based on the first service report.
For a single-country organisation with a few hundred users a full transition usually takes six to ten weeks. We set a firm plan after discovery.
Frequently asked
Not always. We can take over a defined part of the management, or work alongside the existing supplier.
The split of duties and the escalation then have to be recorded clearly, including who holds the administrator accounts and who is called outside office hours. Where a split arrangement goes wrong, nobody owned the space between two contracts.
The client relationship, your service lead, the reviews, the escalations and the contract are handled from Amsterdam. The service desk and engineering work from our delivery centers in Sofia, Varna and Stara Zagora.
That is inside the European Union, under the same GDPR regime, and delivered under the certified management systems of our parent organisation. On-site work is carried out where that is included in the agreement.
Because the Dutch company is new and the engineering organisation behind it is not. Think Smart Europe was formed as a joint venture between its Dutch founders and Think Smart in Bulgaria, which has been registered since December 2019, runs managed services today, and holds the ISO management systems and the vendor partnerships.
So you contract with a Dutch company, and the delivery capacity is not being built from scratch while you wait. Ask us for references in the intake call.
Not as standard. Managed Security and SOC is a separate service that can be taken alongside day-to-day IT management.
Where the same team handles both the management and the monitoring, the evidence lines up. Where those sit with two parties, the contract has to record who is responsible for the handover between them.
Service hours, supported languages, response times and arrangements for on-site support are set per agreement.
Infrastructure monitoring runs around the clock. User support outside office hours and attendance on site are quoted separately.
We map the current service, the responsibilities and the main problem areas. You then receive a proposal covering the scope, the transition approach and the management costs.