Week 1: introductions and the quarterly plan
The CISO meets the board, the IT lead and the other people involved. The scope and the priorities for the first quarter are agreed in writing.
One directive, twenty-seven national laws, and what they ask of you.
Five levels, from the basics in order to group-wide defence.
Every required measure, and the service that delivers it.
Detection and response from our European SOC.
Devices, cloud and support, run as one service.
NIS2, DORA and GDPR in one assessment.
Vendor platforms, rolled out and then run.
One named CISO, two days a month.
Direct help, and your report filed on time.
You leave the call with a prioritised list of your gaps and a price indication for closing them. Free and without obligation.
Plan the callWho we are and how we are set up.
Amsterdam, Sofia, Varna and Stara Zagora.
The platforms we implement and operate.
What the work looks like in practice.
The client team in Amsterdam, the engineering in Bulgaria, everything inside the EU. One contract, under Dutch law.
How we deliverManaged CISO
You get a named CISO in the Netherlands and an appointed deputy. The standard commitment is sixteen planned hours a month. The service is intended for organisations that need continuing leadership on cyber security but do not want, or cannot appoint, a full-time CISO.
The offer
The managed CISO works on a fixed monthly arrangement. The standard is two days a month, usually one day on site and one day remote. The days are planned in advance for the quarter.
The quarterly plan can be extended temporarily for, say, a certification, expansion into a new country or an acquisition. When the extra commitment is no longer needed, it is scaled back.
The service suits an organisation that has to show a board, a regulator, an insurer or a customer who owns security.
Sixteen hours a month is intended to lead the security programme, prepare decisions and oversee delivery. Technical implementation and day-to-day operation do not automatically fall within it.
What the CISO does
The priorities are set with you each quarter. The standing work consists of the following parts.
The CISO draws up the security plan, keeps the risk register current and oversees the delivery plan. Every action gets an owner, a priority and a date.
The CISO prepares monthly management information and periodic board reporting, covering the main risks, incidents, decisions and open measures in plain language. Article 20 of the NIS2 directive asks your management body to approve and supervise the measures.
The CISO guides registration under the Cyberbeveiligingswet, the evidence files, the interaction with the GDPR and DORA, and security questions from customers, insurers and auditors.
The CISO maintains the supplier register, guides security assessments and helps with security and reporting clauses in contracts. Critical suppliers are named separately.
In a serious incident the CISO coordinates the decision-making, the timeline, the reporting deadlines and the communication with the board, the regulator and customers. The SOC provides the technical assessment and response.
The CISO runs crisis exercises with the management team, guides phishing tests and reviews periodically whether the security plan still matches the organisation and the technical environment.
The six parts do not change. The order does, and the first quarter is usually spent on whichever of them is currently nobody's job.
The rhythm
The sixteen hours are divided the same way month after month.
| When | What happens | What comes out of it |
|---|---|---|
| Day one, on site | Steering meeting with your IT lead. Risk, the roadmap and the open actions. A walkthrough per country and per entity. A board update in the months you ask for one. | An updated action list with owners and dates, and decisions taken rather than deferred to the next meeting. |
| Day two, working the actions | Policies, standards and the evidence files. Registration and compliance work. Supplier reviews and acquisition due diligence. The monthly report. | Documents that exist, filed where they can be shown to auditor, insurer or customer on request. |
| Between the two days | Reachable by phone and email. Escalation straight into the 24/7 SOC. Takes the lead if a major incident starts. Extra hours only where you have approved them first. | No waiting for the next scheduled day when something is urgent, and no invoice you did not see coming. |
Two days is the standard commitment. Where you are running a certification programme, entering a new country or absorbing an acquisition, the quarterly plan is raised for that period and lowered again when it is over. Extra hours are only worked once you have approved them.
The difference
With separate advisory engagements, a new consultant often has to work their way into the organisation, the systems and the earlier decisions again. A managed CISO works with the same organisational context every month and builds on the previous reports.
Every engagement opens with a fortnight of explaining your own estate to someone new.
A single accountable partner, from the risk register through to the incident.
Scope
The right-hand column is there because a managed CISO is regularly assumed to include those parts. The scope is therefore agreed in writing in advance.
| Included in the sixteen hours | Offered separately | Not included |
|---|---|---|
| Two planned days a month, on site and remote | Audits, penetration tests and extensive assessments | Legal advice or legal sign-off |
| The security plan and the risk register | Implementation projects and security tooling | The statutory accountability of your board |
| Support with registration and the evidence files | SmartCyber and other managed services | Day-to-day IT administration and user support |
| Reporting for the board and management | Extra days for an acquisition or another temporary programme | Formal filing without your approval |
| Lead during serious incidents, together with the SOC | Additional technical or organisational work | Not included |
Work outside the fixed monthly commitment is offered in advance. You decide whether Think Smart Europe, your own team or another party carries it out.
The first 90 days
The first ninety days follow a fixed plan.
The CISO meets the board, the IT lead and the other people involved. The scope and the priorities for the first quarter are agreed in writing.
We map the technical environment, the legal entities, the countries, the existing controls and the key suppliers. Most groups find at least one entity that nobody had counted.
Contact lists, escalation paths and the connection to the 24/7 SOC are set up and tested, so an incident in month two is not the first time anyone dials the number.
The required registrations and the status of the ten NIS2 measures are mapped. Missing controls and missing evidence are recorded separately, because they do not cost the same to close.
Findings are turned into actions with an owner, a date, a priority and a cost estimate. Your organisation decides which actions are carried out and which risks are knowingly accepted.
The board receives a report on the current position, the main risks, the open measures and the agreed plan, in a form it can discuss, approve and minute.
On day 90 the role has an owner, the board knows where it stands and the work has a sequence.
Frequently asked
For leading and overseeing the security programme, under the current arrangement it usually is.
Sixteen hours is enough to own the plan, keep the risk register current, prepare the board, run the supplier reviews and lead an incident. It is not enough for the same person to also carry out all the technical implementation and day-to-day operational work. That work sits with your own team, our managed services or another supplier.
A named deputy is appointed from the first month. That deputy is involved enough to know the main organisational context and arrangements, and escalation runs into the 24/7 SOC, which holds the same context.
On departure, the deputy can take over the role. The handover is then between two people you already know.
Where the CISO recommends work that Think Smart Europe can supply itself, it is recorded as a separate recommendation with the costs and the alternatives. You are free to place the work elsewhere. The fixed monthly arrangement does not change because of it.
For an independent audit, penetration test or review of our own work, we advise using another party. Your CISO will say the same thing.
No. The CISO sits above the day-to-day IT service and oversees the coherence, the responsibilities and the evidence. Your current supplier can keep carrying out the existing work.
What changes is that someone is accountable for the gaps between contracts: the questions that fall between the party running your endpoints, the party running your network and the party running your cloud. That is where the evidence is usually missing.
The named CISO works from the Netherlands and can come to your site. The deputy, the SOC analysts and the 24-hour monitoring work from our delivery centers in Sofia, Varna and Stara Zagora.
That is nearshore and inside the European Union, under the same GDPR regime and delivered under the certified management systems of our parent organisation in Bulgaria. One contract, a single accountable partner, and you are welcome to visit the delivery center before you sign anything.
Because the Dutch company is new and the engineering organisation behind it is not. Think Smart Europe is a joint venture between Dutch founders and Think Smart in Bulgaria, which has been registered since December 2019, employs around forty people and holds the certifications and the vendor partnerships.
And you are not buying a company age but a named person, whom you can meet and question before you sign.
Not on its own, and no supplier can. Article 20 puts approval and supervision of the measures on your management body and that duty cannot be delegated or bought in.
What a managed CISO does is put the board in a position to carry it. The measures are written down, the decisions are prepared, the training is arranged and the approval is recorded. The duty stays with your board, and the preparation for it stops being something they have to organise themselves.
In the call we discuss your organisation, your obligations, your existing suppliers and the subjects that currently have no clear owner. You then receive a proposal for the monthly commitment and the first ninety days.