NIS2 checkContact

Managed CISO

Your named CISO, two days a month

You get a named CISO in the Netherlands and an appointed deputy. The standard commitment is sixteen planned hours a month. The service is intended for organisations that need continuing leadership on cyber security but do not want, or cannot appoint, a full-time CISO.

1named CISO with a named deputy
2 x 8hours a month planned in advance
90 daysto your first board report
24 / 72 / 30the reporting clock your CISO runs

The offer

Continuing support without a full-time appointment

The managed CISO works on a fixed monthly arrangement. The standard is two days a month, usually one day on site and one day remote. The days are planned in advance for the quarter.

The quarterly plan can be extended temporarily for, say, a certification, expansion into a new country or an acquisition. When the extra commitment is no longer needed, it is scaled back.

The service suits an organisation that has to show a board, a regulator, an insurer or a customer who owns security.

Sixteen hours a month is intended to lead the security programme, prepare decisions and oversee delivery. Technical implementation and day-to-day operation do not automatically fall within it.

What the CISO does

The work your CISO does

The priorities are set with you each quarter. The standing work consists of the following parts.

Security plan and risk register

The CISO draws up the security plan, keeps the risk register current and oversees the delivery plan. Every action gets an owner, a priority and a date.

Reporting to board and management

The CISO prepares monthly management information and periodic board reporting, covering the main risks, incidents, decisions and open measures in plain language. Article 20 of the NIS2 directive asks your management body to approve and supervise the measures.

Compliance and evidence

The CISO guides registration under the Cyberbeveiligingswet, the evidence files, the interaction with the GDPR and DORA, and security questions from customers, insurers and auditors.

Supplier risks

The CISO maintains the supplier register, guides security assessments and helps with security and reporting clauses in contracts. Critical suppliers are named separately.

Lead during serious incidents

In a serious incident the CISO coordinates the decision-making, the timeline, the reporting deadlines and the communication with the board, the regulator and customers. The SOC provides the technical assessment and response.

Exercises and periodic review

The CISO runs crisis exercises with the management team, guides phishing tests and reviews periodically whether the security plan still matches the organisation and the technical environment.

The six parts do not change. The order does, and the first quarter is usually spent on whichever of them is currently nobody's job.

The rhythm

How the two days are spent

The sixteen hours are divided the same way month after month.

A standard month with a Think Smart Europe managed CISO
WhenWhat happensWhat comes out of it
Day one, on siteSteering meeting with your IT lead. Risk, the roadmap and the open actions. A walkthrough per country and per entity. A board update in the months you ask for one.An updated action list with owners and dates, and decisions taken rather than deferred to the next meeting.
Day two, working the actionsPolicies, standards and the evidence files. Registration and compliance work. Supplier reviews and acquisition due diligence. The monthly report.Documents that exist, filed where they can be shown to auditor, insurer or customer on request.
Between the two daysReachable by phone and email. Escalation straight into the 24/7 SOC. Takes the lead if a major incident starts. Extra hours only where you have approved them first.No waiting for the next scheduled day when something is urgent, and no invoice you did not see coming.

Two days is the standard commitment. Where you are running a certification programme, entering a new country or absorbing an acquisition, the quarterly plan is raised for that period and lowered again when it is over. Extra hours are only worked once you have approved them.

The difference

One name, not a rotating pool

With separate advisory engagements, a new consultant often has to work their way into the organisation, the systems and the earlier decisions again. A managed CISO works with the same organisational context every month and builds on the previous reports.

Advice bought by the hour
  • A different consultant on the next engagement
  • Findings handed over, and the work handed back to you
  • Nobody who knows your entities on the day something goes wrong
  • The reporting clock starting before anyone is briefed

Every engagement opens with a fortnight of explaining your own estate to someone new.

A managed CISO on retainer
  • The same person every month, and a deputy who also knows you
  • The plan is written, and then it is carried out
  • Escalation into a SOC that already holds your context
  • A board report that carries forward from the last one

A single accountable partner, from the risk register through to the incident.

Scope

What the retainer covers

The right-hand column is there because a managed CISO is regularly assumed to include those parts. The scope is therefore agreed in writing in advance.

Managed CISO scope, per month
Included in the sixteen hoursOffered separatelyNot included
Two planned days a month, on site and remoteAudits, penetration tests and extensive assessmentsLegal advice or legal sign-off
The security plan and the risk registerImplementation projects and security toolingThe statutory accountability of your board
Support with registration and the evidence filesSmartCyber and other managed servicesDay-to-day IT administration and user support
Reporting for the board and managementExtra days for an acquisition or another temporary programmeFormal filing without your approval
Lead during serious incidents, together with the SOCAdditional technical or organisational workNot included

Work outside the fixed monthly commitment is offered in advance. You decide whether Think Smart Europe, your own team or another party carries it out.

The first 90 days

Your first ninety days

The first ninety days follow a fixed plan.

01

Week 1: introductions and the quarterly plan

The CISO meets the board, the IT lead and the other people involved. The scope and the priorities for the first quarter are agreed in writing.

02

Week 2: inventory

We map the technical environment, the legal entities, the countries, the existing controls and the key suppliers. Most groups find at least one entity that nobody had counted.

03

Week 4: escalation procedure tested

Contact lists, escalation paths and the connection to the 24/7 SOC are set up and tested, so an incident in month two is not the first time anyone dials the number.

04

Week 6: registration and first analysis

The required registrations and the status of the ten NIS2 measures are mapped. Missing controls and missing evidence are recorded separately, because they do not cost the same to close.

05

Week 10: delivery plan

Findings are turned into actions with an owner, a date, a priority and a cost estimate. Your organisation decides which actions are carried out and which risks are knowingly accepted.

06

Day 90: first board report

The board receives a report on the current position, the main risks, the open measures and the agreed plan, in a form it can discuss, approve and minute.

On day 90 the role has an owner, the board knows where it stands and the work has a sequence.

Frequently asked

Frequently asked questions

Is two days a month enough?

For leading and overseeing the security programme, under the current arrangement it usually is.

Sixteen hours is enough to own the plan, keep the risk register current, prepare the board, run the supplier reviews and lead an incident. It is not enough for the same person to also carry out all the technical implementation and day-to-day operational work. That work sits with your own team, our managed services or another supplier.

What happens during absence or departure?

A named deputy is appointed from the first month. That deputy is involved enough to know the main organisational context and arrangements, and escalation runs into the 24/7 SOC, which holds the same context.

On departure, the deputy can take over the role. The handover is then between two people you already know.

How do you handle advice about your own services?

Where the CISO recommends work that Think Smart Europe can supply itself, it is recorded as a separate recommendation with the costs and the alternatives. You are free to place the work elsewhere. The fixed monthly arrangement does not change because of it.

For an independent audit, penetration test or review of our own work, we advise using another party. Your CISO will say the same thing.

Does a managed CISO replace our IT supplier?

No. The CISO sits above the day-to-day IT service and oversees the coherence, the responsibilities and the evidence. Your current supplier can keep carrying out the existing work.

What changes is that someone is accountable for the gaps between contracts: the questions that fall between the party running your endpoints, the party running your network and the party running your cloud. That is where the evidence is usually missing.

Where is the work carried out?

The named CISO works from the Netherlands and can come to your site. The deputy, the SOC analysts and the 24-hour monitoring work from our delivery centers in Sofia, Varna and Stara Zagora.

That is nearshore and inside the European Union, under the same GDPR regime and delivered under the certified management systems of our parent organisation in Bulgaria. One contract, a single accountable partner, and you are welcome to visit the delivery center before you sign anything.

Think Smart Europe is new. Why would we put the CISO role there?

Because the Dutch company is new and the engineering organisation behind it is not. Think Smart Europe is a joint venture between Dutch founders and Think Smart in Bulgaria, which has been registered since December 2019, employs around forty people and holds the certifications and the vendor partnerships.

And you are not buying a company age but a named person, whom you can meet and question before you sign.

Does a managed CISO satisfy Article 20?

Not on its own, and no supplier can. Article 20 puts approval and supervision of the measures on your management body and that duty cannot be delegated or bought in.

What a managed CISO does is put the board in a position to carry it. The measures are written down, the decisions are prepared, the training is arranged and the approval is recorded. The duty stays with your board, and the preparation for it stops being something they have to organise themselves.

Discuss your situation with our CISO

In the call we discuss your organisation, your obligations, your existing suppliers and the subjects that currently have no clear owner. You then receive a proposal for the monthly commitment and the first ninety days.

Cyber Incident