We publish no client names, logos, quotes or results without explicit written permission. There are therefore no general client stories and no anonymised success claims on this page. We do describe the kinds of engagement we carry out. When you are seriously considering working with us, we can on request introduce you to an existing client in a comparable sector or situation.
Your security is confidential and in safe hands with us
Information about security suppliers, the technology in use and internal working methods can be sensitive. We therefore publish nothing about a client without permission for that specific item.
Naming the company that runs your security tells anyone who is
interested which stack you are on, and gives a caller a plausible name
to use on your service desk. Our clients treat that as operational
information.
A client can give separate permission for the use of a name, a logo, a
quote or a result. Without that permission, the client stays off the
website.
We also do not publish anonymous success stories that a reader cannot
verify. Instead, we describe four kinds of engagement below and offer,
where possible, a direct reference conversation.
Four patterns
Security against cyber risks
The examples below do not describe individual clients. They show the situations organisations come to us with, what we then do, and the lead time that fits.
An international group without a named CISO
The situation: an organisation consists of several legal entities in different countries. Responsibility for security is spread across IT, finance, external advisers and the board. Nobody oversees the whole. What we do: a named CISO works two blocks of eight hours a month for the organisation, with a named deputy who sits in the same meetings. The first step is an overview per legal entity and country: which law applies, who is responsible, and through which route incidents have to be reported. A monthly review of risks and incidents and periodic reporting to the board follow.
The overview of entities and countries takes four to six weeks. The CISO service then continues on a monthly basis.
Managed CISO
NIS2 obligations in several countries
The situation: an organisation operates in several European countries and has treated NIS2 as one uniform arrangement. In practice each country has its own national law, supervisor, registration and reporting route. What we do: we carry out a classification scan per country and per legal entity, separating missing controls from controls that exist but cannot yet be evidenced. We can then prepare the registrations, implement the missing controls and record the reporting procedures per country.
The classification and first assessment take two to three weeks per country. The delivery can take several months, depending on which controls are missing.
Country programme
A supplier receiving security questions from a major customer
The situation: the organisation is probably not directly in scope for NIS2, but receives an extensive security questionnaire from a major customer. The response is tied to a contract renewal or a tender. It asks for an ISMS, an incident procedure, multi-factor authentication everywhere, and evidence that a backup has actually been restored. What we do: we first complete the questionnaire factually on the basis of the existing situation. Items for which no control or evidence is available are marked as open. We then draw up a delivery plan based on the weight the customer gives each item. The evidence built up can afterwards be used for other customers as well.
The first factual response can be completed within a few days. Making the improvements usually takes weeks and depends on what is missing.
Supply chain
A cyber incident at an organisation that is not yet a client
The situation: files are encrypted, an account is being misused, or other behaviour points to an active incident. The organisation has no agreement with us yet. What we do: we start the assessment during the first phone call. The first work is aimed at limiting the damage, preserving information and recording the timeline: isolating machines without powering them down, establishing what was reached, and opening the incident record. Where a reporting duty may apply, we collect the information for the first notification and the reports that follow. After the incident, part of the security required can be set up as a managed service.
Response starts on the call. For a reportable NIS2 incident, reporting moments then apply at 24 hours, 72 hours and one month.
Incident
These descriptions are examples of kinds of engagement and not accounts of individual clients. Detail about a specific organisation, how the engagement ran and the parts that went less well is discussed only in a reference conversation and with that client's permission.
What all four have in common
From assessment to day-to-day management
Depending on the existing situation, an engagement can consist of five stages, with one organisation accountable across all of them, including the step where a report and a roadmap normally change hands.
The five stages of a Think Smart Europe engagement, and who owns each one afterwards
Stage
What happens
What you get
Who owns it afterwards
Assess
We establish per entity and per country which obligations apply, and test the existing controls and evidence against the ten Article 21(2) measures.
A classification per country and a delivery plan with priorities.
Think Smart Europe can carry out the plan.
Remediate
Missing controls are put in place: multi-factor authentication, privileged account management, immutable backup, logging and patch management.
Working controls with recorded responsibilities.
Think Smart Europe or your existing team, according to the agreed division of work.
Implement
The required platforms and integrations are rolled out in your estate: endpoint and EDR, SIEM, identity, network, backup and recovery.
A configured technical solution and the accompanying documentation.
Think Smart Europe or your own operations organisation.
Operate
Recurring work is carried out: service desk, endpoints, updates, account management and restore tests.
One agreed way of working, one SLA and one report.
The party named as owner in the agreement.
Monitor
The SOC assesses security alerts and the delivery is reported on periodically.
Information for the board, audits, insurers, customers and supervisors.
Think Smart Europe carries out the agreed monitoring. Your board remains responsible for formal decisions, because Article 20 does not let it delegate that.
Not every organisation needs all five stages. Existing controls that work well are assessed and recorded instead of rebuilt, and where an incumbent provider runs something well we will say so.
References
A conversation rather than a logo
A written client story is selected and edited by the supplier. It usually tells you little about delays, setbacks or the difference between the estimate and the final cost.
A written case study
Approved by two marketing departments before anyone published it
A percentage with no baseline underneath it
The parts that went wrong removed, because nobody publishes those
No way for you to check that the organisation in it exists
Cheap to produce, and read as evidence by almost nobody.
A reference conversation
A named person at an organisation in your sector, on a call you run
Any question you like, including what we got wrong and what it cost
We are not on the call and we do not ask for a summary afterwards
Arranged in about two weeks, because we have to ask them first
Slower, and the only version we would believe ourselves.
How to ask
Requesting a reference
In a reference conversation you speak directly to a client in a comparable situation. You decide which questions you ask. Arranging such a call takes about two weeks, because the client concerned has to agree first.
01
Describe what you want to assess
Give your sector, the rough size of your organisation and the subject you want to discuss with an existing client. That could be the cooperation between Amsterdam and Bulgaria, the use of the Managed CISO or how incident response ran. A general request produces a general call.
02
We ask a suitable client for permission
We approach one or two organisations that fit your situation. We tell them who is asking and why. The client can decline. Where no suitable client is available or nobody wants to take part, we say so. We do not offer a less relevant reference as a substitute.
03
You speak to the client directly
The introduction goes out by email. Think Smart Europe does not take part in the call and does not ask for a report afterwards.
04
You ask your own questions
You can ask what went less well, what caused delay, how the final invoice compared with the estimate and whether the client would choose the same service again. Any of those points can be put to us afterwards.
We arrange reference conversations for organisations that are genuinely assessing our service. That limits the demand on clients who give up their time for the call voluntarily.
Frequently asked
Frequently asked questions
Why is there no client list here?
We do not have general permission to publish client names and logos.
Without specific written permission we do not do so.
Our clients treat their choice of security supplier as operational
information. That is a reasonable position, and we do not talk them
out of it for a logo wall.
Named references are available on request and with the permission of
the client concerned.
Who carried out the work described here?
Both halves, and it is worth being precise about which half does
what.
Think Smart Europe is a joint venture of Dutch founders and Think
Smart in Bulgaria. The Bulgarian organisation was registered on
19 December 2019, employs around forty people, holds the ISO
certifications and the vendor partnerships, and provides the
engineering and monitoring capacity.
The Dutch organisation provides the CISO work, the compliance
advisory, the agreement and accountability for the engagement.
Where is the work carried out?
In Amsterdam and in Bulgaria.
The client team, the CISO and the agreement sit at Vijzelstraat 68 in
Amsterdam. Engineering, the service desk and the 24-hour monitoring
are carried out from Sofia, Varna and Stara Zagora. All locations are
inside the European Union, under one GDPR regime and the certified
management systems of our parent organisation.
Put that question to a reference directly as well.
Can our current IT supplier stay involved?
Yes. Three of the four kinds of engagement commonly start that way.
A Managed CISO, an assessment across several countries or support with
customer questions can be set up alongside an existing IT provider.
Work that is already being done well does not have to be replaced.
Responsibility for the missing controls and evidence does have to be
recorded clearly. The question that matters is who produces the
evidence when a supervisor, an insurer or a customer asks for it. Have
that conversation before anyone asks.
Will we be named as a client later?
Only with written permission for the specific use. Permission for a
name, a logo, a quote and a result is handled separately and can be
withdrawn.
Without permission your organisation stays out of our public
communication. That is the default, and nobody asks you a second time.
Can we receive a written example in advance?
Yes. We can send a short description of a comparable engagement,
without identifying detail, which is useful when a business case needs
a paragraph.
That document is background information rather than independent proof
of our performance. We do not publish it.
Speak to one of our clients
Tell us your sector, the rough size of your organisation and the question you want to discuss. Where we have a suitable client who agrees, we will introduce you directly. Where no suitable reference is available, we will say so.