NIS2 checkContact

Implementation and partnerships

We build and run your security platform

We design, implement and migrate security and infrastructure solutions from Microsoft, Google, Cisco, Fortinet, Check Point and IBM. After go-live we can continue to provide the day-to-day operation, the monitoring, updates, licence reconciliation and reporting. We agree in advance what falls inside the project and which work remains necessary afterwards.

We implement and operate solutions from the vendors you already use.

MicrosoftGoogleCiscoFortinetCheck PointIBM

After delivery

Operation after handover

A security platform keeps changing after go-live. New devices, users and sites have to be added. Temporary exceptions have to be reviewed, and versions, licences and detection rules have to be kept current.

New systems have to be connected

New laptops, servers, accounts and sites only fall under the protection once they have been added to the platform. We therefore check periodically whether the registered estate matches the actual estate.

Temporary exceptions have to be closed

Temporary firewall rules, access rights and policy exceptions sometimes stay active longer than intended. We record the reason, the owner and the end date, and check whether the exception is still needed.

Detection rules have to be tuned

A large volume of unusable alerts makes assessment harder. Detection rules and thresholds are therefore adjusted after go-live on the basis of normal usage and what incidents show.

Licences have to match usage

We check whether licences are still assigned to the right users and systems, and whether the features you pay for have actually been configured.

Versions and integrations have to be maintained

Firewalls, agents, connectors and identity components each change at their own pace. We plan updates, test significant changes and check that integrations keep working.

The delivery has to be recorded

Reporting on coverage, changes, updates, incidents and checks is built up during operation. The behaviour of the platform then does not have to be reconstructed afterwards.

We therefore establish in advance who is responsible after implementation for day-to-day operation, changes, updates, monitoring and reporting.

How a rollout runs

Five phases

The approach is comparable whether we migrate a firewall estate, move to Entra ID or onboard log sources into a SIEM. The size and the lead time differ per environment.

01

Design

We survey the existing environment, including identity sources, sites, circuits, licences, systems and known exceptions. The design is based on the actual setup. Differences between the existing documentation and the current situation are recorded.

02

Test in your own environment

Where it is useful, we test the platform on a limited part of your own environment. That shows how the solution works together with existing identities, network traffic, applications and operational processes. The results feed into the design and the final proposal.

03

Proposal

You receive one proposal covering the scope, the licences, the equipment, the migration windows, the planning, the operational arrangements, the responsibilities and the assumptions. Items that can only be priced after further investigation are named as such.

04

Implementation and integration

We carry out the migration in manageable steps. For each step we record how to roll back if a problem occurs. The platform is connected to the existing identity environment, service desk, ticketing and monitoring as far as that falls within the scope.

05

Operation and monitoring

After go-live we provide the agreed monitoring, tuning, updates, version management, licence reconciliation and reporting. Where SOC monitoring is part of the engagement, the platform is onboarded during the implementation.

A final schedule is only possible once the environment and its dependencies have been assessed. The expected lead time is set out in the proposal.

Scope

What we build for you

The middle column is a project. The right-hand column is a service with a monthly cost attached. Both are quoted separately, so you can see which of the two you are buying.

Platform areas, implementation scope and ongoing operation
Platform areaWhat we implementWhat we then run
Identity and accessEntra ID or Google Workspace identity, multi-factor and conditional access, privileged access management, and a joiner-mover-leaver process wired into your HR sourcePolicy review, access recertification, break-glass account testing and exception reporting each quarter
Endpoint and emailEDR agent deployment, hardened baselines, patch rings, mail filtering and impersonation protectionAgent coverage checked against your actual asset list, patching on an agreed cadence, and detection tuning
Network and edgeFortinet and Check Point firewalls, segmentation, remote access, SD-WAN, Cisco switching and wirelessRule base review, firmware currency, certificate renewals, and change control that records why each rule exists
Detection and responseSIEM and XDR onboarding, log source integration, correlation rules and response playbooks24/7 monitoring, triage, use case development, and the 15-minute response commitment on priority alerts
Cloud and data platformMicrosoft 365, Azure and Google Cloud landing zones, tenant hardening and data loss preventionConfiguration drift detection, secure configuration reporting, and review of new tenant features before they are switched on
Backup and continuityImmutable backup, replication, and a documented recovery time and recovery point per systemRestore tests on a schedule rather than on request, failover exercises, and retention review
Licensing and procurementHardware, licences and subscriptions at partner terms, or the same work inside an agreement you already holdA renewal calendar, reconciliation of licences against actual use, and right-sizing at each renewal date

The vendor partnerships are held within our group. On request we state which legal entity holds the partnership and the relevant certification.

How to contract it

Your contract form

The choice determines who is responsible for operating the platform after go-live. We record that in advance.

Project with handover
  • Scope fixed at signature, against the estate as it was surveyed
  • Success measured on the day the last user is migrated
  • Your team takes the console, the policies and the backlog on day one
  • Anything found later becomes a change request or an internal ticket

This form suits an organisation with a clear internal owner who has enough time and knowledge to operate the platform.

Project with continuing operation
  • The same design, the same migration and the same go-live date
  • We keep the tuning, the version upgrades and the licence reconciliation
  • Coverage, exceptions and licence use reported on a fixed cadence
  • The engineers who built it are the ones you reach in month nine

This form carries a monthly operating cost and suits an organisation whose own team cannot carry out this work on a structural basis.

Handover

Your operating model

These are contract forms rather than product tiers. The difference lies in the capacity available inside your own team. Moving between them later is a scoping exercise, not a migration.

01

Full handover to your team

We implement and document the platform, train the appointed administrators and hand the operation over in full. You receive the runbooks, the design decisions and an explanation of the configuration.

This form requires a named owner with enough time and knowledge, so that the platform does not stall when one person leaves.

02

Joint operation

Your team carries out the day-to-day work. We provide the agreed specialist tasks, major changes, version upgrades, escalations and periodic reviews.

The division of work is recorded in writing. Where that division is vague, both parties assume the other is watching.

03

Fully operated by us

We carry out the day-to-day operation under an SLA and at an agreed reporting frequency. Where SOC monitoring is part of the engagement, the platform is onboarded onto it.

Your organisation remains responsible for business decisions and for approving significant changes. This form carries a monthly cost.

We advise which model fits your organisation. Full operation by us is not needed in every situation.

Supply chain

For your supplier assessment

Article 21(2)(d) of NIS2 makes an organisation in scope responsible for the security of its direct suppliers. As an implementation or operations supplier we may hold access to important systems. We therefore hand over at the start the information you need for your supplier assessment.

What a supplier assessment asks about us, and what we hand over
What you are asked to assessWhat we give you
Certified management systemsThe ISO certificates the delivery organisation works under, ISO 9001, ISO/IEC 20000-1, ISO 27001 and ISO 27701, with the scope statement and the holding entity for each, so a buyer can verify them rather than believe them.
Where the work happens, and who does itClient-facing delivery from Amsterdam, engineering and monitoring from our centers in Sofia, Varna and Stara Zagora. All of it inside the European Union, under one management system, with named engineers on your account.
Access and privilegeWhich accounts we hold in your environment, at what privilege level, how each one is approved and reviewed, and how it is removed on the day one of our engineers leaves your account.
Data location and sub-processorsWhere your configuration data and your logs are stored and processed, a list of any sub-processor involved, and the data processing agreement that covers it.
Incident notificationA written commitment on how quickly we tell you when something on our side touches your environment, measured in hours and not deferred to the next service review.
Continuity of the engagementA named lead engineer and a named deputy, runbooks held in your environment as well as ours, and exit terms stating what you get back and in what format.
Questionnaire and audit supportPrepared answers to the standard security questionnaires, and someone who will join the call with your customer's auditor rather than sending a document and hoping.

Where a certificate or a partnership is held by our parent organisation rather than by Think Smart Europe B.V., the answer says so. A supplier assessment fails faster on an overstated claim than on a missing one.

Frequently asked

Frequently asked questions

Can you implement something we have already bought?

Yes, and it is a common starting point. Licences get bought in a renewal negotiation and then sit unused for a year.

One warning. The licence you hold does not always include the feature the design needs. Conditional access, data loss prevention and advanced hunting sit above the tier organisations assume they are on. We check during the design and say so before the offer.

We already have an IT partner. Does this replace them?

Usually not. Your existing partner keeps the workplace and the service desk, and we implement and then operate the security platform alongside them.

The boundary is settled in writing. Who holds administrative access, who approves a change to a firewall rule or a conditional access policy, and who is called at two in the morning. Where this goes wrong it is almost never technical; nobody owned the gap between two contracts.

Why do the engineers work from Bulgaria?

Bulgaria is a member of the European Union. Our delivery centers in Sofia, Varna and Stara Zagora work under the management systems named within the group. The time difference with Amsterdam is one hour.

Where your procurement policy requires that all administrative access is held solely by staff in the Netherlands, our service does not meet that requirement. We would rather establish that in the first conversation.

Think Smart Europe is new. Who is actually doing the work?

Think Smart Europe was formed as a joint venture between Dutch founders and Think Smart in Bulgaria. The Bulgarian organisation was registered on 19 December 2019 and holds the ISO certifications, the vendor partnerships and the engineering depth.

The Dutch company is new. The delivery organisation behind it is not.

Do you also supply hardware and licences?

Yes. Hardware, licences and subscriptions can be supplied under the same agreement as the implementation.

Where your existing agreement is cheaper or more practical, we can carry out the implementation inside it. If you hold an enterprise agreement that already prices something at the same level, moving it only creates paperwork.

How long does an implementation take?

It depends on the estate rather than on the platform.

What drives the answer is the number of sites and identity sources, the quality of the documentation, existing exceptions, legacy integrations and the amount of change the organisation can absorb. The schedule is set out in the proposal, after the design and any test.

Discuss your platform with us

In the call we map which platform you want to implement, which systems are already in place and which dependencies have to be investigated first. You then receive a proposal setting out the scope, the approach, the planning, the responsibilities and the costs.

Cyber Incident