1
a
Risk and security policies
A current risk assessment covering the main systems, data, threats and dependencies, with an owner, a priority and a planned measure per risk. An asset register, an overview of what you have under management, that is kept current, and security policies that match how the organisation is actually set up and actually works, aligned with ISO 27001.
Shared responsibility We draw up the assessment and the policies together with you. Your board decides which risks are acceptable and approves the policies.
Protect
2
b
Incident handling
Recognising, assessing, containing and reporting security incidents. Detection and response from our SOC, day and night, with SIEM and XDR underneath, rehearsed playbooks, and a response time on priority alerts set out in the SLA. For each type of incident it is recorded which actions the SOC may carry out immediately.
Think Smart Europe carries this out Our SOC handles detection, triage and the agreed response. Your organisation approves formal notifications and external communication.
Essential
3
c
Business continuity
Backups that cannot be altered or deleted, restore tests fixed in the calendar, and recovery objectives that were on paper before anyone needed them. For important processes we record in advance the recovery time required and the maximum data loss allowed.
Think Smart Europe carries this out We manage the agreed backups, restore tests and technical run books. The RTO and RPO, how long recovery may take and how much data you may lose in the process, are set together with you.
Essential
4
d
Supply chain security
Knowing which suppliers have access to systems, data or critical processes and what risks come with that: a maintained supplier register, security requirements in the contracts, and assessments with evidence behind them.
Shared responsibility We run the supplier register and the security assessments. Your organisation remains responsible for the commercial and legal arrangements with suppliers.
Advanced
5
e
System lifecycle
Acquiring, developing, configuring, updating and changing systems securely. Patching on an agreed rhythm, vulnerability scanning, hardened configurations and security testing that follows every system through its life. For software development we look at matters such as access rights, code management, testing and the handling of vulnerabilities found.
Think Smart Europe carries this out We run the agreed scans, updates and technical checks within the recorded remediation windows.
Protect
6
f
Effectiveness assessment
Assessing periodically whether the measures are carried out and have the intended effect: patch coverage, restore tests, follow-up on alerts, account management and vulnerabilities, reported on a fixed rhythm instead of one assessment gathering dust.
Think Smart Europe carries this out We collect and report the agreed data. The internal audit can be run by your organisation or by a separately appointed party.
Advanced
7
g
Cyber hygiene and training
Teaching staff how to recognise and report suspicious email, unusual requests and possible incidents. A structured awareness programme, phishing simulation with per-person completion records, and the training Article 20 obliges the management body itself to follow.
Think Smart Europe carries this out We run the agreed training programme and record attendance and results.
Essential
8
h
Cryptographic controls
Data encrypted where it sits and where it travels, certificates and keys managed across their full lifecycle, and a record of who has access, how keys are replaced and what happens when a key or a certificate expires.
We set it up; your organisation keeps ownership We set up the technical provisions for encryption and key management. Ownership and final control over the keys stay with your organisation.
Protect
9
i
HR security and access control
Access rights that match the role and are adjusted in time when someone changes role or leaves, with joiner, mover and leaver wired to HR, privileges reviewed against least privilege, meaning no more rights than someone needs, and administrator accounts managed separately and checked periodically.
Shared responsibility We run the technical measures and the access reviews. HR and line managers remain responsible for passing on and approving changes in time.
Advanced
10
j
Authentication and communications
Multi-factor authentication reduces the chance that a stolen password gives direct access. Strong sign-in wherever it matters, with conditional access on top, secured collaboration tools, and a separate communication channel for situations in which the normal email or collaboration environment cannot be relied on.
Think Smart Europe carries this out We set up and manage the agreed technical measures: strong sign-in, conditional access and the channel outside your own network (out-of-band).
Essential
The mapping to the SmartCyber levels is a first indication. During the intake we establish which measures fit the risks, the size and the technical environment of your organisation.