Scoping
Targets, test windows and contacts are agreed in writing. The public address ranges are confirmed, the authorisation letter is signed by both parties and the escalation route for critical findings is in place before the first packet is sent.
One directive, twenty-seven national laws, and what they ask of you.
Five levels, from the basics in place to group-wide defence.
Every required measure, and the service that delivers it.
Detection and response from our European SOC.
Your perimeter and your people, tested from outside.
Devices, cloud and support, run as one service.
NIS2, DORA and GDPR in one assessment.
Vendor platforms, rolled out and then run.
One named CISO, two days a month.
Direct help, and your report filed on time.
You leave the call with a prioritised list of your gaps and a price indication for closing them. Free and without obligation.
Plan the callWho we are and how we are set up.
Amsterdam, Sofia, Varna and Stara Zagora.
The platforms we implement and operate.
What the work looks like in practice.
The client team in Amsterdam, the engineering in Bulgaria, everything inside the EU. One contract, under Dutch law.
How we deliverPenetration testing and phishing
A black box penetration test of your internet-facing infrastructure, and a phishing campaign aimed at your staff. Our testers start with nothing but your name and the address ranges you confirm in writing. The result shows what an outsider can actually reach, and what happens when an outsider emails your staff.
The approach
A black box test starts from the position of a real external attacker. We receive no internal documentation, no credentials and no architecture diagrams. What we do receive is a written confirmation of the public address ranges and domains in scope, and an authorisation letter signed by both parties. Nothing outside the agreed scope is touched.
The testing is carried out by certified testers from our delivery centres in Sofia, Varna and Stara Zagora, under the same certified management systems as the rest of our services. You contract with Think Smart Europe B.V. in Amsterdam. Critical findings are escalated on the day they are confirmed, not at the end of the engagement, and the same testers stay on from the first scan to the retest.
Coverage
Twelve standard activities, grouped into six areas. Every finding is rated with CVSS and tied to a named asset, so your IT team knows what to fix first.
Routers, switches, firewalls and intrusion detection and prevention devices, and the rules that hold them together.
VPN endpoints, exposed management interfaces and the password resilience of every login reachable from the internet.
Web, mail, DNS and DHCP services, with service fingerprinting and the version information they give away.
Reachable hosts and services checked against known issues, then verified by hand, so the report contains confirmed findings rather than scanner output.
TLS configuration, certificate management and the use of weak ciphers or outdated protocols on every reachable service.
Spoofing, poisoning and protocol weaknesses, inside the agreed boundary only.
Testing follows OWASP guidance and NIST SP 800-115. Connections to group IT and the segregation from the wider estate are tested at the boundary only.
Method
Five stages, in a fixed order. You know at every moment which stage the test is in and what it produces.
Targets, test windows and contacts are agreed in writing. The public address ranges are confirmed, the authorisation letter is signed by both parties and the escalation route for critical findings is in place before the first packet is sent.
Passive discovery from public sources. What your organisation exposes about itself before anyone has touched your systems.
Port, service and version mapping across the confirmed ranges, so every reachable service is known by name and version.
Controlled attempts on the findings, to establish what is actually reachable rather than what a scanner suggests might be. Critical findings are escalated immediately.
An executive summary for the board and a technical report for IT, followed by a walkthrough with your team.
We work from the agreed scope only. No internal documentation, no credentials and no architecture detail, so the result reflects what a real external attacker can actually reach.
What the campaign measures
The phishing campaign is a separate test with its own report. No email addresses are handed over: the testers build the recipient list from public sources, the way an outsider would. Six measures come out of one campaign, reported by team and never by named employee, so the outcome serves the awareness programme rather than blame.
How many messages reached a mailbox, and how many were opened where that can be measured.
Who followed the link, as a share of the messages actually delivered to the target group.
Who entered details on the simulated page. Nothing entered there is kept or reused.
Who recognised the message and raised it through the normal internal reporting route. This is the figure you want to see rise.
Who went beyond the first interaction. This gives the overall exposure figure per site or per organisation.
Figures per department or group, so awareness effort can be aimed where it does most good.
No malware is deployed, no service is disrupted and no employee account is accessed. Anything entered on the simulated page is neither kept nor reused.
Deliverables
Every engagement ends with the same set of documents, written for different audiences.
| Deliverable | What it contains | Who it is for |
|---|---|---|
| Executive summary | The overall risk position, the most important findings and the recommended order of remediation, in plain language. | Board, management and audit committee |
| Technical report | Every finding with its CVSS score, the affected asset, the evidence, the steps to reproduce it and a concrete recommendation. | IT and security team |
| Phishing analysis | The six measures per team, anonymised examples and advice for the awareness programme. | IT, HR and whoever runs awareness training |
| Walkthrough | A session with your team to go through the findings, answer questions and agree who fixes what. | Everyone involved in remediation |
| Retest, where agreed | After remediation the findings are tested again and the report is updated, so you can show which findings were resolved. | Auditor, insurer, customer |
Weekly written progress reporting and status meetings with your IT team run throughout the engagement. Where several sites are in scope, each site is scoped and reported separately, with one consolidated report on top, and the tests can run in parallel.
NIS2
A penetration test and a phishing campaign are not measures in themselves. They are the evidence that three of the ten measures do what they are supposed to do.
Article 21(2)(e) asks for vulnerability handling across the life of every system. A penetration test shows which vulnerabilities are actually reachable from outside, and in which order to close them.
Article 21(2)(f) asks you to assess periodically whether the measures have the intended effect. An independent test is the most direct form of that assessment, and the report is the evidence.
Article 21(2)(g) asks for training across the organisation. A phishing campaign measures whether the training has landed, and where to aim the next round.
Frequently asked
The test runs inside agreed windows, exploitation is controlled and no denial of service is attempted. Nothing outside the agreed scope is touched.
A critical finding is escalated on the day it is confirmed, to the contact you named at scoping, so your team can act before the report is written.
No. Results are reported per team or department, never per named employee. Anything entered on the simulated page is neither kept nor reused. The purpose is to aim the awareness programme, not to single anyone out.
Certified testers from our delivery centres in Sofia, Varna and Stara Zagora, inside the European Union and under the certified management systems of our parent organisation in Bulgaria. Certifications held across the team include OSCP, OSWE, OSCE, OSWP, CREST CPSA and CRT, CISSP, CISA, CEH and eWPTX. Anonymised CVs are available on request.
Where Think Smart Europe runs the environment itself, we advise having it tested by another party. Independence is the point of the exercise, and our Managed CISO will say the same thing.
The directive does not name it. It does ask for vulnerability handling, for a periodic assessment of whether the measures work and for training across the organisation, in Article 21(2)(e), (f) and (g). A test report is the most direct evidence for all three, and it is what an auditor, an insurer or a customer questionnaire asks for by name.
In the call we go through your internet-facing estate, the number of sites, the target group for the phishing campaign and the test window. You then receive a fixed scope and a fixed fee per site.