Solution
IT service providers and MSPs. Trusted with your customers' systems.
As an IT service provider you work inside your customers' environments every day. They want to know who has access, how you handle incidents and how you manage your own suppliers, and NIS2 has made those questions more frequent. Trustbird brings your answers together in one management system.
- Access to customer environments recorded per customer
- Suppliers and agreements kept current
- NIS2 supply chain questions linked to your controls
Built around managed services
An IT service provider carries risk for its customers as well as for itself. Trustbird helps you show how you manage that risk, with evidence from daily operations.
Access to customer environments
Record which people and accounts have access to which customer, on what basis, and when that access was last reviewed.
Many suppliers, one register
Keep track of the software, hosting and service suppliers you rely on, what they can access and what you agreed with them.
Incidents with customer impact
Record incidents with the customers they affect, the notifications you made and the follow-up, so agreed notification times are visible.
NIS2 in the supply chain
Customers under NIS2 ask their suppliers about measures, incident notification, vulnerabilities and continuity. Trustbird links those questions to your existing controls.
Continuity and recovery
Describe backups, recovery times and continuity plans per service, and keep the results of tests next to them.
Change and operations
Document how changes, patching and monitoring are handled across customer environments, with evidence from the way your team works.
How an IT service provider starts
-
01
Describe your services
Tell Trustbird which services you deliver, to whom, and which systems are involved.
-
02
Record access and suppliers
Capture who has access to customer environments and which suppliers support your services.
-
03
Treat the risks
Assess the risks for you and your customers and link the controls that address them.
-
04
Show it to customers and auditors
Use the same file for your certification audit and for customer questions about security and NIS2.
Frequently asked questions
- Are we in scope for NIS2 ourselves?
- That depends on your services and size. Managed service providers are one of the sectors the law names, and size thresholds apply as well. The self-assessment from the RDI gives a first indication. Trustbird helps you organize the work, but it does not make that legal assessment for you.
- Our customers each have their own requirements. Can Trustbird handle that?
- Yes. You can record customer-specific agreements, such as notification times, next to the controls that meet them, so you see which customer expects what.
- Where is our data stored?
- In the European Union. The data of every customer is kept strictly apart, and every change in Trustbird is recorded in an audit trail.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.