Thinking Machine
Open menu
Thinking Machine d.o.o. · Boutique engineering advisory

Hand us the hard question. We come back with a defensible answer.

Delegate the thinking. We come in, listen carefully, map what's actually there, do the analysis, and deliver the document your board can read in fifteen minutes.

Twenty-plus years across Healthcare ITTelecommunicationsGovernment R&DIndustrial IoTEnergyAviation
Recently engaged by EU mental-health services provider Tier-1 European energy operator EU manufacturer of connected products Multi-tenant SaaS vendor Industrial software vendor See engagements →
20+
Years of enterprise architecture
6
Sectors of deep experience
2–4
Weeks per decision (vs 4–6 months at a Big-4)
1
Senior expert on the work, not a delivery team
Time to a defensible answer

Same depth. A quarter of the calendar.

Typical engagement length for the kind of decision-grade work we do, against the alternatives. Bars show typical span, not a contractual range.

Engagement duration comparison Horizontal bar chart comparing typical engagement duration in weeks. Thinking Machine: 2 to 4 weeks. Domain freelancer: 4 to 12 weeks variable. Internal team: 4 to 20 weeks constrained by politics. Big-4 strategy house: 16 to 24 weeks. 0 4w 8w 12w 16w 20w 24w weeks elapsed Thinking Machine single senior expert 2–4 weeks Domain freelancer deep, but variable 4–12 weeks · variable Internal team politically constrained 4–20 weeks · variable Big-4 / strategy multi-tier delivery team 16–24 weeks · 4–6 months
How we work

Survey. Map. Think. Deliver.

The hard part is not the answer — it is finding out what is actually true inside your organisation, then thinking carefully about what to do. We do both.

01

Survey

We come in and listen — to the people who actually know. Most of what matters is not written down. We surface it.

02

Map

We draw the current situation: data flows, decision rights, dependencies, gaps. Everyone sees the same picture.

03

Think

The hard part. We anchor on published frameworks and our cross-sector pattern library. We look for the analogy that has already been solved.

04

Deliver

A document your board reads in fifteen minutes. Backed by a model that survives a hostile read. With every claim cited.

What we do

Three lanes. Same engagement model.

01 · Cloud

Cloud cost & FinOps strategy

Board-grade cost assessments anchored on published frameworks. Triangulated baselines, multi-scenario reserved-instance modelling, vendor-side pricing playbooks. The document the decision-maker reads.

Read more on cloud cost
02 · Cyber

Cyber resilience, NIS2 & CRA

Cyber Resilience Act readiness. NIS2 transposition. Azure-native security architecture. Structured NFR responses for procurement and pre-contract due diligence. Audit-defensible positions, not opinions.

Read more on cyber resilience
03 · AI

AI integration for established systems

MCP control layers. RAG over enterprise knowledge. On-prem LLM infra for data-residency-sensitive sectors. We connect modern frontier models to the systems you already have — no all-in transformation pitch.

Read more on AI integration
What we bring

A small library of named techniques, stacked.

We do not invent methodology on your dime. Each engagement starts from a small library we have refined across regulatory, cost, and architecture work. The stack below is how they compose into the deliverable.

Methodology stack — how six named techniques compose into a decision-grade deliverable Vertical stack of four tiers. Foundation tier: Primary-source verification using five-pass verbatim citation. Second tier: Position of Record on the regulatory side, Triangulated baseline on the cost side. Third tier: Propagation matrix on the regulatory side, Four-category cost taxonomy on the cost side. Fourth tier: L slash I slash B classification synthesising both tracks. Apex: Decision-grade deliverable. Arrows indicate upward flow. Decision-grade deliverable audit-defensible · board-readable · fixed-scope L / I / B classification Legally Required · Implicit Means · Best Practice every finding tagged · synthesises both tracks Propagation matrix cross-document audit trail N findings × M documents · status per cell Four-category cost taxonomy structure for any cost number fixed overhead · competence · variable · per-server Position of Record authoritative claims with evidence chain REGULATORY TRACK Triangulated baseline when invoices unavailable: pricing × margin band COST TRACK Five-pass verbatim verification — every load-bearing claim cited to source

Read upward. Everything starts at the foundation: regulatory text, cloud-vendor pricing pages, vendor PSIRT advisories — quoted verbatim, five times, by separate passes. Two tracks build on top: one for regulatory claims, one for cost numbers. They converge at L / I / B classification, where every finding is tagged Legally Required, Implicit Means, or Best Practice. Output: a deliverable that survives a hostile read.

Specialised methods when relevant — a six-dimension cost model (CPU · RAM · storage · bandwidth · quality · resilience) for media-heavy platforms where any single dimension misleads, and an adaptive-recording pattern (high-information segments stored at full fidelity, low-information stretches stored as compact derived data) where every minute must be retained but storage cannot scale linearly. Used to anchor codec, transport, and storage choices to multi-axis impact rather than a single metric.

Cross-sector library

Your problem has often already been solved next door.

Most consultants spend a career in one sector. We have shipped systems in six. The patterns travel. Below: four analogies we routinely make on calls.

Cross-domain pattern transfers across six sectors Six sector nodes — Healthcare IT, Telecommunications, Government R and D, Industrial IoT, Energy, Aviation — connected by four labelled curved arcs showing patterns that transfer between them. Arc 1: Healthcare IT to Industrial IoT — lab integration patterns. Arc 2: Energy to Telecommunications — operator-side procurement. Arc 3: Government R and D to Healthcare IT — EU consortium discipline becomes e-Health certification. Arc 4: Aviation to Industrial IoT — multi-tenant fleet operations. 1 2 3 4 Healthcare IT Telco Gov R&D Industrial IoT Energy Aviation
1

Healthcare IT → Industrial IoT

Lab-instrument integration is multi-vendor IoT device onboarding with thirty years' head start. Per-device-type abstraction beats per-protocol abstraction. Read the note →

2

Energy → Telecommunications

Operator-side NFR practice — fifty-line matrices scored compliant / partial / non-compliant — translates directly to telco procurement and onward into any regulated-customer SaaS deal. Read the note →

3

Government R&D → Healthcare IT

EU-funded consortium discipline — verbatim regulation citations, propagation matrices, evidence chains — is exactly what e-Health certification audits ask for.

4

Aviation → Industrial IoT

Multi-tenant fleet operations from aviation map cleanly onto multi-vendor multi-site IoT — same identity-binding, same per-asset commissioning ceremony, same blast-radius discipline.

Why us

Honest comparison.

We know the alternatives. Here is where we slot in — and where we do not.

If you go to You typically get With us
Big-4 / strategy house Branded report, multi-tier delivery team, 4–6-month engagement. One senior expert. 2–4 weeks. Same depth, sharper.
Domain freelancer Deep in one vertical. Project-by-project — no shared methodology library. Twenty years across six sectors. Audit-grade methodology.
System integrator Will gladly recommend the implementation work they’re selling. No implementation conflict. We will not build what we recommend.
Internal team Free, contextual. But politically constrained, no external calibration. External read. Permission to say what is politically inconvenient.
Deliverables

What you actually get.

Tangible artifacts you keep. No deck-only deliverables, no executive summary with nothing underneath.

Primary deliverable

Decision-grade report

A document the board reads in fifteen minutes — anchored on published frameworks, with explicit scope, methodology, evidence trails, and a recommendation that survives a hostile read.

Working artifact

Cost model spreadsheet

Multi-sheet, scenario-modelled, you populate inputs and the answer changes.

NFR / CRA toolkit

Compliance register + evidence log

One row per requirement. Status, justification, evidence, cost-impact, action.

For AI work

Working PoC + go/no-go memo

A demonstration in code, not a slide. Plus an honest evaluation of whether to proceed.

Always

Out-of-scope declaration

Up front, in writing — what we deliver, and what we deliberately do not.

Engagement shapes

Three shapes you can actually approve.

Stage 1

Discovery Sprint

1–2 weeks · fixed fee

Scoped problem, structured deliverable, decision-ready output.

Stage 2

Rapid PoC

2–4 weeks · fixed fee

Working demonstration plus an evidence-based go/no-go.

Stage 3

Fractional CTO

Monthly retainer

A senior architect on call. Sounding-board for the in-house team, RFP due diligence, second-opinion reviews. For when the team is strong but missing one specific area of depth.

We take one to two new engagements per quarter. The first thirty minutes is always free — no pitch, no slide deck.

Recent work

Anonymised case studies.

See all engagements →
Architecture design & technology selection · anonymised internal reference · EU mental-health services provider · 2026

Clinical-grade video consultation platform for an EU mental-health services provider

Designed and specified a self-hosted, EU-only video-consultation platform purpose-built for clinical mental-health consultations. Edge-ML architecture — face-mesh extraction, noise cancellation, ROI encoding, and adaptive framerate all run on the client; the server is a smart switch. Made the deliberate architectural choice not to do emotion recognition, despite the EU AI Act's medical exemption permitting it, because the clinical evidence does not support reliable emotion inference from facial expression. A six-dimension cost-and-quality framework (CPU, RAM, storage, bandwidth, clinical quality, network resilience) applied across codec, recording, transcription, and storage tiering achieves an end-to-end **98% storage reduction** at the cold tier — €2,190/month down to €45–55/month at 500 sessions/day. Per-session AES-256-GCM keys from HashiCorp Vault, crypto-shredding for GDPR Article 9 right-to-erasure in under 24 hours.

Read case study
Applied platform-engineering work · anonymised internal reference · Multi-tenant SaaS vendor · 2024

Software supply-chain controls and platform-IaC rescue for a multi-tenant SaaS vendor

Reconstructed a five-year-old Ansible/Semaphore IaC stack end-to-end across four repositories — orchestration playbooks, production nginx reverse proxy, PostgreSQL container, analytics-stack feature branch. Designed and shipped a gated software supply-chain layer (Composer/Satis, npm/Verdaccio, SQL/Redgate, container/GitLab Registry) with per-package static analysis, vulnerability scanning, and approval before any developer could resolve a third-party dependency. Approximately 30% of the engagement; implemented in 2024, two years before CRA Cliff 2 (11 December 2027) makes SBOM and supply-chain integrity a regulatory obligation across the EU.

Read case study
40-hour fixed-scope advisory · Industrial software vendor · 2026

Cloud cost assessment for a multi-installation SaaS vendor

A vendor preparing to quote a cloud-managed SaaS deal to a tier-1 enterprise customer needed a defensible per-installation pricing model — without access to the incumbent's hosting baseline. We delivered a triangulated baseline, multi-scenario pricing playbook, and a customer-side cost calculator.

Read case study
Applied preparedness work · anonymised internal reference · EU manufacturer of connected products · 2026

Cyber Resilience Act readiness for an EU manufacturer of connected products

Applied preparedness work on CRA Cliff 1 (September 2026) for an EU manufacturer-operator of connected products. Roughly 240 pages of audit-defensible evidence across 13 documents — checklists, briefings, the Article 14 runbook, the RACI, the execution plan — anchored on five-pass verbatim verification of the Official Journal. Published as a methodology reference; client unidentified.

Read case study
Pre-contract due diligence — structured NFR response · Tier-1 European energy operator · 2026

NFR compliance response for a tier-1 European energy operator

A multi-domain NFR matrix from an enterprise procurement team — roughly fifty line items across security and data architecture — required a structured response that would survive procurement review. We produced the compliance register, a deep-dive sheet for the difficult items, and a source-verification log.

Read case study
Most consulting engagements are designed to expand. Discovery becomes Phase 1; Phase 1 becomes Phase 2; the meter runs. We do not work that way.
Why fixed-scope · Read the full About →
Frequently asked

Questions buyers usually ask first.

How long is a typical engagement?

Discovery Sprints run 1–2 weeks. Rapid PoCs run 2–4 weeks. Fractional CTO is monthly retainer. We never sell engagements that expand themselves — every shape has a fixed scope and end date declared up front.

How do you price?

Fixed fee, quoted on the first call before any commitment. We do not bill hourly. There are no expansion clauses. The introductory thirty-minute call is free regardless of outcome.

Will you sign an NDA before the first call?

Yes. Send it ahead of time and we will sign before the call. Many existing engagements remain under reference embargo at the client's request.

Do you also implement what you recommend?

No. Separation of advisory and implementation is structural, not stylistic. If your engagement uncovers work that needs an implementation team, we will help you scope it but not deliver it.

Can you work with clients outside the European Union?

Yes. Our base is Zagreb, Croatia, and most engagements are EU-based, but we have worked with clients in Norway, the UK, Germany, and beyond. Remote-first; we travel for kickoff and final-readout meetings when warranted.

What sectors do you specialise in?

Healthcare IT, telecommunications, government R&D, industrial IoT, energy, and aviation. The cross-domain pattern library is itself the value: your problem has often already been solved in an adjacent sector.

How quickly can you start?

We take one to two new engagements per quarter. Lead time is usually two to six weeks depending on existing commitments.

What if you decide we're not the right fit?

We will say so on the first call and, where possible, point you to someone better suited. We do not take work where AI, cloud, or compliance is not actually the right answer.

What happens if you become unavailable mid-engagement?

Every engagement carries an explicit continuity clause. If a force-majeure event prevents the principal from continuing, the work product to date — every draft, citation, model, evidence file — is handed over within five working days, the engagement is closed at a pro-rated fee, and where useful we provide a one-paragraph briefing for whoever picks up. We have not had to invoke this clause in any engagement to date.

Can you bring in collaborators if scope requires more than one person?

Yes. For clearly bounded sub-scopes (a security architect, a regulatory specialist, a localisation lead) we work with a small set of named partners under sub-NDA. The principal stays accountable for all deliverables and for the writing. We do not staff out the core analytical work.
About

Bruno Božić

Founder of Thinking Machine d.o.o. and Head of IoT at Reos GmbH (Hamburg). Twenty-plus years of enterprise architecture across healthcare IT, telecommunications, government R&D, and industrial IoT. C#/.NET architect by training; integration architect by trade.

Read the full background →

Hand us the question. Thirty minutes, no slides, no pitch — and an honest answer about whether we can help.