Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

Cybersecurity Act and the digital building layer

Why digital resilience also starts at the physical workplace and the building's infrastructure.

Insights··10 min read
Cybersecurity Act and the digital building layer

Key takeaways

  • The Cybersecurity Act transposes the European NIS2 directive into Dutch law and affects roughly 8,000 organisations across 18 sectors.
  • In its explanation of the duty of care, the NCSC explicitly states that the physical environment of network and information systems also requires protection.
  • An organisation can have its policy in order and still know very little about the digital infrastructure of the building it rents.
  • With a structured IT-label methodology, the digital delivery level of a location is made transparent, without replacing a cybersecurity audit.
  • Executives responsible for digital resilience also need insight into the place where their systems physically run.

The Netherlands is setting increasingly strict requirements for the digital resilience of organisations. With the Cybersecurity Act, which transposes the European NIS2 directive into national legislation, executives are expected to know, manage and periodically assess cyber risks. Digital resilience thereby becomes a board-level responsibility, no longer a technical side issue.

Yet resilience consists of more than software, firewalls, passwords, policy and trained staff. Every digital organisation ultimately operates from a physical environment. An office, a hospital, a government building, a research institution or a data centre contains the physical and digital infrastructure on which day-to-day operations rest.

That raises a question that still receives too little attention in the discussion around the new law: can we seriously monitor the digital resilience of organisations if we do not know how digitally resilient the buildings and workplaces are in which they operate?

What the Cybersecurity Act means

The Cybersecurity Act (Cbw) is the Dutch implementation of the NIS2 directive and has entered into force. Where earlier regulation was limited to a relatively small group of essential providers, this act significantly broadens the scope. An estimated 8,000 organisations across 18 sectors will be affected.

The scope covers, among others, government, energy, healthcare, transport and digital infrastructure. These organisations are designated as essential or important and face a number of concrete obligations. The main ones are the duty of care, the registration obligation and the reporting obligation.

The duty of care requires organisations to analyse risks and take appropriate and proportionate measures to protect their network and information systems. The registration obligation ensures that supervisory authorities know which organisations fall under the act. The reporting obligation requires the timely reporting of significant incidents.

Two elements stand out. First, executives bear personal responsibility for managing cyber risks. Second, measures are not a one-off exercise: their effectiveness must be assessed periodically. Both points make the question of the underlying infrastructure more relevant than ever, and with it the role of real estate. This is one of the reasons why cybersecurity in real estate is no longer a separate topic.

The interesting passage: the physical environment

In explaining the duty of care, the NCSC states that organisations must not only protect their network and information systems against incidents, but also the physical environment in which these systems are located. That sentence is small, but its implications are significant.

Because where is IT located? In buildings. Where do fibre optic connections enter? In buildings. Where are routers, switches, patch cabinets and local servers located? In buildings. Where do employees connect to corporate networks and cloud environments? At their workplace. And where are access systems, cameras, building management systems, sensors and increasingly IoT equipment located? Again: in the property.

The conclusion is obvious. Cybersecurity does not stop at the firewall. It also begins, in part, with the physical and digital infrastructure of the location. A technical room accessible to everyone, a single non-redundant internet connection or a network without segmentation are not abstract policy issues, but concrete properties of a building.

An organisation can have its cybersecurity policy perfectly on paper and at the same time know hardly anything about what is physically happening in the utility room of the building it rents.

The blind spot between IT, real estate and legislation

This creates a blind spot. An organisation may have set up its organisational IT layer excellently, with policy, procedures and oversight. But what does it actually know about the digital infrastructure of the building it occupies?

The relevant questions are numerous and concrete:

  • which internet connections are present and from which providers;
  • is fibre optic cable present and what is its quality;
  • is there redundancy of connections;
  • are technical rooms physically separated and secured;
  • how is the network cabling structured;
  • how are patch and server rooms set up;
  • how does access control work;
  • how is the WiFi infrastructure and network segmentation arranged;
  • what backup facilities and continuity measures exist in the event of outages;
  • which building-related IoT and smart building systems are integrated;
  • and where do the responsibilities of landlord, tenant and IT suppliers lie.

Who makes this infrastructure transparent when an organisation rents a new building? In practice, a tenant receives information about floor area, energy label, parking spaces, installations and service costs. But does that same organisation also receive a comprehensible overview of the digital delivery level? Often not, and that information is missing from virtually every rental brochure.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

IT-label as the missing translation layer

This is where the IT-label fits in, as an independent and comprehensible classification of the digital delivery level of commercial real estate. It is important to be precise about what it is and is not. The IT-label is not a replacement for the Cybersecurity Act, NIS2, ISO 27001, the NEN standards, BIO2 or a cybersecurity audit. A building with a certain label is therefore not automatically NIS2-compliant.

The strength lies elsewhere. The IT-label makes visible what often remains invisible. It maps the digital infrastructure of a building or workplace in a structured way and translates technical information into a level that tenants, landlords, asset managers, brokers, IT professionals and executives can understand. The fact that it is not a certification but a translation is precisely why it can exist alongside legislation.

A periodic IT-label audit can therefore contribute to:

  1. insight into the digital infrastructure present;
  2. identification of possible vulnerabilities or missing facilities;
  3. clarity about the digital delivery level;
  4. a clearer demarcation between the responsibilities of tenant and landlord;
  5. documentation of changes in a building;
  6. periodic monitoring of digital readiness;
  7. better decision-making on renting, letting, renovation and investment.

The classification has several levels, ranging from IT1+ PREMIUM for buildings with the most complete, redundant and future-oriented infrastructure to IT5 SHELL for a shell delivery without digital infrastructure. Each level describes a situation, not a judgement. An IT5 SHELL can be a deliberate choice; the label simply ensures that choice becomes visible and open to discussion.

From energy label to digital transparency

The comparison with the energy label is obvious. For virtually every commercial building, government, owner and user want to know how it performs in terms of energy. That insight has become standardised, normalised and widely accepted.

But in an economy where organisations are becoming increasingly dependent on cloud, data, AI, cybersecurity and digital services, we often barely know what the same building can handle digitally. This raises a policy question: why do we systematically make the energy performance of buildings transparent, while there is still hardly a uniform language for their digital infrastructure?

A classification system can provide that uniform language. First as a market standard, so that tenants, owners and advisors mean the same thing when they talk about digital quality. And possibly, in time, as an additional source of information for government, the real estate sector and users. The parallel is not far-fetched: just as with energy labels, digital transparency can become the new baseline from which the market orients itself.

What a label does and does not say about compliance

It is useful to place both concepts side by side, so that it remains clear where the legislation ends and where the label begins. The comparison below shows that they are not competitors, but complementary perspectives.

AspectCybersecurity ActIT-label
CharacterLegal obligationIndependent classification
FocusOrganisation and policyBuilding and workplace
QuestionDo you manage your risksWhat can this location handle digitally
OutcomeDuty of care and reporting obligationTransparent delivery level

A question for government

This blog is therefore also an invitation to the Dutch government, the NCSC, supervisory authorities, municipalities and other public organisations to look beyond the organisational IT layer alone. Not as criticism of the Cybersecurity Act, but precisely as a practical translation of it into the built environment.

The government asks organisations to make risks transparent, to know their assets and to periodically assess measures. The logical follow-up question then is: should we not also better clarify which digital infrastructure is present in the buildings where our essential and important organisations function on a daily basis?

An organisation can protect its systems well while at the same time being housed in a building where no one knows exactly how the technical rooms are secured or how the connections are structured. As long as that building layer remains invisible, part of the resilience also remains invisible. This is exactly the kind of transparency that the policy question surrounding government policy would benefit from.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

What this means for users and executives

For users, the core question changes when searching for business accommodation. The traditional question was: how many square metres do we need? A second question is added: what does our organisation need to be able to do digitally here? And ultimately a third: can this location actually support our digital operations, our cybersecurity requirements and our future AI applications?

For executives, the connection becomes even more direct. When they become explicitly responsible for digital resilience under the Cybersecurity Act, insight into the physical digital infrastructure on which the organisation depends becomes equally relevant. Bearing responsibility for something you cannot see is difficult to account for.

That makes clear agreements on demarcation important. Who is responsible for the cabling, who for the connection, who for the technical room? These questions arise particularly in rented real estate, where the division of responsibilities too often remains implicit.

AI makes this discussion more urgent

In the coming years, organisations will process more data, use more cloud applications, connect more devices and become increasingly dependent on connectivity. As a result, real estate is changing in character. An office is no longer just a collection of square metres. It becomes digital infrastructure in which people work.

A building that functions adequately today does not automatically qualify as suitable for the data usage and AI applications of tomorrow. The demand for bandwidth, redundancy and processing capacity is growing faster than many existing properties were designed to handle. Digital infrastructure must therefore become part of future-proof real estate policy, rather than being caught up with afterwards.

This is how legislation and technology intersect. The Cybersecurity Act calls for resilience, AI increases dependency, and the building is the place where both come together.

The concrete next step

The Cybersecurity Act makes digital resilience a board-level responsibility. The IT-label can help make one of its often invisible components visible: the digital infrastructure of the physical workplace. Not as a replacement for cybersecurity legislation, not as an NIS2 certificate, but as an independent translation between IT, real estate, users and management.

If the Netherlands wants to become more digitally resilient, we must not only know how secure our systems are. We must also know on what, and where, those systems run. Because digital resilience ultimately begins somewhere: at the connection, at the building, at the workplace.

A good first step is to have the digital delivery level of your own location mapped out, so that you know what is present and where the responsibilities lie. Take a look at how the IT-label works or get in touch through the contact page to discuss what an audit could mean for your building. That way, the accommodation question shifts from how many square metres do I need to the question that really matters: what can my workplace handle digitally?

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch