
Key takeaways
- The Cyber Security Act and the underlying NIS2 directive ask organizations not only to protect software, but also the physical environment in which their systems are located.
- Part of digital security starts in the building itself: at the fiber connection, the patch cabinet, the server room and the workplace.
- IT-Label does not make an organization cybersecure or compliant, but with an IT audit as a safety check of your building it shows what is physically and digitally present.
- In rented real estate it is often unclear where one party's responsibility ends and the other's begins.
- Digital quality changes over time and deserves periodic review, comparable to other building performance aspects.
An organization does everything right. Multi-factor authentication has been introduced, employees regularly receive cybersecurity training, endpoints are secured and work follows strict IT protocols. On paper, everything checks out. Yet the server room or patch cabinet at the office turns out to be accessible with a general key. Sometimes the door is even regularly left open, because it gets warm inside or because some storage has been placed there.
Then an uncomfortable question arises: how digitally secure are you really if someone can physically reach your network? Cybersecurity is often discussed as a software issue. In reality, digital infrastructure always has a physical location somewhere. Cables run through buildings, fiber enters somewhere, switches and routers are installed, access points hang from ceilings and servers sit in technical rooms.
With the arrival of the Cyber Security Act, this is no longer a theoretical matter. Cybersecurity may well begin before the firewall, namely at the physical access to the infrastructure behind it. This article is about that forgotten layer, and about the role the building plays in it.
What the Cyber Security Act essentially requires
The Cyber Security Act (Cbw) is the Dutch implementation of the European NIS2 directive. Where the earlier European approach mainly targeted a limited group of critical sectors, NIS2 broadens the playing field considerably. More organizations now face obligations around digital resilience.
The law works with a number of recurring concepts. There is a duty of care: organizations must take appropriate measures to protect their network and information systems. There is attention to risk management and to the continuity of service delivery. Obligations apply around reporting incidents. There is explicit attention to supply chain risks, meaning the suppliers and parties an organization depends on. And there is a clear governance responsibility: digital security is a task for leadership, not just for the IT department.
What often remains underexposed in the discussion is that the duty of care also affects the physical environment in which systems are located. Anyone who wants to seriously protect their systems cannot ignore the space in which those systems stand. This creates a logical translation: if the physical environment is part of digital resilience, the building automatically becomes part of the cybersecurity question. This is exactly where the Cyber Security Act and the digital building layer meet.
The server room as a tangible example
Nothing makes this more concrete than the server room or patch room. Every business owner, landlord and facility manager can picture it. Walk through a series of simple questions about such a room in your mind.
- Is the server or patch room actually locked, and who has access?
- Is that access recorded anywhere?
- Can cleaning staff or an external supplier just walk in?
- Is the room used exclusively for IT equipment, or is storage kept there too?
- How is cooling arranged and is there fire detection?
- Is there emergency power or a UPS present?
- Are network components and patch cabinets physically protected and locked?
- Is it clear which equipment belongs to the landlord and which to the tenant?
- Is there monitoring, and what happens in the event of a power or internet outage?
- Is a second connection or an alternative route available?
Not every part automatically falls under the landlord's responsibility. That is precisely why it matters that what is present, and who is responsible for what, is visible. Without that insight, blind spots arise exactly where many dependencies come together.
The most expensive firewall loses its value the moment the door to the patch cabinet is left open.
From the server room to the whole building
The same principle applies far more broadly than to a single technical room. A modern building contains an increasing number of digital systems: fiber, routers, switches, WiFi, cameras, access control, elevators, charging points, climate installations, building management systems, sensors and all kinds of IoT equipment.
A smart building runs on IT infrastructure as its foundation and thereby creates not only new possibilities but also new digital dependencies. Every connected system is a potential entry point. Every device attached to the network should be accounted for somewhere.
That leads to a pointed question: how SMART is a building if nobody knows exactly how SAFE it is digitally? Real estate is increasingly becoming part of an organization's digital chain. And a chain is only as strong as its weakest, often invisible, link.
Curious about your building's IT-label?
Discover how your property scores on digital infrastructure.
Request IT-labelWhere IT-Label can concretely help
Let one thing be clear. IT-Label is not a replacement for NIS2, the Cyber Security Act, ISO 27001, cybersecurity specialists or penetration tests. An IT-Label does not automatically make an organization cybersecure or NIS2-compliant. That is a misunderstanding that does not do justice to the subject, as also explained in the difference between IT-Label and ISO 27001.
What IT-Label can do is make relevant physical and digital facilities of a building visible during an audit. An IT-Label audit looks, among other things, at the physical security of server and patch rooms, the presence and quality of digital connections, fiber and internet facilities, redundancy and network cabling, technical rooms, WiFi infrastructure and access control. Where relevant and testable at building level, network segmentation is also considered, along with emergency power, continuity facilities, building-related IoT, smart building systems and monitoring. The demarcation between tenant, landlord and IT supplier is part of this as well.
The underlying principle is simple: you cannot secure what you do not have visibility of. That is precisely where insight adds value. Anyone who knows what is present can then make targeted choices about what needs improvement.

From a snapshot to periodic insight
A building does not receive digital infrastructure once and then keep it unchanged for twenty years. Tenants change, equipment is replaced, new access points are added, IoT equipment is installed and providers change. AI applications demand more capacity and buildings keep getting smarter.
That is why digital quality, like other building performance aspects, should be reviewed periodically. View IT-Label in that light as a possible digital equivalent of a periodic technical inspection for commercial real estate. The goal is not to declare that a building is cybersecure, but to make visible what is digitally present, what the delivery level is and which points deserve attention. This aligns with the idea that an IT-Label is not an endpoint, but a starting point.
Make responsibility visible
A persistent problem plays out in rented real estate. Cybersecurity is ultimately the responsibility of the organization itself, but part of the infrastructure that organization depends on may be owned or managed by the building owner, the landlord, a facility manager, an IT supplier, an internet provider, a building manager or the tenant itself.
What happens if nobody knows exactly where one party's responsibility ends and the other's begins? Then a space remains unguarded, not out of unwillingness, but due to unclarity. An IT demarcation list is then a logical addition. It answers five simple questions: what is present, who owns it, who manages it, who maintains it and who must act if something goes wrong? This transparency alone contributes to digital resilience.
Curious about your building's IT-label?
Discover how your property scores on digital infrastructure.
Request IT-labelWho actually discusses the digital foundation?
Cybersecurity should by now be a standard part of conversations about commercial real estate. A broker discusses the energy label. A technical advisor discusses the installations. A landlord discusses the service costs. A tenant discusses the fit-out. But who discusses the digital foundation?
A constructive question is also fitting toward government, the NCSC and the real estate sector. If the Cyber Security Act asks organizations to better manage their digital risks, shouldn't we also pay more attention to the buildings in which those organizations operate digitally? The digital economy ultimately consists of millions of physical workplaces. That is where employees log in, where data is processed, where AI is used, where laptops connect and where external suppliers enter. The workplace is not only the place where digital technology is used, it is also part of the digital line of defense, something explored further in the piece on the Cyber Security Act and the digital workplace.
Start at the front door
We can secure our software, train our employees, mandate MFA, install firewalls and build Security Operations Centers. But if nobody knows who has access to the space where the physical infrastructure comes together, we may be missing, quite literally, the door where cybersecurity begins.
Cybersecurity does not start only in the cloud. It starts at the front door, at the workplace, at the patch cabinet and sometimes quite literally at the lock on the server room. If you want to know what is digitally present in your building and how responsibilities are divided, start with insight. Explore how an IT-Label audit works in practice and map the digital layer of your real estate. Because before you can secure something, you first need to know what is there.

