Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

Cybersecurity starts with the basics of the building

Why digital resilience does not begin in the cloud, but in the physical and digital infrastructure of your building.

Insights··10 min read
Cybersecurity starts with the basics of the building

Key takeaways

  • A large part of digital resilience is determined before an organization installs its first server, namely through the physical and digital infrastructure of the building.
  • Cybersecurity is a combination of people, processes, software, networks and hardware, but the building-related base is often underexposed in that mix.
  • Without insight into what is present and who is responsible for what, responsibilities between tenant, landlord and supplier remain unclear.
  • The digital delivery level of IT-Label, from PREMIUM to SHELL, makes visible on what digital base an organization builds further.
  • IT-Label does not replace a security audit or certification, but delivers the insight that precedes every form of security.

Anyone who hears the word cybersecurity thinks of firewalls, antivirus, multi-factor authentication, encryption, monitoring and zero trust. All justified, all important. Yet the conversation almost always shifts immediately to software, cloud and policy, while a simple question is rarely asked: who can actually access the patch cabinet?

Or more concretely: do you know where the internet connection of your office physically enters the building? Where the network equipment is located, who has access to the technical room and who manages the building-related systems? Digital security does not exist only in the cloud. Behind every digital workplace there is ultimately physical infrastructure: cables, connections, network equipment, technical rooms, access systems, power supplies and connections.

This contribution centers on a provocative position. Cybersecurity does not start in the cloud. The foundation lies in the building. And that foundation is measurable, can be made visible and can be transferred, provided you map it out earlier than the day the tenant logs in.

Start with the hardware

Cybersecurity starts with hardware. That is deliberately sharply formulated, because cybersecurity consists of much more than hardware alone. It is an interplay of people, processes, software, networks, access management, policy and monitoring. But without a secure and well-organized physical base, software-based measures can prove insufficient. A strong lock on a door that hangs the wrong way protects little.

The physical base comprises more components than most real estate professionals have in view. Think of the modem and router where traffic enters, the switches and access points, the data cabling and patch panels, the server and technical rooms, physical access security, camera and access systems, IoT equipment, Building Management Systems, sensors, wired and wireless connections, and emergency power and backup facilities.

For each of these components, it is not only presence that counts. The follow-up questions determine resilience: who manages it, who has access, who is responsible, is it documented, and where does the boundary lie between building-related infrastructure and the tenant's IT environment? These questions relate directly to cybersecurity in real estate, because every unmanaged connection forms a blind spot.

A smart building also means a larger digital surface

Buildings increasingly contain connected technology. Access control, cameras, climate installations, sensors, lighting, charging stations, elevators, building apps, reservation systems and IoT devices make a building more comfortable, more efficient and more manageable. That offers enormous possibilities, and that development cannot be stopped.

At the same time: more connected systems require more attention to architecture, management, segmentation, updates, responsibilities and security. The smarter the building, the more important it becomes to know what is digitally present in it. That is not a message of fear. Smart Buildings are not inherently insecure; digitalization simply calls for visibility and responsibility.

The underlying rule is sober and firm at the same time: you cannot protect what you do not know. A building with many connected systems without an overview is not bad, but it is unknown, and the unknown is difficult to secure.

We record down to the millimeter which floor a tenant receives at delivery. The digital infrastructure that lies beneath it remains an empty field in most contracts.

Who is actually responsible?

In a conventional office building, the boundary between landlord and tenant seems relatively clear. As soon as buildings become more digital, however, new questions arise that no standard agreement answers by itself.

Who is responsible for the fiber connection, the building-related network equipment, the WiFi in common areas, access control, the cameras, the IoT sensors, the building apps, the technical rooms, the patches and firmware of building-related systems, monitoring, incident handling and the security of building-related digital systems? And where does the tenant's responsibility then begin?

A clear demarcation matters here. This delineation belongs in the conversation about responsibilities in the lease agreement, just as detailed as agreements about maintenance and installations. Cybersecurity is not only about technology. It is also about knowing who is responsible for what.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

What does the tenant actually receive digitally at delivery?

At the delivery of real estate, we naturally make agreements about floors, ceilings, lighting, climate installations, pantries, sanitary facilities, painting and electrical work. This is worked out in delivery reports and measurement and inspection documents. But how is the digital delivery level recorded?

What is present on day one? What functions? What is secured? Which infrastructure can the tenant use, what must he install himself, which facilities are managed by the landlord and which responsibilities are transferred? In practice, these points often remain implicit, even though they fully determine the tenant's digital starting position.

The comparison is obvious. We record precisely which floor a tenant receives at delivery. Why don't we do the same with digital infrastructure? Anyone who rents a shell or turn-key space wants to know what is and is not digitally included before the contract is signed.

Glass facade corner with sun shading
Behind every representative facade lies a digital base that determines how resilient the organization can work in it.

IT-Label as digital delivery level

This is where IT-Label comes into view. It is important to emphasize immediately: IT-Label does not claim to replace a cybersecurity certification. It does not replace a specialized security audit, penetration test, ISO certification, NEN standard or cybersecurity specialist. Its role is a different one. IT-Label makes visible what digital base a building offers and where responsibilities lie.

This happens through a clear classification that captures the digital delivery level in one language. The levels range from a fully equipped base to a deliberately empty delivered shell:

LevelWhat it says about the digital base
IT1+ PREMIUMHighest digital readiness, geared towards AI-intensive use.
IT1 HIGH PERFORMANCEEnterprise level with high reliability and redundancy.
IT2 PLUG & PLAYStandard move-in ready; directly usable digital facilities.
IT3 READYBasic infrastructure present as a starting point for the tenant.
IT4 COREMinimal infrastructure; much is arranged by the user themselves.
IT5 SHELLNo digital infrastructure; deliberately delivered empty.

The positioning is clear: IT-Label does not state that an organization is cyber secure. IT-Label makes visible on what digital building base that organization builds further. That distinction is essential, and it makes IT-Label a translation rather than a certification mark: no judgment, but insight.

From building to user

Cybersecurity runs through an entire chain. That chain runs from the building to the physical IT infrastructure, then to connectivity, the network, the systems and applications, the data and finally the user. Risks can arise at every link, and every link should have a designated responsible party.

IT-Label focuses primarily on the digital building layer and the delivery level. That is where the foundation begins on which the tenant, IT supplier and cybersecurity specialist subsequently build further. A firewall can protect a great deal. But it does not tell you who has access to the technical room where the infrastructure is located, and it is precisely that physical layer that often falls outside the security conversation. The topic thus also relates to network redundancy, because reliability and security are not separate from each other.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

First take inventory, then secure

Before you can determine how something should be secured, you first need to know what is there. Which systems, which connections, which hardware, which technical rooms, which suppliers, which responsibilities and which building-related digital facilities? That sounds obvious, but it is precisely the step that is most often skipped in practice.

The order is first insight, then risk, then security. IT-Label follows a recognizable rhythm in this:

  1. taking inventory of what is digitally present;
  2. checking whether it functions and is managed;
  3. documenting systems and responsibilities;
  4. classifying into a clear delivery level;
  5. improving where desired.

What you do not see, you cannot assess. And what you do not know, you can hardly protect. Making this inventory is therefore not bureaucracy, but the first building block of resilience.

AI makes the digital base even more important

Organizations are becoming increasingly dependent on cloud environments, AI, real-time data, connected devices, automation and Smart Building technology. As a result, digital infrastructure is no longer a facility side issue. It has become part of business continuity.

The more digital our organizations become, the more important the digital base of their premises becomes. The discussion about a future-proof, AI-ready building should therefore not only be about speed and capacity. Reliability, management, documentation, responsibilities and digital resilience also belong in that conversation.

Cybersecurity starts before the handover of the keys

Cybersecurity should not become a topic only at the moment the tenant sets up his computers and calls in his IT supplier. By that point, part of the digital base has already been determined by the building. The questions that matter should therefore be asked earlier: during development, during renovation, during technical due diligence, during letting, during viewing, during contract formation and during delivery.

Digital security does not start when the tenant logs in. It starts with what the building delivers. And the real estate professional does not need to become a cybersecurity specialist for that. He does need to learn to ask the right questions: where does the connection enter, where is the hardware located, who can access it, which building systems are connected, who manages them, is there documentation, who is responsible for what and what does the tenant receive digitally at delivery? The real estate professional does not need to carry out cybersecurity himself, but he does need to understand where digital responsibility begins.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Frequently asked questions

Does cybersecurity really start with hardware?

Not exclusively. Cybersecurity is a combination of people, processes, software, networks, access management, policy and monitoring. The statement emphasizes that the physical and building-related digital infrastructure forms a part of that base that is often underexposed.

Does a high IT-Label mean a building is cyber secure?

No. A high IT-Label says nothing about the cybersecurity of an organization. It makes visible what digital base the building offers and where responsibilities lie, as a foundation for further security.

Does IT-Label replace a security audit or ISO certification?

No. IT-Label does not replace a penetration test, security audit, ISO certification or cybersecurity specialist. It provides the insight into the digital building layer that precedes those processes.

Why is demarcation between tenant and landlord so important?

Because unclear responsibilities lead to systems that no one manages or updates. A clear delineation prevents blind spots in management, monitoring and security of building-related systems.

What can I do as a real estate owner in concrete terms?

First map out what is digitally present and record the delivery level. That way you know what you manage, what you transfer and where the tenant builds further. Start with insight into the digital base.

Back to basics: start with the delivery level

We talk about AI, cloud, zero trust, cybersecurity, Smart Buildings and IoT. But ultimately it starts with something much more fundamental: what is in the building, how is it organized, who manages it, who has access and what does the user receive at delivery?

Cybersecurity starts with hardware. Hardware starts with the building. And digital quality starts with insight into the delivery level. If you want to make this base visible for your own real estate, start by taking inventory of the digital building layer and discover via what IT-Label means for real estate owners which delivery level you are actually offering today. The first question you owe your tenant is simple: what does he receive digitally at delivery?

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch