Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

The door to your server room: physical security

Why the weakest link in your cybersecurity is sometimes simply a door left open.

Insights··8 min read
The door to your server room: physical security

Key Takeaways

  • Organizations invest heavily in digital security, while physical access to the server room is sometimes surprisingly easy.
  • Since August 15, 2026, the Cybersecurity Act (Cyberbeveiligingswet) has been in effect in the Netherlands, which explicitly mentions the physical environment of network and information systems as well.
  • NIS2 is based on an all-hazards approach, in which theft, fire, water, power outages and unauthorized access are all considered risks.
  • Physical security of IT spaces is a concrete part of the digital delivery level that becomes visible in an IT-label classification.
  • With a Digital Due Diligence, you map out both the physical and digital infrastructure of a building.

Picture a server room containing thousands of euros' worth of network equipment. Switches, fiber optic connections, patch cabinets, camera infrastructure and perhaps even the building management systems all come together here. But the door? It's open. Or the key hangs at reception, next to the key to the bicycle shed.

This scenario occurs more often than you might think. Significant investment goes into firewalls, multi-factor authentication, monitoring and awareness training, while the room where the core of the network physically stands barely gets any attention. Which raises the question: how digitally secure is an organization when someone can physically reach the heart of the network?

This article is about that door. About the physical security of server rooms, patch rooms and technical IT spaces in commercial real estate, and about why this topic is no longer optional in 2026.

The rules in 2026: NIS2 and the Cybersecurity Act

Since August 15, 2026, the Cybersecurity Act has been in force in the Netherlands. This implements the European NIS2 directive. Organizations that fall under this law must take appropriate and proportionate measures to manage the risks to their network and information systems.

Discussions about NIS2 often focus exclusively on digital measures. Yet the NCSC explicitly states in its explanation of the duty of care that the physical environment in which network and information systems are located must also be protected. The question of who can physically reach your network is therefore not a footnote, but part of the core.

NIS2 is furthermore based on an all-hazards approach. This means organizations must account for various causes of failure or damage:

  • theft;
  • fire;
  • water;
  • power outages;
  • telecom failures;
  • sabotage;
  • human error;
  • unauthorized physical access;
  • damage to IT equipment.

This is not a theoretical point. The European NIS2 rules explicitly mention the protection of the physical environment of network and information systems against unauthorized access, damage and disruption. The door to the server room has thus become part of the legal context.

A network that is digitally locked down but physically wide open is not half secured. It's secured right up to the exact point where it matters most.

Practical measures for a secure server room

Physical security doesn't have to be an overly technical exercise. It involves straightforward measures that any real estate, facility or IT professional can grasp.

Locking down and controlling access

A server room should not be a general storage space where employees, cleaners, suppliers and technicians can walk in freely. Work with controlled access: electronic access control, personal access cards instead of shared keys, logging of who enters the room and periodic review of access rights. Do you actually know who was in your server room yesterday?

Apply the principle of access only when necessary. Not every employee, landlord, cleaner, contractor or supplier needs to be able to enter. Revoke access rights once someone leaves or a supplier has finished the work.

Physical separation in multi-tenant buildings

In business centers and multi-tenant offices, separation is especially important. Prevent different tenants from having access to each other's patch panels, switches, routers, fiber optic connections, server equipment or security systems without clear boundaries. Use separate locked racks or compartments where necessary. This ties in with the question of what you actually rent digitally per floor.

Map out all equipment

Do you actually know everything that is in the server room? Create an up-to-date asset register of, for example, switches, routers, firewalls, access points, UPS systems, modems, 4G/5G routers, fiber optic equipment, camera recorders, access control systems, building management systems and IoT gateways. A router that nobody knows was installed by whom is technically small, but organizationally a major risk. Asset management and access management also explicitly appear in the duty of care under the Cybersecurity Act.

Concrete building corner against a dark sky
The digital core of a building is often located behind an unremarkable door that is rarely opened during transactions.

Pay attention to the environment and redundancy

A server room should not only be protected against people. Check temperature, ventilation, moisture, leak risk, fire and smoke detection, power supply, UPS and emergency power, the placement of water pipes and the presence of flammable storage. A perfectly secured network gets little benefit from cybersecurity when a leaking pipe hangs above the server cabinet.

Also consider continuity. What happens if this room fails completely tomorrow? Is there one internet connection or several, and do they run redundantly via different routes? Is there backup power, are configurations backed up and is there a recovery procedure? Does anyone know which equipment is business critical and how quickly the organization can become operational again? Network redundancy is an important part of digital resilience.

Patch cabinets, cabling and documentation

Servers are not the only thing that deserves attention. Patch panels, fiber optic connections and network cables are also part of the digital infrastructure. Someone with physical access can remove cables, switch off equipment or disrupt connections. How much revenue is lost if someone pulls the wrong fiber optic cable out of a patch cabinet on a Monday morning?

Document every change as well. An installation company places a 4G router for temporary remote maintenance, and three years later it's still there. Nobody remembers whose it is, what it's for, who has access to it, whether it receives updates or which network it's connected to. A proper digital handover should therefore always include documentation and as-built data.

Who is responsible for what?

In commercial real estate, the division of responsibilities is often unclear. Who is responsible for the server room, the patch cabinet, the fiber optic connection to the building, the cabling from the meter cupboard, the active network equipment, access control, monitoring, fire protection, cooling and redundancy?

Is that the owner, the landlord, the tenant, the property manager, the facility manager or the IT supplier? IT-Label believes this division should be part of a clear demarcation list for digital infrastructure, similar to the arrangements already common in the ROZ lease agreement.

Security is furthermore not a one-time inspection. Access changes, tenants leave, suppliers change, equipment gets replaced and new IoT devices are added. That's why a server room must be reassessed periodically. Think of it as a digital roadworthiness check for the building: not a single look followed by ten years of assuming everything still checks out.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Translating this to real estate

When it comes to buildings, we naturally look at fire safety, electrical installations, access control, sustainability, the energy label, climate systems and the technical condition. But the room where virtually all of an organization's digital communication comes together sometimes receives barely any attention during a purchase or lease.

Why do we thoroughly inspect the heating system during a real estate transaction, yet sometimes walk straight past the server room? The IT-label aims to make this blind spot visible by looking not at a single cable or a single internet connection, but at the overall digital delivery level: fiber optics, redundancy, cabling, WiFi, patch rooms, server rooms, physical security, access management, active equipment, building-related IT, documentation, responsibilities, continuity and future readiness.

This integrated view fits a market that increasingly focuses on data capacity rather than just square meters, and in which the future-proof, AI-ready office starts with the infrastructure you don't see.

It's important to remain precise here. An IT-label is not an NIS2 or Cybersecurity Act certificate. An IT-label does not automatically mean an organization meets all its legal obligations. What it does do is help make an important part of the risk profile visible: the physical and building-related digital infrastructure.

In addition, not every company automatically falls under the Cybersecurity Act. Organizations must assess for themselves whether they fall within the legal scope. Base that assessment on current sources such as the NCSC, the Dutch government, EUR-Lex and, where relevant, NEN and ISO documentation. The IT-label is and remains a translation of technology into understandable information, not a legal stamp of approval.

Take the next step

Cybersecurity starts digitally, but it doesn't end at the screen. Behind every cloud environment, AI application and digital workplace lies physical infrastructure. A cable. A switch. A router. A fiber optic connection. And somewhere, a door to a technical room. The question is: who can actually open that door?

Have IT-Label carry out a pre-inspection or a Digital Due Diligence and gain insight into both the physical and digital infrastructure of your building. That way, you'll know not only how your firewall is doing, but also what's going on with the door in front of it. Together we make visible what is still invisible today. Want to know more? Visit www.it-label.com or get in touch with us.

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch