Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

Digital resilience begins at building level

From hybrid warfare to the patch cabinet: why national resilience is ultimately won or lost inside the building.

Insights··10 min read
Digital resilience begins at building level

Key takeaways

  • Modern conflicts have a pronounced digital and hybrid dimension, which means cyber threats are now part of broader security and defence issues.
  • National digital resilience ultimately consists of thousands of individual buildings, technical spaces and connections, each with its own vulnerabilities.
  • Digital infrastructure feels virtual, but is physical: cables, routers and server rooms deserve just as much attention as the data itself.
  • With a digital MOT of the workplace, IT-Label reveals how resilient the infrastructure in a building really is.
  • Resilience at building level protects not only against sabotage, but also against everyday incidents such as excavation damage, fire and power outages.

When people hear the word war, they think of tanks, borders and troops. That picture still holds, but it is no longer complete. Modern conflicts largely play out in networks, cables and systems. Disruption of communication, attacks on logistics chains and disinformation are now just as much part of conflict as classic military resources.

NATO explicitly names cyber threats and hybrid attacks as part of modern security and defence issues. The NCSC, the Dutch national government and the European Union also warn that digital disruption and sabotage form a real part of the security landscape. This article is not about fear, but about preparation: how do we organise resilience, and where does it actually begin?

Because there is a striking blind spot in that story. We invest heavily in national digital resilience, but one level down, inside the building where organisations work every day, the digital infrastructure often remains invisible and unprotected. That is exactly where IT-Label aims to bring clarity.

From geopolitics to the individual building

At macro level, a country does a great deal well. There is investment in cyber defence, national data centres, telecom networks, energy security, military infrastructure, vital sectors and emergency communication. These are legitimate and necessary investments. They form the foundation beneath a modern society that leans entirely on digital services.

The question rarely asked is how things look one level down. How well do we protect the digital infrastructure of offices, business premises, logistics centres, hospitals, care facilities, government buildings, schools and apartment complexes? This is the domain of what we call digital resilience at micro level.

It is an uncomfortable question, because the answer is often unknown. Many owners and users know exactly how their fire safety is arranged, but have no clear picture of who has access to their server room. Yet that information is essential to understanding how vulnerable a building actually is, digitally.

A confronting question

Put the question sharply. What is the value of a sophisticated national cybersecurity strategy when someone can reach the patch cabinet in a business premises unsupervised? Or, more concretely: we carefully protect our digital borders, but is the door to the server room actually locked?

A country can invest billions in cyber defence, but the chain still breaks at the unguarded technical room at the end of the corridor.

Digital infrastructure is physical

Behind every digital service lies an important principle: the internet feels virtual, but the infrastructure behind it is physical. Almost every online service ultimately consists of cables, fibre optics, routers, switches, antennas, servers, technical rooms, power supply, cooling and data centres.

Cloud sounds as if data floats somewhere in the air. In reality, that cloud ultimately sits on hardware, in a building, connected to power and a network. And that hardware, including the equipment in your own premises, can be touched, moved, switched off or damaged. That makes physical access to digital infrastructure a serious part of cybersecurity, not a side condition you leave to a single supplier.

That insight changes the way we look at a building. The door of the server room is no longer a side issue, but a link in the digital resilience of the entire organisation that works there.

Recognisable vulnerabilities at building level

The vulnerabilities are often everyday and recognisable. Think of situations such as:

  • a server room where multiple suppliers hold the same key;
  • a patch cabinet in a publicly accessible corridor;
  • unknown routers or 4G/5G modems without an owner;
  • old switches nobody is responsible for anymore;
  • unsecured fibre optic connections;
  • technical rooms quietly used as storage;
  • equipment without up to date documentation;
  • a single internet connection without any redundancy;
  • cameras and access control linked to poorly documented networks;
  • suppliers with permanent remote connections;
  • unregistered IoT equipment that has a say on the network.

The most important insight is that an attacker does not always need to be a sophisticated hacker. Sometimes physical access to hardware alone is enough to cause enormous disruption. Anyone who can reach a switch or patch cabinet unseen does not need a software vulnerability.

Think beyond data theft

Digital security is not only about stealing information. Availability is essential too. The relevant question is sometimes not whether someone steals your data, but what happens when someone simply switches off your network. Which processes fail then?

That list is often longer than expected: telephony, cloud software, payments, access systems, cameras, logistics, production, building management, elevator installations and meeting technology. For many organisations, connectivity is now just as essential as electricity. Without a network, work grinds to a halt, regardless of how securely the data itself is stored.

Availability is therefore a central theme in the way IT-Label looks at network redundancy. A second, independent connection is not a luxury, but a form of continuity that only stands out the moment the first connection fails.

Facade with a sharply defined shadow area
The resilience of a building is not determined by what you see on the facade, but by what happens in the technical rooms.

How long does recovery take?

We talk a great deal about data backups. But do we also have a recovery plan for the infrastructure itself? That is a different question, and often an unanswered one. What happens if a fibre optic cable is damaged, a patch cabinet is sabotaged, switches are removed, equipment fails due to fire or water, or the server room simply becomes inaccessible?

The core question is: how long does it take to get a building back up and running digitally? An hour, a day, a week? Each of those scenarios means a different story for revenue and business continuity. Anyone who does not know the answer cannot assess the risk either. Insight into what internet outage really costs starts with insight into your own infrastructure.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Where regulation brings digital and physical together

This development is now also visible in legislation. Since 15 August 2026, the Cybersecurity Act and the Critical Entities Resilience Act have been in force in the Netherlands. The Cybersecurity Act focuses on the digital resilience of organisations. The Critical Entities Resilience Act specifically strengthens the physical and operational resilience of essential organisations against, among other things, sabotage.

The fact that these two laws exist side by side is telling. It shows that digital and physical security can increasingly not be seen separately. An attack on a building can be digital, physical, or a combination of both. Legislators acknowledge this and treat both tracks as part of the same resilience.

It is important to stress that not every building or business automatically falls under these laws. They target specific sectors and entities. Still, the underlying logic applies more broadly. Anyone who understands the reasoning behind this legislation sees that digital resilience at building level is relevant, even without a legal obligation. You can read more context in our analysis of the Cybersecurity Act and the digital building layer.

Macro resilience consists of thousands of micro environments

This is where the macro and micro layers come together in a single analysis. National digital resilience ultimately consists of thousands of individual organisations, buildings, technical rooms and connections. Each of these links contributes to the whole, or forms its weak point.

A country can invest in strong fibre optic networks, cyber defence and redundant data centres. But organisations remain vulnerable when the last part of the chain, the connection inside their own building, is insufficiently protected. A chain is only as strong as its weakest link, and digital infrastructure is no exception to that rule.

That makes building level not a side issue, but the final piece. All investments at the top of the chain lose their value when the bottom remains unprotected. Resilience is only complete when those last few metres are in order too.

IT-Label as a digital MOT

This is where IT-Label finds its role. IT-Label is explicitly not a military or national security standard. It is an independent knowledge collective and a classification methodology that makes that often forgotten digital infrastructure at building level visible. Where much attention goes to the abstract, IT-Label maps out the concrete.

Think of physical security, fibre optics, redundancy, server rooms, patch cabinets, cabling, active network equipment, external connections, access control, IoT, building-bound systems, documentation, responsibilities and recovery options. Together these points form a picture comparable to a digital MOT: an inspection that shows what works, what is missing and where the vulnerabilities lie.

This connects to concepts such as Digital Due Diligence, digital delivery level and business continuity. IT-Label does not pass judgement on whether a building is good or bad. It shows what the digital quality is, so that owners and users can act with full information. The full classification from PREMIUM to SHELL provides a shared language for this.

A new question for real estate

In commercial real estate, we naturally assess fire safety, construction, electrics, sustainability, installations and energy performance. For each of these aspects, standards, inspections and reports exist. Nobody buys or rents a property without having insight into these matters.

So why do we not yet assess the digital resilience of a building as standard practice? An organisation can house thousands of employees, sensitive data and essential business processes in a building without knowing, prior to renting or buying, exactly how vulnerable the digital infrastructure is. That is an information gap that grows more uncomfortable by the day.

Micro-resilience

For this layer, we introduce the term micro-resilience: the digital and physical resilience of the infrastructure within a single building or organisation. It is the counterweight to, and at the same time the foundation of, the national resilience so widely discussed.

The premise is simple: macro-resilience begins with micro-resilience. National resilience only emerges when individual organisations, locations and buildings are prepared for disruption. Without that underlying layer, resilience remains a policy term rather than a workable reality.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Not only a security story

It would be a misunderstanding to read this purely as a threat narrative. The same measures that protect against sabotage also protect against ordinary incidents. Not every outage is an attack.

A network can just as easily fail because of an excavator hitting a cable, human error, water, fire, faulty equipment, power outages or poorly executed work. In all these cases, the same preparation helps: redundancy, documentation, clear responsibilities and a recovery plan. Digital resilience is therefore not only relevant to geopolitical threat. It is above all good risk management, and that fits every serious owner and user.

From that perspective, the label is not a defensive instrument, but a way to get the digital foundation of real estate in order. Anyone prepared for the everyday incident is usually also better prepared for the exceptional one.

Start with your own building

Modern conflicts show how dependent our society has become on digital infrastructure. We rightly invest in national cybersecurity, telecom networks and critical infrastructure. But ultimately, digital infrastructure enters somewhere through a building. Through a cable, through a router, through a technical room. And there a new question begins: how well have we actually protected that?

The concrete next step is straightforward. Map out what is happening in your own building. Who has access to the server room? Is there redundancy? Does documentation and a recovery plan exist? An IT-Label pre-inspection makes that situation visible before anything goes wrong, so you can act based on facts rather than assumptions.

Digital resilience begins on a large scale, but is won or lost at micro level. Together we make visible what is still invisible today. We invite property owners, tenants, IT professionals, security experts and government bodies to think together, via www.it-label.com, about digital resilience at building level.

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch