Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

ISO Certification and Cybersecurity in the Office

Why digital security does not only start with policy, but also with the building in which an organization works.

Insights··7 min read
ISO Certification and Cybersecurity in the Office

Key points

  • ISO 27001 focuses on how an organization organizes its information security, not on the physical infrastructure it works with on a daily basis.
  • An organization's digital resilience is partly determined by the connectivity, technical rooms and network facilities of the building.
  • Network segmentation, access control, redundancy and monitoring are building-related factors that support or limit security policy.
  • Through a classification from PREMIUM to SHELL, the IT-Label shows what digital foundation a building offers, without replacing an ISO certification.
  • ISO and the IT-Label reinforce each other: together they create a more complete picture of digital resilience.

Cybersecurity is receiving more attention in almost every organization. For their daily operations, companies have become dependent on cloud applications, digital communication, data, AI applications, smart systems and external connections. Where processes once ran locally and on paper, today almost everything runs through the network. This dependency makes the question of security urgent.

It is therefore logical that much attention goes to processes, employees and software. Awareness campaigns, policy, access management and security certifications rightly get priority. Yet one component often remains out of view: the physical environment in which the digital infrastructure comes together.

An office is not just a workplace. It is also the place where network facilities, connections and technical installations come together. Cybersecurity therefore does not stop at the front door of the organization, but continues into the meter cupboard, the patch room and the connection point on the street.

ISO certification: how organizations organize information security

ISO 27001 is the best-known standard for information security. The certification shows that an organization has structured and controlled its information security. This is not about a single measure, but about a coherent management system.

An ISO 27001 process covers topics such as:

  • the information security policy;
  • risk analysis and risk management;
  • access management;
  • processes and work instructions;
  • incident management;
  • employee awareness;
  • continuous improvement.

In short, ISO 27001 shows how an organization organizes and controls its information security. That is valuable and professional. But there is a question underneath that is asked less often: where does that organization actually stand, and how reliable is the technical environment in which all that policy has to function on a daily basis?

An organization can have excellent security processes and still depend on the infrastructure on which those processes run. Is the network facility reliable? Are critical systems reachable? Is there sufficient capacity? Are connections designed with redundancy, and are the technical rooms suitably equipped? An organization's digital security therefore does not start only with policy, but also with the infrastructure on which employees and systems function. We explain the distinction between these two worlds in our article on the difference between the IT-Label and ISO 27001.

An organization can have its policy perfectly in order and still be vulnerable, simply because the building does not deliver the digital foundation.

The role of the building in cybersecurity

If cybersecurity extends into the accommodation, it is useful to identify which building-related components play a role in this. They do not determine policy themselves, but they make it feasible or not.

Network segmentation

A modern office environment contains an increasing number of connected systems. Alongside the corporate network, there are guest networks, building systems and numerous IoT applications, from lighting to climate control. A well-designed network separates these streams from each other, so that a problem in one part does not automatically affect another. More background on these connected systems can be found in our overview of smart building technology.

Access control

Physical access is a component of digital security that is often underestimated. Secured technical rooms, access registration and limiting access to network facilities are part of a secure office. After all, digital security also starts with who has physical access to the infrastructure on which the organization runs.

Patch rooms and technical rooms

Technical rooms play a larger role than their size suggests. Organized cabling, equipment protection, climate control, accessibility for maintenance and professional design all contribute to reliability and continuity. A cluttered or poorly accessible technical room makes maintenance harder and increases the chance of malfunctions or errors.

Glass facade corner with sun shading
Behind a representative facade, the quality of the technical rooms determines how reliably an organization can work.

Fiber optics and connectivity

Reliable connections are the backbone of almost every organization. Fast internet connections, multiple connection options and future-proof capacity determine whether a building can meet today's and tomorrow's digital demand. An office without reliable connectivity increasingly forms a limitation, no matter how good the policy is. In our explanation of fiber optics in buildings, we go deeper into what a building needs for this.

Monitoring

Insight is becoming increasingly important. Monitoring connections, early detection of malfunctions, system management and preventive action all help to limit problems before they affect the organization. Visibility is a prerequisite for actually being able to manage risks.

Backup connections and redundancy

Security is not only about protection against attacks, but also about preparation for outages. Dual internet connections, alternative routes and minimal dependency on a single supplier ensure that the organization can continue to work if something goes wrong. We elaborate on this principle further in our article on network redundancy. After all, a secure organization must be resilient not only against threats, but also against disruptions.

What does the IT-Label add?

The IT-Label does not replace ISO certification and makes no statements about an organization's information security. The IT-Label is an independent classification methodology that shows what digital foundation a building offers and how prepared that building is for modern organizations.

For real estate parties, this layer of transparency provides insight into the existing IT infrastructure, the digital facilities, the technical possibilities and the future-proofing of a property. This makes visible what digital quality is present behind the facade, even before an organization moves in. How this assessment is established is explained under how the IT-Label works.

ISO and the IT-Label reinforce each other

The distinction is actually simple. ISO 27001 looks at the organization and answers the question: how is information security organized? The IT-Label looks at the building and answers the question: what digital infrastructure supports this organization? Together they create a more complete picture of digital resilience.

An organization can be ISO-certified and still have a vulnerable digital foundation, for example if the building offers insufficient connectivity, redundancy or suitable technical facilities. Policy and infrastructure are not a choice between the two, but two sides of the same resilience. We describe why this combination specifically matters for the security of organizations in our article on the IT-Label and cybersecurity.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Why this is becoming important for real estate

Tenant expectations are changing. A modern office must not only offer a good location, favorable energy performance and comfort, but also reliable digital infrastructure, secure technical facilities and support for hybrid working. Digital quality is thereby becoming part of the overall real estate quality.

For property owners, investors and developers, this means that the digital foundation weighs into the attractiveness and future-proofing of a property. For IT managers and facility managers, this means that when moving or entering a new lease period, they look not only at floor space and layout, but also at what the building delivers digitally. What you can check in advance is described under what tenants should pay attention to.

Building managers also have an interest in this transparency. After all, they are responsible for the daily reliability of technical rooms, connections and management. A clear classification helps them align expectations and responsibilities with owners and tenants. More on this perspective can be found in our article on technical managers and the IT-Label.

A secure office requires cooperation between IT and real estate

Cybersecurity is not solely the responsibility of the IT department. The building in which an organization works also plays an important role in its digital resilience. Policy and infrastructure belong together.

ISO certification helps organizations organize information security professionally. The IT-Label shows what digital foundation the building offers for this. A secure organization starts with good policy, but equally needs a secure and future-proof building infrastructure.

Would you like to know what digital foundation your property or future accommodation offers? Take a look at what the IT-Label precisely entails and map out how your building's infrastructure supports your organization. This way, you make the connection between digital security and real estate quality concrete.

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch