A smart building is convenient. The climate adapts to occupancy, the door opens with your phone and the installer can fix a fault remotely. But everything connected to the network can also be a way in for someone who does not belong there.
What is connected to the network?
In a modern commercial building, that quickly adds up to a lot of devices:
- the building management system for heating, cooling and ventilation;
- access control and visitor registration;
- cameras;
- lighting and sun shading;
- sensors that measure whether rooms are occupied;
- lifts, charging points and meters.
Together this is called the Internet of Things: devices that connect and send data by themselves.
Why this is a risk
Many of these devices are made to work, not to be secure. What we often come across in practice:
- Default passwords that were never changed after installation.
- No updates. A device that has not been updated for years often has known weaknesses.
- Remote access for the installer that was never switched off.
- Everything on one network. The camera, the thermostat and the tenant's laptops are all on the same network.
That last one is the biggest problem. If everything is connected, a weakness in a simple sensor can give someone access to far more important systems.
The solution: separate the networks
The most important measure is network segmentation. You divide the network into separate parts that cannot simply reach each other. For example:
- a network for the building systems;
- a network for each tenant;
- a guest network for visitors.
A firewall determines which traffic is allowed between those parts. That way the climate system can do its job without being able to reach a tenant's files. And one tenant cannot get onto another tenant's network.
Five more measures that make a big difference
- Change all default passwords and record who manages which password.
- Keep a list of all devices connected to the network. You cannot secure what you do not know about.
- Update devices. Agree with suppliers who does this and how often.
- Limit remote access. Only when needed, via a secure connection, and with a log.
- Record who is responsible. In a let building that is often unclear. The IT Demarcation List puts it in black and white.
Laws and regulations
Since 15 August 2026, the Cybersecurity Act (Cyberbeveiligingswet) has applied in the Netherlands. It is the Dutch implementation of the European NIS2 directive. It applies to organisations that provide essential or important services. Whether you fall under it as an owner depends on your sector and size. But tenants who do fall under it will set requirements for the network and building systems of the building they occupy.
The GDPR also plays a role. Cameras, access passes and visitor registration process personal data. Read more on our page IT and regulation.
What does this mean for the IT-Label?
Cybersecurity is one of the six components of the IT-Label, just like Smart Building. During an IT-Label audit we look at how the networks are set up and whether building systems are properly shielded. Buying a building? Then this also belongs in a digital due diligence.
Want to know how your building performs? Start with the free self-scan.