Smart offices equipped with IoT devices make working more efficient, but they also open new doors for cybercriminals. From smart lighting to access control systems, every connected device is a potential gateway into corporate networks and sensitive data. With the average cost of a data breach in the Benelux running as high as €6 million, businesses can't afford to treat cybersecurity as an afterthought when choosing office space.

New risks in modern office environments

The modern office has become an ecosystem of connected devices. Lighting adjusts automatically, sensors measure occupancy, and meeting room systems run entirely in the cloud. These smart systems continuously collect data on presence, movement patterns and meeting activity. For businesses, this means facilities management is no longer just about the kitchen and meeting rooms, it's also about the digital infrastructure and security behind them.

IoT devices are often designed with ease of use in mind, not security. Many ship with default passwords and limited scope for updates. Even seemingly harmless components like smart light bulbs can be exploited to break into the corporate network. IP cameras, printers and wireless access points are among the weakest links in office environments.

Hybrid working adds an extra layer of complexity. Employees switch between the office, home and flexible locations, each with its own security profile. Home networks often run on default settings, and public wifi on trains or in cafés carries risks such as eavesdropping and session hijacking. Neither way of working is automatically safer, actual security depends on the measures put in place.

Office types and their security implications

A dedicated office or floor offers maximum control over the IT environment. Organisations can set up their own network cabling, firewalls and access control according to their own security standards. However, this autonomy also means full responsibility. Configuration errors or negligence fall entirely on the tenant, including all obligations under GDPR and potentially the Cyber Security Act.

Serviced offices take a lot of digital provisioning off your hands. This is appealing for SMEs: no investment in complex network hardware and the benefit of professional management. Because multiple businesses share the same infrastructure, strict separation between networks is crucial. Without proper isolation, an incident affecting one tenant can pose a risk to others. Access system logs and camera footage are managed centrally, meaning tenants need to place a lot of trust in clear agreements on data processing.

From a cybersecurity perspective, coworking spaces are among the most challenging office concepts. High turnover of people, shared wifi and limited control over who's sitting where all increase the risk of incidents, such as unauthorised network access or device theft. Businesses handling privacy-sensitive data should therefore carefully consider which activities they carry out in a coworking environment and take additional measures, such as using a VPN and privacy screens.

Concrete security measures for smart offices

Network segmentation forms the foundation of a secure office environment. By splitting the corporate network into zones with limited traffic between them, a breach stays contained to a single segment. IoT devices belong on a separate network, isolated from critical business applications. Guests are given access to a separate guest network with no connection to internal systems. Under a zero-trust approach, every access request is treated as potentially untrustworthy, regardless of location.

Effective IoT security starts with visibility. Organisations need to maintain an up-to-date inventory of all connected devices, including building systems and their own equipment. Default settings should be changed: replace factory passwords, disable unused features and enable strong encryption. Regular firmware updates are essential to fix known vulnerabilities.

  • Implement strict network segmentation between IoT devices, guest networks and business-critical systems
  • Change all default passwords and disable unnecessary features on IoT devices
  • Maintain an up-to-date inventory of all connected devices and their vulnerabilities
  • Install updates and patches consistently, according to a fixed schedule
  • Actively monitor network traffic for unusual behaviour or unauthorised access attempts

The human factor remains crucial. Successful attacks often exploit weak passwords, phishing links or deception. A positive security culture, in which employees feel safe reporting mistakes, matters more than a culture of blame and shame. Training should focus on practical skills: locking computers, securely disposing of documents, and spotting suspicious individuals in open-plan offices.

GDPR defines personal data broadly. In smart offices, this includes access card logs, camera footage, wifi login details and sensor data, wherever these can be traced back to individuals. The complexity increases because much of this data is technically managed by landlords or third-party suppliers, while the tenant remains jointly responsible for lawfulness and security. This calls for clear data processing agreements and transparent arrangements on roles, access, retention periods and incident reporting.

The Cyber Security Act, the Dutch implementation of NIS2, introduces new obligations for essential and important organisations. Although the law is not yet in force, organisations need to prepare for a registration requirement, a duty to report incidents, and a duty of care to implement appropriate measures. For businesses falling under NIS2, office IT also needs to be factored into risk assessments, particularly where outages could disrupt service delivery.

The Digital Trust Center sets out five basic principles: take stock of vulnerabilities, choose secure settings, apply updates, restrict access, and prevent malware. These principles align with the measures described above and offer a practical starting point for organisations without a dedicated security team.

The business case for office security

With data breach costs averaging €6 million in the Benelux, investment in preventive measures pales in comparison to the potential damage. Yet security investment is often postponed because the payoff isn't immediately visible. For SMEs, realistic cybersecurity costs typically range between €50 and €300 per employee per month, with initial investments of anywhere from a few thousand to tens of thousands of euros, depending on the size and complexity of the organisation.

The business case for office security is about limiting risk and preventing damage. An investment in network segmentation can prevent a compromised IoT device from leading to losses running into the millions. There are also less tangible benefits: greater customer trust, better compliance with laws and regulations, and a stronger position in sectors where security certification is required.

Cyber insurance provides a financial safety net, but it doesn't replace preventive measures. Insurers are setting increasingly strict security requirements, such as timely updates, multi-factor authentication and network segmentation. Reputational damage and business disruption are, moreover, difficult to insure against, which is why prevention needs to remain the priority.

A practical approach when choosing office space

When selecting office space, it's important to ask concrete questions about the digital infrastructure. Ask about network design, separation between tenants, the update policy for building systems, monitoring, and the approach to incidents. Also ask what personal data is collected, how long it's retained, who has access, and how it's secured.

Security should be seen as a core part of an office's quality, not an added extra. An office with strong network isolation, a careful update policy and transparent data processing can justify a higher rent through lower risk of incidents. Be critical: a "smart office" label doesn't guarantee good security. Some environments packed with smart applications are designed purely for convenience, with security given little thought.

For organisations choosing a smart office environment today, it's essential not to see security as a brake on innovation, but as a condition for sustainable growth, continuity and trust.

Many businesses find it difficult to factor security into office decisions. The subject is quickly dismissed as too technical, or there's a fear it will complicate negotiations. A step-by-step approach helps: map out the biggest risks and tackle them in a targeted way. Bring in outside expertise where needed for an objective assessment and concrete recommendations.

The shift to smart offices brings opportunities for efficiency and flexibility. By factoring cybersecurity into decision-making from the outset, organisations can capture these benefits without underestimating the risks. The difference between a smart, secure working environment and a costly pitfall lies in well-considered choices, thoughtful measures and a mature security culture. At a time when a single data breach can cost millions, investing in office security isn't a luxury, it's a necessity.