The Cyberbeveiligingswet Doesn’t Regulate Real Estate. It Doesn’t Have To  |

0
1
The Cyberbeveiligingswet Doesn’t Regulate Real Estate. It Doesn’t Have To  |


The Cyberbeveiligingswet Deadline: Why Dutch Real Estate’s Security Gap Is About to Get Expensive

A Dutch notary moves hundreds of thousands of euros in a single property closing, sometimes with little more than a shared inbox and a scanned passport standing between the money and a criminal running a lookalike domain. Most notary offices, mortgage advisers and small brokerages have no security team and no monitoring in place. Dutch regulators start asking why on August 15, 2026.

A Law That Does Not Name Real Estate, But Reaches It Anyway

The Cyberbeveiligingswet, the Dutch implementation of the European Union’s NIS2 Directive, takes effect on August 15, 2026, according to the Dutch government. The law applies to about 8,000 organizations across eighteen sectors the Dutch National Cyber Security Centre classifies as essential or important, among them energy, transport, banking, digital infrastructure and health. Real estate agents, mortgage brokers, appraisers and notaries do not appear on the NCSC’s list.

Scope on paper is not scope in practice, though. The NCSC’s guidance states that larger regulated companies must manage risk across their supply chains. In practice, the supply-chain clause lets banks, lenders and financial platforms push the requirement down to vendors, brokers and service providers, who now have to prove they are secure too. Layer on the Digital Operational Resilience Act, which has applied to EU banks, lenders and servicers since January 17, 2025, and the pressure compounds. DORA requires financial entities to keep a live register of every ICT third party they rely on and to monitor the vendor relationships on an ongoing basis, according to the European Banking Authority. A mortgage lender filling out its DORA register has to list every software vendor, broker and data processor that touches a loan file, and increasingly ask each one for proof of a working security program.

Why Property Deals Make an Easy Target

Real estate and mortgage transactions combine three things attackers look for: money, personal data and a fragmented supplier base. The FBI’s Internet Crime Complaint Center recorded 12,368 real estate fraud complaints and $275.1 million in reported losses for 2025. Business email compromise, the scheme most closely tied to home closings, caused $3.04 billion in reported losses across all sectors in the same report, more than eleven times the real estate figure alone. A single altered wire instruction sent from a hacked email account can move a down payment into a criminal’s account before anyone notices.

Buildings carry a different kind of risk. Twenty-seven percent of facility managers and building service providers surveyed by the Royal Institution of Chartered Surveyors reported a cyberattack on their building in the past year, up eleven percentage points from the year before. Smart locks, connected cameras, elevators and climate systems increasingly sit on the same networks as tenant portals and payment systems, and building operators rarely patch them with the discipline a bank applies to its core infrastructure.

Liplyn’s Bet on the Long Tail

Small brokerages, notaries and mortgage advisers without security budgets are exactly the gap Liplyn Information Group is now chasing. In June 2026, the Hilversum-based marketing and AI consultancy announced a strategic partnership with HaxUnit, a Dutch platform built for continuous, agentless attack surface monitoring. HaxUnit maps a company’s externally visible domains, subdomains, IP addresses and open ports without installing software on the client side, then flags vulnerabilities with evidence and remediation steps attached. The partnership folds HaxUnit’s monitoring technology into Liplyn’s cybersecurity practice, alongside its data and AI Search Visibility services and new NIS2-readiness support. “Visibility without control creates risk,” Liplyn founder Luke Liplijn said of the deal. 

Liplyn’s cybersecurity pitches a free version of the scan: point a domain at the platform, and it returns a baseline map of up to 100 discovered assets at no cost, a low-friction way for a two-person mortgage advisory firm to see what an attacker already sees. Liplyn cites platform-wide figures of more than 75,000 externally visible assets discovered and over 5,000 vulnerability findings prioritized to date. The numbers describe HaxUnit’s full customer base rather than Liplyn’s specifically, and come from the vendor rather than an independent audit.

What a Scan Cannot Fix

Even the marketing material behind attack surface monitoring concedes its limits. The approach does not replace the fundamentals: strong authentication, staff training, tested backups, supplier vetting and, where warranted, a full penetration test. A continuously updated map of what is visible from the internet answers one question. It does not answer whether a mortgage adviser’s staff can spot a lookalike domain in their inbox, or whether a notary’s payment approval process would catch an altered bank account number before a transfer goes out.

The real value of Liplyn’s cybersecurity practice, in the mortgage chain, is less about the underlying technology and more about the price of entry. A free scan gives a small advisory firm a reason to start a conversation about security it would otherwise put off indefinitely. Whether the conversation turns into a genuine security program, or a compliance checkbox ticked once and forgotten, depends on what the buyer does after the free report lands in their inbox, not on the scan itself.

Beyond the Mortgage Chain

Real estate and mortgages are not the only trade full of small firms sitting inside a regulated supply chain. Law firms, accountants, insurance brokers and independent software vendors serving banks and hospitals face the identical arithmetic: a law that does not name them directly, paired with clients who will ask anyway once their compliance deadline lands.

The Cyberbeveiligingswet will not turn every small Dutch business into a full security operation overnight, but it gives every bank, lender and platform a reason to make security a line item in every vendor contract signed after mid-August. For the thousands of small offices sitting quietly inside the Dutch mortgage chain, ignoring the deadline is no longer an option. How seriously an office takes security might be the only thing standing between it and keeping the client relationship at all.