Case Study · Managed Workplace

Twenty five hotels. Seven countries. Twelve brands. One workplace foundation.

Twenty five hotels, seven countries, twelve brands. How Borealis Hotel Group runs one managed workplace foundation with Sbit.

service-6

Chapter 01 · The situation

A multi brand operator has a workplace problem most groups do not.

Borealis Hotel Group has been building this portfolio since 1997. Twenty five operating hotels. Over 4,400 rooms. Seven countries. Twelve brands, drawn from the Marriott, Hilton, IHG and Accor families. Headquartered in Amstelveen and Wiesbaden, operating from the Atlantic coast to the Danube. Borealis develops, invests and manages, and the world’s largest hotel brands treat them as a preferred partner in Europe. All of that is on the website. What is not on the website is the operating challenge underneath it.

A staff member checking in a guest in Vienna and a staff member checking in a guest in Málaga are working under different brand standards, on different property systems, in different regulatory frameworks. The workplace layer is what makes them one team.

Every brand comes with its own operational IT expectations. Marriott properties integrate with GXP. Hilton properties tie into OnQ and Digital Key. IHG properties connect through Concerto. Accor properties run against TARS. On top of that, every country adds its own compliance layer: GDPR everywhere, NIS2 wherever the group meets scope, plus national variations on labour, tax and data residency. In that environment, the workplace is not a productivity tool. It is the connective tissue that lets 25 different operational contexts function as one company.

What makes this workplace challenge specific

The Borealis workforce is not homogeneous. Reception, F&B and housekeeping staff need frontline devices and shared login environments that turn over multiple times per shift. Sales, revenue management, finance and IT need knowledge worker tools with the full Microsoft 365 stack, secure email, and access to systems that carry the group’s commercial and financial data. Both populations move between properties as the group grows and reshuffles teams. Both populations sit in the same Active Directory. Both have to be onboarded, offboarded and trained without friction.

A workplace layer that only serves one of those populations well is not enough. Borealis needs both, held to one standard, across a portfolio that keeps expanding.

Chapter 02 · What we manage

Managed Workplace, tuned for how Borealis actually runs.

Sbit runs Managed workplace across every operating property in the Borealis portfolio. Not as a stack of licences, but as an operational discipline: identity, devices, access and awareness treated as one integrated layer. It is the domain most hospitality groups underinvest in until an incident forces the conversation. Borealis had the conversation before the incident.

The four pillars of the Borealis workplace

Managed workstations

Fixed workstations across reception, back office and shared operational areas, all managed as one service. Patch management, antivirus, remote support, hardware monitoring and asset inventory under one agreement. Every workstation looks and behaves the same, whether it is in Hamburg or Copenhagen.

Managed user access with awareness training

Per user identity, access and productivity support, with an integrated anti phishing and security awareness training layer purpose built for Borealis staff. Every user is continuously exposed to realistic phishing simulations and short training modules. The result is measurable staff resilience, not compliance box ticking.

License management, tiered by role

Sbit runs the full Microsoft licensing layer for the group, tiered per role. Knowledge workers get the tools their work needs. Frontline staff get what the front desk needs. Provisioning, tracking, changes and renewals sit with Sbit under one agreement. The group pays for what each role actually uses.

Central email and endpoint protection

Central email, calendaring and endpoint protection running across every property. The security posture that comes with knowledge workers handling corporate data at group HQ, and the operational simplicity that frontline staff need at the front desk. One control plane, one baseline.

Together these pillars deliver something Borealis specifically needed: a workplace that works the same for a shift supervisor in Munich and a finance controller in Amstelveen, with each getting the tools and security profile appropriate to their role, and neither having to think about IT.

Chapter 03 · How we operate

The operating model behind the workplace layer.

Managing workplace across 25 hotels in seven countries is not about scale. It is about consistency. The same standards, the same response times, the same access controls, whatever brand is above the door and whatever country the property sits in.

Onboarding at the pace the business runs

New staff at any property have a fully provisioned workplace ready on day one. Identity, mailbox, access to property systems, Microsoft 365 tier appropriate to the role, security awareness training already scheduled. Not three days later. Not “after the local IT person gets to it,” because there is no local IT person. Sbit is the local IT function at every property.

Offboarding measured in minutes

When someone leaves the group, their access is revoked within minutes, not at the next audit. That single discipline is worth more than most security tools stacked together. The former employee cannot log in from home. The mailbox is preserved for the compliance window and then removed. The next hire starts from a clean state.

Multi brand fluency, not multi vendor scramble

Sbit engineers who serve Borealis know the IT standards of every brand in the portfolio. Marriott GXP integration, Hilton OnQ and Digital Key touchpoints, IHG Concerto access, Accor TARS provisioning. When a property opens or a system upgrade lands, the workplace layer is ready to integrate without a discovery phase.

The 3pm Friday moment

Some incidents can wait until Monday morning. Some cannot. A workplace failure at 3pm on a busy Friday, as the check in wave starts and the weekend arrivals stack up in reception, is not a Monday problem. Everyone who operates hotels knows this. What matters is whether your IT partner also knows it, and whether they act on it before you have to explain the operational urgency to a service desk that treats every ticket the same.

The invisible test of managed workplace is what does not happen. No local IT firefighting. No 15 minute waits on hold at check in. No mailbox left open six months after someone left. Absence, engineered.

Chapter 04 · What that delivers

Outcomes across four audiences.

A workplace layer this thoroughly integrated produces different outcomes for different people looking at it. Every one of them is measurable, most of them are quiet, all of them are the reason the partnership renewed.

Four audiences, four outcomes

Frontline and management staff

The workstation just works, whether you are in Vienna or Amsterdam. Login is the same. Access is the same. Support is the same number. Moving between properties for a training week or a temporary cover shift does not involve relearning the workplace.

Group IT leadership

Dashboard visibility of every user across every property. Onboarding and offboarding rate as a monthly metric, not a support anecdote. Phishing simulation results as a staff resilience KPI. Security posture measurable, provable, auditable.

Property management

No local IT firefighting. No cluster of workarounds that grow into a technical debt problem. When something breaks, the escalation goes to one number. When it is fixed, it is fixed for every property with the same configuration.

Finance and the board

Predictable managed workplace fees per user per month, scaled by tier. No surprise capex. NIS2 board level responsibility supported by documented, auditable workplace controls. The workplace investment is a line item finance can plan against, not a variable finance has to explain.

The compliance line, quietly

Access is audited. Devices are patched. Users are trained continuously. Onboarding and offboarding are documented. Under NIS2, these are not luxuries. They are the four things a board is personally accountable for. Borealis has them, running as normal operations, without the compliance conversation dominating the day to day.

Chapter 05 · The partnership

Extension of operation, not extension of vendor list.

Every long partnership eventually gets a shorthand from the client side about what the vendor actually is. In technology, most of that shorthand ends up sounding like “our IT provider.” Sometimes something more specific comes out, and it tells you what the working relationship actually is.

The line that matters, from the person accountable for IT across the group, is that Sbit is not a supplier. Sbit is an extension of the operation. That framing does not describe the SLA. It describes a working relationship where the vendor’s engineers know what a critical outage at 3pm on a busy Friday costs the business, and act on it without waiting for the customer to build the escalation case. In hospitality, where the cost of downtime is compounding and the operational calendar has its own rhythm, that framing is not a soft descriptor. It is the operating requirement.

Borealis has been growing this portfolio since 1997. The next set of properties are already committed in the development pipeline. The workplace layer that Sbit runs today is what makes the next opening land smoothly. Same standards. Same day one readiness. Same 3pm Friday accountability, whichever new city the group opens in next.

Sbit isn't an IT supplier to us. They're an extension of our operation. They understand what a critical system outage means at 3pm on a busy Friday, and they act on it before we have to ask. No escalations. No debate about scope. Just resolution.


Mihai Damian

IT Director · Borealis Hotel Group

Let's talk

Running a multi brand portfolio across countries?

Book a conversation. If you operate hotels across multiple brands and multiple regulatory jurisdictions, we can walk your current workspace layer, name where the standardisation gaps sit, and show you what one accountable partnership changes for the group and the properties.