{"id":1327,"date":"2026-08-07T10:00:22","date_gmt":"2026-08-07T10:00:22","guid":{"rendered":"https:\/\/redzine.co.uk\/index.php\/2026\/08\/07\/museums-face-growing-cyber-threats-but-security-remains-an-afterthought\/"},"modified":"2026-08-07T10:00:22","modified_gmt":"2026-08-07T10:00:22","slug":"museums-face-growing-cyber-threats-but-security-remains-an-afterthought","status":"publish","type":"post","link":"https:\/\/redzine.co.uk\/index.php\/2026\/08\/07\/museums-face-growing-cyber-threats-but-security-remains-an-afterthought\/","title":{"rendered":"Museums face growing cyber threats but security remains an afterthought"},"content":{"rendered":"<figure><img decoding=\"async\" src=\"https:\/\/images.theconversation.com\/files\/752247\/original\/file-20260805-50-xr17hd.jpg?ixlib=rb-4.1.1&amp;rect=0%2C0%2C3000%2C1999&amp;q=45&amp;auto=format&amp;w=1050&amp;h=700&amp;fit=crop\" \/><figcaption><span class=\"caption\">Up to 1,500 items were identified as missing or stolen from the British Museum following a review of its collection in 2023.<\/span> <span class=\"attribution\"><a class=\"source\" href=\"https:\/\/www.shutterstock.com\/image-photo\/london-uk-june-4-2015-unidentified-374244283?trackingId=236aed3f-aa85-42ba-b1b2-c6ee8cd7dadc&amp;listId=searchResults\">Flik47\/Shutterstock<\/a><\/span><\/figcaption><\/figure>\n<p>In the last few years, some of the UK\u2019s biggest cultural institutions have experienced major threats to their security. A <a href=\"https:\/\/committees.parliament.uk\/committee\/127\/public-accounts-committee\/news\/214455\/museums-left-vulnerable-to-cyberattack-as-government-overly-reactive-in-face-of-threats\/\">report<\/a> by the public accounts committee (PAC) has warned that such incidents have exposed serious weaknesses across the sector but that the government has failed to devise a strategy to prevent them. This has left Britain\u2019s cultural institutions open to similar future attacks. <\/p>\n<p>We live in a time when digital systems underpin everything from ticketing to surveillance and building access. Sidelining cybersecurity leaves museums vulnerable to attacks that could threaten both their finances and their collections.<\/p>\n<p>If the UK wants to avoid major attacks and thefts, it needs to learn a lesson from the recent <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cj9722wlmj7o\">Louvre heist<\/a> where \u20ac88 million (\u00a378 million) of jewels were stolen. An <a href=\"https:\/\/www.ccomptes.fr\/sites\/default\/files\/2025-12\/20251106-summary-The-public-establishment-of-the-Louvre-Museum.pdf\">audit<\/a> conducted just weeks before the incident exposed the Louvre\u2019s spending priorities that left them vulnerable to theft. The report found that \u20ac169 million was spent on artwork and exhibitions but only \u20ac26.7 million on all forms of maintenance, including security.<\/p>\n<p>The likely thinking of cultural institutions is that to remain financially resilient they have to spend more on money-making attractions, like artwork and exhibitions. However, this means that security sometimes becomes a low priority \u2013 less money is spent and less thought given to the importance of keeping it up to date. However, the financial loss from theft affects financial resilience by eroding emergency cash reserves and driving up insurance premiums. <\/p>\n<p>As the Louvre\u2019s audit shows, the museum could have perhaps avoided the theft had it taken its findings more seriously. <\/p>\n<p>The issue of outdated security measures at the Louvre goes back to at least 2017. An <a href=\"https:\/\/www.liberation.fr\/checknews\/louvre-en-mot-de-passe-logiciels-obsoletes-mises-a-jour-impossibles-dix-ans-defailles-dans-la-securite-informatique-du-premier-museeau-monde-20251101_RD5YGV6WMVAXLL6U3SRGVFBIBY\/\">audit<\/a> at the time found that \u201ccertain workstations [had] obsolete operating systems (Windows 2000 and Windows XP) which no longer guarantee effective security\u201d. Security updates for Windows 2000 ceased in 2010, and Windows XP in 2014.<\/p>\n<p><strong>Three weeks after the heist in 2025, the Louvre was <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c93dj92d5y0o\">criticised<\/a> by France\u2019s Court of Auditors for not taking the audits seriously and spending money on art instead of security in the years before the theft.<\/strong><\/p>\n<p>Similar weaknesses in investment priorities as the Louvre\u2019s were exposed in a <a href=\"https:\/\/www.bl.uk\/home\/british-library-cyber-incident-review-8-march-2024.pdf\">report<\/a> made by The British Library in March 2024 into their cyber-attack.<\/p>\n<p>In October 2023, The British Library experienced a severe cyber-attack. The library\u2019s systems were infiltrated by hackers who locked out all network users and demanded a ransom of 20 Bitcoin (approximately \u00a3590,000). The ransom was not paid and the stolen data was auctioned and then leaked on the dark web.<\/p>\n<p>The library\u2019s report into the attack acknowledged that it happened because it had muddled through with a historical mixture of old systems from many sources, which didn\u2019t have a recovery plan. This meant it took the British Library months to restore the most basic tool \u2013 the online catalogue. And even now, five major services, including the catalogue of illuminated manuscripts, remain unavailable.<\/p>\n<p>The cultural institutions, government and even the PAC make the classic mistake of divorcing cybersecurity from physical security. <\/p>\n<p>The report by PAC does mention \u201cbringing together chief digital information officers and chief information security officers\u201d and separately it praises the \u201cNational Museum Security Group\u201d. However, there is no mention of encouraging dialogue between the groups.<\/p>\n<p>This divide is very common, and is often built into organisational system. The most junior person responsible for both physical and cybersecurity is often the CEO, or possibly a chief operating officer (COO). This structure worked in the days when physical security did not rely on computers. However, today, when so much physical security relies upon technology, it just does not make sense. There should be someone further down the chain, such as a \u201cchief security manager\u201d or equivalent. <\/p>\n<p>As the report by Apolo Security <a href=\"https:\/\/www.apolocybersecurity.com\/en\/blog-posts\/el-fallo-deciberseguridad-en-el-louvre-que-permitio-el-historicorobo\">into the Louvre attack<\/a> found: \u201cthis case highlights another growing challenge: the convergence between operational technology (OT) and information technology (IT). When camera, climate or access control systems are connected to the network, any digital divide can have immediate physical consequences.\u201d<\/p>\n<p>This false split between standard IT cybersecurity (the domain of the chief information security officer), operational technology (the unnoticed computer-enabled devices that keep things working like electronic doors or intruder alarms) and physical security is far from unique to the scope of PAC\u2019s report. <\/p>\n<p>A classic example is the cyber-attack on the <a href=\"https:\/\/www.nytimes.com\/2021\/05\/08\/us\/politics\/cyberattack-colonial-pipeline.html\">Colonial Pipeline<\/a> in 2021 \u2013 an American energy system that connects 29 refineries and serves major airports, military bases and more than 50 million Americans. Only the classic IT systems (billing) were attacked, but management shut down the entire operation as they feared the attack spreading to the operational devices on the pipelines themselves. This stopped all pipeline operations leading to flight alterations, panic buying and over 10,000 petrol stations running dry. <\/p>\n<p>A more integrated approach was exhibited by the <a href=\"https:\/\/www.theguardian.com\/business\/2022\/sep\/06\/go-ahead-cyberattack-bus-services-thameslink-rail\">train operator Go-Ahead in 2022<\/a> in the UK, which had a similar attack on its systems. The company was able, however, to keep the trains running and deal with the source of the attack instead of halting all their operations. <\/p>\n<p>It would be good to think that the UK culture sector would also learn these lessons. But alas, neither the evidence the government gave PAC nor the final report give us any reason to believe that things will become more connected when it comes to a joined-up view of security and stopping future attacks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/counter.theconversation.com\/content\/286488\/count.gif\" alt=\"The Conversation\" width=\"1\" height=\"1\" \/><\/p>\n<p class=\"fine-print\"><em><span>James Davenport is a Chartered Fellow of the British Computer Society, and sits on relevant British Standards Institute Committees.<\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Up to 1,500 items were identified as missing or stolen from the British Museum following a review of its collection in 2023. Flik47\/Shutterstock In the last few years, some of the UK\u2019s biggest cultural institutions have experienced major threats to their security. A report by the public accounts committee (PAC) has warned that such incidents [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1327","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/1327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=1327"}],"version-history":[{"count":0,"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/1327\/revisions"}],"wp:attachment":[{"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=1327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=1327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/redzine.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=1327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}