Beta

Museums face growing cyber threats but security remains an afterthought

Featured image for article: Museums face growing cyber threats but security remains an afterthought
This is a review of an original article published in: theconversation.com.
To read the original article in full go to : Museums face growing cyber threats but security remains an afterthought.

Below is a short summary and detailed review of this article written by FutureFactual:

UK Museums Face Growing Cyber Threats: PAC Warns of Security Gaps After Louvre Heist and British Library Attack

The article highlights a Public Accounts Committee (PAC) warning that UK cultural institutions face rising cyber threats and outdated security practices. It links a Louvre audit that exposed security gaps to a 2023 British Library ransomware incident, arguing for integrated cyber and physical security across museums and libraries. The piece notes calls for better collaboration between chief digital information officers and chief information security officers, and references the National Museum Security Group. Original publisher: Future Factual.

  • Cyber threats target major museums and libraries, risking finances and collections
  • Louvre audit reveals security underinvestment relative to art spending
  • Calls for closer collaboration between IT and cyber security leadership
  • Real world examples show the need for integrated, reinforced security across the sector

Overview

UK cultural institutions are being exposed to a rising wave of cyber threats as digital systems underpin nearly all operations from ticketing to building access. A Public Accounts Committee (PAC) report argues that these incidents reveal serious weaknesses across the sector and that the government has not articulated a coherent strategy to prevent future attacks. The article connects high profile incidents in museums and libraries to broader security misalignments that threaten both finances and collections.

Security Landscape in Museums

The piece contends that cultural institutions often prioritise money making attractions over maintenance and security, which in turn erodes emergency cash reserves and raises insurance costs after theft or incident. It cites the Louvre as a case study, where an audit found that €169 million was spent on artworks and exhibitions while only €26.7 million went to maintenance including security. The implication is that vulnerabilities persist when funds do not proportionally support security infrastructure.

Case Studies

The article references a 2017 Louvre security audit that flagged obsolete operating systems such as Windows 2000 and Windows XP, noting that security updates for these platforms had long ceased. It also describes the Louvre theft in 2025 and the French Court of Auditors’ critique that the museum did not act on prior audits and continued to prioritise acquisitions over security investments in the years leading up to the theft. In October 2023, The British Library suffered a severe cyber-attack in which hackers demanded a ransom of 20 Bitcoin, approximately £590,000. The data was auctioned and leaked on the dark web after the ransom was not paid. The library’s own report attributes the breach to a muddled mix of old, disparate systems with no recovery plan, which delayed restoring critical services such as the online catalogue and left five services unavailable five years later.

Organizational and Governance Gaps

The PAC report is critical of a persistent divide between cybersecurity and physical security within cultural institutions. It notes an admirable commitment to dialogue through structures like the National Museum Security Group, but argues that there is insufficient cross talk between chief digital information officers and chief information security officers. The article suggests structural changes, such as appointing a lower‑level security leader like a chief security manager who can bridge OT and IT while reporting into broader leadership. A cited Louvre study also emphasizes the convergence challenge between operational technology and information technology when devices such as cameras, climate controls and access systems are networked, highlighting the immediate physical consequences of digital divides.

Lessons from Other Sectors

Examples from other critical infrastructures are invoked to illustrate best practices. The 2021 Colonial Pipeline cyberattack in the United States forced shutdowns that disrupted gas supply, while UK train operator Go-Ahead managed to keep services running by addressing the attack's root cause rather than halting operations entirely. The article argues that a more integrated approach to security in the culture sector could prevent similar widespread disruption and reduce financial and reputational damage from attacks.

Recommendations for the Culture Sector

The PAC report advocates for a joined up vision of security that treats cyber and physical protections as an integrated risk management problem. It praises the National Museum Security Group for its work but calls for more deliberate coordination across chief digital information officers and chief information security officers. The piece also emphasizes the need for adequate maintenance funding and continual updating of security controls in line with evolving threats, rather than treating cybersecurity as a secondary concern to commercial strategies or art acquisitions.

Conclusion

As digital technologies underpin all facets of museum and library operations, the article concludes that the UK culture sector must apply lessons from Louvre and British Library incidents to build a more resilient, integrated security posture. The goal is to safeguard both finances and invaluable collections through sustained investment and closer cross-disciplinary leadership.