Source: The Conversation – UK

In the last few years, some of the UK’s biggest cultural institutions have experienced major threats to their security. A report by the public accounts committee (PAC) has warned that such incidents have exposed serious weaknesses across the sector but that the government has failed to devise a strategy to prevent them. This has left Britain’s cultural institutions open to similar future attacks.
We live in a time when digital systems underpin everything from ticketing to surveillance and building access. Sidelining cybersecurity leaves museums vulnerable to attacks that could threaten both their finances and their collections.
If the UK wants to avoid major attacks and thefts, it needs to learn a lesson from the recent Louvre heist where €88 million (£78 million) of jewels were stolen. An audit conducted just weeks before the incident exposed the Louvre’s spending priorities that left them vulnerable to theft. The report found that €169 million was spent on artwork and exhibitions but only €26.7 million on all forms of maintenance, including security.
The likely thinking of cultural institutions is that to remain financially resilient they have to spend more on money-making attractions, like artwork and exhibitions. However, this means that security sometimes becomes a low priority – less money is spent and less thought given to the importance of keeping it up to date. However, the financial loss from theft affects financial resilience by eroding emergency cash reserves and driving up insurance premiums.
As the Louvre’s audit shows, the museum could have perhaps avoided the theft had it taken its findings more seriously.
The issue of outdated security measures at the Louvre goes back to at least 2017. An audit at the time found that “certain workstations [had] obsolete operating systems (Windows 2000 and Windows XP) which no longer guarantee effective security”. Security updates for Windows 2000 ceased in 2010, and Windows XP in 2014.
Three weeks after the heist in 2025, the Louvre was criticised by France’s Court of Auditors for not taking the audits seriously and spending money on art instead of security in the years before the theft.
Similar weaknesses in investment priorities as the Louvre’s were exposed in a report made by The British Library in March 2024 into their cyber-attack.
In October 2023, The British Library experienced a severe cyber-attack. The library’s systems were infiltrated by hackers who locked out all network users and demanded a ransom of 20 Bitcoin (approximately £590,000). The ransom was not paid and the stolen data was auctioned and then leaked on the dark web.
The library’s report into the attack acknowledged that it happened because it had muddled through with a historical mixture of old systems from many sources, which didn’t have a recovery plan. This meant it took the British Library months to restore the most basic tool – the online catalogue. And even now, five major services, including the catalogue of illuminated manuscripts, remain unavailable.
The cultural institutions, government and even the PAC make the classic mistake of divorcing cybersecurity from physical security.
The report by PAC does mention “bringing together chief digital information officers and chief information security officers” and separately it praises the “National Museum Security Group”. However, there is no mention of encouraging dialogue between the groups.
This divide is very common, and is often built into organisational system. The most junior person responsible for both physical and cybersecurity is often the CEO, or possibly a chief operating officer (COO). This structure worked in the days when physical security did not rely on computers. However, today, when so much physical security relies upon technology, it just does not make sense. There should be someone further down the chain, such as a “chief security manager” or equivalent.
As the report by Apolo Security into the Louvre attack found: “this case highlights another growing challenge: the convergence between operational technology (OT) and information technology (IT). When camera, climate or access control systems are connected to the network, any digital divide can have immediate physical consequences.”
This false split between standard IT cybersecurity (the domain of the chief information security officer), operational technology (the unnoticed computer-enabled devices that keep things working like electronic doors or intruder alarms) and physical security is far from unique to the scope of PAC’s report.
A classic example is the cyber-attack on the Colonial Pipeline in 2021 – an American energy system that connects 29 refineries and serves major airports, military bases and more than 50 million Americans. Only the classic IT systems (billing) were attacked, but management shut down the entire operation as they feared the attack spreading to the operational devices on the pipelines themselves. This stopped all pipeline operations leading to flight alterations, panic buying and over 10,000 petrol stations running dry.
A more integrated approach was exhibited by the train operator Go-Ahead in 2022 in the UK, which had a similar attack on its systems. The company was able, however, to keep the trains running and deal with the source of the attack instead of halting all their operations.
It would be good to think that the UK culture sector would also learn these lessons. But alas, neither the evidence the government gave PAC nor the final report give us any reason to believe that things will become more connected when it comes to a joined-up view of security and stopping future attacks.
![]()
James Davenport is a Chartered Fellow of the British Computer Society, and sits on relevant British Standards Institute Committees.
Original source: https://analysis1.mil-osi.com/2026/08/07/museums-face-growing-cyber-threats-but-security-remains-an-afterthought/
