Rising Cyber Threats Expose Museums’ Neglected Security

0
22

Key Takeaways

  • Recent PAC report warns that UK cultural institutions face growing security threats due to a lack of a coordinated government strategy.
  • Digital systems now underpin ticketing, surveillance, and building access, making cybersecurity inseparable from physical security.
  • The 2025 Louvre heist revealed a stark imbalance: €169 million spent on art versus only €26.7 million on maintenance and security.
  • Out‑of‑date operating systems (Windows 2000/XP) persisted at the Louvre for years, despite audits flagging the risk.
  • The British Library’s 2023 ransomware attack exposed a patchwork of legacy systems and the absence of a recovery plan, leaving core services offline for months.
  • Organizational silos that separate IT cybersecurity from operational technology (OT) and physical security create dangerous gaps.
  • Integrated approaches—exemplified by Go‑Ahead’s response to a cyber incident—show that maintaining operations while addressing threats is possible when OT and IT are unified.
  • The UK culture sector must adopt a joined‑up security strategy that aligns funding, governance, and technology to prevent future losses.

Introduction to Growing Threats
The Public Accounts Committee (PAC) has highlighted that several of the UK’s largest cultural institutions have suffered significant security breaches in recent years. Its report warns that these incidents expose serious sector‑wide weaknesses, yet the government has failed to develop a overarching strategy to prevent them. Consequently, museums, galleries, and libraries remain exposed to similar future attacks unless decisive action is taken.

Digital Infrastructure Dependence
Today, digital systems are embedded in virtually every aspect of cultural‑venue operations: ticketing platforms, visitor‑flow analytics, climate‑control sensors, electronic door locks, and surveillance networks all rely on interconnected IT infrastructure. When cybersecurity is neglected, attackers can exploit these digital footholds to disrupt services, steal valuable data, or even facilitate physical thefts, jeopardising both financial stability and the integrity of collections.

Lessons from the Louvre Heist
In 2025, thieves stole jewellery worth €88 million (≈ £78 million) from the Louvre. An audit conducted just weeks before the robbery showed that the museum had allocated €169 million to artwork and exhibitions while devoting only €26.7 million to all forms of maintenance, including security. The disparity underscores a common belief that revenue‑generating attractions should take precedence over protective measures—a mindset that proved costly when the theft occurred.

Financial Resilience vs. Security Prioritization
Cultural institutions often justify heavy spending on exhibitions by arguing that it bolsters financial resilience. However, diverting funds away from security erodes that very resilience: theft drains emergency cash reserves, drives up insurance premiums, and can result in long‑term reputational damage. The Louvre’s loss illustrates how under‑investment in protection can ultimately outweigh any short‑term gains from blockbuster shows.

Historical Neglect of Security Systems at the Louvre
Security shortcomings at the Louvre are not new. An audit as early as 2017 flagged that many workstations were running obsolete operating systems—Windows 2000 and Windows XP—both of which had ceased receiving security updates years earlier (2010 and 2014, respectively). Despite repeated warnings, the museum continued to prioritize acquisitions, and three weeks after the 2025 heist France’s Court of Auditors criticised it for ignoring the audit findings and under‑funding security.

British Library Cyber‑Attack Overview
In October 2023, the British Library suffered a severe ransomware incident. Hackers infiltrated the network, locked out all users, and demanded a ransom of 20 Bitcoin (≈ £590 000). The library refused to pay; the stolen data was subsequently auctioned and leaked on the dark web. The attack highlighted how a single cyber intrusion can cripple essential services and expose sensitive information.

Aftermath and Recovery Challenges at the Library
The Library’s post‑incident report attributed the breach to a “historical mixture of old systems from many sources” that lacked a coherent recovery plan. Because of this fragmented environment, restoring even the basic online catalogue took months. As of now, five major services—including the catalogue of illuminated manuscripts—remain unavailable, demonstrating how legacy IT can prolong disruption long after the initial attack.

The Persistent Divide Between Cyber and Physical Security
The PAC report acknowledges the need to bring together chief digital information officers and chief information security officers, and it praises the National Museum Security Group. Yet it fails to advocate for concrete dialogue between these teams. This reflects a widespread organisational pattern where the CEO or COO oversees both domains—a structure that made sense when physical security was largely analogue but is inadequate now that locks, alarms, and climate controls are network‑enabled.

Operational Technology and IT Convergence Risks
Apolo Security’s analysis of the Louvre breach stresses the growing convergence between operational technology (OT) and information technology (IT). When cameras, access‑control systems, or environmental monitors are linked to the same network, a digital vulnerability can trigger immediate physical consequences—such as disabling a door lock or altering climate settings that endanger artefacts. Treating OT and IT as separate silos therefore creates blind spots that attackers can exploit.

Case Studies: Colonial Pipeline and Go‑Ahead
The 2021 Colonial Pipeline ransomware attack in the United States showed the danger of treating IT and OT as distinct: although only billing systems were compromised, operators shut down the entire pipeline for fear the infection would spread to OT devices, causing fuel shortages across the East Coast. By contrast, UK train operator Go‑Ahead faced a similar cyber incident in 2022 but kept services running because it had integrated OT and IT security teams, allowing it to isolate the threat without halting trains. These examples illustrate that a unified approach can preserve operational continuity while addressing cyber threats.

Call for a Unified Security Strategy in the UK Culture Sector
The evidence from the Louvre, the British Library, Colonial Pipeline, and Go‑Ahead makes clear that cybersecurity cannot be viewed in isolation from physical security. For the UK’s cultural institutions to safeguard their finances, collections, and public trust, they must adopt a joined‑up strategy that aligns funding priorities, governance structures, and technology practices. This includes bringing OT and IT specialists under a common leadership role (e.g., a chief security manager), conducting regular joint risk assessments, and ensuring that maintenance budgets reflect the true cost of protecting both digital and physical assets. Only through such integration can the sector hope to thwart future attacks and preserve Britain’s cultural heritage for generations to come.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here