In the previous few years, probably the most UK’s greatest cultural establishments have skilled primary threats to their safety. A file by way of the general public accounts committee (PAC) has warned that such incidents have uncovered severe weaknesses around the sector however that the federal government has failed to plan a solution to save you them. This has left Britain’s cultural establishments open to equivalent long term assaults.
We are living in a time when virtual methods underpin the whole thing from ticketing to surveillance and construction get admission to. Sidelining cybersecurity leaves museums susceptible to assaults that would threaten each their budget and their collections.
If the United Kingdom desires to steer clear of primary assaults and thefts, it wishes to be informed a lesson from the hot Louvre heist the place €88 million (£78 million) of jewels have been stolen. An audit carried out simply weeks earlier than the incident uncovered the Louvre’s spending priorities that left them susceptible to robbery. The file discovered that €169 million was once spent on art work and exhibitions however simplest €26.7 million on all kinds of repairs, together with safety.
The most probably pondering of cultural establishments is that to stay financially resilient they have got to spend extra on money-making points of interest, like art work and exhibitions. Then again, which means safety now and again turns into a low precedence – much less cash is spent and no more idea given to the significance of maintaining it up-to-the-minute. Then again, the monetary loss from robbery impacts monetary resilience by way of eroding emergency money reserves and using up insurance coverage premiums.
Because the Louvre’s audit displays, the museum will have in all probability have shyed away from the robbery had it taken its findings extra critically.
The problem of out of date safety features on the Louvre is going again to a minimum of 2017. An audit on the time discovered that “certain workstations [had] obsolete operating systems (Windows 2000 and Windows XP) which no longer guarantee effective security”. Safety updates for Home windows 2000 ceased in 2010, and Home windows XP in 2014.
3 weeks after the heist in 2025, the Louvre was once criticised by way of France’s Court docket of Auditors for now not taking the audits critically and spending cash on artwork as a substitute of safety within the years earlier than the robbery.
Identical weaknesses in funding priorities because the Louvre’s have been uncovered in a file made by way of The British Library in March 2024 into their cyber-attack.
In October 2023, The British Library skilled a critical cyber-attack. The library’s methods have been infiltrated by way of hackers who locked out all community customers and demanded a ransom of 20 Bitcoin (roughly £590,000). The ransom was once now not paid and the stolen information was once auctioned after which leaked at the darkish internet.
Out of date cybersecurity left The British Library open to a ransomware assault.
Previous The town Vacationer/Shutterstock
The library’s file into the assault stated that it came about as it had muddled thru with a ancient mix of outdated methods from many assets, which didn’t have a restoration plan. This supposed it took the British Library months to revive probably the most elementary instrument – the net catalogue. Or even now, 5 primary services and products, together with {the catalogue} of illuminated manuscripts, stay unavailable.
The cultural establishments, executive or even the PAC make the vintage mistake of divorcing cybersecurity from bodily safety.
The file by way of PAC does point out “bringing together chief digital information officers and chief information security officers” and one after the other it praises the “National Museum Security Group”. Then again, there’s no point out of encouraging discussion between the teams.
This divide is quite common, and is steadily constructed into organisational device. Essentially the most junior individual answerable for each bodily and cybersecurity is steadily the CEO, or in all probability a main running officer (COO). This construction labored within the days when bodily safety didn’t depend on computer systems. Then again, nowadays, when such a lot bodily safety is predicated upon era, it simply does now not make sense. There must be any individual additional down the chain, corresponding to a “chief security manager” or identical.
Because the file by way of Apolo Safety into the Louvre assault discovered: “this case highlights another growing challenge: the convergence between operational technology (OT) and information technology (IT). When camera, climate or access control systems are connected to the network, any digital divide can have immediate physical consequences.”

A Paris Police crime scene technician collects DNA proof from a lacking window body that was once lower open by way of thieves all over the Louvre heist.
Phil Pasquini/Shutterstock
This false cut up between usual IT cybersecurity (the area of the manager knowledge safety officer), operational era (the disregarded computer-enabled gadgets that stay issues operating like digital doorways or intruder alarms) and bodily safety is a ways from distinctive to the scope of PAC’s file.
A vintage instance is the cyber-attack at the Colonial Pipeline in 2021 – an American power device that connects 29 refineries and serves primary airports, army bases and greater than 50 million American citizens. Best the vintage IT methods (billing) have been attacked, however control close down all the operation as they feared the assault spreading to the operational gadgets at the pipelines themselves. This stopped all pipeline operations resulting in flight alterations, panic purchasing and over 10,000 petrol stations working dry.
A extra built-in method was once exhibited by way of the educate operator Cross-Forward in 2022 in the United Kingdom, which had a equivalent assault on its methods. The corporate was once in a position, alternatively, to stay the trains working and maintain the supply of the assault as a substitute of halting all their operations.
It will be just right to assume that the United Kingdom tradition sector would additionally be informed those classes. However alas, neither the proof the federal government gave PAC nor the overall file give us any explanation why to imagine that issues will develop into extra hooked up in relation to a joined-up view of safety and preventing long term assaults.