A damning new report from the Public Accounts Committee warns that the UK鈥檚 national museums and galleries remain dangerously exposed to cyber threats, with Whitehall still stuck in a reactive mode years after the British Library ransomware attack.
The UK鈥檚 cultural institutions, from the Natural History Museum to the National Gallery, are being left wide open to cyber-attacks and physical theft, according to a . The findings make for uncomfortable reading: the government has no clear strategy, no concrete actions to point to, and is over-relying on the autonomy of institutions that often lack the in-house expertise to protect themselves.
The PAC鈥檚 warning comes nearly three years after the British Library was hit by a crippling ransomware attack that knocked out services for months and exposed sensitive data. Despite that high-profile wake-up call, the Department for Culture, Media and Sport (DCMS) was unable to provide the committee with specific examples of concrete steps taken across the sector in response.
Sir Geoffrey Clifton-Brown, Chair of the Public Accounts Committee, put it bluntly: 鈥淐yber-attacks, the theft of items from collections and a fall in the number of visitors are just some of the issues museums and galleries are fighting to overcome. The lack of centralised support is leaving them vulnerable.鈥
听
A Watershed Moment The Government Has Wasted
听
Cybersecurity experts say the report confirms what the industry has been flagging for some time.
Graeme Stewart, Head of Public Sector at Check Point Software, describes the British Library incident as a turning point that the sector has yet to properly act on. 鈥淭he 2023 attack on the British Library was a watershed moment for the sector,鈥 he says. 鈥淚t demonstrated that a ransomware incident can cripple operations, compromise data, and cause months of disruption, all while threatening the trust these institutions depend on. That the government has yet to translate the lessons of that incident into concrete, sector-wide protective action is deeply concerning.鈥
Stewart points to a specific tension that makes museums and galleries harder to defend than a typical organisation. 鈥淭hey combine the digital vulnerabilities of any modern organisation, including network-connected systems, online ticketing, and third-party suppliers, with unique physical security considerations and, in many cases, constrained budgets and limited in-house cyber expertise.鈥
His prescription mirrors what the PAC itself is calling for: DCMS taking a genuine coordinating role, facilitating shared threat intelligence, establishing baseline cybersecurity standards, and ensuring that digital record-keeping of collections is both implemented and properly secured.
鈥淭he sector cannot afford to wait for the next incident to act,鈥 Stewart adds. 鈥淭hese institutions are the cultural lifeblood of this country and the long-term damage to the nation鈥檚 heritage, reputation and public trust that could result from continued inaction would be far harder to recover from than any single attack.鈥
听
A Culture Problem Not Just A Budget Problem
听
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, takes a harder line and places some of the responsibility squarely on the institutions themselves.
鈥淭he evidence has been sitting in plain sight for years,鈥 he says. 鈥淯K鈥檚 iconic cultural institutions suffered serious security incidents and the government鈥檚 response was to facilitate lessons-learned sharing. That鈥檚 not a security strategy. That鈥檚 hoping the next institution pays attention.鈥
Patel argues that framing the problem purely as a funding issue lets institutions off the hook. 鈥淭he cultural sector has a security culture problem as much as a resource problem, and conflating the two lets institutions off the hook for the controls that are within their reach regardless of budget.鈥
He also pushes back on the idea that this is a museums-specific issue. 鈥淭he PAC report is specifically about museums and galleries, but the structural problem it describes is not unique to them. Public sector bodies operating with significant autonomy, legacy infrastructure, constrained budgets, and limited in-house security expertise are a common profile across UK public institutions.鈥
More from Cybersecurity
- Sweet Security Brings Autonomous Protection To The AI Enterprise With New Blocking Capabilities
- Hackers Could Hijack Your Car Using Bluetooth 鈥 What Happens Once They鈥檙e In?
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware
- How AI Slop Is Forcing GitHub To Close Its Doors
- Are Home Routers Europe鈥檚 Most Dangerous Cyber Vulnerability?
- Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More?
- Can Software Developers Still Trust Their Own Vulnerability Scanners?
- AI Has Stopped Just Assisting Hackers And Now It鈥檚 Running The Attacks
A Sector Under Financial Pressure
听
The cybersecurity vulnerabilities sit against a backdrop of significant financial strain. The PAC鈥檚 report notes that DCMS provided 15 government-sponsored museums and galleries with 拢484 million in grant-in-aid funding in 2024-25, a real-terms reduction of 16% compared to pandemic-era levels. Visitor numbers have yet to return to pre-pandemic highs, while energy and staffing costs have risen sharply.
That said, institutions have made genuine strides in self-generated income, which totalled 拢563 million in 2024-25, a 53% real-terms increase on 2021-22. But those revenue streams depend on operational continuity and public trust: exactly what a serious cyber incident would put at risk.
The PAC has asked DCMS to set out the concrete actions it and individual museums have taken, and are taking, to address both cyber and physical security threats. It has also called for clear metrics to assess performance, and flagged concerns about high trustee vacancy rates and significant churn in senior financial leadership across the sector.
听
What Needs To Happen Next
听
Both experts agree that reactive incident-sharing is no substitute for genuine prevention. Stewart wants DCMS to take the lead on coordinating threat intelligence and setting minimum security standards across the sector. Patel wants a shift in security culture that doesn鈥檛 wait on central government.
鈥淭he PAC is right that the current approach of sharing lessons after incidents occur is not a substitute for preventing them,鈥 Patel says.
For now, the gap between the scale of the threat and the maturity of the response remains wide and the institutions holding some of Britain鈥檚 most irreplaceable assets are the ones most exposed.
