Overview
- The Public Accounts Committee published a report on June 24, 2026 that concluded DCMS has been reactive rather than strategic in addressing cyber and physical security across national museums and galleries.
- The committee cited the 2023 British Library ransomware attack that damaged much of the library’s server estate, led to the theft of about 600GB of internal data, and cost the library around £1.6m to recover.
- MPs also pointed to reported thefts, missing items and damage at the British Museum as evidence that physical protections and cataloguing controls remain weak at some institutions.
- DCMS says it is working with museums and galleries and has backed a Cyber Action Plan with £210m to raise baseline cyber resilience to 2030 but has not yet produced the specific sector-wide tools and demonstrable actions the PAC has demanded.
- Falling visitor numbers, which were 13% below pre-pandemic levels in 2024–25, and limited in-house cyber skills mean museums face financial and operational strain and may see longer-term reputational effects or new funding measures such as charging international visitors.