When the IT systems of the Dresden State Art Collections suddenly went down in January 2026, it wasn’t just one museum facing a technical problem—it was an entire network of fifteen museums. The cyberattack paralyzed internal processes, hindered access to collection data, and forced those in charge to implement rapid organizational emergency measures. While the physical artworks remained safe, it became clear just how dependent modern museum operations have become on digital infrastructure. Shortly thereafter, reports emerged of similar incidents in Italy, including at the Uffizi Gallery in Florence, and eventually even the Colosseum in Rome became the focus of IT security assessments.
These events exemplify a trend that can be observed in many parts of the cultural world. Museums and archaeological sites are no longer merely physical places of preservation, but highly networked organizations whose daily operations rely on digital systems. These range from ticketing and visitor management to climate control systems in exhibition halls and complex databases that store research findings, provenance records, and digital collections. It is precisely this intertwining of culture and technology that makes these institutions vulnerable to cyberattacks.
The case of the Uffizi Gallery in Florence highlighted particularly clearly just how complex the situation is at the intersection of digital and physical security. As reported by the Italian daily newspaper *Corriere della Sera*, an attempted extortion occurred in February in connection with cyberattacks on the institution. However, museum management emphasized that key measures, such as the relocation of the Medici Treasure, were not taken in response to the cyberattack but were part of long-planned renovation work in the exhibition halls. As a precautionary measure, parts of the collection were moved to a vault at the Bank of Italy to ensure their best possible protection during the construction and renovation phase. At the same time, additional video surveillance systems were installed, though this had already been arranged following the spectacular break-in at the Louvre. Structural changes, such as sealing off or bricking up individual entrances, were also carried out in accordance with fire safety regulations and general structural safety measures and were not prompted by the cyberattack, as the museum emphasizes. Nevertheless, the proximity of these events in time demonstrated how quickly digital incidents are linked in the public perception to physical security measures. The Colosseum in Rome also illustrates how even iconic World Heritage sites are part of this new threat landscape. While the classic museum structure is less prominent here, administration, visitor management, and security coordination are also highly digitized. At the Colosseum, the ticketing system was affected. A cyberattack prevented tickets from being purchased through official channels. This makes it clear that not only traditional museums but also archaeological monuments have become part of the same digital risk zone.
Diverse Threats
The forms of attack themselves are diverse, ranging from targeted phishing campaigns against employees to network intrusions via security vulnerabilities at external service providers, to ransomware attacks in which systems are encrypted and blocked until a ransom is paid. The theft of sensitive data is also playing an increasingly significant role, particularly when it comes to visitor information or internal security plans. In many cases, while the material damage remains limited, the organizational and reputational damage caused by a cyberattack can be significant and disrupt operations for weeks. A particular challenge is that many cultural institutions have evolved over time, and their IT infrastructures often consist of systems from different generations. At the same time, pressure to digitize is increasing, for example through online collections, virtual exhibitions, and data-driven research. This development leads to a growing attack surface, while financial and human resources for cybersecurity often remain limited. This creates a tension between accessibility, modernization, and protection.
The protection of cultural heritage must therefore increasingly be understood as the protection of its digital infrastructure as well. Technical measures alone are not sufficient. Equally important are organizational resilience, trained staff, and clearly defined contingency plans in the event of digital outages. After all, the experience of recent years shows that an attack on systems not only affects data but can also directly impact access to culture, research, and the public. This makes it clear that cultural heritage today must be protected in two ways. In addition to the physical preservation of objects, the digital integrity of the institutions themselves is taking center stage. Museums and historic sites are thus navigating a new area of tension in which the future of cultural memory is no longer decided solely in display cases and storage facilities, but increasingly also in server rooms and networks.












