Submind YouTube summaries
Thumbnail for NEMO Webinar | Cybersecurity  and AI - Staying safe in a rapidly changing digital world | DEN

NEMO Webinar | Cybersecurity and AI - Staying safe in a rapidly changing digital world | DEN

Watch on YouTube

Video summary

This webinar from NEMO, hosted by Mira and featuring experts Nathalie Franzen and Pascal Stomp of DEN, addresses the critical intersection of cybersecurity and artificial intelligence within Europe's museum sector. The session emphasizes that digital security is no longer merely an IT concern but a strategic priority for organizations managing cultural heritage and sensitive data. Speakers highlighted how cybercriminals increasingly target cultural institutions not just for financial gain, but to steal valuable donor information, collection records, or even as precursors to physical break-ins. Real-world examples were provided, including the Louvre's vulnerability due to outdated systems and password choices, an attack on the Uffizi Gallery that compromised internal security codes, and a ransomware incident at a small Dutch museum where paper backups ultimately saved their operations from permanent loss. The discussion extensively covered how AI is reshaping both threats and defenses in this rapidly evolving landscape. On one hand, attackers are leveraging advanced AI to automate phishing campaigns, create deepfake audio-visual content for social engineering attacks, and generate code vulnerabilities at scale; notably, a significant portion of current social engineering attempts now involve AI-generated materials. This includes the concept of "shadow AI," where employees unknowingly upload sensitive data to public models without organizational oversight or policy compliance. Conversely, defenders are utilizing powerful AI tools embedded in platforms like Microsoft Outlook to detect anomalies and block malicious traffic before humans even notice them. The speakers stressed that while these technologies offer robust new capabilities for prevention and detection, they also introduce complex ethical challenges regarding data privacy and the potential misuse of highly accurate code-analysis models by bad actors. To help organizations navigate this complexity, the presenters introduced a practical four-step cybersecurity plan specifically tailored for cultural institutions: identifying "crown jewels" such as ticketing systems and climate controls; conducting risk analysis to prioritize defenses based on likelihood and impact; implementing governance measures including multi-factor authentication, regular backup testing, and staff training; and establishing a continuous cycle of monitoring and adjustment. A key takeaway was the importance of fostering an open reporting culture where employees feel safe admitting mistakes or clicking suspicious links without fear of retribution, as this transparency is vital for early incident response. The speakers also addressed questions about using public AI tools like ChatGPT, advising users to sanitize sensitive data before inputting it into external models and emphasizing that while AI can assist in security decisions, human oversight remains essential to interpret results and maintain ethical standards. Ultimately, the webinar concluded with a message of resilience and collaboration, asserting that museums do not need massive budgets or specialized IT teams to improve their security posture but rather require consistent conversation and basic hygiene practices like enabling multi-factor authentication and conducting regular awareness workshops. The experts encouraged organizations to start small by defining clear internal policies on AI usage and data handling, noting that the cultural sector's inherent focus on ethics often aligns well with responsible AI deployment. By staying informed about emerging threats, maintaining open dialogues within their teams, and leveraging available resources from networks like NEMO and DEN, museums can effectively protect their digital assets while continuing to serve the public in an increasingly complex digital world.
Read the full video transcript
Hello to all colleagues in Europe and beyond and a warm welcome to NEMO's second webinar in 2026 on a topic of growing importance for museum and cultural organizations. Cybersecurity and AI, staying safe in a rapidly changing digital world. My name is Mira and I work for NEMO, the Network of European Museum Organizations. This webinar is part of NEMO's ongoing capacity building offers for the museum community in Europe and beyond. And NEMO provides a wide range of activities such as mentoring, workshops, hands-on trainings, and study visits. And if you're interested in joining this supportive European network, then we would be very happy to hear from you. In today's session, we will look at why cybersecurity is no longer an just IT issue, but a strategic priority for organizations working with digital collections, cultural heritage, and sensitive data. We will also explore how AI is reshaping the cybersecurity landscape for new AI from new AI-driven threats to tools that can help organizations better prevent, detect, and respond to attacks. >> [clears throat] >> At the end of this 1-hour webinar, there will be a short time for a few questions. So, please feel free to put them to use the chat function and put your questions [clears throat] there. And I'm very pleased to welcome today's speakers from DEN, Nathalie Frankenstein and Pascal Stom. Um from DEN, it's a Dutch-based um expertise center for digital transformation on cultural sector. And as Nathalie and Pascal will introduce themselves a bit more in detail, without further ado, so I'll hand over to you, Nathalie and Pascal, the floor is yours. >> Uh thank you, Mira. Um and welcome everyone um who is joining today's session? Um My name is Nathalie Franzen together with my colleague Pascal Stomp. We'll be telling you something more about how cybersecurity and AI are changing the digital landscape for museums in this day. Our goal is to give you a practical tool the step-by-step plan we developed with then. And some insights you can imply immediately no matter the size of your organization. Yes, so my name is Nathalie Franzen. I work as an advisor at then for the topic cybersecurity and Pascal, would you like to introduce yourself? >> Yeah, so my name is Pascal. I've joined then in December last year. I graduated from my master cultural data and AI pretty new master. I guess it really shows how the world is changing and I will be talking about the AI part of today. So yeah, that's me. >> Thank you. And at then then is a knowledge Institute for culture and digital transformation as Mira already mentioned. And we help cultural organizations navigate through the digital transformation. We identify trends support innovation develop knowledge and tools. And we host a lot of like webinars like today and presentations and workshops. And cybersecurity has become a crucial part of that mission. It's no longer just an IT concern as Mira also mentioned. It's a strategic responsibility for the entire organization. Um, and that's exactly why we're here today. Um, this is the program of today. Um. Uh, so first we will tell you something more about why culture is becoming a target. Um, and why cyber security cyber security is essential for uh, museums as well. Uh, then Pascal will tell you more about the relationship between cyber security and AI. Um, afterwards I will tell you more about the cyber security step-by-step plan we developed for the cultural sector. And afterwards we have some time to answer a few of your questions. Um, so first we would like to start with a question for you. Um, we've prepared a poll. Um. So just to get a uh, understanding of the landscape in the room. Um, did your organization experience a type of an attack in the past years? And if so, which type of cyber attack? There's also an option that if you don't know if there has been a cyber attack or there hasn't been any cyber attack. So just for us to get a yeah, um, to see what we're dealing with today. I'll give you a minute to fill in the question. >> See, some people are still giving up their choice. So, I'll wait a bit. See, we're at 75% now. But, we can already see that well, most of you have experiences with fishing. Um and well, part of you is not sure about if there has been any attacks. But, um yeah, the the people who choose for fishing, um it's the same with the the trend we see in the whole world. Um fishing remains the number one entry point for cyber attacks, so um that doesn't surprise me that much. And then we another question. I'm also curious to know more about your organization facing challenges in cybersecurity. So, where does your organization currently face the biggest challenge? So, what's keeping you from making your organization more secure? I'll give you a moment to look at the answers and choose your right answer. So, more than 60% of you fell in their answers. And what we see is that most of you say that the staff knowledge and awareness is the uh biggest challenge. Um and that's something yeah, we see as the often as the number one challenge in uh cultural organizations. Um and it's something you can work on, so that's good news. Um and we will tell you more about that later. Uh but human behavior remains the biggest vulnerability for um uh in to cybersecurity for organizations. Okay, thank you for being uh honest and sharing your experiences with us. Um I'll put on the next slide. Yeah, when culture becomes a target, uh we um cultural institutions are increasingly targeted by cybercriminals. Um and sometimes we get the question, "Why?" Because people think they're not really a target because they don't have that much of money or something um that makes them very special to have a uh cyberattack. Um but you hold valuable data from donor information to collection records. Um and you use the uh systems that public uses like your website or your ticketing systems. Um and many uh organizations rely on older infrastructure or limited IT capacity. And that combinations make you a um attractive uh target for attackers. And most of you probably have heard about the break-in at the Louvre Museum uh a few months ago with the uh service lift that had they had placed be um just in front of a window and they uh went up that stair of the the elevator and they had a break-in. Um it was a physical break-in, but um the intruders reached uh restricted areas using a service elevator. Uh but that also revealed the weakness of the cybersecurity. So, they used really old um systems on Windows Server uh from 2003. And uh there were a lot of gaps in his computer security. Um and that was um a great example for like a uh world-class museum that struggles with cybersecurity. Um and they also used the password Louvre for one of their security systems. Um this it shows how universal the problem is and it's not to um point a finger at them doing it wrong because it's important to be open about what happens uh in the sector. But it gives a good example of how big the problem still is uh in the cultural sector. Next one is the Uffizi Gallery. Um they had also had a cyber attacks a few months ago. Um what makes this attack interesting is that the cyber uh incident was uh involved access to internal system and sensitive data. And in report of media reports that they had access to uh floor plans, uh access codes, and camera locations. So, it looked like they were preparing a physical break-in. So, they first started with a cyber attack to get all the right information so they could prepare the physical break-in. Luckily, they discovered the the the attack so they could take some measures like uh closing temporarily uh some areas and move valuable objects to uh different locations. Um but this shows how cyber incidents can directly impact operations, uh visitor experiences, and uh even collection safety. And one last example is from a really small museum in uh the Netherlands. Um it's called the Vein Colonial Museum in Veendam. It's like a really small museum. Um but this museum was hit by a LockBit ransomware attack and hackers stole some Um demand payment. They did not agree to go on with the payment. And unfortunately, the museum had some paper backups, so that's what that had them saved. They only lost like a week of work, so there wasn't a lot of damage, not financially and not in the the other um damage. But what was what the director, sorry, I have to take the director of the museum said in the media, there was a quote of him that he was happy to discover that there was only like a cyber attack and not a physical break-in. So that really shows the priorities of how people see like a physical break-in and a piece of your collection will be stolen or like a cyber attack. And this also example gives a good example of how like a small museum also can be a target. Now my colleague Pascal will tell you more about AI in cybersecurity. >> Yes, so as the title of this webinar already suggests, it's a rapidly changing digital world and AI is really rapidly interfering with everything in our lives and also with cybersecurity. I want to start with a different example, not out of the cultural sector or not a museum, but very dystopian and made with AI. Arup is a large engineering a British engineering company and in 2024, one of their Hong Kong employees got a phishing email which she already found a little bit suspicious but then they followed up with a meeting and she joined the meeting and she saw her CFO CFO and some of her other colleagues and she wired a lot of money I don't know the exact number right now but a lot of money in in 15 different transfers something like that and later turned out that all those colleagues in that call were deep fake they were made with AI made with public by the attackers with public images and videos found on the internet so yeah so they made a whole different persona and this is of course very dystopian and very weird but luckily it's for now one of the few examples that I could find but it does show that it's really changing and that they AI is really changing the the field of cyber security. Another example I wanted to talk about is the mythos model of anthropic which they decided not to bring out to the public AI is really good at coding a lot of programmers already use it they have AI agents that are coding all night building programs and anthropic made a new system mythos that was so good at discovering mistakes in code and almost every code even the the the website of of our government every code has mistakes and this model was so good at discovering this mistake these mistakes in code that anthropic was hesitant of bringing it out to the public cuz they thought that people could maybe use it with bad intentions to hack into systems that they were not supposed in to hack into so instead of bringing it out to the this model, they made a new project called project Glasswing, which in which they used the model not to attack, but to fix codes. This so to find these mistakes and to patch them so that attackers have a harder way of of of getting in. And they're doing this project with a lot of big tech companies as well. Big tech companies, so they're working together on yeah, making codes and using the AI actually. The reason why they didn't want to bring it out was because it was too dangerous and they could attack with it, but they're now using the model the other way around. So, they're using it to protect their systems and to making it more safe and more secure. Um Yeah, so there's a lot of sources that are now saying that AI is really changing the field. Um there's a quote from this uh threat landscape uh report from ENISA that says that by early 2025, AI supported phishing campaigns and uh 80% of social engineering is also AI made now. And social engineering is what Natalie said it's still the human side of cyber attacks. So, trying for you to click on a link that's not uh secure. Um but you have to imagine we we right now can use AI to write emails super quick or write newsletters, but uh cyber hackers can also use AI to write thousands of phishing emails and send them out automatically without having to do the work themselves. So, they also use AI to send out way more fish phishing emails. So, the AI is being used also in normal uh emails that people are getting. Exactly. I see a comment, AI is a great tool, but a great weapon as well. Um then there's this other report that I found from CrowdStrike. On the left, you see a a picture on where they use AI and what kind of of cyber attacks. Uh I won't get too technical into these uh threats, but I mostly want to want you to look at the the the little, yeah, bars. You can see that the blue one is 2024 and the red one is 2025. And you just have to see how much difference there is. Um AI attacks are growing more and more, and probably this year it will even be more and more. Because it's yeah, AI is being in um embedded in everything and also in cyber attacks. So, they're not using AI to invent new attacks, but they're just using AI to make their existing ones more effective. They can create fake identities, like the extreme example of the Air Up company, but they can also translate their phishing emails and send it to way more companies in different uh parts of the world in any language. Um and AI-driven attacks have also risen by 2025 because AI is getting better and better. Um and sometimes they even have an attack chain fully automated, so they don't need to do anything themselves anymore. It's just an AI that's kind of doing the cyber attacks for them. Um then another thing, something that's a little bit more close by, something that you do have a little bit more influence on, and that's shadow AI uh I wanted to talk about. And um it seems relatively innocent, I guess, cuz it uh shadow AI is just the fact that your employees or your colleagues are using AI and um without not necessarily secretly, but without telling anyone that's in charge they're using AI tools. And the risk of this is that they use AI without having a policy, without maybe thinking about it, and they can upload whatever data they want, and then that data ends up in whatever AI they use, and then you don't know what happens to that data. So, you could be in in not in policy or in line with what your vision is of what you want to do with your customer data, for example. And a way to to fix this is to think with each other about AI and about an AI policy. What how do we want to use it? What what data can we put in AI and what can we not put in AI? And if you have this policy, then it's also easier for employees or your colleagues to to tell you when it's wrong, when when something happened, when they made a mistake, when they accidentally uploaded some data that they're not supposed to. Because now when they're just using it without a policy or without an open conversation about AI, they will not probably tell you or each other that they've made a mistake. There's also European law that protects personal data and visitor data, and you could be in in violation of this law if your colleagues or employees are using AI without you knowing. So, we also recently at Dent created an AI policy. I think it's very important to talk with each other about it, about what your ambitions with AI are, but also what you want to protect when you're using AI. So, this is also really a new threat that um came to be recently, and but it's important to keep an open conversation with each other about that. Um yeah, earlier someone already said it in the comments, but it's true. AI is changing both sides of the game. So, it's on one side changing the the the attack side, but it's also changing uh the tools. There's also many tools now that can protect against phishing emails and against suspicious emails that people are getting. Um some comp In this report from IBM, they mentioned that some companies that use AI tools to prevent uh cyber attacks, they've actually their data breaches costed them less money if if a data breach happened, or they have less data breaches than companies that don't use AI tools yet. Um Yeah, that's for for now my part. Later, I will tell you a little bit what you can do with AI, and I have to say that a bunch of these AI tools that I mentioned are already embedded in, for example, Microsoft in Outlook. There's already a bunch of tools embedded that we don't even notice, that we don't even have control about, but AI is already being used in in cybersecurity. Um yeah, later I'll tell you a little bit more on what you can do yourself. >> [clears throat] >> Thank you, Pascal. Now, let's look at the um four-step step-by-step plan uh we developed specific specifically for uh cultural organizations. Um it's a very practical guide for institutions of any size. Um but before we dive into the step-by-step plan, um I wanted to show you this slide. Um, because within cybersecurity we talk a lot about resilience and adaptability. Um, because we see that the focus mainly is on the prevention side, this the resilience. So, how can you um, try not to experience an attack. Um, and really focus on doing like proactively um, all sides of measures to prevent having an attack. Uh, but what we see is that it's changing a lot because there are so many attacks. Um, also in the cultural organization of cultural sector. So, I also want to uh, tell you uh, that the importance of being uh, also uh, focused on the recovery side. So, today the step-by-step plan is also focusing more on the prevention side, but at then we also try to uh, develop a guide on how to write a uh, incident response plan, for example. So, even though prevention side is very important, it's also important that once you experience an attack, you know how to react to that attack and how you can get um, the organization back on track and all the systems back on track. Um, this is the four steps of the step-by-step plan. Um, so we'll look at all the four steps. The first one is to identify your crown jewels. I'll tell you more about that um, uh, later. The second step is the risk analysis and prioritization. Um, the third step is the measures and the responsibilities. And the last step is a very important one. Uh, is that you have to keep monitor monitoring and making necessary adjustments. And it's like a circle, so once you did like the first step, you get back to maybe after 1 year, back to step one. Start identifying your crown jewels again because you might have some new systems in your organization or certain new data you um gathered, so it's always like a circle that you keep following. Um the first step is to uh identify your crown jewels. Um the crown jewels are the critical processes, essential systems, sensitive information, and indispensable suppliers. Um It's important to know what your crown jewels are because you can't protect everything equally. So you must know what matters the most for your organization. Um And I have a few examples of what crown jewels can be for museums. For example, your ticketing system because once you can't uh sell any more tickets, you have a big problem and you can close the doors of your museum. Or when your customer relationship management system is hacked and all the donor information is getting into the public, you have a big problem. Um climate control is also an important one. Most people don't really think immediately of the climate control, but if you have a big collection, it's important that you can still control your own climate control system. Um And it's important uh uh I made a like a schedule on how you can map um this uh your crown jewels. So, you can just think for yourself what do we have like systems, data, or processes within our organization? Just write down all your crown jewels, uh the impact of the downtime. For example, our website we don't really have a problem if it's down for like a week, but if it's longer down for uh after a week, um we are likely to get a problem uh because we can't sell tickets for workshops or trainings or people are not able to reach us. Um and also who is responsible for that uh process or data or system. So, that's an example on how you can map your crown jewels. And after we go look into the risk analysis because that helps you understand uh which threats you face and which risk you're willing to accept. Uh cuz as I mentioned before, you can't um uh secure all your crown jewels because of money or capacity. So, you're you're really looking into what matters the most to our organization and make a prioritization in that. Um Go to the next slide. Um cuz yeah, common cyber attacks are phishing mails, fake logging pages, ransomware, stolen passwords, CEO fraud, of abuse of supplier accounts. So, if you have the crown jewels, you're going to look at what are the risk we're facing. For example, um ticketing system can be hacked, but what will the risk be of that? And then you can make a risk matrix. Um and you determine your priorities. So, you look at the likelihood of how the is it going to happen or not? Uh what is the impact of the uh the risk? Um and this matrix helps you decide what to act on immediately, uh and what to monitor. Uh it's also a great tool for communication priority priorities to management. Because we also heard that a lot that um well, it's a IT problem, most people think, uh but it's good to have that conversation also with management. Um the first third step is look into the measures and the responsibilities. Um and there we have four categories. Uh the first one is uh governance, and that's about leadership, uh decision-making, um and accountability. So, who is allowed to make decisions, uh who is the leader of the the uh the data or the systems? Uh next up, it's policies. Also where uh Pascal told us more about AI policy, but also cybersecurity policy. So, it covers rules that define required security behaviors and control. Uh it's good for your staff to know what is allowed and what is not allowed to do. Um IT security, so that's more the technical measures. Um so, how you can uh protect your systems, your networks, and your data. I'll tell you more about that later. Um and awareness and training. And in the beginning of the webinar, you told in the poll that um a lot of people have like the biggest challenge in the awareness side of their organization for the staff. Um so, it's really important to give that more attention. Um an example of measures. Uh the first one is like the multi-factor authentication. Um but also, we hear a lot of people that make uh backups, but if we ask if they also test their backups, um most of the time they have to say, "No, we don't." Uh so, that's really important that if you make backups, that's good, but also check if they're working. So, do like a test run once a year to see if the backups really do what they have to do. Um install updates. Uh limit access rights, so not everyone has to go into every system or see every uh set of data. Uh fishing training to erase the awareness for your staff. Um then create an incident response and procedure. And step four is um well, cybersecurity is a continuous process. Um and we encourage a reporting culture. Uh so, mistakes should be reported early and not hidden. So, try to talk a lot about cybersecurity with your colleagues, with your staff. Uh that they feel um that it's okay to make a mistake sometimes. It's good to know that the mistake has uh happened than to hear afterwards that people were afraid to tell you that they clicked on a phishing link, for example. Uh and cybersecurity is just a Well, that's what I said before, the continuous process, the importance of reporting culture. So, do like a coffee moment every um every month, um do a awareness workshop every year. Uh there are a lot of uh examples to think about to raise awareness within the organization. And also, keep evaluating and improving, cuz uh that's the most important part of cybersecurity. Just monitor what happens. Uh are there any attacks? What do we see? Uh and keep talking about it with each other. Um and then to help you uh make a first step uh tomorrow, um I've wrote down some actions. Uh so, turn on multi-factor authentication for all critical accounts and systems. Um schedule a restore test to verify the backups actually works. As I mentioned before, a very important one. Uh create overview of systems and suppliers. Uh define how to contact in case of an incident and set up a call list. Uh and make sure that the call list isn't on your computer, but also have like list of uh people you have to call once uh you experience an attack, because maybe you won't have access to your computer anymore. Uh and share concrete tip about phishing or a suspicious emails with your team to raise staff awareness. Uh that's also just to have that conversation going. >> Yes, and then about the AI part. Um So, as I said, the AI monitoring tools already detect unusual activity, and most of them are already embedded in into our own email systems that we're using. Uh those stop a lot, like 90% more maybe, of spam and phishing malware attacks already. So, AI is already working for us as we speak. Um multi-factor authentication, it's kind of the same as cybersecurity, just for AI. It's just an extra step that I guess you have to take into account in this new day and age. Um Clear staff guidelines are very important, especially with the shadow AI. So, talk with each other about it. Like, make a policy together on how you want to use AI and what tools are allowed and what tools aren't. Um and what data you can use to to um work with AI and what not. So, because when there's guidelines, people also know when they're doing something wrong or not. Um and then they can talk about it. Then they can say, "Oh, I made a mistake." Uh and then you can work together on fixing that mistake. Um So, yeah, make sure your team is aware how to report something, uh what to do in case of an accident, and what tools are approved, and how they can use those tools. And um for that, I just also wanted to end on a note that like you do not need a big budget or a super big IT team. It's just important to start somewhere and to start and to keep talking about it with each other and keep that awareness on both cybersecurity and AI. Um because when that conversation is there, people will admit they make mistakes, or they will ask questions on how they can use it safer. Um So, yeah. Um Talking with your team, and and yeah, kind of what Natalie says, the AI and cybersecurity, it kind of stays the same what you need to do or what you can do. There's one tool that I've also heard of, it's Darktrace, and that tool learns how people behave on your website, for example, and then flags anything that doesn't fall into that behavior. And there's probably going to be more and more AI tools the more and more AI is developing. So, yeah, start with talking, then maybe see what tools fit you and if you need an AI tool to to block cyber attacks. So, yeah. That's our tips, I guess. Are there any questions? >> Yeah, thank you, first of all, Pascal and Natalie for guiding us through today's session. And yeah, we have some time for questions. This session is also recorded, and everyone here can also get in touch with Natalie and Pascal afterwards. So, we see I see a question from Florentina. If someone uses ChatGPT, for example, to, for example, summarize official permit applications, does that mean that the data you enter may end up being used by an unknown unknown user? >> Well, that's the the whole thing about AI and big tech companies that make AI, and ChatGPT is one of those big tech companies. We don't really know what happens to the data, and that's maybe the scary thing. So, you don't know if it's used by someone. It's definitely used mostly to train their data. If you have a paid account, you can turn on some privacy settings, but still it's kind of a black box where our data goes. So, anything you upload into ChatGPT or other AI tools, there's some AI tools that like claim to be a little bit more ethical with their data, or they store it on European surface servers if that's something you care about. For example, Mistral. Um But yeah, the data you upload into ChatGPT, you don't know what happens to it. Um it's mostly used to train their model, I think, but they do have because you send it to them. So, they do have it somewhere saved on one of their servers, and that's just the scary thing about those big AI tools. >> Yeah. >> So, what we do, we you can use those files, um just remove anything of sensitive data. Remove names, remove email addresses, remove addresses, remove phone numbers. Like if it's just the the information or the context, then it's Yeah, you have to really decide with each other what you think is sensitive data, what can you give to the AI. Um public articles or things that are already on your website, that's totally fine because it can already access that cuz it has access to the internet. But just uh with sensitive files, with names and stuff, you can remove them, censor them, and then give it to the AI, and then it at least won't have those uh details that you removed. >> Sophia asked, um can you share any best practice examples of a sound policy in the field by a museum in Europe? >> A very sound policy? >> Sound policy? Uh in the field used by museums in Europe. Sophia, if you want to uh specify the question. Um And by that time the current coherent policy. >> Um Um For cybersecurity or AI? Um >> Hm, Sophia again. >> Any of them. >> [laughter] >> Okay. >> No, I don't have a example of a policy um using a field by UE museums. Pascal, do you have a example? >> Well, with cybers or with AI, I think with AI policies it's pretty new and as like the regulations here in Europe are like everyone is still it's still a little bit open, which is pretty nice because it has a lot of space to develop and be used. Um but the guidelines are really dependent on each company. You can see that like big commercial companies that want to make a uh a lot of profit, they care a little bit less about the privacy of their customers and they do use a lot of AI tools to automate a bunch of processes like um sending invoices or something and we do see that here in the cultural field with museums we they value more the the privacy of their customers and they're more concerned with ethics. Um so it really depends per per organization. We've also spoken to one organization here in Holland who has made their own AI. For example, the the city archive in Amsterdam has made their own AI model so they don't have to use any uh big tech model, so they don't have to so their those big AIs cannot use their data and because they have so much there in archive. So, it really differs right now. There's not really one policy I can say follow it follow it it really depends. We do have a step-by-step plan at then on how to make an AI policy, but it's it's in Dutch. It's not in English yet, but I don't know you can ask AI to translate it [laughter] I guess. It's very good at that. That's public knowledge, so it's not sensitive data. You can share it. Um but those questions are mostly what tools do you want to use? What data can you use? What are the ethical or or um environmental decisions you make, but it it really depends per per company. We just recently made it up and it's a bunch of conversations, a bunch of discussions with each other. What does each colleague think and in the end everyone has different opinions, so um I don't also don't really have one clear answer. It really that conversation of building one is already what's important. >> Yeah. Yeah. And it's the same for cybersecurity. You can have a look into the NIST 2 uh requirements. Um and uh here in the Netherlands we're still working on that law um based on the NIST 2 measurements of requirements. Uh but you can have a look into it and see um what is important for your organization uh to well, take over uh put it in your policy uh and just have a discussion with each other about it. >> Uh another question um can AI be trusted for cybersecurity decisions or should it always remain human supervised? >> So, AI is really because AI is so quick, it can really quickly see fishing emails or suspicious behavior on your website. But with every AI application, I think it's really important that a human stays in the loop. That in the end, the human still takes the decision. So, AI I wouldn't see it as um as its own entity. It's really a tool. A tool used by the people that make the policy or the people that are in charge of cybersecurity. And they still decide what the tool can do, what the tool won't do, uh when to use the tool, when not to use the tool. So, it's really you cannot just give it to an AI and let it do it. It's really important that humans still also are aware of cybersecurity and also are aware what the AI is stopping. Cuz if I don't know if your AI is stopping 100 fishing emails per day, then maybe there's also something wrong somewhere else. Um so, it's really important to stay in the loop as well and um not just give it all to an AI. >> [laughter] >> The big message, yeah. And um what basic security measures give the biggest return of investment? If you can say something. >> I would say um MFA, so multi-factor authentication, because it doesn't really cost that much to uh get that in your organization and um have that uh sourced in your uh systems. But it can help you um a lot in the uh prevention side. So, it keeps out a lot of um unwilling uh uh experiences. Um and next I would say um is to uh do like an awareness workshop to have the awareness raised in your organization because the human factor in cybersecurity is one of the most important entry points. So, I would say spend a lot of attention to how to get your staff improve their knowledge about security, cybersecurity, and how to raise awareness. So, start for example with a coffee moment once in a month. Do like a if there is has been a phishing mail, share it with every person in your organization. Just show the examples. Show the the success stories, but also the moments where it didn't really go that well. So, people can learn from it together. Thank you. There's one question connecting back to Nathalie's comment about the NIS2. Question from Xavier. Maybe it's a bit too complicated. So, we see if we can answer those questions. Otherwise, um as we said, everyone can connect with Nathalie and Pascal afterwards. For a mid to large middle to large museum in the in Europe, what are the concrete first steps to determine NIS2 applicability and begin compliance, especially if the national transposition is still incomplete? Oh, that's a big question. >> [laughter] >> Um I'm reading it in the chat. >> Can you see it? >> Yes. >> Yeah. >> So, what are the concrete first steps to determine NIS2 applicability? Um I can't really answer that question right now. Um Um as I said, it's the requirements are on European level and in the Netherlands they're still discussing the law about it. Uh it probably will be in force this summer. Um so yeah, for the moment I can't really give an answer to this question. Yeah. >> So I think the advice would also be it to stay in touch. As you said, talk to each other. NEMO has upcoming trainings on AI and cybersecurity in autumn. We have our upcoming European Museum Conference in October in Vilnius where also colleagues from DEN will join a workshop or a panel. Um and and also for the next year we are planning a cooperation with DEN. So all NEMO members can participate in in hands-on trainings. I guess this is what what we need nowadays more and more. So um I would say thank you very much, Pascal and Nathalie. And >> Thank you. >> day to all of you. Stay positive and hopeful. >> Exactly. >> And yeah, think about the activities you can start tomorrow. Uh yeah, and start. >> Exactly. It's not all lost. It's hopeful. We can If [snorts] we work together. >> [laughter] >> Exactly. Thank you very much. >> Thank you. >> Bye-bye.