NEMO Webinar | Cybersecurity and AI - Staying safe in a rapidly changing digital world | DEN
Watch on YouTubeVideo summary
This webinar from NEMO, hosted by Mira and featuring experts Nathalie Franzen and Pascal Stomp of DEN, addresses the critical intersection of cybersecurity and artificial intelligence within Europe's museum sector. The session emphasizes that digital security is no longer merely an IT concern but a strategic priority for organizations managing cultural heritage and sensitive data. Speakers highlighted how cybercriminals increasingly target cultural institutions not just for financial gain, but to steal valuable donor information, collection records, or even as precursors to physical break-ins. Real-world examples were provided, including the Louvre's vulnerability due to outdated systems and password choices, an attack on the Uffizi Gallery that compromised internal security codes, and a ransomware incident at a small Dutch museum where paper backups ultimately saved their operations from permanent loss.
The discussion extensively covered how AI is reshaping both threats and defenses in this rapidly evolving landscape. On one hand, attackers are leveraging advanced AI to automate phishing campaigns, create deepfake audio-visual content for social engineering attacks, and generate code vulnerabilities at scale; notably, a significant portion of current social engineering attempts now involve AI-generated materials. This includes the concept of "shadow AI," where employees unknowingly upload sensitive data to public models without organizational oversight or policy compliance. Conversely, defenders are utilizing powerful AI tools embedded in platforms like Microsoft Outlook to detect anomalies and block malicious traffic before humans even notice them. The speakers stressed that while these technologies offer robust new capabilities for prevention and detection, they also introduce complex ethical challenges regarding data privacy and the potential misuse of highly accurate code-analysis models by bad actors.
To help organizations navigate this complexity, the presenters introduced a practical four-step cybersecurity plan specifically tailored for cultural institutions: identifying "crown jewels" such as ticketing systems and climate controls; conducting risk analysis to prioritize defenses based on likelihood and impact; implementing governance measures including multi-factor authentication, regular backup testing, and staff training; and establishing a continuous cycle of monitoring and adjustment. A key takeaway was the importance of fostering an open reporting culture where employees feel safe admitting mistakes or clicking suspicious links without fear of retribution, as this transparency is vital for early incident response. The speakers also addressed questions about using public AI tools like ChatGPT, advising users to sanitize sensitive data before inputting it into external models and emphasizing that while AI can assist in security decisions, human oversight remains essential to interpret results and maintain ethical standards.
Ultimately, the webinar concluded with a message of resilience and collaboration, asserting that museums do not need massive budgets or specialized IT teams to improve their security posture but rather require consistent conversation and basic hygiene practices like enabling multi-factor authentication and conducting regular awareness workshops. The experts encouraged organizations to start small by defining clear internal policies on AI usage and data handling, noting that the cultural sector's inherent focus on ethics often aligns well with responsible AI deployment. By staying informed about emerging threats, maintaining open dialogues within their teams, and leveraging available resources from networks like NEMO and DEN, museums can effectively protect their digital assets while continuing to serve the public in an increasingly complex digital world.
Read the full video transcript
Hello to all colleagues in Europe and
beyond and a warm welcome to NEMO's
second webinar in 2026 on a topic of
growing importance for museum and
cultural organizations.
Cybersecurity
and AI, staying safe in a rapidly
changing digital world.
My name is Mira and I work for NEMO, the
Network of European Museum
Organizations.
This webinar is part of NEMO's ongoing
capacity building offers for the museum
community in Europe and beyond.
And NEMO provides a wide range of
activities such as mentoring, workshops,
hands-on trainings, and study visits.
And if you're interested in joining this
supportive European network, then we
would be very happy to hear from you.
In today's session, we will look at why
cybersecurity is no longer an just IT
issue, but a strategic priority for
organizations working with digital
collections, cultural heritage, and
sensitive data.
We will also explore how AI is reshaping
the cybersecurity landscape for new AI
from new AI-driven threats to tools that
can help organizations better prevent,
detect, and respond to attacks.
>> [clears throat]
>> At the end of this 1-hour webinar,
there will be a short time for a few
questions. So, please feel free to put
them to use the chat function and put
your questions [clears throat] there.
And I'm very pleased to welcome today's
speakers from DEN, Nathalie Frankenstein
and Pascal Stom.
Um from DEN, it's a Dutch-based
um expertise center for digital
transformation on cultural sector.
And as Nathalie and Pascal will
introduce themselves a bit more in
detail, without further ado, so I'll
hand over to you, Nathalie and Pascal,
the floor is yours.
>> Uh thank you, Mira. Um and welcome
everyone
um who is joining today's session?
Um
My name is Nathalie Franzen together
with my colleague Pascal Stomp.
We'll be telling you something more
about how cybersecurity and AI are
changing the digital landscape for
museums
in this day.
Our goal is to
give you a practical
tool the step-by-step
plan we developed with then.
And some insights you can imply
immediately no matter the size of your
organization.
Yes, so my name is Nathalie Franzen. I
work as an advisor at then
for the topic cybersecurity
and Pascal, would you like to introduce
yourself?
>> Yeah, so my name is Pascal. I've joined
then in December last year. I graduated
from my master cultural data and AI
pretty new master. I guess it really
shows how the world is changing and I
will be talking about the AI part of
today. So yeah, that's me.
>> Thank you.
And at then then is a knowledge
Institute for culture and digital
transformation
as Mira already mentioned.
And we help cultural organizations
navigate through the
digital transformation.
We identify trends support innovation
develop knowledge and tools.
And we host a lot of like webinars like
today and presentations and workshops.
And cybersecurity has become a crucial
part of that mission. It's no longer
just an IT concern as Mira also
mentioned.
It's a strategic responsibility for the
entire organization.
Um, and that's exactly why we're here
today.
Um, this is the program of today.
Um.
Uh, so first we will tell you something
more about why culture is becoming a
target. Um, and why cyber security cyber
security is essential for
uh, museums as well.
Uh, then Pascal will tell you more about
the relationship between cyber security
and AI.
Um, afterwards I will tell you more
about the
cyber security step-by-step plan we
developed for the cultural sector. And
afterwards we have some time to answer a
few of your questions.
Um, so
first we would like to start with a
question for you.
Um, we've prepared a poll.
Um.
So just to get a
uh, understanding of the landscape in
the room.
Um,
did your organization
experience a type of an attack in the
past years? And if so, which type of
cyber attack?
There's also an option that if you don't
know if there has been a cyber attack or
there hasn't been any cyber attack. So
just for us to get a yeah,
um, to see
what we're dealing with today.
I'll give you a minute to fill in the
question.
>> See, some people are still
giving up their choice.
So, I'll wait a bit.
See, we're at 75%
now.
But, we can already see that
well,
most of you have experiences with
fishing.
Um
and well,
part of you is not sure about
if there has been any attacks. But, um
yeah, the the people who choose for
fishing,
um
it's the same with the the trend we see
in the whole world.
Um fishing remains the number one entry
point for cyber attacks, so
um
that doesn't surprise me that much.
And then we another question.
I'm also curious to know more about
your organization facing
challenges in cybersecurity. So, where
does your organization currently face
the biggest challenge?
So, what's keeping you from
making your organization more
secure?
I'll give you a moment to
look at the answers and choose your
right answer.
So, more
than 60% of you fell in their
answers. And what we see is that most of
you say that the staff knowledge and
awareness is the uh biggest challenge.
Um and that's something yeah, we see as
the often as the number one challenge in
uh cultural organizations.
Um
and it's something you can work on, so
that's good news.
Um
and we will tell you more about that
later.
Uh but human behavior remains the
biggest vulnerability for um
uh in to cybersecurity for
organizations.
Okay, thank you for being
uh honest and sharing your experiences
with us.
Um
I'll put on the next slide.
Yeah, when culture becomes a target, uh
we
um cultural institutions are
increasingly targeted by cybercriminals.
Um and sometimes we get the question,
"Why?" Because people think they're not
really a target because
they don't have that much of money or
something
um
that makes them very special to have a
uh cyberattack.
Um but you hold valuable data from donor
information to collection records.
Um and you use the uh systems that
public uses like your website or your
ticketing systems. Um and many uh
organizations rely on older
infrastructure or limited IT capacity.
And that combinations make you a
um attractive uh target for attackers.
And
most of you probably have heard about
the break-in at the Louvre Museum uh a
few months ago with the
uh service lift that had they had placed
be um just in front of a window and they
uh went up that stair of the the
elevator and they had a break-in.
Um it was a physical break-in, but um
the intruders reached uh restricted
areas using a service elevator.
Uh but that also revealed the weakness
of the cybersecurity. So, they used
really old
um systems on Windows Server
uh from 2003.
And uh there were a lot of gaps in his
computer security.
Um and that was
um
a great example for like a uh
world-class museum that struggles with
cybersecurity.
Um and they also used the password
Louvre for one of their security
systems.
Um this it shows how universal the
problem is and it's not to
um point a finger at them doing it wrong
because it's important to be open about
what happens uh in the sector.
But it gives a good example of how big
the problem still is uh in the cultural
sector.
Next one is the Uffizi Gallery.
Um
they had also had a cyber attacks a few
months ago.
Um what makes this attack interesting is
that the cyber uh incident was uh
involved access to internal system and
sensitive data.
And in report of media reports that they
had access to uh floor plans, uh access
codes, and camera locations. So, it
looked like they were preparing a
physical break-in.
So, they first started with a cyber
attack to get all the right information
so they could prepare the physical
break-in. Luckily, they discovered the
the the attack so they could take some
measures like
uh closing temporarily uh some areas and
move valuable objects to uh different
locations.
Um
but this shows how cyber incidents can
directly impact operations, uh visitor
experiences, and uh even collection
safety.
And one last example is from a really
small museum in uh the Netherlands. Um
it's called the Vein Colonial Museum in
Veendam.
It's like a really small museum. Um but
this museum was hit by a LockBit
ransomware attack and hackers stole some
Um
demand payment.
They
did not agree to
go on with the payment.
And unfortunately, the museum had some
paper backups, so that's what that
had them saved.
They only lost like
a week of work, so
there wasn't a lot of damage, not
financially and not in the the other
um
damage.
But what was
what the director, sorry, I have to take
the director of the museum
said in the media, there was a quote of
him
that he was happy to discover that there
was only like a cyber attack and not a
physical break-in. So that really shows
the priorities of how people see like a
physical break-in and a piece of your
collection will be stolen or like a
cyber attack.
And this also example gives a good
example of how like a small museum also
can be a target.
Now
my colleague Pascal will tell you more
about AI in cybersecurity.
>> Yes, so as the title of this webinar
already suggests, it's a rapidly
changing digital world and AI is really
rapidly interfering with everything in
our lives and also with cybersecurity.
I want to start with a different
example, not out of the cultural sector
or not a museum, but very dystopian and
made with AI.
Arup is a large engineering a British
engineering company and in 2024,
one of their Hong Kong employees got a
phishing email
which she already found a little bit
suspicious but then they followed up
with a meeting and she joined the
meeting and she saw her CFO CFO and some
of her other colleagues and she wired
a lot of money I don't know the exact
number right now but a lot of money in
in 15 different transfers something like
that and later turned out that all those
colleagues in that call were deep fake
they were made with AI made with public
by the attackers with public images and
videos found on the internet
so yeah so they made
a whole different persona and this is of
course very dystopian and very
weird but luckily it's for now one of
the few examples that I could find
but it does show that it's really
changing and that they AI is really
changing the the field of cyber
security.
Another example I wanted to talk about
is the mythos model of anthropic which
they decided not to
bring out to the public
AI is really good at coding a lot of
programmers already use it they have AI
agents that are coding all night
building programs
and
anthropic made a new system mythos
that was so good at discovering mistakes
in code and almost every code even the
the the website of of our government
every code has mistakes and this model
was so good at discovering this mistake
these mistakes in code that anthropic
was hesitant of bringing it out to the
public cuz they thought that people
could maybe use it with bad intentions
to hack into
systems that they were not supposed in
to hack into so instead of bringing it
out to the this model, they made a new
project called project Glasswing,
which in which they used the model not
to attack, but to fix codes. This so to
find these mistakes and to patch them so
that attackers have a harder way of of
of getting in. And they're doing this
project with a lot of big tech companies
as well.
Big tech companies, so they're working
together on yeah, making codes and
using the AI actually. The reason why
they didn't want to bring it out was
because it was too dangerous and they
could attack with it, but they're now
using the model the other way around.
So, they're using it to protect their
systems and to making it more safe and
more secure.
Um
Yeah, so there's a lot of sources that
are now saying that AI is really
changing the field. Um there's a quote
from this uh threat landscape uh report
from ENISA that says that by early 2025,
AI supported phishing campaigns and uh
80% of social engineering is also AI
made now. And social engineering is what
Natalie said it's still the human side
of cyber attacks. So, trying for you to
click on a link that's not uh secure. Um
but you have to imagine we we right now
can use AI to write emails super quick
or write newsletters, but uh
cyber hackers can also use AI to write
thousands of phishing emails and send
them out automatically without having to
do the work themselves. So,
they also use AI to send out way more
fish phishing emails. So, the AI is
being used also in
normal
uh emails that people are getting.
Exactly. I see a comment, AI is a great
tool, but a great weapon as well.
Um
then there's this other report that I
found from CrowdStrike. On the left, you
see a a picture on
where they use AI and what kind of of
cyber attacks. Uh I won't get too
technical into these uh threats, but I
mostly want to want you to look at the
the the little, yeah, bars. You can see
that the blue one is 2024 and the red
one is 2025.
And you just have to see how much
difference there is. Um
AI attacks are growing more and more,
and probably this year it will even
be more and more.
Because it's yeah, AI is being in um
embedded in everything and also in cyber
attacks. So, they're not using AI to
invent new attacks, but they're just
using AI to make their existing ones
more effective.
They can create fake identities, like
the extreme example of the Air Up
company, but they can also translate
their phishing emails and send it to
way more companies in different uh parts
of the world in any language. Um and
AI-driven attacks have also risen by
2025 because AI is getting better and
better.
Um
and sometimes they even have an attack
chain fully automated, so they don't
need to do anything themselves anymore.
It's just an AI that's kind of doing the
cyber attacks for them.
Um then another thing, something that's
a little bit more close by, something
that you do have a little bit more
influence on, and that's shadow AI uh I
wanted to talk about. And um
it seems relatively innocent, I guess,
cuz it uh shadow AI is just the fact
that your employees or your colleagues
are using AI and um
without not necessarily secretly, but
without telling anyone that's in charge
they're using AI tools.
And the risk of this is that they use AI
without having a policy, without maybe
thinking about it, and they can upload
whatever data they want, and then that
data ends up in whatever AI they use,
and then you don't know what happens to
that data. So, you could be in
in
not in policy or in line with what your
vision is of what you want to do with
your customer data, for example.
And a way to to fix this is to think
with each other about AI and about an AI
policy. What how do we want to use it?
What what data can we put in AI and what
can we not put in AI? And if you have
this policy, then it's also easier for
employees or your colleagues to
to
tell you when it's wrong, when when
something happened, when they made a
mistake, when they accidentally uploaded
some data that they're not supposed to.
Because now when they're just using it
without a policy or without an open
conversation about AI, they will not
probably tell you
or each other that they've made a
mistake.
There's also European law that protects
personal data and visitor
data, and you could be in
in
violation of this law if your colleagues
or employees are using AI without you
knowing.
So,
we also recently at Dent created an AI
policy. I think it's very important to
talk with each other about it, about
what your ambitions with AI are, but
also
what you want to protect when you're
using AI.
So, this is also really a new threat
that um came to be recently, and but
it's important to keep an open
conversation with each other about that.
Um yeah, earlier someone already said it
in the comments, but it's true. AI is
changing both sides of the game. So,
it's on one side changing the the the
attack side, but it's also changing
uh the tools. There's also many tools
now that can protect against phishing
emails and against suspicious emails
that people are getting.
Um some comp In this report from IBM,
they mentioned that some companies that
use AI tools to prevent uh cyber
attacks, they've actually their data
breaches costed them less money if if a
data breach happened, or they have less
data breaches than companies that don't
use AI tools yet.
Um
Yeah, that's for for now my part. Later,
I will tell you a little bit what you
can do with AI, and I have to say that a
bunch of these AI tools that I mentioned
are already embedded in, for example,
Microsoft in Outlook. There's already a
bunch of tools embedded that we don't
even notice, that we don't even have
control about, but AI is already being
used in in cybersecurity.
Um yeah, later I'll tell you a little
bit more on what you can do yourself.
>> [clears throat]
>> Thank you, Pascal.
Now, let's look at the
um four-step step-by-step plan uh we
developed specific specifically for uh
cultural organizations.
Um it's a very practical guide for
institutions of any size.
Um but
before we dive into the step-by-step
plan,
um
I wanted to show you this slide. Um,
because within cybersecurity we talk a
lot about resilience and adaptability.
Um, because we see that the focus mainly
is on the prevention side, this the
resilience. So, how can you um, try not
to experience an attack.
Um,
and really focus on doing like
proactively um,
all sides of measures to prevent having
an attack.
Uh, but what we see is that it's
changing a lot because there are so many
attacks.
Um, also in the cultural organization of
cultural sector. So, I also want to uh,
tell you uh, that the
importance of being
uh, also uh, focused on the recovery
side. So, today the step-by-step plan is
also focusing more on the prevention
side, but at then we also try to uh,
develop a guide on how to write a
uh, incident response plan, for example.
So, even though prevention side is very
important, it's also important that once
you experience an attack, you know how
to react to that attack and how you can
get
um,
the organization back on track and all
the systems back on track.
Um, this is the four steps of the
step-by-step plan.
Um, so we'll look at all the four steps.
The first one is to identify your crown
jewels. I'll tell you more about that
um, uh, later. The second step is the
risk analysis and prioritization.
Um, the third step is the measures and
the responsibilities.
And the last step is a very important
one.
Uh, is that you have to keep monitor
monitoring and making necessary
adjustments. And it's like a circle, so
once you
did like the first step, you get back to
maybe after 1 year, back to step one.
Start identifying your crown jewels
again because you might have some new
systems in your organization or certain
new data you
um
gathered, so it's always
like a circle that you keep following.
Um the first step is to
uh
identify your crown jewels.
Um
the crown jewels are
the
critical processes, essential systems,
sensitive information, and indispensable
suppliers.
Um
It's important to know what your crown
jewels are because you can't protect
everything equally.
So you must know what matters the most
for your organization.
Um
And I have a few examples
of what crown jewels can be for museums.
For example, your ticketing system
because once you can't
uh sell any more tickets,
you have a big problem and you can close
the doors of your museum.
Or when your
customer relationship management system
is hacked and all the
donor information is
getting into the public, you have a big
problem. Um climate control is also an
important one. Most people don't really
think immediately of the climate
control, but if you have a big
collection, it's important that you can
still control your own climate control
system.
Um
And it's
important
uh
uh I made a like a schedule on how you
can map um
this
uh your crown jewels. So, you can just
think for yourself
what do we have like systems, data, or
processes within our organization? Just
write down all your crown jewels,
uh the impact of the downtime. For
example, our website we don't really
have a problem if it's down for like a
week, but if it's longer down for
uh after a week, um we are likely to get
a problem uh because we can't sell
tickets for workshops or trainings or
people are not able to reach us. Um and
also who is responsible for that
uh process or data or system.
So, that's an example on how you can map
your crown jewels.
And after we go look into the risk
analysis because that helps you
understand
uh which threats you face and which risk
you're willing to accept.
Uh cuz as I mentioned before, you can't
um uh secure all your crown jewels
because of money or capacity. So, you're
you're really looking into what matters
the most to our organization and make a
prioritization in that.
Um
Go to the next slide.
Um cuz yeah, common cyber attacks are
phishing mails, fake logging pages,
ransomware, stolen passwords, CEO fraud,
of abuse of supplier accounts.
So, if you have the crown jewels, you're
going to look at what are the risk we're
facing. For example,
um
ticketing system can be hacked, but what
will the risk be of that?
And
then you can make a risk matrix.
Um and you determine your priorities.
So, you look at the likelihood of how
the is it going to happen or not?
Uh what is the impact of the
uh the risk?
Um and this matrix helps you decide what
to act on immediately,
uh and what to monitor. Uh it's also a
great tool for communication priority
priorities to management.
Because we also heard that a lot that um
well, it's a IT problem, most people
think, uh but it's good to have that
conversation also with management.
Um the first third step is look into the
measures and the responsibilities.
Um and there we have four categories.
Uh the first one is uh governance, and
that's about leadership, uh
decision-making,
um and accountability. So, who is
allowed to make decisions,
uh who is the leader of the the uh
the data or the systems?
Uh next up, it's policies. Also where uh
Pascal told us more about AI policy, but
also cybersecurity policy. So, it covers
rules that define required security
behaviors and control. Uh it's good for
your staff to know what is allowed and
what is not allowed to do.
Um IT security, so that's more the
technical measures.
Um so, how you can uh
protect your systems, your networks, and
your data. I'll tell you more about that
later.
Um and awareness and training. And in
the beginning of the webinar, you told
in the poll that
um a lot of people have like the biggest
challenge in the awareness side of their
organization for the staff.
Um so, it's really important to give
that more attention.
Um an example of measures.
Uh the first one is like the
multi-factor authentication.
Um but also, we hear a lot of people
that make uh backups, but if we ask if
they also test their backups,
um most of the time they have to say,
"No, we don't." Uh so, that's really
important that if you make backups,
that's good, but also check if they're
working. So, do like a test run once a
year to see if the backups really do
what they have to do.
Um install updates. Uh limit access
rights, so not everyone has to go into
every system or see every uh set of
data.
Uh fishing training to erase the
awareness for your staff. Um
then create an incident response and
procedure.
And step four is um well, cybersecurity
is a continuous process.
Um and we encourage a reporting culture.
Uh so, mistakes should be reported early
and not hidden. So, try to talk a lot
about cybersecurity with your
colleagues, with your staff.
Uh that they feel
um that it's okay to make a mistake
sometimes. It's good to know that the
mistake has
uh happened than to hear afterwards that
people were afraid to tell you that they
clicked on a phishing link, for example.
Uh and cybersecurity is just a
Well, that's what I said before, the
continuous process, the importance of
reporting culture. So, do like a coffee
moment every
um every month, um do a
awareness workshop every year. Uh there
are a lot of uh examples to think about
to raise awareness within the
organization.
And also, keep evaluating and improving,
cuz
uh that's the most important part of
cybersecurity. Just monitor what
happens.
Uh are there any attacks? What do we
see?
Uh
and keep talking about it with each
other.
Um and then to help you
uh make a first step uh tomorrow,
um
I've wrote down some actions.
Uh so, turn on multi-factor
authentication for all critical accounts
and systems.
Um schedule a restore test to verify the
backups actually works. As I mentioned
before, a very important one.
Uh create overview of systems and
suppliers.
Uh define how to contact in case of an
incident and set up a call list.
Uh and make sure that the call list
isn't on your computer, but also have
like
list of uh people you have to call once
uh you experience an attack, because
maybe you won't have access to your
computer anymore.
Uh and share concrete tip about phishing
or a suspicious emails with your team to
raise staff awareness.
Uh that's also just to have that
conversation going.
>> Yes, and then about the AI part.
Um
So, as I said, the AI monitoring tools
already detect unusual activity, and
most of them are already embedded in
into our own email systems that we're
using.
Uh those stop a lot, like 90% more
maybe, of spam and phishing malware
attacks already. So, AI is already
working for us as we speak.
Um multi-factor authentication, it's
kind of the same as cybersecurity, just
for AI. It's just an extra step that I
guess you have to take into account in
this new day and age.
Um
Clear staff guidelines are very
important, especially with the shadow
AI. So, talk with each other about it.
Like, make a policy together on how you
want to use AI and what tools are
allowed and what tools aren't.
Um and what data you can use to to um
work with AI and what not. So, because
when there's guidelines, people also
know when they're doing something wrong
or not.
Um and then they can talk about it. Then
they can say, "Oh, I made a mistake." Uh
and then you can work together on fixing
that mistake.
Um
So, yeah, make sure your team is aware
how to report something, uh what to do
in case of an accident, and what tools
are approved, and how they can use those
tools. And um for that, I just also
wanted to end on a note that like you do
not need a big budget or a super big IT
team. It's just important to start
somewhere and to start and to keep
talking about it with each other and
keep that awareness on both
cybersecurity and AI. Um because when
that conversation is there, people will
admit they make mistakes, or they will
ask questions on how they can use it
safer. Um
So, yeah.
Um
Talking with your team, and and yeah,
kind of what Natalie says, the AI and
cybersecurity, it kind of stays the same
what you need to do or what you can do.
There's one tool that I've also heard
of, it's Darktrace, and that tool learns
how people behave on your website, for
example, and then flags anything that
doesn't fall into that behavior. And
there's probably going to be more and
more AI tools the more and more AI is
developing.
So, yeah, start with talking, then maybe
see what tools fit you and if you need
an AI tool to to block cyber attacks.
So, yeah.
That's
our tips, I guess.
Are there any questions?
>> Yeah, thank you, first of all, Pascal
and Natalie for guiding us through
today's session. And
yeah, we have some time for questions.
This session is also recorded, and
everyone here can also get in touch with
Natalie and Pascal
afterwards.
So,
we see
I see a question from Florentina.
If someone uses ChatGPT, for example,
to, for example, summarize official
permit applications, does that mean that
the data you enter may end up being used
by an unknown unknown user?
>> Well, that's the the whole thing about
AI and big tech companies that make AI,
and ChatGPT is one of those big tech
companies.
We don't really know what happens to the
data, and that's maybe the scary thing.
So, you don't know if it's
used by someone. It's definitely used
mostly to train their data. If you have
a paid account, you can turn on some
privacy settings, but still it's kind of
a black box where our data goes. So,
anything you upload into ChatGPT
or other AI tools,
there's some AI tools that like claim to
be a little bit more ethical with their
data, or they store it on European
surface servers if that's something you
care about. For example, Mistral.
Um
But yeah, the data you upload into
ChatGPT, you don't know what happens to
it. Um
it's mostly used to train their model, I
think, but they do have because you send
it to them. So, they do have it
somewhere saved on one of their servers,
and that's just the scary thing about
those big AI tools.
>> Yeah.
>> So, what we do, we you can use those
files, um just remove anything of
sensitive data. Remove names, remove
email addresses, remove addresses,
remove phone numbers. Like if it's just
the
the information or the context, then
it's Yeah, you have to really decide
with each other what you think is
sensitive data, what can you give to the
AI. Um public articles or things that
are already on your website, that's
totally fine because it can already
access that cuz it has access to the
internet. But just uh with sensitive
files, with names and stuff, you can
remove them, censor them, and then give
it to the AI, and then it at least won't
have those uh details that you removed.
>> Sophia asked, um can you share any best
practice examples of a sound policy in
the field by a museum in Europe?
>> A very sound policy?
>> Sound policy?
Uh in the field used by museums in
Europe. Sophia, if you want to
uh specify the question.
Um
And by that time
the current coherent policy.
>> Um
Um
For cybersecurity or AI?
Um
>> Hm, Sophia again.
>> Any of them.
>> [laughter]
>> Okay.
>> No, I don't have a example of a
policy
um using a field by UE museums. Pascal,
do you have a example?
>> Well, with cybers or with AI, I think
with AI policies it's pretty new and as
like the regulations here in Europe are
like everyone is still it's still a
little bit open, which is pretty nice
because it has a lot of space to develop
and be used. Um but the guidelines are
really dependent on each company. You
can see that like big commercial
companies that want to make a
uh
a lot of profit, they care a little bit
less about the privacy of their
customers and they do use a lot of AI
tools to automate a bunch of processes
like um sending invoices or something
and we do see that here in the cultural
field with museums we they value more
the the privacy of their customers and
they're more concerned with ethics. Um
so it really depends per per
organization. We've also spoken to one
organization here in Holland who has
made their own AI. For example, the the
city archive in Amsterdam has made their
own AI model so they don't have to use
any uh big tech model, so they don't
have to so their those big AIs cannot
use their data and because they have so
much there in archive. So, it really
differs right now. There's not really
one policy I can say follow it follow it
it really depends. We do have a
step-by-step plan at then on how to make
an AI policy, but it's it's in Dutch.
It's not in English yet, but I don't
know you can ask AI to translate it
[laughter] I guess. It's very good at
that. That's public knowledge, so it's
not sensitive data. You can share it.
Um but those questions are mostly what
tools do you want to use? What data can
you use? What are the ethical or or um
environmental decisions you make, but it
it really depends per per company. We
just recently made it up and it's a
bunch of conversations, a bunch of
discussions with each other. What does
each colleague think and
in the end everyone has different
opinions, so
um I don't also don't really have one
clear answer.
It really
that conversation of building one is
already what's important.
>> Yeah. Yeah.
And it's the same for cybersecurity. You
can have a look into the NIST 2 uh
requirements.
Um and
uh here in the Netherlands we're still
working on that law
um based on the NIST 2 measurements of
requirements. Uh but you can have a look
into it and see um what is important for
your organization
uh
to well, take over uh put it in your
policy
uh and just have a discussion with each
other about it.
>> Uh another question um can AI be trusted
for cybersecurity decisions or should it
always remain human supervised?
>> So, AI is really because AI is so quick,
it can really quickly see fishing emails
or suspicious behavior on your website.
But with every AI application, I think
it's really important that a human stays
in the loop. That in the end, the human
still takes the decision. So, AI I
wouldn't see it as um
as its own entity. It's really a tool. A
tool used by the people that make the
policy or the people that are in charge
of cybersecurity. And they still decide
what the tool can do, what the tool
won't do,
uh when to use the tool, when not to use
the tool. So, it's really you cannot
just give it to an AI and let it do it.
It's really important that humans still
also are aware of cybersecurity
and also are aware what the AI is
stopping. Cuz if I don't know if your AI
is stopping 100 fishing emails per day,
then maybe there's also something wrong
somewhere else. Um so, it's really
important to stay in the loop as well
and um not just give it all to an AI.
>> [laughter]
>> The big message, yeah.
And um what basic security measures give
the biggest return of investment?
If you can say something.
>> I would say um MFA, so multi-factor
authentication, because it doesn't
really cost that much to
uh
get that in your organization and um
have that uh sourced in your
uh systems.
But it can help you um
a lot in the uh prevention side. So, it
keeps out a lot of
um
unwilling uh
uh
experiences.
Um and next I would say
um is to
uh do like an awareness workshop to have
the
awareness raised in your organization
because the human factor in
cybersecurity is one of the most
important entry points.
So, I would say spend a lot of attention
to how to get your staff improve their
knowledge about security, cybersecurity,
and how to raise awareness. So, start
for example with a coffee moment once in
a month.
Do like a if there is has been a
phishing mail, share it with every
person in your organization. Just show
the examples.
Show the the success stories, but also
the moments where it didn't really go
that well. So, people can learn from it
together.
Thank you.
There's one question connecting back to
Nathalie's comment about the NIS2.
Question from Xavier.
Maybe it's a bit too complicated. So, we
see if we can answer those questions.
Otherwise,
um
as we said, everyone can connect with
Nathalie and Pascal afterwards.
For a mid to large middle to large
museum in the in Europe, what are the
concrete first steps to determine NIS2
applicability and begin compliance,
especially if the national transposition
is still incomplete?
Oh, that's a big question.
>> [laughter]
>> Um
I'm reading it in the chat.
>> Can you see it?
>> Yes.
>> Yeah.
>> So, what are the concrete first steps to
determine NIS2 applicability?
Um
I can't really answer that question
right now. Um
Um as I said, it's
the requirements are on European level
and in the Netherlands they're still
discussing the law about it. Uh it
probably will
be in force this summer.
Um so yeah, for the moment I can't
really give an answer to this question.
Yeah.
>> So I think the advice would also be it
to stay in touch. As you said, talk to
each other. NEMO has upcoming trainings
on
AI and cybersecurity in autumn. We have
our upcoming European Museum Conference
in October in Vilnius where also
colleagues from DEN
will join a workshop
or a panel.
Um
and and also for
the next year we are planning a
cooperation with DEN.
So all NEMO members can participate in
in hands-on trainings. I guess this is
what what we need nowadays
more and more. So um
I would say thank you very much, Pascal
and Nathalie.
And
>> Thank you.
>> day to all of you. Stay positive and
hopeful.
>> Exactly.
>> And yeah, think about the activities you
can start tomorrow.
Uh
yeah, and start.
>> Exactly. It's not all lost. It's
hopeful. We can
If [snorts] we work together.
>> [laughter]
>> Exactly. Thank you very much.
>> Thank you.
>> Bye-bye.