Garth Stewart is Head of Good Practice at the Digital Preservation Coalition
In these disruptive geopolitical times, we’ve all become aware of the threat which cyber crime poses to our everyday. Whether it’s targeting government, education, civic infrastructure, even big tech itself, cyber crime is a depressing topic we see on the news a lot, and is a trend which shows no sign of diminishing.
As digital preservation involves the preservation and provision of access to digital materials, it’s no surprise that cyber crime and cyber security have long been hot topics for DPC Members. We’ve responded to this through recent programming.
In June we held an event to shine a light on recent community experiences, via a set of powerful case studies from across the World. DPC Members and Supporters are welcome to log-in to the DPC website to watch back these excellent sessions.
Over the summer, we also released a new mini-series of Technology Watch Guidance Notes on Cyber Security and Resilience for Digital Preservation, to a new provide up-to-date, practice-informed resource. Heather Lowrie, Director of Resilionix, and I were commissioned to lead on this work. Heather and I were former colleagues at National Records of Scotland: Heather was head of cyber security and I led the team which delivered digital preservation services. Our teams – helpfully supported by DPC training materials - successfully collaborated on new workflows, processes and working relationships which enabled critical preservation tasks to be carried out safely and securely. This experience provided Heather and I with a people-centred lens for thinking about this subject, and it was a privilege to collaborate with Heather on this task.
We are delighted that the Guidance Notes go on general release today: each Guidance Note is designed to be practically usable and should take about 15-20 minutes to read, or 60 minutes for the whole set. Cyber security is a fast-paced area, and so we have included plenty of resources and authoritative websites to check back as professional advice and guidance evolves. To support access further, we summarize the Guidance’s Notes’ key guidance and recommendations below.
Understand Cyber Threats
The first Guidance Note provides an introductory framework to cyber crime for digital preservation practitioners. We highlight how the overlap of digital preservation and cyber security can make for a “complex security challenge”, involving many technical processes, high-value content, and finite resourcing. These factors can make digital preservation collections attractive targets for cyber criminals. To support awareness we cite some primary cyber threats on the global and digital preservation-specific level:
| Global Risks | Digital Preservation Risks |
| Malware | Unknown Provenance |
| Ransomware | Old formats, software & systems |
| Geopolitics <-> data sovereignty questions | Working with external media |
| Supply chain = convenient yet vulnerable | Supply chain services = distributed systems, bigger 'attack surface' |
| AI-authenticity and confidentiality | Scale: need to automate & innovate |
Some of these threats may be tackled by conventional IT and cyber security practice, but some digital preservation requirements may require further oversight – such as our permanent need for innovation and hazardous format handling. We need to collaborate with colleagues to envisage and implement safeguards that are well understood and allow our critical work to be carried out safely and securely.
Engaging Stakeholders
This need for effective engagement, especially with organizational leadership and IT laid the basis for our second Guidance Note. We strongly advocate how our overall success is dependent on their collaboration and support to our work, and that they need to understand and accept their own shared responsibility in our mission to preserve our digital content of long-term value. We describe the role of ‘change agent’ for digital preservation practitioners in this, whilst emphasising that no practitioner should tackle this topic alone. Employee health, wellbeing and safety are very real themes here. We identify and refer to a series of industry tools which could support this stakeholder engagement work: Zero Trust thinking for engaging leadership, NIST for working with IT. Dive into the Guidance Note to learn more.
A powerful theme that surfaced is that if implemented correctly, digital preservation not only complements cyber security: it strengthens it, simply through the processes that we have in place to protect the usability, integrity and authenticity of our collections.
Respond
This led to our final Guidance Note, where we dive into the details, and discuss some typical digital preservation tasks which may require particular cyber security implementations: think isolated sandbox environments for innovation, handling collections with very limited provenance, safely unpacking hazardous formats, using open source tools, having known and tested remediation processes in place. Being 2026, we really had to talk about AI(!), and we list some recommendations on the known threats and methods for considering the use of AI in our work. In the spirit of practical output, we finish the series with a draft roadmap of suggested steps towards maturity in cyber security for digital preservation:

It was hugely fun and informative to work with Heather on these Guidance Notes, and we hope they are useful to the wider community. It feels like we have just scraped the surface on what is a huge, evolving topic, but we hope the resources create a basis for further community collaboration. Like digital preservation, cyber security, will never ever be considered ‘done’, it’s too closely coupled to modern life for that! But awareness and collaboration can help and we hope the Guidance Notes can be a springboard for wider, open and trusted discussion on this complex topic.




















































































































































