Image placeholder — to be replaced

4 min read·953 words·Updated July 20, 2026

I spent years coordinating security for a regional gallery, and the question I got asked most often by the board was some version of “what are we actually required to have?” It’s a reasonable question. The honest answer, in Australia, is: less than most people assume.

Every Institution Is Working From the Same Soft Standard #

Whether it’s a state gallery or a two-room regional museum run largely by volunteers, everyone in this sector is ultimately answering to the same non-specific benchmark. That surprises people who assume a bigger institution must be operating under a stricter regime. In practice the size of the collection changes the resourcing available to meet that standard, not the standard itself, which is exactly why museums and institutions of very different scales can end up with very different real-world security, all while technically meeting the same requirement on paper.

There’s No National Rulebook for Museum Security #

Unlike some countries, Australia doesn’t have a single detailed security code that museums and galleries are legally bound to follow. The closest thing this sector has is the National Standards for Australian Museums and Galleries, now in its second edition, and its actual security requirement is a single line: the organisation “meets fire safety standards and uses appropriate security measures.” It lists some suggested measures, alarms, fences, movement sensors, key control, but it doesn’t mandate any of them specifically, and it doesn’t mention CCTV by name at all.

For an institution trying to do the right thing, thats simultaneously reassuring and unhelpful. Reassuring because there’s no long checklist to fail. Unhelpful because “appropriate” is left almost entirely to interpretation, and interpretation tends to default to whatever’s already in place.

Government Indemnity Exists, But Not for What You’d Expect #

A lot of smaller institutions assume there’s some form of government backstop if a major work is lost or damaged. There is, but it’s narrower than people think. The Australian Government International Exhibitions Insurance Program subsidises commercial insurance for touring exhibitions, but only above minimum valuation thresholds of $25 million for fine art or $10 million for museological material. That’s simply not relevant to the overwhelming majority of Australian collecting institutions, who are managing genuinely significant but far smaller collections day to day.

So for most museums and regional galleries, there isn’t a government safety net sitting underneath them. Whatever security programme exists is the actual protection, not a formality sitting alongside a bigger guarantee.

Two Recent Incidents Worth Knowing About #

In May 2025, a bronze bird sculpture was sawn from its outdoor plinth at the New England Regional Art Museum in Armidale over a weekend, discovered missing on the Monday. And in early 2026, an offender smashed a display case at the Abbey Museum in Caboolture and took several ancient Egyptian artefacts, damaging other items in the process, before being arrested with the items still in his possession. Neither of these are large national institutions. They’re the kind of regional and specialist museums that make up most of the sector, running on the same soft standard as everyone else.

I don’t raise these to alarm anyone. I raise them because they’re a useful reality check against the assumption that a break-in only happens to somewhere famous. In both cases the institutions involved were doing broadly what the sector expects of them. The gap wasn’t negligence so much as a soft standard leaving a specific, ordinary vulnerability unaddressed until it was tested.

Where I’d Actually Focus, Given the Standard Is Soft #

Because the National Standards doesn’t specify hardware, the practical question becomes what a genuinely defensible security programme looks like, rather than a minimum one. In my experience that starts with visitor flow and access control, keeping the public separated from storage and back-of-house areas by more than a “staff only” sign, followed by proper key control, which is exactly the area the Standard mentions but almost nobody actually formalises.

Case-level and object-level sensors matter more for open displays than most institutions budget for, precisely because a smashed case, like the one at the Abbey Museum, is often over before a general room alarm would even register it as unusual. And storage rooms, holding the majority of most collections that aren’t on display at any given time, tend to get far less attention than the public galleries, despite holding more value.

Loans and Touring Exhibitions Are Their Own Problem #

Lending institutions genuinely do check security, insurance and incident history before agreeing to a loan, and a touring exhibition concentrates significant value into a space for a limited window. That’s a different risk profile to permanent collection security, and it needs its own planning rather than assuming the everyday setup will cover it. I’ve seen loan applications stall because a borrowing institution’s ordinary security, entirely adequate for its permanent collection, wasn’t judged sufficient for a higher-value visiting exhibition. It’s also worth remembering that risk during a loan isn’t limited to theft. Fire and water damage to a touring work, in an unfamiliar building with unfamiliar systems, is exactly the kind of threat early fire and water detection is meant to catch, and it’s easy to overlook when the focus is entirely on locks and alarms.

What I’d Tell a Board Asking the Original Question #

“What are we required to have” is the wrong question, even though it’s the one everyone asks first. The right one is closer to: if a lending institution, an insurer, or a genuinely determined opportunist looked hard at what we’ve actually got, would it hold up? The National Standards won’t tell you the answer, because it was never written to. A proper security assessment against real risk, not just the soft benchmark, is the only way I’ve found to get a straight answer to that question.

Leave a Reply

Your email address will not be published. Required fields are marked *