Even the Pope needs a firewall. The Vatican could be on the hunt for its first-ever Chief Information Security Officer to help guard the gates of the digital heavens from ever escalating cyber threats.
Posting their plea on social media, the Vatican CyberVolunteers said the Holy See needed urgent, strategic cybersecurity leadership to help protect the Church’s ‘invaluable spiritual, cultural, and diplomatic assets’ at a time of extreme cyber threat.
In an accompanying report outlining the need for advanced cyber protection, instigator of the CyberVolunteers, Joe Shenouda, described the Vatican’s digital and digitised assets as ‘incalculable’, including hundreds of years of diplomatic files, financial and admin records, and, perhaps most at risk, personal data relating to Vatican employees, clergy and millions of church members.
Even the contents of the Vatican’s Secret Archive, now known as the Apostolic Archive, are considered to be at risk, housing centuries of papal and state records, accounts and theological treaties.
By the CyberVolunteers estimate, this Archive alone contains eighty-five kilometres of shelving, with seven million images and tens of thousands of historical assets already accounting for some of the 180 terabytes of digital storage capacity the Secret Archive requires.
Though the contents of its heavenly cloud might be unique from other businesses, the Vatican is just as reliant as any enterprise firm on digital platforms, infrastructure and data as it navigates the online world.
In fact, in some respects, the Vatican has a more dense digital footprint than even the world’s biggest firms. For example, the report highlights that the Holy See is responsible for global communication networks maintained through a host of official websites spanning its various institutions and services, as well as internal systems vital for the running of the Vatican City State.
Those range from healthcare services to economic functions, amenities, education, not to mention the administration of the Vatican’s holy sites.
This wealth of data is, of course, tempting bait for cyber-attackers. According to a report from Politico, the Vatican routinely swats off threat actors’ phishing attempts, while the CyberVolutuneers reported once finding malicious Wi-Fi transmitters around Vatican City aimed at tricking staff into handing over credentials or opening the door for hackers into its systems.
Unfortunately, those efforts can prove ineffective, especially when facing nation-state cyber threats. In 2022, the Vatican was knocked offline in a suspected DDoS attack days after Pope Francis criticised the Russian government regarding the war in Ukraine, while the New York Times reported in 2020 that a Chinese state-sponsored hacking group had tried to breach the Church’s mail servers.
During a conclave, as has just passed, these cyber intrusions become more evident, with the Vatican having to perform regular sweeps for signal jammers and unauthorised devices that might help secrets spill out.
So far, the Church has not proven up to the challenge these incidents present.
According to the CyberVolunteers report, the Vatican suffers from having no overarching, C-level security leader responsible for the entirety of the Holy See’s digital operations.
It also lacks a dedicated cybersecurity policy unit, a national cybersecurity strategy, an implementation plan, a threat analysis unit or a cyber-incident response team. This puts the Vatican’s cyber command far behind that of other first-world nations.
Last year, the UN agency responsible for tech and telecoms, the International Telecommunication Union, rated the Vatican as a Tier 5 nation, the lowest possible ranking, in its Global Cybersecurity Index. Notably, the City State was the only Tier 5 nation in all of Europe.
Recommended reading
- Two-thirds of CISOs Have Had Budgets Slashed Due to AI
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
This isn’t a new problem, but as might be expected from a more than 2,000-year-old institution, the Church moves slowly. In 2023, a group of Catholic IT experts called for the creation of a dedicated “Vatican Cyber Security Authority”, and although that hasn’t yet got off the ground, the Vatican CyberVolunteers are trying to fill the void.
Something like a digital Swiss Guard, the CyberVolunteers do their best to fend off what can be incredibly sophisticated attacks, but are clear that what they need most is more effective and strategic cyber leadership.
“The CyberVolunteers have strived to share threat intelligence, identify vulnerabilities through penetration testing, and offer support where possible,” said Shenouda in the foreword to his report.
“However, such voluntary, and often reactive, efforts, while born out of sincere dedication, cannot substitute for a formal, strategic, and empowered cybersecurity leadership structure.
“The establishment of a dedicated Chief Information Security Officer within the Vatican is not merely an advisable upgrade but an existential necessity.”





