Interoperability – Are we there yet?

Author: Colin Robbins

27 Sep 2023

What is interoperability, and are we there yet?

So, what is interoperability and, most importantly, are we there yet? Throughout my time as Principal Security Consultant at Nexor, a common thread of all the products and projects I have worked on has been interoperability (and this question) – how do you get system A to exchange information with system B? You would have thought after 30+ years the problem of interoperability would be solved, but it keeps making an appearance.


You may have seen a recent press release from Nexor about the MDIS project, which, from my perspective, is all about interoperability between systems to form a Single Information Environment (SInfoE). MDIS brings together many threads of research. In this blog, I explore one such research thread looking at what interoperability is and the challenges it presents.

What is interoperability?

Interoperability is the ability of systems, software and applications to exchange data seamlessly and accurately. Interoperable systems can also allow other systems to read, update and modify data with less human interaction. 

There are various levels of interoperability to be aware of (which we’ll discuss in more detail later on).  ETSI describe interoperability in a four-level hierarchy:

  • Technical Interoperability – Data can be exchanged between systems;

  • Syntactic Interoperability – The format and structure of the data is recognised;

  • Semantic Interoperability – The meaning of the data is understood;

  • Organisational Interoperability – The data can be used across organisational boundaries in automated processes.

What are the benefits of interoperability?

Interoperability is crucial due to its ability to allow data sharing between platforms and software applications. Most importantly, it improves user experience, meaning that users don’t have to sift through various platforms to find a simple piece of data. 

Its ability to allow data sharing between separate information systems also prevents data silos. Interoperability benefits in several other ways too:

Improved efficiency

Interoperability makes operations more efficient by removing the need to retrieve data manually. It allows employees to focus on their role without having to retrieve or spend time correcting data manually.  

Better collaboration

With better efficiency comes improved collaboration between teams. Interoperability removes barriers between data silos and data sharing, allowing employees to share datasets much easier.

Enhanced decision-making

Quick access to data from multiple sources enables a more comprehensive view of data ecosystems. This allows senior stakeholders to make better, more data-driven decisions.

Key aspects of interoperability

The main purpose of interoperability is to make sure data sharing is more efficient, but how is this achieved?

System communication

A key aspect of interoperability is ensuring that computer systems or software can communicate effectively and understand the information/data being exchanged.

Shared data

True interoperability requires that the system receiving the data understands it and knows how to use it. More simple data sharing methods cannot do this, making interoperability unique. 

Adherence to standards and compliance

Interoperability must adhere to certain standards to ensure security and compliance. These standards are also very important to ensure that systems understand the data they are receiving.

The four levels of interoperability

Firstly, as an example of semantic interoperability issues, consider a message that communicates information about an event that occurred in the past, and that the communication includes a data and time. Syntactic interoperability allows me to recognise it as a data and time.  But only semantic interoperability allows me to determine if this is the time the event occurred or the time the message was sent.

Organisation interoperability takes this further, by recognising what the message means and triggers a business process to deal with it.  For example, understanding a flight plan and ingesting it into an air traffic control system.

These last two levels are crucial to understand. All too often engineers connect systems and achieve technical and syntactic interoperability but overlook Semantic and Organisational.  This can be the result of using Open APIs or standards, which very often enable technical and syntactic interoperability, but can lead to engineers blindly using the API without considering the wider aspects of interoperability. An often-quoted example is the crashed Mars lander where an API expected a distance to the surface measurement to be supplied, but the measurement was supplied using the incorrect units.

Challenges in interoperability

Managing large amounts of data

Despite its efficient data sharing capabilities, managing a large amount of data at scale is still an issue. It takes skill, time and expertise to extract large amounts of data cleanly and efficiently. 

Privacy concerns

Organisations, especially those who operate in government and military, must take extra measures to ensure data extraction is safe and secure. Interoperability can become complex with multiple systems to account for, so rigorous security standards must be adhered to.

Interoperability use cases

Military and defence

Interoperability is very important to make military operations more efficient, especially when various countries need to communicate information and data. Interoperable systems make it possible for members of NATO, for example, to share common tactics and procedures and equipment standards when they train and conduct missions

Government

Governments use interoperability to improve communication between different departments and save money by making operations more efficient. These systems are used to plan budgets, enroll citizens in benefits programs and file electronic tax returns.

What is Nexor’s view on interoperability?

Nexor’s own research suggests that Organisational Interoperability is very broad when dealing with interoperability between systems-of-systems, as seen in the military. We prefer to expand this level into:

  • System interoperability – The data can be accessed, verified and used by different systems, across system and organisational boundaries.

  • Business interoperability – Trusted Information is available to business decision makers, anytime, anyplace, anywhere, irrespective of the source.

This approach brings in the dimension of security. The ability to share information is compromised if the information cannot be trusted. In the next blog in this series, I will discuss the challenges of secure interoperability.

So, what does the interoperability hierarchy mean if you have systems which need to interoperate? Our interpretation is you need a robust process that starts with the information exchange requirements and puts them firmly in the context of the business need. Only then can you start to understand what data needs to flow around the system and design how you are going to exchange that data (securely) between dissimilar systems. That’s what I’ve spent, one way or the other, 30+ years at Nexor doing!

“To answer the question “Interoperability - Are we there yet?”. No, and never will be, but if we think about all four levels of interoperability at the outset, for today and any future interoperability needs, then this will help.”

Innovation and system evolution will bring a greater need to share greater volumes of data, in application-optimised formats which are increasingly untrustworthy. Interoperability and secure interoperability will be on the agenda for a long time, so why don’t we start by designing it in!

How Nexor can support your interoperability requirements

At Nexor, secure information exchange is what we do. Our range of cyber security advisory services and our specialist range of products including our Data Diode, can help your organisation streamline interoperability securely.

Get in touch today and see how we can help you.

Read the complete interoperability series

This is part 1 of a 4 part series on Interoperability. Explore the full story:

  1. Interoperability – Are we there yet?

  2. Security and Interoperability – a Conflict

  3. Zero Trust and Interoperability

  4. Standards and Interoperability

Read more posts on

About the author

Colin Robbins is a Principal Security Consultant, leading customer-funded research activities in secure interoperability and information exchange. He has specific technical interests in the Single Information Environment and Data Centric Security, as well as the processes of security, such as Secure by Design and Information Security Management Systems (ISMS). He is a Fellow of CIISec, and a former NCSC certified Security and Information Risk Adviser (Lead CCP).

Colin Robbins on Linkedin

Read more posts by Colin Robbins

Read more posts on