Secure information sharing across boundaries

Author: Nexor

18 Mar 2026

Tags:

Why firewalls are not enough

In this article

  • Why firewalls were never designed to manage information, only connections

  • A better model for thinking about secure data exchange

  • Five questions every organisation should ask before choosing a solution

  • How to share data confidently without expanding your attack surface

Most organisations believe they have a security problem. What they actually have is an information exchange problem. The distinction matters more than most people realise.

Whether it is intelligence moving between teams, data exchanged with partners, or operational insights flowing into decision-making environments, information only delivers value when it can move. The challenge is that most organisations are trying to solve this problem using tools that were never designed for it.

This is not a defence-specific issue. It affects policing, healthcare, local government, finance, and any organisation operating across multiple systems, security domains, or partners. The question is not whether information should be shared. It is how information can be shared without increasing risk.

Why access control is not the same as information control

Firewalls are among the most effective and widely used tools in cyber security. They control which systems and users are allowed to connect. When the objective is to protect a network boundary, this model works well.

As organisations became increasingly networked, firewalls were extended to support data sharing. If two systems needed to exchange information, a connection was opened between them. Often, the level of trust applied to that connection increased discretely over time.

The problem is that firewalls were never designed to manage information itself. They control connections, not content. Once a connection is established, they cannot easily distinguish between what should be shared and what should not.

Relying on access controls alone often leads to aggregated risk. Connections are granted temporarily and never removed. Permissions are broadened to avoid operational delays. Manual workarounds emerge to compensate for technical limitations.

Over time, this creates vulnerability, and assurance becomes harder to demonstrate. The organisation may still appear secure, but its ability to control information flow has been eroded.

This is not a failure of firewalls. It is a mismatch between the tool and the problem.

The office building analogy and why it breaks down

A useful way to understand this is to think of an organisation as an office building. Some rooms are public, some are restricted, and some contain highly sensitive material. Locked doors and access cards are essential. They ensure that only authorised people can enter certain areas. This is the role firewalls play in digital environments.

Problems arise when information needs to move between rooms. Unlocking doors or issuing broader access may be convenient, but it also increases exposure. Once the door is open, everything inside is potentially accessible, whether intended or not.

In practice, many organisations end up opening doors wider than they would like, simply to keep work moving.

A better model:  a motorway traffic control gantry

A more appropriate mental model is not a door, but a traffic control gantry on a motorway. The lanes of traffic on the motorway represent data flows. The motorway gantry controls which lanes (data) can flow and under what conditions. The ubiquitous speed camera enforces compliance. Dynamic measures are applied to ensure traffic flows in a controlled and auditable way.

This model reflects how most organisations actually want information exchange to work: deliberate, limited and enforceable. Not a function of who holds the keys.

This shift in thinking, from access to flow, is where progress begins. It changes the questions organisations ask and, therefore, the solutions they pursue.

Five questions to ask before choosing a solution

Before introducing new technology, it is worth stepping back and considering what the organisation is truly trying to achieve. In most cases, the requirement is not to connect systems more tightly. It is to allow specific information to move safely across a boundary.

Ask these questions first

  • What data genuinely needs to move, and what does not?

  • Does the data need to move in both directions, or only one?

  • What assumptions are being made about trust on either side of the boundary?

  • What happens if something unexpected or unauthorised appears in the transfer?

  • How will compliance and assurance be demonstrated after the fact?

These questions are difficult to answer using access-based controls alone. They require a different framing, one that treats information exchange as a discipline in its own right, rather than a side effect of connectivity.

Sharing information without losing control

Modern organisations cannot avoid information exchange. Digital transformation, collaboration and data-driven decision-making all depend on it. But greater connectivity does not have to mean greater risk.

When information exchange is treated as a discipline in its own right, organisations gain the ability to share data confidently, enforce policy consistently, and demonstrate control even as complexity increases.

The most resilient approaches are those that prioritise control, clarity and proportionality. Information sharing works best when it is deliberate, limited to what is necessary, and supported by mechanisms that reflect the realities of trust across organisational and security boundaries.

Not every information exchange problem is a networking problem. Not every solution should begin with a firewall rule.

Taking the distinction seriously

For many organisations, progress begins by stepping back from individual tools and asking more fundamental questions about how information flows through their environment.

When those flows are well understood, it becomes easier to distinguish between challenges that can be addressed through access controls and those that require a more structured approach to information exchange.

Taking the time to make that distinction does not slow transformation. It enables transformation to happen with confidence. In an increasingly connected world, that confidence is what allows information to be shared without losing control.

Want to explore how your organisation handles information flow?

Understanding the distinction between access control and information control is the first step toward a more confident, auditable approach to data exchange.

Read more posts on

About the author

Nexor is a Secure Information Exchange Specialist that delivers accreditable Cross Domain Services and Solutions into complex and restricted networks globally. Our Consultancy Services are focused on two areas, Advisory services, fixing customer problems of today and Research & Innovation solving customer problems of tomorrow. Our customers benefit from a combination of a highly customisable and flexible secure information exchange product portfolio, with subject matter experts who are leading MOD research projects into the future of cross domain technology and information security. Nexor’s agile development capability complements our services to ensure that the solutions we provide are tailored to enable our customers’ business and security objectives, adeptly balancing risk with budget and functionality.

Nexor on Linkedin

Read more posts by Nexor

Read more posts on