What remained on the table after our data-centric zero trust presentation.
At NATO TIDE Sprint hosted by NATO's Allied Command Transformation (ACT), where the alliance's interoperability agenda takes shape we delivered our session titled "Data-Centric Zero Trust Architecture Across Distributed Environments" to allied military command leadership. After the session, the discussion locked onto a single truth: interoperability is not how fast a system talks while connected to the allied network; it is how much of it remains standing when the connection is severed. This distinction is not a slogan; it is an architectural posture that directly invalidates the comfortable assumptions of today's defence industry.
Allied transformation documents FMN, DaSA, DTIS successfully describe the federation's ideal world: uninterrupted, high-bandwidth, always connected. But the real friction in the field does not begin in the laboratory. It begins at the tactical edge, where connectivity, bandwidth and trust all become contested at the same time.
The approaches accepted as standard in defence procurement today entrust authorization and the trust core to a central backbone. Yet in a spectrum dense with electronic warfare, the moment a tactical element is severed from the network, the central identity server becomes unreachable. The reflex most architectures adopt "we'll synchronise when connectivity returns" means operational blindness on the tactical field. That blindness is not merely a loss of data; it is the collapse of the entire decision chain.
At this point, the question the defence ecosystem must answer is not how fast a system transfers data while connected. The real question is how much of your capability remains standing when the network is gone. A procurement approach that does not ask this question purchases an architecture that has never been tested in the worst-case scenario. But reading interoperability solely through the lens of connectivity loss misses the real promise of zero trust. Because zero trust is not a fallback mechanism that kicks in when the network drops; it is the principle of granting no default trust to any user, device, or connection even when the network is fully available.
Traditional security architectures treat everything inside the network as "trusted" and build their defences at the perimeter. Once a user enters the internal network, they are no longer questioned; once a device is certified, it is no longer monitored; once a connection is established, it is no longer verified. Yet in today's threat environment, a significant portion of breaches feeds on precisely this assumption. When an attacker slips inside, they are treated as trusted and move freely through the network. Zero trust eliminates this assumption: trust is not based on location or network; it is based on continuous verification. Every access request, every transaction, every data flow is re-evaluated, regardless of its origin.
What this means for interoperability is the following: in a multi-national environment, connecting to an ally's system does not mean trusting that system. Each ally enforces its own security policy; each data exchange is verified within its own context; each access is granted within its own boundaries of authority. Federation is built not on mutual trust but on mutual verification. This does not weaken cooperation; on the contrary, it ensures that trust rests on architecture, not on individuals or institutions.
The same principle applies to the supply chain. Every component within a system, every software module, every piece of hardware carries a risk, regardless of its origin. Zero trust manages this risk rather than accepting it: each component operates within its own domain of authority, none can gain unlimited access to another and none can exert control over the system as a whole. This approach confines the impact of a supply chain attack to a single component; it prevents it from spreading to the rest of the system.
Defining interoperability as a posture, therefore, requires not only remaining standing when the connection is severed but also questioning every access while connected, evaluating every piece of data within its context and assuming no trust by default. This is not a capability that can be added to a feature list; it is a principle intrinsic to a system's design. And an architecture that does not embrace this principle is fragile, whether connected or not.
At Lotus Sirius, we have placed this principle at the centre of the systems we design for our defence and critical infrastructure customers. We want to carry this framework further with institutions that treat interoperability not as a feature but as a posture.
