Expert Insight

Interoperability Without Compromise: Secure Communication Across Research Partners

8 July 2026

Space research is rarely carried out by one organisation working alone.

It depends on cooperation between research institutions, technology providers, infrastructure operators, cybersecurity specialists, communication experts, public-sector bodies and industrial partners. Each partner brings different capabilities. Each may also bring different systems, standards, processes and security assumptions.

That is where interoperability becomes essential.

Partners need to exchange data. Systems need to communicate. Research outputs need to move securely between environments. Technical teams need controlled access to shared resources. Software, documentation and operational information need to be distributed without weakening trust.

Interoperability makes this possible.

But interoperability can also introduce risk.

When systems are connected without a clear security model, the result is often complexity. Temporary access becomes permanent. Manual workarounds become routine. Data is copied into uncontrolled locations. Certificates are reused beyond their original purpose. APIs are opened without sufficient monitoring. Partners rely on assumptions that were never formally agreed.

In high-trust environments, this is not sustainable.

The goal is not simply to make systems work together. The goal is to make them work together securely.

That requires a deliberate approach to communication architecture.

Trust model and identity

The first principle is to define the trust model.

Before connecting systems, partners should understand who is trusted, for what purpose, under which conditions and for how long. Trust should not be implied by participation in a project. It should be specific, documented and technically enforced.

This applies to users, devices, services, software, networks and organisations.

A researcher may need access to a data set, but not to administrative systems. A supplier may need a maintenance window, but not continuous access. A partner system may need to send data, but not read from the wider environment. A service account may need to authenticate to one API, but not move laterally across infrastructure.

Clear trust boundaries reduce unnecessary exposure.

The second principle is consistent identity.

Interoperability often fails securely when identity is fragmented. One partner uses one access model. Another relies on local accounts. A third uses certificates. A fourth manages access through a cloud platform. Over time, it becomes difficult to know who has access to what.

For secure cooperation, identity should be governed across the collaboration environment.

This does not mean every organisation must use the same internal system. It does mean that access between organisations should be based on agreed mechanisms, strong authentication and clear lifecycle management. Users, services and devices should be identifiable. Access should be granted for defined purposes and removed when no longer needed.

Controlled data exchange and standards

The third principle is controlled data exchange.

Data should not move simply because it can. It should move through approved channels, with appropriate encryption, access control, logging and retention rules. Sensitive research data, technical documentation and operational information may require different handling depending on its value and confidentiality lifetime.

This is especially important where data crosses organisational boundaries.

Once data leaves one environment, control becomes harder. Partners should agree how data may be stored, processed, shared, archived and deleted. They should also understand whether metadata, logs or derived outputs create additional exposure.

Secure interoperability depends on treating data movement as part of the security design, not as an afterthought.

The fourth principle is protocol and standards alignment.

Communication between partners should rely on well-understood, maintainable and properly implemented protocols. Custom integrations can be necessary in specialised environments, but they should be documented, tested and governed. Unclear or improvised mechanisms create long-term risk.

Standards alignment also supports future change.

As organisations prepare for the post-quantum transition, communication systems will need to evolve. Certificates, key exchange, digital signatures and encryption mechanisms may all need updates. If partners use incompatible or poorly documented approaches, migration becomes harder.

Interoperability designed today should not block security requirements tomorrow.

Crypto-agility and monitoring

The fifth principle is crypto-agility.

In multi-partner environments, cryptographic change can be difficult. One organisation may be ready to migrate. Another may depend on a supplier roadmap. A third may operate legacy systems that cannot be upgraded quickly. Without planning, the result can be fragmented security and operational disruption.

Crypto-agility helps reduce this risk.

Systems should be designed so that cryptographic algorithms, certificates, keys and protocols can be updated in a controlled way. Partners should understand which mechanisms are being used and how changes will be coordinated. Procurement should favour systems that support future cryptographic migration.

This is not only relevant to post-quantum security. It is a general resilience principle.

The sixth principle is monitoring and accountability.

Interoperable systems need visibility. Organisations should be able to see how shared communication channels are used, detect unusual activity and investigate incidents. Logs should support accountability without exposing unnecessary sensitive information.

This is particularly important when access crosses organisational boundaries.

If a partner account behaves unexpectedly, who investigates? If an API begins transferring unusual volumes of data, who receives the alert? If a certificate is misused, who has the authority to revoke it? If an incident affects shared infrastructure, how are partners notified?

These questions should be addressed before a real incident occurs.

Workarounds and supplier governance

The seventh principle is avoiding security workarounds.

Research environments often need flexibility. Teams move quickly. Data needs to be shared. Deadlines matter. When official channels are too slow or difficult, people create alternatives: personal file transfers, unmanaged messaging, shared credentials, temporary servers, informal scripts or uncontrolled cloud storage.

These workarounds are understandable, but they create risk.

Secure interoperability should be practical enough that authorised collaboration can happen through approved channels. Security that blocks legitimate work often pushes risk into the shadows. Good architecture should make the secure path the usable path.

The eighth principle is supplier and platform governance.

Many research collaborations depend on third-party platforms, managed services, cloud systems, communication tools and specialised technical suppliers. These providers may influence identity, encryption, logging, data storage and software updates.

Partners should understand these dependencies before relying on them for sensitive communication.

Who controls the platform? Where is data stored? How is access managed? Which cryptographic standards are supported? What happens when a vulnerability is discovered? How are logs retained? Can the system support post-quantum migration in the future?

Interoperability is not only a technical integration. It is also a governance decision.

The COSMOS-SECURE perspective

For space research, these issues matter because cooperation is central to progress.

The sector depends on shared expertise, distributed infrastructure and long-term collaboration. But the value of that cooperation depends on trust. Partners must be able to exchange information confidently, knowing that communication channels are secure, access is controlled and systems can evolve over time.

COSMOS-SECURE is focused on secure communication in space research with this challenge in mind.

The project recognises that future-ready communication must support cooperation without weakening security. It must allow different organisations and systems to work together while maintaining clear trust boundaries, strong cryptographic protection and long-term adaptability.

The practical message for organisations is straightforward.

Design interoperability deliberately. Define trust before connecting systems. Use consistent identity and access controls. Protect data as it moves between partners. Align on maintainable protocols. Build in crypto-agility. Monitor shared communication paths. Govern suppliers. Make secure collaboration usable.

Interoperability should not mean lowering security expectations.

It should mean building communication systems that allow partners to cooperate confidently, responsibly and securely.

For space research, that balance is essential. The future will depend on connected systems and connected organisations. The challenge is to ensure that connection strengthens the mission rather than expanding the risk.