speaker-1: A G. Activity is driving modern infrastructure. More integration, more data, more value. But every connection also creates risk. Because when systems fail today, they don't just fail in isolation, they cascade. In April 2025, a single failure helped trigger a blackout across Spain and Portugal, affecting 60 million people and costing billions of dollars. So the question is: are we building smarter systems or more fragile ones? Welcome to Nexus Podcasts. I'm Ben Hall. And today I'm joined by Von Gusser, Executive Advisor at GHD. He specializes in operational risk across asset intensive industry sectors. Von thanks for joining us.
speaker-0: Thanks, Ben. It's great to be here. ⁓ been working in this space for many years, even decades, and so it's a very exciting and and ⁓ timely topic.
speaker-1: Well that's good. Well let's let's just set this up nice and easy for everybody out there. When we talk about interoperability, what do we actually mean in simple terms? And where do people see it in everyday systems?
speaker-0: That's a great question, Ben. And and it's one of those kind of the the the detail behind some of the hidden things that we don't really equate with interoperability is the complexity in the systems. But for example, intermodal transportation, you've probably heard about that, where something is placed on a container, it moves by truck, it goes to a rail yard, it's switched to the rail station, then it goes on train, and then it can go on ship. You see a lot of these MERS containers throughout the world. That that's a classic example of interoperability. They can work regardless of the type of shipping that it's on because of a set rule of standards. But really simple ones are like banking. You can cash a check at any bank. You can deposit money at multiple locations. You can withdraw cash from teller machines. Banking industry. The internet is interoperability. The telephone systems are interoperable. It doesn't matter if you have an ATT phone, if you have a Sprint, Verizon, none of those systems matter. You can talk to somebody else with a different system. So that's interoperability. Yes, th those systems work together and and and that's and that's kind of the key of having that connectivity, having that ability to work together regardless of the basis of the platform.
speaker-1: So pretty much it's all around us, it runs our systems, it runs our civilization effectively, is that right?
speaker-0: It it has gotten to that point, yes. I mean it transgresses. It goes beyond just simple I have a pump and I have the ability to run that pump. I have the ability to have my thermostat on. Systems now I can run my thermostat from one state when I want to come home to my air conditioned house without having to the air conditioner on while I'm gone for seven days through the internet.
speaker-1: course you you've gone into this in great detail in ⁓ in a weekly column on on the Nexus platform. ⁓ so let's just ⁓ just want to explore one core idea from that article which is this. It's every connection is a potential point of failure. So what does that actually mean in practice for business leaders?
speaker-0: Yeah, and I just want to be absolutely clear here that when I say every connection is a potential point of failure, it's not a criticism of the technology or some level of integration associated with that. Connection connectivity is exactly how we unlock value. I mean, that's that's what we talk about. If I can actually have visibility into some other systems, that gives me greater value because I can make better decisions, more informed decisions. In the past, failures were usually local. You know, the pump failed, the server went down, a supplier missed a delivery, something along those lines. But today, when systems are connected, failures do not stop at the point of origin. It travels. It travels through that connected ecosystem. So that same connection that creates value in normal operations becomes a pathway for risk when the conditions move outside the expected range that you're looking at associated with that system by itself operating. So for leaders, that's a that's transformational because risk no longer sits neatly inside that asset or a department, but it sits between systems in interfaces, in handoffs. And you have to assume that somehow these systems have to, as they're connected, where is that weakest point? Where is that potential point of failure? That amplifies both the upsides and the downsides. And without shared rules, shared intent, efficiency quietly turns into failure and exposure.
speaker-1: Mm. Let's let's go back to the case study that ⁓ you raised, which I think everybody will know about. It was that ⁓ the Spain and Portugal blackout, which i that's a real world example. I mean, what does that event reveal about how inter c interconnected systems fail today?
speaker-0: Yeah, that's a real good example because, like you said, most people are aware of it. And and again, I want to be absolutely clear. A lot of people pointed towards the fact that that's because the Iberian Peninsula was turning so on to solar and wind and other renewable energies that that was a that was not the point of failure. What happened is the local systems responded as they were intended to do individually. Well, what happened is the connections between those systems. And so you had whether you want to call it power surges or inequality and amperage settings across those systems, they were not aligned so that if one system peaked out, another system would scale back. And so multiple systems were either peaking out or backing off at the same time because there was no scaling done across the systems. And so it became a catastrophic and cascading failure. across those that allowed the systems or caused the systems ultimately to either underride or override each other. And that became so the assets behaved correctly, but the failure appeared from the interactions between the individual systems. And that's how the cascading failure ultimately occurred.
speaker-1: So when you speak with people and explain risks involved in these, do you use that as an example and explain how that happened and why? 'Cause it seems to me to be a pretty clear example of what you're talking about.
speaker-0: Absolutely, because again, the resiliency has to be built in not within the system, but in the connectivity between the system. And if you're not looking for that failure between the systems, then you're intentionally focused on not the potential highest point of failure. So lack of resiliency looking at the connectivity of those systems and how they interact could be a potential point of c cascading failure. Yes.
speaker-1: Mm-hmm. In that Nexus article you wrote, you use the analogy of Lego blocks. Everything fits perfectly until one piece fails. So what are the weak points in that stack that organizations tend to overlook?
speaker-0: Yeah, and and and again, most organizations have gotten very efficient see are very efficient at looking at their internal points of failure and kind of how does this system fail your or fail or what are the points that we're looking at. It's when you don't have defined how do how do the systems work together. Intermodal, for example, had to look at that very heavily and had to come up with what is our single aligned system of how these freight containers work together and came up with a very intentional approach. To what intermodal transportation would look like, so shipping containers could move efficiently between those transportation systems. So when organizations are looking at the same thing, they have to, what are those connection points? What are those integrated pieces that we need to be looking at so that as we have potential issues associated with our systems and the systems that they're interacting with? And so it's all of a sudden it's that risk. translates from a risk that I've identified and worked hard on to control and mitigate. Now all of a sudden I've mitigated that or I've I've propagated that risk to a new system. And not taking that translation into account and looking at the connectivity associated with it is a big misstep that people are making. And so it's not just, it's not a risk, it's how do those risks that I have mitigated translate into now a new system that I'm interacting with.
speaker-1: So how should organisations rethink risk across planning, design, operations and even decommissioning?
speaker-0: Yeah, and that's a great point, Ben, because when you look at it, interoperability is life cycle thinking. So a lot of times people look at taking interoperability kind of as an upfront task and saying, we're gonna build it in up front. But every time you make changes to that system or you connect it to a new system or you expand its usage, you need to go back and look at those same risks, those same Building blocks, that same linkage that you've built into that original assessment of interoperability and look at it again in a more holistic perspective. Because as the life cycle evolves, and we've seen the pace of change now, the pace of change is tremendous. You almost have to do this continuously as an exercise to be able to build in those risk mitigation because it's beyond just the governance that you put behind it. Compliance doesn't necessarily mean that you've mitigated that risk. All it means is that you've controlled something within the boundaries of what you've designed, what you've governed it for. And so assurance doesn't necessarily mean assurance when you expand these systems or when you change these systems and what they're interacting with and what they're operating with. And it really becomes the fact that risk accumulates silently over time if you don't revisit it.
speaker-1: And when you talk about compliance, ⁓ what does going beyond compliance actually look like in practice in real times?
speaker-0: Yeah, that's a great question because if you look at that failure in Spain and Portugal, all those systems independently were compliant within the boundaries that they looked at. So compliance in and of itself does not mean that I have maintained compliance. And even when you build systems on an intermodal basis, the compliance that the same systems are built that same standard then drive consistency? But then if you look at something of scale, have you built in that speed and scale that most people are looking for associated with the advantages of interoperability to account for the risk that's associated with that speed and scale? So compliance drives a certain component of it, but that's a minimum associated with what you need to look at. You need to come up with the governance and the assurance behind it beyond compliance to say, I've mitigated my risk to a certain standard. And does that standard meet what we would consider to be not just good practices, but industry leading practices associated with adoption of interoperability and the various components of how these connected systems of systems have to work together? And then what do those boundary conditions, if you want to put it that way, how do they interact and what do those linkage points look like?
speaker-1: And who inside an organization should own this risk and how should they be thinking about it differently?
speaker-0: Yeah, it and that's the neat part about it. It's not just a technical issue when it boils down to it. It's really become more of in it's not even a management, it's a leadership issue because interoperability spans technology, operations, data, people, systems, ⁓ assets, and it makes an enter it it it makes it an enterprise risk, and therefore it's a leadership issue. There is no default owner that exists over the system behavior. And so when we say leadership, it's even leadership talking. to leadership of these systems that are interacting with the other systems. And they don't necessarily ⁓ they might have accountability, but they might delegate responsibility associated with that. So it doesn't sit within an IT or an engineering department because no single individual is accountable accountable for it. When you look at it, it's how do you develop the controls associated with those risks and then who within that organization has responsibility for maintaining and monitoring those controls to mitigate that risk. And so it's very much on a it's an enterprise level, has a leadership bent to it. And it's ⁓ and again, it's an unknown because the failures appear as a crisis typically at that point.
speaker-1: Yeah, look, we're g that's we're gonna finish with probably the the toughest question so far. We're gonna fast forward ten years. We're gonna be even more connected than we are in our AI enabled systems, autonomous infrastructure, fully integrated supply chains. Do you think we'll look back and see this as a period where we built true resilience into those systems, or are we at the moment where we are knowingly locked in greater systemic risk? And what needs to change to get a better outcome?
speaker-0: Well, and and that's and that's the beauty of it because a lot of people are working with this in inside a lot of artificial intelligence and and a lot of the AI systems right now, a AI in and of itself is somewhat mini mini scale interoperability system because it's pulling information from all different sources and then it's
speaker-1: Whole topic on it on its own, isn't it, within this topic?
speaker-0: And I think the important thing about it is the fact that if you look at it today, what can we do? Well, you wanna build in the resiliency, you wanna build in the connection points, you wanna build in that leadership accountability, you wanna build in the risk environment, you wanna look at the controls environment associated with mitigating those risks. I think it's really one of as we see this technology growing ⁓ at pace, and this pace is the pace of change is incredible right now. And and that's why Accenture coined it industry X.0. They didn't put a number on it because they said the pace of change is so great. And they're right. ⁓ AI has changed a lot of things associated with that. We need to focus right now on the communications and the connections and the and the optimization as we lock systematic risks that become very hard to unwind into those systems. And you don't have to unwind them. That's why AI is so valuable. So you can build the initial system associated with how you define and control that. But as you look at the governance, as you look at the risks, as you look in the controls, as you look in how do you ⁓ actually measure that, that whole compliance piece comes back into focus. And what you need to look at is how do the decisions I make today then allow me to be faster, more agile, and more prepared for tomorrow associated with that system of systems, interoperability and the connections between those system of systems.
speaker-1: It's great way to finish. Von, thank you very much for your time and your insights there. Really appreciate it.
speaker-0: Then it was a pleasure. I really enjoy this topic.
speaker-1: Well, that was Von Gusser. And if there's one takeaway from this conversation, it's this. Interoperability isn't just about making systems work together, it's about understanding how they fail together. If you want to go deeper, you can read Von's full Nexus Weekly column, How to Prevent Your Greatest Asset from Becoming Your Biggest Risk. It's on the homepage. And if you're not already subscribed, head to the Nexus homepage and sign up so you don't miss the next conversation shaping the future of infrastructure, energy, and beyond. Thanks for listening. Brought to you by Nexus, published by GAP Foresight.
speaker-0: Public D actionable