Frequently asked questions

What does "contextual evaluation of industrial control actions" mean?

It means judging an action not only by whether it is permitted, but by whether it fits the operational context of the process at that moment. An action can be authorised, protocol-conformant and within valid ranges and still be inappropriate for the current operational phase. Liscere infers that phase from the observed traffic and judges whether the action is appropriate or inappropriate for it.

How is Liscere different from an intrusion detection system?

An intrusion detection system inspects the traffic; Liscere inspects the process. A signature-based IDS matches packets against patterns of known attacks, and an anomaly-based IDS flags protocol violations or statistical deviations from a network baseline. Both decide over network features, and both are looking for traffic that is malformed, unauthorised or unusual.

Liscere instead reconstructs the operational state of the plant from the observed process variables and evaluates each action against that state. The events it surfaces are well-formed, permitted and statistically ordinary, which is precisely why signature and anomaly sensors have no reason to flag them. It is a semantic layer over the process, not another detection rule over the packets.

Does Liscere sit in the control path?

No. Liscere is a passive external observer. It connects to a switch mirror port, receives a copy of the traffic and injects nothing; it cannot send, block or alter any command, and it is electrically incapable of reaching the control path.

Does Liscere depend on a specific vendor or protocol?

No. Being vendor and protocol agnostic is a design objective, not an afterthought. Liscere evaluates the process rather than any one manufacturer's implementation, so it is not bound to a particular controller, fieldbus or SCADA stack. And because it only observes a copy of the traffic, it deploys alongside existing systems without touching them: nothing is installed on the controllers, nothing is reconfigured, and no new path is opened into the control network.

How is Liscere validated?

Liscere is validated on real industrial hardware, under realistic conditions, and across a growing range of processes and protocols. The work runs on the controllers used in industry, the Siemens S7 family, with real engineering configurations, over protocols including Modbus/TCP and OPC UA, and every result is exercised across many operational variants rather than a single case. Validation is research-led, continuous and expanding, with new processes, process types and protocols brought into the testbed as the framework matures.

What is Liscere working on?

The hardest questions in this field do not have settled answers yet, and those are the ones we choose to work on. How much can be inferred about a physical process from the outside, how little a system needs to see to judge an action soundly, where passive observation truly reaches: this is a young frontier, and we are deliberately working at its edge. Part of that work is published; part of it is not, yet. The direction is set, and the results keep coming.

Where can I read Liscere's research?

In the research section, which indexes Liscere's technical reports (the LTR series) and landscape briefings (the LB series). Each report has its own page with an abstract and a link to the full PDF.

Read more on the About page.

Home · About · Research · LinkedIn · GitHub
© 2026 Liscere sp. z o.o.