LAGAN CYBER

Product, not consultancy Belfast, Northern Ireland

Control library · v0.3 · figures as at 5 August 2026

Security controls, evidence and audit posture for UK and Ireland regulated SMEs.

We read your Microsoft 365, Entra ID and Google Workspace configuration, map what we find to the control frameworks your auditors and customers ask about, and keep the dated evidence behind every answer.

Control library coverage as at 5 August 2026 — figures are our own control library, not certification
Framework Controls mapped Evidence automated Cloud checks Coverage
ISO 27001:2022 Annex A CTRL 93/93 · EVID 24 · CHK 31 93 / 93 24 31 Mapped
Cyber Essentials / Plus NCSC scheme · five technical controls CTRL 5/5 · EVID 18 · CHK 26 5 / 5 18 26 Mapped
NCSC CAF v4 4 objectives · 14 principles · 39 outcomes CTRL 21/39 · EVID 9 · CHK 14 21 / 39 9 14 Partial
NIS2 Directive (EU) 2022/2555 · Art. 21(2)(a)–(j) CTRL 6/10 · EVID 4 · CHK 7 6 / 10 4 7 Partial
  • Mapped — every control in the published framework carries a library entry
  • Partial — the outcomes counted are mapped, and the count is the whole claim

Mapping counts are our own control library, not certification. Framework names and control identifiers are the property of their respective publishers and are used here descriptively. Read how we count →

§ 02 — Control domains

Five domains. Each one produces evidence, not opinions.

The control library is organised as five domains. Every entry inside a domain names the control it answers and the record that answers it — dated, referenced, and fit to put in front of an auditor, an insurer or an enterprise procurement team.

CD-01Automated

Cloud posture

Read-only configuration and posture scanning across Microsoft 365, Entra ID and Google Workspace. We read settings and metadata — tenant policy, role assignment, sharing configuration, logging state — never the contents of your files or mailboxes. Drift between scans is recorded as a change, not silently overwritten.

Checked

  • MFA and conditional access policy 12
  • Privileged role assignment and standing admin 7
  • External sharing, guest and anonymous links 9
  • Mail forwarding and transport rules 6
  • Storage, key and secret exposure 8
  • Audit logging and retention state 5

CD-02Automated

Evidence

Every check writes an evidence record: what was checked, against which control reference, in which system, at what time, by what method, with what result. Records are append-only and carry a content hash so an auditor can see that the answer has not been edited after the fact.

Nine mandatory fields

  • Control reference and framework mapping
  • Source system, tenant and scope
  • Collection timestamp, UTC
  • Collection method and API scope used
  • Result and remediation state
  • Retention clock and integrity hash

CD-03Mapped

Policies

The policy controls an assessor asks about are mapped to a register model: document, version, owner, approver, approval date, next review date, and who acknowledged which version. Fourteen baseline policy documents are drafted against the Annex A themes, each tied to the controls it is offered as evidence for.

In the mapping

  • Baseline policy set, drafted to Annex A 14
  • Version history and approver record
  • Review due dates and escalation
  • Staff acknowledgement log
  • Control references each document answers

CD-04Mapped

Supplier risk

Supplier assurance is mapped the same way: three questionnaire tiers scaled to what a supplier could do to you, the answers and attachments they return, and the review cadence that keeps them current. The point is that supplier assurance stops living in a spreadsheet and starts producing dated records like everything else.

In the mapping

  • Questionnaire tiers by criticality 3
  • Supplier register and data-flow note
  • Response tracking and chase schedule
  • Certificates and reports the supplier sends
  • Review cadence and expiry dates

CD-05Mapped

People

Security-awareness training and phishing-simulation results are treated as compliance evidence rather than as a separate product. Completion and result records carry the same control references as everything else, so “show me your awareness training” has a dated answer instead of a conversation.

In the mapping

  • Awareness module completion records
  • Phishing simulation results by cohort
  • Starter, mover and leaver checks
  • Role-based assignment rules
  • Attestation and sign-off log

Automated means a scheduled read-only scan writes the evidence record without anyone touching it. Mapped means the library carries the entry — the control identifier, what satisfies it, and which record answers it — and that record is assembled by hand. Both count as evidence; only one of them stays current on its own. Full domain detail →

§ 03 — Evidence

What an evidence record actually contains.

Not a screenshot of a dashboard. A record with a reference, a source, a timestamp, a method and a hash — the fields an assessor needs in order to accept it.

Evidence record — specimen Illustrative

Record ID
LC-EV-004182
Control ref
A.8.9 / CE-SECURE-CONFIG
Source system
Microsoft 365 · Entra ID
Scope
tenant/contoso.onmicrosoft.com
Collected at
2026-08-04T09:14:22Z
Collection method
API read-only · Policy.Read.All
Result
PASS
Retained until
2032-08-04
Hash
sha256:9f2c4a1e…7db0

Illustrative only. The values above are invented for the purpose of showing the record shape; they are not from a real tenant, a real customer or a real scan. The full evidence model →

§ 04 — Scope boundary

What Lagan Cyber is not.

The compliance market is crowded with adjacent things that look similar from a distance. Three boundaries worth stating plainly.

  • Not 01

    Not a managed service provider. We do not sell engineer hours, we do not run your helpdesk, and we do not remediate findings on your behalf. The platform tells you what is wrong and produces the record; fixing it is your team’s or your IT provider’s work. We are a subscription product with a fixed scope, not a retainer.

  • Not 02

    Not an identity or KYC verification service. We do not verify the identity of your customers, check documents, or run sanctions and PEP screening. Lagan Cyber looks inward, at the security controls and evidence of the business that subscribes — not outward at the people that business onboards.

  • Not 03

    Not a certification body, auditor or assessor. We cannot certify anyone, and a green result in our platform is not a pass in anyone’s audit. Certification is issued by accredited bodies against their own process. What we do is get you to the audit with the evidence already assembled.

§ 05 — Start here

Map your controls with us.

An assessment conversation is half an hour on three things: the frameworks your customers, insurer or regulator actually name, the tenants you run, and the evidence you can produce today if somebody asks for it this afternoon.

We bring the control library to that conversation, so it is a discussion about your controls rather than a demonstration of our software. You leave it with a written note of what would be in scope and which of those controls a read-only scan can answer on its own.

What we bring to it

  • ISO 27001:2022 Annex A, all 93 controls mapped
  • Cyber Essentials, all five technical controls
  • NCSC CAF v4, 21 outcomes mapped
  • NIS2 Article 21(2), six of the ten measures
  • 47 configuration assertions across six check families
  • An evidence record model with nine mandatory fields

What to bring to it

  • The framework your customers or regulator name
  • Which tenants you run, and who administers them
  • Your assessor or certification body, if you have one
  • What you keep now: spreadsheets, screenshots, policies
  • Any security questionnaire currently sitting unanswered

Book an assessment conversation — hello@lagancyber.co.uk · we reply within two working days

No forms, no newsletter, no tracking. Email is the only route in, and what you send us is covered by our privacy notice.