LAGAN CYBER
Framework coverage · v0.3 · updated August 2026

Security controls, evidence and audit posture for UK and Ireland regulated SMEs.

We scan your Microsoft 365, Azure and Google Workspace configuration, map what we find to the control frameworks your auditors and customers ask about, and keep the evidence behind every answer.

Product, not consultancy Pre-launch · incorporated 7 June 2026 Belfast, Northern Ireland

Control library coverage as at 5 August 2026 — figures are our own build state, not certification
Framework Controls mapped Evidence automated Cloud checks Status
ISO 27001:2022 ISO/IEC 27001:2022 · Annex A CTRL 93/93 · EVID 24 · CHK 31 93 / 93 24 31 Mapped
Cyber Essentials / Plus NCSC scheme · five technical controls CTRL 5/5 · EVID 18 · CHK 26 5 / 5 18 26 Mapped
NCSC CAF v4 4 objectives · 14 principles · 39 outcomes CTRL 21/39 · EVID 9 · CHK 14 21 / 39 9 14 In development
NIS2 Directive (EU) 2022/2555 · Art. 21(2)(a)–(j) CTRL 6/10 · EVID 4 · CHK 7 6 / 10 4 7 In development
DORA Regulation (EU) 2022/2554 · ICT risk CTRL — · EVID — · CHK — Planned
NIST CSF 2.0 6 functions · 106 subcategories CTRL — · EVID — · CHK — Planned
  • Mapped — control library complete, checks running in our internal build
  • In development — partially mapped, figures show progress
  • Planned — scoped, no mapping written yet

Mapping counts are our own control library, not certification. Lagan Cyber does not hold ISO 27001 or Cyber Essentials certification and does not issue certificates. Framework names and control identifiers are the property of their respective publishers and are used here descriptively. Read how we count →

§ 02 — Control domains

Five domains. Each one produces evidence, not opinions.

The platform is organised as five control domains. Every check inside a domain writes a dated, referenced evidence record you can hand to an auditor, an insurer or an enterprise procurement team.

CD-01Build

Cloud posture

Read-only configuration and posture scanning across Microsoft 365, Entra ID, Azure subscriptions and Google Workspace. We read settings and metadata — tenant policy, role assignment, sharing configuration, logging state — never the contents of your files or mailboxes. Drift between scans is recorded as a change, not silently overwritten.

Checked

  • MFA and conditional access policy 12
  • Privileged role assignment and standing admin 7
  • External sharing, guest and anonymous links 9
  • Mail forwarding and transport rules 6
  • Storage, key and secret exposure 8
  • Audit logging and retention state 5

CD-02Build

Evidence

Every check writes an evidence record: what was checked, against which control reference, in which system, at what time, by what method, with what result. Records are append-only and carry a content hash so an auditor can see that the answer has not been edited after the fact.

Recorded

  • Control reference and framework mapping
  • Source system, tenant and scope
  • Collection timestamp, UTC
  • Collection method and API scope used
  • Result and remediation state
  • Retention clock and integrity hash

CD-03Design

Policies

A register for the security policy documents an assessor will ask to see. Versioned, owner-assigned, with review dates that fall due rather than quietly expire, and a record of who acknowledged which version. Specified in full; not yet written.

Planned scope

  • Baseline policy set, drafted to Annex A 14
  • Version history and approver record
  • Review due dates and escalation
  • Staff acknowledgement log
  • Export as an evidence bundle

CD-04Design

Supplier risk

Issue security questionnaires to your own suppliers, track what came back, and hold their answers and attachments against a review cadence. The point is that supplier assurance stops living in a spreadsheet and starts producing dated records like everything else.

Planned scope

  • Questionnaire templates, tiered by criticality 3
  • Supplier register and data-flow note
  • Response tracking and chase schedule
  • Attached certificates and reports
  • Review cadence and expiry alerts

CD-05Design

People

Security-awareness training and phishing-simulation results treated as compliance evidence rather than as a separate product. Completion and result records attach to the same control references as everything else, so “show me your awareness training” has a dated answer.

Planned scope

  • Awareness module completion records
  • Phishing simulation results by cohort
  • Starter, mover and leaver checks
  • Role-based assignment rules
  • Attestation and sign-off log

Build means code exists and runs in our internal environment. Design means the domain is specified and mapped but not yet written. Nothing on this page is available to customers today. Full domain detail →

§ 03 — Evidence

What an evidence record actually contains.

Not a screenshot of a dashboard. A record with a reference, a source, a timestamp, a method and a hash — the fields an assessor needs in order to accept it.

Evidence record — specimen Illustrative

Record ID
LC-EV-004182
Control ref
A.8.9 / CE-SECURE-CONFIG
Source system
Microsoft 365 · Entra ID
Scope
tenant/contoso.onmicrosoft.com
Collected at
2026-08-04T09:14:22Z
Collection method
API read-only · Policy.Read.All
Result
PASS
Retained until
2032-08-04
Hash
sha256:9f2c4a1e…7db0

Illustrative only. The values above are invented for the purpose of showing the record shape; they are not from a real tenant, a real customer or a real scan. Lagan Cyber has no customers. The full evidence model →

§ 04 — Scope boundary

What Lagan Cyber is not.

The compliance market is crowded with adjacent things that look similar from a distance. Three boundaries worth stating plainly.

  • Not 01

    Not a managed service provider. We do not sell engineer hours, we do not run your helpdesk, and we do not remediate findings on your behalf. The platform tells you what is wrong and produces the record; fixing it is your team’s or your IT provider’s work. We are a subscription product with a fixed scope, not a retainer.

  • Not 02

    Not an identity or KYC verification service. We do not verify the identity of your customers, check documents, or run sanctions and PEP screening. Lagan Cyber looks inward, at the security controls and evidence of the business that subscribes — not outward at the people that business onboards.

  • Not 03

    Not a certification body, auditor or assessor. We hold no accreditation, we cannot certify anyone, and a green result in our platform is not a pass in anyone’s audit. Certification is issued by accredited bodies against their own process. What we do is get you to the audit with the evidence already assembled.

§ 05 — Where we are

Pre-launch, and specific about it.

The company behind Lagan Cyber was incorporated in Northern Ireland on 7 June 2026. It is pre-launch: there is no public sign-up, no free trial, no pricing page and no customers.

What exists is a working internal build of the cloud-posture and evidence domains, and a control library mapped against ISO 27001:2022 and Cyber Essentials in full and against NCSC CAF and NIS2 in part. The figures in the matrix at the top of this page are that build state, updated by hand.

We hold no certifications and claim none. We are not ISO 27001 certified, not Cyber Essentials certified and not SOC 2 attested, and we will not imply otherwise in order to sell a compliance product. When that changes we will say so here with the certificate number and the body that issued it.

Private early access is opening to a small number of UK and Ireland businesses who are prepared to work with unfinished software. If that is you, write to us — we reply within two working days.

Exists today

  • Read-only posture scanning, Microsoft 365 and Entra ID
  • Google Workspace posture scanning, partial
  • Evidence record store with content hashing
  • ISO 27001:2022 Annex A control library, complete
  • Cyber Essentials control library, complete
  • NCSC CAF and NIS2 mapping, partial
  • This website and a company bank account

Not yet built

  • Azure subscription and resource checks
  • Policy document register (CD-03)
  • Supplier questionnaires (CD-04)
  • Awareness training and phishing records (CD-05)
  • DORA and NIST CSF 2.0 mappings
  • Auditor read-only access and evidence export
  • Self-service sign-up, billing and pricing
  • Mobile applications for iOS and Android
  • Any third-party security assessment of our own platform

Early access — hello@lagancyber.co.uk · we reply within two working days

No forms, no newsletter, no tracking. Email is the only route in, and what you send us is covered by our privacy notice.