LAGAN CYBER

Five control domains Read-only connectors Nine-field records

§ 02 — Control domains · CD-01 … CD-05

Five domains, each one accountable for a specific class of evidence.

A compliance product stands or falls on the boundary it draws around itself. These are ours: what each domain reads, what it produces, and which controls it answers when an assessor asks.

Domain index

The register

Control domains — coverage as at 5 August 2026
Code Domain Produces Coverage
CD-01Cloud postureConfiguration assertions and drift recordsAutomated
CD-02EvidenceAppend-only evidence records with integrity hashesAutomated
CD-03PoliciesVersioned policy register and acknowledgement logMapped
CD-04Supplier riskQuestionnaire responses and supplier review recordsMapped
CD-05PeopleTraining completion and phishing simulation recordsMapped

Automated — a scheduled read-only scan writes the evidence record with no human step. Mapped — the library carries the control entry and names the record that answers it, and that record is assembled by hand. Every domain on this page is written against published control references, which is what makes the answers auditable.

CD-01 · Cloud posture · Automated

Cloud posture

Scheduled, read-only inspection of how your cloud tenants are configured, compared against a baseline and against the last time we looked. Configuration drift is the thing that quietly invalidates last year’s audit.

Reads

Settings and metadata only

A posture scan requests configuration objects: conditional access policies, role assignments, sharing settings, transport rules, audit-log configuration, key vault and storage account properties. It reads the shape of your tenant, not its contents.

It does not read the body of emails, the contents of documents in SharePoint, OneDrive or Google Drive, chat messages, or any customer data your business holds. Where an API returns a document identifier or a mailbox name as part of a configuration object, that identifier is stored; the document is not fetched.

Connects to

Two connectors, both read-only

Connectors and the consent each one asks for
PlatformMethodChecksCoverage
Microsoft 365 & Entra IDGraph API, read-only app registration31Automated
Google WorkspaceAdmin SDK, read-only service account16Partial

A system nobody has connected produces no evidence, and its absence is a gap in your coverage rather than a pass. The platform reports unconnected scope as unknown. The exact scopes we ask for →

Checks

Forty-seven assertions across six families

Check families — CD-01
FamilyChecksExample assertionMaps to
Authentication12MFA enforced for all accounts holding a privileged role, with no policy exclusionsA.5.15 · A.8.5 · CE-UAC
Privilege7Global administrator count within a defined bound and no standing assignmentA.5.15 · A.5.18 · CE-UAC
Sharing & guests9Anonymous link sharing disabled or time-limited at tenant levelA.5.14 · A.8.12
Mail flow6No automatic external forwarding rule at mailbox or transport levelA.8.12 · CAF B3
Data & secrets8No storage container with public read access; key expiry setA.8.24 · NIS2 21(2)(h)
Logging5Unified audit log enabled with a retention period at or above policyA.8.15 · CAF C1

Example assertions are shortened for readability. Check counts are as at 5 August 2026 and are restated on this page whenever they change.

Does not do

No write access, ever

The connectors request read-only scopes. The platform cannot change a setting in your tenant, cannot disable an account, cannot quarantine a message and cannot remediate a finding. If a check fails, you get the finding, the control reference and the evidence record; the change is made by you or by whoever runs your IT.

This is a deliberate constraint, not a gap. A compliance tool with tenant write access is a very attractive target, and we would rather not be one.

CD-02 · Evidence · Automated

Evidence

The domain that makes the others worth anything. Every check, questionnaire response, policy acknowledgement and training completion resolves to an evidence record in a single append-only store.

Record model

Nine mandatory fields

A record that cannot answer “when”, “from where” and “by what method” is not evidence, it is a screenshot. Every record carries a control reference, a source system, a scope, a UTC collection timestamp, the collection method and API scope used, a result, a retention date and a content hash.

The full record model and a specimen record →

Append-only

Corrections are new records

Records are never edited in place. If a scan was wrong, or a scope changed, a superseding record is written that references the original, and both remain visible with their timestamps. An assessor can see the history rather than a tidied version of it.

Integrity

Content hashing

Each record is hashed at write time over its canonical serialisation. The hash is displayed alongside the record and included in exports, so a record extracted today can be checked against the record in the store later. This is a tamper-evidence measure, not a tamper-proof one, and we describe it that way.

Retention

Every record carries its own expiry

The retention date is calculated at write time and stored in the record rather than applied later by a housekeeping job. Evidence has a shelf life — an assessor decides whether a reading from fourteen months ago still says anything about today — so the date that governs disposal travels with the record it governs.

One check can satisfy several controls in several frameworks at once. The control reference field is a list for that reason: an MFA reading answers Annex A, the Cyber Essentials user access control theme and NIS2 21(2)(j) from a single collection.

CD-03 · Policies · Mapped

Policies

The documentary controls — the ones no scan can answer, and the ones assessors open the file with. Mapped control by control, and documented here at the same level of detail as the domains that run automatically.

Register

A register, not a document generator

Assessors ask for policy documents, and then ask who approved them, when they were last reviewed, and who has read them. The three follow-up questions are where SMEs fail, because the document lives in a shared drive with no owner and a review date that passed in 2023.

CD-03 defines the register that answers all four: document, version, owner, approver, approval date, next review date, and an acknowledgement log per version. Each policy carries the control references it is offered as evidence for, so a gap in the register reads as a gap in the matrix rather than as a silence.

Baseline set

Fourteen drafted policies

A starting set drafted against Annex A themes, intended to be edited rather than adopted verbatim: information security policy, acceptable use, access control, cryptography, supplier security, secure development, change management, asset management, remote and mobile working, incident response, business continuity, data protection, logging and monitoring, and physical security.

These are templates. Adopting a template you have not read is a compliance risk in itself, and we say so at the point somebody adopts one.

Scope note

Templates are not advice

We are not a law firm and the drafted policy set is not legal advice. It is a structured starting point for a business that is writing its policy set for the first time.

CD-04 · Supplier risk · Mapped

Supplier risk

The domain that turns your own supply chain from a spreadsheet into dated records — and the ground any credible NIS2 supply-chain or DORA third-party answer has to stand on.

Model

Questionnaires that produce records

Issue a security questionnaire to a supplier, tiered by how much damage that supplier could do to you. Track what came back, what did not, and when it is due to be asked again. Attach the certificates and reports they send. Hold the whole thing against the same control references as everything else.

Tiering

Three questionnaire templates

Questionnaire tiers and the review cadence attached to each
TierApplies toQuestionsReview cadence
T1Suppliers processing personal data or holding privileged access~60Annual
T2Suppliers material to service delivery, no personal data~25Every 2 years
T3Low-criticality suppliers~10On change

Question counts are indicative and are edited to the supplier in front of you. Tiering by what a supplier could do to you, rather than by how much you spend with them, is the part that makes the answer defensible.

Boundary

We do not score or rate suppliers

There is no risk score, no letter grade, no external scanning of your suppliers’ infrastructure and no threat-intelligence feed. We collect and hold what your supplier told you, with a date on it. Judging whether the answer is acceptable is your decision to make and to record.

CD-05 · People · Mapped

People

Security awareness treated as an evidence source rather than as a separate subscription with its own login and its own quarterly report nobody opens.

Records

Completion records, not engagement metrics

The compliance question is never “did your staff enjoy the training”. It is “show me, for this named person, that they completed the assigned module on this date, and show me the record”. CD-05 stores that, plus phishing simulation results by cohort, plus the starter, mover and leaver checks that keep access aligned to employment.

Fairness

Phishing simulation, handled carefully

Simulated phishing produces personal data about employee behaviour, and it is easy to build something disciplinary out of it. Results are reported at cohort level by default, individual results exist to trigger further training rather than sanction, and an employer who uses them otherwise is making a decision that gets documented in the record like any other.

Where your business runs simulations through us, you are the controller of that data and we are your processor. See the processor sections of the privacy notice.

Boundary

Not an HR system

No performance data, no absence records, no payroll, no disciplinary workflow. The People domain holds security training and simulation records and the minimum identity fields needed to attach them to a person.

§ 06 — Start here

Map your controls with us.

Bring the domains that matter to your assessor. We will work through which of your controls a read-only scan answers on its own, which ones need a document, an owner or a decision from you, and which sit outside anyone’s software. Half an hour, your control set, no demonstration.

Book an assessment conversation — hello@lagancyber.co.uk · we reply within two working days