LAGAN CYBER
§ 04 — Status · updated 5 August 2026

Pre-launch. No customers, no certifications, no revenue.

Compliance software is sold on trust, and the fastest way to lose it is to be vague about your own position. So: this page is the register of where the company and the build actually are.

Incorporated 7 June 2026 Northern Ireland · NI741244 Private early access

§ 04.1 — The company

The registered entity behind Lagan Cyber

The company was incorporated in Northern Ireland on 7 June 2026 and trades under the name Lagan Cyber, after the river that runs through Belfast. The registered name and the trading name are deliberately different; the legal entity is named in full in every footer on this site, in the register below, and in the terms.

Company register
FieldValue
Registered nameWESTPORT CYBER LIMITED
Trading nameLagan Cyber
Registered inNorthern Ireland
Company numberNI741244
Incorporated2026-06-07
Registered office125 Jordanstown Road, Newtownabbey, Northern Ireland, BT37 0NT
Contacthello@lagancyber.co.uk
ICO registrationApplication in progress. We will publish the registration number here once it is issued and will not claim it before then.
Certifications heldNone.
§ 04.2 — Build register

What exists, and what does not

There is a working internal build covering CD-01 Cloud posture and CD-02 Evidence, running against test tenants we control. There is a control library mapped in full against ISO 27001:2022 Annex A and Cyber Essentials, and in part against NCSC CAF v4 and NIS2.

There is no public sign-up, no free trial, no pricing, no billing, no mobile application and no support desk. Three of the five control domains have not been written. Two of the six frameworks in our own matrix have no mapping at all.

We will not put dates against unbuilt work on a public page. Software dates given by pre-launch companies are guesses, and publishing a guess as a commitment is exactly the behaviour this product exists to make visible.

Exists today

  • Microsoft 365 and Entra ID posture scanning, read-only
  • Google Workspace posture scanning, partial
  • Evidence record store, append-only, content hashed
  • ISO 27001:2022 Annex A control library, 93 of 93
  • Cyber Essentials control library, 5 of 5
  • NCSC CAF v4 mapping, 21 of 39 outcomes
  • NIS2 Art. 21(2) mapping, 6 of 10
  • Company, bank account and this website

Not yet built

  • Azure subscription and resource checks
  • CD-03 Policies — register and acknowledgement log
  • CD-04 Supplier risk — questionnaires and tracking
  • CD-05 People — training and phishing records
  • DORA and NIST CSF 2.0 mappings
  • Evidence bundle export, PDF and JSON
  • Time-boxed auditor read-only access
  • Self-service sign-up, pricing and billing
  • iOS and Android applications
  • Any external security assessment of our own platform
  • ICO registration number
  • Any certification of any kind
§ 04.3 — Build order

Sequence, not schedule

The order in which we intend to build. No dates, because we do not know them. Order can change if early-access users tell us it is wrong, and that is most of the point of early access.

Next

Finish what is half-done

Complete the Google Workspace connector to parity with Microsoft 365, finish the NCSC CAF objective B mapping, and build evidence bundle export. Nothing new until the existing two domains are genuinely usable by someone other than us.

Then

CD-03 Policies

The policy register unlocks the largest block of unautomated ISO 27001 controls, and it is the thing every SME we have spoken to is worst at. It is also the cheapest of the three unbuilt domains to write.

Then

CD-04 Supplier risk, then CD-05 People

Supplier risk is a prerequisite for any credible NIS2 supply-chain or DORA third-party answer, so it precedes both of those framework mappings. People follows because it is the least urgent for the businesses we have spoken to so far.

Later

Azure, DORA, NIST CSF 2.0, applications

Azure resource checks, the two unwritten framework mappings, and mobile applications. Each depends on work above it and none of it is started.

Our own posture

We intend to be assessed, and have not been

We intend to pursue Cyber Essentials and, later, ISO 27001 certification for the company itself, and to commission an independent security assessment of the platform. None of that has happened. Until it does, this page will say so, and no page on this site will imply otherwise.

§ 04.4 — Contact

One address, answered by a person

There is no contact form on this site. Forms that post nowhere are worse than no form, and we would rather you had an address you can keep a copy of.

Routes in
PurposeAddressResponse
Early accesshello@lagancyber.co.ukTwo working days
Framework requestshello@lagancyber.co.ukTwo working days
Privacy and data rightshello@lagancyber.co.ukAcknowledged within five working days; substantive response within one month
Security disclosurehello@lagancyber.co.ukAcknowledged within two working days
Post125 Jordanstown Road, Newtownabbey, Northern Ireland, BT37 0NTSlower; email is better

Responsible disclosure

If you believe you have found a security issue in this website or in our platform, write to hello@lagancyber.co.uk with enough detail to reproduce it. We will acknowledge within two working days and keep you informed. We do not currently run a paid bug bounty and will not pretend to; we will credit you if you want to be credited.

Early access — hello@lagancyber.co.uk · we reply within two working days

We do not run a mailing list, do not use analytics or advertising cookies, and do not sell or share contact details. See the privacy notice and the cookie policy.

§ 04.5 — Change log

Changes to this page

Status page revisions
DateChange
2026-08-05First publication of this website. Coverage matrix v0.3, evidence schema v0.3.

When the coverage figures on this site change, the version marker on the matrix changes with them and the change is recorded here.