LAGAN CYBER

Capability statement

§ 04 — Capability statement · figures as at 5 August 2026

What we can evidence, and who stands behind it.

Compliance software is bought on trust, so the four things a careful buyer checks first are kept on one page: the entity you would be contracting with, what the control library covers, how a first conversation runs, and which address reaches a person.

§ 04.1 — The company

The registered entity behind Lagan Cyber

The company is registered in Northern Ireland and trades under the name Lagan Cyber, after the river that runs through Belfast. The registered name and the trading name are deliberately different; the legal entity is named in full in every footer on this site, in the register below, and in the terms.

Company register
FieldValue
Registered nameWESTPORT CYBER LIMITED
Trading nameLagan Cyber
Registered inNorthern Ireland
Company numberNI741244
Contacthello@lagancyber.co.uk
§ 04.2 — Capability register

What the platform reads, maps and keeps

The control library carries an entry for every one of the 93 controls in ISO/IEC 27001:2022 Annex A and for all five Cyber Essentials technical themes, together with 21 of the 39 outcomes in NCSC CAF v4 and six of the ten measures in Article 21(2) of NIS2. Each entry names the control, what would satisfy it for a cloud-first SME, and the record that answers it.

Forty-seven configuration assertions run against connected tenants in six families — authentication, privilege, sharing and guests, mail flow, data and secrets, logging. Each one writes an evidence record rather than lighting a tile on a dashboard, and fourteen baseline policy documents drafted to the Annex A themes cover the controls no scan can reach.

Those two things together are the product: a mapping precise enough to argue with, and a record trail dated and referenced enough to hand to somebody who is paid to doubt it.

What we read

  • Microsoft 365 and Entra ID, read-only Graph app registration
  • Google Workspace, read-only Admin SDK service account
  • 47 configuration assertions across six check families
  • Settings and metadata only, never file or mailbox contents
  • Drift between scans recorded as a change, not an overwrite
  • No write scope on any connector, by deliberate constraint

What we keep

  • Append-only evidence records, nine mandatory fields each
  • Control references from four frameworks on a single record
  • A content hash over the canonical serialisation at write time
  • Corrections written as superseding records, both left visible
  • A retention date calculated when the record is written
  • Attestations marked as attested rather than as verified
§ 04.3 — How an assessment runs

Four steps, and you can stop after any of them

Nothing here needs a procurement process to start. The first two steps cost you half an hour and leave you with something written down either way.

01

The conversation

Half an hour, by email or by call, on three things: the frameworks your customers, insurer or regulator actually name, the tenants you run and who administers them, and what you could produce this afternoon if somebody asked for evidence.

02

The scope note

We write down what would be in scope: tenants, control set, the frameworks that matter to your buyers, and the controls nobody in your organisation currently owns. That note is yours to keep whether or not anything follows it.

03

The mapping walk-through

We take the control library through your scope control by control: which ones a read-only scan answers on its own, which ones need a document, an owner or a decision from you, and which ones sit outside anybody’s software and should be said out loud rather than bought around.

04

The evidence

Where it fits, a tenant is connected read-only under the terms, with the processor obligations our privacy notice writes down, and the checks produce dated, referenced records from the first scan onward. Consent is revocable from your own admin console without asking us.

§ 04.4 — Contact

One address, with somebody on the other end

Four subject lines, one inbox, read by someone here rather than by a ticketing queue. Send it by email and the copy sitting in your outbox is the same record we hold.

Routes in
PurposeAddressResponse
Assessment conversationhello@lagancyber.co.ukTwo working days
Framework requestshello@lagancyber.co.ukTwo working days
Privacy and data rightshello@lagancyber.co.ukAcknowledged within five working days; substantive response within one month
Security disclosurehello@lagancyber.co.ukAcknowledged within two working days
PostThe registered office filed at Companies House for NI741244Slower; email is better

Responsible disclosure

If you believe you have found a security issue in this website or in our platform, write to hello@lagancyber.co.uk with enough detail to reproduce it. We will acknowledge inside two working days, keep you posted while the fix is written, and name you in the change log if that is what you want.

Book an assessment conversation — hello@lagancyber.co.uk · we reply within two working days

We do not run a mailing list, do not use analytics or advertising cookies, and do not sell or share contact details. See the privacy notice and the cookie policy.

§ 04.5 — Revisions

Changes to the figures on this site

Revisions to the published figures
DateChange
2026-08-05Coverage matrix v0.3 and evidence record schema v0.3 published.

A coverage figure that moves without a dated note beside it is a number nobody can check. When the figures on this site change, the version marker on the matrix changes with them and the change is recorded in this table.