Services · Managed Security
Managed security, run on our own ecosystem.
For teams without a dedicated SOC, CyberJungle combines threat
monitoring and attack-surface management with governed
investigation and response. Agree the systems covered, escalation
paths, and response authority—with human approval for high-impact actions.
Continuous Security Operations Cycle
Every product is a stage in one self-reinforcing loop: observe,
discover, plan, decide, execute, and learn.
- Observe — ShadowWatch: Surface who is targeting you.
- Discover — ASMGuard: Map what is exposed.
- Plan — ReActor: Decide what to do.
- Decide — DecisionGuard: Govern before action.
- Execute — ToolHub: Act safely through guardrails.
- Learn — CyberJungle: Feed insight back into the loop.
ShadowWatch — Threat Intelligence
The Huntress · Panther. Who is targeting us? See what others
miss.
- Dark web monitoring
- Threat intelligence and hunting
- Credential exposure and threat actor tracking
- Real-time alerts
Visit shadow-watch.nl
ASMGuard — Attack Surface Management
The Protector · Rhino. What is exposed? Expose the unknown.
- Attack surface discovery and continuous asset inventory
- Vulnerability and exposure management
- Risk-based prioritization, alerts, and reporting
Visit asmguard.com
ReActor — Autonomous Execution
The Pack · Wolves. What should we do? Build. Automate. Evolve.
- Multi-agent teams and investigation
- Action planning, automation, and orchestration
- Agentic workforce and continuous improvement
Visit reactor.decision-guard.com
DecisionGuard — Decision Governance
The Wise One · Elephant. Should we allow it? Govern before
action.
- Intent analysis and risk assessment
- Human approval workflows and policy controls
- Secure execution gating, audit, and evidence
Visit decision-guard.com
ToolHub — Secure MCP and API Connectors
The Trunk · Serpent. How do we act safely? Execute safely through
authorized, encrypted, and audited connections.
- Secure MCP connectors and API integrations
- Identity, network, cloud, data, and OT/IoT access
- Guardrailed execution
Visit decision-guard.com
CyberJungle® — Strategy. Architecture. Impact.
Monitoring and exposure findings flow into triage, evidence,
escalation, and approved response workflows. The Statement of
Work names covered assets, service windows, internal owners,
permitted actions, and handoff points. High-impact action
remains subject to agreed human approval.
- Strategy and advisory
- Security architecture
- MSSP enablement
- vCISO services and customer success
Client engagements
Trusted by teams navigating complexity.
Independent cyber security, automation, and AI advisory delivered
for teams at leading technology and managed-services organizations.
-
ASML — Independent cyber
security and automation advisory supporting teams inside a global
technology leader.
-
OneZero IT — Embedded
advisory and delivery partner for managed IT and security
services.
-
Modelverse — Fact-check
partner for customer-specific cyber-intelligence threat briefings.
Engagements delivered under NDA — references on request.
AI · Decisions & design
Choose viable AI work — then define how it should operate.
Prioritize use cases, select platforms, map data flows, and design
human approval before a prototype or production build.
- AI Readiness & Use Case Discovery — A short list of AI investments your CFO can defend.
- AI Platform & Vendor Selection Sprint — Pick the right AI stack while preserving optionality.
- Custom AI Application Design & Prototyping — A working AI application built to your specification.
- AI Governance & EU AI Act Readiness — AI Act readiness, control evidence, and a publishable policy.
Security · Automation & Advisory
Automate repeatable security work. Clarify the decisions around it.
Work can cover alert enrichment, evidence collection, approval
routing, architecture, and risk decisions. Each engagement defines
permitted actions, owners, rollback or escalation paths,
deliverables, and an end date.
- Clarity in a Day
- Security Strategy & Multi-Year Roadmap
- Vendor & Architecture Decision Sprint
- Zero Trust & Third-Party Access Assessment
- Security Automation for Operations
- Executive Breach Readiness Workshop
- Insider Threat & Public-AI Data Sovereignty
- IoT & OT Threat Analysis
- Guardrails for Automated Change
AI · Business Automation
From bounded workflow to working build — and handover.
Build a prototype, integration, AI-assisted workflow, or focused
application against acceptance criteria. Data sources, tool
access, human approvals, and ownership are defined before delivery.
- POC Sprint — A working prototype against real data and a clean go/no-go decision.
- MVP Build — A launchable product in real users' hands, with IP yours.
- Product Modernization & Re-platforming — A modern, AI-ready stack without throwing away what works.
Selected work
Selected platforms and applications.
Examples of platforms and applications scoped, designed, or delivered by CyberJungle—across security, real estate, travel, and business operations.
- Verloren Energie — Smart and AI-enabled real estate management.
- VE-Vision — 3D drone imaging, rendering, and virtual tours.
- WieWint — Lottery platform with transparent outcomes.
- PartyIn — AI-enabled customized trip advisory.
- DecisionGuard — AI pre-execution risk assessment and security.
- ReActor — Virtual business setup with an industry service bus.
How we work
Five steps. One clean handover.
Every project runs the same disciplined cycle: scope the systems
and data, agree authority and acceptance criteria, deliver,
verify, and hand over.
- Scoping Call — Goals and constraints become a Statement of Work.
- Discovery — Gather inputs and constraints.
- Delivery — Execute against milestones.
- Acceptance — Review deliverables.
- Handover — Documentation and enablement.
Engagement principles
- Each engagement has a defined scope, deliverables, milestones, and end date.
- Work is executed independently with professional autonomy.
- Your team retains internal accountability; delivery responsibilities and any ongoing operations are defined in the Statement of Work.
- Completion includes documentation and knowledge transfer.
- Data sources, access permissions, retention, and permitted model or tool use are agreed before delivery.
- Automated actions stay within defined authority; consequential actions can require named human approval.
- Additional work is contracted as a new, separately scoped Statement of Work.
About
Calm guidance in complex environments.
Mathijs van der Maas — Founder, CyberJungle®
CyberJungle helps organizations navigate modern security and AI
complexity without fear, hype, or unnecessary tooling. I combine
deep network expertise, vendor-side insight, and hands-on AI
application experience to deliver clear outcomes — with
documentation and handover built in.
Based in the Netherlands and working across Europe, CyberJungle
supports organizations with network security architecture, AI
advisory, vendor-neutral decision support, and pragmatic automation.
Vendor-side experience: Palo Alto Networks, CrowdStrike, and VMware.
Connect with Mathijs van der Maas on LinkedIn
The CyberJungle story
See why infrastructure is becoming machine-operated, and how CyberJungle brings security, automation, and control together.
View the original Journey PDF
FAQ
Practical questions, answered.
What are CyberJungle's three services?
Managed security covers agreed monitoring, exposure management, and response workflows. Security automation connects tools and turns repeatable security tasks into governed workflows. AI and business automation delivers bounded applications, integrations, and AI-assisted processes with documentation and handover.
Can managed security replace our SOC?
It can cover agreed monitoring, threat intelligence, attack-surface management, escalation, and response workflows for teams without a dedicated SOC. It is not presented as a staffed 24/7 SOC by default; hours, systems, escalation paths, response authority, and service levels are defined in the Statement of Work.
What security work can you automate?
Examples include alert enrichment, exposure triage, evidence collection, approval routing, ticket creation, and bounded remediation. Each workflow defines its inputs, permitted actions, owner, audit evidence, failure path, and rollback or escalation route before it is enabled.
What AI and business automation do you build?
CyberJungle builds focused prototypes, applications, integrations, and workflow automation around an agreed business process. Typical deliverables include process mapping, architecture and data flows, a working build against acceptance criteria, source code, documentation, and an enablement handover.
Does automation act without human approval?
Only within authority agreed for that workflow. High-impact actions can require named human approval before execution; lower-risk steps can be automated within defined permissions. The Statement of Work records decision owners, access boundaries, evidence requirements, and stop or rollback conditions.
How do you handle our data and systems?
Data sources, residency needs, retention, credentials, environments, subprocessors, and permitted model or tool access are agreed before delivery. Access is limited to the scoped work. NDA and DPA terms are available where applicable. Any use of customer data for model training would require explicit agreement; it is not assumed.
What do we receive at the end?
The Statement of Work defines deliverables and acceptance criteria. Depending on the engagement, handover can include findings, architecture and workflow diagrams, decision records, configured automations or source code, runbooks, evidence, and an enablement session for internal owners.
Can you help with NIS2, DORA, GDPR, or EU AI Act readiness?
Yes. CyberJungle can map relevant requirements to controls, evidence, accountable owners, and a prioritized roadmap. This supports readiness and decision-making; it is not legal advice, certification, or a guarantee of compliance.
How are engagements scoped and priced?
Project work is fixed-scope and time-boxed under a Statement of Work with a fixed fee, milestones, deliverables, acceptance criteria, responsibilities, and an end date. Managed-service coverage and any service levels are priced against the agreed environment and operating scope.