Skip to main content

Help us improve the Digital Marketplace - send your feedback

HACK THE BOX LTD

Hack The Box Enterprise

Hack The Box’s mission is to create cyber-ready individuals and organizations through practical, hands-on learning and realistic cyber environments. The HTB methodology emphasizes experiential learning, adversary-realistic scenarios, and repeatable execution environments so that skills gained translate directly into operational incident response and defensive capability.

Features

  • Hands-on cyber labs
  • Hack The Box Academy
  • Dedicated Labs
  • Enterprise platform
  • Skill assessments
  • Role-based learning paths
  • Browser-based Pwnbox
  • Enterprise SSO support
  • Progress analytics and reporting
  • CTF and simulation exercises

Benefits

  • Accelerated cybersecurity skill development
  • Real-world practical experience
  • Reduced training risk through safe lab environments
  • Role-aligned workforce readiness
  • Measurable skills validation
  • Scalable team training
  • Flexible self-paced learning
  • Improved incident response capability
  • Centralised training oversight
  • Higher learner engagement and retention

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@hackthebox.eu. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 8 8 4 5 6 5 8 8 6 1 5 0 6

Contact

HACK THE BOX LTD Nikos Fountas
Telephone: +30 6970302089
Email: operations@hackthebox.eu

About your service

Service categories

Applications

Collaborative

  • Enterprise community
  • Team collaboration
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
N/A
System requirements
  • Average modern laptop
  • 8–16 GB RAM
  • Stable internet
  • Browser + VPN client

User support

Email or online ticketing support
Yes
Support response times
Within 8 hours of ticket.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Users can access the chatbot via the web interface.
Web chat accessibility testing
N/A
Onsite support
No
Support levels
Enterprise customers have access to a technical support team and a dedicated Customer Success Manager. This is included in the Enterprise licensing model.
Support available to third parties
No
AI chatbot
Yes

Onboarding and offboarding

Getting started
Once the purchase paperwork is completed, you will receive an email from our Solutions Engineering team providing the delivery of your environment. An administrator invite email will be sent to the designated contact.

Onboarding:

1. Kick-Off Meeting
After the Delivery email is sent, you will receive an email from your Customer Success
Manager to schedule our initial kickoff meeting. This meeting is approximately 45 minutes long and will cover the following:

-Review Success Criteria & Training Objectives
-Platform Overview in your environment
-Assistance inviting users
-Space creation for Existing Paths
-Schedule Follow-on Onboarding Meetings
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can sync user progress via the Enterprise account with their individual Community user profile (if it exists). They can also export any reporting at any time.
End-of-contract process
There is no additional costs.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Through the Help Centre at:
help.hackthebox.com

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Enterprise customers can access the Help Centre at:
help.hackthebox.com/en
Accessibility standards
None or don’t know
Description of accessibility
Service is accessible via online interface. A unique username and password is required.
Accessibility testing
All accessibility standards are documented in our Trust Centre:
trust.hackthebox.com
API
Yes
What users can and can't do using the API
There is a private API key that can be made available to Enterprise Customers upon request.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
There are different tiers of of licenses/ Workforce Development Plans. Additionally, each enterprise environment can be customised to bespoke training objectives.

Administrative users can customise job role training environments, cyber ranges, and skill pathways.

Scaling

Independence of resources
Every organisation has their own dedicated VPN servers.

Analytics

Service usage metrics
Yes
Metrics types
-In-app reporting
-Customer success reports (Tableau)
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is encrypted using cloud-provider managed encryption with tenant isolation controls.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export training data via Excel spreading within the platform.

Customer Success Managers can also run custom Tableau reports for bespoke Enterprise reporting.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Hack The Box environments are hosted in segmented, isolated cloud lab networks that are fully separated from customer production networks. Customer users do not establish inbound connectivity into their own environments from HTB infrastructure.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Hack The Box delivers its platform as a cloud-hosted SaaS service designed for high availability and resiliency. The platform is hosted on enterprise-grade third-party cloud infrastructure with redundancy, monitoring, and fault-tolerant architecture to support continuous service delivery.

For Enterprise customers, availability commitments and response targets are defined contractually within the Enterprise agreement and associated Service Level Agreement (SLA).
Approach to resilience
Hack The Box is designed as a cloud-hosted SaaS platform built on enterprise third-party datacentre infrastructure with layered resiliency controls. Core platform services and lab environments are deployed using segmented, virtualised architectures that limit blast radius and prevent single points of failure. Infrastructure uses redundancy at the compute, storage, and network layers, with continuous monitoring, alerting, and automated recovery mechanisms.

Training labs and target environments are isolated and dynamically provisioned, allowing individual lab failures to be reset or re-instantiated without impacting the wider platform. Platform components are updated using controlled release and rollback procedures to reduce service disruption risk. Backups and configuration snapshots are maintained for critical systems to support recovery.

Datacentre resilience is provided by the underlying cloud provider and includes physical security, power redundancy, environmental controls, and multi-zone availability design. Capacity scaling and load distribution are used to maintain performance during peak demand.

Additional architectural and datacentre resilience details are available to customers on request under appropriate confidentiality terms.
Outage reporting
Email alerts: Yes — Incident notifications and maintenance notices are sent to affected Enterprise customers and designated account contacts via email.

Support portal / ticketing updates: Yes — Active incidents and service disruptions are communicated through the HTB support ticketing system and customer success channels.

Customer success / account management notifications: Yes — Enterprise customers receive direct communication from their account or customer success representative for significant incidents.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Hack The Box authenticates users through secure account credentials combined with optional multi-factor authentication (MFA). Standard access uses username and password over encrypted TLS connections. MFA can be enabled to require a second verification factor during login.

For Enterprise customers, identity federation is supported through Single Sign-On (SSO) with approved identity providers (such as Azure Active Directory), allowing organizations to enforce their own authentication and password policies. Access is further controlled through role-based permissions and organization-scoped accounts. Session controls and verification checks help prevent unauthorized access and account misuse.
Access restrictions in management interfaces and support channels
Management interfaces and support channels are restricted using authenticated access, role-based permissions, and least-privilege controls. Administrative functions are available only to authorized accounts and protected by username/password with optional multi-factor authentication and enterprise SSO. Access rights are scoped by role and organization, and privileged actions are logged and monitored. Production changes are performed through controlled admin interfaces rather than direct system access. Support portals and ticketing channels require verified user accounts, and sensitive requests undergo identity verification. Internal support access is permission-limited, approved as needed, and activity is auditable.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Their cloud providers may hold certifications — but HTB itself does not publicly claim a governance certification. For procurement accuracy, this should be marked No unless you have written vendor confirmation.
Information security policies and processes
Hack The Box (HTB) follows a formal information security governance program built around industry-standard security practices covering secure development, access control, vulnerability management, incident response, and data protection. Policies and processes are documented internally and reviewed on a recurring basis.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Hack The Box uses documented configuration and change management processes across application, infrastructure, and lab environments. Service components are tracked through their lifecycle using version control, managed repositories, and deployment pipelines with defined baselines and rollback capability. Changes follow a controlled workflow including review, testing, approval, and staged release rather than direct production edits. Security impact is evaluated during change review through secure code review, automated testing, and vulnerability scanning. Higher-risk changes require additional approval and validation. Detailed procedures are available on request under confidentiality.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Hack The Box operates a continuous vulnerability management program across applications and infrastructure. Threats are identified through automated scanning, dependency checks, configuration review, and regular third-party penetration testing, then risk-rated by severity and exposure. Intelligence sources include CVE/NVD feeds, vendor and cloud security advisories, open-source disclosures, and responsible researcher reports. Critical vulnerabilities are prioritized and patched on an expedited basis through emergency change processes, while lower-severity issues are remediated through scheduled releases. Fixes are tested and deployed via controlled pipelines with rollback capability.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Hack The Box uses continuous protective monitoring across platform and infrastructure components through centralized logging, automated alerts, and security event monitoring. Potential compromises are identified via anomaly detection, access and activity logs, vulnerability signals, and security tooling alerts. Suspected incidents are triaged through a documented incident response process including containment, investigation, remediation, and post-incident review. Response urgency is severity-based, with critical security incidents escalated and acted on immediately and lower-severity events handled through prioritized response workflows. Detailed incident procedures are available to customers on request.
Incident management type
Supplier-defined controls
Incident management approach
Hack The Box maintains a documented incident management program with pre-defined response processes for common security and availability events. Incidents are handled through structured workflows covering detection, triage, containment, remediation, and post-incident review. Users report incidents through the support portal, web chat, or designated support email channels, with Enterprise customers also able to escalate via account representatives. Incidents are severity-rated and prioritized for response. Customers are informed through support communications and direct notifications, and incident summaries or reports are provided to affected customers upon request under appropriate confidentiality controls.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
It will be customized based on the needs of the potential customer.
Link to free trial
N/A

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
12%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@hackthebox.eu. Tell them what format you need. It will help if you say what assistive technology you use.