Hack The Box Enterprise
Hack The Box’s mission is to create cyber-ready individuals and organizations through practical, hands-on learning and realistic cyber environments. The HTB methodology emphasizes experiential learning, adversary-realistic scenarios, and repeatable execution environments so that skills gained translate directly into operational incident response and defensive capability.
Features
- Hands-on cyber labs
- Hack The Box Academy
- Dedicated Labs
- Enterprise platform
- Skill assessments
- Role-based learning paths
- Browser-based Pwnbox
- Enterprise SSO support
- Progress analytics and reporting
- CTF and simulation exercises
Benefits
- Accelerated cybersecurity skill development
- Real-world practical experience
- Reduced training risk through safe lab environments
- Role-aligned workforce readiness
- Measurable skills validation
- Scalable team training
- Flexible self-paced learning
- Improved incident response capability
- Centralised training oversight
- Higher learner engagement and retention
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 8 8 4 5 6 5 8 8 6 1 5 0 6
Contact
HACK THE BOX LTD
Nikos Fountas
Telephone: +30 6970302089
Email: operations@hackthebox.eu
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
- N/A
- System requirements
-
- Average modern laptop
- 8–16 GB RAM
- Stable internet
- Browser + VPN client
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 8 hours of ticket.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Users can access the chatbot via the web interface.
- Web chat accessibility testing
- N/A
- Onsite support
- No
- Support levels
- Enterprise customers have access to a technical support team and a dedicated Customer Success Manager. This is included in the Enterprise licensing model.
- Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Once the purchase paperwork is completed, you will receive an email from our Solutions Engineering team providing the delivery of your environment. An administrator invite email will be sent to the designated contact.
Onboarding:
1. Kick-Off Meeting
After the Delivery email is sent, you will receive an email from your Customer Success
Manager to schedule our initial kickoff meeting. This meeting is approximately 45 minutes long and will cover the following:
-Review Success Criteria & Training Objectives
-Platform Overview in your environment
-Assistance inviting users
-Space creation for Existing Paths
-Schedule Follow-on Onboarding Meetings - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can sync user progress via the Enterprise account with their individual Community user profile (if it exists). They can also export any reporting at any time.
- End-of-contract process
- There is no additional costs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Through the Help Centre at:
help.hackthebox.com
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Enterprise customers can access the Help Centre at:
help.hackthebox.com/en - Accessibility standards
- None or don’t know
- Description of accessibility
- Service is accessible via online interface. A unique username and password is required.
- Accessibility testing
-
All accessibility standards are documented in our Trust Centre:
trust.hackthebox.com - API
- Yes
- What users can and can't do using the API
- There is a private API key that can be made available to Enterprise Customers upon request.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
There are different tiers of of licenses/ Workforce Development Plans. Additionally, each enterprise environment can be customised to bespoke training objectives.
Administrative users can customise job role training environments, cyber ranges, and skill pathways.
Scaling
- Independence of resources
- Every organisation has their own dedicated VPN servers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
-In-app reporting
-Customer success reports (Tableau) - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is encrypted using cloud-provider managed encryption with tenant isolation controls.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can export training data via Excel spreading within the platform.
Customer Success Managers can also run custom Tableau reports for bespoke Enterprise reporting. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Hack The Box environments are hosted in segmented, isolated cloud lab networks that are fully separated from customer production networks. Customer users do not establish inbound connectivity into their own environments from HTB infrastructure.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Hack The Box delivers its platform as a cloud-hosted SaaS service designed for high availability and resiliency. The platform is hosted on enterprise-grade third-party cloud infrastructure with redundancy, monitoring, and fault-tolerant architecture to support continuous service delivery.
For Enterprise customers, availability commitments and response targets are defined contractually within the Enterprise agreement and associated Service Level Agreement (SLA). - Approach to resilience
-
Hack The Box is designed as a cloud-hosted SaaS platform built on enterprise third-party datacentre infrastructure with layered resiliency controls. Core platform services and lab environments are deployed using segmented, virtualised architectures that limit blast radius and prevent single points of failure. Infrastructure uses redundancy at the compute, storage, and network layers, with continuous monitoring, alerting, and automated recovery mechanisms.
Training labs and target environments are isolated and dynamically provisioned, allowing individual lab failures to be reset or re-instantiated without impacting the wider platform. Platform components are updated using controlled release and rollback procedures to reduce service disruption risk. Backups and configuration snapshots are maintained for critical systems to support recovery.
Datacentre resilience is provided by the underlying cloud provider and includes physical security, power redundancy, environmental controls, and multi-zone availability design. Capacity scaling and load distribution are used to maintain performance during peak demand.
Additional architectural and datacentre resilience details are available to customers on request under appropriate confidentiality terms. - Outage reporting
-
Email alerts: Yes — Incident notifications and maintenance notices are sent to affected Enterprise customers and designated account contacts via email.
Support portal / ticketing updates: Yes — Active incidents and service disruptions are communicated through the HTB support ticketing system and customer success channels.
Customer success / account management notifications: Yes — Enterprise customers receive direct communication from their account or customer success representative for significant incidents.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Hack The Box authenticates users through secure account credentials combined with optional multi-factor authentication (MFA). Standard access uses username and password over encrypted TLS connections. MFA can be enabled to require a second verification factor during login.
For Enterprise customers, identity federation is supported through Single Sign-On (SSO) with approved identity providers (such as Azure Active Directory), allowing organizations to enforce their own authentication and password policies. Access is further controlled through role-based permissions and organization-scoped accounts. Session controls and verification checks help prevent unauthorized access and account misuse. - Access restrictions in management interfaces and support channels
- Management interfaces and support channels are restricted using authenticated access, role-based permissions, and least-privilege controls. Administrative functions are available only to authorized accounts and protected by username/password with optional multi-factor authentication and enterprise SSO. Access rights are scoped by role and organization, and privileged actions are logged and monitored. Production changes are performed through controlled admin interfaces rather than direct system access. Support portals and ticketing channels require verified user accounts, and sensitive requests undergo identity verification. Internal support access is permission-limited, approved as needed, and activity is auditable.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Their cloud providers may hold certifications — but HTB itself does not publicly claim a governance certification. For procurement accuracy, this should be marked No unless you have written vendor confirmation.
- Information security policies and processes
- Hack The Box (HTB) follows a formal information security governance program built around industry-standard security practices covering secure development, access control, vulnerability management, incident response, and data protection. Policies and processes are documented internally and reviewed on a recurring basis.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Hack The Box uses documented configuration and change management processes across application, infrastructure, and lab environments. Service components are tracked through their lifecycle using version control, managed repositories, and deployment pipelines with defined baselines and rollback capability. Changes follow a controlled workflow including review, testing, approval, and staged release rather than direct production edits. Security impact is evaluated during change review through secure code review, automated testing, and vulnerability scanning. Higher-risk changes require additional approval and validation. Detailed procedures are available on request under confidentiality.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Hack The Box operates a continuous vulnerability management program across applications and infrastructure. Threats are identified through automated scanning, dependency checks, configuration review, and regular third-party penetration testing, then risk-rated by severity and exposure. Intelligence sources include CVE/NVD feeds, vendor and cloud security advisories, open-source disclosures, and responsible researcher reports. Critical vulnerabilities are prioritized and patched on an expedited basis through emergency change processes, while lower-severity issues are remediated through scheduled releases. Fixes are tested and deployed via controlled pipelines with rollback capability.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Hack The Box uses continuous protective monitoring across platform and infrastructure components through centralized logging, automated alerts, and security event monitoring. Potential compromises are identified via anomaly detection, access and activity logs, vulnerability signals, and security tooling alerts. Suspected incidents are triaged through a documented incident response process including containment, investigation, remediation, and post-incident review. Response urgency is severity-based, with critical security incidents escalated and acted on immediately and lower-severity events handled through prioritized response workflows. Detailed incident procedures are available to customers on request.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Hack The Box maintains a documented incident management program with pre-defined response processes for common security and availability events. Incidents are handled through structured workflows covering detection, triage, containment, remediation, and post-incident review. Users report incidents through the support portal, web chat, or designated support email channels, with Enterprise customers also able to escalate via account representatives. Incidents are severity-rated and prioritized for response. Customers are informed through support communications and direct notifications, and incident summaries or reports are provided to affected customers upon request under appropriate confidentiality controls.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- It will be customized based on the needs of the potential customer.
- Link to free trial
- N/A
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-