Hack The Box

United Kingdom · hackthebox.com · 24 vendors

Hack The Box is a leading online gamified cybersecurity upskilling and talent assessment platform. It provides a cyber readiness platform that helps individuals, businesses, government organizations, and universities to advance their offensive and defensive security skills through real-world scenarios, gamified labs, and live-fire simulations.

Resilience scores

Technology vendors

Insights

Last updated 2026-04-05 · revision 3

24 direct vendors, 286 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Hack The Box's migration readiness is severely limited by a critical lack of information across multiple essential domains. **Challenges:** The most significant challenge is the complete absence of data regarding the company's internal tech stack and key technologies. Without this information, it is impossible to assess the current state of their infrastructure (e.g., legacy vs. cloud-native, monolithic vs. microservices, containerization adoption), which is fundamental to determining the complexity and feasibility of any migration effort. Financial stability data, including revenue concentration and growth history, is also missing, making it impossible to gauge the company's capacity to fund a potentially costly migration. A major impediment is the 'Vendor Lock-in Risk,' which is explicitly unknown. Unquantified vendor lock-in can significantly increase the cost, time, and complexity of migrating services. The statement 'Total Vendors: 0' while using 38 services from diverse countries is confusing; if it suggests a lack of formal vendor relationships, it could lead to unstructured dependencies that are difficult to manage and migrate. **Opportunities/Neutral Factors:** Data residency requirements are 'Not specified,' indicating no explicitly stated constraints that would complicate migration from a data location perspective. The geographic diversity of service providers (9 unique countries for HQ) suggests that vendor relationships are not geographically concentrated, which could potentially simplify some aspects of migration by avoiding concentrated regional dependencies. However, the benefit of this diversity is heavily mitigated by the unknown vendor lock-in risk and the lack of tech stack details.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR carries severe financial penalties (up to 4% of global annual revenue or €20M, whichever is higher) and applies to any organization processing personal data of EU/EEA residents. Given that cybersecurity training platforms typically collect user registration data, payment information, and learning analytics from global users including EU residents, GDPR compliance is critical. The high risk level reflects both the severity of potential fines and the likelihood that a global cybersecurity platform processes EU personal data.

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for cloud-based service providers, especially those handling customer data and providing cybersecurity services. While not legally mandated, SOC2 compliance is often required by enterprise customers and demonstrates security controls maturity. The medium risk reflects that while non-compliance won't result in regulatory fines, it could significantly impact business opportunities and customer trust in the cybersecurity sector.

ISO 27001 (source) — Assessment Required

ISO 27001 is particularly important for cybersecurity companies as it demonstrates information security management system maturity. While not legally required, it's often expected by customers and partners in the cybersecurity industry. The medium risk reflects reputational and business development impacts rather than regulatory penalties, but these can be significant in the cybersecurity sector where trust is paramount.

Financials

Three-year financials

Financial Resilience Score: 6/10

Hack The Box is a privately held cybersecurity training and upskilling platform founded in 2017, headquartered in the UK (London/Nicosia, Cyprus). The company has demonstrated strong growth momentum in the cybersecurity education market, having raised significant venture capital funding including a $55 million Series B round in 2022 led by Carlyle, bringing total funding to approximately $74 million. This external backing provides a meaningful financial cushion and validates the business model in a high-demand sector. The company operates in the rapidly expanding cybersecurity workforce development space, which benefits from structural tailwinds including a global shortage of cybersecurity professionals estimated in the millions. Its platform serves both individual learners (via gamified CTF-style challenges) and enterprise clients, providing some revenue diversification between B2C and B2B segments. The enterprise/business segment (HTB Enterprise) is likely the primary revenue driver and offers more predictable subscription-based recurring revenue. As a private, venture-backed company, Hack The Box does not publicly disclose detailed financial statements, making it impossible to assess precise metrics such as EBIT margins, equity position, or exact revenue figures. The company is likely in a growth-investment phase, potentially operating at a loss as it scales headcount, infrastructure, and go-to-market efforts, which is typical for VC-backed SaaS/platform businesses at this stage. Key resilience risks include dependence on continued venture funding if the path to profitability is extended, competitive pressure from well-capitalized peers such as SANS Institute, Offensive Security (OffSec), TryHackMe, and Cybrary, and potential churn in the individual/prosumer segment. The lack of public financial disclosure limits external assessment confidence.

Key strengths: Approximately $74M total venture funding raised, including $55M Series B (2022) led by Carlyle, Strong brand recognition in the cybersecurity community with over 2 million registered users globally, Dual revenue model: B2C individual subscriptions and B2B enterprise platform (HTB Enterprise), Operates in high-growth cybersecurity workforce development market with structural talent shortage tailwinds, Subscription/SaaS-based recurring revenue model supports revenue predictability, Gamified, hands-on learning platform differentiates from traditional e-learning competitors

Risk factors: Private company with no public financial disclosures; financial health cannot be independently verified, Likely operating at a net loss in growth-investment phase, dependent on continued VC funding, Intense competition from established players: SANS Institute, OffSec/OSCP, TryHackMe, Cybrary, Immersive Labs, B2C segment subject to high churn and price sensitivity among individual learners, Relatively small scale compared to large enterprise training vendors limits pricing power, Geopolitical and macroeconomic pressures could reduce enterprise IT/security training budgets

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report