Executive Summary

With AI compounding cyber risk, demand for skilled security staff will continue to outweigh supply for the foreseeable future. Certification bodies and higher-education institutions struggle to keep up with the breakneck pace of new AI threats and the adoption of AI technologies, forcing security and risk leaders to look within their own organizations to find and develop cybersecurity talent. Cybersecurity skills and training (CS&T) platforms, such as Hack The Box, enable this shift to a skills-based talent management practice that values up-to-date demonstrable skills over point-in-time-based cybersecurity certifications.1

Hack The Box (HTB) is a global cybersecurity learning platform that provides hands-on labs and simulated environments where users can practice hacking and defensive skills legally and securely. Supported by a community of more than 4 million users and 800+ enterprise customers, HTB empowers teams and intelligent systems alike to strengthen cyber defenses and reduce breach risk effectively. It recently expanded defensive security (blue team) and advanced training capabilities via its acquisition of LetsDefend, uniting talent and knowledge to create one of the largest ecosystems for workforce development and peer learning in cybersecurity.

Hack The Box commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential return on investment (ROI) enterprises may realize after deployment.2 The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of Hack The Box on their organizations.

344%

Return on investment (ROI)

 

$979K

Net present value (NPV)

 

To better understand the benefits, costs, and risks associated with this investment, Forrester interviewed seven decision-makers with experience using Hack The Box. For the purposes of this study, Forrester aggregated the experiences of the interviewees and combined the results into a single composite organization, which is a global, technology services organization with $3 billion in annual revenue. The organization has over 30,000 employees and a strong cybersecurity workforce of 300+ people. The company also provides cybersecurity consulting services.

Interviewees said that prior to using Hack The Box, their organizations typically relied on fragmented and often ineffective training approaches and failed to keep pace with evolving threats. These limitations led to inconsistent and unimpactful training, skills gaps, a lack of visibility into team capabilities and, ultimately, higher security risks.

After adopting Hack The Box, interviewees strengthened their cybersecurity posture by improving cyber workforce readiness, detection quality, and operational efficiency. The investment helped organizations reduce cybersecurity risk, scale cyber skills development, accelerate onboarding, support employee retention, and improve productivity across red team, blue team, and AI security functions.

Key Findings

Quantified benefits. The composite organization has achieved three-year, risk-adjusted present value (PV) quantified benefits for three types of roles:

Overall cyber workforce has:

  • Additional 20% of cybersecurity workforce certified every year. HTB enabled organizations to scale cyber workforce development with lower cost and fewer operational resources. It complemented external courses with reusable hands-on learning and certification paths that could be accessed by broader groups of security practitioners, developers, consultants, and new hires. Over three years, enhanced workforce development saves more than $430K for the composite organization.

  • Reduced cyber workforce attrition rate by 4%. HTB contributed to cyber workforce retention by shaping a more engaging technical culture for high-performing cyber talent. It provided employees continuous access to hands-on, role-relevant training, creating team-building opportunities through Capture The Flags (CTF) and collaborative labs, and supporting a culture where practitioners could keep developing technical skills throughout the year. Over three years, the attrition reduction saves the composite organization $250K.

  • Improved new hire onboarding efficiency by 35%. Customers reported that HTB improved onboarding speed and post-onboarding skill quality by helping employees connect individual tools, techniques, and concepts into realistic workflows. Over three years, the reduced onboarding timeline saves the composite organization $77K in present value.

Blue team has:

  • Improved MTTA by 50% and improved MTTR by 30% for the IR team. Practitioners gained hands-on exposure to attacker techniques, realistic environments, and repeatable practice scenarios. This leads to an improvement in mean time to acknowledge (MTTA) and mean time to resolution (MTTR). Over three years, the Incident Response (IR) team efficiency improvement equals to $164K in present value.

  • Reduced breach exposure through shorter dwell time, reducing escalation probability by 50%. By improving detection quality and enabling analysts to identify malicious activity earlier, HTB reduced attacker dwell time, a key driver of breach cost and incident severity. Over three years, the risk avoidance is valued at $125K.

Red team has:

  • Improved pen testing efficiency by 50%. For red teams, HTB improved pen testing efficiency by helping testers enter assessments with more hands-on experience. The testers could complete baseline discovery faster, avoid unproductive investigation paths, and apply tested techniques more consistently. Interviewees also found HTB improved managers’ visibility into practitioner readiness, enabling them to assign the right people to the right engagements and reduce hands-on quality review effort. Over three years, the improved pen testing efficiency and reduced quality review save the composite organization $217K.

Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:

  • Development of an attacker mindset among defenders and testers. All customers have acknowledged the benefit of mindset shift. HTB shifts security teams from a reactive posture to a proactive mindset. This cognitive shift empowers teams to anticipate adversarial behavior and neutralize threats before they impact the business.

  • Improved cyber workforce development visibility and targeted skill development. HTB provides leaders with data-driven visibility into cyber workforce capabilities, allowing them to precisely map skill gaps, optimize resource allocation, and design targeted development pathways that align security team capabilities with evolving business risks.

  • Created an engaging, more collaborative and fun team culture. By leveraging the CTF Platform as well as Dedicated, Professional, and Cloud Labs, HTB customers bridge the gap between distributed teams, boost morale, and create a culture of collective problem-solving.

  • Enhanced employee career development and personal branding. HTB certifications and hands-on learning gives cyber practitioners technical confidence to tackle complex threats while also demonstrating how personal development translates into workplace pride and organizational trust.

Costs. Three-year, risk-adjusted PV costs for the composite organization include:

  • The HTB subscription fee for the composite is $272K over three years. The annual HTB subscription fee is calculated based on seat count and modules included. There were no additional implementation or professional services fees, nor ramp up fees for scaling.

  • The ongoing management and maintenance cost is $13K over three years. The ongoing costs include license administration, content curation, usage tracking, vendor management, and event administration.

The financial analysis that is based on the interviews found that a composite organization experiences benefits of $1.3M over three years versus costs of $285K, adding up to a net present value (NPV) of $979K and an ROI of 344%.

“It makes us faster to respond. It makes us better at looking at what the attacker’s doing… We know the right places to look because we know what an attacker would be looking to do. We’re better at our job, we’re faster at our job, we’re more efficient.”

Head of Global Cyber Incident Response, Professional Services  

Key Statistics

330%

Return on investment (ROI) 

$1.2M

Benefits PV 

$939K

Net present value (NPV) 

<6

Payback 

Benefits (Three-Year)

[CHART DIV CONTAINER]
Enhanced cyber workforce development Improved onboarding efficiency Improved cyber workforce retention Efficiency improvement in incident response Risk avoidance from MTTR reduction Efficiency improvement in penetration testing

The Hack The Box Customer Journey

Drivers leading to the Hack The Box investment

Interviews

Role Industry Region Products used
Director of Red Teams Cybersecurity consulting US Academy, Professional Labs, Dedicated Labs, Talent Sourcing
Global Head of Infrastructure Ethical Hacking Financial services Global with headquarter in the US Academy, Dedicated Lab, Cloud Labs, CTF
Head of Cyber Protection team Federal government US Academy, Dedicated Labs, Professional Labs
Team Lead- Technical Program Manager Technology services Global with headquarter in the US Academy, Dedicated Labs (Sherlocks)
Head of IT Security Financial services Global with headquarter in Europe Academy, Sherlocks, Dedicated / Professional Labs, Cloud Labs,
Threat Range
Global Cyber Incident Response Professional services Global with headquarter in the US Academy, Dedicated / Professional Labs, CTF
Staff Threat Researcher Cloud security US LetsDefend content, labs, and Enterprise Plus

Key Challenges

Before adopting Hack The Box, organizations typically relied on fragmented and often ineffective training approaches and failed to keep pace with evolving threats. Interviewees noted how their organizations struggled with common challenges, including:

  • Cybersecurity skills and readiness gaps. Organizations struggled to build practical, job-ready cyber skills across different experience levels. Junior employees lacked structured foundational training, while advanced red and blue teams needed deeper technical content that could help them think critically, connect tools and techniques, and apply skills in realistic scenarios.

  • Difficulty scaling hands-on training. Customers found it hard to deliver consistent, realistic training across growing, distributed, or diverse teams. Internal lab creation required significant effort, external courses were expensive, and many organizations lacked safe, repeatable environments where employees could practice offensive and defensive techniques without production risk.

  • Fragmented and low-impact training programs. Before HTB, customers often relied on a patchwork of SANS, Offensive Security, Immersive Labs, internal slide decks, ad hoc labs, and self-directed learning. These approaches were either too theoretical, too basic, too advanced for new hires, or too disconnected from day-to-day work, limiting engagement and measurable learning outcomes.

  • Limited visibility into capability development. Managers lacked a clear, scalable way to understand whether training translated into real capability. Activity metrics alone did not show whether employees were grasping concepts, becoming more independent, or ready for client engagements, incident response, threat hunting, or other security responsibilities.

“Beforehand, people were working on traditional training, and the problem with that was it’s not giving you any experience, it’s training. You’re learning some content, and you’re doing some easy exercises. It’s not causing you to think critically… or doing it in a realistic way.”

Head of Cyber Protection team, Federal Government Agency

Composite Organization

Based on the interviews, Forrester constructed a TEI framework, a composite company, and an ROI analysis that illustrates the areas financially affected. The composite organization is representative of the interviewees’ organizations, and it is used to present the aggregate financial analysis in the next section. The composite organization has the following characteristics:

  • Description of composite. A global, technology services organization with $8 billion in annual revenue, over 30,000 employees and a strong cybersecurity workforce of 300+ people. The composite organization also provides cybersecurity consulting services.

  • Deployment characteristics. The users of HTB come from blue, red, consulting teams, and general users with an interest in cybersecurity. The products adopted from HTB include Academy, Dedicated Labs, Professional Labs, and the Capture The Flag (CTF) platform. The planning stage was straightforward and required minimum effort from internal teams besides mapping out the effective path of learning based on organizational requirements.

 KEY ASSUMPTIONS

  • $8 billion in annual revenue

  • 30,000 employees

  • 196 - 208 users of HTB

  • 300 employees in the cyber workforce

Analysis Of Benefits

Quantified benefit data as applied to the composite

Total Benefits

Ref. Benefit Year 1 Year 2 Year 3 Total Present Value
Atr Enhanced cyber workforce development $168,300 $168,300 $177,650 $514,250 $425,562
Btr Improved onboarding efficiency $31,122 $31,122 $31,122 $93,366 $77,396
Ctr Improved cyber workforce retention $100,440 $100,440 $100,440 $301,320 $249,779
Dtr Efficiency improvement in incident response $64,260 $67,473 $67,473 $199,206 $164,874
Etr Risk avoidance from MTTR reduction $36,000 $36,000 $36,000 $108,000 $89,527
Ftr Efficiency improvement in penetration testing $85,599 $85,599 $90,783 $261,981 $216,767
  Total benefits (risk-adjusted) $485,721 $488,934 $503,468 $1,478,123 $1,223,905

Enhanced Cyber Workforce Development

Evidence and data. HTB enabled organizations to scale and enhance cyber workforce development at lower cost and with fewer operational resources. It complemented external courses with reusable hands-on learning and certification paths that could be accessed by broader groups of security practitioners, developers, consultants, and new hires. Interviewees highlighted that HTB enabled:

  • Organizations to reduce reliance on expensive external training while still upskilling the cyber workforce. Interviewees believe HTB provided their organizations an opportunity to upskill more employees that wasn’t possible in the prior learning set up. The technical program manager at a technology services company said, “In just over one and a half years of using Hack The Box, we have over 700 people who have signed up and used the platform, and we have a total of 10,000 plus employees who might be interested in using the product.”

  • Lower-cost certification pathways and broader certification coverage. Interviewees said HTB certifications provided a hands-on and cost effective alternative to traditional certifications. The head of global cyber incident response at a professional services firm said, “I can get the whole team certified in Hack The Box certs with the same cost of 4 to 5 [traditional certifications]. The Hack The Box certs are very good. I think they will get there and we like the technical depth that they require people to have.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • It has not replaced any existing learning platforms with HTB.

  • It has 90 employees in Year 1 working in functions that require security training, including blue, red, and consulting teams; the teams expand to 92 employees in Year 2, and 96 employees in Year 3.

  • 10% of the group attends a traditional certification training course on-site every year.

  • With HTB, an additional 20% are certified without going to on-site training.

Risks. The factors listed below affected the modeling confidence.

  • The workforce development budget varies depending on the industry.

  • The cost for onsite, traditional certification training courses varies by geography and specific types of training.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $426K.

20%

Increase in number of employees certified every year

“Employees might be able to take a [traditional certification] class every three years… but you can do Hack The Box certs anytime you want.”

Head of Global Cyber Incident Response, Professional Services

Enhanced Cyber Workforce Development

Ref. Metric Source Year 1 Year 2 Year 3
A1 Blue, red team and consulting users Composite 90 92 96
A2 Percentage of FTEs doing traditional training per year Year 1: Training
Year 2 and 3: Maintaining cost
10% 10% 10%
A3 Percentage of FTEs being certified with HTB per year Interviews 30% 30% 30%
A4 Number of additional FTEs get certified A1*(A3-A2) 18 18 19
A5 Cost per FTE for traditional training ($) Interviews $9,000 $9,000 $9,000
A6 T&E cost for onsite training Interviews $2,000 $2,000 $2,000
At Enhanced cyber workforce development A4*(A5+A6) $198,000 $198,000 $209,000
  Risk adjustment ↓15%      
Atr Enhanced cyber workforce development (risk-adjusted)   $168,300 $168,300 $177,650
Three-year total: $514,250 Three-year present value: $425,562

Improved Onboarding Efficiency

Evidence and data. Customers reported that HTB improved onboarding speed and post-onboarding skill quality by helping employees connect individual tools, techniques, and concepts into realistic workflows. Interviewees shared the following experiences:

  • Reduced onboarding timeline for junior new hires. Interviewees were able to shorten onboarding timeline for new hires. The head of global cyber incident response at a professional services firm said, “Especially with fundamental knowledge… they will grasp different things they have to analyze sooner or they don’t need to ask a more senior team member about things.”

  • Accelerated new-hire readiness and improved practical skills quality. Interviewees appreciated that HTB provided hands-on instead of theoretical training. The technical program manager at a technology services company said, “It’s not just a slide deck, it’s not just an overview of some terminology or whatever. We’re actually getting people to learn how to use different tools…”
    The Head of cyber protection at a federal government agency shared, “At the end of these missions, you see the analysts being like, ‘I get it now! This is fun!’… they understand the context for all the training they’re doing, which is really hard to get in just a simple training course.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The average time for cyber workforce onboarding training takes about 10 hours a week in the first 6 months.

  • The productivity recapture rate is 75% as the new hires are able to work independently sooner.

Risks. The financial model considered the following modeling risks:

  • The skill level and expectation of the cyber workforce varies by organization.

  • The onboarding timeline depends on the size, industry, and geographical coverage of the organization.

Results. To account for these risks, Forrester adjusted this benefit downward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $77K.

35%

Onboarding efficiency improvement

“Previously it would take us about six to nine months to get a new junior tester on board and doing tests that have manual testing, we’re probably closer to three-four months now. That’s pretty considerable.”

Global Head of Infrastructure Ethical Hacking, Financial Services

Improved Onboarding Efficiency

Ref. Metric Source Year 1 Year 2 Year 3
B1 Number of employees in red and blue teams Composite 75 77 80
B2 Number of cyber employees onboarded B1*10% 8 8 8
B3 Onboarding time prior to HTB (hours) Interviews 260 260 260
B4 Percentage of time saved with HTB Interviews 35% 35% 35%
B5 Onboarding time saved with HTB per new employee (hours) B3*B4 91 91 91
B6 Fully-burdened hourly rate per cyber security engineer TEI standard $60 $60 $60
B7 Productivity recapture rate Composite 75% 75% 75%
Bt Improved onboarding efficiency B2*B5*B6*B7 $32,760 $32,760 $32,760
  Risk adjustment ↓5%      
Btr Improved onboarding efficiency (risk-adjusted)   $31,122 $31,122 $31,122
Three-year total: $93,366 Three-year present value: $77,396

Improved Cyber Workforce Retention

Evidence and data. HTB contributed to cyber workforce retention by shaping a more engaging technical culture for high-performing cyber talent. It provided employees continuous access to hands-on, role-relevant training, creating team-building opportunities through CTFs and collaborative lab environments, and supporting a culture where practitioners could keep developing technical skills throughout the year. Interviewees have shared with us their experiences:

  • Improved team connection and morale. Companies we interviewed have described as the HTB experience as a fun activity to do as a team. The global head of ethical hacking at a financial services firm noted, “Those sessions have brought the team much closer and they’re training in the process but it doesn’t feel like training. At that point, it’s just fun. You’re hacking into things with your teammates. You’re talking to people you usually only email occasionally.”

  • Contributed to talent retention. Several interviewees commented on the effectiveness of HTB training in building team culture. The technical program manager at a technology services company, “It aids in skill enhancement and talent retention because people see this as a differentiator for the company and their job.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The attrition rate in the cybersecurity team have reduced by 4% with HTB

  • We attribute 30% of this improvement to HTB, as team culture, compensation, and management style are also important factors that contributed to an improved retention rate.

Risks. The financial model considered the following modeling risks:

  • Retention varies by industry, geography, and wider company culture.

Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $250K.

4%

Attrition reduction

“Our IR team lost zero people when a major tech company offered double the salary. The reason was they liked the work, they really enjoyed the challenges and at their state of their career, this is what they wanted to do. This is because we’re investing in the team… the challenges that we do with Hack The Box and the Hack The Box certs… that kept our team interested.”

Global Cyber Incident Response, Professional Services

Improved Cyber Workforce Retention

Ref. Metric Source Year 1 Year 2 Year 3
C1 Attrition rate prior to HTB Composite 5% 5% 5%
C2 Attrition rate post HTB Composite 1% 1% 1%
C3 Number of cyber employees retained B1*(C1-C2) 3 3 3
C4 Cost of attrition per cyber security engineer TEI Standard $124,000 $124,000 $124,000
C5 Retention attribution to HTB Composite 30% 30% 30%
Ct Improved cyber workforce retention C3*C4*C5 $111,600 $111,600 $111,600
  Risk adjustment 10%      
Ctr Improved cyber workforce retention (risk-adjusted)   $100,440 $100,440 $100,440
Three-year total: $301,320 Three-year present value: $249,779

Efficiency Improvement In Incident Response

Evidence and data. Rather than relying only on documentation or theoretical training, teams used HTB labs and challenges to understand how attacks unfold, what evidence attackers left behind, and where detections should be implemented in their own environments. Practitioners gained hands-on exposure to attacker techniques, realistic environments, and repeatable practice scenarios. HTB contributed to an improvement in IR efficiency, due to:

  • Improved response effectiveness by understanding attacker behavior and where to investigate. The hands-on exposure made the IR team more confident in incident detection. The head of global cyber incident response at a professional services company said, “I think it makes us faster to our response. It makes us better at looking at what the attacker’s doing. We’re fast. We know the right places to look because we know what an attacker would be looking to do. So I’d say we’re better at our job, we’re faster at our job, we’re more efficient.”

  • Improved detection engineering through safer experimentation with production-like technologies. The head of IT security at a financial services company explained, “Because we’ve learned stuff we hadn’t thought about [through cloud labs], we didn’t know until then how Azure is actually working in the background, we were able to then set up detections with this new knowledge for our SIEM.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • 50% of IR analyst time is spent on the active incident response, the rest of time is split between post-incident reports, research and learning, detection improvement, stakeholder coordination.

  • Mean time to acknowledge (MTTA) has improved by 50%, and Mean time to resolution (MTTR) has improved by 30%.

  • 30% of the improvement can be attributed to HTB among other factors, such as improved detection strategy and security environment.

Risks. The financial model considered the following modeling risks:

  • Time spent on incident is highly dependent on each organization’s security environment, which is affected by region, industry, and size of the organization.

Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $164K.

30%

Reduction in MTTR

“We could improve on our real production environments because of what we’ve learned from different challenges at Hack The Box… this helped us then create better threat detections.”

Head of IT Security, Financial Services

Efficiency Improvement In Incident Response

Ref. Metric Source Year 1 Year 2 Year 3
D1 Number of staff in the IR team Composite 20 21 21
D2 Active time spend on incident response per analyst (hour) Assumption 1,040 1,040 1,040
D3 Percentage of active time spend on acknowledgement before HTB Assumption 40% 40% 40%
D4 Percentage of active time spend on resolution before HTB Assumption 60% 60% 60%
D5 MTTA improvement Interviews 50% 50% 50%
D6 MTTR improvement Interviews 30% 30% 30%
D7 Improvement due to HTB Assumption 30% 30% 30%
D8 Time saved in incidence response due to HTB per IR analyst D2*(D3*D5+D4*D6)*D7 119 119 119
D9 Average cybersecurity engineer hourly salary Composite $60 $60 $60
D10 Productivity recapture rate Forrester Standard 50% 50% 50%
Dt Efficiency improvement in incident response D1*D8*D9*D10 $71,400 $74,970 $74,970
  Risk adjustment 10%      
Dtr Efficiency improvement in incident response (risk-adjusted)   $64,260 $67,473 $67,473
Three-year total: $199,206 Three-year present value: $164,874

Risk Avoidance From MTTR Reduction

Evidence and data. Besides improving the efficiency of defensive security teams, interviewees also observed the improvement of the quality of threat detection. As responders know where to investigate, the operational risks have reduced. HTB eventually contributed reduction in cybersecurity risk by:

  • Reducing breach exposure through shorter attacker dwell time. By improving detection quality and enabling analysts to identify malicious activity earlier, HTB reduced attacker dwell time, a key driver of breach cost and incident severity. The head of IT security at a financial services company commented further, “Dwell time directly correlates with breach cost, and even marginal improvements can prevent highsixfigure impacts in regulated environments.”

  • Improving the incident report granularity. The head of global cyber incident response at a professional services firm said, “I’ve seen a lot more good technical details from our team as they resolve stuff… I need to know what the root cause was. I know how it happened. I need to know… a lot of technical details.”

  • Enabling better detection decisions. The head of IT security at a financial services company explained, “We definitely had more detections implemented… Better detections in regards to understanding what is happening on a technology level and then being able to pinpoint where actually the detection in our environment would be best suited.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • Among all cases handled by the IR team, 5% are at risk for further investigation. Within that, the escalation probability prior to HTB is 15%, which has reduced by 50% with the reduction in dwell time.

  • The escalation probability is at 8% with HTB.

  • Cost per escalated case for the composite organization is $200,000.

  • 20% of the risk reduction can be attributed to HTB, reflecting it’s critical role in improving analyst skill, detection engineering quality, and attacker-behavior understanding, while recognizing that reduced dwell time also depends on broader investments in security tooling, processes, staffing, and governance.

Risks. The financial model considered the following modeling risks:

  • The number of incidents is highly dependent on the organization’s broader investments in security tooling, processes, staffing, and governance.

  • Cost per escalated case varies depending on the nature of the business and their exposed risks.

Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $90K.

50%

Reduction in escalation probability with HTB

“Dwell time directly correlates with breach cost, and even marginal improvements can prevent highsixfigure impacts in regulated environments.”

Head of IT Security, Financial Services

Risk Avoidance From MTTR Reduction

Ref. Metric Source Year 1 Year 2 Year 3
E1 Number of cases handled by IR team per year Composite 400 400 400
E2 Number of at risk incidents per year Assumption (5%) 20 20 20
E3 Escalation probability prior to HTB Composite 15% 15% 15%
E4 Escalation probability with HTB Composite 8% 8% 8%
E5 Number of escalated case reduction E2*(E3-E4) 1 1 1
E6 Cost per escalated case Composite $200,000 $200,000 $200,000
E7 Attribution to HTB Assumption 20% 20% 20%
Et Risk avoidance from MTTR reduction E5*E6*E7 $40,000 $40,000 $40,000
  Risk adjustment 10%      
Etr Risk avoidance from MTTR reduction (risk-adjusted)   $36,000 $36,000 $36,000
Three-year total: $108,000 Three-year present value: $89,527

Efficiency Improvement In Penetration Testing

Evidence and data. For red teams, HTB improved penetration testing efficiency by helping testers enter assessments with more hands-on experience. The testers could complete baseline discovery faster, avoid unproductive investigation paths, and apply tested techniques more consistently. The efficiency improvement in penetration testing includes:

  • Reduced engagement-level research and improved tester evidence. The director of red teams at a cybersecurity consultancy said, “We can do them much faster and more consistently. So, it saved us two to three hours per engagement and then the added confidence of the team, understanding the tooling, knowing how it worked, and being confident in how to perform the test.”

  • Better triage and less wasted effort. HTB improved tester judgment and prioritization, reducing wasted effort during assessments and helping them focus on more fruitful attack paths. The head of ethical hacking at a financial services company shared, “They’re also able to triage better and to prioritize and by having run the images and going down rabbit holes to find that this meant nothing, you start becoming better at realizing, ‘Okay, this isn’t fruitful’ or, ‘I’ve been doing this for too long, let me pause, take a note, go try something else and come back to it with fresh eyes.’”

Interviewees also found HTB improved managers’ visibility into practitioner readiness, enabling them to assign the right people to the right engagements and reduce their level of involvement in day-to-day practitioner activity.

  • Reduced quality review time with improved practitioner readiness. The director of red teams at a cybersecurity consultancy said, “In the past, a manager would have to be a lot more hands on and be engaged with it and they would have to be on one engagement at a time or oversee one engagement or two. And now a manager can oversee maybe three or four just because they don’t have to spend as much time on QA and making sure the team is able to perform.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The average time a tester spends on initial scanning is 8 hours prior to HTB, as it requires more time on engagement level research, learning, and triage.

  • The average time a consulting manager spends on quality control is 2 hours prior to HTB.

  • Productivity recapture rate accounts for the fact that employees typically do not repurpose all time gains into work activity.

Risks. The financial model considered the following modeling risks:

  • The time spent for pen testing and quality assurance are related to cyber workforce skill level and the operating environment.

Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $197K.

50%

Time saved on pen testing

“They’re able to capture low hanging fruit much quicker. So then let’s say there’s 10 days to test, it’ll go from the first four or five days going through scans and going through like the basics, now that initial stuff gets done in a day or two, which gives them a lot more time to be creative, to try new things and to try to develop [ways to exploit vulnerabilities].”

Global Head of Infrastructure Ethical Hacking, Financial Services

Efficiency Improvement In Penetration Testing

Ref. Metric Source Year 1 Year 2 Year 3
F1 Number of employees doing pen testing (red + consulting teams) Assumption 30 30 32
F2 Number of tests per tester per year Assumption 24 24 24
F3 Time spent on initial scanning prior to HTB (hours) Interviews 8 8 8
F4 Time spent on initial scanning with HTB (hours) Interviews 4 4 4
F5 % time saved on pen testing (F3-F4)/F3 50% 50% 50%
F6 Number of hours saved thanks to HTB F1*F2*(F3-F4) 2,880 2,880 3,072
F7 Average cybersecurity engineer hourly salary Composite $60 $60 $60
F8 Number of hours saved per manager on quality control with HTB Composite 260 260 260
F9 Cybersecurity manager hourly salary Composite $67 $67 $67
F10 Productivity recapture Composite 50% 50% 50%
Ft Efficiency improvement in penetration testing (F6*F7+F8*F9)*F10 $95,110 $95,110 $100,870
  Risk adjustment ↓10%      
Ftr Efficiency improvement in penetration testing (risk-adjusted)   $85,599 $85,599 $90,783
Three-year total: $261,981 Three-year present value: $216,767

Unquantified Benefits

Interviewees mentioned the following additional benefits that their organizations experienced but were not able to quantify:

  • Development of an attacker mindset among defenders and testers. All customers have acknowledged HTB shifts security teams from a reactive posture to a proactive mindset. This cognitive shift empowers teams to anticipate adversarial behavior and neutralize threats before they impact the business. “The reason we got it initially… is because we wanted to get our team to be able to think like an attacker and understand what an attacker will be looking for… because we think that makes a better defender,” shared by the head of global cyber incident response at a professional services firm.

  • Improved cyber workforce development visibility and targeted skill development. HTB provides leaders with data-driven visibility into cyber workforce capabilities, allowing them to precisely map skill gaps, optimize resource allocation, and design targeted development pathways that align security team capabilities with evolving business risks. The global head of ethical hacking at a financial services firm said, “With the actual platform and with the solution, we can gauge where somebody is at versus where they were six months ago and that’s very impactful.”

  • Created an engaging, collaborative and fun team culture. By leveraging the CTF Platform as well as Dedicated, Professional, and Cloud Labs, HTB customers bridge the gap between distributed teams, boost morale, and create a culture of collective problem-solving. The head of global cyber incident response at a professional services firm said, “I can’t brag enough about the morale boosting and the team building that we achieved using the CTF.”

  • Enhanced employee career development and personal branding. HTB certifications and hands-on learning gives cyber practitioners technical confidence to tackle complex threats while also demonstrating how personal development translates into workplace pride and organizational trust. The director of red teams at a cybersecurity consultancy shared, “An added benefit especially to each of the team members is for their personal brand. They now have a certification to go with their name to show what they’re capable of doing.”

“Morale is a funny thing. It’s very hard to quantify but you definitely feel it. You feel it when it goes up and you can tell the team is more of a team now… Those sessions have brought the team much closer and they’re training in the process but it doesn’t feel like training. At that point, it’s just fun.”

Global Head of Infrastructure Ethical Hacking, Financial Services

Flexibility

The value of flexibility is unique to each customer. There are multiple scenarios in which a customer might implement Hack The Box and later realize additional uses and business opportunities, including:

  • Improve technical hiring efficiency and candidate quality. Customers could expand HTB usage into talent acquisition by using platform progress, hands-on challenges, and interview labs to validate candidates’ technical capabilities and collaboration style before hiring.

  • Extend hands-on training into realistic defensive cyber range exercises. Organizations could use Threat Range to run blue-team and purple-team simulations, and expect more activities that are full-scenario and team-based. It will provide analysts safe practice as a team with incident response, threat hunting, and detection workflows without exposing production environments to risk.

  • Improve cyber workforce enablement in response to AI-driven threats. As AI expands the speed, sophistication, and reach of cyberattacks, organizations may extend HTB beyond specialist security teams to a wider set of employees who influence cyber risk, including software engineers, cloud teams, AI/ML teams, product security teams, and security-adjacent business users. By scaling practical, hands-on security education across a broader workforce, organizations could improve baseline security knowledge, strengthen secure-by-design practices, and better prepare employees to recognize and respond to emerging AI-enabled threats.

“In just a little over one and a half years of using Hack The Box, we have over 700 people who have signed up, and we have a total addressable market of 10,000 plus employees who might be interested in using the product.”

Technical Program Manager, Technology Services

Analysis Of Costs

Quantified cost data as applied to the composite

Total Costs

Ref. Cost Initial Year 1 Year 2 Year 3 Total Present Value
Gtr Annual subscription fees $0 $106,785 $108,675 $113,400 $328,860 $272,090
Htr Ongoing management and maintenance of the platform $3,652 $3,652 $3,652 $3,652 $14,608 $12,734
  Total costs (risk-adjusted) $3,652 $110,437 $112,327 $117,052 $343,468 $284,824

Annual Subscription Fees

Evidence and data. The annual HTB subscription fees depend on seat count and modules included.

  • There were no additional implementation or professional services fees. There were no ramp up fees for scaling.

  •  Interviewees were generally satisfied with the cost.

Modeling and assumptions. The cost is modeled on the size of the composite’s cyber workforce. We also considered all the modules they currently adopt, including Academy, Dedicated Labs, Professional Labs, and CTF.

Risks. This category considered the following modeling risks:

  • Potential cost increases in the future.

  • Price differences across customer profiles.

Results. To account for these risks, Forrester adjusted this cost upward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $272K.

“For us, it’s really simple. If you want to scale, we just put in a request… Here, it’s just a PO. So, there really is no ramp up if we’re going to scale.”

Global Head of Infrastructure Ethical Hacking, Financial Services

Annual Subscription Fees

Ref. Metric Source Initial Year 1 Year 2 Year 3
G1 Subscription fees Composite   $101,700 $103,500 $108,000
Gt Annual subscription fees G1   $101,700 $103,500 $108,000
  Risk adjustment 5%        
Gtr Annual subscription fees  (risk-adjusted)   $0 $106,785 $108,675 $113,400
Three-year total: $328,860 Three-year present value: $272,090

Ongoing Management And Maintenance Of The Platform

Evidence and data. Interviewees generally thought HTB was easy to manage after initial setup, with most ongoing effort focused on assigning licenses, reviewing usage, curating content, and coordinating with the customer success manager.

For more mature programs, the administrator also maps HTB content to internal skills frameworks or training paths.

To maximize the value of HTB, the ongoing management work includes:

  • License administration. Creating accounts, assigning or rotating seats, managing admins, deconflicting shared licenses across teams, and adding seats as usage scales.

  • Content curation. Selecting relevant modules, labs, job-role paths, certifications, or CTF content; pairing HTB content with internal training materials; and refreshing curated content as new content becomes available.

  • Usage tracking. Monitoring user activity, completion progress, skill development, inactive users, and gaps in capability; using dashboards or internal trackers to inform coaching, staffing, and ROI reporting.

  • Vendor management. Coordinating with HTB customer success, attending monthly or quarterly check-ins, requesting walkthroughs or roadmap updates, discussing certifications, and getting help curating or troubleshooting content.

  • Event administration. Planning and running CTFs, boot camps, HTB Fridays, team walkthroughs, onboarding sessions, and regional or cross-functional training events.

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The initial set up of licenses and content takes 40 hours of the manager’s time.

  • The rest of activities are correlated with the two training cycles the composite has every year.

Risks. This category considered the following modeling risks:

  • Different training set ups and organizational cybersecurity requirements may change the time required for ongoing management.

Results. To account for these risks, Forrester adjusted this cost upward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $13K.

Ongoing Management And Maintenance Of The Platform

Ref. Metric Source Initial Year 1 Year 2 Year 3
H1 Planning phase (hours per year) Interviews 40 0 0 0
H2 Number of FTE involved in planning phase Interviews 1 0 0 0
H3 Hourly rate per (senior)  FTE TEI standard $83 0 0 0
H4 Planning phase pre implementation (hours) H1*H2*H3 $3,320 $0 $0 $0
H5 Number of training cycles per year Composite   2 2 2
H6 Number of hours spent managing the platform per training cycle Interviews   10 10 10
H7 Number of FTEs involved in content review Interviews   2 2 2
H8 Hourly rate per (senior) FTE TEI standard   $83 $83 $83
H9 Ongoing maintenance of the platform H5*H6*H7*H8   $3,320 $3,320 $3,320
Ht Ongoing management and maintenance of the platfom H4+H9 $3,320 $3,320 $3,320 $3,320
  Risk adjustment ↑10%        
Htr Ongoing management and maintenance of the platfom  (risk-adjusted)   $3,652 $3,652 $3,652 $3,652
Three-year total: $14,608 Three-year present value: $12,734

Financial Summary

Consolidated Three-Year, Risk-Adjusted Metrics

Cash Flow Chart (Risk-Adjusted)

[CHART DIV CONTAINER]
Total costs Total benefits Cumulative net benefits Initial Year 1 Year 2 Year 3

Cash Flow Analysis (Risk-Adjusted)

  Initial Year 1 Year 2 Year 3 Total Present Value
Total costs ($3,652) ($110,437) ($112,327) ($117,052) ($343,468) ($284,824)
Total benefits $0 $485,721 $488,934 $503,468 $1,478,123 $1,223,905
Net benefits ($3,652) $375,284 $376,607 $386,416 $1,134,655 $939,081
ROI           330%
Payback period (months)           <6

 Please Note

The financial results calculated in the Benefits and Costs sections can be used to determine the ROI, NPV, and payback period for the composite organization’s investment. Forrester assumes a yearly discount rate of 10% for this analysis.

These risk-adjusted ROI, NPV, and payback period values are determined by applying risk-adjustment factors to the unadjusted results in each Benefit and Cost section.

The initial investment column contains costs incurred at “time 0” or at the beginning of Year 1 that are not discounted. All other cash flows are discounted using the discount rate at the end of the year. PV calculations are calculated for each total cost and benefit estimate. NPV calculations in the summary tables are the sum of the initial investment and the discounted cash flows in each year. Sums and present value calculations of the Total Benefits, Total Costs, and Cash Flow tables may not exactly add up, as some rounding may occur.

From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering an investment in Hack The Box.

The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that Hack The Box can have on an organization.

Due Diligence

Interviewed Hack The Box stakeholders and Forrester analysts to gather data relative to Hack The Box.

Interviews

Interviewed seven decision-makers at organizations using Hack The Box to obtain data about costs, benefits, and risks.

Composite Organization

Designed a composite organization based on characteristics of the interviewees’ organizations.

Financial Model Framework

Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.

Case Study

Employed four fundamental elements of TEI in modeling the investment impact: benefits, costs, flexibility, and risks. Given the increasing sophistication of ROI analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.

Total Economic Impact Approach

Benefits

Benefits represent the value the solution delivers to the business. The TEI methodology places equal weight on the measure of benefits and costs, allowing for a full examination of the solution’s effect on the entire organization.

Costs

Costs comprise all expenses necessary to deliver the proposed value, or benefits, of the solution. The methodology captures implementation and ongoing costs associated with the solution.

Flexibility

Flexibility represents the strategic value that can be obtained for some future additional investment building on top of the initial investment already made. The ability to capture that benefit has a PV that can be estimated.

Risks

Risks measure the uncertainty of benefit and cost estimates given: 1) the likelihood that estimates will meet original projections and 2) the likelihood that estimates will be tracked over time. TEI risk factors are based on “triangular distribution.”

Financial Terminology

Present value (PV)

The present or current value of (discounted) cost and benefit estimates given at an interest rate (the discount rate). The PVs of costs and benefits feed into the total NPV of cash flows.

Net present value (NPV)

The present or current value of (discounted) future net cash flows given an interest rate (the discount rate). A positive project NPV normally indicates that the investment should be made unless other projects have higher NPVs.

Return on investment (ROI)

A project’s expected return in percentage terms. ROI is calculated by dividing net benefits (benefits less costs) by costs.

Discount rate

The interest rate used in cash flow analysis to take into account the time value of money. Organizations typically use discount rates between 8% and 16%.

Payback

The breakeven point for an investment. This is the point in time at which net benefits (benefits minus costs) equal initial investment or cost.

Appendix A

Total Economic Impact

Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.

Appendix B

Supplemental Material

Related Forrester Research

The Forrester Wave™: Cybersecurity Skills And Training Platforms, Q1 2026, Forrester Research, Inc., March 11th, 2026.

Top Recommendations For Your Security Program, 2026, Forrester Research Inc., March 4th, 2026

Appendix C

Endnotes

1 Source: The Cybersecurity Skills And Training Platforms Landscape, Q4 2025 | Forrester

2 Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.

Disclosures

Readers should be aware of the following:

This study is commissioned by Hack The Box and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.

Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in Hack The Box. For any interactive functionality, the intent is for the questions to solicit inputs specific to a prospect's business. Forrester believes that this analysis is representative of what companies may achieve with Hack The Box based on the inputs provided and any assumptions made. Forrester does not endorse Hack The Box or its offerings. Although great care has been taken to ensure the accuracy and completeness of this model, Hack The Box and Forrester Research are unable to accept any legal responsibility for any actions taken on the basis of the information contained herein. The interactive tool is provided ‘AS IS,’ and Forrester and Hack The Box make no warranties of any kind.

Hack The Box reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.

Hack The Box provided the customer names for the interviews but did not participate in the interviews.

Consulting Team:

Diane Deng

Published

August 2026