TryHackMe is a browser-based cyber security training company that delivers gamified, hands-on learning for individuals, teams, and educators. Its platform is built around guided learning paths, interactive labs, and role-aligned practice environments that help users build offensive and defensive skills without local setup. The company centers practical experience in its learning model, using in-browser labs, structured content, and progressive challenges to turn theory into usable skills.
Beyond self-paced learning, TryHackMe supports workforce development and classroom use cases with team management, reporting, custom content, and professional certifications. Its broader offering now includes simulated SOC, threat hunting, and tabletop training experiences designed to help organizations assess readiness, accelerate onboarding, and keep cyber skills current.
Offerings, Capabilities, and Integrations
TryHackMe combines guided training, competitive exercises, simulations, and reporting in one browser-delivered environment. Organizations can assign role-based content, clone or build custom learning paths, create bespoke labs and CTFs, and use workspaces and leaderboards to encourage participation and accountability across teams or cohorts.
For operational fit, TryHackMe supports Single Sign-On through SAML 2.0 and OIDC and offers an enterprise API for user, room, and reporting workflows. Its training environments also reflect common security workflows and tools, including SOC scenarios that can run in Splunk, Elastic, or Microsoft Sentinel. Administrators can track activity, assignment completion, time spent, and skills progression through the Management Dashboard and Skills Matrix.
Products and Services
- Learning Paths: Structured pathways made up of modules and rooms that guide learners through role-based and skill-based cyber security training. Teams can also clone and customize paths for different user groups.
- Interactive Labs: Browser-based hands-on labs delivered through TryHackMe rooms, including walkthrough, challenge, and network-based exercises for offensive and defensive training.
- SOC Simulator: A simulated SOC training environment where analysts investigate realistic alerts, build case reports, receive AI-driven feedback, and train with SIEM options such as Splunk, Elastic, and Microsoft Sentinel.
- Workspaces: Organization-based spaces that let users collaborate and compete with teammates through shared membership, activity views, and leaderboards.
- Custom CTF Builder: A business and education feature for creating tailored capture-the-flag events from existing challenges to support competitive, objective-based team training.
- Management Dashboard: Administrative workspace for managing users, assignments, onboarding, reporting, and training visibility across business and classroom deployments.
- Skills Matrix: A reporting view that compares skill development across individuals and groups based on completed content and tagged topic coverage.
- Security Analyst Level 1 (SAL1): Entry-level professional certification for security analysts, built to reflect real SOC workflows and validate practical defensive skills in a simulated environment.
- Junior Penetration Tester (PT1): Entry-level professional certification focused on practical offensive security skills across web, network, and Active Directory domains.
- Threat Hunting Simulator: A simulator for practicing threat hunting through realistic investigations, log analysis, artefact review, and MITRE ATT&CK-based attack-chain mapping.
- Tabletop Exercises: AI-assisted tabletop exercises for SOC and incident response teams, with chat-based simulation, task tracking, guest access, and reporting for preparedness reviews.
- Pre Security (SEC0): Beginner certification and associated pathway designed to build foundational knowledge of computers, operating systems, networking, web concepts, and core security awareness before role-specific training.
- Security Analyst Level 2 (SAL2): Advanced defensive certification for analysts who need to demonstrate higher-level investigation, decision-making, and incident handling capability in realistic SOC scenarios.
Target Customers
TryHackMe serves individual learners ranging from complete beginners to working cyber security practitioners who want guided, practical training they can access in a browser. Its content is designed for people preparing for junior roles, deepening technical skills, or validating readiness through hands-on certifications.
On the organizational side, TryHackMe targets SOC and incident response teams, security managers, hiring and onboarding leaders, and broader technical teams such as IT, DevOps, and system administration groups that need security upskilling. It also serves universities, schools, and training providers that want structured cyber security content, assignments, reporting, and classroom-friendly administration.
Key People
- Ben Spring: Co-Founder, Chief Executive Officer
- Ashu Savani: Co-Founder
- Tim Woods: Head of Product
- Robert Sugars: Head of Engineering
- Cami Ragano: Head of Marketing
- Daryl Benson: Global Talent Acquisition Lead – People & Operations
- Max Robertson: Senior Content Engineer
Key Facts
- Headquarters: London, England, United Kingdom
- Employees: 150+ employees
- Annual Revenue: Undisclosed
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: Private (not publicly listed)