We train people into real security careers with projects and a mentor who knows their name. And we give small companies the security expertise they could never afford to hire full time.
Four ways people use HackHop. Choose the one that sounds like you and we'll take you straight there.
You're switching fields, finishing a degree, or watching AI reshape your job. You need real skills and something to show for them.
You've done the tutorials and you're still lost. You need one person who tells you exactly what to do next, every week.
You run a company and you can't hire a security expert, but you know there are gaps. Leaked staff passwords, an old server nobody remembers, email anyone can fake, weak network... We show you what's actually open before it costs you anything.
You'd rather not depend on outsiders forever. We train some of your people to watch your systems, spot the warning signs and act on them — and we stay reachable for the hard calls.
A short online session on one practical topic, run regularly and open to anyone. Come, learn something useful, leave. Nothing to buy.
Sit in on a real one-to-one session with a mentor. You'll leave with an honest read on where you are and what to do next, whether or not you carry on.
An hour with us about your company's security. We'll tell you what we'd look at first and what it would take. No obligation to go further.
Everything beyond these is quoted first, so you always know the price before anything starts.
The same hands-on material taught in a university classroom, run as real projects with real tools. You break something, you fix it, then you write it up the way a client would read it. Everything runs online, so it works wherever you are.
Every engagement starts with a free 30-minute call so we both know what you actually need. Where someone genuinely can’t pay, ask us — we keep a small number of assisted places.
There's more security material online than anyone could finish in a lifetime, and that's the problem. People spend a year jumping between tutorials and end up with no direction and nothing to show for it. A mentor fixes that in a way a course never can.
Before anyone pays for anything, we spend an hour together. We look at where you are, and you leave with an honest view of what to do next, whether or not you carry on with us. If it was useful, we'll talk about a plan and a price. No pressure either way.
Book your first classA real conversation, not a test. What you know already, what you've tried, how many hours a week you really have, and what's in the way. Money, visa, a full-time job, a family. A plan that ignores your life is no plan at all.
You leave with: an honest starting point"I want to get into cybersecurity" isn't a goal. It's about nine different careers. We go through what each job looks like day to day, what it pays, and which one suits how you like to work. Then you choose one.
You leave with: one job title to aim atWhich skills, in what order. Which resources are worth your time and which are noise. What to build. Roughly when you should be ready to apply. It changes as you go, but you're never sitting there wondering what's next.
You leave with: a plan you can actually seeThis is the part that makes the difference. Just you and your mentor, screen shared, working on whatever you're stuck on. Bring your errors, your half-finished lab, your bad code. You fix it together and you understand why it works. Between sessions, message us when you hit a wall.
You leave with: nobody letting you quietly fall behindA certificate says you passed a test. A working project says you can do the job. You finish with a portfolio, a public write-up of your work, and if you're ready, supervised hours on a real client job.
You leave with: proof, not claimsYour CV rewritten for the job you're going after. Practice interviews, including the technical ones. Which companies to approach, and how to write to a person instead of a job board. Introductions where we have them.
You leave with: applications that get answeredMost people start by picking a course. That's backwards. Pick the job first, then the skills follow on their own. Here's what the main roles actually involve, so you can tell which one sounds like your kind of day.
You watch alerts, work out which ones matter, and respond when something is real. Shift work in bigger companies. It suits people who are patient, curious and good at noticing when something is slightly off.
You break into systems legally and write up exactly how you did it. The report matters as much as the hack. It suits people who enjoy puzzles and don't mind writing. Almost nobody starts here — most come through analyst or development work first.
You lock down AWS and Azure environments and stop people leaving things open by accident. It suits anyone who likes systems and automation. If you want hired quickest, this is usually the answer.
You attack and defend models — prompt injection, poisoned data, inputs built to fool a system. Very few people can do this properly yet, which is exactly why it's worth learning now.
Audits, frameworks, policy, evidence. Far less coding than people expect. It suits organised people who can talk to executives, and it's the easiest route in for anyone coming from law, finance or admin work.
Firmware, chips, control systems, verification. The steepest learning curve on this list and the smallest pool of people who can do it. Slow to enter, very hard to be made redundant from.
AI is genuinely taking over parts of this field — writing scripts, first-pass log review, drafting reports. What it doesn't do is decide what matters, take responsibility for a call, or walk into a room and explain a risk to a business owner. Those are the parts worth building a career on, and they're the parts we teach. If someone promises you a job title in twelve weeks, be careful. If someone helps you build things you can show people, listen.
Find your direction →Before you spend anything, we run five automated checks on what the internet already knows about your company and send you a two-page summary. Nothing to install, no sales call, and we never touch your systems.
A short report in plain English. For each thing we find: what it is, how bad it is, and what to do about it.
The ones you can fix yourself are marked clearly, and if nothing serious turns up we tell you that too.
This is the automated version. The full External Security Check ($750–$1,500) adds manual validation, subdomain and port discovery, a ranked remediation plan, and a 60-day re-check.
A full-time security hire costs six figures. Most companies under 50 people need a few days of the right attention, not a permanent chair. Nearly all of this work is done remotely, so where you are makes no difference to what it costs. Every price is a range because scope varies — you get a fixed number before any work starts.
Fix what we found and we re-test it free within 60 days. Most consultants hand over a report and disappear.
A dated, signed statement of exactly what was tested and closed — for your insurer, your customers, or a procurement form.
No scanner output pasted into a template. If it’s in your report, we confirmed it and can show you why it matters.
Almost everything we do runs remotely — read-only access, screen shares and video calls. No travel cost, no country limit.
What an attacker sees before they touch anything.
The full picture of how your company actually works.
Stop guessing at the questions on your renewal form.
One environment, reviewed properly.
Manual testing, not a scan with a logo on it.
Where our research background applies directly.
For companies that need a security lead, not a security hire. Run entirely remotely. Three-month minimum.
Monthly meeting, questions answered, risk register, roadmap
Adds quarterly external check, policy work, vendor questionnaires
Adds incident response guidance, insurance renewal support, priority access
Also available: remediation and hardening from $500 — we fix what we found, not just report it. Executive home security review, $600, added to any business engagement. And audit preparation for SOC 2, HIPAA, PCI and CMMC.
On-site work is available where it genuinely helps, quoted separately, with travel and expenses agreed in advance and billed at cost. For anything touching your systems we work from read-only access and a signed authorisation letter naming exactly what we may test and when.
Security is far too broad for one person to cover well, and anyone who tells you otherwise is selling something. HackHop is a small group of practitioners working from different countries, each one deep in their own area rather than spread thin across all of it.
So your work goes to the person who does that thing for a living. You'll always know who is working on your job and why it's them, and everything is reviewed before it reaches you.
Assume nothing.
Verify everything.
That's the rule I work by, and it comes from my research. Formal verification means proving that a system does what it says, instead of assuming it does. It's slower and harder than running a scanner, and it finds things a scanner never will.
Most security consulting works the other way: a firm sends a junior analyst with a tool, and you get back a report from a template. That isn't what happens here, and it isn't how we teach either.
I started HackHop for two reasons. The companies most likely to be hurt by an attack are usually the ones least able to pay for help. And a lot of capable people are watching AI change their careers and don't know what to learn next. Both problems have the same answer: real skills, taught properly, by people who actually do the work.
HackHop is small and growing carefully. When we open a position, it gets posted here first.
When we do hire, we'll be looking for practitioners rather than generalists — people who go deep in one area and can explain it clearly to someone who isn't technical. Teaching ability counts here as much as technical skill, because everyone who works with us ends up doing some of both.
Likely first roles: penetration testing, cloud security, detection and response, and mentors who've actually worked the job they'd be teaching.
If that sounds like you and you'd rather not wait for a posting, send us your work — a write-up, a tool, a research paper, something you built. We read everything, and we'd rather meet good people early than advertise late.
Introduce yourself →Training, mentoring, or a question about your company. Same form for all of it. Every message gets a reply within two working days.