Start Training Mentoring Security roles First check For business Team About Careers Contact
Cybersecurity training & consulting

Proof,
beats promises.

We train people into real security careers with projects and a mentor who knows their name. And we give small companies the security expertise they could never afford to hire full time.

external-check — sample output
$ hackhop check --external yourcompany.com
Pick your way in

What brings you here?

Four ways people use HackHop. Choose the one that sounds like you and we'll take you straight there.

Ways to start at no cost Three doors in. Take one, then decide.
For everyone Open seminar

A short online session on one practical topic, run regularly and open to anyone. Come, learn something useful, leave. Nothing to buy.

For learners One mentoring class

Sit in on a real one-to-one session with a mentor. You'll leave with an honest read on where you are and what to do next, whether or not you carry on.

For companies Free consultation

An hour with us about your company's security. We'll tell you what we'd look at first and what it would take. No obligation to go further.

Everything beyond these is quoted first, so you always know the price before anything starts.

Training

A certificate proves you passed a test. We teach you to do the job.

The same hands-on material taught in a university classroom, run as real projects with real tools. You break something, you fix it, then you write it up the way a client would read it. Everything runs online, so it works wherever you are.

01
How attacks really happenNot theory. You run the attack, watch it work, then close the hole.
02
Defending networks and systemsBuild it, break it, harden it, prove it's fixed.
03
Writing and reviewing safe codeFind the bug in someone else's code before an attacker does.
04
AI and machine learning securityTricking models, poisoned training data, inputs designed to fool them.
05
Proving software correctFormal verification. Showing with maths that a system does what it claims. Almost nobody teaches this.
06
SupervisedStrong students help on live assessments, with every line reviewed before it goes out.
What it costs Hourly, so you only pay for what you use.
Start here

One-to-one mentoring

Career and technical guidance
$85per hour
First session free — then decide
  • A written plan built around one job title
  • Screen-shared sessions on what you’re stuck on
  • Message us between sessions
  • Portfolio, CV and interview practice
  • Security+, PenTest+, CySA+ preparation
Book your free session

Private instruction

Prepared material, labs and projects
$110per hour
  • Structured curriculum, not ad-hoc help
  • Hands-on labs you build and break
  • Project work you can show an employer
  • Written up the way a client would read it
Ask about availability

Open seminar

Career and technical guidance
Freerun regularly, open to anyone
  • One practical topic, taught properly
  • Live online, come and go as you like
  • Career questions answered openly
  • Nothing to buy, no pitch at the end
Save me a seat

Corporate training

Train your own staff
$1,200half day · $2,000 full day
  • Phishing and cyber hygiene
  • Safe use of AI tools at work
  • Secure coding and incident response
  • Delivered online; on site by arrangement
Ask for a quote

Every engagement starts with a free 30-minute call so we both know what you actually need. Where someone genuinely can’t pay, ask us — we keep a small number of assisted places.

Mentoring

The internet has every answer. It won't tell you which one is yours.

There's more security material online than anyone could finish in a lifetime, and that's the problem. People spend a year jumping between tutorials and end up with no direction and nothing to show for it. A mentor fixes that in a way a course never can.

Your first class is on us.

Before anyone pays for anything, we spend an hour together. We look at where you are, and you leave with an honest view of what to do next, whether or not you carry on with us. If it was useful, we'll talk about a plan and a price. No pressure either way.

Book your first class
01Start

We find out where you actually are

A real conversation, not a test. What you know already, what you've tried, how many hours a week you really have, and what's in the way. Money, visa, a full-time job, a family. A plan that ignores your life is no plan at all.

You leave with: an honest starting point
02Aim

You pick a job, not a subject

"I want to get into cybersecurity" isn't a goal. It's about nine different careers. We go through what each job looks like day to day, what it pays, and which one suits how you like to work. Then you choose one.

You leave with: one job title to aim at
03Plan

You get a written plan with dates on it

Which skills, in what order. Which resources are worth your time and which are noise. What to build. Roughly when you should be ready to apply. It changes as you go, but you're never sitting there wondering what's next.

You leave with: a plan you can actually see
04Work

One-to-one, every week

This is the part that makes the difference. Just you and your mentor, screen shared, working on whatever you're stuck on. Bring your errors, your half-finished lab, your bad code. You fix it together and you understand why it works. Between sessions, message us when you hit a wall.

You leave with: nobody letting you quietly fall behind
05Prove

You build things an employer can check

A certificate says you passed a test. A working project says you can do the job. You finish with a portfolio, a public write-up of your work, and if you're ready, supervised hours on a real client job.

You leave with: proof, not claims
06Land

We help with the last part

Your CV rewritten for the job you're going after. Practice interviews, including the technical ones. Which companies to approach, and how to write to a person instead of a job board. Introductions where we have them.

You leave with: applications that get answered
Security roles

Nine jobs hide behind the word "cybersecurity"

Most people start by picking a course. That's backwards. Pick the job first, then the skills follow on their own. Here's what the main roles actually involve, so you can tell which one sounds like your kind of day.

Security analystMost common way in

You watch alerts, work out which ones matter, and respond when something is real. Shift work in bigger companies. It suits people who are patient, curious and good at noticing when something is slightly off.

Penetration testerHardest to get first job

You break into systems legally and write up exactly how you did it. The report matters as much as the hack. It suits people who enjoy puzzles and don't mind writing. Almost nobody starts here — most come through analyst or development work first.

Cloud securityHighest demand right now

You lock down AWS and Azure environments and stop people leaving things open by accident. It suits anyone who likes systems and automation. If you want hired quickest, this is usually the answer.

AI and ML securityNew and wide open

You attack and defend models — prompt injection, poisoned data, inputs built to fool a system. Very few people can do this properly yet, which is exactly why it's worth learning now.

Compliance and riskOverlooked, pays well

Audits, frameworks, policy, evidence. Far less coding than people expect. It suits organised people who can talk to executives, and it's the easiest route in for anyone coming from law, finance or admin work.

Hardware and embeddedHardest to replace

Firmware, chips, control systems, verification. The steepest learning curve on this list and the smallest pool of people who can do it. Slow to enter, very hard to be made redundant from.

An honest word about AI and your career.

AI is genuinely taking over parts of this field — writing scripts, first-pass log review, drafting reports. What it doesn't do is decide what matters, take responsibility for a call, or walk into a room and explain a risk to a business owner. Those are the parts worth building a career on, and they're the parts we teach. If someone promises you a job title in twelve weeks, be careful. If someone helps you build things you can show people, listen.

Find your direction →
For business — where we start

Five questions about your company, answered first

Before you spend anything, we run five automated checks on what the internet already knows about your company and send you a two-page summary. Nothing to install, no sales call, and we never touch your systems.

01
Can someone send email pretending to be you?Three settings on your domain decide this. Most small companies fail here and never find out.
02
Are your staff passwords already for sale?We check leaked password databases for your company's email addresses. This is how most small firms get broken into.
03
What of yours is open to the internet?Old servers, test sites, admin pages and logins that were never meant to be public.
04
Is your website giving things away?Out-of-date software, missing protections, certificates about to expire.
05
Is AI creating new risk for you?Whether your team is likely pasting customer data into chatbots. Right now this is the fastest-growing leak in small business.

What you get back

A short report in plain English. For each thing we find: what it is, how bad it is, and what to do about it.

The ones you can fix yourself are marked clearly, and if nothing serious turns up we tell you that too.

This is the automated version. The full External Security Check ($750–$1,500) adds manual validation, subdomain and port discovery, a ranked remediation plan, and a 60-day re-check.

We only read public information. No scanning, no probing, no testing of your systems. Anything active needs your written permission first. That's the law, and it's also just the right way to work.
Consulting

Rent the expert. Skip the salary.

A full-time security hire costs six figures. Most companies under 50 people need a few days of the right attention, not a permanent chair. Nearly all of this work is done remotely, so where you are makes no difference to what it costs. Every price is a range because scope varies — you get a fixed number before any work starts.

We come back

Fix what we found and we re-test it free within 60 days. Most consultants hand over a report and disappear.

You get something to show

A dated, signed statement of exactly what was tested and closed — for your insurer, your customers, or a procurement form.

Every finding is verified by hand

No scanner output pasted into a template. If it’s in your report, we confirmed it and can show you why it matters.

Wherever you are

Almost everything we do runs remotely — read-only access, screen shares and video calls. No travel cost, no country limit.

Start here

External Security Check

$750 – $1,500

What an attacker sees before they touch anything.

  • Domains, subdomains and forgotten hosts
  • Exposed ports, services and admin pages
  • Email spoofing — SPF, DKIM, DMARC
  • Leaked staff credentials
  • TLS and certificate review
  • Every finding validated by hand
  • Ranked report with fixes
Fully remote · 60-day re-check & signed statement included Book a free consultation
Most complete

Small Business Security Assessment

$1,500 – $3,500

The full picture of how your company actually works.

  • Microsoft 365 or Google Workspace setup
  • MFA and admin account review
  • Devices, endpoints and backups
  • Who can access what, joiners and leavers
  • Vendor and third-party exposure
  • AI usage risk
  • Incident response readiness
  • Ranked risk report and 30/60/90-day roadmap
Remote · 60-day re-check & signed statement included Book a free consultation
Deadline driven

Cyber Insurance Readiness

$1,000 – $2,500

Stop guessing at the questions on your renewal form.

  • Your insurer’s questionnaire, line by line
  • MFA, endpoint, backup and email verified
  • Admin account review
  • Incident response and awareness check
  • Gap analysis against what they actually ask
  • Evidence pack ready to submit
Fully remote · signed statement of controls verified Book a free consultation
Cloud

Cloud & Microsoft 365 Review

$1,500 – $3,500

One environment, reviewed properly.

  • Identity, MFA and admin roles
  • Permissions and IAM
  • External sharing and public resources
  • Storage exposure
  • Logging and audit configuration
  • Stale and unused accounts
Fully remote · M365, Azure, AWS or Google Workspace Book a free consultation
Technical

Web Application & API Testing

From $2,500

Manual testing, not a scan with a logo on it.

  • Authentication and session security
  • Access control and IDOR
  • Input validation and injection
  • File upload and API security
  • Business logic testing
  • OWASP Top 10 coverage
  • Technical report plus executive summary
Fully remote · one retest after fixes included Book a free consultation
Specialist

AI, Firmware & Embedded

From $2,500

Where our research background applies directly.

  • Prompt injection and data exposure
  • System prompt leakage, unsafe output
  • OWASP LLM risks and AI usage policy
  • Firmware analysis and hardcoded secrets
  • Update mechanism and auth controls
  • Secure code review
  • Formal verification where appropriate
Remote · ship us the device for firmware work · from $3,500 Book a free consultation
Ongoing

Fractional Security Advisor

For companies that need a security lead, not a security hire. Run entirely remotely. Three-month minimum.

Essential$1,000/month

Monthly meeting, questions answered, risk register, roadmap

Growth$1,750/month

Adds quarterly external check, policy work, vendor questionnaires

Advanced$2,500/month

Adds incident response guidance, insurance renewal support, priority access

Book a free consultation

Also available: remediation and hardening from $500 — we fix what we found, not just report it. Executive home security review, $600, added to any business engagement. And audit preparation for SOC 2, HIPAA, PCI and CMMC.

On-site work is available where it genuinely helps, quoted separately, with travel and expenses agreed in advance and billed at cost. For anything touching your systems we work from read-only access and a signed authorisation letter naming exactly what we may test and when.

The team

Nobody is good at all of security. We don't pretend to be.

Security is far too broad for one person to cover well, and anyone who tells you otherwise is selling something. HackHop is a small group of practitioners working from different countries, each one deep in their own area rather than spread thin across all of it.

So your work goes to the person who does that thing for a living. You'll always know who is working on your job and why it's them, and everything is reviewed before it reaches you.

Formal verification & hardware security
Penetration testing
Cloud & infrastructure security
Detection & incident response
AI & machine learning security
Compliance, risk & audit
Founder

Who started this, and why

Dr. Fatema Islam Meem
Dr. Fatema Islam Meem Founder & Principal Security Consultant
Formal Verification System Security AI Security Penetration Testing SOC Analysis

Assume nothing.
Verify everything.

That's the rule I work by, and it comes from my research. Formal verification means proving that a system does what it says, instead of assuming it does. It's slower and harder than running a scanner, and it finds things a scanner never will.

Most security consulting works the other way: a firm sends a junior analyst with a tool, and you get back a report from a template. That isn't what happens here, and it isn't how we teach either.

I started HackHop for two reasons. The companies most likely to be hurt by an attack are usually the ones least able to pay for help. And a lot of capable people are watching AI change their careers and don't know what to learn next. Both problems have the same answer: real skills, taught properly, by people who actually do the work.

  • PhD in Computer Science
  • University & College instructor in cybersecurity and computer science
  • Certified career-technical instructor, State of Idaho
Careers

Work with us

HackHop is small and growing carefully. When we open a position, it gets posted here first.

Current openings None right now

When we do hire, we'll be looking for practitioners rather than generalists — people who go deep in one area and can explain it clearly to someone who isn't technical. Teaching ability counts here as much as technical skill, because everyone who works with us ends up doing some of both.

Likely first roles: penetration testing, cloud security, detection and response, and mentors who've actually worked the job they'd be teaching.

If that sounds like you and you'd rather not wait for a posting, send us your work — a write-up, a tool, a research paper, something you built. We read everything, and we'd rather meet good people early than advertise late.

Introduce yourself →
Get started

Tell us what you need

Training, mentoring, or a question about your company. Same form for all of it. Every message gets a reply within two working days.

Prefer email? Write to us directly at info@hackhop.com

We reply within two working days. Your details are only used to answer you — never sold, never added to a mailing list.