TryHackMe is inviting companies with incident response and SOC teams to apply for one of six complimentary Live Breach exercises: a simulated, three hour incident response exercise in TryHackMe’s environment, followed by a debrief.
At a Glance
- Six companies will be selected by a TryHackMe panel from eligible applications. This is an application and selection process, not a competition or a random draw. Companies are selected by the panel on the basis of the information in your application, applying the selection criteria set out in section 4.
- Open to all business incident response and SOC teams (excluding sanctioned entities). No purchase is necessary.
- Applications close at 23:59 Eastern Time (EDT) on 18 October 2026. Sessions run from late October to the end of January 2027.
- The exercise runs in TryHackMe’s environment and does not connect to or test your live systems.
1. About the Giveaway
The TryHackMe Live Breach Giveaway (the “Giveaway”) is an application and selection process run by TryHackMe Ltd (“TryHackMe”, “we” or “us”). Applications open at 00:00 Eastern Time (EDT) on 7 October 2026 and close at 23:59 Eastern Time (EDT) on 18 October 2026. By applying, you agree to these terms.
2. Who can apply
The Giveaway is for business incident response and SOC teams based. It is not open to consumers. You must be aged 18 or over, applying as part of your work for the company you name, and authorised to apply on its behalf. Your company must be willing and able to take part if selected. Existing TryHackMe customers are welcome to apply; customer status plays no part in selection.
Employees, officers and contractors of TryHackMe and its group companies, their immediate families and households, and anyone professionally involved in running the Giveaway cannot apply.
3. How to apply
Complete the application form on the Live Breach giveaway page. This is the only way to apply. There is no purchase or payment required, and one application is allowed per company. You can apply for your own team or nominate a colleague or manager as the main contact (subject to you securing consent from whoever’s details you provide).
The form will not accept email addresses from common free consumer email providers (for example Gmail, Outlook.com, Yahoo or similar); please apply using your business email address. If your company does not use business email addresses, contact us at support@tryhackme.com before applications close. The form asks for:
- first name;
- last name;
- business email address;
- job title;
- company name;
- a brief description of the size of your incident response team;
- whether your team currently uses TryHackMe;
- your TryHackMe username, if you have one; and
- are you interested in hearing more about our products and services even if you are not selected.
We may decline applications that are incomplete, duplicate, automated, fraudulent, ineligible or otherwise do not comply with these terms. We may also ask for reasonable evidence of identity, employment, authority and eligibility.
4. How we select companies
The Giveaway is an application and selection process. It is not a prize competition or a random draw, and the best answer or highest score does not determine who is selected. Selection is made by a TryHackMe panel on the basis of the information you provide in your application, applying the criteria below.
Selection. A TryHackMe panel will select six companies from eligible applications, based on the information you provide and considering:
- how relevant the exercise is to the team’s incident response or SOC role;
- whether the team is suited to a collaborative exercise for around 5 to 10 participants;
- whether the application gives us enough clear and accurate information to assess the team;
- whether the team can take part during the delivery period; and
- the likely learning value of the exercise for the team.
We may check eligibility and whether taking part is practical from an operational and security point of view, and may identify reserve companies using the same criteria. The panel’s decision is final, except in the case of manifest error. We are unable to provide individual feedback on applications.
5. What selected companies receive
Each of the six selected companies receives:
- a short preparation call with the TryHackMe team;
- one approximately three hour simulated Live Breach exercise, responding to a simulated AI driven attacker; and
- a debrief after the session.
The exercise is for the selected company’s incident response team and is designed for 5 to 10 people, with SOC colleagues welcome where relevant; larger groups may be agreed in advance. It takes place entirely in TryHackMe’s environment and does not connect to, access, test or integrate with your systems, network, data, credentials or production environment.
The Live Breach exercise is a simulated training activity. It is not penetration testing, live incident response or managed security services, professional security advice or certification, and it does not guarantee any security outcome. We may make reasonable changes to session timing, format, tooling or content for operational, technical, security or safety reasons.
6. If your company is selected
We will email selected companies between 19 and 23 October 2026 at the work email address on the application. To confirm your place, reply within seven working days confirming that your company accepts, is eligible and that you are authorised to arrange its participation. If a selected company does not respond in time, is ineligible, declines, cannot reasonably take part or cannot agree a session date by the completion deadline, we may offer the place to a reserve company.
We will then agree a session date with you. Sessions are expected to run from late October to mid November 2026 and must be completed by 31st of January 2027, unless we agree a reasonable extension. Before the session, we will ask your company to accept short participation terms covering practical arrangements such as scheduling, attendees, acceptable use, safe use of the simulation, confidentiality and technical requirements. There is no charge for the exercise.
7. Your information and publicity
We use the information you provide to run the Giveaway, assess applications, contact selected companies, contact applicants who expressly indicate they are interested in discussing our services even if they are not selected, prevent fraud and meet our legal obligations, as explained in our Privacy Notice (at https://tryhackme.com/legal/privacy-policy). Entering is not conditional on agreeing to marketing. Any direct marketing will only take place where permitted by law, and you can object or unsubscribe at any time.
We may use anonymised and aggregated learnings from the sessions in campaign content or a closing webinar, but never in a way that identifies a selected company or any individual. We will not use your company’s name, logo or trade marks, identify attendees, record a session, publish a case study or testimonial, or attribute any observation, finding or learning to your company without your separate written consent. Saying no will not affect your place in the Giveaway.
8. Other important terms
The Giveaway is not open to organisations on the UK Sanctions list (https://search-uk-sanctions-list.service.gov.uk).
The Live Breach exercise has no cash alternative, is not transferable or refundable, and cannot be sold or exchanged. It does not include your own staff time, travel, accommodation, equipment, connectivity or other costs. If the advertised exercise cannot reasonably be provided for reasons outside our reasonable control, we may offer an alternative of reasonably equivalent value.
We may decline an application submitted using a personal or free webmail address where we cannot reasonably verify the applicant’s connection with the company named. We may disqualify an application or withdraw a place where we reasonably believe there has been fraud, cheating, manipulation, abusive conduct or a material breach of these terms. We may amend these terms, or suspend or cancel the Giveaway, only where reasonably necessary because of circumstances outside our reasonable control, a legal or regulatory requirement, or to protect the integrity or security of the Giveaway; any change will not unfairly and materially disadvantage applicants, will be published on this page and will be notified to any selected company it affects.
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited, including for death or personal injury caused by negligence, or for fraud. Subject to that, we are not responsible for applications lost or delayed by technical issues outside our reasonable control, or for delays caused by events outside our reasonable control; to the extent permitted by law, we are not liable for indirect or consequential loss, loss of profit, business interruption, loss of data or loss of goodwill; and our total liability in connection with the Giveaway and the exercise is limited to £1,000.
These terms are governed by the laws of England and Wales and subject to the exclusive jurisdiction of its courts, unless mandatory local law in your country provides otherwise. If any part is unenforceable, the rest continues to apply. If campaign material conflicts with these terms, these terms apply.
Promoter: TryHackMe Ltd, company number 11673275, registered office 128 City Road EC1V 2NX London United Kingdom. Contact: support@tryhackme.com