Skip to main content
BUSINESS • 10 min read

Enterprise cybersecurity training outcomes: what real security teams achieved

All it takes is a quick look at the news to realize that the cyber threat landscape no longer sorts neatly by organization size. Regional water utilities, small-town emergency dispatch centers, and multinational banks have all faced the same category of adversary in recent years, and the breach reports make clear that sophistication on the attacker side has not waited for defenders to catch up. For security leaders planning how their teams prepare, investing in training should be unquestioned. But with high stakes and no precious time to waste, it's imperative that the training model they use produces evidence of improvement. Not only are superficial completion records not sufficient to prove impact, they're dangerous, obscuring long capability gaps until the next exercise.

The organizations below moved from ad hoc or annual training to a more continuous model built on regular practice, visible measurement, and tight feedback loops. Their outcomes vary in scale and scope, but the pattern is consistent: teams that practice frequently, measure what they find, and adjust before the next exercise produce operational changes that less frequent models tend to leave on the table.

TL;DR:

  • Security teams that move from annual exercises to continuous, measured practice tend to produce faster onboarding, shorter response times, and operational fixes that surface during exercises rather than during real incidents.
  • The outcomes range from SOC (security operations center) onboarding cut in half at Huntress to IR (incident response) playbooks rewritten mid-session at a financial services firm to DNS logging gaps fixed the same week at a UK utility. Across seven organizations including KPMG, ARAG, and DZ Bank, the evidence is operational: things changed in how teams work, not in how many modules they completed.
  • The common thread across all of them is a feedback loop: practice, measure, adjust, repeat. The organizations treating readiness as a continuous discipline are the ones producing evidence their leadership can reference.

What outcomes should enterprise cybersecurity training actually produce?

Enterprise cybersecurity training should produce measurable changes in how a team performs security work, whether that means faster onboarding for new analysts, shorter investigation times, fewer unnecessary escalations, or gaps identified and remediated before an incident forces the issue.

Completion rates and hours logged are inputs to a training program. They are not outcomes. A team can show high completion rates across a curriculum and still struggle when a real incident requires unfamiliar triage, containment under pressure, or cross-team coordination. The gap between what analysts know in theory and what they can execute under operational conditions tends to become visible during live incidents or realistic exercises, and many security leaders describe recognizing that gap only after an event has already started.

The outcomes that go beyond surface-level measuring fall into a handful of categories: how quickly new hires reach operational readiness, whether exercises surface gaps the team acts on, how regularly a team practices and what changes between sessions, and whether leadership has evidence of capability they can reference for budget, compliance, or board-level reporting. The sections below cover each of these with evidence from named organizations and attributed practitioners.

How long should SOC analyst onboarding take?

Huntress, a cybersecurity company with a growing SOC Support team, reduced new analyst onboarding from approximately 90 days to approximately 45 days and saved roughly $69,000 in onboarding costs across 10 analysts by replacing manually built, manager-led training with a structured, phased program delivered through TryHackMe.

Before the change, onboarding was time-intensive and dependent on individual managers. The SOC Support Manager spent significant hours each week building and maintaining custom training material, and new hires relied heavily on shadowing and ad hoc guidance to reach operational readiness. After moving to a structured program with role-aligned learning paths and automated progress tracking, the team saw measurable improvements across five dimensions.

Metric Before After
Onboarding duration ~90 days ~45 days (50% reduction)
Onboarding cost per hire ~$13,850 (based on SOC Support Specialist salary) ~$6,900 per hire. With 10 analysts onboarded, total savings of ~$69,000
Average reporting time Baseline 77% reduction
Training scalability Manager-developed, time-intensive Centralized platform with automated assignments
Engagement Ad hoc training with varying adoption High engagement; SOC Simulator widely praised

Tyler Benson, SOC Support Manager at Huntress, described the change: "TryHackMe has completely transformed how we onboard and train our SOC Support team. What used to take three months now takes six weeks, thanks to a streamlined and engaging training process. The platform is fun, hands-on, and has given my team the confidence and skills they need to protect our customers. From day one, new hires are building foundational knowledge, and as a manager, the ability to assign and track progress is invaluable."

The full Huntress case study covers the program in detail. Huntress built its onboarding around TryHackMe's SOC Level 1 path, the same structured route many organizations use as a foundation for new analyst ramp-up.

How do training exercises surface real cyber security gaps?

Exercises surface real gaps when they are realistic enough to expose the same failures a live incident would, and when the team acts on what they find immediately rather than filing it in a report that sits untouched until the next annual review.

A SOC Director at a UK water utilities company described one such outcome: "TryHackMe surfaced a real gap for us: our DNS logging wasn't where it needed to be, and we actioned changes to SIEM (security information and event management) ingestion right after. The exercise felt realistic, sparked cross-team collaboration, and the post-exercise report made prioritisation obvious."

A SOC Manager at a financial services firm reported a similar pattern: an escalation gap became visible during a tabletop exercise, and the team updated their IR playbook during the session itself.

In both cases, the gap was specific and actionable: DNS logging coverage in one, escalation procedures in the other. And the fix happened during or immediately after the exercise, with no real lag time. Exercises that produce this kind of immediate operational change tend to require two things: enough realism that the team's actual procedures are tested rather than an idealized version, and a post-exercise report that translates findings into prioritized next steps.

Both teams ran their exercises through TryHackMe's tabletop exercise product, which generates scenario-specific reports with prioritized recommendations after each session. Between team exercises, individual analysts practiced triage and investigation against realistic alert queues in the SOC Simulator.

What does it look like when training becomes a quarterly discipline?

When training moves from a one-off annual event to a quarterly cadence, outcomes tend to compound. Each exercise builds on findings from the previous one, and the team develops a rhythm of practice, measurement, and adjustment that a single yearly session tends not to produce.

A SOC Manager at a financial services firm described how a first tabletop session turned into a standing program: "We spun up an exercise in minutes and it immediately drove productive debate. We updated our IR playbook during the session after identifying an escalation gap. The scenarios kept analysts engaged, and the report turned decisions into clear next steps, so we've added TryHackMe's tabletop exercises to our quarterly training cadence."

A Senior Incident Detection Analyst at an automotive enterprise reported a similar trajectory: "Our teams found the exercises highly engaging and easy to run. Setup and onboarding were quick, the learning curve was minimal, and everyone got it fast. It was so well received that we're building TryHackMe's tabletop exercise into our quarterly training plan immediately. The reporting and scoring also make improvements obvious."

The shift from annual to quarterly was possible in both cases because the exercises did not require months of preparation. Many security leaders describe the traditional model of tabletop exercises as resource-intensive: weeks of planning, facilitation by senior staff, and a long turnaround on findings. The teams above moved to quarterly cadence because the exercises could be set up in minutes and the post-exercise reports were generated immediately, lowering the barrier to running them regularly enough for findings to compound. TryHackMe's SOC Readiness Calendar maps out what that cadence looks like in practice, from weekly individual practice through monthly team simulations to quarterly validation exercises.

How do security leaders measure and prove training outcomes?

The security leaders producing the clearest outcomes tend to measure capability through a combination of platform analytics, exercise results, and operational performance data, then use those measurements to build the case for continued investment.

Aleksandra Dubovik at ARAG described the measurement approach directly: "TryHackMe helps us quantify the knowledge level on defined subjects. We assign a path; once it's completed, we know what the learner knows."

At Travelperk, the emphasis was on visibility across mixed skill levels: "Team progress is easily trackable... employees can be walked through complex themes rather than dropped in the deep end."

The measurement challenge for many security leaders is not collecting data. It is translating that data into evidence a CISO (chief information security officer) or CFO can act on. The Huntress case study is an example of what that evidence looks like in practice: before-and-after metrics across onboarding duration, cost per hire, and reporting time give a budget holder specific numbers to reference. ARAG's approach, assigning structured paths and verifying completion, produces a different kind of evidence, one focused on verified capability rather than cost savings. Both organizations used TryHackMe's Management Dashboard to surface this data without manual aggregation, tracking team and individual progress alongside metrics such as mean time to respond and average dwell time.

How are teams in financial services and critical infrastructure using cyber security training?

Financial services and critical infrastructure teams tend to use hands-on training for two connected purposes: giving SOC and CSIRT (computer security incident response team) staff practice with sector-relevant scenarios, and building the kind of documented evidence of readiness that regulators and insurers increasingly expect.

A Cyber Security Manager and Training Supervisor at DZ Bank described both angles: "TryHackMe has helped us in gaining flexibility, technical knowledge and soft skills. The scenarios were interesting and useful for us as they were in the finance sector as well. I am planning to run these regularly with the CSIRT."

The financial services SOC Manager whose team updated their IR playbook during a tabletop session, referenced earlier, reinforces the pattern. Finance-sector teams tend to face particular scrutiny around incident response procedures, and an exercise that produces a documented playbook change is a more defensible compliance artifact than a certificate of attendance.

The same mechanism applies at different scales. A regional utility and a global financial services firm both surfaced real operational gaps through exercises and acted on them within the same week. The exercises did not require enterprise-scale budgets or dedicated exercise designers. What made them productive was regularity and realism, not size. TryHackMe is used across financial services and government teams for this reason: the exercises reflect the needs of the sector, and the evidence they produce holds up to the scrutiny those sectors require.

What makes cybersecurity training programs produce measurable results?

Every outcome described above came from a team that practiced regularly, measured what happened, and acted on findings before the next incident arrived. Huntress measured onboarding speed and cost. The UK water utilities SOC Director measured DNS logging coverage and fixed it. The financial services SOC Manager measured escalation procedures and updated the playbook. ARAG measured knowledge levels through structured path completion. DZ Bank measured readiness through sector-specific CSIRT exercises. KPMG demonstrated adoption at scale, with more than 40,000 training labs completed in four months and 100% reported satisfaction across participating analysts. SS&C Technology endorsed the practical realism of the training environment as the mechanism that made it transfer to real work.

The pattern across all of them is a feedback loop: practice, measure, adjust, repeat. Readiness is not something these teams purchased once a year. It is a continuous discipline, and the evidence above is what that discipline produces when it is sustained over time.

For teams looking to build a structured cybersecurity training program, the outcomes here show what becomes measurable once the program is in place.

Use case Organization Outcome
SOC onboarding Huntress (Tyler Benson, SOC Support Manager) Onboarding reduced from ~90 to ~45 days; ~$69,000 in cost savings across 10 analysts; 77% faster reporting
Gap identification UK water utilities company (SOC Director) DNS logging gap surfaced; SIEM ingestion changes actioned within the week
IR playbook improvement Financial services firm (SOC Manager) IR playbook updated during tabletop session; exercises added to quarterly cadence
Quarterly readiness Automotive enterprise (Senior Incident Detection Analyst) Tabletop exercises built into quarterly training plan; reporting makes improvement visible
Capability measurement ARAG (Aleksandra Dubovik) Structured path assignments with verified completion; quantified knowledge levels
Sector-specific exercises DZ Bank (Cyber Security Manager) Finance-sector scenarios used for CSIRT training; exercises planned as a regular cadence
Hands-on adoption at scale KPMG 40,000+ training labs completed in four months; 100% reported satisfaction

FAQ

What outcomes should enterprise cybersecurity training produce?

Enterprise cybersecurity training should produce measurable operational improvements: faster onboarding for new analysts, shorter investigation and response times, security gaps identified and remediated through exercises, and capability evidence visible to leadership. Completion rates and hours logged are program inputs. The outcomes that tend to matter for budget decisions are before-and-after comparisons a security leader can put in front of a CISO or CFO: onboarding cost per analyst, time to operational readiness, or documented playbook changes resulting from exercises.

How do you measure cybersecurity training ROI?

Measuring cybersecurity training ROI typically involves comparing operational metrics before and after implementation: onboarding duration, escalation rates, exercise performance scores, and time-to-triage. Huntress measured onboarding cost per analyst and found a 50% reduction after implementing structured training through TryHackMe, saving approximately $69,000 across 10 analysts. The measurement mechanism matters as much as the training itself: automated dashboards that surface progress and performance data tend to produce stronger evidence than manual spreadsheet tracking.

How often should a security team run training exercises?

Quarterly is the cadence several teams in different sectors have adopted after finding that annual exercises leave too long a gap between identifying a finding and acting on it. The value of quarterly exercises is that each session builds on findings from the last, turning isolated events into a compounding feedback loop. The shift from annual to quarterly tends to become practical when exercises can be set up in minutes rather than requiring weeks of facilitation planning.

Can small or midsized teams produce the same training outcomes as enterprise SOCs?

The underlying mechanism is the same regardless of team size: practice regularly, measure what happens, and adjust before the next exercise. A regional utility SOC Director and a global financial services SOC Manager both surfaced real operational gaps through exercises and acted on them the same week. What makes continuous readiness accessible to smaller teams is tooling that does not require months of preparation, dedicated exercise designers, or a large per-exercise budget.

Where can a security team start building continuous training outcomes?

Start with one structured exercise and measure what it surfaces. A tabletop exercise that produces a finding the team acts on within the same week is more valuable than a year-long training plan that has not yet produced a measurable change. TryHackMe's SOC Simulatortabletop exercises, and role-mapped learning paths are designed around this feedback-loop model, with the Management Dashboard providing the visibility layer that makes outcomes reportable to leadership. The SOC Readiness Calendar provides a workbook for planning that cadence across weekly, monthly, quarterly, and annual activities.

Details on team-level training, simulation products, and enterprise pricing are available at TryHackMe for Business.

authorJoanna Duffy
Aug 10, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe