Oslo-based Pistachio acquires Hugin.io to expand into cybersecurity compliance
Pistachio, an Oslo-based AI-powered human risk platform, today announced its IP acquisition of Hugin.io, a Norwegian cyber-risk management platform that helps growing businesses assess, manage and demonstrate their cybersecurity posture and regulatory compliance.
With this acquisition, Pistachio aims to broaden its offering beyond human risk to compliance management, strengthening its proposition for SMBs and mid-market organisations. The financial terms of this deal were not disclosed.
Joe Jones, Pistachio CEO and co-founder, said, “Organisations are being asked to meet increasingly complex security requirements, but few have the resources to manage them. We built Pistachio around the idea that effective cybersecurity should not require constant effort from already stretched teams. Bringing Hugin’s technology into the platform is a natural next step, allowing us to extend that approach from human risk into compliance and help more organisations build resilience without adding another layer of complexity.”
Founded in 2023, Pistachio is a cybersecurity company building human risk management solutions for SMB and mid-market organisations. The company states that its platform automates security awareness training and insider threat detection, adapting to each employee’s role and behaviour.
In 2023, the company announced it had raised €3.25 million in a funding round led by Signals VC. The company currently helps organisations address social engineering and insider threats, two of the biggest human risk factors in cybersecurity. The acquisition of Hugin.io adds compliance management as the next capability on its platform.
Jørgen Færevaag, co-Founder and CEO, Hugin.io, said, “Cybersecurity is one of the most significant challenges for growing businesses. The issue is not simply knowing that requirements exist, but understanding what applies to your organisation, where the gaps are and what needs to be done to address them. Hugin’s technology makes that process simpler and more accessible. With Pistachio, the technology will reach a much larger customer base as part of a broader cybersecurity platform, putting know-how in the hands of those that need it most as they scale.”
The new product is set to officially launch in 2027 and encompasses a suite of capabilities designed to help organisations define, measure, and improve their security posture, along with tools for managing devices and applications. Pistachi notes that with these capabilities, the compliance product helps growing businesses stay continuously secure and audit-ready without the burden of manual certification work.
Once launched, the company will support organisations in meeting standards and regulations including ISO 27001, the international standard for information security management; NIS2, the EU directive strengthening cybersecurity requirements across critical sectors; SOC 2, a framework for demonstrating controls around security and data management; and DORA, the EU regulation establishing cybersecurity and operational resilience requirements for the financial sector.
According to Pistachio, compliance is becoming as much a business imperative as a legal one, especially with legislation such as the UK’s Cyber Security and Resilience Bill and the EU’s Cyber Resilience Act coming into force. Through its new offering, Pistachio’s aim is to automate that burden, helping smaller organisations build cyber resilience without requiring enterprise-level resources.
Headquartered in Oslo, with offices in London and Valencia, Pistachio recently surpassed 1,000 customers, predominantly across Europe.
Related Stories
Cybersecurity
‘Not perfectly aligned’ with human values: Anthropic admits security failures behind AI hacking incidents
7 hours ago
Cybersecurity
78% of South African SMBs encountered cybersecurity incidents over the past year, Kaspersky research shows
1 day ago
Cybersecurity
Doctor's appointment phone call led to data breach
2 days ago
Cybersecurity
'What do they have their hands on?' Customer reacts to Eastlink breach
3 days ago
Cybersecurity
UK’s small power plants face higher cyber risk into 2030s despite Iran
5 days ago
Cybersecurity
Chinese hackers disrupted U.S. Justice Department, NASA, Federal Reserve, U.S. says
6 days ago
Cybersecurity
Prince Harry and others to pay initial US$13m over failed invasion of privacy case
1 week ago
Cybersecurity
Prince Harry, Elton John and others slapped with millions in legal fees after court loss to Daily Mail
1 week ago