Pistachio Acquires Hugin.io IP for Compliance Expansion
  • News
  • Europe

Pistachio Acquires Hugin.io IP for Compliance Expansion

Oslo cybersecurity firm adds compliance capabilities for SMBs with 2027 product launch

9/2/2026
Ghita Khalfaoui
Back to News

Oslo-based Pistachio, an AI-powered human risk platform, has acquired the intellectual property of Hugin.io, a Norwegian cyber-risk management specialist that helps growing businesses assess, manage and demonstrate their cybersecurity posture. The transaction allows Pistachio to broaden its offering beyond human risk into compliance management, strengthening its proposition for small and mid-sized organisations. Financial terms of the deal were not disclosed, but the move signals a strategic expansion toward a more complete cybersecurity platform.


Strategic Expansion Beyond Human Risk

Pistachio was founded in 2023 and has built its platform around the principle that effective cybersecurity should not require constant effort from already stretched teams. Its technology automates personalised security awareness training and insider threat detection, adapting to each employee's role and behaviour to reduce social engineering and account compromise risks. By incorporating Hugin.io's capabilities, the company can now help customers define, measure and improve their security posture while addressing regulatory compliance more efficiently.

Leadership Views on a Natural Next Step

Joe Jones, Pistachio's chief executive and co-founder, said organisations are being asked to meet increasingly complex security requirements but few have the resources to manage them. He described the acquisition as a natural next step that extends Pistachio's approach from human risk into compliance without adding another layer of complexity. Hugin.io co-founder and chief executive Jørgen Færevaag added that the technology will reach a much larger customer base as part of a broader cybersecurity platform.

A Compliance Product Scheduled for 2027

The newly acquired technology is expected to form the basis of a compliance and posture management product that Pistachio plans to officially launch in 2027. The product will include a suite of capabilities designed to help organisations define, measure and improve their security posture, alongside tools for managing devices and applications. Pistachio says these capabilities will help growing businesses remain continuously secure and audit-ready without the burden of manual certification work.

Supporting Key Regulatory Standards

Once launched, the compliance product will support organisations in meeting standards and regulations including ISO 27001, the international standard for information security management, and NIS2, the EU directive strengthening cybersecurity requirements across critical sectors. It will also address SOC 2, a framework for demonstrating security and data management controls, and DORA, the EU regulation establishing cybersecurity and operational resilience requirements for finance. This coverage is intended to make regulatory alignment more accessible for smaller organisations without large compliance teams.

Regulatory Momentum and Company Traction

Compliance is increasingly becoming a business imperative as well as a legal one, especially with legislation such as the UK Cyber Security and Resilience Bill and the EU Cyber Resilience Act coming into force. Pistachio aims to automate that burden for smaller organisations that do not have enterprise-level resources. Headquartered in Oslo with offices in London and Valencia, the company recently surpassed 1,000 customers across Europe and previously raised €3.25 million in a funding round led by Signals VC.


The acquisition of Hugin.io's intellectual property positions Pistachio to address two connected challenges: reducing human risk and simplifying regulatory compliance. By embedding compliance tools into its existing platform, the company aims to help growing businesses build resilience without needing large security teams. With the new product scheduled for 2027, Pistachio is laying a clear foundation for a broader cybersecurity platform tailored to the realities of smaller organisations.