Pistachio acquires Hugin.io to launch cybersecurity compliance platform
Pistachio acquires Hugin Cybersecurity, planning a compliance and posture management service for SMBs.
Founded in 2023, Pistachio builds human risk management products for the SMB market, seeking to reduce the chance that employees, contractors, compromised accounts or other human-controlled assets become the entry point for an attack. The platform automates personalized security-awareness training and phishing attack simulations rather than relying on annual generic compliance courses. Phishing refers to emails, text messages or phone calls designed to trick employees into revealing sensitive information such as credentials, passwords or account details.
Hugin, the acquired company, specializes in cyber-risk management and helps growing businesses assess, manage and demonstrate their cybersecurity posture and regulatory compliance. Pistachio said the technology will be combined with its own platform to launch the new service in 2027, adding tools to define, measure and improve security posture, manage devices and applications, and lay the foundation for an ambient compliance product intended to keep companies secure and audit-ready.
Pistachio co-founder and Chief Executive Joe Jones said the company built its platform on the idea that effective cybersecurity should not require constant effort from already stretched teams. “Bringing Hugin’s technology into the platform is a natural next step,” Jones said in a statement, “allowing us to extend that approach from human risk into compliance and help more organizations build resilience without adding another layer of complexity.”
The combined offering is planned to help organizations comply with ISO 27001, an international information security management standard; NIS2, the European Union directive for cybersecurity in critical sectors; SOC 2, a framework for security and data management; and DORA, an EU regulation on cybersecurity and operational resilience. Pistachio noted that legislation such as the U.K.'s Cybersecurity and Resilience Bill and the EU's Cyber Resilience Act is making compliance an increasingly heavy burden for growing companies.
Hugin co-founder and Chief Executive Jørgen Færevaag said cybersecurity is one of the most significant challenges for growing businesses. “The issue is not simply knowing that requirements exist,” Færevaag said, “but understanding what applies to your organization, where the gaps are and what needs to be done to address them.”