Pistachio Acquires Hugin.io, Pushing Beyond Phishing Training Into Cybersecurity Compliance
Editorial Team

Pistachio
Image credit: Pistachio
Pistachio, an Oslo‑based human risk management cybersecurity firm, has acquired Hugin Cybersecurity AS, a Norwegian cyber‑risk management platform, to launch a new compliance and security posture management service.
Founded in 2023, Pistachio builds what the industry calls human risk management solutions, aimed specifically at the small and medium‑sized business market. Rather than relying on the annual, generic compliance training courses that have long been standard across the industry, Pistachio's platform automates personalized security‑awareness training and phishing attack simulations tailored to individual employee behavior and risk levels. The company's core mission centers on reducing the chances that employees, contractors, or other human‑controlled assets, including compromised accounts, become the entry point for a cyberattack, addressing phishing and social engineering, two of the most common vectors through which attackers gain initial access to corporate networks.
Hugin.io brings a complementary but distinct capability to that mission. The company focuses on cyber‑risk management, helping growing businesses assess, manage, and demonstrate their cybersecurity posture and regulatory compliance, a layer of the security stack that sits downstream of preventing individual human errors and instead addresses the broader question of whether an organization can prove, to regulators, customers, or partners, that its overall security practices meet required standards. Financial terms of the acquisition were not disclosed.
Pistachio co‑founder and chief executive Joe Jones framed the deal as a natural extension of the company's existing philosophy rather than a departure from it. "We built Pistachio around the idea that effective cybersecurity should not require constant effort from already stretched teams," Jones said. "Bringing Hugin's technology into the platform is a natural next step, allowing us to extend that approach from human risk into compliance and help more organizations build resilience without adding another layer of complexity." That framing speaks directly to a persistent tension many smaller organizations face: security and compliance requirements have grown steadily more complex, while the internal teams responsible for managing them have not grown proportionally larger.
Hugin.io co‑founder and chief executive Jørgen Færevaag echoed that same diagnosis of the underlying problem from his side of the business. "Cybersecurity is one of the most significant challenges for growing businesses," Færevaag said. "The issue is not simply knowing that requirements exist, but understanding how to meet them efficiently without a dedicated compliance team." That gap, between awareness of regulatory obligations and the practical capacity to satisfy them, is precisely what the combined Pistachio‑Hugin platform is designed to close.
The newly combined compliance and posture management service is set to officially launch in 2027 and will encompass a suite of tools designed to help organizations define, measure, and improve their security posture over time, rather than treating compliance as a one‑time audit exercise. Pistachio intends to support organizations in meeting industry‑standard regulatory requirements as part of that offering, positioning the combined platform to serve customers who need to demonstrate compliance to external parties, whether regulators, insurers, enterprise customers conducting vendor security reviews, or other stakeholders increasingly demanding documented proof of adequate cybersecurity practices.
Pistachio has built meaningful scale since its founding, raising a total of 10.6 million dollars across two funding rounds, including a 2023 raise led by Signals VC, and growing to roughly 126 employees. The company has positioned itself within a security awareness and training market that includes competitors such as Conscio Technologies, Picnic, and Havoc Shield, differentiating itself through its emphasis on continuous, behavior‑adapted training rather than static, one‑size‑fits‑all content that Pistachio has argued rarely translates into meaningfully changed employee behavior in real‑world situations.
The acquisition reflects a broader pattern taking shape across the cybersecurity industry, where vendors that built their initial products around a single, well‑defined problem, in Pistachio's case, human‑driven security risk, are increasingly expanding into adjacent categories through acquisition rather than solely through internal product development. That approach lets a company like Pistachio add genuinely new capabilities, in this case cyber‑risk assessment and compliance demonstration, without needing to build that expertise entirely from scratch, while giving Hugin.io's technology a larger distribution channel through Pistachio's existing SMB and mid‑market customer base. Whether the combined platform, launching a full year from now in 2027, can integrate Hugin's compliance and posture management tools as seamlessly into Pistachio's existing workflow‑embedded product as the company's messaging suggests will likely become clearer only once the unified service reaches customers.
Topics
Stay informed
Startup news in your inbox
Get important funding rounds, founder stories, and startup updates.
No spam - only important startup updates.





