Pistachio AS, a human risk management cybersecurity firm, has acquired Norwegian cyber-risk platform Hugin.io to develop a comprehensive cybersecurity compliance and posture management platform set to launch in 2027.
- Pistachio to launch integrated cybersecurity compliance and posture platform in 2027
- Platform targets SMBs with automated management of human risk and regulatory compliance
- Supports compliance with ISO 27001, NIS2, SOC 2, DORA, and emerging EU/UK regulations
Market signal
Pistachio’s acquisition of Hugin Cybersecurity AS signals a strategic shift towards providing end-to-end cybersecurity solutions for small and medium-sized enterprises (SMBs). By combining human risk management with compliance and security posture capabilities, Pistachio addresses a broader set of cybersecurity challenges faced by growing businesses globally. This reflects increasing market demand for integrated and user-friendly tools that reduce manual workload while improving resilience against cyber threats.
The upcoming platform will help organizations navigate the complexity of multiple regulatory frameworks including ISO 27001, the EU’s NIS2 directive, SOC 2 standards, and the Digital Operational Resilience Act (DORA). The focus on automation and ongoing risk management aligns with growing regulatory pressures in Europe and other regions, as businesses seek audit-ready, scalable solutions.
Operator impact
For cybersecurity operators and risk managers, the new platform promises to cut down the administrative burden often associated with compliance management and human risk mitigation. Automated personalized training and phishing simulations from Pistachio’s existing offering will now be complemented by tools that help assess and improve overall security posture, device and application management, and continuous compliance monitoring.
This integrated approach enables security teams—often limited in capacity—to prioritize actions based on real risk data and compliance gaps. Operators servicing SMBs can leverage the platform to deliver more holistic cyber risk services, potentially improving client retention and value by addressing evolving regulatory requirements without significantly increasing complexity.
What to watch next
The platform launch in 2027 will be a key milestone as Pistachio transitions from a niche human risk management provider to a broader cybersecurity compliance player. Market reaction from SMB buyers and channel partners will indicate the appetite for combined human risk and compliance services within one toolset.
Additionally, regulatory developments in Europe, including the UK’s Cybersecurity and Resilience Bill and the EU Cyber Resilience Act, will influence feature prioritization and urgency around compliance capabilities. Adoption trends may also reflect how SMBs respond to heightened cybersecurity mandates, and whether they seek integrated platforms to meet ongoing operational resilience and audit-readiness demands.