How a Norwegian Startup's Acquisition Could Simplify Cybersecurity for Growing Businesses

·
Listen to this article~4 min

Oslo's Pistachio acquires Hugin.io, aiming to merge human risk management with automated compliance for SMBs. The move signals a shift toward consolidated cybersecurity platforms ahead of major new EU and UK regulations.

If you're running a growing business in Europe or the U.S., you know the feeling. The cybersecurity regulations keep piling up—ISO 27001, NIS2, SOC 2, DORA—it’s a whole alphabet soup of compliance. And your team? They're stretched thin just keeping the lights on. Well, there's a move happening in Oslo that might just change the game for SMBs and mid-market organizations. Pistachio, an AI-powered human risk platform, just acquired Hugin.io, a Norwegian cyber-risk management specialist. They didn't disclose the price tag, but the strategy is clear. It's about building a one-stop shop for cybersecurity that doesn't require an army of experts to manage. ### The Vision Behind the Deal Joe Jones, Pistachio's CEO, put it simply. "Organizations are being asked to meet increasingly complex security requirements, but few have the resources," he said. Think about that for a second. It's the core pain point for every scaling company. You're expected to have enterprise-level security on a startup budget. Pistachio was built on the idea that security shouldn't demand constant effort from your already busy team. They started by automating security awareness training and insider threat detection. Now, with Hugin's tech, they're pushing into full-blown compliance management. It's a natural extension, really. They're taking the same 'set it and forget it' philosophy from human risk and applying it to the regulatory maze. ### What This Means for Your Business Here's where it gets interesting. The combined platform, set to launch in 2027, aims to automate the grueling work of staying audit-ready. We're talking about: - Defining and measuring your security posture continuously - Managing devices and applications from a single pane of glass - Drastically reducing manual certification work The goal is to let you build cyber resilience without needing the deep pockets of a Fortune 500 company. Jørgen Færevaag, Hugin.io's CEO, nailed the problem. "The issue isn't knowing requirements exist," he noted. "It's understanding what applies to you, where your gaps are, and what to do about them." ### The Regulatory Tsunami Let's be real—compliance is no longer just a legal checkbox. It's a business imperative. With the EU's Cyber Resilience Act and the UK's new Cyber Security and Resilience Bill coming down the pipeline, the pressure is only intensifying. These aren't minor updates; they're foundational shifts in how digital products and services must be secured. Pistachio's new offering wants to be your automated shield against this complexity. They plan to support all the major frameworks, creating a unified system that grows with you. ### A Sign of Things to Come Headquartered in Oslo with offices in London and Valencia, Pistachio recently passed 1,000 customers, mostly in Europe. This acquisition feels like a strategic pivot, a recognition that human risk and compliance are two sides of the same coin. You can't have one without the other and call yourself secure. For U.S. professionals watching the European startup scene, this deal is a signal. It shows where the market is heading: toward consolidated, automated platforms that make enterprise-grade security accessible. It’s about democratizing the tools that were once reserved for the giants. So, keep an eye on this space. If Pistachio can successfully weave human risk and compliance into a seamless experience, they might just solve one of the biggest headaches for growing businesses on both sides of the Atlantic. And honestly, who couldn't use a little less complexity in their life?