Oslo's AI security training firm picks up compliance tech to build an integrated SMB suite, leaving Hugin's 10-person team behind.
Key Takeaways
- Pistachio acquired Hugin Cybersecurity AS's technology only; financial terms were not disclosed and no staff will transfer.
- The combined platform targets SMBs needing both human-risk training and regulatory compliance tooling in one product.
- A formal product launch is planned for 2027, roughly 16 months after deal close.
Lead
Oslo-based Pistachio announced on September 2, 2026, the acquisition of Hugin.io, a Norwegian cyber-risk compliance platform, in a deal structured as a pure technology purchase with no staff transfer. The price was not disclosed. It is Pistachio's first acquisition since the company rebranded from CYBR in late 2023, and it marks a deliberate expansion from behavioral security training into the adjacent - and currently crowded - cybersecurity compliance market for small and mid-sized businesses.
What Did Pistachio Actually Buy?
Pistachio acquired Hugin Cybersecurity AS's intellectual property, not its people. Hugin employed 10 people as recently as March 2026 and had taken no disclosed outside funding since its founding in 2023. The deal is therefore not an acquihire; it is a straightforward technology transfer. Pistachio is betting that Hugin's software - built to help growing businesses assess, document, and demonstrate cybersecurity posture to auditors and regulators - complements its own platform without requiring the overhead of integrating a second team.
That distinction matters for how to read the transaction. Acquihires signal that the buyer values the people over the product. Technology buys signal the opposite: the code is the point, the cap table is settled cheaply, and the seller's team either joins another project or disperses. For Hugin's 10 employees, no position was offered.
Why Does Pistachio Want Compliance Tools?
Human-risk training - the core of Pistachio's business - addresses what happens before a breach: employees clicking phishing links, reusing passwords, bypassing controls. Compliance management addresses what happens alongside and after: proving to regulators, insurers, and enterprise procurement teams that controls exist and are monitored. The two problems are related but distinct, and SMBs typically buy them from different vendors, if they buy them at all.
Pistachio's pitch post-acquisition is that a single platform can handle both. The company's existing product already automates personalized security-awareness training and phishing simulations for more than 600 organizations across 16 countries. Adding Hugin's posture-and-compliance layer gives it a more complete argument for budget-constrained SMB buyers who cannot manage multiple point solutions.
European regulatory pressure makes the timing coherent. NIS2, DORA, and a growing stack of national cybersecurity requirements have created compliance obligations that many SMBs were ignoring a few years ago and can no longer afford to. Vendors that can bundle training with audit-ready documentation are better positioned to capture that demand than those selling half the problem.
Strategic Context
Pistachio closed a $7 million Series A in April 2025, led by Walter Ventures, with participation from Idékapital, Angel Invest, MP PENSJON PK, and J12 Ventures. The company reported a fourfold increase in annual recurring revenue between 2023 and 2024. Founders Joe Jones, Awais Aziz, and Jaan Kitchuk built the original CYBR platform before the rebrand.
Hugin.io was a lean, bootstrapped operation - founded the same year Pistachio completed its rebrand, never publicly funded, and small enough that its entire team fit in a single meeting room. From a deal structure perspective, acquiring its IP was likely far cheaper than building equivalent compliance tooling from scratch. Whether the Hugin technology is production-ready at the scale Pistachio serves, or whether it requires significant re-engineering before a 2027 launch, was not addressed publicly.
What Does the 2027 Timeline Signal?
The integrated platform is not scheduled to reach customers until sometime in 2027, at minimum a year after the acquisition closed. That window suggests the Hugin codebase requires material development work before it can run at Pistachio's scale or meet the UX standards of its existing product. A 12-to-18 month integration runway for a 10-person startup's IP is not unusual, but it does mean Pistachio is carrying the cost of the acquisition and development before seeing revenue from the new product line.
Competitors in the SMB compliance space - vendors offering frameworks like ISO 27001 or SOC 2 readiness tooling - are not standing still. The 2027 launch window gives them time to deepen existing customer relationships.
Outlook
Pistachio is making a logical bet: SMBs increasingly face compliance mandates alongside human-risk exposure, and bundling both into one platform should reduce sales friction. The technology purchase is a faster path to that bundle than a build-from-scratch effort. The 2027 launch timeline and the absence of an acquihire structure suggest the integration effort is non-trivial. Whether the compliance module arrives competitive and on schedule will determine whether this acquisition looks prescient or merely opportunistic.



