Summary
- Pistachio has acquired Hugin.io’s technology and intellectual property from its bankruptcy estate, rather than the operating company, staff, or customer contracts.
- The technology will underpin a compliance product planned for 2027 covering security posture and requirements including NIS2, DORA, ISO 27001, and SOC 2.
- The move takes Pistachio beyond security awareness and insider-risk tools towards software intended to reduce the administrative burden of cyber compliance.
European cybersecurity regulation is creating a software market around proving that controls exist as well as installing them, and Norwegian security company Pistachio is using the assets of a failed startup to expand into that growing compliance layer.
Pistachio has bought technology and intellectual property developed by Norwegian cyber-risk platform Hugin.io from its bankruptcy estate, with the assets set to form the basis of a compliance product scheduled for launch in 2027. The price has not been disclosed.
The transaction is narrower than a conventional company acquisition. Hugin’s employees, founders, customer contracts, and other operating assets are not moving to Pistachio, which has instead acquired the underlying technology after Hugin Cybersecurity entered bankruptcy in May.
That leaves Pistachio with software it can integrate into its existing platform without taking on the failed company itself, while giving it a route beyond the human-risk products around which its business has developed. Pistachio currently sells automated security-awareness training and insider-threat detection, largely to smaller and mid-market organisations without large security teams.
The Oslo-headquartered company says the Hugin technology will support a product intended to help organisations define and measure their security posture, identify gaps, manage devices and applications, and produce compliance evidence. Planned coverage includes ISO 27001, NIS2, SOC 2, and the EU’s Digital Operational Resilience Act.
Although those frameworks differ considerably in scope and legal status, they create a common operational burden for smaller businesses because security obligations increasingly have to be documented, monitored, assigned to people, and demonstrated to customers, auditors, insurers, regulators, or larger companies elsewhere in the supply chain.
Compliance is becoming a software workflow
Much of the cybersecurity market aimed at smaller companies has traditionally concentrated on prevention technologies, phishing training, endpoint protection, and managed detection, while governance remained comparatively manual. Policies sat in documents, evidence was assembled for an audit, and compliance work often became a periodic exercise rather than a continuously maintained view of security controls.
New regulation makes that model harder to sustain because cyber obligations are becoming more closely connected with management accountability, incident reporting, supplier oversight, and demonstrable risk management. The administrative work continues even when no attack has occurred, particularly where several standards or regulatory regimes apply to the same organisation.
NIS2 illustrates that shift. As Dutch implementation of the directive has already shown, organisations covered directly by the rules face requirements around cybersecurity risk management and reporting, while supply chain provisions can push evidence demands onto companies that are not themselves the primary regulated entity.
That creates room for vendors trying to convert questionnaires, evidence collection, control mapping, and remediation into repeatable software processes. Smaller technology suppliers can find themselves answering security requests from several enterprise customers while preparing for formal audits or determining whether new legislation applies to them.
Pistachio’s existing proposition is built around reducing security work that would otherwise sit with a lean IT team. Its training product adapts security-awareness material to individual employees, while its insider-risk system analyses account behaviour for potentially suspicious activity. The Hugin technology extends that automation argument from people and activity towards controls and compliance evidence.
The company has offices in Oslo, London, and Valencia, and says it has grown beyond the narrower security-training market in which it began. That expansion also explains why cyber vendors increasingly want to combine related functions inside one platform: customers without dedicated specialists are unlikely to welcome another standalone dashboard every time a new regulatory requirement appears.
Automation cannot decide what applies
Compliance software nevertheless has a more difficult job than digitising a checklist because frameworks such as NIS2 and DORA apply differently depending on sector, size, jurisdiction, service type, and the organisation’s role in a wider supply chain. A platform can organise evidence and identify missing controls, but determining the correct regulatory perimeter still requires reliable interpretation.
The planned product will therefore need to show where its conclusions come from, how requirements are mapped to an organisation, and how risk scores or recommended actions are calculated. Those questions become more important if software starts prioritising remediation automatically, because a simple score can conceal assumptions about which assets, threats, obligations, and evidence have been included.
There is also a commercial distinction between becoming audit-ready and actually satisfying an auditor or regulator. Certifications, standards, and legal obligations are not interchangeable, while evidence adequate for one customer or framework may not answer another organisation’s questions.
Even so, the volume of work around cyber assurance is likely to support further convergence between security tools and governance software. Regulations are increasing the number of organisations expected to understand their own security posture, while enterprise customers are placing more scrutiny on suppliers that connect to their systems or handle their data.
Pistachio’s purchase gives it technology with which to pursue that market without building the compliance layer entirely from scratch, although the product itself remains some distance from general availability. Hugin’s bankruptcy also provides a useful counterweight to the assumption that regulatory demand automatically produces a sustainable software business, because distribution, integration, and the cost of serving smaller customers still determine whether the economics work.
When Pistachio brings the product to market in 2027, its credibility will rest on whether it can reduce manual compliance work without disguising the judgement those frameworks still require. Buying Hugin’s code provides a technical starting point; turning it into dependable compliance infrastructure is a different commercial test.












