← Home
CYBERSECURITY

Pistachio Acquires Hugin.io to Launch Cybersecurity Compliance Platform

September 9, 2026 Priya Nair

How the Platform Tackles Human Risk in Real Time

Pistachio AS, a human risk management cybersecurity firm based in Norway, announced on September 2, 2026, that it has acquired Hugin Cybersecurity AS. The acquisition enables Pistachio to launch a new cybersecurity compliance platform aimed at helping organizations manage human-related security risks. The deal was finalized earlier this week and integrates Hugin’s risk assessment tools with Pistachio’s existing behavioral security solutions.

The combined platform will focus on identifying and mitigating insider threats, phishing susceptibility, and policy violations through continuous monitoring and employee behavior analytics. Pistachio says the move addresses growing demand for compliance-ready tools that align with frameworks like NIST, ISO 27001, and GDPR. By merging Hugin’s automated risk scoring with Pistachio’s training and simulation modules, the new system aims to reduce human error—a leading cause of data breaches—while providing auditable compliance reports.

Can Technology Really Change Employee Security Habits?

The platform uses AI-driven analytics to detect risky user behaviors such as credential sharing, unsafe data handling, and delayed response to security alerts. It then triggers targeted micro-training sessions or policy reminders based on individual risk profiles. According to Pistachio’s CEO, Ingrid Voss, „We’re shifting from annual training to continuous, personalized risk reduction.” Early pilots showed a 40% decrease in repeat policy violations among participating employees. The system also generates compliance dashboards for auditors, reducing manual reporting workload by up to 60%, the company claims.

While technology can detect and respond to risky behavior, lasting change depends on user engagement and organizational culture. Pistachio emphasizes that its platform avoids punitive measures, instead focusing on education and positive reinforcement. „We want employees to feel supported, not surveilled,” Voss added. The company plans to roll out the platform globally starting in Q1 2027, with initial focus on finance, healthcare, and critical infrastructure sectors. Long-term success will depend on adoption rates and measurable reductions in incident frequency tied to human factors.

What specific compliance frameworks does the new platform support? The platform is designed to help organizations meet requirements under NIST CSF, ISO 27001, GDPR, and SOC 2, with automated evidence collection and reporting features tailored to each standard.

Frequently Asked Questions

How does the system protect employee privacy while monitoring behavior? Pistachio states that all monitoring is anonymized at the individual level unless a policy violation is confirmed, and data is encrypted and stored in compliance with European data protection laws.

Will existing Pistachio customers need to replace their current tools? No, the new compliance platform is designed as an add-on to existing Pistachio licenses, allowing current customers to integrate it gradually without disruption.

Read full article on Tech Site News →