Payments down – cyber simulation, done?

Friday morning at a fintech. Payments have stopped. Customers are firing off messages demanding to know where their money is. A business partner wants an answer that does not yet exist. The cause of the incident is unclear.
The clock is now the measure of the team’s performance. One group hunts for the technical fault. Another drafts answers to the questions lawmakers and regulators are bound to ask. A third wonders what on earth to tell customers.
And the leadership?
A technical anomaly swiftly turns into a compliance problem, a threat to trust, and a customer crisis. Matters slip out of hand because information is scattered, because the silos read the situation differently, and because nobody is quite sure who is authorised to decide what.
The pressure falls not only on technology but on the business itself. The remedy is cyber preparedness of a reputational sort, delivered through a cyber-crisis simulation.
What does one need to know?
Trust, the ultimate business lubricant
Paul Zak, a neuroscientist, argued in the Harvard Business Review in July 2019 that trust is what makes commerce possible. Without it, most transactions would never take place.
It is a dangerous fallacy to imagine that trust in fintech is built solely on regulatory compliance, transactional security or customer experience. Those matter, but only up to a point.
Trust is not measured in regulatory filings or marketing slides. The test comes when the attack lands and the systems fall over; when action is required, but certainty has been replaced by the chilling sense of not knowing.
Finland’s Vastaamo affair remains an uncomfortable case study. Hackers ransomed a psychotherapy clinic, leaked patients’ private notes online and set off a national scandal and a global manhunt. Vastaamo was declared bankrupt by the Helsinki District Court in February 2021. Poor cyber preparedness, compounded by the mishandling of a long-running issue, brought the business down.
Make the call while the weather is still fine
“The art of living is more like wrestling than dancing,” wrote Marcus Aurelius, “in that it stands ready for what comes and is not thrown by the unforeseen.” Almost two thousand years on, the counsel still holds.
Cyber simulations deserve to be seen in that light.
Their point is not merely to sharpen skills. It is to give the organisation a candid view of its wrestle-readiness, of how the team performs when things turn ugly.
The 2026 edition of Netprofile’s SABRE-winning Insight Track report finds that 85% of senior executives regard reputation as central to preparedness and resilience in their industry. It follows that simulations should be run regularly, ideally once a year, and they should bring together the business leadership, reputation, technology, and legal functions.
Together, they become a stronger wrestler, better able to manage a range of scenarios and protect both their reputation and their business in a way that matches stakeholder expectations.
Regulation leaves little room for manoeuvre
Cyber is now a serious legal liability issue. DORA, the regulation that governs digital operational resilience in financial services, has been directly applicable in Finland since January 2025. It covers not only banks and payment institutions but also crypto-asset providers and crowdfunding services.
Responsibility for managing ICT risk rests with the board, and significant incidents must be reported to the Financial Supervisory Authority within strict deadlines.
The Cyber Security Act, which implements the NIS2 directive in Finland, came into force in April 2025. Under it, the execution and oversight of cyber-risk management must be assigned to a party with sufficient expertise. The leadership carries personal responsibility, and lapses can attract fines of up to €10m.
A cyber simulation, in other words, is not a discretionary exercise. It is a means of demonstrating that the expertise and decision-making capacity required by law are actually in place when, on a Friday morning, the incident is real.
Not training but preparation
The value of a well-designed simulation is that, under a barrage of unexpected inputs, it exposes how the organisation truly makes decisions, or fails to. It reveals what authority means in practice, and whether the team can act as one at the moment of truth. The organisation’s well-meaning cyber-crisis governance model is put to test in the real world.
A cyber crisis is not merely a flashpoint of technology.
For a customer, a partner or a financier, what matters is not that the service is briefly unavailable. It is how the organisation conducts itself while putting the problem right.
Do stakeholders see the organisation demonstrating strength of character and capacity to act?
If the story cannot be told in a way that people understand, if the outward communication does not chime with the audience’s values, or if the response betrays panic, the ground beneath trust erodes quickly.
Cyber simulation is a profitable investment
A successful fintech needs to build trust. A significant part of that trust rests on the organisation’s ability, even in adversity, to show direction, reliability and clarity of thought.
History shows that well-run firms can endure reputational hits. Consider Apple’s “antennagate”. A troubled antenna and the fumbled communication around it drove the share price to a low of $6.80 in the summer of 2010. Had one placed €1,000 in the company then and held on, the position would be worth over €31,000 today, in July 2026.
Apple’s patient work on its reputation since the late 1970s is a story of its own, but the point stands: reputational capital compounds.
That capital is built before the frightening morning when payments stop.
Simulations are sometimes left undone because, done well, they require a modest investment. That outlay is trivial next to the damage of a mishandled cyber crisis.
Netprofile’s SABRE-winning work with Visma illustrates the return. The value of a cyber simulation became tangible only four months later, when one of the company’s products encountered a real incident closely resembling the one rehearsed.
The crisis was handled calmly, in a controlled manner and with stakeholder trust intact. Practice had converted into skill.
Should I act now?
A cyber-attack is not a matter of “if”. It is a matter of “when”. And when the “when” arrives, stakeholders will not weigh fine intentions and aspirations. They will look at what the organisation does.
The time to invest in operational readiness is now, not on a Friday morning.
Read also
AI 2026: From an Efficiency Pipeline to an Infrastructure of Power
Exceptional SABRE success – What’s the awards program all about?