HomeFeatured“Code Red” Events: Learn Hands-on How to Deal With a Fintech Cybersecurity...

“Code Red” Events: Learn Hands-on How to Deal With a Fintech Cybersecurity Incident 

BCCS cluster helps high-risk industry professionals test their skills in hands-on crisis simulations.

Cyberattacks have become increasingly prolific and sophisticated. The fear of an attack is especially prominent for fintech founders, given their high value as targets. Against this backdrop, BCCS Cluster has started hosting “Code Red” crisis simulation workshops, giving participants first-hand experience of the pressure, trade-offs, and decision-making required when a cyber incident hits. 

BCCS is a globally operating fintech cluster based in Lithuania, aiming to help fintech companies build their supply chains, especially in cybersecurity and compliance. Most recently, the team brought “Code Red” to Baltic Fintech Days, where leaders from the entire Baltic region had the chance to flex their problem-solving muscles.  

Crisis risk goes company-wide

According to IBM’s annual Cost of a Data Breach report, the average cost of a breach in the financial sector is $5.56 billion, second only to the medical sector. 

AI is only making matters worse. CrowdStrike’s 2026 Global Threat Report says that 2024 saw “an 89% increase in the number of attacks by AI-enabled adversaries year-over-year.” Nation-sponsored attacks remained persistent in 2025, the same report says, with predictions that Russia, China, and the DPRK-nexus adversaries will continue their onslaught to further political aims. Those aims range from collecting military intelligence to amassing funds through cryptocurrency theft. 

Companies are only as strong as their weakest link. Whether the trigger is a cyber incident or an operational/reputational failure, the consequences rarely stay within one department. In organisations where all company processes are closely intertwined, having a coordinated response and a consistent narrative can determine whether the crisis is contained or detrimental to the company. 

“Each person involved must understand the steps they must take and how those steps affect other stakeholders”
Andrius Petkevičius,
Co-Founder and CEO of BCCS

The industry standard for preparing a coordinated response to an attack is called a Tabletop Exercise. Participants receive a role, and the organiser presents a fictitious situation that the participants must respond to. In Tabletop Exercises, participants discuss possible solutions instead of roleplaying them. The organiser then moves the incident forward, prompting participants to further explore how to respond to new developments. 

Code Red uses this format for all its events, and participation is open to all stakeholders in a cybersecurity incident, from IT to managers to marketing to legal to anyone else who must play a role in handling a breach. A breach isn’t only “IT’s problem.” The fallout includes public perception, damage control, regulatory reporting, and so on. Each person involved must understand the steps they must take and how those steps affect other stakeholders.

Andrius Petkevičius, Co-Founder and CEO of BCCS, says each event is different, and that much of the value lies in seeing how different group dynamics produce different outcomes. In the simulation, participants – ranging from CEOs and marketing experts to CISOs and lawyers – are grouped into teams with other professionals from their own fields, while the scenarios are specifically designed to test and challenge their expertise, experience, and ability to respond under pressure. This creates five parallel scenario tracks running simultaneously, each from a different professional perspective, requiring teams to continuously interact, exchange information, and piece together the missing parts of the puzzle in order to respond effectively. Because every group of participants brings a different mix of personalities, experience, and decision-making styles, no two simulations unfold in exactly the same way. “The way people react to situations depends very much on who’s involved,” says Andrius. “Given two different teams, you might have two completely different responses, but both serve as an excellent way to learn about cybersecurity.”

Fake crisis, real connections: A new way to network

According to organisers, the event also presents a unique way to network. 

“Instead of exchanging business cards and listening to a speaker, attendees have the opportunity to see others in action,” says Rūta Petkevičiūtė, event coordinator at BCCS. “They see how people think, how they communicate under pressure, how they prioritise information, and how they contribute when there’s no perfect answer. That creates a much more meaningful connection than a short conversation during a coffee break. In many ways, Code Red turns networking into shared problem-solving.”

Many of the attendees of the Code Red event in Riga agreed that it was a great way to connect. 

Alon Eliya Bigler, VP of International Business Development at Switchio, and one of the attendees at Code Red in Riga, said, “It’s a unique event format that makes professional networking and interaction much more interesting. It makes people work together in a team they’ve never met before, and solve problems under time pressure. This escape-room-style professional workshop is truly engaging, fun, and stimulating. There’s no better way to network professionally with people you’ve never met before.” 

BCCS is creating something extremely valuable: cross-department, multi-layered simulations where people can step into the shoes of CEOs, legal teams, compliance officers, marketing specialists, tech teams, and many others. It’s a safe environment where people can test both their good and bad patterns, reflect on decisions, understand pressure and learn how to cooperate before a real crisis arrives. 

“Modern-day problems require modern-day solutions,” said Kirill Lukin, Head of Commercial Operations at Magnetiq Bank, who also attended the Code Red event in Riga “I think most of us have heard this quote many times already. On one hand, modern problems are shaped by changing expectations around people, regulations and technology. On the other hand, many of these ‘new’ problems are still old human challenges wrapped in new layers of complexity and meaning. During my career, I noticed that both educational institutions and internal corporate development programs often underestimate practical group problem-solving and team dynamics. The problem is that efforts like these are difficult to scale through a single person. And this is exactly why experiences like Code Red Riga matter so much.”

Going beyond the Baltic market: Code Red goes international

BCCS started from a practical challenge that Andrius and his co-founder kept seeing while working with technology and regulated businesses: many client projects required multidisciplinary expertise that one company alone couldn’t credibly provide.

“We often had clients who needed support in areas adjacent to our own work, such as cybersecurity, compliance, legal, fintech infrastructure, product development, market knowledge, and similar fields,” says Andrius. “As a value-add partner, we wanted to recommend the right people, but those recommendations had to be based not only on skillset, but also on trust, culture fit, values and working style.”

Over time, this growing network of trusted partners led Andrius and his co-founder to the cluster model. “The cluster gave us a formal structure to support broader collaboration between companies, experts, institutions and communities,” says Andrius. 

Now, the team is taking it one step further, hoping to bring Code Red to experts beyond the Baltic market.

“I believe the real value of BCCS comes from bringing together people and companies whose combined knowledge, experience and networks create something bigger than each could achieve alone,” says Andrius. “Our long-term vision is to become a global, borderless platform where technology, fintech, cybersecurity and compliance professionals can connect across markets, share knowledge, find partners, meet potential clients and build new initiatives together. Code Red reflects this very well, because it creates a space where people build relationships through shared work, not just conversation.”

Each Code Red scenario is written and moderated by senior industry professionals with years of practical experience in their respective fields. The team behind the format brings together expertise in cybersecurity, fintech, compliance, ICT risk, business continuity, software development, communications and crisis management. This helps ensure that every simulation reflects real-world pressure, difficult trade-offs and the cross-functional nature of a crisis, where technical, regulatory, reputational and business decisions must come together quickly.

In the near future, Code Red will expand its presence in Lithuania with new events in Vilnius, including sessions open to the fintech community, at least one international event, and a dedicated simulation developed in collaboration with the Lithuanian Cyber-Competence Community of the National Cyber Security Centre. Together, these initiatives will strengthen both local and cross-border collaboration in crisis simulation and resilience building.

NFM Publishing Team
NFM Publishing Team
Got a Nordic fintech story to share? We're all ears! At NFM, we're all about embracing the latest trends, innovations, and industry buzz ? Send us your PR, news stories, or anything that's rocking the Nordic fintech scene at hey@nordicfintechmagazine.com. Let's amplify your voice and think bold together! ? Stay tuned for mind-blowing articles, exclusive interviews, and thought leadership that'll keep you on the edge of your seat. Join us as we shape the future of fintech in the Nordic region.