Mitigation strategy development translates the findings of the Risk Analysis and Review into practical measures to reduce the risk of disruption.
The existing controls, current risk ratings, and risk levels established during the RAR phase provide the baseline for deciding whether further treatment is required.
Additional mitigation should focus particularly on threats whose residual exposure remains High or Extreme after accounting for current controls.
The mitigation assessment distinguishes among four treatment approaches:
Existing controls should remain consistent with those recorded during the RAR phase, while risk ratings and levels should be carried forward without alteration.
Additional mitigation strategies are measures introduced above the existing control environment to reduce residual exposure.
Their selection should consider urgency, safety, cost, resource availability, technical feasibility, support requirements, and the expected benefit of the proposed control.
Because ALPS Healthcare’s verified control inventory and approved risk appetite were not provided, the controls below are treated as reasonable assumptions that require organisational validation.
The strategies are intended as implementation recommendations rather than statements that the measures are currently in place.
|
Threat |
Existing Controls |
Risk Rating |
Risk Level |
Risk Treatment (Residual Risk) |
Additional Mitigation Strategy |
Justification for Selected Mitigation Strategy |
|
Flood |
Weather alerts, drainage maintenance, remote working, alternate workplace, protected critical equipment and records |
12 |
High |
Risk Reduction and Transference |
Complete site-specific flood assessments; install water-entry barriers and leak sensors; relocate critical equipment above flood level; test remote-working activation annually; validate property and business interruption insurance. |
Physical protection and remote operation reduce both the likelihood of facility damage and the duration of denial of access. |
|
Flash Flood |
Weather monitoring, staff alerts, flexible working, alternate routes and remote access |
12 |
High |
Risk Reduction |
Map alternative access routes; establish trigger points for remote work; develop transport alternatives for essential personnel; integrate flash-flood alerts into incident notification. |
Flash floods develop quickly, so early warning and rapid relocation of work are more practical than attempting to eliminate the threat. |
|
Severe Storm |
Building maintenance, weather alerts, protected equipment, remote work and supplier notification |
16 |
High |
Risk Reduction and Transference |
Strengthen roof, drainage and window inspections; confirm telecommunications and power redundancy; pre-position critical supplies; test severe-weather continuity annually. |
The strategy protects facilities and sustains operations where weather affects utilities, transport and supplier services simultaneously. |
|
Lightning |
Lightning conductors, surge suppression, UPS, grounding, backup power and data backups |
16 |
High |
Risk Reduction and Transference |
Commission periodic electrical protection testing; install surge monitoring on critical circuits; verify UPS runtime; conduct recovery testing following simulated power surges. |
Electrical testing and recovery validation address the primary risk to ICT, warehouse and building systems. |
|
Earthquake—Regional |
Supplier diversification, safety stock, logistics alternatives, emergency sourcing and regional monitoring |
10 |
High |
Risk Reduction and Transference |
Identify suppliers and transport hubs exposed to regional seismic events; qualify geographically separate suppliers; increase buffers for irreplaceable products; secure alternate freight routes. |
ALPS cannot prevent regional earthquakes, but geographic diversification reduces interruption to imported healthcare supplies. |
|
Haze |
Air-quality monitoring, remote work, respiratory protection, indoor filtration and health advisories |
12 |
High |
Risk Reduction and Acceptance |
Define air-quality activation thresholds; upgrade filtration at essential sites; maintain suitable masks; reduce outdoor duties; test workforce continuity before seasonal haze periods. |
The measures protect employee health while maintaining critical procurement, warehousing and coordination activities. |
|
Extreme Heat |
Temperature monitoring, work-rest cycles, hydration, cold-chain alarms and equipment maintenance |
16 |
High |
Risk Reduction |
Conduct heat-stress assessments; establish mandatory work-rest regimes; improve warehouse cooling and monitoring; validate backup refrigeration and cold-chain contingency arrangements. |
Heat affects people and temperature-sensitive supplies, requiring combined workforce and infrastructure protection. |
|
Pandemic-related Movement Restrictions |
Remote work, split teams, digital workflows, delegated authority, health protocols and service prioritisation |
12 |
High |
Risk Reduction and Acceptance |
Scale remote-access capacity; identify essential on-site roles; maintain electronic approval capability; establish cross-border and local supplier contingencies; conduct annual pandemic exercises. |
Scalable remote operations enable essential procurement services to continue while complying with movement restrictions. |
|
Fire |
Detection, alarms, suppression, extinguishers, evacuation, fire wardens, drills, alternate workplace and data recovery |
15 |
High |
Risk Reduction and Transference |
Complete annual fire-control assurance; protect critical rooms through compartmentation; maintain off-site vital records; conduct denial-of-access recovery exercises; validate insurance coverage. |
Fire can threaten life, premises and information simultaneously, so preventive, life-safety, recovery and financial measures are required. |
|
Explosion |
Building safety controls, hazardous-material restrictions, evacuation, emergency liaison and alternate workplace |
10 |
High |
Risk Avoidance, Reduction and Transference |
Assess neighbouring industrial and gas hazards; remove unnecessary explosive or flammable materials; improve blast-zone evacuation arrangements; exercise full site relocation. |
Avoiding hazardous materials where possible and strengthening relocation reduces severe but infrequent consequences. |
|
Chemical Spill |
Chemical handling procedures, safety data sheets, PPE, spill kits, segregation and emergency response |
8 |
Moderate |
Risk Reduction and Transference |
Maintain a complete hazardous-material inventory; improve containment; contract specialist cleanup support; conduct periodic spill-response drills. |
Existing exposure is Moderate, but specific containment and external specialist support reduce safety and access consequences. |
|
Gas Leak |
Gas detectors, preventive maintenance, isolation valves, ventilation and evacuation |
8 |
Moderate |
Risk Avoidance and Reduction |
Remove unnecessary gas services; increase detector coverage; maintain calibration records; define shutdown responsibilities; test evacuation and re-entry procedures. |
Eliminating unnecessary gas use removes part of the exposure, while detection and isolation limit remaining consequences. |
|
Structural Failure |
Building inspections, defect reporting, landlord coordination, evacuation and alternate workplace |
10 |
High |
Risk Avoidance, Reduction and Transference |
Maintain a structural assurance register; set mandatory remediation deadlines; prohibit use of uncertified areas; pre-arrange temporary workspace; confirm landlord and insurer obligations. |
Unsafe premises should not remain occupied, making avoidance and timely relocation the preferred strategies. |
|
Bomb Threat |
Security procedures, access controls, suspicious-item reporting, evacuation and police liaison |
8 |
Moderate |
Risk Reduction |
Standardise bomb-threat call checklists; train reception and security personnel; improve staff accountability; conduct annual evacuation and communication exercises. |
The strategy strengthens rapid assessment and safe evacuation without disproportionate investment for an infrequent threat. |
|
Terrorism |
Physical security, CCTV, visitor control, national alert monitoring, crisis plans and alternate operations |
5 |
Moderate |
Risk Reduction, Transference and Acceptance |
Conduct site-specific hostile-threat assessments; strengthen protective security where justified; define shelter, lockdown and evacuation criteria; exercise inter-agency crisis coordination. |
Although likelihood is low, consequences may be severe, justifying scenario planning and proportionate physical protection. |
|
Active Assailant |
Access control, CCTV, security response, emergency notification, evacuation and employee assistance |
10 |
High |
Risk Reduction |
Develop active-assailant procedures; train employees in escape, concealment and reporting; improve emergency alerting; conduct security-led exercises; maintain trauma support. |
Personnel safety requires specific response guidance beyond general evacuation arrangements. |
|
Public Transport Disruption |
Remote work, flexible hours, alternate travel guidance and essential-role identification |
12 |
High |
Risk Reduction and Acceptance |
Establish transport assistance for essential staff; enable wider remote processing; maintain staggered shifts; identify backup personnel living near critical sites. |
Practical workforce mobility measures sustain minimum staffing during recurring transport disruption. |
|
Major Traffic Incident |
Route monitoring, delivery tracking, alternate routes, carrier escalation and priority delivery procedures |
12 |
High |
Risk Reduction and Transference |
Pre-plan alternate routes; contract backup carriers; define priority delivery categories; establish rapid communication with healthcare institutions; test route-diversion procedures. |
Multiple transport options reduce delays to urgent healthcare deliveries. |
|
Pandemic |
Pandemic plan, remote work, split teams, cross-training, health surveillance, communications and service prioritisation |
15 |
High |
Risk Reduction, Transference and Acceptance |
Maintain scalable remote operations; establish workforce reserve arrangements; cross-train essential roles; secure critical supply buffers; exercise prolonged absenteeism scenarios. |
Pandemic disruption affects personnel and suppliers over extended periods and requires sustainable rather than short-term recovery arrangements. |
|
Infectious Disease Outbreak |
Health reporting, cleaning, remote work, workplace distancing and incident escalation |
12 |
High |
Risk Reduction |
Develop site-specific outbreak procedures; maintain specialist cleaning contracts; define closure and reopening criteria; segregate essential teams; test local outbreak response. |
Localised containment prevents an outbreak from disabling multiple teams or facilities. |
|
Mass Illness |
Minimum staffing plans, cross-training, role deputies, remote access and temporary staffing |
12 |
High |
Risk Reduction and Transference |
Establish backup rosters; maintain a competency matrix; pre-arrange temporary or shared-service support; prioritise essential activities; test operations with significant absenteeism. |
The strategy sustains minimum service levels when many employees become unavailable simultaneously. |
|
High Staff Turnover |
Workforce planning, training, documented procedures, exit handover and recruitment processes |
16 |
High |
Risk Reduction and Transference |
Identify critical-role turnover thresholds; establish retention and succession plans; require structured handovers; maintain talent pipelines; use managed support for scarce roles where appropriate. |
Turnover creates cumulative loss of capability, so knowledge retention and workforce succession provide the most sustainable reduction. |
|
Loss of Key Personnel |
Deputies, succession plans, cross-training, delegated authority and shared records |
12 |
High |
Risk Reduction and Transference |
Identify all single-person dependencies; nominate two alternates for critical roles; test emergency delegation; document key decisions and procedures; establish external specialist support. |
Removing single-person dependency prevents one absence from stopping an essential function. |
|
Skills Shortage |
Training plans, recruitment, vendor support, procedural documentation and role backups |
16 |
High |
Risk Reduction and Transference |
Maintain a critical-skills register; establish minimum competency coverage; fund accelerated cross-training; develop graduate and specialist pipelines; contract external support for temporary gaps. |
Skills shortages are prolonged exposures best addressed through internal capability development supported by temporary external capacity. |
|
Workplace Violence |
Conduct policies, grievance channels, access controls, security response and employee assistance |
10 |
High |
Risk Avoidance and Reduction |
Establish a formal behavioural threat-assessment process; train managers to identify warning signs; restrict access where lawful and justified; exercise security response. |
Early identification and intervention can remove or reduce a developing threat before violence occurs. |
|
Staff Fatigue |
Rostering, rest periods, overtime approval, workload rotation and welfare monitoring |
16 |
High |
Risk Reduction |
Define maximum incident-working hours; maintain relief teams; automate shift tracking; require fatigue checks during prolonged incidents; rotate decision-makers. |
Fatigue is predictable during extended recovery and can be reduced through enforceable staffing and rest controls. |
|
Psychological Stress |
Employee assistance, manager support, counselling, welfare checks and debriefing |
16 |
High |
Risk Reduction and Transference |
Introduce crisis welfare protocols; train leaders in psychological first aid; provide confidential specialist support; monitor affected personnel after incidents. |
Early and sustained support reduces prolonged absence, impaired decision-making and post-incident harm. |
|
Mandatory Quarantine |
Remote access, team segregation, cross-training, digital approval and workforce communication |
12 |
High |
Risk Reduction and Acceptance |
Test remote access at scale; maintain quarantined-team deputies; enable remote approvals and secure document access; prepare alternate staffing for on-site functions. |
The strategy maintains essential activity when affected personnel cannot enter the workplace. |
|
Supplier Failure |
Due diligence, supplier monitoring, safety stock, alternate suppliers, contract remedies and escalation |
20 |
Extreme |
Risk Avoidance, Reduction and Transference |
Tier suppliers by criticality; diversify critical sources; obtain supplier BCM evidence; pre-qualify substitutes; increase strategic buffers; conduct joint continuity exercises; strengthen continuity clauses. |
Extreme exposure and healthcare supply implications require diversification, contractual assurance and tested alternatives. |
|
Outsourcing Failure |
Contracts, SLAs, governance reviews, audit rights, retained capability, continuity clauses and escalation |
15 |
High |
Risk Reduction and Transference |
Validate exit and transition plans; maintain minimum in-house capability; require recovery-test evidence; establish data portability; conduct joint outage exercises. |
Outsourcing does not transfer accountability, so ALPS must retain sufficient capability to manage provider failure. |
|
Cloud Service Provider Failure |
Provider SLAs, multi-zone services, backups, monitoring, vendor escalation and data export |
15 |
High |
Risk Avoidance, Reduction and Transference |
Assess concentration risk; maintain independent backups; implement multi-region recovery for critical services; develop cloud exit plans; test portability and restoration. |
Independent recovery and portability reduce dependence on a provider’s own recovery capability. |
|
Telecommunications Failure |
Redundant links, mobile devices, collaboration platforms, carrier escalation and emergency call trees |
20 |
Extreme |
Risk Reduction and Transference |
Eliminate single-carrier and common last-mile dependencies; provide automatic failover; maintain mobile or satellite alternatives; test failover quarterly. |
Communications support almost all recovery activities, making diversity and tested failover essential. |
|
Utility Failure |
UPS, generators, environmental alarms, preventive maintenance, alternate sites and remote work |
15 |
High |
Risk Reduction and Transference |
Test generators under load; secure fuel replenishment; identify utility single points of failure; add environmental monitoring; exercise extended outage scenarios. |
Extended utility loss may exceed normal backup capacity, requiring tested endurance arrangements. |
|
Logistics Disruption |
Multiple carriers, route planning, inventory buffers, delivery tracking and emergency transport |
20 |
Extreme |
Risk Avoidance, Reduction and Transference |
Diversify carriers and distribution routes; establish backup hubs; maintain emergency stock; pre-authorise priority allocation; conduct end-to-end delivery disruption exercises. |
Extreme supply consequences require route, carrier and inventory diversification rather than reliance on a single workaround. |
|
Import Restrictions |
Regulatory monitoring, alternate sourcing, product substitution, safety stock and early ordering |
15 |
High |
Risk Avoidance and Reduction |
Identify import-dependent critical products; source from multiple jurisdictions; pre-approve substitutes; increase strategic stocks; establish expedited clinical and quality approval processes. |
Geographic and product diversification reduces dependency on restricted imports and shortens substitution time. |
|
Vendor Insolvency |
Financial due diligence, credit monitoring, termination rights, alternate suppliers and inventory buffers |
15 |
High |
Risk Avoidance, Reduction and Transference |
Conduct periodic financial-health reviews; define insolvency warning triggers; secure performance bonds where justified; maintain transition plans; protect access to data, tooling and inventory. |
Early warning and transition rights reduce sudden loss of an essential supplier. |
|
Third-Party Cyber Incident |
Supplier security assessment, access segregation, MFA, incident clauses, monitoring and backup |
20 |
Extreme |
Risk Avoidance, Reduction and Transference |
Tier cyber-critical suppliers; require minimum security controls and incident-notification times; restrict integrations; continuously monitor exposure; conduct joint cyber exercises. |
Extreme interconnected exposure requires both technical isolation and stronger third-party assurance. |
|
Single Source Dependency |
Sole-source register, inventory buffers, contractual priority, supplier monitoring and substitution procedures |
20 |
Extreme |
Risk Avoidance and Reduction |
Qualify at least one alternative for each essential product where feasible; redesign specifications to permit substitution; reserve production capacity; formally approve unavoidable dependencies. |
Avoiding or reducing sole-source dependency directly removes the primary cause of the Extreme exposure. |
|
Cyber Attack |
Security monitoring, endpoint protection, MFA, firewalls, segmentation, patching, backups and incident response |
25 |
Extreme |
Risk Avoidance, Reduction and Transference |
Remove unsupported systems; strengthen zero-trust controls; improve vulnerability remediation; expand 24-hour monitoring; test cyber crisis and IT recovery; maintain cyber insurance and forensic retainers. |
The highest-rated risk requires layered prevention, detection, containment, recovery and financial preparedness. |
|
Ransomware |
Endpoint detection, email filtering, segmentation, least privilege, immutable backups and response procedures |
20 |
Extreme |
Risk Avoidance, Reduction and Transference |
Validate immutable and offline backups; establish clean-room recovery; restrict privileged access; block lateral movement; conduct ransomware simulations and full restoration tests. |
Clean restoration capability is essential because prevention alone cannot guarantee that ransomware will not succeed. |
|
Malware |
Anti-malware, secure email gateway, web filtering, patching, application controls and staff awareness |
16 |
High |
Risk Reduction and Transference |
Expand endpoint coverage; implement application allow-listing; block unauthorised removable media; improve behavioural detection; conduct regular simulations. |
The measures reduce common infection routes and improve early containment. |
|
Distributed Denial of Service—DDoS |
Firewalls, traffic filtering, monitoring, scalable hosting and provider escalation |
16 |
High |
Risk Reduction and Transference |
Deploy specialist DDoS protection; diversify internet paths; establish rate limiting and content delivery services; test provider escalation and stakeholder communication. |
Specialist upstream filtering is more effective than relying solely on internal network controls. |
|
Insider Threat |
Background checks, least privilege, access reviews, segregation of duties, logging and disciplinary processes |
15 |
High |
Risk Avoidance and Reduction |
Introduce risk-based insider monitoring; certify privileged access quarterly; strengthen joiner-mover-leaver controls; implement data-loss prevention; exercise insider incident scenarios. |
Insider threats use legitimate access, so behavioural monitoring and privilege control are essential. |
|
Data Breach |
Data classification, encryption, access control, monitoring, retention rules and breach-response procedures |
20 |
Extreme |
Risk Avoidance, Reduction and Transference |
Minimise retained sensitive data; map data flows; encrypt information throughout its lifecycle; perform access certification; test breach notification; strengthen supplier data clauses. |
Reducing the amount and accessibility of sensitive data directly limits legal, financial and reputational consequences. |
|
Network Failure |
Redundant switches, routers and links, monitoring, configuration backups and failover |
20 |
Extreme |
Risk Reduction and Transference |
Identify and eliminate single points of failure; deploy physically diverse paths; maintain spare equipment; automate failover; conduct full network resilience testing. |
Network failure can disable multiple critical systems simultaneously, requiring architectural rather than procedural mitigation. |
|
Server Failure |
Clustering, virtualisation, monitoring, backups, spare capacity and disaster recovery replication |
15 |
High |
Risk Avoidance, Reduction and Transference |
Retire unsupported servers; align high availability with business criticality; maintain tested replication; pre-provision recovery capacity; test restoration regularly. |
Technology lifecycle and tested redundancy improve recovery reliability while controlling cost. |
|
Database Corruption |
Transaction logs, access controls, backups, replication, integrity checks and change management |
15 |
High |
Risk Reduction and Transference |
Implement automated integrity monitoring; maintain point-in-time recovery; isolate backup copies; test restoration and business reconciliation; restrict direct database changes. |
Corruption may replicate to backups, so independent recovery and reconciliation are required. |
|
Cloud Service Outage |
Multi-zone hosting, provider monitoring, backups, support escalation and offline procedures |
15 |
High |
Risk Reduction and Transference |
Assess multi-region recovery; maintain independent data copies; implement offline workarounds; test provider outage procedures; establish workload portability. |
The strategy reduces dependence on the availability of one cloud region or provider. |
|
Power Failure |
UPS, generators, automatic transfer, monitoring, fuel arrangements and alternate site |
15 |
High |
Risk Reduction and Transference |
Test failover under realistic load; increase generator autonomy; secure fuel resupply; provide redundant power feeds for critical equipment; test extended outages. |
Routine tests may not reflect full recovery demand, making load and endurance testing necessary. |
|
Hardware Failure |
Asset registers, preventive maintenance, spare devices, standard builds, warranties and support contracts |
16 |
High |
Risk Avoidance, Reduction and Transference |
Replace unsupported equipment; maintain critical spares; standardise configurations; automate device deployment; monitor lifecycle status. |
Standardised spares and rapid replacement reduce interruption at proportionate cost. |
|
Software Failure |
Change control, testing, segregated environments, rollback, vendor support and manual workarounds |
16 |
High |
Risk Avoidance, Reduction and Transference |
Improve regression and integration testing; introduce canary releases; define automated rollback criteria; maintain tested workarounds; review critical defects before release. |
Most software failures arise from changes, so stronger testing and rapid rollback directly reduce exposure. |
|
Internet Failure |
Dual links, failover, mobile hotspots, monitoring and alternate communication channels |
16 |
High |
Risk Reduction and Transference |
Use providers with physically diverse routes; test failover quarterly; verify recovery bandwidth; provide backup connectivity to essential teams and sites. |
Diverse connectivity and capacity validation ensure alternate services can support actual recovery workloads. |
|
Authentication System Failure |
Redundant directories, MFA, emergency accounts, monitoring and identity recovery procedures |
15 |
High |
Risk Reduction and Transference |
Implement geographically redundant identity services; protect and monitor emergency accounts; test failover; create controlled offline access for critical functions. |
Authentication is a common dependency across applications; its recovery must not rely on the failed environment. |
|
Artificial Intelligence System Failure |
Human oversight, output validation, audit logs, access controls and conventional analytical fallback |
12 |
High |
Risk Avoidance, Reduction and Acceptance |
Establish AI governance; prohibit autonomous high-impact decisions; monitor model drift and data quality; maintain manual or conventional fallback; test operations without AI. |
Maintaining human accountability and non-AI fallback prevents unreliable outputs from stopping or distorting critical decisions. |
The mitigation programme should be implemented based on residual risk and the potential impact on healthcare supply continuity.
The following threats require immediate management action:
For these threats, ALPS Healthcare should assign executive sponsors, establish funded remediation plans, set implementation deadlines, and monitor progress through senior risk and continuity governance.
Threats rated High should be grouped into coordinated programmes rather than treated individually. Recommended programmes include:
Moderate risks should not be ignored. Chemical spills, gas leaks, bomb threats and terrorism require maintained response procedures, periodic exercises, threat monitoring, and formal review when facilities or operating conditions change.
Each additional strategy should be entered into a formal mitigation register containing:
Risk acceptance should be used only where further reduction is impracticable or disproportionate.
The decision should be documented, approved at the appropriate governance level, time-limited where remediation remains outstanding, and monitored against clearly defined indicators.
The mitigation strategy assessment provides ALPS Healthcare with a structured method for converting identified threats and current risk ratings into practical resilience improvements.
Existing controls establish the starting point, but they do not by themselves demonstrate that the remaining exposure is acceptable.
High and Extreme risks require further analysis to determine whether existing measures are sufficiently comprehensive, reliable, tested, and capable of operating during a real disruption.
Different threats require different combinations of treatment. Natural and external events generally cannot be eliminated and therefore depend on risk reduction, preparedness, recovery capability, and financial transfer.
Technology and supplier concentration risks may allow greater avoidance by removing unsupported systems, diversifying providers, eliminating single points of failure, and redesigning operating arrangements. Residual exposure should be accepted only through a formal and informed governance decision.
The recommended strategies balance resilience, practicality, cost, urgency, safety, operational dependency, and public-interest obligations.
Priority should be given to cyber threats, critical supplier and logistics dependencies, telecommunications and network resilience, data protection, and single-source exposures because these risks could simultaneously disrupt several Critical Business Functions and affect the availability of essential healthcare supplies and services.
Mitigation strategies should be integrated with Business Continuity Plans, IT Disaster Recovery arrangements, Crisis Management procedures, supplier contracts, workforce planning, facilities management, and operational exercises.
Their effectiveness should be demonstrated through inspection, testing, simulation, assurance review, and evidence-based reporting rather than assumed from the existence of policies or plans.
A well-governed mitigation programme enables ALPS Healthcare to reduce avoidable disruption, limit the consequences of events that cannot be prevented, and improve its ability to continue supporting Singapore’s public healthcare institutions throughout an incident.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||