Ebook

[BCM] [ALPS] [E3] [RAR] [T1] List of Threats

Written by Dr Goh Moh Heng | Aug 5, 2026, 4:02:00 PM

 List of Threats

 

RAR Part 1: List of Threats for ALPS Healthcare

Introduction

 

An effective Business Continuity Management (BCM) programme begins with a clear understanding of the threats that could disrupt the organisation's ability to deliver its critical business functions.

Before an organisation can assess risk, determine business impacts, or develop recovery strategies, it must first identify the potential events that could interrupt its operations.

The purpose of this chapter is to establish a comprehensive Threat Register for ALPS Healthcare that identifies credible sources of disruption affecting its people, facilities, technology, suppliers, information, and operational processes.

Threat identification is the first stage of the Risk Assessment process. A threat is a potential source of harm or disruption, while a vulnerability is a weakness that may be exploited by that threat.

Risk arises when a credible threat can exploit one or more vulnerabilities to affect organisational objectives. By identifying threats before evaluating risks, ALPS Healthcare can conduct more structured and evidence-based assessments in subsequent chapters.

A Threat Register supports Business Continuity Management by providing a systematic inventory of disruptive events that may affect the organisation's ability to procure, store, distribute, and manage healthcare supplies and services.

It ensures that both conventional risks—such as fire, power outages, and equipment failures—and emerging operational resilience threats—such as cyberattacks, cloud service disruptions, geopolitical supply chain instability, and climate-related events—are considered in planning.

Threat identification should not be limited to the organisation itself.

Country-level factors such as Singapore's climate, public infrastructure, regulatory environment, dependence on international trade, technological maturity, and public health considerations influence the operating environment in which ALPS Healthcare functions.

At the same time, organisation-specific characteristics—including its role in supporting Singapore's public healthcare institutions, reliance on suppliers, extensive ICT systems, and logistics operations—introduce additional operational exposures.

Both perspectives are necessary to develop a realistic and comprehensive Threat Register.

The Threat Register developed in this chapter serves as a foundational input to the subsequent Risk Assessment, Business Impact Analysis (BIA), Business Continuity Strategy (BCS), Crisis Management, and Business Continuity Planning (BCP) activities. It identifies only potential sources of disruption.

The evaluation of likelihood, business impact, risk prioritisation, and risk treatment options will be undertaken in later chapters.

 

Table RAR P1: List of Threats for ALPS Healthcare

Category of Threats

Types of Threats

Description of Threat

Country-Level Relevance

Organisation-Level Relevance

Denial of Access – Natural Disaster

Flood

Intense rainfall overwhelms drainage systems, restricting access to facilities and transport routes.

Occasional due to seasonal heavy rainfall and urban flash flooding.

May prevent staff, suppliers and logistics providers from accessing procurement offices, warehouses or distribution centres.

 

Flash Flood

Localised flooding causes sudden road closures and transport disruption.

Commonly encountered during severe storms.

Delays staff attendance, supplier deliveries and emergency procurement activities.

 

Severe Storm

Heavy rain and strong winds disrupt transport, utilities and outdoor operations.

Common during monsoon periods.

Interrupts transportation, warehouse operations and supplier logistics.

 

Lightning

Lightning strikes damage buildings, ICT infrastructure or utility services.

Common in Singapore's tropical climate.

May disrupt procurement systems, communications and power supply.

 

Earthquake (Regional)

Seismic events in neighbouring countries affect regional supply chains or infrastructure.

Low historical occurrence locally, but regional effects are credible.

Overseas suppliers and logistics hubs may experience disruption, delaying healthcare supplies.

 

Haze

Transboundary haze reduces air quality and outdoor visibility.

Occasional regional occurrence.

Affects workforce health, logistics operations and warehouse productivity.

 

Extreme Heat

Prolonged high temperatures affect personnel and temperature-sensitive operations.

Increasing concern due to climate change.

Places additional strain on warehouse staff and cold-chain operations.

 

Pandemic-related Movement Restrictions

Public health measures restrict movement of personnel and goods.

Credible based on recent global experience.

Limits workforce availability and disrupts procurement and distribution activities.

Denial of Access – Man-made Disaster

Fire

Fire damages facilities and requires evacuation.

Credible for all commercial facilities.

Procurement offices, warehouses or ICT facilities may become inaccessible.

 

Explosion

Industrial or gas explosion causes building closure.

Low occurrence but credible.

Interrupts business operations and threatens staff safety.

 

Chemical Spill

Hazardous material release contaminates nearby premises.

Occasional due to industrial activities.

Prevents access to offices or warehouses and requires emergency response.

 

Gas Leak

Gas leakage results in evacuation of affected premises.

Occasional.

Disrupts procurement operations and facility access.

 

Structural Failure

Building defects or failures make facilities unsafe.

Low historical occurrence due to stringent building standards.

Forces relocation to alternate workplaces.

 

Bomb Threat

Security threat results in precautionary evacuation.

Credible but infrequent.

Delays procurement operations and access to critical systems.

 

Terrorism

Intentional attack on critical infrastructure or public facilities.

Low historical occurrence but continuously monitored nationally.

May affect offices, transport networks, suppliers or national healthcare operations.

 

Active Assailant

Violent incident threatens personnel safety.

Credible although infrequent.

Immediate suspension of operations and activation of crisis management procedures.

 

Public Transport Disruption

Failure of MRT or bus services prevents workforce mobility.

Occasional due to infrastructure incidents.

Reduces staff availability at procurement and warehouse facilities.

 

Major Traffic Incident

Road closures delay logistics and personnel movement.

Common urban operational risk.

Delays supplier deliveries and emergency procurement response.

Unavailability of People

Pandemic

Widespread infectious disease significantly reduces workforce availability.

Credible based on recent public health events.

Procurement, logistics and supplier management functions operate with reduced staffing.

 

Infectious Disease Outbreak

Local outbreak affects specific teams or facilities.

Periodically encountered.

Critical procurement teams may require isolation or remote working.

 

Mass Illness

Simultaneous illness affects multiple employees.

Credible seasonal occurrence.

Slows procurement processing and contract administration.

 

High Staff Turnover

Loss of experienced procurement personnel reduces organisational capability.

Emerging workforce challenge.

Loss of specialist procurement knowledge affects continuity.

 

Loss of Key Personnel

Departure or incapacity of critical decision-makers.

Credible organisational risk.

Delays contract approvals, supplier negotiations and procurement governance.

 

Skills Shortage

Insufficient procurement, logistics or ICT expertise.

Increasing concern in specialised sectors.

Limits recovery capability during prolonged disruptions.

 

Workplace Violence

Internal conflict affects employee wellbeing and productivity.

Low occurrence but credible.

Interrupts operations and requires management intervention.

 

Staff Fatigue

Extended incident response results in reduced performance.

Credible during prolonged emergencies.

Increases operational errors during emergency procurement.

 

Psychological Stress

High-pressure situations affect workforce resilience.

Increasing organisational concern.

Reduces decision quality and staff wellbeing during major incidents.

 

Mandatory Quarantine

Employees are unavailable due to public health controls.

Credible during disease outbreaks.

Cross-trained staff and remote working become essential.

Disruption to the Supply Chain

Supplier Failure

A critical supplier is unable to fulfil contractual obligations.

Growing concern amid global market volatility.

Interrupts procurement of essential medicines, consumables and equipment.

 

Outsourcing Failure

The outsourced service provider cannot deliver the contracted services.

Credible across complex supply chains.

Affects procurement systems, logistics or support services.

 

Cloud Service Provider Failure

Cloud-hosted procurement applications become unavailable.

Emerging technology dependency.

Interrupts procurement workflows, supplier management and reporting.

 

Telecommunications Failure

Loss of communication services affects suppliers and operations.

Occasional infrastructure issues.

Disrupts supplier coordination and business communications.

 

Utility Failure

An interruption to electricity or water affects operational facilities.

Occasional but generally short duration.

Warehouse operations and ICT services may be interrupted.

 

Logistics Disruption

Transport providers cannot deliver goods.

Increasing concern due to global supply chain complexity.

Delays delivery of healthcare supplies to hospitals.

 

Import Restrictions

International trade restrictions affect procurement.

Credible due to geopolitical developments.

Limits availability of imported medical products.

 

Vendor Insolvency

Supplier ceases business operations.

Credible in volatile economic conditions.

Requires activation of alternate suppliers.

 

Third-Party Cyber Incident

Supplier suffers cyber attack affecting service delivery.

Increasing concern globally.

Disrupts procurement, logistics and supplier information exchange.

 

Single Source Dependency

Sole supplier becomes unavailable.

Recognised supply chain exposure.

Creates immediate continuity risk for critical healthcare products.

Equipment and IT-Related Disruption

Cyber Attack

Malicious actors compromise procurement systems.

Persistent national cybersecurity concern.

Interrupts procurement, supplier management and business operations.

 

Ransomware

Critical systems are encrypted by attackers.

Increasing threat across all sectors.

Procurement platforms and document repositories become inaccessible.

 

Malware

Malicious software degrades system performance or corrupts information.

Common cyber threat.

Reduces operational capability and system reliability.

 

Distributed Denial of Service (DDoS)

Internet-facing systems become unavailable due to traffic flooding.

Credible against critical digital services.

Supplier portals and procurement systems become inaccessible.

 

Insider Threat

Authorised user intentionally or accidentally compromises information.

Emerging governance concern.

Procurement information, contracts and supplier records may be exposed or altered.

 

Data Breach

Sensitive procurement or supplier information is disclosed.

Persistent cyber risk.

Affects regulatory compliance, supplier confidence and organisational reputation.

 

Network Failure

Internal network infrastructure becomes unavailable.

Occasional infrastructure failure.

Prevents access to procurement systems and shared information.

 

Server Failure

Application servers fail unexpectedly.

Credible ICT operational risk.

Interrupts ERP, procurement and contract management systems.

 

Database Corruption

Critical procurement data becomes damaged or inconsistent.

Credible technology risk.

Procurement records and supplier information become unreliable.

 

Cloud Service Outage

Cloud-hosted applications become unavailable.

Increasing dependency on cloud technologies.

Delays procurement processing and remote working capability.

 

Power Failure

Loss of electrical supply interrupts ICT services.

Occasional infrastructure event.

Affects offices, warehouses and data centre operations.

 

Hardware Failure

Critical ICT equipment becomes inoperable.

Common operational occurrence.

Reduces the availability of business applications that support procurement.

 

Software Failure

Application malfunction prevents business processing.

Credible technology risk.

Procurement workflows and approvals are delayed.

 

Internet Failure

External connectivity is lost.

Occasional telecommunications issue.

Prevents access to cloud systems and supplier communication.

 

Authentication System Failure

Identity management services become unavailable.

Increasing concern as organisations adopt centralised authentication.

Staff cannot securely access procurement applications and collaboration platforms.

 

Artificial Intelligence System Failure

AI-assisted procurement analytics or forecasting tools produce incorrect outputs or become unavailable.

Emerging technology consideration.

Reduces forecasting accuracy and decision support for procurement planning.

 

 

Category of Threats

Types of Threats

Description of Threats

Country Level

Organisation Level

Denial of Access – Natural Disaster

Earthquake

Seismic activity affecting buildings, ICT infrastructure and transportation networks.

Saudi Arabia experiences occasional seismic activity, particularly in western regions, which may affect infrastructure and essential services.

Temporary closure of offices, disruption to mortgage guarantee processing, staff safety concerns and possible ICT service interruption.

Flash Flood

Heavy rainfall is causing flash flooding around business premises or transport routes.

Flash floods periodically affect several regions, disrupting transport, utilities and public services.

Employees are unable to reach offices, there is an interruption to business operations and possible damage to facilities.

Severe Sandstorm

Dust storms are reducing visibility and affecting transport, power and communications.

Sandstorms are common climatic events that disrupt travel, aviation and utility services.

Reduced workforce availability, degraded network connectivity and delays in guarantee processing.

Extreme Heat

Prolonged high temperatures affecting people and critical infrastructure.

Seasonal extreme temperatures increase pressure on national power infrastructure and cooling systems.

Reduced employee productivity, overheating of ICT equipment and increased facility operating risks.

Pandemic

Widespread infectious disease outbreak affecting the workforce.

National health emergencies may restrict movement and business operations.

High absenteeism, remote-working dependency, and reduced operational capacity.

Denial of Access – Man-made Disaster

Fire

Fire affecting offices, archives or ICT facilities.

Fire incidents may disrupt utility infrastructure and neighbouring developments.

Damage to facilities, records and ICT equipment resulting in operational disruption.

Explosion

Explosion in or near operational facilities.

Industrial or urban incidents may affect nearby organisations.

Evacuation of premises, damage to infrastructure and prolonged interruption of services.

Hazardous Material Release

Chemical spill or hazardous substance affecting business premises.

Industrial accidents or transportation incidents may create exclusion zones.

Restricted access to facilities and temporary suspension of operations.

Civil Disturbance

Public disorder affecting transportation or access.

Localised security incidents may disrupt movement within affected areas.

Staff are unable to access workplaces and delays in operational activities.

Terrorist Incident

Deliberate attack targeting public infrastructure or critical services.

National critical infrastructure may become the target of security threats.

Activation of crisis management arrangements and prolonged disruption to essential services.

Building Access Restriction

Authorities prohibit access due to safety or security concerns.

Government-imposed restrictions following emergencies or investigations.

Temporary relocation of staff and interruption to customer services.

Unavailability of People

Loss of Key Personnel

Departure, illness or unavailability of personnel with specialist knowledge.

Competition for specialised financial and ICT professionals within the national labour market.

Delays in mortgage guarantee assessments, approvals and strategic decision-making.

Industrial Action

Workforce disputes affecting employee availability.

Labour-related disruptions may affect outsourced service providers or contractors.

Reduced staffing levels and slower service delivery.

High Staff Absenteeism

Significant number of employees unavailable simultaneously.

Public health events or transport disruptions affecting workforce availability.

Processing backlogs and reduced customer service capability.

Skills Shortage

Insufficient availability of specialised personnel.

National demand for skilled financial, cybersecurity and technology professionals.

Increased dependency on a limited number of employees and reduced organisational resilience.

Human Error

Mistakes during operational activities.

Human error remains a universal organisational risk across all industries.

Incorrect mortgage guarantee decisions, operational delays and increased rework.

Disruption to the Supply Chain

Critical Supplier Failure

Failure of a key supplier providing critical business services.

National or regional disruptions affecting suppliers and logistics.

Loss of essential external services supporting business operations.

Cloud Service Provider Outage

Failure of cloud infrastructure supporting applications.

Regional cloud service disruptions affecting multiple organisations.

Reduced availability of business applications and customer services.

Telecommunications Failure

Failure of telecommunications networks.

Nationwide telecommunications outages affecting public and private sectors.

Loss of communication between staff, customers and financial institutions.

Internet Service Provider Failure

Internet connectivity disruption.

National network failures or infrastructure maintenance affecting connectivity.

Inability to access cloud applications and external business services.

Credit Bureau Service Failure

Credit information services become unavailable.

National financial infrastructure disruption affecting credit reporting services.

Delays in borrower verification and guarantee approval processes.

Banking Partner System Failure

Partner financial institutions experience system outages.

Banking sector operational disruptions affecting financial transactions.

Delayed mortgage guarantee issuance and settlement activities.

Outsourced ICT Support Failure

External ICT support provider unavailable.

Service provider disruption affecting multiple customers.

Delayed incident response and extended ICT recovery times.

Equipment and IT-Related Disruption

Commercial Power Failure

Loss of electrical power to business premises or ICT facilities.

National or regional electricity disruptions affecting businesses.

Interruption of business operations and system availability.

HVAC Failure

Failure of cooling or environmental control systems.

Infrastructure failures affecting commercial buildings.

Overheating of ICT equipment and reduced workplace usability.

Network Failure

Failure of internal or external communications networks.

National telecommunications infrastructure issues affecting connectivity.

Business systems become inaccessible, interrupting guarantee processing.

Data Centre Outage

Primary hosting environment unavailable.

Regional infrastructure disruption affecting hosting facilities.

Critical business applications unavailable for extended periods.

Core Mortgage Guarantee System Failure

Failure of the primary mortgage guarantee application.

Software defects or infrastructure failures affecting financial platforms.

Suspension of guarantee processing and customer services.

Database Failure

Corruption or failure of operational databases.

Technology failures affecting enterprise information management.

Loss of transaction integrity and delayed operational recovery.

Identity and Access Management Failure

Authentication or access control services unavailable.

Cyber or infrastructure incidents affecting identity services.

Employees unable to access critical business applications.

Backup Failure

Backup processes fail or cannot be restored successfully.

Technology failures affecting backup infrastructure.

Increased recovery time and potential information loss.

Storage System Failure

Enterprise storage infrastructure becomes unavailable.

Hardware failures affecting digital infrastructure.

Loss of business information availability and operational disruption.

Cybersecurity Threats

Ransomware Attack

Malware encrypting critical systems and business information.

Increasing cyber threats targeting government and financial sectors globally and nationally.

Complete disruption of business systems and recovery operations.

Malware Infection

Malicious software compromising ICT assets.

Continuous cyber threat environment affecting organisations.

Reduced system availability, data compromise and operational disruption.

Phishing Attack

Fraudulent attempts to obtain credentials or confidential information.

Persistent cybercrime targeting financial institutions.

Compromise of user accounts and unauthorised access to systems.

Business Email Compromise

Fraud involving spoofed or compromised email communications.

Increasing financial cybercrime targeting organisations.

Financial losses, fraudulent transactions and reputational damage.

Distributed Denial-of-Service (DDoS) Attack

Attack overwhelming online services.

National critical infrastructure and financial institutions remain potential targets.

Customer-facing services become unavailable.

Insider Cyber Threat

Malicious or negligent actions by employees or contractors.

Insider risks affecting organisations across all sectors.

Data leakage, fraud and operational disruption.

Data Breach

Unauthorised disclosure of confidential information.

Cybersecurity incidents affecting financial institutions worldwide.

Regulatory investigations, reputational damage and stakeholder loss of confidence.

Information Management

Loss of Physical Records

Destruction or loss of paper-based records.

Fire, flooding or accidental loss affecting document repositories.

Delays in regulatory compliance and customer servicing.

Electronic Record Corruption

Corruption of electronic documents and records.

ICT failures affecting enterprise information repositories.

Loss of business information integrity and operational disruption.

Data Integrity Failure

Information becomes inaccurate or incomplete.

Data quality issues affecting financial decision-making.

Incorrect guarantee decisions and financial exposure.

Financial Threats

 

Fraudulent Mortgage Applications

Submission of false borrower or property information.

Mortgage fraud affecting financial institutions and housing markets.

Financial loss, increased credit risk and reputational damage.

Internal Fraud

Fraud committed by employees or contractors.

Fraud risks inherent across financial organisations.

Financial losses, legal exposure and reduced stakeholder confidence.

Financial Market Instability

Economic fluctuations affecting mortgage markets.

National or global financial uncertainty impacting housing finance.

Increased business volatility and operational planning challenges.

Regulatory and Legal Threats

Regulatory Change

New laws or regulatory expectations were introduced.

Regulatory reforms affecting financial services organisations.

Business process changes, compliance costs and operational adjustments.

Regulatory Investigation

Supervisory reviews or investigations.

Increased regulatory oversight across financial institutions.

Resource diversion, operational disruption and reputational exposure.

Legal Proceedings

Litigation involving the organisation.

Legal disputes affecting financial institutions.

Financial liabilities and management distraction.

Physical Security Threats

Physical Intrusion

Unauthorised access to business premises.

Security incidents affecting commercial buildings.

Theft, sabotage or information compromise.

Theft

Theft of ICT assets or confidential information.

Criminal activities affecting businesses.

Financial loss and disruption to operations.

Vandalism

Deliberate damage to facilities or equipment.

Local criminal activity affecting commercial premises.

Repair costs and temporary service disruption.

Operational Threats

Process Failure

Failure of critical business processes.

Operational weaknesses affecting financial institutions.

Delayed mortgage guarantee processing and customer dissatisfaction.

Manual Workaround Failure

Manual procedures ineffective during ICT disruption.

Organisations unable to sustain operations without technology.

Extended interruption of critical services.

Inadequate Business Continuity Planning

Continuity arrangements are incomplete or outdated.

Organisations insufficiently prepared for disruptive events.

Longer recovery times and increased operational risk.

Inadequate Crisis Management

Ineffective coordination during major incidents.

National emergencies requiring coordinated organisational response.

Poor decision-making and delayed recovery.

Failure of Disaster Recovery Arrangements

ICT recovery capability proves ineffective.

Technology recovery failures affecting critical infrastructure.

Extended ICT outages and prolonged operational disruption.

Reputational Threats

Negative Media Coverage

Adverse publicity concerning the organisation.

Media scrutiny affecting public confidence in financial institutions.

Reduced stakeholder trust and reputational harm.

Social Media Misinformation

False or misleading information is circulating online.

Rapid dissemination of misinformation across digital platforms.

Increased customer enquiries and loss of public confidence.

Service Delivery Failure

Failure to meet customer or stakeholder expectations.

Reduced confidence in financial sector services.

Customer dissatisfaction and reputational damage.

Strategic Threats

Governance Failure

Ineffective leadership or oversight.

Weak governance affecting organisational resilience.

Poor strategic decisions and increased operational risk.

Poor Change Management

Inadequate management of organisational or technology changes.

Transformation initiatives introduce operational risks.

System instability, project failure and business disruption.

Third-Party Concentration Risk

Over-reliance on a small number of suppliers.

National dependence on limited specialised service providers.

Increased exposure to supplier failures and reduced resilience.

Simultaneous Multiple Disruptions

Multiple unrelated incidents occurring concurrently.

Large-scale emergencies affecting multiple sectors simultaneously.

Enterprise-wide disruption requiring coordinated crisis and continuity management.

 

 

 

Maintaining a comprehensive Threat Register is a fundamental component of Business Continuity Management because it establishes a structured understanding of the disruptive events that could affect ALPS Healthcare's ability to deliver its critical business functions.

By systematically identifying credible threats across natural hazards, man-made incidents, workforce disruptions, supply chain dependencies, and technology failures, the organisation creates a solid foundation for proactive resilience planning rather than reactive crisis response.

The Threat Register serves as the starting point for the formal Risk Assessment process.

Each identified threat will subsequently be analysed to determine the associated vulnerabilities, potential business impacts, likelihood of occurrence, and appropriate risk treatment options.

These analyses will inform management decisions regarding risk acceptance, mitigation, transfer, or avoidance, ensuring that continuity strategies are proportionate to the organisation's operational priorities and risk appetite.

The identified threats also provide essential inputs to the Business Impact Analysis by highlighting the types of disruptions that may affect critical business functions, supporting services, technology, suppliers, personnel, and facilities.

This information supports the development of realistic Recovery Time Objectives (RTOs), Minimum Business Continuity Objectives (MBCOs), recovery strategies, and Business Continuity Plans that are aligned with ALPS Healthcare's operational responsibilities.

As the operating environment continues to evolve, the Threat Register should be reviewed and updated regularly to reflect changes in climate patterns, technology, cybersecurity, supply chain complexity, workforce trends, regulatory requirements, and geopolitical developments.

Particular attention should be given to emerging threats such as sophisticated cyber attacks, artificial intelligence-related risks, prolonged supply chain disruptions, and climate-related events, all of which have the potential to significantly affect healthcare procurement and supply chain resilience.

A well-maintained Threat Register strengthens organisational resilience by improving preparedness, supporting informed decision-making, and enabling timely continuity planning. Identifying credible threats is the first step in protecting ALPS Healthcare's critical services and supporting Singapore's public healthcare system.

The subsequent Risk Assessment chapters will build upon this foundation by evaluating the likelihood, business impact, and appropriate treatment of each identified threat.

 

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF

 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.