RAR P3: Risk Impact and Likelihood Assessment for ALPS Healthcare
Introduction
RAR Part 3 converts the Threat Register established in Part 1 and the treatment-and-control assessment completed in Part 2 into prioritised risk information.
It evaluates the credible consequences of each approved threat, estimates the likelihood of occurrence, calculates a current risk rating, and estimates how long the resulting disruption may affect ALPS Healthcare.
The assessment represents the current or residual risk after considering the assumed existing controls documented in RAR Part 2, but before implementing the additional planned controls. Because detailed incident data, verified control-testing results, financial exposure information, and ALPS Healthcare’s approved risk matrix were not supplied, the scores in this chapter are indicative. They should not be treated as confirmed organisational risk ratings until they have been reviewed and approved through ALPS Healthcare’s risk-governance process.
Impact is assessed across seven dimensions:
- Finance
- Operations
- Legal and Regulatory
- Reputation and Image
- Social Responsibility
- People
- Assets, IT Systems and Information
Assessing several impact dimensions prevents management from relying only on financial consequences.
A disruption may create relatively limited direct expenditure while significantly affecting the continuity of healthcare supply, information security, workforce safety, regulatory obligations, stakeholder confidence, or Singapore’s public healthcare institutions.
The highest credible score among the seven impact areas is used as the overall impact score. This approach ensures that a severe consequence in one important area is not diluted by lower scores elsewhere.
Likelihood is assessed independently and reflects the realistic possibility of the threat occurring, taking into account geographic exposure, operating conditions, sector experience, current vulnerabilities, and the assumed effectiveness of existing controls.
The current risk rating is calculated as:
Risk Rating = Highest Impact Score × Likelihood Score
The default risk bands used in this chapter are:
|
Risk Rating |
Risk Level |
|
1–4 |
Very Low/ Low |
|
5–9 |
Moderate |
|
10–16 |
High |
|
17–25 |
Very High (Extreme) |
The expected disruption period estimates the credible duration of operational interruption, accounting for existing controls.
It is neither the Recovery Time Objective nor the Maximum Tolerable Period of Disruption.
The duration may depend on facility access, supplier recovery, technology restoration, staff availability, regulatory restrictions, or the effectiveness of alternate operating arrangements.
Numerical ratings are decision-support tools. They must be interpreted together with professional judgement, stakeholder obligations, control effectiveness, operational dependencies, public-interest consequences, and ALPS Healthcare’s approved risk appetite.
Scoring Key
- 1 – Very Low (Insignificant)
- 2 – Low (Minor)
- 3 – Moderate
- 4 – High (Major)
- 5 – Very High (Severe)
Table RAR P3: Risk Impact and Likelihood Assessment for ALPS Healthcare
|
Threat |
Finance |
Operat-ions |
Legal & Regulatory |
Reputation & Image |
Social Respon-sibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
|
Flood (Denial of Access – Natural Disaster) |
3 |
4 |
3 |
3 |
3 |
3 |
3 |
4 – Operations |
3 – Possible |
4 × 3 = 12 |
High |
8–24 hours, depending on site access and drainage conditions |
|
Flash Flood (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
2 |
2 |
2 |
3 – Operations |
4 – Likely |
3 × 4 = 12 |
High |
4–8 hours, primarily affecting commuting and deliveries |
|
Severe Storm (Denial of Access – Natural Disaster) |
3 |
4 |
2 |
3 |
3 |
3 |
3 |
4 – Operations |
4 – Likely |
4 × 4 = 16 |
High |
8–24 hours, depending on transport and utility restoration |
|
Lightning (Denial of Access – Natural Disaster) |
2 |
3 |
1 |
2 |
2 |
2 |
4 |
4 – Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–4 hours unless critical equipment is damaged |
|
Earthquake—Regional (Denial of Access – Natural Disaster) |
4 |
5 |
3 |
4 |
5 |
2 |
3 |
5 – Operations; Social Responsibility |
2 – Unlikely |
5 × 2 = 10 |
High |
1–2 weeks due to regional manufacturing and logistics disruption |
|
Haze (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
1 |
4 – People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days, potentially longer during persistent regional haze |
|
Extreme Heat (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
3 |
4 – People |
4 – Likely |
4 × 4 = 16 |
High |
3–7 days during prolonged heat conditions |
|
Pandemic-related Movement Restrictions (Denial of Access – Natural Disaster) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
1–2 weeks, potentially longer if restrictions escalate |
|
Fire (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
5 |
5 – Operations; People; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–2 weeks, depending on damage and alternate-site activation |
|
Explosion (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
5 |
5 – Operations; People; Assets, IT Systems and Information |
2 – Unlikely |
5 × 2 = 10 |
High |
1–2 weeks, potentially longer for major structural damage |
|
Chemical Spill (Denial of Access – Man-made Disaster) |
3 |
4 |
3 |
3 |
4 |
4 |
3 |
4 – Operations; Social Responsibility; People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
1–3 days, depending on containment and decontamination |
|
Gas Leak (Denial of Access – Man-made Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
2 |
4 – People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
8–24 hours, subject to detection, isolation and safety clearance |
|
Structural Failure (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
4 |
5 – Operations; People |
2 – Unlikely |
5 × 2 = 10 |
High |
2–4 weeks if the facility requires major repair or relocation |
|
Bomb Threat (Denial of Access – Man-made Disaster) |
2 |
4 |
2 |
4 |
4 |
4 |
2 |
4 – Operations; Reputation and Image; Social Responsibility; People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
4–8 hours, subject to police investigation and clearance |
|
Terrorism (Denial of Access – Man-made Disaster) |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
5 – All impact areas |
1 – Rare |
5 × 1 = 5 |
Moderate |
More than 1 month in a severe multi-site or infrastructure scenario |
|
Active Assailant (Denial of Access – Man-made Disaster) |
3 |
4 |
3 |
4 |
4 |
5 |
2 |
5 – People |
2 – Unlikely |
5 × 2 = 10 |
High |
1–3 days, with longer workforce and psychological effects |
|
Public Transport Disruption (Denial of Access – Man-made Disaster) |
2 |
3 |
1 |
2 |
2 |
3 |
1 |
3 – Operations; People |
4 – Likely |
3 × 4 = 12 |
High |
4–8 hours, depending on the transport network affected |
|
Major Traffic Incident (Denial of Access – Man-made Disaster) |
2 |
3 |
1 |
2 |
3 |
2 |
1 |
3 – Operations; Social Responsibility |
4 – Likely |
3 × 4 = 12 |
High |
1–4 hours, with longer delays for critical delivery routes |
|
Pandemic (Unavailability of People) |
4 |
5 |
4 |
4 |
5 |
5 |
3 |
5 – Operations; Social Responsibility; People |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, potentially extending for successive infection waves |
|
Infectious Disease Outbreak (Unavailability of People) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days for a localised team or facility outbreak |
|
Mass Illness (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days, depending on workforce concentration |
|
High Staff Turnover (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
2–4 weeks, with capability effects potentially lasting longer |
|
Loss of Key Personnel (Unavailability of People) |
3 |
4 |
3 |
3 |
3 |
4 |
2 |
4 – Operations; People |
3 – Possible |
4 × 3 = 12 |
High |
1–2 weeks, depending on succession and delegation readiness |
|
Skills Shortage (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
More than 1 month because specialist capability may be difficult to replace |
|
Workplace Violence (Unavailability of People) |
2 |
3 |
2 |
3 |
3 |
5 |
2 |
5 – People |
2 – Unlikely |
5 × 2 = 10 |
High |
1–3 days, with potentially longer welfare consequences |
|
Staff Fatigue (Unavailability of People) |
2 |
4 |
2 |
3 |
3 |
4 |
1 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
1–2 weeks during prolonged incident response or backlog clearance |
|
Psychological Stress (Unavailability of People) |
2 |
3 |
2 |
3 |
3 |
4 |
1 |
4 – People |
4 – Likely |
4 × 4 = 16 |
High |
1–2 weeks, with some effects continuing after restoration |
|
Mandatory Quarantine (Unavailability of People) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days for affected teams; longer for repeated exposure |
|
Supplier Failure (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, depending on inventory and alternate supplier availability |
|
Outsourcing Failure (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
3 |
5 – Operations |
3 – Possible |
5 × 3 = 15 |
High |
3–7 days, depending on retained capability and exit arrangements |
|
Cloud Service Provider Failure (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days, depending on provider recovery and data portability |
|
Telecommunications Failure (Disruption to the Supply Chain) |
3 |
5 |
2 |
3 |
3 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
8–24 hours, subject to carrier redundancy and failover |
|
Utility Failure (Disruption to the Supply Chain) |
4 |
5 |
3 |
3 |
4 |
3 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days in an extended electricity or facility-service outage |
|
Logistics Disruption (Disruption to the Supply Chain) |
5 |
5 |
3 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
3–7 days, depending on carriers, routes and inventory buffers |
|
Import Restrictions (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, depending on product substitution and approvals |
|
Vendor Insolvency (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
4 |
2 |
2 |
5 – Finance; Operations |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, depending on transition complexity |
|
Third-Party Cyber Incident (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
3–7 days, potentially longer where data or integrations are compromised |
|
Single Source Dependency (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, potentially longer where no substitute is available |
|
Cyber Attack (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
5 |
3 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information |
5 – Almost Certain |
5 × 5 = 25 |
Extreme |
3–7 days, with investigations and remediation continuing longer |
|
Ransomware (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
5 |
3 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, depending on containment and clean restoration |
|
Malware (Equipment and IT-Related Disruption) |
3 |
4 |
3 |
3 |
3 |
2 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–3 days, depending on spread and endpoint coverage |
|
Distributed Denial of Service—DDoS (Equipment and IT-Related Disruption) |
3 |
4 |
2 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, potentially longer for sustained attacks |
|
Insider Threat (Equipment and IT-Related Disruption) |
4 |
5 |
5 |
5 |
4 |
3 |
5 |
5 – Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–2 weeks, depending on discovery and investigation complexity |
|
Data Breach (Equipment and IT-Related Disruption) |
5 |
4 |
5 |
5 |
4 |
3 |
5 |
5 – Finance; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks operationally, with legal and reputational effects continuing longer |
|
Network Failure (Equipment and IT-Related Disruption) |
3 |
5 |
2 |
3 |
3 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
8–24 hours, depending on failover and fault isolation |
|
Server Failure (Equipment and IT-Related Disruption) |
3 |
4 |
2 |
3 |
3 |
1 |
5 |
5 – Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
4–8 hours where high availability and spare capacity operate |
|
Database Corruption (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
4 |
2 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
3–7 days, depending on restoration and reconciliation complexity |
|
Cloud Service Outage (Equipment and IT-Related Disruption) |
4 |
5 |
3 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days, subject to provider restoration and workarounds |
|
Power Failure (Equipment and IT-Related Disruption) |
4 |
5 |
2 |
3 |
4 |
3 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
8–24 hours, potentially longer if backup power is exhausted |
|
Hardware Failure (Equipment and IT-Related Disruption) |
2 |
3 |
1 |
2 |
2 |
1 |
4 |
4 – Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–4 hours where spares and standard builds are available |
|
Software Failure (Equipment and IT-Related Disruption) |
3 |
4 |
3 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, depending on rollback and vendor support |
|
Internet Failure (Equipment and IT-Related Disruption) |
3 |
4 |
1 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, subject to alternate carrier capacity |
|
Authentication System Failure (Equipment and IT-Related Disruption) |
3 |
5 |
3 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
8–24 hours, depending on failover and emergency access |
|
Artificial Intelligence System Failure (Equipment and IT-Related Disruption) |
3 |
3 |
3 |
3 |
3 |
1 |
4 |
4 – Assets, IT Systems and Information |
3 – Possible |
4 × 3 = 12 |
High |
1–3 days where conventional analytical processes remain available |
High and Extreme Risk Analysis
Extreme Risks
Cyber Attack
The highest impacts affect operations, finance, legal and regulatory compliance, reputation, social responsibility, and information assets.
A coordinated cyberattack could interrupt procurement, inventory, logistics, supplier management, financial processing, and reporting while compromising sensitive information.
The likelihood is driven by the persistent global threat environment, reliance on interconnected systems, and exposure through third parties.
The most significant assumed control is ALPS Healthcare’s layered cybersecurity capability, including monitoring, endpoint protection, access management, backups, and incident response.
The principal weakness is that the effectiveness of controls, recovery readiness, and cyber-resilience testing have not been verified.
Management attention: Immediate executive oversight, technical control assurance, cyber-recovery testing, and remediation of critical vulnerabilities are required.
Supplier Failure
A critical supplier failure could interrupt the availability of essential medicines, medical supplies, equipment, or healthcare support services. The most severe consequences affect finance, operations, and social responsibility.
The likelihood is influenced by global supply-chain volatility, supplier concentration, geopolitical factors, and financial pressure on vendors.
Supplier qualification and contingency sourcing are the most significant assumed controls.
The principal weakness is uncertainty about alternative suppliers' readiness and the resilience of tier-two and tier-three dependencies.
Management attention: Urgent supplier-tiering, continuity assurance, substitute qualification, and joint recovery exercises are required.
Telecommunications Failure
Loss of telecommunications could prevent staff, suppliers, warehouses, healthcare institutions, and recovery teams from communicating or accessing cloud-hosted services. Operations and technology assets are the highest-impact areas.
The likelihood is driven by dependence on telecommunications for distributed operations and digital procurement. Redundant links and alternate communication channels are the most important assumed controls. The main weakness is the potential for common infrastructure, carrier, or last-mile dependencies.
Management attention: Validate carrier diversity and test automatic and manual failover.
Logistics Disruption
A major logistics disruption may delay delivery of medicines, consumables, equipment, and emergency supplies to healthcare institutions. Finance, operations, and social responsibility are the highest-impact areas.
The likelihood reflects Singapore’s dependence on efficient transport networks and international supply chains. Alternate carriers and route planning are the most significant assumed controls.
The principal weakness is potential dependency on common ports, routes, distribution hubs, or specialist cold-chain providers.
Management attention: Expand alternate carrier arrangements, map route concentration, and test emergency allocation and delivery procedures.
Third-Party Cyber Incident
A cyber incident affecting a critical supplier, outsourced service provider, logistics partner, or cloud provider may interrupt integrated services or compromise shared information. Operations and information assets are most exposed.
The likelihood is elevated by supply-chain connectivity and varying third-party control maturity. Cyber due diligence and contractual incident-notification requirements are the primary assumed controls. The main weakness is limited visibility beyond direct suppliers.
Management attention: Implement cyber-critical supplier tiering, continuous assurance, access restrictions, and joint incident exercises.
Single Source Dependency
Where ALPS Healthcare relies on a sole provider for an essential item or service, a disruption could immediately affect procurement and continuity of healthcare supply.
Finance, operations, and social responsibility are the highest-impact areas.
The likelihood is driven by specialist products, regulatory qualification requirements, intellectual property, or limited market capacity.
Safety stock and enhanced supplier monitoring are important assumed controls. The main weakness is the absence of a qualified substitute or transition route.
Management attention: Establish an enterprise sole-source register, qualify alternatives, and formally approve unavoidable dependencies.
Ransomware
Ransomware may encrypt applications, endpoints, databases, and file repositories while disrupting operations across multiple business units.
The highest impacts are across most organisational dimensions, except for direct workforce safety.
The likelihood is driven by widespread criminal activity, phishing, third-party compromise, and exploitation of unpatched systems.
Endpoint detection, segmentation, immutable backups, and incident response are the most significant assumed controls. The principal weakness is uncertainty regarding clean restoration and backup integrity.
Management attention: Conduct clean-room recovery tests and verify that critical services can be restored within approved business requirements.
Data Breach
A breach of supplier, employee, financial, procurement, or healthcare-related information could create significant financial, legal, reputational, and information consequences.
The likelihood reflects persistent cyber threats, complex data flows, user error, insider activity, and third-party access.
Encryption, access control, monitoring, and breach response procedures are the primary assumed controls. The key weakness is incomplete visibility of information flows and excessive access or retention.
Management attention: Complete data-flow mapping, access certification, breach exercises, and remediation of unnecessary data exposure.
Network Failure
A major network failure could simultaneously interrupt access to procurement, inventory, logistics, financial, communications, and reporting platforms.
Operations and technology assets are the highest-impact areas.
The likelihood reflects the complexity of network infrastructure and the possibility of device, carrier, configuration, or change failures.
Redundant network architecture and monitoring are the most significant assumed controls. The key weakness is the potential existence of unrecognised single points of failure.
Management attention: Perform architecture assurance and full failover testing.
High Risks
The following threats are assessed as High and require active ownership, proportionate mitigation, continuity arrangements, and periodic assurance:
- Flood
- Flash Flood
- Severe Storm
- Lightning
- Earthquake—Regional
- Haze
- Extreme Heat
- Pandemic-related Movement Restrictions
- Fire
- Explosion
- Structural Failure
- Active Assailant
- Public Transport Disruption
- Major Traffic Incident
- Pandemic
- Infectious Disease Outbreak
- Mass Illness
- High Staff Turnover
- Loss of Key Personnel
- Skills Shortage
- Workplace Violence
- Staff Fatigue
- Psychological Stress
- Mandatory Quarantine
- Outsourcing Failure
- Cloud Service Provider Failure
- Utility Failure
- Import Restrictions
- Vendor Insolvency
- Malware
- Distributed Denial of Service
- Insider Threat
- Server Failure
- Database Corruption
- Cloud Service Outage
- Power Failure
- Hardware Failure
- Software Failure
- Internet Failure
- Authentication System Failure
- Artificial Intelligence System Failure
Key themes across these high-risk areas include:
- dependency on specialist personnel and institutional knowledge;
- reliance on technology and external connectivity;
- limited visibility of supplier and outsourcing resilience;
- possible concentration in facilities, systems, carriers, and vendors;
- prolonged consequences from workforce and supply-chain disruption;
- the need to validate assumed alternate-workplace and manual-workaround arrangements;
- dependency on tested backups, failover capability, and incident escalation; and
- delayed regulatory, reputational, or stakeholder consequences after operational restoration.
The most urgent High-risk mitigation should focus on threats with a rating of 15 or 16, long expected disruption periods, significant personnel-safety implications, or serious public-health supply consequences.
Analysis by Impact Area
Finance
The greatest financial exposures arise from:
- Cyber Attack
- Ransomware
- Data Breach
- Database Corruption
- Supplier Failure
- Logistics Disruption
- Import Restrictions
- Vendor Insolvency
- Single Source Dependency
- Terrorism
The principal financial themes are emergency procurement premiums, system restoration, forensic and legal costs, replacement of products or infrastructure, contractual penalties, supplier transition expenses, inventory losses, and prolonged operational recovery.
Financial effects may continue after services resume because claims, remediation, litigation, regulatory responses, contract renegotiations, and supplier replacements may take months to complete.
Operations
Operations show the largest concentration of Major and Severe scores. The greatest operational exposures include:
- Cyber Attack and Ransomware
- Supplier Failure and Single Source Dependency
- Logistics Disruption
- Telecommunications and Network Failure
- Cloud and Outsourcing Failure
- Utility and Power Failure
- Pandemic
- Fire, Explosion, and Structural Failure
- Import Restrictions
- Database Corruption and Authentication Failure
These threats may interrupt several Critical Business Functions simultaneously. Technology, telecommunications, utilities, suppliers, warehouses, logistics providers, and specialist staff create interconnected dependencies that could amplify the impact.
Legal and Regulatory
The most significant legal and regulatory exposures arise from:
- Cyber Attack
- Ransomware
- Data Breach
- Insider Threat
- Database Corruption
- Terrorism
- Supplier, outsourcing, and cloud failures where contractual or public-sector obligations are affected
Consequences may include delayed statutory reporting, loss of audit trails, failure to preserve records, confidentiality breaches, procurement non-compliance, contract disputes, and criticism regarding governance or control effectiveness.
Some regulatory effects may emerge after a delay when investigations identify incomplete records, inadequate notifications, weak oversight, or failure to test controls.
Reputation and Image
The threats most likely to damage stakeholder confidence include:
- Cyber Attack
- Ransomware
- Data Breach
- Insider Threat
- Terrorism
- Supplier and logistics failures affecting healthcare supplies
- Database corruption
- Major workplace-safety incidents
Reputational damage may persist after normal operations resume, particularly when the incident affects patient-support supplies, sensitive information, public-sector confidence, or perceptions of inadequate preparedness.
Social Responsibility
The most severe social-responsibility impacts arise from:
- Supplier Failure
- Logistics Disruption
- Import Restrictions
- Single Source Dependency
- Pandemic
- Cyber Attack or Ransomware affecting healthcare supply operations
- Regional disasters interrupting essential imports
- Terrorism
The main concern is that disruption to ALPS Healthcare’s procurement and supply chain services could indirectly affect healthcare institutions, clinical operations, patients, and national health system resilience.
People
The greatest workforce and safety exposures include:
- Fire
- Explosion
- Structural Failure
- Terrorism
- Active Assailant
- Workplace Violence
- Pandemic
- Haze and Extreme Heat
- Infectious Disease Outbreak
- Fatigue and Psychological Stress
Life-safety risks require management attention even where the numerical rating is lower because likelihood is infrequent.
Workforce effects such as trauma, illness, fatigue, and skill loss may persist after operational services resume.
Assets, IT Systems and Information
The highest exposures arise from:
- Cyber Attack
- Ransomware
- Data Breach
- Insider Threat
- Database Corruption
- Network Failure
- Telecommunications Failure
- Cloud Service Provider Failure
- Cloud Service Outage
- Authentication System Failure
- Fire and Explosion
- Utility and Power Failure
The concentration of high scores in this area demonstrates the need for coordinated IT Disaster Recovery, cyber incident response, backup and restoration, identity resilience, network failover, cloud exit planning, and business-level manual workarounds.
Likelihood and Expected Disruption Analysis
Highest-Likelihood Threats
Cyber Attack is assessed as Almost Certain due to the persistent threat environment. Threats assessed as Likely include:
- Flash Flood
- Severe Storm
- Lightning
- Extreme Heat
- Public Transport Disruption
- Major Traffic Incident
- High Staff Turnover
- Skills Shortage
- Staff Fatigue
- Psychological Stress
- Supplier Failure
- Telecommunications Failure
- Logistics Disruption
- Third-Party Cyber Incident
- Single Source Dependency
- Ransomware
- Malware
- DDoS
- Data Breach
- Network Failure
- Hardware Failure
- Software Failure
- Internet Failure
These threats require preventive monitoring and tested operating procedures rather than treatment only after an incident occurs.
Low-Likelihood but Severe Threats
The principal low-likelihood but severe threats are:
- Terrorism
- Explosion
- Structural Failure
- Active Assailant
- Workplace Violence
- Earthquake—Regional
They should not be dismissed because of their lower likelihood.
Their potential consequences for safety, public interest, facilities, and service continuity justify scenario-specific response plans and exercises.
Short, Intense Disruptions
Threats expected to cause short but potentially intense interruptions include:
- Lightning
- Flash Flood
- Bomb Threat
- Major Traffic Incident
- Public Transport Disruption
- DDoS
- Server Failure
- Hardware Failure
- Software Failure
- Internet Failure
These require rapid detection, escalation, failover, remote-working activation, and short-duration manual workarounds.
Prolonged Disruptions
Threats capable of causing prolonged interruption include:
- Terrorism
- Skills Shortage
- Pandemic
- Structural Failure
- Import Restrictions
- Vendor Insolvency
- Supplier Failure
- Single Source Dependency
- Ransomware
- Data Breach
- Database Corruption
- Regional Earthquake Effects
These scenarios require sustainable recovery staffing, alternate suppliers or locations, backlog management, welfare support, and prolonged crisis-governance arrangements.
Externally Dependent Durations
The duration of the following threats depends heavily on third parties or public agencies:
- Flood and severe weather
- Bomb Threat and terrorism
- Public transport and traffic disruption
- Supplier and outsourcing failure
- Cloud service failure
- Telecommunications and utility failure
- Logistics disruption
- Import restrictions
- Vendor insolvency
- Third-party cyber incidents
- Internet and carrier outages
ALPS Healthcare should therefore establish escalation routes, information-sharing arrangements, contractual recovery commitments, and alternative service providers.
Threats Potentially Exceeding Recovery Capability
The following threats may exceed current recovery capability if assumed controls are incomplete or untested:
- widespread cyberattack;
- ransomware affecting primary and backup environments;
- prolonged supplier or single-source failure;
- extended import restriction;
- database corruption requiring complex reconciliation;
- multi-site pandemic workforce disruption;
- structural failure of a critical facility;
- prolonged cloud, network, telecommunications, or utility failure.
These threats require scenario-specific Business Continuity Strategies and evidence that recovery arrangements can operate for the expected duration.
Table RAR P3A: Risk Prioritisation for ALPS Healthcare
|
Priority Rank |
Threat |
Highest Impact Area |
Likelihood |
Risk Rating |
Risk Level |
Expected Disruption Period |
|
1 |
Cyber Attack |
Multiple areas, including Operations and Information |
5 – Almost Certain |
25 |
Extreme |
3–7 days |
|
2 |
Ransomware |
Multiple areas, including Operations and Information |
4 – Likely |
20 |
Extreme |
1–2 weeks |
|
3 |
Supplier Failure |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Supplier continuity assurance and diversification |
|
4 |
Single Source Dependency |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Eliminate concentration or obtain formal acceptance |
|
5 |
Logistics Disruption |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Alternate logistics strategy and joint exercises |
|
6 |
Third-Party Cyber Incident |
Operations and Information |
4 – Likely |
20 |
Extreme |
Third-party cyber assurance and response planning |
|
7 |
Data Breach |
Finance, Legal, Reputation and Information |
4 – Likely |
20 |
Extreme |
Data-protection remediation and breach exercise |
|
8 |
Telecommunications Failure |
Operations and Information |
4 – Likely |
20 |
Extreme |
Carrier diversity and failover testing |
|
9 |
Network Failure |
Operations and Information |
4 – Likely |
20 |
Extreme |
Network resilience assessment and failover test |
|
10 |
Severe Storm |
Operations |
4 – Likely |
16 |
High |
Weather continuity and facility-readiness review |
|
11 |
Extreme Heat |
People |
4 – Likely |
16 |
High |
Workforce and cold-chain heat controls |
|
12 |
High Staff Turnover |
Operations and People |
4 – Likely |
16 |
High |
Workforce retention, succession and knowledge transfer |
|
13 |
Skills Shortage |
Operations and People |
4 – Likely |
16 |
High |
Critical-skills programme and cross-training |
|
14 |
Staff Fatigue |
Operations and People |
4 – Likely |
16 |
High |
Recovery rostering and welfare controls |
|
15 |
Psychological Stress |
People |
4 – Likely |
16 |
High |
Crisis welfare and psychological support |
|
16 |
Malware |
Operations and Information |
4 – Likely |
16 |
High |
Endpoint and application-control assurance |
|
17 |
DDoS |
Operations and Information |
4 – Likely |
16 |
High |
Provider protection and response testing |
|
18 |
Hardware Failure |
Information assets |
4 – Likely |
16 |
High |
Lifecycle management and minimum spare holdings |
|
19 |
Software Failure |
Operations and Information |
4 – Likely |
16 |
High |
Release, rollback and workaround improvement |
|
20 |
Internet Failure |
Operations and Information |
4 – Likely |
16 |
High |
Dual-provider connectivity and capacity test |
|
21 |
Lightning |
Information assets |
4 – Likely |
16 |
High |
Electrical protection and recovery assurance |
|
22 |
Fire |
Operations, People and Assets |
3 – Possible |
15 |
High |
Facility recovery strategy and fire assurance |
|
23 |
Pandemic |
Operations, Social Responsibility and People |
3 – Possible |
15 |
High |
Pandemic continuity and workforce sustainability |
|
24 |
Outsourcing Failure |
Operations |
3 – Possible |
15 |
High |
Retained capability and exit-plan validation |
|
25 |
Cloud Service Provider Failure |
Operations and Information |
3 – Possible |
15 |
High |
Cloud portability and provider assurance |
|
26 |
Utility Failure |
Operations and Information |
3 – Possible |
15 |
High |
Extended utility-outage strategy |
|
27 |
Import Restrictions |
Finance, Operations and Social Responsibility |
3 – Possible |
15 |
High |
Substitute qualification and inventory strategy |
|
28 |
Vendor Insolvency |
Finance and Operations |
3 – Possible |
15 |
High |
Financial monitoring and transition planning |
|
29 |
Insider Threat |
Operations, Legal, Reputation and Information |
3 – Possible |
15 |
High |
Privileged-access and insider-risk controls |
|
30 |
Database Corruption |
Multiple areas |
3 – Possible |
15 |
High |
Point-in-time recovery and reconciliation testing |
|
31 |
Cloud Service Outage |
Operations and Information |
3 – Possible |
15 |
High |
Multi-zone recovery and offline procedures |
|
32 |
Power Failure |
Operations and Information |
3 – Possible |
15 |
High |
Power failover and fuel resilience testing |
|
33 |
Authentication System Failure |
Operations and Information |
3 – Possible |
15 |
High |
IAM failover and emergency-access testing |
|
34 |
Flash Flood |
Operations |
4 – Likely |
12 |
High |
Remote-work and access-route planning |
|
35 |
Flood |
Operations |
3 – Possible |
12 |
High |
Site flood assessment and protection |
|
36 |
Haze |
People |
3 – Possible |
12 |
High |
Air-quality and remote-work arrangements |
|
37 |
Pandemic-related Movement Restrictions |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Scalable remote-work arrangements |
|
38 |
Public Transport Disruption |
Operations and People |
4 – Likely |
12 |
High |
Essential-worker transport arrangements |
|
39 |
Major Traffic Incident |
Operations and Social Responsibility |
4 – Likely |
12 |
High |
Alternate routes and critical-delivery escalation |
|
40 |
Infectious Disease Outbreak |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Local outbreak response planning |
|
41 |
Mass Illness |
Operations and People |
3 – Possible |
12 |
High |
Minimum staffing and backup rosters |
|
42 |
Loss of Key Personnel |
Operations and People |
3 – Possible |
12 |
High |
Succession and delegated authority testing |
|
43 |
Mandatory Quarantine |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Remote approval and workforce segregation |
|
44 |
Artificial Intelligence System Failure |
Information assets |
3 – Possible |
12 |
High |
AI governance and manual fallback |
|
45 |
Earthquake—Regional |
Operations and Social Responsibility |
2 – Unlikely |
10 |
High |
Regional supply-chain scenario planning |
|
46 |
Explosion |
Operations, People and Assets |
2 – Unlikely |
10 |
High |
Site emergency and alternate-facility planning |
|
47 |
Structural Failure |
Operations and People |
2 – Unlikely |
10 |
High |
Structural assurance and relocation planning |
|
48 |
Active Assailant |
People |
2 – Unlikely |
10 |
High |
Physical-security and staff-protection exercise |
|
49 |
Workplace Violence |
People |
2 – Unlikely |
10 |
High |
Threat assessment and response arrangements |
|
50 |
Chemical Spill |
Operations, Social Responsibility and People |
2 – Unlikely |
8 |
Moderate |
Hazardous-material and spill-response assurance |
|
51 |
Gas Leak |
People |
2 – Unlikely |
8 |
Moderate |
Detection, isolation and evacuation assurance |
|
52 |
Bomb Threat |
Operations, Reputation, Social Responsibility and People |
2 – Unlikely |
8 |
Moderate |
Security procedures and exercise |
|
53 |
Terrorism |
All impact areas |
1 – Rare |
5 |
Moderate |
Crisis scenario planning despite low likelihood |
Note: The register contains 53 distinct prioritised entries because “Cloud Service Provider Failure” and “Cloud Service Outage” have been retained as separate threats reflecting, respectively, third-party dependency failure and direct application-service unavailability. No approved threat has been intentionally consolidated.
Management Validation
Review by Threat Owners
Each threat should be allocated to an accountable owner. Typical owners may include:
- Facilities and Security for premises and denial-of-access threats;
- Human Resources for workforce threats;
- Procurement and Supply Chain for supplier and logistics threats;
- ICT and Information Security for technology and cyber threats;
- Business Continuity Management for cross-functional recovery exposures; and
- Enterprise Risk Management for methodology, challenge, and governance.
Threat owners should confirm that the scenario, impact scores, likelihood, disruption duration, and assumed controls accurately reflect their area.
Review by Critical Business Function Owners
Critical Business Function owners should validate whether the assessed disruption could affect:
- procurement and sourcing;
- pharmaceuticals and medical supplies;
- inventory and replenishment;
- warehousing and logistics;
- healthcare institution coordination;
- supplier payments;
- information systems;
- governance and compliance; and
- crisis and continuity management.
They should identify where the threat may simultaneously disrupt multiple functions or create downstream consequences for healthcare institutions.
Specialist Validation
ICT, cybersecurity, facilities, security, human resources, procurement, legal, finance, data protection, and records-management specialists should validate the assumptions relevant to their professional areas.
Examples include:
- ICT confirmation of backup, replication, RTO, RPO, and failover capability;
- cybersecurity validation against current threat intelligence;
- Facilities confirmation of fire, power, flood, and structural controls;
- HR validation of absenteeism, skills, succession, and welfare assumptions;
- Procurement confirmation of supplier concentration, alternatives, and contract rights;
- Legal confirmation of statutory, contractual, privacy, and notification consequences; and
- Finance validation of cost ranges, insurance, deductibles, and emergency expenditure.
Confirm Existing Control Effectiveness
Controls identified in RAR Part 2 should be tested rather than accepted solely from policy documentation. Validation evidence may include:
- inspection and maintenance certificates;
- backup and restoration reports;
- cyber and disaster-recovery test results;
- alternate-site exercises;
- remote-working capacity tests;
- supplier continuity evidence;
- service-level performance;
- access reviews;
- incident-response exercises;
- staff competency and attendance records;
- audit results; and
- completed corrective actions.
Where controls are untested, outdated, incomplete, or dependent on a single person or supplier, the likelihood and disruption-duration assumptions should be reconsidered.
Review Incident and Threat Information
The assessment should be compared with:
- internal incidents and near misses;
- supplier outages and performance failures;
- national weather and infrastructure information;
- public-health advisories;
- cyber threat intelligence;
- sector incidents;
- audit and assurance findings;
- insurance claims;
- employee turnover and absenteeism data; and
- exercise observations.
\Validate Impact Assumptions
Financial impacts should be supported by cost data, including emergency purchasing, system recovery, supplier transition, overtime, temporary facilities, professional services, contract penalties, legal expenditure, and product replacement.
Legal and regulatory impacts should be confirmed by Legal, Compliance, Data Protection, Procurement Governance, and relevant public-sector stakeholders.
Public-interest and social-responsibility consequences should be reviewed with healthcare institution stakeholders where supply interruption could affect clinical services or patient support.
Enterprise Risk and BCM Challenge
Enterprise Risk Management and Business Continuity Management should independently challenge:
- inconsistent scoring;
- unsupported low likelihoods;
- understated cross-functional impacts;
- optimistic disruption periods;
- reliance on untested controls;
- duplication or gaps in threat coverage;
- dependency concentration; and
- proposed risk acceptance.
Senior Management Approval
The completed assessment should be submitted to the appropriate senior management or risk-governance body for:
- approval of the assessment basis;
- confirmation of the applicable risk matrix;
- endorsement of High and Extreme risk priorities;
- allocation of mitigation resources;
- approval or rejection of residual-risk acceptance;
- assignment of accountable executives; and
- confirmation of review dates.
Any management override of a proposed score should be documented with its rationale, approving authority, supporting evidence, and implications for treatment.
Periodic Reassessment
The assessment should be reviewed:
- at least annually;
- following a major incident or near miss;
- after a business continuity or disaster-recovery exercise;
- when a critical supplier or system changes;
- after significant organisational restructuring;
- when new technology is introduced;
- when risk appetite or regulatory obligations change; and
- when threat intelligence indicates a material change.
The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.
By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.
The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.
More Information About Business Continuity Management Courses


![[BCM] [ALPS] [Full Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/a577c05a-ab89-4043-9a89-1dea0d883afc.png)

![Banner [BCM] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/1626b4db-b5dd-4c9d-8d1d-c84aa9a691f1.png)


![[BCM] [ALPS] [3/4 Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/5bb3d163-ccf4-4942-8e51-90cb0e0de84f.png)
![[BCM] [ALPS] [E3] [BIA] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/3e0b35d2-08b6-4caf-b7db-144625ec8145.png)
![[BCM] [ALPS] [E3] [BIA] [PS] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/ab611654-bce2-450c-affc-3970de6c8909.png)
![[BCM] [ALPS] [E3] [RAR] [T1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/806c27e6-1db5-42a2-ac84-e0df3624bc49.png)
![[BCM] [ALPS] [E3] [RAR] [T2] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/bf6da142-014d-4c47-83cf-f31e0c55b75e.png)
![[BCM] [ALPS] [E3] [BCS] [T1] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/25548d11-adb7-4e6e-9a5a-054db2ea377d.png)
![[BCM] [ALPS] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/94f8b16c-55da-4543-a948-448f2241296e.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





