Ebook

[BCM] [ALPS] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment

Written by Dr Goh Moh Heng | Aug 5, 2026, 4:00:59 PM

 

RAR P3: Risk Impact and Likelihood Assessment for ALPS Healthcare

Introduction

RAR Part 3 converts the Threat Register established in Part 1 and the treatment-and-control assessment completed in Part 2 into prioritised risk information.

It evaluates the credible consequences of each approved threat, estimates the likelihood of occurrence, calculates a current risk rating, and estimates how long the resulting disruption may affect ALPS Healthcare.

The assessment represents the current or residual risk after considering the assumed existing controls documented in RAR Part 2, but before implementing the additional planned controls. Because detailed incident data, verified control-testing results, financial exposure information, and ALPS Healthcare’s approved risk matrix were not supplied, the scores in this chapter are indicative. They should not be treated as confirmed organisational risk ratings until they have been reviewed and approved through ALPS Healthcare’s risk-governance process.

Impact is assessed across seven dimensions:

  1. Finance
  2. Operations
  3. Legal and Regulatory
  4. Reputation and Image
  5. Social Responsibility
  6. People
  7. Assets, IT Systems and Information

Assessing several impact dimensions prevents management from relying only on financial consequences.

A disruption may create relatively limited direct expenditure while significantly affecting the continuity of healthcare supply, information security, workforce safety, regulatory obligations, stakeholder confidence, or Singapore’s public healthcare institutions.

The highest credible score among the seven impact areas is used as the overall impact score. This approach ensures that a severe consequence in one important area is not diluted by lower scores elsewhere.

Likelihood is assessed independently and reflects the realistic possibility of the threat occurring, taking into account geographic exposure, operating conditions, sector experience, current vulnerabilities, and the assumed effectiveness of existing controls.

The current risk rating is calculated as:

Risk Rating = Highest Impact Score × Likelihood Score

The default risk bands used in this chapter are:

 

Risk Rating

Risk Level

1–4

Very Low/ Low

5–9

Moderate

10–16

High

17–25

Very High (Extreme)

 

The expected disruption period estimates the credible duration of operational interruption, accounting for existing controls.

It is neither the Recovery Time Objective nor the Maximum Tolerable Period of Disruption.

The duration may depend on facility access, supplier recovery, technology restoration, staff availability, regulatory restrictions, or the effectiveness of alternate operating arrangements.

Numerical ratings are decision-support tools. They must be interpreted together with professional judgement, stakeholder obligations, control effectiveness, operational dependencies, public-interest consequences, and ALPS Healthcare’s approved risk appetite.

 

Scoring Key

  • 1 – Very Low (Insignificant)
  • 2 – Low (Minor)
  • 3 – Moderate
  • 4 – High (Major)
  • 5 – Very High (Severe)

Table RAR P3: Risk Impact and Likelihood Assessment for ALPS Healthcare

 

Threat

Finance

Operat-ions

Legal & Regulatory

Reputation & Image

Social Respon-sibility

People

Assets / IT Systems / Information

Highest Impact Score

Likelihood

Risk Rating

Risk Level

Expected Period of Disruption

Flood (Denial of Access – Natural Disaster)

3

4

3

3

3

3

3

4 – Operations

3 – Possible

4 × 3 = 12

High

8–24 hours, depending on site access and drainage conditions

Flash Flood (Denial of Access – Natural Disaster)

2

3

2

2

2

2

2

3 – Operations

4 – Likely

3 × 4 = 12

High

4–8 hours, primarily affecting commuting and deliveries

Severe Storm (Denial of Access – Natural Disaster)

3

4

2

3

3

3

3

4 – Operations

4 – Likely

4 × 4 = 16

High

8–24 hours, depending on transport and utility restoration

Lightning (Denial of Access – Natural Disaster)

2

3

1

2

2

2

4

4 – Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

1–4 hours unless critical equipment is damaged

Earthquake—Regional (Denial of Access – Natural Disaster)

4

5

3

4

5

2

3

5 – Operations; Social Responsibility

2 – Unlikely

5 × 2 = 10

High

1–2 weeks due to regional manufacturing and logistics disruption

Haze (Denial of Access – Natural Disaster)

2

3

2

2

3

4

1

4 – People

3 – Possible

4 × 3 = 12

High

3–7 days, potentially longer during persistent regional haze

Extreme Heat (Denial of Access – Natural Disaster)

2

3

2

2

3

4

3

4 – People

4 – Likely

4 × 4 = 16

High

3–7 days during prolonged heat conditions

Pandemic-related Movement Restrictions (Denial of Access – Natural Disaster)

3

4

3

3

4

4

2

4 – Operations; Social Responsibility; People

3 – Possible

4 × 3 = 12

High

1–2 weeks, potentially longer if restrictions escalate

Fire (Denial of Access – Man-made Disaster)

4

5

3

4

4

5

5

5 – Operations; People; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

1–2 weeks, depending on damage and alternate-site activation

Explosion (Denial of Access – Man-made Disaster)

4

5

3

4

4

5

5

5 – Operations; People; Assets, IT Systems and Information

2 – Unlikely

5 × 2 = 10

High

1–2 weeks, potentially longer for major structural damage

Chemical Spill (Denial of Access – Man-made Disaster)

3

4

3

3

4

4

3

4 – Operations; Social Responsibility; People

2 – Unlikely

4 × 2 = 8

Moderate

1–3 days, depending on containment and decontamination

Gas Leak (Denial of Access – Man-made Disaster)

2

3

2

2

3

4

2

4 – People

2 – Unlikely

4 × 2 = 8

Moderate

8–24 hours, subject to detection, isolation and safety clearance

Structural Failure (Denial of Access – Man-made Disaster)

4

5

3

4

4

5

4

5 – Operations; People

2 – Unlikely

5 × 2 = 10

High

2–4 weeks if the facility requires major repair or relocation

Bomb Threat (Denial of Access – Man-made Disaster)

2

4

2

4

4

4

2

4 – Operations; Reputation and Image; Social Responsibility; People

2 – Unlikely

4 × 2 = 8

Moderate

4–8 hours, subject to police investigation and clearance

Terrorism (Denial of Access – Man-made Disaster)

5

5

5

5

5

5

5

5 – All impact areas

1 – Rare

5 × 1 = 5

Moderate

More than 1 month in a severe multi-site or infrastructure scenario

Active Assailant (Denial of Access – Man-made Disaster)

3

4

3

4

4

5

2

5 – People

2 – Unlikely

5 × 2 = 10

High

1–3 days, with longer workforce and psychological effects

Public Transport Disruption (Denial of Access – Man-made Disaster)

2

3

1

2

2

3

1

3 – Operations; People

4 – Likely

3 × 4 = 12

High

4–8 hours, depending on the transport network affected

Major Traffic Incident (Denial of Access – Man-made Disaster)

2

3

1

2

3

2

1

3 – Operations; Social Responsibility

4 – Likely

3 × 4 = 12

High

1–4 hours, with longer delays for critical delivery routes

Pandemic (Unavailability of People)

4

5

4

4

5

5

3

5 – Operations; Social Responsibility; People

3 – Possible

5 × 3 = 15

High

2–4 weeks, potentially extending for successive infection waves

Infectious Disease Outbreak (Unavailability of People)

3

4

3

3

4

4

2

4 – Operations; Social Responsibility; People

3 – Possible

4 × 3 = 12

High

3–7 days for a localised team or facility outbreak

Mass Illness (Unavailability of People)

3

4

2

3

3

4

2

4 – Operations; People

3 – Possible

4 × 3 = 12

High

3–7 days, depending on workforce concentration

High Staff Turnover (Unavailability of People)

3

4

2

3

3

4

2

4 – Operations; People

4 – Likely

4 × 4 = 16

High

2–4 weeks, with capability effects potentially lasting longer

Loss of Key Personnel (Unavailability of People)

3

4

3

3

3

4

2

4 – Operations; People

3 – Possible

4 × 3 = 12

High

1–2 weeks, depending on succession and delegation readiness

Skills Shortage (Unavailability of People)

3

4

2

3

3

4

2

4 – Operations; People

4 – Likely

4 × 4 = 16

High

More than 1 month because specialist capability may be difficult to replace

Workplace Violence (Unavailability of People)

2

3

2

3

3

5

2

5 – People

2 – Unlikely

5 × 2 = 10

High

1–3 days, with potentially longer welfare consequences

Staff Fatigue (Unavailability of People)

2

4

2

3

3

4

1

4 – Operations; People

4 – Likely

4 × 4 = 16

High

1–2 weeks during prolonged incident response or backlog clearance

Psychological Stress (Unavailability of People)

2

3

2

3

3

4

1

4 – People

4 – Likely

4 × 4 = 16

High

1–2 weeks, with some effects continuing after restoration

Mandatory Quarantine (Unavailability of People)

3

4

3

3

4

4

2

4 – Operations; Social Responsibility; People

3 – Possible

4 × 3 = 12

High

3–7 days for affected teams; longer for repeated exposure

Supplier Failure (Disruption to the Supply Chain)

5

5

4

4

5

2

2

5 – Finance; Operations; Social Responsibility

4 – Likely

5 × 4 = 20

Extreme

1–2 weeks, depending on inventory and alternate supplier availability

Outsourcing Failure (Disruption to the Supply Chain)

4

5

4

4

4

2

3

5 – Operations

3 – Possible

5 × 3 = 15

High

3–7 days, depending on retained capability and exit arrangements

Cloud Service Provider Failure (Disruption to the Supply Chain)

4

5

4

4

4

2

5

5 – Operations; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

1–3 days, depending on provider recovery and data portability

Telecommunications Failure (Disruption to the Supply Chain)

3

5

2

3

3

2

5

5 – Operations; Assets, IT Systems and Information

4 – Likely

5 × 4 = 20

Extreme

8–24 hours, subject to carrier redundancy and failover

Utility Failure (Disruption to the Supply Chain)

4

5

3

3

4

3

5

5 – Operations; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

1–3 days in an extended electricity or facility-service outage

Logistics Disruption (Disruption to the Supply Chain)

5

5

3

4

5

2

2

5 – Finance; Operations; Social Responsibility

4 – Likely

5 × 4 = 20

Extreme

3–7 days, depending on carriers, routes and inventory buffers

Import Restrictions (Disruption to the Supply Chain)

5

5

4

4

5

2

2

5 – Finance; Operations; Social Responsibility

3 – Possible

5 × 3 = 15

High

2–4 weeks, depending on product substitution and approvals

Vendor Insolvency (Disruption to the Supply Chain)

5

5

4

4

4

2

2

5 – Finance; Operations

3 – Possible

5 × 3 = 15

High

2–4 weeks, depending on transition complexity

Third-Party Cyber Incident (Disruption to the Supply Chain)

4

5

4

4

4

2

5

5 – Operations; Assets, IT Systems and Information

4 – Likely

5 × 4 = 20

Extreme

3–7 days, potentially longer where data or integrations are compromised

Single Source Dependency (Disruption to the Supply Chain)

5

5

4

4

5

2

2

5 – Finance; Operations; Social Responsibility

4 – Likely

5 × 4 = 20

Extreme

1–2 weeks, potentially longer where no substitute is available

Cyber Attack (Equipment and IT-Related Disruption)

5

5

5

5

5

3

5

5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information

5 – Almost Certain

5 × 5 = 25

Extreme

3–7 days, with investigations and remediation continuing longer

Ransomware (Equipment and IT-Related Disruption)

5

5

5

5

5

3

5

5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information

4 – Likely

5 × 4 = 20

Extreme

1–2 weeks, depending on containment and clean restoration

Malware (Equipment and IT-Related Disruption)

3

4

3

3

3

2

4

4 – Operations; Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

1–3 days, depending on spread and endpoint coverage

Distributed Denial of Service—DDoS (Equipment and IT-Related Disruption)

3

4

2

3

3

1

4

4 – Operations; Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

4–8 hours, potentially longer for sustained attacks

Insider Threat (Equipment and IT-Related Disruption)

4

5

5

5

4

3

5

5 – Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

1–2 weeks, depending on discovery and investigation complexity

Data Breach (Equipment and IT-Related Disruption)

5

4

5

5

4

3

5

5 – Finance; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information

4 – Likely

5 × 4 = 20

Extreme

1–2 weeks operationally, with legal and reputational effects continuing longer

Network Failure (Equipment and IT-Related Disruption)

3

5

2

3

3

2

5

5 – Operations; Assets, IT Systems and Information

4 – Likely

5 × 4 = 20

Extreme

8–24 hours, depending on failover and fault isolation

Server Failure (Equipment and IT-Related Disruption)

3

4

2

3

3

1

5

5 – Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

4–8 hours where high availability and spare capacity operate

Database Corruption (Equipment and IT-Related Disruption)

5

5

5

5

4

2

5

5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

3–7 days, depending on restoration and reconciliation complexity

Cloud Service Outage (Equipment and IT-Related Disruption)

4

5

3

4

4

2

5

5 – Operations; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

1–3 days, subject to provider restoration and workarounds

Power Failure (Equipment and IT-Related Disruption)

4

5

2

3

4

3

5

5 – Operations; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

8–24 hours, potentially longer if backup power is exhausted

Hardware Failure (Equipment and IT-Related Disruption)

2

3

1

2

2

1

4

4 – Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

1–4 hours where spares and standard builds are available

Software Failure (Equipment and IT-Related Disruption)

3

4

3

3

3

1

4

4 – Operations; Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

4–8 hours, depending on rollback and vendor support

Internet Failure (Equipment and IT-Related Disruption)

3

4

1

3

3

1

4

4 – Operations; Assets, IT Systems and Information

4 – Likely

4 × 4 = 16

High

4–8 hours, subject to alternate carrier capacity

Authentication System Failure (Equipment and IT-Related Disruption)

3

5

3

4

4

2

5

5 – Operations; Assets, IT Systems and Information

3 – Possible

5 × 3 = 15

High

8–24 hours, depending on failover and emergency access

Artificial Intelligence System Failure (Equipment and IT-Related Disruption)

3

3

3

3

3

1

4

4 – Assets, IT Systems and Information

3 – Possible

4 × 3 = 12

High

1–3 days where conventional analytical processes remain available

 

High and Extreme Risk Analysis

Extreme Risks

Cyber Attack

The highest impacts affect operations, finance, legal and regulatory compliance, reputation, social responsibility, and information assets.

A coordinated cyberattack could interrupt procurement, inventory, logistics, supplier management, financial processing, and reporting while compromising sensitive information.

The likelihood is driven by the persistent global threat environment, reliance on interconnected systems, and exposure through third parties.

The most significant assumed control is ALPS Healthcare’s layered cybersecurity capability, including monitoring, endpoint protection, access management, backups, and incident response.

The principal weakness is that the effectiveness of controls, recovery readiness, and cyber-resilience testing have not been verified.

Management attention: Immediate executive oversight, technical control assurance, cyber-recovery testing, and remediation of critical vulnerabilities are required.

Supplier Failure

A critical supplier failure could interrupt the availability of essential medicines, medical supplies, equipment, or healthcare support services. The most severe consequences affect finance, operations, and social responsibility.

The likelihood is influenced by global supply-chain volatility, supplier concentration, geopolitical factors, and financial pressure on vendors.

Supplier qualification and contingency sourcing are the most significant assumed controls.

The principal weakness is uncertainty about alternative suppliers' readiness and the resilience of tier-two and tier-three dependencies.

Management attention: Urgent supplier-tiering, continuity assurance, substitute qualification, and joint recovery exercises are required.

Telecommunications Failure

Loss of telecommunications could prevent staff, suppliers, warehouses, healthcare institutions, and recovery teams from communicating or accessing cloud-hosted services. Operations and technology assets are the highest-impact areas.

The likelihood is driven by dependence on telecommunications for distributed operations and digital procurement. Redundant links and alternate communication channels are the most important assumed controls. The main weakness is the potential for common infrastructure, carrier, or last-mile dependencies.

Management attention: Validate carrier diversity and test automatic and manual failover.

Logistics Disruption

A major logistics disruption may delay delivery of medicines, consumables, equipment, and emergency supplies to healthcare institutions. Finance, operations, and social responsibility are the highest-impact areas.

The likelihood reflects Singapore’s dependence on efficient transport networks and international supply chains. Alternate carriers and route planning are the most significant assumed controls.

The principal weakness is potential dependency on common ports, routes, distribution hubs, or specialist cold-chain providers.

Management attention: Expand alternate carrier arrangements, map route concentration, and test emergency allocation and delivery procedures.

Third-Party Cyber Incident

A cyber incident affecting a critical supplier, outsourced service provider, logistics partner, or cloud provider may interrupt integrated services or compromise shared information. Operations and information assets are most exposed.

The likelihood is elevated by supply-chain connectivity and varying third-party control maturity. Cyber due diligence and contractual incident-notification requirements are the primary assumed controls. The main weakness is limited visibility beyond direct suppliers.

Management attention: Implement cyber-critical supplier tiering, continuous assurance, access restrictions, and joint incident exercises.

Single Source Dependency

Where ALPS Healthcare relies on a sole provider for an essential item or service, a disruption could immediately affect procurement and continuity of healthcare supply.

Finance, operations, and social responsibility are the highest-impact areas.

The likelihood is driven by specialist products, regulatory qualification requirements, intellectual property, or limited market capacity.

Safety stock and enhanced supplier monitoring are important assumed controls. The main weakness is the absence of a qualified substitute or transition route.

Management attention: Establish an enterprise sole-source register, qualify alternatives, and formally approve unavoidable dependencies.

Ransomware

Ransomware may encrypt applications, endpoints, databases, and file repositories while disrupting operations across multiple business units.

The highest impacts are across most organisational dimensions, except for direct workforce safety.

The likelihood is driven by widespread criminal activity, phishing, third-party compromise, and exploitation of unpatched systems.

Endpoint detection, segmentation, immutable backups, and incident response are the most significant assumed controls. The principal weakness is uncertainty regarding clean restoration and backup integrity.

Management attention: Conduct clean-room recovery tests and verify that critical services can be restored within approved business requirements.

Data Breach

A breach of supplier, employee, financial, procurement, or healthcare-related information could create significant financial, legal, reputational, and information consequences.

The likelihood reflects persistent cyber threats, complex data flows, user error, insider activity, and third-party access.

Encryption, access control, monitoring, and breach response procedures are the primary assumed controls. The key weakness is incomplete visibility of information flows and excessive access or retention.

Management attention: Complete data-flow mapping, access certification, breach exercises, and remediation of unnecessary data exposure.

Network Failure

A major network failure could simultaneously interrupt access to procurement, inventory, logistics, financial, communications, and reporting platforms.

Operations and technology assets are the highest-impact areas.

The likelihood reflects the complexity of network infrastructure and the possibility of device, carrier, configuration, or change failures.

Redundant network architecture and monitoring are the most significant assumed controls. The key weakness is the potential existence of unrecognised single points of failure.

Management attention: Perform architecture assurance and full failover testing.

 

High Risks

The following threats are assessed as High and require active ownership, proportionate mitigation, continuity arrangements, and periodic assurance:

  • Flood
  • Flash Flood
  • Severe Storm
  • Lightning
  • Earthquake—Regional
  • Haze
  • Extreme Heat
  • Pandemic-related Movement Restrictions
  • Fire
  • Explosion
  • Structural Failure
  • Active Assailant
  • Public Transport Disruption
  • Major Traffic Incident
  • Pandemic
  • Infectious Disease Outbreak
  • Mass Illness
  • High Staff Turnover
  • Loss of Key Personnel
  • Skills Shortage
  • Workplace Violence
  • Staff Fatigue
  • Psychological Stress
  • Mandatory Quarantine
  • Outsourcing Failure
  • Cloud Service Provider Failure
  • Utility Failure
  • Import Restrictions
  • Vendor Insolvency
  • Malware
  • Distributed Denial of Service
  • Insider Threat
  • Server Failure
  • Database Corruption
  • Cloud Service Outage
  • Power Failure
  • Hardware Failure
  • Software Failure
  • Internet Failure
  • Authentication System Failure
  • Artificial Intelligence System Failure

Key themes across these high-risk areas include:

  • dependency on specialist personnel and institutional knowledge;
  • reliance on technology and external connectivity;
  • limited visibility of supplier and outsourcing resilience;
  • possible concentration in facilities, systems, carriers, and vendors;
  • prolonged consequences from workforce and supply-chain disruption;
  • the need to validate assumed alternate-workplace and manual-workaround arrangements;
  • dependency on tested backups, failover capability, and incident escalation; and
  • delayed regulatory, reputational, or stakeholder consequences after operational restoration.

The most urgent High-risk mitigation should focus on threats with a rating of 15 or 16, long expected disruption periods, significant personnel-safety implications, or serious public-health supply consequences.

Analysis by Impact Area

Finance

The greatest financial exposures arise from:

  • Cyber Attack
  • Ransomware
  • Data Breach
  • Database Corruption
  • Supplier Failure
  • Logistics Disruption
  • Import Restrictions
  • Vendor Insolvency
  • Single Source Dependency
  • Terrorism

The principal financial themes are emergency procurement premiums, system restoration, forensic and legal costs, replacement of products or infrastructure, contractual penalties, supplier transition expenses, inventory losses, and prolonged operational recovery.

Financial effects may continue after services resume because claims, remediation, litigation, regulatory responses, contract renegotiations, and supplier replacements may take months to complete.

Operations

Operations show the largest concentration of Major and Severe scores. The greatest operational exposures include:

  • Cyber Attack and Ransomware
  • Supplier Failure and Single Source Dependency
  • Logistics Disruption
  • Telecommunications and Network Failure
  • Cloud and Outsourcing Failure
  • Utility and Power Failure
  • Pandemic
  • Fire, Explosion, and Structural Failure
  • Import Restrictions
  • Database Corruption and Authentication Failure

These threats may interrupt several Critical Business Functions simultaneously. Technology, telecommunications, utilities, suppliers, warehouses, logistics providers, and specialist staff create interconnected dependencies that could amplify the impact.

Legal and Regulatory

The most significant legal and regulatory exposures arise from:

  • Cyber Attack
  • Ransomware
  • Data Breach
  • Insider Threat
  • Database Corruption
  • Terrorism
  • Supplier, outsourcing, and cloud failures where contractual or public-sector obligations are affected

Consequences may include delayed statutory reporting, loss of audit trails, failure to preserve records, confidentiality breaches, procurement non-compliance, contract disputes, and criticism regarding governance or control effectiveness.

Some regulatory effects may emerge after a delay when investigations identify incomplete records, inadequate notifications, weak oversight, or failure to test controls.

Reputation and Image

The threats most likely to damage stakeholder confidence include:

  • Cyber Attack
  • Ransomware
  • Data Breach
  • Insider Threat
  • Terrorism
  • Supplier and logistics failures affecting healthcare supplies
  • Database corruption
  • Major workplace-safety incidents

Reputational damage may persist after normal operations resume, particularly when the incident affects patient-support supplies, sensitive information, public-sector confidence, or perceptions of inadequate preparedness.

Social Responsibility

The most severe social-responsibility impacts arise from:

  • Supplier Failure
  • Logistics Disruption
  • Import Restrictions
  • Single Source Dependency
  • Pandemic
  • Cyber Attack or Ransomware affecting healthcare supply operations
  • Regional disasters interrupting essential imports
  • Terrorism

The main concern is that disruption to ALPS Healthcare’s procurement and supply chain services could indirectly affect healthcare institutions, clinical operations, patients, and national health system resilience.

People

The greatest workforce and safety exposures include:

  • Fire
  • Explosion
  • Structural Failure
  • Terrorism
  • Active Assailant
  • Workplace Violence
  • Pandemic
  • Haze and Extreme Heat
  • Infectious Disease Outbreak
  • Fatigue and Psychological Stress

Life-safety risks require management attention even where the numerical rating is lower because likelihood is infrequent.

Workforce effects such as trauma, illness, fatigue, and skill loss may persist after operational services resume.

Assets, IT Systems and Information

The highest exposures arise from:

  • Cyber Attack
  • Ransomware
  • Data Breach
  • Insider Threat
  • Database Corruption
  • Network Failure
  • Telecommunications Failure
  • Cloud Service Provider Failure
  • Cloud Service Outage
  • Authentication System Failure
  • Fire and Explosion
  • Utility and Power Failure

The concentration of high scores in this area demonstrates the need for coordinated IT Disaster Recovery, cyber incident response, backup and restoration, identity resilience, network failover, cloud exit planning, and business-level manual workarounds.

 

Likelihood and Expected Disruption Analysis

Highest-Likelihood Threats

Cyber Attack is assessed as Almost Certain due to the persistent threat environment. Threats assessed as Likely include:

  • Flash Flood
  • Severe Storm
  • Lightning
  • Extreme Heat
  • Public Transport Disruption
  • Major Traffic Incident
  • High Staff Turnover
  • Skills Shortage
  • Staff Fatigue
  • Psychological Stress
  • Supplier Failure
  • Telecommunications Failure
  • Logistics Disruption
  • Third-Party Cyber Incident
  • Single Source Dependency
  • Ransomware
  • Malware
  • DDoS
  • Data Breach
  • Network Failure
  • Hardware Failure
  • Software Failure
  • Internet Failure

These threats require preventive monitoring and tested operating procedures rather than treatment only after an incident occurs.

Low-Likelihood but Severe Threats

The principal low-likelihood but severe threats are:

  • Terrorism
  • Explosion
  • Structural Failure
  • Active Assailant
  • Workplace Violence
  • Earthquake—Regional

They should not be dismissed because of their lower likelihood.

Their potential consequences for safety, public interest, facilities, and service continuity justify scenario-specific response plans and exercises.

Short, Intense Disruptions

Threats expected to cause short but potentially intense interruptions include:

  • Lightning
  • Flash Flood
  • Bomb Threat
  • Major Traffic Incident
  • Public Transport Disruption
  • DDoS
  • Server Failure
  • Hardware Failure
  • Software Failure
  • Internet Failure

These require rapid detection, escalation, failover, remote-working activation, and short-duration manual workarounds.

Prolonged Disruptions

Threats capable of causing prolonged interruption include:

  • Terrorism
  • Skills Shortage
  • Pandemic
  • Structural Failure
  • Import Restrictions
  • Vendor Insolvency
  • Supplier Failure
  • Single Source Dependency
  • Ransomware
  • Data Breach
  • Database Corruption
  • Regional Earthquake Effects

These scenarios require sustainable recovery staffing, alternate suppliers or locations, backlog management, welfare support, and prolonged crisis-governance arrangements.

Externally Dependent Durations

The duration of the following threats depends heavily on third parties or public agencies:

  • Flood and severe weather
  • Bomb Threat and terrorism
  • Public transport and traffic disruption
  • Supplier and outsourcing failure
  • Cloud service failure
  • Telecommunications and utility failure
  • Logistics disruption
  • Import restrictions
  • Vendor insolvency
  • Third-party cyber incidents
  • Internet and carrier outages

ALPS Healthcare should therefore establish escalation routes, information-sharing arrangements, contractual recovery commitments, and alternative service providers.

Threats Potentially Exceeding Recovery Capability

The following threats may exceed current recovery capability if assumed controls are incomplete or untested:

  • widespread cyberattack;
  • ransomware affecting primary and backup environments;
  • prolonged supplier or single-source failure;
  • extended import restriction;
  • database corruption requiring complex reconciliation;
  • multi-site pandemic workforce disruption;
  • structural failure of a critical facility;
  • prolonged cloud, network, telecommunications, or utility failure.

These threats require scenario-specific Business Continuity Strategies and evidence that recovery arrangements can operate for the expected duration.

Table RAR P3A: Risk Prioritisation for ALPS Healthcare

Priority Rank

Threat

Highest Impact Area

Likelihood

Risk Rating

Risk Level

Expected Disruption Period

1

Cyber Attack

Multiple areas, including Operations and Information

5 – Almost Certain

25

Extreme

3–7 days

2

Ransomware

Multiple areas, including Operations and Information

4 – Likely

20

Extreme

1–2 weeks

3

Supplier Failure

Finance, Operations and Social Responsibility

4 – Likely

20

Extreme

Supplier continuity assurance and diversification

4

Single Source Dependency

Finance, Operations and Social Responsibility

4 – Likely

20

Extreme

Eliminate concentration or obtain formal acceptance

5

Logistics Disruption

Finance, Operations and Social Responsibility

4 – Likely

20

Extreme

Alternate logistics strategy and joint exercises

6

Third-Party Cyber Incident

Operations and Information

4 – Likely

20

Extreme

Third-party cyber assurance and response planning

7

Data Breach

Finance, Legal, Reputation and Information

4 – Likely

20

Extreme

Data-protection remediation and breach exercise

8

Telecommunications Failure

Operations and Information

4 – Likely

20

Extreme

Carrier diversity and failover testing

9

Network Failure

Operations and Information

4 – Likely

20

Extreme

Network resilience assessment and failover test

10

Severe Storm

Operations

4 – Likely

16

High

Weather continuity and facility-readiness review

11

Extreme Heat

People

4 – Likely

16

High

Workforce and cold-chain heat controls

12

High Staff Turnover

Operations and People

4 – Likely

16

High

Workforce retention, succession and knowledge transfer

13

Skills Shortage

Operations and People

4 – Likely

16

High

Critical-skills programme and cross-training

14

Staff Fatigue

Operations and People

4 – Likely

16

High

Recovery rostering and welfare controls

15

Psychological Stress

People

4 – Likely

16

High

Crisis welfare and psychological support

16

Malware

Operations and Information

4 – Likely

16

High

Endpoint and application-control assurance

17

DDoS

Operations and Information

4 – Likely

16

High

Provider protection and response testing

18

Hardware Failure

Information assets

4 – Likely

16

High

Lifecycle management and minimum spare holdings

19

Software Failure

Operations and Information

4 – Likely

16

High

Release, rollback and workaround improvement

20

Internet Failure

Operations and Information

4 – Likely

16

High

Dual-provider connectivity and capacity test

21

Lightning

Information assets

4 – Likely

16

High

Electrical protection and recovery assurance

22

Fire

Operations, People and Assets

3 – Possible

15

High

Facility recovery strategy and fire assurance

23

Pandemic

Operations, Social Responsibility and People

3 – Possible

15

High

Pandemic continuity and workforce sustainability

24

Outsourcing Failure

Operations

3 – Possible

15

High

Retained capability and exit-plan validation

25

Cloud Service Provider Failure

Operations and Information

3 – Possible

15

High

Cloud portability and provider assurance

26

Utility Failure

Operations and Information

3 – Possible

15

High

Extended utility-outage strategy

27

Import Restrictions

Finance, Operations and Social Responsibility

3 – Possible

15

High

Substitute qualification and inventory strategy

28

Vendor Insolvency

Finance and Operations

3 – Possible

15

High

Financial monitoring and transition planning

29

Insider Threat

Operations, Legal, Reputation and Information

3 – Possible

15

High

Privileged-access and insider-risk controls

30

Database Corruption

Multiple areas

3 – Possible

15

High

Point-in-time recovery and reconciliation testing

31

Cloud Service Outage

Operations and Information

3 – Possible

15

High

Multi-zone recovery and offline procedures

32

Power Failure

Operations and Information

3 – Possible

15

High

Power failover and fuel resilience testing

33

Authentication System Failure

Operations and Information

3 – Possible

15

High

IAM failover and emergency-access testing

34

Flash Flood

Operations

4 – Likely

12

High

Remote-work and access-route planning

35

Flood

Operations

3 – Possible

12

High

Site flood assessment and protection

36

Haze

People

3 – Possible

12

High

Air-quality and remote-work arrangements

37

Pandemic-related Movement Restrictions

Operations, Social Responsibility and People

3 – Possible

12

High

Scalable remote-work arrangements

38

Public Transport Disruption

Operations and People

4 – Likely

12

High

Essential-worker transport arrangements

39

Major Traffic Incident

Operations and Social Responsibility

4 – Likely

12

High

Alternate routes and critical-delivery escalation

40

Infectious Disease Outbreak

Operations, Social Responsibility and People

3 – Possible

12

High

Local outbreak response planning

41

Mass Illness

Operations and People

3 – Possible

12

High

Minimum staffing and backup rosters

42

Loss of Key Personnel

Operations and People

3 – Possible

12

High

Succession and delegated authority testing

43

Mandatory Quarantine

Operations, Social Responsibility and People

3 – Possible

12

High

Remote approval and workforce segregation

44

Artificial Intelligence System Failure

Information assets

3 – Possible

12

High

AI governance and manual fallback

45

Earthquake—Regional

Operations and Social Responsibility

2 – Unlikely

10

High

Regional supply-chain scenario planning

46

Explosion

Operations, People and Assets

2 – Unlikely

10

High

Site emergency and alternate-facility planning

47

Structural Failure

Operations and People

2 – Unlikely

10

High

Structural assurance and relocation planning

48

Active Assailant

People

2 – Unlikely

10

High

Physical-security and staff-protection exercise

49

Workplace Violence

People

2 – Unlikely

10

High

Threat assessment and response arrangements

50

Chemical Spill

Operations, Social Responsibility and People

2 – Unlikely

8

Moderate

Hazardous-material and spill-response assurance

51

Gas Leak

People

2 – Unlikely

8

Moderate

Detection, isolation and evacuation assurance

52

Bomb Threat

Operations, Reputation, Social Responsibility and People

2 – Unlikely

8

Moderate

Security procedures and exercise

53

Terrorism

All impact areas

1 – Rare

5

Moderate

Crisis scenario planning despite low likelihood

Note: The register contains 53 distinct prioritised entries because “Cloud Service Provider Failure” and “Cloud Service Outage” have been retained as separate threats reflecting, respectively, third-party dependency failure and direct application-service unavailability. No approved threat has been intentionally consolidated.

 

Management Validation

Review by Threat Owners

Each threat should be allocated to an accountable owner. Typical owners may include:

  • Facilities and Security for premises and denial-of-access threats;
  • Human Resources for workforce threats;
  • Procurement and Supply Chain for supplier and logistics threats;
  • ICT and Information Security for technology and cyber threats;
  • Business Continuity Management for cross-functional recovery exposures; and
  • Enterprise Risk Management for methodology, challenge, and governance.

Threat owners should confirm that the scenario, impact scores, likelihood, disruption duration, and assumed controls accurately reflect their area.

Review by Critical Business Function Owners

Critical Business Function owners should validate whether the assessed disruption could affect:

  • procurement and sourcing;
  • pharmaceuticals and medical supplies;
  • inventory and replenishment;
  • warehousing and logistics;
  • healthcare institution coordination;
  • supplier payments;
  • information systems;
  • governance and compliance; and
  • crisis and continuity management.

They should identify where the threat may simultaneously disrupt multiple functions or create downstream consequences for healthcare institutions.

Specialist Validation

ICT, cybersecurity, facilities, security, human resources, procurement, legal, finance, data protection, and records-management specialists should validate the assumptions relevant to their professional areas.

Examples include:

  • ICT confirmation of backup, replication, RTO, RPO, and failover capability;
  • cybersecurity validation against current threat intelligence;
  • Facilities confirmation of fire, power, flood, and structural controls;
  • HR validation of absenteeism, skills, succession, and welfare assumptions;
  • Procurement confirmation of supplier concentration, alternatives, and contract rights;
  • Legal confirmation of statutory, contractual, privacy, and notification consequences; and
  • Finance validation of cost ranges, insurance, deductibles, and emergency expenditure.
Confirm Existing Control Effectiveness

Controls identified in RAR Part 2 should be tested rather than accepted solely from policy documentation. Validation evidence may include:

  • inspection and maintenance certificates;
  • backup and restoration reports;
  • cyber and disaster-recovery test results;
  • alternate-site exercises;
  • remote-working capacity tests;
  • supplier continuity evidence;
  • service-level performance;
  • access reviews;
  • incident-response exercises;
  • staff competency and attendance records;
  • audit results; and
  • completed corrective actions.

Where controls are untested, outdated, incomplete, or dependent on a single person or supplier, the likelihood and disruption-duration assumptions should be reconsidered.

Review Incident and Threat Information

The assessment should be compared with:

  • internal incidents and near misses;
  • supplier outages and performance failures;
  • national weather and infrastructure information;
  • public-health advisories;
  • cyber threat intelligence;
  • sector incidents;
  • audit and assurance findings;
  • insurance claims;
  • employee turnover and absenteeism data; and
  • exercise observations.
\Validate Impact Assumptions

Financial impacts should be supported by cost data, including emergency purchasing, system recovery, supplier transition, overtime, temporary facilities, professional services, contract penalties, legal expenditure, and product replacement.

Legal and regulatory impacts should be confirmed by Legal, Compliance, Data Protection, Procurement Governance, and relevant public-sector stakeholders.

Public-interest and social-responsibility consequences should be reviewed with healthcare institution stakeholders where supply interruption could affect clinical services or patient support.

Enterprise Risk and BCM Challenge

Enterprise Risk Management and Business Continuity Management should independently challenge:

  • inconsistent scoring;
  • unsupported low likelihoods;
  • understated cross-functional impacts;
  • optimistic disruption periods;
  • reliance on untested controls;
  • duplication or gaps in threat coverage;
  • dependency concentration; and
  • proposed risk acceptance.
Senior Management Approval

The completed assessment should be submitted to the appropriate senior management or risk-governance body for:

  • approval of the assessment basis;
  • confirmation of the applicable risk matrix;
  • endorsement of High and Extreme risk priorities;
  • allocation of mitigation resources;
  • approval or rejection of residual-risk acceptance;
  • assignment of accountable executives; and
  • confirmation of review dates.

Any management override of a proposed score should be documented with its rationale, approving authority, supporting evidence, and implications for treatment.

Periodic Reassessment

The assessment should be reviewed:

  • at least annually;
  • following a major incident or near miss;
  • after a business continuity or disaster-recovery exercise;
  • when a critical supplier or system changes;
  • after significant organisational restructuring;
  • when new technology is introduced;
  • when risk appetite or regulatory obligations change; and
  • when threat intelligence indicates a material change.

 

The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.

By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.

The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.

 

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF

 

 

More Information About Business Continuity Management Courses

 

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.