It evaluates the credible consequences of each approved threat, estimates the likelihood of occurrence, calculates a current risk rating, and estimates how long the resulting disruption may affect ALPS Healthcare.
The assessment represents the current or residual risk after considering the assumed existing controls documented in RAR Part 2, but before implementing the additional planned controls. Because detailed incident data, verified control-testing results, financial exposure information, and ALPS Healthcare’s approved risk matrix were not supplied, the scores in this chapter are indicative. They should not be treated as confirmed organisational risk ratings until they have been reviewed and approved through ALPS Healthcare’s risk-governance process.
Impact is assessed across seven dimensions:
Assessing several impact dimensions prevents management from relying only on financial consequences.
A disruption may create relatively limited direct expenditure while significantly affecting the continuity of healthcare supply, information security, workforce safety, regulatory obligations, stakeholder confidence, or Singapore’s public healthcare institutions.
The highest credible score among the seven impact areas is used as the overall impact score. This approach ensures that a severe consequence in one important area is not diluted by lower scores elsewhere.
Likelihood is assessed independently and reflects the realistic possibility of the threat occurring, taking into account geographic exposure, operating conditions, sector experience, current vulnerabilities, and the assumed effectiveness of existing controls.
The current risk rating is calculated as:
The default risk bands used in this chapter are:
|
Risk Rating |
Risk Level |
|
1–4 |
Very Low/ Low |
|
5–9 |
Moderate |
|
10–16 |
High |
|
17–25 |
Very High (Extreme) |
The expected disruption period estimates the credible duration of operational interruption, accounting for existing controls.
It is neither the Recovery Time Objective nor the Maximum Tolerable Period of Disruption.
The duration may depend on facility access, supplier recovery, technology restoration, staff availability, regulatory restrictions, or the effectiveness of alternate operating arrangements.
Numerical ratings are decision-support tools. They must be interpreted together with professional judgement, stakeholder obligations, control effectiveness, operational dependencies, public-interest consequences, and ALPS Healthcare’s approved risk appetite.
|
Threat |
Finance |
Operat-ions |
Legal & Regulatory |
Reputation & Image |
Social Respon-sibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
|
Flood (Denial of Access – Natural Disaster) |
3 |
4 |
3 |
3 |
3 |
3 |
3 |
4 – Operations |
3 – Possible |
4 × 3 = 12 |
High |
8–24 hours, depending on site access and drainage conditions |
|
Flash Flood (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
2 |
2 |
2 |
3 – Operations |
4 – Likely |
3 × 4 = 12 |
High |
4–8 hours, primarily affecting commuting and deliveries |
|
Severe Storm (Denial of Access – Natural Disaster) |
3 |
4 |
2 |
3 |
3 |
3 |
3 |
4 – Operations |
4 – Likely |
4 × 4 = 16 |
High |
8–24 hours, depending on transport and utility restoration |
|
Lightning (Denial of Access – Natural Disaster) |
2 |
3 |
1 |
2 |
2 |
2 |
4 |
4 – Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–4 hours unless critical equipment is damaged |
|
Earthquake—Regional (Denial of Access – Natural Disaster) |
4 |
5 |
3 |
4 |
5 |
2 |
3 |
5 – Operations; Social Responsibility |
2 – Unlikely |
5 × 2 = 10 |
High |
1–2 weeks due to regional manufacturing and logistics disruption |
|
Haze (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
1 |
4 – People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days, potentially longer during persistent regional haze |
|
Extreme Heat (Denial of Access – Natural Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
3 |
4 – People |
4 – Likely |
4 × 4 = 16 |
High |
3–7 days during prolonged heat conditions |
|
Pandemic-related Movement Restrictions (Denial of Access – Natural Disaster) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
1–2 weeks, potentially longer if restrictions escalate |
|
Fire (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
5 |
5 – Operations; People; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–2 weeks, depending on damage and alternate-site activation |
|
Explosion (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
5 |
5 – Operations; People; Assets, IT Systems and Information |
2 – Unlikely |
5 × 2 = 10 |
High |
1–2 weeks, potentially longer for major structural damage |
|
Chemical Spill (Denial of Access – Man-made Disaster) |
3 |
4 |
3 |
3 |
4 |
4 |
3 |
4 – Operations; Social Responsibility; People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
1–3 days, depending on containment and decontamination |
|
Gas Leak (Denial of Access – Man-made Disaster) |
2 |
3 |
2 |
2 |
3 |
4 |
2 |
4 – People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
8–24 hours, subject to detection, isolation and safety clearance |
|
Structural Failure (Denial of Access – Man-made Disaster) |
4 |
5 |
3 |
4 |
4 |
5 |
4 |
5 – Operations; People |
2 – Unlikely |
5 × 2 = 10 |
High |
2–4 weeks if the facility requires major repair or relocation |
|
Bomb Threat (Denial of Access – Man-made Disaster) |
2 |
4 |
2 |
4 |
4 |
4 |
2 |
4 – Operations; Reputation and Image; Social Responsibility; People |
2 – Unlikely |
4 × 2 = 8 |
Moderate |
4–8 hours, subject to police investigation and clearance |
|
Terrorism (Denial of Access – Man-made Disaster) |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
5 – All impact areas |
1 – Rare |
5 × 1 = 5 |
Moderate |
More than 1 month in a severe multi-site or infrastructure scenario |
|
Active Assailant (Denial of Access – Man-made Disaster) |
3 |
4 |
3 |
4 |
4 |
5 |
2 |
5 – People |
2 – Unlikely |
5 × 2 = 10 |
High |
1–3 days, with longer workforce and psychological effects |
|
Public Transport Disruption (Denial of Access – Man-made Disaster) |
2 |
3 |
1 |
2 |
2 |
3 |
1 |
3 – Operations; People |
4 – Likely |
3 × 4 = 12 |
High |
4–8 hours, depending on the transport network affected |
|
Major Traffic Incident (Denial of Access – Man-made Disaster) |
2 |
3 |
1 |
2 |
3 |
2 |
1 |
3 – Operations; Social Responsibility |
4 – Likely |
3 × 4 = 12 |
High |
1–4 hours, with longer delays for critical delivery routes |
|
Pandemic (Unavailability of People) |
4 |
5 |
4 |
4 |
5 |
5 |
3 |
5 – Operations; Social Responsibility; People |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, potentially extending for successive infection waves |
|
Infectious Disease Outbreak (Unavailability of People) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days for a localised team or facility outbreak |
|
Mass Illness (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days, depending on workforce concentration |
|
High Staff Turnover (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
2–4 weeks, with capability effects potentially lasting longer |
|
Loss of Key Personnel (Unavailability of People) |
3 |
4 |
3 |
3 |
3 |
4 |
2 |
4 – Operations; People |
3 – Possible |
4 × 3 = 12 |
High |
1–2 weeks, depending on succession and delegation readiness |
|
Skills Shortage (Unavailability of People) |
3 |
4 |
2 |
3 |
3 |
4 |
2 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
More than 1 month because specialist capability may be difficult to replace |
|
Workplace Violence (Unavailability of People) |
2 |
3 |
2 |
3 |
3 |
5 |
2 |
5 – People |
2 – Unlikely |
5 × 2 = 10 |
High |
1–3 days, with potentially longer welfare consequences |
|
Staff Fatigue (Unavailability of People) |
2 |
4 |
2 |
3 |
3 |
4 |
1 |
4 – Operations; People |
4 – Likely |
4 × 4 = 16 |
High |
1–2 weeks during prolonged incident response or backlog clearance |
|
Psychological Stress (Unavailability of People) |
2 |
3 |
2 |
3 |
3 |
4 |
1 |
4 – People |
4 – Likely |
4 × 4 = 16 |
High |
1–2 weeks, with some effects continuing after restoration |
|
Mandatory Quarantine (Unavailability of People) |
3 |
4 |
3 |
3 |
4 |
4 |
2 |
4 – Operations; Social Responsibility; People |
3 – Possible |
4 × 3 = 12 |
High |
3–7 days for affected teams; longer for repeated exposure |
|
Supplier Failure (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, depending on inventory and alternate supplier availability |
|
Outsourcing Failure (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
3 |
5 – Operations |
3 – Possible |
5 × 3 = 15 |
High |
3–7 days, depending on retained capability and exit arrangements |
|
Cloud Service Provider Failure (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days, depending on provider recovery and data portability |
|
Telecommunications Failure (Disruption to the Supply Chain) |
3 |
5 |
2 |
3 |
3 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
8–24 hours, subject to carrier redundancy and failover |
|
Utility Failure (Disruption to the Supply Chain) |
4 |
5 |
3 |
3 |
4 |
3 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days in an extended electricity or facility-service outage |
|
Logistics Disruption (Disruption to the Supply Chain) |
5 |
5 |
3 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
3–7 days, depending on carriers, routes and inventory buffers |
|
Import Restrictions (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, depending on product substitution and approvals |
|
Vendor Insolvency (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
4 |
2 |
2 |
5 – Finance; Operations |
3 – Possible |
5 × 3 = 15 |
High |
2–4 weeks, depending on transition complexity |
|
Third-Party Cyber Incident (Disruption to the Supply Chain) |
4 |
5 |
4 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
3–7 days, potentially longer where data or integrations are compromised |
|
Single Source Dependency (Disruption to the Supply Chain) |
5 |
5 |
4 |
4 |
5 |
2 |
2 |
5 – Finance; Operations; Social Responsibility |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, potentially longer where no substitute is available |
|
Cyber Attack (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
5 |
3 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information |
5 – Almost Certain |
5 × 5 = 25 |
Extreme |
3–7 days, with investigations and remediation continuing longer |
|
Ransomware (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
5 |
3 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Social Responsibility; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks, depending on containment and clean restoration |
|
Malware (Equipment and IT-Related Disruption) |
3 |
4 |
3 |
3 |
3 |
2 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–3 days, depending on spread and endpoint coverage |
|
Distributed Denial of Service—DDoS (Equipment and IT-Related Disruption) |
3 |
4 |
2 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, potentially longer for sustained attacks |
|
Insider Threat (Equipment and IT-Related Disruption) |
4 |
5 |
5 |
5 |
4 |
3 |
5 |
5 – Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–2 weeks, depending on discovery and investigation complexity |
|
Data Breach (Equipment and IT-Related Disruption) |
5 |
4 |
5 |
5 |
4 |
3 |
5 |
5 – Finance; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
1–2 weeks operationally, with legal and reputational effects continuing longer |
|
Network Failure (Equipment and IT-Related Disruption) |
3 |
5 |
2 |
3 |
3 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
4 – Likely |
5 × 4 = 20 |
Extreme |
8–24 hours, depending on failover and fault isolation |
|
Server Failure (Equipment and IT-Related Disruption) |
3 |
4 |
2 |
3 |
3 |
1 |
5 |
5 – Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
4–8 hours where high availability and spare capacity operate |
|
Database Corruption (Equipment and IT-Related Disruption) |
5 |
5 |
5 |
5 |
4 |
2 |
5 |
5 – Finance; Operations; Legal and Regulatory; Reputation and Image; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
3–7 days, depending on restoration and reconciliation complexity |
|
Cloud Service Outage (Equipment and IT-Related Disruption) |
4 |
5 |
3 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
1–3 days, subject to provider restoration and workarounds |
|
Power Failure (Equipment and IT-Related Disruption) |
4 |
5 |
2 |
3 |
4 |
3 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
8–24 hours, potentially longer if backup power is exhausted |
|
Hardware Failure (Equipment and IT-Related Disruption) |
2 |
3 |
1 |
2 |
2 |
1 |
4 |
4 – Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
1–4 hours where spares and standard builds are available |
|
Software Failure (Equipment and IT-Related Disruption) |
3 |
4 |
3 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, depending on rollback and vendor support |
|
Internet Failure (Equipment and IT-Related Disruption) |
3 |
4 |
1 |
3 |
3 |
1 |
4 |
4 – Operations; Assets, IT Systems and Information |
4 – Likely |
4 × 4 = 16 |
High |
4–8 hours, subject to alternate carrier capacity |
|
Authentication System Failure (Equipment and IT-Related Disruption) |
3 |
5 |
3 |
4 |
4 |
2 |
5 |
5 – Operations; Assets, IT Systems and Information |
3 – Possible |
5 × 3 = 15 |
High |
8–24 hours, depending on failover and emergency access |
|
Artificial Intelligence System Failure (Equipment and IT-Related Disruption) |
3 |
3 |
3 |
3 |
3 |
1 |
4 |
4 – Assets, IT Systems and Information |
3 – Possible |
4 × 3 = 12 |
High |
1–3 days where conventional analytical processes remain available |
The highest impacts affect operations, finance, legal and regulatory compliance, reputation, social responsibility, and information assets.
A coordinated cyberattack could interrupt procurement, inventory, logistics, supplier management, financial processing, and reporting while compromising sensitive information.
The likelihood is driven by the persistent global threat environment, reliance on interconnected systems, and exposure through third parties.
The most significant assumed control is ALPS Healthcare’s layered cybersecurity capability, including monitoring, endpoint protection, access management, backups, and incident response.
The principal weakness is that the effectiveness of controls, recovery readiness, and cyber-resilience testing have not been verified.
Management attention: Immediate executive oversight, technical control assurance, cyber-recovery testing, and remediation of critical vulnerabilities are required.
A critical supplier failure could interrupt the availability of essential medicines, medical supplies, equipment, or healthcare support services. The most severe consequences affect finance, operations, and social responsibility.
The likelihood is influenced by global supply-chain volatility, supplier concentration, geopolitical factors, and financial pressure on vendors.
Supplier qualification and contingency sourcing are the most significant assumed controls.
The principal weakness is uncertainty about alternative suppliers' readiness and the resilience of tier-two and tier-three dependencies.
Management attention: Urgent supplier-tiering, continuity assurance, substitute qualification, and joint recovery exercises are required.
Loss of telecommunications could prevent staff, suppliers, warehouses, healthcare institutions, and recovery teams from communicating or accessing cloud-hosted services. Operations and technology assets are the highest-impact areas.
The likelihood is driven by dependence on telecommunications for distributed operations and digital procurement. Redundant links and alternate communication channels are the most important assumed controls. The main weakness is the potential for common infrastructure, carrier, or last-mile dependencies.
Management attention: Validate carrier diversity and test automatic and manual failover.
A major logistics disruption may delay delivery of medicines, consumables, equipment, and emergency supplies to healthcare institutions. Finance, operations, and social responsibility are the highest-impact areas.
The likelihood reflects Singapore’s dependence on efficient transport networks and international supply chains. Alternate carriers and route planning are the most significant assumed controls.
The principal weakness is potential dependency on common ports, routes, distribution hubs, or specialist cold-chain providers.
Management attention: Expand alternate carrier arrangements, map route concentration, and test emergency allocation and delivery procedures.
A cyber incident affecting a critical supplier, outsourced service provider, logistics partner, or cloud provider may interrupt integrated services or compromise shared information. Operations and information assets are most exposed.
The likelihood is elevated by supply-chain connectivity and varying third-party control maturity. Cyber due diligence and contractual incident-notification requirements are the primary assumed controls. The main weakness is limited visibility beyond direct suppliers.
Management attention: Implement cyber-critical supplier tiering, continuous assurance, access restrictions, and joint incident exercises.
Where ALPS Healthcare relies on a sole provider for an essential item or service, a disruption could immediately affect procurement and continuity of healthcare supply.
Finance, operations, and social responsibility are the highest-impact areas.
The likelihood is driven by specialist products, regulatory qualification requirements, intellectual property, or limited market capacity.
Safety stock and enhanced supplier monitoring are important assumed controls. The main weakness is the absence of a qualified substitute or transition route.
Management attention: Establish an enterprise sole-source register, qualify alternatives, and formally approve unavoidable dependencies.
Ransomware may encrypt applications, endpoints, databases, and file repositories while disrupting operations across multiple business units.
The highest impacts are across most organisational dimensions, except for direct workforce safety.
The likelihood is driven by widespread criminal activity, phishing, third-party compromise, and exploitation of unpatched systems.
Endpoint detection, segmentation, immutable backups, and incident response are the most significant assumed controls. The principal weakness is uncertainty regarding clean restoration and backup integrity.
Management attention: Conduct clean-room recovery tests and verify that critical services can be restored within approved business requirements.
A breach of supplier, employee, financial, procurement, or healthcare-related information could create significant financial, legal, reputational, and information consequences.
The likelihood reflects persistent cyber threats, complex data flows, user error, insider activity, and third-party access.
Encryption, access control, monitoring, and breach response procedures are the primary assumed controls. The key weakness is incomplete visibility of information flows and excessive access or retention.
Management attention: Complete data-flow mapping, access certification, breach exercises, and remediation of unnecessary data exposure.
A major network failure could simultaneously interrupt access to procurement, inventory, logistics, financial, communications, and reporting platforms.
Operations and technology assets are the highest-impact areas.
The likelihood reflects the complexity of network infrastructure and the possibility of device, carrier, configuration, or change failures.
Redundant network architecture and monitoring are the most significant assumed controls. The key weakness is the potential existence of unrecognised single points of failure.
Management attention: Perform architecture assurance and full failover testing.
The following threats are assessed as High and require active ownership, proportionate mitigation, continuity arrangements, and periodic assurance:
Key themes across these high-risk areas include:
The most urgent High-risk mitigation should focus on threats with a rating of 15 or 16, long expected disruption periods, significant personnel-safety implications, or serious public-health supply consequences.
The greatest financial exposures arise from:
The principal financial themes are emergency procurement premiums, system restoration, forensic and legal costs, replacement of products or infrastructure, contractual penalties, supplier transition expenses, inventory losses, and prolonged operational recovery.
Financial effects may continue after services resume because claims, remediation, litigation, regulatory responses, contract renegotiations, and supplier replacements may take months to complete.
Operations
Operations show the largest concentration of Major and Severe scores. The greatest operational exposures include:
These threats may interrupt several Critical Business Functions simultaneously. Technology, telecommunications, utilities, suppliers, warehouses, logistics providers, and specialist staff create interconnected dependencies that could amplify the impact.
The most significant legal and regulatory exposures arise from:
Consequences may include delayed statutory reporting, loss of audit trails, failure to preserve records, confidentiality breaches, procurement non-compliance, contract disputes, and criticism regarding governance or control effectiveness.
Some regulatory effects may emerge after a delay when investigations identify incomplete records, inadequate notifications, weak oversight, or failure to test controls.
The threats most likely to damage stakeholder confidence include:
Reputational damage may persist after normal operations resume, particularly when the incident affects patient-support supplies, sensitive information, public-sector confidence, or perceptions of inadequate preparedness.
The most severe social-responsibility impacts arise from:
The main concern is that disruption to ALPS Healthcare’s procurement and supply chain services could indirectly affect healthcare institutions, clinical operations, patients, and national health system resilience.
The greatest workforce and safety exposures include:
Life-safety risks require management attention even where the numerical rating is lower because likelihood is infrequent.
Workforce effects such as trauma, illness, fatigue, and skill loss may persist after operational services resume.
The highest exposures arise from:
The concentration of high scores in this area demonstrates the need for coordinated IT Disaster Recovery, cyber incident response, backup and restoration, identity resilience, network failover, cloud exit planning, and business-level manual workarounds.
Cyber Attack is assessed as Almost Certain due to the persistent threat environment. Threats assessed as Likely include:
These threats require preventive monitoring and tested operating procedures rather than treatment only after an incident occurs.
The principal low-likelihood but severe threats are:
They should not be dismissed because of their lower likelihood.
Their potential consequences for safety, public interest, facilities, and service continuity justify scenario-specific response plans and exercises.
Short, Intense Disruptions
Threats expected to cause short but potentially intense interruptions include:
These require rapid detection, escalation, failover, remote-working activation, and short-duration manual workarounds.
Threats capable of causing prolonged interruption include:
These scenarios require sustainable recovery staffing, alternate suppliers or locations, backlog management, welfare support, and prolonged crisis-governance arrangements.
The duration of the following threats depends heavily on third parties or public agencies:
ALPS Healthcare should therefore establish escalation routes, information-sharing arrangements, contractual recovery commitments, and alternative service providers.
The following threats may exceed current recovery capability if assumed controls are incomplete or untested:
These threats require scenario-specific Business Continuity Strategies and evidence that recovery arrangements can operate for the expected duration.
|
Priority Rank |
Threat |
Highest Impact Area |
Likelihood |
Risk Rating |
Risk Level |
Expected Disruption Period |
|
1 |
Cyber Attack |
Multiple areas, including Operations and Information |
5 – Almost Certain |
25 |
Extreme |
3–7 days |
|
2 |
Ransomware |
Multiple areas, including Operations and Information |
4 – Likely |
20 |
Extreme |
1–2 weeks |
|
3 |
Supplier Failure |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Supplier continuity assurance and diversification |
|
4 |
Single Source Dependency |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Eliminate concentration or obtain formal acceptance |
|
5 |
Logistics Disruption |
Finance, Operations and Social Responsibility |
4 – Likely |
20 |
Extreme |
Alternate logistics strategy and joint exercises |
|
6 |
Third-Party Cyber Incident |
Operations and Information |
4 – Likely |
20 |
Extreme |
Third-party cyber assurance and response planning |
|
7 |
Data Breach |
Finance, Legal, Reputation and Information |
4 – Likely |
20 |
Extreme |
Data-protection remediation and breach exercise |
|
8 |
Telecommunications Failure |
Operations and Information |
4 – Likely |
20 |
Extreme |
Carrier diversity and failover testing |
|
9 |
Network Failure |
Operations and Information |
4 – Likely |
20 |
Extreme |
Network resilience assessment and failover test |
|
10 |
Severe Storm |
Operations |
4 – Likely |
16 |
High |
Weather continuity and facility-readiness review |
|
11 |
Extreme Heat |
People |
4 – Likely |
16 |
High |
Workforce and cold-chain heat controls |
|
12 |
High Staff Turnover |
Operations and People |
4 – Likely |
16 |
High |
Workforce retention, succession and knowledge transfer |
|
13 |
Skills Shortage |
Operations and People |
4 – Likely |
16 |
High |
Critical-skills programme and cross-training |
|
14 |
Staff Fatigue |
Operations and People |
4 – Likely |
16 |
High |
Recovery rostering and welfare controls |
|
15 |
Psychological Stress |
People |
4 – Likely |
16 |
High |
Crisis welfare and psychological support |
|
16 |
Malware |
Operations and Information |
4 – Likely |
16 |
High |
Endpoint and application-control assurance |
|
17 |
DDoS |
Operations and Information |
4 – Likely |
16 |
High |
Provider protection and response testing |
|
18 |
Hardware Failure |
Information assets |
4 – Likely |
16 |
High |
Lifecycle management and minimum spare holdings |
|
19 |
Software Failure |
Operations and Information |
4 – Likely |
16 |
High |
Release, rollback and workaround improvement |
|
20 |
Internet Failure |
Operations and Information |
4 – Likely |
16 |
High |
Dual-provider connectivity and capacity test |
|
21 |
Lightning |
Information assets |
4 – Likely |
16 |
High |
Electrical protection and recovery assurance |
|
22 |
Fire |
Operations, People and Assets |
3 – Possible |
15 |
High |
Facility recovery strategy and fire assurance |
|
23 |
Pandemic |
Operations, Social Responsibility and People |
3 – Possible |
15 |
High |
Pandemic continuity and workforce sustainability |
|
24 |
Outsourcing Failure |
Operations |
3 – Possible |
15 |
High |
Retained capability and exit-plan validation |
|
25 |
Cloud Service Provider Failure |
Operations and Information |
3 – Possible |
15 |
High |
Cloud portability and provider assurance |
|
26 |
Utility Failure |
Operations and Information |
3 – Possible |
15 |
High |
Extended utility-outage strategy |
|
27 |
Import Restrictions |
Finance, Operations and Social Responsibility |
3 – Possible |
15 |
High |
Substitute qualification and inventory strategy |
|
28 |
Vendor Insolvency |
Finance and Operations |
3 – Possible |
15 |
High |
Financial monitoring and transition planning |
|
29 |
Insider Threat |
Operations, Legal, Reputation and Information |
3 – Possible |
15 |
High |
Privileged-access and insider-risk controls |
|
30 |
Database Corruption |
Multiple areas |
3 – Possible |
15 |
High |
Point-in-time recovery and reconciliation testing |
|
31 |
Cloud Service Outage |
Operations and Information |
3 – Possible |
15 |
High |
Multi-zone recovery and offline procedures |
|
32 |
Power Failure |
Operations and Information |
3 – Possible |
15 |
High |
Power failover and fuel resilience testing |
|
33 |
Authentication System Failure |
Operations and Information |
3 – Possible |
15 |
High |
IAM failover and emergency-access testing |
|
34 |
Flash Flood |
Operations |
4 – Likely |
12 |
High |
Remote-work and access-route planning |
|
35 |
Flood |
Operations |
3 – Possible |
12 |
High |
Site flood assessment and protection |
|
36 |
Haze |
People |
3 – Possible |
12 |
High |
Air-quality and remote-work arrangements |
|
37 |
Pandemic-related Movement Restrictions |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Scalable remote-work arrangements |
|
38 |
Public Transport Disruption |
Operations and People |
4 – Likely |
12 |
High |
Essential-worker transport arrangements |
|
39 |
Major Traffic Incident |
Operations and Social Responsibility |
4 – Likely |
12 |
High |
Alternate routes and critical-delivery escalation |
|
40 |
Infectious Disease Outbreak |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Local outbreak response planning |
|
41 |
Mass Illness |
Operations and People |
3 – Possible |
12 |
High |
Minimum staffing and backup rosters |
|
42 |
Loss of Key Personnel |
Operations and People |
3 – Possible |
12 |
High |
Succession and delegated authority testing |
|
43 |
Mandatory Quarantine |
Operations, Social Responsibility and People |
3 – Possible |
12 |
High |
Remote approval and workforce segregation |
|
44 |
Artificial Intelligence System Failure |
Information assets |
3 – Possible |
12 |
High |
AI governance and manual fallback |
|
45 |
Earthquake—Regional |
Operations and Social Responsibility |
2 – Unlikely |
10 |
High |
Regional supply-chain scenario planning |
|
46 |
Explosion |
Operations, People and Assets |
2 – Unlikely |
10 |
High |
Site emergency and alternate-facility planning |
|
47 |
Structural Failure |
Operations and People |
2 – Unlikely |
10 |
High |
Structural assurance and relocation planning |
|
48 |
Active Assailant |
People |
2 – Unlikely |
10 |
High |
Physical-security and staff-protection exercise |
|
49 |
Workplace Violence |
People |
2 – Unlikely |
10 |
High |
Threat assessment and response arrangements |
|
50 |
Chemical Spill |
Operations, Social Responsibility and People |
2 – Unlikely |
8 |
Moderate |
Hazardous-material and spill-response assurance |
|
51 |
Gas Leak |
People |
2 – Unlikely |
8 |
Moderate |
Detection, isolation and evacuation assurance |
|
52 |
Bomb Threat |
Operations, Reputation, Social Responsibility and People |
2 – Unlikely |
8 |
Moderate |
Security procedures and exercise |
|
53 |
Terrorism |
All impact areas |
1 – Rare |
5 |
Moderate |
Crisis scenario planning despite low likelihood |
Note: The register contains 53 distinct prioritised entries because “Cloud Service Provider Failure” and “Cloud Service Outage” have been retained as separate threats reflecting, respectively, third-party dependency failure and direct application-service unavailability. No approved threat has been intentionally consolidated.
Each threat should be allocated to an accountable owner. Typical owners may include:
Threat owners should confirm that the scenario, impact scores, likelihood, disruption duration, and assumed controls accurately reflect their area.
Critical Business Function owners should validate whether the assessed disruption could affect:
They should identify where the threat may simultaneously disrupt multiple functions or create downstream consequences for healthcare institutions.
ICT, cybersecurity, facilities, security, human resources, procurement, legal, finance, data protection, and records-management specialists should validate the assumptions relevant to their professional areas.
Examples include:
Controls identified in RAR Part 2 should be tested rather than accepted solely from policy documentation. Validation evidence may include:
Where controls are untested, outdated, incomplete, or dependent on a single person or supplier, the likelihood and disruption-duration assumptions should be reconsidered.
The assessment should be compared with:
Financial impacts should be supported by cost data, including emergency purchasing, system recovery, supplier transition, overtime, temporary facilities, professional services, contract penalties, legal expenditure, and product replacement.
Legal and regulatory impacts should be confirmed by Legal, Compliance, Data Protection, Procurement Governance, and relevant public-sector stakeholders.
Public-interest and social-responsibility consequences should be reviewed with healthcare institution stakeholders where supply interruption could affect clinical services or patient support.
Enterprise Risk Management and Business Continuity Management should independently challenge:
The completed assessment should be submitted to the appropriate senior management or risk-governance body for:
Any management override of a proposed score should be documented with its rationale, approving authority, supporting evidence, and implications for treatment.
The assessment should be reviewed:
The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.
By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.
The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||