Chapter 9
Introduction
An organisation's ability to maintain continuity during disruptive events depends largely on its understanding of the risks and threats that may affect its operations.![BCM] [Damanat] [E1] [C9] Assessing Risks and Threats](https://no-cache.hubspot.com/cta/default/3893111/23eed9ea-c2fa-4026-8772-c2fade1e1f26.png)
Before appropriate recovery strategies can be developed, Damanat must identify the events that could interrupt its Critical Business Functions (CBFs), evaluate the organisation's exposure to those events, and understand the potential consequences should they occur.
Risk assessment is therefore a fundamental component of Business Continuity Management (BCM). It provides the information necessary to prioritise continuity planning, allocate resources appropriately, and implement preventive and recovery measures that are proportionate to the organisation's operational and regulatory responsibilities.
For the Saudi Mortgage Guarantees Services Company (Damanat), threat assessment should consider both internal and external events that may disrupt mortgage guarantee services, supporting business operations, technology infrastructure, regulatory obligations, and stakeholder confidence.
The objective is not to predict every possible incident but to understand the range of credible disruption scenarios that could significantly affect business continuity.
It is important to recognise that this chapter introduces the concept of threat identification at a strategic level.
The detailed assessment of threats, vulnerabilities, likelihood, consequences, existing controls, and residual risks should be undertaken during the Risk Analysis and Review (RAR) phase of the BCM Planning Methodology.
Understanding Key Risk Management Concepts
Business Continuity Threats
A threat is any event, circumstance, or condition that has the potential to disrupt Damanat's operations or adversely affect its ability to deliver critical business services.
Examples include:
- Cyber attacks
- Fire
- Flooding
- Pandemic
- Utility failure
- Supplier failure
- Human error
A threat represents the source of potential disruption.
Vulnerability
A vulnerability is a weakness that increases the likelihood that a threat will result in operational disruption.
Examples include:
- Single points of failure.
- Lack of alternate suppliers.
- Insufficient staff cross-training.
- Inadequate cybersecurity controls.
- Outdated recovery procedures.
- Poor documentation.
- Dependence on a single facility.
Reducing vulnerabilities improves organisational resilience even when threats cannot be eliminated.
Control
A control is a preventive, detective, or corrective measure implemented to reduce either the likelihood or the impact of a disruptive event.
Examples include:
- Fire suppression systems.
- Access controls.
- Cybersecurity monitoring.
- Backup generators.
- Data backups.
- Employee awareness training.
- Alternate communication systems.
Strong controls reduce organisational exposure to disruption.
Consequence
A consequence describes the operational, financial, legal, regulatory, reputational, or stakeholder impact resulting from a disruptive event.
Potential consequences include:
- Delayed mortgage guarantee approvals.
- Loss of critical information.
- Regulatory non-compliance.
- Customer dissatisfaction.
- Financial losses.
- Reputational damage.
- Reduced stakeholder confidence.
Understanding consequences supports recovery prioritisation.
Likelihood
Likelihood represents the estimated probability that a threat will occur within a given planning period.
Likelihood should be determined using appropriate organisational criteria and supported by historical information, threat intelligence, expert judgement, and recognised risk management practices.
Risk
A risk is the combination of the likelihood that a threat will occur and the severity of its consequences should it materialise.
Business Continuity planning focuses on risks capable of causing significant interruption to Critical Business Functions rather than on routine operational issues.
Disruption Scenario
A disruption scenario is a realistic description of how one or more threats may affect Damanat's operations.
Examples include:
- A ransomware attack preventing access to mortgage guarantee processing systems.
- Loss of the primary office following a fire.
- Prolonged telecommunications outage affecting customer services.
- Simultaneous failure of a cloud service provider and network connectivity.
- Pandemic-related workforce shortages affecting critical operational functions.
Scenario development enables Damanat to evaluate its recovery capability under realistic operating conditions.
Threat Categories Relevant to Damanat
The following threat categories represent an indicative set of disruption scenarios appropriate to Damanat's operating environment.
People-Related Threats
People remain one of the most important organisational resources. Disruptions affecting personnel may significantly reduce operational capability.
Examples include:
- Pandemic or infectious disease outbreak.
- Loss of key personnel.
- Industrial action.
- Insider threat.
- Human error.
- Fraud.
- Workplace violence.
- Failure of succession arrangements.
- Inadequate staffing.
- Travel restrictions.
Effective workforce planning, succession management, cross-training, and employee wellbeing programmes reduce exposure to these threats.
Premises and Physical Threats
Disruption affecting physical facilities may interrupt business operations and employee access.
Examples include:
- Fire.
- Flooding.
- Structural damage.
- Utility failure.
- Air conditioning failure.
- Physical security breach.
- Bomb threat.
- Hazardous materials incident.
- Access denial.
- Building evacuation.
Alternate workplace arrangements should be developed to support continued operations during facility disruptions.
Technology and Cyber Threats
Given Damanat's reliance on digital systems, technology-related disruptions represent one of the most significant business continuity risks.
Examples include:
- Core application failure.
- Network outage.
- Database corruption.
- Ransomware.
- Malware infection.
- Distributed Denial-of-Service (DDoS) attack.
- Identity and access management failure.
- Cloud platform outage.
- Telecommunications disruption.
- Hardware failure.
Technology resilience should be supported through ICT Disaster Recovery, cybersecurity controls, and resilient infrastructure.
Information Threats
Information is essential to every Critical Business Function performed by Damanat.
Potential threats include:
- Loss of vital records.
- Data corruption.
- Confidentiality breach.
- Unauthorised disclosure.
- Backup failure.
- Document management failure.
- Inaccurate information.
- Loss of audit evidence.
Strong information governance and backup arrangements reduce these risks.
Third-Party Threats
Many essential services depend upon external organisations.
Examples include:
- Supplier insolvency.
- Outsourced service disruption.
- Cloud provider outage.
- Telecommunications failure.
- Software vendor failure.
- Facilities contractor failure.
- Cyber incident affecting a supplier.
- Logistics disruption.
- Concentration risk.
- Failure of financial institution interfaces.
Supplier resilience should form an integral part of Damanat's BCM programme.
External and Environmental Threats
Some disruptions originate beyond the organisation's direct control.
Examples include:
- Extreme weather.
- Sandstorms.
- Regional flooding.
- Earthquake.
- Public disorder.
- Transportation disruption.
- Infrastructure failure.
- Utility interruption.
- Public health emergency.
- Geopolitical developments.
These scenarios should be incorporated into Business Continuity exercises where appropriate.
Regulatory and Operational Threats
As a regulated financial services organisation, Damanat should also consider threats affecting governance and regulatory responsibilities.
Examples include:
- Failure of critical decision-making processes.
- Regulatory reporting failure.
- Loss of statutory records.
- Delayed mortgage guarantee processing.
- Communication failures.
- Breakdown in inter-agency coordination.
- Regulatory investigation.
- Significant legal proceedings.
- Failure of governance processes.
- Major operational errors.
Although these events may not always arise from physical disruptions, they can have substantial continuity implications.
Threat Assessment Principles
When identifying threats, Damanat should adopt several guiding principles:
Consider Multiple Threat Sources
Threats may originate from people, technology, facilities, suppliers, environmental conditions, or external events. A comprehensive assessment should include all relevant categories.
Focus on Business Impact
Threat identification should emphasise disruptions capable of affecting Critical Business Functions rather than routine operational issues.
Evaluate Existing Controls
The presence of effective preventive and detective controls influences both the likelihood and the consequences of disruptive events.
Consider Cascading Effects
A single disruption may affect multiple business functions simultaneously. For example, a prolonged telecommunications outage may disrupt customer communications, regulatory reporting, remote working, and access to cloud-based applications.
Review Emerging Risks
The threat landscape evolves continuously. Cybersecurity developments, technological innovation, regulatory changes, and geopolitical events should be reviewed periodically to ensure that the threat catalogue remains current.
Table 1.9: Indicative Threat Categories for The Saudi Mortgage Guarantees Services Company (Damanat)
|
Threat Category |
Illustrative Threat |
Potentially Affected Areas |
Existing Control Examples |
BCM Relevance |
Validation Required |
|
People |
Pandemic, loss of key personnel, and human error |
Business operations, customer service, and management |
Cross-training, succession planning, and HR policies |
High |
Yes |
|
Premises |
Fire, flooding, utility failure, and access denial |
Office facilities, workplace availability |
Fire protection, evacuation plans, and alternate workplace arrangements |
High |
Yes |
|
Technology & Cyber |
Ransomware, system failure, network outage, cloud disruption |
Core business applications, ICT infrastructure |
ICT Disaster Recovery, cybersecurity controls, and backups |
Critical |
Yes |
|
Information |
Data corruption, confidentiality breach, and records loss |
Customer information, guarantee records, and regulatory documentation |
Information security, backup, and records management |
Critical |
Yes |
|
Third Parties |
Supplier failure, telecommunications outage, outsourced service disruption |
Technology services, facilities, operational support |
Vendor management, contracts, supplier resilience reviews |
High |
Yes |
|
External & Environmental |
Extreme weather, infrastructure failure, public health emergency |
Premises, workforce, logistics |
Emergency procedures, alternate working arrangements |
Medium–High |
Yes |
|
Regulatory & Operational |
Regulatory reporting failure, governance breakdown, communication failure |
Compliance, stakeholder confidence, decision-making |
Governance framework, management oversight, compliance monitoring |
High |
Yes |
Transition to the Risk Analysis and Review Phase
The threat categories presented in this chapter provide an initial understanding of the range of disruptions that may affect Damanat's operations.
They should not be regarded as a completed risk assessment. During the Risk Analysis and Review (RAR) phase, each identified threat should be analysed in greater detail to determine:
- Specific threat scenarios.
- Associated vulnerabilities.
- Existing preventive and detective controls.
- Likelihood of occurrence.
- Potential business consequences.
- Overall risk rating.
- Required treatment actions.
- Residual risk after controls.
The resulting Threat Register and Risk Register will provide the evidence-based foundation for the subsequent Business Impact Analysis and Business Continuity Strategy development.
A comprehensive understanding of risks and threats enables Damanat to design a Business Continuity Management programme that is proportionate, resilient, and aligned with its operational and regulatory responsibilities.
By identifying credible disruption scenarios across people, premises, technology, information, suppliers, external events, and governance processes, the organisation can prioritise continuity planning where it is needed most.
This strategic threat assessment establishes the risk context for the remainder of the BCM Planning Methodology.
The detailed evaluation of threats, vulnerabilities, controls, likelihood, consequences, and risk treatment measures will be undertaken during the Risk Analysis and Review phase, ensuring that subsequent Business Impact Analysis, continuity strategies, and recovery plans are based on a sound understanding of Damanat's disruption risks.
| eBook 1: Understanding Your Organisation | |||||
| C1 | C2 | C3 | C4 | C5 | C6 |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
| C7 | C8 | C9 | C10 | C11 | C12 |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)




![Banner [Summary] [BCM] [E1] [C9] Assessing Risks and Threats](https://no-cache.hubspot.com/cta/default/3893111/0d5248d9-47ae-40d5-89d5-1ad12dd73b48.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E1] [C1] Overview of BCM Implementation](https://no-cache.hubspot.com/cta/default/3893111/309edfca-09de-495f-9922-4f348deb8396.png)
![[BCM] [Damanat] [E1] [C2] Understanding Your Organisation](https://no-cache.hubspot.com/cta/default/3893111/f0657049-9531-4486-8c0a-bcdab739d881.png)
![BCM] [Damanat] [E1] [C3] Establishing Organisational Goals](https://no-cache.hubspot.com/cta/default/3893111/5836e2db-2a45-427d-b6c6-de4c30e75c9c.png)
![BCM] [Damanat] [E1] [C4] Establishing Business Continuity Objectives](https://no-cache.hubspot.com/cta/default/3893111/dc123537-eec6-4632-b2ba-5575ee2c042e.png)
![[BCM] [Damanat] [E1] [C5] Determining BC Assumptions](https://no-cache.hubspot.com/cta/default/3893111/5cae3761-0513-4c92-9abf-f36a3a9500be.png)
![x [BCM] [Damanat] [E1] [C6] Composing BCM Team](https://no-cache.hubspot.com/cta/default/3893111/c5f3fdd4-1cb7-4881-bcf9-52dee6c9f200.png)
![BCM] [Damanat] [E1] [C7] Analysing Operating Environment](https://no-cache.hubspot.com/cta/default/3893111/53cb91bf-2418-414a-8447-44939cb90e73.png)
![BCM] [Damanat] [E1] [C8] Implementing the BCM Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/848cffed-7a7a-4f0d-9e35-32a0296f2e8a.png)
![BCM] [Damanat] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/09f61f4b-0a96-4099-90ad-ec4db212874e.png)
![[BCM] [Damanat] [E1] [C11] Summary of Understanding Your Organisation](https://no-cache.hubspot.com/cta/default/3893111/e8f1271d-be35-4f91-b144-970755c19e7b.png)
![BCM] [Damanat] [E1] [C12] Back Cover for E1](https://no-cache.hubspot.com/cta/default/3893111/562b00b9-2b1b-46f9-8201-797106ac3990.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





