Ebook

[BCM] [Damanat] [E1] [C9] Assessing Risks and Threats

Written by Moh Heng Goh | Jul 24, 2026 7:17:20 AM

Chapter 9

Assessing Risks and Threats

 

 

Introduction

An organisation's ability to maintain continuity during disruptive events depends largely on its understanding of the risks and threats that may affect its operations.

Before appropriate recovery strategies can be developed, Damanat must identify the events that could interrupt its Critical Business Functions (CBFs), evaluate the organisation's exposure to those events, and understand the potential consequences should they occur.

Risk assessment is therefore a fundamental component of Business Continuity Management (BCM). It provides the information necessary to prioritise continuity planning, allocate resources appropriately, and implement preventive and recovery measures that are proportionate to the organisation's operational and regulatory responsibilities.

For the Saudi Mortgage Guarantees Services Company (Damanat), threat assessment should consider both internal and external events that may disrupt mortgage guarantee services, supporting business operations, technology infrastructure, regulatory obligations, and stakeholder confidence.

The objective is not to predict every possible incident but to understand the range of credible disruption scenarios that could significantly affect business continuity.

It is important to recognise that this chapter introduces the concept of threat identification at a strategic level.

The detailed assessment of threats, vulnerabilities, likelihood, consequences, existing controls, and residual risks should be undertaken during the Risk Analysis and Review (RAR) phase of the BCM Planning Methodology.


 

Understanding Key Risk Management Concepts

Business Continuity Threats

A threat is any event, circumstance, or condition that has the potential to disrupt Damanat's operations or adversely affect its ability to deliver critical business services.

Examples include:

  • Cyber attacks
  • Fire
  • Flooding
  • Pandemic
  • Utility failure
  • Supplier failure
  • Human error

A threat represents the source of potential disruption.

 

Vulnerability

A vulnerability is a weakness that increases the likelihood that a threat will result in operational disruption.

Examples include:

  • Single points of failure.
  • Lack of alternate suppliers.
  • Insufficient staff cross-training.
  • Inadequate cybersecurity controls.
  • Outdated recovery procedures.
  • Poor documentation.
  • Dependence on a single facility.

Reducing vulnerabilities improves organisational resilience even when threats cannot be eliminated.

 

Control

A control is a preventive, detective, or corrective measure implemented to reduce either the likelihood or the impact of a disruptive event.

Examples include:

  • Fire suppression systems.
  • Access controls.
  • Cybersecurity monitoring.
  • Backup generators.
  • Data backups.
  • Employee awareness training.
  • Alternate communication systems.

Strong controls reduce organisational exposure to disruption.

 

Consequence

A consequence describes the operational, financial, legal, regulatory, reputational, or stakeholder impact resulting from a disruptive event.

Potential consequences include:

  • Delayed mortgage guarantee approvals.
  • Loss of critical information.
  • Regulatory non-compliance.
  • Customer dissatisfaction.
  • Financial losses.
  • Reputational damage.
  • Reduced stakeholder confidence.

Understanding consequences supports recovery prioritisation.

 

Likelihood

Likelihood represents the estimated probability that a threat will occur within a given planning period.

Likelihood should be determined using appropriate organisational criteria and supported by historical information, threat intelligence, expert judgement, and recognised risk management practices.

 

Risk

A risk is the combination of the likelihood that a threat will occur and the severity of its consequences should it materialise.

Business Continuity planning focuses on risks capable of causing significant interruption to Critical Business Functions rather than on routine operational issues.

 

Disruption Scenario

A disruption scenario is a realistic description of how one or more threats may affect Damanat's operations.

Examples include:

  • A ransomware attack preventing access to mortgage guarantee processing systems.
  • Loss of the primary office following a fire.
  • Prolonged telecommunications outage affecting customer services.
  • Simultaneous failure of a cloud service provider and network connectivity.
  • Pandemic-related workforce shortages affecting critical operational functions.

Scenario development enables Damanat to evaluate its recovery capability under realistic operating conditions.

 

Threat Categories Relevant to Damanat

The following threat categories represent an indicative set of disruption scenarios appropriate to Damanat's operating environment.

 

People-Related Threats

People remain one of the most important organisational resources. Disruptions affecting personnel may significantly reduce operational capability.

Examples include:

  • Pandemic or infectious disease outbreak.
  • Loss of key personnel.
  • Industrial action.
  • Insider threat.
  • Human error.
  • Fraud.
  • Workplace violence.
  • Failure of succession arrangements.
  • Inadequate staffing.
  • Travel restrictions.

Effective workforce planning, succession management, cross-training, and employee wellbeing programmes reduce exposure to these threats.

 

Premises and Physical Threats

Disruption affecting physical facilities may interrupt business operations and employee access.

Examples include:

  • Fire.
  • Flooding.
  • Structural damage.
  • Utility failure.
  • Air conditioning failure.
  • Physical security breach.
  • Bomb threat.
  • Hazardous materials incident.
  • Access denial.
  • Building evacuation.

Alternate workplace arrangements should be developed to support continued operations during facility disruptions.

 

Technology and Cyber Threats

Given Damanat's reliance on digital systems, technology-related disruptions represent one of the most significant business continuity risks.

Examples include:

  • Core application failure.
  • Network outage.
  • Database corruption.
  • Ransomware.
  • Malware infection.
  • Distributed Denial-of-Service (DDoS) attack.
  • Identity and access management failure.
  • Cloud platform outage.
  • Telecommunications disruption.
  • Hardware failure.

Technology resilience should be supported through ICT Disaster Recovery, cybersecurity controls, and resilient infrastructure.

 

Information Threats

Information is essential to every Critical Business Function performed by Damanat.

Potential threats include:

  • Loss of vital records.
  • Data corruption.
  • Confidentiality breach.
  • Unauthorised disclosure.
  • Backup failure.
  • Document management failure.
  • Inaccurate information.
  • Loss of audit evidence.

Strong information governance and backup arrangements reduce these risks.

 

Third-Party Threats

Many essential services depend upon external organisations.

Examples include:

  • Supplier insolvency.
  • Outsourced service disruption.
  • Cloud provider outage.
  • Telecommunications failure.
  • Software vendor failure.
  • Facilities contractor failure.
  • Cyber incident affecting a supplier.
  • Logistics disruption.
  • Concentration risk.
  • Failure of financial institution interfaces.

Supplier resilience should form an integral part of Damanat's BCM programme.

 

External and Environmental Threats

Some disruptions originate beyond the organisation's direct control.

Examples include:

  • Extreme weather.
  • Sandstorms.
  • Regional flooding.
  • Earthquake.
  • Public disorder.
  • Transportation disruption.
  • Infrastructure failure.
  • Utility interruption.
  • Public health emergency.
  • Geopolitical developments.

These scenarios should be incorporated into Business Continuity exercises where appropriate.

 

Regulatory and Operational Threats

As a regulated financial services organisation, Damanat should also consider threats affecting governance and regulatory responsibilities.

Examples include:

  • Failure of critical decision-making processes.
  • Regulatory reporting failure.
  • Loss of statutory records.
  • Delayed mortgage guarantee processing.
  • Communication failures.
  • Breakdown in inter-agency coordination.
  • Regulatory investigation.
  • Significant legal proceedings.
  • Failure of governance processes.
  • Major operational errors.

Although these events may not always arise from physical disruptions, they can have substantial continuity implications.

 

Threat Assessment Principles

When identifying threats, Damanat should adopt several guiding principles:

Consider Multiple Threat Sources

Threats may originate from people, technology, facilities, suppliers, environmental conditions, or external events. A comprehensive assessment should include all relevant categories.

Focus on Business Impact

Threat identification should emphasise disruptions capable of affecting Critical Business Functions rather than routine operational issues.

Evaluate Existing Controls

The presence of effective preventive and detective controls influences both the likelihood and the consequences of disruptive events.

Consider Cascading Effects

A single disruption may affect multiple business functions simultaneously. For example, a prolonged telecommunications outage may disrupt customer communications, regulatory reporting, remote working, and access to cloud-based applications.

Review Emerging Risks

The threat landscape evolves continuously. Cybersecurity developments, technological innovation, regulatory changes, and geopolitical events should be reviewed periodically to ensure that the threat catalogue remains current.

 

Table 1.9: Indicative Threat Categories for The Saudi Mortgage Guarantees Services Company (Damanat)

Threat Category

Illustrative Threat

Potentially Affected Areas

Existing Control Examples

BCM Relevance

Validation Required

People

Pandemic, loss of key personnel, and human error

Business operations, customer service, and management

Cross-training, succession planning, and HR policies

High

Yes

Premises

Fire, flooding, utility failure, and access denial

Office facilities, workplace availability

Fire protection, evacuation plans, and alternate workplace arrangements

High

Yes

Technology & Cyber

Ransomware, system failure, network outage, cloud disruption

Core business applications, ICT infrastructure

ICT Disaster Recovery, cybersecurity controls, and backups

Critical

Yes

Information

Data corruption, confidentiality breach, and records loss

Customer information, guarantee records, and regulatory documentation

Information security, backup, and records management

Critical

Yes

Third Parties

Supplier failure, telecommunications outage, outsourced service disruption

Technology services, facilities, operational support

Vendor management, contracts, supplier resilience reviews

High

Yes

External & Environmental

Extreme weather, infrastructure failure, public health emergency

Premises, workforce, logistics

Emergency procedures, alternate working arrangements

Medium–High

Yes

Regulatory & Operational

Regulatory reporting failure, governance breakdown, communication failure

Compliance, stakeholder confidence, decision-making

Governance framework, management oversight, compliance monitoring

High

Yes

 

Transition to the Risk Analysis and Review Phase

The threat categories presented in this chapter provide an initial understanding of the range of disruptions that may affect Damanat's operations.

They should not be regarded as a completed risk assessment. During the Risk Analysis and Review (RAR) phase, each identified threat should be analysed in greater detail to determine:

  • Specific threat scenarios.
  • Associated vulnerabilities.
  • Existing preventive and detective controls.
  • Likelihood of occurrence.
  • Potential business consequences.
  • Overall risk rating.
  • Required treatment actions.
  • Residual risk after controls.

The resulting Threat Register and Risk Register will provide the evidence-based foundation for the subsequent Business Impact Analysis and Business Continuity Strategy development.

 

A comprehensive understanding of risks and threats enables Damanat to design a Business Continuity Management programme that is proportionate, resilient, and aligned with its operational and regulatory responsibilities.

By identifying credible disruption scenarios across people, premises, technology, information, suppliers, external events, and governance processes, the organisation can prioritise continuity planning where it is needed most.

This strategic threat assessment establishes the risk context for the remainder of the BCM Planning Methodology.

The detailed evaluation of threats, vulnerabilities, controls, likelihood, consequences, and risk treatment measures will be undertaken during the Risk Analysis and Review phase, ensuring that subsequent Business Impact Analysis, continuity strategies, and recovery plans are based on a sound understanding of Damanat's disruption risks.

 

eBook 1: Understanding Your Organisation
C1 C2 C3 C4 C5 C6
C7 C8 C9 C10 C11 C12
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

Please feel free to send us a note if you have any questions.