Part 2: Risk Analysis and Review – Treatment and Control
Introduction
Following the completion of the Threat Register in Part 1: Risk Analysis and Review – List of Threats, the next step in the Risk Analysis and Review (RAR) process is to evaluate how each identified threat is currently managed and determine whether the existing control environment is adequate.
The objective is not merely to identify risks but to understand whether Damanat has implemented appropriate measures to prevent, reduce, transfer or formally accept those risks in accordance with its business continuity objectives.
This approach is consistent with the BCM Institute RAR methodology, where threat identification is followed by a structured assessment of treatment strategies and supporting controls.
A threat is a potential event that could disrupt Damanat's operations. A risk treatment is the overall strategy adopted to manage that threat, while a control is the specific administrative, technical or physical measure used to implement the chosen treatment.
A single threat frequently requires more than one treatment strategy. For example, ransomware may be reduced through preventive cybersecurity controls, transferred through cyber insurance and managed through formally approved residual risk acceptance.
Because the actual internal control environment of The Saudi Mortgage Guarantees Services Company (Damanat) has not been publicly documented, the existing controls described below are reasonable assumptions requiring validation during the BCM implementation project.
Recommended planned controls represent improvements that should be evaluated, prioritised and approved by management before implementation.
Table T2-P1: Treatment and Control
This section establishes treatment strategies for the first set of threats based on the Damanat threat register and follows the BCM Institute's structured RAR treatment methodology.
|
Threat |
Existing Risk Treatment – Risk Avoidance |
Existing Risk Treatment – Risk Reduction |
Existing Risk Treatment – Risk Transference |
Existing Risk Treatment – Risk Acceptance |
Existing Controls |
Additional (Planned) Controls |
|
Earthquake |
Not applicable—operations cannot avoid regional seismic events. |
Emergency response procedures, alternate workplace arrangements and resilient ICT infrastructure. |
Property and business interruption insurance. |
Residual exposure accepted within Board-approved risk appetite after continuity arrangements. |
Emergency evacuation procedures, backup power, off-site data backup, alternate workplace capability. |
Seismic assessment of facilities, annual evacuation exercises, enhanced off-site replication, Facilities Manager, High Priority (12 months). |
|
Flash Flood |
Locate critical ICT infrastructure above flood-prone areas where practicable. |
Flood monitoring, remote-working capability, and alternate workplace activation. |
Insurance for property damage. |
Residual exposure monitored during rainy seasons. |
Environmental monitoring, emergency communication procedures. |
Flood response plan, supplier recovery coordination, annual flood exercise, Facilities Manager, Medium Priority. |
|
Severe Sandstorm |
Not applicable. |
Flexible working arrangements, remote access and environmental monitoring. |
Not generally applicable. |
Operational delays are accepted where employee safety is prioritised. |
Remote access capability, weather alerts, work-from-home procedures. |
Enhanced virtual collaboration capability and alternate telecommunications providers. |
|
Extreme Heat |
Avoid locating critical equipment in poorly controlled environments. |
Redundant HVAC systems and preventive maintenance. |
Equipment maintenance contracts. |
Acceptable after environmental controls are verified. |
Server room cooling, building management systems. |
Thermal monitoring sensors and dual cooling redundancy. |
|
Pandemic |
Avoid unnecessary international travel during declared outbreaks. |
Remote working, cross-training, workforce segregation and hygiene measures. |
Employee medical insurance and outsourced occupational health services. |
Residual absenteeism accepted under approved pandemic response plans. |
Remote access, health monitoring, pandemic procedures, HR continuity arrangements. |
Expand remote workforce capacity, digital workflow automation, annual pandemic simulation, HR Director, High Priority. |
|
Fire |
Prohibit hazardous storage and unsafe activities within office premises. |
Fire detection, suppression and evacuation procedures. |
Property insurance. |
Residual damage accepted after protection measures. |
Fire alarms, extinguishers, evacuation plans, emergency wardens. |
Annual fire evacuation exercises, fire compartment review, digital document conversion. |
|
Explosion |
Avoid storing hazardous materials on-site. |
Emergency evacuation and business relocation capability. |
Property insurance. |
Residual risk is accepted because complete avoidance is impractical. |
Crisis response procedures, alternate workplace. |
Coordination with civil defence authorities and crisis simulation exercises. |
|
Hazardous Material Release |
Select facilities away from identified industrial hazards where feasible. |
Building isolation procedures and emergency communications. |
Insurance where applicable. |
Temporary operational disruption accepted. |
Evacuation procedures, emergency notification system. |
Air-quality monitoring and mutual aid arrangements with neighbouring organisations. |
|
Civil Disturbance |
Avoid unnecessary travel to affected locations. |
Flexible working and remote operations. |
Not generally applicable. |
Temporary service delays accepted. |
Employee notification procedures, business travel guidance. |
Crisis communications enhancement and alternative transport arrangements. |
|
Terrorist Incident |
Not applicable. |
Physical security, access controls and emergency response. |
Terrorism insurance is available. |
Residual national security exposure accepted. |
Visitor management, CCTV, security guards, emergency response plan. |
Joint exercises with security agencies, enhanced perimeter protection, Security Manager, High Priority. |
|
Building Access Restriction |
Diversify workplace locations where possible. |
Alternate workplace activation and remote working. |
Facility lease provisions where applicable. |
Temporary disruption accepted pending relocation. |
Remote access capability, alternate office procedures. |
Permanent alternate office arrangements and annual relocation exercises. |
|
Loss of Key Personnel |
Avoid dependence on single specialists. |
Succession planning, cross-training and knowledge management. |
Recruitment agencies and external specialist contracts. |
Short-term resource constraints accepted pending replacement. |
Delegation of authority, documented procedures, competency matrices. |
Formal succession programme, knowledge repository, annual competency review, HR Director, Immediate Priority. |
|
Industrial Action |
Maintain positive employee engagement and compliance with labour obligations. |
Cross-training and workforce contingency planning. |
Outsourced temporary staffing where appropriate. |
Limited operational disruption accepted. |
HR policies, workforce communication plans. |
Framework agreements with temporary staffing providers. |
|
High Staff Absenteeism |
Not applicable. |
Remote working, workforce redistribution and overtime arrangements. |
External contract resources. |
Residual reduction in productivity accepted. |
Flexible work policies and workforce scheduling. |
Workforce resilience dashboard and cross-functional staffing pools. |
|
Skills Shortage |
Avoid sole dependency on scarce expertise. |
Continuous professional development and mentoring. |
External consultants were necessary. |
Accepted only where recruitment is underway. |
Training programmes, competency management. |
Graduate development programme and structured capability framework. |
|
Human Error |
Simplify high-risk manual processes through automation. |
Quality assurance, segregation of duties and maker-checker controls. |
Professional indemnity insurance where applicable. |
Minor residual errors accepted within quality thresholds. |
SOPs, approval workflows, audit trails. |
Workflow automation, AI-assisted validation and enhanced quality reviews. |
Table T2-P2: Treatment and Control
This section assessed the treatment strategies and assumed control environment for supply chain disruptions, ICT failures and cybersecurity threats that are critical to Damanat's mortgage guarantee operations.
|
Threat |
Existing Risk Treatment – Risk Avoidance |
Existing Risk Treatment – Risk Reduction |
Existing Risk Treatment – Risk Transference |
Existing Risk Treatment – Risk Acceptance |
Existing Controls |
Additional (Planned) Controls |
|
Critical Supplier Failure |
Avoid reliance on a single critical supplier through procurement policy. |
Supplier due diligence, continuity assessments and alternate supplier identification. |
Contractual SLAs, indemnities and supplier performance guarantees. |
Residual supplier risk accepted following annual review. |
Vendor management programme, supplier contracts, periodic performance reviews. |
Establish dual sourcing for critical services, annual supplier BCM audit, Procurement Director, High Priority (12 months). |
|
Cloud Service Provider Outage |
Avoid hosting critical services on a single cloud platform where practical. |
Multi-zone deployment, resilient architecture and backup replication. |
Cloud service agreements with defined availability commitments. |
Residual outage risk is accepted after resilience measures are validated. |
Cloud backup, disaster recovery arrangements, SLA monitoring. |
Evaluate multi-cloud strategy, annual cloud recovery testing, CIO, High Priority. |
|
Telecommunications Failure |
Avoid dependence on a single telecommunications carrier. |
Dual communication links, mobile failover and alternate communications. |
Carrier service-level agreements. |
Temporary communication degradation accepted. |
Multiple internet circuits, mobile communications, emergency contact procedures. |
Implement SD-WAN with automatic failover and satellite communications for crisis use. |
|
Internet Service Provider Failure |
Diversify ISP providers. |
Automatic failover to secondary provider. |
Commercial service guarantees. |
Short-term degradation accepted. |
Redundant internet connectivity. |
Quarterly resilience testing of ISP failover capability. |
|
Credit Bureau Service Failure |
Avoid sole dependence on a single credit information source where feasible. |
Manual verification procedures and alternate credit information sources. |
Third-party contractual obligations. |
Temporary delays accepted pending restoration. |
Escalation procedures, manual underwriting guidance. |
Develop secondary credit data integration and contingency workflow. |
|
Banking Partner System Failure |
Avoid sole operational dependency on a single banking interface. |
Queue management, transaction resubmission and manual processing. |
Banking partnership agreements. |
Temporary processing delays accepted. |
Interface monitoring, incident escalation. |
Implement alternate banking connectivity and regular integration testing. |
|
Outsourced ICT Support Failure |
Avoid relying on a single ICT support provider for critical services. |
Cross-training internal ICT staff and documenting recovery procedures. |
Managed service contracts. |
Temporary reduction in support capacity accepted. |
ICT support contracts, escalation matrix. |
Develop internal recovery capability and maintain secondary ICT support provider. |
|
Commercial Power Failure |
Avoid locating critical ICT infrastructure where reliable backup power is unavailable. |
UPS systems and standby generators. |
Generator maintenance contracts. |
Short interruptions accepted during generator transition. |
UPS, emergency generator, preventive maintenance. |
Extend generator runtime and perform quarterly load-bank testing, Facilities Manager, Immediate Priority. |
|
HVAC Failure |
Avoid housing critical systems without environmental controls. |
Preventive maintenance and redundant cooling. |
Maintenance agreements. |
Limited downtime is accepted during repair. |
Environmental monitoring, HVAC maintenance schedule. |
Install N+1 cooling redundancy and automated thermal alerts. |
|
Network Failure |
Avoid a single network architecture. |
Redundant switches, routing and monitoring. |
Network maintenance agreements. |
Residual network disruption accepted. |
Network monitoring, redundancy, documented recovery procedures. |
Network segmentation review and annual resilience testing. |
|
Data Centre Outage |
Avoid operating from a single production site. |
Secondary recovery site and replicated infrastructure. |
Colocation or managed recovery contracts. |
Residual disruption is accepted after recovery capability is verified. |
Disaster Recovery Plan, replicated infrastructure. |
Conduct annual disaster recovery simulation and validate Recovery Time Objectives. |
|
Core Mortgage Guarantee System Failure |
Eliminate unsupported legacy applications. |
High-availability architecture and preventive maintenance. |
Vendor support agreements. |
Short-term service interruption accepted. |
Application monitoring, change management and backups. |
Implement active-active architecture and automated application health monitoring. |
|
Database Failure |
Avoid unsupported database platforms. |
Database clustering, backup and replication. |
Vendor maintenance contracts. |
Residual exposure is accepted after restoration capability is tested. |
Database backup procedures, replication and integrity checks. |
Quarterly database recovery exercises and integrity validation. |
|
Identity and Access Management Failure |
Avoid a single authentication platform where feasible. |
Redundant identity infrastructure and privileged access management. |
Vendor support agreements. |
Temporary authentication delays accepted. |
Active Directory redundancy, MFA, privileged account management. |
Implement cloud identity failover and annual identity recovery testing. |
|
Backup Failure |
Avoid dependence on a single backup technology. |
Multiple backup copies and routine restoration testing. |
Off-site backup provider. |
Minimal residual exposure accepted. |
Scheduled backups, off-site storage and backup monitoring. |
Immutable backup storage and monthly restoration validation. |
|
Storage System Failure |
Avoid single storage platform dependency. |
RAID, storage replication and proactive monitoring. |
Vendor warranty and maintenance. |
Residual storage risk accepted. |
Enterprise SAN monitoring and maintenance. |
Deploy geographically separate replicated storage. |
|
Ransomware Attack |
Eliminate unsupported operating systems and high-risk applications. |
Endpoint protection, network segmentation, MFA, security awareness and immutable backups. |
Cyber insurance and incident response retainers. |
Residual cyber risk is accepted within the approved cyber risk appetite. |
Endpoint detection and response (EDR), SIEM, email filtering, privileged access controls. |
Zero Trust architecture, continuous threat hunting, annual ransomware simulation, CISO, Immediate Priority. |
|
Malware Infection |
Remove unsupported software. |
Antivirus, application control and user awareness. |
Cyber insurance. |
Low residual exposure accepted. |
Endpoint protection and patch management. |
Advanced behavioural malware detection and automated isolation. |
|
Phishing Attack |
Restrict high-risk email behaviours where possible. |
Security awareness, email filtering and MFA. |
Cyber insurance. |
Residual phishing exposure monitored. |
Email gateway protection, phishing simulations. |
Quarterly phishing campaigns with targeted retraining. |
|
Business Email Compromise |
Avoid approving payments manually via email alone. |
Segregation of duties and payment verification. |
Crime insurance. |
Residual fraud exposure accepted after control review. |
Multi-level payment approval and call-back verification. |
AI-powered email fraud detection and payment workflow automation. |
|
Distributed Denial-of-Service (DDoS) Attack |
Avoid exposing unnecessary public-facing services. |
Traffic filtering, content delivery network and rate limiting. |
Managed DDoS protection provider. |
Residual service degradation accepted. |
Firewall, DDoS protection and network monitoring. |
Annual DDoS simulation and enhancement of public service resilience. |
|
Insider Cyber Threat |
Avoid excessive privileged access. |
Least-privilege access, monitoring and segregation of duties. |
Fidelity insurance where applicable. |
Residual insider risk accepted under governance oversight. |
User activity monitoring and privileged access reviews. |
User Behaviour Analytics (UBA) and enhanced insider risk programme. |
|
Data Breach |
Minimise unnecessary storage of confidential information. |
Encryption, DLP, access controls and monitoring. |
Cyber liability insurance. |
Residual privacy exposure accepted after governance approval. |
Encryption, DLP, information classification and incident response. |
Privacy impact assessments and automated data discovery tools. |
Table T2-P3: Treatment and Control
This section completes the Treatment and Control Assessment by addressing the remaining threats identified in the Threat Register.
|
Threat |
Existing Risk Treatment – Risk Avoidance |
Existing Risk Treatment – Risk Reduction |
Existing Risk Treatment – Risk Transference |
Existing Risk Treatment – Risk Acceptance |
Existing Controls |
Additional (Planned) Controls |
|
Loss of Physical Records |
Eliminate unnecessary paper records through digitalisation. |
Fire-resistant storage, secure archiving and document scanning. |
Off-site records storage provider. |
Minimal residual exposure accepted following digitisation. |
Records management procedures, archive storage and controlled access. |
Complete electronic document management system, Records Manager, High Priority (12 months). |
|
Electronic Record Corruption |
Avoid unsupported document repositories. |
Database integrity checking, version control and backups. |
Vendor maintenance agreements. |
Residual corruption risk accepted after restoration testing. |
Backup procedures, integrity monitoring and audit trails. |
Automated file integrity monitoring and quarterly restoration testing. |
|
Data Integrity Failure |
Eliminate duplicate manual data entry where practical. |
Input validation, maker-checker controls and reconciliation. |
Not generally applicable. |
Minor residual discrepancies are accepted within the approved tolerance. |
Validation rules, approval workflow and reconciliation reports. |
AI-assisted data validation and enhanced exception reporting. |
|
Fraudulent Mortgage Applications |
Avoid manual acceptance of unverifiable applications. |
Identity verification, fraud analytics and due diligence. |
Fraud loss insurance where appropriate. |
Residual fraud exposure accepted following investigation controls. |
Customer due diligence, AML screening, document verification and fraud monitoring. |
Deploy advanced fraud detection analytics and property verification integration. |
|
Internal Fraud |
Avoid excessive concentration of authority. |
Segregation of duties, mandatory leave and internal audits. |
Fidelity guarantee insurance. |
Residual exposure accepted under Board oversight. |
Delegation of authority, audit programme and whistleblowing procedures. |
Continuous transaction monitoring and behavioural analytics. |
|
Financial Market Instability |
Avoid excessive dependence on a single market segment. |
Strategic portfolio monitoring and scenario planning. |
Financial hedging where applicable. |
Market fluctuations accepted within corporate strategy. |
Financial monitoring, management reporting and strategic planning. |
Quarterly economic stress testing and scenario analysis. |
|
Regulatory Change |
Avoid processes dependent upon obsolete regulations. |
Regulatory monitoring, compliance reviews and policy updates. |
External legal advisory services. |
Temporary compliance risk accepted during the implementation period. |
Compliance programme, regulatory watch process and legal review. |
Regulatory change management framework and compliance impact assessments, Chief Compliance Officer, High Priority. |
|
Regulatory Investigation |
Avoid non-compliance through effective governance. |
Internal audits, compliance monitoring and issue remediation. |
Professional indemnity insurance where appropriate. |
Residual regulatory exposure accepted following governance review. |
Internal audit programme, compliance reviews and management reporting. |
Annual regulatory readiness assessment and mock supervisory inspections. |
|
Legal Proceedings |
Avoid contractual ambiguity through legal review. |
Legal compliance and contract management. |
Legal expense insurance. |
Litigation risk is accepted where unavoidable. |
Legal review process and contract approval procedures. |
Centralised legal obligations register and litigation response plan. |
|
Physical Intrusion |
Avoid unrestricted public access to secure areas. |
Security guards, access control and surveillance. |
Security services contract. |
Residual physical security risk accepted. |
CCTV, electronic access control and visitor management. |
Biometric access control and integrated security monitoring. |
|
Theft |
Avoid unsecured storage of valuable assets. |
Asset inventory management, CCTV and security patrols. |
Property insurance. |
Minor losses are accepted within the insurance excess. |
Asset register, visitor controls and security patrols. |
RFID asset tracking and enhanced security awareness training. |
|
Vandalism |
Avoid locating critical assets in vulnerable public areas. |
Physical protection and perimeter security. |
Property insurance. |
Minor cosmetic damage accepted. |
Building security, lighting and surveillance. |
Smart intrusion detection and external perimeter reinforcement. |
|
Process Failure |
Eliminate unnecessary manual activities through automation. |
SOPs, workflow management and quality assurance. |
Not applicable. |
Minor process deviations are accepted under the continuous improvement programme. |
Process documentation, approval workflows and quality reviews. |
Business process automation and periodic process maturity assessments. |
|
Manual Workaround Failure |
Reduce reliance on manual workarounds by improving ICT resilience. |
Documented manual procedures, staff training and exercises. |
Not applicable. |
Temporary manual inefficiencies accepted. |
Manual processing procedures and continuity plans. |
Annual manual processing exercises and digital workflow improvements. |
|
Inadequate Business Continuity Planning |
Avoid operating without approved BCM governance. |
BCM programme, periodic reviews and testing. |
External BCM consultancy support where required. |
No acceptance until minimum BCM capability is established. |
Business Continuity Policy, BCM governance and annual exercises. |
ISO 22301 implementation programme, annual maturity assessment, BCM Manager, Immediate Priority. |
|
Inadequate Crisis Management |
Avoid undefined crisis governance arrangements. |
Crisis Management Team, crisis procedures and exercises. |
Specialist crisis advisory services. |
Residual crisis exposure accepted after executive approval. |
Crisis Management Framework, incident escalation procedures and communications plans. |
Executive crisis simulation programme and media response training. |
|
Failure of Disaster Recovery Arrangements |
Avoid unsupported ICT recovery capability. |
Disaster Recovery Plans, replication and recovery exercises. |
Managed disaster recovery provider. |
Residual ICT outage accepted following successful annual testing. |
Disaster Recovery Plan, off-site backup and recovery procedures. |
Semi-annual technical recovery simulations and recovery assurance reviews. |
|
Negative Media Coverage |
Avoid unnecessary disclosure of inaccurate information. |
Media management and stakeholder communications. |
Public relations advisory support. |
Residual reputational exposure is accepted following communications planning. |
Crisis communication procedures and media spokesperson. |
Reputation monitoring platform and executive media training. |
|
Social Media Misinformation |
Avoid unmanaged social media channels. |
Social media monitoring and rapid response. |
Communications agency support. |
Residual misinformation risk is accepted after monitoring. |
Corporate communications procedures. |
Real-time social listening platform and misinformation response playbook. |
|
Service Delivery Failure |
Avoid overdependence on manual service delivery. |
Performance monitoring, customer feedback and quality management. |
Service contracts where applicable. |
Minor service interruptions are accepted within approved service standards. |
KPI monitoring, customer complaints management and operational reporting. |
Customer experience dashboard and operational resilience metrics. |
|
Governance Failure |
Avoid unclear governance responsibilities. |
Defined governance framework and Board oversight. |
Independent assurance reviews. |
Residual governance risk accepted after Board review. |
Governance committees, internal audit and risk management framework. |
Governance effectiveness assessment every two years. |
|
Poor Change Management |
Avoid uncontrolled system or business changes. |
Formal change management process and testing. |
Specialist implementation support. |
Residual implementation risk accepted after CAB approval. |
Change Advisory Board, testing and release management. |
Enterprise change governance framework and post-implementation reviews. |
|
Third-Party Concentration Risk |
Avoid reliance on a single critical supplier. |
Supplier diversification and resilience assessments. |
Multi-vendor contracts. |
Residual dependency accepted following annual review. |
Third-party risk management programme. |
Supplier concentration dashboard and dual-vendor strategy. |
|
Simultaneous Multiple Disruptions |
Cannot realistically be avoided. |
Enterprise Crisis Management, integrated BCM and scenario planning. |
Insurance and reciprocal support arrangements. |
Residual enterprise risk is accepted after Board approval. |
Enterprise Crisis Management Plan, BCM, Disaster Recovery Plan and Emergency Response Plan. |
Enterprise-wide simulation involving multiple concurrent scenarios every year, CEO, Immediate Priority. |
Treatment and Control Gap Analysis
Confirmed and Inferred Control Gaps
Based on the assumed control environment, several important gaps should be validated during the BCM implementation programme.
Threats Without Practical Risk Avoidance
The following threats cannot realistically be eliminated and therefore require robust preventive, response and recovery capabilities:
- Earthquake
- Flash Flood
- Sandstorm
- Pandemic
- Commercial Power Failure
- Cyberattack
- Ransomware
- Data Centre Outage
- Simultaneous Multiple Disruptions
These threats rely predominantly on Risk Reduction supported by continuity planning and resilience investments.
Single Points of Failure Requiring Validation
Potential single-point dependencies include:
- Mortgage Guarantee Processing System
- Identity and Access Management platform
- Credit Bureau integration
- Banking interfaces
- Cloud infrastructure
- Specialist mortgage guarantee personnel
- Critical telecommunications providers
These dependencies should be analysed further during the Business Impact Analysis (BIA) and dependency mapping exercises.
Controls Requiring Periodic Testing
The effectiveness of the following controls depends on regular testing:
- Business Continuity Plans
- Disaster Recovery Plans
- Crisis Management Plans
- Backup restoration procedures
- Generator failover
- Alternate workplace activation
- Cloud recovery capability
- Supplier continuity arrangements
- Emergency communications
- Incident escalation procedures
Untested controls should not be assumed to be fully effective.
Common Weaknesses Across Multiple Threats
Several threats share common vulnerabilities, including:
- Dependence on a limited number of ICT suppliers
- Dependence on key personnel
- Increasing cybersecurity exposure
- Limited automation of manual processes
- Third-party service concentration
- Insufficient integrated testing across business units
Addressing these systemic weaknesses will improve resilience across multiple threat scenarios simultaneously.
Planned Control Priorities
Following the assessment of existing and assumed controls, Damanat should establish a structured improvement programme to address identified gaps.
The implementation priorities below are based on the potential impact on critical business functions, regulatory expectations, operational resilience, and Business Continuity Management (BCM) maturity.
Each recommendation should be validated through detailed project planning, budget approval, and governance oversight.
|
Priority |
Improvement Initiative |
Primary Threat(s) Addressed |
Expected Benefit |
Suggested Owner |
Recommended Timeframe |
|
Immediate |
Implement an ISO 22301-aligned Business Continuity Management System (BCMS). |
All operational disruptions |
Establishes enterprise-wide BCM governance and structured resilience. |
Executive Management / BCM Manager |
6–12 months |
|
Immediate |
Strengthen cybersecurity using a Zero Trust architecture, multi-factor authentication (MFA), endpoint detection and response (EDR), and Security Information and Event Management (SIEM). |
Cyberattack, ransomware, phishing, malware, insider threats |
Reduces cyber risk and improves incident detection and response capability. |
Chief Information Security Officer (CISO) |
6–12 months |
|
Immediate |
Conduct enterprise-wide Business Impact Analysis (BIA) and dependency mapping. |
All critical business disruptions |
Identifies recovery priorities, dependencies and recovery objectives. |
BCM Manager |
6 months |
|
Immediate |
Validate Disaster Recovery (DR) capability through technical recovery testing. |
Data centre outage, application failure, database failure, backup failure |
Confirms recoverability of critical ICT systems within target recovery objectives. |
CIO / ICT Infrastructure Manager |
Annually |
|
Immediate |
Develop an enterprise Crisis Management Plan integrated with BCM. |
Major operational disruptions, multiple concurrent incidents |
Improves strategic decision-making during crises. |
Crisis Management Team |
6 months |
|
High |
Establish an alternate workplace capability with secure remote working. |
Pandemic, fire, building access restriction, severe weather |
Maintains continuity when primary facilities are unavailable. |
Facilities Manager / HR Director |
12 months |
|
High |
Strengthen supplier resilience through Third-Party Risk Management (TPRM). |
Critical supplier failure, cloud provider outage, telecommunications failure |
Reduces dependency on critical third parties and improves supply chain resilience. |
Procurement Director |
12 months |
|
High |
Implement enterprise-wide electronic document and records management. |
Loss of physical records, data integrity issues |
Improves information availability and regulatory compliance. |
Records Manager |
12–18 months |
|
High |
Introduce structured succession planning and cross-training programme. |
Loss of key personnel, skills shortage, absenteeism |
Reduces dependency on specialist staff and improves workforce resilience. |
HR Director |
12 months |
|
High |
Implement automated fraud detection and advanced analytics. |
Fraudulent mortgage applications, internal fraud |
Improves fraud prevention and operational efficiency. |
Risk Management Director |
12–18 months |
|
Medium |
Diversify telecommunications and internet providers. |
Telecommunications failure, ISP outage |
Improves communications resilience. |
CIO |
12–18 months |
|
Medium |
Expand cloud resilience using multi-region or multi-cloud deployment. |
Cloud service outage, data centre failure |
Improves ICT availability and disaster recovery capability. |
CIO |
18 months |
|
Medium |
Enhance physical security with biometric access control and integrated surveillance. |
Physical intrusion, theft, vandalism |
Improves protection of personnel and physical assets. |
Security Manager |
18 months |
|
Medium |
Establish enterprise-wide resilience dashboards and Key Risk Indicators (KRIs). |
Strategic and operational threats |
Provides management with timely resilience reporting. |
Enterprise Risk Manager |
12 months |
|
Ongoing |
Conduct annual integrated BCM, Crisis Management and Disaster Recovery exercises. |
All identified threats |
Validates plans, improves organisational preparedness and supports continual improvement. |
BCM Manager |
Annual |
|
Ongoing |
Perform periodic BCM maturity assessments against ISO 22301 and organisational objectives. |
Enterprise-wide |
Supports continual improvement and governance oversight. |
Internal Audit / BCM Manager |
Every two years |
Control Governance and Ownership
Effective risk treatment requires more than implementing controls; it requires clear governance to ensure that controls remain appropriate, effective, and aligned with Damanat's strategic objectives.
Senior management should establish a governance framework that defines accountability for implementing, monitoring, reviewing, and continually improving business continuity controls.
The Board of Directors should approve the organisation's Business Continuity Policy, risk appetite, and resilience objectives. Executive Management should ensure that sufficient resources are allocated to implement approved control improvements and oversee enterprise-wide resilience initiatives.
A Business Continuity Steering Committee should coordinate implementation across business units, monitor programme progress, and report significant issues to senior leadership.
Operational ownership should be clearly assigned according to functional responsibilities:
|
Role |
Primary Governance Responsibilities |
|
Board of Directors |
Approve BCM policy, risk appetite, strategic resilience objectives, and receive regular assurance reports. |
|
Executive Management |
Sponsor BCM implementation, allocate resources and monitor enterprise resilience performance. |
|
Business Continuity Manager |
Maintain the BCMS, coordinate Business Impact Analysis (BIA), Risk Analysis and Review (RAR), plan development, testing and continual improvement. |
|
Chief Risk Officer / Enterprise Risk Manager |
Integrate BCM risks into the Enterprise Risk Management framework and monitor enterprise risk exposure. |
|
Chief Information Officer (CIO) |
Ensure resilience of ICT infrastructure, cloud services, networks, data centres and disaster recovery capability. |
|
Chief Information Security Officer (CISO) |
Protect information assets through cybersecurity governance, monitoring and incident response. |
|
Chief Compliance Officer |
Monitor regulatory developments and ensure continued compliance with SAMA, the Insurance Authority and other applicable regulatory requirements. |
|
Human Resources Director |
Maintain succession planning, workforce resilience, employee awareness and crisis staffing arrangements. |
|
Procurement / Third-Party Risk Manager |
Manage supplier resilience, contractual obligations and third-party continuity assurance. |
|
Facilities and Security Manager |
Maintain workplace resilience, physical security, emergency preparedness and facility recovery arrangements. |
|
Internal Audit |
Independently assess the effectiveness of the Business Continuity Management System and verify implementation of approved controls. |
Regular governance activities should include quarterly management reviews, annual risk reassessments, periodic Business Continuity Plan reviews, testing and exercising programmes, supplier assurance reviews, internal audits, and management reporting.
Significant changes to business processes, technology, regulatory requirements, or organisational structure should trigger a review of the Risk Analysis and Review to ensure that treatment strategies and controls remain appropriate.
Risk treatment transforms a list of identified threats into a practical resilience programme by determining how each risk will be managed through appropriate treatment strategies and effective controls.
For Damanat, the assessment demonstrates that while some risks can be partially avoided, the majority require a combination of Risk Reduction, Risk Transference, and carefully governed Risk Acceptance.
The effectiveness of these strategies depends not only on the existence of documented controls but also on their regular validation through testing, exercising, monitoring, and continual improvement.
The Treatment and Control assessment also highlights that organisational resilience is strengthened by addressing common dependencies rather than treating each threat in isolation.
Investments in cybersecurity, resilient ICT infrastructure, supplier resilience, workforce capability, governance, and integrated business continuity arrangements simultaneously reduce exposure across multiple threat scenarios.
By implementing the recommended control improvements, validating existing arrangements, and maintaining effective governance, Damanat will be better positioned to protect its critical business functions, fulfil its regulatory obligations, and maintain stakeholder confidence during periods of disruption.
This completed Treatment and Control assessment provides the foundation for the next stage of the Business Continuity Management planning process, in which the effectiveness of the identified controls will be evaluated through likelihood and impact assessments, enabling management to prioritise risks and allocate resources in line with the organisation's overall risk appetite and resilience objectives.
More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [B-3] course and the BCM-5000 Business Continuity Management Expert Implementer [B-5].
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
If you have any questions, click to contact us.
|
![]() |
![]() |
![]() |
![]() |


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)




![[BCM] [Damanat] [E3] [RAR] [T2] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/683192aa-bac0-4658-981a-a392b104aa51.png)

![Banner [Table] [BCM] [E3] [RAR] [Summing Up] [T2] Treatment and Control of Identified Threats](https://no-cache.hubspot.com/cta/default/3893111/6755d2e8-5050-4a5e-be0a-a1568a65e0ed.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E3] [BIA] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/be2d62c7-973a-489a-8556-d73428e73448.png)
![[BCM] [Damanat] [E3] [BIA] [PS] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/db1b84bd-ff7f-4d59-8efb-d610b612a861.png)
![[BCM] [Damanat] [E3] [RAR] [T1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/3c267477-b524-461e-982d-1218d6bcac5b.png)
![[BCM] [Damanat] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/0cbb6459-eaf8-44bb-8d84-8071cc4c1028.png)
![[BCM] [Damanat] [E3] [BCS] [T1] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/65dcb68f-d4c9-4517-94f6-8d6df193c7bd.png)
![BCM] [Damanat] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/09f61f4b-0a96-4099-90ad-ec4db212874e.png)
![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)





![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





