---
title: [BCM] [JCUS] [E3] [RAR] [T1] List of Threats
description: [BCM] [JCUS] [E3] [RAR] [T1] List of Threats
image: https://blog.bcm-institute.org/hubfs/JCU%20Graphic%20Folder/JCU%20E3%20Morepost/%5BBCM%5D%20%5BJCU%5D%20%5BE3%5D%20%5BRAR%5D%20%5BT1%5D%20List%20of%20Threats.jpg
---

. .

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

##### Institutional Resilience in Action: Business Continuity Management Implementation at JCU Singapore

![BCM Ai Gen\_with Cert Logo\_4](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20BCM%20%5BAi%20Gen%20Blog%20Photo%5D/BCM%20Ai%20Gen_with%20Cert%20Logo_4.jpg?width=2000&height=1333&name=BCM%20Ai%20Gen_with%20Cert%20Logo_4.jpg "BCM Ai Gen_with Cert Logo_4")

# \[BCM\] \[JCUS\] \[E3\] \[RAR\] \[T1\] List of Threats

[![\[BCM\] \[JCU\] \[Full Banner\] Business Continuity Management Implementation at JCU Singapore](https://no-cache.hubspot.com/cta/default/3893111/c28ce2ee-dfaa-4e23-b28a-6ae8ca285f06.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c28ce2ee-dfaa-4e23-b28a-6ae8ca285f06)

Risk Analysis and Review is an important component of Business Continuity Management because it establishes the disruption scenarios the organisation should understand before deciding how to assess or treat those risks.

For James Cook University Singapore (JCUS), threat identification should extend beyond obvious emergencies such as fire, flood or power failure.

The University's ability to deliver teaching, examinations, student administration, student support and research depends on an interconnected environment of people, campus facilities, information, ICT, learning platforms, utilities, telecommunications, transport and external service providers.

JCUS operates from its Sims Drive campus, which contains teaching and seminar rooms, library and study facilities, computer laboratories and specialist teaching and research facilities.

The campus is also accessible through nearby MRT stations and multiple bus services.

These characteristics create dependencies on physical access, transport, utilities, ICT and specialist resources.

[![Banner \[BCM\] \[E3\] \[RAR\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/65957ea5-03c3-451d-aabe-bbf23d32c897.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/65957ea5-03c3-451d-aabe-bbf23d32c897)

[Dr Goh Moh Heng](https://blog.bcm-institute.org/ebook/author/dr-goh-moh-heng) Oct 2, 2026

###### Business Continuity Management Certified Planner-Specialist-Expert

### [![x \[BCM\] \[JCU\] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/e57030e6-3c63-46cc-988b-1eabb945de75.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e57030e6-3c63-46cc-988b-1eabb945de75)

[![Part 1: RAR - List of Threats](https://no-cache.hubspot.com/cta/default/3893111/a40e6a2e-edd1-47f8-8caa-b6655d20e294.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a40e6a2e-edd1-47f8-8caa-b6655d20e294)

#### List of Threats**[![Banner \[BCM\] \[E3\] \[RAR\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/65957ea5-03c3-451d-aabe-bbf23d32c897.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/65957ea5-03c3-451d-aabe-bbf23d32c897)**

 

### RAR Part 1: List of Threats for James Cook University

#### Introduction

[![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/de614923-e16d-4c4b-878e-60b97f56183f.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/de614923-e16d-4c4b-878e-60b97f56183f)Risk Analysis and Review is an important component of Business Continuity Management because it establishes the disruption scenarios the organisation should understand before deciding how to assess or treat those risks.

For James Cook University Singapore (JCUS), threat identification should extend beyond obvious emergencies such as fire, flood or power failure.

The University's ability to deliver teaching, examinations, student administration, student support and research depends on an interconnected environment of people, campus facilities, information, ICT, learning platforms, utilities, telecommunications, transport and external service providers.

JCUS operates from its Sims Drive campus, which contains teaching and seminar rooms, library and study facilities, computer laboratories and specialist teaching and research facilities.

The campus is also accessible through nearby MRT stations and multiple bus services.<https://www.jcu.edu.sg/_media/documents/about-us/01_26-Student-Handbook_English_edited-bookmark.pdf?utm_source=chatgpt.com>

These characteristics create dependencies on physical access, transport, utilities, ICT and specialist resources.

 

#### **Threat, Vulnerability and Risk**

Distinguish these concepts during the assessment.

A **threat** is a potential source or event that can cause disruption. A ransomware attack, fire, flood or telecommunications failure is therefore a threat.

A **vulnerability** is a weakness, exposure or dependency that allows the consequences of the threat to materialise or become more severe. Examples could include dependence on a single application, insufficient alternative teaching space, concentration of specialist knowledge in one employee or reliance on one external provider.

**Risk** arises when a credible threat interacts with the organisation's exposure and vulnerabilities and produces consequences affecting organisational objectives.

This chapter deliberately concentrates on the **threat-identification stage**. It does not assign likelihood, impact, risk scores or risk-treatment measures. Those assessments should follow after the threat universe has been established.

#### **Country-Level and Organisation-Level Threats**

Both perspectives are required.

Country-level analysis identifies threats arising from Singapore's physical, environmental, technological, infrastructure and operating environment.

Organisation-level analysis then determines how the same threat could manifest itself within JCUS.

For example, transboundary haze is a recurring environmental concern for Singapore.

NEA states that Singapore experiences smoke haze periodically from regional forest fires, particularly when meteorological conditions carry smoke towards Singapore.

As of 29 September 2026, Singapore's 24-hour PSI was in the Unhealthy range, illustrating the continuing relevance of this threat. [National Environment Agency](https://www.nea.gov.sg/our-services/pollution-control/air-pollution/managing-haze?utm_source=chatgpt.com)

Cyber threats similarly require significant attention.

CSA's 2025/2026 assessment describes a threat environment of increasing complexity, speed, scale and sophistication, including greater use of AI and supply-chain interdependencies; reported ransomware cases increased from 159 in 2024 to 165 in 2025.<https://www.csa.gov.sg/resources/publications/singapore-cyber-landscape-2025-2026/?utm_source=chatgpt.com>

The resulting Threat Register becomes an input to the subsequent Risk Assessment, BIA, Business Continuity Strategy, crisis-management arrangements and continuity-plan development.

 

### **Threat Register**

##### **Table RAR P1: List of Threats for James Cook University**

 

#### **Category 1 — Denial of Access: Natural Disaster**

 

| Types of Threats | Description of Threat | Country-Level Relevance | Organisation-Level Relevance |
| --- | --- | --- | --- |
| Flood | Sustained rainfall or drainage overflow could inundate roads, buildings or surrounding areas and restrict safe access. | Occasional and credible. Singapore's tropical climate and intense rainfall make localised flooding a recognised national disruption scenario. | Flooding affecting Sims Drive or surrounding routes could prevent students and staff from reaching campus, damage facilities and interrupt scheduled teaching, examinations and campus services. |
| Flash Flood | Intense rainfall over a short period can rapidly inundate roads and low-lying locations with limited warning. | Credible and periodically encountered. Singapore maintains public flash-flood and water-level alerts. [National Environment Agency](https://www.nea.gov.sg/myenv?utm_source=chatgpt.com) | A flash flood near Sims Drive or connecting roads could delay staff and students, disrupt examinations and prevent deliveries or emergency access. |
| Severe Thunderstorm | Heavy rain, strong winds and lightning can make travel or outdoor movement unsafe and cause secondary infrastructure disruption. | Common weather exposure in Singapore's tropical environment. | Could disrupt campus access, outdoor activities, facilities and journeys by staff and students and potentially affect power or communications. |
| Lightning | Lightning can create personal-safety risks and cause electrical or telecommunications disruption. | Recurring environmental hazard. Singapore's environmental alert systems include lightning information. [National Environment Agency](https://www.nea.gov.sg/myenv?utm_source=chatgpt.com) | Could restrict outdoor movement, affect campus electrical equipment or networks and interrupt teaching or specialist activities. |
| Extreme Heat | Sustained unusually high temperatures can affect health, equipment performance and safe outdoor activity. | Increasing climate concern. Warmer conditions occur particularly during El Niño periods; MSS forecast warmer and drier conditions in 2026. [National Environment Agency](https://www.nea.gov.sg/media/news/news/index/el-ni%C3%B1o-conditions-expected-in-second-half-of-2026--with-warmer-and-drier-weather-in-the-coming-months?utm_source=chatgpt.com) | Could affect staff and student welfare, outdoor activities, cooling demand, laboratories and facilities dependent on temperature control. |
| Haze | Smoke from regional vegetation and peat fires can cause unhealthy air quality and constrain outdoor activities. | Occasional but significant. Transboundary haze periodically affects Singapore; the risk increases under certain dry-season and wind conditions. <https://www.nea.gov.sg/our-services/pollution-control/air-pollution/faqs?utm_source=chatgpt.com> | Could affect student and employee health, campus activities, attendance, sporting activities and staff or students with respiratory vulnerabilities. |
| Earthquake / Regional Seismic Event | A major regional earthquake may generate tremors in Singapore or indirectly disrupt regional infrastructure and supply chains. | Low direct occurrence but credible regional exposure. Singapore monitors regional seismic activity through a national seismograph network. | Strong regional tremors could prompt evacuation or inspection of campus facilities and disrupt operations even without structural damage. |
| Tsunami | Large undersea seismic or volcanic events can generate regional tsunami waves. | Low historical occurrence. Singapore is relatively sheltered by surrounding landmasses and shallow seas, although it maintains a national warning capability. | Direct impact on Sims Drive is unlikely, but a major regional event could affect transport, suppliers, personnel and regional university activities. |
| Landslide / Ground Movement | Saturated soil, construction activity or ground instability can affect roads, slopes or structures. | Relatively uncommon, but localised ground instability remains physically possible in a highly developed urban environment. | Could block access routes or require precautionary closure of affected campus areas pending engineering assessment. |
| Sinkhole / Ground Subsidence | Underground infrastructure failure, soil movement or construction-related ground loss can create sudden surface collapse. | Infrequent but credible as a localised urban infrastructure event. | A sinkhole affecting campus grounds or nearby roads could restrict access and require evacuation or building inspections. |
| Wildfire / Vegetation Fire | Dry conditions may allow vegetation fires to create smoke, local safety hazards or access restrictions. | Low direct national exposure compared with regional countries; regional fires remain relevant through haze. | A nearby vegetation fire could cause smoke intrusion or temporary access restrictions; regional fires principally affect JCUS through haze. |
| Volcanic Ash | Major eruptions in the wider region may disperse ash into aviation routes or, in exceptional circumstances, affect air quality. | Low direct occurrence but credible regional dependency threat because Singapore is an international transport hub near volcanically active parts of Southeast Asia. | Could affect international staff or student travel, visiting academics, overseas programmes and supply chains even if the campus itself remains accessible. |
| Pandemic-related Movement Restrictions | A severe communicable-disease emergency could lead authorities or institutions to restrict movement, gatherings or physical attendance. | Credible based on prior national experience with large-scale infectious-disease controls. | Could require JCUS to restrict campus attendance and shift teaching, administration and student support to alternative delivery models. |

 

#### **Category 2 — Denial of Access: Man-made Disaster**

 

| Types of Threats | Description of Threat | Country-Level Relevance | Organisation-Level Relevance |
| --- | --- | --- | --- |
| Fire | Fire may originate from electrical faults, equipment, human activity or adjacent premises and make buildings unsafe. | Credible urban emergency despite strong national fire-safety controls. | Could require evacuation and prolonged closure of teaching rooms, laboratories, offices, library areas or an entire campus block. |
| Explosion | Gas, electrical, industrial or malicious incidents may produce blast damage and exclusion zones. | Infrequent but credible within a dense urban environment. | Could cause casualties, structural damage and campus closure, and prevent access until authorities complete investigations. |
| Chemical Spill | Hazardous substances released on campus, during transport or from nearby activities may require isolation or evacuation. | Credible but infrequent, given Singapore's industrial and transport activity. | A spill affecting a laboratory or nearby location could close teaching or research areas and restrict movement. |
| Gas Leak | Leakage from gas systems, cylinders or neighbouring infrastructure may create fire, explosion or inhalation hazards. | Credible localised emergency. | Could trigger evacuation of affected buildings and interrupt classes, laboratories and campus services. |
| Structural Failure | Building component failure may arise from defects, deterioration, impact, construction activity, or other physical causes. | Low-frequency but credible built-environment threat. | Could require immediate evacuation and closure of a campus block pending engineering inspection. |
| Building Collapse | Severe structural failure could render premises completely inaccessible. | Low historical occurrence but potentially severe. | Could result in prolonged loss of facilities, casualties and major relocation requirements. |
| Civil Disturbance / Public Disorder | Demonstrations, disorder or police operations can create safety concerns and restrict access to affected areas. | Low historical occurrence but credible. | Disorder near the campus or transport routes could restrict staff and student access and require cancelling or relocating activities. |
| Terrorism | An attack or credible security incident could cause casualties, infrastructure damage and security cordons. | Credible but infrequent national security threat. | JCUS could experience evacuation, lockdown, access restrictions, trauma and prolonged interruption to campus activities. |
| Bomb Threat / Suspicious Item | A threat or suspicious object may require evacuation and police investigation even if no explosive device is ultimately found. | Credible security scenario. | Could interrupt examinations or classes and deny access to part or all of the campus for several hours or longer. |
| Sabotage | Deliberate damage to facilities, utilities, equipment or technology may make premises or services unusable. | Credible insider or external security threat. | Could affect laboratories, ICT, utilities or access-control systems and interrupt critical university functions. |
| Active Assailant / Workplace Violence | A violent individual may create an immediate life-safety emergency requiring lockdown or evacuation. | Low occurrence but credible high-consequence security scenario. | Could trigger campus lockdown, casualties, trauma and suspension of teaching and student services. |
| Utility Failure Affecting Access | Electrical, water or building-system failure may render premises unsafe or unsuitable for occupation. | Occasional localised infrastructure disruption remains credible despite generally resilient Singapore utilities. | Loss of lighting, lifts, cooling, sanitation or safety systems could force partial or complete campus closure. |
| Road Closure | Emergency works, accidents, security incidents or infrastructure failures can close roads. | Occasional in a dense transport environment. | Closure of Sims Drive or connecting roads could delay staff, students, deliveries and emergency services. |
| Public Transport Disruption | MRT or bus service interruption can prevent or delay large numbers of commuters from reaching their destination. | Credible occasional infrastructure disruption. | JCUS identifies Aljunied and Kallang MRT stations and multiple bus services as campus transport options, making transport availability relevant to attendance.<https://www.jcu.edu.sg/current-students/campus-maps-And-information?utm_source=chatgpt.com> |
| Major Traffic Incident | A serious collision or hazardous-material incident may close surrounding roads. | Credible urban disruption. | Could impede access to Sims Drive, affect examinations and classes and delay emergency response. |
| Aircraft Accident | An aviation incident could produce wider emergency restrictions, casualties or transport disruption. | Low occurrence but credible given Singapore's role as an aviation hub. | Direct campus impact is unlikely, but a major incident could affect travel, international students, visiting academics and transport networks. |
| Nearby Industrial / Construction Accident | A fire, explosion, crane incident, hazardous release, or major works accident at neighbouring premises could establish an exclusion zone. | Credible localised threat within a densely developed city. | Could restrict Sims Drive access or require precautionary campus evacuation even when JCUS facilities are undamaged. |

 

#### **Category 3 — Unavailability of People**

 

| Types of Threats | Description of Threat | Country-Level Relevance | Organisation-Level Relevance |
| --- | --- | --- | --- |
| Pandemic | Widespread infectious disease may cause prolonged workforce absence and restrictions on gatherings or movement. | Credible national preparedness scenario following COVID-19 experience. | Could reduce academic and support staffing while simultaneously increasing demand for remote teaching and student support. |
| Epidemic / Infectious Disease Outbreak | Local or regional transmission may cause illness clusters and precautionary absences. | Recurring public-health consideration in a highly connected international city. | A campus cluster could affect lecturers, students and support staff and disrupt face-to-face teaching. |
| Mass Illness / Foodborne Illness | Contaminated food, environmental exposure or communicable illness may affect many people simultaneously. | Credible localised public-health event. | Could create sudden staff shortages, student welfare demands and cancellation of classes or events. |
| Labour Strike / Industrial Action | Industrial action affecting the organisation or critical external services may reduce workforce or service availability. | Relatively uncommon domestically, but industrial action overseas may affect international services and suppliers. | Direct staff action could reduce operational capacity; transport or supplier industrial action could indirectly affect JCUS. |
| High Staff Turnover | Sustained departures can erode institutional knowledge and reduce available capacity. | Credible workforce-management issue in a competitive labour market. | Could affect academic programmes, specialist administration, ICT or other areas requiring experienced personnel. |
| Loss of Key Personnel | Sudden illness, resignation, death or extended absence removes specialist knowledge or authority. | Universally credible organisational threat. | Could affect specialist teaching, academic approvals, examinations, ICT administration or crisis decision-making where knowledge is concentrated. |
| Skills Shortage | Difficulty obtaining specialised academic, technical or professional expertise can constrain operations. | Credible in specialist and technology occupations. | Could impair delivery of specialised programmes, laboratory activities, cybersecurity, ICT or regulatory functions. |
| Industrial / Workplace Accident | Serious injury can remove key employees and require investigation or area closure. | Credible occupational safety threat. | Could affect specialist staff and disrupt laboratories, facilities or other operational areas. |
| Workplace Violence | Threats or violence may injure personnel and create psychological or physical absence. | Low occurrence but credible. | Could affect employee availability and require closure or security intervention. |
| Staff Fatigue | Extended incident response, peak academic workload or prolonged disruption can reduce workforce effectiveness. | Credible during prolonged emergencies. | BCM, ICT, academic and student-support teams may experience reduced decision quality and capacity during sustained operations. |
| Psychological Stress | Crisis exposure, traumatic incidents or sustained workload can affect staff availability and performance. | Credible people-resilience concern. | Could reduce the University's capacity to sustain extended response and recovery, particularly after a serious campus incident. |
| Travel Restrictions | Border controls, aviation disruption or public-health controls can prevent travel. | Credible for internationally connected Singapore. | Could affect international students, academic staff, visiting faculty and cross-campus activities. |
| Mandatory Quarantine / Isolation | Public-health requirements may prevent affected people from attending campus. | Credible during infectious-disease outbreaks. | Could simultaneously remove groups of lecturers, students or operational staff from physical duties. |
| Family or Caregiving Emergencies | A widespread event may require employees to remain home to care for family members. | A credible secondary effect of public-health, school-closure, or community emergencies. | Staff may be physically well but unavailable, reducing academic and administrative capacity. |
| Mass Resignation / Concentrated Attrition | Multiple departures from one specialist team can remove operational knowledge faster than it can be replaced. | Credible organisational workforce threat. | Particularly relevant where a small team supports specialist academic, ICT, regulatory or laboratory functions. |

 

#### **Category 4 — Disruption to the Supply Chain**

 

| Types of Threats | Description of Threat | Country-Level Relevance | Organisation-Level Relevance |
| --- | --- | --- | --- |
| Supplier Failure | A provider may be unable to deliver contracted goods or services because of operational, financial or technical problems. | Credible across Singapore's outsourced and service-dependent economy. | Could interrupt campus services, technology, teaching resources, maintenance or specialist support. |
| Outsourcing Failure | An outsourced process may become unavailable or perform below required service levels. | Credible where organisations rely on specialised service providers. | Could affect administrative, technology, facilities or student-facing activities depending on the outsourced service. |
| Cloud Service Provider Failure | Provider infrastructure or control-plane failure can make cloud-hosted applications unavailable. | This is an increasing concern because of widespread cloud adoption and digital interdependence. | Could affect learning systems, collaboration, identity, records or administrative applications simultaneously. |
| Telecommunications Provider Failure | Fixed, mobile or data services may become unavailable. | Credible national infrastructure disruption, despite Singapore's mature telecommunications environment. | Could prevent online teaching, authentication, communications and remote work. |
| Electricity Utility Failure | Grid or local distribution failure may interrupt electricity supply. | Infrequent but credible critical-infrastructure dependency. | Could affect campus access, cooling, ICT, laboratories, teaching spaces and safety systems. |
| Water Supply Failure | Water interruption or contamination can render buildings unsuitable for normal occupation. | Credible local infrastructure event. | Extended water loss could affect sanitation, laboratories and campus occupancy. |
| Fuel Supply Disruption | Regional logistics or geopolitical events may constrain fuel availability and transportation. | Credible external dependency for an import-dependent economy. | Could indirectly affect transport, suppliers, emergency logistics and service costs. |
| Logistics Disruption | Port, freight, warehouse or courier interruption can delay goods and equipment. | Credible because Singapore is deeply integrated into international supply chains. | Could delay laboratory supplies, IT hardware, teaching equipment and replacement parts. |
| Transportation Failure | Disruption to road, air or public transport can delay people and materials. | Credible cross-sector dependency. | Could reduce campus attendance and interrupt international academic travel or delivery of essential goods. |
| Banking System Failure | A banking-service outage can interrupt transfers, payroll, or supplier payments. | Credible technology-dependent financial-sector scenario. | Could delay payments, refunds, supplier transactions or other university financial operations. |
| Payment System Failure | Card, online or payment-gateway outages may prevent transactions. | Credible in a highly digital payments environment. | Could affect fee payments and other financial transactions involving students or suppliers. |
| Regulatory Restriction | New emergency controls or regulatory directions may constrain normal activities or suppliers. | Credible during public-health, security or other national emergencies. | Could require JCUS to alter campus operations, teaching arrangements or third-party services quickly. |
| Import Restriction | Trade controls, border disruption or export restrictions may delay specialist equipment or materials. | Credible external dependency for Singapore. | Could particularly affect laboratories, research consumables, specialist equipment and IT hardware. |
| Vendor Insolvency | A provider's financial failure may abruptly terminate a critical service. | Credible commercial threat. | Could remove access to specialised software, cloud services, maintenance or other contracted capabilities. |
| Third-Party Cyber Incident | A supplier compromised by ransomware, data theft or another cyberattack may stop providing services or expose connected customers. | Increasing concern. CSA highlights modern supply-chain interdependencies as an important feature of the current cyber landscape. | Could disrupt JCUS services even when its own systems are uncompromised, or expose data and credentials through trusted connections. |
| Contract Termination | A critical provider may terminate or fail to renew a service unexpectedly. | Credible contractual dependency. | Could require urgent replacement of software, facilities, specialist services or other critical capabilities. |
| Single-Source Dependency | Reliance on one supplier creates concentration exposure if that provider becomes unavailable. | Credible operational-resilience concern. | A unique technology, laboratory supplier or specialist provider could become a single point of failure for a JCUS function. |
| Regional Geopolitical / Trade Disruption | Conflict, sanctions or trade disruption can affect regional transport, technology and supply availability. | Credible external threat for a trade-dependent international hub. | Could affect international students and staff, travel, technology procurement, research materials and supplier lead times. |

 

#### **Category 5 — Equipment and IT-Related Disruption**

JCUS's dependence on technology makes this category particularly important.

The University's own information identifies ICT support for LearnJCU, classroom software and other student technology services.

At national level, CSA reports that Singapore's cyber environment is becoming more complex and that ransomware, infected systems and AI-enabled attacks remain material concerns. 

 

| Types of Threats | Description of Threat | Country-Level Relevance | Organisation-Level Relevance |
| --- | --- | --- | --- |
| Cyberattack | Deliberate compromise of systems, networks, accounts or information may cause loss of availability, integrity or confidentiality. | Increasing concern within Singapore's highly digital economy. | Could disrupt teaching, assessment, student administration, communications and institutional management. |
| Ransomware | Malware encrypts systems or data and may combine operational disruption with data theft and extortion. | Significant current threat. CSA recorded 165 reported ransomware cases in 2025. | It could simultaneously disable academic systems, file services, and administration, creating uncertainty about data integrity. |
| Malware | Malicious software may steal information, corrupt devices or provide persistent unauthorised access. | Common cyber threat. CSA reports substantial infected infrastructure and Malware-as-a-Service activity. | Could compromise endpoints, staff credentials, student systems and network services. |
| DDoS Attack | Large volumes of malicious traffic overwhelm internet-facing services or network capacity. | Credible cyber disruption scenario recognised in CSA incident-response guidance. <https://www.csa.gov.sg/resources/singcert/incident-response-playbooks/?utm_source=chatgpt.com> | Could prevent access to websites, portals, learning platforms or other internet-facing JCUS services. |
| Insider Threat | Authorised users may deliberately or inadvertently misuse privileged access. | Credible across digitally dependent organisations. | Could affect student records, examination material, systems or sensitive institutional information. |
| Data Breach | Unauthorised disclosure or extraction of personal, academic, research or institutional information occurs. | Credible national cyber and privacy threat. | Could affect students and employees, trigger regulatory obligations and undermine stakeholder confidence. |
| Network Failure | Switches, routers, configuration errors or infrastructure faults interrupt internal connectivity. | Credible technology failure. | Could make learning platforms, laboratories, administration and internet services unavailable on campus. |
| Server Failure | Physical or virtual server failure makes hosted applications or data unavailable. | Routine technology failure mode. | Could interrupt applications supporting teaching, administration or specialist university services. |
| Database Corruption | Software defects, storage faults, cyberattack or human error may damage database integrity. | Credible information-system threat. | Student records or academic results may remain technically accessible but cannot safely be trusted for decisions. |
| Cloud Service Outage | Failure of externally hosted infrastructure or SaaS services causes widespread application unavailability. | Emerging concentration and interdependency concern. | Could interrupt digital learning, collaboration, storage or administrative systems with limited direct JCUS control over restoration. |
| Power Failure | Loss of electricity stops ICT equipment and building systems where backup power is insufficient. | Infrequent but credible infrastructure event. | Could disrupt servers, networks, laboratories, classrooms, cooling and physical campus operation. |
| Hardware Failure | Storage, network, endpoint or specialist equipment fails because of a defect or wear. | Common technology failure mode. | Failure of specialised laboratory or teaching equipment could interrupt functions even where general ICT remains operational. |
| Software Failure | Application defects, failed updates or configuration errors make software unusable. | Common digital-operational threat. | Could interrupt learning, assessment, student administration or finance depending on the application affected. |
| Failed Technology Change | An upgrade, patch, migration, or configuration change unintentionally causes service failure. | Credible operational technology risk in highly digital organisations. | Could create sudden outages across interconnected JCUS systems, particularly where shared infrastructure is affected. |
| Telecommunications Failure | Fixed voice, data or mobile services become unavailable. | Credible critical-infrastructure dependency. | Could affect online learning, staff coordination, student communication and remote working. |
| Internet Failure | ISP, routing, DNS or infrastructure failure prevents internet connectivity. | Credible despite mature national connectivity. | Could prevent access to cloud applications, LearnJCU and external digital resources. |
| Loss of Mobile Communications | Cellular network interruption reduces voice, messaging or mobile-data availability. | Credible infrastructure disruption. | Could impair crisis communication and coordination with students and employees. |
| Backup Failure | Backups may be incomplete, corrupted, inaccessible or unusable when restoration is required. | Credible technology resilience threat. | Could substantially prolong recovery from ransomware, corruption or system failure and cause permanent information loss. |
| Data Centre Failure | Power, cooling, fire, network or facility failure affects hosted computing infrastructure. | Credible concentration threat. | Could make multiple JCUS applications unavailable simultaneously if they share infrastructure dependencies. |
| Authentication System Failure | Authentication service failures prevent otherwise functioning systems from being accessed. | This dependency is increasingly important as digital services centralise identity controls. | Students and staff could lose simultaneous access to learning, email, cloud and administrative services. |
| Identity Management Failure | Directory, federation, MFA or account-management services fail or become corrupted. | Credible digital concentration risk. | Could cause widespread inability to access JCUS services or prevent secure provisioning and revocation of access. |
| Artificial Intelligence System Failure | AI-supported tools may become unavailable, generate unreliable outputs or depend on unavailable external services. | Emerging threat as AI adoption expands. CSA reports AI is reshaping cyber threats and increasing their speed and sophistication. | If JCUS adopts AI-dependent academic or administrative processes, failures could interrupt workflows or produce unreliable information that requires manual validation. |
| AI-Enabled Cyberattack | Threat actors use AI to accelerate reconnaissance, social engineering, malware development or attack automation. | Emerging and increasing concern. CSA identifies AI-enabled attacks and agentic AI as changing the national threat environment. <https://www.csa.gov.sg/news-events/press-releases/csa-s-initiatives-to-strengthen-singapore-s-cyber-defences-amid-an-ai-driven-threat-landscape/?utm_source=chatgpt.com> | Could increase phishing, credential compromise and attack speed against staff, students and institutional systems. |
| Compromised Software / Supply-Chain Attack | Malicious code or compromised updates enter through trusted technology providers. | This concern is increasing given modern technology supply-chain interdependencies. | Could compromise multiple JCUS systems through software that would ordinarily be considered trusted. |
| Data Integrity Failure | Information is altered, duplicated, lost or incorrectly processed without necessarily becoming unavailable. | Credible operational and cyber threat. | Incorrect student records, grades or enrolment information could disrupt academic decisions even while systems remain online. |
| Storage Capacity Exhaustion | Storage, database or logging capacity reaches operational limits and prevents normal processing. | Credible technical failure mode. | Could stop applications, backups, research-data capture or student administration processes. |
| Specialist Laboratory Equipment Failure | Critical research or teaching equipment becomes unavailable due to a technical breakdown. | Organisation-specific equipment threat rather than broad national hazard. | JCUS has specialist teaching and research facilities; equipment failure could interrupt practical teaching, experiments or research activities.<https://www.jcu.edu.sg/_media/documents/about-us/01_26-Student-Handbook_English_edited-bookmark.pdf?utm_source=chatgpt.com> |
| Cyber-Physical / Building Management System Failure | Compromise or malfunction of digitally controlled building systems can affect access, cooling, security, or utilities. | Emerging operational-resilience threat as physical infrastructure becomes more digitally connected. | This could make campus areas unusable even when academic applications remain operational. |

 

#### **Cross-Cutting Threat Considerations**

The register demonstrates that threats should not be assessed in isolation. A single initiating event may generate multiple secondary disruptions.

For example, a severe storm may initially be classified as a natural hazard, but its consequences could include transport disruption, power failure, telecommunications interruption and staff unavailability.

Similarly, ransomware may begin as an ICT event but subsequently affect:

- teaching and learning;
- examinations and assessment;
- student records;
- financial administration;
- regulatory obligations;
- stakeholder communications;
- third-party connectivity; and
- institutional confidence.

The subsequent Risk Assessment should therefore evaluate both the **initiating threat** and the **credible disruption consequences** it can produce.

This is especially important for JCUS because its physical and digital environments are interdependent.

The campus includes teaching facilities, computer laboratories, library resources and specialist facilities, while academic and student-support activities also depend upon ICT and learning technologies. [James Cook University Singapore](https://www.jcu.edu.sg/current-students/campus-maps-And-information/campus-operating-hours?utm_source=chatgpt.com)

 

#### **Linking the Threat Register to JCUS Critical Business Functions**

The Threat Register should subsequently be mapped against the University's identified CBFs rather than assessed solely at enterprise level.

For example:

 

| Threat | Illustrative CBF Exposure |
| --- | --- |
| Campus fire | CBF-1 Teaching and Learning; CBF-2 Examinations; CBF-7 Student Safety; CBF-8 Campus Safety |
| Ransomware | CBF-2 Examinations; CBF-3 Student Administration; CBF-4 Student Records; CBF-5 Digital Learning; CBF-6 ICT |
| Pandemic | CBF-1 Teaching; CBF-7 Student Support; CBF-9 Admissions; CBF-12 Communications |
| Cloud outage | CBF-1 Teaching; CBF-5 Digital Learning; CBF-6 ICT; CBF-13 Academic Information Resources |
| Public transport disruption | CBF-1 Teaching; CBF-2 Examinations; CBF-7 Student Support |
| Haze | CBF-1 Teaching; CBF-7 Student Welfare; CBF-8 Campus Operations |
| Data corruption | CBF-2 Assessment; CBF-3 Progression; CBF-4 Student Records |
| Supplier cyber incident | CBF-5 Digital Platforms; CBF-6 ICT and any other CBF dependent on the affected provider |
| Specialist equipment failure | CBF-1 Teaching; CBF-14 Research and Specialist Laboratory Operations |

This mapping should not yet determine whether one threat is more serious than another.

Its purpose is to establish **where disruption could occur**, so that the subsequent assessment can examine the relevant exposure systematically.

 

#### **Maintaining the JCUS Threat Register**

Treat the Threat Register as a living BCM and risk-management record, not a one-time workshop output.

JCUS should review it when there are material changes involving:

- campus facilities or locations;
- new academic programmes;
- learning-delivery models;
- critical ICT platforms;
- cloud adoption;
- cybersecurity threats;
- significant suppliers;
- regulatory requirements;
- specialist research activities;
- student demographics or delivery arrangements;
- regional geopolitical conditions;
- public-health conditions; or
- climate and environmental threats.

The cyber portion requires particularly frequent review because the national threat environment is changing rapidly.

CSA's June 2026 assessment highlights AI-enabled attacks, ransomware, infected infrastructure and supply-chain interdependencies among current developments.

Environmental conditions should likewise be monitored.

For example, NEA's September 2026 advisory reported Unhealthy PSI conditions as smoke from Kalimantan and southern Sumatra affected Singapore, demonstrating why haze should remain an active JCUS continuity scenario rather than merely a historical entry. 

 

[![Banner \[Table\] \[BCM\] \[E3\] \[RAR\] \[Summing Up\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/d4dc8faf-623d-4f0d-acf8-26776beec0f4.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d4dc8faf-623d-4f0d-acf8-26776beec0f4)

A comprehensive Threat Register provides James Cook University Singapore with a structured view of the events and conditions that could disrupt its Critical Business Functions, supporting resources, and stakeholder obligations.

The register should encompass more than conventional emergency scenarios.

Fire, flood and infectious disease remain important, but JCUS must also consider technology concentration, ransomware, cloud-service failure, identity-system disruption, third-party cyber incidents, supply-chain dependencies, data-integrity failures and emerging AI-related threats.

Threat identification is deliberately separated from risk evaluation.

At this stage, the objective is to ensure that credible sources of disruption are recognised without prematurely determining which threats are more likely, more severe or more deserving of treatment.

The Threat Register then informs several parts of the BCM lifecycle.

During the **Risk Assessment**, JCUS can analyse each threat against relevant vulnerabilities and existing controls. During the **Business Impact Analysis**, JCUS can determine the consequences of disruption to individual CBFs over time.

During **Business Continuity Strategy development**, the University can determine how priority activities should continue when the people, premises, technology, information, or suppliers it depends on are unavailable.

The register also provides realistic scenarios for crisis-management and continuity exercises.

Regular review is essential. JCUS's threat environment will change as technology, academic delivery, facilities, suppliers, regulation and the wider Singapore operating environment evolve.

Cyber threats, climate-related events and increasingly interconnected supply chains deserve particular attention because changes can occur rapidly and may create new concentrations of dependency.

A well-maintained Threat Register therefore strengthens preparedness and organisational resilience by giving management a common, systematic view of potential disruption.

**Identifying threats is the first step in protecting JCUS's critical services. The subsequent Risk Assessment should evaluate the likelihood and impact of these threats and determine the appropriate treatment and control requirements.**

 

[![BL-OR-3-5 Blog Under Construction](https://no-cache.hubspot.com/cta/default/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066)

 

[![\[BCM\] \[JCU\] \[3/4 Banner\] Business Continuity Management Implementation at JCU Singapore](https://no-cache.hubspot.com/cta/default/3893111/d81098d9-9f30-4c17-a897-2fc202440adc.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d81098d9-9f30-4c17-a897-2fc202440adc)

| **eBook 3: Starting Your BCM Implementation** |  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- | --- |
| **MBCO** | **P&S** | **RAR T1** | **RAR T2** | **RAR T3** | **BCS T1** | **CBF** |
| [![\[BCM\] \[JCU\] \[E3\] \[BIA\] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/37db16b1-9a61-4815-adbb-527771b7bd35.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/37db16b1-9a61-4815-adbb-527771b7bd35) | [![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[PS\] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/3117a3bf-33fd-4522-a373-4ce343e253a6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3117a3bf-33fd-4522-a373-4ce343e253a6) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/de614923-e16d-4c4b-878e-60b97f56183f.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/de614923-e16d-4c4b-878e-60b97f56183f) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/71606f66-523b-41e0-af99-19f5e4cc2f37.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/71606f66-523b-41e0-af99-19f5e4cc2f37) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/0192071d-0c49-4a20-a2a8-f0894418f873.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/0192071d-0c49-4a20-a2a8-f0894418f873) | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T1\] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/12b9c723-7ba3-4523-a1c2-0e75dc09a4e3.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/12b9c723-7ba3-4523-a1c2-0e75dc09a4e3) | [![\[BCM\] \[JCU\] \[E1\] \[C10\] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/b7aaf4cf-e4f4-4e31-bb8f-6885a5f2203d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b7aaf4cf-e4f4-4e31-bb8f-6885a5f2203d) |
| **CBF-1 Teaching and Learning Delivery** |  |  |  |  |  |  |
| **DP** | **BIAQ P1** | **BIAQ P2** | **BIAQ P3** | **BIAQ P4** | **BIAQ P5** | **BIAQ P6** |
| [![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[DP\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/87dc20a3-b9ed-454a-90ee-2ca3e2419322.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/87dc20a3-b9ed-454a-90ee-2ca3e2419322) | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T1\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/c0d85e4b-2df7-44ee-9c25-4112e99a64f3.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c0d85e4b-2df7-44ee-9c25-4112e99a64f3)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T2\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/3d5d03b2-0465-4e70-8920-efbaf80a835c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3d5d03b2-0465-4e70-8920-efbaf80a835c)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T3\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/4107cc4d-b5ca-486c-bca0-d2a049b8c752.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/4107cc4d-b5ca-486c-bca0-d2a049b8c752)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T4\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/e9bd80ac-aa4d-4da0-873e-92bb036ae9c9.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e9bd80ac-aa4d-4da0-873e-92bb036ae9c9)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T5\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/7c619369-8c50-4876-a478-749b847adee0.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7c619369-8c50-4876-a478-749b847adee0)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T6\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/bdb520b6-bc53-40cf-bc72-5e4eb5c2d1ae.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/bdb520b6-bc53-40cf-bc72-5e4eb5c2d1ae)** |
|  |  | **BCS T2** | **BCS T3** | **PD** |  |  |
|  |  | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T2\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/10a04273-213c-4b93-a69a-966039c382bb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/10a04273-213c-4b93-a69a-966039c382bb) | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T3\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/d2ec73f8-a65d-473f-9a70-afa20ac0b990.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d2ec73f8-a65d-473f-9a70-afa20ac0b990) | [![\[BCM\] \[JCU\] \[E3\] \[PD\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/41fe68b0-13dc-4690-bd61-369c6da03192.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/41fe68b0-13dc-4690-bd61-369c6da03192) |  | **[![\[BCM\] \[JCU\] \[E3\] \[C1\] Starting Your BCM Implementation](https://no-cache.hubspot.com/cta/default/3893111/bbb4751f-aa43-4476-a745-a1d42c6602cb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/bbb4751f-aa43-4476-a745-a1d42c6602cb)** |
|  |  |  |  |  |  |  |

 

#### More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer \[BCM-3\] and the BCM-5000 Business Continuity Management Expert Implementer \[BCM-5\].

| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/f3922b80-e96a-46d6-8993-dc150a5de2d5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/f3922b80-e96a-46d6-8993-dc150a5de2d5) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/9ff8a3dc-e39a-465b-929f-72e232cdd5fb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/9ff8a3dc-e39a-465b-929f-72e232cdd5fb) | [![Register \[BL-B-3\]\*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076) |
| --- | --- | --- |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/21525c10-4003-4934-95fc-fe218174bc5b.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/21525c10-4003-4934-95fc-fe218174bc5b) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/46460171-c91a-4936-9bb2-8dc5928a0e02.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/46460171-c91a-4936-9bb2-8dc5928a0e02) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/1cb17ac7-50b2-4f88-bc4b-c7444e4b57b5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/1cb17ac7-50b2-4f88-bc4b-c7444e4b57b5) |
| [![FAQ \[BL-B-3\]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae) | Please feel free to send us a note if you have any questions. [![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![ FAQ BL-B-5 BCM-5000](https://no-cache.hubspot.com/cta/default/3893111/9c199ae8-c470-4bb7-9612-73c7a084e94c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/9c199ae8-c470-4bb7-9612-73c7a084e94c) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/8999211a-2c51-4be7-bf49-c393f6c67974.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8999211a-2c51-4be7-bf49-c393f6c67974) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/5c1aa95d-f6dd-4067-a95c-5cc0c32d7ed8.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/5c1aa95d-f6dd-4067-a95c-5cc0c32d7ed8) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/086ab3b9-4d66-4a95-b2f7-1148e9803a9c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/086ab3b9-4d66-4a95-b2f7-1148e9803a9c) |

  

 

#### **Your Comments Here:**

 

### More Posts

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/3893111/839787f4-a4fd-456f-accf-54c947026558.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/839787f4-a4fd-456f-accf-54c947026558)

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Dr Goh Moh Heng",
    "url" : "https://blog.bcm-institute.org/ebook/author/dr-goh-moh-heng"
  },
  "dateModified" : "2026-10-03T13:03:30.535Z",
  "datePublished" : "2026-10-02T13:55:41.000Z",
  "headline" : "[BCM] [JCUS] [E3] [RAR] [T1] List of Threats",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/ebook/bcm-jcus-e3-rar-t1-list-of-threats",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```