For James Cook University Singapore (JCUS), this assessment provides a structured method for determining which threats could most disrupt teaching, academic administration, student services, facilities, technology, and other critical activities.
It also provides a quantitative basis for prioritising risk treatment, Business Continuity Strategies and recovery preparedness.
The BCMpedia RAR Part 3 methodology specifies that threats identified previously should be carried forward into the Risk Impact and Likelihood Assessment.
Each threat is assessed across seven impact areas: Finance, Operations, Legal & Regulatory, Reputation & Image, Social Responsibility, People, and Assets/IT Systems/Information.
The methodology applies a 1-to-5 impact scale, where 1 represents Very Low/Insignificant impact, and 5 represents Very High/Catastrophic impact.
The highest score among the seven impact areas becomes the Risk Impact Area (Highest Numeric Score).
Risk likelihood is similarly rated from 1 (Very Low/Rare) to 5 (Very High/Almost Certain). The overall Risk Rating is calculated as:
The resulting rating is then translated into a Risk Level. BCMpedia specifies 1–5 as Very Low, 6–10 as Low, 11–15 as Medium, 16–20 as High, and 20–25 as Very High.
Because the published ranges overlap at 20, JCUS should resolve that boundary in its approved risk matrix before formally adopting the assessment.
The Expected Period of Disruption represents the estimated residual period during which operations could remain disrupted, or access to the primary location could be denied, after accounting for existing controls.
The numerical assessments below are illustrative planning assumptions, not confirmed JCUS risk ratings.
Validate them through workshops with relevant risk owners and representatives from academic and administrative functions, ICT, facilities, security, compliance, and BCM.
Interpret the seven areas in the JCUS operating context as follows. BCMpedia
|
Impact Area |
Application to JCUS |
|
Finance |
Financial loss, additional operating expenditure, asset damage, recovery expenditure or loss of revenue. |
|
Operations |
Disruption to teaching, academic administration, student services and other day-to-day or critical operations. |
|
Legal & Regulatory |
Potential inability to meet applicable regulatory, statutory or contractual obligations. |
|
Reputation & Image |
Adverse stakeholder perception, student dissatisfaction or adverse public/media attention arising from unavailable or delayed services. |
|
Social Responsibility |
Effects on students, the wider university community and other stakeholders whose needs and expectations may be affected. |
|
People |
Injury, illness, unavailability or other adverse consequences affecting employees and other relevant personnel. |
|
Assets/ IT Systems/ Information |
Effects on buildings, facilities, equipment, utilities, ICT, telecommunications, data and information. |
|
Score |
Rating |
|
1 |
Very Low |
|
2 |
Low |
|
3 |
Medium |
|
4 |
High |
|
5 |
Very High |
|
Score |
Rating |
|
1 |
Very Low / Rare |
|
2 |
Low |
|
3 |
Medium |
|
4 |
High |
|
5 |
Very High / Almost Certain |
These scales follow the BCMpedia RAR Part 3 methodology. BCMpedia
The following threat set carries forward the working threats used in the preceding JCUS RAR Part 2 chapter.
The numerical scores and disruption periods are proposed starting values that JCUS must validate.
|
Threat |
Finance |
Operat-ions |
Legal & Regulatory |
Reputation & Image |
Social Respon-sibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
|
Flood |
3 |
4 |
3 |
3 |
3 |
4 |
4 |
4 |
2 |
8 |
Low |
1–5 days |
|
Severe Storm |
2 |
3 |
2 |
2 |
3 |
3 |
3 |
3 |
3 |
9 |
Low |
4–24 hours |
|
Lightning and Severe Weather |
2 |
3 |
2 |
2 |
2 |
3 |
4 |
4 |
3 |
12 |
Medium |
2–24 hours |
|
Haze or Environmental Hazard |
2 |
3 |
2 |
3 |
3 |
4 |
1 |
4 |
3 |
12 |
Medium |
1–7 days |
|
Fire |
4 |
5 |
4 |
4 |
4 |
5 |
5 |
5 |
2 |
10 |
Low |
3 days–4 weeks |
|
Building Access Restriction |
3 |
4 |
3 |
3 |
3 |
2 |
3 |
4 |
3 |
12 |
Medium |
1–5 days |
|
Utility or Building Services Failure |
3 |
4 |
2 |
3 |
2 |
3 |
4 |
4 |
3 |
12 |
Medium |
4 hours–3 days |
|
Security Incident Affecting Campus Access |
3 |
4 |
4 |
5 |
4 |
5 |
3 |
5 |
2 |
10 |
Low |
4 hours–3 days |
|
Pandemic or Infectious Disease Outbreak |
4 |
5 |
4 |
4 |
5 |
5 |
2 |
5 |
3 |
15 |
Medium |
2 weeks–3 months |
|
Loss of Key Personnel |
2 |
4 |
3 |
3 |
2 |
3 |
1 |
4 |
3 |
12 |
Medium |
1–10 working days |
|
Widespread Staff Unavailability |
4 |
5 |
4 |
4 |
4 |
5 |
1 |
5 |
3 |
15 |
Medium |
1–4 weeks |
|
Industrial Action or Transport Disruption Affecting Workforce Availability |
2 |
4 |
2 |
3 |
3 |
3 |
1 |
4 |
2 |
8 |
Low |
1–5 days |
|
Critical Supplier Failure |
3 |
4 |
3 |
3 |
3 |
2 |
3 |
4 |
3 |
12 |
Medium |
1–7 days |
|
Telecommunications Service Provider Failure |
2 |
4 |
2 |
3 |
3 |
1 |
4 |
4 |
3 |
12 |
Medium |
2–24 hours |
|
Critical Technology Service Provider Failure |
3 |
5 |
3 |
4 |
3 |
1 |
5 |
5 |
3 |
15 |
Medium |
4 hours–3 days |
|
Failure of Essential Facilities or Maintenance Provider |
2 |
4 |
2 |
3 |
2 |
3 |
4 |
4 |
3 |
12 |
Medium |
4 hours–3 days |
|
Power Failure |
2 |
4 |
2 |
3 |
3 |
2 |
4 |
4 |
3 |
12 |
Medium |
1–24 hours |
|
Telecommunications Failure |
2 |
4 |
2 |
3 |
3 |
1 |
4 |
4 |
3 |
12 |
Medium |
1–24 hours |
|
Cyberattack |
4 |
5 |
5 |
5 |
4 |
2 |
5 |
5 |
4 |
20 |
High* |
1–14 days |
|
Ransomware |
5 |
5 |
5 |
5 |
4 |
2 |
5 |
5 |
3 |
15 |
Medium |
3 days–3 weeks |
|
Application Failure |
2 |
4 |
2 |
3 |
3 |
1 |
4 |
4 |
4 |
16 |
High |
1–24 hours |
|
Network Failure |
2 |
4 |
2 |
3 |
3 |
1 |
4 |
4 |
3 |
12 |
Medium |
1–24 hours |
|
Data Centre or Hosting Environment Outage |
4 |
5 |
3 |
4 |
3 |
1 |
5 |
5 |
3 |
15 |
Medium |
4 hours–3 days |
|
Critical Hardware Failure |
2 |
3 |
2 |
2 |
2 |
1 |
4 |
4 |
3 |
12 |
Medium |
2–24 hours |
|
Data Loss or Corruption |
4 |
5 |
5 |
5 |
4 |
1 |
5 |
5 |
3 |
15 |
Medium |
1–7 days |
*BCMpedia's published Risk Level ranges overlap at a Risk Rating of 20: both High (16–20) and Very High (20–25) include 20.
This table provisionally treats 20 as High to avoid double classification; JCUS should adopt one unambiguous boundary in its approved risk matrix. BCMpedia
Do not treat the table as a numerical exercise. Its purpose is to support decisions concerning risk priorities and continuity preparedness.
The highest impact score deliberately captures the most severe consequence among the seven impact areas.
BCMpedia specifies that where two or more areas have the same highest score, further deliberation may be used to determine the most significant impact area even though their numerical values are identical.
For example, the illustrative assessment of a Cyberattack produces several impact scores of 5.
This indicates that the threat could simultaneously have major implications for operations, regulatory obligations, reputation and information systems.
The numerical maximum remains 5, but management should retain the multiple affected dimensions when considering treatment and continuity arrangements.
Likewise, Fire receives a high potential impact because it can affect people, physical facilities, technology and operational availability simultaneously.
Its lower illustrative likelihood prevents its overall Risk Rating from automatically becoming one of the highest ratings in the register.
This shows why you must consider both impact and likelihood.
The Expected Period of Disruption is especially important for BCM because it connects the Risk Analysis and Review process to continuity strategy.
BCMpedia defines this period as the estimated residual duration of operational disruption or denial of access after considering existing controls. BCMpedia
JCUS should therefore avoid estimating this duration solely from the incident's physical duration.
For example, a power interruption may last only two hours, but associated technology recovery could extend the operational disruption.
Conversely, campus access may remain restricted for several days while online teaching and remote work enable significant parts of the University's operations to continue.
The estimate should therefore consider:
Before final approval, JCUS should conduct a multidisciplinary risk assessment workshop.
The proposed scores should be reviewed by relevant representatives from:
Participants should evaluate each threat against the same approved impact and likelihood descriptors rather than assigning scores based purely on individual judgement.
Use evidence wherever available, including incident history, system availability records, supplier performance, exercise results, audit findings, cybersecurity assessments, facilities assessments, and previous disruptions.
The completed assessment should inform subsequent BCM decisions.
A practical relationship is:
Identified Threat
Risk Impact Assessment
Risk Likelihood Assessment
Risk Rating and Risk Level
Expected Period of Disruption
Risk Treatment Requirement
Business Continuity Strategy
Recovery Procedure
Testing and Continual Improvement
Threats with significant impact, extended disruption periods or material weaknesses in existing controls warrant particular attention when developing continuity and recovery arrangements.
However, the Risk Rating should not be used in isolation. A relatively low-likelihood threat can still require robust continuity planning when its potential impact is catastrophic.
RAR Part 3 provides JCUS with a structured approach for analysing the threats identified during the earlier stages of Risk Analysis and Review.
By assessing each threat against Finance, Operations, Legal & Regulatory, Reputation & Image, Social Responsibility, People, and Assets/IT Systems/Information, JCUS can develop a multidimensional understanding of the consequences of disruption rather than relying upon a single financial or operational measure.
The highest impact score is combined with the assessed likelihood to calculate the overall Risk Rating. This enables threats to be classified into appropriate Risk Levels and provides a consistent basis for prioritising further risk treatment and continuity planning. BCMpedia
The Expected Period of Disruption adds an important BCM dimension by estimating how long the organisation could remain operationally disrupted after considering existing controls.
This information can subsequently inform Business Continuity Strategies, resource requirements, recovery procedures, ICT Disaster Recovery arrangements and exercising priorities.
The numerical values presented in this chapter should therefore be regarded as proposed JCUS planning assumptions until formally validated.
The completed assessment should ultimately reflect JCUS's approved risk criteria, actual operating environment, existing controls, historical experience and management judgement.
When reviewed regularly and linked to treatment, continuity strategies and recovery capabilities, the Risk Impact and Likelihood Assessment becomes more than a risk register.
It provides a practical mechanism for identifying where resilience investment is most needed and for ensuring that JCUS remains prepared for disruptive events affecting its critical activities.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
| CBF-1 Teaching and Learning Delivery | ||||||
| DP | BIAQ P1 | BIAQ P2 | BIAQ P3 | BIAQ P4 | BIAQ P5 | BIAQ P6 |
| BCS T2 | BCS T3 | PD | ||||
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||