. .

Implementing Business Continuity Management for KK Women's and Children's Hospital: An Enterprise Implementation Guide
BB BCM 6

[BCM] [KKH] [E3] [RAR] [P2] Treatment and Control

[BCM] [KKH] [Full Banner] Implementing Business Continuity Management for KKH

New call-to-action

Part 2 of the Risk Analysis and Review evaluates how the threats identified in the approved Threat Register may be managed through risk treatment and specific controls.

While Part 1 identified credible sources of disruption affecting KK Women’s and Children’s Hospital (KKH), this chapter considers the organisational arrangements that may prevent, reduce, transfer, or formally retain the resulting risk exposure.

A threat is an event or condition capable of causing disruption. A risk treatment is the overall approach selected to manage the exposure created by that threat, while a control is a specific measure used to implement the treatment.

For example, ransomware is a threat; risk reduction may be the selected treatment; and network segmentation, endpoint detection, immutable backups, and cyber-incident response procedures are the controls used to reduce the risk.

More than one treatment approach may be applied to the same threat. KKH may reduce fire risk through detection and suppression systems, transfer part of the financial exposure through insurance, and formally accept a limited residual exposure that cannot be economically eliminated.

New call-to-action

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert

New call-to-action

Part 2: RAR - Treatment and Control

New call-to-action

 

Introduction

BCM] [KKH] [E3] [RAR] [T2] Treatment and Control

Part 2 of the Risk Analysis and Review evaluates how the threats identified in the approved Threat Register may be managed through risk treatment and specific controls.

While Part 1 identified credible sources of disruption affecting KK Women’s and Children’s Hospital (KKH), this chapter considers the organisational arrangements that may prevent, reduce, transfer, or formally retain the resulting risk exposure.

A threat is an event or condition capable of causing disruption. A risk treatment is the overall approach selected to manage the exposure created by that threat, while a control is a specific measure used to implement the treatment.

For example, ransomware is a threat; risk reduction may be the selected treatment; and network segmentation, endpoint detection, immutable backups, and cyber-incident response procedures are the controls used to reduce the risk.

More than one treatment approach may be applied to the same threat. KKH may reduce fire risk through detection and suppression systems, transfer part of the financial exposure through insurance, and formally accept a limited residual exposure that cannot be economically eliminated.

Risk transference does not remove KKH’s accountability for maintaining essential healthcare services, patient safety, regulatory compliance, or effective recovery arrangements.

As KKH’s confirmed control environment has not been provided, the controls described in this chapter are reasonably assumed to be existing controls requiring validation unless otherwise stated. Their inclusion does not establish that they are implemented, adequate, effective, or consistently maintained.

Control adequacy depends on ownership, design, coverage, reliability, testing, monitoring, evidence, and performance during actual incidents.

Control gaps should be converted into specific planned actions with responsible owners, implementation timeframes, testing methods, and evidence of completion.

Formal risk acceptance should only occur after residual exposure has been evaluated against approved risk appetite.

Acceptance should identify the approving authority, review frequency, monitoring arrangements, and conditions requiring reconsideration.

The treatment and control assessment supports Business Continuity Strategy development, Crisis Management, IT Disaster Recovery, supplier resilience, emergency preparedness, and Operational Resilience.

Subsequent Risk Assessment activities should evaluate the effectiveness of these controls before determining likelihood, impact, residual risk, and further mitigation priorities.

New call-to-action

Table T2: Treatment and Control

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional Planned Controls

Flash Flood

Partially Applicable – critical electrical, ICT, pharmaceutical, and medical assets may be located above identified flood exposure levels; validation required.

Drainage maintenance, flood monitoring, protected entrances, alternate access routes, emergency transport arrangements, and relocation of vulnerable assets are reasonably assumed.

Property and business interruption insurance may share financial consequences; coverage requires validation.

Limited residual access disruption may be accepted only with senior management approval, seasonal monitoring, and tested alternate access arrangements.

Assumed controls requiring validation: flood response procedure; water-level monitoring; facilities inspection; emergency pumps and barriers; protected electrical rooms; alternate ambulance and staff access; incident escalation.

Facilities Management, high priority, within 12 months: complete a site-specific flood vulnerability assessment; identify ingress points; install deployable barriers and water sensors; map alternate ambulance routes; test flood response before the monsoon period; retain inspection and exercise records.

Severe Storm / Thunderstorm

Not Applicable – severe weather cannot be avoided; exposure must be managed through preparedness and resilient infrastructure.

Weather monitoring, protected external equipment, safe-work restrictions, standby staffing, backup power, and transport contingency arrangements may reduce consequences.

Insurance may cover storm-related physical damage and selected business interruption losses.

Temporary restrictions on non-critical activities may be accepted under approved severe-weather operating procedures.

Assumed controls: lightning protection; weather alerts; building inspection; generator readiness; protected loading areas; staff notification; postponement of exposed maintenance work; emergency transport coordination.

Facilities and Emergency Planning, medium priority, within 12 months: establish weather-triggered operating thresholds; inspect roof, drainage, façades, and external plant; formalise transport and shift-relief contingencies; test severe-weather communications annually.

Lightning Strike

Partially Applicable – avoid placing exposed critical equipment outside protected zones where practicable.

Lightning protection, surge suppression, equipment grounding, UPS protection, redundant power supplies, and preventive inspection reduce damage.

Equipment warranties and property insurance may transfer part of the financial consequence.

Residual exposure may be accepted only following engineering assurance and annual review.

Assumed controls: building lightning protection system; earthing; surge protection devices; UPS; equipment maintenance; fault alarms; backup power; biomedical and ICT incident escalation.

Facilities and ICT, medium priority, within 12 months: conduct coordinated lightning protection and surge-risk testing; verify protection for rooftop systems, data rooms, imaging equipment, and medical gas controls; document remedial actions and certification.

Extreme Heat

Not Applicable – climatic conditions cannot be eliminated.

Redundant cooling, environmental monitoring, preventive HVAC maintenance, heat-health procedures, workload adjustment, hydration, and equipment temperature controls may reduce consequences.

Maintenance contracts and equipment warranties may share repair costs; insurance may cover physical damage where applicable.

Minor comfort impacts may be accepted, but exposure affecting clinical environments, medicine storage, data rooms, or staff safety should not be accepted.

Assumed controls: HVAC alarms; temperature monitoring; backup cooling for critical rooms; hydration and rest arrangements; medicine and blood-storage temperature alarms; escalation to Facilities.

Facilities, Pharmacy, ICT and HR, medium priority, within 12 months: map heat-sensitive rooms and assets; define temperature escalation thresholds; procure portable cooling for priority areas; include heat stress in workforce plans; test prolonged cooling-loss scenarios.

Haze

Not Applicable – regional haze cannot be avoided.

Indoor air filtration, air-quality monitoring, reduced outdoor exposure, respiratory PPE, staff health guidance, and service-demand planning may reduce effects.

Insurance is generally limited; outsourced air-quality monitoring or filter maintenance may share service delivery responsibilities.

Reduced outdoor activities may be accepted within approved health thresholds; deterioration affecting clinical safety requires escalation.

Assumed controls: national air-quality monitoring; HVAC filtration; N95 stock; staff advisories; clinical surge planning; restriction of outdoor work; communications to patients and visitors.

Infection Control and Facilities, medium priority, before haze season: define PSI-based activation levels; verify filtration performance; maintain PPE stock thresholds; identify vulnerable staff; test staff and public communication procedures.

Pandemic Movement Restrictions

Partially Applicable – avoid unnecessary travel, non-essential physical meetings, and avoidable dependence on single on-site teams during restrictions.

Workforce cohorting, remote work for suitable roles, staff accommodation support, split teams, digital collaboration, transport arrangements, and service prioritisation may reduce disruption.

Reciprocal healthcare support, outsourced logistics, and transport agreements may share selected operational consequences.

Temporary suspension of non-essential activity may be accepted by executive management, subject to clinical governance and regulatory requirements.

Assumed controls: pandemic plan; essential-worker identification; access letters; remote-access capability; staff cohorting; telehealth; alternate transport; emergency rosters; critical supplier coordination.

Emergency Planning and HR, high priority, within 6 months: validate minimum staffing by service; maintain transport and temporary accommodation contracts; test remote administration and telehealth capacity; conduct a movement-restriction exercise; document essential-worker dependencies.

Regional Earthquake Effects

Partially Applicable – critical structures and equipment should avoid known structural weaknesses and unsecured placement.

Building design standards, structural inspection, equipment anchoring, evacuation procedures, utility isolation, and post-tremor safety assessment reduce consequences.

Property insurance and engineering service agreements may transfer part of the financial and technical burden.

Minor tremor exposure may be accepted following engineering review; uncertainty regarding structural safety must not be accepted.

Assumed controls: evacuation plan; structural inspection arrangements; secured medical equipment; emergency lighting; engineering call-out; post-event area closure authority.

Facilities and Safety, lower priority, within 18 months: conduct a non-structural seismic review for suspended equipment, gas cylinders, shelves, laboratories, theatres, and data rooms; prepare a post-tremor inspection checklist; exercise partial evacuation.

Category 2: Denial of Access – Man-made Disaster

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional Planned Controls

Fire

Partially Applicable – prohibit unsafe hot work, uncontrolled storage of combustibles, and use of non-compliant equipment.

Detection, suppression, compartmentation, evacuation, fire watches, equipment maintenance, staff training, and alternate clinical locations reduce consequences.

Property, equipment, and business interruption insurance may transfer part of the financial exposure.

Residual fire exposure may be accepted only after fire-safety certification and management review; deficiencies affecting life safety are not acceptable.

Assumed controls: alarm and sprinkler systems; fire doors; extinguishers; evacuation routes; fire wardens; hot-work permits; emergency response team; fire drills; preventive inspection.

Fire Safety Manager and Facilities, high priority, within 6 months: assess evacuation of NICU, ICU, operating theatres, and immobile patients; test horizontal evacuation; verify smoke compartment integrity; track fire-door and penetrations defects to closure.

Explosion

Partially Applicable – prohibit unsafe handling, storage, or use of explosive and pressurised materials and remove obsolete hazardous equipment.

Pressure monitoring, gas detection, safe storage, preventive maintenance, exclusion zones, emergency shutdowns, and evacuation reduce consequences.

Insurance, equipment warranties, and specialised maintenance contracts may share losses and restoration costs.

Residual exposure requires executive and safety governance approval; uncontrolled explosive risk is not appropriate for acceptance.

Assumed controls: medical gas safety procedures; cylinder segregation; plant-room access controls; pressure alarms; hot-work controls; emergency isolation; incident response.

Facilities and Safety, high priority, within 9 months: conduct a bow-tie review of medical gas, boiler, generator, laboratory, and pressurised systems; verify automatic isolation; test emergency shutdown and evacuation procedures.

Chemical Spill

Partially Applicable – eliminate unnecessary hazardous substances and substitute safer materials where clinically and operationally feasible.

Controlled storage, labelling, spill kits, ventilation, PPE, trained responders, exposure monitoring, isolation, and decontamination reduce consequences.

Specialist hazardous-material response contracts and liability insurance may transfer part of the consequence.

Small controlled residual exposure may be accepted by the safety committee; gaps in containment or response capability should not be accepted.

Assumed controls: chemical register; safety data sheets; secure storage; spill kits; PPE; laboratory procedures; incident notification; decontamination arrangements.

Workplace Safety and Laboratory Services, high priority, within 6 months: validate chemical inventories and maximum quantities; map spill response equipment; train response teams; conduct a laboratory or loading-bay spill exercise; close ventilation and containment gaps.

Medical Gas Leak

Partially Applicable – remove unsafe or obsolete components and prohibit unauthorised modifications.

Zoned isolation valves, pressure and oxygen alarms, preventive maintenance, leak detection, cylinder controls, backup supply, and evacuation procedures reduce consequences.

Engineering maintenance contracts, warranties, and insurance may share repair costs.

Residual exposure may be accepted only after engineering assurance; undetected leakage or single-point supply failure is not acceptable.

Assumed controls: medical gas alarm panels; isolation diagrams; preventive maintenance; cylinder storage controls; emergency shutoff procedures; backup manifolds; engineering call-out.

Facilities and Clinical Engineering, critical priority, within 6 months: verify valve labelling and accessibility; test alarms and backup manifolds; maintain portable oxygen capacity; exercise loss of piped oxygen in ICU, NICU, theatres, and emergency areas.

Structural Failure

Applicable – close, repair, or cease using areas assessed as structurally unsafe.

Preventive inspection, loading controls, defect reporting, engineering assessment, restricted access, and relocation arrangements reduce consequences.

Property insurance and structural engineering contracts may share restoration costs.

Use of an area with unresolved structural safety concerns is not appropriate for acceptance.

Assumed controls: statutory inspections; defect management; building maintenance; area closure authority; evacuation arrangements; alternate clinical space planning.

Facilities, high priority, within 12 months: establish structural criticality maps; assess roofs, façades, plant rooms, suspended services, and heavy equipment zones; pre-identify relocation areas; test partial building closure.

Bomb Threat

Not Applicable – malicious threats cannot be fully avoided.

Screening, access control, suspicious-item reporting, threat assessment, evacuation or lockdown, police liaison, and communications reduce consequences.

Terrorism insurance may share selected financial losses; external security support may assist response.

No threat affecting life safety should be accepted without assessment; temporary operational disruption may be accepted under police and Crisis Management direction.

Assumed controls: security command centre; access control; CCTV; threat-call checklist; suspicious package procedure; police notification; evacuation and lockdown plans.

Security, high priority, within 9 months: develop hospital-specific bomb-threat zoning and patient-movement plans; train call handlers; conduct joint tabletop exercises with emergency agencies; validate alternate command locations.

Terrorism

Not Applicable – the threat cannot be eliminated.

Physical security, intelligence liaison, access control, hostile-vehicle measures, surveillance, lockdown, mass-casualty planning, and staff awareness reduce consequences.

Insurance and mutual aid may share financial and service-delivery consequences, but accountability remains with KKH.

Residual national-security exposure requires executive awareness and regular monitoring; critical gaps should not be accepted.

Assumed controls: security screening; CCTV; access badges; emergency response; mass-casualty plan; police and SCDF liaison; crisis communications.

Security and Emergency Planning, high priority, within 12 months: conduct a site security risk assessment; assess vehicle and public-access vulnerabilities; exercise lockdown and mass-casualty activation; strengthen interoperable communications with agencies.

Active Assailant

Not Applicable – deliberate violence cannot be fully avoided.

Access controls, behavioural reporting, duress alarms, lockdown, security response, police notification, staff awareness, and casualty management reduce consequences.

Security service contracts and insurance may transfer limited consequences.

Exposure should not be passively accepted; residual risk requires executive oversight and periodic testing.

Assumed controls: security patrols; CCTV; panic alarms; visitor controls; workplace violence policy; lockdown procedures; emergency notification.

Security and HR, high priority, within 6 months: define “run, hide, tell” or equivalent hospital-specific guidance; install duress alarms at high-risk points; exercise lockdown without compromising critical patient care; establish post-event psychosocial support.

Public Transport Disruption

Partially Applicable – avoid overdependence on a single commuting mode for essential teams.

Flexible shifts, remote work for suitable functions, staff transport, car-pooling, temporary accommodation, standby teams, and staggered reporting reduce consequences.

Transport contracts and accommodation agreements may share delivery obligations.

Short delays may be accepted within staffing tolerances; inability to maintain minimum clinical staffing requires escalation.

Assumed controls: staff notification; duty rosters; emergency transport contacts; remote-access arrangements; overtime and standby processes.

HR and Operations, medium priority, within 9 months: map essential staff commuting vulnerabilities; contract emergency transport; identify nearby accommodation; define priority transport eligibility; test workforce mobilisation during an MRT disruption.

Major Traffic Incident

Not Applicable – external road incidents cannot be fully avoided.

Alternate ambulance routes, traffic monitoring, security traffic control, supplier rerouting, patient diversion coordination, and staff alerts reduce consequences.

Ambulance, logistics, and courier contracts may share transport responsibilities.

Temporary delays may be accepted where alternate routes are effective; delays affecting emergency arrivals require immediate escalation.

Assumed controls: ambulance liaison; alternate entrances; traffic management; supplier contact lists; public communication; emergency access control.

Operations and Security, medium priority, within 9 months: prepare route maps for ambulances, staff, and suppliers; establish police and transport-agency liaison; test access during a major road closure.

Category 3: Unavailability of People

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional Planned Controls

Pandemic

Partially Applicable – avoid unnecessary exposure, non-essential gatherings, and deployment of vulnerable staff to high-risk settings where practicable.

Infection controls, vaccination, PPE, cohorting, surveillance, surge staffing, cross-training, telehealth, remote work, and service prioritisation reduce consequences.

Mutual aid, agency staffing, outsourced support, and insurance may share selected effects; clinical accountability remains with KKH.

Temporary reduction of non-essential services may be accepted by executive and clinical governance; unsafe staffing levels are not acceptable.

Assumed controls: pandemic plan; infection prevention programme; PPE stock; vaccination; staff screening; isolation; cohorting; business continuity rosters; communications.

Infection Control, HR and Operations, critical priority, within 6 months: validate pandemic staffing thresholds; maintain critical-role succession; secure accommodation and transport; test prolonged absenteeism and patient-surge scenarios; monitor PPE burn rates.

Infectious Disease Outbreak

Partially Applicable – suspend unsafe activities and restrict exposure to affected zones or cases.

Surveillance, case isolation, contact tracing, PPE, environmental cleaning, staff cohorting, exposure management, and outbreak command reduce consequences.

External laboratory, cleaning, and staffing providers may support response.

Residual clinical exposure requires Infection Control and executive oversight; uncontrolled transmission should not be accepted.

Assumed controls: infection surveillance; isolation rooms; PPE; outbreak protocols; occupational health; cleaning standards; reporting and escalation.

Infection Control, high priority, within 6 months: define outbreak staffing and ward-conversion plans; test contact tracing and cohorting; maintain rapid testing access; conduct multidisciplinary outbreak exercises.

Mass Illness

Partially Applicable – remove contaminated food, water, or environmental sources and suspend affected activities.

Rapid case identification, staff recall, redeployment, cross-training, agency support, occupational health assessment, and prioritised service delivery reduce consequences.

Temporary staffing contracts and mutual-aid arrangements may share service-delivery burdens.

Temporary service reduction may be accepted only through executive and clinical governance.

Assumed controls: sickness reporting; staff replacement procedures; occupational health; emergency rosters; cross-department redeployment; incident escalation.

HR and Operations, high priority, within 9 months: develop a 30–50% workforce loss scenario; identify minimum staffing by CBF; establish rapid credential verification for temporary staff; test redeployment.

Loss of Key Personnel

Partially Applicable – avoid single-person dependency and concentration of authority or knowledge.

Deputies, succession plans, delegation matrices, cross-training, documented procedures, shared access, and knowledge transfer reduce consequences.

Specialist locum agreements, professional service contracts, and mutual support may share limited operational consequences.

Short-term residual dependency may be temporarily accepted by the relevant executive, with a named remediation date and quarterly review.

Assumed controls: duty rosters; deputies; job descriptions; on-call arrangements; credential records; standard operating procedures; access delegation.

HR and Department Heads, high priority, within 6 months: identify all single-person dependencies; assign two trained alternates for critical roles; document emergency delegations; test succession through no-notice exercises.

Skills Shortage

Partially Applicable – avoid service expansion or technology deployment without sufficient competent staffing.

Workforce planning, recruitment, retention, cross-training, competency management, flexible staffing, and service prioritisation reduce consequences.

Locum, agency, managed service, and training-provider arrangements may share capacity needs.

Residual shortages may be accepted only within defined safe staffing limits and with executive approval.

Assumed controls: workforce plans; competency matrices; continuing professional education; agency panels; overtime; redeployment; credentialing.

HR and Clinical Leadership, high priority, within 12 months: forecast critical skill gaps over three years; establish training pipelines; develop return-to-practice and cross-skilling programmes; monitor vacancy and fatigue indicators monthly.

Staff Fatigue

Applicable – prohibit unsafe working hours or deployment where fitness for duty is compromised.

Shift limits, rest periods, staffing rotation, welfare checks, relief teams, workload prioritisation, and fatigue monitoring reduce consequences.

Temporary staffing and employee assistance providers may support operations, but duty-of-care accountability remains internal.

Minor temporary workload variation may be accepted within approved limits; sustained unsafe fatigue is not acceptable.

Assumed controls: rostering rules; overtime approval; break requirements; incident welfare support; supervisor observation; staff reporting channels.

HR and Clinical Operations, high priority, within 6 months: implement fatigue risk thresholds; monitor consecutive hours and missed breaks; establish relief pools; include fatigue metrics in prolonged-incident reporting.

Psychological Stress

Partially Applicable – remove avoidable workplace stressors and unsafe exposure where practicable.

Psychological first aid, peer support, counselling, workload adjustment, supervisor training, critical-incident debriefing, and welfare monitoring reduce consequences.

Employee assistance and specialist mental-health services may share support delivery.

Residual stress exposure requires HR and management monitoring; severe untreated exposure should not be accepted.

Assumed controls: employee assistance programme; occupational health; grievance and reporting channels; staff welfare communications; post-incident support.

HR and Occupational Health, medium priority, within 9 months: establish a critical-incident psychosocial plan; train peer supporters; create referral thresholds; monitor absence, turnover, and welfare indicators following major incidents.

Mandatory Quarantine

Partially Applicable – reduce unnecessary exposure and avoid mixing critical teams.

Team segregation, remote work, standby rosters, cross-training, accommodation, telehealth, and rapid replacement processes reduce consequences.

Agency staffing, mutual aid, and remote service providers may supplement capacity.

Temporary quarantine-related absence may be accepted within minimum staffing thresholds; breaches require executive escalation.

Assumed controls: exposure reporting; quarantine procedures; remote access; cohorting; emergency rosters; occupational health clearance.

HR and Infection Control, high priority, within 6 months: model quarantine of an entire specialist team; create segregated rosters; maintain remote clinical advisory capability; test replacement mobilisation.

Family Emergencies

Not Applicable – individual emergencies cannot be fully avoided.

Cross-coverage, flexible work, leave management, standby staff, employee support, and documented handover reduce consequences.

Temporary staffing may share operational consequences.

Normal levels may be accepted within staffing resilience; clustered absence requires escalation and service prioritisation.

Assumed controls: leave procedures; relief staff; on-call rosters; cross-training; emergency contact and handover arrangements.

HR and Department Heads, lower priority, within 12 months: assess concentration of staff with common dependency risks; expand cross-coverage; provide rapid shift-swap and emergency leave replacement procedures.

Category 4: Disruption to the Supply Chain

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional Planned Controls

Supplier Failure

Partially Applicable – avoid suppliers that fail minimum financial, quality, regulatory, or continuity requirements.

Due diligence, performance monitoring, safety stock, alternate suppliers, escalation, substitution, and continuity clauses reduce consequences.

Contracts, service credits, warranties, indemnities, insurance, and framework agreements may share consequences.

Residual exposure may be accepted by Procurement and the service owner only where alternatives are impracticable and contingency stock is adequate.

Assumed controls: approved vendor list; due diligence; contracts; supplier KPIs; stock monitoring; escalation; alternate sourcing; quality assurance.

Procurement and Service Owners, high priority, within 9 months: classify critical suppliers; obtain and assess supplier BCPs; define minimum stock and recovery expectations; conduct annual joint continuity tests; track remediation.

Cloud Service Provider Failure

Partially Applicable – avoid unsupported, non-compliant, or inadequately resilient cloud services.

Multi-zone design, backups, offline exports, local downtime procedures, resilience monitoring, exit plans, and tested restoration reduce consequences.

Contractual availability commitments, service credits, cyber insurance, and managed recovery services may share consequences.

Residual outage exposure requires ICT and business-owner approval; acceptance should be reviewed annually and after material service changes.

Assumed controls: supplier due diligence; SLA; cloud monitoring; identity controls; backups; incident notification; vendor escalation; DR arrangements.

ICT and Procurement, high priority, within 9 months: assess concentration and data portability; require tested recovery evidence; establish provider-exit plans; validate recovery independent of the provider; perform annual outage exercises.

Telecommunications Failure

Partially Applicable – avoid sole dependence on one carrier, circuit, technology, or physical route.

Dual carriers, diverse routing, mobile backup, radios, satellite or alternative communications, redundant PBX, and call-forwarding reduce consequences.

Carrier SLAs and managed telecommunications contracts may share restoration responsibility.

Short degradation may be accepted within defined limits; loss of clinical and emergency communications is not appropriate for acceptance.

Assumed controls: redundant links; mobile phones; pagers; radios; call trees; carrier escalation; network monitoring; manual messaging.

ICT, critical priority, within 6 months: verify physical route diversity; test carrier failover; maintain emergency radios and charging; establish priority restoration contacts; conduct hospital-wide communications-loss exercises.

Utility Failure

Partially Applicable – avoid single points of connection where technically and economically feasible.

Backup generators, UPS, redundant water and gas systems, fuel reserves, preventive maintenance, load prioritisation, and utility monitoring reduce consequences.

Utility agreements, equipment maintenance contracts, and insurance may share restoration costs.

Limited residual outage may be accepted only where tested backup duration exceeds service recovery needs.

Assumed controls: generators; UPS; automatic transfer switches; water storage; medical gas backup; fuel contracts; maintenance; alarms; load-shedding priorities.

Facilities, critical priority, within 6 months: perform integrated utility-loss testing under clinical load; verify fuel endurance and resupply; map generator-supported circuits; test water and medical gas contingencies.

Logistics Disruption

Partially Applicable – avoid dependence on a single route, courier, warehouse, or distribution node for critical supplies.

Alternate routes, multiple logistics providers, buffer stock, emergency deliveries, prioritised receiving, and local sourcing reduce consequences.

Logistics contracts and emergency courier agreements may share service-delivery obligations.

Short delays may be accepted where stock cover is adequate; depletion of critical medical supplies requires escalation.

Assumed controls: delivery schedules; inventory monitoring; approved couriers; receiving procedures; supplier escalation; emergency purchase authority.

Supply Chain, high priority, within 9 months: map critical delivery routes and lead times; establish alternate warehouses and couriers; define emergency delivery SLAs; test a seven-day logistics disruption.

Fuel Supply Disruption

Partially Applicable – reduce reliance on fuel-dependent recovery arrangements where alternatives exist.

On-site reserves, priority fuel contracts, consumption monitoring, load management, alternate transport, and resupply coordination reduce consequences.

Supplier agreements and emergency fuel contracts may share delivery responsibilities.

Residual supply exposure may be accepted only if fuel autonomy and resupply arrangements meet generator and transport requirements.

Assumed controls: fuel tanks; stock monitoring; generator consumption records; supplier contracts; emergency procurement; protected delivery access.

Facilities and Procurement, high priority, within 9 months: verify usable fuel endurance at maximum critical load; contract a secondary supplier; test delivery during road disruption; establish minimum reorder triggers.

Vendor Insolvency

Partially Applicable – avoid financially unstable or highly concentrated vendors for critical services.

Financial monitoring, escrow, documentation ownership, alternate vendors, spare parts, knowledge transfer, and transition plans reduce consequences.

Performance bonds, warranties, indemnities, parent guarantees, and insurance may share financial consequences.

Residual exposure may be accepted by Procurement and the service owner where transition capability is demonstrated and monitored quarterly.

Assumed controls: financial due diligence; contract termination rights; vendor performance review; asset and licence inventories; alternate sourcing.

Procurement and Finance, medium priority, within 12 months: introduce financial early-warning indicators; require transition assistance and data return clauses; identify replacement vendors; test exit plans for critical suppliers.

Third-Party Cyber Incident

Partially Applicable – avoid vendors that cannot meet security and resilience requirements.

Security due diligence, network segmentation, least privilege, incident notification, alternate processing, backup, and third-party monitoring reduce consequences.

Cyber insurance, contractual indemnities, managed security services, and breach-response obligations may share consequences.

Acceptance is not appropriate where the incident could disrupt critical care or compromise sensitive health data without adequate controls.

Assumed controls: third-party security assessments; contractual requirements; access control; logging; vendor incident escalation; data backups; isolation capability.

Cybersecurity and Procurement, critical priority, within 6 months: establish tiered third-party cyber assessments; require rapid notification and recovery testing; monitor remote access; conduct joint cyber exercises with critical vendors.

Single-Source Dependency

Applicable – avoid sole sourcing for essential services where qualified alternatives exist.

Safety stock, approved substitutes, dual sourcing, emergency procurement, equipment standardisation, and demand prioritisation reduce consequences.

Framework agreements and reciprocal supply arrangements may share delivery risk.

Sole-source residual exposure may be accepted only by executive management after documenting clinical necessity, stock coverage, monitoring, and exit triggers.

Assumed controls: critical-item lists; inventory thresholds; supplier review; emergency procurement; substitution approval; stock rotation.

Supply Chain and Clinical Owners, critical priority, within 6 months: identify all sole-source critical items; qualify alternatives; increase strategic stock where justified; develop conservation protocols; report unresolved dependencies quarterly.

Regulatory Import Restrictions

Not Applicable – national or international restrictions cannot be directly avoided.

Regulatory monitoring, advance procurement, local substitutes, inventory reserves, supplier diversification, and clinical conservation protocols reduce consequences.

Supplier and distributor agreements may share sourcing responsibilities; government coordination may support allocation.

Temporary substitution or restricted use may be accepted through clinical governance and executive approval; safety or legal non-compliance is not acceptable.

Assumed controls: regulatory alerts; inventory tracking; procurement escalation; product substitution review; liaison with authorities and distributors.

Procurement, Pharmacy and Regulatory Affairs, high priority, within 9 months: map imported critical products; define substitution pathways; maintain regulatory documentation; develop shortage allocation protocols; exercise an import restriction scenario.

Category 5: Equipment and IT-Related Disruption

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional Planned Controls

Cyber Attack

Partially Applicable – prohibit unsupported technology, unauthorised services, and insecure connections.

Defence-in-depth, segmentation, monitoring, vulnerability management, access controls, backups, incident response, and staff awareness reduce consequences.

Managed security services, cyber insurance, warranties, and contractual obligations may share selected consequences.

Residual cyber exposure requires executive risk-owner approval and continuous monitoring; critical unresolved vulnerabilities should not be accepted.

Assumed controls: security policies; SOC monitoring; firewalls; endpoint protection; MFA; patching; vulnerability scanning; network segmentation; incident response; backups.

Cybersecurity, critical priority, continuous programme: implement threat-led testing; strengthen zero-trust controls; track critical vulnerabilities to closure; exercise clinical cyber downtime; report cyber resilience metrics to senior management quarterly.

Ransomware

Applicable – prohibit unsupported systems, uncontrolled administrative privileges, and unverified executable content.

Endpoint detection, email security, segmentation, privileged access management, immutable backups, application allow-listing, and rehearsed response reduce consequences.

Cyber insurance and specialist incident-response retainers may share recovery costs; accountability remains with KKH.

Acceptance is not appropriate where critical systems lack tested recovery or effective isolation.

Assumed controls: anti-malware; EDR; phishing protection; MFA; restricted privileges; backups; incident response; recovery procedures; user awareness.

Cybersecurity and ICT, critical priority, within 6 months: deploy immutable and offline backups for priority systems; test bare-metal recovery; establish ransomware containment playbooks; run no-notice recovery simulations; verify backup independence from production credentials.

Malware Infection

Applicable – block prohibited software, removable media, and unauthorised applications.

EDR, anti-malware, filtering, patching, least privilege, application control, network isolation, and user awareness reduce consequences.

Managed detection and response services and vendor warranties may share response support.

Minor residual exposure may be accepted under cyber risk appetite if detection and containment remain effective.

Assumed controls: endpoint protection; email filtering; web filtering; patch management; device control; malware alerts; isolation procedures.

Cybersecurity, high priority, within 9 months: improve application allow-listing; enforce removable-media controls; measure detection and isolation times; conduct malware containment exercises.

Distributed Denial of Service

Not Applicable – internet-based attacks cannot be fully avoided.

DDoS protection, traffic filtering, scalable hosting, alternate access channels, content delivery networks, and service prioritisation reduce consequences.

Telecommunications and cloud-provider DDoS services may transfer part of the technical response.

Short disruption to non-critical public services may be accepted; disruption to clinical or emergency connectivity requires escalation.

Assumed controls: ISP filtering; web application firewall; traffic monitoring; cloud scaling; incident escalation; public communication alternatives.

ICT, medium priority, within 12 months: define critical internet services; validate upstream DDoS protection; test failover and public communications; establish attack thresholds and provider escalation times.

Insider Threat

Partially Applicable – avoid excessive privileges, unmanaged conflicts of interest, and incompatible duties.

Screening, least privilege, segregation of duties, monitoring, user behaviour analytics, access reviews, awareness, and rapid revocation reduce consequences.

Fidelity or cyber insurance may share selected financial consequences; outsourcing does not transfer accountability.

Residual exposure may be accepted only following documented access-risk review and management approval.

Assumed controls: background screening; IAM; role-based access; audit logs; privileged access monitoring; HR disciplinary procedures; whistleblowing channels.

Cybersecurity, HR and Internal Audit, high priority, within 9 months: implement privileged-user analytics; automate leaver access removal; conduct quarterly high-risk access reviews; test insider incident response.

Data Breach

Partially Applicable – avoid unnecessary collection, retention, or sharing of sensitive data.

Encryption, access control, data loss prevention, monitoring, privacy procedures, secure disposal, incident response, and staff training reduce consequences.

Cyber insurance, contractual indemnities, and breach-response services may share financial and technical consequences.

Acceptance is not appropriate where legal, patient confidentiality, or material security requirements are unmet.

Assumed controls: data classification; encryption; RBAC; audit logs; DLP; privacy impact assessments; breach response; retention and disposal procedures.

Data Protection and Cybersecurity, critical priority, within 6 months: map sensitive data flows; reduce excessive access and retention; strengthen exfiltration monitoring; test breach notification and stakeholder communications.

Network Failure

Partially Applicable – eliminate unsupported components and avoid single points of failure.

Redundant core and distribution networks, diverse paths, failover, monitoring, spare equipment, and manual clinical workarounds reduce consequences.

Managed network services, maintenance contracts, and warranties may share restoration responsibilities.

Residual failure exposure may be accepted only where redundancy and tested downtime procedures meet clinical recovery needs.

Assumed controls: redundant switches and links; network monitoring; configuration backups; spare hardware; escalation; downtime procedures.

ICT, critical priority, within 6 months: map end-to-end clinical network dependencies; test failover under load; remove shared failure points; maintain offline configurations and critical spares.

Server Failure

Partially Applicable – retire unsupported or unstable servers and consolidate where resilience improves.

Clustering, virtualisation, replication, monitoring, spare capacity, backups, and automated restart reduce consequences.

Vendor maintenance, warranties, managed hosting, and cloud services may share restoration tasks.

Isolated residual hardware failure may be accepted where automatic failover and capacity are demonstrated.

Assumed controls: server clustering; monitoring; preventive maintenance; virtualisation; backups; spare capacity; incident escalation.

ICT, high priority, within 9 months: identify single-instance servers; implement high availability for priority applications; test host and cluster failover; maintain lifecycle replacement schedules.

Database Corruption

Partially Applicable – prohibit untested changes, unsupported database versions, and uncontrolled direct data modification.

Transaction logging, replication, integrity checks, point-in-time recovery, change control, backups, and reconciliation reduce consequences.

Database support agreements and specialist recovery services may share restoration support.

Acceptance is not appropriate where data cannot be restored within approved RPO and RTO.

Assumed controls: database backups; replication; access controls; change management; integrity monitoring; recovery procedures; audit trails.

ICT and Application Owners, critical priority, within 6 months: test point-in-time recovery; implement automated integrity checks; preserve offline logical backups; conduct application-level reconciliation exercises.

Cloud Service Outage

Partially Applicable – avoid cloud architectures with unmitigated regional or provider concentration.

Multi-zone resilience, local fallback, data export, offline procedures, monitoring, backups, and provider escalation reduce consequences.

Cloud SLAs, service credits, managed recovery, and insurance may share selected consequences.

Residual provider outage may be accepted only where business owners validate fallback arrangements and recovery dependencies.

Assumed controls: multi-zone deployment; vendor monitoring; backups; incident notification; downtime procedures; alternate communication channels.

ICT and Procurement, high priority, within 9 months: test regional outage and provider-access loss; validate data portability; establish independent backups; document service exit and substitution options.

Power Failure

Partially Applicable – remove unsafe or obsolete electrical components and avoid single-supply dependency where feasible.

Generators, UPS, automatic transfer, dual feeds, protected circuits, maintenance, fuel reserves, and load prioritisation reduce consequences.

Utility agreements, maintenance contracts, warranties, and insurance may share restoration costs.

Residual exposure may be accepted only after full-load generator and transfer testing confirms adequate endurance.

Assumed controls: emergency generators; UPS; ATS; electrical alarms; preventive maintenance; fuel monitoring; essential-circuit identification.

Facilities and Clinical Engineering, critical priority, within 6 months: conduct full-load black-start testing; verify all critical clinical and ICT equipment connections; test prolonged outage, fuel resupply, and manual transfer procedures.

Hardware Failure

Partially Applicable – retire obsolete, unsupported, or unsafe devices.

Preventive maintenance, spares, redundancy, equipment standardisation, rapid replacement, monitoring, and manual workarounds reduce consequences.

Warranties, maintenance agreements, leasing, and vendor replacement commitments may share consequences.

Limited isolated failure may be accepted where backup devices and service coverage are adequate.

Assumed controls: asset register; maintenance schedules; spare equipment; vendor support; biomedical inspection; failure reporting; replacement procedures.

Clinical Engineering and ICT, high priority, within 9 months: identify equipment with no substitute; set minimum spare holdings; monitor end-of-support dates; test rapid replacement for life-support and diagnostic devices.

Software Failure

Applicable – prohibit untested releases and discontinue unsupported or unstable software.

Change control, testing, rollback, monitoring, staged deployment, configuration management, vendor support, and manual workarounds reduce consequences.

Vendor warranties, maintenance, support SLAs, and escrow may share restoration support.

Residual defects may be accepted only after business-owner review and where safe workarounds exist.

Assumed controls: software development and change management; test environments; release approvals; rollback plans; vendor support; application monitoring.

ICT and Application Owners, high priority, within 6 months: strengthen clinical safety testing; require rollback evidence; conduct failure simulations before major releases; monitor post-release incidents and recovery times.

Backup Failure

Applicable – discontinue unreliable backup technologies and remove configurations that permit production compromise to affect all backups.

Multiple backup copies, immutable storage, off-site replication, monitoring, automated verification, restoration testing, and retention controls reduce consequences.

Managed backup services and cyber insurance may share operational or financial effects.

Acceptance is not appropriate for critical systems lacking verified recoverability.

Assumed controls: scheduled backups; off-site copies; monitoring; retention policies; periodic restoration tests; access restrictions.

ICT, critical priority, within 3 months: implement independent immutable copies; perform monthly sample restores and annual full-system recovery; report backup success and restore evidence; remediate failed jobs within defined thresholds.

Data Centre Failure

Partially Applicable – avoid co-location of all critical systems and dependencies within one failure zone.

Secondary data centre, replication, redundant utilities and networks, automated failover, recovery orchestration, and DR exercises reduce consequences.

Co-location, cloud, and managed DR contracts may share infrastructure recovery responsibilities.

Residual site-loss exposure may be accepted only after proven failover and adequate capacity at the recovery site.

Assumed controls: alternate data centre; replication; backup power and cooling; network diversity; DR plans; failover testing; incident command.

ICT, critical priority, within 6 months: conduct end-to-end data-centre-loss exercises; validate application dependency sequencing, recovery capacity, user access, cyber isolation, and business reconciliation.

Identity and Access Management Failure

Partially Applicable – avoid centralised single points of failure and unsupported authentication mechanisms.

Redundant identity services, cached access, emergency accounts, MFA resilience, directory replication, break-glass procedures, and manual authorisation reduce consequences.

Cloud identity SLAs and managed IAM support may share restoration duties.

Temporary degraded access may be accepted only under controlled emergency access procedures with complete logging and retrospective review.

Assumed controls: directory replication; MFA; privileged access management; emergency accounts; access logs; service monitoring; help-desk escalation.

ICT and Cybersecurity, critical priority, within 6 months: test identity-provider outage; create controlled break-glass access for critical systems; remove dependency loops; audit emergency account use after every activation.

Artificial Intelligence System Failure

Applicable – prohibit unsupervised use of AI where output could directly determine critical clinical or operational decisions without authorised validation.

Human oversight, model validation, input and output monitoring, fallback procedures, change control, audit logs, performance thresholds, and manual decision-making reduce consequences.

Vendor warranties, service agreements, professional indemnity, and contractual assurance may share limited consequences.

Residual model limitations may be accepted only by clinical, data, risk, and executive governance within defined use boundaries and review periods.

Assumed controls requiring validation: approved-use policy; human review; clinical governance; model performance monitoring; access control; incident reporting; manual fallback.

Clinical Governance, Data Office and ICT, high priority, before material deployment: establish AI governance; maintain model and use-case inventories; define stop-use thresholds; test failure, bias, drift, and outage scenarios; retain decision audit trails.

 

Control Validation and Governance Requirements

Because the existing controls above are assumed rather than confirmed, KKH should validate the control environment through a structured assurance exercise. Validation should determine:

  1. Whether the control is formally documented and approved.
  2. Whether a named owner is accountable for operation and maintenance.
  3. Whether the control covers all relevant Critical Business Functions, facilities, systems, suppliers, and recovery locations.
  4. Whether it operates continuously or only when manually activated.
  5. Whether it has been tested under realistic disruption conditions.
  6. Whether evidence demonstrates that it achieves its intended objective.
  7. Whether identified weaknesses have been assigned, funded, monitored, and closed.
  8. Whether dependencies on personnel, technology, utilities, and third parties have been considered.
  9. Whether the control remains effective during concurrent or prolonged disruptions.
  10. Whether residual exposure is within approved risk appetite.

Risk owners should document control validation results in a controlled Risk Assessment Report or governance system. Control status may be classified as:

  • Confirmed and effective;
  • Confirmed but partially effective;
  • Implemented but not recently tested;
  • Assumed and requiring validation;
  • Planned but not implemented;
  • Ineffective or unavailable.

 

Risk Acceptance Governance

Risk acceptance should not be used to legitimise an unaddressed control weakness. Where residual exposure is proposed for acceptance, the record should identify:

  • The specific threat and residual exposure;
  • The reason additional treatment is not reasonably practicable;
  • The operational and clinical consequences being retained;
  • The approving authority;
  • The duration of the acceptance;
  • Monitoring indicators and reporting frequency;
  • Interim or compensating controls;
  • The date for review;
  • Events that trigger immediate reconsideration.

For risks affecting patient safety, life-support services, critical healthcare delivery, sensitive health information, legal compliance, or national healthcare resilience, acceptance should generally require senior executive and appropriate clinical or governance approval.

 

Banner [Table] [BCM] [E3] [RAR] [Summing Up]  [T2] Treatment and Control of Identified Threats

The treatment and control assessment converts KKH’s approved Threat Register into a practical basis for risk management and continuity improvement. It distinguishes the sources of disruption from the approaches used to manage them and from the individual controls that implement those approaches.

Different threats require different combinations of risk avoidance, reduction, transference, and acceptance. Avoidance may be appropriate where an unsafe facility, unsupported technology, or high-risk supplier dependency can be removed. Reduction is generally the principal treatment for operational disruption through resilience, redundancy, preventive controls, monitoring, training, recovery arrangements, and exercises. Transference may reduce selected financial, contractual, or service-delivery consequences, but it does not remove KKH’s responsibility for essential healthcare services. Acceptance should only apply to a defined residual exposure that has been formally assessed, approved, monitored, and periodically reviewed.

The presence of policies, systems, contracts, or recovery plans does not automatically mean that risk is adequately controlled. Their design, ownership, coverage, maintenance, testing, reliability, and demonstrated performance must be assessed. Planned controls should therefore be assigned to accountable owners, supported by clear deadlines, tested through exercises or technical validation, and evidenced through governance reporting.

This chapter provides the structured foundation for subsequent assessment of control effectiveness, likelihood, impact, residual risk, and risk treatment priorities. By systematically validating existing controls and addressing identified gaps, KKH can strengthen Business Continuity Strategy, Crisis Management, IT Disaster Recovery, supplier resilience, and Operational Resilience across its critical clinical and supporting services.

 

 

[BCM] [KKH] [3/4 Banner] Implementing Business Continuity Management for KKH

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1 eBook 1
BCM] [KKH] [E3] [BIA] MBCO Corporate MBCO BCM] [KKH] [E3] [BIA] [PS] Key Product and Services BCM] [KKH] [E3] [RAR] [T1] List of Threats BCM] [KKH] [E3] [RAR] [T2] Treatment and Control BCM] [KKH] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment BCM] [KKH] [E3] [BCS] [T1] Mitigation Strategies and Justification x eBook Cover [BCM] [KKH] [E1] [2D]
 

 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

New call-to-action  New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 
 

Your Comments Here:

 

More Posts

New Call-to-action