---
title: [CM] [BDCB] [E3] [CMS] [P1] Crisis Prevention Strategy
description: [CM] [BDCB] [E3] [CMS] [P1] Crisis Prevention Strategy
image: https://blog.bcm-institute.org/hubfs/BDCB%20Graphic%20Folder/BDCB%20CM%20Graphic%20Folder/BDCB%20CM%20E3%20Morepost/%5BCM%5D%20%5BBDCB%5D%20%5BE3%5D%20%5BCMS%5D%20%5BP1%5D%20Crisis%20Prevention%20Strategy.jpg
---

.

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

##### Crisis Management in Action: A Practical Implementation Guide for BDCB

![CM Ai Gen\_with Cert Logo 21](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20CM%20%5BAi%20Gen%20Blog%20Photo%5D/BB%20CM%20v2%20Jun%20204/CM%20Ai%20Gen_with%20Cert%20Logo%2021.jpg?width=2000&height=1333&name=CM%20Ai%20Gen_with%20Cert%20Logo%2021.jpg "CM Ai Gen_with Cert Logo 21")

# \[CM\] \[BDCB\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy

[![\[CM\] \[BDCB\] \[Full Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07)

**CMS Part 1 — Crisis Prevention Strategy for Brunei Darussalam Central Bank (BDCB)** translates the threats and crisis scenarios identified through the Crisis Risk Assessment into **preventive strategies designed to reduce the probability that an adverse event develops into a crisis**.

The prevention stage should be distinguished from crisis response. Crisis response asks what BDCB should do **after a crisis has developed**.

Crisis prevention focuses on the measures that can be established **before the event** to remove vulnerabilities, reduce likelihood, detect deterioration early, strengthen controls, and intervene before escalation.

For BDCB, crisis prevention needs to reflect its distinctive role as Brunei Darussalam's central bank.

BDCB conducts monetary policy, issues Brunei currency, regulates and supervises banks and other financial institutions, seeks to maintain financial system stability, and assists in establishing and overseeing efficient payment systems.

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/4f131fae-9e5f-4aec-ba80-cc5b33fd5831.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/4f131fae-9e5f-4aec-ba80-cc5b33fd5831)

[Moh Heng Goh](https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh) Oct 7, 2026

###### Crisis Management Certified Planner-Specialist-Expert

##### [![\[CM\] \[BDCB\] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/062c8304-1699-4f7b-a38d-f128d9815304.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/062c8304-1699-4f7b-a38d-f128d9815304)

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/4f131fae-9e5f-4aec-ba80-cc5b33fd5831.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/4f131fae-9e5f-4aec-ba80-cc5b33fd5831)

### **[![\[CM\] \[Table\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/e1249d6b-bf27-4675-b1e3-3fb3c7a7af2a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e1249d6b-bf27-4675-b1e3-3fb3c7a7af2a)Crisis Prevention Strategy for Brunei Darussalam Central Bank**

#### **Introduction**

**[![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d)CMS Part 1 — Crisis Prevention Strategy for Brunei Darussalam Central Bank (BDCB)** translates the threats and crisis scenarios identified through the Crisis Risk Assessment into **preventive strategies that reduce the likelihood that an adverse event develops into a crisis**.

The prevention stage should be distinguished from crisis response. Crisis response asks what BDCB should do **after a crisis has developed**.

Crisis prevention focuses on measures established **before the event** to remove vulnerabilities, reduce likelihood, detect deterioration early, strengthen controls, and intervene before escalation.

For BDCB, crisis prevention needs to reflect its distinctive role as Brunei Darussalam's central bank.

BDCB conducts monetary policy, issues Brunei currency, regulates and supervises banks and other financial institutions, seeks to maintain financial system stability, and helps establish and oversee efficient payment systems.

BDCB also operates the National Payment and Settlement Systems, comprising **RTGS, ACH, and CSD**. RTGS supports large-value and urgent interbank payments; ACH facilitates bulk clearing; and CSD supports government-securities records, transfers, and settlement-related activities.

Crisis prevention must therefore consider not only BDCB's internal resilience but also dependencies that could affect critical financial infrastructure and the wider financial system.

The table below follows the intent of **BCM Institute's CST1 Crisis Prevention Strategy methodology**: start with the identified crisis type and threat/scenario, determine what can reasonably be done to prevent or reduce its occurrence, and document the specific preventive measures required.

The strategies are **illustrative recommendations for the BDCB case study**. They should not be interpreted as statements that BDCB currently operates every control listed.

#### **Crisis Prevention Strategy Table**

##### **Natural Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Natural | Flood | Reduce physical exposure and improve flood protection | Conduct site-specific flood-risk assessments; maintain drainage; protect critical plant and ICT equipment from water exposure; install appropriate barriers; monitor weather warnings; maintain preventive facility inspections. |
| Natural | Flash Flood | Early detection and rapid protective action | Establish severe-weather monitoring and predefined alert thresholds; identify vulnerable access routes; protect critical equipment; establish early site-closure criteria before access becomes unsafe. |
| Natural | Severe Rain / Thunderstorm | Weather preparedness and facility protection | Monitor severe-weather information; maintain roofs, drainage and building envelope; inspect potential water-ingress points; protect critical electrical infrastructure. |
| Natural | Lightning | Electrical and telecommunications protection | Maintain lightning protection, surge protection, earthing, UPS and protective devices; periodically inspect and test protection systems. |
| Natural | Strong Wind / Windstorm | Structural and external-asset protection | Inspect structural vulnerabilities; secure external equipment; maintain roofs, windows and exposed installations; establish wind-related workplace safety thresholds. |
| Natural | Tropical Storm / Severe Weather | Severe-weather preparedness programme | Maintain weather-monitoring arrangements, facility protection, staff advisories, preventive maintenance and predefined escalation thresholds. |
| Natural | Haze / Poor Air Quality | Air-quality monitoring and exposure reduction | Monitor air-quality indicators; maintain HVAC filtration; reduce outdoor activity; establish thresholds for remote work or reduced on-site staffing. |
| Natural | Earthquake / Regional Seismic Event | Structural vulnerability reduction | Assess critical facilities against applicable structural requirements; secure equipment; identify safe evacuation areas; maintain structural inspection arrangements. |
| Natural | Landslide | Avoid exposure and monitor vulnerable infrastructure | Assess nearby slopes and access routes where relevant; monitor severe rainfall; identify alternative routes; coordinate with facility and infrastructure providers. |
| Natural | Extreme Heat | Cooling and electrical resilience | Maintain HVAC systems; monitor equipment-room temperatures; maintain backup cooling where critical; review power-loading risks during extreme conditions. |
| Natural | Natural Fire / Wildfire | External-fire exposure management | Maintain vegetation and combustible-material controls where relevant; monitor external fires; protect air intakes; coordinate with emergency authorities. |
| Natural | Infectious Disease Outbreak | Infection prevention and workforce protection | Maintain hygiene arrangements, health advisories, flexible working, workforce segregation where required, and early activation thresholds for infection-control measures. |
| Natural | Pandemic | Organisational pandemic preparedness | Establish pandemic surveillance, critical-staff identification, split-team capability, remote-working arrangements, cross-training and employee-health protocols. |
| Natural | Regional Natural Disaster | Reduce geographic and supplier concentration | Identify cross-border dependencies; diversify critical providers where practicable; assess geographic concentration; maintain alternative communications and supply arrangements. |

 

#### **Technological Crisis**

BDCB's technology prevention strategy is particularly important because the failure of key infrastructure could disrupt national payment and settlement activity.

BDCB states that safe, reliable, and efficient financial-market infrastructures are key components supporting financial stability and economic growth.

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Technological | Hardware Failure | Eliminate single points of failure | Use resilient architecture, redundant critical components, lifecycle management, preventive maintenance and proactive hardware-health monitoring. |
| Technological | Software / Application Failure | Strengthen application resilience | Maintain supported software; conduct testing before deployment; use redundancy where appropriate; monitor applications; maintain tested rollback capability. |
| Technological | Network Failure | Network resilience and path diversity | Remove critical single points of failure; maintain redundant network equipment, routes and connectivity; test automatic and manual failover. |
| Technological | Telecommunications Failure | Communications diversity | Use diverse telecommunications carriers, physical routes and alternative communications channels where justified by criticality. |
| Technological | Cyberattack | Defence-in-depth cybersecurity | Apply layered preventive security including secure configuration, access controls, patching, endpoint protection, network segmentation, vulnerability management and security monitoring. |
| Technological | Ransomware | Prevent initial compromise and lateral movement | Strengthen email and endpoint security; restrict privileges; segment networks; maintain secure backups; patch vulnerabilities; conduct phishing awareness and privileged-access reviews. |
| Technological | DDoS Attack | DDoS prevention and traffic protection | Maintain upstream DDoS protection, traffic filtering, capacity management and appropriate service-provider arrangements. |
| Technological | IT Sabotage / Malicious Insider | Privileged-access and insider-risk controls | Apply least privilege, segregation of duties, privileged-access management, logging, monitoring, access reviews and rapid revocation of unnecessary access. |
| Technological | Data Corruption / Loss of Integrity | Data-integrity protection | Implement validation, reconciliation, controlled changes, database integrity monitoring, backups and mechanisms to detect unauthorised alteration. |
| Technological | Data Breach | Prevent unauthorised disclosure | Apply data classification, encryption, least privilege, DLP where appropriate, secure transfer controls, monitoring and periodic access certification. |
| Technological | RTGS System Disruption | High-availability payment-system architecture | Maintain resilient infrastructure, redundancy, capacity management, preventive maintenance, controlled changes and end-to-end monitoring. RTGS processes large-value and urgent interbank payments and is a systemically important component of BDCB's payment infrastructure. |
| Technological | ACH System Disruption | Resilient clearing infrastructure | Maintain resilient application, database, network and interface architecture; monitor dependencies; control changes and maintain processing-capacity headroom. ACH payment obligations ultimately feed into RTGS settlement. |
| Technological | CSD System Disruption | Resilient securities infrastructure | Protect application, database, communications and settlement dependencies; maintain strong change and access controls. |
| Technological | Data Centre Failure | Facility and infrastructure resilience | Maintain redundant power, UPS, generators, cooling, environmental monitoring, fire protection, physical security and geographic resilience. |
| Technological | DR / Failover Failure | Continuous recovery-readiness assurance | Maintain configuration consistency between primary and recovery environments; test failover regularly; monitor replication; manage capacity and dependencies. |
| Technological | Failed Technology Change / Upgrade | Strong change and release management | Require risk assessment, segregation of environments, testing, approvals, deployment controls, blackout periods for high-risk changes and tested rollback procedures. |
| Technological | Authentication / Identity Failure | Identity-service resilience | Maintain redundant authentication infrastructure, secure emergency-access mechanisms, privileged-access controls and tested identity-service failover. |
| Technological | Capacity / Performance Failure | Proactive capacity management | Establish performance thresholds, trend monitoring, stress testing and capacity forecasts for critical platforms. |

#### **Confrontation Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Confrontation | Public Protest / Demonstration | Stakeholder engagement and early-warning monitoring | Monitor emerging stakeholder concerns; maintain communication channels; identify potential protest indicators; engage relevant stakeholders before issues escalate where appropriate. |
| Confrontation | Picketing / Blockade | Prevent access conflict | Establish controlled perimeter arrangements, alternative entrances, liaison arrangements with authorities and protocols for managing protesters without unnecessary escalation. |
| Confrontation | Sit-in / Occupation | Access and visitor controls | Maintain visitor identification, controlled access, security awareness and clear protocols governing access to restricted areas. |
| Confrontation | Regulatory Dispute | Transparent regulatory engagement | Maintain documented regulatory processes, clear communications, appropriate review mechanisms and structured engagement with affected entities. |
| Confrontation | Consumer / Public Backlash | Early issue resolution | Monitor complaints and public concerns; identify recurring themes; provide timely factual information; escalate emerging issues before they develop into broader confrontation. |
| Confrontation | Coordinated Online Activism | Digital stakeholder monitoring | Monitor public channels for emerging campaigns; establish communication thresholds; maintain factual communication material for rapidly developing issues. |

#### **Malevolence Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Malevolence | Terrorism / Hostile Attack | Layered protective security | Apply physical security, controlled access, perimeter protection, CCTV, visitor management, security intelligence awareness and liaison with relevant authorities. |
| Malevolence | Bomb Threat | Threat deterrence and detection | Maintain access controls, mail-handling procedures, suspicious-item awareness, perimeter security and staff reporting mechanisms. |
| Malevolence | Sabotage | Protect critical assets | Restrict access to critical plant, technology and operational areas; maintain surveillance, tamper detection and segregation of duties. |
| Malevolence | Cyberattack | Reduce exploitable attack surface | Apply layered cybersecurity, vulnerability remediation, strong authentication, segmentation, endpoint security and continuous security monitoring. |
| Malevolence | Cyber Espionage | Protect sensitive information | Apply need-to-know access, encryption, secure communications, monitoring, privileged-access restrictions and counter-phishing awareness. |
| Malevolence | Malicious Data Manipulation | Integrity and authorisation controls | Apply dual controls, transaction validation, reconciliation, segregation of duties, immutable logs and exception monitoring. |
| Malevolence | Threat Against Personnel | Personnel-security programme | Establish threat-reporting mechanisms, executive protection measures where warranted, controlled disclosure of sensitive personal information and security liaison. |
| Malevolence | Extortion / Blackmail | Reduce exploitable information and access | Protect sensitive information, strengthen personnel security, maintain reporting channels and provide employees with clear escalation procedures. |

#### **Organisational Misdeeds — Skewed Management Values**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Organisational Misdeeds — Skewed Management Values | Stakeholder Interests Inadequately Considered | Strengthen stakeholder-impact governance | Require material decisions to consider financial institutions, consumers, employees, public interest and other affected stakeholders. |
| Organisational Misdeeds — Skewed Management Values | Excessive Short-Term Priority | Balance short- and long-term objectives | Include resilience, risk, governance and longer-term consequences in material management and investment decisions. |
| Organisational Misdeeds — Skewed Management Values | Inadequate Priority to Resilience | Embed resilience in governance | Establish resilience responsibilities, management oversight, appropriate funding and periodic reporting of resilience weaknesses. |
| Organisational Misdeeds — Skewed Management Values | Public Interest Insufficiently Considered | Public-interest impact assessment | Assess significant policy and operational decisions for unintended consumer, market or financial-system consequences. |
| Organisational Misdeeds — Skewed Management Values | Risk Culture Failure | Strengthen speak-up and challenge culture | Encourage constructive challenge, protect escalation channels, reinforce management accountability and monitor behavioural indicators. |

#### **Organisational Misdeeds — Deception**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Organisational Misdeeds — Deception | Concealment of Material Information | Mandatory escalation and disclosure controls | Establish clear thresholds requiring material issues to be escalated to appropriate governance bodies. |
| Organisational Misdeeds — Deception | Misrepresentation of Information | Independent verification | Require review, validation and approval of material management, regulatory and public information. |
| Organisational Misdeeds — Deception | Manipulation of Reports / Records | Data and record integrity controls | Apply segregation of duties, audit trails, controlled amendments, reconciliation and independent review. |
| Organisational Misdeeds — Deception | Misleading Public Communication | Communication governance | Require fact verification, authorised spokespersons, appropriate legal or subject-matter review and controlled approval of material communications. |
| Organisational Misdeeds — Deception | Concealment of Significant Incident | Incident-reporting governance | Define mandatory notification thresholds, reporting deadlines, escalation responsibilities and independent assurance mechanisms. |

#### **Organisational Misdeeds — Management Misconduct**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Organisational Misdeeds — Management Misconduct | Fraud | Anti-fraud control framework | Maintain segregation of duties, approval limits, reconciliation, monitoring, audit, whistleblowing arrangements and fraud-awareness programmes. |
| Organisational Misdeeds — Management Misconduct | Corruption / Bribery | Anti-bribery controls | Maintain conflict declarations, gifts and hospitality requirements, procurement controls, due diligence and protected reporting channels. |
| Organisational Misdeeds — Management Misconduct | Abuse of Authority | Governance and accountability | Define authorities, require documented decisions, establish independent oversight and provide safe escalation channels. |
| Organisational Misdeeds — Management Misconduct | Conflict of Interest | Conflict-management programme | Require periodic declarations, recusal where appropriate, independent review and documented management of conflicts. |
| Organisational Misdeeds — Management Misconduct | Deliberate Control Breach | Control accountability | Monitor exceptions, require approval for deviations, maintain audit trails and investigate repeated or deliberate circumvention. |
| Organisational Misdeeds — Management Misconduct | Misuse of Confidential Information | Information-governance controls | Apply need-to-know access, confidentiality obligations, monitoring, secure information handling and sanctions for misuse. |

#### **Workplace Violence Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Due to Workplace Violence | Physical Assault | Workplace violence prevention programme | Establish behavioural standards, reporting mechanisms, security presence, employee awareness and early intervention arrangements. |
| Due to Workplace Violence | Armed Intruder | Access and protective security | Maintain controlled entrances, visitor screening, security monitoring and mechanisms for rapidly reporting suspicious behaviour. |
| Due to Workplace Violence | Threatened Violence | Early threat assessment | Establish confidential reporting and multidisciplinary assessment of credible threats before escalation. |
| Due to Workplace Violence | Employee-on-Employee Violence | Conflict management and early intervention | Provide grievance channels, management intervention, HR escalation and behavioural-risk assessment. |
| Due to Workplace Violence | Violent Visitor | Visitor and public-access controls | Use controlled access, trained security personnel, interview-room safety arrangements and escalation procedures. |
| Due to Workplace Violence | Domestic Violence Extending into Workplace | Employee protection arrangements | Provide confidential reporting, HR/security coordination and workplace safety arrangements for identified risks. |

#### **Rumours, Misinformation and Disinformation Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Due to Rumours | False Rumour About BDCB | Proactive communication and monitoring | Monitor information channels; publish accurate information promptly; maintain trusted official communication channels. |
| Due to Rumours | False Rumour About Financial-System Stability | Confidence-protection communication | Monitor emerging narratives; maintain validated financial-stability messages; coordinate facts with relevant financial institutions and authorities where appropriate. |
| Due to Rumours | False Rumour About Currency | Authoritative currency communication | Maintain easily accessible official information concerning currency and rapidly correct significant misinformation. |
| Due to Rumours | False Rumour About Bank Failure | Early detection and coordinated correction | Monitor emerging claims; establish verification channels with supervised institutions; prepare rapid factual communication when warranted. |
| Due to Rumours | False Rumour About Payment-System Failure | Payment-status communication | Establish authoritative status information and rapid verification procedures for RTGS, ACH and other important payment services. |
| Due to Rumours | Deepfake of BDCB Official | Authentication of official communications | Maintain verified channels, consistent official branding, rapid authentication processes and monitoring for impersonation. |
| Due to Rumours | Fake BDCB Announcement / Impersonation | Digital brand protection | Monitor fraudulent domains and accounts; maintain reporting/takedown procedures and educate stakeholders on recognising official BDCB communications. |

Public confidence is particularly relevant to central banking and financial stability. BDCB notes that trust and public confidence in financial institutions are important benefits of a stable financial system.

#### **Lack of Fund Crisis**

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Lack of Fund | Liquidity Stress at Financial Institution | Prudential monitoring and early intervention | Monitor relevant liquidity indicators, identify deterioration early, escalate supervisory concerns and require remedial action where appropriate under BDCB's authority. |
| Lack of Fund | Solvency Deterioration | Early-warning financial supervision | Monitor capital, asset quality, profitability, liquidity and other prudential indicators; conduct appropriate supervisory follow-up. |
| Lack of Fund | Bank Run / Rapid Withdrawal | Confidence and liquidity preparedness | Monitor emerging liquidity and confidence indicators; maintain supervisory communication; identify misinformation or other triggers capable of accelerating withdrawals. |
| Lack of Fund | Multiple Institutions Under Stress | System-wide surveillance | Monitor common exposures, concentration, liquidity conditions and correlated vulnerabilities across institutions. |
| Lack of Fund | Market Liquidity Disruption | Liquidity monitoring | Maintain visibility of relevant market and banking-system liquidity conditions and predefined escalation thresholds. |
| Lack of Fund | Settlement Liquidity Shortage | Settlement-liquidity management | Monitor participant settlement positions and liquidity arrangements and identify emerging shortages before payment obligations are affected. |
| Lack of Fund | Financial Contagion | Contagion surveillance | Assess interconnections, common exposures and confidence channels through which financial stress could spread. |
| Lack of Fund | Critical Supplier Financial Failure | Supplier financial-risk management | Conduct financial due diligence on critical providers, monitor deterioration and maintain substitution or exit arrangements. |

BDCB provides overnight standing facilities intended to support banks' liquidity management and describes these facilities as tools for effective and efficient liquidity management.

#### **Due to Natural Factors**

For CST1 purposes, **“Natural”** and **“Due to Natural Factors”** can be distinguished where useful. “Natural” can capture the initiating hazard, while “Due to Natural Factors” can capture **secondary crises caused by the natural event**.

 

| Crisis Type | Types of Threats / Crisis Scenario | Crisis Prevention Strategy | Details of Crisis Prevention Strategy |
| --- | --- | --- | --- |
| Due to Natural Factors | Denial of Access Due to Flooding | Protect access and reduce site dependency | Assess access-route vulnerability, maintain alternative routes and remote-working capability, and establish early closure triggers. |
| Due to Natural Factors | Workforce Shortage Due to Pandemic | Workforce resilience | Cross-train critical roles, maintain succession arrangements, enable remote work and establish minimum staffing requirements. |
| Due to Natural Factors | Power Failure Due to Severe Weather | Power resilience | Maintain UPS, generators, fuel arrangements, maintenance and load testing for critical facilities. |
| Due to Natural Factors | Telecommunications Failure Due to Storm | Communications resilience | Diversify carriers and routes and maintain alternative emergency communications. |
| Due to Natural Factors | Data Centre Impact Due to Flood / Weather | Protect critical technology facilities | Use site-risk assessment, physical protection, geographic separation and alternative processing capability. |
| Due to Natural Factors | Critical Supplier Failure Due to Regional Disaster | Supplier geographic resilience | Map supplier locations and fourth parties, identify concentration and establish alternative sources where feasible. |
| Due to Natural Factors | Simultaneous Financial-Sector Disruption | Sector-wide preparedness | Assess severe-but-plausible scenarios where BDCB and multiple financial institutions are affected simultaneously. |
| Due to Natural F |  |  |  |

#### **Principles for Developing the Crisis Prevention Strategy**

The CST1 table should not be interpreted as a collection of controls assembled independently for each scenario. BDCB should develop **preventive capabilities that work across multiple crisis types**.

Several preventive capabilities are particularly important.

**Governance and accountability** ensure that significant risks have owners, escalation thresholds and management oversight.

**Early-warning capability** allows BDCB to identify deteriorating conditions before an incident becomes a strategic crisis.

**Physical and personnel security** reduces exposure to malevolence, workplace violence, sabotage and confrontation.

**Technology and cyber resilience** reduce both accidental and deliberate technology disruptions.

**Prudential and financial-system surveillance** supports early identification of liquidity, solvency and contagion concerns.

**Stakeholder and communication monitoring** helps identify confrontation, rumours and confidence risks before they escalate.

**Third-party risk management** reduces dependence on individual suppliers and common external points of failure.

**Risk culture and organisational governance** help prevent internal behaviour from becoming the initiating cause of a crisis.

#### **Prevention Versus Preparedness**

Maintain a clear distinction between **prevention** and **preparedness**.

Prevention attempts to stop the crisis from occurring or reduce the probability of escalation. Examples include access controls, preventive maintenance, patch management, prudential monitoring, employee screening, supplier due diligence and early stakeholder engagement.

Preparedness assumes that prevention may fail. It therefore includes crisis plans, alternate sites, crisis communications, business continuity, disaster recovery, exercises and Crisis Management Team readiness.

BDCB requires both.

For example, cybersecurity controls may reduce the likelihood of ransomware, but they cannot guarantee that ransomware will never occur. Similarly, prudential supervision can reduce financial-sector vulnerabilities but cannot eliminate every possible source of institutional stress.

The appropriate principle is therefore:

**Prevent where practicable → Detect deterioration early → Intervene before escalation → Prepare for prevention failure → Respond strategically if crisis occurs**

For the eBook, convert this sequence into a **standalone professional diagram** rather than retaining the text-arrow format.

#### **Relationship with the Crisis Risk Assessment**

CMS Part 1 should use the results from the preceding Crisis Risk Assessment.

The implementation sequence is:

**CRA Part 1-1 — List of Threats → CRA Part 1-2 — List of Crisis Scenarios → CRA Part 2 — Treatment and Control → CRA Part 3 — Risk Impact and Likelihood Assessment → CMS Part 1 — Crisis Prevention Strategy**

For the eBook, present this as a **standalone professional diagram**.

This sequence ensures that prevention measures are not selected generically. They are linked to the threats and crisis scenarios identified for BDCB and informed by the controls and risk assessments already undertaken.

#### **From Prevention to Early Intervention**

An effective Crisis Prevention Strategy should create multiple opportunities to stop escalation.

For example, a technological crisis could progress through:

**Technical Vulnerability → Warning Indicator → Control Failure → Technology Incident → Critical Service Impact → Stakeholder Impact → Crisis**

The objective of CMS Part 1 is to establish preventive measures as far to the **left** of this progression as practicable.

A financial crisis could similarly develop through:

**Financial Weakness → Early-Warning Indicator → Liquidity Stress → Customer Concern → Rapid Withdrawals → Contagion Risk → Financial-Stability Crisis**

Again, the objective is to identify the deteriorating condition and intervene before it reaches the crisis stage.

Convert both sequences into **individual professional diagrams** for the eBook.

#### **Management Validation of the CST1 Table**

The Crisis Prevention Strategy Table should ultimately be validated by the relevant BDCB risk, business, and functional owners. For each scenario, management should confirm:

- whether the scenario is applicable;
- whether the preventive strategy is already implemented;
- whether the existing preventive measures are sufficiently effective;
- who owns the preventive controls;
- what indicators demonstrate deterioration;
- what control gaps remain;
- what additional preventive measures are required;
- what resources and implementation dates apply; and
- when failure of prevention should trigger escalation into crisis preparedness or response.

This validation converts the table from a generic crisis-prevention catalogue into an actionable BDCB Crisis Management Strategy.

 

[![Banner \[CM\] \[Summing Up\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/2062bf33-3f6e-4162-bd55-6eca25b8e8a0.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/2062bf33-3f6e-4162-bd55-6eca25b8e8a0)

**CMS Part 1 — Crisis Prevention Strategy for Brunei Darussalam Central Bank** establishes the preventive component of BDCB's Crisis Management Strategy.

Its purpose is to reduce the probability that the threats and crisis scenarios identified through the CRA develop into events requiring full strategic crisis-management activation.

The approach covers the principal crisis types of **Natural, Technological, Confrontation, Malevolence, Organisational Misdeeds—comprising Skewed Management Values, Deception and Management Misconduct—Workplace Violence, Rumours, Lack of Funds, and crises arising due to Natural Factors**.

For BDCB, prevention matters because disruptions may have consequences beyond the organisation.

BDCB's objectives include financial-system stability and efficient payment systems, while its responsibilities include monetary policy, currency issuance and supervision of financial institutions.

BDCB also operates RTGS, ACH and CSD, creating important dependencies between its resilience and Brunei Darussalam's financial infrastructure.

A robust Crisis Prevention Strategy should therefore answer four questions for every significant scenario:

- **What could initiate the crisis?**
- **What can BDCB reasonably do to prevent it?**
- **What indicators would show that preventive controls are failing?**
- **At what point should BDCB move from prevention to crisis preparedness and strategic response?**

The resulting CST1 table bridges **risk assessment and active crisis management**.

It allows BDCB to move from identifying threats to establishing targeted preventive measures, strengthening early-warning capability and reducing the likelihood that operational events, technology failures, financial-sector stresses, stakeholder issues or external hazards develop into major crises.

 

 

**[![\[CM\] \[BDCB\] \[3/4 Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2)**

| **eBook 3: Starting Your CM Implementation** |  |  |  |
| --- | --- | --- | --- |
| \[RAR\] \[P1-1\] | \[RAR\] \[P1-2\] | \[RAR\] \[P1-3\] | \[RAR\] \[P2\] |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-2\] List of Crisis Scenarios \[Natural and Man-made\]](https://no-cache.hubspot.com/cta/default/3893111/029d6134-feb9-446e-884c-562eb4fd8e70.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/029d6134-feb9-446e-884c-562eb4fd8e70) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-3\] List of Crisis Scenarios \[Technology\] ](https://no-cache.hubspot.com/cta/default/3893111/883a9c65-15e5-408d-a406-3835732e8f16.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/883a9c65-15e5-408d-a406-3835732e8f16) | [![\[CM\] \[BDCB\] \[E3\] \[RAR\] \[P2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf) |
| \[RAR\] \[P3\] | \[CMS\] \[P1\] | \[CMS\] \[P2\] | eBook 3 |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/7a44ac98-15cf-427b-b8fa-011061502369.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7a44ac98-15cf-427b-b8fa-011061502369) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P2\] Crisis Response Strategy](https://no-cache.hubspot.com/cta/default/3893111/0dacc52b-d723-44a2-999f-66752a10d897.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/0dacc52b-d723-44a2-999f-66752a10d897) | [![eBook Cover \[CM\] \[BDCB\] \[E3\] \[2D\]](https://no-cache.hubspot.com/cta/default/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2) |
|  |  |  |  |

 

#### More Information About Crisis Management Blended/ Hybrid Learning Courses

To learn more about the course and schedule, click the buttons below for CM-300 Crisis Management Implementer \[CM-3\] and CM-5000 Crisis Management Expert Implementer \[CM-5\].

| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/03294547-1df3-435c-9243-971c3d9bb6ce.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/03294547-1df3-435c-9243-971c3d9bb6ce) |
| --- | --- | --- |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739) | [![\[BL-CM\] \[5\] Register](https://no-cache.hubspot.com/cta/default/3893111/82024308-16f4-4491-98be-818a882c6286.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/82024308-16f4-4491-98be-818a882c6286) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911) | Please feel free to send us a note if you have any questions. [![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![FAQ BL-CM-5 CM-5000](https://no-cache.hubspot.com/cta/default/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/83d00c12-c51c-4476-9902-69f9b7667a91.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/83d00c12-c51c-4476-9902-69f9b7667a91) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e) |

### Your Comments Here:

 

![CTA Banner\_OR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_OR.jpg "CTA Banner_OR")

---

![CTA Banner\_ORA](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ORA.jpg "CTA Banner_ORA")

---

![CTA Banner\_BCM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_BCM.jpg "CTA Banner_BCM")

---

![CTA Banner\_ITDR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ITDR.jpg "CTA Banner_ITDR")

---

![CTA Banner\_CM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_CM.jpg "CTA Banner_CM")

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Moh Heng Goh",
    "url" : "https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh"
  },
  "dateModified" : "2026-10-09T08:22:23.112Z",
  "datePublished" : "2026-10-07T08:21:48.000Z",
  "headline" : "[CM] [BDCB] [E3] [CMS] [P1] Crisis Prevention Strategy",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cms-p1-crisis-prevention-strategy",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```