---
title: [CM] [BDCB] [E3] [CRA] [P1-1] List of Threats
description: [CM] [BDCB] [E3] [CRA] [P1-1] List of Threats
image: https://blog.bcm-institute.org/hubfs/BDCB%20Graphic%20Folder/BDCB%20CM%20Graphic%20Folder/BDCB%20CM%20E3%20Morepost/%5BCM%5D%20%5BBDCB%5D%20%5BE3%5D%20%5BCRA%5D%20%5BP1-1%5D%20List%20of%20Threats.jpg
---

.

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

##### Crisis Management in Action: A Practical Implementation Guide for BDCB

![CM Ai Gen\_with Cert Logo\_v3-21](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20CM%20%5BAi%20Gen%20Blog%20Photo%5D/BB%20CM%20v3%20Jun%202025/CM%20Ai%20Gen_with%20Cert%20Logo_v3-21.jpg?width=2000&height=1333&name=CM%20Ai%20Gen_with%20Cert%20Logo_v3-21.jpg "CM Ai Gen_with Cert Logo_v3-21")

# \[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-1\] List of Threats

[![\[CM\] \[BDCB\] \[Full Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07)

The first stage of Crisis Risk Assessment (CRA) is to establish a structured list of threats and crisis scenarios that could disrupt the operations, services, people, infrastructure, technology, suppliers, or stakeholders of the **Brunei Darussalam Central Bank (BDCB)**.

The BCMpedia Risk Analysis and Review, in Crisis Management, calls this a Crisis Risk Assessment (CRA) and explains that natural and man-made threats can disrupt organisational operations or services, recommending that threats be assessed at both the country and organisational levels.

It also notes that threats are site-specific and may need to be assessed separately for different operating locations.

BCMpedia groups threats into four broad scenarios: Denial of Access, Unavailability of People, Disruption of Supply Chain, and Equipment and IT-related Disruption.

For this BDCB assessment, Denial of Access has been further separated into **Natural Disaster** and **Man-made Disaster**, resulting in the five crisis types specified for this chapter.

The assessment needs to reflect BDCB's particular role as Brunei Darussalam's central bank.

[![\[Banner\] \[Title\] \[CM\] \[E3\] Part 1-1\_ List of Threats](https://no-cache.hubspot.com/cta/default/3893111/92df076e-1b01-46d4-bf41-d49c0428deb4.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/92df076e-1b01-46d4-bf41-d49c0428deb4)

[Moh Heng Goh](https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh) Oct 7, 2026

###### Crisis Management Certified Planner-Specialist-Expert

##### [![\[CM\] \[BDCB\] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/062c8304-1699-4f7b-a38d-f128d9815304.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/062c8304-1699-4f7b-a38d-f128d9815304)

[![\[Banner\] \[Title\] \[CM\] \[E3\] Part 1-1\_ List of Threats](https://no-cache.hubspot.com/cta/default/3893111/92df076e-1b01-46d4-bf41-d49c0428deb4.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/92df076e-1b01-46d4-bf41-d49c0428deb4)

### **[![\[CM\] \[Table\] \[CRA 1-1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/37e085f5-e646-488e-acec-bcbd9951b666.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/37e085f5-e646-488e-acec-bcbd9951b666)**

### **List of Threats for Brunei Darussalam Central Bank (BDCB)**

#### **Introduction**

[![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6)The first stage of Crisis Risk Assessment (CRA) is to establish a structured list of threats and crisis scenarios that could disrupt the operations, services, people, infrastructure, technology, suppliers, or stakeholders of the Brunei Darussalam Central Bank (BDCB).

The BCMpedia Risk Analysis and Review, in Crisis Management, calls this a Crisis Risk Assessment (CRA) and explains that natural and man-made threats can disrupt organisational operations or services, recommending that threats be assessed at both the country and organisational levels.

It also notes that threats are site-specific and may need to be assessed separately for different operating locations.

BCMpedia groups threats into four broad scenarios: Denial of Access, Unavailability of People, Disruption of Supply Chain, and Equipment and IT-related Disruption.

For this BDCB assessment, Denial of Access has been further separated into **Natural Disaster** and **Man-made Disaster**, resulting in the five crisis types specified for this chapter.

The assessment should reflect BDCB's role as Brunei Darussalam's central bank.

Its core functions include issuing and managing currency, conducting monetary policy, and supervising banks and financial institutions. Its objectives also include maintaining financial system stability and supporting efficient payment systems.

BDCB also operates important national payment and settlement infrastructure, including the **Real-Time Gross Settlement (RTGS), Automated Clearing House (ACH), and Central Securities Depository (CSD)** systems.

Accordingly, the table below is a **working threat catalogue for CRA screening**, rather than a statement that every listed event has previously occurred at BDCB.

The two final columns indicate whether the threat is relevant for assessment at the **Brunei country level** and/or at the **BDCB organisational level**. “Yes” means the scenario should be retained for subsequent risk assessment; it does not mean that the event has actually occurred.

#### **List of Threats and Crisis Scenarios**

##### **Denial of Access – Natural Disaster**

##### **Denial of Access – Man-made Disaster**

##### **Unavailability of People**

##### **Disruption to the Supply Chain**

##### **Equipment and IT-Related Disruption**

 

| Crisis Type | Type of Threat / Crisis Scenario | Description of Threat | Country Level | Organisation Level |
| --- | --- | --- | --- | --- |
| Denial of Access – Natural Disaster | Flood | Prolonged or extensive flooding may make BDCB premises inaccessible, disrupt transport routes, affect utilities and telecommunications, and prevent employees or service providers from reaching critical locations. | Yes | Yes |
|  | Flash Flood | Rapid flooding with little warning may restrict access to BDCB premises, damage infrastructure or equipment, and create immediate employee-safety and evacuation requirements. Flood and flash flood are specifically included in BCMpedia's denial-of-access threat catalogue. | Yes | Yes |
|  | Severe Rain / Thunderstorm | Intense rainfall and thunderstorms may create local flooding, transport disruption, water ingress, electrical problems, and difficulty accessing BDCB facilities. | Yes | Yes |
|  | Lightning | Lightning may damage electrical, telecommunications, or ICT infrastructure and could cause power or equipment failure, even if the BDCB premises remain accessible. | Yes | Yes |
|  | Strong Wind / Windstorm | Strong winds can damage buildings, external equipment, telecommunications infrastructure, and transport networks, potentially restricting physical access and affecting supporting services. | Yes | Yes |
|  | Tropical Storm | A severe regional weather system could bring heavy rain, strong winds, flooding, power interruptions, and transport disruption, creating simultaneous impacts across BDCB and its external dependencies. | Yes | Yes |
|  | Haze / Poor Air Quality | Severe haze may make travel or prolonged outdoor activity unsafe, affect vulnerable employees, and require work-from-home, split-team, or reduced on-site operations. BCMpedia identifies haze under both denial-of-access and people-related threats. | Yes | Yes |
|  | Earthquake Tremors | Regional seismic activity could affect building safety, utilities, telecommunications, or employee confidence and may require precautionary evacuation and facility inspection. | Yes | Yes |
|  | Fire – Wild / External | A significant external fire or smoke event could require evacuation, close roads, restrict access, or disrupt nearby utilities, even if BDCB's premises are not directly damaged. | Yes | Yes |
| Denial of Access – Man-made Disaster | Building Fire | Fire within a BDCB facility may require immediate evacuation, deny access to premises, damage equipment and records, and require relocation of critical activities. | Yes | Yes |
|  | Bomb Threat | A credible or suspected explosive threat could require evacuation and security cordons, preventing access until authorities declare the premises safe. Bomb threat/explosion is included in BCMpedia's denial-of-access category. | Yes | Yes |
|  | Explosion | An accidental or deliberate explosion could cause casualties, structural damage, evacuation, and prolonged denial of access to affected facilities. | Yes | Yes |
|  | Terrorism / Hostile Attack | A terrorist or hostile act directed at BDCB, the financial sector, government infrastructure, or nearby locations could create security restrictions, evacuation, lockdown, and major crisis-management requirements. | Yes | Yes |
|  | Civil Disturbance / Public Disorder | Demonstrations, disorder, or security operations around a BDCB location could prevent employees, visitors, and suppliers from accessing premises and could create reputational and communication issues. | Yes | Yes |
|  | Suspicious Package / Security Threat | Discovering a suspicious item may require evacuation, lockdown, police intervention, and a temporary suspension of normal operations. | Yes | Yes |
|  | Hazardous Material Incident | A chemical, gas, or other hazardous material release in or near BDCB premises could create an exclusion zone and require evacuation or shelter-in-place arrangements. | Yes | Yes |
|  | Major Transport Accident Near Premises | A serious road, aviation, or other transport incident close to BDCB facilities could restrict access, damage infrastructure, or trigger emergency services exclusion zones. | Yes | Yes |
|  | Prolonged Power Outage | Failure of public electricity supply may render premises or technology infrastructure unusable after UPS and generator resilience is exhausted. BCMpedia includes power outage among denial-of-access threats. | Yes | Yes |
| Unavailability of People | Infectious Disease / Pandemic | A widespread infectious disease may cause high absenteeism, quarantine, travel restrictions, remote working, and simultaneous workforce shortages across BDCB, financial institutions, and suppliers. | Yes | Yes |
|  | Localised Infectious Disease Outbreak | An outbreak affecting a BDCB office, team, or critical function could require isolation, workplace closure, or team segregation without developing into a national pandemic. | Yes | Yes |
|  | Loss of Key Appointment Holder | Sudden death, illness, resignation, or prolonged unavailability of a senior executive or specialist could impair decision-making or critical activities where knowledge or authority is concentrated. BCMpedia specifically identifies loss of key appointment holders as a people threat. | Yes | Yes |
|  | Multiple Critical Staff Unavailable | Simultaneous absence of employees with specialist expertise may prevent execution of time-sensitive monetary, supervisory, payment, currency, technology, or crisis-management activities. | Yes | Yes |
|  | Workplace Accident / Safety Incident | A serious workplace accident could injure employees, make part of a facility inaccessible, and trigger investigations and operational disruption. | Yes | Yes |
|  | Workplace Violence | Violence, threats, or aggressive behaviour involving employees, visitors, or external persons could create casualties, lockdown requirements, and psychological impacts on staff. BCMpedia identifies workplace violence as a people-related threat. | Yes | Yes |
|  | Labour Dispute / Strike Affecting Essential Services | Even where BDCB's own workforce remains available, industrial action affecting transportation, utilities, telecommunications, or critical suppliers could prevent employees or service providers from performing essential activities. | Yes | Yes |
|  | Transport Disruption Affecting Workforce | Severe transport interruption could prevent sufficient employees from reaching BDCB locations, particularly where critical functions require on-site access. | Yes | Yes |
|  | Mass Casualty / National Emergency | A major national emergency may affect employee availability through injury, family responsibilities, transport restrictions, or deployment of national emergency measures. | Yes | Yes |
| Disruption to the Supply Chain | Loss of Specialised Technology Vendor | Failure or prolonged unavailability of a specialist ICT supplier could delay maintenance, incident response, system restoration, or replacement of critical technology. BCMpedia identifies loss of specialised vendors, partners, or suppliers as a supply-chain threat. | Yes | Yes |
|  | Telecommunications Provider Failure | Failure of a telecommunications provider could affect BDCB connectivity, communications, remote access, and links with financial institutions or external systems. | Yes | Yes |
|  | Utility Supplier Failure | Prolonged interruption to electricity, water, or other essential utilities could affect premises and technology operations. | Yes | Yes |
|  | Critical ICT / Cloud Service Provider Outage | Failure of an externally provided technology service could make applications or information unavailable and constrain BDCB's ability to control recovery directly. BDCB's regulatory framework separately recognises technology and IT third-party risk. | Yes | Yes |
|  | Cyberattack on Critical Supplier | A cyber incident at an external provider could interrupt BDCB services, expose information, or propagate malicious activity into connected environments. | Yes | Yes |
|  | Failure of the Security Service Provider | Loss or degradation of outsourced physical-security services could affect building access control, employee safety, and protection of sensitive facilities. | Yes | Yes |
|  | Failure of Critical Equipment Supplier | Inability to obtain replacement hardware, network devices, power equipment, or specialised components could extend recovery following an equipment failure. | Yes | Yes |
|  | Logistics / Transportation Disruption | Road closures, border restrictions, transport failures, or other logistics interruptions could delay delivery of critical equipment, supplies, or currency-related resources. | Yes | Yes |
|  | Supplier Financial Failure | Insolvency or severe financial distress at a critical supplier could result in sudden termination or degradation of essential contracted services. | Yes | Yes |
|  | Regulatory / Legal Failure Affecting Supplier | A provider may become unable to continue delivering a service because of licensing, compliance, sanctions, contractual, or other legal issues. Regulatory/legal violation appears within BCMpedia's supply-chain threat group. | Yes | Yes |
|  | Concentration Risk / Common Supplier Failure | A single provider supporting BDCB and multiple financial institutions could create a common point of failure and potentially turn an organisational disruption into a sector-wide event. | Yes | Yes |
| Equipment and IT-Related Disruption | Hardware Failure | Server, storage, end-user device, or other hardware failure could make critical applications or information unavailable. BCMpedia explicitly identifies hardware and software failures. | Yes | Yes |
|  | Software / Application Failure | Defects, corruption, or application errors could interrupt critical BDCB processes even where the underlying infrastructure remains available. | Yes | Yes |
|  | Network Failure | Local or wide-area network failure could prevent communication between systems, locations, users, and external parties. BCMpedia specifically identifies LAN/WAN network failure. | Yes | Yes |
|  | Telecommunications Failure | Loss of telephone or communications services could impede coordination with employees, financial institutions, authorities, and suppliers. | Yes | Yes |
|  | Cyberattack | Malicious compromise of BDCB technology could cause service disruption, unauthorised access, data loss, integrity concerns, and potentially wider financial-sector consequences. BDCB's regulatory materials include technology-risk and cyber-intrusion requirements, reflecting the importance of cyber resilience in the financial sector. | Yes | Yes |
|  | Ransomware | Malware may encrypt systems, steal information, damage backups, and create extortion demands, potentially causing prolonged disruption while restoring system integrity. | Yes | Yes |
|  | Distributed Denial-of-Service (DDoS) | High volumes of malicious network traffic could make internet-facing systems unavailable and disrupt communications or digital services. | Yes | Yes |
|  | IT Sabotage | Deliberate damage or manipulation by an insider or external actor could disable technology or corrupt information. BCMpedia specifically identifies IT sabotage. | Yes | Yes |
|  | Data Corruption / Loss of Data Integrity | Systems may remain available while records become inaccurate, incomplete, or untrustworthy, potentially requiring processing to stop until integrity is restored. | Yes | Yes |
|  | Data Breach / Information Leakage | Unauthorised access to sensitive supervisory, operational, financial, or employee information could create confidentiality, legal, regulatory, and reputational consequences. | Yes | Yes |
|  | RTGS System Disruption | Failure of BDCB's RTGS could disrupt urgent, large-value interbank payments. BDCB describes RTGS as the heart of the national payment system and emphasises that a systemically important payment system must remain reliable, robust, and resilient. | Yes | Yes |
|  | ACH System Disruption | ACH failure could delay bulk electronic transactions and clearing activities and could create downstream settlement impacts because ACH transactions settle through RTGS. | Yes | Yes |
|  | CSD System Disruption | Unavailability or data-integrity problems affecting CSD could disrupt securities registration and settlement-related activity. BDCB's CSD leverages RTGS for securities settlement. | Yes | Yes |
|  | Data Centre Failure | Loss of a primary technology facility through infrastructure, environmental, electrical, or technical failure could make multiple systems unavailable simultaneously. | Yes | Yes |
|  | Disaster Recovery / Failover Failure | A primary-system outage may escalate into a crisis if the alternate environment fails to activate, lacks current data, or cannot support required processing capacity. | Yes | Yes |
|  | Failed Technology Change / Upgrade | A defective software release, configuration change, patch, or migration could simultaneously disrupt interconnected critical systems. | Yes | Yes |
|  | Database Failure | Database corruption, performance degradation, or unavailability could affect applications that depend on common data services. | Yes | Yes |
|  | Authentication / Identity Service Failure | Failure of identity, authentication, or privileged-access systems could prevent authorised employees from accessing otherwise functioning critical systems. | Yes | Yes |
|  | UPS / Backup Generator Failure | Failure of uninterruptible power supplies or backup generation could cause a technology shutdown when utility power is unavailable. BCMpedia includes UPS and backup generators among facility/equipment failure scenarios. | Yes | Yes |
|  | HVAC / Cooling Failure | Loss of cooling in technology facilities may require equipment shutdown to prevent overheating and hardware damage. BCMpedia explicitly includes air-conditioning and HVAC failures. | Yes | Yes |
|  | Capacity / Performance Failure | Exceptional transaction or processing volumes could degrade systems sufficiently to prevent the timely completion of critical operations even without a complete outage. | Yes | Yes |

#### **Interpretation of Country-Level and Organisation-Level Assessment**

The **Country Level** column considers whether the threat is sufficiently relevant to Brunei Darussalam's operating environment to be considered when BDCB undertakes its CRA.

The **Organisation Level** column considers whether the same scenario could directly or indirectly disrupt BDCB's people, premises, technology, critical functions, suppliers, or responsibilities.

This distinction is important. BCMpedia's methodology specifically notes that organisations should identify threats affecting the country and the organisation, while recognising that individual sites can have different threat profiles.

For example, a telecommunications outage may be a country-level infrastructure event but simultaneously become an organisation-level crisis if it prevents BDCB from communicating with financial institutions or operating critical services.

Conversely, a database corruption incident may originate entirely within BDCB's technology environment while still affecting the wider financial sector.

The entries marked **Yes** should therefore proceed to the subsequent CRA stages to assess likelihood, impact, existing controls, vulnerabilities, escalation potential, and treatment requirements.

The assessment team should validate each entry against actual BDCB locations, historical incidents, control arrangements, supplier dependencies, and current technology architecture rather than treating this catalogue as evidence that each threat has previously materialised.

#### **BDCB-Specific Risk Considerations**

BDCB's threat assessment should place particular emphasis on **interdependency and cascading consequences**.

This follows from BDCB's central role in currency management, monetary policy, financial-sector supervision, and financial-system stability, as well as its responsibilities for efficient payment systems.

Payment infrastructure warrants particular attention. BDCB operates RTGS, ACH, and CSD, and has stated that RTGS is systemically important and needs to remain reliable, robust, and resilient even during market crises.

A technological outage, power disruption, telecommunications failure, or supplier incident should consequently be assessed not only for its effect on BDCB but also for possible effects on participating financial institutions and the wider financial system.

The CRA should therefore avoid assessing threats in isolation. For example, severe flooding could simultaneously produce denial of access, employee shortages, telecommunications disruption, utility failure, and supplier interruption.

Likewise, a cyberattack could cause technology failure, data integrity concerns, payment-system disruption, stakeholder enquiries, and reputational consequences. These combinations are particularly important when the threat catalogue is subsequently converted into **severe but plausible crisis scenarios**.

 

### [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/9f00129b-47f5-4a92-8db4-88b9bc250036.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/9f00129b-47f5-4a92-8db4-88b9bc250036)

The **CRA Part 1-1 List of Threats** establishes the starting point for BDCB's structured Crisis Risk Assessment.

Consistent with BCMpedia's methodology, the catalogue considers natural and man-made denial-of-access events, people-related threats, supply-chain disruptions, and equipment and technology failures.

For BDCB, the key question is not simply whether a threat can occur, but **whether it can impair BDCB's ability to fulfil its critical central-bank responsibilities or create wider consequences for Brunei Darussalam's financial system**.

This is particularly relevant because BDCB's responsibilities extend from monetary policy, currency and financial supervision to the operation and oversight of important payment infrastructure.

The completed threat catalogue should therefore become the input to the next stage of the CRA. BDCB should validate the scenarios against its actual operating environment, remove threats that are demonstrably not applicable, add organisation-specific threats identified by business and technology owners, and then evaluate the retained scenarios for **likelihood, impact, existing controls, residual exposure and crisis escalation potential**.

 

**[![\[CM\] \[BDCB\] \[3/4 Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2)**

| **eBook 3: Starting Your CM Implementation** |  |  |  |
| --- | --- | --- | --- |
| \[RAR\] \[P1-1\] | \[RAR\] \[P1-2\] | \[RAR\] \[P1-3\] | \[RAR\] \[P2\] |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-2\] List of Crisis Scenarios \[Natural and Man-made\]](https://no-cache.hubspot.com/cta/default/3893111/029d6134-feb9-446e-884c-562eb4fd8e70.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/029d6134-feb9-446e-884c-562eb4fd8e70) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-3\] List of Crisis Scenarios \[Technology\] ](https://no-cache.hubspot.com/cta/default/3893111/883a9c65-15e5-408d-a406-3835732e8f16.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/883a9c65-15e5-408d-a406-3835732e8f16) | [![\[CM\] \[BDCB\] \[E3\] \[RAR\] \[P2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf) |
| \[RAR\] \[P3\] | \[CMS\] \[P1\] | \[CMS\] \[P2\] | eBook 3 |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/7a44ac98-15cf-427b-b8fa-011061502369.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7a44ac98-15cf-427b-b8fa-011061502369) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P2\] Crisis Response Strategy](https://no-cache.hubspot.com/cta/default/3893111/0dacc52b-d723-44a2-999f-66752a10d897.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/0dacc52b-d723-44a2-999f-66752a10d897) | [![eBook Cover \[CM\] \[BDCB\] \[E3\] \[2D\]](https://no-cache.hubspot.com/cta/default/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2) |
|  |  |  |  |

 

 

#### More Information About Crisis Management Blended/ Hybrid Learning Courses

To learn more about the course and schedule, click the buttons below for the  CM-300 Crisis Management Implementer \[CM-3\] and the CM-5000 Crisis Management Expert Implementer \[CM-5\].

| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/03294547-1df3-435c-9243-971c3d9bb6ce.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/03294547-1df3-435c-9243-971c3d9bb6ce) |
| --- | --- | --- |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739) | [![\[BL-CM\] \[5\] Register](https://no-cache.hubspot.com/cta/default/3893111/82024308-16f4-4491-98be-818a882c6286.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/82024308-16f4-4491-98be-818a882c6286) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911) | Please feel free to send us a note if you have any questions. [![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![FAQ BL-CM-5 CM-5000](https://no-cache.hubspot.com/cta/default/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/83d00c12-c51c-4476-9902-69f9b7667a91.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/83d00c12-c51c-4476-9902-69f9b7667a91) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e) |

### Your Comments Here:

 

![CTA Banner\_OR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_OR.jpg "CTA Banner_OR")

---

![CTA Banner\_ORA](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ORA.jpg "CTA Banner_ORA")

---

![CTA Banner\_BCM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_BCM.jpg "CTA Banner_BCM")

---

![CTA Banner\_ITDR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ITDR.jpg "CTA Banner_ITDR")

---

![CTA Banner\_CM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_CM.jpg "CTA Banner_CM")

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Moh Heng Goh",
    "url" : "https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh"
  },
  "dateModified" : "2026-10-09T08:11:40.005Z",
  "datePublished" : "2026-10-07T08:17:02.000Z",
  "headline" : "[CM] [BDCB] [E3] [CRA] [P1-1] List of Threats",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cra-p1-1-list-of-threats",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```