.

Crisis Management in Action: A Practical Implementation Guide for BDCB
CM 7P_PD8_with Cert Logo

[CM] [BDCB] [E3] [CRA] [P2] Treatment and Control

[CM] [BDCB] [Full Banner] Crisis Management in Action_ A Practical Implementation Guide for BDCB

Following CRA Part 1-1 — List of Threats for Brunei Darussalam Central Bank (BDCB), the next stage of the Crisis Risk Assessment (CRA) is to determine how each identified threat is currently treated, what controls are in place, and what additional controls to consider.

BCMpedia defines existing risk treatment as the mitigating measures already implemented to address recognised threats.

Its RAR (CRA) methodology identifies four treatment approaches: Risk Avoidance, Risk Reduction, Risk Transference, and Risk Acceptance.

It also distinguishes Existing Controls, which are measures already implemented, from Additional (Planned) Controls, which are proposed improvements.

More than one treatment approach can apply to the same threat, and the appropriate treatment ultimately depends on the organisation's risk appetite.

For this chapter, the treatments and controls below are illustrative recommendations for BDCB's CRA, not assertions that BDCB currently operates every control listed.

Validate them with the relevant BDCB business, facilities, security, technology, cyber, procurement, BCM, and crisis-management owners. This distinction matters most for technology-related scenarios.

[Banner] [Title] [CM] [E3] Part 2_ Treatment and Control

Moh Heng Goh
Crisis Management Certified Planner-Specialist-Expert
[CM] [BDCB] Legal Disclaimer Banner

[Banner] [Title] [CM] [E3] Part 2_ Treatment and Control

[CM] [Table] [CRA 2-1] Risk Treatment and Evaluation of Existing ControlsPart 2: CAR – Treatment and Control for the Brunei Darussalam Central Bank

Introduction

[CM] [BDCB] [E3] [RAR] [P2] Treatment and ControlFollowing CRA Part 1-1 — List of Threats for Brunei Darussalam Central Bank (BDCB), the next stage of the Crisis Risk Assessment is to determine how each identified threat is currently treated, what controls are in place, and what additional controls to consider.

BCMpedia defines existing risk treatment as the mitigating measures already implemented to address recognised threats. Its RAR methodology identifies four treatment approaches: Risk Avoidance, Risk Reduction, Risk Transference, and Risk Acceptance.

 

It also distinguishes Existing Controls, measures already implemented, from Additional (Planned) Controls,  proposed improvements.

More than one treatment approach can apply to the same threat, and the appropriate treatment ultimately depends on the organisation's risk appetite.

For this chapter, the treatments and controls below are illustrative recommendations for BDCB's CRA, not assertions that BDCB currently operates every control listed.

BDCB should validate them with the relevant business, facilities, security, technology, cyber, procurement, BCM, and crisis-management owners. This distinction is particularly important for technology-related scenarios.

BDCB publishes technology-risk, cyber-intrusion, IT third-party, and payment-system requirements for regulated entities, demonstrating the relevance of resilience, recoverability, and third-party technology risk within Brunei's financial sector.

Treatment notation used in the table

Applicable means that the treatment approach can reasonably form part of BDCB's treatment strategy.

Limited means that it can be used only for part of the exposure.

Residual means that, after practical controls have been applied, some remaining risk must normally be accepted within the approved risk tolerance.

 

[Banner] [Title] [CM] [E3] Part 2_ Treatment and Control

Denial of Access — Natural Disaster

 

Type of Threats / Crisis Scenario

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional (Planned) Controls

Flood

Avoid locating critical equipment in flood-prone areas; avoid low-level storage of vital assets

Applicable — drainage, barriers, alternate sites, and remote working

Limited — insurance and contracted recovery services

Residual — extreme flooding cannot be eliminated

Emergency response; facility protection; alternate workplace; BCM arrangements; backups

Site-specific flood study; flood barriers; alternate command location; annual flood exercise

Flash Flood

Restrict use of exposed areas for critical operations

Applicable — monitoring, access controls, and rapid evacuation

Limited — insurance

Residual

Weather monitoring; emergency notification; evacuation; alternate working

Automated weather alerts; predetermined closure triggers; alternative staff access routes

Severe Rain / Thunderstorm

Avoid unnecessary travel during severe conditions

Applicable — remote working and infrastructure protection

Limited

Residual

Weather monitoring, UPS, building maintenance, and remote access

Formal weather escalation thresholds; enhanced water-ingress inspection; remote-work activation checklist

Lightning

Avoid exposed external operations during storms

Applicable — lightning and surge protection

Limited — equipment insurance

Residual

Surge protection; earthing; UPS; equipment redundancy

Periodic lightning-protection testing; enhanced protection for critical ICT and telecommunications

Strong Wind / Windstorm

Avoid use of unsafe areas

Applicable — structural maintenance and secured external assets

Limited — property insurance

Residual

Building maintenance; emergency response; staff notification

Structural vulnerability review; formal wind thresholds for site closure

Tropical Storm

Suspend non-essential on-site activities when required

Applicable — BCM, alternate sites, remote work, and emergency preparedness

Limited

Residual

Emergency response, weather monitoring, and alternate work arrangements

Severe-weather playbook; pre-event resource staging; cross-sector communications exercise

Haze / Poor Air Quality

Reduce or suspend outdoor activities

Applicable — remote working and indoor air management

Limited

Residual

HVAC; employee communication; work-from-home capability

Air-quality trigger levels; vulnerable-employee arrangements; protective equipment stock

Earthquake Tremors

Avoid occupancy of structurally unsafe areas

Applicable — structural assessment and evacuation

Limited — insurance

Residual

Evacuation procedures; emergency response; building inspection arrangements

Post-tremor structural inspection protocol; exercise loss-of-premises scenario

External Fire / Wildfire

Avoid operations in affected exclusion zones

Applicable — evacuation, alternate site, and air-quality controls

Limited — insurance

Residual

Fire monitoring; evacuation; alternate workplace

Smoke-impact assessment; alternate access routes; extended premises-loss exercise

 

Denial of Access — Man-made Disaster

 

Type of Threats / Crisis Scenario

Risk Avoidance

Risk Reduction

Risk Transference

Risk Acceptance

Existing Controls

Additional (Planned) Controls

Building Fire

Control ignition sources and prohibit unsafe practices

Applicable — detection, suppression, and evacuation

Applicable — property/business insurance where appropriate

Residual

Fire alarms; extinguishers; fire wardens; evacuation plans; drills

Alternate assembly areas; recovery-site exercise; enhanced fire-compartment review

Bomb Threat

Restrict unauthorised access and suspicious deliveries

Applicable — security screening, evacuation, and liaison with authorities

Limited

Residual

Security controls; evacuation; incident escalation

Bomb-threat checklist; suspicious-package training; command-post exercise

Explosion

Control hazardous activities and access

Applicable — emergency response and building safety

Applicable — insurance where appropriate

Residual

Evacuation; security; emergency services coordination

Mass-casualty scenario exercise; structural recovery assessment procedure

Terrorism / Hostile Attack

Restrict access to sensitive areas

Applicable — layered physical security and intelligence awareness

Limited

Residual

Guards; CCTV; access control; lockdown/evacuation arrangements

Threat-level framework; hostile reconnaissance awareness; multi-agency exercise

Civil Disturbance / Public Disorder

Avoid unnecessary presence in affected areas

Applicable — remote work and alternative access

Limited

Residual

Security monitoring; access controls; employee alerts

Dynamic security assessment; alternative entrances; crisis communication templates

Suspicious Package / Security Threat

Controlled mail and delivery arrangements

Applicable — screening and isolation

Limited

Residual

Security personnel; access control; evacuation

Suspicious-item procedure; specialist training; exercise with authorities

Hazardous Material Incident

Avoid exposure and isolate hazardous zones

Applicable — evacuation/shelter-in-place

Applicable where insurance/contractual arrangements exist

Residual

Emergency procedures; HVAC controls; evacuation

Shelter-in-place capability; air-handling isolation procedure; PPE readiness

Major Transport Accident Near Premises

Avoid affected routes and areas

Applicable — alternative access and remote work

Limited

Residual

Employee alerts; alternate access; BCM arrangements

Traffic/access contingency map; rapid work-from-home activation

Prolonged Power Outage

Avoid single utility dependency where feasible

Applicable — UPS, generators, and alternate sites

Limited — service contracts

Residual

UPS; backup generators; DR/BC arrangements

Extended-runtime testing; fuel-resupply agreements; black-start exercise

 

Unavailability of People

 

Type of Threats / Crisis Scenario

Risk Avoidance

Risk Reduction

Risk Transference

Risk Acceptance

Existing Controls

Additional (Planned) Controls

Infectious Disease / Pandemic

Avoid unnecessary physical contact/exposure

Applicable — remote work, split teams, and hygiene controls

Limited

Residual

Remote access; health guidance; staff communications; succession arrangements

Pandemic staffing thresholds; minimum staffing model; cross-training; periodic pandemic exercise

Localised Infectious Disease Outbreak

Temporarily avoid the affected workplace

Applicable — isolation and remote work

Limited

Residual

Workplace health measures; remote access

Team-segregation procedure; rapid cleaning arrangements

Loss of Key Appointment Holder

Avoid excessive dependency on one individual

Applicable — deputies, succession, and cross-training

Generally not applicable

Residual

Delegation of authority; deputies; succession arrangements

Named alternates for every critical role; knowledge-transfer programme

Multiple Critical Staff Unavailable

Avoid concentration of skills within one team/location

Applicable — cross-training and split teams

Limited — specialist external support

Residual

Cross-training, remote working, and staff redeployment

Minimum staffing matrices; multi-skilled reserve pool; cross-location exercises

Workplace Accident / Safety Incident

Avoid unsafe practices

Applicable — occupational safety controls

Applicable — insurance/medical services

Residual

Safety procedures; first aid; incident reporting

Enhanced safety reviews; casualty-response exercise

Workplace Violence

Avoid uncontrolled access and known high-risk situations

Applicable — security and employee-support measures

Limited

Residual

Security; access control; emergency response

Threat-management protocol; staff awareness; post-incident psychosocial support

Labour Dispute Affecting Essential Services

Avoid dependence on one service channel/provider

Applicable — alternate providers/work arrangements

Applicable — contracted alternatives

Residual

Supplier contracts; BCM arrangements

Alternate supplier agreements; essential-service dependency mapping

Transport Disruption Affecting Workforce

Avoid unnecessary commuting during severe disruption

Applicable — remote work and staggered attendance

Limited

Residual

Remote access; staff communications

Critical-staff accommodation/transport options; alternative staffing arrangements

Mass Casualty / National Emergency

Avoid deployment into unsafe areas

Applicable — distributed teams, succession, and remote work

Limited

Residual

Crisis management; emergency communication; BCM

Workforce-accountability system; family-assistance arrangements; national emergency exercise

 

Disruption to the Supply Chain

 

Type of Threats / Crisis Scenario

Risk Avoidance

Risk Reduction

Risk Transference

Risk Acceptance

Existing Controls

Additional (Planned) Controls

Loss of Specialised Technology Vendor

Avoid unnecessary single-vendor dependency

Applicable — redundancy and internal capability

Applicable — contractual SLAs/support obligations

Residual

Vendor contracts; support agreements; supplier monitoring

Exit strategy; alternate supplier; source/configuration escrow where appropriate

Telecommunications Provider Failure

Avoid reliance on one carrier/path

Applicable — diverse links and backup communications

Applicable — SLA

Residual

Redundant connectivity; mobile communications

Carrier/path diversity validation; satellite/independent emergency communications

Utility Supplier Failure

Reduce reliance on utility supply for critical operations

Applicable — generators, storage and alternate sites

Limited

Residual

UPS; generator; facility BCM

Extended outage test; fuel and maintenance assurance

Critical ICT / Cloud Service Provider Outage

Avoid unsuitable concentration/cloud dependency

Applicable — resilience, backups and portability

Applicable — contracts, SLA and liability provisions

Residual

Vendor due diligence; service monitoring; backups

Cloud exit plan; portability test; concentration-risk assessment

Cyberattack on Critical Supplier

Avoid suppliers lacking adequate security

Applicable — due diligence, segmentation and monitoring

Applicable — contractual obligations/cyber insurance where appropriate

Residual

Third-party risk assessment; security requirements

Supplier cyber exercises; breach-notification testing; fourth-party mapping

Security Service Provider Failure

Avoid sole reliance on outsourced capability

Applicable — internal contingency and alternate staffing

Applicable — contractual replacement provisions

Residual

SLA; supplier monitoring

Backup security provider; emergency staffing protocol

Critical Equipment Supplier Failure

Avoid proprietary single-source dependency where feasible

Applicable — spare inventory and alternative equipment

Applicable — maintenance/support contracts

Residual

Maintenance contracts; spares

Critical-spares analysis; second-source qualification

Logistics / Transportation Disruption

Avoid just-in-time dependence for critical resources

Applicable — buffer stock and alternative routes

Applicable — multiple logistics providers

Residual

Supplier arrangements; stock holdings

Minimum stock thresholds; alternate delivery routes/providers

Supplier Financial Failure

Avoid financially weak critical suppliers

Applicable — financial monitoring and alternatives

Applicable — contractual protections

Residual

Vendor due diligence; procurement controls

Supplier financial early-warning indicators; exit/replacement plan

Regulatory / Legal Failure Affecting Supplier

Avoid non-compliant providers

Applicable — compliance due diligence

Applicable — contractual warranties/termination rights

Residual

Legal review; supplier due diligence

Periodic compliance certification; rapid supplier substitution plan

Concentration / Common Supplier Failure

Applicable — diversify where practical

Applicable — redundancy and contingency arrangements

Limited

Residual

Supplier inventory; dependency management

Sector-wide concentration mapping; alternative-provider strategy; scenario testing

BDCB's published regulatory framework includes dedicated IT third-party risk-management guidance, reinforcing the importance of due diligence, risk-based controls, and management of external technology dependencies in the financial sector.

 

Equipment and IT-Related Disruption

 

Type of Threats / Crisis Scenario

Risk Avoidance

Risk Reduction

Risk Transference

Risk Acceptance

Existing Controls

Additional (Planned) Controls

Hardware Failure

Avoid unsupported/end-of-life equipment

Applicable — redundancy and preventive maintenance

Applicable — warranties/support contracts

Residual

Redundant hardware; monitoring; maintenance

Predictive monitoring; lifecycle replacement programme

Software / Application Failure

Avoid unsupported/unproven software

Applicable — testing, redundancy, and rollback

Applicable — vendor support

Residual

SDLC/change controls; backups; monitoring

Resilience testing; automated rollback; dependency mapping

Network Failure

Avoid single points of failure

Applicable — redundant equipment/routes

Applicable — carrier SLA

Residual

Network redundancy; monitoring

Independent route testing; regular failover exercises

Telecommunications Failure

Avoid single-carrier dependency

Applicable — multiple communication channels

Applicable — carrier SLA

Residual

Backup links; mobile communications

Out-of-band communications capability

Cyberattack

Avoid unnecessary exposure and insecure technology

Applicable — layered cybersecurity

Applicable — specialist response services/cyber insurance where appropriate

Residual

Access control; monitoring; patching; endpoint/network security; incident response

Threat-led penetration testing; cyber crisis exercise; zero-trust enhancements; privileged-access review

Ransomware

Avoid unsupported systems and unnecessary privilege

Applicable — segmentation, EDR, and immutable backups

Limited — response contracts/insurance

Residual

Backups; endpoint protection, email security, and incident response

Offline/immutable recovery validation; ransomware recovery exercise

Distributed Denial-of-Service (DDoS)

Minimise unnecessary public exposure

Applicable — filtering and scalable protection

Applicable — DDoS mitigation provider

Residual

Firewalls; monitoring; ISP controls

DDoS scrubbing capability; stress testing

IT Sabotage

Avoid excessive privileged access

Applicable — segregation of duties and monitoring

Limited

Residual

Access management, logging, and physical security

Privileged-user behavioural monitoring; insider-threat programme

Data Corruption / Loss of Data Integrity

Avoid uncontrolled changes/interfaces

Applicable — validation, reconciliation, and backups

Limited

Residual

Backups; reconciliation; database controls

Point-in-time recovery testing; integrity-validation procedures

Data Breach / Information Leakage

Avoid unnecessary collection/access to sensitive data

Applicable — encryption, DLP, and least privilege

Limited — cyber insurance/services

Residual

Access controls; encryption; monitoring

Enhanced DLP; data classification review; breach simulation

RTGS System Disruption

Avoid uncontrolled change and single points of failure

Applicable — high availability, DR, and operational contingency

Limited — vendor/support contracts

Residual

Monitoring; recovery arrangements; participant procedures

End-to-end RTGS failover exercise; prolonged-outage manual/alternative procedures

ACH System Disruption

Avoid single points of failure

Applicable — redundancy and recovery capability

Limited

Residual

Monitoring; DR; reconciliation

Cross-system dependency test with RTGS; extended outage exercise

CSD System Disruption

Avoid single processing/data dependencies

Applicable — redundancy, backups, and reconciliation

Limited

Residual

Backup/recovery; access control; reconciliation

Data-integrity recovery test; CSD/RTGS combined scenario exercise

Data Centre Failure

Avoid geographic/common-cause concentration

Applicable — alternate recovery facility

Applicable — specialist facility/service contracts

Residual

DR site; UPS/generator; environmental monitoring

Geographic dependency review; full production failover exercise

DR / Failover Failure

Avoid untested recovery designs

Applicable — regular testing and independent validation

Limited

Residual

DR plans; backups, and recovery testing

Unannounced failover exercises; dependency-based recovery testing

Failed Technology Change / Upgrade

Avoid high-risk changes during critical periods

Applicable — testing, approval, and rollback

Limited — vendor support

Residual

Change management; test environments; rollback plans

Enhanced pre-production simulation; automated rollback; crisis trigger for failed major changes

Database Failure

Avoid unsupported or single-instance databases

Applicable — replication and backups

Applicable — vendor support

Residual

Replication; monitoring; backup/recovery

Corruption scenario test; recovery-point validation

Authentication / Identity Service Failure

Avoid single identity-service dependency

Applicable — redundant identity infrastructure and emergency access

Limited

Residual

MFA; replicated services; privileged access controls

Emergency-access procedure; identity-system failover exercise

UPS / Backup Generator Failure

Avoid single backup-power dependency

Applicable — redundant equipment and maintenance

Applicable — maintenance contracts

Residual

UPS; generators; periodic tests

Full-load endurance testing; fuel-supply resilience review

HVAC / Cooling Failure

Avoid single cooling-system dependency

Applicable — redundant cooling and monitoring

Applicable — maintenance contracts

Residual

Environmental monitoring; backup cooling

Thermal shutdown thresholds; extended cooling-failure test

Capacity / Performance Failure

Avoid inadequate capacity design

Applicable — capacity planning, scaling, and load balancing

Applicable for scalable external services

Residual

Performance monitoring; capacity management

Extreme-volume stress testing; automated scaling where appropriate

BDCB's technology-risk framework for the financial sector emphasises robust IT risk management, effective governance, system security, reliability, resilience, and recoverability.

Its regulatory catalogue also includes cyber-intrusion reporting, technology risk, and IT third-party requirements.

These provide useful contextual benchmarks when BDCB validates the proposed technology controls above, although the table should not be interpreted as claiming that every regulatory control imposed on supervised entities is necessarily an internal BDCB control.

 

Applying the Four Risk Treatments

The four treatment approaches should not be treated as mutually exclusive. BCMpedia expressly notes that more than one risk treatment may be selected for a threat.

For example, BDCB could address telecommunications failure by avoiding a single-carrier design, reducing exposure through redundant links, transferring defined service obligations through supplier contracts, and accepting the residual possibility that an exceptional national telecommunications event could disable several providers simultaneously.

Use Risk Avoidance where BDCB can remove the source of unacceptable exposure—for example, by discontinuing unsupported technology or avoiding concentration of critical infrastructure in a vulnerable location.

Risk Reduction is likely to be the dominant treatment for many BDCB threats because critical central-bank activities cannot simply be discontinued. Reduction measures include redundancy, cybersecurity controls, cross-training, alternate premises, disaster recovery, supplier diversification, and crisis preparedness.

Risk Transference transfers some financial, contractual, or operational consequences to another party through insurance, outsourcing, warranties, maintenance contracts, or service-level agreements. It does not transfer BDCB's ultimate accountability for managing crisis consequences.

Risk Acceptance applies to the residual exposure remaining after reasonable controls have been implemented. Acceptance should be explicit, authorised at the appropriate level, and consistent with BDCB's approved risk appetite rather than arising merely because no further action has been taken.

 

Existing Versus Additional Controls

BCMpedia distinguishes controls already implemented from controls proposed for future implementation. Existing controls are instruments or practices already operating to manage the identified risk, while additional controls are improvements identified during the assessment.

Accordingly, before this table becomes an approved BDCB CRA record, the organisation should verify every entry in the Existing Controls column. Where a listed measure does not currently exist, it should be moved to Additional (Planned) Controls rather than being recorded as an established control.

For every proposed additional control, BDCB should subsequently identify a control owner, implementation priority, target completion date, required resources, and evidence of completion.

Escalate material residual risks above the approved risk appetite for management treatment decisions.

 

Banner [CM] [Summing Up] [E3] [CRA] [P2] Treatment and Control

CRA Part 2 converts the threat catalogue developed in CRA Part 1-1 into an actionable risk-treatment framework. The purpose is not to eliminate every conceivable threat.

For a central bank, many threats—such as severe weather, cyberattack, national infrastructure failure, or widespread disease—cannot be completely avoided.

The objective is to reduce the likelihood or consequences to an acceptable level while ensuring that BDCB can continue or recover its critical responsibilities.

Pay particular attention to cascading and common-cause failures. Flooding can simultaneously affect premises, people, utilities, and telecommunications.

A cyberattack can compromise technology availability, data integrity, and stakeholder confidence.

A common technology provider failure can affect BDCB and financial institutions at the same time. These scenarios require controls that operate across organisational boundaries rather than within individual risk silos.

The completed CRA Part 2 should therefore provide BDCB with a traceable relationship between each threat, selected treatment, existing control, and planned improvement.

This creates the foundation for assessing control effectiveness and residual exposure, prioritising remediation, and developing severe-but-plausible scenarios for crisis exercises and preparedness.

 

[CM] [BDCB] [3/4 Banner] Crisis Management in Action_ A Practical Implementation Guide for BDCB

eBook 3: Starting Your CM Implementation

[RAR] [P1-1]

[RAR] [P1-2]

[RAR] [P1-3]

[RAR] [P2]

[CM] [BDCB] [E3] [CRA] [P1-1] List of Threats [CM] [BDCB] [E3] [CRA] [P1-2] List of Crisis Scenarios [Natural and Man-made] [CM] [BDCB] [E3] [CRA] [P1-3] List of Crisis Scenarios [Technology] [CM] [BDCB] [E3] [RAR] [P2] Treatment and Control

[RAR] [P3]

[CMS] [P1]

[CMS] [P2]

eBook 3

[CM] [BDCB] [E3] [CRA] [P3] Risk Impact and Likelihood Assessment [CM] [BDCB] [E3] [CMS] [P1] Crisis Prevention Strategy [CM] [BDCB] [E3] [CMS] [P2] Crisis Response Strategy eBook Cover [CM] [BDCB] [E3] [2D]
 

 

 

 

More Information About Crisis Management Blended/ Hybrid Learning Courses

To learn more about the course and schedule, click the buttons below for the  CM-300 Crisis Management Implementer [CM-3] and the CM-5000 Crisis Management Expert Implementer [CM-5].

New call-to-action New call-to-action New call-to-action
New call-to-action New call-to-action [BL-CM] [5] Register
New call-to-action

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

FAQ BL-CM-5 CM-5000
New call-to-action New call-to-action New call-to-action

Your Comments Here:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM