Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business continuity threat assessment matrix of natural technological and human threats

Business Continuity Threat Assessment Guide 2026

A business continuity threat assessment identifies the events that could disrupt your critical activities and estimates how likely and how severe they are. It sits alongside the business impact analysis. The impact analysis tells you which activities matter and how long you can be without them. The threat assessment tells you what could take them away, so that you can decide where to spend effort on prevention, protection and recovery.

This guide explains how to carry out a business continuity threat assessment: categories to consider, where to find information, how to rate threats, how to turn them into scenarios and how to link the results to your plans.

Where the threat assessment fits in ISO 22301

ISO 22301:2019 requires the organisation to implement and maintain a process for systematically identifying, analysing and evaluating the risk of disruptive incidents, and to determine which risks need treatment. That risk assessment, together with the business impact analysis, drives the continuity strategy. Our guide to the ISO 22301 risk assessment explains the whole process, and the piece on BIA and risk assessment shows how they differ.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

In a threat-led approach, you list threats, assess how they could affect the resources critical activities depend on, and evaluate the resulting risk. An alternative is impact-led: assume the loss of a resource and plan regardless of cause. Most organisations use both, planning for loss of building, systems, people and suppliers, and using threats to decide priorities and likelihood.

Categories of threats

CategoryExamples
NaturalFlood, storm, earthquake, wildfire, extreme heat or cold, pandemic
TechnologicalCyber attack, ransomware, software failure, power or network outage, data centre incident
Human, intentionalSabotage, theft, arson, terrorism, civil unrest, insider misuse
Human, accidentalError, loss of key knowledge, industrial accident, chemical release
Supply and third partySupplier failure, transport disruption, utility loss, outsourcer incident
Political and regulatorySanctions, strikes, border closures, new legislation

Tailor the list. A coastal warehouse needs flood and storm analysis, and a software company needs a detailed view of cloud and cyber threats. Use only threats that are plausible for your locations and operations.

Sources of information

Good assessments use evidence, not guesses. Sources include your own incident history and near misses, insurance surveys and claims data, national and local hazard maps and risk registers, emergency management agencies, utility reliability data, threat intelligence reports, industry incident sharing groups and staff experience at each site. Public guidance such as the US Ready.gov business preparedness pages is a useful starting point for typical hazards and planning steps. Where you operate in other countries, use the equivalent national sources.

Free business continuity risk assessment

What could stop your most important activities?

List your prioritized activities and what they depend on, pick from 32 disruption scenarios, rate them and choose continuity measures for each. Built to ISO 22301 clause 8.2.3, and free.

Run the free continuity risk assessment →  or  View premium report sample

Rating threats for a business continuity threat assessment

Rate each threat by the likelihood of occurring at each site or in each service and by the impact on critical resources if it does. Use the same scales as your organisational risk assessment so results are comparable. Consider how much warning you would have, how long the disruption might last and how widespread it would be. A threat with low likelihood but severe impact, such as a regional flood, may still demand a plan.

Likelihood

Base likelihood on frequency data where you have it, such as flood return periods or historic outage counts, and on expert judgment where you do not. Note the source and any assumptions. Avoid labelling everything medium.

Impact

Judge impact on the resources that critical activities depend on: people, premises, technology, information, suppliers and equipment. Link to the business impact analysis so the threat rating reflects how quickly each activity must recover. The recovery targets are explained in our guide to RTO and RPO.

Vulnerability and existing controls

Consider how exposed you are and what protections exist already: flood defences, backup power, redundancy, insurance, security controls. A threat that is well controlled may be rated lower after controls, but record both the inherent and residual rating, and confirm that the controls are tested.

Turning threats into scenarios

Scenarios make the threats usable for planning. Choose a small number of realistic disruption scenarios that together cover the loss of the main resources: loss of a site, loss of key systems, loss of a key supplier, loss of a large share of staff and loss of a utility. Attach the most likely and most severe threats to each. A single “loss of site” plan can serve for fire, flood and civil unrest, while the threat assessment tells you which causes you should prevent or prepare for at each location.

Use scenarios in exercises. The guide on the business continuity exercise explains how to test them, and the single point of failure analysis guide shows how to find weak dependencies within each scenario.

Recording the assessment in the risk register

Record each material threat with its description, the resources and activities it affects, likelihood, impact, existing controls, residual rating, treatment actions and owner. Store it in your business continuity risk register, and link each risk to the plans that respond to it. Keep the date and the evidence used for each rating so that reviewers can see how the assessment was made and update it later.

A hypothetical example of a business continuity threat assessment

The following is a hypothetical example invented for illustration. A regional logistics company assesses threats at its main depot, which handles most of its critical dispatch activity. It lists twelve plausible threats. Flood risk is rated low after checking hazard maps, a prolonged power outage is rated medium after two outages in five years, and a ransomware attack is rated high because of industry incidents and gaps in the last security review. A driver shortage from a pandemic wave is rated medium.

The company groups them into three scenarios: loss of the depot, loss of dispatch systems and loss of a large share of drivers. It finds that its plan for loss of dispatch systems assumes a restore time of two days, but the impact analysis shows a four-hour tolerance. The assessment leads to funding for an offline dispatch procedure, a tested immutable backup and a mutual aid agreement with another carrier. The threat view made the gaps visible and prioritised them.

Common mistakes in a business continuity threat assessment

Common weaknesses include generic threat lists copied from templates, ignoring site-specific hazards, rating without evidence, forgetting cyber and supplier threats, treating likelihood as the only factor, never linking threats to critical activities, not recording residual risk, plans that do not match the scenarios, and no updates after incidents. Another is preparing for one high-profile threat while leaving common ones, such as software failure or staff absence, unplanned.

Ranking threats by likelihood and consequence

Once threats are listed, rank them so that planning effort follows exposure. A simple three-point scale for likelihood and a matching scale for consequence is enough for most sites. Score each threat against each critical location and process rather than for the organization as a whole, because a flood that matters greatly at one site may be irrelevant at another. Record the evidence behind each score, such as insurance surveys, local authority hazard maps, incident history and supplier notices, so a reviewer can see why a rating was chosen and challenge it.

Keep the output short enough to use. A ranked list of the ten or so threats that most affect your prioritized activities is more useful to a continuity team than a register of eighty items nobody reads. Feed the top items into your continuity strategies and exercise scenarios so the assessment changes what you actually do.

Keeping the assessment current

Review threats at least once a year and after significant events, such as an incident, a move to a new site, a merger, a new supplier or a change in the threat landscape. Update likelihood estimates as new data becomes available, and record what changed. Include the assessment in management review so leaders see the main threats and the status of treatment.

Templates for a business continuity threat assessment

A consistent format helps you capture threats, ratings, scenarios and links to plans for every site. The Business Continuity Risk Assessment Report and Workbook provides a report and workbook for documenting continuity risks and their treatment. Whichever tool you use, keep the structure the same across sites so results can be compared and reported together.

Business continuity threat assessment FAQ

What is a business continuity threat assessment?

A structured review of the events that could disrupt critical activities, with ratings of likelihood and impact, used to prioritise prevention, protection and recovery.

How is it different from a business impact analysis?

The impact analysis shows which activities matter and how quickly they must recover. The threat assessment shows what could disrupt them and how likely it is.

Do we plan for every threat?

No. Plan for scenarios such as loss of premises, systems, suppliers or staff, and use the threat assessment to decide priorities and the events you should prevent.

How often should it be updated?

At least annually and after incidents, site changes, major supplier changes or shifts in the threat landscape.

Who should be involved?

Continuity, risk, security, IT, facilities and the owners of critical activities, with input from insurers and local authorities where relevant.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.