6.2 Threat Scenarios, Single Points of Failure & Supply Chain Risk

Key Takeaways

  • ISO 22301 utilizes a dual analytical approach: while continuity strategies are consequence-based (loss of resources), risk assessment requires comprehensive threat modeling to identify specific failure mechanisms.
  • Threat taxonomies encompass four major categories: Environmental/Natural (seismic, meteorological), Technological/Infrastructure (power grid, cloud, fiber cuts), Human/Malicious (ransomware, DDoS, sabotage), and Operational/Workforce (pandemics, strikes).
  • A Single Point of Failure (SPoF) is any individual component, process, facility, supplier, or person whose sole failure causes the total collapse or unacceptable impairment of a prioritized activity.
  • SPoF elimination strategies include N+1 / 2N architectural redundancy, geographic site separation exceeding correlated hazard radii, cross-training, and automated failover clustering.
  • Supply chain continuity per ISO/TS 22318 mandates multi-tier dependency mapping, addressing supplier concentration, single-source vs. sole-source dependencies, and Just-In-Time inventory vulnerabilities.
Last updated: August 2026

6.2 Threat Scenarios, Single Points of Failure & Supply Chain Risk

Quick Answer: Threat modeling in ISO 22301 systematically catalogs environmental, technological, malicious, and workforce hazards to understand how critical resources can be impaired. Single Points of Failure (SPoFs)—whether architectural, operational, human, or vendor-related—represent the most dangerous vulnerabilities because their isolated failure triggers catastrophic disruption. Managing supply chain continuity per ISO/TS 22318 requires mapping multi-tier dependencies and eliminating sole-source vulnerabilities.

While ISO 22301 emphasizes a consequence-based approach for developing recovery strategies (e.g., preparing for the loss of a data center regardless of whether the cause was a flood, fire, or cyberattack), conducting a thorough Disruption Risk Assessment (Clause 8.2.3) requires deep, scenario-based threat modeling.

Understanding the exact mechanisms by which threats exploit vulnerabilities allows the Lead Implementer to design targeted preventive controls, eliminate systemic Single Points of Failure (SPoFs), and secure fragile multi-tier supply chains.


1. Comprehensive Disruption Threat Taxonomy

Threats to business continuity originate across four primary domains. The Lead Implementer must ensure that risk identification workshops do not suffer from cognitive bias or narrow technical myopia.

┌────────────────────────────────────────────────────────────────────────┐
│                     DISRUPTION THREAT TAXONOMY                         │
├─────────────────────────────┬──────────────────────────────────────────┤
│ 1. ENVIRONMENTAL & NATURAL  │ • Seismic (Earthquakes, Tsunamis)        │
│                             │ • Meteorological (Hurricanes, Floods)    │
│                             │ • Geological & Climatological (Wildfires)│
├─────────────────────────────┼──────────────────────────────────────────┤
│ 2. TECHNOLOGICAL & INFRA    │ • Power Grid Collapse & Transformer Fire │
│                             │ • Telecom & Dark Fiber Severance         │
│                             │ • Cloud Hyperscaler Regional Outages     │
│                             │ • Hardware / Firmware Catastrophic Fault │
├─────────────────────────────┼──────────────────────────────────────────┤
│ 3. HUMAN-INDUCED & MALICIOUS│ • Ransomware & Data-Wiper Malware        │
│                             │ • Distributed Denial of Service (DDoS)   │
│                             │ • Physical Sabotage & Terrorism          │
│                             │ • Malicious Insiders & Data Exfiltration │
├─────────────────────────────┼──────────────────────────────────────────┤
│ 4. WORKFORCE & OPERATIONAL  │ • Epidemic / Pandemic Health Crises      │
│                             │ • Key Personnel Strikes & Union Actions  │
│                             │ • Sudden Loss of Niche Technical Experts │
│                             │ • Workplace Contamination / Hazmat       │
└─────────────────────────────┴──────────────────────────────────────────┘

1. Environmental and Natural Threats

  • Geological Hazards: Earthquakes, fault slips, soil liquefaction, landslides, and volcanic ash clouds that cause structural collapse and long-term geographic denial of access.
  • Hydrometeorological Hazards: Riverine flooding, coastal storm surges, hurricanes, typhoons, tornadoes, and flash floods that breach physical perimeters and destroy ground-level utility connections.
  • Extreme Climatological Events: Prolonged heatwaves causing regional electrical brownouts and datacenter cooling chiller failures; severe blizzards causing transportation gridlock.
  • Wildfires & Environmental Contamination: Urban-interface wildfires causing direct physical destruction, severe atmospheric smoke infiltration into server air intakes, and mandatory regional evacuation orders.

2. Technological and Infrastructure Threats

  • Utility & Power Grid Collapse: High-voltage substation failures, transformer explosions, rolling blackouts, and localized municipal water main breaks disabling water-cooled chiller plants.
  • Telecommunications & Fiber Severance: Accidental backhoe severance of primary and secondary dark fiber trunks sharing the same physical municipal utility conduit (correlated common-mode failure).
  • Cloud Hyperscaler & SaaS Disruptions: Global identity provider (IdP) authentication outages, DNS routing table corruption, storage tier data corruption, and regional cloud availability zone cascading failures.
  • Hardware Obsolescence & Microcode Corruption: Storage Area Network (SAN) controller crashes, corrupted RAID firmware updates, and inability to source legacy replacement parts.

3. Human-Induced and Malicious Threats

  • Cryptographic Ransomware & Wiper Campaigns: Advanced threat actors deploying lateral-movement malware that simultaneously encrypts primary production databases and deletes online shadow-copy backups.
  • Distributed Denial of Service (DDoS): Volumetric and application-layer barrages exceeding terabits-per-second, overwhelming edge firewalls and internet transit pipes.
  • Physical Sabotage & Terrorism: Deliberate severance of facility backup generator fuel lines, arson, active shooter incidents, and bomb threats requiring prolonged building cordoning.
  • Malicious Insiders: Disgruntled system administrators intentionally wiping active directory configurations, altering financial transaction records, or exfiltrating proprietary operational source code.

4. Workforce and Operational Threats

  • Pandemic & Biological Crises: Airborne pathogens resulting in $30% - 50%$ workforce absenteeism, government-mandated lockdowns, and restrictions on physical site staffing.
  • Industrial Actions & Labor Strikes: Organized union walkouts among transport workers, logistics handlers, or port operators halting physical operations.
  • Key Person Dependency Attrition: Sudden departure, incapacitation, or death of the sole engineer possessing proprietary knowledge of critical legacy systems.
Threat CategoryPrimary Resource ImpactedTypical Warning TimeVelocity of OnsetDuration of Impact
EarthquakePhysical Facilities & UtilitiesNone (0 seconds)InstantaneousWeeks to Months
HurricaneFacilities, Supply Chain, Power48 - 72 HoursGradual / PredictableDays to Weeks
RansomwareICT Infrastructure & Data AssetsNone to HoursRapid (Minutes)Days to Weeks
Telecom CutData Transmission & NetworksNoneInstantaneousHours to Days
Pandemic WaveWorkforce Availability2 - 4 WeeksSlow / ProgressiveMonths to Years

2. Single Points of Failure (SPoFs): Discovery & Elimination

A Single Point of Failure (SPoF) is any isolated element—whether a physical machine, software component, power line, building, vendor, or individual—whose failure causes a complete cessation or unacceptable degradation of a prioritized activity.

   VULNERABLE (With SPoF):                   RESILIENT (Redundant Architecture):
   ┌──────────────┐                          ┌──────────────┐      ┌──────────────┐
   │ Web Server A │                          │ Web Server A │      │ Web Server B │
   └──────┬───────┘                          └──────┬───────┘      └──────┬───────┘
          │                                         │                     │
          ▼                                         ▼                     ▼
   ┌──────────────┐ [SPoF]                   ┌──────────────┐      ┌──────────────┐
   │ Single Switch│ ◄─── Catastrophic        │ Core Switch A│◄────►│ Core Switch B│
   └──────┬───────┘      Failure Point       └──────┬───────┘      └──────┬───────┘
          │                                         │ ╲                 ╱ │
          ▼                                         │  ╲               ╱  │
   ┌──────────────┐                                 ▼   ╲             ╱   ▼
   │ Database Svr │                          ┌──────────────┐      ┌──────────────┐
   └──────────────┘                          │ Primary DB   │◄────►│ Standby DB   │
                                             └──────────────┘      └──────────────┘

Taxonomy of Organizational SPoFs

  1. Architectural & Infrastructure SPoFs:
    • Single Power Ingress: A facility equipped with emergency generators, but possessing only a single Automatic Transfer Switch (ATS). If the ATS fails, generator power cannot reach critical server racks.
    • Common Trenching: Primary and secondary internet service providers running diverse fiber cables through the exact same municipal street conduit, susceptible to a single backhoe strike.
    • Shared Cooling Chiller: A primary data center relying on a single closed-loop chilled water distribution header.
  2. Operational & Process SPoFs:
    • Single-Threaded Manual Verification: A critical financial settlement workflow that requires an in-person physical signature from one specific compliance director.
    • Centralized Logistics Chokepoint: Routing all global product distributions through a single automated warehouse without overflow fulfillment capabilities.
  3. Human & Competency SPoFs ("Key Person Dependencies"):
    • A legacy software platform whose underlying code is understood exclusively by one senior developer, with zero documented runbooks or secondary cross-trained engineers.
  4. Geographic SPoFs (Correlated Failure Modes):
    • Locating the primary data center and the secondary disaster recovery hot-site within 15 kilometers of each other along the same active earthquake fault line or municipal power grid substation.

Engineering Frameworks for SPoF Elimination

Redundancy ModelConfiguration DescriptionRecovery CharacteristicsImplementation Cost
$N+1$ RedundancyBaseline capacity ($N$) plus one additional backup unit (e.g., 4 server power supplies required, 5 installed).Protects against a single component failure; vulnerable during maintenance windows.Moderate ($+20% - +30%$)
$2N$ RedundancyFull 100% parallel duplication of systems (e.g., two independent UPS systems, two separate generator yards).Allows concurrent maintainability; seamless instantaneous failover.High ($+100%$)
$2N+1$ RedundancyFull parallel duplication plus an extra reserve unit per side.Maximum resilience; standard for Tier IV mission-critical data center facilities.Very High ($+120% - +150%$)
Active-Active ClusteringOperational workload distributed simultaneously across multiple geographically separate nodes.$\text{RTO} \approx 0$, $\text{RPO} = 0$; instantaneous load rebalancing upon node death.High (Requires distributed database synchronization)
Cross-Skilling & SuccessionDocumented standard operating procedures (SOPs) paired with mandatory rotating backup personnel.Eliminates human SPoFs; ensures continuity during sudden personnel turnover.Low to Moderate (Ongoing training investment)

3. Supply Chain Continuity Risks & ISO/TS 22318

Modern organizations are deeply integrated into complex, global supply ecosystems. An operational disruption within a third-party vendor can paralyze an organization just as effectively as an internal facility fire. ISO/TS 22318:2021 (Security and resilience — Business continuity management systems — Guidelines for supply chain continuity management) provides specialized guidance for managing third-party continuity risks.

                  MULTI-TIER SUPPLY CHAIN DEPENDENCY CASCADE
  ┌────────────────────────────────────────────────────────────────────────┐
  │                            OUR ORGANIZATION                            │
  │                  (Final Prioritized Product / Service)                 │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │ Depends on
                                      ▼
  ┌────────────────────────────────────────────────────────────────────────┐
  │                       TIER-1 DIRECT SUPPLIERS                          │
  │  • Cloud SaaS Provider           • Direct Component Assembly Vendor    │
  │  • Managed Payroll Processor     • Primary Logistics Carrier           │
  └─────────────────┬──────────────────────────────────┬───────────────────┘
                    │ Depends on                       │ Depends on
                    ▼                                  ▼
  ┌─────────────────────────────────┐┌─────────────────────────────────────┐
  │      TIER-2 INFRASTRUCTURE      ││       TIER-2 RAW MATERIALS          │
  │  • Cloud Hyperscaler (IaaS)     ││  • Specialized Microchip Fabricator │
  │  • Subcontracted Data Center    ││  • Chemical Precursor Manufacturer  │
  └─────────────────┬───────────────┘└─────────────────┬───────────────────┘
                    │                                  │
                    ▼ [Hidden SPoF Dependency]         ▼ [Geopolitical Vulnerability]
  ┌────────────────────────────────────────────────────────────────────────┐
  │                       TIER-N SUB-TIER BOTTLENECKS                      │
  │  • Single global port terminal handling 80% of rare-earth mineral flow │
  │  • Single DNS root certificate provider supporting multiple SaaS tools │
  └────────────────────────────────────────────────────────────────────────┘

Core Supply Chain Vulnerabilities

  1. Supplier Concentration Risk: Relying on multiple Tier-1 vendors who, unbeknownst to the organization, all rely on the same single Tier-2 sub-supplier or geographic manufacturing cluster (e.g., global automotive ECU chip shortages).
  2. Single-Source vs. Sole-Source Dependencies:
    • Single-Source: The organization chooses to purchase from one specific vendor (often for volume discounts or convenience), even though viable alternative vendors exist in the marketplace. Mitigation: Establish secondary pre-contracted standby suppliers.
    • Sole-Source: Only one supplier exists in the global marketplace capable of providing the specialized component, patent, raw material, or regulatory service. Mitigation: Maintain strategic safety buffer stock, negotiate source-code escrow agreements, or co-develop internal alternatives.
  3. Just-In-Time (JIT) Fragility: Lean manufacturing models that eliminate warehouse inventories in favor of daily deliveries. While cost-efficient during normal operations, JIT collapses immediately upon minor transport disruptions.
  4. Supplier Financial Distress & Insolvency: A critical vendor abruptly entering bankruptcy liquidation, resulting in immediate cessation of services and physical lock-out of proprietary tooling stored at vendor facilities.

Supply Chain Continuity Management Framework per ISO/TS 22318

┌────────────────────────────────────────────────────────────────────────────┐
│               ISO/TS 22318 SUPPLY CHAIN CONTINUITY LIFECYCLE               │
├────────────────────────────────────────────────────────────────────────────┤
│ 1. Supply Chain BIA & Mapping:                                             │
│    • Map all external dependencies supporting Prioritized Activities.      │
│    • Identify Tier-1, Tier-2, and Tier-N critical supply paths.            │
├────────────────────────────────────────────────────────────────────────────┤
│ 2. Supplier Criticality Tiering:                                           │
│    • Tier 1 (Critical): Supplier downtime directly breaches customer RTO.  │
│    • Tier 2 (Important): Supplier downtime causes degradation within days. │
│    • Tier 3 (Standard): Readily replaceable commodity providers.           │
├────────────────────────────────────────────────────────────────────────────┤
│ 3. Due Diligence & Pre-Contract Evaluation:                                │
│    • Review supplier ISO 22301 certificates, SOC 2 reports, and BCPs.      │
│    • Audit supplier RTO/RPO metrics against internal BIA requirements.     │
├────────────────────────────────────────────────────────────────────────────┤
│ 4. Contractual Continuity Governance:                                      │
│    • Mandatory inclusion of BCMS clauses, SLA downtime penalties.          │
│    • Mandatory notification of disruptive incidents within 2 hours.        │
│    • Right-to-audit business continuity plans and exercise participation.  │
├────────────────────────────────────────────────────────────────────────────┤
│ 5. Ongoing Monitoring & Joint Exercising:                                  │
│    • Annual review of critical supplier financial health and threat profile│
│    • Mandatory inclusion of critical Tier-1 suppliers in joint BC exercises│
└────────────────────────────────────────────────────────────────────────────┘

4. Worked Implementation Scenario: IoT Smart Logistics Platform

Incident Context

NexMove Logistics operates an IoT-enabled fleet tracking platform processing 15 million location pings per hour. The BIA establishes Fleet Telemetry Ingestion as Prioritized Activity #1 with $\text{MTPD} = 2\text{ hours}$ and $\text{RTO} = 30\text{ minutes}$.

┌────────────────────────────────────────────────────────────────────────┐
│                     DISRUPTION INCIDENT SIMULATION                     │
├────────────────────────────────────────────────────────────────────────┤
│ THE CASCADING FAILURE:                                                 │
│ • 08:00 - Primary cloud database cluster experiences storage failover. │
│ • 08:05 - Automated failover fails because the secondary database is   │
│           located in the same cloud availability zone (Geographic SPoF)│
│ • 08:10 - Lead Database Architect is on a transatlantic flight with no │
│           cellular contact (Key Person Competency SPoF).               │
│ • 08:15 - Standby SRE attempts manual rebuild but discovers that the   │
│           third-party DNS provider is suffering a major DDoS attack   │
│           (Unmitigated Tier-1 Single-Source Supply Chain Dependency).  │
├────────────────────────────────────────────────────────────────────────┤
│ POST-INCIDENT SPoF REMEDIATION PLAN:                                   │
│ 1. Infrastructure SPoF: Re-architect database to Active-Active across   │
│    multi-region cloud availability zones separated by > 500 km.        │
│ 2. Competency SPoF: Create detailed automated recovery runbooks;       │
│    cross-train 4 regional SREs; mandate no single-person dependencies. │
│ 3. Supply Chain SPoF: Contract with secondary redundant DNS provider    │
│    using automated Anycast routing failover.                           │
└────────────────────────────────────────────────────────────────────────┘

Implementation Outcome

By applying ISO 22301 Clause 8.2.3 and ISO/TS 22318, the Lead Implementer systematically eliminates architectural, operational, human, and third-party SPoFs, reducing actual disaster recovery time from 4.5 hours down to 120 seconds.


5. Practical Implementation Checklist for Threat Modeling & SPoF Analysis

┌────────────────────────────────────────────────────────────────────────────┐
│                 THREAT & SPoF IMPLEMENTATION CHECKLIST                     │
├────────────────────────────────────────────────────────────────────────────┤
│ [ ] 1. Execute cross-functional threat modeling workshops covering         │
│        Environmental, Technological, Malicious, and Workforce vectors.     │
│ [ ] 2. Map all critical infrastructure components and identify             │
│        architectural SPoFs (power, networking, cooling, compute, storage). │
│ [ ] 3. Audit operational workflows for single-threaded human bottlenecks   │
│        and establish mandatory cross-training and runbook documentation.   │
│ [ ] 4. Verify geographic separation of primary and secondary sites to      │
│        prevent correlated common-mode disaster failures.                   │
│ [ ] 5. Implement ISO/TS 22318 supply chain mapping across Tier-1 and       │
│        critical Tier-2 suppliers.                                          │
│ [ ] 6. Classify suppliers into Criticality Tiers and embed mandatory       │
│        business continuity clauses and audit rights in master contracts.   │
│ [ ] 7. Mandate joint continuity exercises with mission-critical suppliers. │
└────────────────────────────────────────────────────────────────────────────┘

6. PECB Exam Warning Traps & Common Nonconformities

[!CAUTION] Critical Exam Traps for Section 6.2

  1. Trap: Conflating Single-Source with Sole-Source Suppliers: Exam questions test whether an implementer understands the difference. Single-source is a voluntary organizational choice (can be mitigated by contracting alternative vendors); sole-source means no other supplier exists in the market (requires holding buffer inventory, escrow agreements, or re-engineering).
  2. Trap: Assuming Cloud Providers Automatically Eliminate SPoFs: Migrating an application to the public cloud does not inherently eliminate SPoFs. If virtual machines or databases are deployed in a single Availability Zone (AZ) or rely on a single region, an underlying cloud hardware or network outage will cause complete downtime.
  3. Trap: Ignoring Common-Mode / Correlated Hazards: Having redundant servers or secondary buildings is ineffective if both facilities share the same regional electrical grid substation, municipal water pipeline, or flood plain.
Loading diagram...
Comprehensive Bow-Tie Threat and SPoF Resilience Architecture
Test Your Knowledge

A financial institution operates its primary data center in a metropolitan city and establishes a secondary disaster recovery site 8 kilometers away. Both facilities receive power from different local distribution lines that originate from the same municipal electrical substation, and both route internet communications through the same physical underground utility conduit. What type of vulnerability does this configuration represent?

A
B
C
D
Test Your Knowledge

An organization relies on a proprietary, specialized microchip that is manufactured by only one company in the world due to global patent protections. No alternative manufacturer exists in the commercial market. According to supply chain continuity principles (ISO/TS 22318), how is this vendor dependency classified, and what is an appropriate business continuity mitigation strategy?

A
B
C
D
Test Your Knowledge

During a business continuity risk assessment, an engineering firm discovers that a mission-critical automated calculation tool is maintained by a single senior engineer who has never documented the code structure or recovery procedures. If this engineer becomes unavailable, the prioritized activity will fail within 2 hours. What type of Single Point of Failure does this represent?

A
B
C
D