← Back to the demo console · This is the export a security lead drops into a board meeting — print it (or save as PDF) exactly as rendered. Dated as of 2026-10-06: the date of the real-feed snapshot it is computed from.
Risk & resilience board pack
Meridian Dynamics Inc. (fictional demo org) · as of 2026-10-06 · geopolitical + all-hazards exposure over the asset & dependency register · fictional organization, synthetic assets — real global feed
Summary
3 risks are high today; none is critical.
Direction: Mixed: high rows 2→3 while critical rows 3→0, treatment coverage 0%→67%, assets reviewed on time 0%→79% improved.
Open items that need a decision
- EU sensor-revenue line stops if any one of these 5 assets fails, with no backup in place (EMS partner — Kaohsiung, Foundry partner — Hsinchu, Penang grid feed and 2 more) — $1.85M/day of revenue depends on it, $5.55M if it is down for its longest tolerable outage (72h) (your figures).
- 1 asset has a critical or high risk with no decision recorded: EU shipping route — Red Sea transit.
How to read this page
- Risk = recent activity in the region against its usual level (1–5; 2 is normal for that region) × how much the asset matters to you (1–5), out of 25: Critical 15–25 · High 10–12 · Medium 5–9 · Low 1–4.
- Activity (1–5) compares a region's last week with its own usual level from dated, sourced events — 2 is normal for that region, 4 or 5 is well above it. It is not a forecast or a probability.
- Importance (1–5) is how much each asset matters to your organisation, set by you.
- Expected risk after action (residual) is the action owner's estimate, not a measured result.
- Dollar figures are your own planning inputs: revenue that depends on an asset or service, not a loss forecast.
- Natural-hazard scores rate the strongest hazard active now, not conditions at the site — see the method notes at the end.
Posture trend — are we getting better?
Direction: mixed — exposure rose while the risk program improved. critical rows ↓ 3→0 · high rows ↑ 2→3 · treatment coverage ↑ 0%→67% · assets reviewed on time ↑ 0%→79%
Risk matrix
Likelihood × impact (5×5); each chip is an asset at its worst exposure. Levels: low <5 · medium <10 · high <15 · critical ≥15. Likelihood is an evidence-weighted activity index, not a forecast probability.
Rows: L — how the region’s recent activity compares with its usual level (likelihood, 1–5; 2 is normal, highest at the top)Columns: I — how much the asset matters to you (impact, 1–5, most at the right)
Risk = recent activity in the region against its usual level (1–5; 2 is normal for that region) × how much the asset matters to you (1–5), out of 25: Critical 15–25 · High 10–12 · Medium 5–9 · Low 1–4.
Hover, tap, or focus a chip and press Enter for the events driving its likelihood, why it matched this theater, and what to do about it. Pinning is what makes the cited sources clickable.
Top exposures (inherent → residual)
Every likelihood cites its driving events — the top driver is shown under each row and the full list is in the console. A row with no events of its own is an inherited row: it names the upstream asset its likelihood was damped from, and cites that asset's events. Residual reflects the best active treatment on the row.
| Asset | Region / exposure | Threat scenario | L × I | Inherent | Residual | Treatment |
|---|---|---|---|---|---|---|
| Manufacturing plant — Shenzhen plant-shenzhen · Plant | South China Sea direct match ✈ US State L2 · UK FCDO L1 · divergent | Maritime coercion or clashes disrupt shipping lanes and regional manufacturing logistics · Armed clash · Hanoi, Ha Noi, Vietnam, Republic Of — machine-coded · 11 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 3 × 4 | 12 high | 2 low | Active Mitigate · Redundancy · Manufacturing Qualified redundant pair (Shenzhen ↔ Guadalajara) carries the Americas controls line |
| EU shipping route — Red Sea transit route-redsea · Route | Red Sea & Horn of Africa direct match | Attacks on shipping force rerouting via the Cape (+12-18 days lead time) and raise insurance costs · Armed clash · Tabuk, Tabuk, Saudi Arabia — machine-coded · 5 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 3 × 4 | 12 high | ⚠ untreated | — |
| Foundry partner — Hsinchu ⚠ SPOF fab-hsinchu · Supplier (tier 1) | Taiwan Strait direct match ✈ US State L1 · UK FCDO L1 · aligned | Blockade, quarantine, or kinetic escalation halts fab output, port operations, and cross-strait logistics (+2 more) | 2 × 5 | 10 high | 10 high | Active Mitigate · Redundancy · Ops / BCP Qualified second-source fab (Kumamoto) + 60-day finished-goods buffer |
| Manufacturing plant — Guadalajara plant-guadalajara · Plant | Latin America direct match ✈ US State L2 · UK FCDO L2 · aligned | Cartel violence, unrest or coercion disrupts nearshored manufacturing and overland freight · Assault · Managua, Managua, Nicaragua — machine-coded · 4 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 3 × 3 | 9 medium | = 9 inherent | — |
| EMS partner — Kaohsiung ⚠ SPOF ems-kaohsiung · Supplier (tier 1) | Taiwan Strait direct match ✈ US State L1 · UK FCDO L1 · aligned | Blockade, quarantine, or kinetic escalation halts fab output, port operations, and cross-strait logistics (+2 more) | 2 × 4 | 8 medium | 8 medium | Active Mitigate · Resilience · Supply Chain Dual-site EMS with Penang failover + expedited-logistics playbook |
| Assembly & test — Penang ⚠ SPOF plant-penang · Plant | Southeast Asia direct match ✈ US State L1 · UK FCDO L2 · divergent | Coercion, unrest or conflict disrupts electronics assembly, regional manufacturing and Malacca Strait shipping · Armed clash · Malaysia — machine-coded · 3 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 2 × 4 | 8 medium | = 8 inherent | — |
| Titanium mill — St Petersburg supplier-stpetersburg · Supplier (tier 2) | Russia–Ukraine in-country match ✈ US State L4 · UK FCDO L4 · aligned | Strikes, mobilization, or occupation disrupt supplier operations and export corridors · Assault · Moldova — machine-coded · 5 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 2 × 4 | 8 medium | = 8 inherent | — |
| Cloud region — Singapore (ap-southeast-1) cloud-singapore · Data center | Southeast Asia direct match ✈ US State L1 · UK FCDO L1 · aligned | Coercion, unrest or conflict disrupts electronics assembly, regional manufacturing and Malacca Strait shipping · Armed clash · Malaysia — machine-coded · 3 outlets · coder confidence 100/100 representative article ↗ (2026-10-06) (+2 more) | 2 × 4 | 8 medium | = 8 inherent | — |
Business continuity — what breaks, and what it costs
Computed from the dependency graph (ISO 22301 business-impact analysis): single points of failure are size-1 minimal cut sets — no hand-flagging. Revenue figures are customer-entered planning inputs.
| Service | Tier | Recovery target / longest tolerable outage (RTO / MTPD) | Revenue / day | Single points of failure | Loss if down for the longest tolerable outage |
|---|---|---|---|---|---|
| EU sensor-revenue line | 1 | 24h / 72h | $1.85M | ⚠ EMS partner — Kaohsiung⚠ Foundry partner — Hsinchu⚠ Penang grid feed⚠ Assembly & test — Penang⚠ Noble-gas supplier — Odesa | $5.55M |
| Americas controls mfg | 2 | 48h / 120h | $640k | none — survives any single loss (smallest cut: 1 pair) | $3.2M |
The adversarial read: a coercive actor optimizes for the cheapest cut set. Each SPOF above is both a continuity gap and a pressure point — and each is a Redundancy treatment (5Rs) waiting to be recorded and funded.
Treatment program (5Rs)
ISO 31000 decisions with named owners, dates, and the residual each achieves — assessment turned into a managed system.
| Exposure | Decision | Control (5R) | Owner | Status | Due | Residual |
|---|---|---|---|---|---|---|
| Foundry partner — Hsinchu · Taiwan Strait Qualified second-source fab (Kumamoto) + 60-day finished-goods buffer | Mitigate | Redundancy | Ops / BCP | Active | 2026-12-18 | 2×5 = 10 |
| EMS partner — Kaohsiung · Taiwan Strait Dual-site EMS with Penang failover + expedited-logistics playbook | Mitigate | Resilience | Supply Chain | Active | 2027-01-02 | 2×4 = 8 |
| Manufacturing plant — Shenzhen · South China Sea Qualified redundant pair (Shenzhen ↔ Guadalajara) carries the Americas controls line | Mitigate | Redundancy | Manufacturing | Active | 2027-02-17 | 1×2 = 2 |
Framework mapping
| Framework | Requirement | Evidence in this product |
|---|---|---|
| ISO 22301 §8.2.2 | Business impact analysis: prioritized activities, dependencies, and supporting resources | Asset & dependency register — typed dependency graph, service tiers, RTO/MTPD per service |
| ISO 22301 §8.2.3 | Risk assessment: identify and analyze risks of disruption to prioritized activities | Exposure register — likelihood × impact per asset with cited event drivers |
| ISO 22301 §8.3 | Business continuity strategies and solutions, including reducing single points of failure | Computed SPOF / cut-set readout + 5Rs treatments (Redundancy, Resilience, Recovery…) |
| ISO 22301 §9.1 / §9.3 | Monitoring, measurement, evaluation — and management review with evidence | Treatment-coverage & register-hygiene KPIs, posture trend, this board pack |
| ISO 31000 §6.4–6.5 | Risk assessment and risk treatment: decision (accept/mitigate/transfer/avoid), owner, residual | Per-row treatment records — decision + 5Rs control + owner/status/due + residual L×I |
| NIS2 Art. 21(2)(c) | Business continuity and crisis management (the analysis underpinning them) | Documented BIA (dependency graph), recorded RTO/MTPD targets, and continuity treatment decisions — inputs to BC/DR planning, not the backup/recovery capability itself |
| NIS2 Art. 21(2)(d) | Supply-chain security: risks in relationships with direct suppliers and providers | Supplier assets + typed material-supply/logistics edges + inherited (propagated) exposure |
| SEC Reg S-K Item 106(c)(1) | Board oversight of cybersecurity risk — Reg S-K Item 106(c)(1) | Board-pack export + posture trend as recurring oversight artifacts; cyber-posture flags and state-attributed advisory events as the register's cyber slice (not a cyber risk-management program) |
Argus provides evidence and working artifacts for these requirements; it does not by itself constitute compliance with any framework. Figures marked 'customer-entered' are directional planning inputs, not audited financials.