Article

Cascading risk: Why high-value assets matter beyond system boundaries

Risk propagates through shared services, identity, and data pathways—but most programs can’t see or manage how disruption spreads.

In 2024, a cyberattack on a major healthcare payments processor demonstrated how dependent the U.S. healthcare system had become on a small number of critical services that move money and information. 

When the company took its systems offline in response to the attack, hospitals, clinics, and physician practices lost a key pathway for processing transactions. Those organizations faced operational and financial strain, while patients experienced delays and disruptions to care. 

For those organizations, the affected service was essential to daily operations. With limited alternatives available, routine business processes slowed or stopped. The incident drew significant public and government attention. 

This is cascading risk, and it's not unique to healthcare. Many U.S. federal agency missions operate in much the same way. 



Risk follows connections, not boundaries

Behind every service—processing payments, verifying identity and eligibility, issuing benefits—sits a network of connected systems. Identity services, shared platforms, cloud environments, and partners within and outside of federal agencies all play a role in delivering the outcome. 

That interconnectedness keeps missions running. It also determines how service disruption and compromise spread along with the level of risk that organizations may face. 

When one system fails, the impact doesn’t stop at its boundary. The disruption adds further risk, following the same routes as data and access. By relying on trusted relationships and shared infrastructure, disruption impacts can amplify when things go wrong.  

That’s where most cybersecurity programs fall short. They assess systems one at a time, verify controls, document compliance, and check individual assets against requirements. Those activities are necessary for risk management. But they aren’t sufficient to fully illuminate how the level of risk may change once something goes wrong or the potential to increase the risk to other connected systems, processes, and missions. 

Under the Office of Management and Budget’s Memorandum M-19-03 and the Department of Homeland Security’s Binding Operational Directive 18-02, certain systems are designated as high-value assets (HVAs) because of their importance to agency missions and operations. Risks to these systems can have agency-wide consequences, making them a top priority for protection and oversight. 

But HVAs don’t fail alone. 

In practice, risk isn’t defined solely by the consequence to the asset itself. It’s shaped by the potential consequences to systems that connect to it and the impact to the missions and communities those systems support. 



Limited visibility into where and how risk cascades

Cascading risk can be more difficult to manage precisely because systems are often viewed individually rather than as interconnected parts of a larger mission. Most teams understand the systems they own, including how those systems are configured, how controls are applied, and how they perform under normal conditions.  

Data, identities, access, and shared services connect systems across organizational lines. Without mapping systems and risks in a way that shows how disruption in one system could affect another, agency leaders lose critical information necessary to their understanding of mission risk. Leaders may know that individual controls are functioning properly without understanding which mission outcomes could be affected by an incident and how consequences could compound.

Identifying where responsibility lies is equally challenging. Individual systems typically have defined owners, but the dependencies between them often don’t. Those connections cross teams and organizations, relying on relationships and expectations that may be informal or untested.

The consequences become clear during an incident. One team may contain a problem within its own environment while failing to recognize downstream effects. Another may detect signs of disruption without understanding where it originated or who should respond. Coordination slows precisely when rapid action is needed.

Managing this risk requires an end-to-end view of mission dependencies. Agencies must understand how critical systems, services, and partners interact, identify where disruption could spread, and establish clear responsibilities before an incident occurs. Holistic reviews can reveal vulnerabilities and coordination gaps that system-by-system assessments often miss. 



Managing risk to the mission regardless of where the disruption starts

Securing HVA systems begins with understanding the dependencies that enable critical mission outcomes and the risks that threaten them. That involves starting with a mission outcome and tracing the systems that support it. Agencies can use the five-step review process below to identify critical dependencies and potential points of failure. 

  1. Select a critical mission outcome. Start with a service whose disruption would have significant operational, economic, or public consequences, such as processing a benefit or issuing a credential. Keep the scope narrow enough to evaluate quickly.
  2. Trace the essential dependencies. Identify the systems, data, identity services, infrastructure, vendors, and other resources required to deliver the mission outcome. Prioritize dependencies whose loss or compromise would stop or significantly degrade the service.
  3. Test credible disruption scenarios. Examine what would happen if a critical dependency became unavailable, compromised, or unreliable. Determine how the disruption could spread, how long operations could continue, what alternatives exist, and whether the effects could be contained or reversed. 
  4. Assign responsibility to dependencies across boundaries. Define who monitors each of the critical dependencies, leads communication during disruptions, and is charged with leading the response.
  5. Prioritize actions and keep the review current. Prioritize dependencies based on those with the highest mission impact, limited alternatives, or weak recovery options. Update the review as systems, providers, and mission processes change.

Centrality shows how connected a system is; criticality shows what happens if it fails. Closing the gap between those measures will define the next generation of HVA prioritization. Until organizations weigh mission criticality alongside exploitability and exposure, even sophisticated models will continue to rank technology risk rather than mission risk. 

insight_image

Amanda Kane, Partner

insight_image

Nong Nai, Director

Steven McKinnon, Associate Director


Let us guide you

Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.

Stay ahead of the curve with our latest insights, expertly tailored to your industry.