YUNT
Article14 min read

From Crisis Activation to Continuous Risk Sensing: Reframing Crisis Management for the Permacrisis Era

A model of continuous risk sensing and graduated crisis activation, with clear thresholds and learning to build resilience without maintaining a permanent state of emergency.

Daniel InsulzaDaniel InsulzaAbogado & Consultor Senior
imagen de equipo viendo un monitor de riesgos

Abstract

Crisis management is moving from an event-activated function to a continuously operating organizational capability. The traditional model, meaning normal operations, incident, activation of a crisis team, response, recovery, and deactivation remains useful for discrete events such as product recalls, cyberattacks, industrial accidents, or sudden regulatory interventions. However, some in 2026 increasingly describe an operating environment shaped by permacrisis, polycrisis, permanent scrutiny, fragmented information ecosystems, AI-enabled misinformation, geopolitical volatility, regulatory fragmentation, sanctions exposure, and compounding disruption (Chambers and Partners, 2026; PwC, 2026; World Economic Forum, 2026). In that environment, waiting until a crisis team is formally activated can leave organizations exposed during the earlier stages of weak-signal emergence, stakeholder concern, narrative formation, compliance exposure, and reputational escalation. This paper develops a third model: continuous risk sensing with graduated crisis activation. The model separates always-on monitoring and issue management from formal crisis-team activation, allowing organizations to identify, investigate, and intervene before every issue becomes a crisis. It also warns that a permanent crisis culture can create crisis fatigue, desensitization, and escalation blindness. The recommended approach is therefore not permanent crisis-team operation, but permanent organizational readiness supported by clear thresholds, cross-functional ownership, compliance integration, political-risk awareness, and disciplined recovery learning.

Key words: risk monitoring, resilience, and gradual crisis activation

Introduction

Corporate crisis management has traditionally been organized around an episodic logic. Organizations operate normally until an incident occurs; then they activate a crisis-management team, centralize decision-making, communicate with stakeholders, manage the disruption, recover, and deactivate the temporary crisis structure. This model is still appropriate when the organization faces a bounded and clearly identifiable event. A major recall, ransomware attack, industrial accident, plant shutdown, public health issue, or abrupt regulatory action may require a dedicated team with emergency authority and highly coordinated response protocols.

The problem is that many contemporary threats no longer behave like bounded events. The crisis environment described in 2026 is one of recurrence, simultaneity, and acceleration. Chambers and Partners’ Crisis Management 2026 guide states that crisis management has continued to evolve from response-focused mitigation toward a full life-cycle discipline that includes risk identification, prevention, preparedness, rapid response, recovery, and remediation (Chambers and Partners, 2026). PwC’s Global Centre for Crisis and Resilience similarly frames the business environment as an era of “permacrisis” in which companies face a more complex risk landscape and increasing threat of disruption (PwC, 2026). Together, these sources suggest that crisis management is becoming less a temporary emergency function and more a continuous capability embedded in governance, risk, communications, legal, compliance, operations, and leadership systems.

This paper uses that shift to develop a practical distinction. The emerging objective is not to keep the crisis team permanently activated. Instead, organizations should maintain permanent capability for sensing, assessing, and managing crisis precursors, while reserving formal crisis-team activation for issues that cross defined escalation thresholds. This distinction is especially important for reputational risk because reputation crises often develop through weak signals, stakeholder concern, social discussion, media attention, narrative formation, escalation, and only then crisis recognition. By the time the crisis committee is called, the organization may already have lost valuable time.

The Traditional Crisis-Activation Model

The traditional model can be summarized as a linear sequence: normal operations, incident, activation of a crisis team, crisis response, recovery, deactivation, and return to normal operations. Its strength is clarity. It defines when extraordinary governance begins, who has authority, which executives participate, how communications are approved, and when the organization can return to standard operating procedures. It also prevents routine business issues from being over-managed as crises.

However, the model depends on two assumptions that are increasingly fragile. First, it assumes that crises are discrete deviations from a stable baseline. Second, it assumes that the organization can recognize the moment at which a crisis begins. In 2026 risk literature, both assumptions are under strain. Richard Chambers argues that traditional risk management has become inadequate in the era of permacrisis because risks are continuous, interconnected, compounding, and no longer aligned with quarterly or annual review cycles (Chambers, 2026). The implication for crisis management is direct: if risk formation is continuous, then crisis readiness cannot depend only on late activation.

The Permacrisis and Continuous-Resilience Model

The permacrisis model reflects a different sequence: continuous monitoring, emerging issue, escalation, intervention, stabilization, continued monitoring, and the next issue. Rather than treating crises as rare interruptions, this model treats instability as the operating environment. A 2026 Organizational Dynamics special issue call on “Resilience in the Age of Permacrisis” states that managers are no longer navigating discrete crises, but disruptions that compound, overlap, and recur before organizations have recovered from the previous one (Academy of Management, 2026). PwC describes a similar condition, noting that organizations are adapting to constant disruption by transforming their approach to business resilience in an era of permacrisis and polycrisis (PwC, 2026).

In this environment, continuity, agility, sensing, and learning become central governance capabilities. The organization must be able to monitor weak signals, interpret them quickly, decide whether they matter, allocate ownership, and intervene before harm scales. The crisis-management team still exists, but it is no longer the primary mechanism for every emerging issue. Instead, it becomes an escalation mechanism for issues that exceed predefined tolerances or require centralized authority.

A Third Model: Continuous Risk Sensing with Graduated Crisis Activation

The most sophisticated model is not “traditional activation” and not “permanent crisis.” It is continuous risk sensing with graduated crisis activation. This model accepts that organizations must monitor dozens or hundreds of potential issues continuously, especially in multinational, multi-jurisdictional, or highly regulated environments. At the same time, it avoids treating every weak signal as a full crisis. Its operating principle is simple: always-on risk management should precede crisis activation; formal crisis activation should occur only when an issue crosses clear thresholds of probability, impact, stakeholder sensitivity, narrative momentum, operational disruption, legal exposure, compliance exposure, political sensitivity, or reputational consequence (Chambers, 2026; Clyde & Co, 2026). In comparative analysis, Table 1 describes three types of models and identifies their operating logic, as well as their responsiveness and the degree of sophistication of their response to a specific crisis.

Table 1. Three models of crisis-management architecture

Model: Traditional

  • Operating logic: Crisis is an exceptional event.

  • Response pattern: Crisis occurs; crisis team is activated.

Model: Permacrisis

  • Operating logic: Crisis is a continuous condition.

  • Response pattern: Permanent response capability manages constant disruption.

Model: Continuous risk sensing

  • Operating logic: Crisis precursors can be detected and managed before escalation.

  • Response pattern: Always-on monitoring and issue management operate continuously; specialized crisis teams activate only when necessary.

Reputational Risk as the Strongest Case for Continuous Sensing

Reputation is particularly suited to continuous risk sensing because reputational crises usually begin before formal incident recognition. They often develop through a chain of weak signals, stakeholder concern, social discussion, media attention, narrative formation, escalation, and crisis. FGS Global’s 2026 crisis-management analysis emphasizes fragmentation of information sources, declining trust in traditional institutions, and an atomized influence environment in which companies can no longer rely only on legacy media to communicate with stakeholders (FGS Global, 2026). UPRAISE PR’s 2026 analysis similarly argues that crisis management is no longer a reactive communications function, but a proactive discipline embedded in leadership, digital infrastructure, and enterprise risk strategy (UPRAISE PR, 2026).

These arguments matter because reputational harm is narrative-driven. A misleading video, activist claim, employee post, regulatory rumor, customer complaint, executive controversy, or misinformation thread can form a public narrative before the organization has formally classified the issue as a crisis. Jackson Spalding’s 2026 reputation-risk analysis identifies misinformation, AI, and fragmented audiences as forces that require organizations to prepare, verify, and respond at internet speed (Jackson Spalding, 2026). In reputational risk, therefore, the activation question is not simply “Has a crisis occurred?” but “Is a narrative forming, who is amplifying it, which stakeholders are reacting, and what level of intervention is required now?”

Compliance and Political-Volatility Implications

Continuous crisis sensing is also increasingly important for compliance. In 2026, compliance risk is not limited to periodic legal review or annual control testing. Sanctions, export controls, anti-money-laundering expectations, data privacy rules, artificial-intelligence governance, ESG disclosure requirements, and sector-specific enforcement priorities can change quickly across jurisdictions. Moody’s describes the 2026 sanctions environment as more complex, with expanding sanctioned-party networks, ownership-and-control challenges, export-control implications, regional divergence among sanctions regimes, and increasingly sophisticated evasion tactics (Moody’s, 2026). Similarly, Thomson Reuters identifies fraud, financial crime, AI-enabled misconduct, cyber-enabled scams, and evolving regulatory expectations as major global compliance concerns for 2026 (Thomson Reuters, 2026). These conditions make compliance a continuous sensing function rather than a static checklist.

The political environment also strengthens the case for graduated activation. The World Economic Forum’s Global Risks Report 2026 identifies geoeconomic confrontation, interstate conflict, societal polarization, misinformation, and a deteriorating global risk outlook as central features of the 2026 environment (World Economic Forum, 2026). WTW’s 2026 Political Risk Survey reports that political risks are shifting inward as tariffs, domestic polarization, gray-zone threats, infrastructure attacks, sanctions, and economic coercion affect companies’ operating models (WTW, 2026a). WTW’s 2026 directors’ and officers’ survey also finds that geopolitical risk has entered the top tier of board-level concerns because conflicts, trade wars, sanctions, tariffs, and supply-chain fragmentation create financial and reputational exposure for directors and companies (WTW, 2026b).

For companies, the practical danger is that political volatility can turn a routine business decision into a crisis trigger. A supplier relationship may become problematic because of sanctions or forced-labor concerns; a market-entry decision may become politically sensitive because of tariffs or geopolitical alignment; a public statement may be interpreted through polarized political narratives; a regulatory inquiry may quickly become a reputational issue; and an operational disruption may spread across borders through supply-chain, cyber, insurance, and investor channels. Clyde & Co’s 2026 Corporate Risk Radar describes elevated risk as an interconnected and increasingly permanent feature of the operating environment, where one event can trigger operational disruption, regulatory exposure, and reputational impact simultaneously (Clyde & Co, 2026). In this context, compliance, political risk, and reputation should not be monitored in separate silos; they should feed a shared escalation architecture.

A Graduated Activation Framework

The proposed model uses five levels. Levels 1 through 3 are designed to operate without formally activating the crisis-management team. Levels 4 and 5 preserve the traditional crisis function for exceptional situations and structured recovery.

Level 1: Monitor

At the monitoring level, the organization uses AI, social, media, regulatory, stakeholder, operational, sanctions, geopolitical, and market monitoring to detect early signals. The goal is not to label every signal as a crisis; it is to maintain visibility across the risk environment and identify changes in volume, sentiment, stakeholder salience, regulatory attention, political exposure, compliance exposure, or narrative velocity (Moody’s, 2026; WTW, 2026a).

Level 2: Investigate

At the investigation level, the organization validates the signal, assesses probability and impact, identifies affected stakeholders, and determines whether a public, political, legal, regulatory, or internal narrative is forming. Investigation should include communications, legal, compliance, operational, public affairs, and subject-matter perspectives as needed, but it should remain proportionate to the signal (Chambers and Partners, 2026; Clyde & Co, 2026).

Level 3: Manage

At the management level, a business owner takes corrective action while communications, legal, compliance, risk, public affairs, security, or government-affairs functions support the response. Senior management may be informed, but decision-making remains distributed unless escalation criteria are met. This level is the core innovation of the model: it creates a disciplined space for intervention before formal crisis activation, especially when an issue is still manageable as a compliance, stakeholder, operational, or political-risk matter rather than a full crisis (Thomson Reuters, 2026; World Economic Forum, 2026).

Level 4: Crisis

At the crisis level, the formal crisis-management team is activated. Decision-making is centralized, crisis communications protocols apply, legal, regulatory, political-risk, and compliance positions are coordinated, and board escalation occurs when thresholds require it. This level preserves the authority and focus of traditional crisis management but prevents overuse by reserving activation for exceptional cases (WTW, 2026b; Clyde & Co, 2026).

Level 5: Recovery and Learning

At the recovery and learning level, the organization conducts remediation, stakeholder repair, root-cause analysis, lessons learned, and updates to monitoring indicators, thresholds, playbooks, and training. This level closes the loop between crisis response and future sensing, turning each intervention into a refinement of the resilience system.

The Danger of Permanent Crisis Culture

The model must also guard against a major danger: treating every issue as urgent can make organizations worse at detecting true crises. When everything is described as exceptional, nothing remains exceptional. Employees experience crisis fatigue, executives become desensitized, and genuinely dangerous signals may be normalized. This risk is especially acute in organizations that face simultaneous regulatory scrutiny, activism, misinformation, operational disruption, labor issues, sanctions exposure, cyber threats, and political pressure (FGS Global, 2026; World Economic Forum, 2026).

For that reason, the model should include escalation discipline. Thresholds must be explicit, measurable where possible, and revisited after each major issue. Potential criteria include stakeholder vulnerability, safety implications, regulatory exposure, sanctions or export-control implications, media velocity, social amplification, misinformation risk, leadership involvement, litigation exposure, political sensitivity, operational disruption, and whether the issue threatens organizational legitimacy. The purpose of monitoring is not to create permanent alarm; it is to preserve judgment (Chambers, 2026; Moody’s, 2026).

Implications for Companies Operating in Volatile Environments

For companies operating across multiple markets, regulatory systems, political environments, stakeholder communities, and digital information spaces, continuous reputational-risk monitoring is more scalable than continuous crisis activation. A company may need to monitor dozens or hundreds of local issues across countries, brands, supply chains, labor environments, regulatory regimes, community relationships, sustainability debates, health and safety concerns, sanctions exposure, trade restrictions, and digital misinformation risks. Activating a formal crisis team for every issue would overload leadership and dilute urgency. A graduated model allows the organization to detect and manage most issues at Levels 1 through 3, while reserving Level 4 for issues that cross defined thresholds (Clyde & Co, 2026; WTW, 2026a).

This architecture also supports better governance. It clarifies which issues belong to business owners, which require functional support, which require executive awareness, and which require crisis-team activation. It is also consistent with the 2026 movement toward full life-cycle crisis management because it connects prevention, preparedness, response, recovery, compliance learning, political-risk scanning, and stakeholder repair into one operating system rather than treating crisis response as a stand-alone emergency process (Chambers and Partners, 2026; PwC, 2026).

Conclusion

Crisis management is shifting from an event-activated function to a continuously operating organizational capability. The traditional model remains valuable for discrete crises that require centralized authority and rapid mobilization. However, the 2026 risk environment increasingly requires organizations to sense, interpret, and intervene before an issue becomes a full crisis, particularly when compliance exposure, political volatility, misinformation, stakeholder concern, and operational disruption interact. The best answer is not permanent crisis-team activation, which risks fatigue and desensitization, but always-on risk management combined with graduated crisis activation. In this model, monitoring, investigation, and issue management operate continuously, while formal crisis activation remains an escalation mechanism. For reputational risk, where crises often begin through weak signals and narrative formation, this distinction is especially powerful. It allows organizations to protect attention, preserve judgment, and build resilience without normalizing a permanent state of emergency (World Economic Forum, 2026; Clyde & Co, 2026).

References

BDO Canada. (2026). Global Risk Landscape Report 2026. Retrieved from BDO Canada.

Academy of Management. (2026). Resilience in the Age of Permacrisis, Special Issue of Organizational Dynamics. Retrieved from Academy of Management.

Clyde & Co. (2026). Corporate Risk Radar 2026: Navigating Risk Without Respite. Retrieved from Clyde & Co.

Chambers and Partners. (2026). Crisis Management 2026. Retrieved from Chambers and Partners.

Chambers and Partners. (2026). Crisis Management 2026: USA: Washington, DC Trends and Developments. Retrieved from Chambers and Partners.

Chambers, R. (2026). Permacrisis Has Rendered Traditional Risk Management Obsolete. Retrieved from Audit Beacon.

FGS Global. (2026). Crisis Management 2026: Trends and Developments. Retrieved from FGS Global.

Jackson Spalding. (2026). The Age of Chaos: Reputation Risks Communicators Can’t Ignore in 2026. Retrieved from Jackson Spalding.

Moody’s. (2026). The Global Sanctions Landscape, 2026: Implications and Compliance Challenges. Retrieved from Moody’s.

Thomson Reuters Institute. (2026). 10 Global Compliance Concerns for 2026. Retrieved from Thomson Reuters.

PwC. (2026). Global Centre for Crisis and Resilience. Retrieved from PwC.

UPRAISE PR. (2026). PR Crisis Management in 2026: Strategies for a Digital-First World. Retrieved from UPRAISE PR.

World Economic Forum. (2026). Global Risks Report 2026. Retrieved from World Economic Forum.

WTW. (2026a). Political Risk Survey Report 2026. Retrieved from WTW.

WTW. (2026b). Global Directors’ and Officers’ Survey Report 2026: Geopolitical. Retrieved from WTW.

Keep reading

Un colaborador digital de Yunt sentado en el suelo junto a un laptop abierto que muestra su rostro en pantalla.
Article

Harness: What surrounds the model

The model's intelligence is not what makes an AI work. What makes it work is the harness: six decisions a company makes for a digital collaborator, the same ones it makes for a person.

Rodrigo Medina CEO @YuntRodrigo Medina · Founder & CEO
Ilustración de una figura mecánica con el logo de Yunt que intercambia dos módulos, LLM A y LLM B.
Article

Astra, and why we are AI agnostic

OpenAI shipped GPT-6 Astra; the next is weeks away. AI agnostic means swapping the model is one line, and your handbook, data and records stay yours.

Rodrigo Medina CEO @YuntRodrigo Medina · Founder & CEO
All notes