YUNT

Special application · dynamic risk matrix

The risk matrix, alive.

Continuous risk monitoring, performed by a digital collaborator.

The eight categories it keeps alive

  • Cybersecurity
  • AI
  • Operations
  • Third parties
  • Regulatory
  • Reputational
  • Financial
  • Geopolitical

Rolled out in phases, by criticality.

The 2026 context

Periodic reports are no longer enough.

Nothing here is a forecast: it is what the sector is already documenting.

  1. A.

    Faster threats

    Automated, complex attacks that spread across areas and critical third parties.

  2. B.

    Accelerated AI adoption

    New vectors in autonomous agents and non-human identities.

  3. C.

    Crises that escalate fast

    Technology incidents that turn into multi-sector disruptions.

  4. D.

    The quarterly report arrives late

    It limits early detection, prioritization and timely escalation.

In line with what WEF, IBM, KPMG, CISA and ENISA document.

The white paper

The whole argument, written down.

Everything this page summarizes is developed at length here: why periodic reporting stopped being enough, and what architecture replaces it.

The proposal, in one sentence

This is more than a dashboard: it is the specialist who keeps it alive.

A dashboard is a tool: someone has to feed it, prioritize it and explain it. A digital collaborator practices the craft: it monitors the sources, updates the matrix, prioritizes the alerts, escalates what belongs upstairs and prepares the report — every day, inside your systems.

And if the company wants to see that information as a dashboard, it can: the dashboard becomes a view of its work, not the product.

The role, concrete

What it does, every day.

Four jobs it owns end to end, the same way a person in the seat would.

01/04

It monitors the sources
Internal ones (SIEM, IAM, GRC, continuity, third parties) and external ones (CISA, ENISA, WEF, regulatory and geopolitical changes).

02/04

It keeps the risk matrix alive
It updates probability, impact, trend and control status with each module's KRIs — the matrix stops being a spreadsheet somebody remembers to refresh.

03/04

It prioritizes and cuts the noise
It correlates signals, separates what is material from what is merely informative, and escalates only what crosses the threshold — quoting the rule that triggered it.

04/04

It prepares the executive report
Continuous, contextualized information for the Executive Committee and the Board, in their format, ready to decide on.

The engineering behind it

How it connects, what governs it, what it produces.

What comes in

  • Internal sources

    SIEM · IAM · GRC · BCP · TPRM

  • External sources

    CISA · ENISA · WEF · regulatory

  • The role's manual

    KRIs · thresholds · governance

The Risk Specialist

digital collaborator · governed by its manual

continuous cycle

  1. monitor
  2. correlate signals
  3. update the matrix (KRIs)
  4. escalate by threshold
  5. report

What comes out

  • A living risk matrix

    8 categories · continuous status

  • Escalated alerts

    to the owner, with the rule quoted

  • Executive report

    Committee and Board · with a human signature

Glassbox

An auditable record of every analysis and every decision. Everything it does is on record.

Built to measure

Every specialist is built for one company.

The sources above are examples, not a package: the role is built around your systems, your thresholds and your report format. And the real scope is set by what the organization can actually deliver — it integrates the data it is genuinely given access to, not the data it is assumed to have.

That is why deployment starts with 1 or 2 critical modules and grows as the sources open up. What cannot be connected yet is declared as a gap, not filled in.

How it works with people

Like any member of the team: with a boss, with peers and with rules.

Upward

It reports to an owner

The specialist has a human boss (the CISO, the risk manager, whoever is named): it reports to them, asks for approval and answers to them. The question “who owns this data?” has a one-line answer.

Sideways

It works with the teams

It asks security, operations and suppliers for evidence; it delivers findings with context; and the corrections it receives stay installed as rules, for good.

Its criteria

Written in a manual

Tolerance thresholds, escalation rules, report format: written, versioned and auditable. Changing the criteria is editing one line, not retraining anything.

Human signature

Anything material is decided by a person. Always.

  • The specialist detects, analyzes and proposes. Escalating a crisis, briefing the Board or closing a risk carries a human signature.

  • Nothing is invented: a figure without a source is declared missing, not filled in.

  • If an alert turns out to be misclassified, the correction is written into the manual — and it does not happen twice.

The deliverable

This is how the report reaches the Committee, every week.

Same structure every Monday, so the Committee reads it without a preamble.

Weekly risk report — Week 34

Prepared by: The Risk Specialist · Pending review: Risk Management

Monday 08:00

distribution: Executive Committee

Illustrative view, sample data

78 12%

Global risk index

8

Critical alerts

3 of 45

CCM controls failing

6h / 21h

MTTD / MTTR

  • Compromise of AI agents

    AI · Prob. High · Impact Critical

    threshold: 2 CCM controls failing

  • Unauthenticated vulnerabilities

    Cybersecurity · Prob. High · Impact Critical

    CISA alert + exposed asset

  • Critical third-party exposure

    Third parties · Prob. Medium · Impact High

    incident reported at a T1 supplier

Requires your decision this week:

  1. 1.Approve escalating the AI-agent risk to the Board.
  2. 2.Authorize an extraordinary review of supplier T1.

Signature:

The report is not distributed without review and signature by the responsible human. Every figure is traceable in the glassbox.

The area team

A team that specializes in risk.

Corporate governance, consulting, cyber security and data engineering. The digital collaborator practices the craft — these are the people who know it.

Georgina Núñez

Area Director

Georgina Núñez

Corporate Governance Partner

PhD in Economics | ex-Economic Affairs Officer, United Nations (UN)

Who builds it and keeps it running

The specialist reports to the area director. Behind it, the team that engineers it, secures it and audits its criteria.

  • Daniel Insulza

    Daniel Insulza

    Senior Consultant

    Attorney, Colorado USA | MSc Innovation Management and Entrepreneurship | ex-consultant on competitiveness and innovation at the IDB

  • Cristopher Lovold

    Cristopher Lovold

    CTO

    MSc Information Systems, London School of Economics | Founder Elina PMS | Web Dev Northrop Grumman, Pentagon USA

  • Salman Tariq

    Salman Tariq

    Data Software Engineer / cofounder

    Data Science Software Engineer | Masters, Data and Information Science, TH Köln

  • Eduardo Zamorano

    Eduardo Zamorano

    Sr. Cyber Security Engineer

    Ethical Hacker | ex-Head of IT, Comisión Nacional de Valores | Cyber Security Sr. Engineer at Mercado Libre and Falabella

What they write

Their criteria are public.

Risk and corporate governance, signed by the same people who answer for the role — not by the marketing team.

imagen de equipo viendo un monitor de riesgos
Article

From Crisis Activation to Continuous Risk Sensing: Reframing Crisis Management for the Permacrisis Era

A model of continuous risk sensing and graduated crisis activation, with clear thresholds and learning to build resilience without maintaining a permanent state of emergency.

Daniel InsulzaDaniel Insulza · Abogado & Consultor Senior
Imagen de AI y gobierno corporativo
Article

The Role of Corporate Governance in the Company’s Digital Strategy

The Role of Corporate Governance in the Company’s Digital Strategy and Security

Giorgina Nuñez - Doctorado en Economía | Partner Estratégico Gobierno Corporativo @YuntGeorgina Nuñez · Doctorado en Economía | Partner Estratégico Gobierno Corporativo @Yunt
From Periodic Reporting to Continuous Monitoring: A New Architecture for Risk Management in the Digital Age
Article

A New Architecture for Risk Management in the Digital Age

From Periodic Reporting to Continuous Monitoring: A New Architecture for Risk Management in the Digital Age

Daniel InsulzaDaniel Insulza · Abogado & Consultor Senior
Visit the blog