PFV Process Flow Visibility
Work with Don Woodward

The method does the work.
I'm the guide.

Process Flow Visibility finds the weeks of waiting hidden inside a three-day process — and tells you what to fix first. I help security and IT leaders run it on the workflows that matter, then hand the capability back to your team.

Don Woodward — creator of Process Flow Visibility

Map one process with me. In an hour, you’ll see where the time is hiding — and what it’s likely costing.

Book a session →

Is there a delay in your operation you’ll have to answer for?

The problem usually isn’t that your team is slow. It’s that the work waits — in queues and handoffs nobody’s measuring. That idle time is where dwell, cost, and missed timelines come from.

The elevator ask — two questions, fifteen seconds
How many tickets, changes, or findings are open right now? How many finish in a week? Divide the first by the second — that's how long each one really takes. Does that cycle time work for your business? If not, the next thirty minutes shows you where the time goes — and why.
See it on one of your processes — 2-minute assessment →
Creator of PFV· Former Cisco Executive· Fortune 500 Leadership· CISSP· CEH· ITIL Expert
Track record · flow analysis in practice

What organizations discover

The delay was always there. PFV made it visible enough to act on.

These results come from Don’s prior consulting engagements using the flow-analysis discipline PFV now packages — not from the self-serve PFV toolkit, which is entering its own pre-registered field trials below.

Property Management

Hidden delays were destroying accounts receivable

PFV mapped the deployment process end to end and surfaced delays that were directly costing receivables — invisible to everyone inside the organization until the process was made visible.

Visibility restored AR recovery — and the business.
Global Manufacturing

Global network rollout, from “unknown” to predictable

A global manufacturer had no reliable estimate for rolling out new network equipment. PFV mapped every step and produced a credible, data-backed timeline leadership could present and defend.

A defensible rollout timeline, for the first time.
Large Financial Services

Server build: 30+ days reduced to 12

PFV surfaced the exact sources of delay and rework that had pushed cycle time past 30 days — waste never quantified before. Acting on the findings, the firm redesigned the process.

30+ days → 12 days after redesign — engagement result, prior to the PFV toolkit.

Client names withheld by mutual agreement. References available on request for qualified engagements.

The self-serve PFV toolkit itself is entering structured field trials — pre-registered predictions, log-verified results, outcomes recorded whatever they show. The trial program below is open.

Why leaders engage

Four reasons it's worth an outside set of eyes

Need an outside perspective

Internal teams often normalize delays and inefficiencies. A fresh read sees the waiting they've stopped noticing.

Need quantification

Leaders want evidence before committing resources. PFV turns “it feels slow” into a defensible number.

Need prioritization

Not every problem deserves investment. PFV shows which workflow's exposure is actually worth reducing.

Need momentum

Visible process improvements create confidence and organizational buy-in. One clear win earns the next.

Where it applies

Typical PFV engagements

Detection Engineering
Vulnerability Remediation
Incident Response
Threat Intelligence Processing
Change Management
Identity & Access Management
Security Operations
IT Service Delivery
Outcomes, not deliverables

What leaders gain

Faster flow

Reduce waiting and delays across the workflows that matter most.

Greater capacity

Increase throughput without adding headcount.

Lower exposure

Shorten the risk-creating delays between knowing and acting.

Better investment decisions

Focus resources where they produce measurable impact.

The PFV framework — optional reading
The PFV Methodology — Built for Security Processes

The Process Flow Visibility Framework

Lean Six Sigma’s analytical lens, made operable without the certification. A structured methodology that turns operational process data into executive-level risk visibility — in a single session, with no belt required.

Where PFV Sits — and What It Adds

PFV does not claim a new theory. Value stream mapping and Process Cycle Efficiency (Lean Six Sigma — Michael George), cost of delay (Reinertsen), and dwell time / MTTD (IBM, SANS) are all established, and PFV cites them rather than re-inventing them. Applying flow analysis to the DevSecOps pipeline is well-trodden ground — Carnegie Mellon’s SEI and Google’s DORA both document value-stream visibility for delivery work — and the link between slow detection and longer attacker dwell time is standard SOC doctrine.
What PFV contributes is the synthesis: it generalizes the dwell-time insight beyond the incident timeline to the entire security process portfolio — vulnerability remediation, access provisioning, vendor risk, change approval, threat hunting — and packages that analytical lens as a self-serve assessment any security leader can run without a Six Sigma certification, returning a single measure — labeled with the evidence behind it — of where queue time creates operational risk, cost, and reduced capacity.
Not CTEM
Continuous Threat Exposure Management measures exposure on your attack surface. PFV measures exposure in your process time — the risk window that opens while work waits. The two answer different questions and sit comfortably side by side: CTEM finds the gap; PFV measures how long you sit in it.
Choose what's relevant to you
Four ways into the framework

Pick a tab above — a readiness checklist, how to choose your first process, red & green flags, and the questions to ask. Nothing is forced on you; open only what matters.

Overall Readiness Score 0%

How to Pick Your First Process

Ask your team one question: "What process do you dread the most, and why?" The answer is almost always your best starting point — because dread means pain, pain means motivation, and motivation means the team will show up and engage honestly.

Ideal Candidate Process Has These Traits

Painful and everyone knows it
People complain about it regularly in standups or post-incident reviews
Runs frequently
Daily or weekly processes compound improvements fast
Crosses multiple teams
Handoffs between teams are where queue time accumulates invisibly
Has a measurable start and end
Clear trigger and clear output — fuzzy boundaries make measurement impossible
High stakes when it goes wrong
Errors cost money, delay response, or create compliance risk

Cybersecurity Process Candidates

🚨
Incident Response Start Here

High stakes, time-critical, crosses every team. Lead time from detection to containment is a metric everyone cares about but few have actually measured end-to-end. Rework loops around escalation and evidence collection are common and costly.

🔓
Vulnerability Management Strong Candidate

The lifecycle from scan to remediation to verification is notorious for queue time. Tickets sit waiting for asset owners, patches wait for change windows. The gap between "vulnerability identified" and "vulnerability closed" is almost always shocking when measured.

🔍
Threat Detection / Alert Triage Strong Candidate

If your SOC is dealing with alert fatigue, this process is a prime candidate. The lifecycle from alert firing to disposition is full of rework loops and queue time — as the real-world example in this framework shows.

🔑
Access Request & Provisioning Good Option

Sounds mundane but frequently a mess — multiple approvers, unclear ownership, exceptions everywhere. Defect rate shows up as over-provisioning or frustrated employees waiting days for access they needed immediately.

🛡️
Patch Management Good Option

Cross-functional by nature — security identifies, IT deploys, business approves. Queue time between those handoffs is almost always the hidden culprit behind slow patch cycles.

Walk Away If You See These

Consultant won't define green/yellow/red thresholds before color-coding
The deliverable is just a diagram with no action plan or next steps
Day-to-day process experts are excluded — only managers in the room
No one in leadership is sponsoring or will act on findings
Improvements are identified without any root cause analysis
No exit strategy — consultant designs for ongoing dependency

Move Forward If You See These

Thresholds for every metric are agreed on before the session starts
People who live the process daily are doing the mapping
Color-coding is applied to tasks AND overall process lead time
Rework loops and error-prone tasks are explicitly flagged and prioritized
Improvement opportunities are mapped further to find root causes
Exit strategy is clear — capability transfers to your team

Ask these before signing anything. A consultant with a solid methodology will have confident, specific answers to all of them.

01"How will we define green/yellow/red thresholds — and when will we agree on them?"
02"Will thresholds apply to both individual tasks AND overall process lead time?"
03"Who should be in the room — and how do you ensure day-to-day experts are included?"
04"How do you handle it when someone is defensive about their part of the process?"
05"After identifying improvement opportunities, how do you determine root causes?"
06"What are your deliverables at the end of all three sessions?"
07"What's your exit strategy — how do we keep this running after you leave?"
08"Can you share an example where this approach led to a measurable outcome?"

The best sign: If your consultant answers these before you ask them, that's someone who knows their craft. The methodology in this framework — agreed thresholds, participatory mapping, root cause analysis, clear exit strategy — is what best practice looks like.

Get started

Three ways in — all start with one workflow

Join the field-trial program

Be a trial site, not customer number one. One recurring process: ~30 minutes of mapping, a 2-minute seal email, and one CSV export of your last 10–20 tickets (~15 minutes) — about 75 minutes total, under a pre-registered protocol: predictions sealed before the logs are touched, results recorded honestly whichever way they land. You keep the full analysis and the verified map either way. Your raw logs never leave your systems — the only thing you ever send is your own map.

Ask about a trial →
Free 15-minute map review

Map one recurring workflow in the toolkit and export it (the .xlsx download), then send it over. I'll review it and tell you whether the exposure is worth reducing — no obligation.

Email your PFV map →

No email app on this device? Copy don.woodward@dewood.org into your mail and attach the .xlsx export.

Book 30 minutes

A short call to talk through your situation and whether a single session or a sprint fits. Methodology first — no pressure.

Book 30 minutes →
Do you qualify? A 60-second self-check

Five yes/no questions, instant answer — no waiting on me. A trial only works if you own the process and can reach its logs quickly; this check respects your time by telling you now.

Q1  Do you personally own or run the workflow you’d map?
Q2  Is it tracked in a ticketing system (Jira, ServiceNow, similar) that records status-change timestamps — not just created/closed?
Q3  Can you export the last 10–20 completed tickets yourself, this week — no request to another team?
Q4  Can you quickly check the count — and have roughly 10+ of these completed in the last 90 days? (If a 2-minute filter in your system can’t answer this, that itself is a no.)
Q5  Can you personally OK an anonymized published result (you review it first; it’s recorded whichever way it lands)?

Prefer to explore first? Run the full toolkit or see sample workflows — the method is open, and the toolkit runs in your browser.

How engagements work

Scope matched to your situation

Every engagement includes the full PFV methodology, a live heat map, and a prioritised improvement roadmap.

Foundation

Single Process

One process · remote · 3-day engagement
The fastest way to experience PFV — two facilitated group sessions across three days, with an executive business case.
  • Two facilitated PFV sessions over 3 days
  • Complete heat map, all 7 metrics
  • Prioritised roadmap + ROI summary
  • Leadership debrief
Enquire →
Practitioner

90-Day Sprint

Up to 4 processes · 3 months · flat fee
End-to-end implementation — map, fix, validate, and build internal capability to run PFV yourselves.
  • Up to 4 mapping sessions
  • Root-cause work on top Red zones
  • Implementation coaching
  • 30-day re-measurement
Enquire →
Enterprise

Retainer

Multi-team · ongoing
Embedded PFV capability for continuous improvement at scale, with executive-level reporting.
  • Multi-team rollout & coaching
  • Quarterly executive reviews
  • KPI / KVI dashboards
  • Priority response SLA
Enquire →