PFV Process Flow Visibility
Home  /  Lead time, not labor time
Measurement · lead time, not labor time

The Customer Experiences Lead Time, Not Labor Time

One hour of work inside ten days of elapsed time is experienced as ten days. PFV measures the waiting — not the worker effort.

Process Cycle Efficiency

PCE = active work ÷ lead time

If one hour of useful work takes ten hours to complete, the process is not experienced as one hour — it is experienced as ten. As queues build, Process Cycle Efficiency collapses even when the work itself barely changes. The people may still be working hard; the process may still be fully staffed. But the flow of completed outcomes slows down. This is why a process can feel broken even when every individual step looks reasonable in isolation.

The DMV effect

Why does the DMV feel slow?

The form takes minutes; the experience is dominated by waiting. Cybersecurity has the same mechanics — alerts wait for triage, tickets wait for the right analyst, work moves between SecOps, IT, and legal, and incomplete inputs create rework. Different domain, same waste.

50%
Walk in
33%
Short wait
!
20%
Noticeable wait
17%
Busy
11%
Half day

Each bar = PCE = active work ÷ total lead time, for one modeled workflow under rising queue load.

The customer experiences lead time — not labor time.

The collapse comes from queue load, not lazy workers. PCE does not judge creativity — it separates active work from elapsed time, which is exactly the distinction security teams usually cannot see.

Alert-to-detection-rule, drawn to scale

At real scale, the work disappears

The same workflow, with every block sized by actual elapsed time. There are three and a half hours of active work inside twenty days. The work almost vanishes — which is where leaders realize they have been managing activity rather than flow.

all 3.5 hrs of real work — <1% of the timeline
QUEUE FOR ANALYST · 14 DAYS
ESCALATION · 6 DAYS
3.5 hrs
active work · <1% of cycle
20 days
waiting in queues & handoffs · >99%
≈0.7%
process cycle efficiency

Illustrative model anchored to industry data: ~20–30 min triage (IBM 2025); 14-day median dwell (Mandiant M-Trends 2026); 241-day identify-and-contain (IBM 2025). Run the method on your own data for your real numbers.

Common security processes

Most lead time is queue and handoff, not active work

The pattern is not isolated. Across eleven common security processes, active work is a small fraction of elapsed time — all far below the 25% world-class line. The distance to that line is recoverable time.

Patch deployment
0.4%
Access provisioning
0.5%
Vendor risk review
1.3%
Incident response
2.3%
Threat hunting
5.7%
Detection engineering
11.2%
0%5%10%15%20%25% · world-class

Illustrative estimates from published benchmarks (IBM 2025; Mandiant M-Trends 2026; M. L. George, Lean Six Sigma 2002). Linear PCE = active work ÷ (work + queue); rework counted once, in the recovery levers. Actual values require measurement. See all eleven, live →