Most operational risk hides in the time work spends waiting, not working.
PFV finds the days of delay buried inside a process you think takes hours, scores the exposure that delay creates, and tells you what to fix first. Three inputs to start. No login.
Name a process and its steps. For each step, enter the active work time and how long it typically waits before someone picks it up. That’s enough to score your exposure — everything else is optional.
Optional · refines rework, handoff, dependency & cost analysis
Thresholds default to the shared PFV bands (Healthy / Constrained / High Exposure). They are deliberately generic — judge the result against your own SLA expectations.
The Exposure Score reflects how much of this process is spent waiting — the recoverable time and the window it opens. It is not a breach-probability estimate.
—
—
The numbers behind it
Read the exposure framing where this process sits on the attacker’s path — detection, response, vulnerability remediation. For purely operational processes, the same delay is recoverable cost and capacity, not attacker exposure.
Cost of delay, rework, and recovered-capacity figures follow directly from the time you entered. The breach-risk figure is a conditional scenario — it holds only where this process sits on the breach path, not for every process.