Level 2/5
XP 0
Four levels · one real process · load them and see for yourself

One percent of it
was work.

A detection-engineering team has a year to reach risk-based alerting. They need sixty analytics that meet a real bar; they produce about one a week on the good weeks. Nothing is wrong with the engineers.

You are going to load the same eleven-step process at four maturity levels in PFV-EZ, diagnose what is holding each one back, and watch the waiting disappear. No guessing about your own numbers — the samples are already built. Bring your own process afterwards.

◪ Root Cause ↻ Loop Pricer ◆ Level 3 — Defined ◈ Level 4 — Measured ★ Level 5 — Optimizing
Level 2

Managed — and honest about it

Level two is not chaos. There is a backlog, a repeatable-ish way of working, and two engineers who are genuinely good. Things get done when someone pushes.

But prioritisation is whoever asks loudest, "done" means something slightly different to each engineer, coverage is reported as nine hundred rules — which is inventory, not coverage — and when you ask how long an analytic takes, the answer is "depends." That is the level-two answer to every question.

Load it · PFV-EZ · 60 seconds

The line at Level 2

Eleven steps, from an intel note to a tuned analytic in production with a measured false-positive rate. Open it, press See my exposure, and read the three numbers.

Lead time 77.9 days Hands-on work 22.0 h Waiting 66.0 d PCE 1%

Twenty-two hours of work inside seventy-eight business days. One percent of the elapsed time is somebody building a detection. Typical for creative work is about five percent; world-class is twenty-five. This team is not broken and not lazy — they are below average, and nobody knew, because nobody had put the two numbers side by side.

The tool names the biggest wait. Where is it?
Four in ten analytics fail testing and get rebuilt. Why?
Level 3

Defined — the process leaves people's heads

A one-page definition of done: mapped to a technique, risk score and confidence, data model validated with evidence attached, test cases, a tuning plan, a named owner for the 30-day FP review. It is the same bar risk-based alerting needs — promoted from "extra work for the pilot" to "how we work."

A single intake with a two-line priority rule anyone can apply without a meeting. A WIP limit of three per engineer, which was the least popular decision of the quarter and the one that mattered most. And a conversation with the platform team that produced a self-service data catalogue: source, normalisation, coverage, last verified. Twenty-one days became twenty minutes.

What to look for in the tool

Run Level 2 and Level 3 side by side and read the recommendation cards, not just the headline:

  • The biggest wait moves — data validation (21 d) at level 2 becomes tuning (4 d) at level 3. Fixing the top queue always promotes a new one; that is the process working, not a failure.
  • “If halved, lead time drops by” falls from 10.5 days to 2 days. Diminishing returns are visible, and they tell you when to stop chasing queues.
  • The rework card drops a band, and the throughput card shows the recovered capacity in items a year — the only number that justifies claiming more output.
Load it · PFV-EZ

The line at Level 3

Same eleven steps. Compare the heat map to what you just saw.

Lead time fell 78 → 29 days. How would you check whether they are now producing more analytics per year?
Level 4

Quantitatively Managed — predictable, not just fast

Four numbers on the wall, refreshed monthly from the same eleven steps: lead time with its spread, PCE per step, rework rate as a first-class metric rather than an embarrassment, and coverage as the percentage of prioritised techniques with a validated analytic in production — never again as a rule count.

A standard pre-approved change class. Tuning against a measured false-positive baseline instead of instinct. A shared attack-data harness.

What to look for in the tool
  • Lead time improves only 29 → 16 days, but hands-on work drops 21.5 h → 18 h — the first level where the work itself shrinks, because analytics stop being rebuilt.
  • That is exactly where throughput finally moves: 51 → 63 a year. Check it against the throughput card’s rework arithmetic rather than taking it on faith.
  • Set your own target under Advanced → your commitment. A 20-day promise is missed at level 2 and met from here on — and a met commitment is worth more to a board than a good PCE.
Load it · PFV-EZ

The line at Level 4

The median barely moved from level 3 to 4 compared with the first jump. What did level 4 actually buy?
Level 5

Optimizing — the line improves itself

Level five is not "very good at level four." It is when improvement stops needing a champion because the machinery generates it.

Defect prevention: every bounced analytic triggers a five-minute why, and the answer is written into the definition of done. Production telemetry feeding the line: any analytic crossing an FP threshold opens its own tuning ticket — the process consumes its own output. Retirement as a real step: with FP rates and true-positive counts per analytic, they retired 140 noisy or redundant detections in a quarter and the SOC's alert volume fell 11% before risk-based alerting shipped anything.

What to look for in the tool
  • The biggest wait is now peer review at 2 days — two humans reading each other’s work. Halving it saves one day. This is where queue-chasing should stop, and the tool tells you so by how little the halving figure has left.
  • PCE reads 7%, still well under the 25% world-class band. That is honest: judgement work has irreducible waiting, and a number that never reaches the benchmark is not a failed process.
  • Rework is down to 4% of labour, so the throughput card shows only ~3 items a year still recoverable. The capacity argument is exhausted — further gains need a different lever, which is what level 5 is for.
Load it · PFV-EZ

The line at Level 5

Exercise · price the rework yourself

What was the loop actually costing?

The samples ship as the mapped line — the path an analytic takes when nothing goes wrong. Four in ten did go wrong at level 2. Load Level 2 again and model it:

  1. Find step 6, Test against attack data
  2. Tick ↻ back to and choose step 3 — failed tests went back to data validation
  3. Press See my exposure and watch the lead time move
Open Level 2 again ↗