HomeBlog › Threat Lab
A methodology from the field

How to Prove Your Security Is Actually Improving: The MATCH Report

Updated 2026-07-17 · 8 min read · by Mihai Bătrîneanu
How to Prove Your Security Is Actually Improving: The MATCH Report

Almost no security program can honestly answer the one question that matters to the people paying for it: are we actually getting harder to breach? We count alerts — but a rising or falling alert count measures the attacker's activity, not your defense. We count patched vulnerabilities — but patching a hundred flaws nobody was exploiting proves nothing. The two numbers live in separate reports and never speak to each other. The MATCH Report — a methodology I built and have run on real networks for years — makes them speak. It ties every vulnerability to the attacks that actually target it, and then tracks that relationship month over month. The result is the metric the industry keeps promising and rarely delivers: measurable, causal proof that a security program is getting stronger.

ContentsThe question nobody can answer: are we getting safer?
Why the two numbers have to be connected — the MATCH
The monthly evolution — measuring defense, not activity
Causality, context and honesty — why it is not just a dashboard
What it changes: security becomes a capability you can manage
Frequently asked questions

The question nobody can answer: are we getting safer?

Sit in on a board review of a security program and you will hear a lot of activity reported: alerts triaged, incidents handled, vulnerabilities patched, tools deployed. Then someone asks the only question that actually matters — are we more secure than we were last quarter? — and the room goes quiet. The honest answer, in most organizations, is: we hope so.

The reason is that we measure the wrong things. An alert count tells you how busy the attackers were, not how good your defense is; it goes up and down for reasons outside your control. A patch count tells you how much effort you spent, not whether that effort mattered. Activity is not outcome. You can be extremely busy and no safer, and no dashboard of counts will ever tell you the difference. For a board, for a regulator, and for the truth, we hope so is not an answer.

Why the two numbers have to be connected — the MATCH

The insight the MATCH Report is built on is simple: vulnerabilities and attacks are two halves of one story, and almost everyone reports them as if they were unrelated. An attack that succeeds — or partially succeeds — almost always rode a specific weakness. So if you match the attacks your SOC actually detects to the vulnerabilities your scans actually find, causally, you learn something no separate list can tell you: which of your weaknesses are being weaponized against you, right now.

That changes everything about remediation. Not the theoretical critical-severity flaw that no one is touching, but the one an attacker hit on your network last week. The MATCH tells you where a fix actually buys you safety, and where it is busywork. You stop patching by score and start patching by real, observed threat to your own environment.

The monthly evolution — measuring defense, not activity

Here is where it becomes a measurement of your program rather than a snapshot. Run the MATCH every month. As you remediate the vulnerabilities that are genuinely being targeted, the attacks that succeed or partially succeed against those exact vectors begin to fall. Do it again the next month, and the next.

What emerges is a curve — and crucially, a curve of outcomes, not activity. Not alerts (the attacker's noise, outside your control) but attacks that would have landed and did not. When remediation rises and successful or partially successful attacks fall together, in a measurable, proportional relationship, you are no longer hoping your defense is improving — you are watching it improve, month over month, with a trend line. For the first time, we are getting safer is a number, and you can point at it.

Causality, context and honesty — why it is not just a dashboard

Any vendor can put a rising green number on a screen. The reason most security scores are vanity metrics is that they lack the three things that make a number worth trusting, and the MATCH Report is built on exactly those three.

That discipline, tuned to the organization month after month, is the difference between a report a CISO can defend in front of a board and a colorful chart that falls apart under the first hard question.

What it changes: security becomes a capability you can manage

Once you can measure defense actually improving, security stops being a cost you justify with fear and becomes a capability you manage with data. You can prove the program works. You can prioritize the remediation that measurably reduces successful attacks instead of the remediation that merely closes tickets. You can show a board — or a regulator under NIS2, which expects exactly this kind of demonstrable risk management — a real trajectory rather than a pile of activity.

That is what the MATCH Report and its monthly evolution were built to do, and it is a core part of how we run CYBER3.AI: not only detecting and blocking, but proving, month after month, with causality and context and honesty, that your defense is getting stronger. Security you cannot measure is security you are taking on faith. This is how you stop taking it on faith.

Stop guessing whether your security is improving. Measure it.
CYBER3.AI generates the MATCH Report as part of your Cloud SOC — tying your vulnerabilities to the attacks that target them, causally, and tracking the monthly evolution so you can prove your defense is getting stronger. NIS2-ready, fitted to your environment, honest by design.
Explore CYBER3.AI Cloud SOC →
🛡️ Try CYBER3.AI free
AI security copilot + Global Scan of your own network. 700 free credits on sign-up — no card, no strings.
Start free →
About the author: Mihai Bătrîneanu
Founder of CYBER3.AI and a 30-year veteran of internet infrastructure. In 1994 he founded PC-NET, the first Internet Service Provider in Eastern Europe, and built Romania's first e-mail, ADSL broadband and VoIP services. He now builds CYBER3.AI — a sovereign Security LLM and autonomous Security Operations Center.

Frequently asked questions

What is a MATCH Report in cybersecurity?

A MATCH Report is a methodology that correlates the vulnerabilities discovered on a network with the attacks a SOC actually detects against it — causally, not as two separate lists. It reveals which of your weaknesses are genuinely being weaponized, so remediation targets real, observed threat rather than theoretical severity scores. Tracked month over month, it measures whether a security program is actually reducing successful attacks.

How do you measure whether security is actually improving?

By measuring outcomes, not activity. Counting alerts measures attacker activity; counting patches measures effort. Neither proves you are safer. The MATCH Report instead tracks, month over month, the relationship between remediating the vulnerabilities that are actually targeted and the number of attacks that succeed or partially succeed. When remediation rises and successful attacks fall together, you have measurable, causal evidence that your defense is improving.

Why isn't counting alerts or patched vulnerabilities enough?

Because both are activity metrics, not outcome metrics. Alert counts rise and fall with the attacker's behavior, which is outside your control. Patch counts show effort, not effect — you can patch a hundred flaws nobody was exploiting and be no safer. Neither number, on its own, tells a board whether the organization is harder to breach than last month. Connecting the two causally is what produces a real measure of defense.

What does “monthly evolution” mean in the MATCH Report?

It means running the correlation every month and tracking the trend. As an organization remediates the vulnerabilities that are actually being attacked, the successful and partially successful attacks against those vectors decline over successive months. The month-over-month curve turns a one-time snapshot into a trajectory — proof that defensive capability is growing, or a signal that it is not.

How does the MATCH Report support NIS2 compliance?

NIS2 expects essential and important entities to manage cybersecurity risk and to demonstrate it — not just to own tools, but to show risk is being handled and reduced. The MATCH Report provides exactly that: causal, contextual, month-over-month evidence that vulnerabilities are being remediated and that successful attacks are falling as a result. It turns a compliance obligation into a defensible, data-backed trajectory.

Protejează-ți telefonul — CYBER3, gratuit pe Google Play
Instalează