Every healthcare CISO faces the same uncomfortable question from their board: "How do we know if our cybersecurity program is good enough?" The honest answer—historically has been educated guessing. We've compared ourselves to frameworks, counted controls, and hoped we weren't the next Change Healthcare. Meanwhile, AI has exploded across our organizations, introducing risks we're only beginning to understand and certainly can't yet measure. John Riggi has spent the last seven years as healthcare's most trusted cybersecurity advisor, working directly with hundreds of hospitals that have been victimized by ransomware and representing the field's interests before Congress, the White House, and federal agencies. As the architect of AHA's national cybersecurity strategy and the leader who testified before Congress during the Change Healthcare crisis, he's seen what separates organizations that survive attacks from those that don't—and it isn't what most people think. This session addresses the measurement challenge that undermines every cybersecurity program: How do you know where you truly stand? Drawing on his unprecedented national visibility into healthcare cybersecurity performance, Riggi will reveal the benchmarking strategies that actually correlate with resilience, the emerging frameworks for measuring AI risk, and the metrics that boards should demand. If you're tired of defending your program with qualitative narratives and ready to lead with data, this session delivers the benchmarking intelligence you need.