Asbury Automotive Group, Inc. discloses in its 10-K Item 1C that it has experienced targeted cybersecurity incidents in the past resulting in unauthorized access to information systems. No incident has materially affected the company as of the filing date. The company maintains a comprehensive cybersecurity risk management program including governance, training, and technical controls (SOCaas, SIEM, EDR) but acknowledges potential future risks.