CarMax 10-K Item 1C cybersecurity disclosure. The filing describes the company's cybersecurity program, governance (CITO/CISO reporting, Board Technology and Innovation Committee oversight), third-party vendor risk processes, tabletop exercises, and penetration testing. The company explicitly states it has not experienced any material cybersecurity incidents or incurred any material expenses resulting from a cybersecurity breach. No specific incident is disclosed.