|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy
We have developed and continue to enhance our cybersecurity governance program to help protect the security of our computer systems, software, networks, and other technology assets against material risks from cybersecurity threats, including unauthorized attempts to access confidential information or to disrupt or degrade our business operations. Our cybersecurity governance program is strategically integrated into our broader risk management framework and aims to (1) proactively manage cyber and information security risks at AutoNation, (2) implement the internal controls required by cybersecurity regulatory requirements as well as AutoNation’s information security control objective documents and information security standards, and (3) improve the efficiency, maturity, and effectiveness of technology functions and processes.
We regularly evaluate new and emerging risks and ever-changing legal and compliance requirements and examine the effectiveness and maturity of our cyber defenses through various means, including internal audits, targeted testing, incident response exercises, maturity assessments, and industry benchmarking. We also dedicate significant resources that are designed to secure our systems and to protect confidential information, such as firewalls, endpoint protection, and behavior analysis tools, among others, and engage with a range of external experts, including cybersecurity assessors, consultants, and auditors in evaluating and testing our risk management systems. In addition, we annually perform a risk assessment of our third-party service providers.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our cybersecurity governance program is strategically integrated into our broader risk management framework and aims to (1) proactively manage cyber and information security risks at AutoNation, (2) implement the internal controls required by cybersecurity regulatory requirements as well as AutoNation’s information security control objective documents and information security standards, and (3) improve the efficiency, maturity, and effectiveness of technology functions and processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Our Board of Directors is acutely aware of the critical nature of managing risks associated with cybersecurity threats and oversees risks associated with cybersecurity threats.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board’s Audit Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for this area. The Audit Committee is composed of independent directors with diverse expertise, including risk management, technology, and finance, equipping them to oversee cybersecurity risks effectively.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Chief Information Security Officer (“CISO”) plays a pivotal role in informing the Audit Committee on cybersecurity risks. He provides comprehensive briefings to the Audit Committee on a quarterly basis or more frequently as needed. These briefings encompass a broad range of topics, including emerging threats, the status of ongoing cybersecurity initiatives, and incident reports and learnings from any cybersecurity events. The Audit Committee actively participates and offers guidance in strategic decisions related to cybersecurity. This involvement helps ensure that cybersecurity considerations are integrated into our broader strategic objectives.
|Cybersecurity Risk Role of Management [Text Block]
|
Our CISO regularly informs our Chief Executive Officer and Chief Financial Officer of all aspects related to cybersecurity risks and incidents. This helps ensure that the highest levels of management are kept abreast of the cybersecurity posture and potential risks facing the Company. Furthermore, significant cybersecurity matters and strategic risk management decisions are escalated to our Board of Directors, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Board of Directors is acutely aware of the critical nature of managing risks associated with cybersecurity threats and oversees risks associated with cybersecurity threats. The Board’s Audit Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for this area. The Audit Committee is composed of independent directors with diverse expertise, including risk management, technology, and finance, equipping them to oversee cybersecurity risks effectively.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|With nearly three decades of experience in the field of cybersecurity, including extensive experience as an enterprise CISO, his in-depth knowledge and experience are instrumental in developing and executing our cybersecurity strategies.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Our CISO regularly informs our Chief Executive Officer and Chief Financial Officer of all aspects related to cybersecurity risks and incidents. This helps ensure that the highest levels of management are kept abreast of the cybersecurity posture and potential risks facing the Company. Furthermore, significant cybersecurity matters and strategic risk management decisions are escalated to our Board of Directors, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef