XML 56 R31.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Verizon’s Senior Vice President and Chief Information Security Officer (CISO) has responsibility for the management of cybersecurity risks at Verizon. The CISO and her team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.

The CISO brings nearly two decades of cybersecurity experience to her work at Verizon. Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.

Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes. Each of our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO. This structure provides the CISO with line of sight across the enterprise. The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.

The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team. The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions. The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.

Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy. The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.

Verizon also operates a robust internal audit program. Each year, Verizon’s internal audit team conducts an overall business risk assessment, which includes an evaluation of cybersecurity risks. The results of the assessment are presented to the leaders of the relevant business teams, who are responsible for prioritizing and addressing the risks identified.
We have implemented processes to identify and manage risks from cybersecurity threats associated with our use of third-party service providers.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Integrated Cybersecurity Risk Management
Verizon’s Senior Vice President and Chief Information Security Officer (CISO) has responsibility for the management of cybersecurity risks at Verizon. The CISO and her team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.

The CISO brings nearly two decades of cybersecurity experience to her work at Verizon. Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.

Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes. Each of our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO. This structure provides the CISO with line of sight across the enterprise. The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.

The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team. The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions. The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.

Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy. The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.

Verizon also operates a robust internal audit program. Each year, Verizon’s internal audit team conducts an overall business risk assessment, which includes an evaluation of cybersecurity risks. The results of the assessment are presented to the leaders of the relevant business teams, who are responsible for prioritizing and addressing the risks identified.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Audit Committee of the Board of Directors (Board) has primary responsibility for overseeing Verizon’s risk management and compliance programs relating to cybersecurity and data protection and privacy.

As part of the Board’s oversight of risks from cybersecurity threats, the CISO leads an annual review and discussion with the full Board dedicated to Verizon’s cybersecurity risks, threats and protections. The CISO provides a mid-year update to this annual review to the Audit Committee and, as warranted, additional updates throughout the year. The Audit Committee also receives a report from senior management on Verizon’s cybersecurity posture and related matters at each of its other meetings during the year at which the CISO is not present.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team. The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions. The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.

Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy. The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.
The Audit Committee of the Board of Directors (Board) has primary responsibility for overseeing Verizon’s risk management and compliance programs relating to cybersecurity and data protection and privacy.
Board’s oversight
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Audit Committee of the Board of Directors (Board) has primary responsibility for overseeing Verizon’s risk management and compliance programs relating to cybersecurity and data protection and privacy.

As part of the Board’s oversight of risks from cybersecurity threats, the CISO leads an annual review and discussion with the full Board dedicated to Verizon’s cybersecurity risks, threats and protections. The CISO provides a mid-year update to this annual review to the Audit Committee and, as warranted, additional updates throughout the year. The Audit Committee also receives a report from senior management on Verizon’s cybersecurity posture and related matters at each of its other meetings during the year at which the CISO is not present.
Cybersecurity Risk Role of Management [Text Block]
Verizon’s Senior Vice President and Chief Information Security Officer (CISO) has responsibility for the management of cybersecurity risks at Verizon. The CISO and her team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.

The CISO brings nearly two decades of cybersecurity experience to her work at Verizon. Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.

Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes. Each of our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO. This structure provides the CISO with line of sight across the enterprise. The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.

The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team. The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions. The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.

Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy. The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.

Verizon also operates a robust internal audit program. Each year, Verizon’s internal audit team conducts an overall business risk assessment, which includes an evaluation of cybersecurity risks. The results of the assessment are presented to the leaders of the relevant business teams, who are responsible for prioritizing and addressing the risks identified.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Verizon’s Senior Vice President and Chief Information Security Officer (CISO) has responsibility for the management of cybersecurity risks at Verizon. The CISO and her team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.

The CISO brings nearly two decades of cybersecurity experience to her work at Verizon. Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.

Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes. Each of our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO. This structure provides the CISO with line of sight across the enterprise. The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.

The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team. The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions. The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.

Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy. The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.

Verizon also operates a robust internal audit program. Each year, Verizon’s internal audit team conducts an overall business risk assessment, which includes an evaluation of cybersecurity risks. The results of the assessment are presented to the leaders of the relevant business teams, who are responsible for prioritizing and addressing the risks identified.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
The CISO brings nearly two decades of cybersecurity experience to her work at Verizon. Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
As part of the Board’s oversight of risks from cybersecurity threats, the CISO leads an annual review and discussion with the full Board dedicated to Verizon’s cybersecurity risks, threats and protections. The CISO provides a mid-year update to this annual review to the Audit Committee and, as warranted, additional updates throughout the year. The Audit Committee also receives a report from senior management on Verizon’s cybersecurity posture and related matters at each of its other meetings during the year at which the CISO is not present.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true