XML 54 R32.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The UScellular information security program is based on a defense-in-depth approach and aligns with the National Institute of Standards and Technology (NIST) cybersecurity framework. Security control and maturity assessments are conducted periodically leveraging this standard. UScellular also leverages internal and external auditors and consultants to perform independent assessments and tests of security controls. The assessment results are used to drive continuous improvement in the UScellular cybersecurity control environment, as well as to manage potential data security risks of third-party service providers.
UScellular identifies risks across the threat and vulnerability landscape using various commercial, government, vendor and publicly available information sources and tools. Risks related to third-party providers who have access to UScellular data and systems are identified, assessed and managed through a formal third-party risk assessment process. Third-parties who access sensitive company or customer information are contractually obligated to meet specific privacy and security requirements. The UScellular security operations program includes active monitoring of the internal data environment and regular assessment of the environments of third-party service providers who manage sensitive data. In addition, UScellular security leaders conduct regular cyber incident simulations to ensure preparedness in the event of a cyber-attack and further test potential risks. Identified risks are evaluated against a risk classification framework to direct remediation, mitigation and management efforts based on severity. Cybersecurity risks are integrated into the UScellular Enterprise Risk Management (ERM) program with updates provided on a quarterly basis.
The Senior Vice President of Information Technology is responsible for assessing and managing cybersecurity risks. He has over twenty years of experience at the company, encompassing network engineering, information technology and cyber security. Management has a depth of cybersecurity experience focused on increasing the organization's resilience to security threats and stays current on new developments through continuing education and monitoring of the cybersecurity landscape. As part of their accountability for incident response, significant incidents are communicated to an internal committee including the Chief Financial Officer and general counsel to assess their materiality and if materiality is confirmed it is reported by the defined process. To date UScellular has not identified nor become aware of any cybersecurity incidents that individually or in aggregate have materially affected or are reasonably likely to materially affect the company, including its business strategy, results of operations, or financial condition.
The full Board of Directors engages in oversight of UScellular's cybersecurity risks. The Board of Directors receives regular updates from management on technology and security updates and UScellular’s assessment of cybersecurity threats and mitigation plans. The Senior Vice President of Information Technology provides the full Board of Directors an annual update and discussion of the cybersecurity program. The UScellular Audit Committee oversees the processes over internal controls and financial reporting that includes controls and procedures that are designed to ensure that significant cybersecurity incidents are communicated to both senior management and the Audit Committee. The Audit Committee meets with the Senior Vice President of Information Technology at least two times per year. Cybersecurity is also discussed with the Technology Advisory Group of the Board of Directors as warranted, typically on an annual basis.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The UScellular information security program is based on a defense-in-depth approach and aligns with the National Institute of Standards and Technology (NIST) cybersecurity framework. Security control and maturity assessments are conducted periodically leveraging this standard. UScellular also leverages internal and external auditors and consultants to perform independent assessments and tests of security controls. The assessment results are used to drive continuous improvement in the UScellular cybersecurity control environment, as well as to manage potential data security risks of third-party service providers.
UScellular identifies risks across the threat and vulnerability landscape using various commercial, government, vendor and publicly available information sources and tools. Risks related to third-party providers who have access to UScellular data and systems are identified, assessed and managed through a formal third-party risk assessment process. Third-parties who access sensitive company or customer information are contractually obligated to meet specific privacy and security requirements. The UScellular security operations program includes active monitoring of the internal data environment and regular assessment of the environments of third-party service providers who manage sensitive data. In addition, UScellular security leaders conduct regular cyber incident simulations to ensure preparedness in the event of a cyber-attack and further test potential risks. Identified risks are evaluated against a risk classification framework to direct remediation, mitigation and management efforts based on severity. Cybersecurity risks are integrated into the UScellular Enterprise Risk Management (ERM) program with updates provided on a quarterly basis.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] To date UScellular has not identified nor become aware of any cybersecurity incidents that individually or in aggregate have materially affected or are reasonably likely to materially affect the company, including its business strategy, results of operations, or financial condition.
Cybersecurity Risk Board of Directors Oversight [Text Block]
The full Board of Directors engages in oversight of UScellular's cybersecurity risks. The Board of Directors receives regular updates from management on technology and security updates and UScellular’s assessment of cybersecurity threats and mitigation plans. The Senior Vice President of Information Technology provides the full Board of Directors an annual update and discussion of the cybersecurity program. The UScellular Audit Committee oversees the processes over internal controls and financial reporting that includes controls and procedures that are designed to ensure that significant cybersecurity incidents are communicated to both senior management and the Audit Committee. The Audit Committee meets with the Senior Vice President of Information Technology at least two times per year. Cybersecurity is also discussed with the Technology Advisory Group of the Board of Directors as warranted, typically on an annual basis.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The full Board of Directors engages in oversight of UScellular's cybersecurity risks. The Board of Directors receives regular updates from management on technology and security updates and UScellular’s assessment of cybersecurity threats and mitigation plans. The Senior Vice President of Information Technology provides the full Board of Directors an annual update and discussion of the cybersecurity program. The UScellular Audit Committee oversees the processes over internal controls and financial reporting that includes controls and procedures that are designed to ensure that significant cybersecurity incidents are communicated to both senior management and the Audit Committee. The Audit Committee meets with the Senior Vice President of Information Technology at least two times per year. Cybersecurity is also discussed with the Technology Advisory Group of the Board of Directors as warranted, typically on an annual basis.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee meets with the Senior Vice President of Information Technology at least two times per year. Cybersecurity is also discussed with the Technology Advisory Group of the Board of Directors as warranted, typically on an annual basis.
Cybersecurity Risk Role of Management [Text Block] The Senior Vice President of Information Technology is responsible for assessing and managing cybersecurity risks. He has over twenty years of experience at the company, encompassing network engineering, information technology and cyber security. Management has a depth of cybersecurity experience focused on increasing the organization's resilience to security threats and stays current on new developments through continuing education and monitoring of the cybersecurity landscape. As part of their accountability for incident response, significant incidents are communicated to an internal committee including the Chief Financial Officer and general counsel to assess their materiality and if materiality is confirmed it is reported by the defined process.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Senior Vice President of Information Technology is responsible for assessing and managing cybersecurity risks.The full Board of Directors engages in oversight of UScellular's cybersecurity risks.The UScellular Audit Committee oversees the processes over internal controls and financial reporting that includes controls and procedures that are designed to ensure that significant cybersecurity incidents are communicated to both senior management and the Audit Committee.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Senior Vice President of Information Technology is responsible for assessing and managing cybersecurity risks. He has over twenty years of experience at the company, encompassing network engineering, information technology and cyber security. Management has a depth of cybersecurity experience focused on increasing the organization's resilience to security threats and stays current on new developments through continuing education and monitoring of the cybersecurity landscape.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The full Board of Directors engages in oversight of UScellular's cybersecurity risks. The Board of Directors receives regular updates from management on technology and security updates and UScellular’s assessment of cybersecurity threats and mitigation plans. The Senior Vice President of Information Technology provides the full Board of Directors an annual update and discussion of the cybersecurity program. The UScellular Audit Committee oversees the processes over internal controls and financial reporting that includes controls and procedures that are designed to ensure that significant cybersecurity incidents are communicated to both senior management and the Audit Committee. The Audit Committee meets with the Senior Vice President of Information Technology at least two times per year. Cybersecurity is also discussed with the Technology Advisory Group of the Board of Directors as warranted, typically on an annual basis.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true