6 unchanged sentences
Cybersecurity Program:
−Removed: CMS Energy’s and Consumers’ security function, led by the Executive Director of Security, is an integrated organization accountable for cyber and physical security and is subject to various state, federal, and industry cybersecurity, physical security, and privacy regulations.
+Added: CMS Energy’s and Consumers’ security function, led by the Vice President of Information Technology and Security and CIO , is accountable for cyber and physical security and is subject to various state, federal, and industry cybersecurity, physical security, and privacy regulations.
Their cybersecurity program is responsible for assessing, identifying, and managing risks from cybersecurity threats using industry frameworks, as well as best practices developed by government and industry partners.
1 unchanged sentence
Additionally, the companies continuously upgrade technological investments designed to prevent, detect, and respond to attacks.
−Removed: The companies’ electric, natural gas, and corporate systems each follow standards, controls, and requirements designed to maintain compliance with applicable regulations and standards, such as MPSC, NERC critical infrastructure protection, and
−Removed: payment card industry regulations.
+Added: The companies’ electric, natural gas, and corporate systems each follow standards, controls, and requirements designed to maintain compliance with applicable regulations and standards, such as MPSC, NERC critical infrastructure protection, and payment card industry regulations.
Technology projects and third-party service providers are reviewed for adherence to cybersecurity requirements .
CMS Energy’s and Consumers’ cybersecurity program focuses on finding and remediating vulnerabilities in their systems.
−Removed: The companies use third-party firms for penetration testing, audits, and assessments, and conduct exercises to practice their response to simulated events.
−Removed: The companies also have a dedicated, proactive function focused fully on monitoring CMS Energy’s and Consumers’ systems and responding when issues occur.
+Added: The companies use third-party firms for penetration testing, audits, and assessments, and conduct technical exercises to practice their response to simulated events as well as tabletop exercises to test that response using their incident command system, including leadership decisions.
+Added: The companies also have a dedicated, proactive function focused fully on monitoring CMS Energy’s and Consumers’ systems and responding when cybersecurity attacks occur.
This includes regular information sharing with industry partners, peer utilities, and state and federal partners.
The companies’ incident response plan outlines the individuals responsible, the methods employed, and the timeline for notifying state and federal governmental agencies.
−Removed: The companies retain a third-party cybersecurity firm to assist with potentially significant incidents and have invested in cybersecurity insurance to offset costs incurred from any such incidents.
+Added: The companies retain a third-party cybersecurity firm to assist with potentially significant cybersecurity incidents and have invested in cybersecurity insurance to offset costs incurred from any such cybersecurity incidents.
To manage cybersecurity risks associated with the companies’ use of third-party service providers, the companies incorporate security requirements into contracts, when deemed applicable, and pursue third-party security certifications for vendors with a higher risk profile.
4 unchanged sentences
Management’s Role:
−Removed: The Executive Director of Security has 25 years of information technology and security experience.
−Removed: To enhance governance, the Executive Director of Security reports to the Senior Vice President and Chief Customer Officer, who has extensive experience overseeing cybersecurity and has had executive oversight of the security function for nine years at CMS Energy and Consumers.
−Removed: Prior to joining CMS Energy, this officer served as Vice President of Business Technology at Pacific Gas & Electric Company, a non-affiliated company.
−Removed: The Executive Director of Security is responsible for informing the CEO and other members of senior management, as necessary, about cybersecurity incidents, covering prevention, detection, mitigation, and remediation efforts as they are detected by the Executive Director’s team.
−Removed: Cyber incidents are managed using the companies’ standard process for critical events.
−Removed: In the event of such incidents, the Executive Director of Security communicates and collaborates with the officers of the companies and subject matter experts to address business continuity, contingency, and recovery plans.
+Added: The Vice President of Information Technology and Security and CIO has over 25 years of information technology and security experience and, to enhance governance, reports to the Senior Vice President and General Counsel.
+Added: The Vice President of Information Technology and Security and CIO is responsible for informing the CEO and other members of senior management, as necessary, about cybersecurity incidents, covering prevention, detection, mitigation, and remediation efforts as they are detected by the cybersecurity team.
+Added: Cybersecurity incidents are managed using the companies’ standard process for critical events.
+Added: In the event of such cybersecurity incidents, the Vice President of
+Added: Information Technology and Security and CIO communicates and collaborates with the officers of the companies and subject matter experts to address business continuity, contingency, and recovery plans.
Senior management will notify the Board , including the Audit Committee, of any significant cybersecurity incidents.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.