6 unchanged sentences
Cybersecurity Program:
−Removed: CMS Energy’s and Consumers’ security function, led by the Vice President of Information Technology and Security and CIO , is accountable for cyber and physical security and is subject to various state, federal, and industry cybersecurity, physical security, and privacy regulations.
+Added: CMS Energy’s and Consumers’ security function, led by the Vice President of IT and Security and CIO , is accountable for cyber and physical security and is subject to various state, federal, and industry cybersecurity, physical security, and privacy regulations.
Their cybersecurity program is responsible for assessing, identifying, and managing risks from cybersecurity threats using industry frameworks, as well as best practices developed by government and industry partners.
−Removed: All employees and contractors are required to complete annual trainings on a variety of security-related topics.
+Added: All employees and contractors are required to complete annual trainings on a variety of security-related
Additionally, the companies continuously upgrade technological investments designed to prevent, detect, and respond to attacks.
13 unchanged sentences
Management’s Role:
−Removed: The Vice President of Information Technology and Security and CIO has over 25 years of information technology and security experience and, to enhance governance, reports to the Senior Vice President and General Counsel.
−Removed: The Vice President of Information Technology and Security and CIO is responsible for informing the CEO and other members of senior management, as necessary, about cybersecurity incidents, covering prevention, detection, mitigation, and remediation efforts as they are detected by the cybersecurity team.
+Added: The Vice President of IT and Security and CIO has over 25 years of IT and security experience and, to enhance governance, reports to the Executive Vice President of Business Transformation and Chief Legal and Administrative Officer.
+Added: The Vice President of IT and Security and CIO is responsible for informing the CEO and other members of senior management, as necessary, about cybersecurity incidents, covering prevention, detection, mitigation, and remediation efforts as they are detected by the cybersecurity team.
Cybersecurity incidents are managed using the companies’ standard process for critical events.
−Removed: In the event of such cybersecurity incidents, the Vice President of
−Removed: Information Technology and Security and CIO communicates and collaborates with the officers of the companies and subject matter experts to address business continuity, contingency, and recovery plans.
+Added: In the event of such cybersecurity incidents, the Vice President of IT and Security and CIO communicates and collaborates with the officers of the companies and subject matter experts to address business continuity, contingency, and recovery plans.
Senior management will notify the Board , including the Audit Committee, of any significant cybersecurity incidents.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.