Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

ATEN US Equity

A10 Networks, Inc.Information Technology · Computer Communications Equipment · CIK 1580808 · FY ends Dec 31
$26.12
+0.59 (+2.31%)
USD · as of 2026-08-21 · marketstack

ATEN · 10-K · period ended 2023-12-31

← all ATEN documents
filed 2024-02-29 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1549 of 1,419346k characters rendered

aten-20231231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

Form 10-K

(Mark One)

For the fiscal year ended December 31, 2023

OR

For the transition period fromto

Commission file number: 001-36343

A10 NETWORKS, INC.

(Exact Name of Registrant as Specified in its Charter)

2300 Orchard Parkway,San Jose, California95131

(Address of Principal Executive Offices and Zip Code)

(408) 325-8668

(Registrant’s Telephone Number, Including Area Code)

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol Name of Each Exchange on Which Registered

Common Stock, $.00001 Par Value ATEN New York Stock Exchange

Securities registered pursuant to Section 12(g) of the Act:

None.

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and "emerging growth company" in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ̈

Indicate by check mark whether the Registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ̈

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ̈

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of the registrant’s common stock held by non-affiliates of the registrant as of June 30, 2023 (the last business day of the registrant’s most recently completed second fiscal quarter) was approximately $1,017.7 million, based upon the closing sale price of such stock on the New York Stock Exchange. Solely for purposes of this disclosure, shares of common stock held by executive officers and directors of the Registrant as of such date, as well as shares held by entities affiliated with our executive officers and directors, have been excluded because such persons may be deemed to be affiliates. This determination of executive officers and directors as affiliates is not necessarily a conclusive determination for any other purposes.

As of February 16, 2024, the number of outstanding shares of the registrant’s common stock, $0.00001 par value per share, was 74,495,333.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the registrant’s definitive Proxy Statement for the 2023 Annual Stockholders’ Meeting, which the registrant expects to file with the Securities and Exchange Commission within 120 days of December 31, 2023, are incorporated by reference into Part III (Items 10, 11, 12, 13 and 14) of this Annual Report on Form 10-K.

A10 NETWORKS, INC.

ANNUAL REPORT ON FORM 10-K

FOR THE YEAR ENDED DECEMBER 31, 2023

TABLE OF CONTENTS

Page

Note Regarding Forward-Looking Statements 2

Risk Factor Summary 4

PART I

Item 1. Business 6

Item 1A. Risk Factors 18

Item 1B. Unresolved Staff Comments 46

Item 1C. Cybersecurity 45

Item 2. Properties 46

Item 3. Legal Proceedings 46

Item 4. Mine Safety Disclosures 46

PART II

Item 6. [Reserved] 49

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 60

Item 8. Financial Statements and Supplementary Data 61

Item 9A. Controls and Procedures 97

Item 9B. Other Information 99

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 99

PART III

Item 10. Directors, Executive Officers and Corporate Governance 100

Item 11. Executive Compensation 100

Item 14. Principal Accountant Fees and Services 100

PART IV

Item 15. Exhibits, Financial Statement Schedules 101

1

NOTE REGARDING FORWARD-LOOKING STATEMENTS

The Annual Report on Form 10-K contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. The words “believe,” “may,” “will,” “potentially,” “estimate,” “continue,” “anticipate,” “intend,” “could,” “would,” “project,” “plan,” “expect,” and similar expressions that convey uncertainty of future events or outcomes are intended to identify forward-looking statements.

These forward-looking statements include, but are not limited to, statements concerning the following:

• our ability to provide customers with improved benefits relating to their existing products and applications;

• our ability to maintain an adequate rate of revenue growth and other factors contributing to such growth;

• our ability to successfully anticipate market needs and opportunities;

• our business plan and our ability to effectively manage our growth and business operations;

• our plans to strengthen our sales efforts;

• our expectations with respect to recognizing revenue related to remaining performance obligations;

• our plans to introduce new products;

• loss or delay of expected purchases by our largest end-customers;

• our ability to further penetrate our existing customer base;

• our ability to displace existing products in established markets;

• continued growth in markets relating to our networking and network security;

• our ability to timely and effectively scale and adapt our existing technology;

• our ability to innovate new products and bring them to market in a timely manner;

• our ability to conduct business internationally and any related impact on profitability;

• the effects of increased competition in our market and our ability to compete effectively;

• the effects of seasonal trends on our results of operations;

• our expectations concerning relationships with third parties;

• our expectations with respect to the realization of our tax assets and our unrecognized tax benefits;

• our plans with respect to the repatriation of our earnings from our foreign operations;

• the attraction, retention and growth of qualified employees and key personnel;

• our ability to maintain profitability while continuing to invest in our sales, marketing, product development, distribution channel partner programs and research and development teams;

• our expectations regarding our future costs and expenses;

• our expectations with respect to liquidity position and future capital requirements;

• our exploration of strategic alternatives;

• variations in product mix or geographic locations of our sales;

• our stock repurchase program and our quarterly cash dividends;

• our expectations regarding our properties and related costs;

• fluctuations in currency exchange rates;

• tariffs affecting us;

• increased cost requirements of being a public company, including related to environmental, social and governance matters, and future sales of substantial amounts of our common stock in the public markets;

• the cost and potential outcomes of litigation;

• our ability to protect against or adequately remedy security breaches in a timely or capital efficient manner;

• our ability to maintain, protect, and enhance our brand and intellectual property;

• future acquisitions of or investments in complementary companies, products, services or technologies; and

• our ability to effectively integrate operations of entities we have acquired or may acquire.

These forward-looking statements are subject to a number of risks, uncertainties, and assumptions, including those described in “Risk Factors” and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. Important factors that could cause our actual results and financial condition to differ materially from those indicated in the forward-looking statements include, among others, the following: execution risks related to closing key deals and improving our execution; the continued market adoption of our products; our ability to successfully anticipate market needs and opportunities; our timely development of new products and features; our ability to maintain profitability; any loss or delay of expected purchases by our largest end-customers; our ability to maintain or improve our competitive position; competitive and execution

2

risks related to cloud-based computing trends; our ability to attract and retain new end-customers and our largest end-consumers; our ability to maintain and enhance our brand and reputation; changes demanded by our customers in the deployment and payment model for our products; continued growth in markets relating to networking and network security; the success of any future acquisitions or investments in complementary companies, products, services or technologies; the ability of our sales and other teams to execute well; our ability to shorten our close cycles; the ability of our channel partners to sell our products; variations in product mix or geographic locations of our sales; risks associated with our presence in international markets; any unforeseen need for capital which may require us to divert funds we may have otherwise used for the dividend program or stock repurchase program; a significant decline in global macroeconomic or political conditions that have an adverse impact on our business and financial results; business interruptions related to our supply chain; our ability to manage our business and expenses if customers cancel or delay orders; weaknesses or deficiencies in our internal control over financial reporting; and our ability to timely file periodic reports required to be filed under the Securities Exchange Act of 1934, as well as other risks identified in the “Risk Factors” section of this Report.

In light of these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements.

You should not rely upon forward-looking statements as predictions of future events. Although we believe that the expectations reflected in the forward-looking statements are reasonable, we cannot guarantee that the future results, levels of activity, performance or events and circumstances reflected in the forward-looking statements will be achieved or occur. Any forward-looking statements made by us in this report speak only as of the date of this report, and we do not intend to update these forward-looking statements after the filing of this report, except as required by law.

Our investor relations website is located at https://investors.A10networks.com. We use our investor relations website, our company blog (https://www.a10networks.com/blog) and our corporate X (formerly Twitter) account (https://x.com/A10Networks) to post important information for investors, including news releases, analyst presentations, and supplemental financial information, and as a means of disclosing material non-public information and for complying with our disclosure obligations under Regulation FD. Accordingly, investors should monitor our investor relations website, our company blog and our corporate Twitter account, in addition to following press releases, SEC filings and public conference calls and webcasts. We also make available, free of charge, on our investor relations website under “SEC Filings,” our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to these reports as soon as reasonably practicable after electronically filing or furnishing those reports to the SEC.

3

RISK FACTOR SUMMARY

Risks Related to Our Business, Operations and Industry

•anticipating market needs and opportunities, and market adoption of our products;

•timely development and deployment of new products and features;

•maintaining profitability;

•variability in our operating costs and results;

•our reliance on shipments at the end of the quarter;

•intense competition and maintaining or improving our competitive position;

•cloud-based computing trends;

•maintaining and enhancing our brand and reputation;

•a limited number of end-customers comprise a significant portion of revenue;

•changes demanded by customers in our deployment and payment models;

•large end-customers demanding more favorable terms and conditions;

•fluctuations in our gross margin;

•significant revenue from international sources;

•risks associated with continued expansion of our international operations;

•hiring, retaining and motivating qualified personnel;

•exploration of strategic alternatives;

•adverse economic conditions resulting in reduced technology spending;

•our dependence on third-party manufacturers;

•limited supply sources, supply shortages and changes;

•real or perceived defects, errors or vulnerabilities in our operations, products or services;

•warranty claims, returns, liability and defects;

•undetected software and hardware errors;

•use of open source software;

•interoperability challenges with systems developed by others;

•prevention of inventory excesses or shortages;

•our ability to sell products dependent on quality support and services;

•maintaining high-quality support and services;

•product conformity with industry standards, legal and compliance related requirements;

•our dependence on third-party or other information technology systems;

•potential future acquisitions;

•credit risk of distribution partners and customers;

•risk of cyberattacks and other information or security breaches; and

•earthquakes, fires, power outages, floods, criminal activities, acts of war and terrorism.

Risks Related to Intellectual Property, Litigation, Laws and Regulations

•litigation and claims regarding our intellectual property rights;

•protecting our intellectual property rights;

•U.K. and other political developments including Brexit and changes of legal requirements;

•enhanced U.S. tariffs, import/export restrictions, Chinese regulations, trade barriers;

•protecting and securing confidentiality of data, trade secrets and personally identifiable information;

•costs of protecting against or otherwise addressing security breaches;

•adequacy of protection of personal data;

•sales to governmental organizations;

•compliance with governmental laws and regulations;

•governmental export and import controls;

•environmental laws and regulations;

•limitations on use of net operating loss carryforwards;

•changes in tax laws or regulations or, adverse outcomes to tax return examinations;

•changes in generally accepted accounting principles;

•our ability to maintain effective internal controls;

•our charter and Delaware law could discourage takeover attempts leading to management entrenchment;

•certain stockholder actions governed by the Court of Chancery of the State of Delaware; and

4

•increasing attention on environmental, social and governance matters.

Risks Related to Capitalization and Financial Markets

•fluctuations in foreign currency exchange rates;

•ownership concentration of our common stock;

•our ability to raise additional funds and stockholder dilution;

•volatility of the price of our common stock;

•potential substantial sales of common stock in the public markets;

•reports by security and industry analysts,

•changes to our dividend program; and

•our stock repurchase programs.

5

PART I

Item 1. Business

Overview

We are a leading provider of networking solutions that enable next-generation networks focused on reliability, availability, scalability and cybersecurity. Our portfolio supports customers operating in the cloud, on-premise or in hybrid environments providing rapid return on their investment as well as investment protection with best-in-class technical performance. As cyber-attacks increase in volume and complexity, we integrate security as a key attribute in essentially all our solutions that further enable our customers to continue to adapt to market trends in the cloud, internet of things and the ever-increasing need for more efficient data processing, building upon our strong global footprint and leadership in application and network infrastructure. Our customers include leading service providers (cloud, telecommunications, multiple system operators, cable), government organizations, and enterprises.

Industry Trends & Market Drivers

The digitization of business has made applications a critical ingredient in virtually every aspect of operations. The safety and efficiency of applications can directly impact business and financial performance, and security shortfalls can impact brand value and customer retention. The application networking and security industry is experiencing dynamic shifts in the way applications are developed, delivered, monetized and protected. Innovation in artificial intelligence (“AI”) is driving new ways to gain application delivery efficiency and enhance protection. Our corporate strategy and technology address these evolving trends and the needs of our customers and industry, including:

Increased Adoption of Cloud Applications. For decades, businesses operated with applications based in physical, appliance-based data centers. While these traditional applications remain central to businesses around the world, a new genre of cloud-based applications is emerging, presenting new opportunities and challenges that require organizations to reassess the visibility, performance and security of their applications. Some of these challenges relate to how a business effectively manages secure application services across various data centers and cloud types, whether private, public or hybrid clouds. Over time, more and more applications may be born or provided in the cloud, while some applications that existed in traditional data centers may migrate to clouds as well. To address this shift, businesses will need solutions that bridge both traditional and cloud-based application environments and centrally manage all secure application services holistically in this multi-cloud world.

Increased Network Complexity and New Infrastructure Paradigms. Traditional IT vendors may need to shift from hardware-centric models to software-defined approaches across several operating environments to improve agility for critical applications, and subsequently, their business operations. Enabling product portfolios to adapt and diversify to include newer virtualized software, container-based software and cloud-based offerings are key factors determining future market leadership and competitive landscapes.

Growing Importance of Automation, Orchestration.As applications increasingly move to a multi-cloud environment, the deployment of orchestration and automation tools enable efficient automation for the deployment and operations of security and application services. There is a need for increased operational efficiency and agility, improved detection and reporting of security anomalies, enhanced end-user experiences and reduced total cost of ownership (“TCO”), simplified management of distributed application services, improved capacity planning and optimized multi-cloud software lifecycle management. By deploying newly developed secure application delivery automation and predictive analytics tools, enterprises can visualize their application performance, detect anomalous trends and automate their application delivery and network security.

The Rise of DDoS Attacks and use of Artificial Intelligence. The cyberthreat landscape continues to plague enterprises and society as a whole. Malicious actors andcybercriminals such as hacktivists, amateur hackers, and foreign military and intelligence organizations target data centers of every type. Distributed Denial of Service (“DDoS”) attacks are increasing in size, frequency, complexity and notoriety. IT defenders are faced with the increasing sophistication of adversaries who are responsible for the size and frequency of these attacks.

A DDoS attack seeks to render a target network or website unavailable by orchestrating coordinated attacks from massive worldwide networks of compromised endpoints, called botnets. Compromised endpoints can be computing devices or “Internet of Things” driven devices like video cameras. Any internet-connected device can be vulnerable to

6

hackers and utilized as part of a botnet. Innovations in AI enable security teams to temper the rise in DDoS attack signals and apply techniques that accurately address compromised endpoints in a rapid manner.

Rapid growth of TLS, SSL, Encrypted Applications and Hidden Threats. Many applications use Transport Layer Security (“TLS”) and Secure Sockets Layer (“SSL”) protocols. Cyber criminals exploit the protocol to hide malicious malware within encrypted channels and carry out attacks against businesses and users. This malicious trend drives demand for greater visibility within SSL-encrypted channels. Businesses need a way to decrypt traffic and apply outbound security policies efficiently, and require an effective way to inspect, identify, and remediate malicious traffic, then re-encrypt traffic and deliver it quickly to its destination. Conducting this process efficiently without placing a “security performance tax” on the user experience is a capability valued by our customers.

The Advent of 5G Networks and a Smart World. The growing deployment of commercial 5G networks will bring massive increases in network throughput and significant new business opportunities for mobile carriers and others. It will also require a new generation of security infrastructure capable of handling the growing capacity requirements and complex management needs of 5G networks. Capacity requirements increase dramatically in 5G networks due to substantial increases in concurrent sessions, lower packet size and higher connections per second. Operators must dramatically lower latency, reduce total cost of ownership, and improve efficiency which may require advanced consolidation of network functions at the core. Meanwhile, the scope and size of DDoS attacks may also increase dramatically with the proliferation of connected devices and traffic, due in large part to the expansion of Internet of Things (“IoT”)/Machine-to-Machine traffic coming from new 5G-delivered Smart World applications. To address these requirements, mobile and other operators will need new solutions that provide hyperscale and increased performance, richer feature sets, and rich automation, analytics and threat intelligence.

Need for Advanced Multi-Cloud Secure Application Service Solutions. To address these challenges, advanced and integrated solutions for managing secure application services across businesses’ application environments are needed. Of the many solution requirements, some of the more critical include:

•Ability to Centrally Manage Traditional and Cloud Environments. As more applications are provided in the cloud, and they operate alongside traditional applications supported by on-premise and appliance-based data centers, application delivery and security solutions will be called upon to span traditional and cloud-based environments. In doing so, solutions must centrally control and manage secure application services across any combination of traditional data centers and a myriad of different clouds. To support data centers and different cloud types, solutions require a variety of form factors: hardware, software (i.e., virtual, bare metal and containers) and cloud-based offerings.

•ClearVisibility andSophisticatedAnalytics. The effectiveness of application performance and security depends greatly on the level of visibility a business has into its application traffic. That visibility should effectively span any number of data centers and cloud types to provide a holistic view of security threats and performance issues affecting applications. The deeper and clearer the visibility, the better the analytics and actionable information that can be applied to enhancing application performance and protection. Secure application service solutions should provide solid visibility and per-app analytics.

•Ability to Scale. Performance and security at scale are highly desirable to our customers given today’s dynamic application environments. Customers want solutions that analyze application traffic quickly and enhance performance and security in traditional and cloud-based application environments in a centrally managed manner. With the rapid adoption of IoT devices, and the advent of 5G, we believe a solution’s ability to perform at scale will be increasingly important.

•Sophisticated Security Functionality. Secure application service solutions must leverage machine learning and AI to rapidly detect and mitigate sophisticated cybersecurity threats, such as malicious threats hiding in encrypted traffic and DDoS attacks. To defend against the rising volume of sophisticated cyber-attacks, customers want solutions that provide exceptional performance and scale without dramatically increasing footprint and total cost of ownership.

7

Product Portfolio

Our product portfolio seeks to address many of the aforementioned challenges and solution requirements. The portfolio consists of six secure application solutions and two intelligent management and automation tools.

Our software solutions are available to be delivered in a variety of form factors, such as embedded in optimized hardware appliances, as bare metal software, containerized software, virtual appliances and cloud-native software. While our revenue to date has predominantly derived from delivery of our proprietary software on a perpetual license basis embedded in optimized hardware, this model has begun to evolve in various ways including among others, term licenses, subscriptions, and software-only models. Our comprehensive and flexible application solutions portfolio, combined with our Harmony Controller, positions us to address the growing need for shifting workloads to a mix of private clouds and public clouds. A10 Harmony Controller is built on microservices and container technologies and offers a multi-tenant, highly scalable controller architecture that incorporates real-time and predictive analytics at the application level and central management and orchestration of secure application services across hybrid environments, from physical data centers to public, private and hybrid clouds.

The following is an overview of our portfolio:

Secure application solutions:

1.Thunder Application Delivery Controller (“ADC”)

2. Thunder Carrier Grade Networking (“CGN”)

3. Thunder SSL Insight (“SSLi”)

4. Thunder Convergent Firewall (“CFW”)

Intelligent management and automation tool:

1.Harmony Controller

A10 Defend Suite of Products:

1.A10 Defend Threat Control

2.A10 Defend Orchestrator (formerly aGalaxy management system)

3.A10 Defend Detector

4.A10 Defend Mitigator (formerly Thunder TPS)

The following is a further overview of our portfolio:

Secure Application Solutions

1.Thunder Application Delivery Controller. Thunder ADC provides advanced server load balancing, including global server load balancing, high availability, aFleX scripting, aVCS, ADP multi-tenancy, SSL, offload, acceleration, caching and compression, web application firewall (“WAF”), domain name server (“DNS”) application firewall (“DAF”) and others. ADCs are typically deployed in front of a server farm within a data center, including web, application and database servers.

2. Thunder Carrier Grade Networking. Thunder CGN extends the life of increasingly scarce IPv4 address blocks and their associated infrastructure using Carrier-Grade network address translation (“CGNAT”), and also provides translation solutions to the IPv6 addressing standard. Our CGN solution is typically deployed in service provider networks to provide standards-compliant address and protocol translation services between varying types of IP addresses. It has been successfully implemented by many large service providers and enterprises around the world.

3. Thunder SSL Insight. Thunder SSLi focuses on the inherent blind spots created by SSL encryption by offloading CPU-intensive SSL decryption functions that enable security devices to inspect and remove malware within encrypted traffic. Thunder SSLi decrypts SSL-encrypted traffic and forwards it to a third-party security device, such as a firewall, for deep packet inspection (“DPI”). Once the traffic has been analyzed and scrubbed, Thunder SSLi re-encrypts the traffic and forwards it to its intended destination.

8

4. Thunder Convergent Firewall. Thunder CFW addresses multiple critical security capabilities in one package by consolidating multiple security and networking functions in a single appliance, helping customers significantly lower capital and operating expenses. Its performance and scale deliver superior value to customers, all within a small form factor, and streamlines customer operations with a cloud-ready programmable platform.

Thunder CFW includes:

•A high-performance Secure Web Gateway with integrated explicit proxy, URL filtering and SSL visibility, enabling security policy enforcement for outbound HTTP/HTTPS client traffic. Our solution includes a Cloud Access Proxy to provide scalability, performance, and security to overcome deployment and operational challenges.

•A high-performance data center firewall with integrated network denial-of-service protection and server load balancing, which provides a Layer 4 stateful firewall and Layer 7 application-level gateway functionality for protecting data center applications from emerging network and DDoS threats.

•A high-performance Gi/SGi firewall with integrated network DDoS, CGNAT, ADC and application visibility. The Gi/SGi firewall protects the mobile operator infrastructures from Internet-based DDoS and other security threats.

•A high-performance IPsec VPN, a security product designed to strengthen security postures and protect application data.

Intelligent Management and Automation Tool

1. Harmony Controller. Harmony Controller provides intelligent management, automation and analytics for secure application delivery in multi-cloud environments to help simplify operations. Infrastructure and application operations teams can centrally manage and automate configuration and application policies for our Thunder and Lightning application and security services, such as load balancing, application delivery, web application firewall, SSL decryption, Gi/SGi firewall, Carrier Grade NAT and Cloud Access Proxy solutions. Configuration and control can also be automated via application program interface (“API”) and integrated with orchestration systems used within organizations. In addition, the Harmony Controller provides comprehensive infrastructure and per-application metrics and analytics for performance and security monitoring, anomaly detection and faster troubleshooting. The container-based, microservices architecture allows controller capacity to be scaled without interrupting operations. Our Harmony Controller is available in two deployment models: A10 managed software-as-a-service (“SaaS”), or as a self-managed, on-premise deployment.

A10 Defend Suite of Products

1. A10 Defend Threat Control. A10 Defend Threat Control is a standalone SaaS platform that proactively establishes a robust first layer of defense by offering actionable analytics and blocklists. Defend Threat Control is based on proprietary A10 research.

2. A10 Defend Orchestrator (formerly aGalaxy management system). A10 Defend Orchestrator integrates with A10 Defend Detector and A10 Defend Mitigator for intelligent and automated DDoS protection, providing a centralized point of control for seamless DDoS defense management and execution. A10 Defend Orchestrator is designed to help lower operational costs by freeing up staff from repetitive tasks while increasing precision and accuracy with centralized and automated tasks, reducing the potential for human error. A10 Defend Orchestrator highlights included advanced workflow and automated defense capabilities.

3. A10 Defend Detector. A10 Defend Detector is our high-performance Netflow, Sflow, IPFIX-based DDoS detector and is used to easily manage the scale and heterogenous nature of SP networks, resulting in a unified DDoS protection solution. Defend Detector can be used by SPs to deliver DDoS services to downstream customers.

4. A10 Defend Mitigator (formerly Thunder TPS). A10 Defend Mitigator is our high precision, automated, scalable, and intelligent DDoS mitigation solution that is delivered as hardware or virtual appliances ranging from 1Gbps to over 1Tbps. A10 Defend Mitigator is typically deployed at the perimeter of the networks to protect internal network resources from large-scale, volumetric and multi-vector attacks. In 2017, we enhanced the A10 Defend Mitigator solution with the launch of a dedicated detector function, improved workflow and automation in A10

9

Defend Orchestrator. In 2018, we enhanced our detection capabilities with the One-DDoS solution, which enables Thunder ADC, CGN, and CFW solutions to act as in-line detectors to enhance application and infrastructure detection. We also added A10 Defend Mitigator Dynamic Attack Pattern Recognition (“DAPR”) for automatic attack learning, to identify and thwart zero-day attacks, and enhanced machine learning (“ML”) with always-on adaptive learning. Defend Mitigator is augmented by the A10 Threat Control and software licensed from ThreatSTOP, Inc., which can block known bad connections (i.e., IP addresses) from entering protected networks.

Product Form Factors

Our products are offered in a variety of form factors and payment models, including physical appliances and perpetual and subscription-based software licenses, as well as pay-as-you-go licensing models and FlexPool, a flexible consumption-based software model. FlexPool allows businesses to flexibly allocate and re-distribute capacity across applications, multiple clouds and data centers.

Thunder Series: ADC, CGN, TPS, SSLi, and CFW products are available on the Thunder Series family of physical appliances. The Thunder Series products support throughput ranges from 200 Mbps to 550 Gbps. The appliance family provides a variety of other security and performance options.

vThunder virtual appliances operate on all major hypervisor platforms, including VMware, Microsoft Hyper-V and Linux KVM. vThunder is also available from cloud providers like Amazon Web Services (“AWS”), Microsoft Azure, Google Cloud Compute (“GCP”) and service providers. The vThunder Series products support throughput ranges from 200 Mbps to 100 Gbps.

Thunder for Bare Metal is a software version of our ADC and CGN solutions that is designed to run on a variety of Intel x86 servers, allowing the customer to design and select their own hardware platform.

Thunder container is software that can be deployed as a container for cCGN, cADC and cTPS on customers’ own hardware platforms and OS stacks.

Underlying Technology

Since our inception, our solutions have been known for their high performance and scalability in some of the largest and most demanding networks. The value and significance of our high-performance offerings reside in our portfolio’s underlying software operating system. With the exception of Lightning ADC, our products are built on the Advanced Core Operating System (“ACOS”) platform and leverage its performance optimization and security features.

The ACOS platform is optimized for modern 64-bit central processing units (“CPUs”), which increasingly have multiple parallel processing cores that operate within a single CPU for higher efficiency and performance scalability. To maximize the capabilities of these increasingly dense multi-core CPUs, ACOS implements a proprietary shared memory architecture that provides all cores with simultaneous access to common memory. This shared memory software architecture enables our products to utilize these multi-core CPUs efficiently and scale performance with increasing CPU cores. As a result, ACOS provides customers with products that can deliver superior price performance benefits over products that lack these capabilities.

ACOS’ high-performance design enables our products to address a wide range of performance-driven networking challenges. The flexible software design of ACOS allows us to apply our portfolio to a variety of markets for a variety of needs. Some notable details about ACOS include:

High Performance and Intelligent Network Input/Output (“I/O”) Processing. In order to maximize the efficiency of high density, multi-core processors, we have developed a high-performance intelligent network I/O technology that can balance application traffic flows equitably across processor cores. Our Flexible Traffic Accelerator logic can be implemented either as software running within a standard x86 processor or a Field Programmable Gate Array (“FPGA”) semiconductor. Our Flexible Traffic Accelerator (“FTA”) also performs certain hardware-based security checks for each packet and can isolate suspicious traffic before it can impact system performance.

Scalable and Efficient Memory Usage. To improve the performance of the multi-core processor architecture, we have developed a shared memory technology to allow processors to share common memory and the state of the system simultaneously. This avoids the overhead associated with Inter-Processor Communication architectures deployed in

10

first-generation approaches. We optimize memory to be visible to processor cores simultaneously, while minimizing communication overhead and contention among processors for allocated memory space. All processors share a common memory pool, which dynamically allocates memory space based on application processing requirements without constraints. Customers can achieve greater performance and scalability from memory and processor resources because configurations, policies and network databases are efficiently stored within a shared memory architecture.

Optimized Application Networking and Security. Once data is processed and placed into a shared memory, a processor can begin to apply ACOS common services and function-specific logic. To enable every processor utilized to perform key functions and thereby achieve greater system utilization, ACOS uses processor cores symmetrically for functions and services. The ACOS common services perform a set of key operational functions, including configuration management, network I/O, aFleX scripting, Virtual Chassis System (“aVCS”), aXAPI for management integration, Application Delivery Partitions (“ADPs”), virtualization to enable multi-tenancy, and common resource management such as buffer, system memory, timer management and other internal system management tasks. ACOS features a modular software design, which improves reliability by preventing modifications made to one module from causing unwanted side effects on other system functions.

Other noteworthy ACOS Technologies. ACOS incorporates a number of other technologies to provide a rich environment for developing Layer 4-7 application networking solutions, including:

•aFleX Scripting. aFleX scripting technology is based on industry-standard tool command language and enables customers to write custom scripts to augment the application processing.

•ADP. ADP enables multi-tenancy in the ACOS common services so that multiple departments of an organization or multiple customers can share a physical/virtual appliance.

•aVCS. aVCS enables multiple physical/virtual appliances to be managed as a single chassis.

•aXAPI. aXAPI is an industry standard representational state transfer (“RESTful”) program interface to enable management integration for automated management.

Support & Services

One of our founding principles is to provide excellent customer support. Our global support team, with deep technical domain expertise, is part of our engineering organization and is trained across all products and solutions and takes complete ownership of customer issues from the beginning to the end to achieve rapid response and resolution. Our consistent, high-quality customer service and technical support is a key factor in attracting and retaining customers of all sizes, as well as support services that include installation, phone support, repair and replacement, software updates, online tools, consulting and training services.

All customers receive standard warranty support for 90 days with the purchase of our products. We offer four maintenance options - Basic, Basic Plus, Gold and Platinum support programs (Platinum available in select countries). Maintenance contracts may be purchased in 12-month increments up to five years.The average maintenance contract term is approximately 18 months. We invoice resellers or customers directly for maintenance contracts at the time of hardware purchase, and all maintenance contracts are non-cancellable and are generally renewed through the same channel as originally purchased. Software updates are provided to all customers with a current maintenance contract on a when-and-if-available basis. We maintain technical support centers in the United States, Japan, India and the Netherlands.

Thunder TPS features an enhanced support offering that includes access to the A10 DDoS Security Incident Response Team (“SIRT”). Augmenting the standard support, the offering includes access to a dedicated team of DDoS mitigation experts specializing in DDoS prevention, offering efficient assistance for mitigating attacks, and a subscription to the A10 Threat Intelligence Service, leveraging collective intelligence to block known threats.

Our professional services team provides a full range of fee-based consulting services, including pre-sale network assessment, comprehensive network analysis and capacity planning, post-sale migration and implementation services, on-site installation and ongoing support.

11

Customers

Our customers operate in a variety of industries, including telecommunications, technology, industrial, government, retail, financial, gaming, and education. Our customers include the top two United States wireless carriers, four of the top 10 United States cable providers, and the top four service providers in Japan, in addition to other global enterprises, gaming companies and governmental organizations. During the years ended December 31, 2023, 2022 and 2021, purchases from our 10 largest end-customers accounted for approximately 33%, 41% and 39% of our total revenue, respectively.

In 2023, one distribution channel partner accounted for 19% of our total revenue. In 2022, two distribution channel partners accounted for 15% and 13% of our total revenue. In 2021, one distribution channel partner accounted for 12% of our total revenue.

Competition

As security, 5G and cloud trends continue to gain prominence, changes in application delivery needs, cyber security threats, and the technology landscape result in evolving customer requirements. These evolving demands have expanded our addressable market into cybersecurity including DDoS protection, 5G /5G-readiness and hybrid networking, where we compete with a number of companies not included among our traditional competitors of the past. The agility and flexibility of a common management platform enables us to offer multiple product categories that are easier to manage for our customers. Our portfolio also includes container and microservices-based versions of certain of our comprehensive set of hardware, software and cloud offerings.

We do not consider any of these markets to include a single dominant company, nor do we consider the markets to be fragmented. Our main competitors fall into the following categories:

•Companies that sell network security solutions and services including DDoS protection, such as Arbor Networks Inc., a subsidiary of Netscout Systems, F5 Networks, Inc. (“F5 Networks”) and Radware, Ltd;

•Companies that sell network security products, including Secure Web Gateways, SSL Insight/SSL Intercept, data center firewalls and Office 365 proxy solutions;

•Companies that sell Gi/SGi firewall and CGN products, which were originally designed for other networking purposes, such as edge routers and security appliances from vendors like Cisco Systems, Inc. (“Cisco Systems”), Juniper Networks, Inc. (“Juniper Networks”) and Fortinet, Inc. (“Fortinet”); and

•Companies that sell products in the traditional application delivery market, such as F5 Networks, NetScaler from Cloud Software Group, Inc., VMware from Broadcom (through its acquisition of Avi Networks) as well as many startups.

The key competitive factors in our markets include:

•Ability to innovate and respond to customer needs rapidly;

•Ability to prepare for, detect and mitigate large-scale cyber security threats;

•Ability for products to scale to facilitate high-speed network traffic;

•Ability to address on-premise and cloud application environments in a secure, centrally managed manner;

•Ability to accommodate any IT delivery model or combination of models, regardless of form factor and customer consumption model;

•Level of customer intimacy and application know-how;

•Total cost of ownership including ease-of-use and a common platform approach for multiple products;

•Brand awareness and reputation; and

12

•Ability to attract and retain talented employees.

Sales and Marketing

Sales

Our high-touch sales force engages customers directly and through distribution channels. Our sales team is comprised of inside sales and field sales personnel who are organized by geography and maintain sales presence in 28 countries as of December 31, 2023, including in the following countries and regions: United States, Western Europe, the Middle East, Japan, Taiwan, South Korea, Southeast Asia and Latin America. Our sales organization includes sales engineers with deep technical domain expertise who are responsible for pre-sales technical support, solutions engineering, proof-of-concept work and technical training for our distribution channels. Our sales team is also comprised of a channel sales organization that is expanding our market reach through resellers. We may continue to grow our sales headcount, including in geographies where we currently do not have a sales presence.

Some customer sales are originated and completed by our Original Equipment Manufacturer (“OEM”) and distribution channels with little or no direct engagement by our sales personnel. We fulfill nearly all orders globally through our distribution channels, which include distributors, value added resellers and system integrators. Revenue fulfilled through our distribution channels accounted for 95%, 83% and 89% of our total revenue for the years ended December 31, 2023, 2022 and 2021, respectively.

Marketing

Our strategy is focused on driving greater demand for our products and services, and enabling sales to win as that demand broadens. Our marketing drives global demand generation campaigns, as well as additional awareness and demand via joint marketing campaigns worldwide. Our marketing also drives global awareness through industry analyst engagement, media outreach, blogs, social media and events.

Manufacturing

We outsource the manufacturing of our hardware products to original design manufacturers. This approach allows us to benefit from the scale and experience of our manufacturing partners to reduce our costs, overhead and inventory while allowing us to adjust more quickly to changing customer demand. Our manufacturers are Lanner Electronics Inc. (“Lanner”), AEWIN Technologies Co., Ltd. (“AEWIN”) and iBase. These companies manufacture and assemble our hardware products using design specifications, quality assurance programs and standards established and owned or licensed by us. Our manufacturers procure components and assemble our products based on our demand forecasts and purchase orders. These forecasts represent our estimates of future demand for our products based on historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.

We have agreements with Lanner with an initial term of one year and AEWIN with an initial term of six years pursuant to which they manufacture, assemble, and test our products. Each agreement automatically renews for successive one-year terms unless either party gives notice that they do not want to renew. We do not have any long-term manufacturing contracts that guarantee fixed capacity or pricing. Quality assurance and testing is performed at our San Jose, Taiwan and Japan distribution centers, as well as at our manufacturers’ locations. We warehouse and deliver our products out of our San Jose warehouse for the Americas and direct from Taiwan for APAC and EMEA. We outsource delivery to a third-party logistics provider for deliveries in Japan.

Backlog

As of December 31, 2023 and 2022, we had product backlog of approximately $3.8 million and $8.1 million, respectively. Backlog represents orders confirmed with a purchase order for products to be shipped generally within 90 days to customers with approved credit status. Orders may be subject to cancellation, rescheduling by customers and product specification changes by customers. Although we believe that the backlog orders are firm, purchase orders may be canceled by the customer prior to shipment without significant cost. For this reason, we believe that our product backlog at any given date is not a reliable indicator of future revenues.

13

For the years ended December 31, 2023, 2022 and 2021, our total revenue was $251.7 million, $280.3 million, and $250.0 million, respectively, and our gross margin was 80.9%, 79.7%, and 78.6%, respectively. We had net income of $40.0 million, $46.9 million and $94.9 million for the years ended December 31, 2023, 2022 and 2021, respectively.

Intellectual Property

We rely on a combination of patent, copyright, trademark and trade secret laws, and restrictions on disclosure to protect our intellectual property rights. As of December 31, 2023, we had 210 United States (“U.S.”) patents issued, 5 U.S. patent applications pending, 79 overseas patents issued and 9 overseas patent applications pending. Our issued U.S. patents, excluding 14 patents that we acquired, expire between 2024 and 2042. Our issued overseas patents, excluding 5 patents that we acquired, expire between 2024 and 2037. Our future success depends in part on our ability to protect our proprietary rights to the technologies used in our principal products. Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our products or to obtain and use trade secrets or other information that we regard as proprietary. In addition, the laws of some foreign countries do not protect our proprietary rights as fully as do the laws of the United States. Any issued patent may not preserve our proprietary position, and competitors or others may develop technologies similar to or superior to our technology. Our failure to enforce and protect our intellectual property rights could harm our business, operating results and financial condition.

We license software from third parties for development of, or integration into, our products, including proprietary and open source software. We pursue registration of our trademarks and domain names in the United States and other jurisdictions. See Part I, Item 1A. Risk Factors included in this Annual Report on Form 10-K for additional information regarding the risks associated with protecting our intellectual property.

Human Capital

As of December 31, 2023, we had 525 full-time employees, including 236 engaged in research and development and customer support, 235 in sales and marketing and 54 in general and administrative and other activities. None of our employees is represented by a labor union or is a party to any collective bargaining arrangement in connection with his or her employment with us. We have never experienced any work stoppages, and we consider our relations with our employees to be good.

Corporate Responsibility

A10 Networks’ mission is to enable business-critical networks that are secure, available and efficient. In our rapidly expanding digital economy, this has never been more relevant and critical. Our customers rely on us to help them drive better business outcomes now and into the future.

With our mission in mind, we are committed to maintaining the highest standards of ethics and corporate governance, and to fostering a diverse and inclusive workforce and customer and partner ecosystem. We believe these practices will deliver the highest value for our employees, customers, partners and shareholders. Our global footprint provides an additional level of sustainability for business performance, and we drive this responsibility across all our global locations.

We use as a guide the code of conduct policies set forth by the Responsible Business Alliance, the world’s largest industry coalition dedicated to corporate social responsibility in global supply chains,and we expect all of our suppliers to do so as well. The alliance sets standards and practices for a social, environmentally sustainable, and ethical supply chains. Our supply chain has sustained audits based on the Validated Assessment Program.

Further, we have established standards and practices to which our Board of Directors, executives and employees are obligated to adhere, as outlined on our website under Corporate Responsibility.

Environmental, Social and Governance (“ESG”)

Environmental

We are committed to business practices that preserve the environment upon which our society and economy depend. We are committed to meeting or exceeding all legal and compliance guidelines for our people, products and operations. In addition, we strive to deliver products and services that minimize the impact to the environment throughout our value chain.

14

Our environmental initiatives are aligned with the 1.5°C ambition as outlined in the Paris Agreement, and we have corporate goals to support the initiative.

We work with our contract manufacturers and suppliers to maintain compliance with, for example, RoHS, REACH and WEEE in the EU and elsewhere across the globe for other such environmental requirements. The Company’s Conflict Minerals Supply Chain Policy as well as our Code of Business Conduct and Ethics outlines our practices and procedures with respect to human rights to ensure participants in our supply chain do not knowingly contribute to local conflict or human rights abuses. We expect our suppliers to comply with our policy on responsible sourcing of minerals from conflict-affected and high-risk areas and to cooperate with our diligence inquiries and requests for information and certification as may be required by us to comply with reporting and disclosure obligations to which we are subject from time to time.

Our corporate headquarters in San Jose, California, is compliant with the California Building Energy Efficiency Standards - Title 24 to reduce wasteful and unnecessary energy consumption. The Company has planned for greater use of renewable energy in partnership with the local utility, PG&E. At our headquarters, we offer EV charging stations to our employees and visitors, and where applicable according to local requirements, we offer recycling and we properly dispose of e-waste.

Social

Diversity, Inclusion & Equal Opportunity

We are committed to providing a work environment that is free of discrimination and harassment. We are an equal-opportunity employer. We make employment decisions on the basis of a person’s qualifications, and our business needs. We believe in the richness and quality of a working environment that is informed by people from all walks of life and strive to create a genuinely inclusive environment. We have implemented Diversity, Equal Opportunity, and Inclusion action planning teams focused on analysis from diversity surveys and focus groups. We have ongoing outreach efforts to recruit a diverse candidate pool and are building questions into our engagement survey to promote a diverse and inclusive environment.

We are committed to ensuring our team members are treated with fairness and respect. We believe that a cooperative work environment, based on trust and mutual respect, is essential to our success. We embrace the diversity of our workforce and celebrate the creative value added by individuals with differing backgrounds. We expressly prohibit intimidation, hostility, harassment, discrimination and other inappropriate behavior. Furthermore, we expect employees to conduct themselves in a professional and dignified manner at all times; in doing so, we seek to avoid making employees feel uncomfortable at work.

As new employees join us, they learn more about our policies and culture through orientation and onboarding, our Employee Handbook, Code of Business Conduct and Ethics, and compliance trainings. These all provide guidance on how we expect to operate in order to foster diversity, equity and inclusion across our company.

We are an equal opportunity employer and a Vietnam Era Veterans' Readjustment Assistance Act (“VEVRAA”) federal subcontractor. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. We also comply with all applicable state and local laws governing nondiscrimination in employment.

Total Rewards

We offer an attractive mix of compensation and benefit plans to support our employees and their families’ physical, mental, and financial well-being. We believe that we employ a fair and merit-based total compensation system for our employees and offer a variable bonus plan for eligible employees. Employees are generally eligible for medical, dental, vision and other comprehensive benefits, most of which become effective on their start date. Below are some of the types of health and wellness related benefits offered to employees:

•Medical, dental and vision insurance;

•Retirement plan with Company matching contribution feature;

•Flexible Spending Accounts for medical expenses, childcare, parking and transit;

•Health Savings Account (with employer contribution);

•Life insurance;

15

•Short & long-term disability;

•Paid time off and leave of absences; and

•Employee assistance program

Employees have an opportunity for financial inclusion at A10 Networks with an ownership interest in our company.There are several programs that provide employees with the ability to own our stock. Generally, more than 75% of our employees participates in at least one of our stock programs. During their tenure with our company, most employees have an opportunity to receive an equity award, either upon hire and/or during an annual review process to recognize those with significant impact on achieving our goals. Most employees, whether part or full time, also have the ability to participate in our Employee Stock Purchase Plan (“ESPP”). Participants in the ESPP may purchase our stock at a 15% discount to market price. We believe our discounted stock purchase program helps to build an ownership mentality amongst participating employees.

Health, Safety and Wellness

We are committed to maintaining a healthy, safe, and secure work environment that protects our employees and the public from harm. We use a multi-faceted approach to ensure the health and safety of our employees, from our Code of Business Conduct and Ethics to our policies governing the way we act within and outside of our company. We comply with applicable health, safety, and environmental laws as well as related company policies and procedures. We have a zero-tolerance policy against aggressive behavior, violence, direct and indirect threats, harassment, intimidation, and possession of weapons on company property. Moreover, we strive to conduct our everyday business activities in an environmentally sustainable way through wellness programs and webinars through our health insurance providers.

Governance

Our Board of Directors believes that our board should be a diverse body, and our Nominating and Corporate Governance Committee considers a broad range of backgrounds and experiences when selecting nominees for our board. Sixty percent of our directors currently self-identify as being from one or multiple diverse groups, including gender.

We continuously review and improve our corporate governance guidelines in response to changing requirements and feedback from employees, customers, partners, vendors and shareholders. The Nominating and Corporate Governance Committees of the Board of Directors, consisting entirely of independent directors, evaluates the appropriate governance practices as defined by law and industry best practice and takes those recommendations to the Board of Directors. Currently, four of five Board members are independent and three of five have less than five years of tenure.

A10 engages with an independent audit firm to ensure the Company complies with relevant requirements such as the 2002 Sarbanes-Oxley Act.

The Company’s governance and code of conduct policies are outlined in the Code of Business Conduct and Ethics, Corporate Governance Guidelines, Whistleblower Policy and the Employee Handbook. Employees may submit concerns to generalcounsel@a10networks.com or via the Company’s third-party hotline as noted the Employee Handbook.

Corporate Information

A10 Networks, Inc. was incorporated in the State of California in 2004 and subsequently reincorporated in the State of Delaware in March 2014. Our website is located at www.A10networks.com, and our investor relations website is located at https://investors.A10networks.com. The following filings are available through our investor relations website after we file them with the SEC: Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, as well as any amendments to such reports and all other filings pursuant to Section 13(a) or 15(d) of the Securities Act. These filings are also available for download free of charge on our investor relations website. Additionally, copies of materials filed by us with the SEC may be accessed at the SEC’s website at www.sec.gov.

We announce material information to the public about the Company, our products and services and other matters through a variety of means, including our website (www.A10networks.com), the investor relations section of our website (https://investors.A10networks.com), press releases, filings with the Securities and Exchange Commission, public conference calls, and social media, including our corporate X (formerly Twitter) account (@A10Networks) and our corporate Facebook page (https://www.facebook.com/a10networks). Information provided includes press releases and other information about financial performance, information on environmental, social and governance and details related to the Company’s annual

16

meeting of shareholders. The contents of our website and social media contents are not intended to be incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. We encourage investors and others to review the information we make public in these locations, as such information could be deemed to be material information. Please note that this list may be updated from time to time.

17

Item 1A. RISK FACTORS

Investing in our common stock involves a high degree of risk. You should carefully consider the risks and uncertainties described below, together with all of the other information contained in this report and in our other public filings. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, may also become important factors that affect us. If any of the following risks occur, our business, financial condition, operating results, and prospects could be materially harmed. In that event, the trading price of our common stock could decline, perhaps significantly. The order of presentation is not necessarily indicative of the level of risk that each factor poses to us.

Risks Related to Our Business, Operations and Industry

If we do not successfully anticipate market needs and opportunities or if the market does not continue to adopt our application delivery solutions, our business, financial condition and results of operations could be significantly harmed.

The application delivery market is rapidly evolving and difficult to predict. Technologies, customer requirements, security threats and industry standards are constantly changing. As a result, we must anticipate future market needs and opportunities and then develop new products or enhancements to our current products that are designed to address those needs and opportunities, and we may not be successful in doing so.

We continuously seek to enhance and improve our solutions we make available to our customers. However, even if we are able to anticipate, develop and commercially introduce new products and enhancements that address the market’s needs and opportunities, there can be no assurance that new products or enhancements will achieve widespread market acceptance. For example, organizations that use other conventional or first-generation application delivery solutions for their needs may believe that these solutions are sufficient. In addition, as we launch new product offerings, organizations may not believe that such new product offerings offer any additional benefits as compared to the existing application delivery solutions that they currently use. Accordingly, organizations may continue allocating their IT budgets for existing application solutions and may not adopt our solutions, regardless of whether our solutions can offer superior performance or security.

If we fail to anticipate market needs and opportunities or if the market does not continue to adopt our application delivery solutions, then market acceptance and sales of our current and future application delivery solutions could be substantially decreased or delayed, we could lose customers, and our revenue may not grow or may decline. Any of such events would significantly harm our business, financial condition and results of operations.

Our success depends on our timely development of new products and features to address rapid technological changes and evolving customer requirements. If we are unable to timely develop and successfully introduce new products and features that adequately address these changes and requirements, our business and operating results could be adversely affected.

Changes in application software technologies, data center and communications hardware, networking software and operating systems, and industry standards, as well as our end-customers’ continuing business growth, result in evolving application networking needs and requirements. Our continued success depends on our ability to identify, develop and introduce in a timely and successful manner, new products and new features for our existing products that meet these needs and requirements.

Our future plans include significant investments in research and development and related product opportunities. Developing our products and related enhancements is time-consuming and expensive. We have made significant investments in our research and development team in order to address these product development needs. Our investments in research and development may not result in significant design and performance improvements or marketable products or features, or may

result in products that are more expensive than anticipated. We may take longer to generate revenue, or generate less revenue, than we anticipate from our new products and product enhancements. We believe that we must continue to dedicate a significant amount of resources to our research and development efforts to maintain our competitive position.

We continuously seek to enhance and improve our solutions. However, if we are unable to develop new products and features to address technological changes and new customer requirements in the application networking or security markets, or if our investments in research and development do not yield the expected benefits in a timely manner, our business and operating results could be adversely affected.

18

We have experienced net losses in the past and may not maintain profitability in future periods. If we cannot maintain profitability, our financial performance will be harmed and our business may suffer.

We may not be able to increase our quarterly revenue or maintain profitability in the future or on a consistent basis, and we may incur significant losses in the future for a number of possible reasons, including our inability to develop products that achieve market acceptance, general economic conditions, increasing competition, decreased growth in the markets in which we operate, regulatory or other governmental actions over which we have no control, or our failure for any reason to capitalize on growth opportunities. Additionally, we may encounter unforeseen operating expenses, difficulties, complications, delays and other unknown factors that may result in losses in future periods. If these losses exceed our expectations or our revenue growth expectations are not met in future periods, our financial performance will be harmed and our stock price could be volatile or decline.

Our operating results have varied and are likely to continue to vary significantly from period to period and may be unpredictable, which could cause the trading price of our common stock to decline.

Our operating results, in particular, revenue, margins and operating expenses, have fluctuated in the past, and we expect this will continue, which makes it difficult for us to predict our future operating results. The timing and size of sales of our products are highly variable and difficult to predict and can result in significant fluctuations in our revenue from period to period. This is particularly true of sales to our largest end-customers, such as service providers, enterprise customers and governmental organizations, who typically make large and concentrated purchases and for whom close or sales cycles can be long, as a result of their complex networks and data centers, as well as requests that may be made for customized features. Our quarterly results may vary significantly based on when these large end-customers place orders with us and the content of their orders.

Our operating results may also fluctuate due to a number of other factors, many of which are outside of our control and may be difficult to predict. In addition to other risks listed in this “Risk Factors” section, factors that may affect our operating results include:

•fluctuations in and timing of purchases from, or loss of, large customers;

•the budgeting cycles and purchasing practices of end-customers;

• changes in end-customer preferences, practices or personnel;

•our ability to attract and retain new end-customers;

•our ability to provide and enhance efficient operations;

•changes in demand for our products and services, including seasonal variations in customer spending patterns or cyclical fluctuations in our markets;

•our reliance on shipments at the end of our quarters;

•variations in product mix or geographic locations of our sales, which can affect the revenue we realize for those sales;

•the timing and success of new product and service introductions by us or our competitors;

•our ability to increase the size of our distribution channel and to maintain relationships with important distribution channels;

•our ability to improve our overall sales productivity and successfully execute our marketing strategies;

•the effect of currency exchange rates on our revenue and expenses;

19

•changes in legal requirements, our compliance obligations and/or relevant tax schemas;

•the cost and potential outcomes of existing and future litigation;

•expenses related to our facilities, networks, and network operations;

•the effect of discounts negotiated by our largest end-customers for sales or pricing pressure from our competitors;

•changes in the growth rate of the application networking or security markets or changes in market needs;

•inventory write downs, which may be necessary for our older products when our new products are launched and adopted by our end-customers;

•our ability to expand internationally and domestically; and

•our third-party manufacturers’ and component suppliers’ capacity to meet our product demand forecasts on a timely basis, or at all.

Any one of the factors above or the cumulative effect of some of these factors may result in significant fluctuations in our financial and other operating results. This variability and unpredictability could result in our failure to meet our or our investors’ or securities analysts’ revenue, margin or other operating results expectations for a particular period, resulting in a decline in the trading price of our common stock.

Reliance on shipments at the end of the quarter could cause our revenue for the applicable period to fall below expected levels.

As a result of end-customer buying patterns and the efforts of our sales force and distribution channels to meet or exceed their sales objectives, we have historically received a substantial portion of purchase orders and generated a substantial portion of revenue during the last few weeks of each quarter. We may be able to recognize such revenue in the quarter received, however, only if all of the requirements of revenue recognition are met by the end of the quarter. Any significant interruption in our information technology systems, which manage critical functions such as order processing, revenue recognition, financial forecasts, inventory and supply chain management, could result in delayed order fulfillment and thus decreased revenue for that quarter. If expected revenue at the end of any quarter is delayed for any reason, including the failure of anticipated purchase orders to materialize (including delays by our customers or potential customers in consummating such purchase orders), our third-party manufacturers’ inability to manufacture and ship products prior to quarter-end to fulfill purchase orders received near the end of the quarter, our failure to manage inventory to meet demand, our inability to release new products on schedule, any failure of our systems related to order review and processing, or any delays in shipments or achieving specified acceptance criteria, our revenue for that quarter could fall below our, or our investors’ or securities analysts’ expectations, resulting in a decline in the trading price of our common stock. For example, in 2023, we experienced longer sales cycles and customer uncertainty that resulted in delayed orders.

We face intense competition in our market, especially from larger, well-established companies, and we may lack sufficient financial or other resources to maintain or improve our competitive position.

The application networking and security markets are intensely competitive, and we expect competition to increase in the future. To the extent that we sell our solutions in adjacent markets, we expect to face intense competition in those markets as well. We believe that our main competitors fall into the following categories:

•Companies that sell products in the traditional ADC market such as F5 Networks, Inc. (“F5 Networks”) and Citrix Systems, Inc. (“Citrix Systems”);

•Companies that sell open source, software-only, cloud-based ADC services, such as Avi Networks Inc. (“Avi Networks”), NGINX Inc. (“NGiNX”), and HAProxy Technologies, Inc. (“HAProxy”) as well as many startups;

20

•Companies that sell CGN products, which were originally designed for other networking purposes, such as edge routers and security appliances from vendors like Cisco Systems, Inc. (“Cisco Systems”), Juniper Networks, Inc. (“Juniper Networks”) and Fortinet, Inc. (“Fortinet”);

•Companies that sell traditional DDoS protection products, such as Arbor Networks, Inc., a subsidiary of NetScout Systems, Inc. (“Arbor Networks”) and Radware, Ltd. (“Radware”);

•Companies that sell SSL decryption and inspection products, such as Symantec Corporation (through its acquisition of Blue Coat Systems Inc. in 2016) and F5 Networks; and

•Companies that sell certain network security products, including Secure Web Gateways, SSL Insight/SSL Intercept, data center firewalls and Office 365 proxy solutions.

Many of our competitors are substantially larger and have greater financial, technical, research and development, sales and marketing, manufacturing, distribution and other resources and greater name recognition. In addition, some of our larger competitors have broader products offerings and could leverage their customer relationships based on their other products. Potential customers who have purchased products from our competitors in the past may also prefer to continue to purchase from these competitors rather than change to a new supplier regardless of the performance, price or features of the respective products. We could also face competition from new market entrants, which may include our current technology partners. As we continue to expand globally, we may also see new competitors in different geographic regions. Such current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their resources.

Many of our existing and potential competitors enjoy substantial competitive advantages, such as:

•longer operating histories;

•the capacity to leverage their sales efforts and marketing expenditures across a broader portfolio of products and services at a greater range of prices including through selling at zero or negative margins;

•the ability to incorporate functionality into existing products to gain business in a manner that discourages users from purchasing our products, including through product bundling or closed technology platforms;

•broader distribution and established relationships with distribution channel partners in a greater number of worldwide locations;

•access to larger end-customer bases;

•the ability to use their greater financial resources to attract our research and development engineers as well as other employees of ours;

•larger intellectual property portfolios; and

•the ability to bundle competitive offerings with other products and services.

Our ability to compete will depend upon our ability to provide a better solution than our competitors at a competitive price. We may be required to make substantial additional investments in research and development, marketing and sales in order to respond to competition, and there is no assurance that these investments will achieve any returns for us or that we will be able to compete successfully in the future. We also expect increased competition if our market continues to expand. Moreover, conditions in our market could change rapidly and significantly as a result of technological advancements or other factors.

21

In addition, current or potential competitors may be acquired by third parties that have greater resources available. As a result of these acquisitions, our current or potential competitors might take advantage of the greater resources of the larger organization to compete more vigorously or broadly with us. In addition, continued industry consolidation might adversely impact end-customers’ perceptions of the viability of smaller and even medium-sized networking companies and, consequently, end-customers’ willingness to purchase from companies like us.

As a result, increased competition could lead to fewer end-customer orders, price reductions, reduced margins and loss of market share.

Cloud-based computing trends present competitive and execution risks.

We are experiencing an industry-wide trend of customers considering transitioning from purely on-premise network architectures to a computing environment that may utilize a mixture of existing solutions and various new cloud-based solutions. Concurrently with this transition, pricing and delivery models are also evolving. Many companies in our industry, including some of our competitors, are developing and deploying cloud-based solutions for their customers. In addition, the emergence of new cloud infrastructures and artificial intelligence or other tools may enable new companies to compete with our business. These new competitors may include large cloud providers who can provide their own ADC functionality as well as smaller companies targeting applications that are developed exclusively for delivery in the cloud. We are dedicating significant resources to develop and offer our customers new cloud-based solutions and are training our sales teams as necessary to adapt to market trends. Also, some of our largest customers are cloud providers that utilize our existing solutions, and we believe that as cloud infrastructures continue to grow our existing solutions may provide benefits to other cloud providers. While we believe our expertise and dedication of resources to developing new cloud-based solutions, together with the benefits that our existing solutions offer cloud providers, represent advantages that provide us with a strong foundation to compete, it is uncertain whether our efforts to develop new cloud-based and related solutions or our efforts to market and sell our existing solutions to cloud providers will attract the customers or generate the revenue necessary to successfully compete in this new business model. Nor is it clear when or in what manner this new business model will evolve, and this uncertainty may delay purchasing decisions by our customers or prospective customers. Whether we are able to successfully compete depends on our execution in a number of areas, including maintaining the utility, compatibility and performance of our software on the growing assortment of cloud computing platforms and the enhanced interoperability requirements associated with orchestration of cloud computing environments. We will also need to enhance and develop the infrastructure necessary to support the delivery of these services as well as the skills of our personnel who sell, provide and maintain them. Any failure to adapt to these evolving trends may reduce our revenue or operating margins and could have a material adverse effect on our business, results of operations and financial condition.

If we are not able to maintain and enhance our brand and reputation, our business and operating results may be harmed in tangible or intangible ways.

We believe that maintaining and enhancing our brand and reputation are critical to our relationships with and our ability to attract, new end-customers, technology partners and employees. The successful promotion of our brand will depend largely upon our ability to continue to develop, offer and maintain high-quality products and services, our marketing and public relations efforts, and our ability to differentiate our products and services successfully from those of our competitors. Our brand promotion activities may not be successful and may not yield increased revenue. In addition, extension of our brand to products and uses different from our traditional products and services may dilute our brand, particularly if we fail to maintain the quality of products and services in these new areas. We have in the past, and may in the future, become involved in litigation and/or operational difficulties that could negatively affect our brand. If we do not successfully maintain and enhance our brand and reputation, our growth rate may decline, we may have reduced pricing power relative to competitors with stronger brands or reputations, and we could lose end-customers or technology partners, all of which would harm our business, operating results and financial condition.

A limited number of our end-customers, including service providers, make large and concentrated purchases that comprise a significant portion of our revenue. Any loss or delay of expected purchases by our largest end-customers could adversely affect our operating results.

As a result of the nature of our target market and the current stage of our development, a substantial portion of our revenue in any period comes from a limited number of large end-customers, including service providers. During the years ended December 31, 2023, 2022 and 2021, purchases by our ten largest end-customers accounted for approximately 33%, 41% and 39% of our total revenue, respectively. The composition of the group of these ten largest end-customers changes from period to period, but often includes service providers and enterprise customers. During the years ended December 31, 2023,

22

2022 and 2021, service providers accounted for approximately 58%, 66% and 63%, of our total revenue, respectively, and enterprise customers accounted for approximately 42%, 34% and 37% of our total revenue, respectively.

Sales to these large end-customers have typically been characterized by large but irregular purchases with long initial sales cycles. After initial deployment, subsequent purchases of our products typically have a more compressed sales cycle. The timing of these purchases and of the requested delivery of the purchased product is difficult to predict. As a consequence, any acceleration or delay in anticipated product purchases by or requested deliveries to our largest end-customers could materially affect our revenue and operating results in any quarter and cause our revenue and operating results to fluctuate from quarter to quarter.

We cannot provide any assurance that we will be able to sustain or increase our revenue from our largest end-customers nor that we will be able to offset any absence of significant purchases by our largest end-customers in any particular period with purchases by new or existing end-customers in that or a subsequent period. We expect that sales of our products to a limited number of end-customers will continue to contribute materially to our revenue for the foreseeable future. The loss of, or a significant delay or reduction in purchases by, a small number of end-customers could have a material adverse effect on our consolidated financial position, results of operations or cash flows.

Our business could be adversely impacted by changes demanded by our customers in the deployment and payment models for our products.

Our customers have traditionally demanded products deployed in physical, appliance-based on-premise data centers that are paid in full at the time of purchase and include perpetual licenses for our software products. While these products remain central to our business, new deployment and payment models are emerging in our industry that may provide some of our customers with additional technical, business agility and flexibility options. These new models include cloud-based applications provided as SaaS and software subscription licenses where license and service fees are ratable and correlate to the type of service used, the quantity of services consumed or the length of time of the subscription. These models have accounting treatments that may require us to recognize revenue ratably over an extended period of time. If a substantial portion of our customers transition from on-premise-based products to such cloud-based, consumption and subscription-based models, this could adversely affect our operating results and could make it more difficult to compare our operating results during such transition period with our historical operating results.

Some of our large end-customers demand favorable terms and conditions from their vendors and may request price or other concessions from us. As we seek to sell more products to these end-customers, we may agree to terms and conditions that may have an adverse effect on our business.

Some of our large end-customers have significant purchasing power and, accordingly, may request from us and receive more favorable terms and conditions, including lower prices than we typically provide. As we seek to sell products to this class of end-customer, we may agree to these terms and conditions, which may include terms that reduce our gross margin and have an adverse effect on our business.

Our gross margin may fluctuate from period to period based on the mix of products sold, the geographic location of our customers, price discounts offered, required inventory write downs and exchange rate fluctuations.

Our gross margin may fluctuate from period to period in response to a number of factors, such as the mix of our products sold and the geographic locations of our sales. Our products tend to have varying gross margins in different geographic regions. We also may offer pricing discounts from time to time as part of a targeted sales campaign or as a result of pricing pressure from our competitors. In addition, our larger end-customers may negotiate pricing discounts in connection with large orders they place with us. The sale of our products at discounted prices could have a negative impact on our gross margin. We also must manage our inventory of existing products when we introduce new products.

If we are unable to sell the remaining inventory of our older products prior to or following the launch of such new product offerings, we may be forced to write down inventory for such older products, which could also negatively affect our gross margin. Our gross margin may also vary based on international currency exchange rates. In general, our sales are denominated in U.S. Dollars; however, in Japan they are denominated in Japanese Yen. Changes in the exchange rate between the U.S. Dollar and the Japanese Yen has, in the past, and may in the future affect our actual revenue and gross margin. Changes in foreign exchange rates, especially between the U.S. Dollar and the Japanese Yen, could impact the purchasing decisions of our customers.

23

We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks that could adversely affect these international sources of our revenue.

A significant portion of our revenue is generated in international markets, including Japan, Western Europe, Taiwan and South Korea. During the years ended December 31, 2023, 2022, and 2021, approximately 55%, 54% and 60% of our total revenue, respectively, was generated from customers located outside of the United States. If we are unable to maintain or continue to grow our revenue in these markets, our financial results may suffer.

As a result, we must hire and train experienced personnel to staff and manage our foreign operations. To the extent that we experience difficulties in recruiting, training, managing and retaining an international staff, and specifically sales management and sales personnel, we may experience difficulties in sales productivity in foreign markets. We also seek to enter into distributor and reseller relationships with companies in certain international markets where we do not have a local presence. If we are not able to maintain successful distributor relationships internationally or recruit additional companies to enter into distributor relationships, our future success in these international markets could be limited. Business practices in the international markets that we serve may differ from those in the United States and may require us in the future to include terms in customer contracts other than our standard terms. To the extent that we may enter into customer contracts in the future that include non-standard terms, our operating results may be adversely impacted.

We have a significant presence in international markets and plan to continue to expand our international operations, which exposes us to a number of risks that could negatively affect our future business.

We have personnel in numerous countries including in the following countries and regions: the United States, Western Europe, India, the Middle East, Japan, Taiwan, South Korea, Southeast Asia and Latin America. As we maintain our international operations, we are subject to a number of risks, including the following:

•greater difficulty in enforcing contracts and accounts receivable collection and possible longer collection periods;

•increased expenses incurred in establishing and maintaining office space and equipment for our international operations;

•greater difficulty in recruiting local experienced personnel, and the costs and expenses associated with such activities;

•general economic and political conditions in these foreign markets;

•economic uncertainty around the world, including continued economic uncertainty as a result of sovereign debt issues in Europe, the United Kingdom’s exit from the European Union (commonly referred to as “Brexit”), the war between Russia and Ukraine, and tensions between China and Taiwan;

•management communication and integration problems resulting from cultural and geographic dispersion;

•risks associated with trade restrictions and foreign legal requirements, including the importation, certification, and localization of our products required in foreign countries;

•greater risk of unexpected changes in regulatory practices, tariffs, and tax laws and treaties;

•the uncertainty of protection for intellectual property rights in some countries;

•greater risk of a failure of foreign employees to comply with both U.S. and foreign laws, including antitrust regulations, the U.S. Foreign Corrupt Practices Act (“FCPA”), and any trade regulations ensuring fair trade practices; and

24

•heightened risk of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of, or irregularities in, financial statements.

Because of our worldwide operations, we are also subject to risks associated with compliance with applicable anticorruption laws. One such applicable anticorruption law is the FCPA, which generally prohibits U.S. companies and their employees and intermediaries from making payments to foreign officials for the purpose of obtaining or keeping business, securing an advantage, or directing business to another, and requires public companies to maintain accurate books and records and a system of internal accounting controls. Under the FCPA, U.S. companies may be held liable for actions taken by directors, officers, employees, agents, or other strategic or local partners or representatives. As such, if we or our intermediaries, such as channel partners and distributors, fail to comply with the requirements of the FCPA or similar legislation, governmental authorities in the United States and elsewhere could seek to impose civil and/or criminal fines and penalties which could have a material adverse effect on our business, operating results and financial condition.

Our success depends on our key personnel and our ability to hire, retain and motivate qualified product development, sales, marketing and finance personnel.

Our success depends to a significant degree upon the continued contributions of our key management, product development, sales, marketing and finance personnel, many of whom may be difficult to replace. The complexity of our products, their integration into existing networks and ongoing support of our products requires us to retain highly trained technical services, customer support and sales personnel with specific expertise related to our business. Competition for qualified technical services, customer support, engineering and sales personnel in our industry is intense, because of the limited number of people available with the necessary technical skills and understanding of our products. Our ability to recruit and hire these personnel is harmed by tightening labor markets, particularly in the engineering field, in several of our key geographic hiring areas. We may not be successful in attracting, integrating, or retaining qualified personnel to fulfill our current or future needs, nor may we be successful in keeping the qualified personnel we currently have. Our ability to hire and retain these personnel may be adversely affected by volatility or reductions in the price of our common stock, since these employees are generally granted equity-based awards.

Our future performance also depends on the continued services and continuing contributions of certain employees and members of senior management to execute on our business plan and to identify and pursue new opportunities and product innovations. Our senior management team, significant employees with technical expertise, and product and sales managers, among others, are critical to the development of our technology and the future vision and strategic direction of our company. The loss of their services could significantly delay or prevent the achievement of our development and strategic objectives, which could adversely affect our business, financial condition, and operating results.

There can be no assurance that our exploration of strategic alternatives will result in any transaction being consummated, and speculation and uncertainty regarding the outcome of our exploration of strategic alternatives may adversely impact our business.

On July 30, 2019, we announced that our Board of Directors had formed a Strategy Committee tasked and empowered with overseeing and executing specific activities directed to increasing shareholder value. No assurance can be given that a strategic transaction will be consummated in the near term or at all. In addition, speculation and uncertainty regarding our exploration of strategic alternatives may cause or result in:

•disruption of our business;

•distraction of our management and employees;

•difficulty in recruiting, hiring, motivating, and retaining talented and skilled personnel;

•difficulty in maintaining or negotiating and consummating new, business or strategic relationships or transactions;

•increased stock price volatility; and

•increased costs and advisory fees.

25

If we are unable to mitigate these or other potential risks related to the uncertainty caused by our exploration of strategic alternatives, it may disrupt our business or adversely impact our revenue, operating results, and financial condition.

Adverse general economic conditions or reduced information technology spending may adversely impact our business.

A substantial portion of our business depends on the demand for information technology by large enterprises and service providers, the overall economic health of our current and prospective end-customers and the continued growth and evolution of the Internet. The timing of the purchase of our products is often discretionary and may involve a significant commitment of capital and other resources. Volatility in the global economic market or other effects of global or regional economic weakness, including limited availability of credit, a reduction in business confidence and activity, deficit-driven austerity measures that continue to affect governments and educational institutions, and other difficulties may affect one or more of the industries to which we sell our products and services. If economic conditions in the United States, Europe and other key markets for our products continue to be volatile in response to geopolitical developments, macroeconomic trends, or otherwise, and do not improve, or those markets experience a prolonged downturn, many end-customers may delay or reduce their IT spending. From time to time this causes reductions in sales of our products and services, longer sales cycles, slower adoption of new technologies and increased price competition. Any of these events would likely harm our business, operating results and financial condition. In addition, there can be no assurance that IT spending levels will increase following any recovery.

We are dependent on third-party manufacturers, and changes to those relationships, expected or unexpected, may result in delays or disruptions that could harm our business.

We outsource the manufacturing of our hardware components to third-party original design manufacturers who assemble these hardware components to our specifications. Our primary manufacturers are Lanner and AEWIN, each of which is located in Taiwan. Deterioration of relations between Taiwan and China, the resulting actions taken by either country, and other factors affecting the political or economic conditions of Taiwan in the future, could cause disruption to the manufacturing of our hardware components, which could materially adversely affect our business, financial condition and results of operations and the market price and the liquidity of our shares. Our reliance on these third-party manufacturers reduces our control over the manufacturing process and exposes us to risks, including reduced control over quality assurance, product costs, and product supply and timing. Any manufacturing disruption at these manufacturers, including but not limited to disruptions due to tensions with China, could severely impair our ability to fulfill orders. In addition, the ongoing global supply chain issues are expected to continue and may adversely impact our suppliers to a degree that could materially impact us. Our reliance on outsourced manufacturers also may create the potential for infringement or misappropriation of our intellectual property rights or confidential information. If we are unable to manage our relationships with these manufacturers effectively, or if these manufacturers suffer delays or disruptions for any reason, experience increased manufacturing lead-times, experience capacity constraints or quality control problems in their manufacturing operations, or fail to meet our future requirements for timely delivery, our ability to ship products to our end-customers would be severely impaired, and our business and operating results would be seriously harmed.

These manufacturers typically fulfill our supply requirements on the basis of individual orders. We do not have long-term contracts with our manufacturers that guarantee capacity, the continuation of particular pricing terms, or the extension of credit limits. Accordingly, they are not obligated to continue to fulfill our supply requirements, which could result in supply shortages, and the prices we are charged for manufacturing services could be increased on short notice. In addition, our orders may represent a relatively small percentage of the overall orders received by our manufacturers from their customers. As a result, fulfilling our orders may not be considered a priority by one or more of our manufacturers in the event the manufacturer is constrained in its ability to fulfill all of its customer obligations in a timely manner.

Although the services required to manufacture our hardware components may be readily available from a number of established manufacturers, it is time-consuming and costly to qualify and implement such relationships. If we are required to change manufacturers, whether due to an interruption in one of our manufacturers’ businesses, quality control problems or otherwise, or if we are required to engage additional manufacturers, our ability to meet our scheduled product deliveries to our customers could be adversely affected, which could cause the loss of sales to existing or potential customers, delayed revenue or an increase in our costs that could adversely affect our gross margin.

Because some of the key components in our products come from limited sources of supply, we are susceptible to supply shortages or supply changes, which could disrupt or delay our scheduled product deliveries to our end-customers and may result in the loss of sales and end-customers.

26

Our products incorporate key components, including certain integrated circuits that we and our third-party manufacturers purchase on our behalf from a limited number of suppliers, including some sole-source providers. In addition, the lead times associated with these and other components of our products can be lengthy and preclude rapid changes in quantities and delivery schedules. Moreover, long-term supply and maintenance obligations to our end-customers increase the duration for which specific components are required, which may further increase the risk we may incur component shortages or the cost of carrying inventory. If we are unable to obtain a sufficient quantity of these components in a timely manner for any reason, sales and/or shipments of our products could be delayed or halted, which would seriously affect present and future sales and cause damage to end-customer relationships, which would, in turn, adversely affect our business, financial condition and results of operations.

Our component suppliers change their selling prices frequently in response to market trends, including industry-wide increases in demand, and because we do not necessarily have contracts with these suppliers, we are susceptible to price fluctuations related to raw materials and components. If we are unable to pass component price increases along to our end-customers or maintain stable pricing, our gross margin and operating results could be negatively impacted. Furthermore, poor quality in sole-sourced components or certain other components in our products could also result in lost sales or lost sales opportunities. If the quality of such components does not meet our standards or our end-customers’ requirements, if we are unable to obtain components from our existing suppliers on commercially reasonable terms, or if any of our sole source providers cease to continue to manufacture such components or to remain in business, we could be forced to redesign our products and qualify new components from alternate suppliers. The development of alternate sources for those components can

be time-consuming, difficult and costly, and we may not be able to develop alternate or second sources in a timely manner. Even if we are able to locate alternate sources of supply, we could be forced to pay for expedited shipments of such components or our products at dramatically increased costs.

Real or perceived defects, errors, or vulnerabilities in our products or services or the failure of our products or services to block a threat or prevent a security breach could harm our reputation and adversely impact our results of operations.

Because our products and services are complex, they have contained and may contain design or manufacturing defects or errors that are not detected until after their commercial release and deployment by our customers. Even if we discover those weaknesses, we may not be able to correct them promptly, if at all. Defects may cause our products to be vulnerable to security attacks, cause them to fail to help secure networks, or temporarily interrupt end-customers’ networking traffic. Furthermore, our products may fail to detect or prevent malware, viruses, worms or similar threats for any number of reasons, including our failure to enhance and expand our platform to reflect industry trends, new technologies and new operating environments, the complexity of the environment of our end-customers and the sophistication of malware, viruses and other threats. Data thieves and hackers are increasingly sophisticated, often affiliated with organized crime or state-sponsored groups, and may operate large-scale and complex automated attacks. The techniques used to obtain unauthorized access or to sabotage networks change frequently and may not be recognized until launched against a target. Additionally, as a well-known provider of enterprise security solutions, our networks, products, and services could be targeted by attacks specifically designed to disrupt our business and harm our reputation. For example, in January 2023, we identified a cyber-security incident in our corporate IT infrastructure (not related to any of our products or solutions used by customers) (the “Cyber Incident”). Upon detecting the incident, we launched an investigation and engaged the services of cyber-security experts and advisors, incident response professionals and external counsel to support the investigation. While, to date, this incident has not had a material impact on our operations, it did result in additional expense incurred in connection with the investigation. As our products are adopted by an increasing number of enterprises and governments, it is possible that the individuals and organizations behind advanced attacks will focus on finding ways to defeat our products. In addition, defects or errors in our updates to our products could result in a failure of our services to effectively update end-customers’ products and thereby leave our end-customers vulnerable to attacks. Our data centers and networks may experience technical failures and downtime, may fail to distribute appropriate updates, or may fail to meet the increased requirements of a growing installed end-customer base, any of which could temporarily or permanently expose our end-customers’ networks, leaving their networks unprotected against security threats. Our end-customers may also misuse or wrongly configure our products or otherwise fall prey to attacks that our products cannot protect against, which may result in loss or a breach of business data, data being inaccessible due to a “ransomware” attack, or other security incidents. For all of these reasons, we may be unable to anticipate all data security threats or provide a solution in time to protect our end-customers’ networks. If we fail to identify and respond to new and increasingly complex methods of attack and to update our products to detect or prevent such threats in time to protect our end-customers’ critical business data, our business, operating results and reputation could suffer.

If any companies or governments that are publicly known to use our platform are the subject of a cyber-attack that becomes publicized, our other current or potential channel partners or end-customers may look to our competitors for

27

alternatives to our products. Real or perceived security breaches of our end-customers’ networks could cause disruption or damage to their networks or other negative consequences and could result in negative publicity to us, damage to our reputation, declining sales, increased expenses and end-customer relations issues. To the extent potential end-customers or industry analysts believe that the occurrence of any actual or perceived failure of our products to detect or prevent malware, viruses, worms or similar threats is a flaw or indicates that our products do not provide significant value, our reputation and business could be harmed.

Any real or perceived defects, errors, or vulnerabilities in our products, or any failure of our products to detect a threat, could result in:

•a loss of existing or potential end-customers or channels;

•delayed or lost revenue;

•a delay in attaining, or the failure to attain, market acceptance;

•the expenditure of significant financial and product development resources in efforts to analyze, correct, eliminate, or work around errors or defects, to address and eliminate vulnerabilities, to remediate harms potentially caused by those vulnerabilities, or to identify and ramp up production with third-party providers;

•an increase in warranty claims, or an increase in the cost of servicing warranty claims, either of which would adversely affect our gross margins;

•harm to our reputation or brand; and

•litigation, regulatory inquiries, or investigations that may be costly and further harm our reputation.

Although we maintain cybersecurity liability coverage that may cover certain liabilities in connection with a security breach such as the Cyber Incident, we cannot be certain that our insurance coverage will be adequate for liabilities actually incurred, that insurance will continue to be available to use on commercially reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have a material adverse effect on our business, including our financial condition, results of operation and reputation.

Our business is subject to the risks of warranty claims, product returns, product liability, and product defects.

Real or perceived errors, failures or bugs in our products could result in claims by end-customers for losses that they sustain. If end-customers make these types of claims, we may be required, or may choose, for customer relations or other reasons, to expend additional resources in order to help correct the problem. Historically, the amount of warranty claims has not been significant, but there are no assurances that the amount of such claims will not be material in the future. Liability provisions in our standard terms and conditions of sale, and those of our resellers and distributors, may not be enforceable under some circumstances or may not fully or effectively protect us from customer claims and related liabilities and costs, including indemnification obligations under our agreements with resellers, distributors or end-customers. The sale and support of our products also entail the risk of product liability claims. We maintain insurance to protect against certain types of claims associated with the use of our products, but our insurance coverage may not adequately cover any such claims. In addition, even claims that ultimately are unsuccessful could result in expenditures of funds in connection with litigation and divert management’s time and other resources.

Undetected software or hardware errors may harm our business and results of operations.

Our products may contain undetected errors or defects when first introduced or as new versions are released. We have experienced these errors or defects in the past in connection with new products and product upgrades. We expect that these errors or defects will be found from time to time in new or enhanced products after commencement of commercial distribution. These problems have in the past and may in the future cause us to incur significant warranty and repair costs, divert the

28

attention of our engineering personnel from our product development efforts and cause significant customer relations problems. We may also be subject to liability claims for damages related to product errors or defects. While we carry insurance policies covering this type of liability, these policies may not provide sufficient protection should a claim be asserted. A material product liability claim may harm our business and results of operations.

Any errors, defects or vulnerabilities in our products could result in:

•expenditures of significant financial and product development resources in efforts to analyze, correct, eliminate or work around errors and defects or to address and eliminate vulnerabilities;

•loss of existing or potential end-customers or distribution channels;

•delayed or lost revenue;

•delay or failure to attain market acceptance;

•indemnification obligations under our agreements with resellers, distributors and/or end-customers;

•an increase in warranty claims compared with our historical experience or an increased cost of servicing warranty claims, either of which would adversely affect our gross margin; and

•litigation, regulatory inquiries, or investigations that may be costly and harm our reputation.

Our use of open source software and generative artificial intelligence (AI) in our products could negatively affect our ability to sell our products and subject us to possible litigation.

We incorporate open source software such as the Linux operating system kernel into our products. We have implemented a formal open source use policy, including written guidelines for use of open source software and business processes for approval of that use. We have developed and implemented our open source policies according to industry practice; however, best practices in this area are subject to change, because there is little reported case law on the interpretation of material terms of many open source licenses. We are in the process of reviewing our open source use and our compliance with open source licenses and implementing remediation and changes necessary to comply with the open source licenses related thereto. While we do not currently utilize software generated by artificial intelligence tools in our products we may at some point choose to do so, and, if we do, we will likely treat AI generated code as a form of open source software. We cannot guarantee that our use of open source software has been, and will be, managed effectively for our intended business purposes and/or compliant with applicable open source licenses. We may face legal action by third parties seeking to enforce their intellectual property rights related to our use of such open source software. Failure to adequately manage open source license compliance and our use of open source or AI generated software may result in unanticipated obligations regarding our products and services, such as a requirement that we license proprietary portions of our products or services on unfavorable terms, that we make available source code for modifications or derivative works we created based upon, incorporating or using open source software, that we license such modifications or derivative works under the terms of the particular open source license and/or that we redesign the affected products or services, which could result, for example, in a loss of intellectual property rights, or delay in providing our products and services. From time to time, there have been claims against companies that distribute or use third-party open source or other software in their products and services, asserting that the open source or AI generated software or its combination with the products or services infringes third parties’ patents or copyrights, or that the companies’ distribution or use of the open source software does not comply with the terms of the applicable licenses. Use of certain open source or AI generated software can lead to greater risks than use of warranted third-party commercial software, as open source licensors and AI generated software generally do not provide warranties or controls on the origin of such software. From time to time, there have been claims against companies that use open source or AI generated software in their products, challenging the ownership of rights in such open source or AI generated software. As a result, we could also be subject to suits by parties claiming ownership of rights in such software and so challenging our right to use such software in our products. If any such claims were asserted against us, we could be required to incur significant legal expenses defending against such a claim. Further, if our defenses to such a claim were not successful, we could be, for example, subject to significant damages, be required to seek licenses from third parties in order to continue offering our products and services without infringing such third party’s intellectual property rights, be required to re-engineer such products and services, or be required to discontinue making available such products and services if re-engineering cannot be accomplished on a timely or successful basis. The need to

29

engage in these or other remedies could increase our costs or otherwise adversely affect our business, operating results and financial condition.

Our products must interoperate with operating systems, software applications and hardware that are developed by others and if we are unable to devote the necessary resources to ensure that our products interoperate with such software and hardware, we may fail to increase, or we may lose market share and we may experience a weakening demand for our products.

Our products must interoperate with our end-customers’ existing infrastructure, specifically their networks, servers, software and operating systems, which may be manufactured by a wide variety of vendors and original equipment manufacturers. As a result, when problems occur in a network, it may be difficult to identify the source of the problem. The occurrence of software or hardware problems, whether caused by our products or another vendor’s products, may result in the delay or loss of market acceptance of our products. In addition, when new or updated versions of our end-customers’ software operating systems or applications are introduced, we must sometimes develop updated versions of our software so that our products will interoperate properly. We may not accomplish these development efforts quickly, cost-effectively or at all. These development efforts require capital investment and the devotion of engineering resources. If we fail to maintain compatibility with these applications, our end-customers may not be able to adequately utilize our products, and we may, among other consequences, fail to increase, or we may lose market share and experience a weakening in demand for our products, which would adversely affect our business, operating results and financial condition.

We license technology from third parties, and our inability to maintain those licenses could harm our business.

Many of our products include proprietary technologies licensed from third parties. In the future, it may be necessary to renew licenses for third party technology or obtain new licenses for other technology. These third-party licenses may not be available to us on acceptable terms, if at all. As a result, we could also face delays or be unable to make changes to our products until equivalent technology can be identified, licensed or developed and integrated with our products. Such delays or an inability to make changes to our products, if it were to occur, could adversely affect our business, operating results and financial condition. The inability to obtain certain licenses to third-party technology, or litigation regarding the interpretation or enforcement of license agreements and related intellectual property issues, could have a material adverse effect on our business, operating results and financial condition.

Failure to prevent excess inventories or inventory shortages could result in decreased revenue and gross margin and harm our business.

We purchase products from our manufacturers outside of, and in advance of, reseller or end-customer orders, which we hold in inventory and sell. We place orders with our manufacturers based on our forecasts of our end-customers’ requirements and forecasts provided by our distribution channel partners. These forecasts are based on multiple assumptions, each of which might cause our estimates to be inaccurate, affecting our ability to provide products to our customers. There is a risk we may be unable to sell excess products ordered from our manufacturers. Inventory levels in excess of customer demand may result in obsolete inventory and inventory write-downs. The sale of excess inventory at discounted prices could impair our brand image and have an adverse effect on our financial condition and results of operations. Conversely, if we underestimate demand for our products, or if our manufacturers fail to supply products we require at the time we need them, we may experience inventory shortages. Inventory shortages might delay shipments to resellers, distribution channel partners and customers and cause us to lose sales. These shortages may diminish the loyalty of our distribution channel partners or customers.

The difficulty in forecasting demand also makes it difficult to estimate our future financial condition and results of operations from period to period. A failure to accurately predict the level of demand for our products could adversely affect our total revenue and net income, and we are unlikely to forecast such effects with any certainty in advance.

Our sales cycles can be long and unpredictable, primarily due to the complexity of our end-customers’ networks and data centers and the length of their budget cycles. As a result, our sales and revenue are difficult to predict and may vary substantially from period to period, which may cause our operating results to fluctuate significantly.

The timing of our sales is difficult to predict because of the length and unpredictability of our products’ sales cycles. A sales cycle is the period between initial contact with a prospective end-customer and any sale of our products. Our sales cycle, in particular to our large end-customers, may be lengthy due to the complexity of their networks and data centers. Because of this complexity, prospective end-customers generally consider a number of factors over an extended period of time before committing to purchase our products. End-customers often view the purchase of our products as a significant and strategic

30

decision that can have important implications on their existing networks and data centers and, as a result, require considerable time to evaluate, test and qualify our products prior to making a purchase decision and placing an order to ensure that our products will successfully interoperate with our end-customers’ complex network and data centers. Additionally, the budgetary decisions at these entities can be lengthy and require multiple organization reviews. The length of time that end-customers devote to their evaluation of our products and decision-making process varies significantly. The length of our products’ sales cycles typically ranges from three to 12 months but can be longer for our large end-customers. In addition, the length of our close or sales cycle can be affected by the extent to which customized features are requested, in particular in our large deals.

For all of these reasons, it is difficult to predict whether a sale will be completed or the particular fiscal period in which a sale will be completed, both of which contribute to the uncertainty of our future operating results. If our close or sales cycles lengthen, our revenue could be lower than expected, which would have an adverse impact on our operating results and could cause our stock price to decline.

Our ability to sell our products is highly dependent on the quality of our support and services offerings, and our failure to offer high-quality support could have a material adverse effect on our business, revenue and results of operations.

We believe that our ability to provide consistent, high quality customer service and technical support is a key factor in attracting and retaining end-customers of all sizes and is critical to the deployment of our products. When support is purchased our end-customers depend on our support organization to provide a broad range of support services, including on-site technical support, 24-hour support and shipment of replacement parts on an expedited basis. If our support organization or our distribution channel partners do not assist our end-customers in deploying our products effectively, succeed in helping our end-customers resolve post-deployment issues quickly, or provide ongoing support, it could adversely affect our ability to sell our products to existing end-customers and could harm our reputation with potential end-customers. We currently have technical support centers in the United States, Japan, India and the Netherlands. As we continue to expand our operations internationally, our support organization will face additional challenges, including those associated with delivering support, training and documentation in languages other than English.

We typically sell our products with maintenance and support as part of the initial purchase, and a substantial portion of our support revenue comes from renewals of maintenance and support contracts. Our end-customers have no obligation to renew their maintenance and support contracts after the expiration of the initial period. If we are unable to provide high quality support, our end-customers may elect not to renew their maintenance and support contracts or to reduce the product quantity under their maintenance and support contracts, thereby reducing our future revenue from maintenance and support contracts.

Our failure or the failure of our distribution channels to maintain high-quality support and services could have a material and adverse effect on our business, revenue and operating results.

We depend on growth in markets relating to network security, management and analysis, and lack of growth or contraction in one or more of these markets could have a material adverse effect on our results of operations and financial condition.

Demand for our products is linked to, among other things, growth in the size and complexity of network infrastructures and the demand for networking technologies addressing the security, management and analysis of such infrastructures. These markets are dynamic and evolving. Our future financial performance will depend in large part on continued growth in the number of organizations investing in their network infrastructure and the amount they commit to such investments. If this demand declines, our results of operations and financial condition would be materially and adversely affected. Segments of the network infrastructure industry have in the past experienced significant economic downturns. Furthermore, the market for network infrastructure may not continue to grow at historic rates, or at all. The occurrence of any of these factors in the markets relating to network security, management and analysis could materially and adversely affect our results of operations and financial condition.

Because we recognize subscription revenue from our customers over the term of their agreements, downturns or upturns in sales of our subscription-based offerings will not be immediately reflected in our operating results and may adversely affect our revenue in the future.

We recognize subscription revenue over the term of our customer agreements. As a result, most of our subscription revenue arises from agreements entered into during previous periods. A shortfall in orders for our subscription-based solutions in any one period would most likely not significantly reduce our subscription revenue for that period, but could adversely affect

31

the revenue contribution in future periods. In addition, we may be unable to quickly reduce our cost structure in response to a decrease in these orders. Accordingly, the effect of downturns in sales of our subscription-based solutions will not be fully reflected in our operating results until future periods. A subscription revenue model also makes it difficult for us to rapidly increase our revenue through additional subscription sales in any one period, as revenue is generally recognized over a longer period.

Our business and operations have experienced growth in certain prior periods and may experience rapid growth at certain times in the future, and if we do not effectively manage any future growth or are unable to sustain and improve our controls, systems and processes, our operating results will be adversely affected. In certain prior periods, we have significantly increased the number of our employees and independent contractors. As we hire new employees and independent contractors and expand into new locations outside the United States, we are required to comply with varying local laws for each of these new locations. We anticipate that further expansion of our infrastructure and headcount will be required. Our growth has placed, and will continue to place, a significant strain on our administrative and operational infrastructure and financial resources. Our ability to manage our operations and growth across multiple countries will require us to continue to refine our operational, financial and management controls, human resource policies, and reporting systems and processes. We need to continue to improve our internal systems, processes, and controls to effectively manage our operations and growth. We may not be able to successfully implement improvements to these systems, processes and controls in an efficient or timely manner. In addition, our systems and processes may not prevent or detect all errors, omissions or fraud. We may experience difficulties in managing improvements to our systems, processes, and controls or in connection with third-party software, which could impair our ability to provide products or services to our customers in a timely manner, causing us to lose customers, limit us to smaller deployments of our products, increase our technical support costs, or damage our reputation and brand. Furthermore, given our growth and size, our management team may lack oversight on certain side agreements between sales personnel and customers. Our failure to improve our systems and processes, or their failure to operate in the intended manner, may result in our inability to manage the growth of our business and to accurately forecast our revenue, expenses, and earnings, or to prevent certain losses, any of which may harm our business and results of operations. We may not be able to sustain or develop new distributor and reseller relationships, and a reduction or delay in sales to significant distribution channel partners could hurt our business.

We sell our products and services through multiple distribution channels in the United States and internationally. We may not be able to increase our number of distributor or reseller relationships or maintain our existing relationships. Recruiting and retaining qualified distribution channel partners and training them on our technologies requires significant time and resources. These distribution channel partners may also market, sell and support products and services that are competitive with ours and may devote more resources to the marketing, sales and support of such competitive products. Our sales channel structure could subject us to lawsuits, potential liability and reputational harm if, for example, any of our distribution channel partners misrepresent the functionality of our products or services to end-customers or violate laws or our corporate policies. If we are unable to establish or maintain our sales channels or if our distribution channel partners are unable to adapt to our future sales focus and needs, our business and results of operations will be harmed.

Our products must conform to industry standards in order to be accepted by end-customers in our markets.

Generally, our products comprise only a part of a data center. The servers, network, software and other components and systems of a data center must comply with established industry standards in order to interoperate and function efficiently together. We depend on companies that provide other components of the servers and systems in a data center to support prevailing industry standards. Often, these companies are significantly larger and more influential in driving industry standards than we are. Some industry standards may not be widely adopted or implemented uniformly, and competing standards may emerge that may be preferred by our end-customers. If larger companies do not support the same industry standards that we do, or if competing standards emerge, market acceptance of our products could be adversely affected and we may need to incur substantial costs to conform our products to such standards, which could harm our business, operating results and financial condition.

We are dependent on various information technology systems, and failures of or interruptions to those systems could harm our business.

Many of our business processes depend upon our information technology systems, the systems and processes of third parties, and on interfaces with the systems of third parties. If those systems fail or are interrupted, or if our ability to connect to or interact with one or more networks is interrupted, our processes may function at a diminished level or not at all. This could harm our ability to ship or support our products, and our financial results may be harmed.

32

In addition, reconfiguring or upgrading our information technology systems or other business processes in response to changing business needs may be time-consuming and costly and is subject to risks of delay or failed deployment. To the extent this impacts our ability to react timely to specific market or business opportunities, our financial results may be harmed.

Future acquisitions we may undertake may not result in the financial and strategic goals that are contemplated at the time of the transaction.

Future acquisitions we may undertake may not result in the financial and strategic goals that are contemplated at the time of the transaction.

We may make future acquisitions of complementary companies, products or technologies. With respect to any acquisitions we may undertake, we may find that the acquired businesses, products or technologies do not further our business strategy as expected, that we paid more than what the assets are later worth or that economic conditions change, all of which may generate future impairment charges. Acquisitions may be viewed negatively by customers, financial markets or investors. There may be difficulty integrating the operations and personnel of an acquired business, and we may have difficulty retaining the key personnel of an acquired business. We may also have difficulty in integrating acquired technologies or products with our existing product lines. Any integration process may require significant time and resources, and we may not be able to manage the process successfully. Our ongoing business and management’s attention may be disrupted or diverted by transition or integration issues and the complexity of managing geographically and culturally diverse locations. We may have difficulty maintaining uniform standards, controls, procedures and policies across locations. We may experience significant problems or liabilities associated with product quality, technology and other matters.

Our inability to successfully operate and integrate future acquisitions appropriately, effectively and in a timely manner, or to retain key personnel of any acquired business, could have a material adverse effect on our revenue, gross margin and expenses.

We are exposed to the credit risk of our distribution channels and end-customers, which could result in material losses and negatively impact our operating results.

Most of our sales are on an open credit basis, with typical payment terms ranging from 30 to 90 days depending on local customs or conditions that exist in the sale location. If any of the distribution channel partners or end-customers responsible for a significant portion of our revenue becomes insolvent or suffers a deterioration in its financial or business condition and is unable to pay for our products, our results of operations could be harmed. The sales price of our products and subscriptions may decrease, which may reduce our gross profits and adversely impact our financial results. The sales prices for our products and subscriptions may decline for a variety of reasons, including competitive pricing pressures, discounts, a change in our mix of products and subscriptions, anticipation of the introduction of new products or subscriptions, or promotional programs. Competition continues to increase in the market segments in which we participate, and we expect competition to further increase in the future, thereby leading to increased pricing pressures. Larger competitors with more diverse product and service offerings may reduce the price of products or subscriptions that compete with ours or may bundle them with other products and subscriptions. Additionally, although we price our products and subscriptions worldwide in U.S. Dollars (except in Japan), currency fluctuations in certain countries and regions may negatively impact actual prices that channel partners and end-customers are willing to pay in those countries and regions. Furthermore, we anticipate that the sales prices and gross profits for our products will decrease over product life cycles. We cannot guarantee that we will be successful in developing and introducing new offerings with enhanced functionality on a timely basis, or that our product and subscription offerings, if introduced, will enable us to maintain our prices and gross profits at levels that will allow us to achieve and maintain profitability.

Our business is subject to the risks of earthquakes, fire, power outages, floods, and other catastrophic events, and to interruption by man-made problems such as acts of war and terrorism.

A significant natural disaster, such as an earthquake, fire, a flood, or significant power outage could have a material adverse impact on our business, operating results, and financial condition. Our corporate headquarters are located in the San Francisco Bay Area, a region known for seismic activity. In addition, our two primary manufacturers are located in Taiwan, which is near major earthquake fault lines and subject to typhoons during certain times of the year. In the event of a major earthquake or typhoon, or other natural or man-made disaster, our manufacturers in Taiwan may face business interruptions, which may impact quality assurance, product costs, and product supply and timing. In the event our or our service providers’ information technology systems or manufacturing or logistics abilities are hindered by any of the events discussed above, shipments could be delayed, resulting in missed financial targets, such as revenue and shipment targets, and our operations could be disrupted, for the affected quarter or quarters. In addition, large-scale cybersecurity attacks, acts of war or terrorism,

33

global pandemics such as the COVID-19 pandemic or other geo-political unrest could cause disruptions in our business or the business of our supply chain, manufacturers, logistics providers, channels, or end-customers or the economy as a whole. Any disruption in the business of our supply chain, manufacturers, logistics providers, channels or end-customers that impacts sales at the end of a quarter could have a significant adverse impact on our quarterly results. All of the aforementioned risks may be further increased if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above should result in delays or cancellations of customer orders, or the delay in the manufacture, deployment or shipment of our products, our business, financial condition and operating results would be adversely affected.

Risks Related to Intellectual Property, Litigation, Laws and Regulations

We have been, may presently be, or in the future may be, a party to litigation and claims regarding intellectual property rights, resolution of which has been and may in the future be time-consuming, expensive and adverse to us, as well as require a significant amount of resources to prosecute, defend, or make our products non-infringing.

Our industry is characterized by the existence of a large number of patents and by increasingly frequent claims and related litigation based on allegations of infringement or other violations of patent and other intellectual property rights. In the ordinary course of our business, we have been and may presently be in disputes and licensing discussions with others regarding their patents and other claimed intellectual property and proprietary rights. Intellectual property infringement and misappropriation lawsuits and other claims are subject to inherent uncertainties due to the complexity of the technical and legal issues involved, and we cannot be certain that we will be successful in defending ourselves against such claims or in concluding licenses on reasonable terms or at all.

We may have fewer issued patents than some of our major competitors, and therefore may not be able to utilize our patent portfolio effectively to assert defenses or counterclaims in response to patent infringement claims or litigation brought against us by third parties. Further, litigation may involve patent holding companies or other adverse patent owners that have no relevant products revenue and against which our potential patents may provide little or no deterrence. In addition, many potential litigants have the capability to dedicate substantially greater resources than we can to enforce their intellectual property rights and to defend claims that may be brought against them. We expect that infringement claims may increase as the number of product types and the number of competitors in our market increases. Also, to the extent we gain greater visibility, market exposure and competitive success, we face a higher risk of being the subject of intellectual property infringement claims.

If we are found in the future to infringe the proprietary rights of others, or if we otherwise settle such claims, we could be compelled to pay damages or royalties and either obtain a license to those intellectual property rights or alter our products such that they no longer infringe. Any license could be very expensive to obtain or may not be available at all. Similarly, changing our products or processes to avoid infringing the rights of others may be costly, time-consuming or impractical. Alternatively, we could also become subject to an injunction or other court order that could prevent us from offering our products. Any of these claims, regardless of their merit, may be time-consuming, result in costly litigation and diversion of technical and management personnel, or require us to cease using infringing technology, develop non-infringing technology or enter into royalty or licensing agreements.

Many of our commercial agreements require us to indemnify our end-customers, distributors and resellers for certain third-party intellectual property infringement actions related to our technology, which may require us to defend or otherwise become involved in such infringement claims, and we could incur liabilities in excess of the amounts we have received for the relevant products and/or services from our end-customers, distributors or resellers. These types of claims could harm our relationships with our end-customers, distributors and resellers, may deter future end-customers from purchasing our products or could expose us to litigation for these claims. Even if we are not a party to any litigation between an end-customer, distributor or reseller, on the one hand, and a third party, on the other hand, an adverse outcome in any such litigation could make it more difficult for us to defend our intellectual property rights in any subsequent litigation in which we are a named party.

We may not be able to adequately protect our intellectual property, and if we are unable to do so, our competitive position could be harmed, or we could be required to incur significant expenses to enforce our rights.

We rely on a combination of patent, copyright, trademark and trade secret laws, and contractual restrictions on disclosure of confidential and proprietary information, to protect our intellectual property. Despite the efforts we take to protect our intellectual property and other proprietary rights, these efforts may not be sufficient or effective at preventing their

34

Source: SEC EDGAR (public domain) · 10-K for the period ended 2023-12-31, filed 2024-02-29 · accession 0001580808-24-000049

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.