Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

FTNT US Equity

Fortinet, Inc.Information Technology · Computer Peripheral Equipment, NEC · CIK 1262039 · FY ends Dec 31
$153.51
+2.72 (+1.80%)
USD · as of 2026-08-21 · marketstack

FTNT · 10-K · period ended 2022-12-31

← all FTNT documents
filed 2023-02-24 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1517 of 1,853444k characters rendered

ftnt-20221231

Table of Contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

FORM 10-K

(Mark One)

For the year ended December 31, 2022

or

For the transition period from to

Commission file number: 001-34511

______________________________________

FORTINET, INC.

(Exact name of registrant as specified in its charter)

______________________________________

899 Kifer Road

Sunnyvale, California94086

(Address of principal executive offices, including zip code)

(408) 235-7700

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each class Trading Symbol Name of each exchange on which registered

Common Stock, $0.001 Par Value FTNT The Nasdaq Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Table of Contents

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 (“Exchange Act”) during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Exchange Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b).☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of voting stock held by non-affiliates of the registrant, as of June 30, 2022, the last business day of the registrant’s most recently completed second quarter, was $25,621,924,666 (based on the closing price for shares of the registrant’s common stock as reported by The Nasdaq Global Select Market on that date). Shares of common stock held by each executive officer, director, and holder of 5% or more of the registrant’s outstanding common stock have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.

As of February 17, 2023, there were 784,066,289 shares of the registrant’s common stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the registrant’s definitive Proxy Statement relating to its 2023 Annual Meeting of Stockholders (“Proxy Statement”) are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated. Such Proxy Statement will be filed with the United States Securities and Exchange Commission within 120 days after the end of the fiscal year to which this report relates.

FORTINET, INC.

ANNUAL REPORT ON FORM 10-K

For the Year Ended December 31, 2022

Table of Contents

Page

Risk Factor Summary 1

Part I

Item 1. Business 3

Item 1A. Risk Factors 13

Item 1B. Unresolved Staff Comments 48

Item 2. Properties 48

Item 3. Legal Proceedings 48

Item 4. Mine Safety Disclosures 48

Part II

Item 6. [Reserved] 50

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 71

Item 8. Financial Statements and Supplementary Data 73

Item 9A. Controls and Procedures 112

Item 9B. Other Information 114

Part III

Item 10. Directors, Executive Officers and Corporate Governance 114

Item 11. Executive Compensation 114

Item 14. Principal Accounting Fees and Services 114

Part IV

Item 15. Exhibits and Financial Statement Schedules 115

Exhibit Index 116

Table of Contents

Summary of Risk Factors

Our business is subject to numerous risks and uncertainties, including those described in Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K. You should carefully consider these risks and uncertainties when investing in our common stock. Some of the principal risks and uncertainties include:

•Our operating results are likely to vary significantly and be unpredictable.

•Adverse economic conditions, such as a possible economic downturn or recession, and possible impacts of inflation or stagflation, rising interest rates or reduced information technology spending may adversely impact our business.

•We are susceptible to supply chain constraints, supply shortages and disruptions, long lead times for components and finished goods and supply changes because some of the key components in our products come from limited sources of supply.

•The effects of the COVID-19 pandemic, including its ongoing variants, will likely continue to adversely affect our business, for example, through product and component shortages, longer product lead times, changes in customer buying-behavior, including delays in service contract registrations, accelerating or delaying purchases, changes in the mix of backlog and the related margins.

•Our billings, revenue, and free cash flow growth may slow or may not continue, and our operating margins may decline.

•We are dependent on the continued services and performance of our senior management, as well as our ability to hire, retain and motivate qualified personnel, particularly for our sales organization.

•We rely on third-party channel partners for substantially all of our revenue and a small number of distributors represents a large percentage of our revenue and accounts receivable.

•Reliance on a concentration of shipments at the end of the quarter could cause our billings and revenue to fall below expected levels or delay collections and the related addition to free cash flow.

•We rely significantly on revenue from FortiGuard security subscription and FortiCare technical support services, and revenue from these services may decline or fluctuate.

•We have incurred indebtedness and may incur other debt in the future, which may adversely affect our financial condition and future financial results.

•We generate a majority of revenue and cash flow from sales outside of the United States.

•We may not be successful in executing our strategy to increase our sales to large- and medium-sized end-customers.

•A portion of our revenue is generated by sales to government organizations and customers, which are subject to a number of regulatory requirements, challenges and risks.

•The war in Ukraine, its related macroeconomic effects and our decision to reduce operations in Russia have affected and may continue to affect our business.

•We face intense competition in our market and we may not maintain or improve our competitive position.

•Insufficient inventory or components, including finished goods, chips and other components, and including component or inventory shortages related to the COVID-19 pandemic, manufacturer’s capacity, shipping challenges, delays in timing of receipts of inventory, or other factors affecting the global supply chain, may result in lost sales opportunities or delayed billings and revenue and increased costs, and may harm our gross margins and our product price increases designed to help mitigate lower gross margins may not be acceptable to customers.

•We depend on third-party manufacturers to provide various components for our products and build our products and are susceptible to manufacturing delays, capacity constraints and cost increases.

1

Table of Contents

•We are susceptible to defects or vulnerabilities in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities in our products or services or the failure of our products or services to detect or prevent a security breach could harm our operational results and reputation more significantly as compared to certain other companies given we are a security company.

•Our inability to successfully acquire and integrate other businesses, products or technologies, or to successfully invest in and form successful strategic alliances with other businesses, could seriously harm our competitive position and could negatively affect our financial condition and results of operations. In addition, any potential future impairment of the value of our investment in Linksys Holdings, Inc. (“Linksys”) could negatively affect our financial condition and results of operations.

•Investors’ and regulators’ expectations of our performance relating to environmental, social and governance factors may impose additional costs and expose us to new risks.

•We are exposed to fluctuations in currency exchange rates, which could negatively affect our financial condition and results of operations.

•Our proprietary rights may be difficult to enforce and we may be subject to claims by others that we infringe their proprietary technology.

•The trading price of our common stock may be volatile, which volatility may be exacerbated by share repurchases under our Share Repurchase Program (the “Repurchase Program”).

•Anti-takeover provisions contained in our certificate of incorporation and bylaws, as well as provisions of Delaware law, could impair a takeover attempt.

•Global economic uncertainty and weakening product demand caused by political instability, changes in trade agreements, wars and foreign conflicts, such as the war in Ukraine or tensions between China and Taiwan, could adversely affect our business and financial performance.

2

Table of Contents

Part I

ITEM 1. Business

Overview

Fortinet is a global leader in cybersecurity and networking solutions for organizations, including enterprises, communication service providers, security service providers, government organizations and small businesses.

The focus areas of our business consist of:

•Secure Networking—Our Secure Networking solutions enable the convergence of networking and security across all edges to provide next-generation firewall (“NGFW”), software-defined wide area network (“SD-WAN”), LAN Edge (Wi-Fi and switch) and secure access service edge (“SASE”). Traditional networking lacks awareness of content, applications, users, devices, location and more. A secure networking approach converges networking and security into a single, accelerated solution. A specially designed operating system and security processors work in concert to improve network performance and security posture while decreasing footprint and power consumption. We derive a majority of product sales from our Core Platform (previously referred to as FortiGate) network security appliances. Core Platform network security appliances include a broad set of built-in security and networking features and functionalities, including firewall, next-generation firewall, secure web gateway, secure sockets layer (“SSL”) inspection, SD-WAN, intrusion prevention system (“IPS”), sandboxing, data leak prevention, virtual private network (“VPN”), switch and wireless controller and wide area network (“WAN”) edge. Our network security appliances are managed by our FortiOS network operating system, which provides the foundation for Core Platform security functions. We enhance the performance of our network security appliances from branch to data center by designing and implementing Application-Specific Integrated Circuits (“ASIC”) technology within our appliances, enabling us to add security and network functionality with minimal impact to network throughput performance. Along with our secure Wi-Fi access points and switches, Fortinet helps organizations secure their networks across campuses, branches and work from anywhere (“WFA”) deployments. For the Japanese market, we also offer high performance network switches marketed under Alaxala Networks Corporation for data center switching.

FortiOS supports many more secure networking markets and applications than just firewall. These include:

•Network Firewall (“NFW”)

•Software-Defined Wide Area Network (“SD-WAN”)

•Secure LAN/WLAN (Wi-Fi and Switch) (SD-Branch/Campus)

•Secure Access Service Edge (“SASE”)

•Universal Zero Trust Network Access (“ZTNA”)

•Encryption Applications (SSL Inspection, Virtual Private Network (“VPN”), and IPsec Connectivity)

Further each security application has number of customer use cases. For example, Network Firewall has the following use cases:

•Data Center Perimeter NGFW

•North–South Internal Segmentation Firewall

•Distributed Network Edge Firewall

•East–West Micro Segmentation Firewall

•Virtual Firewall (“VM”)

•Cloud Native Firewall (“CNF”)

•Firewall as a Service (“FWaaS”)

•Containerized Firewall

•Endpoint Firewall

•SMB Firewall

•Home Firewall

•Zero Trust Access—Our Zero Trust Access solutions enable customers to know and control who and what is on their network, in addition to providing security for WFA. Zero Trust Access solutions include FortiNAC,

3

Table of Contents

FortiAuthenticator, FortiClient/EDR and FortiToken. Our network access control solutions provide visibility, control and automated event responses in order to secure internet of things (“IoT”) and OT devices.

•Cloud Security—We help customers connect securely to and across their individual, hybrid-cloud, multi-cloud and virtualized data center environments by offering security through our virtual firewall and other software products and through integrated capabilities with major cloud platforms. Our public and private cloud security solutions, including virtual appliances and hosted solutions, extend the core capabilities of Fortinet’s cybersecurity mesh architecture (“Fortinet Security Fabric”) in and across cloud environments, delivering security that follows their applications and data. Our solutions include network security, web application firewall and application programming interface (“API”) protection, cloud-native security and workload protection. Our Secure SD-WAN for multi-cloud solution automates deployment of an overlay network across different cloud networks and offers visibility, control and centralized management that integrates functionality across multiple cloud environments. Our cloud security portfolio also includes securing applications in all environments in which they can be deployed, including physical and virtual data centers, cloud and edge compute instances. Fortinet cloud security offerings are available for deployment in major public and private cloud environments, including Amazon Web Services, Google Cloud, IBM Cloud, Microsoft Azure, Oracle Cloud and VMWare Cloud. We also offer managed web application firewall (“WAF”) rules delivered by FortiGuard Labs as an overlay service to native security offerings offered by Amazon Web Services.

•AI-Driven Security Operations—We develop and provide a range of products and services that enable the security operations center (“SOC”) teams to identify, investigate and remediate potential incidents in which cybercriminals bypass prevention-oriented controls. Given the breadth of the attack surface to monitor, as well as the volume and sophistication of cyber threats, artificial intelligence (“AI”) is a key part of these offerings, which include: FortiGuard and other security subscription services, endpoint security with endpoint detection and response (“EDR”), a range of breach-protection technologies plus our security information and event management (“SIEM”) and security orchestration, automation and response (“SOAR”), all of which can be applied across the Fortinet Security Fabric. These solutions automatically deliver security intelligence and insights that help organizations to protect against and respond to threats through integration with Fortinet and third-party solutions.

•FortiGuard Security Services—FortiGuard security services counter threats in real time with AI-powered, coordinated protection. All of our security services are natively integrated into the Fortinet Security Fabric. This enables fast detection and enforcement across the entire attack surface. Risk is continually assessed and the Security Fabric automatically adjusts to counter the latest known and unknown threats in real time. It is able to close security gaps with context-aware, consistent security policies for users and applications in hybrid deployments across the network, endpoints and clouds.

•Support and Professional Services—FortiCare Technical Support Service is a per-device support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet capabilities. Global technical support is offered 24x7 with flexible add-ons, including enhanced service level agreements (“SLAs”) and premium hardware replacement through in-country depots. Organizations have the flexibility to procure different levels of service for different devices based on their availability needs. We offer three per-device support options tailored to the needs of our enterprise customers: FortiCare Premium, FortiCare Elite and FortiCare Essential. The newly launched FortiCare Elite service provides 15-minute response times for key product families.

During our year ended December 31, 2022, we generated total revenue of $4.42 billion and net income of $857.3 million. See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, 2022 and 2021 and our consolidated statements of income, comprehensive income, equity (deficit), and cash flows for each of the three years ended December 31, 2022, 2021 and 2020.

We were incorporated in Delaware in November 2000. Our principal executive office is located at 899 Kifer Road, Sunnyvale, California 94086 and our telephone number at that location is (408) 235-7700.

Consolidation of Technology and Architecture

Cybersecurity has traditionally been deployed one solution at a time and not designed to work well with other deployed solutions while also increasing management complexity. A Fortinet Security Fabric approach consolidates point products into a platform, allowing for much tighter integration, increased automation and a more rapid, coordinated and effective response to threats across the network. The Fortinet Security Fabric has an open architecture designed to integrate Fortinet solutions and third-party solutions.

4

Table of Contents

Our product offerings consist of our Core Platform network security products and our Enhanced Platform Technology (previously referred to as Platform Extension) products, which are offered in a broad range of form factors spanning physical appliances, virtual appliances, software and cloud-hosted services. This enables us to protect customers across all edges and deployment scenarios including users, devices, networks, cloud and virtual data center. Our cloud- and hosted- products and services include sandboxing, EDR, email security, web application and API security, cloud networking security and cloud-native protection as well as Fortinet Security Fabric management and analytics. Additionally, we offer cloud-delivered and hosted-security services. Our FortiGuard security services are enabled by FortiGuard Labs, which provides threat research and artificial intelligence capabilities from a cloud network to deliver protection through Core Platform appliance and virtual machine as well as Fortinet Security Fabric products that are registered by the end-customer. All these are combined to form the Fortinet Security Fabric, which is an approach to security that consolidates discrete security solutions together into an integrated offering. This integrated approach to security extends across both Fortinet-developed solutions and a broad ecosystem of technology partner solutions and technologies.

ASIC

Our proprietary FortiASIC technology family consists of three processors. First, a Network Processor Generation 7, FortiNP 7 (“NP 7”), which accelerates the processing of firewall traffic and offloads this function from the central processing unit (“CPU”). Second, a Content Processor Generation 9, FortiCP (“CP 9”), helps the CPU with deep packets inspection functions, such as intrusion prevention and antivirus. Multiple NP7s and CP 9s can be placed in larger firewalls to provide more scale. Third, the central CPU, network processing and content processing functions are all brought together in a single ASIC called the Security Processor Generation 5. These Fortinet Proprietary ASICs, along with off-the-shelf CPU/ASICs, allow our systems to scale from the smallest branch to a hyperscale cloud and run multiple applications at high performance.

The use of ASICs allows our appliances to consolidate security functionality and converge security with a minimal impact to network throughput performance, which we believe delivers a lower total cost of ownership (“TCO”) to our customers. As the security needs and technologies of our end-customers increase, we believe our TCO-driven ASIC approach give our products a competitive advantage against other architectural approaches.

FortiOS

FortiOS, its associated security and networking functions and products that run or are integrated with FortiOS are combined to form the Fortinet Security Fabric. This approach to security ties discrete security solutions together into an integrated offering.

Our proprietary FortiOS operating system provides the foundation for the operation of Core Platform network security appliances, whether physical, virtual, private- or public-cloud based. We make regular enhancements and other updates to FortiOS available through our FortiCare support services.

The convergence of security and networking capabilities provided by the Fortinet Security Fabric are powered and controlled through FortiOS. FortiOS provides (i) multiple layers of security, including a hardened kernel layer providing protection for the Core Platform system, (ii) a network security layer, providing security for end-customers’ network infrastructures and (iii) application content protection, providing security for end-customers’ workstations and applications. FortiOS directs the operations of processors and ASICs and provides system management functions such as command line, graphical user interfaces, multiple network and security topology views.

FortiOS also enables advanced, integrated routing and switching, allowing end-customers to deploy Core Platform devices within a wide variety of networks, as well as providing a direct replacement solution option for legacy switching and routing equipment. FortiOS implements a suite of commonly used standards-based routing protocols as well as network address translation technologies, allowing the Core Platform appliance to integrate and operate in a wide variety of network environments. Additional features include virtual domain capabilities, which can provide support for multiple customers on a single device or FortiOS instance in support of service provider and managed security service provider (“MSSP”) deployments. FortiOS also provides traffic-logging capabilities for forensic analysis purposes. FortiOS is designed to help control network traffic in order to optimize performance by including functionality such as packet classification, queue disciplines, policy enforcement, congestion management, WAN optimization and caching.

Products

Our core product offerings consist of our Core Platform firewall product family and our Enhanced Platform Technology products, which may be purchased to integrate and expand security architectures. Our Enhanced Platform Technology products include the Fortinet Security Fabric, email security, cloud security, endpoint protection and other products. Our Core Platform hardware and software licenses are sold with a set of Core Platform broad security services. These

5

Table of Contents

security services are enabled by FortiGuard Labs, which provides threat research and artificial intelligence capabilities from a global cloud network to deliver protection services.

Core Platform

Core Platform converges a broad set of security and networking functions, including firewall, intrusion prevention, anti-malware, VPN, application control, web filtering, anti-spam and WAN acceleration. Core Platform is available as a hardware appliance or as a virtual appliance. All Core Platform appliances run on FortiOS. Core Platform platforms can be centrally managed through both embedded web-based and command line interfaces, as well as through FortiManager, which provides a central management architecture for Core Platform appliances and the Fortinet Security Fabric.

With over 35 models in the Core Platform product line, Core Platform is designed to address security requirements for small- to medium-sized businesses, large enterprises and government organizations worldwide.

Most Core Platform hardware appliances include one of our ASICs to accelerate content and network security features implemented within FortiOS. The significant differences between each model are the performance and scalability targets each model is designed to meet, while the security features and associated services offered are common throughout all models. The FortiGate-20 through -90 series models are designed for perimeter protection for small- to medium-sized businesses and enterprises with distributed offices. The FortiGate-100 through -900 series models are designed for perimeter deployment in medium-sized to large enterprise networks. The FortiGate-1000 through -7000 series models deliver high performance and scalable network security functionality for perimeter, data center and hyper-scale data centers, and core deployment in large enterprises. In addition to networking security features, all FortiGate models and form factors also deliver secure SD-WAN capabilities.Fortinet also offers FortiGate Rugged models for OT applications where ruggedized appliances are needed.

We also incorporate additional technologies within Core Platform appliances that differentiate our solutions, including data leak protection, traffic optimization, SSL inspection, threat vulnerability management and wireless controller technology. In addition to these built-in features, we offer a full range of wireless access points and controllers, complementing Core Platform appliances with the flexibility of wireless local area network access.

Fortinet Security Fabric and Enhanced Platform Technology Products

As part of the Fortinet Security Fabric, we offer products that provide network security, endpoint security, cloud security, web-based application security, identity and access management, sandbox protection and email security. The integration of devices using open standards, common operating systems, and unified management platforms enables the sharing and correlation of real-time threat intelligence. The following Fortinet products can operate as part of the Fortinet Security Fabric:

•FortiAnalyzer—Our FortiAnalyzer family of products provides centralized network logging, analyzing and reporting solutions that securely aggregate content and log data from our Core Platform devices, other Fortinet products and third-party devices.

•FortiAP—Our FortiAP product family provides secure wireless networking solutions. FortiAPs allow a variety of management options, including from the cloud and directly from our Core Platform firewall product. FortiAPs create a scalable and secure access layer for connecting wireless devices such as computers, laptops, cell phones and tablets, as well as IoT devices.

•FortiClient—Our FortiClient provides advanced endpoint protection with pattern-based anti-malware, behavior-based exploit protection, web-filtering and an application firewall. FortiClient integrates with FortiSandbox to detect zero-day threats and custom malware. FortiClient also provides secure remote access with built-in VPN, single-sign-on and two-factor authentication for added security.

•FortiEDR/XDR—Our FortiEDR/XDR is an endpoint protection solution that provides both machine-learning anti-malware protection and remediation. FortiEDR/XDR supports broad OS coverage workstations, servers, and virtual machines, including legacy operating and embedded systems.

•FortiGate VM— FortiGate VM is our network firewall virtual appliance that extends the Fortinet Security Fabric through the cloud on-ramp into the cloud, enabling customers to achieve converged security and networking capabilities networking within the cloud and between clouds and hybrid clouds. FortiGate VM is powered by the same FortiOS that runs FortiGate appliances to deliver consistent security across data centers

6

Table of Contents

and the cloud. FortiGate VM is also powered by Fortinet virtualized Application-Specific Integrated Circuits (“vASICs”) to deliver accelerated security and performance with minimal impact to performance. Our cloud networking solution enables better, more secure application experiences for users and branch offices by providing for encrypted data transports, granular segmentation and application-layer protection against advanced threats, and seamless overlay network with uniform policies across multi-clouds. FortiGate VM is available for all major cloud providers, hypervisors and software-defined network (“SDN”) platforms.

•FortiMail—Our FortiMail product family provides secure email gateway solutions. FortiMail utilizes the technologies and security services from FortiGuard Labs to deliver protection against threats that use email as an attack vector. FortiMail also integrates data protection capabilities to avoid data loss.

•FortiManager—Our FortiManager family of products provides a central and scalable management solution for our Core Platform products, including software updates, configuration, policy settings and security updates. FortiManager facilitates the coordination of policy-based provisioning, device configuration and operating system revision management, as well as network security monitoring and device control.

•FortiSandbox—Our FortiSandbox technology delivers proactive detection and mitigation with the ability to generate a directly actionable protection capability. Available in both hardware and cloud-based form, the FortiSandbox subjects suspicious code to a set of multi-layer protection techniques, culminating in execution within an operating system, allowing real-time behavioral analysis to be performed in a secure environment. When malicious code is identified, a signature can be generated locally for distribution across the Fortinet Security Fabric.

•FortiSwitch—Our FortiSwitch product family provides secure switching solutions that can be deployed in traditional network switching designs with Layer 2 or Layer 3 access control features. FortiSwitch creates a scalable and secure access layer for customers to connect their end devices, such as computers and laptops, as well as to expand the field of IoT devices.

•FortiToken—Our FortiToken allows organizations to implement two-factor authentication to better safeguard systems, assets and data. With two-factor authentication, a password is used along with a security token and authentication server to provide seamless yet highly secured access between users and applications. Authorized employees can access company resources safely using a variety of devices, ranging from laptops to mobile phones.

•FortiWeb—Our FortiWeb product family provides web application firewall solutions, including internet protocol (“IP”) reputation and anti-botnet security, distributed denial-of-service protection, protocol validation, application attack signatures and deep learning AI to protect applications against a wide range of threats.

The products listed above are available in multiple form factors, such as hardware, virtual machine, cloud or software-as-a-service (“SaaS”), except for FortiSwitch, FortiAP and FortiExtender, which are available as hardware appliances only and FortiGate VM and FortiEDR/XDR which are available as virtual solutions only.

Services

FortiGuard Security Subscription Services

Security requirements are dynamic due to the constantly changing nature of threats. Our FortiGuard security subscription services are designed to deliver threat detection and prevention capabilities to end-customers worldwide as threats evolve. Our FortiGuard Labs global threat research team identifies emerging threats, collects threat samples, and replicates, reviews, characterizes and collates attack data through the use of AI, automation and original research. Based on this research, we develop updates for virus signatures, attack definitions, scanning engines and other security solution components to distribute to end-customers. FortiGuard functionality varies depending on the Core Platform and Enhanced Platform Technology products, and will typically include one or more of the following functions: application control, antivirus, intrusion prevention, web filtering, anti-spam, VPN functions, email image analysis, vulnerability management, database functions, web functions, advanced threat protection, sandboxing and domain and IP reputation services.

End-customers purchase FortiGuard security subscription services in advance, typically with terms of one to five years. We provide FortiGuard security subscription services 24 hours a day, seven days a week.

7

Table of Contents

FortiCare Technical Support Services

Our FortiCare support services portfolio includes technical support, FortiOS updates and extended product warranty. For our standard technical support, our channel partners may provide first-level support to the end-customer. We also provide first-level support to our end-customers, as well as second- and third-level support as appropriate. We also provide knowledge management tools and customer self-help portals to help augment our support capabilities in an efficient and scalable manner. We deliver technical support to partners and end-customers 24 hours a day, seven days a week, through regional technical support centers. In addition to our technical support services, we offer a range of advanced services, including premium support, professional services and expedited warranty replacement.

Service Bundles

We also sell FortiGuard and FortiCare services as bundles, consolidating security services into packages that are appropriate for different use cases or end-customers.

•Advanced Threat Protection—Our Advanced Threat Protection bundle includes antivirus, data sanitation sandbox, intrusion prevention, virus outbreak protection, mobile security, application control, IP reputation and anti-botnet security, along with FortiCare support services.

•Unified Threat Protection—Our Unified Threat Protection bundle includes the Advanced Threat Protection security services noted above, as well as intrusion prevention, virus outbreak protection, web filtering and FortiCare support services.

•Enterprise Protection—Our Enterprise Protection bundle includes the Unified Threat Protection services noted above, as well as industrial control systems, security rating, along with enhanced FortiCare support services.

•Small Medium Business—Our Small Medium Business bundle includes the Unified Threat Protection services noted above, as well as FortiGate Cloud which provides cloud-based management, reporting, and analytics for Core Platforms along with enhanced FortiCare support services.

Professional Services

We offer professional services to end-customers including technical account managers (“TAMs”), resident engineers (“REs”) and professional service consultants, security architects for implementations and remote, cloud-based incident response (“IR”).

TAMs and REs are dedicated support engineers available to help identify and eliminate issues before problems arise. Each TAM and RE acts as a single point of contact and customer advocate within Fortinet, offering a deep understanding of our customers’ businesses and security requirements.

Our professional services consultants and security architects help to formulate customer-specific security strategies, develop roadmaps for securing digital initiatives and design product deployments. They work closely with end-customers to implement our products according to design, utilizing network analysis tools, traffic simulation software and scripts.

Fortinet also offers remote, cloud-based IR and monitoring services to help customers identify, remediate and understand compromises. This service leverages our FortiEDR capabilities either as part of a premium FortiEDR subscription for continuous monitoring or alternatively, can be deployed to help deliver IR services on a per incident basis.

Training Services

We offer training services to our end-customers and channel partners through our training team and authorized training partners. We have also implemented a training certification program, Network Security Expert, to help ensure an understanding of our products and services. Since 2020, Fortinet also offers a number of free online training courses to help address prevalent industry-wide cybersecurity skills gaps and shortages.

8

Table of Contents

Customers

We typically sell our security solutions to distributors that sell to networking security focused resellers and to service providers and MSSPs, who, in turn, sell products and/or services to end-customers. At times, we also sell directly to large service providers and major systems integrators who may sell to our end-customers or use our products and services to provide hosted solutions to other enterprises. Our end-customers are located in over 100 countries and include small, medium and large enterprises and government organizations across a wide range of industries, including education, financial services, government, healthcare, manufacturing, retail, technology and telecommunications. An end-customer deployment may involve as few as one or as many as thousands of appliances as well as other Fortinet Security Fabric products. Customers may also access our products via the cloud through certain cloud providers such as Amazon Web Services, Google Cloud, IBM Cloud, Microsoft Azure and Oracle Cloud. Often, our customers also purchase our FortiGuard security subscription services and FortiCare technical support services. Refer to Note 16. Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers that accounted for 10% or more of our revenue or net accounts receivable.

Sales and Marketing

We primarily sell our products and services through a two-tier distribution model. We sell to distributors that sell to resellers and to service providers and MSSPs, who, in turn, sell products and/or services to end-customers. In certain cases, we sell directly to large service providers and major systems integrators. We work with many technology distributors, including Arrow Electronics, Inc., Exclusive, Ingram Micro and TD Synnex (formerly Tech Data Corporation and Synnex Corporation, separately).

We support our channel partners with a dedicated team of experienced channel account managers, sales professionals and sales engineers who provide business planning, joint marketing strategy, pre-sales and operational sales support. Additionally, our sales teams help drive and support large enterprise and service provider sales through a direct touch model. Our sales professionals and engineers typically work closely with our channel partners and directly engage with large end-customers to address their unique security and deployment requirements. To support our broadly dispersed global channel and end-customer base, we have sales professionals in over 90 countries around the world.

Our marketing strategy is focused on building our brand, driving thought leadership with emphasis on the criticality of cybersecurity platform adoption and the convergence of security and networking as well as driving end-customer demand for our security solutions. We use a combination of internal marketing professionals and a network of regional and global channel partners. Our internal marketing organization is responsible for messaging, branding, demand generation, product marketing, channel marketing, partner incentives and promotions, event marketing, digital marketing, communications, analyst relations, public relations and sales enablement. We focus our resources on campaigns, programs and activities that can be leveraged by partners worldwide to extend our marketing reach, such as sales tools and collateral, product awards and technical certifications, media engagement, training, regional seminars and conferences, webinars and various other demand-generation activities.

In 2022, we continued to invest in sales and marketing resources, particularly in the enterprise market where we believe there is an opportunity to expand our business. We intend to continue to make investments in sales and marketing resources, which are critical to support our growth.

Manufacturing and Suppliers

We outsource the manufacturing of our security appliance products to a variety of contract manufacturers and original design manufacturers. Our current manufacturing partners include ADLINK Technology, Inc. (“ADLINK”), IBASE Technology, Inc. (“IBASE”), Micro-Star International Co. (“Micro-Star”), Senao Networks, Inc. (“Senao”), Wistron Corporation (“Wistron”) and a number of other manufacturers. Approximately 88% of our hardware is manufactured in Taiwan. We submit purchase orders to our contract manufacturers that describe the type and quantities of our products to be manufactured, the delivery date and other delivery terms. Once our products are manufactured, they are sent to either our warehouse in California or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed. We believe that outsourcing our manufacturing and a substantial portion of our logistics enables us to focus resources on our core competencies. Our proprietary ASICs, which are key to the performance of our appliances, are built by contract manufacturers including Toshiba America Electronic Components, Inc. (“Toshiba America”) and Renesas Electronics America, Inc. (“Renesas”). These contract manufacturers use foundries in Taiwan and Japan operated by either Taiwan Semiconductor Manufacturing Company Limited (“TSMC”) or by the contract manufacturer itself.

The components included in our products are sourced from various suppliers by us or, more frequently, by our contract manufacturers. Some of the components important to our business, including certain CPUs from Intel Corporation (“Intel”) and Advanced Micro Devices, Inc. (“AMD”), network and wireless chips from Broadcom Inc. (“Broadcom”), Marvell Technology

9

Table of Contents

Group Ltd. (“Marvell”), Qualcomm Incorporated (“Qualcomm”) and Intel and memory devices from Intel, Micron Technology (“Micron”), ADATA Technology Co., Ltd. (“ADATA”), Toshiba Corporation (“Toshiba”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from limited or sole sources of supply.

We have no long-term contracts related to the manufacturing of our ASICs or other components that guarantee any capacity or pricing terms.

Research and Development

We focus our research and development efforts on developing new hardware and software products and services, and adding new features to existing products and services. Our development strategy is to identify features, products and systems for both software and hardware that are, or are expected to be, important to our end-customers. Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including identification of market demand for new products or new features, components selection, timely implementation of product design and development, product performance, quality, ease of use, costs of development, bill of materials, effective manufacturing and assembly processes and sales and marketing.

Intellectual Property

We rely primarily on patent, trademark, copyright and trade secrets laws, confidentiality procedures and contractual provisions to protect our technology. We periodically have discussions with third parties regarding licensing Fortinet’s intellectual property (“IP”) and have sometimes taken legal action against competitors to protect our IP, and as a result third parties have paid us fees in return for licenses or covenants-not-to-sue related to Fortinet IP. As of December 31, 2022, we had 1,285 U.S. and foreign-issued patents and 255 pending U.S. and foreign patent applications. We also license software from third parties for inclusion in our products, including open source software and other software.

Despite our efforts to protect our rights in our technology, unauthorized parties may attempt to copy aspects of our products or obtain and use information and technology that we regard as proprietary. We generally enter into confidentiality agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot provide assurance that the steps we take will prevent misappropriation of our technology. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other IP rights. Third parties have asserted, are currently asserting and may in the future assert patent, copyright, trademark or other IP rights against us, our channel partners or our end-customers. Successful claims of infringement by a third-party could prevent us from distributing certain products or performing certain services or require us to pay substantial damages (including treble damages if we are found to have willfully infringed patents or copyrights), royalties or other fees. Even if third parties offer a license to their technology, the terms of any offered license may not be acceptable and the failure to obtain a license or the costs associated with any license could cause our business, operating results or financial condition to be materially and adversely affected. In certain instances, we indemnify our end-customers, distributors and resellers against claims that our products infringe the IP of third parties.

Government Regulation

We are subject to regulation by various federal, state, regional, local and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, product safety, product labeling, environmental laws, consumer protection laws, anti-bribery laws, data privacy laws, import and export controls, federal securities laws and tax laws and regulations. Many of the laws and regulations that are or may be applicable to our business are changing or being tested in courts and could be interpreted in ways that could adversely impact our business. In addition, the application and interpretation of these laws and regulations often are uncertain, particularly in the industry in which we operate. We believe we take reasonable steps designed to ensure we are in compliance with current laws and regulations and do not expect continued compliance to have a material impact on our capital expenditures, earnings, or competitive position. We continue to monitor existing and pending laws and regulations and while the impact of regulatory changes cannot be predicted with certainty, we do not currently expect compliance to have a material adverse effect.

10

Table of Contents

Seasonality

For information regarding seasonality in our sales, see the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Seasonality, Cyclicality and Quarterly Revenue Trends” in Part II, Item 7 of this Annual Report on Form 10-K.

Competition

The markets for our products are extremely competitive and are characterized by rapid technological change. The principal competitive factors in our markets include:

•product security performance, throughput, features, effectiveness, interoperability and reliability;

•addition and integration of new networking and security features and technological expertise;

•compliance with industry standards and certifications;

•price of products and services and total cost of ownership;

•brand recognition;

•customer service and support across varied and complex customer segments and use cases;

•sales and distribution capabilities;

•size and financial stability;

•breadth of product line;

•form factor of the solution; and

•other competitive differentiators.

Among others, our competitors include Arista Networks, Inc.(“Arista”), Aruba Networks, Inc.(“Aruba”), Barracuda Networks, Inc. (“Barracuda”), Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), CrowdStrike Holdings, Inc. (“CrowdStrike”), F5 Networks, Inc. (“F5 Networks”), Huawei Technologies Co., Ltd. (“Huawei”), Juniper Networks, Inc. (“Juniper”), Palo Alto Networks, Inc. (“Palo Alto Networks”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc (“Sophos”), Trend Micro Incorporated (“Trend Micro”), VMware, Inc. (“VMware”) and Zscaler, Inc. (“Zscaler”).

We believe we compete favorably based on our products’ security performance, throughput, reliability, breadth and ability to work together, our ability to add and integrate new networking and security features and our technological expertise. Several competitors are significantly larger, have greater financial, technical, marketing, distribution, customer support and other resources, are more established than we are, and have significantly better brand recognition. Some of these larger competitors have substantially broader product offerings and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages users from purchasing our products. Based in part on these competitive pressures, we may lower prices or attempt to add incremental features and functionalities to our products.

Conditions in our markets could change rapidly and significantly as a result of technological advancements, market consolidation, supply chain constraints,price list or discount changes or inflation. The development and market acceptance of alternative technologies could decrease the demand for our products or render them obsolete. Our competitors may introduce products that are less costly, provide superior performance, are better marketed, or achieve greater market acceptance than our products. Additionally, our larger competitors often have broader product lines and are better positioned to withstand a significant reduction in capital spending by end-customers, and will therefore not be as susceptible to downturns in a particular market. The above competitive pressures are likely to continue to impact our business. We may not be able to compete successfully in the future, and competition may harm our business.

Human Capital Management

As of December 31, 2022, our total headcount was 12,595 employees, approximately 30% of whom were employed in the United States and approximately 70% of whom were employed outside of the United States.

Our employees are the foundation of our innovation and cybersecurity leadership for the benefit of our customers. We understand there is a shortage of highly skilled employees for security companies like ours, and we believe that our success and competitive advantage depends largely on our ability to continue to attract and retain highly skilled employees with diverse backgrounds and experiences. We believe we offer fair, competitive compensation and benefits, and we encourage a culture of fairness and meritocracy. Our compensation programs for our employees include base pay, incentive compensation, opportunities for equity ownership where local statutes allow and employee benefits that promote well-being across different aspects of our employees’ lives, which may include health and welfare insurance, retirement benefits and paid time off.

11

Table of Contents

As a global company, much of our success is rooted in the diversity of our teams and our commitment to diversity, equity and inclusion (“DEI”). Such commitment starts at the top, with a highly skilled and diverse board of directors. As of December 31, 2022, women represented 25% of the members of our board of directors, and approximately 50% of our board of directors was from underrepresented communities. We value diversity at all levels and continue to focus on enhancing our DEI initiatives across our workforce.

We are also committed to community engagement and social responsibility with regards to our employees and beyond, and our board of directors has active oversight of such initiatives. Examples of our initiatives focused on our employees include our company matching program for employee charitable contributions and the free security training programs we offer to help with career development for our employees, in addition to the general public.

Our culture is defined by our commitment to ethics and integrity. We reinforce our ethical “tone at the top” through clear policies including our Code of Business Conduct and Ethics, regular compliance training for our employees, quarterly meetings of our cross-functional Ethics Committee, clear messaging from our executives, enforcement of company policies and oversight by our board of directors. In addition, our Chief Executive Officer regularly communicates the importance of Fortinet’s core values of openness, teamwork and innovation.

We are committed to providing our employees a safe and healthy work environment. We sponsor a global wellness program designed to enhance physical, financial and mental wellbeing for all our employees around the world. Throughout the year, we encourage healthy behaviors through communications, educational sessions, wellness challenges and other incentives.

None of our U.S. employees are represented by a labor union. Our employees in certain European and Latin American countries, however, have the right to be represented by external labor organizations if they maintain up-to-date union membership. We have not experienced any work stoppages, and we consider our relations with our employees to be good.

Environmental, Social and Governance

We are committed to responsible environmental, social and governance (“ESG”) practices. This commitment starts with the Social Responsibility Committee of our board of directors providing oversight of our Corporate Social Responsibility (“CSR”) strategy, initiatives and execution related to ESG matters. Our senior leadership sponsors the integration of CSR priorities throughout our business operations. In addition, our Global Head of Sustainability and CSR, along with our internal cross-functional employee CSR Committee, engage with internal and external stakeholders to lead CSR execution, communications and disclosure.

Environmental. We recognize that environmental considerations such as climate change, resource scarcity and the energy crisis are top priorities for the future of our planet. We are committed to helping address climate change impacts and minimizing the environmental footprint of our solutions, operations and our broader value chain. We have engaged with a consultancy to measure our Scope 1 and Scope 2 emissions and to further engage on our path to carbon neutrality in alignment with the Paris Agreement we formally signed on to the Science-Based Target Initiative commitment in September 2022. We implemented an Environmental Management Systems platform to track our energy, water and waste impact, and engaged on the ISO14001 certification process for our company-owned warehouse in Union City, California. We began aligning our climate strategy and disclosures to the Task Force on Climate Related Financial Disclosures framework and submitted our Carbon Disclosure Project report. We continue to combine innovation with environmental sustainability to reduce the use of energy, cooling and space required for our solutions, thereby helping our customers minimize power consumption and greenhouse gas emissions.

Social. We are committed to building an inclusive, equitable and diverse workforce within our organization and across the security industry to help empower individuals to reach their full potential. We continue to focus on skilling, upskilling and reskilling individuals to reach our goal of training one million people in cybersecurity by 2026. At the 2022 White House National Cyber Workforce and Education Summit, we announced the expansion of our existing free training offerings, focusing on schools. We introduced an enhanced enterprise-grade Security Awareness and Training service to help Information Technology (“IT”), security and compliance leaders build a cyber-aware culture within their organizations. We continued to expand partnerships with educational institutions and now count over 500 Authorized Academic Partners. Our Education Outreach Program focuses on creating cyber career pathways for underrepresented populations, including women, veterans and disadvantaged individuals. In total, we trained over 210,000 people through our various initiatives in 2022. Internally, we pursue our progress on DEI and have established organizational governance by forming a global DEI Organizing Committee and DEI Council to provide a shared direction and commitment to recruiting and valuing a diverse workforce, fostering a culture of teamwork and openness, and building a more inclusive workplace.

12

Table of Contents

Governance. Our approach to responsible business is based on strong corporate governance practices that aim to ensure accountability while meeting our responsibilities across our value chain. Our board of directors frequently reviews our governance practices to ensure that they are appropriate and reflect our company’s maturity. To promote ethical business practices, we have adopted policies related to proper business conduct and ethics that apply to employees, partners and suppliers, and we have compliance trainings and controls in place. In 2022, we expanded the human rights language in our compliance and business ethics training and updated our supplier and partner codes of conduct to reference our environmental and human rights policies. As part of our engagement with stockholders and our commitment to ESG, we regularly evaluate our corporate governance structure and practices, and have implemented the following measures, among others: majority voting standard for uncontested elections of directors, allowing stockholders to call special meetings of our stockholders, declassification of our board of directors, proxy access and stock ownership guidelines with respect to our non-employee directors.

Available Information

Our web site is located at https://www.fortinet.com, and our investor relations web site is located at https://investor.fortinet.com. The information posted on our website is not incorporated by reference into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Act of 1933, as amended (the “Securities Act”), are available free of charge on our investor relations web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC”). You may also access all of our public filings through the SEC’s website at https://www.sec.gov.

We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations website. Additionally, we provide notifications of news or announcements regarding our financial performance, including SEC filings, investor events and press and earnings releases, as part of our investor relations website. The contents of these websites are not intended to be incorporated by reference into this report or in any other report or document we file.

ITEM 1A. Risk Factors

Investing in our common stock involves a high degree of risk. Investors should carefully consider the following risks and all other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes, before investing in our common stock. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition and results of operations could be materially harmed. In that case, the trading price of our common stock could decline substantially, and investors may lose some or all of their investment. We have summarized risks immediately below and encourage investors to carefully read the entirety of this Risk Factors section.

Risks Related to Our Business and Financial Position

Our operating results are likely to vary significantly and be unpredictable.

Our operating results have historically varied from period to period, and we expect that they will continue to do so as a result of a number of factors, many of which are outside of our control or may be difficult to predict, including:

•economic conditions, including macroeconomic and regional economic challenges resulting, for example, from a recession or other economic downturn, increased inflation or possible stagflation in certain geographies, rising interest rates, the war in Ukraine, the COVID-19 pandemic or other factors;

•our ability to attract and retain new end-customers or sell additional products and services to our existing end-customers;

•component shortages, including chips and other components, and product inventory shortages, including those caused by factors outside of our control, such as the COVID-19 pandemic, supply chain disruptions, inflation and other cost increases, international trade disputes or tariffs, natural disasters, health emergencies, power outages, civil unrest, labor disruption, international conflicts, terrorism, wars, such as the war in Ukraine, and critical infrastructure attacks;

•inventory management;

13

Table of Contents

•the level of demand for our products and services, which may render forecasts inaccurate, increase backlog and may be impacted by the COVID-19 pandemic and supply chain constraints in ways that we are not able to foresee;

•supplier cost increases and any lack of market acceptance of our price increases designed to help offset any supplier cost increases;

•the effects of our reduction of operations in Russia;

•the timing of channel partner and end-customer orders, market acceptance of our price increases and our reliance on a concentration of shipments at the end of each quarter;

•the impact to our business, the global economy, disruption of global supply chains and creation of significant volatility and disruption of the financial markets due to the COVID-19 pandemic, increased inflation or possible stagflation in certain geographies, rising interest rates, the war in Ukraine and other factors;

•any actual or perceived vulnerabilities in our products or services, and any actual or perceived breach of our network or our customers’ networks;

•the timing of shipments, which may depend on factors such as inventory levels, logistics, manufacturing or shipping delays, our ability to ship products on schedule and our ability to accurately forecast inventory requirements and our suppliers’ ability to deliver components and finished goods;

•increased expenses, unforeseen liabilities or write-downs and any negative impact on results of operations from any acquisition or equity investment consummated, as well as accounting risks, integration risks related to product plans and products and risks of negative impact by such acquisitions and equity investments on our financial results;

•the mix of products sold, such as the mix between Core Platform and Enhanced Platform Technology solutions, and the mix of revenue between products and services, as well as the degree to which products and services are bundled and sold together for a package price;

•the purchasing practices and budgeting cycles of our channel partners and end-customers, including the effect of the end of product lifecycles or refresh cycles;

•any decreases in demand by channel partners or end-customers, including any such decreases caused by factors outside of our control such as natural disasters and health emergencies, including earthquakes, droughts, fires, power outages, typhoons, floods, pandemics or epidemics such as the COVID-19 pandemic and manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars, such as the war in Ukraine, and critical infrastructure attacks;

•the effectiveness of our sales organization, generally or in a particular geographic region, including the time it takes to hire sales personnel, the timing of hiring and our ability to hire and retain effective sales personnel;

•sales execution risk related to effectively selling to all segments of the market, including enterprise and small- and medium-sized businesses, government organizations and service providers, and to selling our broad security product and services portfolio, including, among other execution risks, risks associated with the complexity and distraction in selling to all segments, increased competition and unpredictability of timing to close larger enterprise and large organization deals, and the risk that our sales representatives do not effectively sell our Enhanced Platform Technology products;

•execution risk associated with our efforts to capture the opportunities related to our identified growth drivers, such as risk associated with our ability to capitalize on the convergence of networking and security, vendor consolidation of various cyber security solutions, SD-WAN, infrastructure security, cloud security and endpoint protection, and IoT and OT security opportunities;

•the seasonal buying patterns of our end-customers;

•the timing and level of our investments in sales and marketing, and the impact of such investments on our operating expenses, operating margin and the productivity, capacity, tenure and effectiveness of execution of our sales and marketing teams;

14

Table of Contents

•the timing of revenue recognition for our sales, including any impacts resulting from extension of payment terms to distributors and fluctuations in backlog levels, which could result in more variability and less predictability in our quarter-to-quarter revenue and operating results;

•the level of perceived threats to network security, which may fluctuate from period to period;

•changes in the requirements, market needs or buying practices and patterns of our distributors, resellers or end-customers;

•changes in the growth rates of the network security market in particular and other security and networking markets, such as SD-WAN, OT, switches, access points and cloud solutions for which we and our competitors sell products and services;

•the timing and success of new product and service introductions or enhancements by us or our competitors, or any other change in the competitive landscape of our industry, including consolidation among our competitors, partners or end-customers;

•the deferral of orders from distributors, resellers or end-customers in anticipation of new products or product enhancements announced by us or our competitors, or the acceleration of orders in response to our announced or expected price list increases;

•increases or decreases in our billings, revenue and expenses caused by fluctuations in foreign currency exchange rates or a strengthening of the U.S. dollar, as a significant portion of our expenses is incurred and paid in currencies other than the U.S. dollar, and the impact such fluctuations may have on the actual prices that our partners and customers are willing to pay for our products and services;

•compliance with existing laws and regulations;

•our ability to obtain and maintain permits, clearances and certifications that are applicable to our ability to conduct business with the public sector, including the U.S. federal government, and other sectors;

•litigation, litigation fees and costs, settlements, judgments and other equitable and legal relief granted related to litigation;

•the impact of cloud-based security solutions on our billings, revenues, operating margins and free cash flow;

•decisions by potential end-customers to purchase network security solutions from newer technology providers, from larger, more established security vendors or from their primary network equipment vendors;

•price competition and increased competitiveness in our market, including the competitive pressure caused by product refresh cycles;

•our ability to both increase revenues and manage and control operating expenses in order to maintain or improve our operating margins;

•changes in customer renewal rates or attach rates for our services;

•changes in the timing of our billings, collection for our contracts or the contractual term of service sold;

•changes in our estimated annual effective tax rates;

•changes in circumstances and challenges in business conditions, including decreased demand, which may negatively impact our channel partners’ ability to sell the current inventory they hold and negatively impact their future purchases of products from us;

•increased demand for cloud-based services and the uncertainty associated with transitioning to providing such services;

•our channel partners having insufficient financial resources to withstand changes and challenges in business conditions;

15

Table of Contents

•disruptions in our channel or termination of our relationship with important channel partners, including as a result of consolidation among distributors and resellers of security solutions;

•insolvency, credit or other difficulties confronting our key suppliers and channel partners, which could affect their ability to purchase or pay for products and services and which could disrupt our supply or distribution chain;

•policy changes and uncertainty with respect to immigration laws, trade policy and tariffs, including increased tariffs applicable to countries where we manufacture our products, foreign imports and tax laws related to international commerce;

•political, economic and social instability, including geo-political instability and uncertainty, such as that caused by the war in Ukraine, and any disruption or negative impact on our ability to sell to, ship product to and support customers in certain regions based on trade restrictions, embargoes and export control law restrictions;

•general economic conditions, both in domestic and foreign markets;

•future accounting pronouncements or changes in our accounting policies as well as the significant costs that may be incurred to adopt and comply with these new pronouncements;

•possible impairments or acceleration of depreciation of our existing real estate due to our current real estate holdings and future development plans; and

•legislative or regulatory changes, such as with respect to privacy, information and cybersecurity, exports, the environment and applicable accounting standards.

Any one of the factors above or the cumulative effect of some of the factors referred to above may result in significant fluctuations in our quarterly financial and other operating results. This variability and unpredictability could result in our failing to meet our internal operating plan or the expectations of securities analysts or investors for any period. If we fail to meet or exceed such expectations for these or any other reasons, the market price of our shares could fall substantially and we could face costly lawsuits, including securities class action suits. In addition, a significant percentage of our operating expenses are fixed in nature over the near term. Accordingly, in the event of revenue shortfalls, we are generally unable to mitigate the negative impact on margins in the short term.

Adverse economic conditions, such as a possible recession and possible impacts of inflation or stagflation, rising interest rates or reduced information technology spending, may adversely impact our business.

Our business depends on the overall demand for information technology and on the economic health of our current and prospective customers. In addition, the purchase of our products is often discretionary and may involve a significant commitment of capital and other resources. Weak global and regional economic conditions and spending environments, based on a downturn in the economy, a possible recession and the effects of ongoing or increased inflation or possible stagflation in certain geographies, rising interest rates, geopolitical instability and uncertainty, a reduction in information technology spending regardless of macroeconomic conditions, the effects of the COVID-19 pandemic and the impact of the war in Ukraine each could have a material adverse impacts on our business, financial condition and results of operations, including longer sales cycles, lower prices for our products and services, increased component costs, higher default rates among our channel partners, reduced unit sales and slower or declining growth.

We may be adversely affected by the effects of inflation or stagflation, rising interest rates or any economic downturn or recession.

Inflation or possible stagflation, rising interest rates and any economic downturn or recession in certain regions or worldwide each have the potential to adversely affect our liquidity, business, financial condition and results of operations by increasing our overall product cost structure or decreasing demand. These can negatively impact our business by putting downward pressure on growth or if we are unable to achieve the increases in product prices necessary to appropriately offset the additional costs sufficient to maintain margins. The existence of inflation in certain economies has resulted in, and may continue to result in, rising interest rates and capital costs, increased shipping costs, increased costs of labor, weakening exchange rates and other similar effects. As a result of inflation, we have experienced and may continue to experience component, product and shipping cost increases. Inflation, stagflation and any economic downturn or a recession may

16

Table of Contents

materially adversely affect our business, financial condition, results of operations and liquidity. Although we take measures to mitigate risks such as those associated with inflation, the mitigating measures may not be effective or their impact may not offset the increased cost of inflation in a timely manner. Inflation, an economic downturn, a recession and any other economic challenges may also adversely impact spending patterns by our distributors, resellers and end-customers.

The COVID-19 pandemic, including its ongoing variants, may adversely affect our business, for example, through product and component shortages.

The COVID-19 pandemic, including its ongoing variants, has negatively impacted the global economy, disrupted global supply chains, reduced demand for certain solutions and created significant volatility in, and disruption of, global markets. The extent of the future impact of the COVID-19 pandemic on our operational and financial performance is unpredictable, adds uncertainty to our business and will depend on future developments, including the duration and spread of the COVID-19 pandemic and related restrictions on, and disruptions of business, supply chain and world economies, all of which are uncertain and difficult to predict. There is a worldwide shortage of various components, impacting many industries, caused in-part by the COVID-19 pandemic. We continue to experience ongoing product and component shortages, which have resulted in, and which we expect will continue to result in, extended lead times of certain products and significant disruption to our production schedule and predictability. In fact, certain of our contract manufacturers and component suppliers have de-committed from their scheduled delivery dates and product and component delivery commitments. We also have experienced and expect to continue to experience increased component costs, which have negatively impacted our gross margins. An extended period of global supply chain disruption, demand reduction and economic slowdown would materially negatively affect our overall business and our operating results, including billings, revenue, gross margins, operating margins, cash flows and other operating results. If the effects of the COVID-19 pandemic continue to limit the availability of our products, either by limiting components available, the actual manufacture and assembly or by limiting or restricting shipping of components and products, this could continue to result in increased product backlog, and result in lower billings, lower revenue and decreased profitability, and would negatively impact, and may materially negatively impact, our operating results and business. In addition, we may face personnel-related risks as certain departments and locations continue to transition back to an in-person working model, including that “return to office” plans may be viewed negatively by employees and lead to attrition and difficulty in hiring.

The COVID-19 pandemic may adversely affect certain of our partners’ and customers’ ability or willingness to purchase our products and services, delay certain customers’ purchasing decisions and increase customer attrition rates, all of which will adversely affect our future sales, billings and operating results, possibly in a material way. As a result, we may experience extended sales cycles; our ability to close transactions with new and existing customers and partners may be negatively impacted; our ability to recognize revenue from sales we do close may be negatively impacted; certain businesses will not buy our products and services when they otherwise would have; certain current partners, customers and customer prospects may go out of business or face significant business challenges, thereby negatively impacting our sales; product or component shortages, implementation delays or other factors; and our ability to provide technical and other support to our customers may be affected. We have also offered, and may continue to offer, payment terms in excess of our contractual agreements to some of our distributors, which may decrease the likelihood that we will be able to collect from these customers. In addition, the COVID-19 pandemic has caused an increase in certain of our expenses, including increased shipping costs, increased cancellation charges and increased component and product manufacturing costs. The full impact of the COVID-19 pandemic is unknown at this time. While we continue to monitor developments and the potential effect on our business, it is clear that the COVID-19 pandemic may negatively impact certain sales and may have a material negative impact on our operating results in the near term and longer term.

Our billings, revenue and free cash flow growth may slow or may not continue, and our operating margins may decline.

We may experience slowing growth or a decrease in billings, revenue, operating margin and free cash flow for a number of reasons, including as a result of the COVID-19 pandemic, a slowdown in demand for our products or services, a shift in demand from products to services, decrease in services revenue growth, increased competition, worldwide or regional economic challenges based on inflation or possible stagflation, a regional recession or a recession in the global economy, rising interest rates, the war in Ukraine, a decrease in the growth of our overall market or softness in demand in certain geographies or industry verticals, such as the service provider industry, changes in our strategic opportunities, execution risks and our failure for any reason to continue to capitalize on sales and growth opportunities due to other risks identified in the risk factors described in this periodic report. Our expenses as a percentage of total revenue may be higher than expected if our revenue is lower than expected. If our investments in sales and marketing and other functional areas do not result in expected billings and revenue growth, we may experience margin declines. In addition, we may not be able to sustain profitability in future periods if we fail to increase billings, revenue or deferred revenue, and do not appropriately manage our cost structure, free cash flow, or encounter unanticipated liabilities. As a result, any failure by us to maintain profitability and margins and continue our billings, revenue and free cash flow growth could cause the price of our common stock to materially decline.

17

Table of Contents

We are dependent on the continued services and performance of our senior management, the loss of any of whom could adversely affect our business, operating results and financial condition.

Our future performance depends on the continued services and continuing contributions of our senior management to execute on our business plan and to identify and pursue new opportunities and product innovations. The loss of services of members of senior management, particularly Ken Xie, our Co-Founder, Chief Executive Officer and Chairman, or Michael Xie, our Co-Founder, President and Chief Technology Officer, or of any of our senior sales leaders or functional area leaders, could significantly delay or prevent the achievement of our development and strategic objectives. The loss of the services or the distraction of our senior management for any reason, including the COVID-19 pandemic, could adversely affect our business, financial condition and results of operations.

We rely on third-party channel partners for substantially all of our revenue. If our partners fail to perform, our ability to sell our products and services will be limited, and if we fail to optimize our channel partner model going forward, our operating results may be harmed. Additionally, a small number of distributors represents a large percentage of our revenue and gross accounts receivable, and one distributor accounted for 32% of our total net accounts receivable as of December 31, 2022.

A significant portion of our sales is generated through a limited number of distributors, and substantially all of our revenue is from sales by our channel partners, including distributors and resellers. We depend on our channel partners to generate a significant portion of our sales opportunities and to manage our sales process. To the extent our channel partners are unsuccessful in selling our products, or if we are unable to enter into arrangements with and retain a sufficient number of high-quality channel partners in each of the regions in which we sell products, we are unable to keep them motivated to sell our products, or our channel partners shift focus to other vendors and/or our competitors, our ability to sell our products and operating results may be harmed. The termination of our relationship with any significant channel partner may adversely impact our sales and operating results.

In addition, a small number of channel partners represents a large percentage of our revenue and gross accounts receivable. We are exposed to the credit and liquidity risk of some of our channel partners and to credit exposure in weakened markets, which could result in material losses. Our dependence on a limited number of key channel partners means that our billings, revenue and operating results may be harmed by the inability of these key channel partners to successfully sell our products and services, or if any of these key channel partners is unable or unwilling to pay us, terminates its relationship with us or goes out of business. Although we have programs in place that are designed to monitor and mitigate credit and liquidity risks, we cannot guarantee these programs will be effective in reducing our credit risks. If we are unable to adequately control these risks, our business, operating results, and financial condition could be harmed. If channel partners fail to pay us under the terms of our agreements or we are otherwise unable to collect on our accounts receivable from these channel partners, we may be adversely affected both from the inability to collect amounts due and the cost of enforcing the terms of our contracts, including litigation. Our channel partners may seek bankruptcy protection or other similar relief and fail to pay amounts due to us, or pay those amounts more slowly, either of which could adversely affect our operating results, financial position, and cash flow. We may be further impacted by consolidation of our existing channel partners. In such instances, we may experience changes to our overall business and operational relationships due to dealing with a larger combined entity, and our ability to maintain such relationships on favorable contractual terms may be more limited. We may also become increasingly dependent on a more limited number of channel partners, as consolidation increases the relative proportion of our business for which each channel partner is responsible, which may magnify the risks described in the preceding paragraphs.

Six distributor customers accounted for 69% and 68% of our total net accounts receivable in the aggregate as of December 31, 2022 and 2021, respectively. See Note 16. Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers that accounted for 10% or more of our revenue or net accounts receivable. Our largest distributors may experience financial difficulties, face liquidity risk or other financial challenges, which may harm our ability to collect on our accounts receivable.

We provide sales channel partners with specific programs to assist them with selling our products and incentivize them to sell our products, but there can be no assurance that these programs will be effective. In addition, our channel partners may be unsuccessful in marketing, selling and supporting our products and services and may purchase more inventory than they can sell. Our channel partners generally do not have minimum purchase requirements. Some of our channel partners may have insufficient financial resources to withstand changes and challenges in business conditions. Moreover, many of our channel partners are privately held, including our largest distributor, and we may not have sufficient information to assess their financial condition. If our channel partners’ financial condition or operations weaken, their ability to sell our product and services could be negatively impacted. Our channel partners may also market, sell and support products and services that are competitive with ours, and may devote more resources to the marketing, sales and support of such products, or may decide to cease selling our products and services altogether in favor of a competitor’s products and services. They may also have incentives to promote our

18

Table of Contents

competitors’ products to the detriment of our own, or they may cease selling our products altogether. We cannot ensure that we will retain these channel partners or that we will be able to secure additional or replacement partners or that existing channel partners will continue to perform. The loss of one or more of our significant channel partners or the failure to obtain and ship a number of large orders each quarter through them could harm our operating results.

Any new sales channel partner will require extensive training and may take several months or more to achieve productivity. Our channel partner sales structure could subject us to lawsuits, potential liability and reputational harm if, for example, any of our channel partners misrepresent the functionality of our products or services to end-customers, our service provider customers suffer a cyber event impacting end-users, or our channel partners violate laws or our corporate policies. We depend on our global channel partners to comply with applicable legal and regulatory requirements. To the extent that they fail to do so, that could have a material adverse effect on our business, operating results and financial condition. If we fail to optimize our channel partner model or fail to manage existing sales channels, our business will be seriously harmed.

Reliance on a concentration of shipments at the end of the quarter could cause our billings and revenue to fall below expected levels or delay collections and the related increase in free cash flow.

As a result of customer buying patterns and the efforts of our sales force and channel partners to meet or exceed quarterly quotas, we have historically received a substantial portion of each quarter’s sales orders and generated a substantial portion of each quarter’s billings and revenue during the last two weeks of the quarter. We typically arrange for a logistics partner to pick up the last shipment of our products a few hours prior to the end of the quarter, and a delay in the arrival of the logistics partner or other factors such as a power outage could prevent us from shipping and billing for a material amount of products for which we have orders. Further, it is possible that the dollar value of these products intended to be shipped late on the last day of the quarter may be material. Additionally, our service billings are dependent on the completion of certain automated processes by our internal business management systems, some of which cannot be performed until after the related products have been shipped. If we do not have enough time after shipping our products for our systems to perform these processes prior to the end of the quarter, or we have system issues that prevent processing in time to realize service billings in a quarter, we will not be able to bill and realize billings for those services until the following quarter, which may materially negatively impact our billings for a particular quarter. We implemented a cloud-based quoting tool to help provide our sales team with the ability to have faster quote generation, reduce quote errors and increase sales productivity. Our ability to integrate the data from this tool into our order processing may cause order processing delays that could have an effect on our financial results. Our billings and revenue for any quarter could fall below our expectations or those of securities analysts and investors, resulting in a decline in our stock price, if expected orders at the end of any quarter are delayed for any reason or our ability to fulfill orders at the end of any quarter is hindered for any reason, including, among others:

•the failure of anticipated purchase orders to materialize;

•our logistics partners’ failure or inability to ship products prior to quarter-end to fulfill purchase orders received near the end of the quarter;

•disruption in manufacturing or shipping based on power outages, system failures, labor disputes or constraints, excessive demand, natural disasters or widespread public health problems including pandemics and epidemics such as the COVID-19 pandemic;

•our failure to accurately forecast our inventory requirements and to appropriately manage inventory to meet demand;

•our inability to release new products on schedule;

•any failure of our systems related to order review and processing; and

•any delays in shipments due to trade compliance requirements, labor disputes or logistics changes at shipping ports, airline strikes, severe weather or otherwise.

We rely significantly on revenue from FortiGuard and other security subscription and FortiCare technical support services, and revenue from these services may decline or fluctuate. Because we recognize revenue from these services over the term of the relevant service period, downturns or upturns in sales of FortiGuard and other security subscription and FortiCare technical support services are not immediately reflected in full in our operating results.

Our FortiGuard and other security subscription and FortiCare technical support services revenue has historically accounted for a significant percentage of our total revenue. Revenue from the sale of new, or from the renewal of existing,

19

Table of Contents

FortiGuard and other security subscription and FortiCare technical support service contracts may decline and fluctuate as a result of a number of factors, including fluctuations in purchases of Core Platform appliances or our Enhanced Platform Technology products, changes in the sales mix between products and services, end-customers’ level of satisfaction with our products and services, the prices of our products and services, the prices of products and services offered by our competitors, reductions in our customers’ spending levels and the timing of revenue recognition with respect to these arrangements. If our sales of new, or renewals of existing, FortiGuard and other security subscription and FortiCare technical support service contracts decline, our revenue and revenue growth may decline and our business could suffer. In addition, in the event significant customers require payment terms for FortiGuard and other security subscription and FortiCare technical support services in arrears or for shorter periods of time than annually, such as monthly or quarterly, this may negatively impact our billings and revenue. Furthermore, we recognize FortiGuard and other security subscription and FortiCare technical support services revenue ratably over the term of the relevant service period, which is typically from one to five years. As a result, much of the FortiGuard and other security subscription and FortiCare technical support services revenue we report each quarter is the recognition of deferred revenue from FortiGuard and other security subscription and FortiCare technical support services contracts entered into during previous quarters or years. Consequently, a decline in new or renewed FortiGuard and other security subscription and FortiCare technical support services contracts in any one quarter will not be fully reflected in revenue in that quarter but will negatively affect our revenue in future quarters. Accordingly, the effect of significant downturns in sales of new, or renewals of existing, FortiGuard and other security subscription and FortiCare technical support services is not reflected in full in our statements of income until future periods. Our FortiGuard and other security subscription and FortiCare technical support services revenue also makes it difficult for us to rapidly increase our revenue through additional service sales in any period, as revenue from new and renewal support services contracts must be recognized over the applicable service term.

If we are unable to hire, retain and motivate qualified personnel, our business will suffer.

Our future success depends, in part, on our ability to continue to attract and retain highly skilled personnel. The loss of the services of any of our key personnel, the inability to attract or retain qualified personnel, any failure to have in place and execute an effective succession plan for key executives or delays in hiring required personnel, particularly in engineering, sales and marketing, may seriously harm our business, financial condition and results of operations. From time to time, we experience turnover in our management-level personnel. None of our key employees has an employment agreement for a specific term, and any of our employees may terminate their employment at any time. Our ability to continue to attract and retain highly skilled personnel will be critical to our future success.

Competition for highly skilled personnel is frequently intense, especially for qualified sales, support and engineering employees in network security and especially in the locations where we have a substantial presence and need for highly skilled personnel, such as the San Francisco Bay Area and the Vancouver, Canada area. We may not be successful in attracting, assimilating or retaining qualified personnel to fulfill our current or future needs. In addition, to the extent we hire personnel from competitors, we may be subject to allegations that they have been improperly solicited or divulged proprietary or other confidential information. Changes in immigration laws, including changes to the rules regarding H1-B visas, may also harm our ability to attract personnel from other countries. Our inability to hire properly qualified and effective sales, support and engineering employees could harm our growth and our ability to effectively support growth.

We have incurred indebtedness and may incur other debt in the future, which may adversely affect our financial condition and future financial results.

As of December 31, 2022, we had an aggregate of $990.4 million of indebtedness outstanding under our senior notes. Under the agreements governing our indebtedness, we are permitted to incur additional debt. This debt, and any debt that we may incur in the future, may adversely affect our financial condition and future financial results by, among other things:

•increasing our vulnerability to downturns in our business, to competitive pressures and to adverse economic and industry conditions;

•requiring the dedication of a portion of our expected cash from operations to service our indebtedness, thereby reducing the amount of expected cash flow available for other purposes, including capital expenditures, share repurchases and acquisitions; and

•limiting our flexibility in planning for, or reacting to, changes in our businesses and our industries;

If we are unable to generate sufficient cash flow from operations in the future to service our debt, we may be required, among other things, to seek additional financing in the debt or equity markets, refinance or restructure all or a portion of our

20

Table of Contents

indebtedness, sell selected assets or reduce or delay planned capital, operating or investment expenditures. Such measures may not be sufficient to enable us to service our debt.

Additionally, the agreements governing our indebtedness impose restrictions on us and require us to comply with certain covenants. If we breach any of these covenants and do not obtain a waiver from the noteholders, then, subject to applicable cure periods, any or all of our outstanding indebtedness may be declared immediately due and payable. There can be no assurance that any refinancing or additional financing would be available on terms that are favorable or acceptable to us, if at all.

Under the terms of our outstanding senior notes, we may be required to repurchase the notes for cash prior to their maturity in connection with the occurrence of certain changes of control that are accompanied by certain downgrades in the credit ratings of the notes. The repayment obligations under the notes may have the effect of discouraging, delaying or preventing a takeover of our company. If we were required to pay the notes prior to their scheduled maturity, it could have a negative impact on our cash position and liquidity and impair our ability to invest financial resources in other strategic initiatives.

In addition, changes by any rating agency to our credit rating may negatively impact the value and liquidity of both our debt and equity securities, as well as affect our ability to obtain additional financing in the future and may negatively impact the terms of any such financing.

Risks Related to Our Sales and End-Customers

We generate a majority of revenue from sales to distributors, resellers and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations.

We market and sell our products throughout the world and have established sales offices in many parts of the world. Our international sales have represented a majority of our total revenue in recent periods. Therefore, we are subject to risks associated with having worldwide operations. We are also subject to a number of risks typically associated with international sales and operations, including:

•disruption in the supply chain or in manufacturing or shipping, or decreases in demand by channel partners or end-customers, including any such disruption or decreases caused by factors outside of our control such as natural disasters and health emergencies, including earthquakes, droughts, fires, power outages, typhoons, floods, pandemics or epidemics such as the COVID-19 pandemic and manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars or other foreign conflicts, such as the war in Ukraine or tensions between China and Taiwan, and critical infrastructure attacks;

•fluctuations in foreign currency exchange rates or a strengthening of the U.S. dollar, as a significant portion of our expenses is incurred and paid in currencies other than the U.S. dollar, and the impact such fluctuations may have on the actual prices that our partners and customers are willing to pay for our products and services;

•economic or political instability in foreign markets, such as any economic or political instability caused by economic downturns and wars or other foreign conflicts, such as the war in Ukraine, tensions between China and Taiwan and any expansions thereof;

•greater difficulty in enforcing contracts and accounts receivable collection, including longer collection periods;

•longer sales processes for larger deals, particularly during the summer months or as a result of the COVID-19 pandemic and related travel and gathering restrictions;

•changes in regulatory requirements;

•difficulties and costs of staffing and managing foreign operations;

•the uncertainty of protection for IP rights in some countries;

•costs of compliance with foreign policies, laws and regulations and the risks and costs of non-compliance with such policies, laws and regulations;

21

Table of Contents

•protectionist policies and penalties, and local laws, requirements, policies and perceptions that may adversely impact a U.S.-headquartered business’s sales in certain countries outside of the U.S.;

•costs of complying with, and the risks, reputational damage and other costs of non-compliance with, U.S. or other foreign laws and regulations for foreign operations, including the U.S. Foreign Corrupt Practices Act, the United Kingdom Bribery Act 2010, the General Data Protection Regulation (the “GDPR”), import and export control laws, trade laws and regulations, tariffs and retaliatory measures, trade barriers and economic sanctions;

•other regulatory or contractual limitations on our ability to sell our products in certain foreign markets, and the risks and costs of non-compliance;

•heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales or sales-related arrangements, such as sales “side agreements” to allow return rights, that could disrupt the sales team through terminations of employment or otherwise, and may adversely impact financial results as compared to those already reported or forecasted and result in restatements of financial statements and irregularities in financial statements;

•our ability to effectively implement and maintain adequate internal controls to properly manage our international sales and operations;

•political unrest, changes and uncertainty associated with terrorism, hostilities, war or natural disasters;

•management communication and integration problems resulting from cultural differences and geographic dispersion; and

•changes in tax, tariff, employment and other laws.

The ongoing effects of the COVID-19 pandemic may increase the severity and unpredictability of a number of the foregoing risks, and the risks to our business presented by the COVID-19 pandemic may be more significant and for a longer term in certain international geographies where we do meaningful business.

Product and service sales and employee and contractor matters may be subject to foreign governmental regulations, which vary substantially from country to country. Further, we may be unable to keep up to date with changes in government requirements as they change over time. Failure to comply with these regulations could result in adverse effects to our business. In many foreign countries, it is common for others to engage in business practices that are prohibited by our internal policies and procedures or U.S. regulations applicable to us. Although we implemented policies and procedures designed to ensure compliance with these laws and policies, there can be no assurance that all of our employees, contractors, channel partners and agents will comply with these laws and policies. Violations of laws or key control policies by our employees, contractors, channel partners or agents could result in litigation, regulatory action, costs of investigation, delays in revenue recognition, delays in financial reporting, financial reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our products and services, any of which could have a material adverse effect on our business and results of operations.

We may undertake corporate operating restructurings or transfers of assets that involve our group of foreign country subsidiaries through which we do business abroad, in order to maximize the operational and tax efficiency of our group structure. If ineffectual, such restructurings or transfers could increase our income tax liabilities, and in turn, increase our global effective tax rate. Moreover, our existing corporate structure and intercompany arrangements have been implemented in a manner we believe reasonably ensures that we are in compliance with current prevailing tax laws. However, the tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed technology or intercompany arrangements, which could impact our worldwide effective tax rate and harm our financial position and operating results.

If we are not successful in continuing to execute our strategy to increase our sales to large and medium-sized end-customers, our results of operations may suffer.

An important part of our growth strategy is to increase sales of our products to large- and medium-sized businesses, service providers and government organizations. While we have increased sales in recent periods to large- and medium-sized businesses, our sales volume varies by quarter and there is risk as to our level of success selling to these target customers. Such

22

Table of Contents

sales involve unique sales skillsets, processes and structures, are often more complex and feature a longer contract term and may be at higher discount levels. We also have experienced uneven traction selling to certain government organizations and service providers and MSSPs, and there can be no assurance that we will be successful selling to these customers. Sales to these organizations involve risks that may not be present, or that are present to a lesser extent, with sales to smaller entities. These risks include:

•increased competition from competitors that traditionally target large and medium-sized businesses, service providers and government organizations and that may already have purchase commitments from those end-customers;

•increased purchasing power and leverage held by large end-customers in negotiating contractual arrangements;

•unanticipated changes in the capital resources or purchasing behavior of large end-customers, including changes in the volume and frequency of their purchases and changes in the mix of products and services, willingness to change to cloud delivery model and related payment terms;

•more stringent support requirements in our support service contracts, including stricter support response times, more complex requirements and increased penalties for any failure to meet support requirements;

•longer sales cycles and the associated risk that substantial time and resources may be spent on a potential end-customer that elects not to purchase our products and services;

•increased requirements from these customers that we have certain third-party security or other certifications, which we may not have, the lack of which may adversely affect our ability to successfully sell to such customers;

•uncertainty as to timing to close large deals and any delays in closing those deals; and

•longer ramp-up periods for enterprise sales personnel as compared to other sales personnel.

Large and medium-sized businesses, service providers and MSSPs and government organizations often undertake a significant evaluation process that results in a lengthy sales cycle, in some cases longer than 12 months. Although we have a channel sales model, our sales representatives typically engage in direct interaction with end-customers, along with our distributors and resellers, in connection with sales to large- and medium-sized end-customers. We may spend substantial time, effort and money in our sales efforts without being successful in producing any sales. In addition, purchases by large- and medium-sized businesses, service providers and government organizations are frequently subject to budget constraints, multiple approvals and unplanned administrative, processing and other delays; in light of current economic conditions and regulations in place by various government authorities, some of these sales cycles are being further extended. Furthermore, service providers and MSSPs represent our largest industry vertical and consolidation or continued changes in buying behavior by larger customers within this industry could negatively impact our business. Large- and medium-sized businesses, service providers and MSSPs and government organizations typically have longer implementation cycles, require greater product functionality and scalability, expect a broader range of services, including design, implementation and post go-live services, demand that vendors take on a larger share of risks, require acceptance provisions that can lead to a delay in revenue recognition and expect greater payment flexibility from vendors. In addition, large- and medium-sized businesses, service providers and government organizations may require that our products and services be sold differently from how we offer our products and services, which could negatively impact our operating results. Our large business and service provider customers may also become more deliberate in their purchases as they plan their next-generation network security architecture, leading them to take more time in making purchasing decisions or to purchase based only on their immediate needs. All these factors can add further risk to business conducted with these customers. In addition, if sales expected from a large- and medium-sized end-customer for a particular quarter are not realized in that quarter or at all, our business, operating results and financial condition could be materially and adversely affected.

If we do not increase the effectiveness of our sales organization, we may have difficulty adding new end-customers or increasing sales to our existing end-customers and our business may be adversely affected.

Although we have a channel sales model, sales in our industry are complex and members of our sales organization often engage in direct interaction with our prospective end-customers, particularly for larger deals involving larger end-customers. Therefore, we continue to be substantially dependent on our sales organization to obtain new end-customers and sell additional products and services to our existing end-customers. There is significant competition for sales personnel with the

23

Table of Contents

skills and technical knowledge that we require, including experienced enterprise sales employees and others. Our ability to grow our revenue depends, in large part, on our success in recruiting, training and retaining sufficient numbers of sales personnel to support our growth and on the effectiveness of those personnel in selling successfully in different contexts, each of which has its own different complexities, approaches and competitive landscapes, such as managing and growing the channel business for sales to small businesses and more actively selling to the end-customer for sales to larger organizations. New hires require substantial training and may take significant time before they achieve full productivity. Our recent hires and planned hires may not become productive as quickly as we expect, and we may be unable to hire or retain sufficient numbers of qualified individuals in the markets where we do business or plan to do business. Furthermore, hiring sales personnel in new countries requires additional setup and upfront costs that we may not recover if the sales personnel fail to achieve full productivity. If our sales employees do not become fully productive on the timelines that we have projected, our revenue may not increase at anticipated levels and our ability to achieve long-term projections may be negatively impacted. If we are unable to hire and train sufficient numbers of effective sales personnel, the sales personnel are not successful in obtaining new end-customers or increasing sales to our existing customer base or sales personnel do not effectively sell our Enhanced Platform Technology products, our business, operating results and prospects may be adversely affected. If we do not hire properly qualified and effective sales employees and organize our sales team effectively to capture the opportunities in the various customer segments we are targeting, our growth and ability to effectively support growth may be harmed.

Unless we continue to develop better market awareness of our company and our products, and to improve lead generation and sales enablement, our revenue may not continue to grow.

Increased market awareness of our capabilities and products and increased lead generation are essential to our continued growth and our success in all of our markets, particularly the market for sales to large businesses, service providers and government organizations. While we have increased our investments in sales and marketing, it is not clear that these investments will continue to result in increased revenue. If our investments in additional sales personnel or our marketing programs are not successful in continuing to create market awareness of our company and products or increasing lead generation, in growing billings for our broad product suite or if we experience turnover and disruption in our sales and marketing teams, we may not be able to achieve sustained growth, and our business, financial condition and results of operations may be adversely affected.

A portion of our revenue is generated by sales to government organizations and to companies that perform on government contracts. These sales subject us to a number of regulatory requirements, challenges and risks.

We derive a portion of our revenue from sales to government organization in the US (federal, state, local and education markets) and in foreign markets. Sales to government organizations are subject to several risks. Because of public sector budgetary cycles and laws or regulations governing public procurements, such sales often require significant upfront time and expense without any assurance of winning a sale.

Government demand, sales and payment for our products and services may be negatively impacted by numerous factors and requirements unique to selling to government agencies, such as:

•policies, laws or regulations have in the past, and may in the future, require us to hold certain third-party and government security certifications in order to sell our products and services and to make organizational and operational changes in order to sell into specific government agencies or programs, and such certifications may be costly to obtain and maintain;

•funding authorizations and requirements unique to government agencies, with funding or purchasing reductions or delays adversely affecting public sector demand for our products; and

•geopolitical matters, including tariff and trade disputes, government shutdowns, impact of the war in Ukraine, tensions between China and Taiwan and trade protectionism and other political dynamics that may adversely affect our ability to sell in certain locations or obtain the requisite permits and clearances required for certain purchases by government organizations of our products and services.

In addition, government certifications and requirements may restrict our ability to sell to certain government customers until we have obtained certain certifications or meet other applicable requirements, which we are not guaranteed to do. For example, certain of our competitors may be certified under the U.S. Federal Risk and Authorization Management Program (“FedRAMP”) and until such a time that are also certified under FedRAMP, we risk losing sales to certain government customers to certified competitors.

The rules and regulations applicable to sales to government organizations may also negatively impact sales to other organizations. For example, government organizations may have contractual or other legal rights to terminate contracts with our

24

Table of Contents

distributors and resellers for convenience or due to a default, and any such termination may adversely impact our future results of operations. If the distributor receives a significant portion of its revenue from sales to government organizations, the financial health of the distributor could be substantially harmed, which could negatively affect our future sales to such distributor. Governments routinely investigate, review and audit government vendors’ administrative and other processes, and any unfavorable investigation, audit, other review or unfavorable determination related to any government clearance or certification could result in the government’s refusing to continue buying our products and services, a limitation and reduction of government purchases of our products and services, a reduction of revenue or fines, or civil or criminal liability if the investigation, audit or other review uncovers improper, illegal or otherwise concerning activities. Any such penalties could adversely impact our results of operations in a material way. Further, any refusal to grant certain certifications or clearances by one government agency, or any decision by one government agency that our products do not meet certain standards, may reduce business opportunities and cause reputational harm and cause concern with other government agencies, governments and businesses and cause them to not buy our products and services and/or lead to a decrease in demand for our products generally.

Finally, purchases by some governments, including the U.S. federal government, may require certain products to be manufactured in the United States or in other high-cost manufacturing locations. We may not manufacture all products in locations that meet such requirements meaning our products will not be eligible for certain government purchases.

The war in Ukraine and any expansion thereof and our reduction of operations in Russia have affected, and may continue to affect, our business.

The war in Ukraine and resulting disruption are ongoing and likely to continue, and may also expand into other regions. Some of the impacts and potential impacts of the war in Ukraine and possible expansion thereof include, but are not limited to:

•reduction of sales and revenue based on our reduction of operations and sales in Russia;

•difficulty in business planning and forecasting due to the uncertainty of the impact of the war on aspects of our business, such as on our distributors, resellers and end-customers;

•uncertainty and disruption in the general demand environment, including Russia, Belarus and Ukraine, which could reduce demand by distributors;

•increased costs and the diversion of management’s attention related to oversight of our international operations;

•failure of Russian distributors to pay outstanding accounts receivables owed to us;

•retaliatory actions by Russia or other countries against us and other Western companies that chose to limit or remove business operations in the region;

•increased risk of data breach and other threats from ransomware, destructive malware, distributed denial-of-service attacks, as well as fraud, spam and fake accounts, cyber-attacks or other illegal activity conducted generally by bad actors seeking to take advantage of us, our distributors, resellers or end-customers;

•any devaluation of local currency or other inflationary effects caused by the impact of sanctions and other macroeconomic effects of the war; and

•significant volatility and disruption of global financial markets and negative impact to global and regional economies.

Sanctions and trade control measures that have been implemented against Russia and Belarus, and others that may be implemented, are complex and still evolving. Our efforts to comply with such measures may be costly, time consuming and divert the attention of management. Any alleged or actual failure to comply with these measures as we work to reduce our business operations in Russia may subject us to government scrutiny, civil or criminal proceedings, sanctions and other liabilities, which may have a material adverse effect on our international operations, financial condition and results of operations.

Any of the above-mentioned factors could adversely affect our business, prospects, financial condition and results of operations. The extent and duration of the military action, sanctions and resulting market disruptions are impossible to predict,

25

Table of Contents

but could be substantial. Any such disruptions may also magnify the impact of other risks described in this Annual Report on Form 10-K.

Risks Related to Our Industry, Customers, Products and Services

We face intense competition in our market and we may not maintain or improve our competitive position.

The market for network security products is intensely competitive and dynamic, and we expect competition to continue to intensify. We face many competitors across the different cybersecurity markets. Our competitors include companies such as Arista, Aruba, Barracuda, Check Point, Cisco, CrowdStrike, F5 Networks, Huawei, Juniper, Palo Alto Networks, SonicWALL, Sophos, Trend Micro, VMware and Zscaler.

Some of our existing and potential competitors enjoy competitive advantages such as:

•greater name recognition and/or longer operating histories;

•larger sales and marketing budgets and resources;

•broader distribution and established relationships with distribution partners and end-customers;

•access to larger customer bases;

•greater customer support resources;

•greater resources to make acquisitions;

•stronger U.S. government relationships;

•lower labor and development costs; and

•substantially greater financial, technical and other resources.

In addition, certain of our larger competitors have broader product offerings, and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages customers from purchasing our products. These larger competitors often have broader product lines and market focus, and are in a better position to withstand any significant reduction in capital spending by end-customers in these markets. Therefore, these competitors will not be as susceptible to downturns in a particular market. Also, many of our smaller competitors that specialize in providing protection from a single type of security threat are often able to deliver these specialized security products to the market more quickly than we can.

Conditions in our markets could change rapidly and significantly as a result of technological advancements or continuing market consolidation. Our competitors and potential competitors may also be able to develop products or services, and leverage new business models, that are equal or superior to ours, achieve greater market acceptance of their products and services, disrupt our markets, and increase sales by utilizing different distribution channels than we do. For example, certain of our competitors are focusing on delivering security services from the cloud which include cloud-based security providers, such as Zscaler. In addition, current or potential competitors may be acquired by third parties with greater available resources, and new competitors may arise pursuant to acquisitions of network security companies or divisions. As a result of such acquisitions, competition in our market may continue to increase and our current or potential competitors might be able to adapt more quickly to new technologies and customer needs, devote greater resources to the promotion or sale of their products and services, initiate or withstand substantial price competition, take advantage of acquisition or other opportunities more readily, or develop and expand their product and service offerings more quickly than we do. In addition, our competitors may bundle products and services competitive with ours with other products and services. Customers may accept these bundled products and services rather than separately purchasing our products and services. As our customers refresh the security products bought in prior years, they may seek to consolidate vendors, which may result in current customers choosing to purchase products from our competitors on an ongoing basis. Due to budget constraints or economic downturns, organizations may be more willing to incrementally add solutions to their existing network security infrastructure from competitors than to replace it with our solutions. These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer customer orders, reduced revenue and gross margins and loss of market share.

26

Table of Contents

Managing inventory of our products and product components is complex. Insufficient inventory or components may result in lost sales opportunities or delayed revenue, while excess inventory may harm our gross margins.

Managing our inventory is complex, especially given current supply chain disruption. Our channel partners may increase orders during periods of product shortages, cancel orders or not place orders commensurate with our expectations if their inventory is too high, return products or take advantage of price protection (if any is available to the particular partner) or delay orders in anticipation of new products, and accurately forecasting inventory requirements and demand can be challenging. Our channel partners also may adjust their orders in response to the supply of our products and the products of our competitors that are available to them and in response to seasonal fluctuations in end-customer demand. Furthermore, the time required to source components including chips and other components, and manufacture or ship certain products has increased, and so we expect inventory shortfalls to continue and costs to manufacture and ship on-time to continue to increase. If we cannot manufacture and ship our products due to, for example, global chip shortages, excessive demand on contract manufacturers capacity, natural disasters and health emergencies such as earthquakes, fires, power outages, typhoons, floods, cyber events, pandemics and epidemics such as the COVID-19 pandemic or manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars or other foreign conflicts, such as the war in Ukraine or tensions between China and Taiwan, and critical infrastructure attacks, our business and financial results could be materially and adversely impacted.

The global chip shortage caused by the COVID-19 pandemic and other factors affecting manufacturing capacity is having, and we expect to continue to have, an adverse impact on our ability to manage our inventory and to meet product demand in a timely fashion. We expect this shortage will persist for an indefinite period of time. Management of our inventory is further complicated by the significant number of different products and models that we sell which may impact our billings, revenue, margins and free cash flow. Mismanagement of our inventory, whether due to imprecise forecasting, employee errors or malfeasance, inaccurate information or otherwise, may adversely affect our results of operations. The COVID-19 pandemic has resulted in challenges for us to obtain components and inventory, as well as increases to freight and shipping costs, and may result in a material adverse effect on our results of operations.

Inventory management remains an area of focus as we balance the need to maintain inventory levels that are sufficient to ensure competitive lead times against the risk of inventory obsolescence because of rapidly changing technology, product transitions, customer requirements or excess inventory levels. If we ultimately determine that we have excess inventory, we may have to reduce our prices and write-down inventory, which in turn could result in lower gross margins. Alternatively, insufficient inventory levels may lead to shortages that result in delayed billings and revenue or loss of sales opportunities altogether as potential end-customers turn to competitors’ products that are readily available. For example, we have in the past experienced inventory shortages and excesses due to the variance in demand for certain products from forecasted amounts. Our inventory management systems and related supply chain visibility tools may be inadequate to enable us to effectively manage inventory. If we are unable to effectively manage our inventory and that of our channel partners, our results of operations could be adversely affected.

If our new products and product enhancements do not achieve sufficient market acceptance, our results of operations and competitive position will suffer.

We spend substantial amounts of time and money to develop internally and acquire new products and enhanced versions of our existing products in order to incorporate additional features, improved functionality or other enhancements in order to meet our customers’ rapidly evolving demands for network security in our highly competitive industry. When we develop a new product or an enhanced version of an existing product, we typically incur expenses and expend resources upfront to market, promote and sell the new offering. Therefore, when we develop and introduce new or enhanced products, they must achieve high levels of market acceptance in order to justify the amount of our investment in developing and bringing them to market.

Our new products or product enhancements could fail to attain sufficient market acceptance for many reasons, including:

•delays in releasing our new products or enhancements to the market;

•failure to accurately predict market demand in terms of product functionality and to supply products that meet this demand in a timely fashion;

•failure to have the appropriate research and development expertise and focus to make our top strategic Enhanced Platform Technology products successful;

27

Table of Contents

•failure of our sales force and partners to focus on selling new products;

•inability to interoperate effectively with the networks or applications of our prospective end-customers;

•inability to protect against new types of attacks or techniques used by hackers;

•actual or perceived defects, vulnerabilities, errors or failures;

•negative publicity about their performance or effectiveness;

•introduction or anticipated introduction of competing products by our competitors;

•poor business conditions for our end-customers, causing them to delay IT purchases;

•changes to the regulatory requirements around security; and

•reluctance of customers to purchase products incorporating open source software.

If our new products or enhancements do not achieve adequate acceptance in the market, our competitive position will be impaired, our revenue will be diminished and the effect on our operating results may be particularly acute because of the significant research, development, marketing, sales and other expenses we incurred in connection with the new product or enhancement.

Demand for our products may be limited by market perception that individual products from one vendor that provide multiple layers of security protection in one product are inferior to point solution network security solutions from multiple vendors.

Sales of many of our products depend on increased demand for incorporating broad security functionality into one appliance. If the market for these products fails to grow as we anticipate, our business will be seriously harmed. Target customers may view “all-in-one” network security solutions as inferior to security solutions from multiple vendors because of, among other things, their perception that such products of ours provide security functions from only a single vendor and do not allow users to choose “best-of-breed” defenses from among the wide range of dedicated security applications available. Target customers might also perceive that, by combining multiple security functions into a single platform, our solutions create a “single point of failure” in their networks, which means that an error, vulnerability or failure of our product may place the entire network at risk. In addition, the market perception that “all-in-one” solutions may be suitable only for small and medium-sized businesses because such solution lacks the performance capabilities and functionality of other solutions may harm our sales to large businesses, service provider and government organization end-customers. If the foregoing concerns and perceptions become prevalent, even if there is no factual basis for these concerns and perceptions, or if other issues arise with our market in general, demand for multi-security functionality products could be severely limited, which would limit our growth and harm our business, financial condition and results of operations. Further, a successful and publicized targeted attack against us, exposing a “single point of failure”, could significantly increase these concerns and perceptions and may harm our business and results of operations.

If functionality similar to that offered by our products is incorporated into existing network infrastructure products, organizations may decide against adding our appliances to their network, which would have an adverse effect on our business.

Large, well-established providers of networking equipment, such as Cisco, offer, and may continue to introduce, network security features that compete with our products, either in standalone security products or as additional features in their network infrastructure products. The inclusion of, or the announcement of an intent to include, functionality perceived to be similar to that offered by our security solutions in networking products that are already generally accepted as necessary components of network architecture may have an adverse effect on our ability to market and sell our products. Furthermore, even if the functionality offered by network infrastructure providers is more limited than our products, a significant number of customers may elect to accept such limited functionality in lieu of adding appliances from an additional vendor such as us. Many organizations have invested substantial personnel and financial resources to design and operate their networks and have established deep relationships with other providers of networking products, which may make them reluctant to add new components to their networks, particularly from other vendors such as us. In addition, an organization’s existing vendors or new vendors with a broad product offering may be able to offer concessions that we are not able to match because we currently offer

28

Table of Contents

only network security products and have fewer resources than many of our competitors. If organizations are reluctant to add additional network infrastructure from new vendors or otherwise decide to work with their existing vendors, our business, financial condition and results of operations will be adversely affected.

Because we depend on several third-party manufacturers to build our products, we are susceptible to manufacturing delays that could prevent us from shipping customer orders on time, if at all, and may result in the loss of sales and customers, and third-party manufacturing cost increases could result in lower gross margins and free cash flow.

We outsource the manufacturing of our security appliance products to contract manufacturing partners and original design manufacturing partners, including manufacturers with facilities located in Taiwan and other countries outside the United States such as ADLINK, IBASE, Micro-Star, Senao and Wistron. Our reliance on our third-party manufacturers reduces our control over the manufacturing process, exposing us to risks, including reduced control over quality assurance, costs, supply and timing and possible tariffs. Any manufacturing disruption related to our third-party manufacturers or their component suppliers for any reason, including global chip shortages, natural disasters and health emergencies such as earthquakes, fires, power outages, typhoons, floods, health pandemics and epidemics such as the COVID-19 pandemic and manmade events such as civil unrest, labor disruption, cyber events, international trade disputes, international conflicts, terrorism, wars, such as the war in Ukraine, and critical infrastructure attacks, could impair our ability to fulfill orders. If we are unable to manage our relationships with these third-party manufacturers effectively, or if these third-party manufacturers experience delays, increased manufacturing lead-times, disruptions, capacity constraints or quality control problems in their manufacturing operations, or fail to meet our future requirements for timely delivery, our ability to ship products to our customers could be impaired and our business would be seriously harmed. Further, certain components for our products come from Taiwan and approximately 88% of our hardware is manufactured in Taiwan. Any increase in tensions between China and Taiwan, including threats of military actions or escalation of military activities, could adversely affect our manufacturing operations in Taiwan.

These manufacturers fulfill our supply requirements on the basis of individual purchase orders. We have no long-term contracts or arrangements with our third-party manufacturers that guarantee capacity, the continuation of particular payment terms or the extension of credit limits. Accordingly, they are not obligated to continue to fulfill our supply requirements, and the prices we are charged for manufacturing services could be increased on short notice. If we are required to change third-party manufacturers, our ability to meet our scheduled product deliveries to our customers would be adversely affected, which could cause the loss of sales and existing or potential customers, delayed revenue or an increase in our costs, which could adversely affect our gross margins. Our individual product lines are generally manufactured by only one manufacturing partner. Any production or shipping interruptions for any reason, such as a natural disaster, epidemic, capacity shortages, quality problems or strike or other labor disruption at one of our manufacturing partners or locations or at shipping ports or locations, would severely affect sales of our product lines manufactured by that manufacturing partner. Furthermore, manufacturing cost increases for any reason could result in lower gross margins.

Our proprietary ASICs, which are key to the performance of our appliances, are built by contract manufacturers including Renesas and Toshiba America. These contract manufacturers use foundries operated by TSMC or Renesas on a purchase-order basis, and these foundries do not guarantee their capacity and could delay orders or increase their pricing. Accordingly, the foundries are not obligated to continue to fulfill our supply requirements, and due to the long lead time that a new foundry would require, we could suffer inventory shortages of our ASIC as well as increased costs. In addition to our proprietary ASIC, we also purchase off-the-shelf ASICs or integrated circuits from vendors for which we have experienced, and may continue to experience, long lead times. Our suppliers may also prioritize orders by other companies that order higher volumes or more profitable products. If any of these manufacturers materially delays its supply of ASICs or specific product models to us, or requires us to find an alternate supplier and we are not able to do so on a timely and reasonable basis, or if these foundries materially increase their prices for fabrication of our ASICs, our business would be harmed.

In addition, our reliance on third-party manufacturers and foundries limits our control over environmental regulatory requirements such as the hazardous substance content of our products and therefore our ability to ensure compliance with the Restriction of Hazardous Substances Directive (the “EU RoHS”) adopted in the European Union (the “EU”) and other similar laws. It also exposes us to the risk that certain minerals and metals, known as “conflict minerals”, that are contained in our products have originated in the Democratic Republic of the Congo or an adjoining country. As a result of the passage of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank”), the Securities and Exchange Commission (the “SEC”) adopted disclosure requirements for public companies whose products contain conflict minerals that are necessary to the functionality or production of such products. Under these rules, we are required to obtain sourcing data from suppliers, perform supply chain due diligence, and file annually with the SEC a specialized disclosure report on Form SD covering the prior calendar year. We have incurred and expect to incur additional costs to comply with the rules, including costs related to efforts to determine the origin, source and chain of custody of the conflict minerals used in our products and the adoption of conflict minerals-related governance policies, processes and controls. Moreover, the implementation of these compliance measures could adversely affect the sourcing, availability and pricing of materials used in the manufacture of our

29

Table of Contents

products to the extent that there may be only a limited number of suppliers that are able to meet our sourcing requirements, which would make it more difficult to obtain such materials in sufficient quantities or at competitive prices. We may also encounter customers who require that all of the components of our products be certified as conflict-free. If we are not able to meet customer requirements, such customers may choose to not purchase our products, which could impact our sales and the value of portions of our inventory.

Because some of the key components in our products come from limited sources of supply, we are susceptible to supply shortages, long lead times for components, and supply changes, each of which could disrupt or delay our scheduled product deliveries to our customers, result in inventory shortage, cause loss of sales and customers or increase component costs resulting in lower gross margins and free cash flow.

We and our contract manufacturers currently purchase several key parts and components used in the manufacture of our products from limited sources of supply. We are therefore subject to the risk of shortages and long lead times in the supply of these components and the risk that component suppliers may discontinue or modify components used in our products. We have in the past experienced, and are currently experiencing, shortages and long lead times for certain components. Our limited source components for particular appliances and suppliers of those components include specific types of CPUs from Intel and AMD, network and wireless chips from Broadcom, Marvell, Qualcomm and Intel, and memory devices from Intel, Micron, ADATA, Toshiba, Samsung and Western Digital. We also may face shortages in the supply of the capacitors and resistors that are used in the manufacturing of our products. For example, the global chip shortage caused by the COVID-19 pandemic and other factors affecting manufacturing continues to affect the manufacturing capacity of us and our contract manufacturers. This shortage may persist for an indefinite period of time. The introduction by component suppliers of new versions of their products, particularly if not anticipated by us or our contract manufacturers, could require us to expend significant resources to incorporate these new components into our products. In addition, if these suppliers were to discontinue production of a necessary part or component, we would be required to expend significant resources and time in locating and integrating replacement parts or components from another vendor. Qualifying additional suppliers for limited source parts or components can be time-consuming and expensive.

Our manufacturing partners have experienced long lead times for the purchase of components incorporated into our products. Lead times for components may be adversely impacted by factors outside of our control such as global chip shortages, natural disasters and health emergencies such as earthquakes, fires, power outages, typhoons, floods, health pandemics and epidemics such as the COVID-19 pandemic, and manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars, such as the war in Ukraine, critical infrastructure attacks and other factors. Our reliance on a limited number of suppliers involves several additional risks, including:

•a potential inability to obtain an adequate supply of required parts or components when required;

•financial or other difficulties faced by our suppliers;

•infringement or misappropriation of our IP;

•price increases;

•failure of a component to meet environmental or other regulatory requirements;

•failure to meet delivery obligations in a timely fashion;

•failure in component quality; and

•inability to ship products on a timely basis.

The occurrence of any of these events would be disruptive to us and could seriously harm our business. Any interruption or delay in the supply of any of these parts or components, or the inability to obtain these parts or components from alternate sources at acceptable prices and within a reasonable amount of time, would harm our ability to meet our scheduled product deliveries to our distributors, resellers and end-customers. This could harm our relationships with our channel partners and end-customers and could cause delays in shipment of our products and adversely affect our results of operations. In addition, increased component costs could result in lower gross margins.

30

Table of Contents

We offer retroactive price protection to certain of our major distributors, and if we fail to balance their inventory with end-customer demand for our products, our allowance for price protection may be inadequate, which could adversely affect our results of operations.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2022-12-31, filed 2023-02-24 · accession 0001262039-23-000010

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 22 headings are on that chain and 15 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.