Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

OSPN US Equity

OneSpan Inc.Information Technology · Services-Computer Integrated Systems Design · CIK 1044777 · FY ends Dec 31
$15.73
+0.14 (+0.90%)
USD · as of 2026-08-21 · marketstack

OSPN · 10-K · period ended 2022-12-31

← all OSPN documents
filed 2023-02-28 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1458 of 1,478343k characters rendered

ospn-20221231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

_____________________________________

FORM 10-K

FOR ANNUAL AND TRANSITION REPORTS PURSUANT TO

SECTIONS 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

(Mark One)

xANNUAL REPORT PURSUANT TO SECTION 13 OR 15(D) OF THE SECURITIES EXCHANGE ACT OF 1934 FOR THE FISCAL YEAR ENDED DECEMBER 31, 2022

or

oTRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 FOR THE TRANSITION PERIOD FROM TO

Commission file number 000-24389

OneSpan Inc.

(Exact Name of Registrant as Specified in Its Charter)

121 West Wacker Drive, Suite 2050

Chicago,Illinois60601

(Address of Principal Executive Offices)(Zip Code)

Registrant’s telephone number, including area code:

312-766-4001

Securities registered pursuant to Section 12(b) of the Act:

Title of each class Trading Symbol Name of exchange on which registered

Common Stock, par value $.001 per share OSPN NASDAQ Capital Market

Securities registered pursuant to Section 12(g) of the Act:

None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined by Rule 405 of the Securities Act. Yes oNox

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or 15(d) of the act. Yes oNox

Indicate by check mark whether the registrant: (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yesx No o

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yesx No o

Indicate by check mark if disclosure of delinquent filers pursuant to Item 405 of Regulation S-K is not contained herein, and will not be contained, to the best of registrant’s knowledge, in definitive proxy or information statements incorporated by reference in Part III of this Form 10-K or any amendment to this Form 10-K. o

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See definition of “large accelerated filer,” “accelerated filer”, “smaller reporting company”, and “emerging growth company” in Rule 12b-2 of the Exchange Act.

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards pursuant to Section 13(a) of the Exchange Act. o

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. x

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. o

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). o

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes o No x

As of June 30, 2022, the aggregate market value of voting and non-voting common equity (based upon the last sale price of the common stock as reported on the NASDAQ Capital Market on June 30, 2022) held by non-affiliates of the registrant was $471,211,321 at $11.90 per share.

As of February 25, 2023, there were 40,001,325 shares of common stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Certain sections of the registrant’s Notice of Annual Meeting of Stockholders and Proxy Statement for its 2023 Annual Meeting of Stockholders are incorporated by reference into Part III of this report.

Auditor Name: KPMG LLP Auditor Location: Chicago, IL Auditor Firm ID: 185

OneSpan Inc.

Annual Report on Form 10-K

For the Year Ended December 31, 2022

TABLE OF CONTENTS

PAGE

PART I

Item 1. Business 1

Item 1A. Risk Factors 10

Item 1B. Unresolved Staff Comments 30

Item 2. Properties 30

Item 3. Legal Proceedings 30

Item 4. Mine Safety Disclosures 31

PART II

Item 6. [Reserved] 33

Item 7A. Quantitative and Qualitative Disclosures About Market Risk 51

Item 8. Financial Statements and Supplementary Data 52

Item 9A. Controls and Procedures 52

Item 9B. Other Information 53

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspection 54

PART III

Item 10. Directors, Executive Officers and Corporate Governance 54

Item 11. Executive Compensation 54

Item 14. Principal Accounting Fees and Services 55

PART IV

Item 15. Exhibits, Financial Statement Schedules 55

CONSOLIDATED FINANCIAL STATEMENTS AND SCHEDULE F-1

Cautionary Note Regarding Forward-Looking Statements

This Annual Report on Form 10-K contains forward-looking statements within the meaning of applicable U.S. securities laws, including statements regarding the outcomes we expect from our strategic transformation plan; expected results of the investments we are making in sales, marketing, and product development; our plans for managing our Digital Agreements and Security Solutions segments; expectations regarding our ability to attract new customers and retain existing customers; efficiency, functionality and other expectations for our next-generation transaction-cloud platform; the timing for general availability of new or enhanced products, including Digipass CX; our expectations regarding our use of technology acquired in our ProvenDB acquisition or other acquisitions we may complete in the future; the expectation that software as a service, or SaaS, will constitute an increasingly important part of our business in the future; the potential benefits, performance and functionality of our products and solutions, including future offerings; future plans or trends in sales and marketing, research and development, and general and administrative expenditures; expectations regarding sources and uses of cash; plans to expand our salesforce and distribution channels; the impact of foreign currency exchange rate fluctuations; the impact of inflation; trends in microprocessor or other costs affecting our Digipass business; the effects of supply chain disruptions; plans or expectations for inventory management in our Digipass business; impacts of macroeconomic conditions or geopolitical conflict; trends in hiring or compensation costs or in gender diversity at our company; and our general expectations regarding our operational or financial performance in the future. Forward-looking statements may be identified by words such as "seek", "believe", "plan", "estimate", "anticipate", “expect", "intend", "continue", "outlook", "may", "will", "should", "could", or "might", and other similar expressions. These forward-looking statements involve risks and uncertainties, as well as assumptions that, if they do not fully materialize or prove incorrect, could cause our results to differ materially from those expressed or implied by such forward-looking statements. Factors that could materially affect our business and financial results include, but are not limited to: our ability to execute our strategic transformation plan; our ability to attract new customers and retain and expand sales to existing customers; our ability to effectively develop and expand our sales and marketing capabilities; our ability to hire, train, and retain sales and other employees necessary to implement our strategic transformation plan; our ability to successfully develop and market new product offerings and product enhancements; the loss of one or more large customers; difficulties enhancing and maintaining our brand recognition; competition; lengthy sales cycles; departures of senior management or other key employees; changes in customer requirements; interruptions or delays in the performance of our products and solutions; real or perceived malfunctions or errors in our products; the potential effects of technological changes; economic recession, inflation, and political instability; the impact of the COVID-19 pandemic and actions taken to contain it; our ability to effectively manage third party partnerships, acquisitions, divestitures, alliances, or joint ventures; security breaches or cyber-attacks; claims that we have infringed the intellectual property rights of others; price competitive bidding; changing laws, government regulations or policies; pressures on price levels; component shortages; delays and disruption in global transportation and supply chains; reliance on third parties for certain products and data center services; impairment of goodwill or amortizable intangible assets causing a significant charge to earnings; actions of activist stockholders; and exposure to increased economic and operational uncertainties from operating a global business, as well as other factors described in the “Risk Factors” section of this Form 10-K.Our filings with the Securities and Exchange Commission (the “SEC”) and other important information can be found in the Investor Relations section of our website at investors.onespan.com. We do not have any intent, and disclaim any obligation, to update the forward-looking information to reflect events that occur, circumstances that exist or changes in our expectations after the date of this Form 10-K, except as required by law.

PART I

Item 1 – Business

Overview

OneSpan helps organizations accelerate digital transformations by enabling secure, compliant, and refreshingly easy digital customer agreements and transaction experiences. We deliver digital agreement products and services that automate and secure customer-facing and revenue-generating business processes. Our solutions help organizations streamline and secure user experiences, which in turn allows them to drive growth, reduce risk, and unlock their business potential.

We are a global leader in providing high-assurance identity and authentication security as well as enterprise-grade electronic signature (e-signature) solutions, for use cases ranging from simple transactions to workflows that are complex or require higher levels of security. Our solutions help our clients ensure the integrity of the people and records associated with digital agreements, transactions, and interactions in industries including banking, financial services, healthcare, and professional services. We are trusted by global blue-chip enterprises, including more than 60% of the world’s largest 100 banks, and process millions of digital agreements and billions of transactions in more than 100 countries annually.

Our solutions are powered by a portfolio of products and services across identity verification, authentication, virtual interactions and transactions, and secure digital storage. These products and services can be acquired and embedded individually within enterprise business workflows or assembled into tailored solutions for simple yet secure business-to-business, business-to-employee, and business-to-customer experiences.

We offer our solutions through cloud-based and, in select cases, on-premises solutions using both open standards and proprietary technologies. We offer our products primarily through a subscription licensing model. Our solutions are sold worldwide through our direct sales force, as well as through distributors, resellers, systems integrators, and original equipment manufacturers.

Business Transformation

We are currently in the midst of a business transformation. Our total revenue decreased on a year-over-year basis in 2020 and 2021, and we experienced negative operating income and net losses in both of those years. During 2021 and early 2022, our previous CEO, CFO, and several other senior executives left the company. In late November 2021, our current CEO joined us and has built a new executive team over the course of 2022 to effect the transformation.

In May 2022, we announced a three-year strategic transformation plan that began on January 1, 2023. We believe this transformation plan will enable us to build on our strong solution portfolio and market position, enhance our enterprise go-to-market strategy, accelerate revenue growth, and drive efficiencies to support margin expansion and increased profitability. In conjunction with the strategic transformation plan and to enable a more efficient capital deployment model, effective with the quarter ended June 30, 2022, we began reporting under the following two lines of business, which are our reportable operating segments: Digital Agreements and Security Solutions.

•Digital Agreements. Digital Agreements consists of solutions that enable our clients to secure and automate business processes associated with their digital agreement and customer transaction lifecycles that require consent, non-repudiation and compliance. These solutions, which are largely cloud-based, include our OneSpan Sign e-signature solution and our recently introduced OneSpan Notary and Virtual Room solutions.. As our transformation plan progresses, we expect to include other cloud-based security modules associated with the secure transaction lifecycle of identity verification, authentication, virtual interaction and transactions, and secure digital storage in the Digital Agreements segment. This segment also includes costs attributable to our transaction-cloud platform.

•Security Solutions. Security Solutions consist of our broad portfolio of software products and/or software development kits (SDKs) that are used to build applications designed to defend against attacks on digital transactions across online environments, devices and applications. These solutions, which are largely on-premises software products, include identity verification, multi-factor authentication and transaction signing, such as mobile application security, mobile software tokens, and Digipass authenticators that are not cloud connected devices.

1

We expect to manage Digital Agreements for accelerated growth and market share gains and Security Solutions for cash flows given its more modest growth profile. Across both segments, we plan to build on our strong foundation in both e-signature and cybersecurity by enhancing product features, developing new solutions, and building out our next-generation transaction cloud platform, which we expect will allow us to efficiently deliver security and e-signature solutions to our customers across their entire digital agreement lifecycle. We also plan to enhance our go-to-market strategy by prioritizing growth at large enterprise accounts, expanding our direct sales force, and accessing new routes to market through alliances and partnerships.

Our transformation plan involves numerous risks and uncertainties. Please see Item IA, Risk Factors.

Industry Background

While digital transformation and the shift to cloud-delivered experiences across all industries has helped increase the pace of innovation and business execution, it has also increased security risks for organizations, their customers, and their employees. People and records associated with business interactions, transactions, and agreements have become the biggest attack surface, or point of vulnerability, to cyber-attacks.

Today’s cybersecurity bad actors are more sophisticated and well-resourced, which means that enterprises everywhere are confronted with security threats on all fronts, from identity fraud and firewall breaches to nation-state espionage. Without secure and enforceable business processes and outcomes, economies everywhere are vulnerable. However, current security measures are typically at odds with the pressure for organizations to drive growth and support increasing customer expectations for frictionless user experiences.

For high-value transactions and agreements that have shifted to digital workflows, these challenges are amplified due to the fragmented legal requirements, regulatory rules, and complexity associated with doing business across state and national borders. In addition to automating and securing these digital workflows, cross-border identity verification, data privacy, and sovereignty regulations vary from one jurisdiction to the next, complicating compliance for organizations operating globally.

We believe that these trends will continue to accelerate and evolve, creating a unique opportunity for OneSpan to leverage its global security roots to deliver technology that enables frictionless customer experiences, with security seamlessly interwoven throughout every action and interaction. OneSpan is uniquely positioned to help organizations deliver the simple and intuitive experiences their customers demand today, while preparing them for the security challenges of tomorrow.

Our Products and Services Portfolio

We offer a portfolio of products and solutions to enable secure, compliant and refreshingly easy customer interactions and transactions. Whereas other companies provide point solutions for either security or digital agreements, we support the entire lifecycle of digital agreements for global enterprises that need to meet the highest levels of assurance, security, and compliance, all while using a human-centric approach that minimizes friction for customers. Our portfolio spans across the stages of the digital agreement process:

•Verify – Identity Proofing and Verification: Establish a relationship with your customer, starting with knowing who they are.

•Authenticate – User Authentication: Protect yourself and your customer’s identity with strong customer authentication.

•Interact – Virtual Room: Connect and collaborate with your customers in a secure, virtual environment.

•Transact – E-Sign: Sign transactions and agreements remotely and securely.

•Store – Secure Vaulting: Complete the digital agreement process by securely storing transaction records and documentation.

Since June 30, 2022, we have reported our financial results under two operating segments: Digital Agreements and Security Solutions. The products and services that currently fall under each segment are shown below; however, as our transformation plan progresses and we deliver more of our products and services through our next-generation transaction- cloud platform, we expect to include other cloud-based security modules across the digital agreements lifecycle in the Digital Agreements segment.

2

Digital Agreements

OneSpan Sign supports a broad range of e-signature requirements from simple to complex, and from the occasional agreement to processing tens of thousands of transactions. OneSpan Sign provides multiple deployment options, including public cloud or private cloud, without compromising security or functionality. The solution is also available in a Federal Risk and Authorization Management Program (FedRAMP) SaaS-level compliant cloud, allowing U.S. government agencies to implement e- signatures in the cloud and meet General Services Administration (GSA) security requirements.

Customers can configure OneSpan Sign to reinforce their brand for a seamless signing experience. Each step of the digital agreement workflow can be customized, from authentication to e-signing and secure storage. OneSpan Sign also provides comprehensive and secure electronic evidence for strong legal protection by capturing all actions that took place during the agreement process. This reduces the time and cost of gathering evidence and demonstrating legal and regulatory compliance. Electronic signature capabilities can be a critical component of the account opening and onboarding processes, providing a secure and user-friendly way to execute legally binding agreements.

Virtual Room is a purpose-built, high-assurance solution that blends the simplicity of a consumer video collaboration app with high-assurance identity and authentication security. OneSpan’s secure Virtual Room cloud service enables organizations to deliver live, high-touch assistance to their customers in a secure virtual environment. This next-generation customer engagement solution gives organizations the ability to combine identity verification, authentication, and e-signature solutions from the broader OneSpan portfolio with a high-assurance virtual experience that removes the friction of entering a branch or meeting in person. In addition, robust audit and compliance controls help manage risk and meet regulatory requirements.

OneSpan Notary is the newest addition to the OneSpan product portfolio that spans the entire digital agreements lifecycle from identifying an unknown signer all the way to securely storing an agreement and associated assets. Developed for organizations with in-house notaries, OneSpan Notary includes live electronic signature, two-way secured videoconferencing, and strong identity proofing options, like ID Verification and Knowledge-based Authentication (KBA). It also simplifies the notarization process with guided workflows, the ability to upload eNotary Seal, recording, eJournaling, and audit trail capabilities in a single solution.

Digipass CX is OneSpan’s latest family of cloud-connected high-assurance identity verification and authentication devices designed to increase security, minimize fraud, and simplify the user experience. These new devices rely on biometrics rather than one-time passwords which can be stolen via social engineering. Because these devices are connected to the cloud, they can be dynamically provisioned, reprovisioned, and even updated to incorporate new features and applications as they become available in the future. We plan for the first two Digipass CX models to be generally available later in 2023.

Secure Storage is a new addition to the OneSpan product portfolio through the first quarter 2023 acquisition of ProvenDB. OneSpan plans to integrate the ProvenDB Compliance Vault technology obtained through the acquisition to add blockchain-backed secure storage initially for the OneSpan Sign product and eventually across the entire portfolio. This new secure storage capability is designed for high-value, high-risk use-cases by providing tamper resistant document storage supported by immutable compliance data, all protected by blockchain technology.

Security Solutions

OneSpan Identity Verification gives banks and other financial institutions access to a wide range of identity verification services – all through a single API integration. This includes identity document (e.g., driver’s license, passport, etc.) capture and real-time authenticity verification, as well as facial comparison (“selfie”) and liveness detection (the ability to detect whether a digital interaction is with a live human being) to establish that the individual presenting the identity document is the same person whose picture appears on the authenticated identity document.

OneSpan Cloud Authentication is a quick-to-deploy, cloud-based multifactor authentication solution that supports a full range of authentication options including biometrics, push notification, visual cryptograms for transaction data security, SMS, and hardware authenticators. This allows customers to solve strong authentication problems across different endpoints to best meet their unique requirements through a single provider rather than integrating multiple modalities together. It eliminates cost associated with managing legacy on-premises authentication technology and

3

provides a seamless upgrade path to more comprehensive capabilities such as Intelligent Adaptive Authentication, which applies a precise level of security for each unique customer interaction using advanced real-time risk analysis and scoring.

Mobile Security Suite is a comprehensive software development kit that helps protect mobile transactions from bad actors by allowing organizations to natively integrate security features including geolocation, device identification, jailbreak and root detection, fingerprint and face recognition, one-time password delivery via push notification, and transaction data security, among others. Through a comprehensive library of APIs, application developers can extend and strengthen application security, deliver enhanced convenience to their application users, and streamline application deployment and lifecycle management processes. Mobile Security Suite also includes a Runtime Application Self-Protection module, which can detect and mitigate malicious app activity and potential loss to hacking activities.

Authentication Server resides on-premises and incorporates a range of strong authentication utilities and solutions designed to allow organizations to securely authenticate users and transactions. The solution, once integrated, becomes largely transparent to users, minimizing rollout and support issues. Authentication Server encompasses multiple authentication technologies (e.g., passwords, dynamic password technologies, certificates, and biometrics) and allows the use of any combination of those technologies simultaneously.

Digipass Authenticators are our family of hardware authenticators, consisting of a wide variety of authentication devices, each of which has its own distinct characteristics to meet the needs of our customers. All models of the Digipass family of authenticators are designed to work together so customers can switch devices without changes to their existing infrastructure. Our models range from one-button devices and smart card readers to devices that include more advanced technologies, such as public key infrastructure (PKI) and visual cryptography. Digipass devices included in the Security Solutions segment are not cloud-connected, in contrast to our cloud-connected Digipass CX device, which we expect to include in the Digital Agreements segment.

Intellectual Property and Proprietary Rights and Licenses

We rely on a combination of patent, copyright, trademark, design, and trade secret laws, as well as employee and third-party non-disclosure agreements to protect our intellectual property, or IP, and other proprietary rights. In particular, we hold several patents in the U.S. and in other countries, which cover multiple aspects of our technology. These patents expire between 2023 and 2040. In addition to the issued patents, we also have several patent applications pending in the U.S., Europe, and other countries. Many of our issued and pending patents are related to our Digipass product line. In addition to our owned IP, we license software from third parties for integration into our solutions, including open-source software and other software available on commercially reasonable terms.

We furthermore have registrations for most of our trademarks in most of the markets where we sell the corresponding products and services, as well as registrations of the designs of many of our hardware products, primarily in the European Union (EU) and China.

Protecting IP rights can be difficult, particularly in countries that provide less protection to IP rights and in the absence of harmonized international IP standards. Competitors and others may already have IP rights covering similar products. We may not be able to secure IP rights covering our own products or may have difficulties obtaining IP licenses from other companies on commercially favorable terms. For a discussion of IP-related risks, see Item IA, Risk Factors.

Research and Development

Our research and development efforts are focused primarily on enhancing our solutions by building new features, functionality, and applications; developing technology to support new products; enhancing our next-generation transaction- cloud platform; and conducting product and quality assurance testing. We employ a team of full-time engineers and, from time to time, also engage independent engineering firms to conduct certain product development efforts on our behalf. For fiscal years ended December 31, 2022, 2021, and 2020, we incurred expenses, net of software capitalization, of $41.7 million, $47.4 million, and $41.2 million, respectively, for research and development.

Production

Our Digipass authentication devices are manufactured by third-party manufacturers pursuant to purchase orders that we issue. The majority of our Digipass products are manufactured by four independent factories in Southern China and one in Romania. We maintain local teams in China and Romania to conduct quality control and quality assurance

4

procedures. Periodic visits are conducted by our personnel for quality management, assembly process review, and supplier relations.

Digipass devices are made primarily from commercially available electronic components, including microprocessors purchased from several suppliers. We purchase microprocessors and arrange for shipment to third parties for assembly and testing in accordance with our design specifications. The microprocessors are the most important components of the devices which are not commodity items readily available on the open market.

During 2022, the supply chain for our Digipass devices was impacted by global issues related to the effects of the COVID-19 pandemic, the Russia-Ukraine conflict and the inflationary cost environment, particularly with respect to materials in the semiconductor market, including part shortages, increased freight costs, diminished transportation capacity and labor constraints. This has resulted in disruptions in our supply chain, as well as difficulties and delays in procuring certain microprocessors. Since late 2021, our costs have increased due to elevated lead times and increased material costs, in particular the need to purchase microprocessors from alternative sources. We expect increased costs to procure materials within the semiconductor market to continue in 2023. Further, we anticipate that the broader impact of inflationary pressures, increased material costs, and supply chain disruptions may continue in 2023.

In response to these supply chain conditions, in 2022 we focused on improving our supplier network, engineering alternative designs, and working to reduce supply shortages. We are actively managing our inventory in an effort to minimize supply chain disruptions and enable continuity of supply and services to our customers, and we may maintain elevated levels of inventory for certain of our products until supply constraints have been remediated. We are also considering alternative manufacturing and supply arrangements, including moving more of our manufacturing from China to Romania or other locations, to mitigate supply chain risks in the future.

Our software solutions are produced in-house or developed by third parties and sold under license.

Competition

The market for digital solutions for identity, authentication, and secure digital agreements is very competitive and, like most technology-driven markets, is subject to rapid change and constantly evolving solutions and services. Our identity verification and authentication products are designed to allow authorized users access to digital business processes and properties, in some cases using patented technology, as a replacement for or supplement to a static password. Our main competitors in our identity verification and authentication markets are Gemalto, a subsidiary of Thales Group, and RSA Security. There are also many other companies, such as Transmit Security, Symantec, and Duo Security, that offer competing services.

In addition to these companies, we face competition from many small authentication solution providers, many of whom offer new technologies and niche solutions such as biometric or risk and behavioral analysis. We believe that competition in this market is likely to intensify as a result of increasing demand for security products.

Our primary competitors for electronic signature solutions are DocuSign and Adobe Systems. Both companies are significantly larger than us. In addition to these companies, there are numerous smaller and regional or niche providers of electronic signing solutions.

We believe that the principal competitive factors affecting the market for digital solutions for identity, security, and electronic signatures include the strength and effectiveness of the solution, technical features, ease of use, quality and reliability, customer service and support, brand recognition, customer base, distribution channels, and the total cost of ownership of the solution. Although we believe that our products currently compete favorably with respect to most of these factors, we may not be able to maintain our competitive position against current and potential competitors. Some of our present and potential competitors have significantly greater financial, technical, marketing, purchasing, and other resources. As a result, they may be able to respond more quickly to new or emerging technologies and changes in customer requirements, or to devote greater resources to the development, promotion and sale of products, or to deliver competitive products at a lower end-user price. Please see Item IA, Risk Factors.

Sales and Marketing

Our solutions are sold worldwide through our direct sales force as well as through distributors, resellers, systems integrators, and original equipment manufacturers. Our sales staff coordinates sales activity through both our sales channels

5

and those of our partners, making direct sales calls either alone or with the sales personnel of our partners. Our sales staff also provides product education seminars to sales and technical personnel of resellers and distributors, with whom we have working relationships, and to potential end users of our products.

As part of our three-year strategic plan, we are enhancing our go-to-market strategy in several ways, including: shifting to a unified sales force that sells across our full solution portfolio (rather than separate sales forces for e-signature and security solutions); prioritizing growth at large enterprise accounts; expanding our direct sales force; and accessing new routes to market through alliances and partnerships. Our expanded selling effort also includes identifying additional applications for our solutions, cross-selling our products to existing enterprise customers, and selling our full portfolio into new market segments and additional geographic markets.

CustomersandMarkets

The majority of our revenue is derived from financial institutions, which include traditional banks, credit unions, and online-only banks. We also sell to the enterprise market segment, government, healthcare, and insurance industries in select regions around the globe. We believe there are substantial opportunities for future growth, both within the market segments we currently serve and in new market segments, as we expand our product portfolio and go-to-market strategy.

Our top 10 customers contributed 23%, 22%, and 21% in 2022, 2021, and 2020, respectively, of our total worldwide revenue.

Because a significant portion of our sales is denominated in foreign currencies, changes in exchange rates impact results of operations. To mitigate exposure to risks associated with fluctuations in currency exchange rates, we attempt to denominate an amount of billings in a currency such that it would provide a hedge against operating expenses being incurred in that currency. For additional information regarding how currency fluctuations can affect our business, please refer to Item 7, Management’s Discussion and Analysis of Financial Condition and Results of Operations.

We also experience seasonality or variation across the year in our markets. These trends can include lower sales during the summer months, particularly in Europe.

Financial Information Relating to Foreign and Domestic Operations

For financial information regarding OneSpan, see our consolidated financial statements and the related notes, which are included in Part IV of this Annual Report on Form 10-K. See Note 17, Geographic, Customer and Supplier Information in the notes to consolidated financial statements for a breakdown of revenue, gross profit and long-lived assets between the U.S. and other regions.

Government Regulation

As a global cybersecurity company, we are subject to complex and evolving global regulations in the various jurisdictions in which our products and services are used. Also, because banking and financial services is our largest industry target market, the government regulations affecting our customers in this area have a significant indirect effect on our business. Similar regulatory dynamics occur in the other primary markets where we have customers, such as healthcare and government. Additional proposed or new legislation and regulations could also significantly affect our business.

See Item IA, Risk Factors, for additional information about the laws and regulations we are subject to and the risks to our business associated with those laws and regulations.

Human Capital

OneSpan is powered by a team of approximately 790 employees that spans the globe, consisting of approximately 300 employees in Canada, 292 in Europe, 27 in the Middle East and Latin America, 134 in the United States, and 37 in the Asia Pacific Region. As of December 31, 2022, approximately 309 of our employees were in research and development, 338 in sales and marketing, and 143 in general and administrative.

We are currently in the early stages of a business transformation that we believe will disrupt our industry by securing the digital agreements process while taking a human-centric approach to end-user experience. We understand that

6

achieving this ambitious goal will depend primarily on the skills, creativity, and determination of our people, and we believe that people do their best work in an environment built on a compelling shared purpose, openness, trust, mutual accountability, and the opportunity to make a meaningful impact.To that end, our human capital objectives are built on the following five pillars, which we refer to as our “People Promise”:

•Now is the time. With a bold vision and an ambitious market opportunity, we are ready to seize the moment. There’s never been a better time to join the team and play a part in the OneSpan story.

•Start from openness. We lead with transparency, engage with open minds, and promote diversity in our thinking and in our culture. That’s why we encourage each of our people to bring their whole self to work and be open to different ideas, new challenges, and new possibilities.

•Build it on trust. Real connections and true collaboration are built on trust. We trust each other and have no time for internal politics. We trust our people to always to bring their best. We trust ourselves to take chances and to build something bigger – together.

•Own it. We believe in empowerment through freedom: giving our people flexibility and enabling them to carve their path, their way. We don’t just ask our team to embrace change; we ask them to own it.

•Make a global impact. We challenge the now by thinking ahead, speaking up, and working together to constantly improve. Everyone is an integral part of the work we do with an equal opportunity to participate and make a global impact.

The goal of our People Promise is to create an environment that will attract, retain and develop talented people who are motivated to find opportunities and create new possibilities for our customers, for themselves and their teams, and for OneSpan. To achieve this goal, we focus on the areas described below.

Competitive Compensation and Benefits. We seek to provide our employees with competitive and fair compensation and benefit offerings, and use market benchmarks to ensure external competitiveness while maintaining equity within the organization. We tie incentive compensation to both business and individual performance and provide a range of health, wellness, family leave, savings, retirement, and time-off benefits for our employees, which vary based on local regulations and norms.

Engagement. We regularly request input from employees, including through a broad employee engagement survey conducted annually and through more frequent, “pulse” surveys. These surveys are intended to measure our progress in promoting an environment where employees are engaged, productive, and have a strong sense of belonging. As part of our commitment to acting on employee input, we also use survey results to identify areas where we can do better and expect our managers to actively work to improve those areas.

Hybrid Workplace Policy. For our employees who live near one of our offices, we have adopted a hybrid work model whereby employees generally come to the office in person once a week, on a day designated by local office leadership. For the rest of the week, employees may work either remotely or from their local office. We believe this approach maintains the flexibility of remote work while also providing a regular opportunity for in-person interactions to collaborate, innovate, and build relationships with colleagues.

Diversity and Inclusion. With approximately 790 employees around the world and customers in more than 100 countries, we understand the importance of diversity in perspectives, experience, backgrounds and cultures. As part of our efforts to encourage diversity and inclusion, all employees take an annual diversity and inclusion training and an unconscious bias training. We also work with diversity focused job sites and candidate application platforms to increase access to diverse talent. In addition, we have an active employee resource group, Women at OneSpan, focused on providing support, mentoring and other resources for our female employees, and are beginning the process of making other employee resource groups available to interested employees.

We monitor the gender diversity of our workforce regularly. We measure gender diversity overall, by job level, and by job category. As of December 31, 2022, approximately 31% of our employees identified as female, up from 27% at the end of 2021. The percentage of women in all job levels and categories also improved year over year. Although our gender diversity metrics may fluctuate from period to period, over the longer term, we hope and expect to see continued improvement in the representation of women across the company.

7

We are also proud of the strides we have made during 2022 in the diversity of our executive leadership team. As a result of new management hires during 2022, more than half of our 13-person executive team identifies as female, LGBTQ, and/or a person of color, which represents significant progress as compared to the prior year.

Training and Talent Development. We promote and support employee development, compliance and organizational effectiveness by providing compliance training and professional development programs. All of our employees take a required annual training on the following topics: our code of conduct and ethics; cybersecurity; diversity and inclusion; and preventing sexual harassment. In addition, in 2022, we added a training on psychological safety at work, which covers ways managers and employees can promote an open, trusting and non-judgmental environment that promotes creativity and the free exchange of ideas.

Feedback and Coaching. We believe regular feedback is an integral component of employee development, and that creating a culture of ongoing performance coaching is critical to our success. To that end, we conduct quarterly coaching sessions, where each employee is evaluated by their personal manager. Employee performance is assessed in significant part based on the achievement of goals set collaboratively by the employee and their manager.We also encourage managers to provide ongoing feedback and performance coaching to their direct reports, and to solicit their teams’ feedback on their own performance.

Employee Recognition. We regularly recognize our employees for driving business results and exemplifying our company values. We believe that these recognition programs help drive strong employee performance. Employees also have access to an internal communications channel to recognize their peers for their contributions to the company.

Community Outreach and Support. We believe it is important to promote community outreach through corporate giving and employee volunteerism in the communities where we live and work. We provide each employee with one paid day off each year to participate in volunteer activities of their choice. Beginning in mid-2023, we plan to launch a global social impact platform that will help our employees to find volunteer opportunities and collaborate with colleagues on social impact efforts.

Monitoring our Progress

We monitor our progress toward the goal of our People Promise by tracking the following metrics:

•Employee Survey Results. As discussed above under “Engagement”, we conduct a comprehensive employee engagement survey annually, and compare results for each survey question from year to year.

•Employee Turnover. We monitor attrition, voluntary turnover, and total turnover, as a whole and by tenure, region, and by job family. Attrition captures all reasons employees leave, including voluntary turnover and involuntary turnover due tojob eliminations or performance reasons, whereas voluntary turnover is limited to elective departures by employees. Total turnover is the sum of attrition plus voluntary turnover. Our voluntary turnover across our global employee base in 2022 was 16%, which we believe compares favorably with global turnover rates in the technology industry.

•Diversity. As discussed above under “Diversity and Inclusion”, we measure gender diversity at least annually overall, by geography, by job role, and by job level. We also monitor the racial and ethnic diversity of our U.S.-based employees, to the extent that our employees disclose their race and ethnicity to us.

Corporate Information

Our predecessor company, VASCO Corp., entered the data security business in 1991 through the acquisition of a controlling interest in ThumbScan, Inc., which we renamed VASCO Data Security, Inc. In 1997, VASCO Data Security International, Inc. was incorporated and in 1998, we completed a registered exchange offer with the holders of the outstanding securities of VASCO Corp., thereby becoming a publicly traded company. In May 2018, VASCO Data Security International, Inc., our publicly traded parent company, changed its name to OneSpan Inc.

Including our predecessor companies, we have completed 17 acquisitions and two dispositions since our inception, including the 2013 acquisition of Cronto Limited, a provider of secure visual transaction authentication solutions

8

for online banking, and the 2015 acquisition of Silanis Technology Inc., a provider of e-signature and digital transaction solutions which we now market and sell under the OneSpan Sign name.

Our principal executive offices are located at 121 West Wacker Drive, Suite 2050, Chicago, IL 60601.

“OneSpan” and other trademarks, trade names or service marks of OneSpan Inc. or its subsidiaries appearing in this Annual Report on Form 10-K are the property of OneSpan Inc. or its appliable subsidiary. This Annual Report on Form 10-K may contain additional trade names, trademarks and service marks of others, which are the property of their respective owners. Solely for convenience, trademarks and trade names referred to in this Annual Report on Form 10-K may appear without the ® or TM symbols.

Available Information

We maintain an Internet website at www.onespan.com. The information on, or that can be accessed through, our website is not incorporated by reference into this Annual Report on Form 10-K and should not be considered to be a part of this Annual Report on Form 10-K. Our website address is included in this Annual Report on Form 10-K as inactive textual reference only. Our reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (Exchange Act), including our Annual Reports on Form 10-K, our Quarterly Reports on Form 10-Q and our Current Reports on Form 8-K, and amendments to those reports, are accessible through our website, free of charge, as soon as reasonably practicable after these reports are filed electronically with, or otherwise furnished to, the Securities and Exchange Commission, or the SEC. We also make available on our website the charters of our audit committee, compensation committee and nominating and corporate governance committee, as well as our corporate governance guidelines and our code of business conduct and ethics. In addition, we intend to disclose on our website any amendments to, or waivers from, our code of business conduct and ethics that are required to be disclosed pursuant to SEC rules.

Information about our Executive Officers

The following sets forth certain information with regard to each of our executive officers. There are no family relationships between any of the executive officers, and there is no arrangement or understanding between any executive officer and any other person pursuant to which the executive officer was selected.

MATTHEW P. MOYNAHAN — Mr. Moynahan has served as OneSpan’s President and Chief Executive Officer since November 2021 and as a director since June 2022. Before OneSpan, he was the Chief Executive Officer of Forcepoint LLC, a global provider of commercial and government cybersecurity solutions and a subsidiary of Raytheon Technologies Corporation, from May 2016 until its acquisition by Francisco Partners in January 2021. Prior to that, Mr. Moynahan served as President of Arbor Networks, a network security and monitoring software company and a subsidiary of Danaher Corporation, from January 2012 through May 2016, where he was responsible for building a large commercial cloud DDoS platform and network-based advanced threat protection systems, and as President and Chief Executive Officer of Veracode, Inc., a SaaS pioneer of cloud-based software security testing platforms, from April 2006 through May 2011. Earlier in his career, he served as Vice President of Symantec’s enterprise product management group, as well as Vice President and General Manager of its consumer division. Mr. Moynahan is 52 years old.

JORGE MARTELL— Mr. Martell has served as OneSpan’s Chief Financial Officer since September 2022. From July 2016 to September 2022, he served as Chief Financial Officer and Treasurer and from April 2015 to July 2016 as Vice President of Finance, Corporate Controller, at Extreme Reach Inc., a private-equity owned omnichannel creative logistics company for brand advertising, where he played an integral role in optimizing the company’s balance sheet and in executing the company’s growth strategy through global M&A, prior to its acquisition by another private equity firm. From September 2012 to March 2015, Mr. Martell was Treasurer and Assistant Corporate Controller at Sapient Corporation, a technology company, where he led its global revenue organization, execution of its M&A financial strategy, and global treasury organization prior to its acquisition by Publicis Groupe. Earlier in his career, Mr. Martell held leadership roles at ABM Industries, Inc., a provider of facilities management solutions, and at KPMG LLP, a public accounting firm. Mr. Martell is 44 years old.

LARA MATAAC — Ms. Mataac has served as OneSpan’s General Counsel, Chief Compliance Officer and Secretary since June 2022. From April 2021 to June 2022, Ms. Mataac was General Counsel at Constant Contact, Inc., a provider of cloud-based online marketing solutions, where she led the legal and compliance team during a period of transition after the company’s spinout from Endurance International Group (EIG) in February 2021. Before Constant Contact, Ms. Mataac was at EIG, a provider of cloud-based web presence and online marketing solutions, from February

9

2013 through March 2021, most recently as Deputy General Counsel. Before EIG, Ms. Mataac was corporate legal director at Bottomline Technologies, a software company. Earlier in her career, Ms. Mataac practiced corporate law at the firms Wilmer Cutler Pickering Hale & Dorr LLP and Fenwick & West LLP. Ms. Mataac is 46 years old.

Item 1A - Risk Factors

Risk Factors Summary

Our business is subject to numerous risks and uncertainties, including those highlighted in the section titled “Risk Factors” immediately following this Risk Factors Summary. These summary risks provide an overview of many of the risks we are exposed to in the normal course of our business, some of which have manifested and any of which may occur in the future. As a result, the following summary risks do not contain all of the information that may be important to you, and you should read them together with the more detailed discussion of risks set forth following this section under the heading “Risk Factors,” and with the other information in this Annual Report on Form 10-K. Additional risks beyond those summary risks discussed below, in “Risk Factors” or elsewhere in this Annual Report on Form 10-K, could have an adverse effect on our business, results of operations, financial condition or prospects, and could cause the trading price of our common stock to decline. Our business, results of operations, financial condition or prospects could also be harmed by risks and uncertainties not currently known to us or that we currently do not believe are material. Consistent with the foregoing, we are exposed to a variety of risks, including the following significant risks:

•Our strategic transformation plan involves numerous risks and may not achieve the results we expect.

•If we are unable to attract new customers and retain and expand sales to existing customers, we will be unable to grow our business.

•Failure to effectively develop and expand our sales and marketing capabilities, and particularly our ability to hire, train, and retain sales personnel, may have a material adverse effect on our ability to grow our business.

•If our new product offerings and product enhancements do not keep pace with the needs of our customers or do not achieve sufficient customer acceptance, our competitive position and financial results will be negatively impacted.

•A significant portion of our sales are to a limited number of customers. The loss of substantial sales to any one of them could have an adverse effect on revenues and profits.

•If we are not able to enhance our brand recognition and maintain our brand reputation, our business may be adversely affected.

•The market we serve is highly competitive, which may negatively affect our ability to add new customers, retain existing customers and grow our business.

•Our Digipass authenticator business is dependent on a limited number of suppliers, and the loss of their manufacturing capability, components and technology could materially impact our operations. Our Digipass business may also experience inventory-related losses.

•The sales cycle for our products is often long, and we may incur substantial expenses for sales that do not occur when anticipated or at all.

•If we are unable to successfully hire, train, and retain qualified personnel, we may be unable to achieve our business objectives. In addition, we are dependent on the continued services and performance of our senior management and other key employees, the loss of whom could adversely affect our business, operating results and financial condition.

•Security breaches or cyberattacks could expose us to significant liability, cause our business and reputation to suffer, and harm our competitive position.

•Real or perceived malfunctions and errors in our products could result in warranty and product liability risks and economic and reputational damages.

•We depend on third party hosting providers and other technology vendors, as well as our own infrastructure, to provide our products and solutions to our customers in a timely manner. Interruptions or delays in performance of our products and solutions could result in customer dissatisfaction, damage to our reputation, loss of customers, and a reduction in revenue.

•Our success depends in part on establishing and maintaining relationships with other companies to distribute our technology and products or to incorporate their technology into our products and services, or vice versa.

•We have operated at a loss for each of the past three years, and we may not be profitable in the future.

•Our financial results may fluctuate from period to period, making it difficult to project future results. If we fail to meet the expectations of securities analysts or investors, the price of our common stock could decline.

•We face a number of risks associated with our international operations, any or all of which could result in a disruption in our business and a decrease in our revenue.

10

•Acquisitions or other strategic transactions may not achieve the intended benefits or may disrupt our current plans and operations.

•We may be subject to legal proceedings for a variety of claims, including intellectual property disputes, labor and employment issues, commercial disagreements, securities law violations and other matters. These proceedings may be costly, subject us to significant liability, limit our ability to use certain technologies, increase our costs of doing business or otherwise adversely affect our business and operating results.

•We are subject to numerous laws and regulations and customer requirements governing the production, distribution, sale and use of our products. Any failure to comply with these laws, regulations and requirements could result in unanticipated costs and could have a materially adverse effect on our business, results of operations and financial condition.

Risk Factors

Our business involves significant risks, some of which are described below. You should carefully consider the following risks, some of which have manifested and any of which may occur in the future, together with all of the other information in this Annual Report on Form 10-K, including in the preceding Risk Factors Summary, and our consolidated financial statements and the related notes included elsewhere in this Annual Report on Form 10-K before making an investment decision with respect to any of our securities. .

Risks Related to our Business and Industry

Our strategic transformation plan involves numerous risks and may not achieve the results we expect.

In May 2022, we announced a three-year strategic transformation plan that began on January 1, 2023. Although we believe that this plan will enable to us accelerate revenue growth and increase profitability, we may not be successful in executing the plan on our expected timeframe or at all, or the plan may not achieve the results we expect, for a number of reasons, including the following:

•The assumptions we used in developing the plan, including assumptions regarding customer acquisition, customer retention, market needs, market opportunity size, and the impact of our marketing initiatives, may prove incorrect;

•We may experience challenges or delays in growing our salesforce and marketing programs to support our growth plans or in training and incentivizing our salespeople to execute our new go-to-market approach;

•We may have difficulties in hiring and retaining employees in general due to the challenging hiring environment;

•It may be more difficult, time consuming, or expensive than we anticipate to build a robust sales pipeline, increase our brand awareness, or enhance our product distribution channels;

•We may encounter difficulties and delays in platform and product-related initiatives to support our growth, including delays in the availability of new product offerings or the buildout of our next-generation transaction- cloud platform due to staffing and other resource constraints;

•Ongoing component shortages and shipping delays affecting our Digipass authenticator devices could negatively impact revenue and cash flow for our Security Solutions segment, which we are relying upon to help fund growth in our Digital Agreements segment; and

•Economic slowdown or recession, heightened inflation, capital markets volatility, political instability or conflict, and changes in interest rates and foreign exchange rates may negatively affect our financial and operating results.

If we are unable to attract new customers and retain and expand sales to existing customers, we will be unable to grow our business.

Our success will depend significantly on our ability to attract new customers, particularly enterprise customers. We have experienced, and expect to continue to experience in the near term, challenges in adding new customers, in part because we are in the early stages of scaling our sales and marketing capabilities to support our strategic transformation plan. If we are unable to adequately enhance our sales and marketing organizations in the timeframe we expect, we may not be able to attract sufficient new enterprise customers to achieve the growth objectives in our strategic transformation plan, which would have an adverse effect on our business.

The achievement of our growth objectives also depends on our ability to retain and expand sales to existing customers. Our renewal and expansion rates may be below our expectations, decline or fluctuate as a result of a number of factors, including customer budgets, decreases in the number of users at our customers, changes in the type and size of our customers, pricing, competitive conditions, customer attrition and general economic and global market conditions. If our

11

efforts to expand sales to our existing customers are not successful or if our customers do not renew their subscriptions at the rates we expect, our business will be negatively impacted.

Failure to effectively develop and expand our sales and marketing capabilities, and particularly our ability to hire, train, and retain sales personnel, may have a material adverse effect on our ability to grow our business.

Our ability to increase our customer base and achieve broader market acceptance of our products and solutions depends to a significant extent on our ability to effectively develop and expand our sales and marketing operations. As part of our three-year strategic transformation plan, we are making significant investments in and changes to our sales operations. We are in the process of implementing a unified go-to-market approach across our entire business rather than having separate salespeople for Digital Agreements and Security Solutions. This initiative involves intensive training to enable our sales force to sell across our full product portfolio. We are also shifting our sales model to target high-potential enterprise sales prospects using an account-based engagement model. This buildout of our salesforce involves, among other things, hiring of additional salespeople to support our growth plans. To achieve this, we must locate and hire a significant number of qualified individuals with the experience and skills necessary to sell our full product portfolio, and competition for such individuals is intense. Once a new salesperson is hired, we must invest considerable time and resources into training before the person is able to achieve full productivity. If we are unable to retain the individual for a sufficiently long period of time, we may never recoup this investment.

We are also dedicating significant resources to demand generation and marketing efforts, and doing more outbound targeted marketing than we have historically. Since our investment in marketing has been relatively limited in the past and because we have limited brand awareness in many of our markets, it may take time and substantial expense to generate demand and a robust and consistent sales pipeline.

If we cannot train or expand our sales force or successfully generate demand for our products through our marketing efforts in the timeframe contemplated by our strategic transformation plan, we may not be able to achieve the goals of the plan on time or at all, which may have a material adverse effect on our business.

If our new product offerings and product enhancements do not keep pace with the needs of our customers or do not achieve sufficient customer acceptance, our competitive position and financial results will be negatively impacted.

Technological changes occur rapidly in our industry and our development of new products and features is critical to maintain and grow our revenue. Our future growth will depend in part upon our ability to enhance our current products and develop innovative new solutions to distinguish us from the competition and to meet customers’ changing needs. Product developments and technology innovations by others may adversely affect our competitive position and we may not successfully anticipate or adapt to changing technology, industry standards or customer requirements on a timely basis. The introduction by our competitors of products embodying new technologies and the emergence of new industry standards could render our existing products obsolete and unmarketable.

We spend substantial amounts of time and money to research and develop new offerings and enhanced versions of our existing offerings in order to meet our customers’ rapidly evolving needs. When we develop a new offering or an enhanced version of an existing offering, we typically incur expenses and expend resources upfront to market, promote and sell the new offering. Therefore, when we develop or acquire new or enhanced offerings, their introduction must achieve high levels of market acceptance in order to justify the amount of our investment in developing and bringing them to market. For example, if our recent new product offerings, such as our Digipass CX and OneSpan Notary products, do not garner widespread customer adoption and implementation, our business may be adversely affected. Any such adverse effect may be particularly acute because of the significant research, development, marketing, sales and other expenses we will have incurred in connection with the new offerings or enhancements.

A significant portion of our sales are to a limited number of customers. The loss of substantial sales to any one of them could have an adverse effect on revenues and profits.

We derive a substantial portion of our revenue from a limited number of customers. The loss of substantial sales to any one of them could adversely affect our operations and results. In 2022, 2021, and 2020, our top 10 largest customers contributed 23%, 22%, and 21%, respectively, of our total worldwide revenue.

If we are not able to enhance our brand recognition and maintain our brand reputation, our business may be adversely affected.

12

We believe that enhancing our brand recognition is important to our efforts to attract new customers and channel partners. If we do not build awareness of our brand, we could be at a competitive disadvantage to companies whose brands are, or become, more recognizable than ours. Our brand recognition and reputation are dependent upon numerous factors including:

•our marketing efforts;

•our ability to continue to offer high quality, innovative and reliable products;

•our ability to maintain customer satisfaction with our products;

•our ability to be responsive to customer concerns and provide high quality customer support, training and professional services;

•any misuse or perceived misuse of our products;

•positive or negative publicity, including through reviews by industry analysts;

•our ability to prevent or quickly react to any cyberattack on our information technology systems or security breach of or related to our software; and

•litigation or regulatory-related developments.

Improving our brand recognition is likely to require significant additional expenditures and may not be successful or yield increased revenues. If we do not successfully enhance our brand and maintain our reputation, we may have reduced pricing power relative to competitors with stronger brands and we could lose customers or renewals, which would adversely affect our business.

The market we serve is highly competitive, which may negatively affect our ability to add new customers, retain existing customers and grow our business.

The market for digital solutions for identity, authentication, and secure digital agreements is very competitive and, like most technology-driven markets, is subject to rapid change and constantly evolving solutions and services.

Our identity verification and authentication products are designed to allow authorized users access to digital business processes and properties, in some cases using patented technology, as a replacement for or supplement to a static password. Our main competitors in our identity verification and authentication markets are Gemalto, a subsidiary of Thales Group, and RSA Security. There are also many other companies, such as Transmit Security, Symantec, and Duo Security, that offer competing services. In addition to these companies, we face competition from many small authentication solution providers, many of whom offer new technologies and niche solutions such as biometric or risk and behavioral analysis. We believe that competition in this market is likely to intensify as a result of increasing demand for security products.

Our primary competitors for electronic signature solutions are DocuSign and Adobe Systems. Both companies are significantly larger than us. In addition to these companies, there are numerous smaller and regional or niche providers of electronic signing solutions.

Some of our present and potential competitors have significantly greater financial, technical, marketing, purchasing, and other resources than we do. As a result, they may be able to respond more quickly to new or emerging technologies and changes in customer requirements, devote greater resources to the development, promotion and sale of products, or deliver competitive products at a lower end-user price than we do. Any of these factors would make it difficult for us to compete successfully, which would negatively affect our business.

Our Digipass authenticator business is dependent on a limited number of suppliers, and the loss of their manufacturing capability, components and technology could materially impact our operations. Our Digipass business may also experience inventory-related losses.

In the event that the supply of components or finished products for our Digipass authenticator business is interrupted or relations with any of our principal vendors is terminated, there could be increased costs and considerable delay in finding suitable replacement sources to manufacture our hardware products. Our hardware Digipass authentication devices are assembled at facilities located in mainland China and Romania. The importation of these products from China and Romania exposes us to the possibility of product supply disruption and increased costs in the event of changes in the policies of the Chinese government, political unrest or unstable economic conditions in China, or developments in the U.S. or EU that are adverse to trade, including enactment of protectionist legislation. We experienced supply chain disruption in 2022 as a result of the impact on our Chinese contract manufacturers of China’s implementation and subsequent reversal of

13

its “Zero COVID” policy. To mitigate the risks associated with our China-based contract manufacturing facilities, we are considering alternative manufacturing and supply arrangements, such as moving some of the Digipass manufacturing currently done in China to Romania or to other locations. It is possible that this transition may cause a disruption in our Digipass manufacturing operations. Product supply disruptions or related cost increases could have a material adverse impact on our business.

Under some circumstances, we purchase multiple years’ supply of parts for our Digipass authenticator devices based on internal forecasts of demand, anticipated supply chain constraints, or other reasons. To meet customers’ demands for accelerated delivery of product, we sometimes produce finished product for existing customers before we receive the executed order from the customer. Should our forecasts of future demand be inaccurate or if we produce product that is never ordered, we could incur substantial losses related to the realization of our inventory.

The sales cycle for our products is often long, and we may incur substantial expenses for sales that do not occur when anticipated or at all.

The sales cycle for our products, which is the period of time between the identification of a potential customer and completion of the sale, is typically lengthy and subject to a number of significant risks over which we have little control.

A typical sales cycle in the financial services market is often nine to 18 months long. We often need to spend significant time and resources to better educate and familiarize these potential customers with the value proposition of our products and solutions. Purchasing decisions for our products and services may be subject to delays due to a number of factors, many of which are outside of our control, such as:

•Time required for a prospective customer to recognize the need for our products;

•Effectiveness of our salesforce;

•Changes to regulatory requirements;

•The complexity of contracts with certain large business customers;

•The significant expense of some of our products and systems;

•Customer budgeting and procurement processes;

•Economic and other factors impacting customer budgets; and

•Customer evaluation, testing and approval process.

The timing of sales with our enterprise customers and related revenue recognition is difficult to predict because of the length and unpredictability of the sales cycle for these customers. As our operating expenses are based on anticipated revenue levels, a small fluctuation in the timing of sales can cause our operating results to vary significantly between periods. In addition, during the sales cycle, we expend significant time and money on sales and marketing and contract negotiation activities, which may not result in a sale.

If we are unable to successfully hire, train, and retain qualified personnel, we may be unable to achieve our business objectives.

Our ability to successfully pursue our three-year strategic transformation plan will depend significantly on our ability to attract, motivate and retain employees, especially those in sales. We face intense competition for these employees from numerous technology, software and other companies, many of whom have greater resources than we do. In 2022, we incurred higher compensation-related expenses in order to remain competitive in a tight labor market, particularly in light of wage inflation, and we expect to continue to experience this type of cost pressure. Even with an increase in the compensation we offer, we may not be able to attract, motivate and/or retain sufficient qualified employees. Difficulties attracting and retaining personnel could have an adverse effect on our ability to achieve our sales, operational, or other business objectives and, as a result, our ability to compete could decrease and our financial results could be adversely affected. In addition, even if we are able to identify and recruit a sufficient number of new hires, these new hires will require significant training before they achieve full productivity, particularly in the case of sales employees.

We are dependent on the continued services and performance of our senior management and other key employees, the loss of any of whom could adversely affect our business, operating results and financial condition.

Our future performance depends on the continued services and contributions of our senior management, particularly Matthew Moynahan, our Chief Executive Officer, and other key sales and technical employees. Our senior management and key employees are employed on an at-will basis, which means that they could terminate their employment

14

with us at any time. The temporary or permanent loss of the services of our senior management or other key employees for any reason could significantly delay or prevent the achievement of our objectives and harm our business, financial condition and results of operations. Further, such a loss could be negatively perceived in the capital markets, which could reduce the market value of our securities.

Security breaches or cyberattacks could expose us to significant liability and cause our business and reputation to suffer and harm our competitive position.

Our corporate infrastructure stores and processes our sensitive, proprietary and other confidential information (including as related to financial, technology, employees, marketing, sales, etc.) which is used on a daily basis in our operations. In addition, our software involves transmission and processing of our customers' confidential, proprietary and sensitive information. We have legal and contractual obligations to protect the confidentiality and appropriate use of customer data. Because we are a cybersecurity company, and because the majority of our customers are banks and other financial institutions, which are frequent targets of cyberattacks, we may be an attractive target for cyber attackers or other data thieves.

High-profile cyberattacks and security breaches have increased in recent years, with the potential for such acts heightened as a result of the number of employees working remotely due to the COVID-19 pandemic. Security industry experts and government officials have warned about the risks of hackers and cyberattacks targeting IT products and enterprise infrastructure. Because techniques used to obtain unauthorized access or to sabotage systems change frequently and often are not recognized until launched against a specific target, we may be unable to anticipate these techniques or to implement adequate preventative measures. As we seek to increase our client base and expand awareness of our brand, we may become more of a target for third parties seeking to compromise our security systems and we anticipate that hacking attempts and cyberattacks will increase in the future.

We have experienced several security incidents in the past. None have been material to date, but it is possible that we will experience a material event in the future. Even though we have established teams, processes and strategies to protect our assets, we may not always be successful in preventing or repelling unauthorized access to our systems. We also may face delays in our ability to identify or otherwise respond to any cybersecurity incident or any other breach. Additionally, we use third-party service providers to provide some services to us that involve the storage or transmission of data, such as software as a service (SaaS), cloud computing, and internet infrastructure and bandwidth, and they face various cybersecurity threats and also may suffer cybersecurity incidents or other security breaches. Despite our security measures, our IT and infrastructure may be vulnerable to attacks. Threats to IT security can take a variety of forms. Individual and groups of hackers and sophisticated organizations, including state-sponsored organizations or nation-states, continuously undertake attacks that pose threats to our customers and our IT. These actors may use a wide variety of methods, which may include developing and deploying malicious software or exploiting vulnerabilities in hardware, software, or other infrastructure in order to attack our products and services or gain access to our networks, using social engineering techniques to induce our employees, users, partners, or customers to disclose passwords or other sensitive information or take other actions to gain access to our data or our users’ or customers’ data, or acting in a coordinated manner to launch distributed denial of service or other coordinated attacks. Inadequate account security practices may also result in unauthorized access to confidential and/or sensitive data.

Security risks, including, but not limited to, unauthorized use or disclosure of customer data, theft of proprietary information, theft of intellectual property, theft of internal employees' personally identifiable information, theft of financial data and financial reports, loss or corruption of customer data and computer hacking attacks or other cyberattacks, could require us to expend significant capital and other resources to alleviate the problem and to improve technologies, may impair our ability to provide services to our customers and protect the privacy of their data, may result in product development delays, may compromise confidential or technical business information, may harm our competitive position, may result in theft or misuse of our intellectual property or other assets and could expose us to substantial litigation expenses and damages, indemnity and other contractual obligations, government fines and penalties, mitigation expenses, costs for remediation and incentives offered to affected parties, including customers, other business partners and employees, in an effort to maintain business relationships after a breach or other incident, and other liabilities. We are continuously working to improve our IT systems, together with creating security boundaries around our critical and sensitive assets. We provide advanced security awareness training to our employees and contractors that focuses on various aspects of cybersecurity. All of these steps are taken in order to mitigate the risk of attack and to ensure our readiness to responsibly handle any security violation or attack. However, because techniques used to obtain unauthorized access or to sabotage systems change frequently and generally are not recognized until successfully launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures. If an actual or perceived breach

15

of our security occurs, the market perception of the effectiveness of our security measures and our products could be harmed, we could lose potential sales and existing customers, our ability to operate our business could be impaired, we may incur significant liabilities, we could suffer harm to our reputation and competitive position, and our business and financial condition could be negatively impacted.

Real or perceived malfunctions and errors in our products could result in warranty and product liability risks and economic and reputational damages.

Our products are inherently complex and may malfunction or contain undetected errors or defects when first introduced or as new versions are released. We have experienced these malfunctions and errors or defects in connection with new products and product upgrades, and we expect that these malfunctions, errors and defects will continue to be found from time to time in new or enhanced products. Malfunctions and defects may make our products vulnerable to attacks, prevent vulnerability detection, or temporarily impact our customer’s environments. These problems may result in a breach of a legal obligation or may cause physical harm or damage which could result in tort or warranty claims against us. We seek to reduce the risk of these losses by using qualified engineers in the design, manufacturing and testing of our hardware products, proper development, testing, and scanning of our software solutions (including SaaS), attempting to negotiate warranty disclaimers and liability limitation clauses in our sales agreements, and maintaining customary insurance coverage. However, these measures may ultimately prove ineffective in limiting our liability for damages.

In addition to any monetary liability for the failure of our products, a publicly known defect or perceived defect in our products could lead to customers delaying or withholding payments, divert the attention of our key personnel, adversely affect the market’s perception of us and our products, and have an adverse effect on our reputation and the demand for our products.

Our financial results may fluctuate from period to period, making it difficult to project future results. If we fail to meet the expectations of securities analysts or investors, the price of our common stock could decline.

Our revenue and results of operations have historically varied from period to period, and we expect that they will continue to do so as a result of a number of factors, many of which are outside of our control, including:

•The size, timing, and payment terms of significant orders, and any unexpected delay or cancelation of such orders;

•The variability of revenue realized from individual customers, as their buying patterns can vary significantly from period to period and are affected by the individual solutions purchased and the structure of the contract;

•Larger customers delaying renewal of their subscriptions or failing to renew at all;

•Changes in customer budgets;

•The effectiveness of our sales and marketing programs, including our ability to hire, train and retain our sales personnel;

•Changes in pricing by competitors;

•New product announcements or introductions by competitors;

•Technological changes in the market for our products, including the adoption of new technologies and standards;

•Our ability to develop, introduce and market new products and product enhancements on a timely basis;

•Market and customer acceptance of any new products and product enhancements that we introduce;

•With respect to our Digipass business, component costs and availability;

•Network outages, security breaches, technical difficulties or interruptions affecting our products;

•Seasonality in our business;

•Changes in foreign currency exchange rates;

•General economic and political conditions, as well as economic conditions specifically affecting industries in which our customers operate; and

•Other events or factors, including those resulting from pandemics, war, natural disasters, incidents of terrorism or responses to these events.

Any one of these or other factors discussed elsewhere in this Annual Report on Form 10-K, or the cumulative effect of a combination of these factors, may result in fluctuations in our financial results, which may cause us to miss our guidance and analyst expectations and cause the price of our common stock to decline.

We have operated at a loss for each of the past three fiscal years, and we may not be profitable in the future.

16

Over our approximately 30-year operating history, we have operated at a loss for many of those years, including for the years ended December 31, 2022, 2021 and 2020, for which we reported a net loss of $14.4 million, $30.6 million, and $5.5 million, respectively. We will need to generate and sustain increased revenue levels and manage our expenses in future periods to become profitable and, even if we do, we may not be able to maintain or increase our level of profitability. We intend to continue to incur significant expenses to support growth, further develop and enhance our products and solutions, expand our infrastructure and technology, increase our sales headcount and marketing activities, and grow our customer base. Our efforts to grow our business may be costlier than we expect, and we may not be able to increase our revenue enough to offset our increased operating expenses. We may incur significant losses in the future for a number of reasons, including the other risks described herein, and experience unforeseen expenses, difficulties, complications and delays and other unknown events. If we are unable to achieve and sustain profitability, the value of our business and common stock may significantly decrease.

Our business, operations and financial performance may be negatively affected by adverse changes in the evolving COVID-19 pandemic.

The COVID-19 pandemic is continuing to evolve, and significant adverse changes in the spread or severity of COVID-19 infections and the resulting economic impact could have a material adverse effect on our business, operations and financial performance.

In our Digipass authenticator device business, we are exposed to specific risks related to manufacturing, supply chain, shipping and distribution, all of which have been impacted by the COVID-19 pandemic. As a result of COVID-19, we have experienced, and may continue to experience, delays and increased costs related to fulfilling our device orders. Although we have managed these issues to date, ongoing disruptions in global transportation may continue to delay fulfillment, which may in turn delay our recognition of revenue from customer orders, or even prevent us from satisfying certain customer orders for our products in the future if orders substantially increase and/or further supply chain problems emerge. In order to meet our customers’ needs, we have and may continue to incur increased freight and other costs related to our Digipass devices, which would reduce our margins.

We experienced some increased sales for our e-signature solution and products used to facilitate remote employee access in 2020 that we attribute in part to the COVID-19 pandemic; however, since that time, customer buying patterns have generally returned to more typical pre-pandemic levels.

A resurgence or similar development in the COVID-19 pandemic would likely create additional economic uncertainty and have a number of adverse effects, including: a negative impact on our customers’ ability or willingness to attend our sales and marketing events or to purchase our offerings; a delay in prospective customers’ purchasing decisions; our inability to provide on-site sales meetings or professional services to our customers; delays in the provisioning of our products; longer customer payment terms; lower value or shorter duration of customer contracts; lower margins, especially in our Digipass business; or an increase in customer attrition rates, all of which could adversely affect our future sales, operating results and overall financial performance.

We depend on third-party hosting providers and other technology vendors, as well as our own infrastructure, to provide our products and solutions to our customers in a timely manner. Interruptions or delays in performance of our products and solutions could result in customer dissatisfaction, damage to our reputation, loss of customers, and reduction in revenue.

We outsource portions of our cloud infrastructure to third-party hosting providers, principally Amazon Web Services, or AWS. We also outsource components of our services to third-party technology vendors who host their products in the cloud. Customers of our products need to be able to access our platform at any time, without interruption or degradation of performance. AWS and other third-party hosting providers run their own platforms that we access, and we are therefore vulnerable to service interruptions on these third-party platforms, as well as to service interruptions affecting our third-party technology vendors. We have experienced interruptions, delays and outages in service and availability from time to time due to a variety of factors impacting our third-party hosting providers or other vendors, and we expect to experience these types of incidents in the future.

If our products or platform are unavailable or our users are otherwise unable to use our products within a reasonable amount of time or at all, then our business, results of operations and financial condition could be adversely affected. In some instances, we may not be able to identify the cause or causes of these performance problems within a period of time acceptable to our customers. It may become increasingly difficult to maintain and improve our platform

17

performance, especially during peak usage times, as our products become more complex and the usage of our products increases. We have in the past and may in the future experience capacity constraints that affect our product performance and cause us to miss our service level agreements with our customers. These capacity constraints can be due to a number of causes, including technical failures, natural disasters, fraud or security attacks. To the extent that we do not effectively address capacity constraints, either through our current providers or alternative providers of cloud infrastructure, our business, results of operations and financial condition may be adversely affected. In addition, any changes in service levels from our third-party hosting providers or other cloud-based technology vendors may adversely affect our ability to meet our customers' requirements.

Our third-party hosting providers have no obligations to renew their agreements with us on commercially reasonable terms or at all, and the agreements governing these relationships can generally be terminated by either party with limited notice. Access to hosting services may also be restricted by the provider at any time, with no or limited notice. Although we expect that we could receive similar services from other third parties, if any of our arrangements with AWS or other third-party hosting providers are terminated, we could experience interruptions on our platform and in our ability to make our platform available to customers, as well as downtime, delays and additional expenses in arranging alternative cloud infrastructure services.

It is also possible that our customers and potential customers would hold us accountable for any breach of security affecting infrastructure of our third-party hosting providers. We may incur significant liability from those customers and from third parties with respect to any such breach, and we may not be able to recover a material portion of our liabilities to our customers and third parties from our hosting providers in the event of any breach affecting their systems.

Any of the above circumstances or events may harm our reputation, cause customers to stop using our products, impair our ability to increase revenue from existing customers, impair our ability to grow our customer base, subject us to financial penalties and liabilities under our service level agreements and otherwise harm our business, results of operations and financial condition.

Our success depends in part on establishing and maintaining relationships with other companies to distribute our technology and products or to incorporate their technology into our products and services, or vice versa.

Part of our business strategy is to enter into partnerships and other cooperative arrangements with third parties. We are regularly involved in cooperative efforts with respect to the incorporation of our products into products of others and vice versa, research and development efforts, and marketing, distributor and reseller arrangements. These relationships are generally non-exclusive, and some of our partners also have cooperative relationships with certain of our competitors or offer some products and services that are competitive with ours. If we lose third-party relationships, if these relationships are not commercially successful, or if we are unable to enter into third-party relationships on commercially reasonable terms in the future, our business could be negatively impacted.

SaaS offerings, which involve various risks, constitute an important part of our business.

We expect that our SaaS offerings will constitute an increasingly important part of our business. As a result, we will need to continue to evolve our processes to meet a number of regulatory, intellectual property, contractual, service, and security compliance challenges. These challenges include compliance with licenses for open-source and third-party software embedded in our SaaS offerings, maintaining compliance with export control and privacy regulations (including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the General Data Protection Regulation (GDPR)), protecting our products from external threats, maintaining continuous service levels and data security practices expected by our customers, preventing inappropriate use of our products, and incurring significant up-front costs where desired higher margins are dependent on achieving significant sales volume and adapting our go-to-market efforts. In addition to using our internal resources, we also utilize third-party resources to deliver SaaS offerings, such as third-party data hosting vendors. The failure of a third-party provider to prevent service disruptions, data losses or security breaches may require us to issue credits or refunds or to indemnify or otherwise be liable to customers or third parties for damages that may occur. Additionally, if these third-party providers fail to deliver on their obligations, our reputation could be damaged, and our customers could lose confidence in us and our ability to maintain and expand our SaaS offerings. Finally, our SaaS offerings need to be designed to operate at significant transaction volumes. When combined with third-party software and hosting infrastructure, our SaaS offerings may not perform as designed, which could lead to service disruptions and associated damages.

Failure to maintain high-quality customer support could have a material adverse effect on our business.

18

Our business relies on our customers’ satisfaction with the technical and customer support and professional services we provide to support our products. If we fail to provide customer and technical support services that are high-quality, responsive, and able to promptly resolve issues that our customers encounter with our products and services, then they may elect not to purchase or renew subscription licenses or may otherwise reduce or discontinue their business relationship with us. This would likely result in loss of revenue and damage to our reputation, which could have an adverse effect on our business.

Failure to effectively manage our product and service lifecycles could harm our business.

As part of the natural lifecycle of our products and services, we periodically inform customers that products or services have reached their end of life or end of availability and will no longer be supported or receive updates and security patches. Failure to effectively manage our product and service lifecycles could lead to customer dissatisfaction and contractual liabilities, which could adversely affect our business and operating results. In addition, the failure to generate new revenue to replace and/or expand the revenue realized from discontinued products or services could adversely affect our business and operating results.

We are subject to foreign currency exchange rate fluctuations, which could adversely affect our financial condition and results of operations.

Because a significant number of our principal customers are located outside the United States, we expect that international sales will continue to generate a significant portion of our total revenue. We are subject to foreign exchange fluctuations and risks because the majority of our product costs are denominated in U.S. Dollars, whereas a significant portion of the sales and expenses of our foreign operating subsidiaries are denominated in various foreign currencies. A decrease in the value of any of these foreign currencies relative to the U.S. Dollar could adversely affect our revenue and profitability in U.S. Dollars of our products sold in these markets. Furthermore, a strengthening of the U.S. dollar could increase the cost in local currency of our products and services to customers outside the United States, which could adversely affect our business, results of operations, financial condition and cash flows.

The exchange rate between the U.S. Dollar and foreign currencies has fluctuated in recent years and may fluctuate substantially in the future. As discussed in Management’s Discussion and Analysis of Financial Condition and Results of Operations, the U.S. Dollar’s strength during foreign currencies, particularly the Euro, during 2022 had a significant impact on our 2022 financial results and may continue to adversely affect our results in the future. We do not currently use forward contracts or other hedging strategies such as options or foreign exchange swaps to mitigate our exposure to foreign currency fluctuations.

We face a number of risks associated with our international operations, any or all of which could result in a disruption in our business and a decrease in our revenue.

In 2022, approximately 83% of our revenue and approximately 66% of our operating expenses were generated/incurred outside of the U.S, In 2021, approximately 86% of our revenue and approximately 68% of our operating expenses were generated/incurred outside of the U.S. In 2020, approximately 88% of our revenue and approximately 73% of our operating expenses were generated/incurred outside of the U.S. A severe economic decline in any of our major foreign markets could adversely affect our results of operations and financial condition.

In addition to exposures to changes in the economic conditions of our major foreign markets, we are subject to a number of risks related to our international operations, any or all of which could result in a disruption in our business and a decrease in our revenue. These include:

•increased management, infrastructure and legal costs associated with having international operations;

•costs of compliance with foreign legal and regulatory requirements, including, but not limited to data privacy, data protection and data security regulations, and the risks and costs of non-compliance;

•costs of compliance with U.S. laws and regulations for foreign operations, including the U.S. Foreign Corrupt Practices Act, import and export control laws, tariffs, trade barriers, economic sanctions and other regulatory or contractual limitations on our ability to sell or provide our solutions in certain foreign markets, and the risks and costs of non-compliance;

19

•heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of, and irregularities in, financial statements;

•costs of compliance with multiple and possibly overlapping tax structures, and related potential adverse tax impacts;

•risks of reliance on channel partners for sales in some countries;

•differing technology standards in certain international markets;

•the uncertainty and limitation of protection for intellectual property rights in some countries;

•greater difficulty in enforcing contracts, accounts receivable collection and longer collection periods;

•difficulties and costs of staffing and managing international operations, including maintaining internal controls and challenges in closing or restructuring such operations;

•difficulty in providing support and training to customers in certain international locations;

•management communication and integration problems resulting from cultural and linguistic differences and geographic dispersion;

•foreign currency exchange rate fluctuations;

•adverse tax burdens and foreign exchange controls that could make it difficult to repatriate earnings and cash;

•increased exposure to climate change, natural disasters, acts of war, terrorism, epidemics, or pandemics and other health crises, including the ongoing COVID-19 pandemic; and

•economic or political instability in foreign markets, including instability related to the United Kingdom’s recent exit from the EU, China’s “zero COVID” policies, and the impact of geopolitical tensions between China and the U.S. over Taiwan, Hong Kong, tariffs and other matters.

Our business, including the sales of our products and professional services by us and our channel partners, may be subject to foreign governmental regulations, which vary substantially from country to country and change from time to time. Our failure, or the failure by our channel partners, to comply with these regulations could adversely affect our business. Further, in some foreign countries, it may be more common for others to engage in business practices that are prohibited by our internal policies and procedures or U.S. regulations applicable to us. Violations of laws or internal policies by our employees, contractors, channel partners or agents could result in delays in revenue recognition, financial reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our products and could have a material adverse effect on our business and results of operations. If we are unable to successfully manage the challenges of international expansion and operations, our business and operating results could be adversely affected.

If our goodwill or intangible assets become impaired, we may be required to record a significant charge to earnings.

We review our goodwill and intangible assets for impairment when events or changes in circumstances indicate the carrying value may not be recoverable. Goodwill is required to be tested for impairment at least annually. At December 31, 2022, we had goodwill and intangible assets with a net book value of $103.0 million primarily related to our acquisitions. An adverse change in market conditions, particularly if such change has the effect of changing one of our critical assumptions or estimates, could result in a change to the estimation of fair value that could result in an impairment charge to our goodwill or intangible assets. Any such charges may have a material negative impact on our operating results.

Because we recognize revenue from subscription-based software licenses over the term of the relevant contract, downturns or upturns in sales contracts are not immediately reflected in full in our operating results. In addition, our reported revenue may fluctuate widely due to the interpretation or application of accounting rules.

Approximately 41% of our total revenue for the year ended December 31, 2022 was attributable to subscription license contracts. We recognize subscription revenue over the term of each of our subscription contracts,which are typically one year in length but may be up to three years or longer. As a result, much of our revenue is generated from the recognition of contract liabilities from contracts entered into during previous periods. Consequently, a shortfall in demand for our products or a decline in new or renewed contracts in any one quarter may not significantly reduce our revenue for that quarter but could negatively affect our revenue in future quarters. Our revenue recognition model also makes it difficult for us to rapidly increase our revenue through additional sales contracts in any period, as revenue from new customers is recognized over the applicable term of their contracts.

In addition, our sales arrangements often include multiple elements, including hardware, services, software, maintenance and support. We have sold software related arrangements in multiple forms, including perpetual licenses, term-based licenses and SaaS subscriptions, each of which may be treated differently under accounting rules. The accounting rules for such arrangements are complex and subject to change from time to time. The nature of the

20

arrangement can create variations in the timing of revenue recognition. If applicable accounting standards or practices change, or if the judgments or estimates we use when applying existing standards prove to be incorrect, our financial results may be adversely affected.

We could be subject to additional tax liabilities, and our ability to use our net operating losses may be limited.

We are subject to U.S. federal, state, local and sales taxes in the United States and foreign income taxes, withholding taxes and transaction taxes in numerous foreign jurisdictions. Significant judgment is required in evaluating our tax positions and our worldwide provision for taxes. During the ordinary course of business, there are many activities and transactions for which the ultimate tax determination is uncertain and the relevant taxing authorities may disagree with our determinations as to the income and expenses attributable to specific jurisdictions. In addition, our tax obligations and effective tax rates could be adversely affected by changes in the relevant tax, accounting and other laws, regulations, principles and interpretations by recognizing tax losses or lower than anticipated earnings in jurisdictions where we have lower statutory rates and higher than anticipated earnings in jurisdictions where we have higher statutory rates, by changes to our operating structure (including a currently in-process revenue of our intellectual property structure), by changes in foreign currency exchange rates, or by changes in the valuation of our deferred tax assets and liabilities. We may be audited in various jurisdictions, and such jurisdictions may assess additional taxes, sales taxes and value-added taxes against us. Although we believe our tax estimates are reasonable, the final determination of any tax audits or litigation could be materially different from our historical tax provisions and accruals, which could have a material adverse effect on our operating results or cash flows in the period for which a determination is made.

At December 31, 2022 we had U.S. federal, state and foreign net operating losses (NOLs), of $18.0 million, $27.7 million, and $80.1 million, respectively, available to offset future taxable income, some of which begin to expire in 2023. Federal NOLs incurred in taxable years beginning after December 31, 2017 can be carried forward indefinitely, but the deductibility of federal NOLs in taxable years beginning after December 31, 2021, is subject to certain limitations. A lack of future taxable income would adversely affect our ability to utilize these NOLs before they expire.

In addition, under the provisions of the Internal Revenue Code of 1986, as amended, or the Internal Revenue Code, substantial changes in our ownership may limit the amount of pre-change NOLs that can be utilized annually in the future to offset taxable income. Section 382 of the Internal Revenue Code imposes limitations on a company’s ability to use its NOLs if one or more stockholders or groups of stockholders that own at least 5% of the company’s stock increase their ownership by more than 50 percentage points over their lowest ownership percentage within a rolling three-year period. Similar rules may apply under state tax laws. Based upon an analysis as of December 31, 2021, we determined that we do not expect these limitations to materially impair our ability to use our NOLs prior to expiration. However, if changes in our ownership occurred after such date, or occur in the future, our ability to use our NOLs may be further limited. Subsequent statutory or regulatory changes in respect of the utilization of NOLs for federal or state purposes, such as suspensions on the use of NOLs or limitations on the deductibility of NOLs carried forward, or other unforeseen reasons, may result in our existing NOLs expiring or otherwise being unavailable to offset future income tax liabilities. For these reasons, we may not be able to utilize a material portion of the NOLs, even if we achieve profitability.

Acquisitions or other strategic transactions may not achieve the intended benefits or may disrupt our current plans and operations.

In order to remain competitive, we have in the past and may in the future seek to acquire additional businesses, products or technologies or to make investments in, or enter into joint ventures or similar transactions with, third parties. These transactions involve numerous risks, including the following:

•Difficulties or delays in integrating the acquired businesses, which could prevent us from realizing the anticipated benefits of acquisitions;

•Delays or reductions in customer purchases for both us and the company we acquired due to customer uncertainty about continuity and effectiveness of service from either company;

•Challenges in successfully cross-selling acquired products to our existing customer base, or in cross-selling our products to the acquired company’s customer base;

•Difficulties in supporting and migrating acquired customers, if any, to our platforms, which could cause customer churn, unanticipated costs, and damage to our reputation;

•Disruption of our ongoing business and diversion of management and other resources from existing operations;

•Constraints on our liquidity and in the event that we use cash or incur debt to fund an acquisition, or dilution to existing stockholders in the event we issue equity securities as part of the consideration for the acquisition;

21

•Our use of cash to pay for acquisitions would limit other potential uses for our cash and affect our liquidity;

•Assumption of debt or other actual or contingent liabilities of the acquired company, including litigation risk;

•Differences in in corporate culture, compliance protocols, and risk management practices between us and acquired companies;

•Potential loss of the key employees of an acquired business;

•Potential loss of the customers or partners of an acquired business due to the actual or perceived impact of the acquisition;

• Difficulties associated with governance, management, and control matters in majority or minority investments or joint ventures;

•Unforeseen or undisclosed liabilities or challenges associated with the companies, businesses, or technologies we acquire;

•Adverse tax consequences, including exposure of our entire business to taxation in additional jurisdictions; and

•Accounting effects, including potential impairment charges and requirements that we record acquired deferred revenue at fair value.

Any of these risks could result in acquisitions or other strategic transactions disrupting our business and/or failing to achieve their intended objectives.

We also review our product portfolio from time to time for contributions to our objectives and alignment with our strategy, and we may pursue divestiture activities as a result of these reviews. However, we may not be successful in separating any underperforming or non-strategic assets, and gains or losses on any divestiture of, or lost operating income from, such assets may adversely affect our results of operations. Divestitures could also expose us to unanticipated liabilities or result in ongoing obligations, including transition service obligations and indemnity obligations.

Provisions in various agreements potentially expose us to substantial liability for intellectual property infringement and other losses.

Our agreements with customers, solution partners and channel partners generally include provisions under which we agree to indemnify them for losses suffered or incurred as a result of claims of intellectual property infringement and, in some cases, for damages caused by us to property or persons or for other damages. In the past, we worked with a customer at our expense to resolve a claim brought against the customer related to our technology, and it is likely that we will need to indemnify our customers for similar claims in the future. The expense of defending these types claims may adversely affect our financial results and may not be covered by any insurance policies we maintain. In addition, any such disputes and litigation could divert management attention and harm our reputation in the market.

We also make certain representations and warranties and incur obligations under our contracts in the ordinary course of business, including for items related to data security and potential data privacy breaches. Although we normally contractually limit our liability with respect to such representations, warranties and other contractual obligations, we may still incur substantial liability related to them. Not all of our potential losses under our contracts are covered by insurance policies, which could increase the impact of any such loss should it occur. Large indemnity payments or damages resulting from our contractual obligations could harm our business, operating results and financial condition.

Any failure to protect our proprietary technology and intellectual property rights could substantially harm our business and operating results.

Our success is dependent, in part, upon protecting our proprietary technology. We rely on a combination of patents, copyrights, trademarks, service marks, trade secret laws and contractual provisions in an effort to establish and protect our proprietary rights. However, the steps we take to protect our intellectual property may be inadequate. While we have been issued patents in the U.S. and other countries and have additional patent applications pending, we may be unable to obtain patent protection for the technology covered in our patent applications. In addition, any patents issued in the future may not provide us with competitive advantages or may be successfully challenged by third parties. Any of our patents, trademarks or other intellectual property rights may be challenged or circumvented by others or invalidated through administrative process or litigation. There can be no guarantee that others will not independently develop similar products, duplicate any of our products or design around our patents. Furthermore, legal standards relating to the validity, enforceability and scope of protection of intellectual property rights are uncertain. Despite our precautions, it may be possible for unauthorized third parties to copy our products and use information that we regard as proprietary to create products and solutions that compete with ours. Some license provisions protecting against unauthorized use, copying, transfer and disclosure of our products may be unenforceable under the laws of jurisdictions outside the U.S. To the extent

22

we expand our international activities, our exposure to unauthorized copying and use of our products and proprietary information may increase.

We enter into confidentiality and invention assignment agreements with our employees and consultants and enter into confidentiality agreements with the parties with whom we have strategic relationships and business alliances. These agreements may not be effective in controlling access to and distribution of our products and proprietary information. Further, these agreements do not prevent our competitors or partners from independently developing technologies that are substantially equivalent or superior to our products and solutions.

In order to protect our intellectual property rights, we may be required to spend significant resources to monitor and protect and enforce these rights, including through litigation. Litigation brought to protect and enforce our intellectual property rights could be costly, time consuming and distracting to management and could result in the impairment or loss of portions of our intellectual property. Furthermore, our efforts to enforce our intellectual property rights may be met with defenses, counterclaims and countersuits attacking the validity and enforceability of our intellectual property rights. Our inability to protect our proprietary technology against unauthorized copying or use, as well as any costly litigation or diversion of our management’s attention and resources, could delay further sales or the implementation of our products and solutions, impair the functionality of our products and solutions, delay introductions of new solutions, result in our substituting inferior or more costly technologies into our products and solutions or injure our reputation. We will not be able to protect our intellectual property if we are unable to enforce our rights or if we do not detect unauthorized use of our intellectual property. Moreover, policing unauthorized use of our technologies, trade secrets and intellectual property may be difficult, expensive and time-consuming, particularly in foreign countries where the laws may not be as protective of intellectual property rights as those in the U.S. and where mechanisms for enforcement of intellectual property rights may be weak. If we fail to adequately protect our intellectual property and proprietary rights, our business, operating results and financial condition could be adversely affected.

We may be subject to legal proceedings for a variety of claims, including intellectual property disputes, labor and employment issues, commercial disagreements, securities law violations and other matters. These proceedings may be costly, subject us to significant liability, limit our ability to use certain technologies, increase our costs of doing business or otherwise adversely affect our business and operating results.

From time to time, we are involved as a party or an indemnitor in disputes or regulatory inquiries. These may include alleged claims, lawsuits and proceedings regarding intellectual property disputes, labor and employment issues, commercial disagreements, securities law violations and other matters. In particular, companies in the software industry are often required to defend against litigation or claims based on allegations of infringement or other violations of intellectual property rights. In certain instances, we receive claims that we have infringed the intellectual property rights of others, including claims regarding patents, copyrights, and trademarks. Because of constant technological change in the markets in which we compete, the extensive patent coverage of existing technologies, and the rapid rate of issuance of new patents, it is possible that the number of these claims may grow. Such claims sometimes involve patent holding companies or other adverse patent owners that have no relevant product revenue and against which our own patents may therefore provide little or no deterrence. In addition, former employers of our former, current, or future employees may assert claims that such employees have improperly disclosed to us the confidential or proprietary information of these former employers. If we are not successful in defending such claims, we could be required to stop selling our products, delay shipments, redesign our products, pay monetary amounts as damages, enter into royalty or licensing arrangements (which may not be available to us on commercially reasonable terms), or satisfy indemnification obligations to our customers, any of which could have a material adverse effect on our business.

Regardless of the merits or ultimate outcome of any claims that have been or may be brought against us or that we may bring against others, lawsuits are time-consuming and expensive to resolve, divert management’s time and attention, and could harm our reputation. Although we carry general liability and other forms of insurance, our insurance may not cover potential claims that arise or may not be adequate to indemnify us for all liability that may be imposed. We may also determine that the most cost-effective way to resolve a dispute is to enter into a settlement agreement. Litigation is inherently unpredictable and we cannot predict the timing, nature, controversy or outcome of lawsuits, and it is possible that litigation could have an adverse effect on our business, operating results or financial condition.

We use open-source software in our products, which could subject us to litigation or other actions.

We use open-source software in our products and solutions. Any use of open-source software may expose us to greater risks than the use of commercial software because open-source licensors generally do not provide warranties or

23

controls on the functionality or origin of the software. Any use of open-source software may involve security risks, making it easier for hackers and other third parties to determine how to compromise our platform. From time to time, there have been claims challenging the ownership of open-source software against companies that incorporate open-source software into their products. As a result, we could be subject to lawsuits by parties claiming ownership of what we believe to be open-source software. Litigation could be costly for us to defend, have a negative effect on our operating results and financial condition or require us to devote additional research and development resources to change our products. In addition, if we were to combine our proprietary software products with open-source software in a certain manner, we could, under certain of the open-source licenses, be required to release the source code of our proprietary software products. If we inappropriately use or incorporate open-source software subject to certain types of open-source licenses that challenge the proprietary nature of our software products, we may be required to re-engineer our products, discontinue the sale of our products and solutions or take other remedial actions.

There is significant government regulation of technology imports and exports. If we cannot meet the requirements of the regulations we may be prohibited from exporting some of our products, which could negatively impact our revenue.

Our international sales and operations are subject to risks such as the imposition of government controls, new or changed export license requirements, restrictions on the export of critical technology, trade restrictions and changes in tariffs. If we are unable to obtain regulatory approvals on a timely basis, our business may be impacted. Certain of our products are subject to export controls under U.S. law including the U.S. Export Administration Regulations, U.S. Customs regulations, and various economic and trade sanctions administered by the U.S. Treasury Department’s Office of Foreign Assets Control. The list of products and countries for which export approval is required, and the regulatory policies with respect thereto, may be revised from time to time and our inability to obtain required approvals under these regulations could materially and adversely affect our ability to make international sales. Additionally, we may be negatively affected if our third-party technology partners fail to obtain proper licenses and permits for the import and export of their products. We maintain trade control compliance requirements for our partners; however, we cannot guarantee that our partners will comply with these requirements. Violations of export control and international trade laws could result in penalties, fines, adverse reputational consequences, and other materially adverse consequences. In the past, we voluntarily disclosed a trade control matter to the U.S. government. Although this matter was closed during 2019 with no fines, penalties, or finding of wrongdoing, similar issues could arise in the future. In addition, future changes in government regulation technology imports and exports could negatively affect our business.

We employ cryptographic technology in our authentication products. If the codes used in our cryptographic technology are eventually broken or become subject to additional government regulation, our technology and products may become less effective, which would have a material adverse effect on our business.

A portion of our products are based on cryptographic technology. With cryptographic technology, a user is given a key that is required to encrypt and decode messages. The security afforded by this technology depends on the integrity of a user’s key and in part on the application of algorithms, which are advanced mathematical factoring equations. These codes may eventually be broken or become subject to government regulation regarding their use, which would render our technology and products less effective. The occurrence of any one of the following could result in a decline in demand for our technology and products, which would have a material adverse effect on our business:

•Any significant advance in techniques for attacking cryptographic systems, including the development of an easy factoring method or faster, more powerful computers, such as quantum computing;

•Publicity of the successful decoding of cryptographic messages or the misappropriation of keys; and

•Increased government regulation limiting the use, scope or strength of cryptography.

International and domestic regulatory environments regarding privacy and data protection regulations could have a material adverse impact on our results of operations.

We collect, transmit, store, and otherwise process (on our systems and on our third-party partners’ systems) our customers’ and our employees’ data that includes personally identifiable information that is subject to international and domestic privacy and data protection regulations. For example, in Europe, we are subject to the European Union's General Data Protection Regulation, (EU) 2016/679, commonly known as the GDPR, and laws implemented by EU member states. The GDPR and member state laws impose restrictions on the collection and use of personal data that are generally more stringent, and impose more significant burdens on subject businesses, than current privacy standards in the United States.

24

They establish several obligations that organizations must follow with respect to use of personal data, including a prohibition on the transfer of personal information from the EU to other countries whose laws do not protect personal data to an adequate level of privacy or security. We continue to adapt our compliance with GDPR through the use of standard contractual clauses and other methods; however, it is difficult to be certain that compliance has been achieved. We have expended significant resources to comply, but those methods may be subject to scrutiny by data protection authorities in EU member states.

Moreover, the decision of the United Kingdom, or UK to leave the EU has created uncertainty with regard to data protection regulations in the UK, particularly because the UK government has recently announced that it intends to revise aspects of its data protection regime to move further away from the EU approach. This may result in substantively different compliance obligations with respect to transfers of personal data out of the UK and the EU. Compliance with a newly adopted UK data privacy regime may result in substantial operational costs and require us to modify our data handling practices. The costs of compliance with GDPR and new UK data privacy laws, and other burdens imposed by such laws, regulations and policies that are applicable to us may limit our use of personal data and solutions and could have a material adverse impact on our results of operations. Additionally, we may face audits or investigations by one or more foreign government agencies relating to our compliance with GDPR and new UK data privacy laws that could result in the imposition of penalties or fines.

In the United States the federal and state governments have also enacted privacy and data protection regulations that impact us, our customers, and partners. For example, in June 2018, California enacted the California Consumer Privacy Act, or CCPA, which took effect January 1, 2020, and imposed many requirements on businesses that process the personal information of California residents. Many of the CCPA’s requirements are similar to those found in the GDPR, including requiring businesses to provide notice to data subjects regarding the information collected about them and how such information is used and shared, and providing data subjects the right to request access to such personal information and, in certain cases, request the erasure of such personal information. The CCPA also affords California residents the right to opt-out of “sales” of their personal information. The CCPA contains significant penalties for companies that violate its requirements. In November 2020 California voters passed a ballot initiative for the California Privacy Rights Act of 2020, or CPRA, which went into effect on January 1, 2023, and significantly expanded the CCPA to incorporate additional GDPR-like provisions including requiring that the use, retention, and sharing of personal information of California residents be reasonably necessary and proportionate to the purposes of collection or processing, granting additional protections for sensitive personal information, and requiring greater disclosures related to notice to residents regarding retention of information. The CPRA also created a new enforcement agency – the California Privacy Protection Agency – whose sole responsibility is to enforce the CPRA, which will further increase compliance risk. The provisions in the CPRA may apply to some of our business activities. In addition, other states, including Virginia, Colorado, Utah, and Connecticut, already have passed state privacy laws. Virginia’s privacy law also went into effect on January 1, 2023, and the laws in the other three states will go into effect later in the year. Other states will be considering these laws in the future, and Congress has also been debating passing a federal privacy law. These laws may impact our business activities, including our identification of research subjects, relationships with business partners and ultimately the marketing and distribution of our products.

We work to comply with all applicable international and domestic privacy and data protection regulations; however, these laws vary greatly from jurisdiction to jurisdiction, change rapidly, and are subject to interpretation, all of which leads to uncertainty in their applicability. Preparation and compliance with these regulations may require that we implement new processes and policies, or change our existing processes and policies or features of our systems, which may require substantial financial and other resources and which otherwise may be difficult to undertake. Any failure or perceived failure by us (or our third-party partners) to comply with these privacy and data protection regulations, our processes and policies, contractual provisions, or an actual, perceived or suspected data protection or information security incident could result in serious consequences for us. These consequences may include enforcement actions, investigations, prosecutions, fines, penalties, debarment, litigation, claims for damages by customers and other affected individuals, reputational loss, and financial and business losses.

We must comply with the requirements of being a public company, including developing and maintaining proper and effective disclosure controls and procedures and internal control over financial reporting. Any failure to comply with these requirements may adversely affect investor confidence in our company and, as a result, the value of our common stock.

As a public company, we are subject to the reporting requirements of the Exchange Act, the Sarbanes-Oxley Act, the Dodd-Frank Wall Street Reform and Consumer Protection Act, the listing requirements of Nasdaq and other applicable securities rules and regulations that impose various requirements on public companies. Our management and other

25

personnel devote a substantial amount of time to compliance with these requirements and such compliance has increased, and may continue to increase, our legal, accounting and financial costs.

The Sarbanes-Oxley Act requires that we maintain effective disclosure controls and procedures and internal control over financial reporting and furnish a report by management on, among other things, the effectiveness of our internal control over financial reporting on an annual basis. This assessment includes disclosure of any material weaknesses identified by our management in our internal control over financial reporting. We are also required to have our independent registered public accounting firm issue an opinion annually on the effectiveness of our internal control over financial reporting. During the evaluation and testing process, if we identify one or more material weaknesses in our internal control over financial reporting, we will be unable to assert that our internal control over financial reporting is effective.

We identified a material weakness in our internal control over financial reporting as of December 31, 2019. Although we remediated that material weakness, it is possible that additional material weaknesses, or significant deficiencies, in our internal controls will be identified in the future. Failure to maintain effective controls or implement new or improved controls could result in significant deficiencies or material weaknesses, affect management evaluations and auditor attestations regarding the effectiveness of our internal controls, failure to meet periodic reporting obligations, and material misstatements in our financial statements. Any material misstatement of our financial statements may result in a restatement, loss of investor and customer confidence, a decline in the market price of our common stock, and potential sanctions or investigations by Nasdaq, the SEC or other regulatory authorities. Failure to remedy any material weakness in our internal control over financial reporting, or to implement or maintain other effective control systems required of public companies, could also restrict our future access to the capital markets.

Our business in countries with a history of corruption and transactions with foreign governments increase the risks associated with our international activities.

We are subject to anti-corruption laws in the jurisdictions in which we operate, including the U.S. Foreign Corrupt Practices Act (FCPA), the U.K. Bribery Act, and other similar laws that prohibit improper payments or offers of payments to foreign governments and their officials and political parties by U.S. and other business entities for the purpose of obtaining or retaining business. We have operations, deal with and make sales to governmental or quasi-governmental customers in countries known to experience corruption, particularly certain countries in the Middle East, Africa, East Asia and South and Central America, and further expansion of our international selling efforts may involve additional regions. Our activities in these countries create the risk of unauthorized payments or offers of payments by one of our employees, consultants, sales agents or channel partners that could be in violation of various laws, including the FCPA and the U.K. Bribery Act, even though these parties are not always subject to our control. While we have implemented policies and training that mandate compliance with these anti-corruption laws, we cannot guarantee that these policies and procedures will prevent reckless or criminal acts committed by our employees, consultants, sales agents or channel partners. Violations of these laws may result in materially significant diversion of management’s resources as well as significant investigation and outside counsel expense. Violations of these laws may also result in severe criminal or civil sanctions, including suspension or debarment from government contracting, and we may be subject to other liabilities which could disrupt our business and result in materially adverse effect on our reputation, business, results of operations, and financial condition.

We are subject to numerous laws, regulations and customer requirements governing the production, distribution, sale and use of our products. Any failure to comply with these laws, regulations and requirements could result in unanticipated costs and could have a materially adverse effect on our business, results of operation, and financial condition.

We are subject to global legal, regulatory, and customer compliance requirements that span many different areas. For example, we are subject to the Restriction on the Use of Hazardous Substances Directive 2002/95/EC (also known as the RoHS Directive) and the Waste Electrical and Electronic Equipment Directive (also known as the WEEE Directive), which restrict the distribution of products containing certain substances, including lead, within applicable geographies and require a manufacturer or importer to recycle products containing those substances. These directives affect the worldwide electronics and electronics components industries as a whole. If we or our customers fail to comply with such laws and regulations, we could incur liabilities and fines and our operations could be suspended.

In addition, like many electronic devices, our hardware products contain certain minerals and derivatives that are subject to SEC disclosure and reporting requirements, or (Conflict Minerals). Compliance with these rules also requires due diligence including country of origin inquiries to determine the sources of Conflict Minerals used in our products. We may incur continued costs associated with complying with these disclosure requirements. These requirements may affect

26

pricing, sourcing and availability of Conflict Minerals used to produce our devices. We may be unable to verify the origin of all Conflict Minerals in our products. We may encounter challenges with customers and stakeholders if we are unable to certify that our products are conflict free.

Environmental compliance and management of environmental factors has produced significant regulatory and legislative efforts on a global basis, a trend we expect to continue. New laws and regulations intended to curb environmental impacts such as climate change and pollution may result in added compliance requirements and increased costs of energy for the Company and our suppliers which could result in a significant negative impact on our ability to operate or operate profitably. In addition, disclosures we may be required to make with respect to climate change may damage our reputation and have an adverse impact on our business.

We sell products and services to U.S. federal, state and local, as well as foreign government entities. Risks associated with selling our products and services to government entities include compliance with complex procurement regulations and government-specific contractual requirements that may vary from our standard terms and conditions, longer sales cycles that are not easy to predict, and varying government funding and budgeting processes. Selling to these entities is expensive and time-consuming and often requires significant up-front resource effort and expense. We have certain policies and processes in place to aid in compliance with applicable government contracting requirements; however, it is difficult to be certain that compliance has been achieved. Non-compliance with government entity requirements may result in significant material risk to the Company including debarment, reputational loss, and financial and business losses.

New laws and regulations and changes to current laws and regulations are always possible and, in some jurisdictions they may be introduced with little or no time to bring related products into compliance. Furthermore, our products are used by customers to assist with achieving compliance with laws and regulations that apply to their industry. Our failure to comply with laws and regulations and to adapt to our customers’ needs may prevent us from selling our products in a certain country or to a particular customer. In addition, these laws, regulations, and requirements may increase our cost of supplying the products by forcing us to redesign existing products, change manufacturing practices, or to use more expensive designs or components. In these cases, we may experience unexpected disruptions in our ability to supply customers with products, or we may incur unexpected costs or operational complexities to bring products into compliance, and we may experience lowered customer demand. This could have an adverse effect on our revenues, gross profit margins and results of operations and increase the volatility of our financial results.

We may require additional capital to support business growth, and this capital might not be available on acceptable terms, if at all.

We expect that our existing cash and cash equivalents will be sufficient to meet our anticipated cash needs for working capital and capital expenditures for at least the next 12 months. Our estimate as to how long we expect our cash and cash equivalents to be able to fund our operations is based on assumptions that may prove to be wrong, and we could use our available capital resources sooner than we currently expect. Further, changing circumstances, some of which may be beyond our control, could cause us to consume capital significantly faster than we currently anticipate, and we may need to seek additional funds sooner than planned. We intend to continue to make investments to support our business growth and may require additional funds to achieve our objectives and respond to business challenges, including the need to develop new features or enhance our products, improve our operating infrastructure or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds. If we raise additional funds through future issuances of equity or convertible debt securities, our existing stockholders could suffer significant dilution, and any new equity securities we issue could have rights, preferences and privileges superior to those of holders of our common stock.

General economic conditions both inside and outside the U.S., as well as the COVID-19 pandemic and geopolitical events, have recently resulted in a significant disruption of global financial markets. If the disruption persists and deepens, we could experience an inability to access additional capital, which could in the future negatively affect our capacity for certain corporate development transactions or our ability to make other important, opportunistic investments. In addition, market volatility, high levels of inflation and interest rate fluctuations may increase our cost of financing or restrict our access to potential sources of future liquidity. Adequate additional financing may not be available to us on acceptable terms, or at all. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.

Risks Related to Ownership of Our Common Stock

Our stock price has been and will likely continue to be volatile.

27

The market price of our common stock has been and may continue to be highly volatile and may fluctuate substantially as a result of a variety of factors, including those described in this “Risk Factors” section, many of which are beyond our control and may not be related to our operating performance. Factors that could cause fluctuations in the market price of our common stock include the following:

•Actual or anticipated fluctuations in our quarterly or annual operating results;

•Variance in our financial performance from our own financial guidance or from expectations of securities analysts;

•The trading volume of our common stock;

•Failure of securities analysts to maintain coverage of our company or changes in financial estimates by any securities analysts who follow our company;

•Changes in market valuations of other technology companies;

•Announcements by us or our competitors of significant technical innovations, contracts, acquisitions, strategic partnerships, joint ventures or capital commitments;

•Our involvement in any litigation or investigations by regulators;

•Our sale of our common stock or other securities in the future;

•Sales of large blocks of our common stock, including sales by our executive officers, directors and significant stockholders;

•Repurchases pursuant to Board-authorized share repurchase programs, or announcements of the inception or discontinuation of any such program;

•Short sales, hedging and other derivative transactions involving our capital stock;

•Additions or departures of any of our key personnel;

•Changing legal or regulatory developments;

•The inclusion or exclusion of our stock in ETFs, indices and other benchmarks, and changes made to related methodologies;

•Reactions by investors to uncertainties in the world economy and financial markets.

In recent years, the stock markets have experienced price and volume fluctuations that have affected and continue to affect the market prices of equity securities of many companies due to, among other factors, the actions of market participants or other actions outside of our control, including general market volatility caused by geopolitical events, developments in the COVID-19 pandemic, and general economic developments. These fluctuations have often been unrelated or disproportionate to the operating performance of those companies. Broad market and industry fluctuations, as well as general economic, political, regulatory and market conditions, may negatively impact the market price of our common stock. In the past, companies that have experienced volatility in the market price of their securities have been subject to securities class action litigation. We have been the target of this type of litigation in the past, and may be targeted again the future, which could result in substantial costs and divert our management’s attention.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2022-12-31, filed 2023-02-28 · accession 0001628280-23-005639

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 21 headings are on that chain and 16 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.