vrns-20221231
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
_____________________
FORM 10-K
_____________________
(Mark One)
for the Fiscal Year Ended December 31, 2022
or
for the transition period from to
Commission file number: 001-36324
________________________
VARONIS SYSTEMS, INC.
(Exact name of registrant as specified in its charter)
_____________________________
1250 Broadway, 28th Floor
New York, NY10001
(Address of principal executive offices) (zip code)
Registrant’s telephone number, including area code: (877) 292-8767
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol(s) Name of each exchange on which registered
Common Stock, par value $0.001 per share VRNS The NASDAQ Stock Market LLC
Securities registered pursuant to Section 12(g) of the Act: None
_____________________________
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large Accelerated Filer ☒ Accelerated Filer ☐
Non-accelerated Filer ☐ Smaller reporting company ☐
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report.☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements
of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
As of June 30, 2022, the aggregate market value of the registrant's voting and non-voting common equity held by non-affiliates was approximately $3.17 billion.
As of February 3, 2023, the registrant had 107,616,152 shares of common stock, par value $0.001 per share, outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the Registrant’s Proxy Statement relating to the 2023 Annual Meeting of Stockholders are incorporated by reference into Part III of this Annual Report on Form 10-K.
Special Note Regarding Forward-Looking Statements and Summary Risk Factors
This report contains, and management may make, certain forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended (the “Securities Act”), and Section 21E of the Securities Exchange Act of 1934, as amended (the “Exchange Act”). All statements, other than statements of historical facts, may be forward-looking statements. Forward-looking statements are often identified by the use of words such as “anticipate,” “believe,” “can,” “continue,” “could,” “estimate,” “expect,” “intend,” “likely,” “may,” “plan,” “project,” “seek,” “should,” “strategy,” “target,” “will,” “would” and similar expressions or variations intended to identify forward-looking statements. These statements are based on the beliefs and assumptions of our management based on information currently available to management. Such forward-looking statements are subject to risks, uncertainties and other important factors, many of which are difficult to predict and generally beyond our control, that could cause actual results and the timing of certain events to differ materially from future results expressed or implied by such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those identified in the “Summary Risk Factors” below and those discussed in “Item 1A-Risk Factors” and “Item 7-Management’s Discussion and Analysis of Financial Condition and Results of Operations.” Furthermore, such forward-looking statements speak only as of the date of this report. Except as required by law, we undertake no obligation to update any forward-looking statements to reflect events or circumstances after the date of such statements.
The risks that might cause actual results to differ from our expectations include, among other things, those that may be disclosed from time to time in subsequent reports filed with or furnished to the SEC, those described under “Risk Factors” set forth in Item 1A of this Annual Report, and the following, which also summarizes the principal risks of our business:
•the fact that the market for software that analyzes, secures, governs, manages and migrates enterprise data may not continue to grow or grow at the same pace;
•prolonged economic uncertainties or downturns;
•currency exchange rate fluctuations;
•increased competition;
•security breaches, cyberattacks or other cyber-risks and failure to comply with legal requirements, contractual obligations and industry standards regarding security, data protection and privacy;
•fluctuation in our quarterly results of operations due to variability in our revenues;
•our expansion into cloud-delivered services;
•our ability to predict renewal rates and manage growth effectively;
•our limited operating history at our current scale, which makes it difficult to evaluate and predict our future prospects;
•our history of losses;
•our ability to maintain strong relationships with our channel partners, including distributors and resellers, to whom we sell substantially all of our products and services;
•risks inherent in our international operations, including the effect of export and import controls and the risk of a violation or alleged violation of applicable anti-corruption or anti-bribery laws;
•collection and credit risks;
•our ability to maintain or enhance our brand recognition or reputation;
•our ability to retain, attract and recruit highly qualified personnel;
•our dependency on the continued services and performance of our co-founder, Chief Executive Officer and President;
•our ability to continually enhance and improve our technology;
•the fact that we derive substantially all of our revenues and cash flows from sales of licenses from a single platform of products;
•the fact that, if we experience interruptions or performance problems with our products, or if our software is not perceived as being secure, customers may reduce the use of or stop using our products;
•our ability to protect our proprietary technology and intellectual property rights;
•the fact that our tax rate may vary significantly depending on our stock price;
•our ability to fully utilize our net operating loss carryforwards;
•our indebtedness; and
•stock price volatility.
You should not place undue reliance on forward-looking statements. All forward-looking statements attributable to us or persons acting on our behalf are expressly qualified in their entirety by the foregoing cautionary statements. All such statements speak only as of the date of this Annual Report and, except as required by law, we undertake no obligation to update or revise publicly any forward-looking statements, whether as a result of new information, future events or otherwise.
i
VARONIS SYSTEMS, INC.
ANNUAL REPORT ON FORM 10-K
For The Fiscal Year Ended December 31, 2022
TABLE OF CONTENTS
Page
PART I
Item 1 Business 1
Item 1A Risk Factors 11
Item 1B Unresolved Staff Comments 35
Item 2 Properties 35
Item 3 Legal Proceedings 35
Item 4 Mine Safety Disclosures 35
PART II
Item 6 Reserved 38
Item 7A Quantitative and Qualitative Disclosures About Market Risk 50
Item 8 Financial Statements and Supplementary Data 52
Item 9A Controls and Procedures 89
Item 9B Other Information 89
Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 90
PART III
Item 10 Directors, Executive Officers and Corporate Governance 91
Item 11 Executive Compensation 91
Item 14 Principal Accounting Fees and Services 91
PART IV
Item 15 Exhibits and Financial Statement Schedules 92
ii
PART I
Item 1. Business
We were incorporated under the laws of the State of Delaware on November 3, 2004 and commenced operations on January 1, 2005. Our principal executive offices are located at 1250 Broadway, 28th Floor, New York, NY 10001. For convenience in this report, the terms “Company,” “Varonis,” “we” and “us” may be used to refer to Varonis Systems, Inc. and/or its subsidiaries, except where indicated otherwise. Our telephone number is (877) 292-8767.
Overview
Varonis is a pioneer in data security and analytics, fighting a different battle than conventional cybersecurity companies. We are pioneers because more than 15 years ago we recognized that enterprise capacity to create and share data far exceeded its capacity to protect it. We believed that rapid data growth combined with increasing information dependence would change both the global economy and the risk profiles of corporations and governments. Since our founding, our focus has been on using innovation to address the cyber-implications of these trends, creating software that provides new ways to track, alert and protect data wherever it is stored.
Data continues to grow in new and existing data stores both on-premises and in the cloud, a trend we have seen accelerate as companies around the world undergo a wave of digital transformation initiatives which have significantly impacted how they must approach data security. These data stores facilitate rapid collaboration from a hybrid workforce, but as these data stores grow in size and criticality, the relationships between the data they hold and the users that collaborate with it grow more complex, making those relationships difficult to visualize, understand and control without the benefit of automation.
In addition to data growth, companies face an environment where threat actors continue to refine their strategies to monetize sensitive data and the risk of substantial fines for noncompliance with data-centric regulations continues to grow. At the same time, organizations are seeing a global scarcity of in-house technical expertise, as the demand for cybersecurity professionals significantly outpaces supply, and IT and security experts are under pressure to solve growing problems with fewer resources. We believe that these trends provide us a long-term opportunity to fulfill our mission of protecting sensitive data for our customers and alleviating the resource pressure that companies are facing through our automation capabilities.
Enterprises now use many different combinations of data stores and require varying levels of automated protection. We believe our offering provides comprehensive data coverage and we aim to keep pace with the relentless growth and complexity of data. We started in 2005 with coverage for Windows file shares. Today, we offer coverage for more than 40 of the most mission-critical on-premises and cloud data stores and applications. In 2021, we launched our DatAdvantage Cloud hosted solution that centrally monitors and protects data across multiple cloud data stores, Software-as-a-Service ("SaaS") applications and Infrastructure-as-a-Service ("IaaS") environments as well as Data Classification Cloud to help automatically identify sensitive information. In 2022, we continued to enhance DatAdvantage Cloud and Data Classification Cloud with new functionality. In addition, we announced the availability of our flagship Varonis Data Security Platform as a SaaS, which offers simpler deployment, faster time-to-value, and groundbreaking new automation capabilities. Given these benefits to our customers, we expect SaaS deployments to grow significantly over the next several years to become the primary driver of our sales as we transition our business to a predominately SaaS-based company.
Our software specializes in data protection, threat detection and response, data privacy and compliance. Varonis software enables enterprises of all sizes and industries to protect data stored on-premises and in the cloud, including: sensitive files and emails; confidential personal data belonging to customers, patients and employees; financial records; source code, strategic and product plans; and other intellectual property. Recognizing the complexities of securing data, we have built an integrated platform for security and analytics to simplify and streamline security and data management.
The Varonis Data Security Platform helps enterprises protect data against cyberattacks from both external and internal threats. Our technology enables enterprises to analyze data, account activity and user behavior to help detect and prevent attacks. Varonis prevents or limits unauthorized use of sensitive information, detects and prevents potential cyberattacks and limits potential damage by automatically locking down data, allowing access to only those who need it and automating the removal of stale data when it is no longer useful. Customers can efficiently sustain a secure state with automation and address additional important use cases, including data protection, data governance, Zero Trust, compliance, data privacy, classification and threat detection and response. The Varonis Data Security Platform is driven by a proprietary technology, our Metadata Framework, that extracts critical metadata, or data about data, from an enterprise’s information technology ("IT") infrastructure. Our platform uses this contextual information to map functional relationships among employees, data objects, systems, content and usage. In doing so, our platform provides real-time intelligence about an enterprise’s massive volumes of data, making it more secure, accessible and manageable.
1
We believe that the (i) Varonis Data Security Platform technology, (ii) coverage of more than 40 of the most mission-critical on-premises and cloud data stores and applications and (iii) technical experts within the Company who continue to expand and improve our offering are our primary, hard to replicate competitive advantages. The strength of our solution is driven by several proprietary technologies and methodologies that we have developed, coupled with how we have combined them into our highly versatile platform. Our belief in our technological advantage stems from us having developed a way to do each of the following:
•analyze the relationships between users and data with sophisticated algorithms, including cluster analyses and machine learning;
•visualize and depict the analyses in an intuitive manner, including simulating contemplated changes and automatically executing tasks that are becoming increasingly more complex for IT and business personnel;
•identify and automatically classify data as sensitive, critical, private or regulated, to help organizations ensure compliance with regulations, including the General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA");
•automate remediation of excessive access to sensitive information across large data stores and cloud applications to safely ensure a Zero Trust or least privilege model;
•profile users, devices and data to detect suspicious account behavior and unusual file and email activity using deep analysis of metadata, machine learning and user behavior analytics;
•profile cloud configuration and interconnectivity to identify potential exposure and abuse;
•generate meaningful, actionable alerts when security-related incidents are detected;
•enable security teams to investigate and respond to cyber threats more quickly and conclusively;
•automatically respond to severe incidents, such as ransomware, to limit potential impact and reduce recovery times;
•provide customers Live Updates to our platform which address the rapidly evolving threats they face;
•determine relevant metadata and security information to capture without impacting the enterprise's computing and network infrastructure;
•modify and enrich that metadata in a way that makes it comparable and analyzable despite it having originated from disparate IT systems, and create supplemental metadata, as needed, when the existing IT infrastructure’s activity logs are insufficient;
•decipher the key functional relationships of metadata, the underlying data, and its creators; and
•use those functional relationships to create a graphical depiction, or map, of the data that will endure as enterprises continuously add large volumes of data to their network and storage resources.
The broad applicability of our technology has resulted in our customers deploying our software for numerous use cases. These use cases include: automatic discovery and classification of high-risk, sensitive data; data security posture management; automated remediation of over-exposed data; centralized visibility and risk analysis of enterprise data and monitoring of user behavior and file activity; security monitoring and risk reduction; data breach, insider threat, malware and ransomware detection; automatic response to ransomware and other severe incidents to limit exposure and reduce recovery times; data ownership identification, assignment, and automatic involvement; forensics, reporting and auditing with searchable logs; meeting security policy and compliance regulation; automatic data migration; cloud migration; automation of retention and disposition policies; automatic data quarantine; intelligent archiving; and automated indexing for data subject requests related to privacy and compliance requirements.
We sell substantially all of our products and services to channel partners, including distributors and resellers, which sell to end-user customers, which we refer to in this report as our customers. We believe that our sales model, which combines the leverage of a channel sales model with our highly trained and professional sales force, has and will continue to play a major role in our ability to grow and to successfully deliver our unique value proposition for securing enterprise data. While our products serve customers of all sizes, in all industries and all geographies, the marketing focus and majority of our sales focus is on
2
targeting organizations with 1,000 users or more who can make larger initial purchases with us and, over time, have a greater potential lifetime value. Our customers span leading firms in the financial services, public, healthcare, industrial, insurance, technology, consumer and retail, energy and utilities, construction and engineering and education sectors. We believe our existing customer base serves as a strong source of incremental revenues given our broad data coverage, the growing volumes and complexity of their enterprise data and the associated security concerns.
In the first quarter of 2019, we began offering subscription licenses whereby the customer has the right to install our software on premises and use it over a designated period of time. At this time, our subscription revenues now account for substantially all of our total license revenues.
To date, a small portion of our sales were derived from our SaaS offerings that allow customers to use hosted software. As we transition to a predominantly SaaS-based business model, we expect that sales from these arrangements will become a significant portion of our total sales over the next several years.
Size of Our Market Opportunity
The International Data Corporation’s Global DataSphere Forecast, 2022-2026, predicts that over the next five years, data will grow at a compound annual growth rate of 21% to reach more than 221 zettabytes (or 221 trillion Gigabytes) by 2026. That data will include both structured and unstructured data, but unstructured data overwhelmingly dominates, accounting for more than 90% of the data created each year. We expect this significant growth to continue creating a need for technologies that use automation to protect and manage data. We believe that the diverse functionalities offered by our platform position us well to capitalize on this powerful trend in the digital universe.
Our Technology
Our proprietary technology extracts critical information about an enterprise’s data and its supporting infrastructure, and uses this contextual information, or metadata, to create a functional map of an enterprise’s data and underlying file systems. Our Metadata Framework technology has been architected to process large volumes of enterprise data and the related metadata at a massive scale with minimal demands on the existing IT infrastructure. On October 31, 2022, Varonis announced the availability of our flagship Varonis Data Security Platform as a SaaS; prior to this announcement, only the DatAdvantage Cloud licenses were available as a cloud-hosted solution. The benefits of SaaS delivery are widely established for both customers and providers, and we believe this evolution will be transformational for several reasons: customers will be able to more quickly and easily deploy and maintain our solutions with reduced infrastructure requirements and lower upfront costs; and risk assessments, the core of our sales motion, are expected to be quicker and more controllable.
Key Benefits of Our Technology
We believe our transition to SaaS enhances many of the below benefits and will allow us to deliver additional benefits to customers that our cloud technology unlocks. Varonis will have better visibility into customer usage, issues, and behaviors that will better inform our innovation; customers will seamlessly benefit from continual threat model updates that will help them stay ahead of evolving threats; and the SaaS model will allow us to deliver additional features and functionality to customers more efficiently.
Data Protection
Comprehensive Solution for Managing and Protecting Enterprise Data. Our products enable a broad range of functionality, including data governance, least privilege and Zero Trust, as well as intelligent retention. Moreover, our solution is applicable across most major enterprise data stores and SaaS applications (Windows, UNIX/Linux, Intranets, email systems, Microsoft 365, including SharePoint Online, Teams and OneDrive for Business, Salesforce, AWS, Slack, GitHub, Okta, Google Drive and Box).
Actionable Insight and Automation. Our products help customers identify and prioritize risks to their data and automatically remediate exposures so that they are less vulnerable to internal and external threats, more compliant and consistently follow a least privilege model. Because of the complexity present in even modest enterprises, we believe that effective remediation is impossible at scale without intelligent automation.
Visibility and Data Monitoring Capabilities All in One Place. Our solution combines analysis from disparate on-premises and cloud stores, applications and infrastructure and presents them in a single view, even as data storage and user access become more dispersed and complex in hybrid environments.
3
Fast Time to Value and Low Total Cost of Ownership. Our solutions do not require custom implementations or long deployment cycles. Our software can be deployed in under an hour and allows customers to realize real value with minimal effort. The availability of our platform as a SaaS is expected to further reduce the total cost of ownership and accelerate the time-to-value for our customers.
Ease of Use. While we utilize complex data structures and algorithms in our data engine, we abstract that complexity to provide a sleek, intuitive interface. Our software is accessible through a standard web browser and requires limited training, saving time and cost and making it accessible to a broader set of users. The availability of our platform as a SaaS is expected to further improve the ease of use for our customers, with a more modern, responsive front-end user interface and a best-of-breed cloud infrastructure on the backend.
Highly Scalable and Flexible Data Engine. Our metadata analysis technology is built to be highly scalable, allowing our customers to analyze vast amounts of enterprise data. Moreover, our proprietary platform is built with a flexible, modern cloud architecture, allowing customers to seamlessly and transparently expand their data coverage without impacting performance.
Threat Detection and Response
Threat Detection and Response with User, Data and System Context. Our solutions combine classification and data access governance with User and Entity Behavior Analytics ("UEBA") on data stores, cloud applications, directory services and perimeter devices, including Domain Name System ("DNS"), Virtual Private Network ("VPN") and web proxy, for accurate detection and risk reduction. Our solutions reduce risk relating to unauthorized use and cyberattacks and reduce incident time to detection (TTD) and time to resolution (TTR).
Protect Data from Insider Threats, Data Breaches, Malware and Cyberattacks. Our solutions analyze how employee accounts, service accounts and admin accounts use and access data, profile employees’ roles and file contents, baseline “normal” behavior patterns, and alert on significant deviations from profiled behaviors. Our customers are able to detect advanced persistent threats ("APTs"), cybercriminals, rogue insiders, attackers that have compromised internal systems and employee accounts, malware, ransomware and other significant threats.
Proactive Incident Response. Under a SaaS delivery model, the Varonis incident response and forensics teams can review, triage, and proactively notify customers of any incidents that require their attention. Because Varonis centrally monitors a wide array of customer environments, we can spot patterns across tenants and take action to prevent data breaches. We expect this ability will be accelerated with our transition to a SaaS-based business model.
Compliance
Discover and Identify Regulated Data. Our solutions automatically discover, identify and classify sensitive, critical and regulated data to help meet privacy and compliance requirements.
Monitor and Detect Security Vulnerabilities. Our solutions analyze, monitor, detect and report on potential security vulnerabilities: helping companies achieve compliance by creating full audit trails, achieving a least privilege model and locking down sensitive data to only those who need it, and facilitate breach notification and security investigations. By ensuring least privilege, monitoring all access and alerting on potential misuse, Varonis enables privacy-by-design on data stores containing sensitive and regulated information.
Fulfill Data Subject Access Requests ("DSARs") and Protect Consumer Data. Our solutions help fulfill DSARs from file systems on-premises and in the cloud. Customers can easily find relevant files, pinpoint who has access and enforce policies to move and quarantine regulated data.
Our Growth Strategy
Our objective is to be the primary vendor to which enterprises turn to protect their data. The following are key elements of our growth strategy.
Extend Our Technological Capabilities Through Innovation and Strategic Transactions. We intend to increase, in absolute dollars, our current level of investment in product development in order to enhance existing products to address new use cases and continue to deliver new products. We believe that the flexibility, sophistication and broad applicability of our platform will allow us to use this framework as the core of numerous future products built on our same core technology. Our
4
ability to leverage our research and development resources has enabled us to create a new product development engine that we believe can proactively identify and solve enterprise needs and help us further penetrate and grow our markets. Additionally, in 2021, we introduced new data coverage to protect additional cloud applications and infrastructure that were further developed by us after acquiring a provider of software that maps and analyzes relationships between users and data across a number of cloud applications and services. Lastly, we recently announced the availability of our flagship Varonis Data Security Platform as a SaaS, which we believe will be mutually beneficial for us and our customers. We will continue to seek additional opportunities to extend our technological capabilities and grow our business, from continued organic investments in our research and development efforts to technological tuck-in acquisitions.
Grow Our Customer Base. The unabated rise in enterprise data, ubiquitous reliance on digital collaboration and increased cybersecurity concerns continue to drive demand for data protection, compliance and threat detection and response solutions. We intend to capitalize on this demand by targeting new customers, underpenetrated markets and use cases for our solutions. Our solutions address the needs of customers of all sizes, ranging from small and medium sized businesses to large multinational companies with hundreds of thousands of employees and petabytes of data. Although our solutions are applicable to organizations of all sizes, we have and will continue our focus on targeting larger organizations who can make larger purchases with us initially and over time.
Increase Sales to Existing Customers. We believe significant opportunities exist to further expand relationships with existing customers. Data growth and related security concerns continue across all data stores, and enterprises want to standardize solutions that help them manage, protect and extract more value from their data, wherever it is stored. We expect to continue to drive incremental sales from our existing customers through the increased use of our software within our installed base by expanding footprint and usage. We believe our existing customer base serves as a strong source of incremental revenues given our broad product functionality, their growing volume and complexity of enterprise data and the associated security concerns. As we continue to innovate by addressing more use cases, adding more data coverage, and providing automated data security outcomes to customers, we expect to see broader and stickier adoption of our platform. In addition, our transition to a predominately SaaS-based business model provides us with a unique opportunity to convert existing customers to SaaS. Our renewal rate for the year ended December 31, 2022 continued to be over 90%. Our key strategies to ensure a high renewal rate for our products include focusing on the quality and reliability of our customer service and support teams and providing software upgrades and enhancements when available.
Grow Sales from Our Newer Licenses and Functionality. We continue to introduce additional licenses and enhancements to existing products to support new functionalities and believe these can also be a meaningful contributor to our growth. In October 2020, we announced the acquisition of Polyrize Security Ltd. ("Polyrize"), whose technology was used to the launch of the DatAdvantage Cloud and Data Classification Cloud licenses. In the second half of 2021, we launched our first SaaS offering, introducing products and support for cloud applications and infrastructure, including AWS, Box, GitHub, Google Drive, Jira, Okta, Salesforce, Slack and Zoom. On October 31, 2022, we announced the availability of our flagship Varonis Data Security Platform as a SaaS, which was previously only sold as a self-hosted solution.
Expand Our Sales Force. Continuing to expand our sales force will be essential to achieving our customer base expansion goals. Our approach to in-house development of sales representatives through the Varonis Academy have been key to our successful growth in the past and will be central to our growth plan in the future. While our products serve customers of all sizes, in all industries and all geographies, the marketing focus and majority of our sales focus is on targeting organizations with 1,000 users or more who can make larger initial purchases with us and, over time, generate a greater potential lifetime value. Our customers span leading firms in the financial services, public, healthcare, industrial, insurance, technology, consumer and retail, energy and utilities, construction and engineering and education sectors. We also believe our existing customers represent significant future revenue opportunities for us. We believe that our sales model, which combines the leverage of a channel sales model with our highly trained and professional sales force to efficiently identify leads, perform risk assessments and convert them to satisfied customers, has and will continue to play a major role in our ability to grow and to successfully deliver our unique value proposition for enterprise data.
Establish Our Data Security Platform as the Industry Standard. We have worked with several of the leading providers of NAS and hybrid cloud storage, including Dell/EMC, IBM, NetApp, HP, Hitachi and Nasuni in order to expand our market reach and deliver enhanced functionality to our customers. We have worked with these vendors to assure compatibility with their product lines. Through the use of application programming interfaces (APIs), and other integration work, our solutions also integrate with many providers of solutions in the ecosystem. We will continue to pursue such collaborations wherever they advance our strategic goals, thereby expanding our reach and establishing our platform as the de facto industry standard when it comes to enterprise data.
Continue International Expansion. We believe there is a significant opportunity for our platform to address the need for data protection and threat detection and response in international markets. Revenues from Europe, the Middle East and Africa
5
(“EMEA") accounted for 23% and revenues from Rest of World (“ROW”) accounted for 3% of our revenues, respectively, in 2022. We believe that international expansion will be a key component of our growth strategy, and we will continue to invest and market our products and services overseas. These investments have recently included key hires in the APAC region, including an overall head of the region, as well as country managers in different locations.
Our Products
With the introduction of our flagship Varonis Data Security Platform as a SaaS, our licensing model is expanding. While our on-premises subscription licensing will remain the same, we are transitioning away from selling only those licenses, in which we offer an array of modular licenses which customers can purchase individually or as a bundle, to SaaS, which will be sold as platform licenses providing, by default, the functionality of multiple core modules. Details are provided in the sections below.
On-Premises Subscription ("OPS")
Our self-hosted product licenses utilize our core technology to deliver features and functionality that allow enterprises to fully understand, secure and benefit from the value of their data. This architecture gives our clients the ability to select the features they require for their business needs and the flexibility to expand their usage simply by adding a license, and the fully-integrated nature of our products allows individual products to enhance the functionality of the others. At the same time, the ease of consumption under a subscription-based model has allowed us to deliver on customer demand for a greater number of our licenses, providing our customers more value more quickly while leading to substantial future license upsell and cross-sell opportunities.
•DatAdvantage. DatAdvantage, our flagship product, captures, aggregates, normalizes and analyzes every data access event for every user on Windows and UNIX/Linux servers, storage devices, email systems, Intranet servers, cloud applications and data stores, without requiring native operating system auditing functionalities or impacting performance or storage on file systems.
•DatAlert. DatAlert profiles users and devices and their associated behaviors with respect to systems and data, detects and alerts on meaningful deviations that indicate compromise, provides a web-based dashboard and investigative interface and seamlessly integrates with security information and event management systems (SIEM). DatAlert helps enterprises quickly detect suspicious activity, prevents data breaches and cyberattacks, performs security forensics, visualizes risk and prioritizes and accelerates investigation.
•Data Classification Engine. Data Classification Engine identifies and tags data based on criteria set in multiple metadata dimensions and provides business and IT personnel with actionable intelligence about this data, including a prioritized list of folders and files containing the most sensitive data and with the most inadequate permissions. For the identified folders and files, it also identifies who has access to that data, who is using it, who owns it, and recommendations for how to restrict access without disrupting workflow.
•DataPrivilege. DataPrivilege provides a self-service web portal that allows users to request access to data necessary for their business functions, and allows owners to review accessibility, sensitivity and usage of their data assets and grant and revoke access without IT intervention.
•Data Transport Engine. Data Transport Engine provides an execution engine that unifies the manipulation of data and metadata, translating business decisions and instructions into technical commands, such as data migration or archiving. Data Transport Engine allows both IT and business personnel to standardize and streamline activities for data management and retention.
•DatAnswers. DatAnswers provides a secure, relevant and timely search functionality for enterprise data and helps companies comply with data privacy regulations, eDiscovery requests and to facilitate data subject access requests.
Software-as-a-Service ("SaaS")
Our SaaS product portfolio currently includes two product lines: (1) our flagship Varonis Data Security Platform, which protects Microsoft 365, Windows file shares, Active Directory, Edge devices (VPN, DNS, proxy) and hybrid NAS storage, and (2) DatAdvantage Cloud, which protects SaaS and IaaS environments such as Salesforce, AWS, Google Drive, Box, GitHub, Zoom, Slack, Jira and Okta.
6
•Varonis Data Security Platform. The early success of our license bundles under the OPS model demonstrated that customers want to utilize and benefit from the majority of Varonis’ core functionality from the start. We know that customers who utilize a higher number of licenses see more value upfront through automation and synergy between modules. Therefore, we are drastically simplifying our subscription licensing under SaaS, combining five of our most popular licenses into a single Varonis Data Security Platform license. The Varonis Data Security Platform SaaS license will include, by default, the functionality of five core modules: DatAdvantage, DatAlert, Automation Engine, Data Classification Engine and Data Classification Policy Pack. We will no longer refer to these licenses by name; rather, they will be considered built-in functionality of the Varonis Data Security Platform SaaS license. In addition to the functionality mentioned above, the Varonis Data Security Platform SaaS license includes new capabilities not available in our self-hosted product suite. Today, the Varonis Data Security Platform SaaS license includes:
◦Risk assessment dashboards. Provides customers with real-time visibility of their data security posture across their multi-cloud and on-premises data, helps prioritize remediation efforts, and tracks progress over time.
◦Data access intelligence. Combines data sensitivity, permissions, and activity to show customers who has access to critical data (i.e., their data blast radius), how they got access, and whether access is necessary.
◦Data discovery & classification. Automatically and continuously scans the contents of files, folders, and other objects to determine sensitivity with a high degree of accuracy and precision.
◦Discovery policy library. A frequently updated library for identifying and classifying personal information specific to GDPR, CCPA, and US federal controlled unclassified information (CUI).
◦Least privilege automation. Automatically and continuously remediates excessive data access granted via shared links, direct permissions, and group memberships without manual effort and without impacting business continuity.
◦Data activity monitoring. Gives customers a real-time view into who is accessing data via a normalized and enriched log of data-centric events such as create, open, read, move, modify, and delete. Varonis also tracks, among other things, permission changes, authentication events, password updates and shared link activity.
◦Data detection and response. Provides high-fidelity, data-centric alerts and automated response actions. Includes a web-based alerts dashboard and investigative interface, and seamlessly integrates with security information and event management systems (SIEM).
◦User & entity behavior analytics. Profiles users and devices and their associated behaviors with respect to systems and data, detects and alerts on meaningful deviations that indicate compromise. New UEBA threat models are automatically delivered to customers to guard against evolving tactics used by cybercriminals, insiders, and APTs.
Varonis Data Security Platform SaaS customers can decide which data stores, applications, and infrastructure they want to protect by purchasing “Protection Packages.” Our SaaS platform supports virtually every resource covered by our self-hosted version, and we believe our SaaS architecture will allow us to add support for new resources faster than ever.
The Protection Packages currently available for the Varonis Data Security Platform SaaS are:
◦Microsoft 365. Includes support for SharePoint Online, OneDrive for Business, Microsoft Teams, and Azure AD. Customers can purchase add-on support for Exchange Online.
◦Windows & NAS. Includes support for Windows/CIFS-based file shares and NAS storage such as NetApp and Dell EMC. Customers can purchase add-on support for on-premises Active Directory and Edge devices (VPN, DNS, proxy).
◦Hybrid. Combined support for the protected resources in the Microsoft 365 and Windows & NAS packages.
•Varonis DatAdvantage Cloud. DatAdvantage Cloud is a SaaS platform that helps organizations protect data across SaaS applications and IaaS environments. DatAdvantage Cloud offers functionality similar to our flagship Varonis Data Security Platform including, but not limited to, data risk assessment dashboards, data classification, data access
7
intelligence, data activity monitoring, data detection and response, and least privilege automation. The protected resources currently available for DatAdvantage Cloud are Salesforce, Google Drive, Box, AWS (including S3), GitHub, Slack, Zoom, Okta, and Jira.
Our Customers
We currently have customers in over 90 countries. Our customers span numerous industries and vary greatly in size, ranging from small and medium businesses to large multinational enterprises and government agencies. Our customers include leading firms in the financial services, public, healthcare, industrial, insurance, technology, consumer and retail, energy and utilities, construction and engineering and education sectors, with hundreds of thousands of employees and petabytes of data.
Services
Maintenance and Support of Subscription and Perpetual Licenses
Maintenance and support associated with a subscription contract is included in the Subscriptions revenue line of the statement of operations. Maintenance and support associated with perpetual licenses is included in the Maintenance and services line of the statement of operations. These maintenance agreements provide customers the right to receive support and unspecified upgrades and enhancements when and if they become available during the maintenance period and access to our technical support services.
We maintain a customer support organization that provides all levels of support to our customers. Our customers that purchase maintenance and support services receive guaranteed response times, direct telephonic support and access to online support portals. Our customer support organization has global capabilities with expertise in both our software and complex IT environments and associated third-party infrastructure.
Professional Services
While users can easily deploy our software on their own, certain enterprises use our professional service team to provide fee-based services, which include training our customers in the use of our products, providing advice on network design, product configuration and implementation, automating and customizing reports and tuning policies and configuration of our products for the particular characteristics of the customer’s environment. Although professional services have always been a small percentage of our total revenues, we have recently seen, and expect to continue to see, that percentage decline as many of our newer licenses can provide remediation in more automated ways.
Sales and Marketing
Sales
We sell substantially all of our products and services to a global network of resellers and distributors that we refer to as our channel partners. Our channel partners, in turn, sell the products they purchase from us to customers. In addition, we maintain a highly trained professional sales force that is responsible for overall market development, including the management of the relationships with our channel partners and supporting channel partners in winning customers through operating demonstrations and risk assessments. Our channel partners identify potential sales targets, maintain relationships with customers and introduce new products to existing customers. Sales to our channel partners are generally subject to our standard, non-exclusive channel partner agreement. These agreements are generally for a term of one year with a one-year renewal term and can be terminated by us or the channel partner for any reason upon 30 days’ notice. A termination of the agreement has no effect on orders already placed. Payment to us from the channel partner is typically due within 30 to 60 calendar days of the invoice date.
Marketing
Our marketing strategy focuses on building our brand and product awareness, increasing customer adoption and demand, communicating advantages and business benefits as well as generating leads for our channel partners and sales force. We market our software as the Varonis Data Security Platform, a solution for securing and managing enterprise data. We execute our marketing strategy by leveraging a combination of internal marketing professionals, external marketing partners and a network of regional and global channel partners. Our marketing organization is responsible for branding, content generation, demand generation, field marketing and product marketing, and works with our business operations team to support channel marketing and sales support programs. We provide one-on-one and community education and awareness and promote the
8
expanded use of our software. We host in-person or virtual Varonis Connect! customer events across sales regions, as well as free, online technical webinars in multiple regions. We focus our efforts on highly relevant content creation, events, campaigns and activities that can be leveraged by our channel partners worldwide to extend our marketing reach, such as information regarding product awards and technical certifications, security training, regional seminars and conferences, webinars, podcasts and various other demand-generation activities. Our marketing efforts also include public relations in multiple regions, industry analyst relations, customer marketing, account-based marketing, targeted advertising, extensive content development available through our website and content syndication, and our active blog.
Research and Development
Our research and development efforts are focused primarily on improving and enhancing our existing products, including features and new SaaS functionalities for our products, as well as developing new products. Use of our products has expanded from data governance into areas such as data security, threat detection and response, privacy, accessibility and retention, and we anticipate that customer demand and innovation will drive functionality into additional areas. We regularly release updates to our products which incorporate new features and enhancements to existing ones. We conduct the majority of our research and development activities in Israel, and we believe this provides us with access to world-class engineering talent. In addition, we continue to seek opportunities to extend our technological capabilities and grow our business from strategic technological tuck-in acquisitions.
Intellectual Property
We attempt to protect our technology and the related intellectual property under patent, trademark, copyright and trade secret laws, confidentiality procedures and contractual provisions. No single intellectual property right is solely responsible for protecting our products. The nature and extent of legal protection of our intellectual property rights depends on, among other things, its type and the jurisdiction in which it arises. As of December 31, 2022, we had 85 issued patents and 12 pending patent applications in the United States. Our issued U.S. patents expire between 2025 and 2039. We also had 55 patents issued and 42 applications pending for examination in non-U.S. jurisdictions, and two pending Patent Cooperation Treaty (“PCT”) patent applications, all of which are counterparts of our U.S. patent applications. The claims for which we have sought patent protection relate primarily to inventions we have developed for incorporation into our products.
In addition to patented technology, we rely on our unpatented proprietary technology and trade secrets. We generally enter into confidentiality agreements with our employees, consultants, service providers, vendors and customers and generally limit internal and external access to, and distribution of, our proprietary information and proprietary technology through certain procedural safeguards. We also rely on invention assignment agreements with our employees, consultants and others, to assign to the Company all inventions developed by such individuals in the course of their engagement with the Company.
Moreover, we have registered the “Varonis” name and logo and “DatAdvantage,” “DataPrivilege,” “DatAlert,” and other names in the United States and, as related to some of these names, certain other countries.
In addition to Company-owned intellectual property, we license software from third parties for integration into our solution, including open source software and other software available on commercially reasonable terms. It may be necessary in the future to seek or renew licenses relating to various aspects of our products, processes and services. While we have generally been able to obtain such licenses on commercially reasonable terms in the past, such third parties may not continue to maintain such software or continue to make it available to us.
Seasonality
See Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations — Seasonality and Quarterly Trends.”
Competition
While there are some companies which offer certain features similar to those embedded in our solutions, as well as others with which we compete in certain use cases, we believe that we do not currently compete with a company that offers the same breadth of functionalities on the number of platforms and application that we cover. Nevertheless, we do compete against a select group of software vendors that provide standalone solutions, similar to those found in our comprehensive software suite, in the specific markets in which we operate. We also face direct competition with respect to certain use cases, specifically data migration, data subject access requests and Active Directory security. As we continue to augment our functionality with insider threat detection and user behavior analytics and as we expand our classification capabilities to better serve compliance needs with new regulations, like GDPR, CCPA and other data privacy laws, and as these functionalities continue to be recognized as
9
critical to protect enterprise data, we may face increased perceived and real competition from other security and classification technologies. In the future, as customer requirements evolve and new technologies are introduced, we may experience increased competition if established or emerging companies develop solutions that address the enterprise data market. Furthermore, because we operate in an evolving market, we anticipate that competition will increase based on customer demand for these types of products.
A number of factors influence our ability to compete in the markets in which we operate, including, without limitation: the continued reliability and effectiveness of our products’ functionalities; the breadth and completeness of our solutions’ features; the scalability of our solutions; and the ease of deployment and use of our products. We believe that we generally compete favorably in each of these categories. We also believe that we distinguish ourselves from others by delivering a single, integrated solution and sophisticated automation to address our customers’ needs regarding security access, governance, privacy and retention with respect to their enterprise data. However, we may not be able to remain unique in this capacity or continue to be able to compete favorably with other providers in the future.
If a more established company were to target our market, we may face significant competition. They may have competitive advantages, such as greater name recognition, larger sales, marketing, research and acquisition resources, access to larger customer bases and channel partners, a longer operating history and lower cloud labor and development costs, all of which may enable them to respond more quickly to new or emerging technologies and changes in customer requirements or to devote greater resources to the development, promotion and sale of their products than we do. Increased competition could result in us failing to attract customers or maintain renewals and licenses at the same rate. It could also lead to price cuts, alternative pricing structures or the introduction of products available for free or a nominal price, reduced gross margins, longer sales cycles and loss of market share.
In addition, our current or prospective channel partners may establish cooperative relationships with any future competitors. These relationships may allow future competitors to rapidly gain significant market share. Such developments could also limit our ability to generate revenues from existing and new customers. If we are unable to compete successfully against current and future competitors our business, results of operations and financial condition may be harmed.
Employees and Human Capital Resources
As of December 31, 2022, we had 2,143 employees and independent contractors who developed, marketed, sold and supported our technology solutions, including 952 in the United States, 708 in Israel and 483 in other countries.
We understand that our innovation leadership is ultimately rooted in our people. Competition for qualified personnel in the technology space is intense, and our success depends in large part on our ability to recruit, develop and retain a productive and engaged workforce. Accordingly, investing in our employees and their well-being, offering competitive compensation and benefits, promoting diversity and inclusion, adopting effective human capital management practices and community outreach constitute core elements of our corporate strategy.
•Offer Competitive Compensation and Benefits. We strive to ensure that our employees receive competitive and fair compensation and innovative benefit offerings, tying incentive compensation to both business and individual performance, offering competitive maternal and paternal leave policies, providing meaningful retirement and health benefits and maintaining an employee stock purchase plan.
•Support Employee Well-being and Engagement. We support the overall well-being of our employees from a physical, emotional, financial and social perspective. We also regularly seek input from employees, including through broad employee satisfaction and pulse surveys on specific issues, intended to assess our degree of success in promoting an environment where employees are engaged, satisfied, productive and possess a strong understanding of our business goals. Our global well-being programs include a long-standing practice of remote working arrangements, flexible paid time off, life planning benefits, wellness platforms and employee assistance. In addition, we ensure ongoing check-ins with employees by HR and managers to provide additional channels of support.
•Promote Sense of Belonging through Diversity and Inclusion Initiatives. We conduct diversity and code of conduct trainings with employees and managers to share our views on the importance of diversity and the promotion of an inclusive and diverse workplace, where all individuals are respected and feel they belong regardless of their age, race, national origin, gender, religion, disability, sexual orientation or gender identity. We also require all employees to participate in unconscious bias training to improve awareness. We work with diversity focused candidate application platforms to increase access to diverse talent. Our customers are located in over 90 countries and our global workforce operates across cultures, functions, language barriers and time zones to provide them dedicated and ongoing support.
10
•Provide Programs for Employee Recognition. We offer rewards and recognition programs to our employees, including awards to recognize employees who best exemplify our values and spot awards to recognize employee contributions. We believe that these recognition programs help drive strong employee performance. We conduct semi-annual employee performance reviews, where each employee is evaluated by their personal manager and also conducts a self-assessment, a process which empowers our employees. Employee performance is assessed based on a variety of key performance metrics, including the achievement of objectives specific to the employee’s department or role. Employees have access to an internal platform to recognize their peers based on their professional and socially responsible contributions to the Company.
•Create Opportunities for Growth and Development. We focus on creating opportunities for employee growth, development, training and education, including opportunities to cultivate talent and identify candidates for new roles from within the company, as well as management and leadership development programs. Employee training and education includes online certification, in person certification and new hire training bootcamps. We also conduct manager training programs on an annual basis, which include in-depth managerial and coaching skills, as well as tailored feedback. We have established an internal mentoring program in which seasoned employees mentor new managers based on defined goals.
•Promote Community Outreach and Support. We believe it is important to give back and promote community outreach and support through corporate giving and employee volunteerism in the communities in which we live and work. We also provide corporate matching of employee charitable donations and flexible volunteering during work time, letting our employees know that we support the charitable efforts that matter to them.
Available Information
Our website is located at www.varonis.com, and our investor relations website is located at https://ir.varonis.com. The information posted on our website is not incorporated into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Exchange Act are available free of charge on our investor relations website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC"). You may also access all of our public filings through the SEC’s website at www.sec.gov.
Investors and other interested parties should note that we use our media and investor relations website and our social media channels to publish important information about us, including information that may be deemed material to investors. We encourage investors and other interested parties to review the information we may publish through our media and investor relations website and the social media channels listed on our media and investor relations website, in addition to our SEC filings, press releases, conference calls and webcasts.
Item 1A. Risk Factors
Investing in our common stock involves a high degree of risk. You should carefully consider the following risks and all other information contained herein, including our consolidated financial statements and the related notes thereto, before investing in our common stock. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition and results of operations could be materially harmed. In that case, the trading price of our common stock could decline, and you may lose some or all of your investment.
Risks Related to the Industry in which we Operate
The market for software that analyzes, secures, governs, manages and migrates enterprise data may not continue to grow or grow at the same pace.
We believe our future success depends in large part on the continued growth of the market for software that enables enterprises to analyze, secure, govern, manage and migrate their data. In order for us to market and sell our products, we must successfully demonstrate to enterprise IT, security and business personnel the potential value of their data and the risk of that data getting compromised or stolen. Despite a number of high-profile cyberattacks around the world, we must still persuade customers to devote a portion of their budgets to a unified platform that we offer to analyze, secure, govern, manage and extract value from this resource. Enterprises may not recognize the need for our products or, if they do, may not decide that they need a solution
11
that offers the range of functionalities that we offer. Software solutions focused on enterprise data may not yet be viewed as a necessity, and accordingly, our sales effort is and will continue to be focused in large part on explaining the need for, and value offered by, our solution. The market for our solution may not continue to grow at its current rate or at all. The failure of the market to continue to develop would materially adversely impact our results of operations.
Prolonged economic uncertainties or downturns could materially adversely affect our business.
Our business depends on our current and prospective customers’ ability and willingness to invest in IT services, including cybersecurity projects, which in turn is dependent upon their overall economic health. Negative conditions in the general economy both in the United States and abroad, including inflationary pressure, recession, currency fluctuations and a higher interest rate environment, changes in gross domestic product growth, potential future government shutdowns, the federal government’s failure to raise the debt ceiling, financial and credit market fluctuations, the imposition of trade barriers and restrictions such as tariffs, political deadlock, restrictions on travel, natural catastrophes, warfare, including geopolitical turmoil and sanctions caused by the war between Russia and Ukraine, and terrorist attacks, could cause a decrease in business investments, including corporate spending on enterprise software in general and negatively affect the rate of growth of our business. For example, our operations, and the operations of our customers and partners, were affected by the COVID-19 pandemic and efforts to control its spread, including by mandatory business closures and capacity limitations imposed by the jurisdictions in which we operate. Similar restrictions in the future could negatively affect our business.
Uncertainty in the global economy makes it extremely difficult for our customers and us to forecast and plan future business activities accurately. This could cause our customers to reevaluate decisions to purchase our product or to delay their purchasing decisions, which could lengthen our sales cycles and negatively impact our results. In the beginning of 2022, in connection with the war between Russia and Ukraine and related sanctions, we made the decision to exit our Russia business. As 2022 progressed, the European economy began to experience increased economic turmoil that has caused the devaluation of local European currencies (specifically, the Euro and the Pound Sterling), inflationary pressures and general economic uncertainty. As a result, there has been increasing budgetary tightening and we have started to see longer sales cycles in the region and our results of operations to date have been negatively impacted. In the United States, we have also experienced a higher inflationary environment, which may put further pressure on discretionary spending by our customers, and we may in the future see a lengthening of our sales cycle in the region which could negatively impact our results.
A downturn in any of our leading industries, or a reduction in any revenue-generating vertical, may cause enterprises to react to worsening conditions by reducing their spending on IT. Customers may delay or cancel IT projects, choose to focus on in-house development efforts or seek to lower their costs by renegotiating maintenance and support agreements. To the extent purchases of licenses for our software are perceived by customers and potential customers to be discretionary, our revenues may be disproportionately affected by delays or reductions in general IT spending. In addition, consolidation in certain industries may result in reduced overall spending on our software. If the economic conditions of the general economy or industries in which we operate worsen from present levels, our business, results of operations and financial condition could be adversely affected.
Overall economic uncertainty has resulted in, and may in the future give rise to, a number of risks, including, but not limited to, the following:
• reduced economic activity could lead to a prolonged recession, which could negatively impact spending by our customers or the ability of consumers to pay for our services and in return could severely impact our business operations, financial condition and liquidity;
• an impairment of our ability to continue to show the positive trends at the levels we have shown in the last several quarters for certain key performance metrics, such as renewal rates and annual recurring revenues;
• a negative effect on our customer success efforts, our ability to enter into new markets and our ability to acquire new customers, in part due to potentially lower conversion rates on risk assessments and delay and lengthen our sales cycles;
• a reduction in the number of users as customers terminate and furlough employees;
• an increase in bad debt reserves as customers face economic hardship and collectability becomes more uncertain, including the risk of bankruptcies;
• variability with forward-looking guidance and financial results, including management’s accounting estimates and assumptions; and
• our ability to raise capital.
The challenges posed by and the full impact of negative conditions in the general economy on our business and our future performance are difficult to predict and there is a risk that any guidance we provide to the market may turn out to be incorrect.
12
We may face increased competition in our market.
While there are some companies which offer certain features similar to those embedded in our solutions, as well as others with whom we compete in certain tactical use cases, we believe that we do not currently compete with a company that offers the same breadth of functionalities on the number of platforms and application that we cover. Nevertheless, we do compete against a select group of software vendors that provide standalone solutions, similar to those found in our comprehensive software suite, in the specific markets in which we operate. We also face direct competition with respect to certain of our products, specifically Data Transport Engine, DatAnswers and DatAdvantage for Directory Services. As we continue to augment our functionality with insider threat detection and user behavior analytics and as we expand our classification capabilities to better serve compliance needs, such as GDPR, CCPA and other data privacy laws, we may face increased perceived and real competition from other security and classification technologies. As we expand our coverage and penetration in the cloud, we may face increased perceived and real competition from other cloud-focused technologies. In the future, as customer requirements evolve and new technologies are introduced, we may experience increased competition if established or emerging companies develop solutions that address the enterprise data market. Furthermore, because we operate in an evolving area, we anticipate that competition will increase based on customer demand for these types of products.
In particular, if a more established company were to target our market, we may face significant competition. They may have competitive advantages, such as greater name recognition, larger sales, marketing, research and acquisition resources, access to larger customer bases and channel partners, a longer operating history and lower labor and development costs, which may enable them to respond more quickly to new or emerging technologies and changes in customer requirements or devote greater resources to the development, promotion and sale of their products than we do. Increased competition could result in us failing to attract customers or maintain licenses at the same rate. It could also lead to price cuts, alternative pricing structures or the introduction of products available for free or a nominal price, reduced gross margins, longer sales cycles, lower renewal rates and loss of market share.
In addition, our current or prospective channel partners may establish cooperative relationships with future competitors. These relationships may allow future competitors to rapidly gain significant market share. These developments could also limit our ability to obtain revenues from existing and new customers.
Our ability to compete successfully in our market will also depend on a number of factors, including ease and speed of product deployment and use, the quality and reliability of our customer service and support, total cost of ownership, return on investment and brand recognition. Any failure by us to successfully address current or future competition in any one of these or other areas may reduce the demand for our products and adversely affect our business, results of operations and financial condition.
We are subject to a number of legal requirements, contractual obligations and industry standards regarding security, data protection and privacy, and any failure to comply with these requirements, obligations or standards could have an adverse effect on our reputation, business, financial condition and operating results.
Privacy and data information security have become a significant issue in the United States and in many other countries where we have employees and operations and where we offer licenses to our products. The regulatory framework for privacy and personal information security issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. The U.S. federal and various state and foreign government bodies and agencies have adopted or are considering adopting laws and regulations limiting, or laws and regulations regarding, the collection, distribution, use, disclosure, storage and security of personal information. For example, the CCPA, which went into effect on January 1, 2020, requires, among other things, covered companies to provide new disclosures to California consumers and afford such consumers new abilities to opt-out of certain sales of personal information. Consumer rights and obligations under the CCPA were expanded by the California Privacy Rights Act (CPRA) on November 3, 2020. The CPRA took effect on January 1, 2023, along with the Virginia Consumer Data Protection Act. In addition, the Colorado Privacy Act, the Utah Consumer Privacy Act and the Connecticut Act Concerning Personal Data Privacy and Online Monitoring are all set to go into effect in 2023. These laws impose similar obligations on businesses with regard to the use, disclosure and security of personal information, and grant additional rights in that personal information to consumers.
Internationally, virtually every jurisdiction in which we operate has established its own data security and privacy legal framework with which we or our customers must comply. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure and security of data that identifies or may be used to identify or locate an individual, such as names, email addresses and, in some jurisdictions, Internet Protocol addresses. These laws and regulations often are more restrictive than those in the United States and are rapidly evolving. For example, the European Union’s (“EU”) data protection regime, the GDPR, became enforceable on May 25, 2018. Additionally, the United Kingdom has enacted legislation that
13
substantially implements the GDPR, but the United Kingdom’s exit from the EU (which formally occurred on January 31, 2020), commonly referred to as “Brexit,” has created uncertainty with regard to the regulation of data protection in the United Kingdom. In particular, the United Kingdom’s government has announced that it is considering revising some aspects of its domestic data protection regime to move further away from the EU approach, and it is unclear how the two regimes will interact after that. In addition, the United Kingdom is reviewing its data transfer rules with respect to transfers to the United States and other jurisdictions, and has issued its own UK-specific International Data Transfer Agreement, together with a UK Addendum to the EU Standard Contractual Clauses. Depending on how these measures are implemented, and how they are enforced, they may result in substantively different compliance obligations with respect to transfers of personal data out of the United Kingdom and the EU, respectively. Complying with the GDPR or other laws, regulations or other obligations relating to privacy, data protection or information security may cause us to incur substantial operational costs or require us to modify our data handling practices. Non-compliance could result in proceedings against us by governmental entities or others, could result in substantial fines or other liability, and may otherwise adversely impact our business, financial condition and operating results.
Some statutory requirements, both in the United States and abroad, include obligations of companies to notify individuals of security breaches involving particular personal information, which could result from breaches experienced by us or our service providers. Even though we may have contractual protections with our service providers, a security breach could impact our reputation, harm our customer confidence, hurt our sales or cause us to lose existing customers and could expose us to potential liability or require us to expend significant resources on data security and in responding to such breach.
In addition to government regulation, privacy advocates and industry groups may propose new and different self-regulatory standards that either legally or contractually apply to us. We also expect that there will continue to be new proposed laws and regulations concerning privacy, data protection and information security, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. New laws, amendments to or re-interpretations of existing laws and regulations, industry standards, contractual obligations and other obligations may require us to incur additional costs and restrict our business operations. Because the interpretation and application of laws and other obligations relating to privacy and data protection are still uncertain, it is possible that these laws and other obligations may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the features of our software. If so, in addition to the possibility of fines, lawsuits and other claims, we could be required to fundamentally change our business activities and practices or modify our software, which could have an adverse effect on our business. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new features could be limited. Any inability to adequately address privacy concerns, even if unfounded, or comply with applicable privacy or data protection laws, regulations and policies could result in additional cost and liability to us, damage our reputation, inhibit sales and adversely affect our business.
Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations and policies that are applicable to the businesses of our customers may increase the costs associated with, limit the use and adoption of, and reduce the overall demand for, our products. Privacy and personal information security concerns, whether valid or not valid, may inhibit market adoption of our products particularly in certain industries and foreign countries.
Risks Related to Our Operations
Security breaches, cyberattacks or other cyber-risks of our IT and production systems could expose us to significant liability and cause our business and reputation to suffer and harm our competitive position.
Our corporate infrastructure stores and processes our sensitive, proprietary and other confidential information (including as related to financial, technology, employees, marketing, sales, etc.) which is used on a daily basis in our operations. In addition, our software involves transmission and processing of our customers’ confidential, proprietary and sensitive information. We have legal and contractual obligations to protect the confidentiality and appropriate use of customer data. Being a leading pioneer in the cyber industry, we may be an attractive target for cyber attackers or other data thieves.
High-profile cyberattacks and security breaches have increased in recent years, with the potential for such acts heightened as a result of the number of employees working remotely due to many companies adopting a hybrid working model. Security industry experts and government officials have warned about the risks of hackers and cyberattacks targeting IT products and enterprise infrastructure. Because techniques used to obtain unauthorized access or to sabotage systems change frequently and often are not recognized until launched against a specific target, we may be unable to anticipate these techniques or to implement adequate preventative measures. As we continue to increase our client base and expand our brand, we may become more of a target for third parties seeking to compromise our security systems and we anticipate that hacking attempts and cyberattacks will increase in the future. We may not always be successful in preventing or repelling unauthorized access to our
14
systems. We also may face delays in our ability to identify or otherwise respond to any cybersecurity incident or any other breach. Additionally, we use third-party service providers to provide some services to us that involve the cloud hosting, storage or transmission of data, such as SaaS, cloud computing, and internet infrastructure and bandwidth, and they face various cybersecurity threats and also may suffer cybersecurity incidents or other security breaches. Despite our security measures, our IT and infrastructure may be vulnerable to attacks. Threats to IT security can take a variety of forms. Individual and groups of hackers and sophisticated organizations, including state-sponsored organizations or nation-states, continuously undertake attacks that pose threats to our customers and our IT. These actors may use a wide variety of methods, which may include developing and deploying malicious software or exploiting vulnerabilities in hardware, software, or other infrastructure in order to attack our products and services or gain access to our networks, using social engineering techniques to induce our employees, users, partners, or customers to disclose passwords or other sensitive information or take other actions to gain access to our data or our users’ or customers’ data, or acting in a coordinated manner to launch distributed denial of service or other coordinated attacks. Inadequate account security practices may also result in unauthorized access to confidential and/or sensitive data or loss of SaaS platform availability.
Security risks, including, but not limited to, unauthorized use or disclosure of customer data, loss of availability of our SaaS platform offering, cyberattack on our cloud providers theft of proprietary information, theft of intellectual property, theft of internal employee’s PII/PHI information, theft of financial data and financial reports, loss or corruption of customer data and computer hacking attacks or other cyberattacks, could require us to expend significant capital and other resources to alleviate the problem and to improve technologies, may impair our ability to provide services to our customers and protect the privacy of their data, may result in product development delays, may compromise confidential or technical business information, may harm our competitive position, may result in theft or misuse of our intellectual property or other assets and could expose us to substantial litigation expenses and damages, indemnity and other contractual obligations, government fines and penalties, mitigation expenses, costs for remediation and incentives offered to affected parties, including customers, other business partners and employees, in an effort to maintain business relationships after a breach or other incident, and other liabilities. We are continuously working to improve our IT systems, together with creating security boundaries around our critical and sensitive assets. We provide advanced security awareness training to our employees and contractors that focuses on various aspects of the cybersecurity world. All of these steps are taken in order to mitigate the risk of attack and to ensure our readiness to responsibly handle any security violation or attack. If an actual or perceived breach of our security occurs, the market perception of the effectiveness of our security measures and our products could be harmed, we could lose potential sales and existing customers, our ability to operate our business could be impaired, we may incur significant liabilities, we could suffer harm to our reputation and competitive position, and our operating results could be negatively impacted.
Our quarterly results of operations have fluctuated and may fluctuate significantly due to variability in our revenues which could adversely impact our stock price.
Our revenues and other results of operations have fluctuated from quarter to quarter in the past and could continue to fluctuate in the future. Historically, the fluctuation was partially due to the front-loaded revenue recognition nature of our business. Additionally, as the Company transitions to a predominantly SaaS-based business model that recognizes revenue ratably, we will no long front-load revenue and, as a result, expect to present reduced revenues as compared to prior periods. As a result, comparing our revenues and results of operations on a period-to-period basis may not be meaningful, and should not be relied on for any particular period. Our revenues depend in part on the conversion of enterprises that have undergone risk assessments, which can be performed remotely, into paying customers; however, these risk assessments may not be converted at the same historical rates. At the same time, the majority of our sales are typically made during the last three weeks of every quarter. We may fail to meet market expectations for that quarter if we are unable to close the number of transactions that we expect during this short period and closings are deferred to a subsequent quarter or not closed at all. In addition, our sales cycle from initial contact to delivery of and payment for the software license generally becomes longer and less predictable with respect to large transactions and often involves multiple meetings or consultations at a substantial cost and time commitment to us. The closing of a large transaction in a particular quarter may raise our revenues in that quarter and thereby make it more difficult for us to meet market expectations in subsequent quarters and our failure to close a large transaction in a particular quarter or any renewals may adversely impact our revenues in that quarter. Moreover, we base our current and future expense levels on our revenue forecasts and operating plans, and our expenses are relatively fixed in the short-term. Accordingly, we would likely not be able to reduce our costs sufficiently to compensate for an unexpected shortfall in revenues and even a relatively small decrease in revenues could disproportionately and adversely affect our financial results for that quarter.
The variability and unpredictability of these and other factors, many of which are outside of our control, could result in our failing to meet or exceed financial expectations for a given period and may cause the price of our common stock to decline substantially.
15
If the transition to a SaaS-based business model fails to yield the benefits that we expect, our results of operations could be negatively impacted.
We successfully completed our transition to a subscription-based business model and are currently transitioning our business to a SaaS-based business model. It is uncertain whether this transition will prove successful. Market acceptance of our products is dependent on our ability to include functionality and usability that address certain customer requirements. Additionally, we must optimally price our products in light of marketplace conditions, our costs and customer demand. This transition may have negative revenue and earnings implications, including on our quarterly results of operations.
This SaaS strategy may give rise to a number of risks, including the following:
•our revenues and operating margins may fluctuate more than anticipated over the short-term as a result of this strategy;
•if new or current customers desire only self-hosted licenses our SaaS sales may lag behind our expectations;
•the shift to a SaaS strategy may raise concerns among our customer base, including concerns regarding changes to pricing over time and access to data once a subscription has expired;
•we may be unsuccessful in maintaining or implementing our target pricing or new pricing models, product adoption and projected renewal rates, or we may select a target price or new pricing model that is not optimal and could negatively affect our sales or earnings;
•our shift to a SaaS business model may result in confusion among new or existing customers (which can slow adoption rates), resellers and investors;
•if our customers do not renew their subscriptions or do not renew them on a timely basis, our revenues may decline and our business may suffer;
•we may incur sales compensation costs at a higher than forecasted rate if the pace of our subscription transition is faster than anticipated; and
•our sales force may struggle with the transition which may lead to increased turnover rates and lower headcount.
The expansion of cloud-delivered services (as opposed to traditional on-premises delivery of our products) has and will introduce a number of risks and uncertainties unique to such a shift, which could adversely affect our business, results of operations and financial condition.
We recently launched cloud offerings that allow customers to use hosted software. This launch required, and any future expansion of our cloud-delivered services may require, a considerable investment in resources, including technical, financial, legal, sales, information technology and operation systems. Additionally, market acceptance of such offerings is affected by a variety of factors, including but not limited to: security, reliability, scalability, customization, performance, current license terms, customer preference, customer concerns with entrusting a third party to store and manage their data, public concerns regarding privacy and the enactment of restrictive laws or regulations. It is possible that demand for our cloud offerings will not be as strong as anticipated. Moreover, expansion of our cloud offerings may cause a decline in revenue of our existing products and services that is not offset by revenue from the new products or services. For example, customers may delay making purchases of products and services to permit them to make a more thorough evaluation of these new products and services or until industry and marketplace reviews become widely available. In addition, the transition to a SaaS-based business model, and the additional demands involved in selling multiple products as well as new product offerings, has increased the complexity and to some extent imposed new challenges in finding, hiring and retaining qualified sales force members. We may be unable to realize the benefits of our investments, or the resources we have committed, toward launching or expanding our cloud-delivered services.
An increasing number of jurisdictions are imposing data localization laws, which require personal information, or certain subcategories of personal information, to be stored in the jurisdiction of origin. These regulations may deter customers from using cloud-based services, and may inhibit our ability to expand into certain markets or prohibit us from continuing to offer services in those markets without significant additional costs.
Our hosted offerings rely upon third-party providers to supply data center space, equipment maintenance and other colocation services and rely upon the ability of those providers to maintain continuous service availability and protect customer data on their services. Customers of our cloud-based offerings need to be able to access our platform at any time, without interruption or degradation of performance, and we provide them with service level commitments with respect to uptime. Third-party cloud providers run their own platforms that we access, and we are, therefore, vulnerable to their service interruptions. Although we have entered into various agreements for the lease of data center space, equipment maintenance and other services, third parties could fail to live up to their contractual obligations. The failure of a third-party provider to prevent service disruptions, data losses or security breaches may require us to issue credits or refunds or indemnify or otherwise be liable to customers or third parties for damages that may occur, and contractual provisions with our third-party providers and public cloud partners may
16
limit our recourse against the third-party provider or public cloud partner responsible for such failure. Additionally, if these third-party providers fail to deliver on their obligations, our reputation could be damaged, our customers could lose confidence in us, and our ability to maintain and expand our hosted offerings would be impaired. Lastly, our cloud product offering and pricing is new and hosting and other costs may be more expensive to us than anticipated.
We may not be able to predict renewal rates and their impact on our future revenues and operating results.
Although our subscription solutions are designed to increase the number of customers that purchase our solutions and the number of products purchased by existing and new customers to create a recurring revenue stream that increases and is more predictable over time, our customers are not required to renew their subscriptions for our solutions and they may elect not to renew when, or as we expect, or they may elect to reduce the scope of their original purchases or delay their purchase. We cannot accurately predict renewal rates given our varied customer base of enterprise and small and medium size business customers and the number of multiyear subscription contracts. Customer renewal rates may decline or fluctuate due to a number of factors, including offering pricing, competitive offerings, customer satisfaction and reductions in customer spending levels or customer activity due to economic downturns, the adverse impact of import tariffs, inflation, the pandemic or other market uncertainty. If our customers do not renew their subscriptions when or as we expect, or if they choose to renew for fewer subscriptions (in quantity or products) or renew for shorter contract lengths or if they renew on less favorable terms, our revenues and earnings may decline, and our business may suffer.
We have been growing and expect to continue to invest in our growth for the foreseeable future. If we fail to manage this growth effectively, our business and results of operations will be adversely affected.
We intend to continue to grow our business and plan to continue to hire new sales employees either for expansion or replacement of existing sales personnel. If we cannot adequately and timely hire new employees and if we fail to adequately train these new employees, including our sales force, engineers and customer support staff, our sales may not grow at the rates we project and/or our sales productivity might suffer, our customers might decide not to renew or reduce the scope of their original purchases, or our customers may lose confidence in the knowledge and capability of our employees or products. We must successfully manage our growth to achieve our objectives. Although our business has experienced significant growth in the past, we may not be able to continue to grow at the same rate, or at all.
Our ability to effectively manage any significant growth of our business will depend on a number of factors, including our ability to do the following:
• satisfy existing customers and attract new customers;
• adequately and timely recruit, train, motivate and integrate new employees, including our sales force and engineers, while retaining existing employees, maintaining the beneficial aspects of our corporate culture and effectively executing our business plan;
• successfully introduce new products and enhancements;
• effectively manage existing channel partnerships and expand to new ones;
• improve our key business applications and processes to support our business needs;
• enhance information and communication systems to ensure that our employees and offices around the world are well-coordinated and can effectively communicate with each other and our growing customer base;
• enhance our internal controls to ensure timely and accurate reporting of all of our operations and financial results;
• protect and further develop our strategic assets, including our intellectual property rights;
• continue to capitalize on the transition to a subscription-based business model and manage our introduction of cloud-based solutions; and
• successfully manage and integrate any future acquisitions of businesses, including without limitation, the amount and timing of expenses and potential future charges for impairment of goodwill from acquired companies.
These activities will require significant investments and allocation of valuable management and employee resources, and our growth will continue to place significant demands on our management and our operational and financial infrastructure. We may not be able to grow our business in an efficient or timely manner, or at all. Moreover, if we do not effectively manage the growth of our business and operations, the quality of our software could suffer, which could negatively affect our brand, results of operations and overall business.
We have a limited operating history at our current scale, which makes it difficult to evaluate and predict our future prospects and may increase the risk that we will not be successful.
17
We have a relatively short history operating our business at its current scale. For example, we have increased the number of our employees and have expanded our operations and product offerings. This limits our ability to forecast our future operating results and subjects us to a number of uncertainties, including our ability to plan for and model future growth. We have encountered and will continue to encounter risks and uncertainties frequently experienced by growing companies in new markets that may not develop as expected. Because we depend in part on the market’s acceptance of our products, it is difficult to evaluate trends that may affect our business. If our assumptions regarding these trends and uncertainties, which we use to plan our business, are incorrect or change in reaction to changes in our markets, or if we do not address these risks successfully, our operating and financial results could differ materially from our expectations and our business could suffer. Moreover, although we have experienced significant growth historically, we may not continue to grow as quickly in the future.
Our future success will depend in large part on our ability to, among other things:
• successfully transition to a SaaS-based business model and manage our introduction of cloud-based solutions;
• maintain and expand our business, including our customer base and operations, to support our growth, both domestically and internationally;
• develop new products and services and bring products and services in beta to market;
• renew customer agreements and sell additional products to existing customers;
• maintain high customer satisfaction and ensure quality and timely releases of our products and product enhancements;
• increase market awareness of our products and enhance our brand;
• maintain compliance with applicable governmental regulations and other legal obligations, including those related to intellectual property, international sales and taxation;
• hire, integrate, train and retain skilled talent, including members of our sales force and engineers; and
• our ability to successfully manage and integrate any acquisitions of businesses.
If we fail to address the risks and difficulties that we face, including those associated with the challenges listed above as well as those described elsewhere in this “Risk Factors” section, our business will be adversely affected, and our results of operations will suffer.
If we are unable to attract new customers and expand sales to existing customers, both domestically and internationally, our growth could be slower than we expect, and our business may be harmed.
Our success will depend, in part, on our ability to support new and existing customer growth and maintain customer satisfaction. Our sales and marketing teams host in-person events and have, and in the future may continue to engage with customers online and through other communications channels, including virtual meetings. Our sales and marketing teams may not be as successful or effective in building relationships. If we cannot provide the tools and training to our teams to efficiently do their jobs and satisfy customer demands, we may not be able to achieve anticipated revenue growth as quickly as expected.
Our future growth depends upon expanding sales of our products to existing customers and their organizations and receiving renewals. If our customers do not purchase additional licenses or capabilities, our revenues may grow more slowly than expected, may not grow at all or may decline. Our efforts may not result in increased sales to existing customers (“upsells”) and additional revenues. If our efforts to upsell to our customers are not successful, our business would suffer.
Our future growth also depends in part upon increasing our customer base, particularly those customers with potentially high customer lifetime values. Our ability to achieve significant growth in revenues in the future will depend, in large part, upon the effectiveness of our sales and marketing efforts, both domestically and internationally, and our ability to attract new customers. Our ability to attract new customers may be adversely affected by newly enacted laws that may prohibit certain sales and marketing activities, such as legislation passed in the State of New York, pursuant to which unsolicited telemarketing sales calls are prohibited. If we fail to attract new customers and maintain and expand those customer relationships, our revenues may be adversely affected, and our business will be harmed.
We have a history of losses, and we may not be profitable in the future.
We have incurred net losses in each year since our inception, including a net loss of $124.5 million, $116.9 million and $94.0 million in each of the years ended December 31, 2022, 2021 and 2020, respectively. Because the market for our software is rapidly evolving and has still not yet reached widespread adoption, it is difficult for us to predict our future results of operations. We expect our operating expenses to increase over the next several years as we hire additional personnel, expand and improve the effectiveness of our distribution channels, and continue to develop features and applications for our software.
If we are unable to maintain successful relationships with our channel partners, our business could be adversely affected.
18
We rely on channel partners, such as distribution partners and resellers, to sell licenses and support and maintenance agreements for our software and to perform some of our professional services. In 2022, our channel partners fulfilled substantially all of our sales, and we expect that sales to channel partners will continue to account for substantially all of our revenues for the foreseeable future. Our ability to achieve revenue growth in the future will depend in part on our success in maintaining successful relationships with our channel partners.
Our agreements with our channel partners are generally non-exclusive, meaning our channel partners may offer customers the products of several different companies. If our channel partners do not effectively market and sell our software, choose to use greater efforts to market and sell their own products or those of others, or fail to meet the needs of our customers, including through the provision of professional services for our software, our ability to grow our business, sell our software and maintain our reputation may be adversely affected. Our contracts with our channel partners generally allow them to terminate their agreements for any reason upon 30 days’ notice. A termination of the agreement has no effect on orders already placed. The loss of a substantial number of our channel partners, our possible inability to replace them, or the failure to recruit additional channel partners could materially and adversely affect our results of operations. If we are unable to maintain our relationships with these channel partners, our business, results of operations, financial condition or cash flows could be adversely affected.
Finally, even if we are successful, our relationships with channel partners may not result in greater customer usage of our products and professional services or increased revenue.
Our long-term growth depends, in part, on being able to continue to expand internationally on a profitable basis, which subjects us to risks associated with conducting international operations.
Historically, we have generated the majority of our revenues from customers in North America. For the year ended December 31, 2022, approximately 74% of our total revenues were derived from sales in North America. Nevertheless, we have operations across the globe, and we plan to continue to expand our international operations as part of our long-term growth strategy. The further expansion of our international operations will subject us to a variety of risks and challenges, including:
• sales and customer service challenges associated with operating in different countries;
• increased management travel, infrastructure and legal compliance costs associated with having multiple international operations and a lack of travel due to pandemics;
• difficulties in receiving payments from different geographies, including difficulties associated with currency fluctuations, payment cycles, transfer of funds or collecting accounts receivable, especially in emerging markets;
• variations in economic or political conditions between each country or region;
• economic uncertainty around the world and adverse effects arising from economic interdependencies across countries and regions;
• the uncertainty around the effects of global pandemics on our business and results of operations;
• uncertainty around a potential reverse or renegotiation of international trade agreements and partnerships;
• compliance with foreign laws and regulations and the risks and costs of non-compliance with such laws and regulations;
• ability to hire, retain and train local employees and the ability to comply with foreign labor laws and local labor requirements, such as representations by an internal labor committee in France which is affiliated with an external trade union and the applicability of collective bargaining arrangements at the national level in certain European countries;
• compliance with laws and regulations for foreign operations, including the U.S. Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.K. Bribery Act of 2010 (the “UK Bribery Act”), import and export control laws, tariffs, trade barriers, economic sanctions and other regulatory or contractual limitations on our ability to sell our software in certain foreign markets, and the risks and costs of non-compliance;
• heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of financial statements and irregularities in financial statements;
• reduced protection for intellectual property rights in certain countries and practical difficulties and costs of enforcing rights abroad; and
• compliance with the laws of numerous foreign taxing jurisdictions and overlapping of different tax regimes and digital tax imposed on our operations in foreign taxing jurisdictions.
Any of these risks could adversely affect our international operations, reduce our revenues from outside the United States or increase our operating costs, adversely affecting our business, results of operations and financial condition and growth prospects. There can be no assurance that all of our employees, independent contractors and channel partners will comply with the formal policies we have and will implement, or applicable laws and regulations. Violations of laws or key control policies by our employees, independent contractors and channel partners could result in delays in revenue recognition, financial
19
reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our software and services and could have a material adverse effect on our business and results of operations.
We are exposed to collection and credit risks, which could impact our operating results.
Our accounts receivable and contract assets are subject to collection and credit risks. These agreements may include purchase commitments for multiple years of subscription-based software licenses and maintenance services, which may be invoiced over multiple reporting periods increasing these risks. For example, our operating results may be impacted by significant bankruptcies among customers and resellers, which could negatively impact our revenues and cash flows. Although we have processes in place that are designed to monitor and mitigate these risks, we cannot guarantee these programs will be effective. If we are unable to adequately control these risks, our business, operating results and financial condition could be harmed.
If currency exchange rates fluctuate substantially in the future, our results of operations, which are reported in U.S. dollars, could be adversely affected.
Our functional and reporting currency is the U.S. dollar, and we generate the majority of our revenues and incur the majority of our expenses in U.S. dollars. Revenues and expenses are also incurred in other currencies, primarily Euros, Pounds Sterling, Canadian dollars, Australian dollars and the New Israeli Shekel. Accordingly, changes in exchange rates may have a material adverse effect on our business, results of operations and financial condition. The exchange rates between the U.S. dollar and foreign currencies have fluctuated substantially in recent years and may continue to fluctuate substantially in the future. Furthermore, a strengthening of the U.S. dollar could increase the cost in local currency of our software and renewals to customers outside the United States, which could adversely affect our business, results of operations, financial condition and cash flows.
We incur expenses for employee compensation and other operating expenses at our non-U.S. locations in local currencies. The weakening of the U.S. dollar against such currencies would cause the U.S. dollar equivalent of such expenses to increase which could have a negative impact on our reported results of operations and our ability to attract employees in such non-U.S. locations due to the actual increase in the compensation to be paid to such employees. We use forward foreign exchange contracts to hedge or mitigate the effect of changes in foreign exchange rates on our operating expenses denominated in certain foreign currencies. However, this strategy might not eliminate our exposure to foreign exchange rate fluctuations and involves costs and risks of its own, such as cash expenditures, ongoing management time and expertise, external costs to implement the strategy and potential accounting implications. Additionally, our hedging activities may contribute to increased losses as a result of volatility in foreign currency markets and the difference between the interest rates of the currencies being hedged.
Our business is highly dependent upon our brand recognition and reputation, and the failure to maintain or enhance our brand recognition or reputation may adversely affect our business.
We believe that enhancing the “Varonis” brand identity and maintaining our reputation in the IT industry is critical to our relationships with our customers and to our ability to attract new customers. Our brand recognition and reputation are dependent upon:
• our ability to continue to offer high quality, innovative and error- and bug-free products;
• our ability to maintain customer satisfaction with our products;
• our ability to be responsive to customer concerns and provide high quality customer support, training and professional services;
• our marketing efforts;
• any misuse or perceived misuse of our products;
• positive or negative publicity;
• our ability to prevent or quickly react to any cyberattack on our IT systems or security breach of or related to our software;
• interruptions, delays or attacks on our website; and
• litigation or regulatory-related developments.
We may not be able to successfully promote our brand or maintain our reputation. In addition, independent industry analysts often provide reviews of our products, as well as other products available in the market, and perception of our product in the marketplace may be significantly influenced by these reviews. If these reviews are negative, or less positive than reviews about other products available in the market, our brand may be adversely affected. Furthermore, negative publicity relating to events or activities attributed to us, our employees, our channel partners or others associated with any of these parties, may tarnish our reputation and reduce the value of our brand. If we do not successfully enhance our brand and maintain our reputation, our business may not grow, we may have reduced pricing power relative to competitors with stronger brands, and we could lose
20
customers or renewals, all of which would adversely affect our business, operations and financial results. Moreover, damage to our reputation and loss of brand equity may reduce demand for our products and have an adverse effect on our business, results of operations and financial condition. Any attempts to rebuild our reputation and restore the value of our brand may be costly and time consuming, and such efforts may not ultimately be successful.
Moreover, it may be difficult to enhance our brand and maintain our reputation in connection with sales to channel partners. Promoting our brand requires us to make significant expenditures, and we anticipate that the expenditures will increase as our market becomes more competitive, as we expand into new markets and geographies and as more sales are generated to our channel partners. To the extent that these activities yield increased revenues, these revenues may not offset the increased expenses we incur.
Our success depends in part on maintaining and increasing our sales to customers in the public sector.
We derive a portion of our revenues from contracts with federal, state, local and foreign governments and government-owned or -controlled entities (such as public health care bodies, educational institutions and utilities), which we refer to as the public sector herein. We believe that the success and growth of our business will continue to depend on our successful procurement of public sector contracts. Selling to public sector entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense without any assurance that our efforts will produce any sales. Government demand and payment for our products and services may be impacted by public sector budgetary cycles, or lack of, and funding authorizations, including in connection with an extended government shutdown, with funding reductions or delays adversely affecting public sector demand for our products and services. Factors that could impede our ability to maintain or increase the amount of revenues derived from public sector contracts include:
• changes in public sector fiscal or contracting policies;
• decreases or elimination of available public sector funding;
• non-compliance with or an inability to attain the proper certification to conduct business in the public sector;
• changes in public sector programs or applicable requirements;
• the adoption of new laws or regulations or changes to existing laws or regulations;
• potential delays or changes in the public sector appropriations or other funding authorization processes;
• the requirement of contractual terms that are unfavorable to us, such as most-favored-nation pricing provisions; and
• delays in the payment of our invoices by public sector payment offices.
Furthermore, we must comply with laws and regulations relating to public sector contracting, which affect how we and our channel partners do business in both the United States and abroad. These laws and regulations may impose added costs on our business, and failure to comply with these or other applicable regulations and requirements, including non-compliance in the past, could lead to claims for damages from our channel partners, penalties, termination of contracts, and temporary suspension or permanent debarment from public sector contracting. Moreover, governments routinely investigate and audit government contractors’ administrative processes, and any unfavorable audit could result in the government refusing to continue buying our products, which would adversely impact our revenue and results of operations, or institute fines or civil or criminal liability if the audit uncovers improper or illegal activities.
The occurrence of any of the foregoing could cause public sector customers to delay or refrain from purchasing licenses of our software in the future or otherwise have an adverse effect on our business, operations and financial results.
We are subject to governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
We incorporate certain encryption technology into certain of our products and, as a result, are required to comply with U.S. export control laws and regulations, including the Export Administration Regulations administered by the U.S. Department of Commerce’s Bureau of Industry and Security (“BIS”). We are also subject to Israeli export control laws on encryption technology. These export control laws and regulations prohibit, restrict, or regulate our ability to, directly or indirectly, export, re-export, or transfer certain products to certain countries and territories, entities, and individuals for certain end uses. If the applicable U.S. or Israeli legal requirements regarding the export of encryption technology were to change or if we change the encryption means in our products, we may (i) be unable to export our products, (ii) need to apply for new licenses or (iii) be unable to rely on certain license exceptions. Furthermore, various other countries regulate the import of certain encryption technology, including import permitting and licensing requirements, and have enacted laws that could limit our ability to distribute our products or could limit our customers’ ability to implement our products in those countries.
We are also subject to U.S. and Israeli economic sanctions laws, which prohibit the shipment of certain products to embargoed or sanctioned countries, sanctioned governments and sanctioned persons. Like with export controls, we take precautions to
21
prevent our products from being provided in violation of these laws, including requiring our business partners to commit to compliance through contractual undertakings. However, if our business partners were to provide our products to certain countries, governments, or sanctioned persons in violation of these laws, such provision could have negative consequences, including government investigations, penalties and reputational harm.
Any change in export or import regulations, economic sanctions or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons or technologies targeted by such regulations, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential customers with international operations. Moreover, any new export or import restrictions, new legislation or shifting approaches in the enforcement or scope of existing regulations, or in the countries, persons or technologies targeted by such regulations, could result in decreased use of our products. Any decreased use of our products or limitation on our ability to export or sell our products would likely adversely affect our business, financial condition and results of operations
Our business in countries with a history of corruption and transactions with foreign governments increase the risks associated with our international activities.
As we operate and sell internationally, we are subject to the FCPA, the UK Bribery Act and other laws that prohibit improper payments or offers of payments to foreign governments and their officials and political parties for the purpose of obtaining or retaining business. We have operations, deal with and make sales to governmental customers in countries known to experience corruption, particularly certain emerging countries in Eastern Europe, South and Central America, East Asia, Africa and the Middle East. Our activities in these countries create the risk of unauthorized payments or offers of payments by one of our employees, consultants, channel partners or sales agents that could be in violation of various anti-corruption laws, even though these parties may not be under our control. While we have implemented safeguards to prevent these practices by our employees, consultants, channel partners and sales agents, our existing safeguards and any future improvements may prove to be less than effective, and our employees, consultants, channel partners or sales agents may engage in conduct for which we might be held responsible. Violations of the FCPA or other anti-corruption laws may result in severe criminal or civil sanctions, including suspension or debarment from government contracting, and we may be subject to other liabilities, which could negatively affect our business, operating results and financial condition.
Acquisitions could disrupt our business and adversely affect our results of operations, financial condition and cash flows.
As we continue to pursue business opportunities, we may make acquisitions that could be material to our business, results of operations, financial condition and cash flows. Acquisitions involve many risks, including the following:
• an acquisition may negatively affect our results of operations, financial condition or cash flows because it may require us to incur charges or assume substantial debt or other liabilities, may cause adverse tax consequences or unfavorable accounting treatment, including potential write-downs of deferred revenues, may expose us to claims and disputes by third parties, including intellectual property claims and disputes, or may not generate sufficient financial return to offset additional costs and expenses related to the acquisition;
• we may encounter difficulties or unforeseen expenditures in integrating the business, technologies, products, personnel or operations of any company that we acquire, particularly if key personnel of the acquired company decide not to work for us;
• an acquisition may disrupt our ongoing business, divert resources, increase our expenses and distract our management;
• an acquisition may result in a delay or reduction of customer purchases for both us and the company we acquired due to customer uncertainty about continuity and effectiveness of service from either company;
• we may encounter difficulties in, or may be unable to, successfully sell any acquired products;
• an acquisition may involve the entry into geographic or business markets in which we have little or no prior experience or where competitors have stronger market positions;
• challenges inherent in effectively managing an increased number of employees in diverse locations;
• the potential strain on our financial and managerial controls and reporting systems and procedures;
• potential known and unknown liabilities or deficiencies associated with an acquired company that were not identified in advance;
• our use of cash to pay for acquisitions would limit other potential uses for our cash and affect our liquidity;
• if we incur debt to fund such acquisitions, such debt may subject us to material restrictions on our ability to conduct our business as well as financial maintenance covenants;
• the risk of impairment charges related to potential write-downs of acquired assets or goodwill in future acquisitions;
• to the extent that we issue a significant amount of equity or convertible debt securities in connection with future acquisitions, existing stockholders may be diluted and earnings per share may decrease; and
• managing the varying intellectual property protection strategies and other activities of an acquired company.
22
We may not succeed in addressing these or other risks or any other problems encountered in connection with the integration of any acquired business. Our ability as an organization to successfully acquire and integrate technologies or businesses is limited. The inability to successfully integrate the business, technologies, products, personnel or operations of any acquired business, or any significant delay in achieving integration, could have a material adverse effect on our business, results of operations, financial condition and cash flows.
Risks Related to Human Capital
A failure to maintain sales and marketing personnel productivity or hire and integrate additional sales and marketing personnel could adversely affect our results of operations and growth prospects.
Our business requires intensive sales and marketing activities. Our sales and marketing personnel are essential to attracting new customers and expanding sales to existing customers, both of which are key to our future growth. We face a number of challenges in successfully expanding our sales force. Our transition to a SaaS-based business model, and the additional demands involved in selling our platform, has increased the complexity and to some extent imposed new challenges in finding, hiring and retaining qualified sales force members. We must locate and hire a significant number of qualified individuals, and competition for such individuals is intense. In addition, as we expand into new markets with which we have less familiarity and develop existing territories, we will need to recruit individuals who have skills particular to a certain geography or territory, and it may be difficult to find candidates with those qualifications. We may be unable to achieve our hiring or integration goals due to a number of factors, including, but not limited to, the challenge in remotely recruiting employees and adequately training them, the number of individuals we hire, challenges in finding individuals with the correct background due to increased competition for such hires, increased attrition rates among new hires and existing personnel as well as the necessary experience to sell the Varonis Data Security Platform rather than individual software products. Furthermore, based on our past experience in mature territories, it can take up to 12 months before a new sales force member is trained and operating at a level that meets our expectations. We invest significant time and resources in training new members of our sales force, and we may be unable to achieve our target performance levels with new sales personnel as rapidly as we have done in the past, or at all, due to larger numbers of hires or lack of experience training sales personnel to operate in new jurisdictions or because of the remote hiring and training process. Our failure to hire a sufficient number of qualified individuals, to integrate new sales force members within the time periods we have achieved historically or to keep our attrition rates at levels comparable to others in our industry may materially impact our projected growth rate.
Failure to retain, attract and recruit highly qualified personnel could adversely affect our business, operating results, financial condition and growth prospects.
Our future success and growth depend, in part, on our ability to continue to recruit and retain highly skilled personnel and to preserve the key aspects of our corporate culture. Because our future success is dependent on our ability to continue to enhance and introduce new products, we are particularly dependent on our ability to hire and retain engineers. Any of our employees may terminate their employment at any time, and we face intense competition for highly skilled employees. Competition for qualified employees, particularly in Israel, where we have a substantial presence and need for qualified engineers, from numerous other companies, including other software and technology companies, many of whom have greater financial and other resources than we do, is intense. Moreover, to the extent we hire personnel from other companies, we may be subject to allegations that they have been improperly solicited or may have divulged proprietary or other confidential information to us. If we are unable to timely attract, retain or train qualified employees, particularly our engineers, salespeople and key managers, our ability to innovate, introduce new products and compete would be adversely impacted, and our financial condition and results of operations may suffer. Lastly, equity grants are a critical component of our current compensation programs. If we reduce, modify or eliminate our equity compensation programs or if there is a decline in our stock price, which will result in the value of our equity compensation being lower, we may have difficulty attracting and retaining employees.
We are dependent on the continued services and performance of our co-founder, Chief Executive Officer and President, the loss of whom could adversely affect our business.
Much of our future performance depends on the continued services and continuing contributions of our co-founder, Chief Executive Officer and President, Yakov Faitelson, to successfully manage our company, to execute on our business plan and to identify and pursue new opportunities and product innovations. The loss of Mr. Faitelson’s services could significantly delay or prevent the achievement of our development and strategic objectives and adversely affect our business.
Risks Related to our Technology, Products, Services and Intellectual Property
Our failure to continually enhance and improve our technology could adversely affect sales of our products.
23
The market is characterized by the exponential growth in enterprise data, rapid technological advances, changes in customer requirements, including customer requirements driven by changes to legal, regulatory and self-regulatory compliance mandates, frequent new product introductions and enhancements and evolving industry standards in computer hardware and software technology. As a result, we must continually change and improve our products in response to changes in operating systems, application software, computer and communications hardware, networking software, data center architectures, programming tools, computer language technology and various regulations. Moreover, the technology in our products is especially complex because it needs to effectively identify and respond to a user’s data retention, security and governance needs, while minimizing the impact on database and file system performance. Our products must also successfully interoperate with products from other vendors.
While we extend our technological capabilities though innovation and strategic transactions, including our recently announced cloud-based solutions, we cannot guarantee that we will be able to anticipate future market needs and opportunities or be able to extend our technological expertise and develop new products or expand the functionality of our current products in a timely manner or at all. Even if we are able to anticipate, develop and introduce new products and expand the functionality of our current products, there can be no assurance that enhancements or new products will achieve widespread market acceptance.
Our product enhancements or new products could fail to attain sufficient market acceptance for many reasons, including:
• failure to accurately predict market demand in terms of product functionality and to supply products that meet this demand in a timely fashion;
• inability to interoperate effectively with the database technologies and file systems of prospective customers;
• defects, errors or failures;
• negative publicity or customer complaints about performance or effectiveness; and
• poor business conditions, causing customers to delay IT purchases.
If we fail to anticipate market requirements or stay abreast of technological changes, we may be unable to successfully introduce new products, expand the functionality of our current products or convince our customers and potential customers of the value of our solutions in light of new technologies. Accordingly, our business, results of operations and financial condition could be materially and adversely affected.
If our technical support, customer success or professional services are not satisfactory to our customers, they may not renew their agreements or not buy additional products in the future, which could adversely affect our future results of operations.
Our business relies on our customers’ satisfaction with the technical support and professional services we provide to support our products. Our customers have no obligation to renew their agreements with us after the initial terms have expired. Our customers have an option to renew their agreements and, for us to maintain and improve our results of operations, it is important that our existing customers renew their agreements, if applicable, when the existing contract term expires. For example, our renewal rate for the years ended December 31, 2022, 2021 and 2020 continued to be over 90%. Customer satisfaction will become even more important as almost all of our licensing has shifted to subscription license agreements.
If we fail to provide technical support services that are responsive, satisfy our customers’ expectations and resolve issues that they encounter with our products and services, then they may elect not to purchase or renew contracts and they may choose not to purchase additional products and services from us. Accordingly, our failure to provide satisfactory technical support or professional services could lead our customers not to renew their agreements with us or renew on terms less favorable to us, and therefore have a material and adverse effect on our business and results of operations.
Because we derive substantially all of our revenues and cash flows from sales of licenses from a single platform of products, failure of the products in the platform to satisfy customers or to achieve increased market acceptance would adversely affect our business.
In 2022, we generated substantially all of our revenues from sales of licenses from DatAdvantage, DatAlert, Data Classification Engine, DataPrivilege and Data Transport Engine. We expect to continue to derive the majority of our revenues from license sales relating to these products in the future. As such, market acceptance of these products is critical to our continued success. Demand for licenses for our platform of products is affected by a number of factors, some of which are outside of our control, including continued market acceptance of our software by referenceable accounts for existing and new use cases, technological change and growth or contraction in our market. We expect the proliferation of enterprise data to lead to an increase in the data analysis demands, and data security and retention concerns, of our customers, and our software, including the software underlying the Varonis Data Security Platform, may not be able to scale and perform to meet those demands. If we are unable to continue to meet customer demands or to achieve more widespread market acceptance of our software, our business, operations, financial results and growth prospects will be materially and adversely affected.
24
Interruptions or performance problems, including associated with our website or support website or any caused by cyberattacks, may adversely affect our business.
Our continued growth depends in part on the ability of our existing and potential customers to quickly access our website and support website. Access to our support website is also imperative to our daily operations and interaction with customers, as it allows customers to download our software, fixes and patches, as well as open and respond to support tickets and register license keys for evaluation or production purposes. We have experienced, and may in the future experience, website disruptions, outages and other performance problems due to a variety of factors, including technical failures, cyberattacks, natural disasters, infrastructure changes, human or software errors, capacity constraints due to an overwhelming number of users accessing our website simultaneously and denial of service or fraud. In some instances, we may not be able to identify the cause or causes of these performance problems within an acceptable period of time. System failures or outages, including any potential disruptions due to a period of increased global demand on certain cloud-based systems or disruptions of our cloud-based solutions, could compromise our or our customer’s ability to perform day-to-day operations in a timely manner, which could negatively impact our business or delay our financial reporting. It may become increasingly difficult to maintain and improve the performance of our websites, especially during peak usage times and as our software becomes more complex and our user traffic increases. If our websites are unavailable or if our users are unable to download our software, patches or fixes within a reasonable amount of time or at all, we may suffer reputational harm and our business would be negatively affected.
If our software is perceived as not being secure, customers may reduce the use of or stop using our software, and we may incur significant liabilities.
Our software involves the transmission of data between data stores, and between data stores and desktop and mobile computers, and will increasingly involve the storage of data. We have a legal and contractual obligation to protect the confidentiality and appropriate use of customer data. Any security breaches with respect to such data could result in the loss of this information, litigation, indemnity obligations and other liabilities. The security of our products and accompanied services is important in our customers’ decisions to purchase or use our products or services. Security threats are a significant challenge to companies like us whose business is providing technology products and services to others. While we have taken steps to protect the confidential information that we have access to, including confidential information we may obtain through our customer support services or customer usage of our products, we have no direct control over the substance of the content. Security measures might be breached as a result of third-party action, employee error, malfeasance or otherwise. We also incorporate open source software and other third-party software into our products. There may be vulnerabilities in open source software and third-party software that may make our products likely to be harmed by cyberattacks. Moreover, our products operate in conjunction with and are dependent on products and components across a broad ecosystem of third parties. If there is a security vulnerability in one of these components, and if there is a security exploit targeting it, such security vulnerability may adversely impact our product vulnerability and we could face increased costs, liability claims, reduced revenue, or harm to our reputation or competitive position. Because techniques used to obtain unauthorized access or sabotage systems change frequently and generally are not identified until they are launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures.
The limitations of liability in our contracts may not be enforceable or adequate or otherwise protect us from any such liabilities or damages with respect to any particular claim. While we maintain insurance coverage for some of the above events, the potential liabilities associated with these security breach events could exceed the insurance coverage we maintain.
Any or all of these issues could tarnish our reputation, negatively impact our ability to attract new customers or sell additional products to our existing customers, cause existing customers to elect not to renew their maintenance and support agreements or subject us to third-party lawsuits, regulatory fines or other action or liability, thereby adversely affecting our results of operations.
Our use of open source software could negatively affect our ability to sell our software and subject us to possible litigation.
We use open source software and expect to continue to use open source software in the future. Some open source software licenses require users who distribute open source software as part of their own software product to publicly disclose all or part of the source code to such software product or to make available any derivative works of the open source code on unfavorable terms or at no cost. We may face ownership claims of third parties over, or seeking to enforce the license terms applicable to, such open source software, including by demanding the release of the open source software, derivative works or our proprietary source code that was developed using such software. These claims could also result in litigation, require us to purchase a costly license or require us to devote additional research and development resources to change our software, any of which would have a negative effect on our business and results of operations. In addition, if the license terms for the open source code change, we may be forced to re-engineer our software or incur additional costs. Finally, while we implement policies and procedures, we cannot provide assurance that we have incorporated open source software into our own software in a manner that conforms with
25
our current policies and procedures and we cannot assure that all open source software is reviewed prior to use in our solution, that our programmers have not incorporated open source software into our solution, or that they will not do so in the future.
In addition, our solution may incorporate third-party software under commercial licenses. We cannot be certain whether such third-party software incorporates open source software without our knowledge. In the past, companies that incorporate open source software into their products have faced claims alleging noncompliance with open source license terms or infringement or misappropriation of proprietary software. Therefore, we could be subject to suits by parties claiming noncompliance with open source licensing terms or infringement or misappropriation of proprietary software. Because few courts have interpreted open source licenses, the manner in which these licenses may be interpreted and enforced is subject to some uncertainty. There is a risk that open source software licenses could be construed in a manner that imposes unanticipated conditions or restrictions on our ability to market or provide our solution. As a result of using open source software subject to such licenses, we could be required to release proprietary source code, pay damages, re-engineer our solution, limit or discontinue sales or take other remedial action, any of which could adversely affect our business.
False detection of security breaches, false identification of malicious sources or misidentification of sensitive or regulated information could adversely affect our business.
Our cybersecurity products may falsely detect threats that do not actually exist. For example, our DatAlert product may enrich metadata collected by our products with information from external sources and third-party data providers. If the information from these data providers is inaccurate, the potential for false positives increases. These false positives, while typical in the industry, may affect the perceived reliability of our products and solutions and may therefore adversely impact market acceptance of our products. As definitions and instantiations of personal identifiers and other sensitive content change, automated classification technologies may falsely identify or fail to identify data as sensitive. If our products and solutions fail to detect exposures or restrict access to important systems, files or applications based on falsely identifying legitimate use as an attack or otherwise unauthorized, then our customers’ businesses could be adversely affected. Any such false identification of use and subsequent restriction could result in negative publicity, loss of customers and sales, increased costs to remedy any problem and costly litigation.
Failure to protect our proprietary technology and intellectual property rights could substantially harm our business.
The success of our business and competitive position depends on our ability to obtain, protect and enforce our trade secrets, trademarks, copyrights, patents and other intellectual property rights. We attempt to protect our intellectual property under patent, trademark, copyrights and trade secret laws, and through a combination of confidentiality procedures, contractual provisions and other methods, all of which offer only limited protection and may not now or in the future provide us with a competitive advantage.
As of December 31, 2022, we had 85 issued patents in the United States and 12 pending U.S. patent applications. We also had 55 patents issued and 42 applications pending for examination in non-U.S. jurisdictions, and two pending PCT patent applications, all of which are counterparts of our U.S. patent applications. We may file additional patent applications in the future. The process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner all the way through to the successful issuance of a patent. We may choose not to seek patent protection for certain innovations and may choose not to pursue patent protection in certain jurisdictions. Furthermore, it is possible that our patent applications may not issue as granted patents, that the scope of our issued patents will be insufficient or not have the coverage originally sought, that our issued patents will not provide us with any competitive advantages, and that our patents and other intellectual property rights may be challenged by others or invalidated through administrative process or litigation. In addition, issuance of a patent does not guarantee that we have an absolute right to practice the patented invention. Our policy is to require our employees (and our consultants and service providers that develop intellectual property included in our products) to execute written agreements in which they assign to us their rights in potential inventions and other intellectual property created within the scope of their employment (or, with respect to consultants and service providers, their engagement to develop such intellectual property). However, we may not be able to adequately protect our rights in every such agreement or execute an agreement with every such party. Finally, in order to benefit from patent and other intellectual property protection, we must monitor, detect and pursue infringement claims in certain circumstances in relevant jurisdictions, all of which is costly and time-consuming. As a result, we may not be able to obtain adequate protection or to enforce our issued patents or other intellectual property effectively.