vrns-20251231
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
_____________________
FORM 10-K
_____________________
(Mark One)
for the Fiscal Year Ended December 31, 2025
or
for the transition period from to
Commission file number: 001-36324
________________________
VARONIS SYSTEMS, INC.
(Exact name of registrant as specified in its charter)
_____________________________
801 Brickell Avenue
Miami, FL33131
(Address of principal executive offices) (zip code)
Registrant’s telephone number, including area code: (877) 292-8767
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol(s) Name of each exchange on which registered
Common Stock, par value $0.001 per share VRNS The NASDAQ Stock Market LLC
Securities registered pursuant to Section 12(g) of the Act: None
_____________________________
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large Accelerated Filer ☒ Accelerated Filer ☐
Non-accelerated Filer ☐ Smaller reporting company ☐
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report.☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements
of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
As of June 30, 2025, the aggregate market value of the registrant's voting and non-voting common equity held by non-affiliates was approximately $5.56 billion.
As of January 30, 2026, the registrant had 117,447,726 shares of common stock, par value $0.001 per share, outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the Registrant’s Proxy Statement relating to the 2026 Annual Meeting of Stockholders are incorporated by reference into Part III of this Annual Report on Form 10-K.
Special Note Regarding Forward-Looking Statements and Summary Risk Factors
This report contains, and management may make, certain forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended (the “Securities Act”), and Section 21E of the Securities Exchange Act of 1934, as amended (the “Exchange Act”). All statements, other than statements of historical facts, may be forward-looking statements. Forward-looking statements are often identified by the use of words such as “anticipate,” “believe,” “can,” “continue,” “could,” “estimate,” “expect,” “intend,” “likely,” “may,” “plan,” “project,” “seek,” “should,” “strategy,” “target,” “will,” “would” and similar expressions or variations intended to identify forward-looking statements. These statements are based on the beliefs and assumptions of our management based on information currently available to management. Such forward-looking statements are subject to risks, uncertainties and other important factors, many of which are difficult to predict and generally beyond our control, that could cause actual results and the timing of certain events to differ materially from future results expressed or implied by such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those identified in the “Summary Risk Factors” below and those discussed in “Item 1A-Risk Factors” and “Item 7-Management’s Discussion and Analysis of Financial Condition and Results of Operations.” Furthermore, such forward-looking statements speak only as of the date of this report. Except as required by law, we undertake no obligation to update any forward-looking statements to reflect events or circumstances after the date of such statements.
The risks that might cause actual results to differ from our expectations include, among other things, those that may be disclosed from time to time in subsequent reports filed with or furnished to the SEC, those described under “Risk Factors” set forth in Item 1A of this Annual Report, and the following, which also summarizes the principal risks of our business:
•the fact that the market for software that analyzes, secures, governs, manages and migrates enterprise data may not continue to grow or grow at the same pace;
•prolonged economic uncertainties or downturns;
•currency exchange rate fluctuations;
•increased competition;
•security breaches, cyberattacks or other cyber-risks and failure to comply with legal requirements, contractual obligations and industry standards regarding security, data protection and privacy;
•our expansion into cloud-delivered services;
•our ability to predict renewal rates and manage growth effectively;
•fluctuation in our quarterly results of operations due to variability in our revenues;
•our limited operating history at our current scale, which makes it difficult to evaluate and predict our future prospects;
•our history of losses;
•our ability to maintain strong relationships with our channel partners, including distributors and resellers, to whom we sell substantially all of our products and services;
•risks inherent in our international operations, including military conflicts that could impact operations, the effect of export and import controls and the risk of a violation or alleged violation of applicable anti-corruption or anti-bribery laws;
•collection and credit risks;
•stock price volatility;
•our ability to maintain or enhance our brand recognition or reputation;
•our ability to retain, attract and recruit highly qualified personnel;
•our dependency on the continued services and performance of our co-founder, Chief Executive Officer and President;
•our ability to continually enhance and improve our technology;
•the fact that, if we experience interruptions or performance problems with our products, or if our software is not perceived as being secure, customers may reduce the use of or stop using our products;
•our ability to protect our proprietary technology and intellectual property rights;
•the fact that our tax rate may vary significantly depending on our stock price;
•our ability to fully utilize our net operating loss carryforwards; and
•our indebtedness.
You should not place undue reliance on forward-looking statements. All forward-looking statements attributable to us or persons acting on our behalf are expressly qualified in their entirety by the foregoing cautionary statements. All such statements speak only as of the date of this Annual Report and, except as required by law, we undertake no obligation to update or revise publicly any forward-looking statements, whether as a result of new information, future events or otherwise.
i
VARONIS SYSTEMS, INC.
ANNUAL REPORT ON FORM 10-K
For The Fiscal Year Ended December 31, 2025
TABLE OF CONTENTS
Page
PART I
Item 1 Business 1
Item 1A Risk Factors 9
Item 1B Unresolved Staff Comments 32
Item 1C Cybersecurity 33
Item 2 Properties 34
Item 3 Legal Proceedings 34
Item 4 Mine Safety Disclosures 34
PART II
Item 6 Reserved 37
Item 7A Quantitative and Qualitative Disclosures About Market Risk 51
Item 8 Financial Statements and Supplementary Data 53
Item 9A Controls and Procedures 95
Item 9B Other Information 96
Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 96
PART III
Item 10 Directors, Executive Officers and Corporate Governance 97
Item 11 Executive Compensation 97
Item 14 Principal Accounting Fees and Services 97
PART IV
Item 15 Exhibits and Financial Statement Schedules 98
ii
PART I
Item 1. Business
We were incorporated under the laws of the State of Delaware on November 3, 2004 and commenced operations on January 1, 2005. Our principal offices are located at 801 Brickell Avenue, Miami, FL 33131. For convenience in this report, the terms “Company,” “Varonis,” “we” and “us” may be used to refer to Varonis Systems, Inc. and/or its subsidiaries, except where indicated otherwise. Our telephone number is (877) 292-8767.
Overview
Varonis is a data security company focused on protecting what matters most to organizations: their data. Modern enterprises run on data that is created, copied, shared and accessed across cloud services, SaaS applications and on-premises environments, often faster than security teams can see, understand or control. We started Varonis around a simple observation that we believe has only intensified over time: the ability to create and share data scales far faster than the ability to secure it. Our strategy is built around closing that gap, giving organizations the deep visibility and automated controls to deeply understand their enterprise data, reduce exposure and respond to threats quickly, wherever their data lives.
Data growth itself is not new. What has changed is the combination of scale, sprawl and speed. Cloud transformation and artificial intelligence ("AI") initiatives are pushing data into more systems, across more environments and making it accessible to more users, applications and AI agents. As adoption of software-a-service (“SaaS”) and infrastructure-as-a-service (“IaaS”) has accelerated collaboration and productivity, it has also expanded and fragmented the enterprise data footprint. In many organizations, data security controls have not kept pace, increasing the likelihood that misconfigurations or credential compromise can lead to significant data exposure, threats and regulatory penalties.
We believe the adoption of AI materially raises the stakes for security and risk. Copilots, agents and automated workflows are now embedded in widely used enterprise platforms such as Microsoft 365, Salesforce, Google Workspace and Box and they increasingly act on data at machine speed. These systems typically rely on existing access controls to determine what data can be surfaced, summarized or acted upon. When those controls are overly permissive, poorly understood and unmonitored, AI can unintentionally amplify risk by scaling access faster than organizations can manage manually. As companies customize AI agents and train their own small and large language models, we believe the security of data, identities, agents and underlying infrastructure will increasingly require automated solutions.
In this environment, access becomes the risk multiplier. When too many people, systems or automated agents can reach sensitive data ungoverned, small incidents can quickly become large ones. We refer to this risk as the “blast radius.” We believe organizations must continuously reduce their blast radius – limiting unnecessary ability to access, move or misuse data – to reap the tremendous benefits of AI. Achieving this consistently and at scale isn’t possible through manual processes, making automation essential.
At the same time, threat actors continue to refine their methods of monetizing sensitive data, and regulatory expectations around privacy, data protection, and AI governance continue to evolve. Many organizations are also operating under real constraints – the demand for skilled security professionals continues to exceed supply, and teams are expected to manage growing complexity with limited resources. We believe these pressures will continue to drive adoption of automated approaches that reduce data exposure by default and enable faster detection and response.
Enterprises today rely on many combinations of data stores, cloud services and SaaS applications, making it difficult to understand data exposure holistically or control breach risk without a unified approach. We believe comprehensive coverage and automation are required to keep pace with the scale and complexity of modern data environments. Our platform has expanded from an initial focus on Windows files shares to cover a broad range of mission-critical cloud and on-premises data stores, cloud infrastructure environments, identity repositories, and key SaaS and AI applications. In 2022, we introduced the Varonis Data Security Platform as a SaaS offering to simplify deployment, accelerate time-to-value, and enable continuous cloud-delivered automation for protecting data.
Varonis software helps organizations of all sizes and industries protect sensitive data stored in the cloud and on-premises, including: files, emails and databases, confidential personal data, financial records, source code, strategic and product plans, and other intellectual property. As the volume, velocity and variety of enterprise data continues to grow, we have built an integrated platform designed to simplify and streamline data security, threat detection and response, and privacy and compliance workflows.
Platform and Technology
1
Our platform is designed around a core belief: in modern data environments, security outcomes are determined less by perimeter controls and more by how much access exists when something goes wrong. As data spreads across cloud services, SaaS applications and on-premises systems – and as humans, services and AI agents interact with that data at increasing speed – manual approaches to security do not scale. We believe reducing unnecessary access to sensitive data and automatically responding to abnormal behavior are essential to limiting the impact of inevitable failures.
At the foundation of the Varonis Data Security Platform is our ability to understand data in context. Our proprietary technology, continuously collects and analyzes metadata – data about data – across an organizations' environments. We understand what types of data exists, where it lives, who can access it and how it’s being used. This contextual view allows us to map relationships among users, devices, applications, automated agents and data objects, creating a durable model of the organization’s data exposure even as environments change.
This metadata-driven approach enables our platform to operate at enterprise scale with minimal impact on production systems. Rather than relying on static rules or periodic scans, the platform continuously normalizes metadata from disparate sources, making it actionable across hybrid and multi-cloud environments. We believe this persistent, contextual understanding of data is critical to enabling productivity and AI adoption that is effective and safe.
Building on this foundation, the Varonis Data Security Platform is designed to automate outcomes across data protection, threat detection and response, and privacy and compliance. The platform continuously discovers and classifies well-defined sensitive data like credit card numbers, SSNs and patient IDs, and uses machine learning and AI to identify novel domain- and organization-specific data such as recipes, contracts, formulas and other intellectual property. Beyond understanding the data estate, Varonis identifies excessive or risky access and automatically remediates exposure by right-sizing permissions and removing outdated or unnecessary access. By reducing the amount of data that users, systems and automated agents can reach, the platform helps organizations move toward a least-agency model that limits the potential blast radius of an incident without disrupting everyday business operations.
The same model is used to detect and respond to threats. By analyzing data access patterns – user and entity behavior and system activity together – the platform can identify suspicious behavior that could be compromised credentials, insider misuse, malware or ransomware. When threats are detected, the platform can automatically take action to contain it such as restricting access or locking down affected accounts, limiting potential damage and reducing recovery time.
The Varonis platform is offered as a SaaS offering, which we believe is key to our ability to deliver these outcomes at scale. SaaS delivery allows customers to deploy quickly, reduce infrastructure and operational overhead, and benefit from continuous updates to threat models, automation workflows and security capabilities, including our Managed Data Detection and Response (“MDDR”) offering, which are only available through our SaaS platform.
We have further expanded the platform’s capabilities with the introduction of Athena AI, a generative AI layer designed to enhance security operations rather than replace human judgement. Athena AI combines small and large language models with the platform’s deep understanding of data, identities, and prior incidents to help security teams with investigation, response and reporting. By enabling natural-language interaction and generating tailored response guidance, Athena AI helps teams act more quickly and effectively without requiring specialized expertise.
Our platform architecture is designed to be extensible. We continue to expand coverage across additional data stores, cloud services, and SaaS applications. We enhance functionality both organically and through strategic acquisitions. Our recent acquisition of Cyral, Inc. ("Cyral") enhanced our data security offering with database activity monitoring capabilities. We also acquired SlashNext, Inc. ("SlashNext"), an AI-based email security technology that gives Varonis the ability to detect and block modern social-engineering attacks across multiple communication channels. We believe this approach allows customers to consolidate security capabilities onto a single platform while giving us a framework to address emerging risks, including those introduced by AI-driven systems, new data types, and evolving regulatory requirements.
SaaS Delivery Model
Our platform is designed to deliver security outcomes at scale without requiring proportional increases in customer effort or staffing. By automating discovery, classification, access reduction and response, customers can reduce risk across large and complex data environments without relying on manual processes that do not scale.
The SaaS delivery model supports this approach by enabling rapid deployment, continuous updates and lower operational overhead. Customers can begin assessing risk and reducing exposure quickly, while benefiting from ongoing improvements to detection models, automation workflows and new capabilities delivered through the platform.
2
As part of our strategic transition to SaaS, we have announced the end-of-life of our self-hosted products as of December 31, 2026.
Size of Our Market Opportunity
The International Data Corporation’s Global DataSphere Forecast, 2025-2029, predicts that over the next five years, data will grow at a compound annual growth rate of 25.4% to reach more than 527 zettabytes (or 527 trillion Gigabytes) by 2029. That data will include both structured and unstructured data, but unstructured data overwhelmingly dominates, accounting for approximately 90% of the data created each year. We expect this significant growth to continue creating a need for automation technologies to protect and manage data. We believe that the diverse coverage and functionality offered by our platform positions us well to capitalize on this powerful trend in the digital universe.
Growth Strategy
Our objective is to be the primary platform enterprises rely on to protect their most sensitive data. We believe the combination of accelerating data growth, expanding use of SaaS and cloud infrastructure, and the adoption of AI-driven systems creates a durable, long-term opportunity for automated data security. Our growth strategy is focused on scaling a unified platform that reduces data exposure, limits the impact of incidents and enables customers to operate securely as their environments become more complex.
Extend the Platform Through Innovation and Strategic Transactions. We intend to continue investing in product development to expand the capabilities of the Varonis Data Security Platform and address new use cases from changes in how data is created, accessed and used. Our platform architecture allows us to add coverage across additional data stores, cloud services and SaaS applications, as well as introduce new automation and response capabilities without requiring customers to deploy separate point solutions.
In addition to organic innovation, we selectively pursue strategic acquisitions that extend our platform or accelerate entry into adjacent markets where we believe automation and context provide a competitive advantage. We focus on technologies that can be integrated into our platform to enhance data visibility, reduce exposure and improve detection and response outcomes, including recent additions in database activity monitoring and email security. We believe this disciplined approach allows us to expand functionality while maintaining a unified operating model.
Grow Adoption Within Existing Customers. We believe our existing customer base represents a significant opportunity for continued growth. As customer environments evolve, data volumes increase and AI-driven workflows expand, organizations typically extend data security controls to additional systems and use cases. Our platform is designed to scale with customer needs, enabling broader adoption across data stores, applications and environments over time. Our renewal rate for the year ended December 31, 2025 continued to be over 90%,
We expect increased adoption to be driven by customers consolidating security capabilities onto a single platform. By delivering ongoing improvements through our platform and focusing on risk reduction outcomes, we aim to deepen customer relationships and maintain high renewal rates.
Acquire New Customers Through Platform-Led Expansion.. We continue to target new customers across industries and geographies that face growing data security, compliance and operational challenges. While our platform is built to support organizations of all sizes, we remain focused on larger enterprises that can benefit most from automation at scale.
Our go-to-market approach combines a global network of channel partners with a highly trained sales organization that engages customers through risk assessments and platform demonstrations. We believe this model creates efficiencies in customer acquisition while clearly articulating the value of reducing data exposure and limiting incident impact.
Scale SaaS, Automation, and Managed Services. The transition to a SaaS delivery model is central to our growth strategy. SaaS delivery enables faster deployment, continuous improvement and increased automation, while also supporting recurring revenue and operational leverage. It also provides the foundation for advanced capabilities including our MDDR offering, which delivers 24x7x365 monitoring and response backed by service-level commitments.
3
We believe demand for managed and automated security outcomes will continue to increase as organizations seek to operate securely with constrained internal resources. By combining platform automation with expert-led response, we aim to help customers reduce risk and simplify operations.
Expand Internationally and Establish Platform Leadership. We believe there is a significant opportunity to expand adoption of our platform internationally as data protection, privacy and security requirements become increasingly global. We continue to invest in international sales, marketing, and partner relationships to support this expansion.
We also work closely with leading cloud services providers, storage vendors and SaaS platforms to ensure compatibility and integration across the enterprise ecosystem. We believe these relationships, combined with our broad coverage and automation capabilities, position the Varonis Data Security Platform to become a standard foundation for enterprise data security.
Competition
The markets in which we operate are competitive and evolving. Enterprises address data security, privacy and threat detection through a combination of internal processes and software solutions, including point products designed to address specific use cases. While some vendors offer functionality that overlaps with individual components of our platform, we believe the competitive landscape is increasingly shaped by differences in approach, rather than by any single feature.
Many organizations have historically addressed data security through fragmented tools focused on visibility, classification or monitoring within isolated environments. We believe this approach is insufficient as data becomes more distributed across cloud services, SaaS applications, and on-premises systems, and as access is granted not only to users but also to services and automated agents. In this environment, the ability to understand data in context and reduce unnecessary access at scale becomes a critical differentiator.
We compete with a range of vendors that provide standalone or partially integrated solutions across areas such as data security posture management, data discovery and classification, data privacy, directory and identity security, and threat detection and response. We also face competition from broader security platforms that offer adjacent capabilities. In addition, large cloud providers and SaaS vendors continue to expand native security features within their platforms.
We believe our competitive position is strengthened by the breadth of environments we support and by our ability to deliver automated outcomes across data security, threat detection and response, and privacy and compliance within a single platform. Our approach is designed to reduce data exposure proactively, limit the potential impact of incidents and respond quickly when threats occur, rather than relying primarily on alerts and manual intervention.
As organizations increasingly adopt SaaS, cloud infrastructure, and AI-driven systems, we believe the limitations of manual, rules-based and alert-centric security models become more apparent. Solutions that depend heavily on customer configuration, tuning and ongoing human oversight may struggle to scale as environments grow in size and complexity. We believe automation will become an essential requirement for effective data security.
Competition in our markets is influenced by several factors including the effectiveness and reliability of solutions, the breadth of support environments, scalability, ease of deployment and the ability to deliver measurable risk reduction. We believe we compete favorably across these areas, however, some competitors may have greater resources, longer operating histories, broader brand recognition or deeper relationships with certain customers and partners, which could affect our ability to compete in specific situations.
As the market continues to evolve, we expect competition to increase as new vendors enter the space and existing providers expand their offerings. We believe our focus on platform consolidation, automation, and reducing data exposure positions us to compete effectively as customer requirements continue to change.
Products
Our products are delivered through our flagship Varonis Data Security Platform, a unified platform designed to protect enterprise data across cloud, SaaS and on-premises environments. With the introduction of our SaaS offering, we have simplified how customers use our capabilities by moving away from individually licensed modules and towards a platform-based model. This approach is intended to reduce complexity, accelerate adoption ,and enable customers to realize value from automation across multiple use cases.
4
Software-as-a-Service ("SaaS")
The Varonis Data Security Platform is offered as a SaaS solution and is sold as a platform license that includes a core set of integrated capabilities. We believe this delivery and licensing model reflects how customers increasingly prefer to consume security technology: as a continuously updated service that reduces operational overhead and supports automation at scale.
The Varonis Data Security Platform SaaS license includes capabilities designed to help customers understand their data exposure, reduce unnecessary access, and detect and respond to threats. These capabilities include:
•Varonis Data Security Platform. We know that customers who utilize a higher number of licenses see more value upfront through automation and synergy between modules. Therefore, we drastically simplified our subscription licensing under SaaS, combining five of our most popular licenses into a single Varonis Data Security Platform license. The Varonis Data Security Platform SaaS license includes new capabilities not available in our self-hosted product suite. Today, the Varonis Data Security Platform SaaS license includes:
◦Data security posture management ("DSPM"). Provides customers with real-time visibility of their data security posture across their multi-cloud and on-premises data, helps prioritize remediation efforts, and tracks progress over time.
◦Data access intelligence. Combines data sensitivity, permissions, and activity to show customers who has access to critical data (i.e., their data blast radius), how they got access, and whether access is necessary.
◦Data discovery & classification. Automatically and continuously scans the contents of files, folders, and other objects to determine sensitivity with a high degree of accuracy and precision.
◦Discovery policy library. A frequently updated library for identifying and classifying personal information specific to GDPR, CCPA, and US federal controlled unclassified information (CUI).
◦Least privilege automation. Automatically and continuously remediates excessive data access granted via shared links, direct permissions, and group memberships without manual effort and without impacting business continuity.
◦Data activity monitoring. Gives customers a real-time view into who is accessing data directly or through AI (such as copilots) via a normalized and enriched log of data-centric events such as create, open, read, move, modify, and delete. Varonis also tracks, among other things, permission changes, authentication events, password updates and shared link activity.
◦Data detection and response. Provides high-fidelity, data-centric alerts and automated response actions. Includes a web-based alerts dashboard and investigative interface, and seamlessly integrates with security information and event management systems (SIEM).
◦User & entity behavior analytics. Profiles users, agents and devices and their associated behaviors with respect to systems and data, detects and alerts on meaningful deviations that indicate compromise. New UEBA threat models are automatically delivered to customers to guard against evolving tactics used by cybercriminals, insiders and advanced persistent threats (APTs).
Customers select which environments to protect by purchasing “Protection Packages.” These packages allow customers to extend the platform across:
◦Microsoft 365. Includes support for SharePoint Online, OneDrive for Business, Microsoft Teams, and Entra ID (formerly known as Azure AD). Customers can purchase add-on support for Exchange Online, Microsoft 365 Copilot and ChatGPT Enterprise.
◦Windows & NAS. Includes support for Windows/CIFS-based file shares and NAS storage such as Nutanix, Nasuni, Panzura, Pure Storage, NetApp and Dell EMC. Customers can purchase add-on support for on-premises Active Directory, UNIX/Linux and Edge devices (VPN, DNS, proxy).
◦Hybrid. Combined support for the protected resources in the Microsoft 365 and Windows & NAS packages.
5
◦Cloud Environments. Protects data across SaaS applications and IaaS environments. The protected resources currently include Salesforce, AWS, Azure, Google Cloud, Google Workspace, Databricks, ServiceNow, Snowflake, Confluence, Slack, GitHub, Okta, Box, Jira, Zoom and databases.
We believe this packaging approach enables customers to scale coverage over time while maintaining a consistent operating model.
The SaaS platform also serves as the foundation for advanced capabilities that require persistent visibility and automation, including our MDDR offering. MDDR provides customers with continuous monitoring and response backed by defined service-level commitments and is available exclusively through our SaaS platform.
Database and Email Security Capabilities
In addition to our core platform functionality, we offer specialized capabilities that extend protection to additional high-risk areas.
•Varonis Database Activity Monitoring (“DAM”). Provides cloud-native monitoring and security for on-premises and cloud databases and is integrated with the broader platform to deliver consistent visibility, classification, and response.
•Varonis Interceptor. Provides best-of-breed phishing prevention and malicious link interception with multi-modal AI and URL sandboxing technologies, extending platform protection to email and collaboration channels. When combined with our MDDR solution, Varonis Interceptor detects and protects across data stores, applications, and communication channels.
On-Premises Subscription Products
Prior to the introduction of our SaaS offering, we sold our products primarily through self-hosted subscription licenses that allowed customers to deploy individual modules on-premises. These products used our core technology to provide visibility, classification, access governance and monitoring across enterprise data environments.
As part of our strategic transition to SaaS, we have announced the end-of-life of our on-premises subscriptions as of December 31, 2026. We expect customers to adopt our SaaS platform as the primary way to engage our capabilities going forward.
Customers
We serve a global customer base across more than 95 countries, supporting organizations that operate in different environments and face significant security, privacy and compliance requirements. Our customers span a wide range of industries, including financial services, public, healthcare, industrial, insurance, energy and utilities, technology, construction and engineering, education, and consumer and retail sectors.
Our platform is used by organizations ranging from small and mid-sized businesses to large multinational enterprises with hundreds of thousands of employees and petabytes of data. While our solutions are applicable across company sizes, a significant portion of our customer base consists of larger enterprises that benefit most from automation at scale and from a unified approach to data security.
We believe our customer relationships are durable and expand over time. As customer data volumes grow, environments become more distributed and AI-driven workflows are adopted, customers typically extend platform coverage to additional data stores, applications, and use cases. This expansion is supported by our platform-based model, continuous SaaS delivery and focus on reducing data exposure and operational burden.
Our customers include organizations that manage highly sensitive information, such as personal and financial data, intellectual property and regulated data. We believe our ability to deliver automated risk reduction, rapid detection and response, and measurable security outcomes, positions as a long-term partner rather than a point solution provider.
6
Services
Maintenance and Support of Subscription and Perpetual Licenses
Maintenance and support associated with a term license subscription is included in the Term license subscriptions revenue line of the statement of operations. Maintenance and support associated with past perpetual licenses is included in the Maintenance and services line of the statement of operations. These maintenance agreements provide customers the right to receive support and unspecified upgrades and enhancements when and if they become available during the maintenance period and access to our technical support services. Our renewal rate for 2025 continued to be over 90%. Due to the transition to a SaaS delivery model, we expect maintenance and support revenues related to term license subscriptions to decline, as we move closer to their end-of-life. Additionally, we do not expect perpetual license revenues in the future and, accordingly, we also expect the associated maintenance and support to decline.
We maintain a customer support organization that provides all levels of support to our customers. Our customers receive guaranteed response times, direct telephonic support and access to online support portals. Our customer support organization has global capabilities with expertise in both our software and complex IT environments and associated third-party infrastructure.
Sales and Marketing
Sales
We sell our products and services through a global network of resellers and distributors, which we refer to as our channel partners. These channel partners sell our products to end customers and play a key role in identifying opportunities, maintaining customer relationships and supporting deployment. Sales to channel partners are subject to our standard, non-exclusive channel partner agreements that are generally renewed annually and can be terminated by either party with notice.
Our channel model is complemented by a highly trained, professional sales organization that is responsible for market development, managing partner relationships and supporting customer engagements. Our sales teams work closely with channel partners to conduct platform demonstrations and risk assessments that help customers understand their data exposure and the value of reducing risk through automation. We believe this approach allows us to clearly articulate and show the value of our platform.
Marketing
Our marketing strategy is focused on building brand and product awareness of the Varonis Data Security Platform, educating the market on data risk and automation, and supporting customer adoption and expansion. We seek to communicate the business and security outcomes our platform delivers rather than emphasizing individual features or point solutions.
We execute our marketing programs through a combination of internal teams, external partners and channel collaboration. Our activities include brand and content marketing, demand generation, field marketing and partner marketing, customer education and public relations. We also engage with industry analysts, host customer and community events and provide educational resources such as webinars, training programs, and technical content.
We believe that sustained investment in thought leadership and education is important as data security requirements evolve, particularly in areas such as cloud adoption and AI-driven systems. Our marketing efforts are designed to support long-term platform adoption by helping customers and partners understand how to reduce data exposure and operate as environments grow more complex.
Research and Development
Our research and development efforts are focused on advancing the Varonis Data Security Platform by expanding coverage, increasing automation and improving our ability to reduce data exposure and respond to threats at scale. We invest in innovation that strengthens the platform’s core capabilities and allows it to adapt as enterprise data environments, threat models and regulatory requirements evolve.
We conduct the majority of our research and development activities in Israel, which we believe provides access to a highly skilled engineering workforce with deep expertise in security, data systems and large-scale software development. In
7
addition to organic development, we selectively pursue strategic acquisitions that bring specialized technologies and talent to the platform, accelerating innovation while maintaining a unified architecture.
We believe our sustained investment in research and development supports the long-term competitiveness of our platform and positions us to address emerging risks, including those introduced by new data types, cloud architecture and AI-driven systems.
Intellectual Property
We attempt to protect our technology and the related intellectual property under patent, trademark, copyright and trade secret laws, confidentiality procedures and contractual provisions. No single intellectual property right is solely responsible for protecting our products. The nature and extent of legal protection of our intellectual property rights depends on, among other things, its type and the jurisdiction in which it arises. As of December 31, 2025, we had 116 issued patents and 63 pending patent applications in the United States. Our issued U.S. patents expire between 2026 and 2043. We also had 95 patents issued and 79 applications pending for examination in non-U.S. jurisdictions, and 31 pending Patent Cooperation Treaty (“PCT”) patent applications, all of which are counterparts of our U.S. patent applications. The claims for which we have sought patent protection relate primarily to inventions we have developed for incorporation into our products.
In addition to patented technology, we rely on our unpatented proprietary technology and trade secrets. We generally enter into confidentiality agreements with our employees, consultants, service providers, vendors and customers and generally limit internal and external access to, and distribution of, our proprietary information and proprietary technology through certain procedural safeguards. We also rely on invention assignment agreements with our employees, consultants and others, to assign to the Company all inventions developed by such individuals in the course of their engagement with the Company.
Moreover, we have registered the “Varonis” name and logo and “DatAdvantage,” “DataPrivilege,” “DatAlert,” and other names in the United States and, as related to some of these names, certain other countries.
In addition to Company-owned intellectual property, we license software from third parties for integration into our solution, including open-source software and other software available on commercially reasonable terms. It may be necessary in the future to seek or renew licenses relating to various aspects of our products, processes and services. While we have generally been able to obtain such licenses on commercially reasonable terms in the past, such third parties may not continue to maintain such software or continue to make it available to us.
Seasonality
See Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations — Seasonality and Quarterly Trends.”
Employees and Human Capital Resources
As of December 31, 2025, we had 2,658 employees and independent contractors who developed, marketed, sold and supported our technology solutions, including 1,139 in the United States, 916 in Israel and 603 in other countries.
We understand that our innovation leadership is ultimately rooted in our people. Competition for qualified personnel in the technology space is intense, and our success depends in large part on our ability to recruit, develop and retain a productive and engaged workforce. Accordingly, investing in our employees and their well-being, offering competitive compensation and benefits, promoting diversity and inclusion, adopting effective human capital management practices and community outreach constitute core elements of our corporate strategy.
•Offer Competitive Compensation and Benefits. We strive to ensure that our employees receive competitive and fair compensation and innovative benefit offerings, tying incentive compensation to both business and individual performance, offering competitive maternal and paternal leave policies, providing meaningful retirement and health benefits and maintaining an employee stock purchase plan.
•Support Employee Well-being and Engagement. We support the overall well-being of our employees from a physical, emotional, financial and social perspective. Our global well-being programs include a long-standing practice of remote working arrangements, flexible paid time off, life planning benefits, wellness platforms and employee assistance. In addition, we ensure ongoing check-ins with employees by HR and managers to provide additional channels of support. We also regularly seek input from employees, including through broad employee satisfaction and pulse surveys on
8
specific issues, intended to assess our degree of success in promoting an environment where employees are engaged, satisfied, productive and possess a strong understanding of our business goals.
•Promote Sense of Belonging. We conduct code of conduct trainings with employees and managers to share our views on the importance of respecting all individuals and creating a culture where everyone feels they belong. We have Employee Resource Groups, led by our employees, designed to foster connection, understanding and support. Our customers are located in over 95 countries and our global workforce operates across cultures, functions, language barriers and time zones to provide them dedicated and ongoing support.
•Provide Programs for Employee Recognition. We offer rewards and recognition programs to our employees, including awards to recognize employees who best exemplify our values and spot awards to recognize employee contributions. We believe that these recognition programs help drive strong employee performance. We conduct semi-annual employee performance reviews, where each employee is evaluated by their personal manager and also conducts a self-assessment, a process which empowers our employees. Employee performance is assessed based on a variety of key performance metrics, including the achievement of objectives specific to the employee’s department or role. Employees have access to an internal platform to recognize their peers based on their professional and socially responsible contributions to the Company.
•Create Opportunities for Growth and Development. We focus on creating opportunities for employee growth, development, training and education, including opportunities to cultivate talent and identify candidates for new roles from within the company, as well as management and leadership development programs. Employee training and education includes online certification, in person certification and new hire training bootcamps. We also conduct manager training programs on an annual basis, which include in-depth managerial and coaching skills, as well as tailored feedback. We have established an internal mentoring program in which seasoned employees' mentor new managers based on defined goals.
•Promote Community Outreach and Support. We believe it is important to give back and promote community outreach and support through corporate giving and employee volunteerism in the communities in which we live and work. We partner with several organizations providing life skills trainings, coding and basic IT skills, financial literacy and more. All programs are led by our employees on a volunteering basis. We also provide corporate matching of employee charitable donations and flexible volunteering during work time, letting our employees know that we support the charitable efforts that matter to them.
Available Information
Our website is located at www.varonis.com, and our investor relations website is located at https://ir.varonis.com. The information posted on our website is not incorporated into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Exchange Act are available free of charge on our investor relations website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC"). You may also access all of our public filings through the SEC’s website at www.sec.gov.
Investors and other interested parties should note that we use our media and investor relations website and our social media channels to publish important information about us, including information that may be deemed material to investors. We encourage investors and other interested parties to review the information we may publish through our media and investor relations website and the social media channels listed on our media and investor relations website, in addition to our SEC filings, press releases, conference calls and webcasts.
Item 1A. Risk Factors
Investing in our securities involves risk. You should carefully consider the following risks and all other information contained herein, including our consolidated financial statements and the related notes thereto. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition and results of operations could be materially harmed.
Risks Related to the Industry in which we Operate
9
The market for software that analyzes, secures, governs, manages and migrates enterprise data may not continue to grow or grow at the same pace.
We believe our future success depends in large part on the continued growth of the market for software that enables enterprises to analyze, secure, govern, manage and migrate their data. In order for us to market and sell our products, we must successfully demonstrate to enterprise IT, security and business personnel the risk of their valuable data getting compromised or stolen and the effectiveness of our products to mitigate these risks. Despite a number of high-profile cyberattacks around the world, we must still persuade customers to devote a portion of their budgets to a unified platform that we offer to analyze, secure, govern, manage and extract value from this resource. Enterprises may not recognize the need for our products or, if they do, may not decide that they need a solution that offers the range of functionalities that we offer. The market for our solution may not continue to grow at its current rate or at all and the failure of the market to continue to develop would materially adversely impact our results of operations.
Prolonged economic uncertainties or downturns could materially adversely affect our business.
Our business depends on our current and prospective customers’ ability and willingness to invest in IT services, including cybersecurity projects, which in turn is dependent upon their overall economic health. Negative conditions in the general economy both in the United States and abroad, including inflationary pressure, currency fluctuations and a higher interest rate environment, changes in gross domestic product growth, instability in connection with political elections, potential future government shutdowns, the federal government’s failure to raise the debt ceiling, financial and credit market fluctuations, the imposition of trade barriers and restrictions such as tariffs, including tariffs implemented around the world by the United States or other countries, political deadlock, restrictions on travel, natural catastrophes, warfare and terrorist attacks, could cause a decrease in business investments, including corporate spending on enterprise software in general and negatively affect the rate of growth of our business. For example, our operations, and the operations of our customers and partners, were affected by geopolitical turmoil and sanctions caused by the war between Russia and Ukraine, and the COVID-19 pandemic and efforts to control its spread, including by mandatory business closures and capacity limitations imposed by the jurisdictions in which we operate. Similar events and restrictions in the future could negatively affect our business.
Uncertainty in the global economy makes it extremely difficult for our customers and us to forecast and plan future business activities accurately. This could cause our customers to reevaluate decisions to purchase our product or to delay their purchasing decisions, which could lengthen our sales cycles and negatively impact our results. In recent years, the European economy experienced economic turmoil that caused the devaluation of local European currencies (specifically, the Euro and the Pound Sterling), inflationary pressures and general economic uncertainty. As a result, there has been, and may in the future be, budgetary tightening and longer sales cycles in the region which may negatively impact our results of operations. In addition, the imposition of tariffs, such as those implemented by the United States or other countries in 2025, may materially impact business performance for companies operating around the world and may cause budgetary tightening and longer sales cycles for companies in those impacted countries. The United States could also experience a sustained period of elevated inflation, which may put pressure on discretionary spending by our customers, and a lengthening of our sales cycle in the region, which could negatively impact our results.
A downturn in any of our leading industries, or a reduction in any revenue-generating vertical, may cause enterprises to react to worsening conditions by reducing their spending on IT. Customers may delay or cancel IT projects, choose to focus on in-house development efforts or seek to lower their costs by renegotiating maintenance and support agreements. To the extent purchases of our software are perceived by customers and potential customers to be discretionary, our revenues may be disproportionately affected by delays or reductions in general IT spending. In addition, consolidation in certain industries may result in reduced spending on our software. If the economic conditions of the general economy or industries in which we operate worsen from present levels, our business, results of operations and financial condition could be adversely affected.
Overall economic uncertainty may in the future give rise to a number of risks, including, but not limited to, the following:
• reduced economic activity could lead to a prolonged recession, which could negatively impact spending by our customers or the ability of customers to pay for our services;
• not meeting expectations with respect to certain key performance metrics, such as renewal rates and annual recurring revenues;
• our ability to enter into new markets and to acquire new customers;
• an increase in bad debt reserves as customers face economic hardship and collectability becomes more uncertain, including the risk of bankruptcies;
• variability with forward-looking guidance and financial results, including management’s accounting estimates and assumptions; and
• our ability to raise capital.
10
The challenges posed by and the full impact of negative conditions in the general economy on our business and our future performance are difficult to predict and there is a risk that any guidance we provide to the market may turn out to be incorrect.
We may face increased competition in our market.
Data security is a rapidly growing and evolving market, driven by increasing regulatory demands, the proliferation of data across hybrid environments, the rising sophistication of cyber threats and increasing AI usage, which increases the need for data security. As a result, the market is attracting investment from both established players and emerging innovators, which is driving increased awareness for the need to secure data, increasing the size of the data security market and intensifying the competitive landscape. Over time, we have strategically made investments in our platform to better serve our customers and also address new use cases, which has grown our market opportunity and also brought us into more competitive discussions.
While there are some companies which offer certain features similar to those embedded in our solutions, and others with whom we compete in certain tactical use cases, we believe that no single competitor delivers the same automated outcomes on the number of platforms and applications that we support. However, we do face competition from a select group of software vendors that provide standalone solutions similar to those features embedded in our comprehensive platform, particularly in the markets we serve. We also face direct competition in specific use cases, specifically DSPM, data discovery and classification, privacy, data migration, data subject access requests and Active Directory security. As we continue to augment our functionality with AI security, insider threat detection and user behavior analytics and as we expand our classification capabilities to better serve compliance needs, such as General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA") and other data privacy laws, we may face increased perceived and real competition from other security and classification technologies. Our growing presence in the cloud data security market and our broader product coverage are also placing us in more direct competition with companies focused on discovery and classification. As customer requirements evolve and new technologies emerge, we face heightened competition from companies—both established and emerging—that develop solutions targeting the enterprise data market.
In particular, if a more established company were to target our market, we may face significant competition. They may have competitive advantages, such as greater name recognition, larger sales, marketing, research and acquisition resources, access to larger customer bases and channel partners, a longer operating history and lower labor and development costs, which may enable them to respond more quickly to new or emerging technologies and changes in customer requirements or devote greater resources to the development, promotion and sale of their products than we do. Increased competition could result in us failing to attract customers or maintain licenses at the same rate. It could also lead to price cuts, alternative pricing structures or the introduction of products available for free or a nominal price, reduced gross margins, longer sales cycles, lower renewal rates and loss of market share.
In addition, our current or prospective channel partners may establish cooperative relationships with future competitors. These relationships may allow future competitors to rapidly gain significant market share. These developments could also limit our ability to obtain revenues from existing and new customers.
Our ability to compete successfully in our market will also depend on a number of factors, including ease and speed of product deployment and use, the quality and reliability of our customer service and support, total cost of ownership, return on investment and brand recognition. Any failure by us to successfully address current or future competition in any one of these or other areas may reduce the demand for our products and adversely affect our business, results of operations and financial condition.
Lastly, at times, we engage in discussions and collaborations with other technology companies, including companies that offer security‐related products, regarding potential partnerships, integrations, or commercial relationships. While these discussions are intended to expand our ecosystem and market reach, they may involve the sharing of information about our products, strategy, and potential future development plans. Even where appropriate confidentiality measures are in place, these counterparties may use knowledge gained through such interactions to inform their own product development, roadmap decisions, or competitive strategies, including in ways that increase competition with us. As a result, our efforts to pursue partnerships could accelerate the development of competing offerings or otherwise adversely affect our competitive position.
We are subject to a number of legal requirements, contractual obligations and industry standards regarding security, data protection and privacy, and any failure to comply with these requirements, obligations or standards could have an adverse effect on our reputation, business, financial condition and operating results.
Privacy and data protection laws in the United States and internationally are rapidly evolving and remain subject to uncertainty. U.S. federal, state, and foreign authorities have enacted, and continue to consider, laws governing the collection, use,
11
disclosure, storage, and security of personal information. In the United States, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) impose significant obligations on businesses and grant consumers enhanced rights, such as the ability to opt out of certain sales of personal information. In 2025, additional comprehensive privacy laws took effect in Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, and Maryland, and further state privacy laws are scheduled to take effect in 2026, including in Indiana, Kentucky, and Rhode Island. Collectively, these frameworks generally require detailed disclosures, honoring consumer rights, and implementing robust data protection safeguards, and they expand the patchwork of compliance obligations across the United States.
Internationally, nearly every jurisdiction where we operate has established its own privacy and data security framework, often more restrictive than U.S. laws, governing the collection, use, storage, disclosure, and protection of data that identifies or could identify an individual (for example, names, email addresses, and, in some jurisdictions, IP addresses). The European Union’s General Data Protection Regulation (GDPR) imposes stringent obligations, and the United Kingdom has implemented similar legislation. In 2025, the United Kingdom enacted the Data (Use and Access) Act 2025, which amends the UK GDPR regime, including targeted changes related to automated decision‐making, cookies, recognized legitimate interests, regulator powers, and international transfers. In December 2025, the European Commission renewed its UK adequacy decisions (subject to review), supporting continued data flows between the UK and the EEA.
Cross‐border data transfers from the European Economic Area and the UK to the United States rely on mechanisms such as standard contractual clauses, the UK’s International Data Transfer Agreement (or Addendum), and the EU–U.S. Data Privacy Framework (including its UK extension). In September 2025, the European General Court upheld the validity of the EU–U.S. Data Privacy Framework, providing near‐term stability for organizations that self‐certify to the framework; however, challenges and appeals remain possible, and the transfer landscape continues to evolve. Compliance with GDPR, the UK regime as amended by the Data (Use and Access) Act 2025, and other international privacy laws may require significant operational changes and costs, while non‐compliance could result in substantial fines, litigation, and reputational harm, adversely affecting our business, financial condition, and results of operations.
Certain U.S. and international laws also require companies to notify individuals of security breaches involving personal information, whether caused by us or our service providers. Despite contractual protections, a breach could harm our reputation, erode customer trust, reduce sales, lead to customer loss, and expose us to liability or significant remediation costs. Beyond government regulation, privacy advocates and industry groups may introduce new self‐regulatory standards that could apply to us. We also anticipate continued legislative and regulatory developments in privacy, data protection, and information security, the impact of which remains uncertain. New laws, amendments, or reinterpretations of existing requirements—as well as evolving industry standards and contractual obligations—may increase compliance costs and restrict our operations. Because interpretation and enforcement of these requirements are uncertain, they may conflict with our current practices or product features. If so, we could face fines, litigation, or be required to make fundamental changes to our business or software, which may not be commercially feasible and could limit our ability to innovate. Failure to adequately address privacy concerns—whether valid or perceived—or to comply with applicable requirements could result in additional costs, liability, reputational harm, inhibited sales, and other adverse effects on our business.
Furthermore, compliance costs and other burdens imposed by privacy and data protection laws applicable to our customers may increase the cost of using our products, limit their adoption, and reduce overall demand. In addition, privacy and personal information security concerns—whether well‐founded or not—may discourage market acceptance of our products, particularly in certain industries and international markets.
Risks Related to Our Operations
Security breaches, cyberattacks or other cyber-risks of our IT and production systems could expose us to significant liability and cause our business and reputation to suffer and harm our competitive position.
Our corporate infrastructure stores and processes our sensitive, proprietary and other confidential information (including as related to financial, technology, employees, marketing, sales, etc.) which is used on a daily basis in our operations. In addition, our software involves transmission and processing of our customers’ confidential, proprietary and sensitive information. We have legal and contractual obligations to protect the confidentiality and appropriate use of customer data. As a leader in the cyber industry, we may be an attractive target for cyber attackers or other data thieves.
High-profile cyberattacks and security breaches have increased in recent years, with the potential for such acts heightened as a result of the number of employees working remotely due to many companies adopting a hybrid working model. Security industry experts and government officials have warned about the risks of hackers and cyberattacks targeting IT products and
12
enterprise infrastructure. Because techniques used to obtain unauthorized access or to sabotage systems change frequently and often are not recognized until launched against a specific target, we may be unable to anticipate these techniques or to implement adequate preventative measures. As we continue to increase our client base and expand our brand, we may become more of a target for third parties seeking to compromise our security systems and we anticipate that hacking attempts and cyberattacks will increase in the future. We may not always be successful in preventing or repelling unauthorized access to our systems. We also may face delays in our ability to identify or otherwise respond to any cybersecurity incident or any other breach. Additionally, we use third-party service providers to provide some services to us that involve the cloud hosting, storage or transmission of data, such as SaaS, cloud computing, and internet infrastructure and bandwidth, and they face various cybersecurity threats and also may suffer cybersecurity incidents or other security breaches. Despite our security measures, our IT and infrastructure may be vulnerable to attacks. Threats to IT security can take a variety of forms. Individual and groups of hackers and sophisticated organizations, including state-sponsored organizations or nation-states, continuously undertake attacks that pose threats to our customers and our IT. These actors may use a wide variety of methods, which may include developing and deploying malicious software or exploiting vulnerabilities in hardware, software, or other infrastructure in order to attack our products and services or gain access to our networks, using social engineering techniques to induce our employees, users, partners, or customers to disclose passwords or other sensitive information or take other actions to gain access to our data or our users’ or customers’ data, or acting in a coordinated manner to launch distributed denial of service or other coordinated attacks. Inadequate account security practices may also result in unauthorized access to confidential and/or sensitive data or loss of SaaS platform availability.
Security risks, including, but not limited to, unauthorized use or disclosure of customer data, loss of availability of our SaaS platform offering, cyberattack on our cloud providers, theft of proprietary information, theft of intellectual property, theft of internal employee’s PII/PHI information, theft of financial data and financial reports, loss or corruption of customer data and computer hacking attacks or other cyberattacks, could require us to expend significant capital and other resources to alleviate the problem and to improve technologies, may impair our ability to provide services to our customers and protect the privacy of their data, may result in product development delays, may compromise confidential or technical business information, may harm our competitive position, may result in theft or misuse of our intellectual property or other assets and could expose us to substantial litigation expenses and damages, indemnity and other contractual obligations, government fines and penalties, mitigation expenses, costs for remediation and incentives offered to affected parties, including customers, other business partners and employees, in an effort to maintain business relationships after a breach or other incident, and other liabilities. We are continuously working to improve our IT systems, together with creating security boundaries around our critical and sensitive assets. We provide advanced security awareness training to our employees and contractors that focuses on various aspects of the cybersecurity world. All of these steps are taken in order to mitigate the risk of attack and to ensure our readiness to responsibly handle any security violation or attack. If an actual or perceived breach of our security occurs, the market perception of the effectiveness of our security measures and our products could be harmed, we could lose potential sales and existing customers, our ability to operate our business could be impaired, we may incur significant liabilities, we could suffer harm to our reputation and competitive position, and our operating results could be negatively impacted.
The expansion of cloud-delivered services introduces a number of risks and uncertainties, which could adversely affect our business, results of operations and financial condition.
The launch of our cloud offerings that allow customers to use hosted software required, and any future expansion of our cloud-delivered services may require, a considerable investment in resources, including technical, financial, legal, sales, information technology and operation systems. Additionally, market acceptance of such offerings is affected by a variety of factors, including but not limited to: security, reliability, scalability, customization, performance, current license terms, customer preference, customer concerns with entrusting a third-party to store and manage their data, public concerns regarding privacy and the enactment of restrictive laws or regulations. It is possible that demand for our cloud offerings may not continue to be as strong as it has been to date. Moreover, expansion of our cloud offerings may cause a decline in revenue of our existing products and services that is not offset by revenue from the new products or services. For example, customers may delay making purchases of products and services to permit them to make a more thorough evaluation of these new products and services or until industry and marketplace reviews become widely available. We may be unable to realize the benefits of our investments or the resources we have committed to expanding our cloud-delivered services.
An increasing number of jurisdictions are imposing data localization laws, which require personal information, or certain subcategories of personal information, to be stored in the jurisdiction of origin. These regulations may deter customers from using cloud-based services, and may inhibit our ability to expand into certain markets or prohibit us from continuing to offer services in those markets without significant additional costs.
Our hosted offerings rely upon third-party providers to supply data center space, equipment maintenance and other colocation services and rely upon the ability of those providers to maintain continuous service availability and protect customer data on
13
their services. Customers of our cloud-based offerings need to be able to access our platform at any time, without interruption or degradation of performance, and we provide them with service level commitments with respect to uptime. Third-party cloud providers run their own platforms that we access, and we are, therefore, vulnerable to their service interruptions. Although we have entered into various agreements for the lease of data center space, equipment maintenance and other services, third parties could fail to live up to their contractual obligations. The failure of a third-party provider to prevent service disruptions, data losses or security breaches may require us to issue credits or refunds or indemnify or otherwise be liable to customers or third parties for damages that may occur, and contractual provisions with our third-party providers and public cloud partners may limit our recourse against the third-party provider or public cloud partner responsible for such failure. Additionally, if these third-party providers fail to deliver on their obligations, our reputation could be damaged, our customers could lose confidence in us, and our ability to maintain and expand our hosted offerings would be impaired. Lastly, our cloud product offering and pricing is new and hosting and other costs may be more expensive to us than anticipated.
We may not be able to predict renewal or conversion rates and their impact on our future revenues and operating results.
Although our solutions are designed to increase the number of customers that purchase our products and the number of products purchased by existing and new customers to create a recurring revenue stream that increases and is more predictable over time, our customers are not required to renew their subscriptions for our solutions and they may elect not to renew when, or as we expect, or they may elect to reduce the scope of their original purchases or delay their purchase. We cannot accurately predict renewal or conversion rates given our varied customer base of enterprise and small and medium size business customers and the number of multiyear contracts. Customer renewal or conversion rates may decline or fluctuate due to a number of factors, including offering pricing, competitive offerings, customer satisfaction and reductions in customer spending levels or customer activity due to economic downturns, the adverse impact of import tariffs, inflation or other market uncertainty. If our customers do not renew their contracts when or as we expect, or if they choose to renew for fewer products or renew for shorter contract lengths or if they renew on less favorable terms, our revenues and earnings may decline, and our business may suffer. Further, we plan to end-of-life our self-hosted business as of December 31, 2026, which we expect to increase the uncertainty with our remaining term license customers going forward. This may result in a decline in revenues and cause revenues to be more difficult to predict for a period of time. We may occasionally inform customers that products or services will be reaching their end-of-life and will no longer be supported or receive updates or security patches. Failure to effectively manage this process could lead to customer dissatisfaction and contractual liabilities, which could adversely affect our business and operating results.
Our quarterly results of operations have fluctuated and may fluctuate significantly due to variability in our revenues which could adversely impact our stock price.
Our revenues and other results of operations have fluctuated from quarter to quarter in the past and could continue to fluctuate in the future. Historically, the fluctuation was partially due to the front-loaded revenue recognition nature of our business. Additionally, the Company has converted the significant majority of its customers to a SaaS delivery model that recognizes revenue ratably and not up front. However, there are still a number of term license subscriptions remaining to be converted and, as a result, we may present reduced revenues as compared to prior periods, and comparing our revenues and results of operations on a period-to-period basis may not be meaningful and should not be relied on for any particular period. Our revenues depend in part on the conversion of enterprises that have undergone risk assessments into paying customers; however, these risk assessments may not be converted at the same historical rates or at all. At the same time, the majority of our sales are typically made during the last three weeks of every quarter. We may fail to meet market expectations for that quarter if we are unable to close the number of transactions that we expect during this short period and closings are deferred to a subsequent quarter or not closed at all. The closing of a large transaction in a particular quarter may raise our revenues in that quarter and thereby make it more difficult for us to meet market expectations in subsequent quarters and our failure to close a large transaction in a particular quarter or any renewals may adversely impact our revenues in that quarter. In addition, our sales cycle from initial contact to delivery of and payment for the software license generally becomes longer and less predictable with respect to large transactions and often involves multiple meetings or consultations at a substantial cost and time commitment to us. Further, we have been focusing on the conversion of our current OPS customers to our SaaS platform and the sales cycle of such conversions can and may continue to take longer than the acquisition of new customers. Moreover, we base our current and future expense levels on our revenue forecasts and operating plans, and our expenses are relatively fixed in the short-term. Accordingly, we would likely not be able to reduce our costs sufficiently to compensate for an unexpected shortfall in revenues and even a relatively small decrease in revenues could disproportionately and adversely affect our financial results for that quarter.
The variability and unpredictability of these and other factors, many of which are outside of our control, could result in our failing to meet or exceed financial expectations for a given period and may cause the price of our common stock to decline substantially.
14
If we do not successfully optimize and manage our predominantly SaaS‐based business model, or if the remaining transition away from self‐hosted products fails to progress as expected, our results of operations could be negatively impacted.
As our business is now substantially SaaS‐focused, our future performance depends heavily on our ability to effectively operate, scale, and continuously improve our SaaS offerings. Although customer adoption of our SaaS solutions has increased significantly, uncertainties remain regarding whether and when our remaining self‐hosted customers will convert and the degree to which our SaaS offerings will continue to meet evolving customer expectations for functionality, reliability, security, and value.
This SaaS strategy continues to pose a number of risks, including the following:
•our revenues and operating margins may fluctuate more than anticipated as our business model relies increasingly on subscription revenues, which may be more sensitive to renewal rates, customer usage patterns, and macroeconomic conditions;
•the remaining self‐hosted customer base may convert more slowly than projected, or certain customers may choose not to transition at all, which could reduce expected growth or require continuing investment in legacy offerings;
•customers may continue to express concerns related to long‐term pricing, data access, data residency, or vendor lock‐in, which could affect new subscription sales or renewal rates;
•we may be unsuccessful in maintaining or adjusting our pricing models, product tiers, or packaging strategies, or such changes may adversely affect customer adoption, demand, or earnings;
•if our customers do not renew their subscriptions, reduce usage, or delay renewal decisions, our revenues may decline and our business and operating results may suffer;
•our hosting, infrastructure, or third‐party cloud costs may exceed forecasts, or our SaaS platform may not scale or operate as efficiently as anticipated, negatively affecting gross margins;
•we may incur higher than expected sales compensation expenses if the pace of remaining conversions or new SaaS sales varies from forecasted levels; and
•our sales force and customer facing teams may face ongoing challenges with selling and supporting SaaS solutions, which may lead to productivity issues, increased turnover, or the need for additional training and investment.
If we fail to effectively manage or optimize our SaaS‐focused operating model, or if customer adoption, retention, or conversion does not continue at expected levels, our revenues, margins, and overall results of operations could suffer.
Our results of operations could be negatively affected by foreign currency exposures.
Our functional and reporting currency is the U.S. dollar. While the majority of our revenues and expenses are denominated in U.S. dollars, we also generate revenues and incur operating expenses in foreign currencies, primarily the Euro, British Pound, Canadian dollar, Australian dollar, Singapore dollar and New Israeli Shekel. As a result, our operating results are exposed to movements in foreign currency exchange rates.
Exchange rates between the U.S. dollar and foreign currencies have been volatile in recent years. In addition, based on our current geographic revenue mix, cost structure and expected growth profile, even if foreign exchange rates remain at or near current levels, we expect to experience foreign currency‐related headwinds in future periods, which could adversely affect our reported revenues, operating margins and results of operations.
A strengthening of the U.S. dollar relative to foreign currencies may increase the local‐currency cost of our software and renewals for customers outside the United States and may adversely affect demand, pricing, renewal rates and revenue growth. At the same time, a weakening of the U.S. dollar against currencies in which we incur expenses would increase the U.S. dollar equivalent of those costs, including employee compensation and other operating expenses at our non‐U.S. locations, which could negatively impact operating margins and increase compensation pressure in those regions.
We use foreign currency forward contracts to hedge a portion of our exposure to foreign‐currency‐denominated revenues and operating expenses. These hedging activities may not fully offset the impact of current or future exchange rate movements and involve costs and risks, including cash requirements, management time and resources, external implementation costs, potential accounting impacts and the risk of losses resulting from volatility in foreign currency markets or differences between the exchange rates of the currencies being hedged. As a result, our results of operations and financial condition may be adversely affected by foreign exchange rate movements even if exchange rates remain stable.
We have been growing and expect to continue to invest in our growth for the foreseeable future. If we fail to manage this growth effectively, our business and results of operations will be adversely affected.
15
We intend to continue to grow our business and plan to continue to hire new sales employees either for expansion or replacement of existing sales personnel. If we cannot adequately and timely hire new employees and if we fail to adequately train these new employees, including our sales force, engineers and customer support staff, our sales may not grow at the rates we project and/or our sales productivity might suffer, our customers might decide not to renew or reduce the scope of their original purchases, or our customers may lose confidence in the knowledge and capability of our employees or products. We must successfully manage our growth to achieve our objectives. Although our business has experienced significant growth in the past, we may not be able to continue to grow at the same rate, or at all.
Our ability to effectively manage any significant growth of our business will depend on a number of factors, including our ability to do the following:
• satisfy existing customers and attract new customers;
• adequately and timely recruit, train, motivate and integrate new employees, including our sales force and engineers, while retaining existing employees, maintaining the beneficial aspects of our corporate culture and effectively executing our business plan;
• successfully introduce new products and enhancements;
• effectively manage existing channel partnerships and expand to new ones;
• improve our key business applications and processes to support our business needs;
• enhance information and communication systems to ensure that our employees and offices around the world are well-coordinated and can effectively communicate with each other and our growing customer base;
• enhance our internal controls to ensure timely and accurate reporting of all of our operations and financial results;
• protect and further develop our strategic assets, including our intellectual property rights;
• continue to capitalize on the transition to a SaaS delivery model; and
• successfully manage and integrate any future acquisitions of businesses, including without limitation, the amount and timing of expenses and potential future charges for impairment of goodwill from acquired companies.
These activities will require significant investments and allocation of valuable management and employee resources, and our growth will continue to place significant demands on our management and our operational and financial infrastructure. We may not be able to grow our business in an efficient or timely manner, or at all. Moreover, if we do not effectively manage the growth of our business and operations, the quality of our software could suffer, which could negatively affect our brand, results of operations and overall business.
We have a limited operating history at our current scale, which makes it difficult to evaluate and predict our future prospects and may increase the risk that we will not be successful.
We have a relatively short history operating our business at its current scale. For example, we have increased the number of our employees and have expanded our operations and product offerings. This limits our ability to forecast our future operating results and subjects us to a number of uncertainties, including our ability to plan for and model future growth. We have encountered and will continue to encounter risks and uncertainties frequently experienced by growing companies in new markets that may not develop as expected. Because we depend in part on the market’s acceptance of our products, it is difficult to evaluate trends that may affect our business. If our assumptions regarding these trends and uncertainties, which we use to plan our business, are incorrect or change in reaction to changes in our markets, or if we do not address these risks successfully, our operating and financial results could differ materially from our expectations and our business could suffer. Moreover, although we have experienced significant growth historically, we may not continue to grow as quickly, or at all, in the future.
Our future success will depend in large part on our ability to, among other things:
• convert our remaining self-hosted customers to our SaaS delivery model;
•manage our introduction of cloud-based solutions;
• maintain and expand our business, including our customer base and operations, to support our growth, both domestically and internationally;
• develop new products and services and bring products and services in beta to market;
• renew customer agreements and sell additional products to existing customers;
• maintain high customer satisfaction and ensure quality and timely releases of our products and product enhancements;
• increase market awareness of our products and enhance our brand;
• maintain compliance with applicable governmental regulations and other legal obligations, including those related to intellectual property, international sales and taxation;
• hire, integrate, train and retain skilled talent, including members of our sales force and engineers; and
16
• our ability to successfully manage and integrate any acquisitions of businesses.
If we fail to address the risks and difficulties that we face, including those associated with the challenges listed above as well as those described elsewhere in this “Risk Factors” section, our business will be adversely affected, and our results of operations will suffer.
If we are unable to attract new customers and expand sales to existing customers, both domestically and internationally, our growth could be slower than we expect, and our business may be harmed.
Our success will depend, in part, on our ability to support new and existing customer growth and maintain customer satisfaction. Our sales and marketing teams host in-person events and engage with customers online and through other communications channels, including virtual meetings. Our sales and marketing teams may not be as successful or effective in building relationships. If we cannot provide the tools and training to our teams to efficiently do their jobs and satisfy customer demands, we may not be able to achieve anticipated revenue growth as quickly as expected.
Our future growth depends upon expanding sales of our products to existing customers and their organizations and receiving renewals. If our customers do not purchase additional products or capabilities, our revenues may grow more slowly than expected, may not grow at all or may decline. Our efforts may not result in increased sales to existing customers (“upsells”) and additional revenues. If our efforts to upsell to our customers are not successful, our business would suffer.
Our future growth also depends in part upon increasing our customer base, particularly those customers with potentially high customer lifetime values. Our ability to achieve significant growth in revenues in the future will depend, in large part, upon the effectiveness of our sales and marketing efforts, both domestically and internationally, and our ability to attract new customers. Our ability to attract new customers may be adversely affected by newly enacted laws that may prohibit certain sales and marketing activities, such as legislation passed in the State of New York, pursuant to which unsolicited telemarketing sales calls are prohibited. If we fail to attract new customers and maintain and expand those customer relationships, our revenues may be adversely affected, and our business will be harmed.
We have a history of losses, and we may not be profitable in the future.
We have incurred net losses in each year since our inception, including a net loss of $129.3 million, $95.8 million and $100.9 million in each of the years ended December 31, 2025, 2024 and 2023, respectively. Because the market for our software is rapidly evolving and has still not yet reached widespread adoption, it is difficult for us to predict our future results of operations. We expect our operating expenses to increase over the next several years as we hire additional personnel, expand and improve the effectiveness of our distribution channels, and continue to develop features and applications for our software.
If we are unable to maintain successful relationships with our channel partners, our business could be adversely affected.
We rely on channel partners, such as distribution partners and resellers, to sell the Varonis Data Security Platform. In 2024 and 2025, our channel partners fulfilled substantially all of our sales, and we expect that sales to channel partners will continue to account for substantially all of our revenues for the foreseeable future. Our ability to achieve revenue growth in the future will depend in part on our success in maintaining successful relationships with our channel partners.
Our agreements with our channel partners are generally non-exclusive, meaning our channel partners may offer customers the products of several different companies. If our channel partners do not effectively market and sell our software, choose to use greater efforts to market and sell their own products or those of others, or fail to meet the needs of our customers, our ability to grow our business, sell our software and maintain our reputation may be adversely affected. Our contracts with our channel partners generally allow them to terminate their agreements for any reason upon 30 days’ notice. A termination of the agreement has no effect on orders already placed. The loss of a substantial number of our channel partners, our possible inability to replace them, or the failure to recruit additional channel partners could materially and adversely affect our results of operations. If we are unable to maintain our relationships with these channel partners, our business, results of operations, financial condition or cash flows could be adversely affected.
Finally, even if we are successful, our relationships with channel partners may not result in greater customer usage of our products or increased revenue.
Our long-term growth depends, in part, on being able to continue to expand internationally on a profitable basis, which subjects us to risks associated with conducting international operations.
Historically, we have generated the majority of our revenues from customers in the United States. For the years ended December 31, 2025 and 2024, approximately 71% and 73%, respectively, of our total revenues were derived from sales in the
17
United States. Nevertheless, we have operations across the globe, and we plan to continue to expand our international operations as part of our long-term growth strategy. The further expansion of our international operations will subject us to a variety of risks and challenges, including:
• sales and customer service challenges associated with operating in different countries;
• increased management travel, infrastructure and legal compliance costs associated with having multiple international operations;
• difficulties in receiving payments from different geographies, including difficulties associated with currency fluctuations, payment cycles, transfer of funds or collecting accounts receivable, especially in emerging markets;
• variations in economic or political conditions between each country or region;
• economic uncertainty around the world and adverse effects arising from economic interdependencies across countries and regions;
• uncertainty around a potential reverse or renegotiation of international trade agreements and partnerships;
• compliance with foreign laws and regulations and the risks and costs of non-compliance with such laws and regulations;
• ability to hire, retain and train local employees and the ability to comply with foreign labor laws and local labor requirements, such as representations by an internal labor committee in France which is affiliated with an external trade union and the applicability of collective bargaining arrangements at the national level in certain European countries;
• compliance with laws and regulations for foreign operations, including the U.S. Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.K. Bribery Act of 2010 (the “UK Bribery Act”), import and export control laws, tariffs, trade barriers, economic sanctions and other regulatory or contractual limitations on our ability to sell our software in certain foreign markets, and the risks and costs of non-compliance;
• heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of financial statements and irregularities in financial statements;
• reduced protection for intellectual property rights in certain countries and practical difficulties and costs of enforcing rights abroad; and
• compliance with the laws of numerous foreign taxing jurisdictions and overlapping of different tax regimes and digital tax imposed on our operations in foreign taxing jurisdictions.
Any of these risks could adversely affect our international operations, reduce our revenues from outside the United States or increase our operating costs, adversely affecting our business, results of operations and financial condition and growth prospects. There can be no assurance that all of our employees, independent contractors and channel partners will comply with the formal policies we have and will implement, or applicable laws and regulations. Violations of laws or key control policies by our employees, independent contractors and channel partners could result in delays in revenue recognition, financial reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our software and services and could have a material adverse effect on our business and results of operations.
We are subject to governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
We incorporate certain encryption technology into certain of our products and, as a result, are required to comply with U.S. export control laws and regulations, including the Export Administration Regulations administered by the U.S. Department of Commerce’s Bureau of Industry and Security (“BIS”). We are also subject to Israeli export control laws on encryption technology. These export control laws and regulations prohibit, restrict, or regulate our ability to, directly or indirectly, export, re-export, or transfer certain products to certain countries and territories, entities, and individuals for certain end uses. If the applicable U.S. or Israeli legal requirements regarding the export of encryption technology were to change or if we change the encryption means in our products, we may (i) be unable to export our products, (ii) need to apply for new licenses or (iii) be unable to rely on certain license exceptions. Furthermore, various other countries regulate the import of certain encryption technology, including import permitting and licensing requirements, and have enacted laws that could limit our ability to distribute our products or could limit our customers’ ability to implement our products in those countries.
We are also subject to U.S. and Israeli economic sanctions laws, which prohibit the shipment of certain products to embargoed or sanctioned countries, sanctioned governments and sanctioned persons. Like with export controls, we take precautions to prevent our products from being provided in violation of these laws, including requiring our business partners to commit to compliance through contractual undertakings. However, if our business partners were to provide our products to certain countries, governments, or sanctioned persons in violation of these laws, such provision could have negative consequences, including government investigations, penalties and reputational harm.
18
Any change in export or import regulations, economic sanctions or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons or technologies targeted by such regulations, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential customers with international operations. Moreover, any new export or import restrictions, new legislation or shifting approaches in the enforcement or scope of existing regulations, or in the countries, persons or technologies targeted by such regulations, could result in decreased use of our products. Any decreased use of our products or limitation on our ability to export or sell our products would likely adversely affect our business, financial condition and results of operations.
Our business in countries with a history of corruption and transactions with foreign governments increase the risks associated with our international activities.
As we operate and sell internationally, we are subject to the FCPA, the UK Bribery Act and other laws that prohibit improper payments or offers of payments to foreign governments and their officials and political parties for the purpose of obtaining or retaining business. We have operations, deal with and make sales to governmental customers in countries known to experience corruption, particularly certain emerging countries in Eastern Europe, South and Central America, East Asia, Africa and the Middle East. Our activities in these countries create the risk of unauthorized payments or offers of payments by one of our employees, consultants, channel partners or sales agents that could be in violation of various anti-corruption laws, even though these parties may not be under our control. While we have implemented safeguards to prevent these practices by our employees, consultants, channel partners and sales agents, our existing safeguards and any future improvements may prove to be less than effective, and our employees, consultants, channel partners or sales agents may engage in conduct for which we might be held responsible. Violations of the FCPA or other anti-corruption laws may result in severe criminal or civil sanctions, including suspension or debarment from government contracting, and we may be subject to other liabilities, which could negatively affect our business, operating results and financial condition.
Acquisitions could disrupt our business and adversely affect our results of operations, financial condition and cash flows.
As we continue to pursue business opportunities, we may make acquisitions that could be material to our business, results of operations, financial condition and cash flows. Acquisitions involve many risks, including the following:
• an acquisition may negatively affect our results of operations, financial condition or cash flows because it may require us to incur charges or assume substantial debt or other liabilities, may cause adverse tax consequences or unfavorable accounting treatment, including potential write-downs of deferred revenues, may expose us to claims and disputes by third parties, including intellectual property claims and disputes, or may not generate sufficient financial return to offset additional costs and expenses related to the acquisition;
• we may encounter difficulties or unforeseen expenditures in integrating the business, technologies, products, personnel or operations of any company that we acquire, particularly if key personnel of the acquired company decide not to work for us;
• an acquisition may disrupt our ongoing business, divert resources, increase our expenses and distract our management;
• an acquisition may result in a delay or reduction of customer purchases for both us and the company we acquired due to customer uncertainty about continuity and effectiveness of service from either company;
• we may encounter difficulties in, or may be unable to, successfully sell any acquired products;
• an acquisition may involve the entry into geographic or business markets in which we have little or no prior experience or where competitors have stronger market positions;
• challenges inherent in effectively managing an increased number of employees in diverse locations;
• the potential strain on our financial and managerial controls and reporting systems and procedures;
• potential known and unknown liabilities or deficiencies associated with an acquired company that were not identified in advance;
• our use of cash to pay for acquisitions would limit other potential uses for our cash and affect our liquidity;
• if we incur debt to fund such acquisitions, such debt may subject us to material restrictions on our ability to conduct our business as well as financial maintenance covenants;
• the risk of impairment charges related to potential write-downs of acquired assets or goodwill in future acquisitions;
• to the extent that we issue a significant amount of equity or convertible debt securities in connection with future acquisitions, existing stockholders may be diluted and earnings per share may decrease; and
• managing the varying intellectual property protection strategies and other activities of an acquired company.
We may not succeed in addressing these or other risks or any other problems encountered in connection with the integration of any acquired business. Our ability as an organization to successfully acquire and integrate technologies or businesses is limited. The inability to successfully integrate the business, technologies, products, personnel or operations of any acquired business, or any significant delay in achieving integration, could have a material adverse effect on our business, results of operations, financial condition and cash flows.
19
We are exposed to collection and credit risks, which could impact our operating results.
Our trade receivables are subject to collection and credit risks. These agreements may include purchase commitments for multiple years of SaaS and term license subscriptions, which may be invoiced over multiple reporting periods increasing these risks. For example, our operating results may be impacted by significant bankruptcies among customers and resellers, which could negatively impact our revenues and cash flows. Although we have processes in place that are designed to monitor and mitigate these risks, we cannot guarantee these programs will be effective. If we are unable to adequately control these risks, our business, operating results and financial condition could be harmed.
Our business is highly dependent upon our brand recognition and reputation, and the failure to maintain or enhance our brand recognition or reputation may adversely affect our business.
We believe that enhancing the “Varonis” brand identity and maintaining our reputation in the IT industry is critical to our relationships with our customers and to our ability to attract new customers. Our brand recognition and reputation are dependent upon:
• our ability to continue to offer high quality, innovative and error- and bug-free products;
• our ability to maintain customer satisfaction with our products;
• our ability to be responsive to customer concerns and provide high quality customer support, training and professional services;
• our marketing efforts;
• any misuse or perceived misuse of our products;
• positive or negative publicity;
• our ability to prevent or quickly react to any cyberattack on our IT systems or security breach of or related to our software;
• interruptions, delays or attacks on our website; and
• litigation or regulatory-related developments.
We may not be able to successfully promote our brand or maintain our reputation. In addition, independent industry analysts often provide reviews of our products, as well as other products available in the market, and perception of our product in the marketplace may be significantly influenced by these reviews. If these reviews are negative, or less positive than reviews about other products available in the market, our brand may be adversely affected. Furthermore, negative publicity relating to events or activities attributed to us, our employees, our channel partners or others associated with any of these parties, may tarnish our reputation and reduce the value of our brand. If we do not successfully enhance our brand and maintain our reputation, our business may not grow, we may have reduced pricing power relative to competitors with stronger brands, and we could lose customers or renewals, all of which would adversely affect our business, operations and financial results. Moreover, damage to our reputation and loss of brand equity may reduce demand for our products and have an adverse effect on our business, results of operations and financial condition. Any attempts to rebuild our reputation and restore the value of our brand may be costly and time consuming, and such efforts may not ultimately be successful.
Moreover, it may be difficult to enhance our brand and maintain our reputation in connection with sales to channel partners. Promoting our brand requires us to make significant expenditures, and we anticipate that the expenditures will increase as our market becomes more competitive, as we expand into new markets and geographies and as more sales are generated to our channel partners. To the extent that these activities yield increased revenues, these revenues may not offset the increased expenses we incur.
Our success depends in part on maintaining, converting to SaaS and increasing our sales to customers in the public sector.
We derive a portion of our revenues from contracts with federal, state, local and foreign governments and government-owned or -controlled entities (such as public health care bodies, educational institutions and utilities), which we refer to as the public sector herein. We believe that part of the success and growth of our business will continue to depend on our successful procurement of public sector contracts. Selling to public sector entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense without any assurance that our efforts will produce any sales. Government demand and payment for our products and services may be impacted by public sector budgetary cycles, or lack of, and funding authorizations, including in connection with an extended government shutdown, with funding reductions or delays adversely affecting public sector demand for our products and services. Factors that could impede our ability to maintain or increase the amount of revenues derived from public sector contracts include:
• changes in public sector fiscal or contracting policies;
20
• decreases or elimination of available public sector funding;
• non-compliance with or an inability to attain the proper certification to conduct business in the public sector;
• changes in public sector programs or applicable requirements;
• the adoption of new laws or regulations or changes to existing laws or regulations;
• potential delays or changes in the public sector appropriations or other funding authorization processes;
• the requirement of contractual terms that are unfavorable to us, such as most-favored-nation pricing provisions; and
• delays in the payment of our invoices by public sector payment offices.
In addition, we must comply with laws and regulations relating to public sector contracting, which affect how we and our channel partners do business in both the United States and abroad. These laws and regulations may impose added costs on our business, and failure to comply with these or other applicable regulations and requirements, including non-compliance in the past, could lead to claims for damages from our channel partners, penalties, termination of contracts, and temporary suspension or permanent debarment from public sector contracting. Moreover, governments may investigate and audit government contractors’ administrative processes, and any unfavorable audit could result in the government refusing to continue buying our products, which would adversely impact our revenue and results of operations, or institute fines or civil or criminal liability if the audit uncovers improper or illegal activities.
Furthermore, on January 20, 2025, President Donald J. Trump announced an executive order establishing the “Department of Government Efficiency” to maximize government efficiency and productivity. Pressures on and uncertainty surrounding the U.S. federal government’s budget and potential changes in budgetary priorities, could adversely affect the funding for individual programs and delay purchasing decisions by our customers.
The occurrence of any of the foregoing could cause public sector customers to delay or refrain from purchasing licenses of our software in the future or otherwise have an adverse effect on our business, operations and financial results.
Risks Related to Human Capital
Talent acquisition and retention challenges could adversely affect our growth and operational performance.
Our ability to sustain growth and execute our strategy depends heavily on attracting, retaining and scaling a highly productive workforce, particularly in sales, marketing and research and development. As we continue to expand our platform, the complexity of our sales process has increased, requiring a more consultative and technically skilled sales force. This shift has introduced new challenges in hiring and onboarding qualified personnel, especially in competitive markets. We face intense competition for top talent, particularly in regions like Israel where we maintain a significant research and development presence. Recruiting individuals with the right expertise, whether for new geographies, specialized sales roles, or advanced research and development positions is increasingly difficult. Remote hiring and training, high attrition rates and the time required to ramp new hires (which can take up to 12 months for sales personnel to operate at a level that meets our expectations) further complicate our ability to scale effectively. Our growth also depends on retaining key employees and preserving our corporate culture. Any inability to attract or retain skilled personnel, including key managers, could hinder our ability to innovate, deliver new products and compete effectively. Additionally, equity compensation is a critical component of our talent strategy. A decline in our stock price or changes to our equity programs could reduce the attractiveness of our compensation packages, making it harder to recruit and retain top talent. If we fail to maintain or improve the productivity of our teams, or if we are unable to hire and integrate new personnel efficiently, our ability to meet growth targets, expand into new markets and serve our customers effectively could be materially impacted.
We are dependent on the continued services and performance of our co-founder, Chief Executive Officer and President, the loss of whom could adversely affect our business.
Much of our future performance depends on the continued services and continuing contributions of our co-founder, Chief Executive Officer and President, Yakov Faitelson, to successfully manage our company, to execute on our business plan and to identify and pursue new opportunities and product innovations. The loss of Mr. Faitelson’s services could significantly delay or prevent the achievement of our development and strategic objectives and adversely affect our business.
Risks Related to our Technology, Products, Services and Intellectual Property
Our failure to continually enhance and improve our technology could adversely affect sales of our products.
The market is characterized by the exponential growth in enterprise data, rapid technological advances, changes in customer requirements, including customer requirements driven by changes to legal, regulatory and self-regulatory compliance mandates,
21
frequent new product introductions and enhancements and evolving industry standards in computer hardware and software technology. As a result, we must continually change and improve our products in response to changes in operating systems, application software, computer and communications hardware, networking software, data center architectures, programming tools, computer language technology and various regulations. Moreover, the technology in our products is especially complex because it needs to effectively identify and respond to a user’s data retention, security and governance needs, while minimizing the impact on database and file system performance. Our products must also successfully interoperate with products from other vendors.
While we extend our technological capabilities though innovation and strategic transactions, including our recently announced MDDR, DAM, email security and cloud-based solutions, we cannot guarantee that we will be able to anticipate future market needs and opportunities or be able to extend our technological expertise and develop new products or expand the functionality of our current products in a timely manner or at all. Even if we are able to anticipate, develop and introduce new products and expand the functionality of our current products, there can be no assurance that enhancements or new products will achieve widespread market acceptance.
Our product enhancements or new products could fail to attain sufficient market acceptance for many reasons, including:
• failure to accurately predict market demand in terms of product functionality and to supply products that meet this demand in a timely fashion;
• inability to interoperate effectively with the database technologies and file systems of prospective customers;
• defects, errors or failures;
• negative publicity or customer complaints about performance or effectiveness; and
• poor business conditions, causing customers to delay IT purchases.
If we fail to anticipate market requirements or stay abreast of technological changes, we may be unable to successfully introduce new products, expand the functionality of our current products or convince our customers and potential customers of the value of our solutions in light of new technologies. In addition, it is possible that our product innovations, including our recently announced MDDR, DAM, email security and cloud-based solutions, may not provide satisfactory results to our customers. Accordingly, our business, results of operations and financial condition could be materially and adversely affected.
If our technical support, customer success or professional services are not satisfactory to our customers, they may not renew their agreements or not buy additional products in the future, which could adversely affect our future results of operations.
Our business relies on our customers’ satisfaction with the technical support, customer success and professional services we provide to support our products. Our customers have no obligation to renew their agreements with us after the initial terms have expired. Our customers have an option to renew their agreements and, for us to maintain and improve our results of operations, it is important that our existing customers renew their agreements, if applicable, when the existing contract term expires. For example, our renewal rate for the years ended December 31, 2025, 2024 and 2023 continued to be over 90%.
If we fail to provide technical support services that are responsive, satisfy our customers’ expectations and resolve issues that they encounter with our products and services, then they may elect not to purchase or renew contracts and they may choose not to purchase additional products and services from us. Accordingly, our failure to provide satisfactory technical support, customer success or professional services could lead our customers not to renew their agreements with us or renew on terms less favorable to us, and therefore have a material and adverse effect on our business and results of operations.
Interruptions or performance problems, including associated with our website or support website or any caused by cyberattacks, may adversely affect our business.
Our continued growth depends in part on the ability of our existing and potential customers to quickly access our website and support website. Access to our support website is also imperative to our daily operations and interaction with customers, as it allows customers to download our software, fixes and patches, as well as open and respond to support tickets and register license keys for evaluation or production purposes. We have experienced, and may in the future experience, website disruptions, outages and other performance problems due to a variety of factors, including technical failures, cyberattacks, natural disasters, infrastructure changes, human or software errors, capacity constraints due to an overwhelming number of users accessing our website simultaneously and denial of service or fraud. In some instances, we may not be able to identify the cause or causes of these performance problems within an acceptable period of time. System failures or outages, including any potential disruptions due to a period of increased global demand on certain cloud-based systems or disruptions of our cloud-based solutions, could compromise our or our customer’s ability to perform day-to-day operations in a timely manner, which could negatively impact our business or delay our financial reporting. It may become increasingly difficult to maintain and improve the performance of our websites, especially during peak usage times and as our software becomes more complex and
22
our user traffic increases. If our websites are unavailable or if our users are unable to download our software, patches or fixes within a reasonable amount of time or at all, we may suffer reputational harm and our business would be negatively affected.
If our software is perceived as not being secure, customers may reduce the use of or stop using our software, and we may incur significant liabilities.
Our software involves the transmission of data between data stores, and between data stores and desktop and mobile computers, and will increasingly involve the storage of data. We have a legal and contractual obligation to protect the confidentiality and appropriate use of customer data. Any security breaches with respect to such data could result in the loss of this information, litigation, indemnity obligations and other liabilities. The security of our products and accompanied services is important in our customers’ decisions to purchase or use our products or services. Security threats are a significant challenge to companies like us whose business is providing technology products and services to others. While we have taken steps to protect the confidential information that we have access to, including confidential information we may obtain through our customer support services or customer usage of our products, we have no direct control over the substance of the content. Security measures might be breached as a result of third-party action, employee error, malfeasance or otherwise. We also incorporate open source software and other third-party software into our products. There may be vulnerabilities in open source software and third-party software that may make our products likely to be harmed by cyberattacks. Moreover, our products operate in conjunction with and are dependent on products and components across a broad ecosystem of third parties. If there is a security vulnerability in one of these components, and if there is a security exploit targeting it, such security vulnerability may adversely impact our product vulnerability and we could face increased costs, liability claims, reduced revenue, or harm to our reputation or competitive position. Because techniques used to obtain unauthorized access or sabotage systems change frequently and generally are not identified until they are launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures.
The limitations of liability in our contracts may not be enforceable or adequate or otherwise protect us from any such liabilities or damages with respect to any particular claim. While we maintain insurance coverage for some of the above events, the potential liabilities associated with these security breach events could exceed the insurance coverage we maintain.
We incorporate machine learning and AI solutions into parts of our platform, offerings, services and features, and these applications may become more important in our operations over time. AI technologies, including generative AI, are complex and rapidly evolving, and we face competition from other companies as well as an evolving regulatory landscape. Several jurisdictions around the globe, including Europe and the United States, have already proposed or enacted laws governing AI, and we may need to commit significant resources to maintain business practices that comply with the evolving regulatory landscape. Our competitors or other third parties may incorporate AI into their products more quickly and successfully than us, which could impair our ability to compete effectively and adversely affect our results of operations.
Any or all of these issues could tarnish our reputation, negatively impact our ability to attract new customers or sell additional products to our existing customers, cause existing customers to elect not to renew their agreements or subject us to third-party lawsuits, regulatory fines or other action or liability, thereby adversely affecting our results of operations.
Our use of open source software could negatively affect our ability to sell our software and subject us to possible litigation.
We use open source software and expect to continue to use open source software in the future. Some open source software licenses require users who distribute open source software as part of their own software product to publicly disclose all or part of the source code to such software product or to make available any derivative works of the open source code on unfavorable terms or at no cost. We may face ownership claims of third parties over, or seeking to enforce the license terms applicable to, such open source software, including by demanding the release of the open source software, derivative works or our proprietary source code that was developed using such software. These claims could also result in litigation, require us to purchase a costly license or require us to devote additional research and development resources to change our software, any of which would have a negative effect on our business and results of operations. In addition, if the license terms for the open source code change, we may be forced to re-engineer our software or incur additional costs. Some open source software may include generative AI software or other software that incorporates or relies on generative AI. The use of such software may expose us to risks as the intellectual property ownership and license rights, including copyright, of generative AI software and tools, has not been fully interpreted by U.S. courts or been fully addressed by federal or state regulation. Finally, while we implement policies and procedures, we cannot provide assurance that we have incorporated open source software into our own software in a manner that conforms with our current policies and procedures and we cannot assure that all open source software is reviewed prior to use in our solution, that our programmers have not incorporated open source software into our solution, or that they will not do so in the future.
In addition, our solution may incorporate third-party software under commercial licenses. We cannot be certain whether such third-party software incorporates open source software without our knowledge. In the past, companies that incorporate open
23
source software into their products have faced claims alleging noncompliance with open source license terms or infringement or misappropriation of proprietary software. Therefore, we could be subject to suits by parties claiming noncompliance with open source licensing terms or infringement or misappropriation of proprietary software. Because few courts have interpreted open source licenses, the manner in which these licenses may be interpreted and enforced is subject to some uncertainty. There is a risk that open source software licenses could be construed in a manner that imposes unanticipated conditions or restrictions on our ability to market or provide our solution. As a result of using open source software subject to such licenses, we could be required to release proprietary source code, pay damages, re-engineer our solution, limit or discontinue sales or take other remedial action, any of which could adversely affect our business.
False detection of security breaches, false identification of malicious sources or misidentification of sensitive or regulated information could adversely affect our business.
Our cybersecurity products may falsely detect threats that do not actually exist. For example, our DatAlert product may enrich metadata collected by our products with information from external sources and third-party data providers. If the information from these data providers is inaccurate, the potential for false positives increases. These false positives, while typical in the industry, may affect the perceived reliability of our products and solutions and may therefore adversely impact market acceptance of our products. As definitions and instantiations of personal identifiers and other sensitive content change, automated classification technologies may falsely identify or fail to identify data as sensitive. If our products and solutions fail to detect exposures or restrict access to important systems, files or applications based on falsely identifying legitimate use as an attack or otherwise unauthorized, then our customers’ businesses could be adversely affected. Any such false identification of use and subsequent restriction could result in negative publicity, loss of customers and sales, increased costs to remedy any problem and costly litigation.
Failure to protect our proprietary technology and intellectual property rights could substantially harm our business.
The success of our business and competitive position depends on our ability to obtain, protect and enforce our trade secrets, trademarks, copyrights, patents and other intellectual property rights. We attempt to protect our intellectual property under patent, trademark, copyrights and trade secret laws, and through a combination of confidentiality procedures, contractual provisions and other methods, all of which offer only limited protection and may not now or in the future provide us with a competitive advantage.
As of December 31, 2025, we have 116 issued patents in the United States and 63 pending U.S. patent applications. We also had 95 patents issued and 79 applications pending for examination in non-U.S. jurisdictions, and 31 pending PCT patent applications, all of which are counterparts of our U.S. patent applications. We may file additional patent applications in the future. The process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner all the way through to the successful issuance of a patent. We may choose not to seek patent protection for certain innovations and may choose not to pursue patent protection in certain jurisdictions. Furthermore, it is possible that our patent applications may not issue as granted patents, that the scope of our issued patents will be insufficient or not have the coverage originally sought, that our issued patents will not provide us with any competitive advantages, and that our patents and other intellectual property rights may be challenged by others or invalidated through administrative process or litigation. In addition, issuance of a patent does not guarantee that we have an absolute right to practice the patented invention. Our policy is to require our employees (and our consultants and service providers that develop intellectual property included in our products) to execute written agreements in which they assign to us their rights in potential inventions and other intellectual property created within the scope of their employment (or, with respect to consultants and service providers, their engagement to develop such intellectual property). However, we may not be able to adequately protect our rights in every such agreement or execute an agreement with every such party. Finally, in order to benefit from patent and other intellectual property protection, we must monitor, detect and pursue infringement claims in certain circumstances in relevant jurisdictions, all of which is costly and time-consuming. As a result, we may not be able to obtain adequate protection or to enforce our issued patents or other intellectual property effectively.
In addition to patented technology, we rely on our unpatented proprietary technology and trade secrets. Despite our efforts to protect our proprietary technologies and our intellectual property rights, unauthorized parties, including our employees, consultants, service providers or customers, may attempt to copy aspects of our products or obtain and use our trade secrets or other confidential information. We generally enter into confidentiality agreements with our employees, consultants, service providers, vendors, channel partners and customers, and generally limit access to and distribution of our proprietary information and proprietary technology through certain procedural safeguards. These agreements may not effectively prevent unauthorized use or disclosure of our intellectual property or technology and may not provide an adequate remedy in the event of unauthorized use or disclosure of our intellectual property or technology. We cannot provide assurance that the steps taken by us will prevent misappropriation of our trade secrets or technology or infringement of our intellectual property. In addition, the laws of some foreign countries where we operate do not protect our proprietary rights to as great an extent as the laws of the
24
United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.
We have registered the “Varonis” name and logo and “DatAdvantage,” “DataPrivilege,” “DatAlert,” and other names in the United States and, as related to some of these names, certain other countries. However, we cannot provide assurance that any future trademark registrations will be issued for pending or future applications or that any registered trademarks will be enforceable or provide adequate protection of our proprietary rights.
Despite our efforts to protect our proprietary technology and trade secrets, unauthorized parties may attempt to misappropriate, reverse engineer or otherwise obtain and use them. In addition, others may independently discover our trade secrets, in which case we would not be able to assert trade secret rights or develop similar technologies and processes. Further, the contractual provisions that we enter into may not prevent unauthorized use or disclosure of our proprietary technology or intellectual property rights and may not provide an adequate remedy in the event of unauthorized use or disclosure of our proprietary technology or intellectual property rights. Moreover, policing unauthorized use of our technologies, trade secrets and intellectual property is difficult, expensive and time-consuming, particularly in foreign countries where the laws may not be as protective of intellectual property rights as those in the United States and where mechanisms for enforcement of intellectual property rights may be weak. We may be unable to determine the extent of any unauthorized use or infringement of our solution, technologies or intellectual property rights. If we are unable to protect our intellectual property rights and ensure that we are not violating the intellectual property rights of others, we may find ourselves at a competitive disadvantage to others who need not incur the additional expense, time and effort required to create the innovative products that have enabled us to be successful to date.
Assertions by third parties of infringement or other violations by us of their intellectual property rights, whether or not correct, could result in significant costs and harm our business and operating results.
The industries in which we operate, such as data security, cybersecurity, compliance, data retention and data governance are characterized by the existence of a large number of relevant patents and frequent claims and related litigation regarding patent and other intellectual property rights. From time to time, third parties have asserted and may assert their patent, copyright, trademark and other intellectual property rights against us, our channel partners or our customers. Successful claims of infringement or misappropriation by a third-party could prevent us from distributing certain products, performing certain services or could require us to pay substantial damages (including, for example, treble damages if we are found to have willfully infringed patents and increased statutory damages if we are found to have willfully infringed copyrights), royalties or other fees. Such claims also could require us to cease making, licensing or using solutions that are alleged to infringe or misappropriate the intellectual property of others or to expend additional development resources to attempt to redesign our products or services or otherwise to develop non-infringing technology. Even if third parties may offer a license to their technology, the terms of any offered license may not be acceptable, and the failure to obtain a license or the costs associated with any license could cause our business, results of operations or financial condition to be materially and adversely affected. In some cases, we indemnify our channel partners and customers against claims that our products infringe the intellectual property of third parties. Defending against claims of infringement or being deemed to be infringing the intellectual property rights of others could impair our ability to innovate, develop, distribute and sell our current and planned products and services.
Risks Related to our Tax Regime
Our tax rate may vary significantly depending on our stock price.
The tax effects of the accounting for stock-based compensation may significantly impact our effective tax rate from period to period. In periods in which our stock price is higher than the grant price of the stock-based compensation vesting in that period, we will recognize excess tax benefits that will decrease our effective tax rate, while in periods in which our stock price is lower than the grant price of the stock-based compensation vesting in that period, our effective tax rate may increase. The amount and value of stock-based compensation issued relative to our earnings in a particular period will also affect the magnitude of the impact of stock-based compensation on our effective tax rate. These tax effects are dependent on our stock price, which we do not control, and a decline in our stock price could significantly increase our effective tax rate and adversely affect our financial results.
Multiple factors may adversely affect our ability to fully utilize our net operating loss carryforwards.
A U.S. corporation’s ability to utilize its federal and state net operating loss (“NOL”) and tax credit carryforwards to offset its taxable income is limited under Section 382 and Section 383 of the Internal Revenue Code of 1986, as amended (the “Code”), if the corporation undergoes an ownership change (within the meaning of Code Section 382).
25
As of December 31, 2025, we have accumulated $211.5 million of federal NOL, $182.0 million of state NOL and $10.5 million of federal research credit carryforwards since inception. Future changes in our stock ownership, including future offerings, as well as changes that may be outside of our control, could result in a subsequent ownership change under Section 382, that would impose an annual limitation on NOLs. In addition, the cash tax benefit from our NOLs is dependent upon our ability to generate sufficient taxable income. Accordingly, we may be unable to earn enough taxable income in order to fully utilize our current NOLs.
Changes in our provision for income taxes or adverse outcomes resulting from examination of our income tax returns could adversely affect our results.
We are subject to income taxation in the United States, Israel and numerous other jurisdictions. Determining our provision for income taxes requires significant management judgment. In addition, our provision for income taxes could be adversely affected by many factors, including, among other things, changes to our operating structure including a review of our intellectual property (“IP”) structure, changes in the amounts of earnings in jurisdictions with different statutory tax rates, changes in the valuation of deferred tax assets and liabilities and changes in tax laws. Significant judgment is required to determine the recognition and measurement attributes prescribed in Accounting Standards Codification 740-10-25 (“ASC 740-10-25”). ASC 740-10-25 applies to all income tax positions, including the potential recovery of previously paid taxes, which if settled unfavorably could adversely impact our provision for income taxes. Our income in certain countries is subject to reduced tax rates provided we meet certain criteria. Failure to meet these commitments could adversely impact our provision for income taxes.
We are also subject to the regular examination of our income tax returns by the U.S. Internal Revenue Services and other tax authorities in various jurisdictions. Tax authorities may disagree with our intercompany charges, cross-jurisdictional transfer pricing, IP structure or other matters and assess additional taxes. While we believe that we are currently in material compliance with our obligations under applicable taxing regimes, and regularly assess the likelihood of adverse outcomes resulting from these examinations to determine the adequacy of our provision for income taxes, there can be no assurance that the outcomes from these regular examinations will not have a material adverse effect on our results of operations and cash flows. Further, we may be audited in various jurisdictions, and such jurisdictions may assess additional taxes against us. Although we believe our tax estimates are reasonable, the final determination of any tax audits or litigation could be materially different from our historical tax provisions and accruals, which could have a material adverse effect on our results of operations or cash flows in the period or periods for which a determination is made.
The adoption of the U.S. tax reform and the enactment of additional legislation changes could materially impact our financial position and results of operations.
On July 4, 2025, the One Big Beautiful Bill Act ("OBBBA") was enacted. Included in the OBBBA are provisions that allow for the immediate expensing of U.S. research and development expenses and certain capital expenditures, as well as changes to the U.S. taxation of profits derived from foreign operations. While we continue to evaluate the impact of these legislative changes as additional guidance becomes available, uncertainty remains regarding the timing and interpretation by tax authorities in affected jurisdictions. These legislative changes could have an adverse impact on our future effective tax rate, tax liabilities and cash paid for income taxes.
On December 22, 2017, the Tax Cuts and Jobs Act (the "TCJA") was enacted. The TCJA remains unclear in some respects and has been, and may continue to be, subject to amendments and technical corrections, as well as interpretations and implementing regulations by the Treasury and Internal Revenue Service, any of which could lessen or increase certain adverse impacts of TCJA. Effective in July 2025, the TCJA, as revised by the OBBBA, requires all U.S. companies to capitalize and subsequently amortize research and development expenses that fall within the scope of Section 174 over fifteen years for research and development activities conducted outside of the U.S. As of the fourth quarter of 2025, we have accounted for an estimate of the effects of the research and development capitalization, based on interpretation of the law as currently enacted. Once our available NOLs or tax credits are fully utilized, then, due to the capitalization of research and development expenses for those activities conducted outside of the U.S., we would incur a significant increase in our tax expenses and a decrease in our cash flows provided by operations.
The Organization for Economic Cooperation and Development (“OECD”) introduced the base erosion and profit shifting project which sets out a plan to address international taxation principles in a globalized, digitized business world (the “BEPS Plan”). As a result, changes have been and continue to be made to numerous international tax principles and local tax regimes. Due to the expansion of our international business activities, those modifications may increase our worldwide effective tax rate, create tax and compliance obligations in jurisdictions in which we previously had none and adversely affect our financial position.
Risks Related to the 2029 Notes
26
We have incurred substantial indebtedness that may decrease our business flexibility, access to capital, and/or increase our borrowing costs, and we may still incur substantially more debt, which may adversely affect our operations and financial results.
In September 2024, we issued the 2029 Notes. As of December 31, 2025, we have $460.0 million outstanding aggregate principal amount of the 2029 Notes. Our indebtedness may limit our ability to borrow additional funds for working capital, capital expenditures, acquisitions or other general business purposes, limit our ability to use our cash flow or obtain additional financing for future working capital, capital expenditures, acquisitions or other general business purposes, require us to use a substantial portion of our cash flow from operations to make debt service payments, limit our flexibility to plan for, or react to, changes in our business and industry, place us at a competitive disadvantage compared to our less leveraged competitors and increase our vulnerability to the impact of adverse economic and industry conditions.
Our debt obligations may adversely affect our ability to raise additional capital and will be a burden on our future cash resources, particularly if we elect to settle these obligations in cash upon conversion or upon maturity or required repurchase.