FULLTEXT DEL 2 AV 4

10-K – 2026-02-25 – ftnt-20251231.htm

Föregående del · Dokumentindex · Nästa del

• the loss of existing or potential end-customers or channel partners;

• delayed or lost revenue;

• delay or failure to attain market acceptance;

• negative publicity and harm to our reputation; and

• disclosure requirements, litigation, regulatory inquiries or investigations that may be costly and harm our reputation and, in some instances, subject us to potential liability that is not contractually limited.

If our internal enterprise IT networks, on which we conduct internal business and interface externally, our operational networks, through which we connect to customers, vendors and partners systems and provide services, or our research and development networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers, through which we research, develop and host products and services, are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted.

Our success depends on the market’s confidence in our ability to provide effective network security protection. Despite our efforts and processes to prevent breaches of our internal networks, systems and websites, whether in our owned data centers, cloud providers or colocations, we are still vulnerable to computer viruses, break-ins, phishing attacks, ransomware attacks, attempts to overload our servers with denial-of-service, vulnerabilities in vendor hardware and software that we leverage, advanced persistent threats from sophisticated actors and other cyberattacks and similar disruptions from unauthorized access to our internal networks, systems or websites, whether in our owned data centers, cloud providers or colocations. Our security measures may also be breached due to employee error, malfeasance or otherwise, which breaches may be more difficult to detect than outsider threats, and the existing programs and trainings we have in place to prevent such insider threats may not be effective or sufficient. Third parties may also attempt to fraudulently induce our employees to transfer funds or
27

Table of Contents

disclose information in order to gain access to our networks and confidential information. Third parties may also send our customers or others malware or malicious emails that falsely indicate that we are the source, potentially causing lost confidence in us and reputational harm. We cannot guarantee that the measures we have taken to protect our networks, systems and websites, whether in our owned data centers, cloud providers or colocations, will provide adequate security. Moreover, because we provide network security products, we may be a more attractive target for attacks by computer hackers and any security breaches and other security incidents involving us may result in more harm to our reputation and brand than companies that do not sell network security solutions. Hackers and malicious parties may be able to develop and deploy viruses, worms, ransomware and other malicious software programs that attack our products and customers, that impersonate our update servers in an effort to access customer networks and negatively impact customers, or otherwise exploit any security vulnerabilities of our products, or attempt to fraudulently induce our employees, customers or others to disclose passwords or other sensitive information or unwittingly provide access to our internal networks, systems or data. Moreover, the threat landscape continues to evolve as a result of new technologies, including AI, and malicious parties may use AI to help attack our solutions, systems, and our customers.

For example, from time to time, we have discovered that unauthorized parties have targeted us using sophisticated techniques, including by stealing technical data and attempting to steal private encryption keys, in an effort to both impersonate our products and threat intelligence update services and possibly attempt other attack methodologies. Using these techniques, these unauthorized parties have tried, and may in the future try, to gain access to certain of our and our customers’ systems. We have also, for example, discovered that unauthorized parties have targeted vulnerabilities, including critical vulnerabilities, in our product software and infrastructure in an effort to gain entry into our customers’ networks. In addition, in general threat actors use dark web forums to sell organizations’ stolen credentials. If threat actors sell valid credentials used by our customers to access our services, it is possible that unauthorized third parties may use such stolen credentials to try to gain access to our services. These and other hacking efforts against us and our customers may be ongoing and may happen in the future.

Although we take numerous measures and implement multiple layers of security to protect our networks, we cannot guarantee that our security products, processes and services will secure against all threats. Further, we cannot be sure that third parties have not been, or will not in the future be, successful in improperly accessing our systems and our customers’ systems, which could negatively impact us and our customers. An actual breach could significantly harm us and our customers, and an actual or perceived breach, or any other actual or perceived data security incident, threat or vulnerability, that involves our supply chains, networks, systems or websites and/or our customers’ supply chains, networks, systems or websites could adversely affect the market perception of our products and services and investor confidence in our company. Any breach of our networks, systems or websites could impair our ability to operate our business, including our ability to provide FortiGuard and other security subscriptions and FortiCare technical support services to our end-customers, lead to interruptions or system slowdowns, cause loss of critical data or lead to the unauthorized disclosure or use of confidential, proprietary or sensitive information. We could also be subject to liability and litigation and reputational harm and our channel partners and end-customers may be harmed, lose confidence in us and decrease or cease using our products and services. Any breach of our internal networks, systems or websites could have an adverse effect on our business, operating results and stock price.

In addition, there has been a general increase in phishing attempts and spam emails as well as social engineering attempts from hackers, and many of our employees continue to work remotely which may pose additional data security risks in the event remote work environments are not as secure as office environments. Any security incident could negatively impact our reputation and results of operations.

Managing inventory of our products and product components is complex. We order components from third-party manufacturers based on our forecasts of future demand and targeted inventory levels, which exposes us to the risk of product shortages, which may result in lost sales, higher expenses and excess inventory, which may require us to sell our products at discounts and lead to inventory charges or write-offs.

Managing our inventory is complex, especially in times of supply chain disruption. Our channel partners may increase orders during periods of product shortages, cancel orders or not place orders commensurate with our expectations if their inventory is too high, return products or take advantage of price protection (if any is available to the particular partner) or delay orders in anticipation of new products, and accurately forecasting inventory requirements and demand can be challenging. Our channel partners also may adjust their orders in response to the supply of our products and the products of our competitors that are available to them and in response to seasonal fluctuations in end-customer demand. If we cannot manufacture and ship our products due to, for example, global chip shortages, excessive demand on contract manufacturers capacity, natural disasters and health emergencies such as earthquakes, fires, power outages, typhoons, floods, health pandemics and epidemics or manmade events such as civil unrest, labor disruption, tariffs, cyber events, international trade disputes, international conflicts, terrorism, wars or other foreign conflicts, such as the war in Ukraine, tensions between China and Taiwan or conflicts in the Middle East, and critical infrastructure attacks, our business and financial results could be materially and adversely impacted. Conflicts in the Middle East highlights potential risks associated with geopolitical instability in the region, including disruption to shipping routes, longer lead times for components and products, increased insurance costs for vessels passing through conflict zones,
28

Table of Contents

potential increased costs for shipping and products, and potential delays and interruptions in the supply chain. We may face challenges in sourcing materials, fulfilling orders and managing logistics efficiently, which could ultimately affect our operations, financial performance and overall business continuity. For example, as a result of the rapid global build-out of AI infrastructure, there is currently a global shortage of memory chips, which are a component in certain of our products. As a result, we are currently experiencing, and may continue to experience, constraints on the availability of memory chips. If we are unable to obtain sufficient quantities of memory chips on commercially reasonable terms, we have experienced, and may continue to experience, delays in the production and delivery of our products and increased costs to source available memory chips, any of which could harm our business, financial condition and results of operations. To mitigate increased hardware costs resulting from these shortages, we are implementing price increases, which may negatively impact demand for our products and may not be sufficient or timely to offset rising input costs, potentially resulting in margin compression and adversely affecting our business, financial condition and results of operations.

During prior periods of supply chain disruption, including during the COVID-19 pandemic we increased our purchase order commitments. Similar conditions could arise in the future, which may require us to accept or pay for components and finished goods regardless of our level of sales in a particular period, which may negatively or unpredictably impact our operating results and financial condition. For additional information and a further discussion of impacts and risks related to our purchase commitments with our suppliers, refer to Note 11. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K.

Inventory management remains an area of focus as we balance the need to maintain inventory levels that are sufficient to ensure competitive lead times against the risk of inventory obsolescence because of rapidly changing technology, product transitions, customer requirements or excess inventory levels. If we ultimately determine that we have excess inventory, we may have to reduce our prices, which may result in inventory charges and/or write-down of inventory, which in turn could result in lower gross margins. Alternatively, insufficient inventory levels may lead to shortages that result in delayed billings and revenue or loss of sales opportunities altogether as potential end-customers turn to competitors’ products that are readily available. For example, we have in the past experienced inventory shortages and excesses due to the variance in demand for certain products from forecasted amounts. Our inventory management systems and related supply chain visibility tools may be inadequate to enable us to effectively manage inventory. If we are unable to effectively manage our inventory and that of our channel partners, our results of operations could be adversely affected.

If our new products, services and enhancements do not achieve sufficient market acceptance, our results of operations and competitive position will suffer.

We spend substantial amounts of time and money to develop internally and acquire new products and services and enhance versions of our existing products and services in order to incorporate additional features, improved functionality or other enhancements in order to meet our customers’ rapidly evolving demands for network security in our highly competitive industry. When we develop a new product or service, or an enhanced version of an existing product or service, we typically incur expenses and expend resources upfront to market, promote and sell the new offering. Therefore, when we develop and introduce new or enhanced products or services, they must achieve high levels of market acceptance in order to justify the amount of our investment in developing and bringing them to market.

Our new products, services or enhancements could fail to attain sufficient market acceptance for many reasons, including:
 
• actual or perceived defects, vulnerabilities, errors or failures;

• delays in releasing our new products, services or enhancements to the market;
 
• failure to accurately predict market demand in terms of product and service functionality and to supply products and services that meet this demand in a timely fashion;

• failure to have the appropriate research and development expertise and focus to make our top strategic products and services successful;
 
• failure of our sales force and partners to focus on selling new products and services;
 
• inability to interoperate effectively with the networks or applications of our prospective end-customers;
 
• inability to protect against new types of attacks or techniques used by hackers;
29

Table of Contents

 
• negative publicity about their performance or effectiveness;
 
• introduction or anticipated introduction of competing products and services by our competitors;
 
• poor business conditions for our end-customers, causing them to delay IT purchases;
 
• changes to the regulatory requirements around security; and
 
• reluctance of customers to purchase products or services incorporating open source software.
 
If our new products, services or enhancements do not achieve adequate acceptance in the market, our competitive position will be impaired, our revenue will be diminished and the effect on our operating results may be particularly acute because of the significant research, development, marketing, sales and other expenses we incurred in connection with the new product, service or enhancement.

The network security market is rapidly evolving and the complex technology incorporated in our products makes them difficult to develop. If we do not accurately predict, prepare for and respond promptly to technological and market developments, changing end-customer needs, and expanding regulatory requirements and standards, our competitive position and prospects may be harmed.

The network security market is expected to continue to evolve rapidly. Moreover, many of our end-customers operate in markets characterized by rapidly changing technologies and business plans, which require them to add numerous network access points and adapt increasingly complex networks, incorporating a variety of hardware, software applications, operating systems and networking protocols. In addition, computer hackers and others who try to attack networks employ increasingly sophisticated techniques to gain access to and attack systems and networks. The technology in our products is especially complex because of the requirements to effectively identify and respond to new and increasingly sophisticated methods of attack, while minimizing the impact on network performance. Additionally, some of our new products and enhancements may require us to develop new hardware architectures and ASICs that involve complex, expensive and time-consuming research and development processes. For example, we enter into development agreements with third parties. If our development projects are not successfully completed, or are not completed in a timely fashion, our product development could be delayed and our business generally could suffer. Costs for development can be substantial and our profitability may be harmed if we are unable to recover these costs. Although the market expects rapid introduction of new products or product enhancements to respond to new threats, the development of these products is difficult and the timetable for commercial release and availability is uncertain and there can be long time periods between releases and availability of new products. We have in the past and may in the future experience unanticipated delays in the availability of new products and services and fail to meet previously announced timetables for such availability. If we do not quickly respond to the rapidly changing and rigorous needs of our end-customers by developing, releasing and making available on a timely basis new products and services or enhancements that can respond adequately to new security threats, our competitive position and business prospects may be harmed.

Moreover, business models based on a subscription cloud-based software service have become increasingly in demand by our end-customers and adopted by other providers, including our competitors. While we have introduced additional cloud-based solutions and will continue to do so, most of our platform is currently deployed on premise, and therefore, as customers demand that solutions be provided through a subscription cloud-based business model, we are making additional investments in our infrastructure and personnel to be able to more fully provide our platform through a subscription cloud-based model in order to maintain the competitiveness of our platform. Such investments involve expanding our data centers, servers and networks, and increasing our technical operations and engineering teams and this results in added cost and risks associated with managing new business models, such as obligations to deliver certain functionality and features and to meet certain service level agreements related to cloud-based solutions. There is also a risk that we are slower to offer these solutions than competitors. The risks are compounded by the uncertainty concerning the future success of any of our particular subscription cloud-based business models and the future demand for our subscription cloud-based models by customers. Additionally, if we are unable to meet the demand to provide our services effectively through a subscription cloud-based model, we may lose customers to competitors.

Demand for our products may be limited by market perception that individual products from one vendor that provide multiple layers of security protection in one product are inferior to point products from multiple vendors.
 
Sales of many of our products depend on increased demand for incorporating broad security functionality into one appliance. If the market for these products fails to grow as we anticipate, our business will be seriously harmed. Target customers may view “all-in-one” network security solutions as inferior to security solutions from multiple vendors because of, among other things, their perception that such products of ours provide security functions from only a single vendor and do not
30

Table of Contents

allow users to choose “best-of-breed” defenses from among the wide range of dedicated security applications available. Target customers might also perceive that, by combining multiple security functions into a single platform, our solutions create a “single point of failure” in their networks, which means that an error, vulnerability or failure of our product may place the entire network at risk. In addition, the market perception that “all-in-one” solutions may be suitable only for small- and medium-sized businesses because such solution lacks the performance capabilities and functionality of other solutions may harm our sales to large businesses, service provider and government organization end-customers. If the foregoing concerns and perceptions become prevalent, even if there is no factual basis for these concerns and perceptions, or if other issues arise with our market in general, demand for multi-security functionality products could be severely limited, which would limit our growth and harm our business, financial condition and results of operations. Further, a successful and publicized targeted attack against us, exposing a “single point of failure”, could significantly increase these concerns and perceptions and may harm our business and results of operations.

If functionality similar to that offered by our products is incorporated into existing network infrastructure products, organizations may decide against adding our appliances to their network, which would have an adverse effect on our business.
 
Large, well-established providers of networking equipment, such as Cisco, offer, and may continue to introduce, network security features that compete with our products, either in standalone security products or as additional features in their network infrastructure products. The inclusion of, or the announcement of an intent to include, functionality perceived to be similar to that offered by our security solutions in networking products that are already generally accepted as necessary components of network architecture may have an adverse effect on our ability to market and sell our products. Furthermore, even if the functionality offered by network infrastructure providers is more limited than our products, a significant number of customers may elect to accept such limited functionality in lieu of adding appliances from an additional vendor such as us. Many organizations have invested substantial personnel and financial resources to design and operate their networks and have established deep relationships with other providers of networking products, which may make them reluctant to add new components to their networks, particularly from other vendors such as us. In addition, an organization’s existing vendors or new vendors with a broad product offering may be able to offer concessions that we are not able to match because we currently offer only network security products and have fewer resources than many of our competitors. If organizations are reluctant to add additional network infrastructure from new vendors or otherwise decide to work with their existing vendors, our business, financial condition and results of operations will be adversely affected.

Because we depend on several third-party manufacturers to build our products, we are susceptible to manufacturing delays that could prevent us from shipping customer orders on time, if at all, and may result in the loss of sales and customers; additionally third-party manufacturing cost increases and changes in the geopolitical environment could result in lower gross margins and free cash flow.

We outsource the manufacturing of our security appliance products to contract manufacturing partners and original design manufacturing partners, including manufacturers with facilities located in Taiwan and other countries outside the United States such as Accton, IBASE, Micro-Star, Senao and Wistron. Our reliance on our third-party manufacturers reduces our control over the manufacturing process, exposing us to risks, including reduced control over quality assurance, costs, supply and timing and possible tariffs. Any manufacturing disruption related to our third-party manufacturers or their component suppliers for any reason, including global chip shortages, natural disasters and health emergencies such as earthquakes, fires, power outages, typhoons, floods, health pandemics and epidemics and manmade events such as civil unrest, labor disruption, cyber events, international trade disputes, tariffs, international conflicts, terrorism, wars or other foreign conflicts, such as the war in Ukraine, tensions between China and Taiwan or conflicts in the Middle East, and critical infrastructure attacks, could impair our ability to fulfill orders. If we are unable to manage our relationships with these third-party manufacturers effectively, or if these third-party manufacturers experience delays, increased manufacturing lead-times, disruptions, capacity constraints or quality control problems in their manufacturing operations, or fail to meet our future requirements for timely delivery, our ability to ship products to our customers could be impaired and our business would be seriously harmed. Further, certain components for our products come from Taiwan and the majority of our hardware is manufactured in Taiwan. Any increase in tensions between China and Taiwan, including threats of military actions or escalation of military activities, could adversely affect our manufacturing operations in Taiwan, which, given the large percentage of our hardware that is manufactured in Taiwan, could have significant impacts on our business and operations. Any new restrictions that negatively impact our ability to receive supply of hardware components from Taiwan would negatively impact our business and financial results.
 
These manufacturers fulfill our supply requirements on the basis of individual purchase orders. We have no long-term contracts or arrangements with our third-party manufacturers that guarantee capacity, the continuation of particular payment terms or the extension of credit limits. Accordingly, they are not obligated to continue to fulfill our supply requirements, and the prices we are charged for manufacturing services could be increased on short notice. If we are required to change third-party manufacturers, our ability to meet our scheduled product deliveries to our customers would be adversely affected, which could
31

Table of Contents

cause the loss of sales and existing or potential customers, delayed revenue or an increase in our costs, which could adversely affect our gross margins. Our individual product lines are generally manufactured by only one manufacturing partner. Any production or shipping interruptions for any reason, such as a natural disaster, epidemics, pandemics, capacity shortages, quality problems or strike or other labor disruption at one of our manufacturing partners or locations or at shipping ports or locations, would severely affect sales of our product lines manufactured by that manufacturing partner. Furthermore, manufacturing cost increases for any reason could result in lower gross margins.
 
Our proprietary ASIC, which are key to the performance of our appliances, are built by contract manufacturers including Renesas and Toshiba America. These contract manufacturers use foundries operated by TSMC or Renesas on a purchase-order basis, and these foundries do not guarantee their capacity and could delay orders or increase their pricing. Accordingly, the foundries are not obligated to continue to fulfill our supply requirements, and due to the long lead time that a new foundry would require, we could suffer inventory shortages of our ASIC as well as increased costs. In addition to our proprietary ASIC, we also purchase off-the-shelf ASICs or integrated circuits from vendors for which we have experienced, and may continue to experience, long lead times. Our suppliers may also prioritize orders by other companies that order higher volumes or more profitable products. If any of these manufacturers materially delays its supply of ASICs or specific product models to us, or requires us to find an alternate supplier and we are not able to do so on a timely and reasonable basis, or if these foundries materially increase their prices for fabrication of our ASICs, our business would be harmed.

In addition, our reliance on third-party manufacturers and foundries limits our control over environmental regulatory requirements such as the hazardous substance content of our products and therefore our ability to ensure compliance with the Restriction of Hazardous Substances Directive (the “EU RoHS”) adopted in the European Union (the “EU”) and other similar laws. It also exposes us to the risk that certain minerals and metals, known as “conflict minerals”, that are contained in our products have originated in the Democratic Republic of the Congo or an adjoining country. As a result of the passage of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank”), the SEC adopted disclosure requirements for public companies whose products contain conflict minerals that are necessary to the functionality or production of such products. Under these rules, we are required to obtain sourcing data from suppliers, perform supply chain due diligence, and file annually with the SEC a specialized disclosure report on Form SD covering the prior calendar year. We have incurred and expect to incur additional costs to comply with the rules, including costs related to efforts to determine the origin, source and chain of custody of the conflict minerals used in our products and the adoption of conflict minerals-related governance policies, processes and controls. Moreover, the implementation of these compliance measures could adversely affect the sourcing, availability and pricing of materials used in the manufacture of our products to the extent that there may be only a limited number of suppliers that are able to meet our sourcing requirements, which would make it more difficult to obtain such materials in sufficient quantities or at competitive prices. We may also encounter customers who require that all of the components of our products be certified as conflict-free. If we are not able to meet customer requirements, such customers may choose to not purchase our products, which could impact our sales and the value of portions of our inventory.

Because some of the key components in our products come from limited sources of supply, we are susceptible to supply shortages, long or uncertain lead times for components, and supply changes, each of which could disrupt or delay our scheduled product deliveries to our customers, result in inventory shortage, cause loss of sales and customers or increase component costs resulting in lower gross margins and free cash flow.

We and our contract manufacturers currently purchase several key parts and components used in the manufacture of our products from limited sources of supply. We are therefore subject to the risk of shortages and long or uncertain lead times in the supply of these components and the risk that component suppliers may discontinue or modify components used in our products. We have in the past experienced shortages and long or uncertain lead times for certain components. Our limited source components for particular appliances and suppliers of those components include specific types of CPUs from Intel and AMD, network and wireless chips from Broadcom, Marvell, Qualcomm and Intel, and memory devices from Intel, Micron, ADATA, Toshiba, Samsung and Western Digital. We also may face shortages in the supply of the capacitors and resistors that are used in the manufacturing of our products, which may persist for an indefinite period of time. The introduction by component suppliers of new versions of their products, particularly if not anticipated by us or our contract manufacturers, could require us to expend significant resources to incorporate these new components into our products. In addition, if these suppliers were to discontinue production of a necessary part or component, we would be required to expend significant resources and time in locating and integrating replacement parts or components from another vendor. Qualifying additional suppliers for limited source parts or components can be time-consuming and expensive.

If we are unable to obtain sufficient quantities of any of these components on commercially reasonable terms or in a timely manner, or if we are unable to obtain alternative sources for these components, shipments of our products could be delayed or halted entirely or we may be required to redesign our products. Any of these events could result in a cancellation of orders, lost sales, reduced gross margins or damage to our end customer relationships, which would adversely impact our business, financial condition, results of operations and prospects. Additionally, if actual demand does not directly match with
32

Table of Contents

our demand forecasts, due to our purchase order commitments, we in some instances have been required to and may in the future be required to accept or pay for components and finished goods. This may result in us discounting our products or excess or obsolete inventory, which we would be required to write down to its estimated realizable value, which in turn could result in lower gross margins. Our reliance on a limited number of suppliers involves several additional risks, including:

• a potential inability to obtain an adequate supply of required parts or components when required;

• financial or other difficulties faced by our suppliers;
 
• infringement or misappropriation of our IP;
 
• price increases;
 
• failure of a component to meet environmental or other regulatory requirements;
 
• failure to meet delivery obligations in a timely fashion;
 
• failure in component quality; and

• inability to ship products on a timely basis.
 
The occurrence of any of these events would be disruptive to us and could seriously harm our business. Any interruption or delay in the supply of any of these parts or components, or the inability to obtain these parts or components from alternate sources at acceptable prices and within a reasonable amount of time, would harm our ability to meet our scheduled product deliveries to our distributors, resellers and end-customers. This could harm our relationships with our channel partners and end-customers and could cause delays in shipment of our products and adversely affect our results of operations. In addition, increased component costs could result in lower gross margins.

We offer retroactive price protection to certain of our major distributors in North America, and if we fail to balance their inventory with end-customer demand for our products, our allowance for price protection may be inadequate, which could adversely affect our results of operations.

We provide certain of our major distributors in North America with price protection rights for inventories of our products held by them. If we reduce the list price of our products, as we have recently done, certain distributors in North America receive refunds or credits from us that reduce the price of such products held in their inventory based upon the new list price. Future credits for price protection will depend on the percentage of our price reductions for the products in inventory and our ability to manage the levels of certain of our major distributors’ inventories in North America. If future price protection adjustments are higher than expected, our future results of operations could be materially and adversely affected.

The sales prices of our products and services may decrease, which may reduce our gross profits and operating margin and may adversely impact our financial results and the trading price of our common stock.
 
The sales prices for our products and services may decline for a variety of reasons or our product mix may change, resulting in lower growth and margins based on a number of factors, including competitive pricing pressures, discounts or promotional programs we offer, a change in our mix of products and services and anticipation of the introduction of new products and services. We have recently conducted such price decreases. Competition continues to increase in the market segments in which we participate, and we expect competition to further increase in the future, thereby leading to increased pricing pressures. Larger competitors with more diverse product offerings may reduce the price of products and services that compete with ours in order to promote the sale of other products or services or may bundle them with other products or services. Additionally, although we price our products and services worldwide in U.S. dollars, currency fluctuations in certain countries and regions have in the past, and may in the future, negatively impact actual prices that partners and customers are willing to pay in those countries and regions. Additionally, while our U.S distribution agreements contain price protections, our international distribution agreements do not contain such protections. Furthermore, we anticipate that the sales prices and gross profits for our products or services will decrease over product life cycles. We cannot ensure that we will be successful in developing and introducing new offerings with enhanced functionality on a timely basis, or that our product and service offerings, if introduced, will enable us to maintain our prices, gross profits and operating margin at levels that will allow us to maintain profitability.
33

Table of Contents

 
Our uniform resource locator (“URL”) database for our web filtering service may fail to keep pace with the rapid growth of URLs and may not categorize websites in accordance with our end-customers ’ expectations.

The success of our web filtering service depends on the breadth and accuracy of our URL database. Although our URL database currently catalogs millions of unique URLs, it contains only a portion of the URLs for all of the websites that are available on the internet. In addition, the total number of URLs and software applications is growing rapidly, and we expect this rapid growth to continue in the future. Accordingly, we must identify and categorize content for our security risk categories at an extremely rapid rate. Our database and technologies may not be able to keep pace with the growth in the number of websites, especially the growing amount of content utilizing foreign languages and the increasing sophistication of malicious code and the delivery mechanisms associated with spyware, phishing and other hazards associated with the internet. Further, the ongoing evolution of the internet and computing environments will require us to continually improve the functionality, features and reliability of our web filtering function. Any failure of our databases to keep pace with the rapid growth and technological change of the internet could impair the market acceptance of our products, which in turn could harm our business, financial condition and results of operations.

In addition, our web filtering service may not be successful in accurately categorizing internet and application content to meet our end-customers’ expectations. We rely upon a combination of automated filtering technology and human review to categorize websites and software applications in our proprietary databases. Our end-customers may not agree with our determinations that particular URLs should be included or not included in specific categories of our databases. In addition, it is possible that our filtering processes may place material that is objectionable or that presents a security risk in categories that are generally unrestricted by our customers’ internet and computer access policies, which could result in such material not being blocked from the network. Conversely, we may miscategorize websites such that access is denied to websites containing information that is important or valuable to our customers. Any miscategorization could result in customer dissatisfaction and harm our reputation. Any failure to effectively categorize and filter websites according to our end-customers’ and channel partners’ expectations could impair the growth of our business.

False positive detection of legitimate non-malicious files as viruses or malware or false identification of legitimate emails as spam, could adversely affect our business.

Our FortiGuard and other security subscription services may falsely detect, report and act on viruses or other threats that do not actually exist. This risk is heightened by the inclusion of heuristics, ML or AI features in our products, which attempt to identify viruses and other threats not based on any known signatures but based on characteristics or anomalies that may indicate that a particular item is a threat. With these features in our products, the risk of falsely identifying viruses and other threats significantly increases. These false positives, while typical in the industry, may impair the perceived reliability of our products and may therefore adversely impact market acceptance of our products. Also, our FortiGuard and other security subscription services may falsely identify emails or programs as unwanted spam or potentially unwanted programs, or alternatively fail to properly identify unwanted emails or programs, particularly as spam emails or spyware are often designed to circumvent anti-spam or spyware products. Parties whose emails or programs are blocked by our products may seek redress against us for labeling them as spammers or spyware, or for interfering with their business. In addition, false identification of emails or programs as unwanted spam or potentially unwanted programs may reduce the adoption of our products. If our system restricts important files or applications based on falsely identifying them as malware or some other item that should be restricted, this could adversely affect end-customers’ systems and cause material system failures. In addition, our threat researchers periodically identify vulnerabilities in various third-party products, and, if these identifications are perceived to be incorrect or are in fact incorrect, this could harm our business. Any such false identification or perceived false identification of important files, applications or vulnerabilities could result in negative publicity, loss of end-customers and sales, increased costs to remedy any problem and costly litigation.

Our ability to sell our products is dependent on our quality control processes and the quality of our technical support services, and our failure to offer high-quality technical support services could have a material adverse effect on our sales and results of operations.

Once our products are deployed within our end-customers’ networks, our end-customers depend on our technical support services, as well as the support of our channel partners and other third parties, to resolve any issues relating to our products. If we, our channel partners or other third parties do not effectively assist our customers in planning, deploying and operational proficiency for our products, succeed in helping our customers quickly resolve post-deployment issues and provide effective ongoing support, our ability to sell additional products and services to existing customers could be adversely affected and our reputation with potential customers could be damaged. Many large end-customers, and service provider or government organization end-customers, require higher levels of support than smaller end-customers because of their more complex
34

Table of Contents

deployments and more demanding environments and business models. If we, our channel partners or other third parties fail to meet the requirements of our larger end-customers, it may be more difficult to execute on our strategy to increase our penetration with large businesses, service providers and government organizations. Our failure to maintain high-quality support services could have a material adverse effect on our business, financial condition and results of operations and may subject us to litigation, reputational damage, loss of customers and additional costs.

Our business is subject to the risks of warranty claims, product returns, product liability and product defects.

Our products are very complex and, despite testing prior to their release, have contained and may contain undetected defects or errors, especially when first introduced or when new versions are released. Product errors have affected the performance and effectiveness of our products and could delay the development or release of new products or new versions of products, adversely affect our reputation and our end-customers’ willingness to buy products from us, result in litigation and disputes with customers and adversely affect market acceptance or perception of our products. Any such errors or delays in releasing new products or new versions of products or allegations of unsatisfactory performance could cause us to lose revenue or market share, increase our service costs, cause us to incur substantial costs in redesigning the products, cause us to lose significant end-customers, subject us to litigation, litigation costs and liability for damages and divert our resources from other tasks, any one of which could materially and adversely affect our business, results of operations and financial condition. Our products must successfully interoperate with products from other vendors. As a result, when problems occur in a network, it may be difficult to identify the sources of these problems. The occurrence of hardware and software errors, whether or not caused by our products, could delay or reduce market acceptance of our products and have an adverse effect on our business and financial performance, and any necessary revisions may cause us to incur significant expenses. The occurrence of any such problems could harm our business, financial condition and results of operations.
 
Although we generally have limitation of liability provisions in our standard terms and conditions of sale, they may not fully or effectively protect us from claims if exceptions apply or if the provisions are deemed unenforceable, and in some circumstances, we may be required to indemnify a customer in full, without limitation, for certain liabilities, including liabilities that are not contractually limited. The sale and support of our products also entail the risk of product liability claims. We maintain insurance to protect against certain claims associated with the use of our products, but our insurance coverage may not adequately cover any claim asserted against us, if at all, and in some instances may subject us to potential liability that is not contractually limited. In addition, even claims that ultimately are unsuccessful could result in our expenditure of funds in litigation and divert management’s time and other resources. Changes to our warranty reserve estimates could materially impact our gross margins and operating results.

If the availability of our cloud-based subscription services does not meet our service-level commitments to our customers, our current and future revenue may be negatively impacted.

We typically commit to our customers that our cloud-based subscription services will maintain a minimum service-level of availability. If we are unable to meet these commitments, this could negatively impact our business. We rely on public cloud providers, such as Amazon Web Services, Microsoft Azure and Google Cloud colocation providers, such as Equinix, and our own data centers and PoPs, and any availability interruption in any of these cloud solutions could result in us not meeting our service-level commitments to our customers. In some cases, we may not have a contractual right with our public cloud or colocation providers that compensates us for any losses due to availability interruptions in our cloud-based subscription services. Further, any failure to meet our service-level commitments could damage our reputation and adoption of our cloud-based subscription services, and we could face loss of revenue from reduced future subscriptions and reduced sales and face additional costs associated with any failure to meet service-level agreements. Any service-level failures could adversely affect our business, financial condition and results of operations.

Risks Related to our Systems and Technology

If we do not appropriately manage any future growth, including through the expansion of our real estate facilities, or are unable to improve our systems, processes and controls, our operating results will be negatively affected.
 
We rely heavily on information technology to help manage critical functions such as order configuration, pricing and quoting, revenue recognition, financial forecasts, inventory and supply chain management and trade compliance reviews. In addition, we have been slow to adopt and implement certain automated functions, which could have a negative impact on our business. For example, our order processing relies on both manual data entry of customer purchase orders received through email and electronic data interchange. Due to the use of manual processes and the fact that we may receive a large volume of our orders in the last few weeks of any given quarter, an interruption in our email service or other systems could result in delayed order fulfillment and decreased billings and revenue for that quarter.
35

Table of Contents

To manage any future growth effectively, we must continue to improve and expand our information technology and financial, operating, security and administrative systems and controls, and our business continuity and disaster recovery plans and processes. We must also continue to manage headcount, capital and processes in an efficient manner. We may not be able to successfully implement requisite improvements to these systems, controls and processes, such as system capacity, access, security and change management controls, in a timely or efficient manner. Our failure to improve our systems and processes, or their failure to operate in the intended manner, whether as a result of the significant growth of our business or otherwise, may result in our inability to manage the growth of our business and to accurately forecast our revenue, expenses and earnings, or to prevent certain losses. Moreover, the failure of our systems and processes could undermine our ability to provide accurate, timely and reliable reports on our financial and operating results and could impact the effectiveness of our internal control over financial reporting. In addition, our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud.

Our productivity and the quality of our products and services may also be adversely affected if we do not integrate and train our new employees quickly and effectively. Any future growth would add complexity to our organization and require effective coordination throughout our organization. Failure to ensure appropriate systems, processes and controls and to manage any future growth effectively could result in increased costs and harm our reputation and results of operations.

We have expanded our office real estate holdings to meet our projected growing need for office space. These plans will require significant capital expenditure over the next several years and involve certain risks, including impairment charges and acceleration of depreciation, changes in future business strategy that may decrease the need for expansion (such as a decrease in headcount or increase in work from home) and risks related to construction. Future changes in growth or fluctuations in cash flow may also negatively impact our ability to pay for these projects or free cash flow. Additionally, inaccuracies in our projected capital expenditures could negatively impact our business, operating results and financial condition.
 
We may experience difficulties maintaining and expanding our internal business management systems.
 
The maintenance of our internal business management systems, such as our Enterprise Resource Planning (“ERP”) and Customer Relationship Management (“CRM”) systems, has required, and will continue to require, the investment of significant financial and human resources. In addition, we may choose to upgrade or expand the functionality of our internal systems, leading to additional costs. Deficiencies in our design or maintenance of our internal systems may adversely affect our ability to sell products and services, forecast orders, process orders, ship products, provide services and customer support, send invoices and track payments, fulfill contractual obligations, accurately maintain books and records, provide accurate, timely and reliable reports on our financial and operating results or otherwise operate our business. Additionally, if any of our internal systems does not operate as intended, the effectiveness of our internal control over financial reporting could be adversely affected or our ability to assess it adequately could be delayed. Further, we may expand the scope of our ERP and CRM systems. Our operating results may be adversely affected if these upgrades or expansions are delayed or if the systems do not function as intended or are not sufficient to meet our operating requirements.

We may not be successful in our artificial intelligence initiatives, which could adversely affect our business, reputation, or financial results.

AI presents new risks and challenges that may affect our business. We have made, and expect to continue to make investments to integrate AI and ML technology into our solutions, as evidenced by our acquisition of Lacework. AI presents risks, challenges, and potentially unintended consequences that could impact our ability to effectively use AI successfully in our business. Given the nature of AI technology, we face an evolving regulatory landscape and significant competition from other companies. Our AI efforts may not be successful and our competitors may incorporate AI into their products more quickly or more successfully than us, which could impair our ability to compete effectively, reduce demand for our products and services and adversely affect our financial results. Increased competition from other companies implementing AI more effectively or rapidly could impact customer preferences and reduce demand for our products or services. Data practices by us or others, AI governance, AI development and validation practices that result in controversy could also impair the acceptance of AI solutions. This in turn could undermine confidence in the decisions, predictions, analysis, and effectiveness of our AI-related initiatives. In addition, vulnerabilities within our AI systems or solutions may be identified by competitors, researchers, or malicious actors before we detect or remediate them, which could result in security incidents, reputational damage, or loss of customer confidence.

The rapid evolution of AI, including potential government regulation of AI, may require significant additional resources related to AI in our solutions. Our AI-related initiatives may result in new or enhanced governmental or regulatory
36

Table of Contents

scrutiny, including regarding the use of AI in our solutions and the marketing of products using AI, litigation, customer reporting or documentation requirements, ethical or social concerns, or other complications. For example, AI technologies, including generative AI, may create content that appears correct but is factually inaccurate (hallucinations) or flawed, or contains copyrighted or other protected material, and if our customers or others use this flawed content to their detriment, or use our AI solutions outside of their intended use cases with an adverse impact to their operations, we may be exposed to brand or reputational harm, competitive harm, or legal liability. If customer data is used to train AI based systems and such data is not adequately anonymized, this may lead to breach of sensitive information and loss of customer trust. The use of AI also brings ethical issues related to privacy, surveillance and consent of use, as well as potential for bias and discrimination. Any of the foregoing could adversely affect our business, reputation, or financial results.

The use of AI technology in our IT infrastructure could improve internal process but poses security and privacy risks.

The adoption of AI in internal processes presents an opportunity to bolster decision making, productivity and customer satisfaction, but the new technology poses risks. AI can be exploited by hackers and malicious actors to develop advanced cyberattacks, bypass security measures, and exploit system vulnerabilities including potentially identifying weaknesses in our systems before we become aware of or can remediate them. The use of AI involves handling large amounts of data. If the security measures around the usage of AI are insufficient, there’s risk of data breaches, leading to unauthorized access to sensitive information. Failure to comply with data protection regulations (such as GDPR or the California Consumer Privacy Act (the “CCPA”) and DORA) can result in legal consequences. The intellectual property risks associated with AI include uncertainties around the ownership of AI-generated works, potential infringement of existing patents and copyrights, unauthorized use of third-party data, and exposure of proprietary algorithms or trade secrets. Dependence on AI systems or AI vendors means that any downtime or outages can disrupt business operations. Usage of our confidential data to train AI models by us or our vendors could result in legal risk, especially if it involves customer data. Other risks that have been observed in AI models and documentation, include risks related to bias, discrimination, job displacements and violating human rights.

Risks Related to our Intellectual Property

Our proprietary rights may be difficult to enforce and we may be subject to claims by others that we infringe their propriety technology.
 
We rely primarily on patent, trademark, copyright and trade secrets laws and confidentiality procedures and contractual provisions to protect our technology. Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to protect our technology or products. Any issued patents may be challenged, invalidated or circumvented, and any rights granted under these patents may not actually provide adequate defensive protection or competitive advantages to us. Patent applications in the United States are typically not published until at least 18 months after filing, or, in some cases, not at all, and publications of discoveries in industry-related literature lag behind actual discoveries. We cannot be certain that we were the first to make the inventions claimed in our pending patent applications or that we were the first to file for patent protection. Additionally, the process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner. In addition, recent changes to the patent laws in the United States may bring into question the validity of certain software patents and may make it more difficult and costly to prosecute patent applications. As a result, we may not be able to obtain adequate patent protection or effectively enforce our issued patents.
 
Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our products or obtain and use information that we regard as proprietary. We generally enter into confidentiality or license agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot guarantee that the steps taken by us will prevent misappropriation of our technology. Policing unauthorized use of our technology or products is difficult. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States. From time to time, legal action by us may be necessary to enforce our patents and other IP rights, to protect our trade secrets, to determine the validity and scope of the proprietary rights of others or to defend against claims of infringement or invalidity. Such litigation could result in substantial costs and diversion of resources and could negatively affect our business, operating results and financial condition. If we are unable to protect our proprietary rights (including aspects of our software and products protected other than by patent rights), we may find ourselves at a competitive disadvantage to others who need not incur the additional expense, time and effort required to create the innovative products that have enabled us to be successful to date.

37

Table of Contents

Our products contain third-party open-source software components, and failure to comply with the terms of the underlying open-source software licenses could restrict our ability to sell our products or result in loss of IP.
 
Our products contain software modules licensed to us by third-party authors under “open source” licenses, including but not limited to, the GNU Public License, the GNU Lesser Public License, the BSD License, the Apache License, the MIT X License and the Mozilla Public License. From time to time, there have been claims against companies that distribute or use open-source software in their products and services, asserting that open-source software infringes the claimants’ IP rights. We could be subject to suits by parties claiming infringement of IP rights in what we believe to be licensed open-source software. Use and distribution of open-source software may entail greater risks than use of third-party commercial software, as, for example, open-source licensors generally do not provide warranties or other contractual protections regarding infringement claims or the quality of the code. Some open-source licenses contain requirements that we make available source code for modifications or derivative works we create based upon the type of open-source software we use. If we combine our proprietary software with open-source software in a certain manner, we could, under certain open-source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar products with lower development effort and time and ultimately could result in a loss of product sales for us.
 
Although we monitor our use of open source software to avoid subjecting our products to conditions we do not intend, the terms of many open source licenses have not been interpreted by U.S. courts, and there is a risk that these licenses could be construed in a way that, for example, could impose unanticipated conditions or restrictions on our ability to commercialize our products. In this event, we could be required to seek licenses from third parties to continue offering our products, to make our proprietary code generally available in source code form, to re-engineer our products or to discontinue the sale of our products if re-engineering could not be accomplished on a timely basis, any of which requirements could adversely affect our business, operating results and financial condition.
 
Claims by others that we infringe their proprietary technology or other litigation matters could harm our business.
 
Patent and other IP disputes are common in the network security industry. Third parties are currently asserting, have asserted and may in the future assert claims of infringement of IP rights against us. Third parties have also asserted such claims against our end-customers or channel partners whom we may indemnify against claims that our products infringe the IP rights of third parties. As the number of products and competitors in our market increases and overlaps occur, infringement claims may increase. Any claim of infringement by a third party, even those without merit, could cause us to incur substantial costs defending against the claim and could distract our management from our business. In addition, litigation may involve patent holding companies, non-practicing entities or other adverse patent owners who have no relevant product revenue and against whom our own patents may therefore provide little or no deterrence or protection.
 
Although third parties may offer a license to their technology, the terms of any offered license may not be acceptable, and the failure to obtain a license or the costs associated with any license could cause our business, financial condition and results of operations to be materially and adversely affected. In addition, some licenses may be non-exclusive and, therefore, our competitors may have access to the same technology licensed to us.
 
Alternatively, we may be required to develop non-infringing technology, which could require significant time, effort and expense, and may ultimately not be successful. Furthermore, a successful claimant could secure a judgment or we may agree to a settlement that prevents us from distributing certain products or performing certain services or that requires us to pay substantial damages (including treble damages if we are found to have willfully infringed such claimant’s patents or copyrights), royalties or other fees. Any of these events could seriously harm our business, financial condition and results of operations.

From time to time, we are subject to lawsuits claiming patent infringement. We are also subject to other litigation in addition to patent infringement claims, such as employment-related litigation and disputes, as well as general commercial litigation, and could become subject to other forms of litigation and disputes, including stockholder litigation. If we are unsuccessful in defending any such claims, our operating results and financial condition and results may be materially and adversely affected. For example, we may be required to pay substantial damages and could be prevented from selling certain of our products. Litigation, with or without merit, could negatively impact our business, reputation and sales in a material fashion.

We have several ongoing patent lawsuits, certain companies have sent us demand letters proposing that we license certain of their patents, and organizations have sent letters demanding that we provide indemnification for patent claims. Given this and the proliferation of lawsuits in our industry and other similar industries by both non-practicing entities and operating entities, and recent non-practicing entity and operating entity patent litigation against other companies in the security space, we expect that we will be sued for patent infringement in the future, regardless of the merits of any such lawsuits. The cost to
38

Table of Contents

defend such lawsuits and any settlement payment or adverse result in such lawsuits could have a material adverse effect on our results of operations and financial condition.

We rely on the availability of third-party licenses.

Many of our products include software or other IP licensed from third parties. It may be necessary in the future to renew licenses relating to various aspects of these products or to seek new licenses for existing or new products. Licensors may claim we owe them additional license fees for past and future use of their software and other IP or that we cannot utilize such software or IP in our products going forward. There can be no assurance that the necessary licenses would be available on acceptable terms, if at all. The inability to obtain certain licenses or other rights or to obtain such licenses or rights on favorable terms or for reasonable pricing, or the need to engage in litigation regarding these matters, could result in delays in product releases until equivalent technology can be identified, licensed or developed, if at all, and integrated into our products and may result in significant license fees and have a material adverse effect on our business, operating results, and financial condition. Moreover, the inclusion in our products of software or other IP licensed from third parties on a non-exclusive basis could limit our ability to differentiate our products from those of our competitors.

We also rely on technologies licensed from third parties in order to operate functions of our business. If any of these third parties allege that we have not properly paid for such licenses or that we have improperly used the technologies under such licenses, we may need to pay additional fees or obtain new licenses, and such licenses may not be available on terms acceptable to us or at all or may be costly. In any such case, or if we were required to redesign our internal operations to function with new technologies, our business, results of operations and financial condition could be harmed.

Other Risks Related to Our Business and Financial Position

Our inability to successfully acquire and integrate other businesses, products or technologies, or to successfully invest in and form successful strategic alliances with other businesses, could seriously harm our competitive position and could negatively affect our financial condition and results of operations.

In order to remain competitive, we may seek to acquire additional businesses, products, technologies or IP, such as patents, and to make equity investments in businesses coupled with strategic alliances. F or any possible future acquisitions or investments, we may not be successful in negotiating the terms of the acquisition or investment or financing the acquisition or investment. For both our prior and future acquisitions, we may not be successful in effectively integrating the acquired business, product, technology, IP or sales force into our existing business and operations, and the acquisitions may negatively impact our financial results. We may have difficulty incorporating acquired technologies, IP or products with our existing product lines, integrating reporting systems and procedures, and maintaining uniform standards, controls, development practices, procedures and policies. For example, we may experience difficulties integrating an acquired company’s ERP or CRM systems, SaaS delivery systems, sales support, cyber risk management and compliance and other processes and systems, with our current systems and processes. We may also find that the personnel of the companies we acquire do not adequately adhere to our corporate policies and it may take time to bring them in line with our policies and standards. If we are unable to do so efficiently or effectively, our reputation and business, operating results and financial condition could be adversely impacted.

The results of certain businesses that we invest in are, or may in the future, be reflected in our operating results, and we depend on these companies to provide us financial information in a timely manner in order to meet our financial reporting requirements. We may experience difficulty in timely obtaining financial information from the companies in which we have invested in order to meet our financial reporting requirements. Further, we are required to record goodwill and intangible assets that are subject to impairment testing on a regular basis and potential periodic impairment charges, which may adversely affect our financial condition and results of operations. Our due diligence for acquisitions and investments may fail to identify all of the problems, liabilities or other shortcomings or challenges of an acquired business, product or technology, including issues with IP, product quality or product architecture, regulatory compliance practices, environmental and sustainability compliance practices, revenue recognition or other accounting practices or employee or customer issues. We also may not accurately forecast the financial impact of an acquisition or an investment and alliance. In addition, any acquisitions and significant investments we are able to complete may be dilutive to revenue growth and earnings and may not result in any synergies or other benefits we had expected to achieve, which could negatively impact our operating results and result in impairment charges that could be substantial. We may have to pay cash, incur debt or issue equity securities to pay for any acquisition, each of which could affect our financial condition or the value of our capital stock and could result in dilution to our stockholders. Acquisitions or investments during a quarter may result in increased operating expenses and adversely affect our cash flows or our results of operations for that period and future periods compared to the results that we have previously forecasted or achieved. Further, completing a potential acquisition or investment and alliance and integrating acquired businesses, products, technologies or IP are challenging to do successfully and could significantly divert management time and resources.
39

Table of Contents

Failure to comply with laws and regulations applicable to our business could subject us to fines and penalties and could also cause us to lose end-customers or negatively impact our ability to contract.

Our business is subject to regulation by various federal, state, regional, local and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, product safety, product labeling, environmental laws, consumer protection laws, anti-bribery laws, data privacy laws, import and export controls, federal securities laws and tax laws and regulations. In certain jurisdictions, these regulatory requirements may be more stringent than in the United States. Non-compliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, disgorgement of profits, fines, damages and civil and criminal penalties or injunctions. If any governmental sanctions are imposed, or if we do not prevail in any possible civil or criminal litigation, our business, operating results and financial condition could be adversely affected. In addition, responding to any action will likely result in a significant diversion of management’s attention and resources and an increase in professional fees. Enforcement actions and sanctions could harm our business, operating results and financial condition.

For example, the GDPR imposes stringent data handling requirements on companies that operate in the EU or receive or process personal data about individuals in the EU in certain contexts. Non-compliance with the GDPR could result in data protection audits and significant penalties, heavy fines imposed on us and bans on other businesses’ use of our services. Compliance with, and the other burdens imposed by, the GDPR and local regulatory authorities may limit our ability to operate or expand our business in the EU and could adversely impact our operating results. In July 2020, the European Court of Justice issued a judgment declaring invalid the EU-U.S. Privacy Shield Framework (the “Privacy Shield”) as a mechanism for the transfer of GDPR-regulated personal data to recipients in the United States and calling into question the validity of certain popular alternative mechanisms for addressing GDPR restrictions on transfers to the United States and other areas where we operate. The Privacy Shield has now been replaced with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework (collectively, the “Framework”) following certain changes to U.S. law intended to address the concerns underlying that court decision with respect to transfers of personal data to the United States. We are an active participant in the Framework. However, there remains a possibility that our business could be negatively impacted by restrictions on transfers of GDPR-regulated personal data (including transfers made by our customers) to other areas we operate. In addition, it is possible that the Framework may ultimately be deemed insufficient in a court case similar to the one that invalidated Privacy Shield. The mere possibility of this outcome, and our reliance on global data transfers within our corporate family and between us and our service providers, may create challenges for us to compete with companies that may be able to offer services in which personal data never exits the EU, thereby avoiding risks of noncompliance with GDPR data transfer restrictions.

In addition to the GDPR, the EU has also enacted legislation that would regulate non-personal data and establish new cybersecurity standards, and other countries, including the U.K., may similarly do so in the future. In particular, the EU Data Act went into effect in 2024 and imposes certain data and cloud service interoperability and switching obligations to enable users to switch between cloud service providers (as well as certain requirements concerning cross-border international transfers of non-personal data outside the EEA). Additionally, the EU’s Network and Information Security Directive II, adopted in 2023, regulates resilience and incident response capabilities of entities operating in a number of sectors, including the digital infrastructure sector and provides for EU member states to have issued implementing legislation by October 2024. Further, DORA became effective in January 2025 and imposes certain requirements on entities in the financial sector and their third-party cloud service providers related to managing and mitigating information and communication technology risk. If we are unable to transfer data, including personal data, between and among countries and regions in which we operate, or are otherwise required to modify our practices, including our data privacy and security controls and procedures, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.

Additionally, we may be subject to other legal regimes throughout the world governing data handling, protection and privacy. For example, in June 2018, California passed the CCPA, which provides new data privacy rights for consumers and new operational requirements for companies and became effective on January 1, 2020. The CCPA was expanded pursuant to the California Privacy Rights Act, which was passed in 2020 and became effective in 2023. Other states have since passed similar laws, adding to the complexity of compliance with overlapping and sometimes conflicting requirements. The costs of compliance with and the penalties for violations of the GDPR, the CCPA and other laws, along with other burdens imposed by these regulations, may limit the use and adoption of our products and services and could have an adverse impact on our business. For example, our sales cycles may lengthen and face an increased risk of failure as customers take more time to vet our services for compliance with these legal requirements and to negotiate data-related contract terms with us, causing delays or loss of revenue.

Selling our solutions to governments, both within the U.S and internationally, whether directly or through channel partners, also subjects us to certain regulatory and contractual requirements, government permit and clearance requirements and
40

Table of Contents

other risks. Failure to comply with these requirements or to obtain and maintain government permits and clearances required to do certain business, by either us or our channel partners, could subject us to investigations, fines, suspension, limitations on business or debarment from doing business with such governments, as well as other penalties, damages and reputational harms, which could have an adverse effect on our business, operating results, financial condition and prospects. Any violations of regulatory and contractual requirements could result in us being suspended or debarred from future government contracting. Any of these outcomes could have an adverse effect on our revenue, operating results, financial condition and prospects.

The landscape of laws, regulations, and industry standards related to cybersecurity is evolving globally. We may be subject to increased compliance burdens by regulators and customers with respect to our products and services, as well as additional costs to oversee and monitor security risks. Additionally, this evolving global landscape could impact on our ability to conduct business in certain jurisdictions if the laws, regulation and industry standards in such jurisdictions changed in a manner that is adverse to our business. Many jurisdictions have enacted laws mandating companies to inform individuals, stockholders, regulatory authorities, and others of security incidents. For example, the SEC recently adopted cybersecurity risk management and disclosure rules, which require the disclosure of information pertaining to cybersecurity incidents and cybersecurity risk management, strategy, and governance. In addition, certain of our customer agreements may require us to promptly report security incidents involving their data on our systems or those of subcontractors processing such data on our behalf. This mandatory disclosure can be costly, harm our reputation, erode customer trust, reduce demand, and require significant resources to mitigate issues stemming from actual or perceived security incidents.

These laws, regulations and other requirements impose added costs on our business, and failure to comply with these or other applicable regulations and requirements, including non-compliance in the past, could lead to claims for damages from our channel partners, penalties, termination of contracts, loss of exclusive rights in our IP and temporary suspension, permanent debarment from government contracting, or other limitations on doing business. Any such damages, penalties, disruptions or limitations in our ability to do business could have an adverse effect on our business and operating results.

We are currently, and may in the future become, involved in litigation that may adversely affect us.

We are regularly subject to claims, suits and government investigations and other proceedings including patent, product liability, class action, personal injury, property damage, labor and employment, commercial disputes, securities litigation, compliance with laws and regulatory requirements and other matters, and we may become subject to additional types of claims, suits, investigations and proceedings as our business expands. Such claims, suits and government investigations and proceedings are inherently uncertain and their results cannot be predicted with certainty. Regardless of the outcome, any of these types of legal proceedings can have an adverse impact on us because of legal costs and diversion of management attention and resources, and could cause us to incur significant expenses or liability, adversely affect our brand recognition and/or require us to change our business practices. The expense of litigation and the timing of this expense from period to period are difficult to estimate, subject to change and could adversely affect our results of operations. It is possible that a resolution of one or more such proceedings could result in substantial damages, settlement costs, fines and penalties that could adversely affect our business, consolidated financial position, results of operations or cash flows in a particular period. These proceedings could also result in reputational harm, sanctions, consent decrees or orders requiring a change in our business practices. Because of the potential risks, expenses and uncertainties of litigation, we may, from time to time, settle disputes, even where we have meritorious claims or defenses, by agreeing to settlement agreements. Because litigation is inherently unpredictable, we cannot assure you that the results of any of these actions will not have a material adverse effect on our business, financial condition, results of operations, and prospects. Any of these consequences could adversely affect our business and results of operations. For additional information regarding our litigation, claims and related contingencies, see Note 11. Commitments and Contingencies, of our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.

We are subject to governmental export and import controls that could subject us to liability or restrictions on sales, and that could impair our ability to compete in international markets.

Because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the United States only with the required export license or through an export license exception, or may be prohibited altogether from export to certain countries. If we were to fail to comply with U.S. export laws, U.S. Customs regulations and import regulations, U.S. economic sanctions and other countries’ import and export laws, we could be subject to substantial civil and criminal penalties, including fines for the company and incarceration for responsible employees and managers, and the possible loss of export or import privileges. In addition, if our channel partners fail to obtain appropriate import, export or re-export licenses or permits (e.g., for stocking orders placed by our partners), we may also be adversely affected through reputational harm and penalties and we may not be able to provide support related to appliances shipped pursuant to such orders. Obtaining the necessary export license for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities.

41

Table of Contents

Furthermore, U.S. export control laws and economic sanctions prohibit the shipment of certain products to U.S. embargoed or sanctioned countries, governments and persons, such as the sanctions and trade restrictions that have been implemented against Russia and Belarus. Even though we take precautions to prevent our product from being shipped to U.S. sanctions targets, our products could be shipped to those targets by our channel partners, despite such precautions. Any such shipment could have negative consequences including government investigations and penalties and reputational harm. In addition, various countries regulate the import of certain encryption technology, including import permitting and licensing requirements, and have enacted laws that could limit our ability to distribute our products or could limit our customers’ ability to implement our products in those countries. Changes in our products or changes in export and import regulations may create delays in the introduction of our products in international markets, prevent our customers with international operations from deploying our products globally or, in some cases, prevent the export or import of our products to certain countries, governments or persons altogether. Any change in export or import regulations, economic sanctions or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons or technologies targeted by such regulations, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential customers with international operations. Any decreased use of our products or limitation on our ability to export or sell our products would likely adversely affect our business, financial condition and results of operations.

If we fail to comply with environmental requirements, our business, financial condition, operating results and reputation could be adversely affected.

We are subject to various environmental laws and regulations, including laws governing the hazardous material content of our products, laws relating to our real property and future expansion plans and laws concerning the recycling and packaging of Electrical and Electronic Equipment. The laws and regulations to which we are subject include the EU RoHS Directive, EU Regulation 1907/2006 – Registration, Evaluation, Authorization and Restriction of Chemicals (the “REACH” Regulation) and the EU Waste Electrical and Electronic Equipment Directive (the “WEEE Directive”), as well as the implementing legislation of the EU member states. Similar laws and regulations have been passed or are pending in China, South Korea, Taiwan, Japan, Norway, Saudi Arabia and the UAE and may be enacted in other regions, including in the United States, and we are, or may in the future be, subject to these laws and regulations. These legal and regulatory regimes, including the laws, rules and regulations thereunder, evolve frequently and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another. Moreover, the timing and effect of these laws and regulations on our business may be uncertain. To the extent we have not complied with such laws, rules and regulations, we could be subject to significant fines, revocation of licenses, limitations on our products and services, reputational harm and other regulatory consequences, each of which may be significant and could adversely affect our business, operating results and financial condition. These laws and regulations may also impact our suppliers, which could have, among other things, an adverse impact on the costs of components in our products.

The EU RoHS Directive and the similar laws of other jurisdictions ban or restrict the presence of certain hazardous substances such as lead, mercury, cadmium, hexavalent chromium and certain fire-retardant plastic additives in electrical equipment, including our products. We have incurred costs to comply with these laws, including research and development costs and costs associated with assuring the supply of compliant components. We expect to continue to incur costs related to environmental laws and regulations in the future. With respect to the EU RoHS, we and our competitors rely on exemptions for lead and other substances in network infrastructure equipment. It is possible one or more of these use exemptions will be revoked in the future. Additionally, although some of the EU RoHS exemptions have been extended, it is possible that some of these exemptions may expire in the future without being extended. If this exemption is revoked or expires without extension, if there are other changes to these laws (or their interpretation) or if new similar laws are passed in other jurisdictions, we may be required to re-engineer our products to use components compatible with these regulations. This re-engineering and component substitution could result in additional costs to us and/or disrupt our operations or logistics.

As part of the Circular Economy Action Plan, the European Commission amended the EU Waste Framework Directive (“WFD”) to include a number of measures related to waste prevention and recycling, whereby we are responsible for submitting product data to a Substances of Concern In articles as such or in complex objects (Products) (“SCIP”) database containing information on Substances of Very High Concern in articles and in complex objects. The SCIP database is established under the WFD and managed by the European Chemicals Agency. We have incurred costs in order to comply with this new requirement. Similar laws and regulations have been passed or are pending in the European Economic Area and the UK.

The EU’s WEEE Directive requires electronic goods producers to be responsible for the collection, recycling and treatment of such products. Although currently our EU international channel partners are responsible for the requirements of this directive as the importer of record in most of the European countries in which we sell our products, changes in interpretation of the regulations may cause us to incur costs or have additional regulatory requirements in the future to meet in order to comply with this directive, or with any similar laws adopted in other jurisdictions including the United States.
42

Table of Contents

Additional regulations involving single-use plastics in packaging resulting in import taxes in certain countries in the EU have resulted in additional costs to source appropriate packaging for hardware. Alternatively, for our cloud based systems, new EU energy efficiency laws relating to the power usage effectiveness and emerging water usage regulations of data centers will require us to source specific data centers or retrofit existing ones to meet the stringent energy efficiency requirements.

Our failure to comply with these and future environmental rules and regulations could result in decreased demand for our products and services resulting in reduced sales of our products, increased demand for competitive products and services that result in lower emissions than our products, increased costs, substantial product inventory write-offs, reputational damage, penalties and other sanctions, any of which could harm our business and financial condition. To date, our expenditures for environmental compliance have not had a material impact on our operating results or cash flows, and, although we cannot predict the future impact of such laws or regulations, they will likely result in additional costs. New laws may result in increased penalties associated with violations or require us to change the content of our products or how they are manufactured, which could have a material adverse effect on our business, operating results and financial condition.

Investors’ expectations of our performance relating to corporate responsibility and sustainability factors may impose additional costs and expose us to new risks.

Certain investors, employees, customers and other stakeholders have a focus on corporate responsibility. Some investors may use these non-financial performance factors to guide their investment strategies and, in some cases, may choose not to invest in us if they believe our policies and actions relating to corporate responsibility are inadequate. Investor demand for measurement of non-financial performance is addressed by third-party providers of sustainability assessment and ratings on companies. The criteria by which our corporate responsibility practices are assessed may change due to the constant evolution of the global sustainability landscape, which could result in greater expectations of us and cause us to undertake costly initiatives to satisfy such new criteria. If we elect not to or are unable to satisfy such new criteria, investors may conclude that our policies and/or actions with respect to corporate social responsibility are inadequate and we may be subject to fines from regulatory authorities. We may face reputational damage in the event that we do not meet the standards set by various constituencies.

Furthermore, in the event that we communicate certain initiatives and goals regarding corporate responsibility and sustainability matters, we could fail, or be perceived to fail, in our achievement of such initiatives or goals, or we could be criticized for the scope, target and timelines of such initiatives or goals. If we fail to satisfy the expectations of investors, customers, employees, and other stakeholders or our initiatives are not executed as planned, our reputation and business, operating results and financial condition could be adversely impacted.

Risks Related to Finance, Accounting and Tax Matters

If our estimates or judgments relating to our critical accounting policies are based on assumptions that change or prove to be incorrect, our operating results could fall below expectations of securities analysts and investors, resulting in a decline in our stock price.
 
The preparation of financial statements in conformity with generally accepted accounting principles requires management to make estimates and assumptions that affect the amounts reported in the consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, as provided in “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Critical Accounting Policies and Estimates” in this Annual Report on Form 10-K, the results of which form the basis for making judgments about the carrying values of assets and liabilities that are not readily apparent from other sources. Our operating results may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our operating results to fall below the expectations of securities analysts and investors, resulting in a decline in our stock price. Significant assumptions and estimates used in preparing our consolidated financial statements include those related to revenue recognition, deferred contract costs and commission expense, accounting for business combinations, contingent liabilities and accounting for income taxes.

We are exposed to fluctuations in currency exchange rates, which could negatively affect our financial condition and results of operations.

A significant portion of our operating expenses are incurred outside the United States. These expenses are denominated in foreign currencies and are subject to fluctuations due to changes in foreign currency exchange rates, particularly changes in the Euro, Japanese yen, Canadian dollar and British pound. A weakening of the U.S. dollar compared to foreign currencies would negatively affect our expenses and operating results, which are expressed in U.S. dollars. While we are not currently engaged in material hedging activities, we have been hedging currency exposures relating to certain balance sheet accounts through the use of forward exchange contracts. If we stop hedging against any of these risks or if our attempts to
43

Table of Contents

hedge against these currency exposures are not successful, our financial condition and results of operations could be adversely affected. Our sales contracts are primarily denominated in U.S. dollars and therefore, while substantially all of our revenue is not subject to foreign currency risk, it does not serve as a hedge to our foreign currency-denominated operating expenses. In addition, a strengthening of the U.S. dollar may increase the real cost of our products to our customers outside of the United States, which may also adversely affect our financial condition and results of operations. 

We could be subject to changes in our tax rates, the adoption of new U.S. or international tax legislation, exposure to additional tax liabilities or impacts from the timing of tax payments.

We are subject to taxes in the United States and numerous foreign jurisdictions, where a number of our subsidiaries are organized. Our provision for income taxes is subject to volatility and could be adversely affected by several factors, many of which are outside of our control. These include:

• the mix of earnings in countries with differing statutory tax rates or withholding taxes;

• changes in the valuation of our deferred tax assets and liabilities;

• transfer pricing adjustments;

• increases to corporate tax rates;

• an increase in non-deductible expenses for tax purposes, including certain stock-based compensation expense;

• changes in availability of tax credits and/or tax deductions;

• the timing of tax payments;

• tax costs related to intercompany realignments;

• tax assessments resulting from income tax audits or any related tax interest or penalties that could significantly affect our provision for income taxes for the period in which the settlement takes place; and

• changes in accounting principles, court decisions, tax rulings, and interpretations of or changes to tax laws, and regulations by international, federal or local governmental authorities.

We have open tax years that could be subject to the examination by the Internal Revenue Service (the “IRS”) and other tax authorities. We currently have ongoing tax audits in the United Kingdom, Canada, Germany and several other foreign jurisdictions. The focus of all of these audits is the allocation of profits among our legal entities. We regularly assess the likelihood of adverse outcomes resulting from such examinations to determine the adequacy of our provision for income taxes. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded in our consolidated financial statements and may materially affect our financial results.

We may undertake corporate operating restructurings or transfers of assets that involve our group of foreign country subsidiaries through which we do business abroad, in order to maximize the operational and tax efficiency of our group structure. If ineffectual, such restructurings or transfers could increase our income tax liabilities, and in turn, increase our global effective tax rate. Moreover, our existing corporate structure and intercompany arrangements have been implemented in a manner we believe reasonably ensures that we are in compliance with current prevailing tax laws. However, the tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed technology or intercompany arrangements, which could impact our worldwide effective tax rate and harm our financial position and operating results.

Significant judgment is required in determining any valuation allowance recorded against deferred tax assets. In assessing the need for a valuation allowance, we consider all available evidence, including past operating results, estimates of future taxable income and the feasibility of tax planning strategies. In the event that we change our determination as to the amount of deferred tax assets that can be realized, we will adjust our valuation allowance with a corresponding impact to the provision for income taxes in the period in which such determination is made.

44

Table of Contents

Forecasting our estimated annual effective tax rate is complex and subject to uncertainty, and there may be material differences between our forecasted and actual tax rates.

Forecasts of our income tax position and effective tax rate are complex, subject to uncertainty and periodic updates because our income tax position for each year combines the effects of a mix of profits earned and losses incurred by us in various tax jurisdictions with a broad range of income tax rates, as well as changes in the valuation of deferred tax assets and liabilities, the impact of various accounting rules and changes to these rules and tax laws, the results of examinations by various tax authorities, and the impact of any acquisition, business combination or other reorganization or financing transaction. To forecast our global tax rate, we estimate our pre-tax profits and losses by jurisdiction and forecast our tax expense by jurisdiction. If the mix of profits and losses, our ability to use tax credits or our effective tax rate in a given jurisdiction differs from our estimate, our actual tax rate could be materially different than forecasted, which could have a material impact on our results of business, financial condition and results of operations. Additionally, our actual tax rate may be subject to further uncertainty due to potential changes in U.S. and foreign tax rules.

As a multinational corporation, we conduct our business in many countries and are subject to taxation in many jurisdictions. The taxation of our business is subject to the application of multiple and sometimes conflicting tax laws and regulations, as well as multinational tax conventions. Our effective tax rate is highly dependent upon the geographic distribution of our worldwide earnings or losses, the tax regulations in each geographic region, the availability of tax credits and carryforwards and the effectiveness of our tax planning strategies. The application of tax laws and regulations is subject to legal and factual interpretation, judgment and uncertainty. Tax laws themselves are subject to change as a result of changes in fiscal policy, changes in legislation and the evolution of regulations and court rulings. Consequently, tax authorities may impose tax assessments or judgments against us that could materially impact our tax liability and/or our effective income tax rate.

The Organisation for Economic Co-operation and Development (the “OECD”), an international association comprised of 38 countries, including the United States, has issued and continues to issue guidelines and proposals that change various aspects of the existing framework under which our tax obligations are determined in many of the countries in which we do business. Due to our extensive international business activities, any changes in the taxation of such activities could increase our tax obligations in many countries and may increase our worldwide effective tax rate.

Risks Related to Ownership of Our Common Stock

As a public company, we are subject to compliance initiatives that will require substantial time from our management and result in significantly increased costs that may adversely affect our operating results and financial condition.

The Sarbanes-Oxley Act of 2002 (“Sarbanes-Oxley”), Dodd-Frank and other rules implemented by the SEC and The Nasdaq Stock Market impose various requirements on public companies, including requiring changes in corporate governance practices. These requirements, as well as proposed corporate governance laws and regulations under consideration, may further increase our compliance costs. If compliance with these various legal and regulatory requirements diverts our management’s attention from other business concerns, it could have a material adverse effect on our business, financial condition and results of operations. Sarbanes-Oxley requires, among other things, that we assess the effectiveness of our internal control over financial reporting annually, and of our disclosure controls and procedures quarterly. Although our most recent assessment, testing and evaluation resulted in our conclusion that, as of December 31, 2025, our internal controls over financial reporting were effective, we cannot predict the outcome of our testing in 2026 or future periods and there can be no assurance that, in the future, our internal controls over financial reporting will be effective or deemed effective. We may incur additional expenses and commitment of management’s time in connection with further evaluations, both of which could materially increase our operating expenses and accordingly reduce our operating results.

If equity research or industry analysts stop publishing research or reports about our business, issue unfavorable commentary, downgrade our shares of common stock or publish inaccurate information, our stock price and trading volume could decline.

The trading market for our common stock is influenced in part by the research and reports that equity research and industry analysts publish about us or our business. If one or more of these analysts ceases coverage of our company or fails to publish reports on us regularly, we could lose visibility in the financial markets, which in turn could cause our stock price or trading volume to decline. Furthermore, if one or more of these analysts downgrades our stock or issues unfavorable commentary about our business, the price of our stock could decline. We have in the past experienced downgrades and may in the future experience downgrades. In addition, these analysts may publish their own financial projections, which may vary widely and may not accurately predict the results we actually achieve, which in turn could cause our stock price to decline if our actual results do not match their projections. If one of these analysts were to publish inaccurate negative information about us or
45

Table of Contents

our business, our stock price could decline. Moreover, if securities analysts publish inaccurate positive information, stockholders could buy our stock and the stock price may later decline.
 
The trading price of our common stock may be volatile, which may be exacerbated by share repurchases under our Share Repurchase Program.
 
The market price of our common stock may be subject to wide fluctuations in response to, among other things, the risk factors described in this periodic report, news about us and our financial results, news about our competitors and their results, and other factors such as rumors or fluctuations in the valuation of companies perceived by investors to be comparable to us. For example, during 2025, the closing price of our common stock ranged from $74.39 to $114.57 per share.

 Furthermore, stock markets have experienced price and volume fluctuations that have affected and continue to affect the market prices of equity securities of many companies. These fluctuations often have been unrelated or disproportionate to the operating performance of those companies. These broad market and industry fluctuations, as well as general economic, geopolitical and market conditions, such as recessions, interest rate changes or international currency fluctuations, may negatively affect the market price of our common stock.
 
In the past, many companies that have experienced volatility in the market price of their stock have been subject to securities class action litigation. We currently are, and may be in the future, the target of this type of litigation in the future. Securities litigation against us could result in substantial costs and divert our management’s attention from other business concerns, which could seriously harm our business.

Share repurchases under the Repurchase Program could increase the volatility of the trading price of our common stock, could diminish our cash reserves, could occur at non-optimal prices and may not result in the most effective use of our capital.

In August 2025, our board of directors approved a $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program and extended the term of the Repurchase Program to February 28, 2027, and in January 2026, our board of directors approved an additional $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program, bringing the aggregate amount authorized to be repurchased to $10.25 billion of our outstanding common stock through February 28, 2027. As of February 24, 2026, approximately $1.27 billion remained available for future share repurchases. Share repurchases under the Repurchase Program could affect the price of our common stock, increase stock price volatility and diminish our cash reserves. In addition, an announcement of the reduction, suspension or termination of the Repurchase Program could result in a decrease in the trading price of our common stock. Moreover, our stock price could decline, resulting in repurchases made at non-optimal prices. Our failure to repurchase our stock at optimal prices may be perceived by investors as an inefficient use of our cash and cash equivalents, which could result in litigation that may have an adverse effect on our business, operating results and financial condition. In addition, while our board of directors carefully considers various alternative uses of our cash and cash equivalents in determining whether to authorize stock repurchases, there can be no assurance that the decision by our board of directors to repurchase stock would result in the most effective uses of our cash and cash equivalents, and there may be alternative uses of our cash and cash equivalents that would be more effective, such as investing in growing our business organically or through acquisitions.

Anti-takeover provisions contained in our certificate of incorporation and bylaws, as well as provisions of Delaware law, could impair a takeover attempt.
 
Our certificate of incorporation, bylaws and Delaware law contain provisions that could have the effect of rendering more difficult, delaying or preventing an acquisition deemed undesirable by our board of directors. Our corporate governance documents include provisions:

• authorizing “blank check” preferred stock, which could be issued by the board without stockholder approval and may contain voting, liquidation, dividend and other rights superior to our common stock;
 
• limiting the liability of, and providing indemnification to, our directors and officers;
 
• requiring advance notice of stockholder proposals for business to be conducted at meetings of our stockholders and for nominations of candidates for election to our board of directors;

• providing that certain litigation matters may only be brought against us in state or federal courts in the State of Delaware;
 
46

Table of Contents

• controlling the procedures for the conduct and scheduling of board and stockholder meetings; and
 
• providing the board of directors with the express power to postpone previously scheduled annual meetings and to cancel previously scheduled special meetings.
 
These provisions, alone or together, could delay or prevent hostile takeovers and changes in control or changes in our management.
 
In addition, our amended and restated bylaws provide that unless we consent in writing to the selection of an alternative forum, to the fullest extent permitted by law, the federal district courts of the United States shall be the exclusive forum for the resolution of any complaint asserting a cause of action arising under the Securities Act. Any person or entity purchasing or otherwise acquiring any interest in any of our securities shall be deemed to have notice of and consented to this provision. This provision, as well as provisions providing that certain litigation matters may only be brought against us in state or federal courts in the State of Delaware, may limit a stockholder’s ability to bring a claim in a judicial forum that it finds favorable for disputes with us or any of our directors, officers or other employees, which may discourage lawsuits against us and our directors, officers and other employees.

As a Delaware corporation, we are also subject to provisions of Delaware law, including Section 203 of the Delaware General Corporation Law, which prevents stockholders holding more than 15% of our outstanding common stock from engaging in certain business combinations without approval of the holders of a substantial majority of all of our outstanding common stock.
 
Any provision of our certificate of incorporation, bylaws or Delaware law that has the effect of delaying or deterring a change in control could limit the opportunity for our stockholders to receive a premium for their shares of our common stock, and could also affect the price that some investors are willing to pay for our common stock.

However, these anti-takeover provisions will not have the effect of preventing activist stockholders from seeking to increase short-term stockholder value through actions such as nominating board candidates and requesting that we pursue strategic combinations or other transactions. These actions could disrupt our operations, be costly and time-consuming and divert the attention of our management and employees. In addition, perceived uncertainties as to our future direction as a result of activist stockholder actions could result in the loss of potential business opportunities, as well as other negative business consequences. Actions of an activist stockholder may also cause fluctuations in our stock price based on speculative market perceptions or other factors that do not necessarily reflect our business. Further, we may incur significant expenses in retaining professionals to advise and assist us on activist stockholder matters, including legal, financial, communications advisors and solicitation experts, which may negatively impact our future financial results.

General Risks

Global economic uncertainty, an economic downturn, the possibility of a recession, inflation, changing interest rates, changes to government spending and regulations, and weakening product demand could adversely affect our business and financial performance.

Economic challenges caused by economic downturn, any resulting recession, inflation, GDP impact (both domestically and internationally) or change in interest rates can weaken and harm our financial position. The U.S. capital markets have experienced and continue to experience extreme volatility and disruption. Further deterioration of the macroeconomic environment and regulatory action may adversely affect our business, operating results and financial condition.

Political instability, changes in trade policies and agreements and conflicts could adversely affect our business and financial performance.

Economic uncertainty in various global markets caused by political instability and conflict, such as the war in Ukraine, tensions between China and Taiwan or conflicts in the Middle East has resulted, and may continue to result in weakened demand for our products and services and difficulty in forecasting our financial results and managing inventory levels. Geopolitical developments impacting government spending and international trade, including potential government shutdowns and trade disputes and tariffs may negatively impact markets and cause weaker macroeconomic conditions. The effects of these events may continue due to potential U.S. government shutdowns, the transition in administrations, changing in the U.S. government’s trade policy and the United States’ ongoing trade disputes with Russia, China and other countries, including the United States’ tariffs, and any new or additional retaliatory tariffs from foreign countries. For example, the Chinese government recently instructed domestic companies in certain industries not to use cybersecurity products manufactured by the companies
47

Table of Contents

based in the United States or Israel, including us and certain of our competitors. The continuing effect of any or all of these events could adversely impact demand for our products, harm our operations and weaken our financial results.

Our business is subject to the risks of earthquakes, drought, fire, power outages, typhoon, floods, virus outbreaks and other broad health-related challenges, cyber events and other catastrophic events, and to interruption by manmade problems such as civil unrest, war, labor disruption, critical infrastructure attack and terrorism.

A significant natural disaster, such as an earthquake, drought, fire, power outage, typhoon, flood, viral outbreak or other catastrophic event, could have a material adverse impact on our business, operating results and financial condition. Our corporate headquarters are located in the San Francisco Bay Area, a region known for seismic activity, and our research and development and data center in Burnaby, Canada, from which we deliver to customers our FortiGuard and other security subscription updates, is subject to the risk of flooding and is also in a region known for seismic activity. Any earthquake in the Bay Area or Burnaby, or flooding in Burnaby, could materially negatively impact our ability to provide products and services, such as FortiCare support and FortiGuard subscription services and could otherwise materially negatively impact our business. In addition, natural disasters could affect our manufacturing vendors, suppliers or logistics providers’ ability to perform services, such as obtaining product components and manufacturing products, or performing or assisting with shipments, on a timely basis, as well as our customers’ ability to order from us and our employees’ ability to perform their duties. For example, a typhoon in Taiwan could materially negatively impact our ability to manufacture and ship products and could result in delays and reductions in billings and revenue, or the effects of epidemics and pandemics may negatively impact our ability to manufacture and ship products, possibly in a material way, and could result in delays and reductions in billings and revenue, also possibly in a material way. The impact of climate change could affect economies in ways that negatively impact us and our results of operations. In the event our or our service providers’ information technology systems or manufacturing or logistics abilities are hindered by any of the events discussed above, shipments could be delayed, resulting in our missing financial targets, such as revenue and shipment targets, for a particular quarter. In addition, regional instability, international disputes, wars, such as the war in Ukraine, tensions between China and Taiwan or conflicts in the Middle East and any expansion thereof, and other acts of aggression, civil and political unrest, labor disruptions, rebellions, acts of terrorism and other geo-political unrest could cause disruptions in our business or the business of our manufacturers, suppliers, logistics providers, partners or end-customers, or of the economy as a whole. Given our typical concentration of sales at the end of each quarter, any disruption in the business of our manufacturers, logistics providers, channel partners or end-customers that impacts sales at the end of our quarter could have a significant adverse impact on our quarterly results. For example, if one of our channel partners experiences issues such as cyberattacks or other operational disruptions at the end of a quarter, it could negatively impact our ability to receive orders from them and, among other things, may adversely affect our billings and revenue. To the extent that any of the above results in security risks to our customers, delays or cancellations of customer orders, the delay of the manufacture, deployment or shipment of our products or interruption or downtime of our services, our business, financial condition and results of operations would be adversely affected.

Changes in financial accounting standards may cause adverse unexpected fluctuations and affect our reported results of operations.

A change in accounting standards or practices, and varying interpretations of existing or new accounting pronouncements, as well as significant costs incurred or that may be incurred to adopt and to comply with these new pronouncements, could have a significant effect on our reported financial results or the way we conduct our business. If we do not ensure that our systems and processes are aligned with the new standards, we could encounter difficulties generating quarterly and annual financial statements in a timely manner, which could have an adverse effect on our business, our ability to meet our reporting obligations and compliance with internal control requirements.

Management will continue to make judgments and assumptions based on our interpretation of new standards. If our circumstances change or if actual circumstances differ from our assumptions, our operating results may be adversely affected and could fall below our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock. Further, marketable equity investments are required to be measured at fair value (with subsequent changes in fair value recognized in net income), which may increase the volatility of our earnings.

ITEM 1B.     Unresolved Staff Comments

Not applicable.

48

Table of Contents

ITEM 1C.     Cybersecurity

Our board of directors recognizes the critical importance of maintaining the trust and confidence of our customers, end users, business partners, governmental entities, stockholders and employees. Our board of directors is actively involved in oversight of our risk management program, and information and product security represent an important component of our overall approach to enterprise risk management (“ERM”). Our risks from cybersecurity threats are considered in conjunction with other risks in our ERM program. In addition, we leverage a cybersecurity-specific risk assessment process and strategy based on the NIST Cybersecurity Framework to manage risks to organizational operations and assets, individuals and other organizations associated with the operation and use of systems. Risk assessments are periodically conducted to identify threats and vulnerabilities, and then used to determine the likelihood and impact for each risk using a qualitative risk assessment methodology. In general, we seek to address cybersecurity risks through a broad, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.

Governance

As a global cybersecurity provider, cybersecurity risk management is integral to our company. Historically, the Audit Committee of our board of directors (the “Audit Committee”) was responsible for reviewing with management our cybersecurity and other information technology risks, controls and processes, including the processes used to prevent or mitigate cybersecurity risks and respond to cybersecurity events. However, due to the importance of cybersecurity to our company, in July 2024, our board of directors formed Cybersecurity Committee of our board of directors (the “ Cybersecurity Committee ”), which is solely dedicated to cybersecurity risk management. Our executives with responsibility over cybersecurity, including our Chief Information Security Officer, provide quarterly reports to the Cybersecurity Committee as well as to the Chief Executive Officer and other members of our senior management as appropriate. Each member of our board of directors is invited to attend all meetings of the committees of our board of directors, including the Cybersecurity Committee, and thus all of the members of our board of directors are apprised of cybersecurity developments. The quarterly reports to the Cybersecurity Committee include updates on cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program and the emerging threat landscape. Our cybersecurity program is regularly evaluated by internal and external experts with the results of those reviews reported to senior management and the Cybersecurity Committee. We also actively engage with key vendors and intelligence and law enforcement communities as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures. The Cybersecurity Committee also receives prompt and timely information regarding any cybersecurity threat or incident that meets established reporting thresholds, as well as ongoing updates regarding any such threat or incident until it has been mitigated, resolved or otherwise addressed.

We believe our systems and processes with respect to the management of risks associated with cybersecurity threats are adequate. We have experienced, and may in the future experience, adverse impacts to our operations as a result of cybersecurity incidents. However, to date, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business strategy, operating results, and/or financial condition. If we were to experience a material cybersecurity incident in the future, such incident may have a material effect, including on our business strategy, operating results or financial condition. For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see our risk factors, including our risk factor titled “ If our internal enterprise IT networks, on which we conduct internal business and interface externally, our operational networks, through which we connect to customers, vendors and partners systems and provide services, or our research and development networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers, through which we research, develop and host products and services, are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted. ”

Risk Management and Strategy

As one of the critical elements of our overall ERM approach, our cybersecurity program is focused on the following key areas:

Governance: As discussed in more detail above under the heading, “Governance,” our board of directors’ oversight of cybersecurity risk management is supported by the Cybersecurity Committee, which regularly interacts with executives with responsibility for cybersecurity, our Chief Executive Officer, Chief Technology Officer and President, Chief Financial Officer, Chief Operating Officer/General Counsel, our CISO, and other members of management. Our CISO is primarily responsible for our cybersecurity risk management program and partners with our legal team on data privacy matters at the management level. Our CISO, Dr. Carl Windsor, has over 26 years of experience in various technology and cybersecurity leadership positions, including over 19 years at our company driving product security and strategy and reports to the board Cybersecurity Committee. The CISO’s leadership team members are all seasoned information security professionals, covering a wide range of security disciplines, who have worked at some of the largest well-known brand names and are experts in their fields. Our CISO
49

Table of Contents

monitors, and participates in, our various cybersecurity policies and procedures, and our cybersecurity team regularly updates our CISO on the current status.

Management is promptly updated regarding any significant security events and the Cybersecurity Committee regularly reviews updates from our CISO, information security and product security leaders about cyber threat response preparedness, security controls and procedures, security program maturity milestones, risk and approaches to risk mitigation and the current and emerging threat landscape. In addition, all members of our board of directors receive management’s cybersecurity updates to the Cybersecurity Committee as part of their regular attendance at meetings of our board of directors.

Collaborative Approach: We have implemented a broad, cross-functional approach to identifying, preventing and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. In addition, we manage a cross-functional program across our engineering, manufacturing and technical services teams, together with our suppliers and channel partners, designed to ensure the proper security of our products from design through manufacture and shipment.

Information Security: We implement organizational, administrative and technical measures based on commercially reasonable procedures using: (i) industry standard information security measures prescribed for use by NIST; (ii) security measures aligned with the ISO/IEC 27000 series of standards, (iii) Sarbanes-Oxley and SSAE 18/ISAE 3402; (iv) privacy regulations such as the GDPR and the CCPA; (v) business continuity management measures aligned with the ISO/IEC 22301 standard; and (vi) other generally recognized industry standards, in each case, designed to safeguard the confidentiality, integrity, and availability of our infrastructure and data and the resiliency of our operations.

Technical Safeguards: We deploy technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence.

Incident Response and Recovery Planning: We have established and maintain broad incident response and recovery plans that help enable its effective and orderly management of, and response to, any identified security incidents, including escalation and internal and external-notification steps, allowing the incident response team to respond in a timely manner and enlist appropriate personnel and third-party experts. We maintain a process to promptly assess and assign severity levels to any identified security incidents in order to prioritize their importance and promptly direct resources to those issues of potentially greater impact. The notification plan establishes steps to alert external stakeholders as appropriate, including law enforcement, regulatory bodies, investors, customers and other business partners.

Third-Party Risk Management: We maintain a broad, risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems. In addition, our Trusted Supplier Program is designed to ensure manufacturing partners undergo a selection and qualification process that adheres to NIST 800-161.

Education and Awareness: We provide regular, mandatory training for personnel and contractors regarding cybersecurity threats as a means to equip our personnel with effective tools to address cybersecurity threats and to communicate our evolving information security policies, standards, processes and practices.

Risk and Readiness Assessments: We engage in the periodic assessment and testing of our policies, standards, process es and practices that are designed to identify vulnerabilities and weaknesses, address cybersecurity threats and test its readiness to respond to cyber security incidents. These efforts include a wide range of activities, including threat modeling, a variety of vulnerability and configuration scans, penetration testing, audits, tabletop exercises and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning. We regularly engage third parties to perform assessments on our cybersecurity measures, including information security maturity assessments, audits and independent reviews of our information security control environment and operating effectiveness and penetration tests. The results of such assessments, audits and reviews are reported to the Cybersecurity Committee and our board of directors and to our management, and we adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews .

Insurance: We maintain information security risk insurance coverage.

50

Table of Contents

ITEM 2.     Properties

Our corporate headquarters is located in Sunnyvale, California, and comprises approximately 395,000 square feet of building space on 21 acres of land .

As of December 31, 2025, we operated the facilities in the following geographies (square feet in thousands):

Location Approximate Owned Square Footage Description of Use
United States
2,400  Corporate headquarters, data centers, research and development, warehousing and operations, sales and support functions, and PoP
Canada
1,000  Data center and office space, sales and support, research and development functions, and PoP

EMEA
910  Data center and office space, warehousing and operations, sales and support functions, and PoP
Asia Pacific (“APAC”)
40  Office space and PoP
Total
4,350 

We maintain additional leased offices throughout the world, predominantly used as sales and support offices and PoP, and leased data center spaces throughout the world operated under colocation arrangements. We believe that our existing properties are sufficient and suitable to meet our current needs. We intend to expand our facilities, develop unoccupied space, or add new facilities to support our future growth and enter new product markets, and we believe that suitable additional space will be available or can be developed as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional operating expenses and capital expenditures in connection with such new or expanded facilities.

For information regarding the geographical location of our property and equipment, refer to Note 15. of our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.

ITEM 3.     Legal Proceedings

We are subject to various claims, complaints and legal actions that arise from time to time in the ordinary course of business. We accrue for contingencies when we believe that a loss is probable and that we can reasonably estimate the amount of any such loss. There can be no assurance that existing or future legal proceedings arising in the ordinary course of business or otherwise will not have a material adverse effect on our business, consolidated financial position, results of operations or cash flows. Refer to Note 11. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for additional information.

ITEM 4.     Mine Safety Disclosure

Not applicable.

51

Table of Contents

Part II

ITEM 5.     Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Common Stock

Our common stock is traded on The Nasdaq Global Select Market under the symbol “FTNT.”

Holders of Record

As of February 20, 2026, there were 51 holders of record of our common stock. A substantially greater number of holders of our common stock are “street name” or beneficial holders, whose shares are held by banks, brokers and other financial institutions.

Dividends

We have never declared or paid cash dividends on our capital stock. We do not anticipate paying any cash dividends in the foreseeable future. Any future determination to declare cash dividends will be made at the discretion of our board of directors and will depend on our financial condition, operating results, capital requirements, general business conditions and other factors that our board of directors may deem relevant.

Securities Authorized for Issuance Under Equity Compensation Plans

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the Securities and Exchange Commission (the “SEC”) within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Stock Performance Graph

This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934 ( the “Exchange Act”), or incorporated by reference into any filing of Fortinet under the Securities Act of 1933, as amended (the “Securities Act”), or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.

52

Table of Contents

The following graph compares the cumulative five-year total return for our common stock, the Standard & Poor’s 500 Stock Index (the “S&P 500 Index”) and the NASDAQ Computer Index. Such returns are based on historical results and are not intended to suggest future performance. Data for the S&P 500 Index and the NASDAQ Computer Index assume reinvestment of dividends.

COMPARISON OF CUMULATIVE TOTAL RETURN*
Among Fortinet, Inc., the S&P 500 Index and
the NASDAQ Computer Index

December 2020 *
December 2021
December 2022
December 2023
December 2024
December 2025

Fortinet, Inc. $ 100  $ 242  $ 165  $ 197  $ 318  $ 267 
S&P 500 Index $ 100  $ 127  $ 102  $ 127  $ 157  $ 182 
NASDAQ Computer $ 100  $ 138  $ 89  $ 147  $ 201  $ 258 
 
* Assumes that $100 was invested on December 31, 2020 in stock or index, including reinvestment of dividends. Stockholder returns over the indicated period should not be considered indicative of future stockholder returns.

Sales of Unregistered Securities

None.

Purchases of Equity Securities by the Issuer and Affiliated Purchasers

Share Repurchase Program

In January 2016, our board of directors approved our Share Repurchase Program, which authorized the repurchase of up to $200.0 million of our outstanding common stock through December 31, 2017. From 2016 through 2024, our board of directors approved increases to our Repurchase Program by various amounts and extended the term to February 28, 2026. In August 2025, our board of directors approved a $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program and extended the term of the Repurchase Program to February 28, 2027, bringing the aggregate amount authorized for repurchases to $9.25 billion of our outstanding common stock through February 28, 2027. Under the Repurchase Program, we may repurchase common stock from time to time in privately negotiated transactions or in open market transactions. The Repurchase Program does not require us to purchase a minimum number of shares, and may be suspended, modified or discontinued at any time without prior notice. Since its inception through December 31, 2025, we have repurchased 267.3 million shares of our common stock under the Repurchase Program for an aggregate purchase price of $8.51 billion.

53

Table of Contents

The following table provides information with respect to the shares of common stock we repurchased under the Repurchase Program during the three months ended December 31, 2025 (in millions, except average price paid per share amounts):

Period Total Number of Shares Purchased Average Price Paid per Share Total Number of Shares Purchased as Part of Publicly Announced Plan or Program
Approximate Dollar Value of Shares that May Yet Be Purchased Under the Plans or Programs

October 1 - October 31, 2025
—  $ —  —  $ 795.9 
November 1 - November 30, 2025
0.7  $ 78.46  0.7  $ 738.6 
December 1 - December 31, 2025
—  $ —  —  $ 738.6 
Total 0.7  $ —  0.7 

In January 2026, our board of directors approved a $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program, bringing the aggregate amount authorized to be repurchased to $10.25 billion of our outstanding common stock through February 28, 2027. As of February 24, 2026, approximately $1.27 billion remained available for future share repurchases.

ITEM 6.     [Reserved]
54

Table of Contents

ITEM 7.     Management’s Discussion and Analysis of Financial Condition and Results of Operations

In addition to historical information, this Annual Report on Form 10-K contains forward-looking statements within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. These statements include, among other things, statements concerning our expectations regarding:

• continued growth and market share gains;

• variability in sales in certain product and service categories from year to year and between quarters;

• expected impact of sales from certain products and services;

• increasing or decreasing inflation or stagflation, and changing interest rates in many geographies and changes in currency exchange rates and currency regulations;

• competition in our markets;

• macroeconomic, geopolitical factors and other disruption on our manufacturing or sales, including tariffs or other trade disruptions, public health issues, wars, natural disasters and economic growth;
 
• government regulation and other policies;

• drivers of long-term growth and operating leverage, such as pricing of our products and services, sales productivity, pipeline and capacity, functionality, value and technology improvements in our product and service offerings;

• growing our solution sales through channel partners to businesses, service providers and government organizations, our ability to execute these sales and the complexity of providing solutions to all segments (including the increased competition and unpredictability of timing associated with sales to larger enterprises), the impact of sales to these organizations on our long-term growth, expansion and operating results, and the effectiveness of our sales organization;

• our ability to successfully anticipate market changes, including those related to cloud-based and AI solutions and to sell, support and meet service level agreements related to cloud-based solutions;

• growth expectations for the secure networking market;

• supply chain constraints, component availability and other factors affecting our manufacturing capacity, delivery, cost and inventory management;

• forecasts of future demand and targeted inventory levels, including changing market drivers and demands;

• the effect of backlog from current or prior quarters, including its effect on growth of in-quarter billings and revenue;

• our ability to hire properly qualified and effective sales, support and engineering employees;

• risks and expectations related to acquisitions and equity interests in private and public companies, including integration issues related to go-to-market plans, product plans, employees of such companies, controls and processes and the acquired technology, and risks of negative impact by such acquisitions and equity investments on our financial results;

• trends in revenue, cost of revenue and gross margin, including product revenue, service revenue and inventory related charges;
 
• trends in our operating expenses, including sales and marketing expenses, research and development expenses, general and administrative expenses;

55

Table of Contents

• expected impact of plans and strategy for the acceleration of our data center footprint and our PoP deployment;

• our gross margins and operating expenses for 2026;

• expectations that proceeds from the exercise of stock options in future years will be adversely impacted by the increased mix of restricted stock units and performance stock units versus stock options granted or a decline in our stock price;

• uncertain tax benefits and our effective domestic and global tax rates, the impact of interpretations of or changes to tax law, and the timing of tax payments;

• spending related to real estate assets, acquisitions and development, including data centers and points of presence, office building and warehouse investments, as well as other capital expenditures and to the impact on free cash flow and expenses;

• estimates of a range of 2026 spending on capital expenditures;

• expansions, development, improvements, operating, subleasing and other real property holdings activities;

• expected outcomes and liabilities in litigation;

• our intentions regarding share repurchases and the sufficiency of our existing cash, cash equivalents and investments to meet our cash needs, including our debt servicing requirements, for at least the next 12 months;

• other statements regarding our future operations, financial condition and prospects and business strategies; and

• adoption and impact of new accounting standards.

These forward-looking statements are subject to certain risks and uncertainties that could cause our actual results to differ materially from those reflected in the forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K and, in particular, the risks discussed under the heading “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K and those discussed in other documents we file with the SEC. We undertake no obligation, and specifically disclaim any obligation, to revise or publicly release the results of any revision to these and any other forward-looking statements. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.

Business Overview

Fortinet is a leader in cybersecurity, driving the convergence of networking and security. Our mission is to secure people, devices and data everywhere. Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified SASE and AI-driven security operations. As of December 31, 2025, our end-customers were located in over 100 countries and included enterprises across a wide variety of market verticals, including financial services, retail, healthcare and operational technology market verticals, communication and security service providers, and government organizations. As a global company headquartered in Sunnyvale, California, our research and development is centered in the United States and Canada with a global footprint of support and centers of excellence around the world. As of December 31, 2025, we held 1,064 U.S. patents and a total of 1,405 global patents, including 321 AI-related patents. We have been recognized in over 140 enterprise analyst reports demonstrating both our vision and execution across security and networking products.

Our competitive differentiation lies in our core technologies, which together provide performance, security, flexibility and integration across diverse environments.

• FortiOS —Our unified operating system enables the convergence of networking and AI-powered security to enforce consistent policies across all form factors and edges. As the foundational engine of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and analytics, providing network visibility and control at scale. FortiOS includes advanced encryption and other security technologies designed to address evolving cybersecurity threats, including emerging quantum-resistant cryptographic capabilities.

56

Table of Contents

• FortiASIC —Our ASIC-based SPUs increase the speed, scale, efficiency and value of our solutions while reducing footprint and power requirements. From branch and campus to data center solutions, SPU-powered Fortinet appliances deliver superior Security Compute Ratings versus industry alternatives.

• FortiCloud —Our organically built global cloud infrastructure provides customers with global reach, flexible connectivity and cost savings. FortiCloud is our private cloud SaaS platform, powered by FortiStack, which is our secure SaaS platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all layers.

• FortiAI —FortiAI provides a dual-layered defense across the Fortinet Security Fabric through the AI for Security and Security for AI framework. Within AI for Security, FortiAI-Assist uses generative and agentic AI to support NOC and SOC teams in monitoring, analysis and response activities across enterprise environments. Security for AI comprises of FortiAI-Protect and FortiAI-SecureAI. FortiAI-Protect utilizes AI/ML to address AI-driven threats and zero-day attacks, and support governance over GenAI applications, FortiAI-SecureAI focus on protecting an organization’s AI infrastructure, including LLMs and APIs, and preventing data leakage into and out of LLMs. FortiAI protects the AI ecosystem, infrastructure, models, workloads, data and supply chains, while leveraging unified AI intelligence across the Fortinet Security Fabric to defend against threats.

• FortiEndpoint —FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and ZTNA, into a single agent. It simplifies management and enhances visibility while reducing costs and complexity. The solution gives IT teams the visibility and control they need, while security teams benefit from automated threat detection and response. This minimizes the need for manual intervention and provides faster remediation of threats across environments.

• OT Security —The Fortinet Security Fabric enables security for OT systems and CPS, including converged IT/OT architectures. Our OT Security Platform is purpose-built to protect the engineered systems that underpin critical infrastructure and supply chains around the world. This includes securing energy and utilities systems, manufacturing environments, and transportation, utilizing FortiGuard OT Security Services. These offerings include security capabilities for CPS assets and tools that support centralized NOC and SOC functions.

These competitive differentiators provide networking and security professionals with a cyber security platform comprised of over 50 products across three solution pillars:

• Secure Networking —Our Secure Networking solutions focus on the convergence of networking and security via FortiOS, our networking and security operating system that is the foundation of our Fortinet Security Fabric platform and supports a broad range of functions that can be delivered via a physical, virtual, cloud or SaaS solutions. When delivered through our network firewall appliances, functionality is accelerated through our proprietary ASIC technology. These proprietary ASICs, allow our systems to scale, run multiple applications at higher performance, lower power consumption and perform more processor-intensive operations, such as inspecting encrypted traffic, including streaming video. Our network firewall offerings consist of a FortiGate, which can be deployed at branch, campus, data center, internal segmentation, private and public cloud to enable hybrid mesh firewall solutions, as well as encrypted applications (SSL inspection, virtual private network and IPsec connectivity). Our ability to converge networking and security also enables the ethernet to become an extension of our customers’ security infrastructure through FortiSwitch and FortiLink. FortiExtender secures 5G/LTE and remote ethernet extenders to connect and secure any branch environment. Our Secure Connectivity solution includes FortiSwitch secure ethernet switches, FortiAP wireless local area network access points and FortiExtender 5G connectivity gateways and NAC for securing IoT devices.

• Unified Secure Access Service Edge (SASE) —As applications move to the cloud and hybrid workforce is now the norm, enabling secure access for users with zero trust framework becomes important. The Fortinet Unified SASE solution includes a single-vendor SASE solution that includes firewall, SD-WAN, secure web gateway, cloud access services broker, DLP, DEM, RBI and ZTNA to deliver flexible secure access for all users. We are one of the few vendors to deliver consistent convergence and AI-powered security across Secure SD-WAN and SSE to enable a single-vendor SASE framework with a cloud-centric architecture powered by FortiOS. Our global and scalable cloud network includes over 190 PoPs to deliver a seamless secure access experience. Leveraging this global infrastructure, we believe we are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform. We also allow our customers to deploy our FortiSASE as Sovereign SASE, which provides control over the technology elements needed for a SASE solution. FortiSASE Sovereign delivers full SASE capabilities within infrastructure environments that organizations control, including on-premises, in private data centers or trusted colocation environments. Additionally, we offer a full suite of integrated cloud security solutions that enable customers to secure their applications from code to cloud. Our solutions include application security that includes web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application
57

Table of Contents

protection and code security. We deliver a holistic approach to cloud security, offering a single unified platform, consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and multi-clouds. Additionally, we also offer flexible consumption licensing programs that enable organizations to dynamically optimize their cloud security needs and investments as well as readily meet their cloud minimum spend commitment obligations with Cloud Service Providers. We continue to develop all the core SASE capabilities in a single operating system, FortiOS, including Next-Gen Firewall, SD-WAN, ZTNA, secure web gateway, cloud access security broker and DLP. This native integration of our Next-Gen Firewall, SD-WAN and SASE has become the New-Generation SASE Firewall.

• AI-Driven Security Operations (SecOps) —Our AI-Driven SecOps portfolio provides a suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric. At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that provides: built-in SIEM, SOAR, XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control. FortiSIEM delivers security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response. This solution set also includes FortiEndpoint, FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications. To bolster their security posture, organizations contending with staff shortages can tap into FortiGuard services, including SOCaaS, MDR, Security Posture Assessment and Incident Response. Finally, FortiAI generative AI assistance streamlines operations, helping security teams stay ahead of an ever-evolving threat landscape.

FortiGuard Labs is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize ML and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers. Using millions of global network sensors, FortiGuard Labs monitors the worldwide attack surface and employs AI to mine that data for new threats.

FortiGuard and Other Security Services are a suite of AI-powered security capabilities that are natively integrated as part of the Fortinet Security Fabric to deliver coordinated detection and enforcement across the entire attack surface. The portfolio consists of FortiGuard application security services, content security services, device security services, NOC/SOC security services and web security services.

FortiCare Technical Support Service is a technical support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet solution. Global technical support is offered 24x7 with flexible add-ons, including enhanced SLAs and priority hardware replacement through in-country and local depots. Organizations have the flexibility to procure different levels of service for different solutions based on their availability needs. We offer three support options tailored to the needs of our enterprise customers: FortiCare Elite, FortiCare Premium and FortiCare Essential. The FortiCare Elite service aims to provide a 15-minute response time for key product families.

In addition to FortiCare solution based services, Advanced Support service options are available per account. These services are available for regional account support in three options: Core, Pro and Pro Plus, and can be available or provided on a global basis at the Pro and Pro Plus levels. Advanced Support brings support directly to each account, helping account holders to make their operations more effective and to plan and manage their solution lifecycle.

Additionally, we are committed to addressing the cybersecurity skills shortage through training and certification programs for customers, partners and employees. The Fortinet Training Institute’s ecosystem of public and private partnerships around the world extend to industry, academia, government and nonprofits to ensure we are reaching and increasing access of our cybersecurity certifications and training to all populations. The Fortinet Training Institute has issued approximately two million certifications to date.

Financial Summary

• Total revenue was $6.80 billion in 2025, an increase of 14% compared to $5.96 billion in 2024.

• Product revenue was $2.22 billion in 2025, an increase of 16% compared to $1.91 billion in 2024.

• Service revenue was $4.58 billion in 2025, an increase of 13% compared to $4.05 billion in 2024.

• Total gross profit was $5.47 billion in 2025, an increase of 14% compared to $4.80 billion in 2024.

• Total gross margin was 80.5% in 2025, remaining comparatively flat compared to 80.6% in 2024.
58

Table of Contents

• Operating income was $2.08 billion in 2025, an increase of 16% compared to $1.80 billion in 2024.

• Operating margin was 30.7% in 2025, an increase of 0.4 percentage points compared to 30.3% in 2024.

• Cash, cash equivalents, short-term and long-term investments were $3.92 billion as of December 31, 2025, a decrease of $144.3 million, or 4%, from December 31, 2024.

• Deferred revenue was $7.12 billion as of December 31, 2025, an increase of $754.9 million, or 12%, from December 31, 2024. Short-term deferred revenue was $3.64 billion as of December 31, 2025, an increase of $359.8 million, or 11%, from December 31, 2024.

• Cash flows from operating activities were $2.59 billion in 2025, an increase of $332.5 million, or 15%, compared to 2024.

Revenue continues to be diversified globally, which remains a key strength of our business. In 2025, the Americas region, the EMEA region and the APAC region contributed 40%, 42% and 18% of our total revenue, respectively, and increased 11%, 18% and 13% compared to 2024, respectively.

Product revenue grew 16% in 2025 compared to 2024 . We experienced product revenue growth across our hardware products and software licensing, which mainly benefited from growth in secure networking hardware products and term licenses. We expect our product revenue to continue to grow in 2026.

Service revenue grew 13% in 2025 compared to 2024 , primarily driven by the strength of our security subscription revenue, which grew 14% in 2025 compared to 2024 . The increase was primarily due to the recognition of service revenue from our growing deferred revenue balance related to FortiGuard and other security subscriptions delivered to on-premise and cloud-based environments and strength in unified SASE and SecOps. We expect our service revenue to continue to grow in 2026.

Our billings were diversified on a geographic basis. In 2025, seven countries represented approximately 50% of our billings and the remaining approximately 50% in the aggregate were from over 100 countries that each individually contributed less than 3% of our billings.

Total gross margin remained comparatively flat in 2025 compared to 2024 . O ur overall gross margin in 2026 will be impacted by service and product revenue mix and their respective gross margins. While we are implementing price increases to mitigate higher hardware component costs, the impact on our margins will depend on the timing and market acceptance of these adjustments. Our product gross margin may decline if these pricing actions do not fully offset rising input costs. Our service gross margin is expected to remain relatively consistent, for full year 2026 compared to full year 2025, despite continued expansion of our data center footprint and colocation and cloud hosting capacity to support the growth in our unified SASE and SecOps offerings. We currently do not expect the U.S. tariffs to have a meaningful impact on our gross margin. However, changes in trade policy, including increases in tariff rates, changes in customs or tariffs classifications, or modifications to tariff exemptions, could adversely affect our gross margin in the future, and we expect any resulting impact would primarily relate to our hardware sales to the U.S. customers.

Operating expenses as a percentage of revenue decreased 0.5 percentage points in 2025 compared to 2024, mainly because our revenue growth outpaced our personnel costs growth. Headcount increased 7% to 15,109 employees as of December 31, 2025, up from 14,138 as of December 31, 2024.

Operating margin increased 0.4 percentage points in 2025, driven by revenue growth exceeding expense growth, resulting in improved operating leverage. For the full year 2026, we expect our operating margin to decrease compared to 2025 as we continue to make strategic investments. Total revenue is expected to increase in 2026 compared to the prior year; however, our expenses are expected to outpace revenue growth, primarily reflecting investments in sales and marketing headcount, product development and the continued capital expenditures in data centers and real estate. While these strategic investments are intended to drive long-term revenue growth and market expansion, we anticipate they may result in near-term compression of our operating margins. In addition, we may experience higher operating expenses driven in part by the weakening of the U.S. dollar relative to foreign currencies, as a portion of our expenses are incurred and paid in currencies other than the U.S. dollar.

59

Table of Contents

Impact of Macroeconomic and Geopolitical and Supply Chain Developments

Our overall performance depends in part on worldwide economic and geopolitical conditions, such as trade policies and tariffs, GDP growth or contraction (both domestically and internationally), geopolitical instability and uncertainty, the war in Ukraine, tensions between China and Taiwan or conflicts in the Middle East, and their impact on customer behavior. Worsening economic conditions, including tariffs, inflation, changing interest rates and other trade disruptions, slower growth, any recession, fluctuations in foreign exchange rates and other changes in economic conditions, may result in decreased sales productivity, lower growth and adversely affect our results of operations and financial performance. We have seen, and could continue to see, certain impacts on our business, results of operations, financial condition, cash flows, liquidity and capital and financial resources such as longer sales cycles, delayed purchases and increased commitments with certain suppliers and increased inventory and inventory purchase commitment reserves. Tariffs imposed by the United States, as well as any new or additional retaliatory tariffs that could be imposed by other countries in response, could have a material adver se impact on global trade, supply chains and other worldwide economic and geopolitical conditions, which could increase our product costs and also affect customer sentiment in deciding whether to purchase our products. We continue to monitor the impact of tariffs on our business. In addition, as a result of the rapid global build-out of AI infrastructure, there is currently a global shortage of memory chips, which are a component in certain of our products. As a result, we are currently experiencing, and may continue to experience, constraints on the availability of memory chips, which may lead to delays in the production and delivery of our products and increased costs to source available memory chips, any of which could harm our business, financial condition and results of operations. To mitigate increased hardware costs resulting from these shortages, we are implementing price increases, which may negatively impact demand for our products and may not be sufficient or timely to offset rising input costs, potentially resulting in margin compression and adversely affecting our business, financial condition and results of operations.

Worsening economic, geopolitical and supply chain developments may have a material negative impact on our results in future periods and may negatively impact our billings, revenue and costs, and may decrease growth and profitability. The extent of the impact of such conditions on our operational and financial performance will depend on ongoing developments, including those discussed above and others identified in Part I, Item 1A “Risk Factors” in this Form 10-K. Given the dynamic nature of these circumstances, the full impact of worsening economic, geopolitical and supply chain developments on our business and operations, results of operations, financial condition, cash flows, liquidity and capital and financial resources cannot be reasonably estimated at this time.

Business Model

We typically sell our security solutions to distributors that sell to networking security focused resellers and to certain service providers and MSSPs, who, in turn, sell to end-customers or use our products and services to provide hosted solutions to other enterprises. At times, we also sell directly to enterprise customers, service providers, systems integrators and large enterprises. We also sell our software licenses and cloud delivered services via different cloud service provider platforms, both directly and through our channel partners. Our end-customers are located in over 100 countries and include small, medium and large enterprises and government organizations across a wide range of industries, including financial services, government, healthcare, manufacturing, retail, technology and telecommunications. An end-customer deployment may involve as few as one or as many as thousands of secure networking, unified SASE and security operations technology products or users, depending on the end-customer’s size and security requirements.

Our customers purchase our hardware products, software licenses, SaaS subscriptions and cloud-delivered solutions, including our FortiGuard security subscriptions and FortiCare technical support services. Depending on the solution, these may be sold in a bundle or standalone as part of a solution sale. We generally invoice at the time of our sale for the total price of the products and services. Standard payment terms are generally no more than 60 days, though we may offer extended payment terms to certain distributors or large enterprises.

We offer our products hosted in our own data centers, PoPs, and through colocations and major cloud service providers, including Amazon Web Services, Microsoft Azure and Google Cloud.

Key Metrics

We monitor several key metrics, including the key financial metrics set forth below, in order to help us evaluate growth trends, establish budgets, measure the effectiveness of our sales and marketing efforts, and assess operational efficiencies. The following table summarizes revenue, deferred revenue, billings (non-GAAP), net cash provided by operating activities, and free cash flow (non-GAAP). We discuss revenue below under “—Components of Operating Results,” and we discuss net cash provided by operating activities below under “—Liquidity and Capital Resources.” Deferred revenue, billings (non-GAAP), and free cash flow (non-GAAP) are discussed immediately below the following table.
60

Table of Contents

  Year Ended or As of December 31,
2025 2024 2023

(in millions)
Revenue $ 6,799.6  $ 5,955.8  $ 5,304.8 
Deferred revenue $ 7,115.8  $ 6,360.9  $ 5,735.0 
Billings (non-GAAP) $ 7,553.7  $ 6,532.5  $ 6,399.5 
Net cash provided by operating activities $ 2,590.6  $ 2,258.1  $ 1,935.5 
Free cash flow (non-GAAP) $ 2,211.8  $ 1,879.2  $ 1,731.4 

Deferred revenue. Our deferred revenue consists of amounts that have been invoiced but that have not yet been recognized as revenue. The majority of our deferred revenue balance consists of the unrecognized portion of service revenue from FortiGuard and other security subscriptions and FortiCare technical support service contracts, which is recognized as revenue ratably over the service term. We monitor our deferred revenue balance, short term and total deferred revenue growth and the mix of short-term and long-term deferred revenue because deferred revenue represents a significant portion of free cash flow and of revenue to be recognized in future periods. Deferred revenue was $7.12 billion as of December 31, 2025, an increase of $754.9 million, or 12%, from December 31, 2024. Short term deferred revenue was $3.64 billion as of December 31, 2025, an increase of $359.8 million, or 11%, from December 31, 2024.

Billings (non-GAAP). We define billings as revenue recognized in accordance with generally accepted accounting principles in the United States (“GAAP”) plus the change in deferred revenue from the beginning to the end of the period less any deferred revenue balances acquired from business combinations during the period. We consider billings to be a useful metric for management and investors because billings drive current and future revenue as well as cash flows. There are a number of limitations related to the use of billings instead of GAAP revenue. First, billings are impacted by the term of security subscription and support agreements and do not provide an indication as to the timing of revenue being recognized from these service contracts. Second, we may calculate billings in a manner that is different from peer companies that report similar financial measures. Management accounts for these limitations by providing specific information regarding GAAP revenue and evaluating billings together with GAAP revenue. Total billings were $7.55 billion in 2025, an increase of 16% compared to $6.53 billion in 2024.

A reconciliation of revenue, the most directly comparable financial measure calculated and presented in accordance with GAAP, to billings is provided below:

  Year Ended December 31,
2025 2024 2023

(in millions)
Billings:
Revenue $ 6,799.6  $ 5,955.8  $ 5,304.8 
Add: Change in deferred revenue 754.9  625.9  1,094.7 
Less: Deferred revenue balance acquired in business combinations (0.8) (49.2) — 
Total billings (non-GAAP) $ 7,553.7  $ 6,532.5  $ 6,399.5 

Free cash flow (non-GAAP). We define free cash flow as net cash provided by operating activities minus purchases of property and equipment and excluding any significant non-recurring items, such as proceeds from IP matters. We believe free cash flow to be a liquidity measure that provides useful information to management and investors about the amount of cash generated by the business that, after capital expenditures and net of proceeds from IP matters, can be used for strategic opportunities, including repurchasing outstanding common stock, investing in our business, making strategic acquisitions and strengthening the balance sheet. A limitation of using free cash flow rather than the GAAP measures of cash provided by or used in operating activities, investing activities, and financing activities is that free cash flow does not represent the total increase or decrease in the cash and cash equivalents balance for the period because it excludes cash flows from significant non-recurring items, such as proceeds from IP matters, investing activities other than capital expenditures and cash flows from financing activities. Management accounts for this limitation by providing information about our proceeds from IP matters, our capital expenditures and other investing and financing activities on the consolidated statements of cash flows and under “Liquidity and Capital Resources” and by presenting cash flows from investing and financing activities in our reconciliation of free cash flow. In addition, it is important to note that other companies, including companies in our industry, may not use free cash flow, may calculate free cash flow in a different manner than we do or may use other financial measures to evaluate their
61

Table of Contents

performance, all of which could reduce the usefulness of free cash flow as a comparative measure. A reconciliation of net cash provided by operating activities, the most directly comparable financial measure calculated and presented in accordance with GAAP, to free cash flow is provided below:

  Year Ended December 31,
2025 2024 2023

(in millions)
Free Cash Flow:
Net cash provided by operating activities $ 2,590.6  $ 2,258.1  $ 1,935.5 
Less: Purchases of property and equipment (364.8) (378.9) (204.1)
Less: Proceeds from intellectual property matter (14.0) —  — 
Free cash flow (non-GAAP) $ 2,211.8  $ 1,879.2  $ 1,731.4 
Net cash used in investing activities $ (599.1) $ (727.4) $ (649.3)
Net cash used in financing activities
$ (2,371.5) $ (50.1) $ (1,570.4)

Components of Operating Results

Revenue. We generate the majority of our revenue from sales of our hardware and software products and amortization of amounts included in deferred revenue related to previous sales of FortiGuard and other security subscriptions and FortiCare technical support services. We also recognize revenue from cloud security solutions, professional services, and training.

Our total revenue is comprised of:

• Product revenue . Product revenue is primarily generated from sales of our physical and virtual machine appliances. The majority of our product revenue continues to be generated by our secure networking product lines. Product revenue also includes revenue from sales of unified SASE and SecOps. As a percentage of total revenue, our product revenue has varied from quarter to quarter.

• Service revenue . Service revenue is generated primarily from FortiGuard and other security subscription services and FortiCare technical support services. We recognize revenue from FortiGuard and other security subscriptions and FortiCare technical support services ratably over the service term. Our typical contractual support and subscription term is one to five years. We also generate our revenue from other services, for which we recognize revenue as the services are provided, and cloud-based services, for which we recognize revenue as the services are delivered or on a monthly usage basis. As a percentage of total revenue, we continue to expect service revenue to be higher than product revenue. Our service revenue growth rate depends significantly on the growth of our customer base, the expansion of our service bundle offerings, the mix of our product sales, pricing actions, the expansion and introduction of new service offerings, the attach rate of service contracts to new product sales, and the renewal of service contracts by our existing customers.

Our total cost of revenue is comprised of: