Grouped by the filing’s own headings.
Risks Related to Global Economic and Geopolitical Conditions
T1Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.
rewrittenTariffs & tradeAdded government-mandated technology restrictions, export controls, import restrictions, and requirements limiting product availability in certain countries or regions.
We operate globally, and our business and revenues are impacted by global economic and geopolitical conditions. Instability in global credit markets, inflation, changes in public policies, changes in domestic and international regulations, changes in interest rates, foreign currency exchange rate fluctuations, trade regulations and tariffs, international trade disputes and agreements, changes in tax laws, geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions. Military actions or armed conflict, including the hostilities in Israel and the surrounding region, the Russia-Ukraine war and related political or economic responses, and uncertainty about, or changes in, government and trade relationships could further worsen economic and market conditions and the geopolitical environment.
For example, in response to Russia’s invasion of Ukraine, the United States, along with the European Union (the “E.U.”), has imposed restrictive sanctions on Russia, Russian entities, and Russian citizens. We are subject to these governmental sanctions and export controls, which may subject us to liability if we are not in full compliance with applicable laws. In addition, government-mandated restrictions on technology access, including export controls, import restrictions, or requirements that certain technologies not be made available in particular countries or regions, could limit our ability to sell or support our products and subscriptions in affected markets, require us to modify or discontinue certain products or features, or require us to exit certain markets.
Any continued or further uncertainty or deterioration in economic and market conditions or the geopolitical environment, or any expansion or imposition of government-mandated technology restrictions, could have a material and adverse impact on our business, financial condition, and operating results, including reductions in sales, longer sales cycles, reductions in subscription or contract duration and value, slower adoption of new technologies, changes in spending patterns or priorities of current and prospective customers, increased component, memory or compute costs, and increased price competition.
Compare with the 2025 10-K
Prior heading: Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.
We operate globally, and as a result, our business and revenues are impacted by global economic and geopolitical conditions. The instability Instability in the global credit markets, inflation, changes in public policies such as policies, changes in domestic and international legislation or regulations, changes in enforcement and administration policies, taxes, any increases in interest rates, fluctuations in foreign currency exchange rates, or international rate fluctuations, trade agreements, regulations and tariffs, international trade disputes, trade regulations, tariffs disputes and agreements, changes in tariffs, tax laws, geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions. Military actions or armed conflict, including the hostilities in Israel and the surrounding region, the Russia-Ukraine war and any related political or economic responses and counter-responses, responses, and uncertainty about, or changes in, government and trade relationships, policies, and treaties relationships could also lead to worsening further worsen economic and market conditions and the geopolitical environment. In For example, in response to Russia’s invasion of Ukraine, the United States, along with the European Union (the “E.U.”) “E.U.”), has imposed restrictive sanctions on Russia, Russian entities, and Russian citizens (“Sanctions on Russia”). citizens. We are subject to these governmental sanctions and export controls, which may subject us to liability if we are not in full compliance with applicable laws. In addition, government-mandated restrictions on technology access, including export controls, import restrictions, or requirements that certain technologies not be made available in particular countries or regions, could limit our ability to sell or support our products and subscriptions in affected markets, require us to modify or discontinue certain products or features, or require us to exit certain markets. Any continued or further uncertainty, weakness uncertainty or deterioration in economic and market conditions or the geopolitical environment environment, or any expansion or imposition of government-mandated technology restrictions, could have a material and adverse impact on our business, financial condition, and results of operations, operating results, including reductions in sales of our products and subscriptions, sales, longer sales cycles, reductions in subscription or contract duration and value, slower adoption of new technologies, alterations changes in the spending patterns or priorities of current and prospective customers (including delaying purchasing decisions), customers, increased costs for the chips and components to manufacture our products, component, memory or compute costs, and increased price competition.
Added · Removed · word-level comparison of the two filings
RISKS RELATED TO OUR GROWTH
Our business and operations have experienced growth in recent periods, and if we do not effectively manage our future growth or are unable to improve our systems, processes, and controls, our business and operating results could be adversely affected.
rewrittenLabor & talentAdded specific headcount increase of approximately 4,223 employees from CyberArk acquisition; removed discussion of operational disruption risks and third-party software implementation challenges.
We have experienced growth and increased demand for our products and subscriptions over recent years. As a result, our employee headcount has increased, and we expect it to continue to grow over the next year. For example, from the end of fiscal 2025 to the end of fiscal 2026, our headcount increased from 16,068 to 21,921 employees, including approximately 4,223 additional headcount as a result of the CyberArk acquisition. In addition, as we have grown, the number of end-customers has also increased, and we have managed more complex deployments of our products and subscriptions with larger end-customers. The growth and expansion of our business and products, subscriptions, and support offerings places a significant strain on our management, operational, and financial resources.
To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner.
We may not be able to successfully implement, scale, or manage improvements to our systems, processes, and controls in an efficient or timely manner, and our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud. Any future growth would add complexity to our organization and require effective coordination. Failure to manage any future growth effectively could result in increased costs, disruption to end-customer relationships, reduced demand for our products, or material harm to our business and operating results.
Compare with the 2025 10-K
Prior heading: Our business and operations have experienced growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected.
We have experienced growth and increased demand for our products and subscriptions over the last few recent years. As a result, our employee headcount has increased, and we expect it to continue to grow over the next year. For example, from the end of fiscal 2024 2025 to the end of fiscal 2025, 2026, our headcount increased from 15,289 to 16,068 employees. to 21,921 employees, including approximately 4,223 additional headcount as a result of the CyberArk acquisition. In addition, as we have grown, the number of end-customers has also increased, and we have managed more complex deployments of our products and subscriptions with larger end-customers. The growth and expansion of our business and product, subscription, products, subscriptions, and support offerings places a significant strain on our management, operational, and financial resources. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner. We may not be able to successfully implement, scale, or manage improvements to our systems, processes, and controls in an efficient or timely manner, which could result in material disruptions of our operations and business. In addition, our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud. We may also experience difficulties in managing improvements to our systems, processes, and controls, or in connection with third-party software licensed to help us with such improvements. Any future growth would add complexity to our organization and require effective coordination throughout our organization. coordination. Failure to manage any future growth effectively could result in increased costs, disrupt our existing disruption to end-customer relationships, reduce reduced demand for or limit us to smaller deployments of our products, or materially material harm to our business performance and operating results.
Added · Removed · word-level comparison of the two filings
Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.
rewrittenMacro & demandSimplified language on growth sustainability and profitability maintenance; removed prior loss history and specific demand shift scenarios.
We have experienced revenue growth rates of 24% and 15% in fiscal 2026 and fiscal 2025, respectively. Our revenue for any quarterly or annual period should not be relied upon as an indication of our future revenue or revenue growth for any future period. If we are unable to maintain consistent or increasing revenue or revenue growth, the market price of our common stock could be volatile, and it may be difficult for us to maintain profitability or maintain or increase cash flow on a consistent basis.
In addition, we anticipate that our operating expenses will continue to increase as our business grows. Our growth efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenues sufficiently to offset increasing expenses. Revenue growth may slow or decline, including due to slowing or declining demand, increasing competition, market shifts, or a failure to capitalize on growth opportunities. We have also entered into substantial capital commitments for operating lease obligations and other purchase commitments. If we are unable to increase our revenue sufficiently to offset these costs and commitments, our profitability, cash flow, financial condition, and operating results may suffer.
Compare with the 2025 10-K
Prior heading: Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.
We have experienced revenue growth rates of 14.9% 24% and 16.5% 15% in fiscal 2025 2026 and fiscal 2024, 2025, respectively. Our revenue for any quarterly or annual period should not be relied upon as an indication of our future revenue or revenue growth for any future period. If we are unable to maintain consistent or increasing revenue or revenue growth, the market price of our common stock could be volatile, and it may be difficult for us to maintain profitability or maintain or increase cash flow on a consistent basis. In addition, we have incurred losses in fiscal years prior to fiscal 2023. We anticipate that our operating expenses will continue to increase in the foreseeable future as we continue to grow our business. business grows. Our growth efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenues sufficiently, or at all, sufficiently to offset increasing expenses. Revenue growth may slow or revenue may decline for a number of possible reasons, decline, including due to slowing demand for our products or subscriptions, declining demand, increasing competition, a decrease in the growth of, or a demand shift in, our overall market, market shifts, or a failure to capitalize on growth opportunities. We have also entered into a substantial amount of capital commitments for operating lease obligations and other purchase commitments. Any failure to increase our revenue as we grow our business could prevent us from maintaining profitability or maintaining or increasing cash flow on a consistent basis, or satisfying our capital commitments. If we are unable to navigate increase our revenue sufficiently to offset these challenges as we encounter them, costs and commitments, our business, profitability, cash flow, financial condition, and operating results may suffer.
Added · Removed · word-level comparison of the two filings
T2Our operating results may vary significantly from period to period, including due to seasonality, which makes our results difficult to predict and could cause our results to fall short of expectations.
rewrittenMacro & demandAdded explicit seasonality language: Q2 and Q4 record greater revenue due to end-customer budget cycles, sales compensation structure, and calendar-year planning; noted variations may become more pronounced as company grows.
Our operating results have fluctuated in the past, and will likely continue to fluctuate in the future, as a result of a number of factors, many of which are outside of our control, including those described in this Risk Factors section. For example, we have historically received a substantial portion of sales orders and generated a substantial portion of revenue during the last few weeks of each fiscal quarter. If expected revenue at the end of any fiscal quarter is delayed for any reason, including failed purchase orders, logistics delays, inventory management issues, trade compliance requirements (and changes to such requirements), or failure of systems related to order review and processing, our revenue could fall below our expectations and the estimates of analysts for that quarter.
In addition, seasonal factors may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal quarters, driven primarily by end-customer budget cycles, our annual sales compensation structure, and the timing of calendar-year budget planning. As we grow, these seasonal and cyclical variations may become more pronounced. Due to these fluctuations, comparing our results on a period-to-period basis may not be meaningful, and our past results should not be relied on as an indication of our future performance.
This variability and unpredictability could also result in our failure to meet our revenue, margin, or other operating result expectations contained in any forward-looking statements (including financial or business expectations we have provided) or those of securities analysts or investors for a particular period. If we fail to meet or exceed such expectations for these, or any other, reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits.
Compare with the 2025 10-K
Prior heading: Our operating results may vary significantly from period to period, which makes our results difficult to predict and could cause our results to fall short of expectations, and such results may not be indicative of future performance.
Our operating results have fluctuated in the past, and will likely continue to fluctuate in the future, as a result of a number of factors, many of which are outside of our control and may be difficult to predict, control, including those factors described in this Risk Factor Factors section. For example, we have historically received a substantial portion of sales orders and generated a substantial portion of revenue during the last few weeks of each fiscal quarter. If expected revenue at the end of any fiscal quarter is delayed for any reason, including the failure of anticipated failed purchase orders to materialize (particularly for large enterprise end-customers with lengthy sales cycles), our orders, logistics partners’ inability to ship products prior to fiscal quarter-end to fulfill purchase orders received near the end of a fiscal quarter, our failure to manage delays, inventory management issues, trade compliance requirements (and changes to meet demand, any such requirements), or failure of our systems related to order review and processing, or any delays in shipments based on trade compliance requirements (including new compliance requirements imposed by new or renegotiated trade agreements), our revenue could fall below our expectations and the estimates of analysts for that quarter. In addition, seasonal factors may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal quarters, driven primarily by end-customer budget cycles, our annual sales compensation structure, and the timing of calendar-year budget planning. As we grow, these seasonal and cyclical variations may become more pronounced. Due to these fluctuations, comparing our revenue, margins, or other operating results on a period-to-period basis may not be meaningful, and our past results should not be relied on as an indication of our future performance. This variability and unpredictability could also result in our failure to meet our revenue, margin, or other operating result expectations contained in any forward-looking statements (including financial or business expectations we have provided) or those of securities analysts or investors for a particular period. If we fail to meet or exceed such expectations for these, or any other, reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits.
Added · Removed · word-level comparison of the two filings
RISKS RELATED TO OUR PRODUCTS AND TECHNOLOGY
If we are unable to sell new and additional products, subscriptions, and support offerings to existing end-customers or attract new customers, especially large enterprise customers, our future revenue and operating results will be harmed.
rewrittenCompetitionAdded emphasis on platformization strategy costs, switching costs, and geopolitical/economic environment impacts on customer spending; removed product breadth and deployment complexity details.
Our future success depends, in part, on our ability to expand the deployment of our portfolio and new offerings with existing end-customers, especially large enterprise customers, including through our platformization and go-to-market strategies, and to attract new customers. The rate at which existing end-customers purchase additional products, subscriptions, and support offerings, and our ability to win new customers, depend on a number of factors, including the perceived need for security products, including related subscription and support offerings, general economic conditions, switching costs from incumbent vendors, and the time and resources required to deploy our solutions. We are engaging in costly marketing and sales efforts to accelerate our strategies, including platformization, which may not be as successful as intended.
Any deterioration in general economic conditions, including as a result of the geopolitical or economic environment, may cause current and prospective customers to delay or cut their overall security and IT spending. If our efforts to sell additional products and subscriptions to existing end-customers or attract new customers are not successful, our revenues may grow more slowly than expected or decline.
Sales to large enterprise end-customers involve risks not typically present with smaller entities, including longer sales cycles, the risk that substantial resources may be spent on a potential end-customer that does not ultimately purchase our products, subscriptions, and support offerings, and increased purchasing power and leverage held by large end-customers in negotiating contractual arrangements. Deployments for large enterprise end-customers are also more complex, require greater product functionality and scalability, and are resource-intensive. Failure to realize sales from large enterprise end-customers could materially and adversely affect our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: If we are unable to sell new and additional product, subscription, and support offerings to our end-customers, especially to large enterprise customers, our future revenue and operating results will be harmed.
Our future success depends, in part, on our ability to expand the deployment of our portfolio and new offerings with existing end-customers, especially large enterprise customers, including through our platformization strategy, and create demand for our go-to-market strategies, and to attract new offerings. customers. The rate at which our existing end-customers purchase additional products, subscriptions, and support depends offerings, and our ability to win new customers, depend on a number of factors, including the perceived need for additional security products, including related subscription and support offerings, general economic conditions, switching costs from incumbent vendors, and the time and resources required to deploy our solutions. We are engaging in costly marketing and sales efforts to accelerate our strategies, including platformization, which may not be as well successful as intended. Any deterioration in general economic conditions. conditions, including as a result of the geopolitical or economic environment, may cause current and prospective customers to delay or cut their overall security and IT spending. If our efforts to sell additional products and subscriptions to our existing end-customers or attract new customers are not successful, our revenues may grow more slowly than expected or decline. Sales to large enterprise end-customers, which is part of our growth strategy, end-customers involve risks that may not be present, or that are typically present to a lesser extent, with sales to smaller entities, such as (a) including longer sales cycles and cycles, the associated risk that substantial time and resources may be spent on a potential end-customer that elects does not to ultimately purchase our products, subscriptions, and support, support offerings, and (b) increased purchasing power and leverage held by large end-customers in negotiating contractual arrangements. Deployments for large enterprise end-customers are also more complex, require greater product functionality, scalability, functionality and a broader range of services, scalability, and are more time-consuming and resource-consuming. All of these factors add further risk to business conducted with these end-customers. resource-intensive. Failure to realize sales from large enterprise end-customers could materially and adversely affect our business, operating results, and financial condition.condition, and operating results.
Added · Removed · word-level comparison of the two filings
We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.
rewrittenMacro & demandAdded that subscription revenue may not be reflected in results at all, removing specifics on historical revenue mix and customer behavior factors.
Subscription and support revenue accounts for a significant portion of our revenue, comprising 80% of total revenue in fiscal 2026, 81% in fiscal 2025, and 80% in fiscal 2024. Sales and renewals of subscription and support contracts may decline and fluctuate as a result of a number of factors, including end-customer satisfaction levels with our products and subscriptions, subscription outages, product uptime or latency, pricing, and reductions in our end-customers’ spending levels. T3Existing end-customers have no contractual obligation to renew their subscription and support contracts after their initial contract period and may renew for shorter contract terms or terms that are less economically beneficial to us, or not at all.
If our sales of new or renewal subscription and support contracts decline, our total revenue and revenue growth rate may decline. Because we recognize subscription and support revenue over the term of the service period typically one to five years, a decline in subscription or support contracts in any one fiscal quarter will not be fully or immediately reflected in that quarter’s revenue but will negatively affect future fiscal quarters.
Compare with the 2025 10-K
Prior heading: We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.
Subscription and support revenue accounts for a significant portion of our revenue, comprising 80.5% 80% of total revenue in fiscal 2025, 80.0% of total revenue 2026, 81% in fiscal 2024, 2025, and 77.1% of total revenue 80% in fiscal 2023. 2024. Sales and renewals of subscription and support contracts may decline and fluctuate as a result of a number of factors, including end-customers’ level of end-customer satisfaction levels with our products and subscriptions, the frequency and severity of subscription outages, our product uptime or latency, the prices of our products and subscriptions, pricing, and reductions in our end-customers’ spending levels. Existing end-customers have no contractual obligation to, and may not, to renew their subscription and support contracts after the completion of their initial contract period. Additionally, our end-customers period and may renew their subscription and support agreements for shorter contract lengths terms or on other terms that are less economically beneficial to us. us, or not at all. If our sales of new or renewal subscription and support contracts decline, our total revenue and revenue growth rate may decline, and our business will suffer. In addition, because decline. Because we recognize subscription and support revenue over the term of the relevant service period, which is period typically one to five years, a decline in subscription or support contracts in any one fiscal quarter will not be fully or immediately reflected in revenue in that fiscal quarter quarter’s revenue but will negatively affect our revenue in future fiscal quarters.
Added · Removed · word-level comparison of the two filings
T4Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
addedMacro & demandAdded risk that consumption-based pricing for observability and AI offerings exposes company to customer optimization behavior reducing usage and creating revenue volatility.
A growing portion of our revenue is generated from offerings priced on a consumption or usage basis, including certain of our observability and AI-related offerings. Pricing on this basis may result in significant near-term revenue growth as customers scale their usage but also creates exposure to customer optimization behavior, where customers who have rapidly increased usage subsequently seek to reduce, optimize, or reconfigure their consumption or usage to lower costs. This dynamic has been observed in the industry with cloud-native customers and, more recently, with AI-native customers, whose data volumes and usage patterns can fluctuate significantly. Certain customer cohorts, including large enterprises and AI-native customers, may represent a meaningful portion of our consumption- or usage-based revenue growth, and any material optimization or reduction in usage by these cohorts, or their failure to renew subscriptions on comparable terms, could result in revenue volatility. If we are unable to accurately forecast or manage consumption or usage dynamics, our business, financial condition, and operating results may be adversely affected.
The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.
rewrittenCompetitionNarrowed focus to pricing decreases' impact on revenue and gross profits, removing discussion of product introductions and competitive pressures.
The sales prices for our products, subscriptions, and support offerings may decline for a variety of reasons, including competitive pricing pressures, discounts, changes in our product mix, anticipation of new offerings, or promotional programs. We also anticipate that sales prices and gross profits for our products, subscriptions, and support offerings could decrease over product life cycles. Declining sales prices could reduce our revenue, gross profits, and profitability and adversely impact our financial and operational results.
Compare with the 2025 10-K
Prior heading: The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.
The sales prices for our products, subscriptions, and support offerings may decline for a variety of reasons, including competitive pricing pressures, discounts, a change changes in our mix of products, subscriptions, and support offerings, product mix, anticipation of the introduction of new products, subscriptions, or support offerings, or promotional programs or pricing pressures. Furthermore, we programs. We also anticipate that the sales prices and gross profits for our products products, subscriptions, and support offerings could decrease over product life cycles. Declining sales prices could adversely affect reduce our revenue, gross profits, and profitability.profitability and adversely impact our financial and operational results.
Added · Removed · word-level comparison of the two filings
We rely on our channel partners to sell a substantial portion of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
rewrittenConcentrationChanged from "substantially all" to "substantial portion" of products sold through channel partners; reduced distributor concentration from three to one distributor in 2026.
A substantial portion of our revenue is generated by sales through our channel partners, including distributors and resellers. T5For fiscal 2026, two distributors individually represented 10% or more of our total revenue and in the aggregate represented 30% of our total revenue. As of July 31, 2026, one distributor individually represented 19% of our gross accounts receivable.
Training and programs provided to our channel partners to assist them in selling our products, subscriptions, and support offerings may not be effective or utilized. Our channel partners may be unsuccessful in marketing, selling, and supporting our products and subscriptions, and we may not be able to incentivize our channel partners to sell our products and subscriptions, or our channel partners may have incentives to promote our competitors' products and subscriptions. Our agreements with channel partners may generally be terminated for any reason by either party with advance notice prior to each annual renewal date, and we cannot be certain that we will retain them or secure additional or replacement channel partners.
Any new channel partner requires extensive training and may take months to achieve productivity. Our channel partner structure could also subject us to lawsuits, liability, and reputational harm if, for example, channel partners misrepresent the functionality of our products or subscriptions or violate laws or our policies. If we fail to effectively manage our channel partners, our ability to sell our products and subscriptions and our operating results will be harmed.
Compare with the 2025 10-K
Prior heading: We rely on our channel partners to sell substantially all of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
Substantially all A substantial portion of our revenue is generated by sales through our channel partners, including distributors and resellers. For fiscal 2025, three 2026, two distributors individually represented 10% or more of our total revenue and in the aggregate represented 44.2% 30% of our total revenue. As of July 31, 2025, three distributors 2026, one distributor individually represented 10% or more of our gross accounts receivable and in the aggregate represented 44.8% 19% of our gross accounts receivable. We provide Training and programs provided to our channel partners with specific training and programs to assist them in selling our products, including subscriptions subscriptions, and support offerings, but there can be no assurance that these steps will offerings may not be utilized effective or effective. In addition, our utilized. Our channel partners may be unsuccessful in marketing, selling, and supporting our products and subscriptions. We subscriptions, and we may not be able to incentivize these our channel partners to sell our products and subscriptions to end-customers and, in particular, to large enterprises. These subscriptions, or our channel partners may also have incentives to promote our competitors’ competitors' products and may devote more resources to the marketing, sales, and support of competitive products. subscriptions. Our agreements with our channel partners may generally be terminated for any reason by either party with advance notice prior to each annual renewal date. We date, and we cannot be certain that we will retain these channel partners them or that we will be able to secure additional or replacement channel partners. In addition, any Any new channel partner requires extensive training and may take several months or more to achieve productivity. Our channel partner sales structure could also subject us to lawsuits, potential liability, and reputational harm if, for example, any of our channel partners misrepresent the functionality of our products or subscriptions to end-customers or violate laws or our corporate policies. If we fail to effectively manage our sales channels or channel partners, our ability to sell our products and subscriptions and our operating results will be harmed.
Added · Removed · word-level comparison of the two filings
We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.
rewrittenCredit & liquiditySharpened credit and liquidity risk language; removed details on open credit arrangements, financing programs, and risk mitigation specifics.
Most of our sales are made on an open credit basis, and we have also experienced demands for customer financing and deferred payments due to, among other things, macro-economic conditions. Increases in deferred payments negatively impact our short-term cash flows and subject us to risk of non-payment, including as a result of insolvency. Our efforts to monitor customer payment capability and maintain reserves adequate to cover exposure for doubtful accounts may not be effective. Our exposure to these credit risks may increase if our customers are adversely affected by an economic downturn. In the past, we have experienced non-material losses due to customer bankruptcies or insolvency. If credit market turmoil makes it more difficult for customers to obtain financing or affects their ability to pay, or if these losses increase, our business, financial condition, and operating results could be materially adversely affected.
Compare with the 2025 10-K
Prior heading: We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.
Most of our sales are made on an open credit basis. Beyond our open credit arrangements, basis, and we have also experienced demands for customer financing and deferred payments due to, among other things, macro-economic conditions. Increases in deferred payments result in payments being made over time, negatively impacting impact our short-term cash flows, flows and subject us to risk of non-payment by our customers, non-payment, including as a result of insolvency. We Our efforts to monitor customer payment capability in granting such financing arrangements, seek to limit the amounts to what we believe customers can pay and maintain reserves we believe are adequate to cover exposure for doubtful accounts to mitigate credit risks of these customers. However, there can be no assurance that these programs will be effective in reducing our credit risks. To the degree that turmoil in the credit markets makes it more difficult for some customers to obtain financing, those customers’ ability to pay could may not be adversely impacted, which in turn could have a material adverse impact on our business, operating results, and financial condition. effective. Our exposure to the these credit risks relating to the financing activities described above may increase if our customers are adversely affected by a global economic downturn or periods of an economic uncertainty. If we are unable to adequately control these risks, our business, operating results, and financial condition could be harmed. downturn. In addition, in the past, we have experienced non-material losses due to customer bankruptcies among customers. or insolvency. If credit market turmoil makes it more difficult for customers to obtain financing or affects their ability to pay, or if these losses increase due to global economic conditions, they could harm increase, our business and business, financial condition.condition, and operating results could be materially adversely affected.
Added · Removed · word-level comparison of the two filings
T6A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.
rewrittenConcentrationNarrowed government sales risk disclosure; removed specifics on federal certifications, compliance standards, audit consequences, and distributor termination impacts.
Sales to government entities are subject to a number of risks. Selling to government entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront investment of resources without any assurance of generating a sale and involving longer sales cycles. The substantial majority of our government sales to date have been made indirectly through our channel partners. Government certification and technical requirements may change, and if our products and subscriptions fail to achieve or are late in achieving compliance with these certifications and standards or technical requirements, we may be disqualified or restricted from selling to such entities or be at a competitive disadvantage. Government demand and payment for our products, subscriptions, and support offerings may be impacted by government shutdowns, changes in administrations, budgetary cycles, contracting policies, fiscal policies, and funding authorizations, with funding reductions or delays adversely affecting public sector demand for our products, subscriptions, and support offerings.
Government entities may also have rights to terminate contracts for convenience or due to a default, and government audits of their contractors, suppliers, or vendors could result in the government refusing to continue purchasing our products, subscriptions, and support offerings, revenue reductions, or fines and civil or criminal liability, all of which may adversely impact our operating results. Additionally, the U.S. government may require certain products to be manufactured domestically or in other relatively high-cost manufacturing locations, and we may not manufacture all products in locations that meet such requirements, affecting our ability to sell our offerings to the U.S. government.
Compare with the 2025 10-K
Prior heading: A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.
Sales to government entities are subject to a number of risks. Selling to government entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront time and expense investment of resources without any assurance that these efforts will generate of generating a sale. sale and involving longer sales cycles. The substantial majority of our government sales to date to government entities have been made indirectly through our channel partners. Government certification or and technical requirements for products and subscriptions like ours may change, thereby restricting our ability to sell into the federal government sector until we have attained the revised certification or technical requirements. If and if our products and subscriptions are late in achieving or fail to achieve compliance with these certifications and standards or technical requirements, or our competitors achieve are late in achieving compliance with these certifications and standards or technical requirements, we may be disqualified or restricted from selling our products, subscriptions, and support offerings to such governmental entity, entities or be at a competitive disadvantage, which would harm our business, operating results, and financial condition. disadvantage. Government entity demand and payment for our products, subscriptions, and support offerings may be impacted by government shutdowns, changes in governmental administrations, public sector budgetary cycles, contracting policies, fiscal policies, contracting policies or requirements, and funding authorizations, and efforts by a government to evaluate and reduce overall government spending and analyze and enhance its operational efficiency, with funding reductions or delays adversely affecting public sector demand for our products, subscriptions, and support offerings. Government entities may also have statutory, contractual, or other legal rights to terminate contracts with our distributors and resellers for convenience or due to a default, and any such termination may adversely impact our future operating results. Governments routinely investigate and audit government contractors’ administrative processes, and any unfavorable audit audits of their contractors, suppliers, or vendors could result in the government refusing to continue buying purchasing our products, subscriptions, and support offerings, a reduction of revenue, revenue reductions, or fines or and civil or criminal liability if the audit uncovers improper or illegal activities, liability, all of which could may adversely impact our operating results in a material way. results. Additionally, the U.S. government may require certain of the products that it purchases to be manufactured in the United States domestically or in other relatively high-cost manufacturing locations, and we may not manufacture all products in locations that meet such requirements, affecting our ability to sell these products, subscriptions, and support our offerings to the U.S. government.
Added · Removed · word-level comparison of the two filings
We face intense competition and we may lack sufficient financial or other resources to maintain or improve our competitive position.
rewrittenCompetitionNamed specific competitors (CrowdStrike, Okta, SailPoint, Datadog, Dynatrace, Elasticsearch); added cloud hyperscalers and AI companies as emerging competitive threats; added AI incorporation as competitive factor.
The industry for enterprise security products and the other spaces in which we have offerings is intensely competitive, and we expect competition to increase in the future from established competitors and new market entrants. Our main competitors fall into four categories:
•large companies that incorporate security or observability features in their products, such as Alphabet Inc., Cisco Systems, Inc., and Microsoft Corporation, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;
•independent vendors that may offer a mix of security products, such as Check Point Software Technologies Ltd., CrowdStrike Holdings, Inc., Delinea, Inc., Fortinet, Inc., Okta, Inc., SailPoint Technologies, Inc., and Zscaler, Inc., vendors that may offer a mix of observability products, such as DataDog, Inc., Dynatrace, Inc., and elasticsearch B.V., or vendors that may offer a mix of security and observability products;
•startups and point-product vendors that offer independent or emerging solutions across various areas of security; and •public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).
Some of our competitors have or may attain greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do. Our competitors may devote greater resources to the research and development, promotion and sale of products and services, offer lower pricing, and have broader product and service offerings and more mature intellectual property portfolios to gain business in a manner that discourages users from purchasing our products and subscriptions, including incorporating cybersecurity features into their existing products or services, product bundling, selling at zero or negative margins, and offering concessions. We also face competition from companies with entrenched legacy offerings.
End-user customers who have invested substantial resources in their existing infrastructure may prefer to continue purchasing from their existing suppliers rather than switch to our products and subscriptions. As our customers refresh security products, achieve efficiencies, or face budget constraints or economic downturns, they may seek to consolidate vendors or add solutions to their existing infrastructure rather than replacing it with our products and subscriptions.
The maturity and expansion of the enterprise cybersecurity space may attract new players, including cloud hyperscalers, advance AI companies and enterprise software companies in adjacent industries, which may meaningfully enter or further expand into additional cybersecurity categories, including the identity security category. Conditions in our market could change rapidly as a result of technological advancements, including with respect to artificial intelligence ("AI"), acquisitions or strategic investments by our competitors, or continuing market consolidation. Our competitors may develop new or disruptive technologies, products, or services that are equal or superior to ours, more successfully incorporate AI into their products and achieve higher market acceptance of their AI solutions, or deliver products to market more quickly than we can.
To compete successfully, we must accurately anticipate technology developments and deliver innovative, relevant, and useful products and technologies in a timely manner. Our current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their resources or offerings.
These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, and loss of market share. If we are unable to compete successfully, or if competing successfully requires us to take aggressive pricing or other actions, our business, financial condition, and operating results would be adversely affected.
Compare with the 2025 10-K
Prior heading: We face intense competition in our market and we may lack sufficient financial or other resources to maintain or improve our competitive position.
The industry for enterprise security products and the other spaces in which we have offerings is intensely competitive, and we expect competition to increase in the future from established competitors and new market entrants. Our main competitors fall into four categories: •large companies that incorporate security or observability features in their products, such as Cisco, Microsoft, Alphabet Inc., Cisco Systems, Inc., and Microsoft Corporation, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market; •independent vendors that may offer a mix of security vendors, products, such as Check Point, Point Software Technologies Ltd., CrowdStrike Holdings, Inc., Delinea, Inc., Fortinet, CrowdStrike, Inc., Okta, Inc., SailPoint Technologies, Inc., and Zscaler, Inc., vendors that may offer a mix of observability products, such as DataDog, Inc., Dynatrace, Inc., and Wiz, elasticsearch B.V., or vendors that may offer a mix of security and observability products; •startups and point-product vendors that offer independent or emerging solutions across various areas of security; and •public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud). Some of our competitors have or may attain greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do. They Our competitors may be able to devote greater resources to the research and development, promotion and sale of products and services than we can, and they may services, offer lower pricing than we do. Further, they may have greater resources for research and development of new technologies, the provision of customer support, pricing, and the pursuit of acquisitions or other strategic investments. They may also have larger broader product and service offerings and more mature intellectual property portfolios, and broader and more diverse product and service offerings, which allow them to leverage their relationships based on other products or incorporate functionality into existing products portfolios to gain business in a manner that discourages users from purchasing our products and subscriptions, including incorporating cybersecurity features into their existing products or services and services, product bundling, selling at zero or negative margins, and offering concessions or a closed technology offering. Some competitors may have broader distribution and established relationships with distribution partners and end-customers. Other competitors specialize in providing protection from a single type of security threat, which may allow them to deliver these specialized security products to the market more quickly than we can. concessions. We also face competition from companies that have with entrenched legacy offerings at end-user customers. offerings. End-user customers who have also often invested substantial personnel and financial resources to design and operate in their networks and have established deep relationships with other providers of networking and security products. As a result, these organizations existing infrastructure may prefer to purchase continue purchasing from their existing suppliers rather than add or switch to a new supplier such as us. In addition, as our products and subscriptions. As our customers refresh the security products bought in prior years, they may seek to consolidate vendors, which may result in current customers choosing to purchase products from our competitors. Due to products, achieve efficiencies, or face budget constraints or economic downturns, organizations they may seek to consolidate vendors or add solutions to their existing network security infrastructure rather than replacing it with our products and subscriptions. The maturity and expansion of the enterprise cybersecurity space may attract new players, including cloud hyperscalers, advance AI companies and enterprise software companies in adjacent industries, which may meaningfully enter or further expand into additional cybersecurity categories, including the identity security category. Conditions in our market could change rapidly and significantly as a result of technological advancements, partnering, including with respect to artificial intelligence ("AI"), acquisitions or strategic investments by our competitors, or continuing market consolidation. Our competitors and potential competitors may be able to develop new or disruptive technologies, products, or services, and leverage new business models services that are equal or superior to ours, more successfully incorporate AI into their products and achieve greater higher market acceptance of their AI solutions, or deliver products and services, disrupt our markets, and increase sales by utilizing different distribution channels to market more quickly than we do. In addition, new and enhanced technologies, including AI and machine learning, continue to increase our competition. can. To compete successfully, we must accurately anticipate technology developments and deliver innovative, relevant, and useful products, services, products and technologies in a timely manner. Some of our competitors have made or could make acquisitions of businesses that may allow them to offer more directly competitive and comprehensive solutions than they had previously offered and adapt more quickly to new technologies and end-customer needs. Our current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their resources or product or service offerings. These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, and loss of market share. If we are unable to compete successfully, or if competing successfully requires us to take aggressive pricing or other actions, our business, financial condition, and operating results of operations would be adversely affected.
Added · Removed · word-level comparison of the two filings
The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
addedCompetitionAdded risk that undefined "identity security" market definition could lead to mischaracterization of offerings and unfavorable analyst evaluations affecting customer purchasing.
We have significantly expanded our participation in what is commonly referred to as the “identity security” market. However, this market lacks a standardized definition and is subject to varying interpretations by industry analysts, customers, and competitors. This ambiguity could lead to mischaracterization of our identity security products or market positioning by industry stakeholders, resulting in unfavorable evaluations, reviews, or accreditations. Industry analyst reports and rankings can materially influence customer purchasing decisions in the security industry, and unfavorable reviews, downgrades in accreditation, or evolving definitions of the identity security category could negatively affect our reputation, competitive standing, and ability to attract and retain customers.
Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.
addedCompetitionAdded risk that customer vendor consolidation trends may favor competitors offering broader platforms, disadvantaging company despite platformization strategy.
Enterprise cybersecurity buyers are increasingly seeking to consolidate their vendors to reduce costs, complexity, and integration challenges. While our platformization strategy is designed to benefit from this trend, consolidation may also create opportunities for competitors, including large cybersecurity platform vendors, cloud hyperscalers, and enterprise software companies, to offer broader bundled solutions that include capabilities in categories where we compete, such as identity security and observability. If customers choose to consolidate with vendors offering more comprehensive suites, or if competitors more successfully utilize acquisitions or partnerships to combine capabilities, we may be at a competitive disadvantage. Furthermore, organizations continuously evaluate their information security priorities and may allocate budgets to solutions offered by our competitors, or may not adopt or expand the use of our solutions, which could adversely affect our business, financial condition, and operating results.
T7Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.
addedCompetitionAdded risk that cloud providers and AI model companies offer native security and observability capabilities bundled at low cost, creating pricing pressure and demand reduction.
The major public cloud infrastructure providers increasingly offer native security, identity, and observability capabilities that compete with our products and subscriptions. These providers have significant resources and may bundle native capabilities with their cloud infrastructure services at low or no incremental cost to customers, may leverage privileged access to their platforms and telemetry, and may design their native offerings to integrate more seamlessly with their infrastructure than third-party solutions can. As customers increasingly deploy workloads across multiple cloud environments, or as cloud providers expand the scope and depth of their native security and observability capabilities, demand for our offerings could be adversely affected. We may also face pricing pressure as competitors utilize cloud provider economics or offer bundled solutions at reduced total cost of ownership.
In addition, frontier or foundational AI model providers, or similar companies with advanced large language model capabilities, have entered or may enter the cybersecurity and observability markets, whether directly, through partnerships, or by enabling third parties to build competing security applications on top of their models. These companies possess substantial capital, technical talent, and have developed, or proprietary access to, foundational or frontier AI models. Their ability to rapidly iterate on model capabilities, attract AI research talent, and leverage significant compute infrastructure may allow them to introduce competing security capabilities more quickly or at lower cost than we can. If these or other AI companies develop and commercialize security products or embed security functionality into their broader AI platforms, customers may choose to consolidate their security spend with such providers rather than purchase our solutions, which could adversely affect our revenue, market share, and competitive position.
We have acquired and may in the future acquire other businesses, which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
rewrittenOtherRemoved specific reference to pending CyberArk acquisition; generalized language to cover future acquisitions while adding financial condition impact language.
As part of our business strategy, we acquire and make investments in complementary companies, products, or technologies. We continue to evaluate such opportunities and expect to continue to make such acquisitions and investments in the future. The identification of suitable acquisition candidates is difficult, and we may not be able to complete such acquisitions on favorable terms, if at all. In addition, we may be subject to claims or liabilities assumed from an acquired company, product, or technology; acquisitions we complete could be viewed negatively by our end-customers, investors, and securities analysts; and we may incur costs and expenses necessary to address an acquired company’s failure to comply with laws and governmental rules and regulations.
Additionally, we may be subject to litigation or other claims in connection with the acquired company, product, or technology, including claims from terminated employees, customers, former stockholders, or other third parties, which may differ from or be more significant than the risks our business faces.
If we are unsuccessful at integrating past or future acquisitions in a timely manner or at all, our revenue and operating results could be adversely affected. Any integration process may require significant time and resources, which may disrupt our ongoing business and divert management’s attention. We may have difficulty retaining key personnel or customers of the acquired business, or may not successfully evaluate or utilize acquired technology, products, or personnel, realize anticipated synergies, or accurately forecast the financial impact of an acquisition or its integration, including accounting charges and any potential impairment of goodwill and intangible assets. In particular, we believe there are significant benefits and synergies that may be realized from our recent acquisitions of CyberArk and Chronosphere, including through leveraging our combined products, scale, and enterprise customer bases.
However, integrating these businesses is a complex process that may disrupt our existing operations if not implemented efficiently. The full benefits of these acquisitions, including the anticipated sales or growth opportunities, may not be realized as expected or within the anticipated time frame, or at all.
We have recorded, and may in the future record, liability for contingent consideration obligations from acquisitions that are to be settled in cash, the fair value of which is assessed on a quarterly basis. If changes are made in our assumptions used to determine the liability’s fair value or our assumptions are incorrect, adjustments could be made that may have a material impact, favorable or unfavorable, on our operating results. We may also be required to make cash payments of contingent consideration in excess of its initial fair value, or in excess of our expectations for a particular period, which could adversely impact cash flows.
We may have to pay cash, incur debt, or issue equity or equity-linked securities to pay for any future acquisitions, each of which could adversely affect our financial condition or the market price of our common stock and result in dilution to our stockholders.
In addition, any acquisitions may be viewed negatively by our customers, financial markets, or investors and may not ultimately strengthen our competitive position or achieve our goals and business strategy. The occurrence of any of these risks could harm our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: We have and may in the future acquire other businesses (including CyberArk), which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
As part of our business strategy, we acquire and make investments in complementary companies, products, or technologies. We continue to evaluate such opportunities and expect to continue to make such acquisitions and investments in the future, such as our pending acquisition of CyberArk Software Ltd. (“CyberArk”). future. The identification of suitable acquisition candidates is difficult, and we may not be able to complete such acquisitions on favorable terms, if at all. In addition, we may be subject to claims or liabilities assumed from an acquired company, product, or technology; acquisitions we complete could be viewed negatively by our end-customers, investors, and securities analysts; and we may incur costs and expenses necessary to address an acquired company’s failure to comply with laws and governmental rules and regulations. Additionally, we may be subject to litigation or other claims in connection with the acquired company, product, or technology, including claims from terminated employees, customers, former stockholders, or other third parties, which may differ from or be more significant than the risks our business faces. If we are unsuccessful at integrating past or future acquisitions, including the pending acquisition of CyberArk, acquisitions in a timely manner, or the technologies, products, manner or operations associated with such acquisitions, into our company, at all, our revenue and operating results could be adversely affected. Any integration process may require significant time and resources, which may disrupt our ongoing business and divert management’s attention, and we may not be able to manage the integration process successfully or in a timely manner. attention. We may have difficulty retaining key personnel or customers of the acquired business. We business, or may not successfully evaluate or utilize any acquired technology, products, or personnel, realize anticipated synergies from an acquisition, synergies, or accurately forecast the financial impact of an acquisition transaction and integration of such acquisition, or its integration, including accounting charges and any potential impairment of goodwill and intangible assets recognized in connection with such acquisitions. assets. In particular, we believe that there are significant benefits and synergies that may be realized from our proposed acquisition recent acquisitions of CyberArk, CyberArk and Chronosphere, including through leveraging our and CyberArk’s combined products, scale, and combined enterprise customer bases. However, the efforts to realize the anticipated benefits and synergies will be integrating these businesses is a complex process and that may disrupt both our and CyberArk’s existing operations if not implemented in a timely and efficient manner. efficiently. The full benefits of the proposed acquisition of CyberArk, these acquisitions, including the anticipated sales or growth opportunities, may not be realized as expected or may not be achieved within the anticipated time frame, or at all. We have recorded, and may in the future record, liability for contingent consideration obligations from acquisitions that are to be settled in cash, the fair value of which is assessed on a quarterly basis. If changes are made in our assumptions used to determine the liability’s fair value or our assumptions are incorrect, adjustments could be made that may have a material impact, favorable or unfavorable, on our operating results. We may also be required to make cash payments of contingent consideration in excess of its initial fair value, or in excess of our expectations for a particular period, which could adversely impact cash flows. We may have to pay cash, incur debt, or issue equity or equity-linked securities to pay for any future acquisitions, including the pending acquisition of CyberArk, each of which could adversely affect our financial condition or the market price of our common stock, stock and result in dilution to our stockholders. Furthermore, the sale or issuance of equity or equity-linked debt to finance any future acquisitions could result in dilution to our stockholders. In addition, any acquisitions may be viewed negatively by our customers, financial markets, or investors and may not ultimately strengthen our competitive position or achieve our goals and business strategy. The occurrence of any of these risks could harm our business, operating results, and financial condition.condition, and operating results.
Added · Removed · word-level comparison of the two filings
T8As a result of the CyberArk acquisition, the scope and size of our business have substantially changed, which resulted in certain incremental risks, including increased competition.
rewrittenCompetitionChanged from prospective language about anticipated CyberArk acquisition effects to completed acquisition; removed details on management distraction and CyberArk's competitive landscape.
Our recent CyberArk acquisition has expanded the scope and size of our business by adding substantial assets and operations to our existing business. The integration process for CyberArk could create uncertainty for our and CyberArk’s employees, partners, and customers, divert senior management’s attention, and result in disruption to existing business relationships and the development of new business relationships.
Our success, including with respect to realizing the anticipated benefits and synergies from the CyberArk acquisition, will depend, in part, on our ability to manage our expansion, which poses numerous risks and uncertainties, including the need to integrate the operations and business of CyberArk into our existing business in a timely and efficient manner, to combine systems and management controls, and to integrate relationships with industry contacts and business partners. In addition, we will be required to devote significant attention and resources to successfully align our and CyberArk’s business practices and operations. This process may disrupt our business and, if ineffective, would limit the anticipated benefits and synergies of the acquisition.
In addition, we expect that the CyberArk acquisition will result in increased competition, including as a result of our entry into a new product category. The identity security industry is characterized by constant innovation, evolving customer requirements, and rapid adoption of different technologies and services. These added competitive pressures could result in decreased sales, price reductions, increased operating costs, and lower revenues, margins, and net income for the combined company. These impacts could also result in a delay in realizing, or our failure to realize, expected synergies or cost savings from the CyberArk acquisition.
The occurrence of any of these risks could harm our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition.
We believe that the Our recent CyberArk acquisition will expand has expanded the scope and size of our business by adding substantial assets and operations to our existing business. The anticipated future growth of our business may impose significant added responsibilities on our senior management, and our senior management’s attention may be diverted from the management of our business and its day-to-day operations to the completion and integration of the CyberArk acquisition. The process for CyberArk acquisition could also create uncertainty for our and CyberArk’s employees, partners, and customers, particularly during the anticipated post-acquisition integration process, divert senior management’s attention, and result in disruption to existing business relationships and the development of new business relationships. Following completion of the proposed acquisition of CyberArk, our Our success, including with respect to realizing the anticipated benefits and synergies from the proposed CyberArk acquisition, will depend, in part, on our ability to manage our expansion, which poses numerous risks and uncertainties, including the need to integrate the operations and business of CyberArk into our existing business in a timely and efficient manner, to combine systems and management controls controls, and to integrate relationships with industry contacts and business partners. In addition, we will be required to devote significant attention and resources prior to closing to prepare for the post-closing integration and operation of the combined company, and we will be required post-closing to devote significant attention and resources to successfully align our and CyberArk’s business practices and operations. This process may disrupt our business and, if ineffective, would limit the anticipated benefits and synergies of the acquisition. In addition, we expect that the completion of the CyberArk acquisition will result in increased competition, including, including as a result of our entry into a new product category. CyberArk faces intense competition in the information security and The identity security industry in which it operates, is characterized by constant innovation, evolving customer requirements, and rapid adoption of different technologies and services. These added competitive pressures could result in decreased sales, price reductions, increased operating costs, and lower revenues, margins margins, and net income for the combined company. These impacts could also result in a delay in realizing, or our failure to realize, expected synergies or cost savings from the CyberArk acquisition. The occurrence of any of these risks could harm our business, operating results, and financial condition.condition, and operating results.
Added · Removed · word-level comparison of the two filings
If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.
rewrittenAI & technologyAdded financing risks: company may need equity or debt to develop new features, improve infrastructure, or acquire technologies; financing terms could restrict indebtedness or require specified liquidity ratios.
The enterprise security industry has grown quickly and continues to evolve rapidly. Moreover, many of our end-customers operate in markets characterized by rapidly changing technologies and business plans, which require them to add numerous network access points and adapt increasingly complex enterprise networks, incorporating a variety of hardware, software applications, operating systems, and networking protocols. If we fail to effectively anticipate, identify, and respond to rapidly evolving technological and market developments in a timely manner, our business will be harmed.
In order to anticipate and respond effectively to rapid technological changes and market developments, as well as evolving security threats, we must invest effectively in research and development to increase the reliability, availability, and scalability of our existing products and subscriptions and introduce new products and subscriptions. Our investments in research and development, including investments in AI, may not result in design or performance improvements, marketable products, subscriptions, or features, or may not achieve the cost savings or additional revenue that we expect. In addition, new and evolving products and services, including those that use AI, require significant investment and raise ethical, technological, legal, regulatory, and other challenges, which may negatively affect our brands and demand for our products and services.
Because all of these investment areas are inherently risky, no assurance can be given that such strategies and offerings will be successful or will not harm our reputation, financial condition, and operating results.
We must also continually adapt our products and strategy in response to changes in network infrastructure requirements, including the expanding use of cloud computing and third-party service providers. While we have historically been successful in developing or acquiring and marketing new products and product enhancements that respond to technological and industry changes, we cannot assure that our new or future offerings will achieve widespread market acceptance or be successful. If we fail to accurately predict and address end-customers’ changing needs and emerging technological trends, including in the areas of AI, mobility, virtualization, cloud computing, and software-defined networks, our business could be harmed. The technology in our portfolio is especially complex because it needs to effectively identify and respond to new and increasingly sophisticated methods of attack while minimizing the impact on network performance.
Some of our new features and enhancements may require us to develop new hardware architectures involving complex, expensive, and time-consuming research and development processes, and the timetable for commercial availability is uncertain. The success of new products depends on several factors, including appropriate product definition, differentiation from competitors, market acceptance, management of production ramp-up issues, availability of application software, effective management of purchase commitments and inventory, and the risk that new products may have quality defects in the early stages of introduction. If we fail to identify opportunities for new products and subscriptions, experience unanticipated delays in the availability of new products and subscriptions, or fail to meet customer expectations, our competitive position and business prospects will be harmed.
Furthermore, we may require additional funds to respond to business challenges, including the need to develop new features to enhance our portfolio, improve our operating infrastructure, or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds, which may contain terms that, among other things, restrict our ability to incur additional indebtedness. In addition, we may be required to take other actions that would otherwise be in the interests of the debt holders and would require us to maintain specified liquidity or other ratios, any of which could harm our business, financial condition, and operating results. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.
Compare with the 2025 10-K
Prior heading: If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.
The enterprise security industry has grown quickly and continues to evolve rapidly. Moreover, many of our end-customers operate in markets characterized by rapidly changing technologies and business plans, which require them to add numerous network access points and adapt increasingly complex enterprise networks, incorporating a variety of hardware, software applications, operating systems, and networking protocols. If we fail to effectively anticipate, identify, and respond to rapidly evolving technological and market developments in a timely manner, our business will be harmed. In order to anticipate and respond effectively to rapid technological changes and market developments, as well as evolving security threats, we must invest effectively in research and development to increase the reliability, availability, and scalability of our existing products and subscriptions and introduce new products and subscriptions. Our investments in research and development, including investments in AI, may not result in design or performance improvements, marketable products, subscriptions, or features, or may not achieve the cost savings or additional revenue that we expect. In addition, new and evolving products and services, including those that use AI, require significant investment and raise ethical, technological, legal, regulatory, and other challenges, which may negatively affect our brands and demand for our products and services. Because all of these investment areas are inherently risky, no assurance can be given that such strategies and offerings will be successful or will not harm our reputation, financial condition, and operating results. In addition, we We must also continually change adapt our products and expand our business strategy in response to changes in network infrastructure requirements, including the expanding use of cloud computing. For example, organizations are moving portions of their data to be managed by third parties, primarily infrastructure, platform, computing and application third-party service providers, and may rely on such providers’ internal security measures. providers. While we have historically been successful in developing, acquiring, developing or acquiring and marketing new products and product enhancements that respond to technological change and evolving industry standards, changes, we may not be able to continue to do so, and there can be no assurance cannot assure that our new or future offerings will be successful or will achieve widespread market acceptance. acceptance or be successful. If we fail to accurately predict and address end-customers’ changing needs and emerging technological trends in the enterprise security industry, trends, including in the areas of AI, mobility, virtualization, cloud computing, and software-defined networks, our business could be harmed. harmed. The technology in our portfolio is especially complex because it needs to effectively identify and respond to new and increasingly sophisticated methods of attack, attack while minimizing the impact on network performance. Additionally, some Some of our new features and related enhancements may require us to develop new hardware architectures that involve involving complex, expensive, and time-consuming research and development processes. The development of our portfolio is difficult processes, and the timetable for commercial release and availability is uncertain as there can be long time periods between releases and availability of new features. If we experience unanticipated delays in the availability of new products, features, and subscriptions, and fail to meet customer expectations for such availability, our competitive position and business prospects will be harmed. uncertain. The success of new features products depends on several factors, including appropriate new product definition, differentiation of new products, subscriptions, and features from those of our competitors, and market acceptance of these products, services, and features. Moreover, successful new product introduction and transition depends on a number acceptance, management of factors, including our ability to manage the risks associated with new product production ramp-up issues, the availability of application software for new products, the software, effective management of purchase commitments and inventory, the availability of products in appropriate quantities and costs to meet anticipated demand, and the risk that new products may have quality or other defects or deficiencies, especially in the early stages of introduction. There can be no assurance that If we will successfully fail to identify opportunities for new products and subscriptions, develop and bring experience unanticipated delays in the availability of new products and subscriptions subscriptions, or fail to market in a timely manner, achieve market acceptance of meet customer expectations, our products competitive position and subscriptions, business prospects will be harmed. Furthermore, we may require additional funds to respond to business challenges, including the need to develop new features to enhance our portfolio, improve our operating infrastructure, or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds, which may contain terms that, among other things, restrict our ability to incur additional indebtedness. In addition, we may be required to take other actions that products, subscriptions, would otherwise be in the interests of the debt holders and technologies developed by others will not render would require us to maintain specified liquidity or other ratios, any of which could harm our products, subscriptions, business, financial condition, and technologies obsolete operating results. If we are unable to obtain adequate financing or noncompetitive.financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.
Added · Removed · word-level comparison of the two filings
The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.
addedCompetitionAdded risk that maintaining broad third-party technology integrations requires continuous investment; vendors may modify APIs or introduce competing capabilities reducing integration value.
The success of our strategy depends in part on the breadth and depth of our integrations with third-party technologies, including cloud infrastructure providers, identity providers, security tools, and business applications. Maintaining and expanding these integrations requires continuous engineering, sales, and marketing investment, and we may not always be able to develop, maintain, or update integrations as quickly as customers or channel partners expect. Third-party technology vendors may modify their APIs, deprecate integrations, or introduce competing capabilities that reduce the need for our platform integrations. If we are unable to maintain a broad and current integration ecosystem, or if certain third-party vendors limit or terminate their integrations with our platform, the utility of our offerings could be reduced, adversely affecting our business, financial condition, and operating results.
Issues in the development, deployment, or use of AI may result in reputational harm, legal liability, and could adversely affect our business and operating results.
rewrittenAI & technologyExpanded AI risk to include unintended consequences, zero-day vulnerabilities in AI systems, threat sophistication acceleration, commoditization concerns, and AI-specific regulatory compliance costs.
We have incorporated, and are continuing to develop and deploy, AI into many of our products, solutions, and business operations. AI presents challenges, risks, and potentially unintended consequences. For example, AI algorithms may have flaws, and training datasets may be insufficient or contain biased information. The AI incorporated into our products and operations may not be successful or beneficial, and instead may cause technical, legal, or ethical problems or result in increased costs. Our investments in AI ultimately may not be commercially viable or result in an adequate return of capital, and this could depress the market price of our stock or lead to us incurring unanticipated liabilities.
Vulnerabilities within our AI systems may be identified by researchers or malicious actors before we detect or remediate them, which could result in security incidents, data privacy issues, reputational damage, or loss of customer confidence. Advances in AI have also increased the speed, scale, and sophistication of cybersecurity threat activity, including reducing the time between vulnerability discovery and exploitation. To the extent customers, investors, or other market participants perceive that AI can automate or commoditize aspects of cybersecurity functions, the perceived value of certain cybersecurity solutions could diminish, and customer buying patterns, competitive dynamics, and demand for our products, subscriptions, and support offerings could be adversely affected. Investor and market perceptions regarding AI-related disruption to the cybersecurity industry could adversely affect our business and operating results, or the trading price of our common stock, even if these perceptions do not reflect actual changes in our business, customer demand, competitive positions, or financial performance.
The rapid evolution of AI, including current and future government regulation of AI, requires us to invest significant resources to develop, test, and maintain AI in our products and services in a manner that meets evolving requirements and expectations. The laws, rules, and regulations that have and continue to be adopted by policymakers, and the manner in which such requirements are interpreted or enforced, may require us to incur additional costs to comply with such requirements or make changes to our business practices, including our products and services that incorporate AI. Our efforts and investments regarding AI, and our failure or perceived failure to comply with applicable legal requirements, could damage our customer relationships, cause brand or reputational harm, or subject us to regulatory risk and legal liability, including under laws, rules, and regulations in jurisdictions such as the E.U. and U.S. and laws and regulations in other jurisdictions in which we and our customers operate. Developing, testing, and deploying AI systems may also increase the cost profile of our offerings due to the nature of the computing costs involved in such systems.
The intellectual property ownership and license rights surrounding AI technologies, as well as data protection laws related to the use and development of AI, are currently not fully addressed by courts or regulators. The use or adoption of AI technologies in our products may result in exposure to claims by third parties, including alleging copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties, as well as regulatory action and enforcement. The evolving legal, regulatory, and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringement.
The cybersecurity industry is undergoing a transformation as customers increasingly expect AI-native solutions that are designed from the ground up to leverage AI capabilities. If we fail to anticipate, invest in, or execute on the transition to AI-native platforms, or if our competitors develop AI-native offerings that achieve greater market acceptance, we may miss critical opportunities for growth and market leadership, and our business, including our gross margin, and competitive position could be materially harmed.
Compare with the 2025 10-K
Prior heading: Issues in the development and deployment of AI may result in reputational harm and legal liability and could adversely affect our results of operations.
We have incorporated, and are continuing to develop and deploy, AI into many of our products and products, solutions, including services that support our products and solutions. We are also incorporating AI into the operations of our business. business operations. AI presents challenges and risks that could affect our products and solutions, challenges, risks, and the operations of our business. potentially unintended consequences. For example, AI algorithms may have flaws, and training datasets used to train models may be insufficient or contain biased information. The AI that is being incorporated into our products, solutions, products and business operation tools operations may not be successful or beneficial, and instead may cause technical, legal legal, or ethical problems or result in increased costs. The Our investments that we are making across our business in AI reflect our ongoing efforts to innovate and provide products and services that are useful to our customers, as well as provide efficiencies in our business. Such investments ultimately may not be commercially viable or may not result in an adequate return of capital capital, and we may incur unanticipated liabilities. These efforts this could subject us depress the market price of our stock or lead to regulatory risk, legal liability, including under legislation regulating us incurring unanticipated liabilities. Vulnerabilities within our AI systems may be identified by researchers or malicious actors before we detect or remediate them, which could result in jurisdictions such as security incidents, data privacy issues, reputational damage, or loss of customer confidence. Advances in AI have also increased the E.U. speed, scale, and laws sophistication of cybersecurity threat activity, including reducing the time between vulnerability discovery and regulations being considered in exploitation. To the extent customers, investors, or other jurisdictions, market participants perceive that AI can automate or brand commoditize aspects of cybersecurity functions, the perceived value of certain cybersecurity solutions could diminish, and customer buying patterns, competitive dynamics, and demand for our products, subscriptions, and support offerings could be adversely affected. Investor and market perceptions regarding AI-related disruption to the cybersecurity industry could adversely affect our business and operating results, or reputational harm. the trading price of our common stock, even if these perceptions do not reflect actual changes in our business, customer demand, competitive positions, or financial performance. The rapid evolution of AI, including potential current and future government regulation of AI, requires us to invest significant resources to develop, test, and maintain AI in our products and services in a manner that meets evolving requirements and expectations. The rules laws, rules, and regulations that have and continue to be adopted by policymakers over time policymakers, and the manner in which such requirements are interpreted or enforced, may require us to incur additional costs to comply with such requirements or make changes to our business practices. practices, including our products and services that incorporate AI. Our efforts and investments regarding AI, and our failure or perceived failure to comply with applicable legal requirements, could damage our customer relationships, cause brand or reputational harm, or subject us to regulatory risk and legal liability, including under laws, rules, and regulations in jurisdictions such as the E.U. and U.S. and laws and regulations in other jurisdictions in which we and our customers operate. Developing, testing, and deploying AI systems may also increase the cost profile of our offerings due to the nature of the computing costs involved in such systems. The intellectual property ownership and license rights surrounding AI technologies, as well as data protection laws related to the use and development of AI, are currently not fully addressed by courts or regulators. The use or adoption of AI technologies in our products may result in exposure to claims by third parties of parties, including alleging copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties. parties, as well as regulatory action and enforcement. The evolving legal, regulatory, and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringing use.infringement. The cybersecurity industry is undergoing a transformation as customers increasingly expect AI-native solutions that are designed from the ground up to leverage AI capabilities. If we fail to anticipate, invest in, or execute on the transition to AI-native platforms, or if our competitors develop AI-native offerings that achieve greater market acceptance, we may miss critical opportunities for growth and market leadership, and our business, including our gross margin, and competitive position could be materially harmed.
Added · Removed · word-level comparison of the two filings
T9The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.
addedAI & technologyAdded risk that AI agents as new identity class require evolved security solutions; failure to address or competitor advantage could reduce demand for identity offerings.
The rapid deployment of generative AI systems and AI agents is creating a new class of identity that requires authenticated, secure access to sensitive resources at a scale and speed exceeding traditional identity models designed for human users. As AI agents gain capabilities and access within organizations, managing their identities and permissions is emerging as a significant operational and security challenge. The ability of our identity security solutions to evolve to effectively secure this new identity class will depend on continued investment in research and development, the availability of appropriate AI technologies, and market acceptance of our approach and products. If we fail to adequately address the security requirements associated with AI agents, or if our competitors more effectively secure AI identities, demand for our offerings could decline. Additionally, evolving standards, customer expectations, or regulatory requirements could require us to make significant changes to our offerings.
A significant network or data security incident may materially impact our reputation, financial condition, and operating results.
rewrittenCyber & dataBroadened security incident risk to emphasize geopolitical environment, third-party service provider criticality, and insurance availability; removed specific attack types and Russia sanctions references.
Like all companies, our systems, data, and products are subject to an increasingly wide variety of attacks on an ongoing basis from a variety of sources, including from traditional hackers, malicious code, phishing and ransomware attacks, employee theft or misuse, and sophisticated nation-state actors engaging in intrusions and attacks, including advanced persistent threat intrusions and supply chain attacks. Despite our efforts to prevent breaches, our data, products, corporate systems, and security measures, as well as those of our third-party service providers, remain vulnerable. Malicious actors are using AI to develop advanced cyberattacks and to exploit system vulnerabilities that are not known or remediated. We cannot guarantee that our security measures will provide adequate protection.
As a well-known provider of security solutions, we and others in our industry are attractive targets for cyberattacks. The geopolitical environment, including the Russia-Ukraine war and other global events as described in "Risks Related to Global Economic and Geopolitical Conditions" above, increase the risk of cyberattacks on our infrastructure and operations. Because certain third-party service providers are critical to our business, such as cloud services that support various customer-facing operations, cyberattacks that compromise third-party systems could materially impact us.
A significant security breach or incident suffered by us or our third-party service providers could materially impact the confidentiality, integrity, or availability of our networks and products, or networks secured by our products and subscriptions, creating system disruptions and compromise of information. Information stored or otherwise processed on our networks or those of our third-party service providers has previously been, and could in the future be, accessed, disclosed, altered, lost, or stolen, or otherwise used or processed without authorization. Any actual or perceived vulnerability, breach, or data security incident we or our third-party service providers suffer could result in significant reputational damage, loss of channel partners and end-customers, regulatory investigations or enforcement actions, costly litigation, and other liability.
We may also incur significant costs and expend significant resources to investigate, remediate, and prevent future incidents, as well as costs to comply with notification obligations resulting from any security incidents. Any of these outcomes could adversely impact the market perception of our products and subscriptions and end-customer and investor confidence in our company, and could materially harm our business, financial condition, and operating results. We cannot guarantee that costs and liabilities incurred in relation to a breach or other incident will be covered by existing insurance policies or that applicable cybersecurity insurance will be available to us in the future on economically reasonable terms or at all.
Compare with the 2025 10-K
Prior heading: A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.
Increasingly, companies Like all companies, our systems, data, and products are subject to a an increasingly wide variety of attacks on an ongoing basis. In addition to basis from a variety of sources, including from traditional computer “hackers,” hackers, malicious code (such as viruses and worms), code, phishing attempts, and ransomware attacks, employee theft or misuse, and denial of service attacks, sophisticated nation-state and nation-state supported actors engage engaging in intrusions and attacks (including attacks, including advanced persistent threat intrusions and supply chain attacks), and add to the risks to our internal networks, cloud-deployed enterprise and customer-facing environments and the information they store and process. Incidences of cyberattacks and other cybersecurity breaches and incidents have increased and are likely to continue to increase. We and our third-party service providers face security threats and attacks from a variety of sources. attacks. Despite our efforts and processes to prevent breaches of our internal networks, systems, and websites, breaches, our data, products, corporate systems, and security measures, as well as those of our third-party service providers, remain vulnerable. Malicious actors are still vulnerable using AI to computer viruses, break-ins, phishing attacks, ransomware attacks, or other types of attacks from outside parties, or breaches due develop advanced cyberattacks and to employee error, malfeasance, exploit system vulnerabilities that are not known or some combination of these. remediated. We cannot guarantee that the measures we have taken to protect our networks, systems, and websites security measures will provide adequate security. Furthermore, as protection. As a well-known provider of security solutions, we may be a more and others in our industry are attractive target targets for such attacks. cyberattacks. The geopolitical environment, including the Russia-Ukraine war and associated activities other global events as described in Ukraine "Risks Related to Global Economic and Russia may Geopolitical Conditions" above, increase the risk of cyberattacks on various types of our infrastructure and operations, and the United States government has warned companies operations. Because certain third-party service providers are critical to be prepared for additional Russian our business, such as cloud services that support various customer-facing operations, cyberattacks in response to the Sanctions on Russia. that compromise third-party systems could materially impact us. A significant security breach or incident, or an attack against our service availability incident suffered by us, us or our third-party service providers, providers could materially impact the confidentiality, integrity, or availability of our networks and products, or networks secured by our products and subscriptions, creating system disruptions or slowdowns and exploiting security vulnerabilities compromise of our products. In addition, the information information. Information stored or otherwise processed on our networks, networks or those of our third-party service providers, providers has previously been, and could be in the future be, accessed, publicly disclosed, altered, lost, or stolen, rendered unavailable, or otherwise used or processed without authorization, which could subject us to liability and cause us financial harm. authorization. Any actual or perceived breach of security in our systems or networks, or any other actual vulnerability, breach, or perceived data security incident we or our third-party service providers suffer, suffer could result in significant damage to our reputation, negative publicity, reputational damage, loss of channel partners, end-customers, and sales, loss of competitive advantages over our competitors, increased costs to remedy any problems partners and otherwise respond to any incident, end-customers, regulatory investigations and or enforcement actions, demands, costly litigation, and other liability. In addition, we We may also incur significant costs and operational consequences of investigating, remediating, eliminating, and putting in place additional tools, devices, and other measures designed expend significant resources to prevent actual or perceived security breaches investigate, remediate, and other security prevent future incidents, as well as the costs to comply with any notification obligations resulting from any security incidents. Any of these negative outcomes could adversely impact the market perception of our products and subscriptions and end-customer and investor confidence in our company company, and could seriously materially harm our business or business, financial condition, and operating results.results. We cannot guarantee that costs and liabilities incurred in relation to a breach or other incident will be covered by existing insurance policies or that applicable cybersecurity insurance will be available to us in the future on economically reasonable terms or at all.
Added · Removed · word-level comparison of the two filings
Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.
rewrittenLitigationRewritten to emphasize geopolitical environment increasing technical failure risks and zero-day vulnerabilities; removed specific Russia-Ukraine war references and PAN-OS remediation details.
Because our products and subscriptions are complex, they have contained and may contain design or manufacturing defects, vulnerabilities, or errors that are not detected until after deployment. For example, end-customers have reported defects in our products related to performance, scalability, and compatibility. Defects or vulnerabilities may cause our products or subscriptions to become unavailable, to be vulnerable to security attacks, fail to secure networks, or interrupt end-customers’ networking traffic. For example, in May 2026, we became aware of an authentication bypass vulnerability in certain versions of our PAN-OS software and published a security advisory, provided software updates, and engaged in customer outreach, support, and remediation efforts. Because attack techniques change frequently and are generally not recognized until launched, we are unable to comprehensively anticipate, detect, or provide responsive solutions or remediation in all instances. As described in "Risks Related to Global Economic and Geopolitical Conditions" above, the geopolitical environment increases the risk of cyberattacks against us and our customers.
Defects or errors in our products or software, or migrations or updates, could result in a failure to effectively update end-customers’ hardware, software, and products or otherwise cause problems in our customers’ hardware, networks, software, or IT infrastructure. Defects, errors, or a technical failure of our products may temporarily or permanently disable our end-customers’ networks, IT infrastructure, or other systems. Our products must interoperate with end-customers’ existing infrastructure, which often has varied specifications, multiple protocol standards, and products from multiple vendors. When problems occur, it may be difficult to identify the source. The data centers, networks, and cloud infrastructure we use to deliver our products, subscriptions, and support offerings may experience technical failures or downtime that could expose end-customers’ networks to security threats or attacks.
The occurrence of any such problem in our products and subscriptions, or migrations or updates to those products or software, whether real or perceived, could result in:
•expenditure of significant financial and product development resources in efforts to analyze, correct, eliminate, or work-around errors or defects or to address and eliminate vulnerabilities;
•loss of existing or potential end-customers or channel partners;
•delayed or lost revenue;
•delay or failure to attain market acceptance;
•an increase in warranty claims compared with our historical experience, or an increased cost of servicing warranty claims, either of which would adversely affect our gross margins; and •litigation, regulatory inquiries, investigations, or other proceedings, each of which may be costly and harm our reputation.
Our products and subscriptions may be misused by end-customers or third parties. For example, our products and subscriptions could be used to censor private access to information on the Internet. Such misuse could result in negative press coverage and harm our reputation.
The limitation of liability provisions in our standard terms and conditions may not fully or effectively protect us from claims as a result of applicable laws or unfavorable judicial decisions. The sale and support of our products and subscriptions also entails the risk of product liability claims. Indemnification by third-party manufacturers may not cover claims arising from design or manufacturing defects. Additionally, our insurance coverage may not adequately cover claims asserted against us, and even unsuccessful claims could result in litigation expenses, diversion of management's attention, and reputational harm.
In addition, our classifications of application type, virus, spyware, vulnerability exploits, data, or URL categories may falsely detect and act on threats that do not actually exist. This risk is heightened by the inclusion of heuristics features in our products and subscriptions that identify threats based on characteristics or anomalies rather than known signatures. These false positives may impair the perceived reliability of our products and adversely impact market acceptance of our products and subscriptions, our reputation, and our sales, and result in loss of channel partners or end-customers.
Compare with the 2025 10-K
Prior heading: Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.
Because our products and subscriptions are complex, they have contained and may contain design or manufacturing defects defects, vulnerabilities, or errors that are not detected until after their commercial release and deployment by our end-customers. deployment. For example, from time to time, certain of our end-customers have reported defects in our products related to performance, scalability, and compatibility. Additionally, defects Defects or vulnerabilities may cause our products or subscriptions to become partially or fully unavailable temporarily or permanently, unavailable, to be vulnerable to security attacks, cause them to fail to help secure networks, or interrupt end-customers’ networking traffic, or the availability of other information technology infrastructure or systems. traffic. For example, in November 2024, May 2026, we became aware of an authentication bypass vulnerability through the management web interface of in certain versions of our PAN-OS software. To remediate the matter, we software and published a security advisory to advise customers, advisory, provided software updates for affected PAN-OS versions, updates, and engaged in customer outreach, support support, and remediation efforts for potentially impacted customers. efforts. Because the attack techniques used by computer hackers to access or sabotage networks change frequently and generally are generally not recognized until launched against a target, launched, we may be are unable to anticipate these techniques and comprehensively anticipate, detect, or provide a solution responsive solutions or remediation in time to protect our end-customers’ networks. In addition, due all instances. As described in "Risks Related to Global Economic and Geopolitical Conditions" above, the Russia-Ukraine war, there could be a significant increase in Russian cyberattacks against our customers, resulting in an increased geopolitical environment increases the risk of a security breach of cyberattacks against us and our end-customers’ systems. Furthermore, defects customers. Defects or errors in our products or software, or migrations or updates to those products or software, updates, could result in a failure to effectively update end-customers’ hardware hardware, software, and cloud-based products or otherwise cause problems in our customers’ hardware, networks networks, software, or information technology infrastructure IT infrastructure. Defects, errors, or systems. The data centers, networks, and cloud infrastructure that we use to deliver a technical failure of our products and services may experience technical failures and downtime or may fail to meet the increased requirements of a growing installed end-customer base, any of which could temporarily or permanently expose disable our end-customers’ networks, leaving their networks unprotected against the latest security threats. Moreover, our IT infrastructure, or other systems. Our products must interoperate with our end-customers’ existing infrastructure, which often have has varied specifications, utilize multiple protocol standards, deploy and products from multiple vendors, and contain multiple generations of products that have been added over time. As a result, when vendors. When problems occur in a network, occur, it may be difficult to identify the sources of these problems. Any such technical failure, downtime or failures in general may temporarily or permanently disable our end-customers’ source. The data centers, networks, information technology and cloud infrastructure or other systems, we use to deliver our products, subscriptions, and support offerings may experience technical failures or downtime that could expose our end-customers’ networks to attacks from security threats. threats or attacks. The occurrence of any such problem in our products and subscriptions, or migrations or updates to those products or software, whether real or perceived, could result in: •expenditure of significant financial and product development resources in efforts to analyze, correct, eliminate, or work-around errors or defects or to address and eliminate vulnerabilities; •loss of existing or potential end-customers or channel partners; •delayed or lost revenue; •delay or failure to attain market acceptance; •an increase in warranty claims compared with our historical experience, or an increased cost of servicing warranty claims, either of which would adversely affect our gross margins; and •litigation, regulatory inquiries, investigations, or other proceedings, each of which may be costly and harm our reputation. Further, our Our products and subscriptions may be misused by end-customers or third parties that obtain access to our products and subscriptions. parties. For example, our products and subscriptions could be used to censor private access to certain information on the Internet. Such use of our products and subscriptions for censorship misuse could result in negative press coverage and negatively affect harm our reputation. The limitation of liability provisions in our standard terms and conditions of sale may not fully or effectively protect us from claims as a result of federal, state, or local applicable laws or ordinances, or unfavorable judicial decisions in the United States or other countries. decisions. The sale and support of our products and subscriptions also entails the risk of product liability claims. Although we may be indemnified Indemnification by our third-party manufacturers for product liability claims arising out of manufacturing defects, because we control the design of our products and subscriptions, we may not be indemnified for product liability cover claims arising out of from design or manufacturing defects. While we maintain insurance coverage for certain types of losses, Additionally, our insurance coverage may not adequately cover any claim claims asserted against us, if at all. In addition, and even claims that ultimately are unsuccessful claims could result in our expenditure litigation expenses, diversion of funds in litigation, divert management’s time and other resources, management's attention, and harm our reputation. reputational harm. In addition, our classifications of application type, virus, spyware, vulnerability exploits, data, or URL categories may falsely detect, report, detect and act on applications, content, or threats that do not actually exist. This risk is heightened by the inclusion of a “heuristics” feature heuristics features in our products and subscriptions, which attempts to subscriptions that identify applications and other threats not based on any known signatures but based on characteristics or anomalies which indicate that a particular item may be a threat. rather than known signatures. These false positives may impair the perceived reliability of our products and subscriptions and may therefore adversely impact market acceptance of our products and subscriptions subscriptions, our reputation, and could our sales, and result in damage to our reputation, negative publicity, loss of channel partners, end-customers and sales, increased costs to remedy any problem, and costly litigation.partners or end-customers.
Added · Removed · word-level comparison of the two filings
Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.
addedCyber & dataAdded risk that under shared responsibility model, customer configuration errors or misuse could cause security incidents harming company reputation despite company not being at fault.
We deliver certain of our products under a model in which we are responsible for the security of the underlying platform and infrastructure and our customers are responsible for configuring, deploying, patching, and using our products and configuring and implementing the security controls and posture within their environments. Customers may fail to implement, or may misconfigure, security features made available in our products and subscriptions, or may fail to follow best practices, resulting in security incidents affecting their environments or data. Even if we are not the cause of a customer security incident, our reputation, brand, and customer relationships may nonetheless be adversely impacted. Enterprise customers, regulators, and the market generally may not consistently distinguish between security incidents caused by our products and those caused by a customer failing to implement or misconfiguring security features of our products, and we may face claims, negative publicity, or regulatory scrutiny in either case. Any such incidents could adversely affect market perception of our offerings and, correspondingly, our business, financial condition, and operating results.
Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
rewrittenOtherSimplified technical support risk language; removed detailed discussion of support scaling challenges and resource constraints.
After our products and subscriptions are deployed, our end-customers depend on our technical support services and those of our channel partners. Larger enterprise, service provider, and government entity end-customers have more complex networks and require higher levels of support. If our channel partners do not effectively provide support, we may need to provide direct support, requiring additional personnel and resources. If we cannot hire and deploy resources fast enough to meet demand, end-customer satisfaction will be adversely affected, and reliance on sales engineers for post-sales support would negatively impact our sales productivity. Failure by our company and our channel partners to provide high-quality support services could have a material adverse effect on our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
After our products and subscriptions are deployed within our end-customers’ networks, deployed, our end-customers depend on our technical support services, as well as the support services and those of our channel partners, to resolve any issues relating to our products. Many larger partners. Larger enterprise, service provider, and government entity end-customers have more complex networks and require higher levels of support than smaller end-customers. support. If our channel partners do not effectively provide support to the satisfaction of our end-customers, support, we may be required need to provide direct support to such end-customers, which would require us to hire support, requiring additional personnel and to invest in additional resources. If we are not able to cannot hire such and deploy resources fast enough to keep up with unexpected meet demand, support to our end-customers will be negatively impacted, and our end-customers’ end-customer satisfaction with our products and subscriptions will be adversely affected. Additionally, to the extent that we may need to rely affected, and reliance on our sales engineers to provide for post-sales support while we are ramping up our support resources, our sales productivity will be negatively impacted, which would harm negatively impact our revenues. Accordingly, sales productivity. Failure by our failure, or company and our channel partners’ failure, partners to provide and maintain high-quality support services could have a material adverse effect on our business, financial condition, and operating results.
Added · Removed · word-level comparison of the two filings
Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.
addedCredit & liquidityAdded risk that service-level commitment failures in subscription agreements could trigger service credits, refunds, or terminations, reducing revenue and harming reputation.
Our subscription agreements for certain of our product offerings typically contain service-level commitments, including uptime and response time requirements. If we are unable to meet these commitments, we may be contractually obligated to provide service credits, refunds, or, in certain cases, permit customers to terminate their subscriptions. Any such credits or refunds could significantly affect our revenue in the periods in which they are applied. Service-level failures could also damage our reputation, reduce renewals, and expose us to litigation. As our SaaS-based revenues grow and our offerings expand to serve more mission-critical use cases, our exposure to service-level commitment obligations will continue to increase. Any material failure to meet these commitments could adversely affect our business, financial condition, and operating results.
We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.
addedSupply chainAdded risk that cloud service providers may limit capacity, prioritize other customers, or terminate contracts, impeding product delivery and customer onboarding.
We rely on data center facilities operated by third-party cloud service providers to host and operate our cloud-based products and services. Any limitation on the capacity of these third-party providers, or tightening availability of cloud computing resources and machine compute capacity due to increased demand from other customers, supply chain constraints, or allocation decisions by providers, could impede our ability to onboard new customers, expand usage by existing customers, or deliver our products and services with the performance and reliability our customers expect. Demand for cloud computing infrastructure and specialized computing resources, including for AI and machine learning workloads, has increased significantly across industries, and our third-party providers may prioritize other customers or uses, limit our access to capacity, or be unable to meet our requirements.
In addition, decisions by the owners and operators of these data center facilities to terminate our contracts, discontinue services, shut down operations, increase prices, change service levels, limit bandwidth, or prioritize the traffic of other parties could have a material adverse effect on our operations.
RISKS RELATED TO INTELLECTUAL PROPERTY AND TECHNOLOGY LICENSING
Claims by others that we infringe their intellectual property rights could harm our business.
rewrittenLitigationRemoved extensive detail on patent portfolio, litigation costs, trade secret disclosure risks, and settlement discussions; added reference to IP infringement claims against enterprise security industry companies.
Companies in the enterprise security industry own large numbers of patents, copyrights, trademarks, domain names, and trade secrets and frequently enter into litigation based on allegations of infringement, misappropriation, or other violations of intellectual property rights. Non-practicing entities also frequently bring such claims against companies in the enterprise security industry. Third parties have asserted, and may in the future assert, claims of infringement against us. For example, on January 31, 2024, in the Centripetal Networks, Inc. lawsuit against us, the jury returned a verdict of non-willful infringement, and a judgment was issued on October 3, 2024 assessing damages of $114 million, plus statutory interest, which is currently on appeal. Additional patent infringement cases are disclosed in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K.
Third parties may also assert such claims against our end-customers or channel partners, whom our standard license and other agreements obligate us to indemnify against claims that our products and subscriptions infringe the intellectual property rights of third parties. In addition, to the extent we hire personnel from competitors, we may be subject to allegations that they have been improperly solicited, that they have divulged proprietary or other confidential information, or that their former employers own their inventions or other work product. Furthermore, we may be unaware of the intellectual property rights of others that may cover some or all of our technology, products, subscriptions, and services. As we expand our footprint, both in our platforms, products, subscriptions, and services and geographically, more overlaps occur and we may face more infringement claims both in the United States and abroad.
Our competitors and others may have significantly larger and more mature patent portfolios than we have, and litigation has involved and will likely continue to involve patent-holding companies or owners who have no relevant product revenue and against whom our own patents provide little or no deterrence. We have not registered our trademarks in all geographic markets, which could adversely affect our ability to enforce and defend our trademark rights. Any infringement claim, even without merit, could cause us to incur substantial defense costs, distract management, and could require us to cease use of such intellectual property. Furthermore, because of the substantial discovery required in IP litigation, there is a risk that our confidential information could be compromised.
A successful claimant could secure a judgment or settlement that prevents us from distributing certain products, performing certain services, or that requires us to pay substantial damages, royalties, or other fees. Any of these events could seriously harm our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: Claims by others that we infringe their intellectual property rights could harm our business.
Companies in the enterprise security industry own large numbers of patents, copyrights, trademarks, domain names, and trade secrets and frequently enter into litigation based on allegations of infringement, misappropriation, or other violations of intellectual property rights. In addition, non-practicing Non-practicing entities also frequently bring such claims of infringement of intellectual property rights. against companies in the enterprise security industry. Third parties are asserting, have asserted, and may in the future assert assert, claims of infringement of intellectual property rights against us. For example, on January 31, 2024, in the Centripetal Networks, Inc. lawsuit against us, a the jury returned a verdict of non-willful infringement, and, after post-trial motions, and a judgment was issued in the lawsuit on October 3, 2024 assessing a lump sum damages amount of $113.6 $114 million, plus statutory interest, which is currently on appeal. Additional examples of patent infringement cases have been are disclosed in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K. Third parties may also assert such claims against our end-customers or channel partners, whom our standard license and other agreements obligate us to indemnify against claims that our products and subscriptions infringe the intellectual property rights of third parties. In addition, to the extent we hire personnel from competitors, we may be subject to allegations that they have been improperly solicited, that they have divulged proprietary or other confidential information, or that their former employers own their inventions or other work product. Furthermore, we may be unaware of the intellectual property rights of others that may cover some or all of our technology, products, subscriptions, and services. As we expand our footprint, both in our platforms, products, subscriptions, and services and geographically, more overlaps occur and we may face more infringement claims both in the United States and abroad. While we have been increasing the size of our patent portfolio, our Our competitors and others may now and in the future have significantly larger and more mature patent portfolios than we have. In addition, have, and litigation has involved and will likely continue to involve patent-holding companies or other adverse patent owners who have no relevant product revenue and against whom our own patents may therefore provide little or no deterrence or protection. In addition, we deterrence. We have not registered our trademarks in all of our geographic markets and failure to secure those registrations markets, which could adversely affect our ability to enforce and defend our trademark rights. Any claim of infringement by a third party, claim, even those without merit, could cause us to incur substantial costs defending against the claim, could defense costs, distract our management from our business, management, and could require us to cease use of such intellectual property. Furthermore, because of the substantial amount of discovery required in connection with intellectual property IP litigation, there is a risk that some of our confidential information could be compromised by disclosure during this type of litigation. compromised. A successful claimant could secure a judgment, judgment or we may agree to a settlement that prevents us from distributing certain products or products, performing certain services services, or that requires us to pay substantial damages, royalties, or other fees. Any of these events could seriously harm our business, financial condition, and operating results.
Added · Removed · word-level comparison of the two filings
Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
rewrittenLitigationRemoved extensive detail on confidentiality agreements, enforcement efforts, litigation costs, and international IP enforcement disparities; added reference to company as well-known security provider target.
We rely and expect to continue to rely on a combination of confidentiality and license agreements with our employees, consultants, and third parties with whom we have relationships, as well as trademark, copyright, patent, and trade secret protection laws, to protect our proprietary rights. We have filed various applications for certain aspects of our intellectual property. Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to comprehensively protect our technology or products and subscriptions. We cannot be certain that we were the first to make the inventions claimed in our pending patent applications or that we were the first to file for patent protection, which could prevent our patent applications from issuing as patents or invalidate our patents following issuance.
Additionally, the process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner. Any issued patents may be challenged, invalidated or circumvented, and any rights granted under these patents may not actually provide adequate defensive protection or competitive advantages to us. Additional uncertainty may result from changes to patent-related laws and court rulings in the United States and other jurisdictions. As a result, we may not be able to obtain adequate patent protection or effectively enforce any issued patents.
Unauthorized parties may attempt to copy aspects of our products or subscriptions or obtain and use information that we regard as proprietary. We enter into confidentiality or license agreements with employees, consultants, vendors, and end-customers and limit access to our proprietary information; however, these agreements may not be honored or our measures may not prevent misappropriation. As a well-known security provider, we may face a greater risk of unauthorized access to our proprietary information. In addition, the laws of some foreign countries do not protect proprietary rights to the same extent as U.S. laws. We may need to take legal action to enforce our intellectual property rights, which could result in substantial costs and diversion of resources, and could provoke counterclaims.
If we are unable to protect our proprietary rights, we may find ourselves at a competitive disadvantage, which would have a material adverse effect on our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
We rely and expect to continue to rely on a combination of confidentiality and license agreements with our employees, consultants, and third parties with whom we have relationships, as well as trademark, copyright, patent, and trade secret protection laws, to protect our proprietary rights. We have filed various applications for certain aspects of our intellectual property. Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to comprehensively protect our technology or products and subscriptions. We cannot be certain that we were the first to make the inventions claimed in our pending patent applications or that we were the first to file for patent protection, which could prevent our patent applications from issuing as patents or invalidate our patents following issuance. Additionally, the process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner. Any issued patents may be challenged, invalidated or circumvented, and any rights granted under these patents may not actually provide adequate defensive protection or competitive advantages to us. Additional uncertainty may result from changes to patent-related laws and court rulings in the United States and other jurisdictions. As a result, we may not be able to obtain adequate patent protection or effectively enforce any issued patents. Despite our efforts to protect our proprietary rights, unauthorized Unauthorized parties may attempt to copy aspects of our products or subscriptions or obtain and use information that we regard as proprietary. We generally enter into confidentiality or license agreements with our employees, consultants, vendors, and end-customers, end-customers and generally limit access to and distribution of our proprietary information. However, we cannot be certain that we have entered into such information; however, these agreements with all parties who may have or have had access to our confidential information or that the agreements we have entered into will not be breached. We cannot guarantee that any of the measures we have taken will prevent misappropriation of honored or our technology. Because we measures may be an attractive target for computer hackers, not prevent misappropriation. As a well-known security provider, we may have face a greater risk of unauthorized access to, and misappropriation of, to our proprietary information. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently same extent as government agencies and private parties in the United States. From time to time, we U.S. laws. We may need to take legal action to enforce our patents and other intellectual property rights, to protect our trade secrets, to determine the validity and scope of the proprietary rights of others, or to defend against claims of infringement or invalidity. Such litigation which could result in substantial costs and diversion of resources and could negatively affect our business, operating results, resources, and financial condition. Attempts to enforce our rights against third parties could also provoke these third parties to assert their own intellectual property or other rights against us or result in a holding that invalidates or narrows the scope of our rights, in whole or in part. counterclaims. If we are unable to protect our proprietary rights (including aspects of our software and products protected other than by patent rights), rights, we may find ourselves at a competitive disadvantage to others who need not incur the additional expense, time, and effort required to create the innovative products that have enabled us to be successful to date. Any of these events disadvantage, which would have a material adverse effect on our business, financial condition, and operating results.
Added · Removed · word-level comparison of the two filings
Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
rewrittenLitigationRemoved detailed description of open source software monitoring processes; now emphasizes financial condition risk and usage request uncertainties without specifying control limitations.
Our products and subscriptions contain software modules licensed to us by third-party authors under “open source” licenses. Some open source licenses contain requirements that we make available applicable source code for modifications or derivative works we create based upon the type of open source software we use. If we combine our proprietary software with, or otherwise distribute or use open source software in a certain manner, we could, under certain open source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar products or subscriptions with lower development effort and time and ultimately could result in a loss of product sales for us.
The terms of many open source licenses have not been interpreted by United States courts, and these licenses could be construed in a way that imposes unanticipated conditions or restrictions on our ability to commercialize our products and subscriptions. From time to time, there have been claims against companies that distribute or use open source software in their products and subscriptions, asserting that open source software infringes the claimants’ intellectual property rights. We could be subject to suits by parties claiming infringement of intellectual property rights in what we believe to be licensed open source software. If we are held to have breached the terms of an open source software license, we could be required to seek licenses from third parties to continue offering our products and subscriptions on terms that are not economically feasible, to reengineer our products and subscriptions, to discontinue the sale of our products and subscriptions if reengineering could not be accomplished on a timely basis, or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, financial condition, and operating results.
In addition, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or assurance of title. Our processes to help alleviate these risks, including a review process for screening open source usage requests, may not be effective.
Compare with the 2025 10-K
Prior heading: Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
Our products and subscriptions contain software modules licensed to us by third-party authors under “open source” licenses. Some open source licenses contain requirements that we make available applicable source code for modifications or derivative works we create based upon the type of open source software we use. If we combine our proprietary software with, or otherwise distribute or use open source software in a certain manner, we could, under certain open source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar products or subscriptions with lower development effort and time and ultimately could result in a loss of product sales for us. Although we take reasonable steps to monitor our use of open source software to avoid subjecting our products and subscriptions to conditions we do not intend, the The terms of many open source licenses have not been interpreted by United States courts, and there is a risk that these licenses could be construed in a way that could impose imposes unanticipated conditions or restrictions on our ability to commercialize our products and subscriptions. From time to time, there have been claims against companies that distribute or use open source software in their products and subscriptions, asserting that open source software infringes the claimants’ intellectual property rights. We could be subject to suits by parties claiming infringement of intellectual property rights in what we believe to be licensed open source software. If we are held to have breached the terms of an open source software license, we could be required to seek licenses from third parties to continue offering our products and subscriptions on terms that are not economically feasible, to reengineer our products and subscriptions, to discontinue the sale of our products and subscriptions if reengineering could not be accomplished on a timely basis, or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, operating results, and financial condition. condition, and operating results. In addition to risks related to license requirements, addition, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or assurance of title or controls on origin of the software. In addition, many of the risks associated with usage of open source software, such as the lack of warranties or assurances of title, cannot be eliminated, and could, if not properly addressed, negatively affect our business. We have established title. Our processes to help alleviate these risks, including a review process for screening requests from our development organizations for the use of open source software, but we cannot be sure that our processes for controlling our use of open source software in our products and subscriptions will usage requests, may not be effective.
Added · Removed · word-level comparison of the two filings
We license technology from third parties, and our inability to maintain those licenses could harm our business.
unchanged
We incorporate technology that we license from third parties, including software, into our products and subscriptions. We cannot be certain that our licensors are not infringing the intellectual property rights of third parties or that our licensors have sufficient rights to the licensed intellectual property in all jurisdictions in which we may sell our products and subscriptions. In addition, some licenses may be non-exclusive, and therefore our competitors may have access to the same technology licensed to us. Some of our agreements with our licensors may be terminated for convenience by them. We may also be subject to additional fees or be required to obtain new licenses if any of our licensors allege that we have not properly paid for such licenses or that we have improperly used the technologies under such licenses, and such licenses may not be available on terms acceptable to us or at all.
If we are unable to continue to license any of this technology because of intellectual property infringement claims brought by third parties against our licensors or against us, or claims against us by our licensors, or if we are unable to continue our license agreements or enter into new licenses on commercially reasonable terms, our ability to develop and sell products and subscriptions containing such technology would be severely limited and our business could be harmed. Additionally, if we are unable to license necessary technology from third parties, we may be forced to acquire or develop alternative technology, which we may be unable to do in a commercially feasible manner or at all, and we may be required to use alternative technology of lower quality or performance standards.
This would limit and delay our ability to offer new or competitive products and subscriptions and increase our costs of production. As a result, our margins, market share, and operating results could be significantly harmed.
RISKS RELATED TO OPERATIONS
We depend on manufacturing partners and limited sources of supply for our hardware products, making us susceptible to manufacturing delays, supply shortages, pricing fluctuations, and international trade risks that could prevent timely shipment of customer orders and result in the loss of sales and end-customers.
rewrittenSupply chainExpanded to include limited supply sources, international trade risks, tariffs, China-Taiwan tensions, U.S.-China tensions, Asia geographic concentration, and fiscal 2026 Q4 inflationary pressures on memory components and gross margin.
We depend on manufacturing partners, primarily our EMS provider, Flex, to manufacture our hardware product lines. Our substantial reliance on Flex or other manufacturing partners subjects us to concentration risks, such as reduced control over the manufacturing process, quality assurance, product costs and supply, and timing. Our hardware products are manufactured primarily in the United States, but some components are sourced outside the United States, subjecting us to geopolitical risks, trade regulations, tariffs, logistical risks, and foreign compliance requirements.
Changes to international trade agreements, tariffs, or trade regulations could lead to sourcing or logistics disruptions and increased costs. For example, U.S. and Chinese import tariffs have impacted some of our components, increasing our costs and potentially requiring us to further raise prices on our hardware products.
In the past, we experienced supply chain disruption and have incurred increased costs resulting from inflationary pressures and changes in U.S. trade policy. For example, T10we experienced supply chain disruption and inflationary pressures during our fourth quarter of fiscal 2026, resulting in increased costs for memory and other components, which have negatively affected our gross margin and could continue to affect our gross margin. Our manufacturing partners typically fulfill supply requirements on individual purchase orders without long-term capacity or pricing guarantees. Our contract with Flex permits termination for convenience, subject to prior notice requirements. Our manufacturing partners procure components and build products based on our forecasts, and from time to time, we issue non-cancelable, non-returnable forecasts.
If we are required to change manufacturing partners, or if our forecasting and inventory management systems prove inadequate, our ability to meet scheduled deliveries could be adversely affected. If our forecasts overestimate demand, we may be obligated to purchase excess inventory that we cannot sell, resulting in write-downs, increased carrying costs, and lower gross margins. Conversely, if our forecasts underestimate demand, we may experience insufficient supply, leading to product shortages, delayed deliveries, lost sales opportunities, and potential damage to customer relationships. Any production interruptions, whether from natural disasters, epidemics or pandemics, capacity shortages, or quality problems, would negatively affect sales and our business and operating results.
Our hardware products rely on key components, including integrated circuit components, purchased from a limited number of suppliers, including sole source providers. The manufacturing operations of some suppliers are geographically concentrated in Asia, making our supply chain vulnerable to regional disruptions and international regulations, including tariffs, sanctions, and export controls. We are also monitoring the tensions between China and Taiwan, and between the U.S. and China, which have increased our costs and could have an adverse impact on our business or results of operations in future periods. We do not have volume purchase contracts with our component suppliers, and they could cease selling to us or change prices at any time.
For example, there is currently a global shortage of memory-related components, and certain of our hardware appliances require higher memory content, which has led to and may continue to lead to increased production costs. If we are unable to obtain sufficient components on commercially reasonable terms, we could be forced to redesign our products and qualify new suppliers, resulting in lost sales opportunities and damage to customer relationships.
Compare with the 2025 10-K
Prior heading: Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers.
We depend on manufacturing partners, primarily our EMS provider, Flex, to manufacture our hardware product lines. Our substantial reliance on Flex, as well as Flex or other manufacturing partners subjects us to potential concentration risks, such as reduced control over the manufacturing process, quality assurance, product costs, product costs and supply, and timing. Our hardware products are manufactured by our manufacturing partners at facilities located primarily in the United States. Some of the States, but some components in our products are sourced either through Flex or directly by us from component suppliers outside the United States. The portion of our hardware products that are sourced outside the United States may subject States, subjecting us to geopolitical risks, additional logistical risks, risks associated with international trade agreements, international trade disputes, trade regulations, tariffs, or risks associated with complying with local rules logistical risks, and regulations in foreign countries. Significant changes compliance requirements. Changes to existing international trade agreements, tariffs, or trade regulations could lead to sourcing or logistics disruption resulting from import delays or the imposition of disruptions and increased tariffs on our sourcing partners. costs. For example, the United States U.S. and Chinese governments have each enacted, and discussed additional, import tariffs. Some components that we import for final manufacturing in the United States tariffs have been impacted by these tariffs. As a result, some of our components, increasing our costs have increased and we have raised, and may be required potentially requiring us to further raise, raise prices on our hardware products in response to these products. In the past, we experienced supply chain disruption and potential new have incurred increased costs resulting from inflationary pressures and changes in U.S. trade regulations. policy. For example, we experienced supply chain disruption and inflationary pressures during our fourth quarter of fiscal 2026, resulting in increased costs for memory and other components, which have negatively affected our gross margin and could continue to affect our gross margin. Our manufacturing partners typically fulfill our supply requirements on the basis of individual purchase orders. We do not have orders without long-term contracts with these manufacturers that guarantee capacity, the continuation of particular pricing terms, capacity or the extension of credit limits. Accordingly, they are not obligated to continue to fulfill our supply requirements and the prices we pay for manufacturing services could be increased on short notice. pricing guarantees. Our contract with Flex permits them to terminate the agreement termination for their convenience, subject to prior notice requirements. Our manufacturing partners procure components and build products based on our forecasts, and from time to time, we issue non-cancelable, non-returnable forecasts. If we are required to change manufacturing partners, or if our forecasting and inventory management systems prove inadequate, our ability to meet our scheduled product deliveries to our end-customers could be adversely affected, which could cause the loss of sales affected. If our forecasts overestimate demand, we may be obligated to existing or potential end-customers, delayed revenue or an increase purchase excess inventory that we cannot sell, resulting in our costs which could adversely affect our write-downs, increased carrying costs, and lower gross margins. Conversely, if our forecasts underestimate demand, we may experience insufficient supply, leading to product shortages, delayed deliveries, lost sales opportunities, and potential damage to customer relationships. Any production interruptions for any reason, such as a interruptions, whether from natural disaster, epidemic disasters, epidemics or pandemic, pandemics, capacity shortages, or quality problems at one of our manufacturing partners problems, would negatively affect sales of and our product lines manufactured by that business and operating results. Our hardware products rely on key components, including integrated circuit components, purchased from a limited number of suppliers, including sole source providers. The manufacturing partner operations of some suppliers are geographically concentrated in Asia, making our supply chain vulnerable to regional disruptions and adversely affect international regulations, including tariffs, sanctions, and export controls. We are also monitoring the tensions between China and Taiwan, and between the U.S. and China, which have increased our costs and could have an adverse impact on our business or results of operations in future periods. We do not have volume purchase contracts with our component suppliers, and operating results.they could cease selling to us or change prices at any time. For example, there is currently a global shortage of memory-related components, and certain of our hardware appliances require higher memory content, which has led to and may continue to lead to increased production costs. If we are unable to obtain sufficient components on commercially reasonable terms, we could be forced to redesign our products and qualify new suppliers, resulting in lost sales opportunities and damage to customer relationships.
Added · Removed · word-level comparison of the two filings
If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.
unchangedLabor & talent
Our future success depends, in part, on our ability to continue to attract, retain, and motivate the members of our management team and other key employees. For example, we are substantially dependent on the continued service of our engineering personnel because of the complexity of our offerings. Competition for highly skilled personnel, particularly in engineering, including in the areas of AI and machine learning, is intense, especially in the San Francisco Bay Area, where we have a substantial presence and need for such personnel. In addition, the industry in which we operate generally experiences high employee attrition. Our future performance depends on the continuing services and contributions of our senior management to execute on our business plan and to identify and pursue new opportunities and product innovations.
If we are unable to hire, integrate, train, or retain the qualified and highly skilled personnel required to fulfill our current or future needs, our business, financial condition, and operating results could be harmed. Moreover, our hybrid work environment may also create operational, security, and workplace culture challenges that could hinder execution of our business objectives and our ability to attract and retain qualified and highly skilled personnel.
Further, we believe that a critical contributor to our success and our ability to retain highly skilled personnel has been our corporate culture, which we believe fosters innovation, inclusion, teamwork, passion for end-customers, focus on execution, and the facilitation of critical knowledge transfer and knowledge sharing. As we grow and change, and as we acquire and integrate other businesses, we may find it difficult to maintain these important aspects of our corporate culture. While we are taking steps to develop a more inclusive workforce, there is no guarantee that we will be able to do so. Any failure to preserve our culture as we grow could limit our ability to innovate and could negatively affect our ability to retain and recruit personnel, continue to perform at current levels, or execute on our business strategy.
We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.
rewrittenTariffs & tradeAdded export/import controls, encryption technology regulations, U.S. sanctions compliance, and penalties for non-compliance as specific international operation risks.
Our ability to successfully grow our business will depend to a significant extent on our ability to expand our operations and customer base worldwide. Operating in a global marketplace, we are subject to risks associated with international reach, compliance, and regulatory requirements. We may experience difficulties in attracting and retaining international personnel or strategic distributor relationships, and business practices in international markets may require non-standard end-customer contract terms related to payment, warranties, or performance obligations.
Additionally, our international sales and operations are subject to a number of risks, including the following:
•political, economic, and social uncertainty around the world, health risks such as epidemics and pandemics, macroeconomic challenges, terrorist activities, the Russia-Ukraine war, tensions between China and Taiwan, the hostilities in Israel and the surrounding region, and continued hostilities in the Middle East;
•unexpected changes in, or the application of, foreign and domestic laws and regulations (including intellectual property rights protections), regulatory practices or enforcement policies, trade restrictions, international trade agreements, and foreign legal requirements, including those applicable to the importation, certification, localization and regulatory approval of our products, tariffs, and tax laws and treaties, including regulatory and trade policy changes adopted by the current administration, such as sanctions, or foreign countries’ response to regulatory changes adopted by the current administration; and •non-compliance with U.S. and foreign laws, including antitrust regulations, anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the United Kingdom (“U.K.”) Bribery Act, U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices.
These and other factors could harm our future international revenues and, consequently, materially impact our business, financial condition, and operating results. In addition, because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the United States only with the required export license or license exception. U.S. export control laws and economic sanctions prohibit shipment of certain products to embargoed or sanctioned countries, governments, and persons. Various countries also regulate the import of encryption technology. Changes in export or import regulations, economic sanctions, or the countries and technologies targeted by such regulations could decrease use of our products internationally.
Any failure by us or our channel partners to comply with trade regulations could subject us to substantial civil and criminal penalties. International trade laws continuously evolve, and monitoring and responding to these developments may require significant resources. Our failure to successfully manage our international operations and the associated risks could limit the future growth of our business.
Compare with the 2025 10-K
Prior heading: We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations.
Our ability to successfully grow our business and our future success will depend to a significant extent on our ability to expand our operations and customer base worldwide. Many of our customers, resellers, partners, suppliers, and manufacturers operate around the world. Operating in a global marketplace, we are subject to risks associated with having an international reach and compliance reach, compliance, and regulatory requirements. We may experience difficulties in attracting, managing, attracting and retaining an international staff, and we may not be able to recruit and maintain successful personnel or strategic distributor relationships internationally. Business relationships, and business practices in the international markets that we serve may differ from those in the United States and may require us in the future to include terms other than our standard non-standard end-customer contract terms related to payment, warranties, or performance obligations in end-customer contracts. obligations. Additionally, our international sales and operations are subject to a number of risks, including the following: •political, economic, and social uncertainty around the world, health risks such as epidemics and pandemics like COVID-19, pandemics, macroeconomic challenges, terrorist activities, the Russia-Ukraine war, tensions between China and Taiwan, the hostilities in Israel and the surrounding region, and continued hostilities in the Middle East; •unexpected changes in, or the application of, foreign and domestic laws and regulations (including intellectual property rights protections), regulatory practices or enforcement policies, trade restrictions, international trade agreements, and foreign legal requirements, including those applicable to the importation, certification, and localization and regulatory approval of our products, tariffs, and tax laws and treaties, including regulatory and trade policy changes adopted by the current administration, such as the Sanctions on Russia, sanctions, or foreign countries in countries’ response to regulatory changes adopted by the current administration; and •non-compliance with U.S. and foreign laws, including antitrust regulations, anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the United Kingdom (“U.K.”) Bribery Act, U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices. These and other factors could harm our future international revenues and, consequently, materially impact our business, financial condition, and operating results, results. In addition, because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and financial condition. The expansion may be exported outside the United States only with the required export license or license exception. U.S. export control laws and economic sanctions prohibit shipment of certain products to embargoed or sanctioned countries, governments, and persons. Various countries also regulate the import of encryption technology. Changes in export or import regulations, economic sanctions, or the countries and technologies targeted by such regulations could decrease use of our existing international operations products internationally. Any failure by us or our channel partners to comply with trade regulations could subject us to substantial civil and entry into additional international markets will criminal penalties. International trade laws continuously evolve, and monitoring and responding to these developments may require significant management attention and financial resources. Our failure to successfully manage our international operations and the associated risks effectively could limit the future growth of our business.
Added · Removed · word-level comparison of the two filings
Our products and subscriptions are subject to certification, testing, and regulatory approval requirements in foreign jurisdictions, and our failure to obtain or maintain such approvals could limit our ability to sell in those markets.
addedRegulatoryAdded risk that foreign regulatory requirements—including China's cybersecurity laws, network security review, data storage mandates, and source code escrow—may prevent product sales in affected markets.
Our products and subscriptions are subject to regulatory requirements in a number of foreign jurisdictions, and the scope and complexity of these requirements continue to expand. For example, in China, our products may be required to comply with cybersecurity and data security laws, including the Cybersecurity Law, the Data Security Law, and related regulations, and may be subject to network security review, critical information infrastructure protection requirements, and mandatory product certifications. Other jurisdictions impose similar requirements, including local testing and certification requirements, in-country data storage or processing mandates, source code review or escrow obligations, and restrictions on the use of foreign-developed encryption or security technologies. Compliance with these requirements is costly and time-consuming, and the regulatory landscape in many jurisdictions is evolving and subject to change with limited or no notice.
If we are unable to obtain or maintain required certifications, approvals, or authorizations in a timely manner, or if new or revised requirements render our products or subscriptions non-compliant, we may be unable to sell, deploy, or support our products in affected markets, which could result in lost revenue opportunities, reputational harm, and a material adverse effect on our business, financial condition, and operating results.
We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
rewrittenMacro & demandRemoved detailed discussion of hedging strategies, channel partners' foreign currency exposure, and effectiveness of hedging transactions.
Our sales contracts are primarily denominated in U.S. dollars, and therefore, a predominant amount of our revenue is not subject to foreign currency risk. However, a strengthening of the U.S. dollar could increase the cost of our products to end-customers outside the United States. Increased international sales in the future may result in greater foreign currency denominated sales, increasing our foreign currency risk.
Our operating expenses incurred outside the United States and denominated in foreign currencies are generally increasing and are subject to fluctuations due to changes in exchange rates. We have entered into forward contracts to reduce our foreign currency exchange exposure. As of July 31, 2026, the total notional amount of our outstanding foreign currency forward contracts was $2.2 billion. For more information, refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K. The effectiveness of our hedging transactions may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results.
Compare with the 2025 10-K
Prior heading: We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
Our sales contracts are primarily denominated in U.S. dollars, and therefore, a predominant amount of our revenue is not subject to foreign currency risk. However, in the event of a strengthening of the U.S. dollar against foreign currencies in which we conduct business, could increase the cost of our products to our end-customers outside of the United States would increase, which could adversely affect our financial condition and operating results. In addition, increased States. Increased international sales in the future, including through our channel partners and other partnerships or as a result of our acquisitions, future may result in increased greater foreign currency denominated sales, increasing our foreign currency risk. Our operating expenses incurred outside the United States and denominated in foreign currencies are generally increasing and are subject to fluctuations due to changes in foreign currency exchange rates. If we are not able to successfully hedge against the risks associated with foreign currency fluctuations, our financial condition and operating results could be adversely affected. We have entered into forward contracts in an effort to reduce our foreign currency exchange exposure related to our foreign currency denominated revenue and operating expenditures. exposure. As of July 31, 2025, 2026, the total notional amount of our outstanding foreign currency forward contracts was $1.5 $2.2 billion. For more information on our hedging transactions, information, refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results.
Added · Removed · word-level comparison of the two filings
We face risks associated with having operations and employees located in Israel.
rewrittenGeopolitical & warExpanded Israel operations risk scope following CyberArk acquisition; added Iran escalation as specific concern.
We have business operations in Israel, which meaningfully expanded as a result of the acquisition of CyberArk, and we intend to continue growing our presence in Israel. Our operations in Israel could be disrupted by political instability, civil unrest, terrorist attacks, acts of violence or war, or other military actions, including ongoing hostilities in the region. The effects of such hostilities on the Israeli economy and our operations in Israel are unclear, and current or future tensions and conflicts in the Middle East, including any escalation involving Iran, could adversely affect our business, financial condition, operating results, and cash flows.
Many of our employees in Israel are obligated to perform annual reserve duty in the Israeli military and are subject to being called for active duty under emergency circumstances, which has occurred as a result of regional hostilities. If many of our employees in Israel are called for active duty for a significant period of time, our operations could be disrupted and may not function at full capacity, which could adversely affect our business.
Compare with the 2025 10-K
Prior heading: We face risks associated with having operations and employees located in Israel.
We have business operations in Israel Israel, which meaningfully expanded as a result of the acquisition of CyberArk, and we intend to continue growing our presence in Israel, including in connection with our proposed acquisition of CyberArk. Israel. Our operations in Israel could be disrupted by political instability, civil unrest, terrorist attacks, acts of violence, acts of violence or war, or other military actions, including the ongoing hostilities in Israel and the surrounding region. The future of peace efforts between Israel and its Arab neighbors remains uncertain. The effects of such hostilities and violence on the Israeli economy and our operations in Israel are unclear, and we cannot predict the effect on us of further increases in these hostilities or future armed conflict, political instability, or violence in the region. Current current or future tensions and conflicts in the Middle East East, including any escalation involving Iran, could adversely affect our business, operating results, financial condition, operating results, and cash flows. In addition, many Many of our employees in Israel are obligated to perform annual reserve duty in the Israeli military and are subject to being called for active duty under emergency circumstances, which has occurred as a result of hostilities in Israel and the surrounding region. We cannot predict the full impact of these conditions on us in the future, particularly if emergency circumstances or an escalation in the political situation or hostilities occurs. regional hostilities. If many of our employees in Israel are called for active duty for a significant period of time, our operations and our business could be disrupted and may not be able to function at full capacity. Any disruption in our operations in Israel capacity, which could adversely affect our business.
Added · Removed · word-level comparison of the two filings
RISKS RELATED TO PRIVACY AND DATA PROTECTION
We may incur significant costs to comply with privacy and data protection laws and other requirements, and, if we fail to comply, we could be subject to government enforcement actions, private litigation, and adverse publicity, which could materially adversely affect our business, financial condition, and operating results.
rewrittenRegulatoryExpanded privacy risk disclosure to include data localization laws, HIPAA, GDPR, E.U. NIS Directive II, and class action litigation; added materiality language and insurance availability concerns.
A wide variety of laws, regulations, industry standards, contractual requirements, and other obligations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data in jurisdictions where we and our customers operate. Compliance with these laws and other obligations is difficult and costly, and they are subject to frequent and unexpected changes. For example, we are subject to the E.U. General Data Protection Regulation (“E.U. GDPR”) and the U.K. General Data Protection Regulation (“U.K. GDPR,” and collectively the “GDPR”), each of which imposes stringent data protection requirements and provides for costly penalties for noncompliance (up to the greater of (a) €20 million under the E.U.
GDPR or £17.5 million under the U.K. GDPR, and (b) 4% of annual worldwide turnover), and confers the right upon data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations.
The GDPR restricts transfers of personal data outside of the European Economic Area (“EEA”) (or, in the case of the U.K. GDPR, the U.K.) to non-EEA countries, such as the United States, unless adequate safeguards are implemented or a derogation applies. We rely on standard contractual clauses approved under the GDPR to carry out such transfers and to receive personal data subject to the GDPR (directly or indirectly) in the United States. In addition, with respect to the personal data that we process on behalf of our customers, we self-certified to the E.U.-U.S. Data Privacy Framework (“E.U.-U.S. DPF”), the UK Extension to the E.U.-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (collectively, the "DPF") as set forth by the U.S.
Department of Commerce for such transfers. However, the DPF may be subject to legal challenges that could invalidate its use. In addition, the U.K. Data (Use and Access) Act 2025 includes changes to the U.K.'s data protection regime that deviate from the GDPR, creating new compliance challenges. We anticipate future legal challenges and developments to approved data transfer mechanisms, including to the E.U.-U.S. DPF, which could result in additional compliance costs and harm our business. Among other effects of these developments, we may also experience reduced demand for our products and subscriptions from current or prospective customers in the EEA, Switzerland, and the U.K. (collectively, “Europe”) on account of the risks identified in the Schrems II decision or other developments relating to cross-border data transfers, and we may find it necessary or desirable to make further changes to our processing of personal data of European residents.
The regulatory environment applicable to the handling of European residents’ personal data and cross-border data transfers, and our actions taken in response, may cause us to assume additional liabilities or incur additional costs.
We are also subject to U.S. privacy and data protection laws, including the California Consumer Privacy Act (the "CCPA"), which, among other requirements, requires enhanced disclosures, affords California residents with certain rights regarding their personal data, and creates a private right of action for data breaches caused by a lack of reasonable security. Over twenty other U.S. states have enacted similar privacy laws. Additionally, the U.S. Department of Justice has issued rules regarding access to or transfer of certain bulk sensitive personal data by countries of concern or covered persons, and we are subject to the Health Insurance Portability and Accountability Act ("HIPAA"), both of which carry significant enforcement penalties for non-compliance. These and other increasingly complex federal and state privacy laws and their enforcement may also require us to modify our data practices and incur additional substantial compliance costs.
We are also subject to obligations relating to personal data and data protection by contract and self-regulatory and industry standards. Additionally, the Federal Trade Commission and state attorneys general are more regularly bringing enforcement actions for deceptive practices related to the collection and security of personal data.
We and our customers could face risk of regulatory investigations, enforcement actions, private litigation (including class action litigation), and adverse publicity, including reputational damage and loss of customer confidence, for actual or perceived violations of any of the foregoing data protection obligations. Any such claims could result in substantial costs, remedial and reporting obligations, distraction of management, and diversion of resources. Our insurance may not cover all types of claims that may arise, and we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all. If any of the foregoing were to occur, our business, results of operations, and financial condition could be materially adversely affected.
Moreover, new legislation affecting the scope of personal data and information, especially relating to IP addresses, machine identification, AI and machine learning, location data, health information, and other information, may limit or inhibit our ability to operate or expand our business and may require significant additional expenditures to comply. Data localization laws may mandate that personal data collected in a foreign country be processed and stored within that country, potentially requiring costly restructuring of our cloud infrastructure. Public perception of privacy or information security concerns, whether or not valid, may harm our reputation and inhibit adoption of our products and subscriptions. Additionally, existing laws and regulations, and any changes to them, or new laws and regulations, could impose significant limitations or require changes to our business model, which may increase our compliance costs.
We are also subject to federal, state, provincial, and foreign laws regarding cybersecurity and the protection of our systems and confidential information. Many jurisdictions have enacted laws, such as the GDPR and the E.U. Network and Information Systems Directive II, requiring companies to adopt cybersecurity risk management measures and notify regulators (and individuals) of data breaches or cybersecurity incidents. If our data security measures fail to adequately protect our systems or confidential information, we could be liable to both our customers and their users for any related losses. Additionally, we could face regulatory action or face litigation, and our customers could terminate or materially change their relationships with us, any of which could harm our business, financial condition, or operating results.
Compare with the 2025 10-K
Prior heading: We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.
A wide variety of laws laws, regulations, industry standards, contractual requirements, and regulations other obligations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data in jurisdictions where we and our customers operate. Compliance with these laws and regulations other obligations is difficult and costly. These laws costly, and regulations they are also subject to frequent, inconsistent frequent and unexpected changes; new, modified or additional laws or regulations may be adopted; and rulings that invalidate prior laws, regulations, or interpretations of such laws or regulations may be issued. changes. For example, we are subject to the E.U. General Data Protection Regulation (“E.U. GDPR”) and the U.K. General Data Protection Regulation (“U.K. GDPR,” and collectively the “GDPR”), each of which imposes stringent data protection requirements, provide requirements and provides for costly penalties for noncompliance (up to the greater of (a) €20 million under the E.U. GDPR or £17.5 million under the U.K. GDPR, and (b) 4% of annual worldwide turnover), and confer confers the right upon data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations. The GDPR imposes restrictions, among other things, on the transfer restricts transfers of personal data outside of the European Economic Area (“EEA”) (or, in the case of the U.K. GDPR, the U.K.) to non-EEA countries, such as the United States, unless adequate safeguards are implemented or a derogation applies. In practice, we We rely on standard contractual clauses approved under the GDPR to carry out such transfers and to receive personal data subject to the GDPR (directly or indirectly) in the United States. In addition, with respect to the personal data that we process on behalf of our customers, we self-certified to the E.U.-U.S. Data Privacy Framework (“E.U.-U.S. DPF”), the UK Extension to the E.U.-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (collectively, the “DPF”), "DPF") as set forth by the U.S. Department of Commerce, regarding transfers of certain personal data from the E.U., the U.K., and Switzerland to the United States. The DPF has been recognized as adequate under applicable law to allow transfers of personal data from the E.U., U.K., and Switzerland, as the case may be, to companies in the U.S. that have self-certified to the framework. Commerce for such transfers. However, the DPF may be subject to legal challenges, which challenges that could invalidate its use, disrupt our ability to rely on such data transfer mechanisms, and otherwise cause the legal requirements for such data transfers to be uncertain. use. In addition, the U.K. government enacted the U.K. Data (Use and Access) Act 2025 on June 19, 2025, which includes targeted amendments changes to the U.K.’s U.K.'s data protection regime that cause it to expressly deviate from the GDPR. This development creates GDPR, creating new compliance challenges. We anticipate future legal challenges and has created uncertainty with respect to the European Commission’s adequacy determination regarding the U.K.’s data protection regime, which has been extended until December 2025 and must be renewed developments to permit ongoing relatively unrestricted approved data flows from the EEA transfer mechanisms, including to the UK. E.U.-U.S. DPF, which could result in additional compliance costs and harm our business. Among other effects of these developments, we may also experience additional costs associated with increased compliance burdens, reduced demand for our offerings products and subscriptions from current or prospective customers in the EEA, Switzerland, and the U.K. (collectively, “Europe”) to use our products, on account of the risks identified in the Schrems II decision or other developments relating to cross-border data transfers, and we may find it necessary or desirable to make further changes to our processing of personal data of European residents. The regulatory environment applicable to the handling of European residents’ personal data and cross-border data transfers, and our actions taken in response, may cause us to assume additional liabilities or incur additional costs. Moreover, much like with Schrems II, we anticipate future legal challenges to the approved data transfer mechanisms between Europe and the United States, including a challenge to the E.U.-U.S. DPF. Such legal challenges could result in additional legal and regulatory risk, compliance costs, and in our business, operating results, and financial condition being harmed. costs. We are also subject to U.S. privacy and data protection laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”). The CCPA requires, (the "CCPA"), which, among other things, covered businesses to provide requirements, requires enhanced disclosures to disclosures, affords California consumers and to afford such consumers residents with certain rights regarding their personal data, including the right to opt out of data sales for targeted advertising, and creates a private right of action to individuals affected by a for data breach, if the breach was breaches caused by a lack of reasonable security. The effects of the CCPA have been significant, requiring us to modify our data processing practices and policies and to incur substantial costs and expenses for compliance. Moreover, Over twenty other U.S. states have enacted laws relating to similar privacy and security that are potentially relevant to us. These include laws enacted in at least 20 U.S. states, a portion of which are expected to come into effect over laws. Additionally, the course of our fiscal 2026. The U.S. Department of Justice also has issued rules regarding access to, to or transfer of, of certain bulk sensitive personal data by countries of concern. Increasingly complex federal concern or state laws covered persons, and regulations relating we are subject to privacy the Health Insurance Portability and security, Accountability Act ("HIPAA"), both of which carry significant enforcement penalties for non-compliance. These and interpretations other increasingly complex federal and enforcement of existing state privacy laws and regulations relating to these matters, their enforcement may also require us to modify our data practices and policies, incur additional substantial compliance costs and expenses, and add further complexity to our compliance efforts that could adversely affect our business or increase our potential liability if we fail to comply or are alleged to have done so. costs. We may are also from time to time be subject to obligations relating to personal data and data protection by contract, or face assertions that we are subject to contract and self-regulatory obligations or and industry standards. Additionally, the Federal Trade Commission and many state attorneys general are more regularly bringing enforcement actions in connection with federal and state consumer protection laws for false or deceptive acts or practices in relation related to the online collection, use, dissemination, collection and security of personal data. Internationally, data localization laws may mandate that personal data collected in a foreign country be processed and stored within that country. data. We and our customers may could face risk of regulatory investigations, enforcement actions by regulators or data protection authorities, actions, private litigation (including class action litigation), and adverse publicity publicity, including reputational damage and loss of customer confidence confidence, for alleged actual or perceived violations of any of the foregoing data protection obligations. Any such claims could result in substantial costs, ongoing remedial, audit remedial and reporting obligations, and diversion distraction of resources, and distract management and technical personnel. These potential liabilities and enforcement actions could also have an overall negative effect on our business, operating results, and financial condition. The amount management, and scope diversion of resources. Our insurance we maintain may not cover all types of claims that may arise. New arise, and we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all. If any of the foregoing were to occur, our business, results of operations, and financial condition could be materially adversely affected. Moreover, new legislation affecting the scope of personal data and personal information where we or our customers and partners have operations, information, especially relating to classification of Internet Protocol (“IP”) IP addresses, machine identification, AI and machine learning, location data, health information, and other information, may limit or inhibit our ability to operate or expand our business, including limiting strategic partnerships that may involve the sharing or uses of data, business and may require significant additional expenditures and efforts in order to comply. Notably, public Data localization laws may mandate that personal data collected in a foreign country be processed and stored within that country, potentially requiring costly restructuring of our cloud infrastructure. Public perception of potential privacy, data protection, privacy or information security concerns—whether concerns, whether or not valid—may valid, may harm our reputation and inhibit adoption of our products and subscriptions by current and future end-customers. Each of these subscriptions. Additionally, existing laws and regulations, and any changes to these laws and regulations, them, or new laws and regulations, could impose significant limitations, limitations or require changes to our business model or practices or growth strategy, model, which may increase our compliance expenses costs. We are also subject to federal, state, provincial, and make foreign laws regarding cybersecurity and the protection of our business more costly systems and confidential information. Many jurisdictions have enacted laws, such as the GDPR and the E.U. Network and Information Systems Directive II, requiring companies to adopt cybersecurity risk management measures and notify regulators (and individuals) of data breaches or less efficient cybersecurity incidents. If our data security measures fail to conduct.adequately protect our systems or confidential information, we could be liable to both our customers and their users for any related losses. Additionally, we could face regulatory action or face litigation, and our customers could terminate or materially change their relationships with us, any of which could harm our business, financial condition, or operating results.
Added · Removed · word-level comparison of the two filings
Tax, Accounting, Compliance, and Regulatory Risks
We may have exposure to tax liabilities that are greater than anticipated.
rewrittenRegulatoryAdded OECD Pillar Two 15% global minimum tax framework effective 2024, January 2026 SbS Package exemption for U.S. multinationals, and CyberArk convertible notes fair value tax exposure.
Our income tax obligations are based in part on our corporate structure and intercompany arrangements, including the manner in which we develop, value, and use our intellectual property and the valuations of our intercompany transactions. The tax laws applicable to our business, including the laws of the United States and various other jurisdictions, are subject to interpretation and certain jurisdictions may aggressively interpret their laws, regulations, and policies, including in an effort to raise additional tax revenue. The tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed or acquired technology or determining the proper charges for intercompany arrangements, which could increase our worldwide effective tax rate, harm our financial position and operating results, and have a negative effect on our cash flow.
Some tax authorities of jurisdictions other than the United States may seek to assert extraterritorial taxing rights on our transactions or operations. It is possible that domestic or international tax authorities may subject us to tax examinations or audits, and such tax authorities may disagree with certain positions we have taken, and any adverse outcome of such an examination, review, or audit could result in additional tax liabilities and penalties and otherwise have a negative effect on our financial condition, operating results, and cash flow. Further, the determination of our worldwide provision for income taxes and other tax liabilities requires significant judgment by management, and there are transactions where the ultimate tax determination is uncertain.
Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded on our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made.
In addition, our future income tax obligations and effective tax rates could be adversely affected by changes in, or interpretations of, tax laws, regulations, policies, or decisions in the United States or in the other jurisdictions in which we operate including as a result of the U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act, which was signed into law on July 4, 2025. In addition, our effective tax rates could be affected by fluctuations in the market price of our common stock and changes in the fair value of CyberArk’s $1.25 billion aggregate principal amount of 0.00% Convertible Senior Notes due 2030 (the “2030 Notes”) and the fair value of the capped call transactions (the “Capped Calls”) we acquired in connection with the CyberArk acquisition. If our future tax obligations or effective tax rates increase as a result of these or other factors, it could have an adverse effect on our financial condition and operating results.
Moreover, in October 2021, the Organization for Economic Co-operation and Development (“OECD”) issued model rules for a new global minimum tax framework, commonly referred to as “Pillar Two,” which included the introduction of a 15% global minimum tax effective beginning January 1, 2024. To date, approximately 140 countries have tentatively signed a framework agreeing in principle to this initiative. A number of countries in which we do business have implemented or may implement Pillar Two proposals into local tax legislation. On January 5, 2026, the OECD released a “side-by-side” package (the “SbS Package”) that generally establishes an exemption for U.S. multinationals from the 15% global minimum tax. However, the implementation of the SbS Package depends on domestic legislation and regulation in OECD member countries and is subject to subsequent review.
Details around the proposals are still uncertain as the OECD and local jurisdictions continue to issue the technical guidance. Our effective tax rate and cash tax payments could increase in future years as a result of these changes.
Compare with the 2025 10-K
Prior heading: We may have exposure to tax liabilities that are greater than anticipated.
Our income tax obligations are based in part on our corporate structure and intercompany arrangements, including the manner in which we develop, value, and use our intellectual property and the valuations of our intercompany transactions. The tax laws applicable to our business, including the laws of the United States and various other jurisdictions, are subject to interpretation and certain jurisdictions may aggressively interpret their laws, regulations, and policies, including in an effort to raise additional tax revenue. The tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed or acquired technology or determining the proper charges for intercompany arrangements, which could increase our worldwide effective tax rate, harm our financial position and operating results, and have a negative effect on our cash flow. Some tax authorities of jurisdictions other than the United States may seek to assert extraterritorial taxing rights on our transactions or operations. It is possible that domestic or international tax authorities may subject us to tax examinations, examinations or audits, and such tax authorities may disagree with certain positions we have taken, and any adverse outcome of such an examination, review review, or audit could result in additional tax liabilities and penalties and otherwise have a negative effect on our financial position, condition, operating results, and cash flow. Further, the determination of our worldwide provision for income taxes and other tax liabilities requires significant judgment by management, and there are transactions where the ultimate tax determination is uncertain. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded on our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made. In addition, our future income tax obligations and effective tax rates could be adversely affected by changes in, or interpretations of, tax laws, regulations, policies, or decisions in the United States or in the other jurisdictions in which we operate including as a result of the U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act, which was signed into law on July 4, 2025.2025. In addition, our effective tax rates could be affected by fluctuations in the market price of our common stock and changes in the fair value of CyberArk’s $1.25 billion aggregate principal amount of 0.00% Convertible Senior Notes due 2030 (the “2030 Notes”) and the fair value of the capped call transactions (the “Capped Calls”) we acquired in connection with the CyberArk acquisition. If our future tax obligations or effective tax rates increase as a result of these or other factors, it could have an adverse effect on our financial condition and operating results. Moreover, in October 2021, the Organization for Economic Co-operation and Development (“OECD”) issued model rules for a new global minimum tax framework, commonly referred to as “Pillar Two,” which included the introduction of a 15% global minimum tax effective beginning January 1, 2024. To date, approximately 140 countries have tentatively signed a framework agreeing in principle to this initiative. A number of countries in which we do business have implemented or may implement Pillar Two proposals into local tax legislation. On January 5, 2026, the OECD released a “side-by-side” package (the “SbS Package”) that generally establishes an exemption for U.S. multinationals from the 15% global minimum tax. However, the implementation of the SbS Package depends on domestic legislation and regulation in OECD member countries and is subject to subsequent review. Details around the proposals are still uncertain as the OECD and local jurisdictions continue to issue the technical guidance. Our effective tax rate and cash tax payments could increase in future years as a result of these changes.
Added · Removed · word-level comparison of the two filings
Our estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that may change or prove to be incorrect and, as a result, our operating results may differ from our publicly announced guidance or the expectations of securities analysts and investors, which may result in a decline in the market price of our common stock.
unchanged
The preparation of consolidated financial statements in conformity with U.S. generally accepted accounting principles (“U.S. GAAP”) requires management to make estimates and assumptions that affect the amounts reported on our consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, the results of which form the basis for making judgments about the carrying amounts of assets, liabilities, equity, revenue, and expenses that are not readily apparent from other sources. For more information relating to critical accounting policies, refer to the section entitled “Critical Accounting Estimates” in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” in Part II, Item 7 of this Annual Report on Form 10-K.
In general, if our estimates, judgments, or assumptions relating to our critical accounting policies change or if actual circumstances differ from our estimates, judgments, or assumptions, our operating results may be adversely affected and could fall below our publicly announced guidance or the expectations of securities analysts and investors, which may result in a decline in the market price of our common stock.
We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and, as a result, the value of our common stock.
unchangedRegulatory
If we are unable to assert that our internal controls are effective, our independent registered public accounting firm may not be able to formally attest to the effectiveness of our internal control over financial reporting. If, in the future, our chief executive officer, chief financial officer, or independent registered public accounting firm determines that our internal control over financial reporting is not effective as defined under Section 404, we could be subject to one or more investigations or enforcement actions by state or federal regulatory agencies, stockholder lawsuits, or other adverse actions requiring us to incur defense costs and pay fines, settlements, or judgments, causing investor perceptions to be adversely affected and potentially resulting in a decline in the market price of our common stock.
Our reputation and business could be negatively impacted by corporate responsibility matters, including our reporting of such matters.
rewrittenOtherNarrowed focus from broad corporate responsibility risks to evolving, potentially contradictory stakeholder expectations; removed SEC disclosure and investor impact language.
Governmental authorities, certain investors, and other stakeholders continue to focus on, set and revise, expectations relating to corporate responsibility matters, both in the United States and internationally. Such expectations are evolving and may be contradictory. We communicate corporate responsibility initiatives, goals, and commitments regarding sustainability, inclusion, responsible sourcing, and community impact in our annual Corporate Responsibility Report, on our website, in our SEC filings, and elsewhere. These initiatives may be difficult to achieve and costly to implement. We could be criticized for their scope, nature, timing, or any revisions to them, and for the accuracy or completeness of our disclosures. Our actual or perceived failure to undertake these initiatives and achieve these goals, or the fact that we are undertaking these initiatives, could negatively impact our reputation or otherwise materially harm our business.
In addition, we are or may become subject to various new, proposed, and evolving sustainability-related laws and regulations, including, for example, the E.U.’s Corporate Sustainability Reporting Directive. Additional regulation may require us to incur significant costs associated with increased compliance burdens, including the implementation of additional internal controls processes and procedures, and impose increased oversight obligations on our management and board of directors, as well as require us to retain third-party experts. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, fines, or litigation, which could negatively impact our business, financial condition, and operating results.
Compare with the 2025 10-K
Prior heading: Our reputation and/or business could be negatively impacted by corporate responsibility matters and/or our reporting of such matters.
There is an increasing focus from regulators, Governmental authorities, certain investors, and other stakeholders concerning continue to focus on, set and revise, expectations relating to corporate responsibility matters, both in the United States and internationally. Such expectations are evolving and may be contradictory. We communicate certain corporate responsibility-related responsibility initiatives, goals, and/or and commitments regarding sustainability matters, sustainability, inclusion, responsible sourcing and social investments, sourcing, and other matters community impact in our annual Corporate Responsibility Report, on our website, in our filings with the SEC, SEC filings, and elsewhere. These initiatives, goals, or commitments could initiatives may be difficult to achieve and costly to implement. We could fail to achieve, or be perceived to fail to achieve, our corporate responsibility-related initiatives, goals, or commitments. In addition, we could be criticized for the their scope, nature, timing, scope or nature of these initiatives, goals, or commitments, or for any revisions to them. To the extent that our required them, and voluntary disclosures about corporate responsibility matters increase, we could be criticized for the accuracy, adequacy, accuracy or completeness of such our disclosures. Our actual or perceived failure to undertake these initiatives and achieve our corporate responsibility-related initiatives, these goals, or commitments the fact that we are undertaking these initiatives, could negatively impact our reputation, result in corporate responsibility-focused investors not purchasing and holding our stock, reputation or otherwise materially harm our business. In addition, we are or may become subject to various new new, proposed, and proposed evolving sustainability-related laws and regulations, including, for example, the E.U.’s Corporate Sustainability Reporting Directive. Additional regulation may require us to incur significant additional costs associated with increased compliance burdens, including the implementation of additional internal controls processes and procedures, and impose increased oversight obligations on our management and board of directors, as well as require us to retain third-party experts. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, fines fines, or litigation, which could negatively impact our business, operating results or financial condition.condition, and operating results.
Added · Removed · word-level comparison of the two filings
Failure to comply with governmental laws and regulations could harm our business.
rewrittenRegulatorySimplified language on governmental compliance harm; removed specific references to sanctions, litigation outcomes, and enforcement action consequences.
Our business is subject to regulation by various federal, state, local, and foreign governmental agencies, including agencies responsible for employment and labor laws, workplace safety, product safety, environmental laws, consumer protection laws, privacy, data security, and data protection laws, anti-bribery laws (including the U.S. Foreign Corrupt Practices Act and the U.K. Anti-Bribery Act), import/export controls, securities laws, and tax laws and regulations. These laws and regulations may also impact our ability to develop new technologies, including emerging technologies such as AI. In certain jurisdictions, regulatory requirements may be more stringent than in the United States. Noncompliance could subject us to investigations, sanctions, mandatory product recalls, enforcement actions, disgorgement of profits, fines, damages, civil and criminal penalties, litigation, or injunctions.
Responding to any action will likely result in significant diversion of management’s attention and resources. If any governmental sanctions are imposed, our business, financial condition, and operating results could be materially adversely affected.
Compare with the 2025 10-K
Prior heading: Failure to comply with governmental laws and regulations could harm our business.
Our business is subject to regulation by various federal, state, local, and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, product safety, environmental laws, consumer protection laws, privacy, data security, and data-protection data protection laws, anti-bribery laws (including the U.S. Foreign Corrupt Practices Act and the U.K. Anti-Bribery Act), import/export controls, federal securities laws, and tax laws and regulations. These laws and regulations may also impact our innovation and business drivers in developing ability to develop new and technologies, including emerging technologies (e.g., AI and machine learning). such as AI. In certain jurisdictions, these regulatory requirements may be more stringent than those in the United States. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, mandatory product recalls, enforcement actions, disgorgement of profits, fines, damages, civil and criminal penalties, litigation, or injunctions. If any governmental sanctions are imposed, or if we do not prevail in any possible civil or criminal litigation resulting from any alleged noncompliance, our business, operating results, and financial condition could be materially adversely affected. In addition, responding Responding to any action will likely result in a significant diversion of management’s attention and resources and an increase in professional fees. Enforcement actions, litigation, and resources. If any governmental sanctions could harm are imposed, our business, operating results, and financial condition.condition, and operating results could be materially adversely affected.
Added · Removed · word-level comparison of the two filings
Risks Related to Our Common Stock and Convertible Notes
The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline.
rewrittenOtherExpanded stock price volatility factors: added cyberattack reports, insurance coverage limitations, and clarified acquisition-related issuances; removed key personnel departures as standalone factor.
The market price of our common stock has historically been, and is likely to continue to be, volatile and could be subject to wide fluctuations in response to various factors, some of which are beyond our control and unrelated to our business, financial condition, or operating results. These fluctuations could cause a loss of all or part of an investment in our common stock. Factors that could cause fluctuations in the market price of our common stock include, but are not limited to:
•announcements by us or our competitors of new products, subscriptions, technologies, commercial relationships, strategic partnerships, acquisitions, or similar events;
•broader price and volume fluctuations in the stock market, and in particular the trading prices and volumes of technology companies and companies in our industry;
•fluctuations in the trading volume of our shares or the size of our public float, including sales or repurchases of large blocks of our common stock and future sales by our directors, executive officers, employees, or significant stockholders;
•issuances or sales of our common stock, or of debt or securities convertible into or exchangeable for our common stock, including in capital-raising transactions or as consideration in connection with acquisitions;
•actual or anticipated changes or fluctuations in our operating results, and whether our operating and/or financial results meet the expectations of securities analysts or investors;
•actual or anticipated changes in analyst or investor expectations, including as a result of our forward-looking statements or our failure to meet such expectations;
•inaccurate or unfavorable research reports about our business and industry, or reduced analyst coverage of our company;
•news or events affecting investor perception of our industry, including reports of significant cyberattacks;
•litigation involving us or our industry, and actions instituted by activist shareholders or others;
•regulatory developments in the United States or other jurisdictions;
•major catastrophic events and geopolitical or economic uncertainty around the world; or •departures of key personnel.
Securities class action litigation has often been brought against companies that experience periods of volatility in the market price of such company’s securities. Securities litigation could result in substantial costs, divert our management’s attention and resources from our business, and have a material adverse effect on our business, financial condition, and operating results. Our insurance may not cover all types of claims that may arise, and we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all.
Compare with the 2025 10-K
Prior heading: The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline.
The market price of our common stock has historically been, and is likely to continue to be, volatile and could be subject to wide fluctuations in response to various factors, some of which are beyond our control and unrelated to our business, operating results, or financial condition. condition, or operating results. These fluctuations could cause a loss of all or part of an investment in our common stock. Factors that could cause fluctuations in the market price of our common stock include, but are not limited to: •announcements by us or our competitors of new products, subscriptions or subscriptions, technologies, commercial relationships, strategic partnerships, acquisitions, or other events by us or our competitors; •price similar events; •broader price and volume fluctuations in the overall stock market from time to time; •news announcements that affect investor perception of our industry, including reports related to the discovery of significant cyberattacks; •significant volatility market, and in particular the market price and trading volume prices and volumes of technology companies in general and of companies in our industry; •fluctuations in the trading volume of our shares or the size of our public float; float, including sales or repurchases of large blocks of our common stock and future sales by our directors, executive officers, employees, or significant stockholders; •issuances or sales of our common stock, or of debt or securities convertible into or exchangeable for our common stock, including in capital-raising transactions or as consideration in connection with acquisitions; •actual or anticipated changes in our operating results or fluctuations in our operating results; •whether results, and whether our operating and/or financial results meet the expectations of securities analysts or investors; •actual or anticipated changes in the expectations of securities analysts analyst or investors, whether investor expectations, including as a result of our forward-looking statements, statements or our failure to meet such expectations or otherwise; expectations; •inaccurate or unfavorable research reports about our business and industry published by securities analysts industry, or reduced analyst coverage of our company by securities analysts; company; •news or events affecting investor perception of our industry, including reports of significant cyberattacks; •litigation involving us, us or our industry, or both; •actions and actions instituted by activist shareholders or others; •regulatory developments in the United States, foreign countries, States or both; other jurisdictions; •major catastrophic events; •sales or repurchases of large blocks of our common stock or substantial future sales by our directors, executive officers, employees, events and significant stockholders; •issuances or sales of shares of our common stock, including as part of a capital-raising transaction or as consideration in or in connection with acquisitions; •issuances or sales of debt or securities convertible into or exchangeable for shares of our common stock, including in connection with acquisitions; •departures of key personnel; or •geopolitical geopolitical or economic uncertainty around the world. In the past, following periods of volatility in the market price world; or •departures of a company’s securities, securities key personnel. Securities class action litigation has often been brought against companies that company. experience periods of volatility in the market price of such company’s securities. Securities litigation could result in substantial costs, divert our management’s attention and resources from our business, and have a material adverse effect on our business, financial condition, and operating results, results. Our insurance may not cover all types of claims that may arise, and financial condition.we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all.
Added · Removed · word-level comparison of the two filings
The issuance of additional common stock in connection with financings, acquisitions, investments, our stock incentive plans, convertible notes, or otherwise will dilute the stock held by all other stockholders.
unchangedOther
Our restated certificate of incorporation authorizes us to issue up to 2.0 billion shares of common stock and up to 100 million shares of preferred stock with such rights and preferences as may be determined by our board of directors. Subject to compliance with applicable rules and regulations, we may issue shares of common stock or securities convertible into or exchangeable for shares of our common stock from time to time in connection with a financing or other capital raising transaction, acquisitions, investments, our stock incentive plans, the settlement of our 2030 Notes, or otherwise. Any such issuance could result in substantial dilution to our existing stockholders and cause the market price of our common stock to decline.
We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock.
rewrittenOtherRemoved language about program suspension/termination risk and its potential effect on stock price; narrowed focus to repurchase completion uncertainty.
As of July 31, 2026, we had $1.0 billion available under our share repurchase program which will expire on December 31, 2026 and may be suspended or discontinued at any time without prior notice. Although our board of directors authorized the program, we are not obligated to repurchase any specific dollar amount or number of shares under the program. The share repurchase program could affect the price of our common stock, increase volatility, and diminish our cash reserves.
Compare with the 2025 10-K
Prior heading: We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock.
As of July 31, 2025, 2026, we had $1.0 billion available under our share repurchase program which will expire on December 31, 2025 2026 and may be suspended or discontinued at any time without prior notice. Although our board of directors has authorized a share repurchase the program, we are not obligated to repurchase any specific dollar amount or to acquire any specific number of shares under the program. The share repurchase program could affect the price of our common stock, increase volatility, and diminish our cash reserves. In addition, the program may be suspended or terminated at any time, which may result in a decrease in the price of our common stock.reserves.
Added · Removed · word-level comparison of the two filings
We do not intend to pay dividends for the foreseeable future.
unchanged
We have never declared or paid any dividends on our common stock. We intend to retain any earnings to finance the operation and expansion of our business, and we do not anticipate paying any cash dividends in the future. As a result, stockholders may only receive a return on their investments in our common stock if the market price of our common stock increases.
Our charter documents and Delaware law could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
unchanged
Provisions in our restated certificate of incorporation and amended and restated bylaws may have the effect of delaying or preventing a change in control of our company or changes in our management. Our restated certificate of incorporation and amended and restated bylaws include provisions that, among other things:
•establish that our board of directors is divided into three classes, Class I, Class II, and Class III, with three-year staggered terms;
•authorize our board of directors to issue shares of preferred stock and to determine the price and other terms of those shares, including preferences and voting rights, without stockholder approval;
•provide our board of directors with the exclusive right to elect a director to fill a vacancy created by the expansion of our board of directors or the resignation, death, or removal of a director;
•prohibit our stockholders from taking action by written consent;
•specify that special meetings of our stockholders may be called only by the chairman of our board of directors, our president, our secretary, or a majority vote of our board of directors;
•require the affirmative vote of holders of at least 66 2/3% of the voting power of all of the then outstanding shares of the voting stock, voting together as a single class, to amend the provisions of our restated certificate of incorporation relating to the issuance of preferred stock and management of our business or our amended and restated bylaws;
•authorize our board of directors to amend our bylaws by majority vote; and •establish advance notice procedures with which our stockholders must comply to nominate candidates to our board of directors or to propose matters to be acted upon at a stockholders’ meeting.
These provisions may frustrate or prevent any attempts by our stockholders to replace or remove our current management by making it more difficult for our stockholders to replace members of our board of directors, which is responsible for appointing the members of management. In addition, as a Delaware corporation, we are subject to Section 203 of the Delaware General Corporation Law. These provisions may prohibit large stockholders, in particular those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time. Any of these provisions could, under certain circumstances, depress the market price of our common stock.
We may not have the ability to raise the funds necessary to settle conversions of the 2030 Notes, repurchase the 2030 Notes upon a fundamental change, or repay the 2030 Notes in cash at their maturity, and our other debt may contain limitations on our ability to pay cash upon conversion or repurchase of the 2030 Notes.
addedCredit & liquidityAdded risk that company may lack funds to settle 2030 Notes conversions, repurchases upon fundamental change, or maturity repayment following CyberArk acquisition guarantee.
In connection with the consummation of the CyberArk acquisition, we entered into a supplemental indenture (the “Supplemental Indenture”) to the Indenture, dated as of June 10, 2025 (as supplemented by the Supplemental Indenture, the “Indenture”), governing the 2030 Notes, and in the Supplemental Indenture we agreed to guarantee the 2030 Notes.
Accordingly, we will need to make cash payments (a) if holders of the 2030 Notes require us to repurchase all, or a portion of, the 2030 Notes upon the occurrence of a fundamental change before the maturity date, (b) upon conversion of the 2030 Notes, or (c) to repay the 2030 Notes in cash at their maturity, unless earlier converted or repurchased.
If our cash provided by operating activities, together with our existing cash, cash equivalents, and investments, and existing sources of financing, are inadequate to satisfy these obligations, we will need to obtain third-party financing, which may not be available to us on commercially reasonable terms or at all, to meet these payment obligations.
In addition, our ability to repurchase or to pay cash upon conversion of the 2030 Notes may be limited by law, regulatory authority, or agreements governing our other indebtedness. Our failure to repurchase the 2030 Notes at a time when the repurchase is required by the Indenture, or to pay any cash amount due upon their maturity or conversion when required by the Indenture would constitute a default under the Indenture. A default under the Indenture could also lead to a default under agreements governing our other indebtedness. If the payment of the related indebtedness were to be accelerated after any applicable notice or grace periods, we may not have sufficient funds to satisfy all amounts due under our other indebtedness and the 2030 Notes.
The Capped Calls may affect the value of the 2030 Notes and our common stock.
addedCredit & liquidityAdded risk that Capped Calls assigned from CyberArk acquisition may affect 2030 Notes value and common stock through Dealer hedging and secondary market transactions.
In connection with the issuance of the 2030 Notes, CyberArk had previously entered into the Capped Calls, each with a financial institution (each, together with its affiliates, a “Dealer”). In connection with the CyberArk acquisition, we entered into substantially identical amended and restated letter agreements with respect to the Capped Calls, under which the Capped Calls were assigned to us and now reference our common stock. The Capped Calls are generally expected to reduce the potential dilution to our common stock upon conversion of the 2030 Notes and/or offset any potential cash payments we are required to make in excess of the principal amount of converted 2030 Notes, with such reduction and/or offset subject to a cap.
Any Dealer may modify or unwind its hedge positions by entering into or unwinding various derivatives with respect to our common stock and/or purchasing or selling our common stock or other securities of ours in secondary market transactions prior to the maturity of the 2030 Notes (and is likely to do so following any conversion of the 2030 Notes, any repurchase of the 2030 Notes by us on any fundamental change repurchase date, any redemption date, or any other date on which the 2030 Notes are retired by us, in each case, if we exercise the relevant election under the Capped Calls and in connection with any negotiated unwind or modification of the Capped Calls).
This activity could cause or prevent an increase or a decrease in the market price of our common stock or the 2030 Notes, which could affect a note holder’s ability to convert its 2030 Notes and, to the extent the activity occurs during any observation period related to a conversion of the 2030 Notes, it could affect the amount and value of the consideration that the note holder would receive upon conversion of the 2030 Notes.
We do not make any representation or prediction as to the direction or magnitude of any potential effect that the transactions described above may have on the price of the 2030 Notes or our common stock. In addition, we do not make any representation that any Dealer has engaged with or will engage in these transactions or that these transactions, if commenced, have not been or will not be discontinued without notice.
General Risk Factors
Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, climate change, and other catastrophic events, and to interruption by man-made problems, such as terrorism.
rewrittenClimate & physicalAdded climate-related events (drought, flooding, heat waves, wildfires, sea level rise) as specific risks; added data center climate risks and climate regulation/compliance costs.
Our corporate headquarters are located in the San Francisco Bay Area, a region known for seismic activity. In addition, climate-related events, including drought, flooding, heat waves, wildfires, increased storm severity, and sea level rise, may increase in frequency and intensity and could disrupt our business operations and damage our facilities. In addition, the data centers and cloud infrastructure we and our third-party providers use to deliver our products, subscriptions, and support offerings are subject to risks from extreme weather events and power disruptions associated with climate change. Other natural disasters, a significant power outage, telecommunications failure, terrorism, an armed conflict, cyberattacks, epidemics and pandemics, or other geopolitical unrest could affect our supply chain, manufacturers, logistics providers, channel partners, end-customers, or the economy as a whole, and such disruption could impact our shipments and sales.
We may be subject to increased regulations, reporting requirements, standards, or stakeholder expectations regarding climate change that may impact our business, increase compliance costs, and require additional investment in our operations and disclosures. These risks may be further increased if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above should result in delays or cancellations of customer orders, the loss of customers, or the delay in the manufacture, deployment, or shipment of our products, our business, financial condition, and operating results would be adversely affected.
Compare with the 2025 10-K
Prior heading: Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, and other catastrophic events, and to interruption by man-made problems, such as terrorism.
Both our Our corporate headquarters and the location where our products are manufactured are located in the San Francisco Bay Area, a region known for seismic activity. In addition, other climate-related events, including drought, flooding, heat waves, wildfires, increased storm severity, and sea level rise, may increase in frequency and intensity and could disrupt our business operations and damage our facilities. In addition, the data centers and cloud infrastructure we and our third-party providers use to deliver our products, subscriptions, and support offerings are subject to risks from extreme weather events and power disruptions associated with climate change. Other natural disasters, such as fire or floods, a significant power outage, telecommunications failure, terrorism, an armed conflict, cyberattacks, epidemics and pandemics such as COVID-19, pandemics, or other geopolitical unrest could affect our supply chain, manufacturers, logistics providers, channel partners, end-customers, or the economy as a whole, and such disruption could impact our shipments and sales. We may be subject to increased regulations, reporting requirements, standards, or stakeholder expectations regarding climate change that may impact our business, increase compliance costs, and require additional investment in our operations and disclosures. These risks may be further increased if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above should result in delays or cancellations of customer orders, the loss of customers, or the delay in the manufacture, deployment, or shipment of our products, our business, financial condition, and operating results would be adversely affected.
Added · Removed · word-level comparison of the two filings
Removed this year
Risk factors in the 2025 10-K with no counterpart in this one. Shown as they read last year.
removed Seasonality may cause fluctuations in our revenue.
Macro & demand · Removed risk disclosure about seasonal revenue fluctuations in Q2 and Q4 driven by customer budget cycles and sales compensation structures.
Last year’s text
We believe there are significant seasonal factors that may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal quarters. We believe that this seasonality results from a number of factors, including: •end-customers with a December 31 fiscal year-end choosing to spend remaining unused portions of their discretionary budgets before their fiscal year-end, which potentially results in a positive impact on our revenue in our second fiscal quarter; •our sales compensation plans, which are typically structured around annual quotas and commission rate accelerators, which potentially results in a positive impact on our revenue in our fourth fiscal quarter; and •the timing of end-customer budget planning at the beginning of the calendar year, which can result in a delay in spending at the beginning of the calendar year, potentially resulting in a negative impact on our revenue in our third fiscal quarter. As we continue to grow, seasonal or cyclical variations in our operations may become more pronounced, and our business, operating results, and financial position may be adversely affected.
removed If we are unable to attract new customers, our future results of operations could be harmed.
Competition · Removed risk that company may fail to attract new customers due to switching costs, deployment resource requirements, and economic conditions affecting customer spending.
Last year’s text
To increase our revenue and maintain profitability, we must add new customers. To do so, we must successfully convince prospective customers of the value of adopting our solutions. We are engaging in costly marketing and sales efforts to accelerate our strategies, including platformization, and attract new customers, which may fail or may not be as successful as intended or at all. Additionally, prospective customers’ decisions to purchase our solutions depend on a variety of factors, many of which are out of our control. These factors significantly impact our ability to add new customers and increase the time, resources and sophistication required to do so. For example, prospective customers may face real or perceived switching costs when switching to our solutions from legacy security vendors and products. Deployment of our solutions may require a significant commitment of resources from our customers. Any deterioration in general economic conditions, including as a result of the geopolitical environment or inflation (as well as government policies such as raising interest rates in response to inflation), have in the past caused, and may in the future cause, our current and prospective customers to delay or cut their overall security and IT operations spending. If our efforts to attract new customers are not successful, our sales may not grow as quickly as anticipated, or at all, and our business, operating results, and financial condition will be harmed.
removed We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
Other · Removed risk that CyberArk acquisition may not complete due to regulatory approvals, shareholder votes, HSR Act compliance, or governmental restraints.
Last year’s text
The completion of the acquisition of CyberArk is subject to a number of conditions, including, among others: •the effectiveness of a registration statement on Form S-4 to be filed by us registering the shares of our common stock to be issued to CyberArk shareholders as consideration in the acquisition and the absence of any stop order or proceedings seeking a stop order; •the approval for listing on Nasdaq of our shares of common stock to be issued in connection with the proposed acquisition; •obtaining the requisite CyberArk shareholder approval in connection with the proposed acquisition; •the expiration or termination of any waiting period (or extensions thereof) applicable to the acquisition under the Hart-Scott-Rodino Antitrust Improvements Act of 1976, as amended (the “HSR Act”) and the making, approval, expiration, termination or receipt of, as applicable, all applicable filings, registrations, waiting periods (or extensions of waiting periods) and approvals under specified antitrust and foreign investment laws; and •the absence of governmental restraints or prohibitions preventing the consummation of the proposed acquisition. No assurance can be given that the required CyberArk shareholder approval and governmental and regulatory consents and approvals will be obtained or that any of the required conditions to closing will be satisfied in a timely manner or at all. As a result, although it is currently anticipated that we will complete the acquisition of CyberArk during the second half of our fiscal 2026, the possible timing and likelihood of completion are uncertain. There can be no assurance that the acquisition of CyberArk will be completed in the anticipated timeframe or at all. Any delay in completing the proposed acquisition could cause the combined company not to realize, or to be delayed in realizing, some or all of the benefits and synergies that we anticipate to achieve if the proposed acquisition were to be successfully completed within its expected time frame. In addition, the relevant governmental authorities from which approvals under specified antitrust and foreign investment laws must be obtained may impose or seek to impose conditions on the completion of the acquisition or require changes to the terms of the proposed acquisition or agreements to be entered into in connection with the CyberArk acquisition. Such conditions or changes and the process of obtaining these approvals, could have the effect of delaying or impeding completion of the CyberArk acquisition or imposing additional costs or limitations on us following the acquisition, which may have an adverse effect on our business, results of operations, and financial condition. The failure or inability to satisfy all of the required conditions could delay the completion of the acquisition for a significant period of time or prevent it from occurring at all. In addition, under limited circumstances, we or CyberArk may elect to terminate the definitive agreement or we and CyberArk may mutually decide to terminate the definitive agreement, before or after obtaining the requisite CyberArk shareholder approval. A termination of the definitive agreement could materially and adversely affect our business, results of operations and reputation. If the acquisition of CyberArk is delayed or not completed, we could be subject to a number of risks that may adversely affect our business, operating results and financial condition, including, among other things: •we may experience negative reactions from the financial markets, including negative impacts on the market price of our common stock; •we could incur significant acquisition costs that we would be unable to recoup; •under specified circumstances in connection with the termination of the definitive agreement, we would be required to pay CyberArk a termination fee of $1.0 billion; •negative perception from industry contacts, business partners, and other third parties, which could impact our operations or our ability to compete for new business or obtain renewals in the marketplace more broadly; and •reputational harm, negative publicity, negative reactions from employees, and other negative impacts resulting from delay or failure to complete the acquisition of CyberArk.
removed Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.
Supply chain · Removed risk that inadequate inventory management and supply chain visibility for hardware products could cause excess inventory, margin pressure, or lost sales from shortages.
Last year’s text
Our manufacturing partners procure components and build our hardware products based on our forecasts, and we generally do not hold inventory for a prolonged period of time. These forecasts are based on historical trends and analysis, adjusted for overall market conditions. In order to reduce manufacturing lead times and plan for adequate component supply, from time to time we may issue forecasts for components and products that are non-cancelable and non-returnable. Our inventory management systems and related supply chain visibility tools may be inadequate to enable us to forecast accurately and effectively manage supply of our hardware products and product components. If we ultimately determine that we have excess supply, we may have to reduce our prices and write down inventory, which in turn could result in lower gross margins. If our actual component usage and product demand are lower than the forecast we provide to our manufacturing partners, we accrue for losses on manufacturing commitments in excess of forecasted demand. Alternatively, insufficient supply levels may lead to shortages that result in delayed hardware product revenue or loss of sales opportunities altogether as potential end-customers turn to competitors’ products that are readily available. If we are unable to effectively manage our supply and inventory, our operating results could be adversely affected.
removed Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
Supply chain · Removed risk disclosure on hardware component supply concentration in Asia, sole-source suppliers, and China-Taiwan tensions impact.
Last year’s text
Our hardware products rely on key components, including integrated circuit components, which our manufacturing partners purchase on our behalf from a limited number of component suppliers, including sole source providers. The manufacturing operations of some of our component suppliers are geographically concentrated in Asia and elsewhere, which makes our supply chain vulnerable to regional disruptions, such as natural disasters, fire, political instability, civil unrest, power outages, or health risks, and international regulations, such as tariffs, sanctions and import and export controls. In the past, we experienced supply chain disruption and have incurred increased costs resulting from inflationary pressures and changes in U.S. trade policy. We are also monitoring the tensions between China and Taiwan, and between the U.S. and China, which could have an adverse impact on our business or results of operations in future periods. Further, we do not have volume purchase contracts with any of our component suppliers, and they could cease selling to us at any time. If we are unable to obtain a sufficient quantity of these components in a timely manner for any reason, sales of our hardware products could be delayed or halted, or we could be forced to expedite shipment of such components or our hardware products at dramatically increased costs. Our component suppliers also change their selling prices frequently in response to market trends, including industry-wide increases in demand. Because we do not have, for the most part, volume purchase contracts with our component suppliers, we are susceptible to price fluctuations related to raw materials and components and may not be able to adjust our prices accordingly. Additionally, poor quality in any of the sole-sourced components in our products could result in lost sales or sales opportunities. If we are unable to obtain a sufficient volume of the necessary components for our hardware products on commercially reasonable terms or the quality of the components do not meet our requirements, we could also be forced to redesign our products and qualify new components from alternate component suppliers. The resulting stoppage or delay in selling our hardware products and the expense of redesigning our hardware products would result in lost sales opportunities and damage to customer relationships, which would adversely affect our business and operating results.
removed We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
Tariffs & trade · Removed risk on U.S. export controls for encryption products, sanctions compliance, and international import restrictions on encryption technology.
Last year’s text
Because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the United States only with the required export license or through an export license exception. If we were to fail to comply with U.S. export licensing requirements, U.S. customs regulations, U.S. economic sanctions, or other laws or regulations, we could be subject to substantial civil and criminal penalties, including fines, incarceration for responsible employees and managers, and the possible loss of export or import privileges. Obtaining the necessary export license for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities. Furthermore, U.S. export control laws and economic sanctions prohibit the shipment of certain products to U.S. embargoed or sanctioned countries, governments, and persons. Even though we take precautions to ensure that our channel partners comply with all relevant regulations, any failure by our channel partners to comply with such regulations could have negative consequences for us, including reputational harm, government investigations, and penalties. In addition, various countries regulate the import of certain encryption technology, including through import permit and license requirements, and have enacted laws that could limit our ability to distribute our products or could limit our end-customers’ ability to implement our products in those countries. Changes in our products or changes in export and import regulations may create delays in the introduction of our products into international markets, prevent our end-customers with international operations from deploying our products globally or, in some cases, prevent or delay the export or import of our products to certain countries, governments, or persons altogether. Any change in export or import regulations, economic sanctions, such as the Sanctions on Russia, or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons, or technologies targeted by such regulations could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential end-customers with international operations. Any decreased use of our products or limitation on our ability to export to or sell our products in international markets would likely adversely affect our business, financial condition, and operating results. International trade laws and regulations continuously evolve to address technological developments and changes in geopolitical conditions. New regulations or other governmental restrictions that may result from these circumstances could inhibit our ability to transact with foreign suppliers, customers, or other business partners. Monitoring and responding to these developments may require significant resources, and failure to comply with resulting regulations and restrictions may have an adverse impact on our business or results of operation.
removed The warrant transactions may affect the value of our common stock.
Other · Removed risk on 2025 Convertible Notes warrant dilution and counterparty hedging activity affecting common stock price, as notes matured June 2025.
Last year’s text
In June 2020, we issued our 0.375% Convertible Senior Notes due 2025 (the “2025 Notes”), which matured on June 1, 2025. In connection with the sale of our 2025 Notes, we entered into convertible note hedge transactions (the “2025 Note Hedges”) with certain counterparties. In connection with the sale of the 2025 Notes and purchase of the 2025 Note Hedges, we also entered into warrant transactions with the counterparties pursuant to which we sold warrants (the “2025 Warrants”) for the purchase of our common stock. The 2025 Warrants could have a dilutive effect to the extent that the market price per share of our common stock exceeds the applicable strike price of the 2025 Warrants unless, subject to certain conditions, we elect to cash settle such 2025 Warrants. The applicable counterparties to the 2025 Warrants or their respective affiliates may modify their related hedge positions by entering into or unwinding various derivatives with respect to our common stock and/or purchasing or selling our common stock or other securities of ours in secondary market transactions prior to the expiration of the 2025 Warrants. This activity could cause or prevent an increase or a decrease in the market price of our common stock. We do not make any representation or prediction as to the direction or magnitude of any potential effect that the transactions described above may have on the price of our common stock. In addition, we do not make any representation that the counterparties or their respective affiliates will engage in these transactions or that these transactions, once commenced, will not be discontinued without notice.
removed Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.
Credit & liquidity · Removed risk on need for additional capital through equity or debt financing to fund growth, product development, and acquisitions.
Last year’s text
We intend to continue to make investments to support our business growth and may require additional funds to respond to business challenges, including the need to develop new features to enhance our portfolio, improve our operating infrastructure, or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds. If we engage in future debt financings, the holders of such additional debt would have priority over the holders of our common stock. Current and future indebtedness may also contain terms that, among other things, restrict our ability to incur additional indebtedness. In addition, we may be required to take other actions that would otherwise be in the interests of the debt holders and would require us to maintain specified liquidity or other ratios, any of which could harm our business, operating results, and financial condition. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.
Mentions · how they’re counted
| Category | Underlined | Word counter | Model’s count |
|---|---|---|---|
| AI AI, artificial intelligence, generative AI, machine learning, large language model, LLM | 58 | 60 | 12 |
| Layoffs layoffs, RIF, headcount reduction, workforce optimization, restructuring | 1 | — | 0 |
| Recession recession, downturn, contraction, slowdown | 1 | 1 | 4 |
| Tariffs tariff, trade war, trade barriers, trade restrictions, trade policy | 9 | 9 | 2 |
| Buybacks share repurchase, buyback program | 4 | — | 0 |
Underlines use the same word lists the scores use. AI, recession and tariffs follow Palanor’s word counter, so those counts match it exactly on the same text. Layoffs and buybacks use the terms the model was given. The model’s count is an estimate by meaning, not by string, so it can differ from the underlines. This view is built from the parsed risk factors, so it can differ slightly from the section text the counts were taken on.
Source: SEC EDGAR · public domain · Highlights by Palanor