Fortinet 10-K 2017-12-31
Filed 2018-02-26. 19 sections, 455K characters. Original on sec.gov · Markdown · JSON
Cover and table of contents
10-K 1 ftnt-201710xk.htm FORM 10-K
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
(Mark One)
| x | ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the fiscal year ended December 31, 2017
or
| o | TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the transition period from to
Commission file number: 001-34511
FORTINET, INC.
(Exact name of registrant as specified in its charter)
| Delaware | 77-0560389 |
| (State or other jurisdiction of incorporation or organization) | (I.R.S. Employer Identification No.) |
| 899 Kifer Road Sunnyvale, California | 94086 |
| (Address of principal executive offices) | (Zip Code) |
(408) 235-7700
(Registrant’s telephone number, including area code)
Securities registered pursuant to Section 12(b) of the Act:
| Common Stock, $0.001 Par Value | The Nasdaq Stock Market LLC | |
| (Title of each class) | (Name of exchange on which registered) |
Securities registered pursuant to Section 12(g) of the Act: None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes x No o
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes o No x
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 (“Exchange Act”) during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes x No o
Indicate by check mark whether the registrant has submitted electronically and posted on its corporate Website, if any, every Interactive Data File required to be submitted and posted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit and post such files). Yes x No o
Indicate by check mark if disclosure of delinquent filers pursuant to Item 405 of Regulation S-K (§229.405 of this chapter) is not contained herein, and will not be contained, to the best of the registrant’s knowledge, in definitive proxy or information statements incorporated by reference in Part III of this Form 10-K or any amendment to this Form 10-K. x
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
| Large accelerated filer | x | Accelerated filer | o | ||
| Non-accelerated filer | o | (Do not check if smaller reporting company) | Smaller reporting company | o | |
| Emerging growth company | o |
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. o
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes o No x
The aggregate market value of voting stock held by non-affiliates of the registrant, as of June 30, 2017, the last business day of the registrant’s most recently completed second quarter, was $4,597,906,585 (based on the closing price for shares of the registrant’s common stock as reported by The Nasdaq Global Select Market on that date). Shares of common stock held by each executive officer, director, and holder of 5% or more of the registrant’s outstanding common stock have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.
As of February 16, 2018, there were 168,024,163 shares of the registrant’s common stock outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the registrant’s definitive Proxy Statement relating to its 2018 Annual Meeting of Stockholders are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated. Such Proxy Statement will be filed with the United States Securities and Exchange Commission within 120 days after the end of the fiscal year to which this report relates.
FORTINET, INC.
ANNUAL REPORT ON FORM 10-K
For the Year Ended December 31, 2017
Table of Contents
Part I
Item 1. Business
Overview
Fortinet is a global leader in broad, automated and integrated cybersecurity solutions. We provide high performance cybersecurity solutions to a wide variety of businesses, such as carriers, data centers, enterprises and distributed offices, including a majority of the Fortune 100 companies. Our cybersecurity solutions are designed to provide broad, automated and integrated protection against dynamic and sophisticated security threats, while simplifying the information technology (“IT”) and security infrastructure of our end-customers.
We have four current focus areas for our business.
| • | Core Business (FortiGate)—We derive a majority of product sales from our FortiGate appliances. Our FortiGate appliances include the FortiGate-20 to -100 series, designed for small businesses and enterprises with distributed offices (“low-end products”), the FortiGate-200 to -900 series for medium-sized businesses (“mid-range products”) and the FortiGate-1000 to -7000 series for large businesses and service providers (“high-end products”). In February 2018, we launched the new FortiGate 6000 series, which is built upon a new hardware process and architecture that delivers over 100 gigabytes of advanced threat protection and secure sockets layer (“SSL”) inspection to handle the volume of traffic driven by increased adoption of the cloud. |
Our FortiOS operating system provides the foundation for all FortiGate security functions and offers end-customers the ability to manage security capabilities across their cloud assets and software-defined wireless area networks. Our network security platform also includes our FortiGuard security subscription services, which end-customers can subscribe to in order to obtain access to updates to application control, anti-virus, intrusion prevention, web filtering and anti-spam functionality. End-customers may also purchase FortiCare technical support services for our products and FortiCare professional services to assist in the design, implementation and maintenance of their networks. We complement our core FortiGate product line with other products and software that offer additional protection from security threats to other critical areas of the business.
| • | Fortinet Security Fabric—We developed the Fortinet Security Fabric to provide unified security across the entire digital attack surface, including network core, endpoints, applications, data centers, access and private and public cloud. The Fortinet Security Fabric is designed to enable traditionally disparate security devices to work together as an integrated and collaborative whole. It delivers integrated scalability, access control, awareness, security, traffic segmentation, centralized management, visibility and orchestration. The breadth of the Fortinet Security Fabric helps businesses and government agencies defend the expanding attack surface. |
At the core of the Fortinet Security Fabric are our FortiGate hardware products and software, which include a broad set of security services, including firewall, virtual private network, anti-malware, anti-spam, application control, intrusion prevention, access control, web filtering, traffic and device segmentation and advanced threat protection (“ATP”). Through these security services, our FortiGuard Labs team provides updates using threat research and a global cloud network of data collection and intelligence resources to deliver subscription-based security services to FortiGate appliances and software products.
We continue to expand the adoption of the Fortinet Security Fabric to third-party solution providers. In 2017, we welcomed 18 new partners to our Fabric-Ready partner program, including Intel, Amazon Web Services and Microsoft. Our Fabric-ready program consisted of 37 ecosystem partners as of February 3, 2018. Billings for non-FortiGate products and services increased in 2017.
| • | Fortinet Cloud Security—Our technology positions us to deliver security to the cloud and for the cloud. We help our customers secure their cloud implementations by offering integration, visibility and automation across multi-cloud and hybrid deployments. We have a variety of software products designed to extend traditional network security protection into the cloud as standalone solutions, or as part of our distributed Security Fabric architecture. Our FortiCASB extends the core capabilities of our security fabric architecture to provide businesses the same level of cybersecurity and threat intelligence in cloud environments as they do on their physical networks. The Fortinet cloud security is available across all major cloud providers, including Microsoft Azure, Amazon Web Services, Google Cloud, IBM Cloud and Oracle Cloud. |
| • | Internet of Things (“IoT”) and Operational Technology Security (“OT”)—The emergence of the IoT has created an environment where data moves freely between devices across locations, network environments, remote offices, mobile workers and public cloud environments, making it difficult to consistently track and secure. We are continuing to extend broad security to these IoT and OT environments. Our products enable critical infrastructure and industrial organizations to deliver advanced segmentation, access control and malware protection needed to unify their security architecture and defend their OT networks regardless of the operating environment. |
During our year ended December 31, 2017, we generated total revenue of $1.49 billion and net income of $31.4 million. See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, 2017 and 2016 and our consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years ended December 31, 2017, 2016 and 2015.
We were incorporated in Delaware in November 2000. Our principal executive office is located at 899 Kifer Road,
Sunnyvale, California 94086 and our telephone number at that location is (408) 235-7700.
Technology and Architecture
Our proprietary SPU hardware architecture, FortiOS operating system and associated security and networking functions combine to form the Fortinet Security Fabric. This approach to security ties together discrete security solutions into an integrated whole, which enables our products to perform security processing for networks with high throughput requirements across a broad threat landscape.
SPU
Our proprietary SPU consists of Application-Specific Integrated Circuits (“ASICs”) consisting of three main lines of processors: (i) the Content Processor (“SPU CP”), (ii) the Network Processor (“SPU NP”) and (iii) the System-on-a-Chip (“SPU SOC”). Our proprietary ASICs are designed to enhance the security processing capabilities implemented in software by accelerating computationally intensive tasks such as firewall policy enforcement, network address translation, IPS threat detection and encryption. This architecture provides the flexibility of implementing accelerated processing of new threat detection without requiring a new ASIC. The SPU CP is currently included in most of our entry-level and all of our mid-range and high-end FortiGate appliances. The SPU NP is currently included in some of our mid-range and high-end FortiGate appliances, delivering additional accelerated firewall and VPN performance. Entry-level FortiGate products often use the SPU SOC2 or SPU SOC3 to provide the necessary acceleration at this level. Mid-range FortiGate products use a central processing unit (“CPU”) and include the SPU NP and SPU CP hardware acceleration. The high-end FortiGate products use multiple CPUs, SPU CPs and SPU NPs.
FortiOS
Our proprietary FortiOS operating system provides the foundation for the operation of all FortiGate appliances, whether physical, virtual, private or public cloud or on-demand based, and is at the heart of our Security Fabric implementation. The core kernel functions to the security processing feature sets work together to provide a highly integrated solution. FortiOS provides (i) multiple layers of security, including a hardened kernel layer providing protection for the FortiGate system, (ii) a network security layer providing security for end-customers’ network infrastructures and (iii) application content protection providing security for end-customers’ workstations and applications. FortiOS directs the operations of processors and SPUs and provides system management functions such as command-line, graphical user interfaces, multiple network and security topology views.
Key high-level functions and capabilities of FortiOS include:
| • | key enablement for the Fortinet Security Fabric architecture; |
| • | allowing for FortiGate appliances to be configured into different security environments such as our Internal Network Firewall, NGFW and DCFW; |
| • | configuration of the physical aspects of the appliance such as ports, onboard Wi-Fi and switching; |
| • | extending the Fortinet Security Fabric by directly managing FortiSwitch and FortiAP devices; |
| • | key network functions such as routing and deployment modes (network routing, transparent, sniffer, etc.); |
| • | implementation of security updates from our FortiGuard distribution network, delivering ATP, such as IPS, antivirus and application control; |
| • | access to cloud-based web and email filtering databases; |
| • | direct integration with both cloud and on premises FortiSandbox technology; |
| • | security policy objects and enforcement; |
| • | data leak prevention and document finger printing; and |
| • | real-time reporting and logging. |
FortiOS also enables advanced, integrated routing and switching, allowing end-customers to deploy FortiGate devices within a wide variety of networks, as well as providing a direct replacement solution option for legacy switching and routing equipment. FortiOS implements a suite of commonly used standards-based routing protocols as well as network address translation technologies, allowing the FortiGate appliance to integrate and operate in a wide variety of network environments. Additional features include virtual domain capabilities, which can provide support for multiple customers on a single device or FortiOS instance. FortiOS also provides capabilities for logging of traffic for forensic analysis purposes that are particularly important for regulatory compliance initiatives like payment card industry data security standard. FortiOS is designed to help control network traffic in order to optimize performance by including functionality such as packet classification, queue disciplines, policy enforcement, congestion management, WAN optimization and caching. These features enable administrators to set the appropriate configurations and policies that meet their infrastructure needs. We make updates to FortiOS available through our FortiCare technical support services.
Products
Our core product offerings consist of our FortiGate product family, along with our non-FortiGate products, all of which may be purchased to complement commercial and enterprise deployments. Our FortiGate hardware and software licenses are sold with a set of broad security services. These security services are enabled by FortiGuard which provides extensive threat research and artificial intelligence capabilities from a global cloud network to deliver protection services to each FortiGate appliance. Our non-FortiGate products include the Fortinet Security Fabric (such as FortiSandbox, FortiSIEM and FortiManager), cloud security products (such as Fabric virtual machines and cloud services) and other products.
FortiGate
Our flagship FortiGate hardware appliances and software offer a broad set of security and networking functions, including firewall, intrusion prevention, anti-malware, VPN, application control, web filtering, anti-spam and WAN acceleration. All FortiGate models run on our FortiOS operating system. FortiGate platforms can be centrally managed through both embedded web-based and command line interfaces, as well as through FortiManager, which provides central management architecture for thousands of FortiGate hardware appliance and software licenses across a range of hypervisor platforms.
By combining multiple network security functions in our purpose-built security platform, the FortiGate appliances provide broad, high-quality protection capabilities and deployment flexibility while reducing the operational burden and costs associated with managing multiple point products. With over 30 models in the FortiGate product line, FortiGate is designed to address security requirements for small- to medium-sized businesses, large enterprises and government organizations worldwide.
Typically, all FortiGate hardware appliances include our SPUs to accelerate content and network security features implemented within FortiOS. The significant differences between each model are the performance and scalability targets each model is designed to meet, while the security features and associated services offered are common throughout all models. The FortiGate-20 through -100 series models are designed for perimeter protection for small- to medium-sized businesses and enterprises with distributed offices. The FortiGate-200 through -900 series models are designed for perimeter deployment in medium-sized to large enterprise networks. The FortiGate-1000 through -7000 series models deliver high performance and scalable network security functionality for perimeter, data center and core deployment in large enterprises.
We also incorporate additional technologies within FortiGate appliances that differentiate our solutions, including data leakage protection, traffic optimization, secure socket layer inspection, threat vulnerability management and wireless controller technology. In addition to these in-built features, we offer a full range of wireless access points and controllers, complementing FortiGate with the flexibility of wireless local area network access.
FortiSandbox
The FortiSandbox technology delivers proactive detection and mitigation with the capability to generate a directly actionable protection capability. Available in both hardware and cloud-based form, the FortiSandbox technology has a dual-layer sandbox complemented by FortiGuard’s anti-malware intelligence. FortiSandbox allows suspicious code to be subject to a set of multi-layer protection techniques culminating in execution within an operating system to allow detailed real-time behavioral analysis to be performed. When malicious code is identified in this way, a signature can be generated locally for distribution across the Fortinet Security Fabric. Additional insight on the nature of the threat is provided through an intuitive dashboard showing threat information, including system activity, exploit efforts, web traffic and any related subsequent downloads. In addition to integrating within FortiOS, the FortiSandbox can also deliver its detection and local threat intelligence to registered FortiMail, FortiWeb appliances and FortiClient enabled end points.
FortiSIEM
Our FortiSIEM family of products provides a cloud-ready security information and event management (“SIEM”) solution for enterprises and service providers. FortiSIEM unifies analytics that are traditionally monitored discretely, parses the information and then processes it in an event-based analytics engine for handling real-time searches, rules, dashboards and ad-hoc queries. This unification of diverse sources of data enables organizations to create comprehensive dashboards and reports to identify root causes of threats, and take the steps necessary to remediate and prevent them in the future. Our FortiSIEM products are available either through subscription or perpetual licenses.
FortiSwitch
Our FortiSwitch product family provides secure switching solutions. It can be deployed in traditional network switching designs with layer 2 and layer 3 access control features. FortiSwitch is part of Fortinet’s Security Fabric solution. FortiSwitch within Fortinet Security Fabric creates a scalable and secure access layer on which customers depend for connecting their end devices, such as computers and laptops, as well as an expanding field of IoT devices.
Fortinet Management and Analysis Products
Our FortiManager and FortiAnalyzer hardware and software products are typically sold in conjunction with most commercial and enterprise deployments.
FortiManager. Our FortiManager family of products provides a central and scalable management solution for our FortiGate products, including software updates, configuration, policy settings and security updates. One FortiManager product is capable of managing thousands of FortiGate units. FortiManager facilitates the coordination of policy-based provisioning, device configuration and operating system revision management, as well as network security monitoring and device control.
FortiAnalyzer. Our FortiAnalyzer family of products provides centralized network logging, analyzing and reporting solutions that securely aggregate content and log data from our FortiGate devices and other Fortinet products as well as third-party devices to enable network logging, analysis and reporting.
Services
FortiGuard Security Subscription Services
Security requirements are dynamic due to the constantly changing nature of threats. Our FortiGuard security subscription services are designed to allow us to quickly deliver new threat detection and prevention capabilities to end-customers worldwide as new threats evolve. Our FortiGuard Labs global threat research team identifies emerging threats, collects threat samples, and replicates, reviews, characterizes and collates attack data. Based on this research, we develop updates for virus signatures, attack definitions, scanning engines and other security solution components to distribute to end-customers. End-customers purchase FortiGuard security subscription services in advance, typically with terms of one or more years, to obtain access to regular updates for application control, antivirus, intrusion prevention, web filtering and anti-spam functions for our FortiGate products; antivirus, web filtering and VPN functions for our FortiClient software; antivirus and anti-spam functions for our FortiMail products; vulnerability management for our FortiGate, FortiAnalyzer and FortiMonitor products; database functions for our FortiDB appliance; web functions for our FortiWeb appliances; and ATP for our FortiSandbox on premise and cloud products. We provide FortiGuard security subscription services 24 hours a day, seven days a week.
FortiCare Technical Support Services
Our FortiCare services portfolio includes technical support and extended product warranty. For our standard technical support, our channel partners may provide first-level support to the end-customer. We also provide first-level support to our end-customers, as well as second- and third-level support as appropriate. We also provide knowledge management tools and customer self-help portals to help augment our support capabilities in an efficient and scalable manner. We deliver technical support to partners and end-customers 24 hours a day, seven days a week through regional technical support centers located worldwide. In addition to our appliance technical support services, we offer a range of advanced services, including premium support and professional services.
Professional Services
We offer professional services to end-customers including Technical Account Managers (“TAMs”), Resident Engineers (“REs”) and professional service consultants for implementations.
Dedicated support engineers are available to help identify and eliminate issues before problems arise. These TAMs and REs are seasoned professionals with broad and deep experience in the security and networking field. Each TAM and RE acts as a single point of contact and customer advocate within Fortinet, and is focused on building and maintaining a deep understanding of our customers’ businesses and security requirements.
Our professional services consultants help in the design of deployments of our products and work closely with end-customer engineers, managers and other project team members to implement our products according to design, utilizing network analysis tools, traffic simulation software and scripts.
Training Services
We offer training services to our end-customers and channel partners through our training department and authorized training partners. We have also implemented a training certification program, Network Security Expert, to help ensure an understanding of our products and services.
Customers
We typically sell our security solutions to channel partners, who in turn sell to end-customers of various sizes and, at times, we also sell directly to end-customers. Our end-customers include small and medium-sized businesses, large enterprises and government organizations across a wide range of industries, including telecommunications, technology, government, financial services, education, retail, manufacturing and healthcare. An end-customer deployment may involve one of our appliances or thousands, depending on our end-customer’s size and security requirements. We also offer access to our products via the cloud through certain cloud providers such as Amazon Web Services and Microsoft Azure. Many of our customers also purchase our FortiGuard security subscription services and FortiCare technical support services. For information regarding our geographic revenue based on billing address, see Note 14 to our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.
One distributor, Exclusive Networks Group (“Exclusive”), which distributed our solutions to a large group of resellers and end-customers, accounted for 18%, 20% and 25% of total revenue during 2015, 2016 and 2017, respectively. In July 2017, Exclusive acquired the U.S. division of Fine Tec Computers (“Fine Tec U.S.”). Fine Tec U.S.’s revenue has been combined with Exclusive’s from the date of acquisition. Since the acquisition of Fine Tec U.S., Exclusive’s business with us has increased and may continue to increase in the future.
Sales and Marketing
We primarily sell our products and services through a distribution model. We sell to distributors that sell to networking security and enterprise-focused resellers and service providers, who, in turn, sell to our end-customers. In certain cases, we sell directly to government-focused resellers, as well as to large service providers and financial institutions who have large purchasing power and unique customer deployment demands. We work with many technology distributors, including Exclusive, Ingram Micro Inc., Westcon and Tech Data.
We support our channel partners with a dedicated team of experienced channel account managers, sales professionals and sales engineers who provide business planning, joint marketing strategy, and pre-sales and operational sales support. Additionally, our sales teams help drive and support large enterprise and service provider sales through a direct touch model. Our sales professionals and engineers typically work closely with our channel partners and directly engage with large end-customers to address their unique security and deployment requirements. To support our broadly dispersed global channel and end-customer base, we have sales professionals in over 80 countries around the world.
Our marketing strategy is focused on building our brand and driving end-customer demand for our security solutions. We use a combination of internal marketing professionals and a network of regional and global channel partners. Our internal marketing organization is responsible for messaging, branding, demand generation, product marketing, channel marketing, event marketing, digital marketing, communications, analyst relations, public relations and sales enablement. We focus our resources on campaigns, programs and activities that can be leveraged by partners worldwide to extend our marketing reach, such as sales tools and collateral, product awards and technical certifications, media engagement, training, regional seminars and conferences, webinars and various other demand-generation activities.
In 2017, we continued to invest in sales and marketing, particularly in the enterprise market where enterprise customers tend to have a higher lifetime value. We intend to continue to make investments in our sales resources and infrastructure and marketing strategy, which are critical to support our growth.
Manufacturing and Suppliers
We outsource the manufacturing of our security appliance products to a variety of contract manufacturers and original design manufacturers. Our current manufacturing partners include Micro-Star International Co., Wistron Corporation, Flextronics International Ltd, Senao Networks, Inc., Adlink Technology, Inc. and a number of manufacturers located in Taiwan and other countries outside the United States. We submit purchase orders to our contract manufacturers that describe the type and quantities of our products to be manufactured, the delivery date and other delivery terms. Once our products are manufactured, they are sent to either our warehouse in California, or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed. We believe that outsourcing our manufacturing and a substantial portion of our logistics enables us to focus resources on our core competencies. Our proprietary SPUs, which are the key to the performance of our appliances, are built by contract manufacturers including Faraday Technology Corporation (“Faraday”), Kawasaki Microelectronics America, Inc. and Renesas Electronics Corporation (“Renesas”). These contract manufacturers use foundries operated by either United Microelectronics Corporation (“UMC”) or Taiwan Semiconductor Manufacturing Company Limited (“TSMC”), or their own foundry, such as Renesas’ fab.
The components included in our products are sourced from various suppliers by us or more frequently by our contract manufacturers. Some of the components important to our business, including specific types of CPUs from Intel Corporation (“Intel”), network chips from Broadcom Corporation (“Broadcom”), Marvell Technology Group Ltd. (“Marvell”) and Intel, and solid-state drives (silicon-based storage devices) from Intel, ADATA Technology Co., Ltd. (“ADATA”), OCZ Technology Group, Inc. (“OCZ”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from a limited or sole source of supply.
We have no long-term contracts related to the manufacturing of our ASICs or other components that guarantee any capacity or pricing terms.
Research and Development
We focus our research and development efforts on developing new products and services, and adding new features to existing products and services. Our development strategy is to identify features, products and systems for both software and hardware that are, or are expected to be, important to our end-customers. Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including the identification of market demand for new products, product selection, timely implementation of product design and development, product performance, effective manufacturing and assembly processes and sales and marketing. Our research and development expense was $210.6 million, $183.1 million and $158.1 million in 2017, 2016 and 2015, respectively.
Intellectual Property
We rely primarily on patent, trademark, copyright and trade secrets laws, confidentiality procedures and contractual provisions to protect our technology. As of December 31, 2017, we had 467 issued U.S.- and foreign-issued patents and 291 pending U.S. and foreign patent applications. We also license software from third parties for inclusion in our products, including open source software and other software available on commercially reasonable terms.
Despite our efforts to protect our rights in our technology, unauthorized parties may attempt to copy aspects of our products or obtain and use information that we regard as proprietary. We generally enter into confidentiality agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot provide assurance that the steps we take will prevent misappropriation of our technology. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. Third parties have asserted, are currently asserting and may in the future assert patent, copyright, trademark or other intellectual property rights against us, our channel partners or our end-customers. Successful claims of infringement by a third party could prevent us from distributing certain products or performing certain services or require us to pay substantial damages (including treble damages if we are found to have willfully infringed patents or copyrights), royalties or other fees. Even if third parties may offer a license to their technology, the terms of any offered license may not be acceptable and the failure to obtain a license or the costs associated with any license could cause our business, operating results or financial condition to be materially and adversely affected. We typically indemnify our end-customers, distributors and certain resellers against claims that our products infringe the intellectual property of third parties.
Seasonality
For information regarding seasonality in our sales, see the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Quarterly Results of Operations—Seasonality, Cyclicality and Quarterly Revenue Trends” in Part II, Item 7 of this Annual Report on Form 10-K.
Competition
The markets for our products are extremely competitive and are characterized by rapid technological change. The principal competitive factors in our markets include the following:
-
product performance, features, effectiveness, interoperability and reliability;
-
our ability to add and integrate new networking and security features and technological expertise;
-
compliance with industry standards and certifications;
-
price of products and services and total cost of ownership;
-
brand recognition;
-
customer service and support;
-
sales and distribution capabilities;
-
size and financial stability of operations; and
-
breadth of product line.
Among others, our competitors include Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), F5 Networks, Inc. (“F5 Networks”), FireEye, Inc. (“FireEye”), Forcepoint LLC (“Forcepoint”), Imperva, Inc. (“Imperva”), Juniper Networks, Inc. (“Juniper”), McAfee, LLC. (“McAfee”), Palo Alto Networks, Inc. (“Palo Alto Networks”), Proofpoint, Inc. (“Proofpoint”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc (“Sophos”), Symantec Corporation (“Symantec”) and Trend Micro Incorporated (“Trend Micro”).
We believe we compete favorably based on our products’ performance, reliability and breadth, our ability to add and integrate new networking and security features and our technological expertise. Several competitors are significantly larger, have greater financial, technical, marketing, distribution, customer support and other resources, are more established than we are and have significantly better brand recognition. Some of these larger competitors have substantially broader product offerings and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages users from purchasing our products. Based in part on these competitive pressures, we may lower prices or attempt to add incremental features and functionality.
Conditions in our markets could change rapidly and significantly as a result of technological advancements or continuing market consolidation. The development and market acceptance of alternative technologies could decrease the demand for our products or render them obsolete. Our competitors may introduce products that are less costly, provide superior performance, market their products better, or achieve greater market acceptance than us. In addition, our larger competitors often have broader product lines and are in a better position to withstand any significant reduction in capital spending by end-customers in these markets, and will therefore not be as susceptible to downturns in a particular market. The above competitive pressures are likely to continue to impact our business. We may not be able to compete successfully in the future, and competition may harm our business.
Employees
As of December 31, 2017, our total headcount was 5,066 employees and contractors. None of our U.S. employees are represented by a labor union; however, our employees in certain European countries have the right to be represented by external labor organizations if they maintain up-to-date union membership. We have not experienced any work stoppages, and we consider our relations with our employees to be good.
Available Information
Our web site is located at www.fortinet.com, and our investor relations web site is located at http://investor.fortinet.com. The information posted on our website is not incorporated by reference into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Act, are available free of charge on our investor relations web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the SEC. You may also access all of our public filings through the SEC’s website at www.sec.gov. Further, a copy of this Annual Report on Form 10-K is located at the SEC’s Public Reference Room at 100 F Street, NE, Washington, D.C. 20549. Information on the operation of the Public Reference Room can be obtained by calling the SEC at 1-800-SEC-0330.
We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations web site. Additionally, we provide notifications of news or announcements regarding our financial performance, including SEC filings, investor events, press and earnings releases, as part of our investor relations web site. The contents of these web sites are not intended to be incorporated by reference into this report or in any other report or document we file.
Item 1A. Risk Factors
Investing in our common stock involves a high degree of risk. Investors should carefully consider the following risks and all other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes, before investing in our common stock. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition and results of operations could be materially harmed. In that case, the trading price of our common stock could decline substantially, and investors may lose some or all of their investment.
Risks Related to Our Business
Our operating results are likely to vary significantly and be unpredictable.
Our operating results have historically varied from period to period, and we expect that they will continue to do so as a result of a number of factors, many of which are outside of our control or may be difficult to predict, including:
| • | our ability to attract and retain new end-customers or sell additional products and subscriptions to our existing end-customers; |
| • | the level of demand for our products and services, which may render forecasts inaccurate; |
| • | the timing of channel partner and end-customer orders, and our reliance on a concentration of shipments at the end of each quarter; |
| • | the timing of shipments, which may depend on factors such as inventory levels, logistics, manufacturing or shipping delays, our ability to ship new products on schedule and our ability to accurately forecast inventory requirements; |
| • | inventory management; |
| • | the mix of products sold and the mix of revenue between products and services, as well as the degree to which products and services are bundled and sold together for a package price; |
| • | the purchasing practices and budgeting cycles of our channel partners and end-customers; |
| • | the effectiveness of our sales organization, generally or in a particular geographic region, the time it takes to hire sales personnel and the timing of hiring, and our ability to retain, sales personnel; |
| • | the seasonal buying patterns of our end-customers; |
| • | the timing and level of our investments in sales and marketing, and the impact of such investments on our operating expenses, operating margin and the productivity and effectiveness of execution of our sales and marketing teams; |
| • | the timing of revenue recognition for our sales; |
| • | the level of perceived threats to network security, which may fluctuate from period to period; |
| • | changes in the requirements, market needs or buying practices and patterns of our distributors, resellers or end-customers; |
| • | changes in the growth rate of the network security market; |
| • | the timing and success of new product and service introductions or enhancements by us or our competitors, or any other change in the competitive landscape of our industry, including consolidation among our competitors, partners or end-customers; |
| • | the deferral of orders from distributors, resellers or end-customers in anticipation of new products or product enhancements announced by us or our competitors; |
| • | increases or decreases in our billings, revenue and expenses caused by fluctuations in foreign currency exchange rates or a strengthening of the U.S. dollar, as a significant portion of our expenses is incurred and paid in currencies other than the U.S. dollar, and the impact such fluctuations may have on the actual prices that our partners and customers are willing to pay for our products and services; |
| • | compliance with existing laws and regulations that are applicable to our ability to conduct business with the public sector; |
| • | the impact of cloud-based platforms on the timing of our revenue recognition, billings and free cash flow; |
| • | decisions by potential end-customers to purchase network security solutions from newer technology providers, from larger, more established security vendors or from their primary network equipment vendors; |
| • | price competition and increased competitiveness in our market; |
| • | our ability to both increase revenues and manage and control operating expenses in order to improve our operating margins; |
| • | changes in customer renewal rates for our services; |
| • | changes in the payment terms of services contracts or the length of services contracts sold; |
| • | changes in our estimated annual effective tax rates; |
| • | changes in circumstances and challenges in business conditions, including decreased demand, which may negatively impact our channel partners’ ability to sell the current inventory they hold and negatively impact their future purchases of products from us; |
| • | increased demand for cloud-based services and the uncertainty associated with transitioning to providing such services; |
| • | increased expenses, unforeseen liabilities or write-downs and any impact on results of operations from any acquisition consummated; |
| • | our channel partners having insufficient financial resources to withstand changes and challenges in business conditions; |
| • | disruptions in our channel or termination of our relationship with important channel partners, including as a result of consolidation among distributors and resellers of security solutions; |
| • | insolvency, credit or other difficulties confronting our key suppliers and channel partners, which could affect their ability to purchase or pay for products and services and which could disrupt our supply or distribution chain; |
| • | policy changes and uncertainty with respect to immigration laws, trade policy, foreign imports and tax laws related to international commerce; |
| • | political, economic and social instability; |
| • | general economic conditions, both in domestic and foreign markets; |
| • | future accounting pronouncements or changes in our accounting policies, such as changes in the revenue recognition standards or accounting for leases, as well as the significant costs that may be incurred to adopt and comply with these new pronouncements; |
| • | possible impairments or acceleration of depreciation of our existing real estate due to our current real estate holdings and future development plans; and |
| • | legislative or regulatory changes, such as with respect to privacy, information and cybersecurity, exports, the environment and applicable accounting standards. |
Any one of the factors above or the cumulative effect of some of the factors referred to above may result in significant fluctuations in our quarterly financial and other operating results. This variability and unpredictability could result in our failing to meet our internal operating plan or the expectations of securities analysts or investors for any period. If we fail to meet or exceed such expectations for these or any other reasons, the market price of our shares could fall substantially and we cou
Showing the first 8K of 138K characters. Open the full section
Item 1B. Unresolved Staff Comments
Not applicable.
Item 2. Properties
Our corporate headquarters is located in Sunnyvale, California and comprises approximately 162,000 square feet of office and building space. Along with our corporate headquarters, as of December 31, 2017, we also owned approximately 200,000 square feet in Union City, California used as a distribution facility; approximately 135,000 square feet of buildings adjacent to our corporate headquarters intended to support growth in our business operations; approximately 340,000 square feet of office and building space in Burnaby and Ottawa, Canada used for operations, support and research and development work; and 40,000 square feet of office space in Sophia, France predominantly used as a sales and support office.
We maintain additional offices throughout the United States and various international locations, including Singapore, Japan, France, India, China, the United Kingdom, Mexico and Germany. We believe that our existing properties are sufficient and suitable to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional operating expenses and capital expenditures in connection with such new or expanded facilities.
For information regarding the geographical location of our property and equipment, see Note 14 to our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.
Item 3. Legal Proceedings
We are subject to various claims, complaints and legal actions that arise from time to time in the normal course of business. We accrue for contingencies when we believe that a loss is probable and that we can reasonably estimate the amount of any such loss. There can be no assurance that existing or future legal proceedings arising in the ordinary course of business or otherwise will not have a material adverse effect on our business, consolidated financial position, results of operations or cash flows.
In October 2016, we received a letter from the United States Attorney's Office for the Northern District of California requesting information relating to our compliance with the Trade Agreements Act. We have been fully cooperating with this ongoing inquiry and have periodically met and spoken with the United States Attorney’s Office in connection with this matter.
Item 4. Mine Safety Disclosure
Not applicable.
Part II
| ITEM 5. | Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities |
Our common stock is traded on The Nasdaq Global Select Market under the symbol “FTNT.” The following table sets forth, for the time periods indicated, the high and low closing sales price of our common stock, as reported on the Nasdaq Global Select Market.
| 2017 | 2016 | ||||||||||||||
| High | Low | High | Low | ||||||||||||
| Fourth Quarter | $ | 45.09 | $ | 36.35 | $ | 36.94 | $ | 28.61 | |||||||
| Third Quarter | $ | 41.10 | $ | 35.84 | $ | 37.17 | $ | 31.57 | |||||||
| Second Quarter | $ | 40.97 | $ | 37.20 | $ | 34.78 | $ | 28.79 | |||||||
| First Quarter | $ | 38.35 | $ | 30.12 | $ | 30.63 | $ | 23.83 |
Holders of Record
As of February 16, 2018, there were 57 holders of record of our common stock. A substantially greater number of holders of our common stock are “street name” or beneficial holders, whose shares are held by banks, brokers and other financial institutions.
Dividends
We have never declared or paid cash dividends on our capital stock. We do not anticipate paying any cash dividends in the foreseeable future. Any future determination to declare cash dividends will be made at the discretion of our board of directors and will depend on our financial condition, operating results, capital requirements, general business conditions and other factors that our board of directors may deem relevant.
Stock Performance Graph
This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities and Exchange Act of 1934 (the “Exchange Act”), or incorporated by reference into any filing of Fortinet under the Securities Act of 1933, as amended (the “Securities Act”), or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.
The following graph compares the cumulative five-year total return for our common stock, the NASDAQ Composite Index and the NASDAQ Computer Index. Such returns are based on historical results and are not intended to suggest future performance. Data for the NASDAQ Composite Index and the NASDAQ Computer Index assume reinvestment of dividends. We have never declared or paid cash dividends on our capital stock, nor do we anticipate paying any such cash dividends in the foreseeable future.
COMPARISON OF CUMULATIVE TOTAL RETURN*
Among Fortinet, Inc., The NASDAQ Composite Index and
The NASDAQ Computer Index

| December 2012 * | December 2013 | December 2014 | December 2015 | December 2016 | December 2017 | |||||||||||||||||||
| Fortinet, Inc. | $ | 100 | $ | 91 | $ | 146 | $ | 148 | $ | 143 | $ | 208 | ||||||||||||
| NASDAQ Composite | $ | 100 | $ | 138 | $ | 157 | $ | 166 | $ | 178 | $ | 229 | ||||||||||||
| NASDAQ Computer | $ | 100 | $ | 132 | $ | 158 | $ | 168 | $ | 189 | $ | 262 |
- Assumes that $100 was invested on December 31, 2012 in stock or index, including reinvestment of dividends. Stockholder returns over the indicated period should not be considered indicative of future stockholder returns.
Sales of Unregistered Securities
None.
Purchases of Equity Securities by the Issuer and Affiliated Purchasers
Share Repurchase Program
In January 2016, our board of directors approved a Share Repurchase Program (the “Repurchase Program”), which authorized the repurchase of up to $200.0 million of our outstanding common stock through December 31, 2017. In 2016 and 2017, our board of directors approved the increases in the aggregate authorized repurchase amount under the Repurchase Program by $100.0 million and $700.0 million, respectively, bringing the total amount authorized to $1.0 billion through January 31, 2019. Under the Repurchase Program, share repurchases may be made by us from time to time in privately negotiated transactions or in open market transactions. The Repurchase Program does not require us to purchase a minimum number of shares, and may be suspended, modified or discontinued at any time without prior notice.
The following table provides information with respect to the shares of common stock we repurchased during the three months ended December 31, 2017 (in thousands, except share and per share amounts):
| Period | Total Number of Shares Purchased | Average Price Paid per Share | Total Number of Shares Purchased as Part of Publicly Announced Plan or Program | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Plans or Programs | ||||||||||
| October 1 - October 31, 2017 | 955,867 | $ | 38.68 | 955,867 | $ | 728,242 | ||||||||
| November 1 - November 30, 2017 | 4,688,088 | $ | 40.18 | 4,688,088 | $ | 539,865 | ||||||||
| December 1 - December 31, 2017 | 2,270,446 | $ | 42.73 | 2,270,446 | $ | 442,839 |
Item 6. Selected Financial Data
The following selected consolidated financial data set forth below was derived from our historical audited consolidated financial statements and should be read in conjunction with the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations” and “Financial Statements and Supplementary Data,” and other financial data included elsewhere in this Annual Report on Form 10-K. Our historical results of operations are not indicative of our future results of operations.
| Year Ended December 31, | |||||||||||||||||||
| 2017 | 2016 | 2015 | 2014 | 2013 | |||||||||||||||
| (in thousands, except per share amounts) | |||||||||||||||||||
| Consolidated Statement of Operations Data: | |||||||||||||||||||
| Total revenue | $ | 1,494,930 | $ | 1,275,443 | $ | 1,009,268 | $ | 770,364 | $ | 615,297 | |||||||||
| Gross profit | $ | 1,109,646 | $ | 937,606 | $ | 722,491 | $ | 539,355 | $ | 434,654 | |||||||||
| Operating income | $ | 109,804 | $ | 42,944 | $ | 14,877 | $ | 59,324 | $ | 72,090 | |||||||||
| Net income | $ | 31,399 | $ | 32,187 | $ | 7,987 | $ | 25,343 | $ | 44,273 | |||||||||
| Net income per share : | |||||||||||||||||||
| Basic | $ | 0.18 | $ | 0.19 | $ | 0.05 | $ | 0.15 | $ | 0.27 | |||||||||
| Diluted | $ | 0.18 | $ | 0.18 | $ | 0.05 | $ | 0.15 | $ | 0.26 | |||||||||
| Weighted-average shares outstanding: | |||||||||||||||||||
| Basic | 174,315 | 172,621 | 170,385 | 163,831 | 162,435 | ||||||||||||||
| Diluted | 178,079 | 176,338 | 176,141 | 169,289 | 168,183 |
| As of December 31, | |||||||||||||||||||
| 2017 | 2016 | 2015 | 2014 | 2013 | |||||||||||||||
| (in thousands) | |||||||||||||||||||
| Consolidated Balance Sheet Data: | |||||||||||||||||||
| Cash, cash equivalents and investments | $ | 1,349,299 | $ | 1,310,508 | $ | 1,164,310 | $ | 991,744 | $ | 843,045 | |||||||||
| Total assets | $ | 2,257,916 | $ | 2,139,941 | $ | 1,790,510 | $ | 1,424,774 | $ | 1,168,464 | |||||||||
| Total stockholders’ equity | $ | 589,377 | $ | 837,681 | $ | 755,377 | $ | 675,966 | $ | 585,760 |
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
In addition to historical information, this Annual Report on Form 10-K contains forward-looking statements within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. These statements include, among other things, statements concerning our expectations regarding:
| • | continued growth and market share gains; |
| • | variability in sales in certain product categories from year to year and between quarters; |
| • | expected impact of sales of certain products and services; |
| • | the impact of macro-economic and geopolitical factors on our international sales; |
| • | the proportion of our revenue that consists of our product and service revenue, and the mix of billings between products and services, and the duration of service contracts; |
| • | the impact of our product innovation strategy; |
| • | drivers of long-term growth and operating leverage, such as increased sales productivity, functionality and value in our standalone and bundled subscription service offerings; |
| • | growing our sales to businesses, service providers and government organizations, the impact of sales to these organizations on our long-term growth, expansion and operating results, and the effectiveness of our internal sales organization; |
| • | trends in revenue, costs of revenue and gross margin; |
| • | trends in our operating expenses, including sales and marketing expense, research and development expense, general and administrative expense, and expectations regarding these expenses as a percentage of total revenue; |
| • | continued investments in research and development; |
| • | managing our continued investments in sales and marketing, and the impact of those investments; |
| • | expectations regarding uncertain tax benefits and our effective tax rate; |
| • | the impact of the 2017 Tax Act; |
| • | expectations regarding spending related to real estate and other capital expenditures and to the impact on free cash flows; |
| • | competition in our markets; |
| • | our intentions regarding repatriation of cash, cash equivalents and investments held by our international subsidiaries and the sufficiency of our existing cash, cash equivalents and investments to meet our cash needs for at least the next 12 months; |
| • | other statements regarding our future operations, financial condition and prospects and business strategies; and |
| • | adoption and impact of new accounting standards, including those related to revenue recognition and accounting for leases. |
These forward-looking statements are subject to certain risks and uncertainties that could cause our actual results to differ materially from those reflected in the forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K and, in particular, the risks discussed under the heading “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K and those discussed in other documents we file with the Securities and Exchange Commission (the “SEC”). We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.
Business Overview
Fortinet is a global leader in broad, automated and integrated cybersecurity solutions. We provide high performance cybersecurity solutions to a wide variety of businesses, such as enterprises, data centers and distributed offices, including majority of the Fortune 100 companies. Our cybersecurity solutions are designed to provide broad, automated and integrated protection against dynamic and sophisticated security threats, while simplifying the IT and security infrastructure of our end-customers.
We have four current focus areas for our business. First, we derive a majority of product sales from our FortiGate network security appliances. We continue to develop and improve our offerings, which provide opportunities for market share gains. Second, the Fortinet Security Fabric has been developed to provide unified security across the entire digital attack surface, including network core, endpoints, applications, data centers, access and private and public cloud, and is designed to enable traditionally disparate security devices to work together as an integrated and collaborative whole. As a result of the increased success in selling the Security Fabric, billings for non-FortiGate products and services grew significantly in 2017. Third, cloud security provides opportunity for growth and was one of the fastest growing parts of our business in 2017. We help customers secure their cloud implementations by offering integration, visibility and automation across multi-cloud and hybrid deployments. Our FortiCASB extends the core capabilities of our security fabric architecture to provide businesses the same level of cybersecurity and threat intelligence in cloud environments as they do on their physical networks. The Fortinet cloud security is available across all major cloud providers, including Microsoft Azure, Amazon Web Services, Google Cloud, IBM Cloud and Oracle Cloud. Fourth, the emergence of the IoT has created an environment where data move freely between devices across locations, network environments, remote offices, mobile workers and public cloud environments, making it difficult to consistently track and secure.
Financial Highlights
| • | We recorded total revenue of $1.49 billion in 2017, an increase of 17% compared to $1.28 billion in 2016. Product revenue was $577.2 million in 2017, an increase of 5% compared to $548.1 million in 2016. Service revenue was $917.8 million in 2017, an increase of 26% compared to $727.3 million in 2016. |
| • | We generated operating income of $109.8 million in 2017, an increase of 156% compared to $42.9 million in 2016. |
| • | Cash, cash equivalents and investments were $1.35 billion as of December 31, 2017, an increase of $38.8 million, or 3%, from December 31, 2016. |
| • | Deferred revenue was $1.34 billion as of December 31, 2017, an increase of $301.0 million, or 29%, from December 31, 2016. |
| • | We generated cash flows from operating activities of $594.4 million in 2017, an increase of $248.7 million, or 72%, compared to 2016. |
| • | In 2017, we repurchased 11.2 million shares of common stock under the Repurchase Program for an aggregate purchase price of $446.3 million. In 2016, we repurchased 3.9 million shares of common stock for a total purchase price of $110.8 million. |
Our revenue growth was driven by the strength in sales of our FortiGate and non-FortiGate products and the sale of new, and the renewal and upgrade of existing, FortiCare technical support and FortiGuard security subscription service contracts. Revenue grew in 2017 as the investment made in sales and marketing enabled us to continue to gain enterprise customers.
We continue to see a shift in our revenue mix from product revenues to higher-margin, recurring service revenues, reflecting our success in driving higher-priced subscription bundles and services. On a geographic basis, revenue continues to be diversified globally, which remains a key strength of our business.
The percentage of our FortiGate-related billings from high-end products increased from 38% in 2016 to 39%
Showing the first 8K of 100K characters. Open the full section
Item 7A. Quantitative and Qualitative Disclosures about Market Risk
Interest Rate Fluctuation Risk
The primary objectives of our investment activities are to preserve principal, provide liquidity and maximize income without significantly increasing risk. Some of the securities we invest in are subject to market risk. This means that a change in prevailing interest rates may cause the principal amount of the investment to fluctuate. To minimize this risk, we maintain our portfolio of cash, cash equivalents and investments in a variety of securities, including corporate debt securities, money market funds, commercial paper, municipal bonds, U.S. government and agency securities, certificates of deposit and term deposits. The risk associated with fluctuating interest rates is limited to our investment portfolio. A 10% decrease in interest rates in 2017, 2016 and 2015 would have resulted in an insignificant decrease in our interest income in each of these periods.
Foreign Currency Exchange Risk
Our sales contracts are primarily denominated in U.S. dollars and therefore substantially all of our revenue is not subject to foreign currency translation risk. However, a substantial portion of our operating expenses incurred outside the United States are denominated in foreign currencies and are subject to fluctuations due to changes in foreign currency exchange rates, particularly changes in the Canadian dollar (“CAD”), the Euro (“EUR”) and the British pound (“GBP”). To help protect against significant fluctuations in value and the volatility of future cash flows caused by changes in currency exchange rates, we engage in foreign currency risk management activities to minimize the impact of balance sheet items denominated in CAD. We do not use these contracts for speculative or trading purposes. All of the derivative instruments are with high quality financial institutions and we monitor the credit worthiness of these parties. These contracts typically have a maturity of one month. We record changes in the fair value of forward exchange contracts related to balance sheet accounts as other expense in the consolidated statement of operations. We recognized an expense of $1.0 million in Other income (expense)—net, in 2017 due to foreign currency transaction gains.
Our use of forward exchange contracts is intended to reduce, but not eliminate, the impact of currency exchange rate movements, are relatively short-term in nature and are focused on the CAD, long-term material changes in the value of the U.S. dollar against other foreign currencies, such as the EUR and GBP, could adversely impact our operating expenses in the future. We assessed the risk of loss in fair values from the impact of hypothetical changes in foreign currency exchange rates. For foreign currency exchange rate risk, a 10% increase or decrease of foreign currency exchange rates against the U.S. dollar with all other variables held constant would have resulted in a $5.5 million change in the value of our foreign currency cash balances as of December 31, 2017.
Inflation Risk
Our monetary assets, consisting primarily of cash, cash equivalents and short-term investments, are not affected significantly by inflation because they are short-term. We believe the impact of inflation on replacement costs of equipment, furniture and leasehold improvements will not materially affect our operations. The rate of inflation, however, affects our cost of revenue and expenses, such as those for employee compensation, which may not be readily recoverable in the price of products and services offered by us.
| ITEM 8. | Financial Statements and Supplementary Data |
INDEX TO CONSOLIDATED FINANCIAL STATEMENTS
For the years ended December 31, 2017, 2016, and 2015
The supplementary financial information required by this Item 8 is included in Part II, Item 7 of this Annual Report on Form 10-K under the caption “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Quarterly Results of Operations.”
REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM
To the Shareholders and Board of Directors of Fortinet, Inc.
Opinion on the Financial Statements
We have audited the accompanying consolidated balance sheets of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, 2017 and 2016, and the related consolidated statements of operations, comprehensive income, stockholders’ equity, and cash flows for each of the three years in the period ended December 31, 2017, and the related notes and the schedule listed in the Index at Item 15 (collectively referred to as the “financial statements”). In our opinion, such consolidated financial statements present fairly, in all material respects, the financial position of the Company as of December 31, 2017 and 2016, and the results of their operations and its cash flows for each of the three years in the period ended December 31, 2017, in conformity with accounting principles generally accepted in the United States of America.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of December 31, 2017, based on the criteria established in Internal Control — Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission and our report dated February 26, 2018, expressed an unqualified opinion on the Company's internal control over financial reporting.
Basis for Opinion
These financial statements and financial statement schedule are the responsibility of the Company’s management. Our responsibility is to express an opinion on the financial statements and financial statement schedule based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. An audit included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.
/s/ DELOITTE & TOUCHE LLP
San Jose, California
February 26, 2018
We have served as the Company's auditor since 2002.
FORTINET, INC.
CONSOLIDATED BALANCE SHEETS
(in
Showing the first 8K of 137K characters. Open the full section
Item 9. Changes in and Disagreements With Accountants on Accounting and Financial Disclosure
None.
Item 9A. Controls and Procedures
Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) or 15d-15(e) under the Securities Exchange Act of 1934 (the “Exchange Act”) as of the end of the period covered by this Annual Report on Form 10-K. In designing and evaluating the disclosure controls and procedures, management recognized that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.
Based on that evaluation, our chief executive officer and chief financial officer concluded that our disclosure controls and procedures were effective as of December 31, 2017 to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized and reported within the time periods specified in SEC rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Management’s Report on Internal Control Over Financial Reporting
Our management is responsible for establishing and maintaining adequate internal control over financial reporting, as defined in Rule 13a-15(f) and 15d-15(f) under the Exchange Act. Management conducted an evaluation of the effectiveness of our internal control over financial reporting based on the framework in Internal Control—Integrated Framework (2013) set forth by the Committee of Sponsoring Organizations of the Treadway Commission.
Based on this evaluation, management concluded that our internal control over financial reporting was effective as of December 31, 2017. Management reviewed the results of its assessment with our Audit Committee. The effectiveness of our internal control over financial reporting as of December 31, 2017 has been audited by Deloitte & Touche LLP, an independent registered public accounting firm, as stated in its report, which appears in this Item under the heading “Report of Independent Registered Public Accounting Firm.”
Changes in Internal Control over Financial Reporting
There were no changes in our internal control over financial reporting (as defined in Rules 13a-15(f) or 15d-15(f) under the Exchange Act) during the fourth quarter of 2017 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM
To the Shareholders and Board of Directors of Fortinet, Inc.
Opinion on Internal Control over Financial Reporting
We have audited the internal control over financial reporting of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, 2017, based on criteria established in Internal Control — Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In our opinion, the Company maintained, in all material respects, effective internal control over financial reporting as of December 31, 2017, based on the criteria established in Internal Control — Integrated Framework (2013) issued by the COSO.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements and financial statement schedule as of and for the year ended December 31, 2017, of the Company and our report dated February 26, 2018, expressed an unqualified opinion on those financial statements and financial statement schedule.
Basis for Opinion
The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Management’s Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.
A company’s internal control over financial reporting is a process designed by, or under the supervision of, the company’s principal executive and principal financial officers, or persons performing similar functions, and effected by the company’s board of directors, management, and other personnel to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company's assets that could have a material effect on the financial statements.
Because of the inherent limitations of internal control over financial reporting, including the possibility of collusion or improper management override of controls, material misstatements due to error or fraud may not be prevented or detected on a timely basis. Also, projections of any evaluation of the effectiveness of the internal control over financial reporting to future periods are subject to the risk that the controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
/s/ DELOITTE & TOUCHE LLP
San Jose, California
February 26, 2018
Item 9B. Other Information
None.
Part III
Item 10. Directors, Executive Officers and Corporate Governance
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2018 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
As part of our system of corporate governance, our board of directors has adopted a code of business conduct and ethics. The code applies to all of our employees, officers (including our principal executive officer, principal financial officer, principal accounting officer or controller, or persons performing similar functions), agents and representatives, including our independent directors and consultants, who are not our employees, with regard to their Fortinet-related activities. Our code of business conduct and ethics is available on our website at www.fortinet.com under “Corporate—Investor Relations—Corporate Governance.” We will post on this section of our website any amendment to our code of business conduct and ethics, as well as any waivers of our code of business conduct and ethics, that are required to be disclosed by the rules of the SEC or the Nasdaq Stock Market.
Item 11. Executive Compensation
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2018 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2018 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 13. Certain Relationships and Related Transactions, and Director Independence
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2018 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 14. Principal Accounting Fees and Services
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2018 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Part IV
Item 15. Exhibits, Financial Statement Schedules
(a) The following documents are filed as part of this Annual Report on Form 10-K:
| 1. | Financial Statements: The information concerning Fortinet’s financial statements and the Report of Independent Registered Public Accounting Firm required by this Item 15(a)(1) is incorporated by reference herein to the section of this Annual Report on Form 10-K in Part II, Item 8, titled “Financial Statements and Supplementary Data.” |
| 2. | Financial Statement Schedule: The following financial statement schedule of Fortinet, Inc., for the fiscal years ended December 31, 2017, 2016 and 2015, is filed as part of this Annual Report on Form 10-K and should be read in conjunction with our consolidated financial statements. |
SCHEDULE II—VALUATION AND QUALIFYING ACCOUNTS
| Year Ended December 31, | |||||||||||
| 2017 | 2016 | 2015 | |||||||||
| (in thousands) | |||||||||||
| Sales Returns Reserve and Allowance for Doubtful Accounts: | |||||||||||
| Beginning balance | $ | 11,235 | $ | 6,228 | $ | 6,204 | |||||
| Charged to costs and expenses, net of deductions | 3,268 | 5,007 | 24 | ||||||||
| Ending balance | $ | 14,503 | $ | 11,235 | $ | 6,228 |
Schedules not listed above have been omitted because they are not applicable or are not required or the information required to be set forth therein is included in the consolidated financial statements or notes thereto.
| 3. | Exhibits: See Item 15(b) below. We have filed, or incorporated into this Annual Report on Form 10-K by reference, the exhibits listed on the accompanying Exhibit Index immediately preceding the signature page of this Annual Report on Form 10-K. |
(b) Exhibits:
The exhibit list in the Exhibit Index immediately preceding the signature page of this Annual Report on Form 10-K is incorporated herein by reference as the list of exhibits required by this Item 15(b).
(c) Financial Statement Schedules: See Item 15(a) above.
EXHIBIT INDEX
| Exhibit Number | Description | Incorporated by reference herein | ||||||
| Form | Date | Exhibit Number | ||||||
| 3.1 | Amended and Restated Certificate of Incorporation | Registration Statement on Form S-l (File No. 333-161190) | August 10, 2009 | 3.2 | ||||
| 3.2 | Bylaws | Current Report on Form 8-K (File No. 001-34511) | April 21, 2014 | 3.1 | ||||
| 4.1 | Specimen common stock certificate of the Company | Registration Statement on Form S-l, as amended (File No. 333-161190) | November 2, 2009 | 4.1 | ||||
| 10.1† | Forms of Indemnification Agreement between the Company and its directors and officers | Registration Statement on Form S-l (File No. 333-161190) | August 10, 2009 | 10.1 | ||||
| 10.2† | 2000 Stock Plan and forms of agreement thereunder | Registration Statement on Form S-l (File No. 333-161190) | August 10, 2009 | 10.2 | ||||
| 10.3† | 2008 Stock Plan and forms of agreement thereunder | Registration Statement on Form S-l (File No. 333-161190) | August 10, 2009 | 10.3 | ||||
| 10.4† | 2009 Equity Incentive Plan and forms of restricted stock unit award and restricted stock agreement thereunder | Registration Statement on Form S-l (File No. 333-161190) | August 10, 2009 | 10.4 | ||||
| 10.5† | Forms of stock option agreement under 2009 Equity Incentive Plan | Annual Report on Form 10-K (File No. 001-34511) | February 28, 2012 | 10.5 | ||||
| 10.6† | Form of performance stock unit award agreement under 2009 Equity Incentive Plan | Quarterly Report on Form 10-Q (File No. 001-34511) | August 6, 2013 | 99.1 | ||||
| 10.7† | Forms of restricted stock unit award and performance stock unit award agreement under 2009 Equity Incentive Plan (Additional Forms) | Annual Report on Form 10-K (File No. 001-34511) | March 2, 2015 | 10.7 | ||||
| 10.8† | Fortinet, Inc. 2011 Employee Stock Purchase Plan | Current Report on Form 8-K (File No. 001-34511) | June 27, 2011 | 10.1 | ||||
| 10.9† | Meru Networks, Inc. 2010 Equity Incentive Plan | Registration Statement on Form S-8 (File No. 333-205958) | July 30, 2015 | 99.1 | ||||
| 10.10† | Meru Networks, Inc. 2013 New Employee Stock Inducement Plan | Registration Statement on Form S-8 (File No. 333-205958) | July 30, 2015 | 99.2 | ||||
| 10.11† | Forms of Fortinet, Inc. Restricted Stock Unit Assumption Agreement | Registration Statement on Form S-8 (File No. 333-205958) | July 30, 2015 | 99.3 | ||||
| 10.12† | Fortinet, Inc. Bonus Plan | Current Report on Form 8-K (File No. 001-34511) | January 26, 2010 | 10.1 | ||||
| 10.13† | Fortinet, Inc. Cash and Equity Incentive Plan | Quarterly Report on Form 10-Q (File No. 001-34511) | November 5, 2013 | 10.1 | ||||
| 10.14† | Form of Change of Control Agreement between the Company and its directors | Quarterly Report on Form 10-Q (File No. 001-34511) | August 4, 2015 | 10.1 | ||||
| 10.15† | Amended and Restated Change of Control Agreement, dated as of February 4, 2016, between the Company and Ken Xie | Annual Report on Form 10-K (File No. 001-34511) | February 26, 2016 | 10.15 | ||||
| 10.16† | Amended and Restated Change of Control Agreement, dated as of February 4, 2016, between the Company and Michael Xie | Annual Report on Form 10-K (File No. 001-34511) | February 26, 2016 | 10.16 | ||||
| 10.17† | Amended and Restated Change of Control Agreement, dated as of February 4, 2016, between the Company and John Whittle | Annual Report on Form 10-K (File No. 001-34511) | February 26, 2016 | 10.17 | ||||
| 10.18† | Amended and Restated Change of Control Agreement, dated as of February 4, 2016, between the Company and Andrew Del Matto | Annual Report on Form 10-K (File No. 001-34511) | February 26, 2016 | 10.18 | ||||
| 10.19† | Offer Letter, dated as of August 31, 2007, by and between the Company and John Whittle | Registration Statement on Form S-l, as amended (File No. 333-161190) | August 10, 2009 | 10.10 | ||||
| 10.20† | Offer Letter, dated as of December 17, 2013, by and between the Company and Andrew Del Matto | Current Report on Form 8-K (File No. 001-34511) | December 20, 2013 | 99.1 | ||||
| 10.21† | Letter regarding stock grants, dated as of December 17, 2013, between the Company and Andrew Del Matto | Current Report on Form 8-K (File No. 001-34511) | December 20, 2013 | 99.2 | ||||
| 10.22†* | Offer Letter, dated as of April 3, 2014, by and between the Company and Keith Jensen | |||||||
| 10.23†* | Change of Control Severance Agreement, dated as of February 4, 2016, between the Company and Keith Jensen | |||||||
| 21.1* | List of subsidiaries | |||||||
| 23.1* | Consent of Independent Registered Public Accounting Firm | |||||||
| 24.1* | Power of Attorney (incorporated by reference to the signature page of this Annual Report on Form 10-K) |
| 31.1* | Certification of Chief Executive Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | |
| 31.2* | Certification of Chief Financial Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | |
| 32.1* | Certifications of Chief Executive Officer and Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002 | |
| 101.SCH* | XBRL Taxonomy Extension Schema Document | |
| 101.CAL* | XBRL Taxonomy Extension Calculation Linkbase Document | |
| 101.PRE* | XBRL Taxonomy Extension Presentation Linkbase Document | |
| 101.DEF* | XBRL Taxonomy Extension Definition Linkbase Document | |
| 101.LAB* | XBRL Taxonomy Extension Label Linkbase Document | |
| 101.INS* | XBRL Instance Document |
† Indicates management compensatory plan, contract or arrangement.
- Filed herewith.
SIGNATURES
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on February 26, 2018.
| FORTINET, INC. | ||
| By: | /s/ Ken Xie | |
| Ken Xie, Chief Executive Officer and Chairman | ||
| (Duly Authorized Officer and Principal Executive Officer) |
| FORTINET, INC. | ||
| By: | /s/ Keith Jensen | |
| Keith Jensen, Interim Chief Financial Officer | ||
| (Duly Authorized Officer and Principal Financial Officer and Principal Accounting Officer) |
POWER OF ATTORNEY
KNOW ALL PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Ken Xie and Keith Jensen, jointly and severally, his or her attorney-in-fact, with the power of substitution, for him or her in any and all capacities, to sign any amendments to this Annual Report on Form 10-K and to file the same, with exhibits thereto and other documents in connection therewith, with the Securities and Exchange Commission, hereby ratifying and confirming all that each of said attorneys-in-fact, or his substitute or substitutes, may do or cause to be done by virtue hereof.
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the registrant and in the capacities and on the dates indicated.
| Signature | Title | Date | ||
| /s/ Ken Xie | Chief Executive Officer and Chairman | February 26, 2018 | ||
| Ken Xie | (Principal Executive Officer) | |||
| /s/ Keith Jensen | Interim Chief Financial Officer | February 26, 2018 | ||
| Keith Jensen | (Principal Financial Officer and Principal Accounting Officer) | |||
| /s/ Michael Xie | President, Chief Technology Officer and Director | February 26, 2018 | ||
| Michael Xie | ||||
| /s/ Peter D. Cohen | Director | February 26, 2018 | ||
| Peter D. Cohen | ||||
| /s/ Ming Hsieh | Director | February 26, 2018 | ||
| Ming Hsieh | ||||
| /s/ Gary Locke | Director | February 26, 2018 | ||
| Gary Locke | ||||
| /s/ William H. Neukom | Director | February 26, 2018 | ||
| William H. Neukom | ||||
| /s/ Christopher B. Paisley | Director | February 26, 2018 | ||
| Christopher B. Paisley | ||||
| /s/ Judith Sim | Director | February 26, 2018 | ||
| Judith Sim |