Item 1. Business
34K characters. Original on sec.gov · Markdown
Item 1. Business
Overview
Fortinet is a global leader in cybersecurity solutions provided to a wide variety of businesses, such as enterprises, communication service providers and small businesses. Our cybersecurity solutions are designed to provide broad visibility and segmentation of the digital attack surface through our integrated Security Fabric platform, which features automated protection, detection and responses.
The focus areas of our business consist of:
| • | Network Security—We derive a majority of product sales from our FortiGate network security appliances. Our FortiGate network security appliances include a broad set of built-in security and networking features and functionalities, including firewall, software-defined wide-area network (“SD-WAN”), secure sockets layer (“SSL”) data leak prevention, virtual private network (“VPN”), switch and wireless controller and wide area network (“WAN”) acceleration. Our network security appliances include our FortiOS operating system, which provides the foundation for FortiGate security functions, and FortiASIC integrated circuit, which is designed to accelerate the processing of security and networking functions. Our customers may also purchase FortiGuard subscription services to receive threat intelligence updates. We provide standard technical support across all of our products through our FortiCare support services. We also offer services to end-customers including Technical Account Managers (“TAMs”), Resident Engineers (“REs”) and professional service consultants for implementations, as well as training services to our end-customers and channel partners. |
| • | Fortinet Security Fabric—The Fortinet Security Fabric platform is an architectural approach that protects the entire digital attack surface, including network core, endpoints, applications, data centers and private and public cloud. Together with our network of Fabric-Ready Partners, the Fortinet Security Fabric platform enables disparate security devices to work together as an integrated, automated and collaborative solution. |
| • | Cloud Security—We help customers connect securely to and across their cloud environments by offering security through our virtual firewall and other software products in public and private cloud environments. Our Cloud Security solutions, including our Client Access Security Broker Solution, FortiCASB, extend the core capabilities of the Fortinet Security Fabric platform to provide businesses with the same level of cybersecurity and threat intelligence in cloud environments that they receive on their physical networks. Fortinet cloud security offerings are available across all major cloud providers, including Amazon Web Services, Microsoft Azure, Google Cloud, Oracle Cloud and IBM Cloud. |
| • | Internet of Things and Operational Technology—The proliferation of Internet of Things (“IoT”) and Operational Technology (“OT”) devices has generated new opportunities for us to grow our business. IoT and OT have created an environment where data move freely between devices across locations, network environments, remote offices, mobile workers and public cloud environments, making the data difficult to consistently track and secure. |
During our year ended December 31, 2018, we generated total revenue of $1.80 billion and net income of $332.2 million. See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, 2018 and 2017 and our consolidated statements of income, comprehensive income, stockholders’ equity, and cash flows for each of the three years ended December 31, 2018, 2017 and 2016.
We were incorporated in Delaware in November 2000. Our principal executive office is located at 899 Kifer Road, Sunnyvale, California 94086 and our telephone number at that location is (408) 235-7700.
Technology and Architecture
Our proprietary Security Processing Unit (“SPU”) hardware architecture, FortiOS operating system and associated security and networking functions are combined to form the Fortinet Security Fabric platform. This approach to security ties together discrete security solutions into an integrated whole, which enables our products to perform security processing for networks with high throughput requirements across a broad threat landscape.
SPU
Our proprietary SPUs are Application-Specific Integrated Circuits (“ASICs”) that are divided into three main types: (i) the Content Processor (“SPU CP”), (ii) the Network Processor (“SPU NP”) and (iii) the System-on-a-Chip (“SPU SOC”). Our SPUs are designed to enhance the security processing capabilities implemented in software by accelerating computationally intensive tasks such as firewall policy enforcement, network address translation, Intrusion Prevention Systems (“IPS”) threat detection and encryption. This architecture provides the ability to implement accelerated processing of new threat detection. Entry-level FortiGate products often use the SPU SOC2 or SPU SOC3 to provide the necessary acceleration at this level. Mid-range FortiGate products use a central processing unit (“CPU”) and include the SPU NP and SPU CP hardware acceleration. The high-end FortiGate products use multiple CPUs, SPU CPs and SPU NPs.
FortiOS
Our proprietary FortiOS operating system provides the foundation for the operation of all FortiGate appliances, whether physical, virtual, private or public cloud based, and is at the heart of the Fortinet Security Fabric platform. The security and networking capabilities of the Fortinet Security Fabric platform are controlled through FortiOS. The core kernel functions to the security processing feature sets work together to provide a highly integrated solution. FortiOS provides (i) multiple layers of security, including a hardened kernel layer providing protection for the FortiGate system, (ii) a network security layer, providing security for end-customers’ network infrastructures and (iii) application content protection, providing security for end-customers’ workstations and applications. FortiOS directs the operations of processors and SPUs and provides system management functions such as command line, graphical user interfaces, multiple network and security topology views.
Key high-level functions and capabilities of FortiOS include:
| • | key enablement for the Fortinet Security Fabric architecture; |
| • | option for FortiGate appliances to be configured into different security environments, such as our Internal Network Firewall, Next-Generation Firewall and Data Center Firewall; |
| • | configuration of the physical aspects of the appliance, such as ports, onboard Wi-Fi and switching; |
| • | extension of the Fortinet Security Fabric platform through direct management of FortiSwitch and FortiAP devices; |
| • | key network functions such as routing and deployment modes (network routing, transparent, sniffer, etc.); |
| • | implementation of security updates from our FortiGuard distribution network, delivering Advanced Threat Protection (“ATP”), such as IPS, antivirus and application control; |
| • | access to cloud-based web and email filtering databases; |
| • | direct integration with both cloud and on-premises FortiSandbox technology; |
| • | security policy objects and enforcement; |
| • | data leak prevention and document finger printing; and |
| • | real-time reporting and logging. |
FortiOS also enables advanced, integrated routing and switching, allowing end-customers to deploy FortiGate devices within a wide variety of networks, as well as providing a direct replacement solution option for legacy switching and routing equipment. FortiOS implements a suite of commonly used standards-based routing protocols as well as network address translation technologies, allowing the FortiGate appliance to integrate and operate in a wide variety of network environments. Additional features include virtual domain capabilities, which can provide support for multiple customers on a single device or FortiOS instance. FortiOS also provides capabilities for the logging of traffic for forensic analysis purposes, which are particularly important for regulatory compliance initiatives such as payment card industry data security standards. FortiOS is designed to help control network traffic in order to optimize performance by including functionality such as packet classification, queue disciplines, policy enforcement, congestion management, WAN optimization and caching. These features enable administrators to set the appropriate configurations and policies that meet their infrastructure needs. We make updates to FortiOS available through our FortiCare support services.
Products
Our core product offerings consist of our FortiGate product family and our non-FortiGate products, all of which may be purchased to complement commercial and enterprise deployments. Our FortiGate hardware and software licenses are sold with a set of broad security services. These security services are enabled by FortiGuard, which provides extensive threat research and artificial intelligence capabilities from a global cloud network to deliver protection services to each FortiGate appliance. Our non-FortiGate products include the Fortinet Security Fabric (such as FortiAP, FortiAnalyzer, FortiSwitch and FortiManager), certain cloud security products (such as virtual machines and cloud services) and other products.
FortiGate
FortiGate offers a broad set of security and networking functions, including firewall, intrusion prevention, anti-malware, VPN, application control, web filtering, anti-spam and WAN acceleration. FortiGate is available as a hardware appliance or as a virtual appliance. All FortiGate appliances run on FortiOS. FortiGate platforms can be centrally managed through both embedded web-based and command line interfaces, as well as through FortiManager, which provides a central management architecture for FortiGate appliances and the Fortinet Security Fabric platform.
By combining multiple network security functions in our purpose-built security platform, FortiGate appliances provide broad, high-quality protection capabilities and deployment flexibility while reducing the operational burden and costs associated with managing multiple point products. With over 30 models in the FortiGate product line, FortiGate is designed to address security requirements for small- to medium-sized businesses, large enterprises and government organizations worldwide.
Typically, all FortiGate hardware appliances include our SPUs to accelerate content and network security features implemented within FortiOS. The significant differences between each model are the performance and scalability targets each model is designed to meet, while the security features and associated services offered are common throughout all models. The FortiGate-20 through -100 series models are designed for perimeter protection for small- to medium-sized businesses and enterprises with distributed offices. The FortiGate-200 through -900 series models are designed for perimeter deployment in medium-sized to large enterprise networks. The FortiGate-1000 through -7000 series models deliver high performance and scalable network security functionality for perimeter, data center and core deployment in large enterprises.
We also incorporate additional technologies within FortiGate appliances that differentiate our solutions, including data leakage protection, traffic optimization, secure socket layer inspection, threat vulnerability management and wireless controller technology. In addition to these in-built features, we offer a full range of wireless access points and controllers, complementing FortiGate appliances with the flexibility of wireless local area network access.
Fortinet Security Fabric
As part of the Fortinet Security Fabric platform, we offer products that provide network security, end point security, cloud security, web-based application security, identity and access management, sandbox protection and email security. The integration of devices using open standards, common operating systems, and unified management platforms enables the sharing and correlation of real-time threat intelligence. The following products are key elements of the Fortinet Security Fabric platform:
| • | FortiAP—Our FortiAP product family provides secure wireless networking solutions. FortiAPs allow a variety of management options including from the cloud and directly from our FortiGate Next Generation Firewall product. FortiAPs create a scalable and secure access layer for connecting wireless devices such as computers, laptops, cell phones and tablets, as well as IoT devices. |
| • | FortiSwitch—Our FortiSwitch product family provides secure switching solutions that can be deployed in traditional network switching designs with Layer 2 or Layer 3 access control features. FortiSwitch creates a scalable and secure access layer for customers to connect their end devices, such as computers and laptops, as well as to expand the field of IoT devices. |
| • | FortiAnalyzer—Our FortiAnalyzer family of products provides centralized network logging, analyzing and reporting solutions that securely aggregate content and log data from our FortiGate devices, other Fortinet products and third-party devices to enable network logging, analysis and reporting. |
| • | FortiManager—Our FortiManager family of products provides a central and scalable management solution for our FortiGate products, including software updates, configuration, policy settings and security updates. FortiManager facilitates the coordination of policy-based provisioning, device configuration and operating system revision management, as well as network security monitoring and device control. |
| • | FortiSandbox—Our FortiSandbox technology delivers proactive detection and mitigation with the ability to generate a directly actionable protection capability. Available in both hardware and cloud-based form, the FortiSandbox subjects suspicious code to a set of multi-layer protection techniques, culminating in execution within an operating system, allowing real-time behavioral analysis to be performed in a secure environment. When malicious code is identified, a signature can be generated locally for distribution across the Fortinet Security Fabric. |
| • | FortiSIEM—Our FortiSIEM family of software solutions provides a cloud-ready security information and event management (“SIEM”) solution. FortiSIEM unifies analytics that are traditionally monitored discretely, parses the information and then processes it in an event-based analytics engine for handling real-time searches, rules, dashboards and ad-hoc queries. This unification of diverse sources of data enables organizations to create comprehensive dashboards and reports to identify root causes of threats, and take the steps necessary to remediate and prevent them in the future. |
Services
FortiGuard Security Subscription Services
Security requirements are dynamic due to the constantly changing nature of threats. Our FortiGuard security subscription services are designed to allow us to quickly deliver new threat detection and prevention capabilities to end-customers worldwide as new threats evolve. Our FortiGuard Labs global threat research team identifies emerging threats, collects threat samples, and replicates, reviews, characterizes and collates attack data. Based on this research, we develop updates for virus signatures, attack definitions, scanning engines and other security solution components to distribute to end-customers. FortiGuard functionality varies depending on which FortiGate and non-FortiGate products the end-customer is using, but will typically include one or more of the following functions: application control, antivirus, intrusion prevention, web filtering, anti-spam, VPN functions, email image analysis, vulnerability management, database functions, web functions, advanced threat protection and domain and IP reputation services.
End-customers purchase FortiGuard security subscription services in advance, typically with terms of one or more years. We provide FortiGuard security subscription services 24 hours a day, seven days a week.
FortiCare Technical Support Services
Our FortiCare services portfolio includes technical support and extended product warranty. For our standard technical support, our channel partners may provide first-level support to the end-customer. We also provide first-level support to our end-customers, as well as second- and third-level support as appropriate. We also provide knowledge management tools and customer self-help portals to help augment our support capabilities in an efficient and scalable manner. We deliver technical support to partners and end-customers 24 hours a day, seven days a week, through worldwide regional technical support centers. In addition to our technical support services, we offer a range of advanced services, including premium support and professional services.
Service Bundles
We also sell FortiGuard and FortiCare services as bundles, consolidating security services into packages that would be typical for certain types of end-customer.
| • | Threat Protection—Our Threat Protection bundle includes application control, antivirus, IP reputation and anti-botnet security, mobile security, data sanitation, sandbox, intrusion prevention and virus outbreak protection, along with FortiCare security services. |
| • | Unified Threat Management (“UTM”)—Our UTM bundle includes antispam, antivirus, data sanitation, sandbox, application control, intrusion prevention, virus outbreak protection and web filtering, along with FortiCare security services. |
| • | Enterprise Protection—Our Enterprise Protection bundle includes application control, intrusion prevention, web filtering, sandbox, antivirus, mobile security, IP reputation and anti-botnet security, antispam, CASB, industrial control systems, security rating, virus outbreak protection and data sanitation, along with FortiCare security services. |
Professional Services
We offer professional services to end-customers including Technical Account Managers (“TAMs”), Resident Engineers (“REs”) and professional service consultants for implementations.
TAMs and REs are dedicated support engineers available to help identify and eliminate issues before problems arise. Each TAM and RE acts as a single point of contact and customer advocate within Fortinet, offering a deep understanding of our customers’ businesses and security requirements.
Our professional services consultants help in the design of product deployments and work closely with end-customers to implement our products according to design, utilizing network analysis tools, traffic simulation software and scripts.
Training Services
We offer training services to our end-customers and channel partners through our training department and authorized training partners. We have also implemented a training certification program, Network Security Expert, to help ensure an understanding of our products and services.
Customers
We typically sell our security solutions to channel partners, who in turn sell to end-customers. At times, we also sell directly to end-customers. Our end-customers include small and medium-sized businesses, large enterprises and government organizations across a wide range of industries, including telecommunications, technology, government, financial services, education, retail, manufacturing and healthcare. An end-customer deployment may involve as few as one or as many as thousands of appliances and other Fortinet Security Fabric products, depending on our end-customer’s size and security requirements. Customers may also access our products via the cloud through certain cloud providers such as Amazon Web Services, Microsoft Azure, Google Cloud, Oracle Cloud and IBM Cloud. Typically, our customers also purchase our FortiGuard security subscription services and FortiCare technical support services.
For information regarding our geographic revenue based on the billing address of our distributors and direct customers, see Note 14 to our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K. During 2018, Exclusive Networks Group (“Exclusive”) and Ingram Micro Inc. (“Ingram Micro”) accounted for 30% and 10% of total revenue, respectively. During 2017 and 2016, Exclusive accounted for 25% and 20% of total revenue, respectively.
Sales and Marketing
We primarily sell our products and services through a two-tier distribution model. We sell to distributors that sell to networking security and enterprise-focused resellers and service providers and managed security service providers (“MSSPs”), who, in turn, sell to our end-customers. We work with many technology distributors, including Exclusive, Ingram Micro Inc., Arrow Electronics, Inc., Synnex Corporation and Tech Data Corporation.
We support our channel partners with a dedicated team of experienced channel account managers, sales professionals and sales engineers who provide business planning, joint marketing strategy, and pre-sales and operational sales support. Additionally, our sales teams help drive and support large enterprise and service provider sales through a direct touch model. Our sales professionals and engineers typically work closely with our channel partners and directly engage with large end-customers to address their unique security and deployment requirements. To support our broadly dispersed global channel and end-customer base, we have sales professionals in over 70 countries around the world.
Our marketing strategy is focused on building our brand and driving end-customer demand for our security solutions. We use a combination of internal marketing professionals and a network of regional and global channel partners. Our internal marketing organization is responsible for messaging, branding, demand generation, product marketing, packaging support and subscription services into service bundles, channel marketing, event marketing, digital marketing, communications, analyst relations, public relations and sales enablement. We focus our resources on campaigns, programs and activities that can be leveraged by partners worldwide to extend our marketing reach, such as sales tools and collateral, product awards and technical certifications, media engagement, training, regional seminars and conferences, webinars and various other demand-generation activities.
In 2018, we continued to invest in sales and marketing, particularly in the enterprise market where enterprise customers tend to have a higher lifetime value. We intend to continue to make investments in our sales resources and infrastructure and marketing strategy, which are critical to support our growth.
Manufacturing and Suppliers
We outsource the manufacturing of our security appliance products to a variety of contract manufacturers and original design manufacturers. Our current manufacturing partners include ADLINK Technology, Inc., IBASE Technology, Inc. (“IBASE”), Micro-Star International Co. (“Micro-Star”), Senao Networks, Inc. (“Senao”), Wistron Corporation (“Wistron”) and a number of other manufacturers. The majority of our hardware is manufactured in Taiwan, with some products manufactured in the United States or China. We submit purchase orders to our contract manufacturers that describe the type and quantities of our products to be manufactured, the delivery date and other delivery terms. Once our products are manufactured, they are sent to either our warehouse in California, or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed. We believe that outsourcing our manufacturing and a substantial portion of our logistics enables us to focus resources on our core competencies. Our proprietary SPUs, which are the key to the performance of our appliances, are built by contract manufacturers including Faraday Technology Corporation (“Faraday”), Kawasaki Microelectronics America, Inc. and Renesas Electronics Corporation (“Renesas”). These contract manufacturers use foundries operated by either United Microelectronics Corporation (“UMC”) or Taiwan Semiconductor Manufacturing Company Limited (“TSMC”), or their own foundry, such as Renesas’ fab.
The components included in our products are sourced from various suppliers by us or, more frequently, by our contract manufacturers. Some of the components important to our business, including certain CPUs from Intel Corporation (“Intel”); network chips from Broadcom Inc. (“Broadcom”), Marvell Technology Group Ltd. (“Marvell”) and Intel, and memory devices from Intel, ADATA Technology Co., Ltd. (“ADATA”), OCZ Technology Group, Inc. (“OCZ”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from limited or sole sources of supply.
We have no long-term contracts related to the manufacturing of our ASICs or other components that guarantee any capacity or pricing terms.
Research and Development
We focus our research and development efforts on developing new hardware and software products and services, and adding new features to existing products and services. Our development strategy is to identify features, products and systems for both software and hardware that are, or are expected to be, important to our end-customers. Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including identification of market demand for new products, product selection, timely implementation of product design and development, product performance, costs of development, bills of materials, effective manufacturing and assembly processes and sales and marketing.
Intellectual Property
We rely primarily on patent, trademark, copyright and trade secrets laws, confidentiality procedures and contractual provisions to protect our technology. As of December 31, 2018, we had 596 U.S. and foreign-issued patents and 199 pending U.S. and foreign patent applications. We also license software from third parties for inclusion in our products, including open source software and other software available on commercially reasonable terms.
Despite our efforts to protect our rights in our technology, unauthorized parties may attempt to copy aspects of our products or obtain and use information and technology that we regard as proprietary. We generally enter into confidentiality agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot provide assurance that the steps we take will prevent misappropriation of our technology. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. Third parties have asserted, are currently asserting and may in the future assert patent, copyright, trademark or other intellectual property rights against us, our channel partners or our end-customers. Successful claims of infringement by a third party could prevent us from distributing certain products or performing certain services or require us to pay substantial damages (including treble damages if we are found to have willfully infringed patents or copyrights), royalties or other fees. Even if third parties offer a license to their technology, the terms of any offered license may not be acceptable and the failure to obtain a license or the costs associated with any license could cause our business, operating results or financial condition to be materially and adversely affected. In certain instances, we indemnify our end-customers, distributors and resellers against claims that our products infringe the intellectual property of third parties.
Seasonality
For information regarding seasonality in our sales, see the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Quarterly Results of Operations—Seasonality, Cyclicality and Quarterly Revenue Trends” in Part II, Item 7 of this Annual Report on Form 10-K.
Competition
The markets for our products are extremely competitive and are characterized by rapid technological change. The principal competitive factors in our markets include the following:
-
product performance, throughput, features, effectiveness, interoperability and reliability;
-
addition and integration of new networking and security features and technological expertise;
-
compliance with industry standards and certifications;
-
price of products and services and total cost of ownership;
-
brand recognition;
-
customer service and support across varied and complex customer segments;
-
sales and distribution capabilities;
-
size and financial stability; and
-
breadth of product line.
Among others, our competitors include Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), F5 Networks, Inc. (“F5 Networks”), FireEye, Inc. (“FireEye”), Forcepoint LLC (“Forcepoint”), Imperva, Inc. (“Imperva”), Juniper Networks, Inc. (“Juniper”), McAfee, LLC (“McAfee”), Palo Alto Networks, Inc. (“Palo Alto Networks”), Proofpoint, Inc. (“Proofpoint”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc (“Sophos”) and Trend Micro Incorporated (“Trend Micro”).
We believe we compete favorably based on our products’ performance, throughput, reliability, breadth and ability to work together; our ability to add and integrate new networking and security features and our technological expertise. Several competitors are significantly larger, have greater financial, technical, marketing, distribution, customer support and other resources, are more established than we are, and have significantly better brand recognition. Some of these larger competitors have substantially broader product offerings, and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages users from purchasing our products. Based in part on these competitive pressures, we may lower prices or attempt to add incremental features and functionalities to our products.
Conditions in our markets could change rapidly and significantly as a result of technological advancements or market consolidation. The development and market acceptance of alternative technologies could decrease the demand for our products or render them obsolete. Our competitors may introduce products that are less costly, provide superior performance, are better marketed, or achieve greater market acceptance than our products. Additionally, our larger competitors often have broader product lines and are better positioned to withstand a significant reduction in capital spending by end-customers, and will therefore not be as susceptible to downturns in a particular market. The above competitive pressures are likely to continue to impact our business. We may not be able to compete successfully in the future, and competition may harm our business.
Employees
As of December 31, 2018, our total headcount was 5,845 employees and contractors. None of our U.S. employees are represented by a labor union; however, our employees in certain European countries have the right to be represented by external labor organizations if they maintain up-to-date union membership. We have not experienced any work stoppages, and we consider our relations with our employees to be good.
Available Information
Our web site is located at https://www.fortinet.com, and our investor relations web site is located at https://investor.fortinet.com. The information posted on our website is not incorporated by reference into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Act, are available free of charge on our investor relations web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the SEC. You may also access all of our public filings through the SEC’s website at https://www.sec.gov.
We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations web site. Additionally, we provide notifications of news or announcements regarding our financial performance, including SEC filings, investor events and press and earnings releases, as part of our investor relations web site. The contents of these web sites are not intended to be incorporated by reference into this report or in any other report or document we file.
Previous: Cover and table of contents · Next: Item 1A. Risk Factors