Item 1. Business

31K characters. Original on sec.gov · Markdown

Item 1. Business

Overview

Fortinet is a leader in cybersecurity and the convergence of networking and security. Our mission is to secure people, devices and data everywhere. Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified Secure Access Service Edge (“SASE”) and AI-driven security operations to deliver cybersecurity where our customers need it. As of December 31, 2023, over a half million customers trusted our solutions, including enterprises such as in the financial services, retail and operational technology market verticals, communication and security service providers, government organizations and small and medium-sized businesses. As a global company headquartered in Sunnyvale, California with a large international customer base, the majority of our research and development is in the United States and Canada with a global footprint of support and centers of excellence around the world. As of December 31, 2023, we held 957 U.S. patents and 1,299 global patents and we are recognized in over 80 enterprise analyst reports demonstrating both our vision and execution across networking and security products.

  • Secure Networking**—Our Secure Networking solutions focus on the convergence of networking and security via our network firewall and our switches, access points and other secure connectivity solutions. FortiOS is our networking and security operating system that is consistent across our firewalls and secure connectivity solutions and supports over 30 functions that can be delivered via a physical, virtual, cloud or Software as a Service (“SaaS”) solution. When delivered via our network firewall appliances, functionality is accelerated through our proprietary Application-Specific Integrated Circuits (“ASIC”) technology. These proprietary ASICs, combined with off-the-shelf central processing units (“CPUs”) and ASICs, allow our systems to scale, run multiple applications at higher performance, lower power consumption and perform more processor-intensive operations, such as inspecting encrypted traffic, including streaming video. The Network Firewall solution consists of FortiGate data centers, hyperscale and distributed firewalls, as well as encrypted applications (secure sockets layer (“SSL”) inspection, Virtual Private Network and IPsec connectivity). Our ability to converge networking and security also enables the ethernet to become an extension of a company’s security infrastructure through FortiSwitch and FortiLink. Our wireless local area network (“LAN”) solution leverages secure networking to provide secure wireless access for the enterprise LAN edge. FortiExtender secures 5G/LTE and remote ethernet extenders to connect and secure any branch environment. The Secure Connectivity solution includes FortiSwitch Secure Ethernet Switches, FortiAP Wireless Local Area Network Access Points and FortiExtender 5G Connectivity Gateways, among other products.

  • Unified Secure Access Service Edge (SASE)**—As applications move to the cloud and work from anywhere becomes established, cloud delivery is needed to enable secure access to applications on any cloud. The Fortinet Unified SASE solution is a single-vendor SASE solution that includes Firewall, SD-WAN, Secure Web Gateway, Cloud Access Services Broker, Data Loss Prevention, Zero Trust Network Access and cloud security, including Web Application Firewalls, Virtualized Firewalls and Cloud-Native Firewalls, among other products. These functions are delivered through our FortiOS operating systems, which can deploy the full SASE stack through the cloud or on our ASIC-driven appliances. All functions can be managed through a unified management console.

  • Security Operations (SecOps)**—Fortinet’s Security Operations solutions comply with the National Institute of Standards and Technology (“NIST”) cybersecurity framework of identify, protect, detect, respond and recover, and are delivered as a platform that automates detection and response to accelerate discovery and remediation. The SecOps solution includes FortiAI generative AI assistant, FortiSIEM Security Information and Event Management, FortiSOAR Security Orchestration, Automation and Response, FortiEDR Endpoint Detection and Response, FortiXDR Extended Detection and Response, FortiMDR Managed Detection and Response Service, FortiNDR Network Detection and Response, FortiRecon Digital Risk Protection, FortiDeceptor Deception technology, FortiGuard SoCaaS, FortiSandbox Sandboxing Services and FortiGuard Incident Response Services, among other products.

FortiGuard Labs is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize machine learning and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers. FortiGuard Security Services are a suite of AI-powered security capabilities that are natively integrated as part of the Fortinet Security Fabric to deliver coordinated detection and enforcement across the entire attack surface. The portfolio consists of FortiGuard application security services, content security services, device security services, NOC/SOC security services and web security services.

FortiCare Technical Support Service is a per-device support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet capabilities. Global technical support is offered 24x7 with flexible add-ons, including enhanced Service Level Agreements (“SLAs”) and premium hardware replacement through in-

country depots. Organizations have the flexibility to procure different levels of service for different devices based on their availability needs. We offer three per-device support options tailored to the needs of our enterprise customers: FortiCare Premium, FortiCare Elite and FortiCare Essential. The FortiCare Elite service aims to provide 15-minute response times for key product families.

We also offer training services to our end-customers and channel partners through our training team and authorized training partners. We have also implemented a training certification program, Network Security Expert (“NSE”), to help ensure an understanding of our products and services. Since 2020, Fortinet has also offered a number of free online training courses to help address prevalent industry-wide cybersecurity skills gaps and shortages.

During the year ended December 31, 2023, we generated total revenue of $5.30 billion and net income of $1.15 billion. See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, 2023 and 2022 and our consolidated statements of income, comprehensive income, equity (deficit), and cash flows for each of the three years ended December 31, 2023, 2022 and 2021.

We were incorporated in Delaware in November 2000. Our principal executive office is located at 909 Kifer Road, Sunnyvale, California 94086 and our telephone number at that location is (408) 235-7700.

Industry Background: The Trends Driving the Need for a Platform Approach

Modern networks are increasingly complex, spanning many edges as well as a mix of cloud and on-premises deployments. Fortinet was founded with the mission of providing a converged networking and security approach that empowers organizations to adopt new technologies without worrying about how it would impact their ability to manage and secure their environments. The escalating threat landscape has resulted in a significant increase in the demand for secure networking solutions. In fact, we believe the demand for secure networking will overtake the pure networking market by 2030. At the same time, businesses contend with an escalating threat landscape, a cybersecurity skills shortage, and siloed security tools that do not work well together. They need to consolidate point products to gain better visibility and faster threat response times.

A platform approach–what we call the Fortinet Security Fabric–has emerged to address these challenges and support enterprises in reducing complexity and improving risk mitigation. The concept of an integrated cybersecurity platform that converges networking and security and consolidates point products is what guides how we design our products and advise our customers and partners.

Customers

Our end-customers are located in over 100 countries and include small, medium and large enterprises and government organizations across a wide range of industries, including financial services, government, manufacturing, retail, technology, education, healthcare and telecommunications. An end-customer deployment may involve as few as one or as many as dozens of different types of integrated products and services from across our broad portfolio that spans secure networking, unified SASE, and security operations. Customers may also access our products via the cloud through certain cloud providers such as Amazon Web Services, Microsoft Azure and Google Cloud. Often, our customers also purchase our FortiGuard security subscription services and FortiCare technical support services. Refer to Note 16 Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers that accounted for 10% or more of our revenue or net accounts receivable.

Sales and Marketing

We primarily sell our products and services through a two-tier distribution model. We sell to distributors that sell to resellers and to service providers and managed security service providers (“MSSPs”), who, in turn, sell products and/or services to end-customers. In certain cases, we sell directly to large service providers and major systems integrators. We work with many technology distributors, including Arrow Electronics, Inc., Exclusive, Ingram Micro and TD Synnex (formerly Tech Data Corporation and Synnex Corporation, separately). In addition, we provide our cloud-based subscription offerings through Fortinet-owned data centers, as well as data centers operated under co-location arrangements globally, and via public cloud providers.

We support our channel partners with a dedicated team of experienced channel account managers, sales professionals and sales engineers who provide business planning, joint marketing strategy, pre-sales and operational sales support. Additionally, our sales teams help drive and support large enterprise and service provider sales through a direct touch model. Our sales professionals and engineers typically work closely with our channel partners and directly engage with large end-customers to address their unique security and deployment requirements. To support our broadly dispersed global channel and end-customer base, we have sales professionals in over 100 countries around the world.

Our marketing strategy is focused on building our brand, driving thought leadership with emphasis on the criticality of cybersecurity platform adoption and the convergence of security and networking as well as driving end-customer demand for our security solutions. We use a combination of internal marketing professionals and a network of regional and global channel partners. Our internal marketing organization is responsible for messaging, branding, demand generation, product marketing, channel marketing, partner incentives and promotions, event marketing, digital marketing, communications, analyst relations, public relations, and sales enablement. We focus our resources on campaigns, programs, and activities that can be leveraged by partners worldwide to extend our marketing reach, such as sales tools and collateral, product awards and technical certifications, media engagement, training, regional seminars and conferences, webinars, and various other demand-generation activities.

Manufacturing and Suppliers

We outsource the manufacturing of our security appliance products to a variety of contract manufacturers and original design manufacturers. Our current manufacturing partners include ADLINK Technology, Inc. (“ADLINK”), IBASE Technology, Inc. (“IBASE”), Micro-Star International Co. (“Micro-Star”), Senao Networks, Inc. (“Senao”), Wistron Corporation (“Wistron”), and a number of other manufacturers. Approximately 95% of our hardware is manufactured in Taiwan. We submit purchase orders to our contract manufacturers that describe the type and quantities of our products to be manufactured, the delivery date and other delivery terms. Once our products are manufactured, they are sent to either our warehouse in California or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed. We believe that outsourcing our manufacturing and a substantial portion of our logistics enables us to focus resources on our core competencies. Our proprietary ASICs, which are key to the performance of our appliances, are built by contract manufacturers including Toshiba America Electronic Components, Inc. (“Toshiba America”) and Renesas Electronics America, Inc. (“Renesas”). These contract manufacturers use foundries in Taiwan and Japan operated by either Taiwan Semiconductor Manufacturing Company Limited (“TSMC”) or by the contract manufacturer itself.

The components included in our products are sourced from various suppliers by us or, more frequently, by our contract manufacturers. Some of the components important to our business, including certain CPUs from Intel Corporation (“Intel”) and Advanced Micro Devices, Inc. (“AMD”), network and wireless chips from Broadcom Inc. (“Broadcom”), Marvell Technology Group Ltd. (“Marvell”), Qualcomm Incorporated (“Qualcomm”) and Intel and memory devices from Intel, Micron Technology (“Micron”), ADATA Technology Co., Ltd. (“ADATA”), Toshiba Corporation (“Toshiba”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from limited or sole sources of supply.

We have no long-term contracts related to the manufacturing of our ASICs or other components that guarantee any capacity or pricing terms.

Research and Development

We focus our research and development efforts on developing new hardware and software products and services, and adding new features to existing products, services and operating systems. Our development strategy is to identify features, products and systems for both software and hardware that are, or are expected to be, important to our end-customers. Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including identification of market demand for new products or new features, components selection, timely implementation of product design and development, product performance, quality, ease of use, costs of development, bill of materials, effective manufacturing and assembly processes and sales and marketing.

Intellectual Property

We rely primarily on patent, trademark, copyright and trade secrets laws, confidentiality procedures and contractual provisions to protect our technology. We periodically have discussions with third parties regarding licensing Fortinet’s intellectual property (“IP”) and have sometimes taken legal action against competitors to protect our IP, and as a result third parties have paid us fees in return for licenses or covenants-not-to-sue related to Fortinet IP. As of December 31, 2023, we had 1,299 U.S. and foreign-issued patents and 252 pending U.S. and foreign patent applications. We also license software from third parties for inclusion in our products, including open source software and other software.

Despite our efforts to protect our rights in our technology, unauthorized parties may attempt to copy aspects of our products or obtain and use information and technology that we regard as proprietary. We generally enter into confidentiality agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot provide assurance that the steps we take will prevent misappropriation of our technology. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws

of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other IP rights. Third parties have asserted, are currently asserting and may in the future assert patent, copyright, trademark or other IP rights against us, our channel partners or our end-customers. Successful claims of infringement by a third-party could prevent us from distributing certain products or performing certain services or require us to pay substantial damages (including treble damages if we are found to have willfully infringed patents or copyrights), royalties or other fees. Even if third parties offer a license to their technology, the terms of any offered license may not be acceptable and the failure to obtain a license or the costs associated with any license could cause our business, operating results or financial condition to be materially and adversely affected. In certain instances, we indemnify our end-customers, distributors and resellers against claims that our products infringe the IP of third parties.

Government Regulation

We are subject to regulation by various federal, state, regional, local and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, security, product safety, product labeling, environmental laws, consumer protection laws, anti-bribery laws, data privacy laws, import and export controls, federal securities laws and tax laws and regulations. Many of the laws and regulations that are or may be applicable to our business are changing or being tested in courts and could be interpreted in ways that could adversely impact our business. In addition, the application and interpretation of these laws and regulations often are uncertain, particularly in the industry in which we operate. We believe we take reasonable steps designed to ensure we are in compliance with current laws and regulations and do not expect continued compliance to have a material impact on our capital expenditures, earnings, or competitive position. We continue to monitor existing and pending laws and regulations and while the impact of regulatory changes cannot be predicted with certainty, we do not currently expect compliance to have a material adverse effect.

Seasonality

For information regarding seasonality in our sales, see the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Seasonality, Cyclicality and Quarterly Revenue Trends” in Part II, Item 7 of this Annual Report on Form 10-K.

Competition

The markets for our products are extremely competitive and are characterized by rapid technological change. The principal competitive factors in our markets include:

  • product security performance, throughput, features, effectiveness, interoperability and reliability;

  • addition and integration of new networking and security features and technological expertise;

  • compliance with industry standards and security and other certifications;

  • price of products and services and total cost of ownership;

  • brand recognition;

  • customer service and support across varied and complex customer segments and use cases;

  • sales and distribution capabilities;

  • size and financial stability;

  • breadth of product line;

  • form factor of the solution; and

  • other competitive differentiators.

Among others, our competitors include Aruba Networks, Inc. (“Aruba”), Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), CrowdStrike Holdings, Inc. (“CrowdStrike”), F5 Networks, Inc. (“F5 Networks”), Huawei Technologies Co., Ltd. (“Huawei”), Juniper Networks, Inc. (“Juniper”), Palo Alto Networks, Inc. (“Palo Alto Networks”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc (“Sophos”), VMware, Inc. (“VMware”) and Zscaler, Inc. (“Zscaler”).

We believe we compete favorably based on our products’ security performance, throughput, reliability, breadth and ability to work together, our ability to add and integrate new networking and security features and our technological expertise. Several competitors are significantly larger, have greater financial, technical, marketing, distribution, customer support and other resources, are more established than we are, and have significantly better brand recognition. Some of these larger competitors have substantially broader product offerings and leverage their relationships based on other products or incorporate

functionality into existing products in a manner that discourages users from purchasing our products. Based in part on these competitive pressures, we may lower prices or attempt to add incremental features and functionalities to our products.

Conditions in our markets could change rapidly and significantly as a result of technological advancements, market consolidation, supply chain constraints, price list or discount changes or inflation. The development and market acceptance of alternative technologies could decrease the demand for our products or render them obsolete. Our competitors may introduce products that are less costly, provide superior performance, are better marketed, or achieve greater market acceptance than our products. Additionally, our larger competitors often have broader product lines and are better positioned to withstand a significant reduction in capital spending by end-customers, and will therefore not be as susceptible to downturns in a particular market. The above competitive pressures are likely to continue to impact our business. We may not be able to compete successfully in the future, and competition may harm our business.

Human Capital Management

As of December 31, 2023, our total headcount was 13,568 employees, approximately 30% of whom were employed in the United States and approximately 70% of whom were employed outside of the United States.

Our employees are the foundation of our innovation and cybersecurity leadership for the benefit of our customers. We understand there is a shortage of highly skilled employees for security companies like ours, and we believe that our success and competitive advantage depends largely on our ability to continue to attract and retain highly skilled employees with diverse backgrounds and experiences. We believe we offer fair, competitive compensation and benefits, and we encourage a culture of fairness and meritocracy. Our compensation programs for our employees include base pay, incentive compensation, opportunities for equity ownership where local statutes allow and employee benefits that promote well-being across different aspects of our employees’ lives, which may include health and welfare insurance, retirement benefits and paid time off.

As a global company, much of our success is rooted in the diversity of our teams and our commitment to diversity, equity and inclusion (“DEI”). Such commitment starts at the top, with a highly skilled and diverse board of directors. As of December 31, 2023, women represented 25% of the members of our board of directors, and approximately 50% of our board of directors was from underrepresented communities. We value diversity at all levels and continue to focus on enhancing our DEI initiatives across our workforce.

We are also committed to community engagement and social responsibility with regards to our employees and beyond, and our board of directors has active oversight of such initiatives. Examples of our initiatives focused on our employees include our company matching program for employee charitable contributions and the free security training programs we offer to help with career development for our employees, in addition to the general public.

Our culture is defined by our commitment to ethics and integrity. We reinforce our ethical “tone at the top” through clear policies including our Code of Business Conduct and Ethics, regular compliance training for our employees, quarterly meetings of our cross-functional Ethics Committee, clear messaging from our executives, enforcement of company policies and oversight by our board of directors. In addition, our Chief Executive Officer regularly communicates the importance of Fortinet’s core values of openness, teamwork and innovation.

None of our U.S. employees are represented by a labor union. Our employees in certain European and Latin American countries, however, have the right to be represented by external labor organizations if they maintain up-to-date union membership. We have not experienced any work stoppages, and we consider our relations with our employees to be good.

Environmental, Social and Governance

We are committed to responsible environmental, social and governance (“ESG”) practices and having a positive impact on the sustainability of our society and planet. Fortinet is a member of the Dow Jones Sustainability Indices — World and North America, for the second consecutive year. Our approach to ESG is based on a strong corporate governance structure, starting with the Social Responsibility Committee of our board of directors, which provides oversight of our Corporate Social Responsibility (“CSR”) strategy, initiatives and execution related to ESG matters. Our senior leadership sponsors the integration of CSR priorities throughout our business operations. In addition, our CSR team, along with our internal cross-functional employee CSR Committee, engage with internal and external stakeholders to lead CSR execution, communications and disclosure.

Environmental. We recognize that environmental considerations such as climate change, resource scarcity and the energy crisis are top priorities for the future of our planet. We are committed to helping address climate change impacts and minimizing the environmental footprint of our solutions, operations and our broader value chain. We are engaged on a

decarbonization path to reach net zero for our Scope 1 and Scope 2 emissions by 2030, and formally signed on to the Science-Based Target Initiative commitment in September 2022. In 2023, we obtained the ISO14001 certification for our largest company-owned warehouse in Union City, California, and have continued to be a leader on energy efficiency with the launch of our SP5 ASIC and our FortiGate-90G model. We submitted our survey on environment to CDP, which is a not-for-profit charity organization that runs the global disclosure system for companies to manage their environmental impacts. We also disclosed for the first time our Scope 3 emissions, across all 12 relevant categories, as part of our annual reporting on sustainability.

Social. We are committed to building an inclusive, equitable and diverse workforce within our organization and across the security industry to help empower individuals to reach their full potential. We continue to focus on skilling, upskilling and reskilling individuals and are on track to reach our goal of training one million people in cybersecurity by 2026 with over 430,000 individuals trained as of the end of 2023. As part of our Education Outreach Program, which focuses on creating a more diverse cybersecurity talent pool, we launched the Veterans Program Advisory Council to help build on the Veterans Program's success in providing more cybersecurity training pathways for military veterans across the United States, the United Kingdom, Canada, Australia and New Zealand. We offered our Security Awareness Curriculum at no cost to primary and secondary schools across the same countries. We continued to expand partnerships with educational institutions and now have over 650 Authorized Academic Partners in 99 countries or territories across the world. Internally, we continue to foster a culture of diversity and inclusion through our DEI Council, which meets quarterly, Employee Resource Groups and various campaigns and activities that engage our broader workforce.

Governance. Our approach to responsible business is based on strong corporate governance practices that aim to ensure accountability while meeting our responsibilities across our value chain, starting with our employees. Our board of directors regularly reviews our governance practices. Our Codes of Conduct apply to employees, partners and suppliers, and we have compliance trainings and controls in place. In 2023, we established a risk management committee and steering committee to further enhance our anti-corruption program and we employ a thorough screening process for partners and suppliers, including continuous monitoring in high-risk zones, and resolution process for risk mitigation.

Available Information

Our web site is located at https://www.fortinet.com, and our investor relations web site is located at https://investor.fortinet.com. The information posted on our website is not incorporated by reference into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Act of 1933, as amended (the “Securities Act”), are available free of charge on our investor relations web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC”). You may also access all of our public filings through the SEC’s website at https://www.sec.gov.

We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations website. Additionally, we provide notifications of news or announcements regarding our financial performance, including SEC filings, investor events and press and earnings releases, as part of our investor relations website. The contents of these websites are not intended to be incorporated by reference into this report or in any other report or document we file.

Previous: Cover and table of contents · Next: Item 1A. Risk Factors