Fortinet 10-K 2024-12-31

Filed 2025-02-21. 24 sections, 571K characters. Original on sec.gov · Markdown · JSON

What changed since the 2023-12-31 10-KNew, removed and reworded risk factor headings, then every item sentence by sentence.

Cover and table of contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

FORM 10-K

(Mark One)

☒ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the year ended December 31, 2024

or

☐TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from to

Commission file number: 001-34511


FORTINET, INC.

(Exact name of registrant as specified in its charter)


Delaware77-0560389
(State or other jurisdiction of incorporation or organization)(I.R.S. Employer Identification No.)

909 Kifer Road

Sunnyvale, California 94086

(Address of principal executive offices, including zip code)

(408) 235-7700

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each classTrading SymbolName of each exchange on which registered
Common Stock, $0.001 Par ValueFTNTThe Nasdaq Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 (“Exchange Act”) during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer☒Accelerated filer☐
Non-accelerated filer☐Smaller reporting company☐
Emerging growth company☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Exchange Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of voting stock held by non-affiliates of the registrant, as of June 30, 2024, the last business day of the registrant’s most recently completed second quarter, was $31,496,083,015 (based on the closing price for shares of the registrant’s common stock as reported by The Nasdaq Global Select Market on that date). Shares of common stock held by each executive officer, director, and holder of 5% or more of the registrant’s outstanding common stock have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.

As of February 18, 2025, there were 768,974,062 shares of the registrant’s common stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the registrant’s definitive Proxy Statement relating to its 2025 Annual Meeting of Stockholders (“Proxy Statement”) are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated. Such Proxy Statement will be filed with the United States Securities and Exchange Commission within 120 days after the end of the fiscal year to which this report relates.

FORTINET, INC.

ANNUAL REPORT ON FORM 10-K

For the Year Ended December 31, 2024

Table of Contents

Page
Risk Factor Summary1
Part I
Item 1.Business3
Item 1A.Risk Factors11
Item 1B.Unresolved Staff Comments46
Item 1C.Cybersecurity46
Item 2.Properties49
Item 3.Legal Proceedings49
Item 4.Mine Safety Disclosures49
Part II
Item 5.Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities50
Item 6.[Reserved]52
Item 7.Management’s Discussion and Analysis of Financial Condition and Results of Operations53
Item 7A.Quantitative and Qualitative Disclosures about Market Risk72
Item 8.Financial Statements and Supplementary Data73
Item 9.Changes in and Disagreements with Accountants on Accounting and Financial Disclosure113
Item 9A.Controls and Procedures113
Item 9B.Other Information115
Item 9C.Disclosure Regarding Foreign Jurisdictions that Prevents Inspections115
Part III
Item 10.Directors, Executive Officers and Corporate Governance116
Item 11.Executive Compensation116
Item 12.Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters116
Item 13.Certain Relationships and Related Transactions, and Director Independence116
Item 14.Principal Accounting Fees and Services116
Part IV
Item 15.Exhibits and Financial Statement Schedules117
Exhibit Index118
Item 16.Form 10-K Summary120
Signatures121

Summary of Risk Factors

Our business is subject to numerous risks and uncertainties, including those described in Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K. You should carefully consider these risks and uncertainties when investing in our common stock. Some of the principal risks and uncertainties include:

  • Our operating results are likely to vary significantly and be unpredictable.

  • Adverse economic conditions, such as a possible economic downturn or recession, and possible impacts of inflation or stagflation, tariffs or other trade disruptions, changing interest rates, changes in government spending or regulation or reduced information technology (“IT”) spending, including firewall spending, may adversely impact our business.

  • We have been, and may in the future be, susceptible to supply chain constraints, supply shortages and disruptions, long or less predictable lead times for components and finished goods and supply changes because some of the key components in our products come from limited sources of supply.

  • As a result of supply chain disruptions in previous periods, we increased our purchase order commitments in previous periods and, were in some instances required to and may in the future be required to accept or pay for components and finished goods regardless of our level of sales in a particular period, which may negatively or unpredictably impact our operating results and financial condition.

  • Our billings, revenue, and free cash flow growth may slow or may not continue to grow, and our operating margins may decline.

  • Our real estate assets, including construction, acquisitions, leasing activity, and ongoing maintenance and management of office buildings, warehouses, data centers and points of presence (“PoPs”), as well as data center expansions or enhancements, could involve significant risks to our business.

  • Our backlog may fluctuate over quarters. If we experience supply chain shortages and cannot fulfill orders or if customers cancel or delay delivery of orders, our backlog may be affected, which will negatively impact our aggregate backlog to billings conversion and revenue in such quarter. A reduction to backlog increases our aggregate billings and revenue during the quarter when delivered.

  • As the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings. For the fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates.

  • Any weakness in sales strategy, productivity, personnel and execution could negatively impact our results of operations.

  • We are dependent on the continued services and performance of our senior management, as well as our ability to hire, retain and motivate qualified personnel.

  • We rely on third-party channel partners for substantially all of our billings, revenue, and a small number of distributors represents a large percentage of our revenue and accounts receivable.

  • Reliance on a concentration of shipments at the end of the quarter or changes in shipping terms could cause our billings and revenue to fall below expected levels.

  • We rely significantly on revenue from FortiGuard and other security subscriptions and FortiCare technical support services, and revenue from these services may decline or fluctuate.

  • We face intense competition in our market and we may not maintain or improve our competitive position.

  • We are susceptible to defects or vulnerabilities, including critical vulnerabilities, in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities, including critical vulnerabilities, in our products or services, failure of our products or services to detect or prevent a security incident or to cause a disruption to operations, failure of our customers to implement preventative actions such as updates to one of our deployed solutions or failure to help secure our customers, could cause our products or services to allow unauthorized access to our customers’ networks and harm our operational results and reputation more significantly as compared to other companies. Our Product Security Incident Response

Team publicly posts on our FortiGuard Labs website known product vulnerabilities, including critical vulnerabilities, and methods for customers to mitigate the risk of vulnerabilities. However, there can be no assurance that such posts will be sufficiently timely, accurate or complete or that those customers will see such posts or take steps to mitigate the risk of vulnerabilities, and certain customers may be negatively impacted.

  • If our internal enterprise IT networks, our operational networks, our research and development (“R&D”) networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted.

  • We have incurred indebtedness and may incur other debt in the future, which may adversely affect our financial condition and future financial results.

  • We generate a majority of billings, revenue and cash flow from sales outside of the United States.

  • We may not be successful in executing our strategy to increase our sales to large- and medium-sized end-customers.

  • A portion of our revenue is generated by sales to government organizations and other customers, which are subject to a number of regulatory requirements, their own supply chain constraints and contractual requirements, challenges and risks.

  • We order components from third-party manufacturers based on our forecasts of future demand and targeted inventory levels, which exposes us to the risk of product shortages, may result in lost sales, higher expenses and inventory excesses which may lead to inventory charges and costs related to future purchase commitments, possibly requiring us to sell our products at discounts or offer various other incentives.

  • We depend on third parties to provide various components for our products and build our products and are susceptible to manufacturing delays, capacity constraints, cost increases, and changes in the geopolitical environment.

  • Our inability to successfully acquire and integrate other businesses, products or technologies, or to successfully invest in and form successful strategic alliances with other businesses, could seriously harm our competitive position and could negatively affect our financial condition and results of operations.

  • Investors’, activists’ and regulators’ expectations of our investments and performance relating to environmental, social and governance factors may impose additional costs and expose us to new risks.

  • We are exposed to fluctuations in currency exchange rates, which could negatively affect our financial condition and results of operations.

  • Our proprietary rights may be difficult to enforce and we may be subject to claims by others that we infringe their proprietary technology.

  • The trading price of our common stock may be volatile, which volatility may be exacerbated by share repurchases under our Share Repurchase Program (the “Repurchase Program”).

  • Anti-takeover provisions contained in our certificate of incorporation and bylaws, as well as provisions of Delaware law, could impair a takeover attempt.

  • Global economic uncertainty can weaken and harm our financial position.

  • Weakening product demand caused by political instability, changes in trade agreements, wars and foreign conflicts, such as the war in Ukraine or tensions between China and Taiwan, could adversely affect our business and financial performance.

Part I

Item 1. Business

Overview

Fortinet is a leader in cybersecurity, driving the convergence of networking and security. Our mission is to secure people, devices and data everywhere. Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified Secure Access Service Edge (“SASE”) and artificial intelligence (“AI”)-driven security operations (“SecOps”). As of December 31, 2024, our end-customers were located in over 100 countries and included enterprises across a wide variety of market verticals, including financial services, retail, healthcare and operational technology (“OT”) market verticals, communication and security service providers, and government organizations. As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies. We were also ranked #7 in the Forbes Most Trusted Companies list in 2024. As a global company headquartered in Sunnyvale, California, our research and development is centered in the United States and Canada with a global footprint of support and centers of excellence around the world. As of December 31, 2024, we held 1,034 U.S. patents and 1,378 global patents and we have been recognized in over 140 enterprise analyst reports demonstrating both our vision and execution across security and networking products.

Our competitive differentiation lies in our core technologies, which together provide performance, security, flexibility and integration across diverse environments.

  • FortiOS**—FortiOS enables the convergence of security and networking to enforce consistent security policies across form factors and edges. As the foundation of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and analytics for comprehensive network visibility and control at scale. To further validate our strategy, FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, Software-Defined Wide-Area Network (“SD-WAN”), Security Service Edge (“SSE”), SASE Platforms and Wired and Wireless Local Area Network (“LAN”).

  • FortiASIC**—Our Application-Specific Integrated Circuit (“ASIC”)-based security processing units (“SPUs”) increase the speed, scale, efficiency and value of our solutions while improving user experience, reducing footprint and power requirements. From branch and campus to data center solutions, SPU-powered Fortinet appliances deliver superior Security Compute Ratings versus industry alternatives.

  • FortiCloud**—Our organically built global cloud infrastructure, powered by FortiStack which is our secure software as a service (“SaaS”) platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all layers, provides customers with global reach, flexible connectivity, and cost savings.

  • FortiAI**—Our AI innovations encompass generative AI (“GenAI”), big data AI for threat intelligence to process and analyze trillions of events using AI/Machine Learning (“ML”), network operations AI for self-healing networks and automated network orchestration, automation and response, and AI for Large Language Model (“LLM”) leakage to protection against data leakage into LLMs. Our GenAI assists security teams to make better decisions, rapidly respond to threats and save time on even the most complex tasks. FortiAI is seamlessly integrated into the user experience of several of our products, including FortiAnalyzer, FortiSIEM and FortiSOAR, to help optimize threat investigation and response, Security information and event management (“SIEM”) queries, Security, orchestration, automation, and response (“SOAR”) playbook creation, among other functions.

  • FortiEndpoint**—FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and extended detection and response (“XDR”), into a single agent. It simplifies management and enhances visibility while reducing costs and complexity. The solution gives IT teams the visibility and control they need, while security teams benefit from automated threat detection and response. This minimizes the need for manual intervention and provides faster remediation of threats across all environments.

  • OT Security**—The Fortinet Security Fabric enables security for converged IT/OT ecosystems. It also provides an OT Security Platform with features and products to extend Security Fabric capabilities to OT networks in factories, plants, remote locations and ships. To help alleviate security risks across the organization, we have continued to enhance our OT Security Platform offerings. These innovations range from edge products to Network Operations Center (“NOC”) and Security Operations Center (“SOC”) tools and services to provide effective and efficient networking and cybersecurity performance and operation.

These competitive differentiators allow us to provide Chief Information Officer (“CIO”)s, Chief Information Security Officer (“CISO”)s, Chief Technology Officer (“CTO”)s, and their organizations with an integrated AI-driven cybersecurity platform with over 50 products across three solution pillars.

  • Secure Networking**—Our Secure Networking solutions focus on the convergence of networking and security via FortiOS, our networking and security operating system that is the foundation of our Fortinet Security Fabric platform and supports over 30 functions that can be delivered via a physical, virtual, cloud or software as a SaaS solution. When delivered through our network firewall appliances, functionality is accelerated through our proprietary ASIC technology. These proprietary ASICs, allow our systems to scale, run multiple applications at higher performance, lower power consumption and perform more processor-intensive operations, such as inspecting encrypted traffic, including streaming video. Our network firewall offerings consist of a FortiGate data center, hyperscale and distributed firewalls, as well as encrypted applications (secure sockets layer (“SSL”) inspection, virtual private network and Internet Protocol Security (“IPsec”) connectivity). Our ability to converge networking and security also enables the ethernet to become an extension of our customers’ security infrastructure through FortiSwitch and FortiLink. Our wireless LAN solution leverages secure networking to provide secure wireless access for the enterprise LAN edge. FortiExtender secures 5G/LTE and remote ethernet extenders to connect and secure any branch environment. Our Secure Connectivity solution includes FortiSwitch secure ethernet switches, FortiAP wireless local area network access points and FortiExtender 5G connectivity gateways.

  • Unified Secure Access Service Edge (SASE)**—As applications move to the cloud and hybrid workforce is now the norm, enabling secure access for users with zero trust framework becomes important. The Fortinet Unified SASE solution includes a single-vendor SASE solution that includes firewall, SD-WAN, secure web gateway, cloud access services broker, Data Loss Prevention (“DLP”) and zero trust network access to deliver flexible secure access for all users. We are one of the few vendors to deliver consistent convergence and AI-powered security across Secure SD-WAN and SSE to enable a single-vendor SASE framework with a cloud-centric architecture powered by FortiOS. Our global and scalable cloud network includes 150+ points of presence to deliver the seamless secure access experience. Given this, we are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform. Additionally, we offer a full suite of comprehensive, integrated cloud security solutions that enable customers to secure their applications from code to cloud. Our solutions include application security that includes our web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application protection and code security. We deliver a holistic approach to cloud security, offering a single unified platform for cloud security and secure Continuous Integration/Continuous Delivery (“CI/CD”) application development needs, consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and multi-clouds, and delivering AI-driven security across integrated solutions with visibility and context across hybrid and multi-cloud. Additionally, we also offer flexible consumption licensing programs that enable organizations to dynamically optimize their cloud security needs and investments as well as readily meet their cloud minimum spend commitment obligations with Cloud Service Providers.

  • AI-Driven Security Operations (SecOps)**—Our AI-Driven SecOps portfolio provides a comprehensive suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric. At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that provides built-in SIEM, SOAR, XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control. FortiSIEM delivers robust security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response. This solution set also includes FortiEDR, FortiXDR, FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications. To bolster their security posture, organizations contending with staff shortages can tap into FortiGuard services, including SOC-as-a-Service (“SOCaaS”), Managed detection and response (“MDR”), Security Posture Assessment and Incident Response. Finally, FortiAI generative AI assistance streamlines operations, helping security teams stay ahead of an ever-evolving threat landscape.

FortiGuard Labs is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize machine learning and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers. Using millions of global network sensors, FortiGuard Labs monitors the worldwide attack surface and employs AI to mine that data for new threats.

FortiGuard and Other Security Services are a suite of AI-powered security capabilities that are natively integrated as part of the Fortinet Security Fabric to deliver coordinated detection and enforcement across the entire attack surface. The portfolio consists of FortiGuard application security services, content security services, device security services, NOC/SOC security services and web security services.

FortiCare Technical Support Service is a per-device technical support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet capabilities. Global technical support is offered 24x7 with flexible add-ons, including enhanced service-level agreements (“SLAs”) and priority hardware replacement through in-country and local depots. Organizations have the flexibility to procure different levels of service for different devices based on their availability needs. We offer three per-device support options tailored to the needs of our enterprise customers: FortiCare Elite, FortiCare Premium and FortiCare Essential. The FortiCare Elite service aims to provide a 15-minute response time for key product families.

In addition to FortiCare device level services, Advanced Support service options are available per account. These services are available for regional account support in three options: Core, Pro and Pro Plus, and can be globalized at the Pro and Pro Plus levels. Advanced Support brings support directly to each account, helping account holders to make their operations more effective and to plan and manage their solution lifecycle.

Additionally, we are committed to addressing the cybersecurity skills shortage through training and certification programs for customers, partners and employees. The Fortinet Training Institute’s ecosystem of public and private partnerships around the world extend to industry, academia, government and nonprofits to ensure we are reaching and increasing access of our cybersecurity certifications and training to all populations. The Fortinet Training Institute has issued over one million certifications to date.

During the year ended December 31, 2024, we generated total revenue of $5.96 billion and net income of $1.75 billion. See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, 2024 and 2023 and our consolidated statements of income, comprehensive income, equity (deficit), and cash flows for each of the three years ended December 31, 2024, 2023 and 2022.

We were incorporated in Delaware in November 2000. Our principal executive office is located at 909 Kifer Road, Sunnyvale, California 94086 and our telephone number at that location is (408) 235-7700.

Industry Background: The Trends Driving the Need for a Platform Approach

Modern networks are increasingly complex, spanning many edges as well as a mix of cloud and on-premises deployments. We were founded with the mission of providing a converged networking and security approach that empowers organizations to adopt new technologies without worrying about how it would impact their ability to manage and secure their environments. The escalating threat landscape has resulted in a significant increase in the demand for secure networking solutions. In fact, we believe the demand for secure networking will overtake the pure networking market by 2030. At the same time, businesses contend with an escalating threat landscape, a cybersecurity skills shortage, and siloed security tools that do not work well together. They need to consolidate point products to gain better visibility and faster threat response times.

A platform approach–what we call the Fortinet Security Fabric–has emerged to address these challenges and support enterprises in reducing complexity and improving risk mitigation. The concept of an integrated cybersecurity platform that converges networking and security and consolidates point products is what guides how we design our products and advise our customers and partners.

As organizations continue to modernize their cybersecurity infrastructure, we anticipate a significant firewall refresh and upgrade cycle in the coming years. Given our platform approach, this refresh presents a strategic opportunity to expand our footprint within existing customer environments. By leveraging our integrated security and networking capabilities, we can drive opportunities across our broader portfolio, including LAN, SD-WAN, SASE, Cloud-Native Application Protection Platform (“CNAPP”) and SecOps solutions. With a unified management console, we enable consistent security policies, simplified operations, and an improved user experience across on-premises, cloud, and hybrid deployments. This approach strengthens security effectiveness and helps reduce complexity and total cost of ownership.

Customers

Our end-customers are located in over 100 countries and include small, medium and large enterprises and government organizations across a wide range of industries, including financial services, government, manufacturing, retail, technology, education, healthcare and telecommunications. An end-customer deployment may involve as few as one or as many as dozens of different types of integrated products and services from across our broad portfolio that spans secure networking, unified SASE, and security operations. Depending on the solution or form factor purchased, customers may also access our products via the cloud through our data centers and PoPs, third-party colocations and cloud providers such as Amazon Web Services, Microsoft Azure and Google Cloud. Often, our customers also purchase our FortiGuard and other security subscription services and FortiCare technical support services. Refer to Note 16 Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers accounted for 10% or more of our revenue or net accounts receivable.

Sales and Marketing

We primarily sell our products and services through a two-tier distribution model. We sell to distributors that sell to resellers and to service providers and managed security service providers (“MSSPs”), who, in turn, sell products and/or services to end-customers. In certain cases, we sell directly to large service providers, major systems integrators and large end users. We work with many technology distributors, including Arrow Electronics, Inc., Exclusive, Ingram Micro, and TD Synnex. In addition, we provide our cloud-based subscription offerings through Fortinet-owned data centers and PoPs, as well as data centers operated under colocation arrangements globally, and via public cloud providers.

We support our channel partners with a dedicated team of experienced channel account managers, sales professionals and sales engineers who provide business planning, joint marketing strategy, pre-sales and operational sales support. Additionally, our sales teams help drive and support large enterprise and service provider sales through a direct touch model. Our sales professionals and engineers typically work closely with our channel partners and directly engage with large end-customers to address their unique security and deployment requirements. To support our broadly dispersed global channel and end-customer base, we have sales professionals in over 100 countries around the world.

Our marketing strategy is focused on building our brand, driving thought leadership with emphasis on the criticality of cybersecurity platform adoption and the convergence of security and networking as well as driving end-customer demand for our security solutions. We use a combination of internal marketing professionals and our network of regional and global channel partners. Our internal marketing organization is responsible for messaging, branding, demand generation, product marketing, channel marketing, partner incentives and promotions, event marketing, digital marketing, communications, analyst relations, public relations, and sales enablement. We focus our resources on campaigns, programs, and activities that can be leveraged by partners worldwide to extend our marketing reach, such as sales tools and collateral, product awards and technical certifications, media engagement, training, regional seminars and conferences, webinars, and various other demand-generation activities.

Manufacturing and Suppliers

We outsource the manufacturing of our security appliance products to a variety of contract manufacturers and original design manufacturers. Our current manufacturing partners include Accton Technology (“Accton”), IBASE Technology, Inc. (“IBASE”), Micro-Star International Co. (“Micro-Star”), Senao Networks, Inc. (“Senao”), Wistron Corporation (“Wistron”), and a number of other manufacturers. Approximately 88% of our hardware is manufactured in Taiwan. We submit purchase orders to our contract manufacturers that describe the type and quantities of our products to be manufactured, the delivery date and other delivery terms. Once our products are manufactured, they are sent to either our warehouse in California or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed. We believe that outsourcing our manufacturing and a substantial portion of our logistics enables us to focus resources on our core competencies. Our proprietary ASICs, which are key to the performance of our appliances, are built by contract manufacturers including Toshiba America Electronic Components, Inc. (“Toshiba America”) and Renesas Electronics America, Inc. (“Renesas”). These contract manufacturers use foundries in Taiwan and Japan operated by either Taiwan Semiconductor Manufacturing Company Limited (“TSMC”) or by the contract manufacturer itself.

The components included in our products are sourced from various suppliers by us or, more frequently, by our contract manufacturers. Some of the components important to our business, including certain Central Processing Units (“CPUs”) from Intel Corporation (“Intel”) and Advanced Micro Devices, Inc. (“AMD”), network and wireless chips from Broadcom Inc. (“Broadcom”), Marvell Technology Group Ltd. (“Marvell”), Qualcomm Incorporated (“Qualcomm”) and Intel and memory devices from Intel, Micron Technology (“Micron”), ADATA Technology Co., Ltd. (“ADATA”), Toshiba Corporation (“Toshiba”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from limited or sole sources of supply.

We have no long-term contracts related to the manufacturing of our ASICs or other components that guarantee any capacity or pricing terms.

Our supply chain plays a critical role in providing safety for our customers and protection for our brand. Supply chain security management begins with the establishing control of a qualified supplier base, which provides qualified and trusted components for use in design, development, manufacturing and post-sale product support.

Our Trusted Supplier Program (“TSP”) was developed in accordance with the requirements defined in National Institute of Standards and Technology Special Publications (“NIST SP”) 800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations and other directives as periodically established by the U.S. government for

securing the Information and Communication Technology Services supply chain, in response to increasing customer demand for transparency in the security of the hardware, firmware and software that is included in our products and to comply with U.S. government directives.

We conduct a thorough security assessment of our key TSP partners to ensure they satisfactorily comply with applicable controls established by NIST SP 800-161, and work side by side with them to remediate gaps and monitor their security posture.

Research and Development

We focus our research and development efforts on developing new hardware and software products and services, and adding new features to existing products, services and operating systems. Our development strategy is to identify features, products and systems for both software and hardware that are, or are expected to be, important to our end-customers. Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including identification of market demand for new products or new features, components selection, timely implementation of product design and development, product performance, quality, ease of use, costs of development, bill of materials, delivery models, effective manufacturing and assembly processes and sales and marketing.

Fortinet Secure Product Development Life Cycle

We recognize that supply chain security is an increasingly important dimension of cybersecurity and enterprise risk management. We are committed to implementing a comprehensive approach to protecting the security and integrity of our products throughout the product design, development, manufacturing, delivery and support processes.

We manage a coordinated program across our engineering, manufacturing, technical services teams, together with our suppliers and channel partners, to ensure the security of our supply chain.

  • We develop our own Network Processors, Content Processors and System-on-Chip Application-Specific Integrated Circuits technology in house.

  • Our research and development is conducted primarily in the United States and Canada. We do not perform source code development or internal research and development in Russia or China.

  • We operate a Trusted Supplier Program with a rigorous selection and qualification of manufacturing partners, adhering to National Institute of Standards and Technology (“NIST”) 800-161.

  • We implement technical measures to prevent malware and rogue components that could compromise functionality.

  • We provide technical support from dedicated Fortinet regional centers.

  • We leverage application of secure development best practices (including NIST 800-53, NIST 800-160, NIST 800-218, US Executive Order 14028, and UK Telecoms Security Act).

  • We conduct regular patch release cycles and operate a notification service to support and encourage customers to apply security patches.

We pursue and maintain a broad portfolio of product and information security certifications available at the Fortinet Trust Site.

Intellectual Property

We rely primarily on patent, trademark, copyright and trade secrets laws, confidentiality procedures and contractual provisions to protect our technology. We periodically have discussions with third parties regarding licensing our intellectual property (“IP”) and have sometimes taken legal action against competitors to protect our IP, and as a result third parties have paid us fees in return for licenses or covenants-not-to-sue related to Fortinet IP. As of December 31, 2024, we had 1,034 U.S. and 1,378 global patents and 451 pending U.S. and foreign patent applications. We also license software from third parties for inclusion in our products, including open source software and other software.

Despite our efforts to protect our rights in our technology, unauthorized parties may attempt to copy aspects of our products or obtain and use information and technology that we regard as proprietary. We generally enter into confidentiality

agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information. However, we cannot provide assurance that the steps we take will prevent misappropriation of our technology. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other IP rights. Third parties have asserted, are currently asserting and may in the future assert patent, copyright, trademark or other IP rights against us, our channel partners or our end-customers. Successful claims of infringement by a third-party could prevent us from distributing certain products or performing certain services or require us to pay substantial damages (including treble damages if we are found to have willfully infringed patents or copyrights), royalties or other fees. Even if third parties offer a license to their technology, the terms of any offered license may not be acceptable and the failure to obtain a license or the costs associated with any license could cause our business, operating results or financial condition to be materially and adversely affected. In certain instances, we indemnify our end-customers, distributors and resellers against claims that our products infringe the IP of third parties.

Government Regulation

We are subject to regulation by various federal, state, regional, local and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, security and security certifications, product safety, product labeling, environmental laws, consumer protection laws, anti-bribery laws, data privacy laws, import and export controls and tariffs, securities laws and tax laws and regulations. Many of the laws and regulations that are or may be applicable to our business are changing or being tested in courts and could be interpreted in ways that could adversely impact our business and additional laws and regulations applicable to our business may be enacted. In addition, the application and interpretation of these laws and regulations often are uncertain, particularly in the industry in which we operate. We believe we take reasonable steps designed to ensure we are in compliance with current laws and regulations and do not expect continued compliance to have a material impact on our capital expenditures, earnings, or competitive position. We continue to monitor existing and pending laws and regulations and while the impact of regulatory changes cannot be predicted with certainty, we do not currently expect compliance to have a material adverse effect.

Seasonality

For information regarding seasonality in our sales, see the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations—Seasonality, Cyclicality and Quarterly Revenue Trends” in Part II, Item 7 of this Annual Report on Form 10-K.

Competition

The markets for our products are extremely competitive and are characterized by rapid technological change. The principal competitive factors in our markets include:

  • product security performance, throughput, features, effectiveness, interoperability and reliability;

  • addition and integration of new networking and security features and technological expertise;

  • compliance with industry standards and security and other certifications;

  • price of products and services and total cost of ownership;

  • brand recognition;

  • customer service and support across varied and complex customer segments and use cases;

  • sales and distribution capabilities;

  • size and financial stability;

  • breadth of product line;

  • form factor of the solution; and

  • other competitive differentiators.

Among others, our competitors include Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), CrowdStrike Holdings, Inc. (“CrowdStrike”), F5 Networks, Inc. (“F5 Networks”), Hewlett-Packard Enterprise (“HPE”), Huawei Technologies Co., Ltd. (“Huawei”), Juniper Networks, Inc. (“Juniper”), Microsoft Corporation (“Microsoft”), Netskope Inc. (“Netskope”), Palo Alto Networks, Inc. (“Palo Alto Networks”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc (“Sophos”) and Zscaler, Inc. (“Zscaler”).

We believe we compete favorably based on our products’ security performance, throughput, reliability, breadth and ability to work together, our ability to add and integrate new networking and security features and our technological expertise. Several competitors are significantly larger, have greater financial, technical, marketing, distribution, customer support and other resources, are more established than we are, and have significantly better brand recognition. Some of these larger competitors have substantially broader product offerings and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages users from purchasing our products. Other, often smaller competitors, may intensely focus on a small group of point solutions and be positioned as a leader in discrete technologies that we compete with. Based in part on these competitive pressures, we may lower prices or attempt to add incremental features and functionalities to our products.

Conditions in our markets could change rapidly and significantly as a result of technological advancements, market consolidation or de-consolidation, supply chain constraints, price list or discount changes or inflation. The development and market acceptance of alternative technologies could decrease the demand for our products or render them obsolete. Our competitors may introduce products that are less costly, provide superior performance, are better marketed, or achieve greater market acceptance than our products. Additionally, our larger competitors often have broader product lines and are better positioned to withstand a significant reduction in capital spending by end-customers, and will therefore not be as susceptible to downturns in a particular market. The above competitive pressures are likely to continue to impact our business. We may not be able to compete successfully in the future, and competition may harm our business.

Human Capital Management

As of December 31, 2024, our total headcount was 14,138 employees, approximately 30% of whom were employed in the United States, approximately 20% of whom were employed in Canada and approximately 50% of whom were employed outside of the United States and Canada. We do not own any manufacturing or research and development activities in China.

Our employees are the foundation of our innovation and cybersecurity leadership for the benefit of our customers. We understand there is a shortage of highly skilled employees for security companies like ours, and we believe that our success and competitive advantage depends largely on our ability to continue to attract and retain highly skilled employees with diverse backgrounds and experiences. We believe we offer fair, competitive compensation and benefits, and we encourage a culture of fairness and meritocracy. Our compensation programs for our employees include base pay, incentive compensation, opportunities for equity ownership where local statutes allow and employee benefits that promote well-being across different aspects of our employees’ lives, which may include health and welfare insurance, retirement benefits and paid time off.

As a global company, we value diversity and inclusion across our workforce. Such commitment starts at the top, with a highly skilled and diverse board of directors. As of December 31, 2024, women represented 40% of the members of our board of directors, and approximately 50% of our board of directors was from underrepresented communities.

We are also committed to community engagement and social responsibility with regards to our employees and beyond, and our board of directors has active oversight of such initiatives. Examples of our initiatives focused on our employees include our company matching program for employee charitable contributions and the free security training programs we offer to help with career development for our employees, in addition to the general public.

Our culture is defined by our commitment to ethics and integrity. We reinforce our ethical “tone at the top” through clear policies including our Code of Business Conduct and Ethics, regular compliance training for our employees, quarterly meetings of our cross-functional Ethics Committee, clear messaging from our executives, enforcement of company policies and oversight by our board of directors. In addition, our Chief Executive Officer regularly communicates the importance of our core values of openness, teamwork and innovation.

None of our U.S. employees are represented by a labor union. Our employees in certain European and Latin American countries, however, have the right to be represented by external labor organizations if they maintain up-to-date union membership. We have not experienced any work stoppages, and we consider our relations with our employees to be good.

Corporate Sustainability

We are committed to responsible corporate sustainability practices and having a positive impact on the sustainability of our society and planet. We are a member of the Dow Jones Sustainability Indices — World and North America, for the second consecutive year. Our approach to corporate sustainability is based on a strong corporate governance structure, starting with the Governance and Social Responsibility Committee (the “GSR Committee”) of our board of directors, which provides oversight of our Corporate Social Responsibility (“CSR”) strategy, initiatives and execution related to corporate sustainability matters. Our senior leadership sponsors the integration of CSR priorities via a CSR Committee, comprised of cross-functional team of senior leaders that drives CSR initiatives and functionality across the company including engaging with internal and external stakeholders to lead CSR execution, communications and disclosure via an annual Sustainability Report.

We recognize that environmental considerations such as climate change, resource scarcity and the energy crisis are top priorities for the future of our planet. We are committed to helping address climate change impacts and minimizing the environmental footprint of our solutions, operations and our broader value chain. We have completed our validation process and have been approved by the Science Based Targets Initiatives for a near-term target. We are engaged on a decarbonization path to reach zero emissions for our Scope 1 and Scope 2 emissions by 2030. In 2023, we obtained the ISO14001 certification for our largest company-owned warehouse in Union City, California, and have continued to be a leader on energy efficiency with the launch of our SP5 ASIC and our FortiGate-90G model. We submitted our survey on environment to CDP, which is a not-for-profit charity organization that runs the global disclosure system for companies to manage their environmental impacts. We also disclosed for the first time our Scope 3 emissions, across all 12 relevant categories, as part of our annual reporting on sustainability.

We are committed to empower individuals within our organization and across the security industry to reach their full potential. We continue to focus on skilling, upskilling and reskilling individuals and are on track to reach our goal of training one million people in cybersecurity by 2026 with over 630,000 individuals trained as of the end of 2024. As part of our Education Outreach Program, which focuses on creating a more diverse cybersecurity talent pool, we launched the Veterans Program Advisory Council to help build on the Veterans Program’s success in providing more cybersecurity training pathways for military veterans across the United States, the United Kingdom, Canada, Australia and New Zealand. We offered our Security Awareness Curriculum at no cost to primary and secondary schools across the same countries. We are involved in over 700 education partnerships across more than 100 countries and participates in public-private partnerships, including the World Economic Forum’s Cybersecurity Talent Framework.

Our approach to responsible business is based on strong corporate governance practices that aim to ensure accountability while meeting our responsibilities across our value chain, starting with our employees. Our board of directors regularly reviews our governance practices and in 2024 we formed our GSR committee which combined our Governance Committee with the Social Responsibility Committee to GSR Committee. Our Codes of Conduct apply to employees, partners and suppliers, and we have compliance trainings and controls in place. In 2023, we established a risk management committee and steering committee to further enhance our anti-corruption program and we employ a thorough screening process for partners and suppliers, including continuous monitoring in high-risk zones, and resolution process for risk mitigation.

Available Information

Our website is located at https://www.fortinet.com, and our investor relations website is located at https://investor.fortinet.com. The information posted on our website is not incorporated by reference into this Annual Report on Form 10-K. Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Act of 1933, as amended (the “Securities Act”), are available free of charge on our investor relations website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (the “SEC”). You may also access all of our public filings through the SEC’s website at https://www.sec.gov.

We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations website. Additionally, we provide notifications of news or announcements regarding our financial performance, including SEC filings, investor events and press and earnings releases, as part of our investor relations website. The contents of these websites are not intended to be incorporated by reference into this report or in any other report or document we file.

Item 1A. Risk Factors

Investing in our common stock involves a high degree of risk. Investors should carefully consider the following risks and all other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes, before investing in our common stock. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition and results of operations could be materially harmed. In that case, the trading price of our common stock could decline substantially, and investors may lose some or all of their investment. We have summarized risks immediately below and encourage investors to carefully read the entirety of this Risk Factors section.

Risks Related to Our Business and Financial Position

Our operating results are likely to vary significantly and be unpredictable.

Our operating results have historically varied from period to period, and we expect that they will continue to do so as a result of a number of factors, many of which are outside of our control or may be difficult to predict, including:

  • economic conditions, including macroeconomic and regional economic challenges resulting, for example, from a recession, tariffs or other economic downturn, increased inflation or possible stagflation in certain geographies, changing interest rates, the war in Ukraine, tensions between China and Taiwan, or other factors;

  • policy changes and uncertainty with respect to immigration laws, trade policy and tariffs, including increased tariffs applicable to countries where we manufacture our products, foreign imports and tax laws related to international commerce;

  • sales strategy, productivity, retention and execution, and our ability to attract and retain new end-customers or sell additional products and services to our existing end-customers, including customer demand for platform solutions like ours versus point solutions;

  • our ability to successfully anticipate market changes related to cloud-based solutions and to sell, support and meet service level agreements related to cloud-based solutions;

  • component shortages, including chips and other components, and product inventory shortages, including those caused by factors outside of our control, such as epidemics and pandemics, supply chain disruptions, inflation and other cost increases, international trade disputes or tariffs, natural disasters, health emergencies, power outages, civil unrest, labor disruption, international conflicts, terrorism, wars, such as the war in Ukraine and critical infrastructure attacks;

  • inventory management, including future inventory purchase commitments;

  • the level of demand for our products and services, which may render forecasts inaccurate, increase backlog or future inventory purchase commitments and lead to price decreases;

  • our backlog may fluctuate over quarters. If we experience supply chain shortages and cannot fulfill orders or if customers cancel or delay delivery of orders, our backlog may be affected, which will negatively impact our aggregate backlog to billings conversion and revenue in such quarter. A reduction to backlog increases our aggregate billings and revenue during the quarter when delivered;

  • as the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings. For fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates;

  • supplier cost increases and any lack of market acceptance of our price increases designed to help offset any supplier cost increases;

  • the timing of channel partner and end-customer orders and our reliance on a concentration of shipments at the end of each quarter or changes in shipping terms;

  • the impact to our business, the global economy, disruption of global supply chains and creation of significant volatility and disruption of the financial markets due to factors such as increased inflation or possible stagflation in certain geographies, changing interest rates, the war in Ukraine and other factors;

  • defects or vulnerabilities, including critical vulnerabilities, in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities, including critical vulnerabilities, in our products or services, failure of our products or services to detect or prevent a security incident or to cause a disruption to operations, failure of our customers to implement preventative actions such as updates to one of our deployed solutions or failure to help secure our customers;

  • compromising of our internal enterprise IT networks, our operational networks, our research and development networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers, and resulting harm to public perception of our products and services;

  • the timing of shipments, which may depend on factors such as inventory levels, logistics, manufacturing or shipping delays, our ability to ship products on schedule and our ability to accurately forecast inventory requirements and our suppliers’ ability to deliver components and finished goods;

  • increased expenses, unforeseen liabilities or write-downs and any negative impact on results of operations from any acquisition or equity investment, as well as accounting risks, integration risks related to product plans and products and risks of negative impact by such acquisitions and equity investments on our financial results;

  • investors’ expectations of our performance relating to environmental, social and governance (“ESG”) and commitment to carbon neutrality;

  • certain customer agreements which contain service-level agreements, under which we guarantee specified availability of our platform and solutions;

  • inconsistent and evolving data and other security requirements and enforcement across certain jurisdictions;

  • impairments as a result of certain events or changes in circumstances;

  • the mix of products sold and the mix of revenue between products and services, as well as the degree to which products and services are bundled and sold together for a package price;

  • the purchasing practices and budgeting cycles of our channel partners and end-customers, including the effect of the end of product lifecycles, refresh cycles or price decreases;

  • any decreases in demand by channel partners or end-customers, including any such decreases caused by factors outside of our control such as natural disasters and health emergencies, including earthquakes, droughts, fires, power outages, typhoons, floods, pandemics or epidemics and manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars, such as the war in Ukraine and critical infrastructure attacks;

  • the effectiveness of our sales organization, generally or in a particular geographic region, including the time it takes to hire sales personnel, the timing of hiring and our ability to hire and retain effective sales personnel, our efforts to align our sales capacity and productivity with market demand and any negative impact to our sales and the effectiveness of our sales team based on changes to sales compensation or to our sales compensation plan;

  • sales productivity and sales execution risk related to effectively selling to all segments of the market, including enterprise and small- and medium-sized businesses, government organizations and service providers, and to selling our broad security product and services portfolio, including, among other execution risks, ris

Showing the first 8K of 195K characters. Open the full section

Item 1B. Unresolved Staff Comments

Not applicable.

Item 1C. Cybersecurity

Our board of directors recognizes the critical importance of maintaining the trust and confidence of our customers, end users, business partners, governmental entities, stockholders and employees. Our board of directors is actively involved in oversight of our risk management program, and information and product security represent an important component of our overall approach to enterprise risk management (“ERM”). Our risks from cybersecurity threats are considered in conjunction with other risks in our ERM program. In addition, we leverage a cybersecurity-specific risk assessment process and strategy based on the NIST Cybersecurity Framework to manage risks to organizational operations and assets, individuals and other organizations associated with the operation and use of systems. Risk assessments are periodically conducted to identify threats and vulnerabilities, and then used to determine the likelihood and impact for each risk using a qualitative risk assessment methodology. In general, we seek to address cybersecurity risks through a broad, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.

Governance

As a global cybersecurity provider, cybersecurity risk management is integral to our company. Historically, the Audit Committee of our board of directors (the “Audit Committee”) was responsible for reviewing with management our cybersecurity and other information technology risks, controls and processes, including the processes used to prevent or mitigate cybersecurity risks and respond to cybersecurity events. However, due to the importance of cybersecurity to our company, in July 2024, our board of directors formed Cybersecurity Committee of our board of directors (the “Cybersecurity

Committee”), which is solely dedicated to cybersecurity risk management. Our executives with responsibility over cybersecurity, including our Chief Information Security Officer, provide quarterly reports to the Cybersecurity Committee as well as to the Chief Executive Officer and other members of our senior management as appropriate. Each member of our board of directors is invited to attend all meetings of the committees of our board of directors, including the Cybersecurity Committee, and thus all of the members of our board of directors are apprised of cybersecurity developments. The quarterly reports to the Cybersecurity Committee include updates on cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program and the emerging threat landscape. Our cybersecurity program is regularly evaluated by internal and external experts with the results of those reviews reported to senior management and the Cybersecurity Committee. We also actively engage with key vendors and intelligence and law enforcement communities as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures. The Cybersecurity Committee also receives prompt and timely information regarding any cybersecurity threat or incident that meets established reporting thresholds, as well as ongoing updates regarding any such threat or incident until it has been mitigated, resolved or otherwise addressed.

We believe our systems and processes with respect to the management of risks associated with cybersecurity threats are adequate. We have experienced, and may in the future experience, adverse impacts to our operations as a result of cybersecurity incidents. However, to date, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business strategy, operating results, and/or financial condition. If we were to experience a material cybersecurity incident in the future, such incident may have a material effect, including on our business strategy, operating results or financial condition. For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see our risk factors, including our risk factor titled “If our internal enterprise IT networks, on which we conduct internal business and interface externally, our operational networks, through which we connect to customers, vendors and partners systems and provide services, or our research and development networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers, through which we research, develop and host products and services, are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted.”

Risk Management and Strategy

As one of the critical elements of our overall ERM approach, our cybersecurity program is focused on the following key areas:

Governance: As discussed in more detail above under the heading, “Governance,” our board of directors’ oversight of cybersecurity risk management is supported by the Cybersecurity Committee, which regularly interacts with executives with responsibility for cybersecurity, our Chief Executive Officer, Chief Technology Officer and President, Chief Financial Officer, Chief Operating Officer/General Counsel, our CISO, and other members of management. Our CISO is primarily responsible for our cybersecurity risk management program and partners with our legal team on data privacy matters at the management level. Our CISO, Dr. Carl Windsor, has over 25 years of experience in various technology and cybersecurity leadership positions, including over 18 years at our company driving product security and strategy and reports to the board Cybersecurity Committee. The CISO’s leadership team members are all seasoned information security professionals, covering a wide range of security disciplines, who have worked at some of the largest well-known brand names and are experts in their fields. Our CISO monitors, and participates in, our various cybersecurity policies and procedures, and our cybersecurity team regularly updates our CISO on the current status.

Management is promptly updated regarding any significant security events and the Cybersecurity Committee regularly reviews updates from our CISO, information security and product security leaders about cyber threat response preparedness, security controls and procedures, security program maturity milestones, risk and approaches to risk mitigation and the current and emerging threat landscape. In addition, all members of our board of directors receive management’s cybersecurity updates to the Cybersecurity Committee as part of their regular attendance at meetings of our board of directors.

Collaborative Approach: We have implemented a broad, cross-functional approach to identifying, preventing and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. In addition, we manage a cross-functional program across our engineering, manufacturing and technical services teams, together with our suppliers and channel partners, designed to ensure the proper security of our products from design through manufacture and shipment.

Information Security: We implement organizational, administrative and technical measures based on commercially reasonable procedures using: (i) industry standard information security measures prescribed for use by NIST; (ii) security measures aligned with the ISO/IEC 27000 series of standards, (iii) Sarbanes-Oxley and SSAE 18/ISAE 3402; (iv) privacy regulations such as the GDPR and the CCPA; (v) business continuity management measures aligned with the ISO/IEC 22301 standard; and (vi) other generally recognized industry standards, in each case, designed to safeguard the confidentiality, integrity, and availability of our infrastructure and data and the resiliency of our operations.

Technical Safeguards: We deploy technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence.

Incident Response and Recovery Planning: We have established and maintain broad incident response and recovery plans that help enable its effective and orderly management of, and response to, any identified security incidents, including escalation and internal and external-notification steps, allowing the incident response team to respond in a timely manner and enlist appropriate personnel and third-party experts. We maintain a process to promptly assess and assign severity levels to any identified security incidents in order to prioritize their importance and promptly direct resources to those issues of potentially greater impact. The notification plan establishes steps to alert external stakeholders as appropriate, including law enforcement, regulatory bodies, investors, customers and other business partners.

Third-Party Risk Management: We maintain a broad, risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems. In addition, our Trusted Supplier Program is designed to ensure manufacturing partners undergo a selection and qualification process that adheres to NIST 800-161.

Education and Awareness: We provide regular, mandatory training for personnel and contractors regarding cybersecurity threats as a means to equip our personnel with effective tools to address cybersecurity threats and to communicate our evolving information security policies, standards, processes and practices.

Risk and Readiness Assessments: We engage in the periodic assessment and testing of our policies, standards, processes and practices that are designed to identify vulnerabilities and weaknesses, address cybersecurity threats and test its readiness to respond to cyber security incidents. These efforts include a wide range of activities, including threat modeling, a variety of vulnerability and configuration scans, penetration testing, audits, tabletop exercises and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning. We regularly engage third parties to perform assessments on our cybersecurity measures, including information security maturity assessments, audits and independent reviews of our information security control environment and operating effectiveness and penetration tests. The results of such assessments, audits and reviews are reported to the Cybersecurity Committee and our board of directors and to our management, and we adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.

Insurance: We maintain information security risk insurance coverage.

Item 2. Properties

Our corporate headquarters is located in Sunnyvale, California, and comprises approximately 395,000 square feet of building space on 21 acres of land and includes space for future development of PoPs. In January 2024, we purchased an additional 480,000 square feet of building space in Santa Clara, California, which is located in close proximity to our corporate headquarters and includes space for future development of a data center. Refer to Note 17. Subsequent Events, in Part II, Item 8 of this Annual Report on Form-10K for the February 2025 signing of a definitive agreement subject to regulatory approval for an additional 540,000 square feet of building space in Frankfurt, Germany.

Along with our corporate headquarters, as of December 31, 2024, we operated the following facilities:

LocationOwned Square FootageDescription of Use
Union City, California770,000Warehousing, operations, and PoP
Burnaby, Calgary and Ottawa, Canada680,000Data center, PoP, support functions and research and development
Atlanta, Georgia226,000Sales and support functions and PoP
Plano & Frisco, Texas130,000Office space and data center
Torija, Spain120,000Data center
Chicago, Illinois114,000Office space and PoP
Sunrise, Florida100,000Office space
Sunnyvale, California97,000Development
Valbonne, France70,000Sales and support functions and PoP
McMahons Point, Australia40,000Office space and PoP
New York, New York40,000Sales and support functions and PoP

We maintain additional leased offices throughout the world, predominantly used as sales and support offices and PoPs, and leased data center spaces throughout the world operated under colocation arrangements. We believe that our existing properties are sufficient and suitable to meet our current needs. We intend to expand our facilities, develop unoccupied space, or add new facilities to support our future growth and enter new product markets, and we believe that suitable additional space will be available or can be developed as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional operating expenses and capital expenditures in connection with such new or expanded facilities.

For information regarding the geographical location of our property and equipment, refer to Note 16 of our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.

Item 3. Legal Proceedings

We are subject to various claims, complaints and legal actions that arise from time to time in the ordinary course of business. We accrue for contingencies when we believe that a loss is probable and that we can reasonably estimate the amount of any such loss. There can be no assurance that existing or future legal proceedings arising in the ordinary course of business or otherwise will not have a material adverse effect on our business, consolidated financial position, results of operations or cash flows. Refer to Note 12. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for additional information.

Item 4. Mine Safety Disclosure

Not applicable.

Part II

All share and per share amounts presented in this Part II have been retroactively adjusted to reflect the five-for-one forward stock split of our common stock effective June 22, 2022.

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Common Stock

Our common stock is traded on The Nasdaq Global Select Market under the symbol “FTNT.”

Holders of Record

As of February 18, 2025, there were 50 holders of record of our common stock. A substantially greater number of holders of our common stock are “street name” or beneficial holders, whose shares are held by banks, brokers and other financial institutions.

Dividends

We have never declared or paid cash dividends on our capital stock. We do not anticipate paying any cash dividends in the foreseeable future. Any future determination to declare cash dividends will be made at the discretion of our board of directors and will depend on our financial condition, operating results, capital requirements, general business conditions and other factors that our board of directors may deem relevant.

Securities Authorized for Issuance Under Equity Compensation Plans

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2024 Annual Meeting of Stockholders to be filed with the Securities and Exchange Commission (the “SEC”) within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Stock Performance Graph

This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934 (the “Exchange Act”), or incorporated by reference into any filing of Fortinet under the Securities Act of 1933, as amended (the “Securities Act”), or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.

The following graph compares the cumulative five-year total return for our common stock, the Standard & Poor’s 500 Stock Index (the “S&P 500 Index”) and the NASDAQ Computer Index. Such returns are based on historical results and are not intended to suggest future performance. Data for the S&P 500 Index and the NASDAQ Computer Index assume reinvestment of dividends.

COMPARISON OF CUMULATIVE TOTAL RETURN*

Among Fortinet, Inc., the S&P 500 Index and

the NASDAQ Computer Index

Capture.jpg

**December 2019 ***December 2020December 2021December 2022December 2023December 2024
Fortinet, Inc.$100$139$337$229$274$442
S&P 500 Index$100$116$148$119$148$182
NASDAQ Computer$100$150$207$133$221$301
* Assumes that $100 was invested on December 31, 2019 in stock or index, including reinvestment of dividends. Stockholder returns over the indicated period should not be considered indicative of future stockholder returns.

Sales of Unregistered Securities

None.

Purchases of Equity Securities by the Issuer and Affiliated Purchasers

Share Repurchase Program

In January 2016, our board of directors approved our Share Repurchase Program, which authorized the repurchase of up to $200.0 million of our outstanding common stock through December 31, 2017. From 2016 through 2023, our board of directors approved increases to our Repurchase Program by various amounts and extended the term to February 29, 2024. In January 2024, our board of directors approved a $500.0 million increase in the authorized stock repurchase amount under the Repurchase Program, bringing the aggregate amount authorized to be repurchased to $7.25 billion of our outstanding common stock. In February 2024, our board of directors approved an extension of the Repurchase Program to February 28, 2025. In October 2024, our board of directors approved a $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program and extended the term of the Repurchase Program to February 28, 2026, bringing the aggregate amount authorized to be repurchased to $8.25 billion of our outstanding common stock through February 28, 2026. Under the Repurchase Program, share repurchases may be made by us from time to time in privately negotiated transactions or in open market transactions. The Repurchase Program does not require us to purchase a minimum number of shares, and may be

suspended, modified or discontinued at any time without prior notice. Since its inception, we have repurchased 238.6 million shares of our common stock under the Repurchase Program for an aggregate purchase price of $6.22 billion.

There were no repurchases of common stock during the three months ended December 31, 2024. As of December 31, 2024, approximately $2.03 billion remained available for future share repurchases under the Repurchase Program.

Item 6. [Reserved]

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations

In addition to historical information, this Annual Report on Form 10-K contains forward-looking statements within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. These statements include, among other things, statements concerning our expectations regarding:

*•*continued growth and market share gains;

*•*variability in sales in certain product and service categories from year to year and between quarters;

*•*expected impact of sales from certain products and services;

*•*increasing or decreasing inflation or stagflation, and changing interest rates in many geographies and changes in currency exchange rates and currency regulations;

*•*competition in our markets;

*•*macroeconomic, geopolitical factors and other disruption on our manufacturing or sales, including the transition in administrations, tariffs or other trade disruptions, public health issues, wars, natural disasters and economic growth;

  • government regulation, tariffs and other policies;

  • drivers of long-term growth and operating leverage, such as pricing of our products and services, sales productivity, pipeline and capacity, functionality, value and technology improvements in our service offerings;

  • growing our solution sales through channel partners to businesses, service providers and government organizations, our ability to execute these sales and the complexity of providing solutions to all segments (including the increased competition and unpredictability of timing associated with sales to larger enterprises), the impact of sales to these organizations on our long-term growth, expansion and operating results, and the effectiveness of our sales organization;

*•*our ability to successfully anticipate market changes, including those related to cloud-based solutions and to sell, support and meet service level agreements related to cloud-based solutions;

*•*growth expectations for the secure networking market;

*•*supply chain constraints, component availability and other factors affecting our manufacturing capacity, delivery, cost and inventory management;

*•*forecasts of future demand and targeted inventory levels, including changing market drivers and demands;

*•*the effect of backlog from current or prior quarters, including its effect on growth of in-quarter billings and revenue;

  • our ability to hire properly qualified and effective sales, support and engineering employees;

*•*risks and expectations related to acquisitions and equity interests in private and public companies, including integration issues related to go-to-market plans, product plans, employees of such companies, controls and processes and the acquired technology, and risks of negative impact by such acquisitions and equity investments on our financial results;

  • trends in revenue, cost of revenue and gross margin, including expectations regarding product revenue, service revenue and inventory related charges;

  • trends in our operating expense, including sales and marketing expense, research and development expense, general and administrative expense, and expectations regarding these expenses;

*•*expected impact of plans and strategy for the acceleration of our data center footprint and our points of presence deployment;

*•*expectations that our operating expense will increase year over year in absolute dollars during 2025;

*•*expectations that proceeds from the exercise of stock options in future years will be adversely impacted by the increased mix of restricted stock units and performance stock units versus stock options granted or a decline in our stock price;

*•*uncertain tax benefits and our effective domestic and global tax rates, the impact of interpretations of or changes to tax law, and the timing of tax payments;

*•*expectations regarding spending related to real estate assets, acquisitions and development, including data centers and points of presence, office building and warehouse investments, as well as other capital expenditures and to the impact on free cash flow and expenses;

  • estimates of a range of 2025 spending on capital expenditures;

*•*expansions and other changes to our real property holdings and development;

  • expected outcomes and liabilities in litigation;

  • our intentions regarding share repurchases and the sufficiency of our existing cash, cash equivalents and investments to meet our cash needs, including our debt servicing requirements, for at least the next 12 months;

*•*other statements regarding our future operations, financial condition and prospects and business strategies; and

*•*adoption and impact of new accounting standards.

These forward-looking statements are subject to certain risks and uncertainties that could cause our actual results to differ materially from those reflected in the forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K and, in particular, the risks discussed under the heading “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K and those discussed in other documents we file with the SEC. We undertake no obligation, and specifically disclaim any obligation, to revise or publicly release the results of any revision to these and any other forward-looking statements. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.

Business Overview

Fortinet is a leader in cybersecurity, driving the convergence of networking and security. Our mission is to secure people, devices and data everywhere. Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified SASE and AI-driven security operations. As of December 31, 2024, our end-customers were located in over 100 countries and included enterprises across a wide variety of market verticals, including financial services, retail, healthcare and operational technology market verticals, communication and security service providers, and government organizations. As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies. We were also ranked #7 in the Forbes Most Trusted Companies list in 2024. As a global company headquartered in Sunnyvale, California, our research and development is centered in the United States and Canada with a global footprint of support and centers of excellence around the world. As of December 31, 2024, we held 1,034 U.S. patents and 1,378 global patents and we have been recognized in over 140 enterprise analyst reports demonstrating both our vision and execution across security and networking products.

Our competitive differentiation lies in our core technologies, which together provide performance, security, flexibility and integration across diverse environments.

  • FortiOS**—FortiOS enables the convergence of security and networking to enforce consistent security policies across form factors and edges. As the foundation of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and analytics for comprehensive network visibility and control at scale. To further validate our strategy,

FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, SD-WAN, SSE, SASE Platforms and Wired and Wireless LAN.

  • FortiASIC**—Our ASIC-based SPUs increase the speed, scale, efficiency and value of our solutions while improving user experience, reducing footprint and power requirements. From branch and campus to data center solutions, SPU-powered Fortinet appliances deliver superior Security Compute Ratings versus industry alternatives.

  • FortiCloud**—Our organically built global cloud infrastructure, powered by FortiStack, which is our SaaS platform operating as a private cloud service provider and leveraging software a

Showing the first 8K of 89K characters. Open the full section

Item 7A. Quantitative and Qualitative Disclosures about Market Risk

Investment and Interest Rate Fluctuation Risk

We are exposed to interest rate risks related to our investment portfolio and outstanding debt.

The primary objectives of our investment activities are to preserve principal, provide liquidity and maximize income without significantly increasing risk. Some of the securities we invest in are subject to market risk. This means that a change in prevailing interest rates may cause the principal amount of the investment to fluctuate. To minimize this risk, we maintain our portfolio of cash, cash equivalents, investments and marketable equity securities in a variety of securities, including commercial paper, corporate debt securities, U.S. government and agency securities, certificates of deposit and term deposits, money market funds, municipal bonds and marketable equity securities. The risk associated with fluctuating interest rates is limited to our investment portfolio. A 10% decrease in interest rates would have resulted in a decrease of $15.5 million in our interest income in 2024, and would have resulted in an insignificant decrease in our interest income in 2023 and 2022.

Foreign Currency Exchange Risk

Our sales contracts are primarily denominated in U.S. dollars and therefore substantially all of our revenue is not subject to foreign currency translation risk. However, a substantial portion of our operating expenses incurred outside the United States are denominated in foreign currencies and are subject to fluctuations due to changes in foreign currency exchange rates, particularly changes in the Euro (“EUR”), the Canadian dollar (“CAD”), the British pound (“GBP”) and the Japanese yen (“JPY”). To help protect against significant fluctuations in value and the volatility of future cash flows caused by changes in currency exchange rates, we engage in foreign currency risk management activities to minimize the impact of balance sheet items denominated in CAD. We do not use these contracts for speculative or trading purposes. All of the derivative instruments are with high quality financial institutions and we monitor the credit worthiness of these parties. These contracts typically have a maturity of one month and settle on the last day of each month. We record changes in the fair value of forward exchange contracts related to balance sheet accounts in other income (expense)—net in the consolidated statements of income. We recognized an expense of $16.9 million in 2024 due to foreign currency transaction losses.

Our use of forward exchange contracts is intended to reduce, but not eliminate, the impact of currency exchange rate movements. Our forward exchange contracts are relatively short-term in nature and are focused on the CAD. Long-term material changes in the value of the U.S. dollar against other foreign currencies, such as the EUR, GBP and JPY could adversely impact our operating expenses in the future. We assessed the risk of loss in fair values from the impact of hypothetical changes in foreign currency exchange rates. For foreign currency exchange rate risk, a 10% increase or decrease of foreign currency exchange rates against the U.S. dollar with all other variables held constant would have resulted in a $14.2 million change in the value of our foreign currency cash balances as of December 31, 2024.

Inflation Risk

Our monetary assets, consisting primarily of cash, cash equivalents and short-term investments, are not affected significantly by inflation because they are predominantly short-term. We believe the impact of inflation on replacement costs of equipment, furniture and leasehold improvements will not materially affect our operations. The rate of inflation, however, affects our cost of revenue and expenses, such as those for employee compensation, which may not be readily recoverable in the price of products and services offered by us.

Item 8. Financial Statements and Supplementary Data

INDEX TO CONSOLIDATED FINANCIAL STATEMENTS

Page
Report of Independent Registered Public Accounting Firm (PCAOB ID No.34)74
Consolidated Balance Sheets as of December 31, 2024 and 202376
Consolidated Statements of Income for the years ended December 31, 2024, 2023 and 202277
Consolidated Statements of Comprehensive Income for the years ended December 31, 2024, 2023 and 202278
Consolidated Statements of Equity (Deficit) for the years ended December 31, 2024, 2023 and 202279
Consolidated Statements of Cash Flows for the years ended December 31, 2024, 2023 and 202280
Notes to Consolidated Financial Statements81

REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM

To the stockholders and the Board of Directors of Fortinet, Inc.

Opinion on the Financial Statements

We have audited the accompanying consolidated balance sheets of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, 2024 and 2023, the related consolidated statements of income, comprehensive income, equity (deficit), and cash flows, for each of the three years in the period ended December 31, 2024, and the related notes (collectively referred to as the “financial statements”). In our opinion, the financial statements present fairly, in all material respects, the financial position of the Company as of December 31, 2024 and 2023, and the results of its operations and its cash flows for each of the three years in the period ended December 31, 2024, in conformity with accounting principles generally accepted in the United States of America.

We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of December 31, 2024, based on criteria established in Internal Control – Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission and our report dated February 21, 2025, expressed an unqualified opinion on the Company’s internal control over financial reporting.

Basis for Opinion

These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the US federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.

Critical Audit Matter

The critical audit matter communicated below is a matter arising from the current-period audit of the financial statements that was communicated or required to be communicated to the audit committee and that (1) relates to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective, or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the financial statements, taken as a whole, and we are not, by communicating the critical audit matter below, providing a separate opinion on the critical audit matter or on the accounts or disclosures to which it relates.

Revenue – Refer to Note 1 and Note 2 to the financial statements

Critical Audit Matter Description

The Company’s contracts with customers often include multiple performance obligations, such as hardware, software license, security subscription, technical support services, cloud and other services, which are generally capable of being distinct and accounted for as separate performance obligations. Pursuant to accounting principles generally accepted in the United States of America, the Company is required to evaluate whether each performance obligation represents goods and services that are distinct for purposes of determining the amount and timing of revenue recognition. A good or service is distinct where the customer can benefit from the product without the services and the services are separately identifiable within a contract, and the transfer of the good or service is separately identifiable from other promises in the contract. The evaluation of performance obligations can require significant judgment in certain contracts and could change the amount of revenue recognized in a given period.

We identified the evaluation of performance obligations in certain contracts as a critical audit matter because of the significant judgment management makes in evaluating such contracts and the impact of such judgment on the amount of revenue recognized in a particular period. This required a high degree of auditor judgment and an increased extent of testing.

How the Critical Audit Matter Was Addressed in the Audit

Our audit procedures related to the Company's identification and evaluation of performance obligations within certain contracts and the resulting impact on the pattern and timing of revenue recognition included the following, among others:

  • We assessed management’s significant accounting policies related to revenue recognition for compliance with Accounting Standards Codification 606, Revenue from Contracts with Customers.

  • We evaluated the design and tested the operating effectiveness of internal controls over review of contracts, including those over the identification and evaluation of contr

Showing the first 8K of 164K characters. Open the full section

Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure

None.

Item 9A. Controls and Procedures

Evaluation of Disclosure Controls and Procedures

Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) or 15d-15(e) under the Securities Exchange Act of 1934 (the “Exchange Act”)) as of the end of the period covered by this Annual Report on Form 10-K. In designing and evaluating the disclosure controls and procedures, management recognized that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.

Based on that evaluation, our chief executive officer and chief financial officer concluded that our disclosure controls and procedures were effective as of December 31, 2024 to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized and reported within the time periods specified in SEC rules and forms, and that such information is accumulated and communicated to our management, including our Chief Executive Officer and Chief Financial Officer, as appropriate, to allow timely decisions regarding required disclosure.

Management’s Report on Internal Control over Financial Reporting

Our management is responsible for establishing and maintaining adequate internal control over financial reporting, as defined in Rule 13a-15(f) and 15d-15(f) under the Exchange Act. Management conducted an evaluation of the effectiveness of our internal control over financial reporting based on the framework in Internal Control—Integrated Framework (2013) set forth by the Committee of Sponsoring Organizations of the Treadway Commission.

As permitted by applicable SEC guidance, management has excluded Lacework, a privately held data-driven cloud security company, Next DLP, a privately held data security company, and Perception Point, a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024, because Lacework, Next DLP and Perception Point were acquired by us in business combinations during the fiscal year ended December 31, 2024. Lacework, Next DLP and Perception Point revenues represented approximately 0.5%, less than 0.1% and less than 0.1% of our consolidated total revenue, respectively, for the year ended December 31, 2024.

Based on this evaluation, management concluded that our internal control over financial reporting was effective as of December 31, 2024. Management reviewed the results of its assessment with our Audit Committee. The effectiveness of our internal control over financial reporting as of December 31, 2024 has been audited by Deloitte & Touche LLP, an independent registered public accounting firm, as stated in its report, which appears in this Item under the heading “Report of Independent Registered Public Accounting Firm.”

Changes in Internal Control over Financial Reporting

There were no other changes in our internal controls over financial reporting (as defined in Rules 13a-15(f) or 15d-15(f) under the Exchange Act) during 2024 that have materially affected, or are reasonably likely to materially affect, our internal controls over financial reporting.

REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM

To the stockholders and the Board of Directors of Fortinet, Inc.

Opinion on Internal Control over Financial Reporting

We have audited the internal control over financial reporting of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, 2024, based on criteria established in Internal Control – Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In our opinion, the Company maintained, in all material respects, effective internal control over financial reporting as of December 31, 2024, based on criteria established in Internal Control – Integrated Framework (2013) issued by COSO.

We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year ended December 31, 2024, of the Company and our report dated February 21, 2025, expressed an unqualified opinion on those financial statements.

As described in “Management’s Report on Internal Control over Financial Reporting”, management excluded from its assessment the internal control over financial reporting at Lacework, Inc. (“Lacework”), a privately held data-driven cloud security company, Next DLP Holdings Limited (“Next DLP”), a privately held data security company, and Perception Point, Ltd. (“Perception Point”), a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024. Lacework, Next DLP, and Perception Point revenues represented approximately 0.5%, less than 0.1%, and less than 0.1%, respectively, of the Company’s consolidated total revenue for the year ended December 31, 2024.

Basis for Opinion

The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Management’s Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.

Definition and Limitations of Internal Control over Financial Reporting

A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.

Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.

/s/ DELOITTE & TOUCHE LLP

San Jose, California

February 21, 2025

Item 9B. Other Information

Rule 10b5-1 Trading Plans

On December 9, 2024, William H. Neukom, one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the purchase of shares of our common stock (the “Neukom Plan”) during an open trading window in accordance with our insider trading policy. The Neukom Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act. The Neukom Plan provides for the potential purchase by Mr. Neukom of up to $35,000 worth of shares of our common stock per at the market price, on five dates between March 6, 2025 and March 6, 2026, as specified in the Neukom Plan.

On December 9, 2024, Kenneth A. Goldman, one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Goldman Plan”) during an open trading window in accordance with our insider trading policy. The Goldman Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act. The Goldman Plan provides for the potential sale by Mr. Goldman of up to 3,000 shares of our common stock, issued upon the exercise of vested options to purchase shares of our common stock, at the market price, so long as the market price is equal to or greater than $95.00 per share, between March 10, 2025 and March 10, 2026.

On December 9, 2024, Ken Xie, our Chief Executive Officer and one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Ken Xie Plan”) during an open trading window in accordance with our insider trading policy. The Ken Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act. The Ken Xie Plan provides for the potential sale by Mr. Xie of up to (a) 734,880 shares of our common stock, issued upon the vesting and settlement of RSUs and PSUs for shares of our common stock and the exercise of vested options to purchase shares of our common stock and (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and settlement of RSUs and PSUs, in each case, at the market price, all between March 10, 2025 and May 6, 2026.

On December 10, 2024, Michael Xie, our Chief Technology Officer and one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Michael Xie Plan”) during an open trading window in accordance with our insider trading policy. The Michael Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act. The Michael Xie Plan provides for the potential sale by Mr. Xie of up to (a) 624,285 shares of our common stock, issued upon the vesting and settlement of RSUs for shares of our common stock and the exercise of vested options to purchase shares of our common stock and (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and settlement of RSUs and PSUs, in each case, at the market price, all between March 11, 2025 and May 6, 2026.

Each of the Neukom Plan, Goldman Plan, Ken Xie Plan and Michael Xie Plan (each, a “10b5-1 Plan,” and together, the “10b5-1 Plans”) includes a representation from each of Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie, respectively, to the broker administering the plan that they were not in possession of any material nonpublic information regarding us or the securities subject to the respective 10b5-1 Plan at the time the respective 10b5-1 Plan were entered into. A similar representation was made to us in connection with the adoption of each 10b5-1 Plan under our insider trading policy. Those representations for each 10b5-1 Plan were made as of the respective date of adoption of the applicable 10b5-1 Plan, and speak only as of that date. In making those representations, there is no assurance with respect to any material nonpublic information of which Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie, as applicable, were unaware, or with respect to any material nonpublic information acquired by Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie or us, as applicable, after the date of each such representation.

Once executed, transactions under the 10b5-1 Plans will be disclosed publicly through Form 4 and/or Form 144 filings with the SEC in accordance with applicable securities laws, rules and regulations. Except as may be required by law, we do not undertake any obligation to update or report any modification, termination, or other activity under current or future Rule 10b5-1 plans that may be adopted by Mr. Neukom, Mr. Goldman, Mr. Ken Xie or Mr. Michael Xie or our other officers or directors, or their affiliated entities.

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevents Inspections

Not applicable.

Part III

Item 10. Directors, Executive Officers and Corporate Governance

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

As part of our system of corporate governance, our board of directors has adopted a code of business conduct and ethics. The code applies to all of our employees, officers (including our principal executive officer, principal financial officer, principal accounting officer or controller, or persons performing similar functions), agents and representatives, including our independent directors and consultants, who are not our employees, with regard to their Fortinet-related activities. Our code of business conduct and ethics is available on our website at www.fortinet.com under “Corporate—Investor Relations—Corporate Governance.” We will post on this section of our website any amendment to our code of business conduct and ethics, as well as any waivers of our code of business conduct and ethics, which are required to be disclosed by the rules of the SEC or the Nasdaq Stock Market.

Insider Trading Policy

We have adopted an Insider Trading Policy that governs the purchase, sale and/or other dispositions of our securities by directors, officers and employees. Our Insider Trading Policy also provides that we will not transact in any of our own securities unless in compliance with U.S. securities laws. We believe that our Insider Trading Policy is reasonably designed to promote compliance with insider trading laws, rules and regulations, and the Nasdaq listing standards applicable to us. A copy of our Insider Trading Policy is filed as Exhibit 19.1 to this Annual Report on Form 10-K.

Item 11. Executive Compensation

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Item 13. Certain Relationships and Related Transactions, and Director Independence

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Item 14. Principal Accounting Fees and Services

Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our 2025 Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.

Part IV

Item 15. Exhibits and Financial Statement Schedules

(a) The following documents are filed as part of this Annual Report on Form 10-K:

1.Financial Statements: The information concerning Fortinet’s financial statements and the Report of Independent Registered Public Accounting Firm required by this Item 15(a)(1) is incorporated by reference herein to the section of this Annual Report on Form 10-K in Part II, Item 8, titled “Financial Statements and Supplementary Data.”

2.Financial Statement Schedule: Financial statement schedules have been omitted because they are not applicable or are not required or the information required to be set forth therein is included in the consolidated financial statements or notes thereto.

  1. Exhibits: See Item 15(b) below. We have filed, or incorporated into this Annual Report on Form 10-K by reference, the exhibits listed on the accompanying Exhibit Index immediately preceding the signature page of this Annual Report on Form 10-K.

(b) Exhibits:

The exhibits listed on the Exhibit Index immediately preceding the signature page of this Annual Report on Form 10-K is incorporated herein by reference as the list of exhibits required by this Item 15(b).

(c) Financial Statement Schedules: See Item 15(a) above.

EXHIBIT INDEX

Exhibit NumberDescriptionForm Incorporated by reference hereinDate FiledExhibit Number
3.1Restated Certificate of IncorporationQuarterly Report on Form 10-Q (File No. 001-34511)August 7, 20233.3
3.2Amended and Restated BylawsCurrent Report on Form 8-K (File No. 001-34511)June 23, 20233.3
4.1Specimen common stock certificate of the CompanyRegistration Statement on Form S-l, as amended (File No. 333-161190)November 2, 20094.1
4.2*Description of Securities Registered Pursuant to Section 12 of the Exchange Act
10.1†Forms of Indemnification Agreement between the Company and its directors and officersRegistration Statement on Form S-l (File No. 333-161190)August 10, 200910.1
10.2†Amended and Restated 2009 Equity Incentive PlanQuarterly Report on Form 10-Q (File No. 001-34511)August 1, 201910.1
10.3†Forms of stock option agreement under Amended and Restated 2009 Equity Incentive PlanAnnual Report on Form 10-K (File No. 001-34511)February 28, 201210.5
10.4†Form of performance stock unit award agreement under Amended and Restated 2009 Equity Incentive PlanQuarterly Report on Form 10-Q (File No. 001-34511)August 6, 201399.1
10.5†Forms of restricted stock unit award and performance stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Forms)Annual Report on Form 10-K (File No. 001-34511)March 2, 201510.7
10.6†Form of restricted stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Form)Annual Report on Form 10-K (File No. 001-34511)February 26, 202010.6
10.7†Form of stock option award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Form)Annual Report on Form 10-K (File No. 001-34511)February 26, 202010.7
10.8†Fortinet, Inc. Amended Bonus PlanAnnual Report on Form 10-K (File No. 001-34511)February 19, 202110.8
10.9†Fortinet, Inc. Cash and Equity Incentive PlanQuarterly Report on Form 10-Q (File No. 001-34511)November 5, 201310.1
10.10†Form of Change of Control Agreement between the Company and its directorsQuarterly Report on Form 10-Q (File No. 001-34511)August 4, 201510.1
10.11†Amended and Restated Change of Control Severance Agreement, effective as of August 7, 2024, between the Company and Ken XieQuarterly Report on Form 10-Q (File No. 001-34511)August 8, 202410.1
10.12†Amended and Restated Change of Control Severance Agreement, effective as of August 7, 2024, between the Company and Michael XieQuarterly Report on Form 10-Q (File No. 001-34511)August 8, 202410.2
10.13†Amended and Restated Change of Control Severance Agreement, effective as of August 7, 2024, between the Company and John WhittleQuarterly Report on Form 10-Q (File No. 001-34511)August 8, 202410.3
10.14†Offer Letter, dated as of October 23, 2006, by and between the Company and John WhittleRegistration Statement on Form S-l, as amended (File No. 333-161190)August 10, 200910.10
10.15†Offer Letter, dated as of April 3, 2014, by and between the Company and Keith JensenAnnual Report on Form 10-K (File No. 001-34511)February 26, 201810.22
10.16†Amended and Restated Change of Control Severance Agreement, effective as of August 7, 2024, between the Company and Keith JensenQuarterly Report on Form 10-Q (File No. 001-34511)August 8, 202410.4
10.17†Form of performance stock unit award agreement under Amended and Restated 2009 Equity Incentive PlanQuarterly Report on Form 10-Q (File No. 001-34511)May 8, 202310.1
10.18†Form of restricted stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Form)Quarterly Report on Form 10-Q (File No. 001-34511)May 8, 202310.2
19.1*Insider Trading Policy
21.1*List of subsidiaries
23.1*Consent of Independent Registered Public Accounting Firm
24.1*Power of Attorney (incorporated by reference to the signature page of this Annual Report on Form 10-K)
31.1*Certification of Chief Executive Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002
31.2**Certification of Chief Financial Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002
32.1**Certifications of Chief Executive Officer and Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002
97.1Compensation Recovery PolicyAnnual Report on Form 10-K (File No. 001-34511)February 6, 202497.1
101.INS*Inline XBRL Instance Document - the instance document does not appear in the interactive data file because its XBRL tags are embedded within the inline XBRL document.
101.SCH*Inline XBRL Taxonomy Extension Schema Document
101.CAL*Inline XBRL Taxonomy Extension Calculation Linkbase Document
101.DEF*Inline XBRL Taxonomy Extension Definition Linkbase Document
101.LAB*Inline XBRL Taxonomy Extension Label Linkbase Document
101.PRE*Inline XBRL Taxonomy Extension Presentation Linkbase Document
104*Cover Page Interactive Data File - the cover page from the Company’s Annual Report on Form 10-K for the year ended December 31, 2024 is formatted in inline XBRL.

† Indicates management compensatory plan, contract or arrangement.

  • Filed herewith.

** Furnished herewith. This certification is deemed not filed for purposes of Section 18 of the Exchange Act, or otherwise subject to the liability of that section, nor shall it be deemed incorporated by reference into any filing under the Securities Act or the Exchange Act.

Item 16. Form 10-K summary

None.

SIGNATURES

Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized.

Date: February 21, 2025
FORTINET, INC.
By:/s/ Ken Xie
Ken Xie, Chief Executive Officer and Chairman
(Duly Authorized Officer and Principal Executive Officer)
Date: February 21, 2025
FORTINET, INC.
By:/s/ Keith Jensen
Keith Jensen, Chief Financial Officer
(Duly Authorized Officer and Principal Financial Officer)
Date: February 21, 2025
FORTINET, INC.
By:/s/ Christiane Ohlgart
Christiane Ohlgart, Chief Accounting Officer
(Duly Authorized Officer and Principal Accounting Officer)

POWER OF ATTORNEY

KNOW ALL PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Ken Xie and Keith Jensen, jointly and severally, his or her attorney-in-fact, with the power of substitution, for him or her in any and all capacities, to sign any amendments to this Annual Report on Form 10-K and to file the same, with exhibits thereto and other documents in connection therewith, with the Securities and Exchange Commission, hereby ratifying and confirming all that each of said attorneys-in-fact, or his substitute or substitutes, may do or cause to be done by virtue hereof.

Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the registrant and in the capacities and on the dates indicated.

SignatureTitleDate
/s/ Ken XieChief Executive Officer and ChairmanFebruary 21, 2025
Ken Xie(Principal Executive Officer)
/s/ Keith JensenChief Financial OfficerFebruary 21, 2025
Keith Jensen(Principal Financial Officer)
/s/ Michael XiePresident, Chief Technology Officer and DirectorFebruary 21, 2025
Michael Xie
/s/ Christiane OhlgartPrincipal Accounting OfficerFebruary 21, 2025
Christiane Ohlgart
/s/ Kenneth A. GoldmanDirectorFebruary 21, 2025
Kenneth A. Goldman
/s/ Ming HsiehDirectorFebruary 21, 2025
Ming Hsieh
/s/ Jean HuDirectorFebruary 21, 2025
Jean Hu
/s/ Janet NapolitanoDirectorFebruary 21, 2025
Janet Napolitano
/s/ William H. NeukomDirectorFebruary 21, 2025
William H. Neukom
/s/ Judith SimDirectorFebruary 21, 2025
Judith Sim
/s/ Admiral James StavridisDirectorFebruary 21, 2025
Admiral James Stavridis
/s/ Maggie WilderotterDirectorFebruary 21, 2025
Maggie Wilderotter