Fortinet (FTNT) 10-K risk factor changes: FY2024 vs FY2023
The 2024-12-31 10-K against the 2023-12-31 one, compared heading by heading and sentence by sentence.
Item 1A151 rewritten61 added40 removed755 unchanged
All filing items1,005 rewritten547 added319 removed2,208 unchanged
Summary
counted, not written
- Item 1A lists 57 risk factor headings: 4 new, 11 reworded and 42 unchanged since FY2023. 3 headings from FY2023 no longer appear.
- Sentence by sentence, 547 added, 319 removed, 1,005 rewritten and 2,208 unchanged across 18 items that differ.
New Item 1A headings (4)
- False positive detection of legitimate non-malicious files as viruses or malware or false identification of legitimate emails as spam, could adversely affect our business.
- The use of AI technology in our IT infrastructure could improve internal process but poses security and privacy risks.AI
- Political instability, changes in trade agreements and conflicts such as the war in Ukraine could adversely affect our business and financial performance.
- Global economic uncertainty, an economic downturn, the possibility of a recession, inflation, changing interest rates, changes to government spending and regulations, and weakening product demand could adversely affect our business and financial performance.Interest rates
Removed Item 1A headings (3)
- Actual, possible or perceived defects, errors or vulnerabilities in our products or services, the failure of our products or services to detect or prevent a security incident, or the misuse of our products could harm our operational results and reputation.
- False detection of vulnerabilities, viruses or security incidents or false identification of spam or spyware could adversely affect our business.
- Global economic uncertainty, an economic downturn, the possibility of a recession, inflation, rising interest rates, weakening product demand caused by political instability, changes in trade agreements and conflicts such as the war in Ukraine and the Israel-Hamas war, could adversely affect our business and financial performance.
Reworded Item 1A headings (11)
- Adverse economic conditions, such as a possible recession and possible impacts of inflation or stagflation,
[removed: increasing][added: tariffs] or[removed: decreasing][added: other trade disruptions, changing] interest rates, reduced information technology spending, including firewall and other security spending, or any economic downturn or recession, may adversely impact our business. [removed: Efforts][added: Any efforts] to withdraw from or materially modify international trade agreements,[removed: to]change tax provisions related to global manufacturing and sales or[removed: to]impose new tariffs, economic sanctions or related legislation,[removed: any of which]could adversely affect our financial condition and results of operations.- Our real estate investments, including
[removed: construction or][added: construction,] acquisition [added: or leasing] of new data centers, data center expansions or office buildings, could involve significant risks to our business. - We rely on third-party channel partners for substantially all of our revenue. If our partners fail to perform, our ability to sell our products and services will be limited, and if we fail to optimize our channel partner model going forward, our operating results may be harmed. Additionally, a small number of distributors represents a large percentage of our revenue and accounts receivable, and one distributor accounted for
[removed: 33%][added: 31%] of our total net accounts receivable as of December 31,[removed: 2023.][added: 2024.] - Reliance on a concentration of shipments at the end of the quarter [added: or changes in shipping terms] could cause our billings and revenue to fall below expected levels.
- We rely significantly on revenue from FortiGuard and other security
[removed: subscription][added: subscriptions] and FortiCare technical support services, and revenue from these services may decline or fluctuate. Because we recognize revenue from these services over the term of the relevant service period, downturns or upturns in sales of FortiGuard and other security[removed: subscription][added: subscriptions] and FortiCare technical support services are not immediately reflected in full in our operating results. - Some of our sales are to government organizations, which subjects us to a number of regulatory requirements, [added: their own supply chain constraints and contractual requirements,] challenges and risks.
- If our internal enterprise IT networks, on which we conduct internal business and interface externally, our operational networks, through which we connect to customers, vendors and partners systems and provide services, or our research and development networks, our back-end labs and cloud stacks hosted in our data
[removed: centers,][added: centers or PoPs,] colocation vendors or public cloud providers, through which we research, develop and host products and services, are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted. - Managing inventory of our products and product components is complex. We order components from third-party manufacturers based on our forecasts of future demand and targeted inventory levels, which exposes us to the risk of
[removed: both]product shortages, which may result in lost[removed: sales and][added: sales,] higher[removed: expenses,][added: expenses] and excess inventory, which may require us to sell our products at discounts and lead to [added: inventory charges or] write-offs. - Because we depend on several third-party manufacturers to build our products, we are susceptible to manufacturing delays that could prevent us from shipping customer orders on time, if at all, and may result in the loss of sales and customers,
[removed: and][added: additional] third-party manufacturing cost increases [added: and changes in the geopolitical environment] could result in lower gross margins and free cash flow. - Our products contain third-party open-source software components, and failure to comply with the terms of the underlying open-source software licenses could restrict our ability to sell our
[removed: products.][added: products or result in loss of IP.]
A heading is new when no FY2023 heading matches it after ignoring case and punctuation, and reworded when it shares at least 60 percent of its words with one that went away. All current risk factor headings.
Sentences by item
24 items, with every count and a link to each item that changed
Underlined words on a shaded ground are new in FY2024; struck-through words were in FY2023. Sentences that are wholly new or wholly gone are labelled rather than marked.
Item 1A. Risk Factors
151 rewritten, 61 added, 40 removed, 755 unchanged
- economic conditions, including macroeconomic and regional economic challenges resulting, for example, from a [removed: recession] [added: recession, tariffs] or other economic downturn, increased inflation or possible stagflation in certain geographies, [removed: rising] [added: changing] interest rates, the war in Ukraine, [removed: the Israel-Hamas war,] tensions between China and Taiwan, or other factors;
- sales strategy, [removed: productivity] [added: productivity, retention] and execution, and our ability to attract and retain new end-customers or sell additional products and services to our existing end-customers, including customer demand for platform solutions like ours versus point solutions;
- component shortages, including chips and other components, and product inventory shortages, including those caused by factors outside of our control, such as epidemics and pandemics, supply chain disruptions, inflation and other cost increases, international trade disputes or tariffs, natural disasters, health emergencies, power outages, civil unrest, labor disruption, international conflicts, terrorism, wars, such as the war in Ukraine and [removed: the Israel-Hamas war, and] critical infrastructure attacks;
- inventory management, including future inventory purchase [removed: order] commitments;
- the level of demand for our products and services, which may render forecasts inaccurate, increase backlog or future inventory purchase [removed: order] commitments and lead to price decreases;
- the timing of channel partner and end-customer orders and our reliance on a concentration of shipments at the end of each [removed: quarter;][added: quarter or changes in shipping terms;]
- the impact to our business, the global economy, disruption of global supply chains and creation of significant volatility and disruption of the financial markets due to factors such as increased inflation or possible stagflation in certain geographies, [removed: increasing or decreasing] [added: changing] interest rates, the war in Ukraine and [removed: the Israel-Hamas war and] other factors;
- increased expenses, unforeseen liabilities or write-downs and any negative impact on results of operations from any acquisition or equity [removed: investment consummated,] [added: investment,] as well as accounting risks, integration risks related to product plans and products and risks of negative impact by such acquisitions and equity investments on our financial results;
- the purchasing practices and budgeting cycles of our channel partners and end-customers, including the effect of the end of product [removed: lifecycles or] [added: lifecycles,] refresh [removed: cycles;][added: cycles or price decreases;]
- any decreases in demand by channel partners or end-customers, including any such decreases caused by factors outside of our control such as natural disasters and health emergencies, including earthquakes, droughts, fires, power outages, typhoons, floods, pandemics or epidemics and manmade events such as civil unrest, labor disruption, international trade disputes, international conflicts, terrorism, wars, such as the war in Ukraine and [removed: the Israel-Hamas war, and] critical infrastructure attacks;
- the effectiveness of our sales organization, generally or in a particular geographic region, including the time it takes to hire sales personnel, the timing of hiring and our ability to hire and retain effective sales personnel, [removed: as well as] our efforts to align our sales capacity and [added: productivity with] market [removed: demand;][added: demand and any negative impact to our sales and the effectiveness of our sales team based on changes to sales compensation or to our sales compensation plan;]
- execution risk associated with our efforts to capture the opportunities related to our identified growth drivers, such as risk associated with our ability to capitalize on the convergence of networking and security, vendor consolidation of various cyber security solutions, SD-WAN, infrastructure security, security operations, [removed: SASE and other cloud security solutions, endpoint protection, and IoT and OT security opportunities;]
- the timing of revenue recognition for our sales, including any impacts resulting from extension of payment terms [removed: to distributors] and fluctuations in backlog levels, which could result in more variability and less predictability in our quarter-to-quarter revenue and operating results;
- the impact of cloud-based [added: and hosted] security solutions on our billings, revenue, operating margins and free cash flow;
- price competition and increased competitiveness in our market, including the competitive pressure caused by product refresh [removed: cycles;][added: cycles and inventory levels;]
- increased demand for cloud-based [added: and hosted] services and the uncertainty associated with transitioning to providing such services;
- political, economic and social instability, including geo-political instability and uncertainty, such as that caused by the war in Ukraine, [removed: the Israel-Hamas war,] tensions between China and Taiwan, and any disruption or negative impact on our ability to sell to, ship product to and support customers in certain regions based on trade restrictions, embargoes and export control law restrictions;
Adverse economic conditions, such as a possible recession and possible impacts of inflation or stagflation, [removed: increasing] [added: tariffs] or [removed: decreasing] [added: other trade disruptions, changing] interest rates, reduced information technology spending, including firewall and other security spending, or any economic downturn or recession, may adversely impact our business.
Weak global and regional economic conditions and spending environments, based on a downturn in the economy, a possible recession and the effects of ongoing or increased inflation or possible stagflation in certain geographies, [removed: increasing] [added: tariffs] or [removed: decreasing] [added: other trade disruptions, changing] interest rates, geopolitical instability and uncertainty, a reduction in information technology spending regardless of macroeconomic conditions, the effects of epidemics and pandemics and the impact of the war in Ukraine [removed: and the Israel-Hamas war each] could have a material adverse impacts on our financial condition and results of operations and our business, including resulting in longer sales cycles, lower prices for our products and services, increased component costs, higher default rates among our channel partners, reduced unit sales, lower prices and slower or declining growth.
These can negatively impact our business by putting downward pressure on growth if we are unable to achieve the increases in [removed: product prices necessary to appropriately offset the additional costs in a manner sufficient to maintain margins.]
The existence of inflation in certain economies has resulted in, and may continue to result in, [removed: increasing or decreasing] [added: changing] interest rates and capital costs, increased component or shipping costs, increased costs of labor, weakening exchange rates and other similar effects.
We may experience slowing growth or a decrease in billings, revenue, operating margin and free cash flow for a number of reasons, including a slowdown in [added: pipeline growth or for] demand for our products or [removed: services,] [added: services generally,] a shift in demand from products to services, decrease in services revenue growth, increased competition, execution challenges including sales execution challenges and lack of optimal sales productivity, worldwide or regional economic challenges based on inflation or possible stagflation, a regional recession or a recession in the global economy, [removed: rising] [added: changing] interest rates, the war in [removed: Ukraine and the Israel-Hamas war,] [added: Ukraine,] a decrease in the growth of our overall market or softness in demand in certain geographies or industry verticals, such as the service provider industry, changes in our strategic opportunities, execution risks, lower sales productivity and our failure for any reason to continue to capitalize on sales and growth opportunities due to other risks identified in the risk factors described in this periodic report.
Our real estate investments, including [removed: construction or] [added: construction,] acquisition [added: or leasing] of new data centers, data center expansions or office buildings, could involve significant risks to our business.
In order to sustain our growth in certain of our existing and new markets, we may [added: acquire or] expand existing data centers, lease new facilities or acquire suitable land, with or without structures, to build new data centers or office buildings.
[added: These projects] expose us to risks which could have an adverse effect on our results of operations and financial condition.
[removed: The] current global supply chain and inflation issues have exacerbated many of these construction risks and created additional risks for our business.
- unanticipated environmental [added: or regulatory] issues and geological problems;
- unexpected lack of power [removed: access;][added: access or unexpected increases in power needs;]
- failure or inability for any reason to meet customer [removed: requirements;][added: requirements and service level agreements, and any resulting penalties or liabilities related thereto;]
- investor expectations regarding [removed: ESG;][added: sustainability;]
Additionally, a small number of distributors represents a large percentage of our revenue and accounts receivable, and one distributor accounted for [removed: 33%] [added: 31%] of our total net accounts receivable as of December 31, [removed: 2023.][added: 2024.]
Six distributor customers [added: who purchase directly from us] accounted for [removed: 70% and] 69% [added: and 70%] of our total net accounts receivable in the aggregate as of December 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] respectively.
Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers [removed: that] accounted for 10% or more of our revenue or net accounts receivable.
We provide channel partners with specific programs to assist them with selling our products [removed: and incentivize them to sell our products,] but there can be no assurance that these programs will be effective.
Reliance on a concentration of shipments at the end of the quarter [added: or changes in shipping terms] could cause our billings and revenue to fall below expected levels.
- disruption in manufacturing or shipping based on power outages, system failures, labor disputes or constraints, excessive demand, natural [removed: disasters] [added: disasters, geopolitical matters] or widespread public health problems including pandemics and epidemics;
We rely significantly on revenue from FortiGuard and other security [removed: subscription] [added: subscriptions] and FortiCare technical support services, and revenue from these services may decline or fluctuate.
Because we recognize revenue from these services over the term of the relevant service period, downturns or upturns in sales of FortiGuard and other security [removed: subscription] [added: subscriptions] and FortiCare technical support services are not immediately reflected in full in our operating results.
Our FortiGuard and other security [removed: subscription] [added: subscriptions] and FortiCare technical support services revenue has historically accounted for a significant percentage of our total revenue.
Revenue from the sale of new, or from the renewal of existing, FortiGuard and other security [removed: subscription] [added: subscriptions] and FortiCare technical support service contracts may decline and fluctuate as a result of a number of factors, including fluctuations [added: and changes] in [removed: purchases] [added: the mix] of [added: our sales from] secure networking, unified SASE and security [removed: operations, changes in the sales mix] [added: operations] between products and services, end-customers’ level of satisfaction with our products and services, the prices of our products and services, the prices of products and services offered by our competitors, reductions in our customers’ spending levels and the timing of revenue recognition with respect to [removed: these arrangements.][added: such sales.]
- our backlog may fluctuate over quarters.
If we experience supply chain shortages and cannot fulfill orders or if customers cancel or delay delivery of orders, our backlog may be affected, which will negatively impact our aggregate backlog to billings conversion and revenue in such quarter.
A reduction to backlog increases our aggregate billings and revenue during the quarter when delivered;
- as the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings.
For fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates;
- defects or vulnerabilities, including critical vulnerabilities, in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities, including critical vulnerabilities, in our products or services, failure of our products or services to detect or prevent a security incident or to cause a disruption to operations, failure of our customers to implement preventative actions such as updates to one of our deployed solutions or failure to help secure our customers;
- compromising of our internal enterprise IT networks, our operational networks, our research and development networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers, and resulting harm to public perception of our products and services;
- inconsistent and evolving data and other security requirements and enforcement across certain jurisdictions;
SASE and other cloud security solutions, endpoint protection, IoT and OT security opportunities and product refresh cycles;
product prices necessary to appropriately offset the additional costs in a manner sufficient to maintain margins.
The
- greater expertise in certain single point solutions;
Customers may accept these bundled
- economic instability in foreign markets, such as any economic instability caused by economic downturns or recessions, could adversely affect our business and financial performance;
We periodically implement new sales compensation plans, which may change the method, amount and timing for sales-based compensation for our sales personnel.
If we are not successful in implementing new sales compensation plans, or members of our sales team react negatively to such new plans, this may negatively impact our ability to execute and grow sales and we may be unable to hire, retain and motivate qualified sales personnel.
We may not manufacture all
For example, we recently discovered, and subsequently released to customers an advisory update and patch for, a critical vulnerability in our FortiManager product.
We are subject to various risks due to the FortiManager vulnerability, including reputational harm, adverse impacts to customer relationships, potential litigation, and additional regulatory scrutiny, which could negatively impact our business, operating results and financial condition.
Further, customers may choose not to apply patches in a timely manner for business or operational reasons, or may neglect to upgrade at all and may run unpatched or unsupported devices against our guidance and industry best practice.
Such lack of action to remediate known product vulnerabilities in the customer environment could negatively impact their own security posture, increasing the likelihood of exploitation and negatively impacting our reputation.
prospects not to buy from us and, in some instances, subject us to potential liability that is not contractually limited.
For example, recently, an individual gained unauthorized access to a limited number of files stored on our instance of a third-party cloud-based shared file drive, which included limited data related to a small percentage of our customers.
We do not currently believe that this incident was material as a result of our assessment of various factors, including, but not limited to, because (i) our operations, products, and services have not been impacted, and (ii) we have identified no evidence of additional access to any other of our resources.
As a result, we have not experienced, and do not currently believe that the incident is reasonably likely to have a material impact to our financial condition, operating results or business.
However, we remain subject to various
risks due to the incident and its impact, including reputational harm, adverse impacts to customer relationships, potential litigation, and additional regulatory scrutiny.
available.
sophisticated techniques to gain access to and attack systems and networks.
Many organizations have invested substantial personnel and financial resources to design and operate their networks and have
Under these rules, we are required to obtain sourcing data
This could harm our relationships with our channel partners
Additionally, while our U.S distribution agreements contain price protections, our international distribution agreements do not contain such protections.
We
If customer data is used to train AI based systems and such data is not adequately anonymized, this may lead to breach of sensitive information and loss of customer trust.
The use of AI also brings ethical issues related to privacy, surveillance and consent of use, as well as potential for bias and discrimination.
The use of AI technology in our IT infrastructure could improve internal process but poses security and privacy risks.
The adoption of AI in internal processes presents an opportunity to bolster decision making, productivity and customer satisfaction, but the new technology poses risks.
AI can be exploited by hackers and malicious actors to develop advanced cyberattacks, bypass security measures, and exploit system vulnerabilities.
The use of AI involves handling large amounts of data.
- based on supply chain shortages, including component and other shortages, our backlog has fluctuated over past quarters and any decrease in growth or negative growth of in-quarter billings and revenue may not be reflected by our aggregate billings and revenue.
As we have fulfilled, shipped and billed during a quarter to satisfy backlog, this has increased our aggregate billings and revenue during any particular quarter, and as the supply chain challenges normalize, the growth comparisons versus prior quarters where backlog contributed more to billings have become more challenging and may become increasingly challenging;
- the effects of our reduction of operations in Russia;
- any actual or perceived vulnerabilities in our products or services, and any actual or perceived breach of our network or our customers’ networks;
- data security requirements that may be inconsistently enforced in certain jurisdictions;
These projects
- instability in the global banking system;
export control laws, trade laws and regulations, tariffs and retaliatory measures, trade barriers and economic sanctions;
effectively sell our unified SASE and security operations technology solutions, our business, operating results and prospects may be adversely affected.
reduce business opportunities and cause reputational harm and cause concern with other government agencies, governments and businesses and cause them to not buy our products and services and/or lead to a decrease in demand for our products generally.
replace it with our solutions.
cloud-based business models and the future demand for our subscription cloud-based models by customers.
of our hardware is manufactured in Taiwan.
require us to expend significant resources to incorporate these new components into our products.
services.
could impair our ability to compete effectively and adversely affect our financial results.
Linksys sells predominantly into the consumer Wi-Fi market, and its sales have declined since our investment.
Because we are accounting for our Linksys investment using the equity method of accounting, we are required to assess the investment for other-than-temporary impairment (“OTTI”) when events or circumstances suggest that the carrying amount of the investment may be impaired.
We have analyzed whether there should be an OTTI of the value of our investment in Linksys and during the three months ended December 31, 2022 we recorded an OTTI charge of $22.2 million.
In evaluating OTTI, we considered factors such as Linksys’ financial results and operating history, our ability and intent to hold the investment until its fair value recovers, the implied revenue valuation multiples compared to guideline public companies, Linksys’ ability to achieve milestones and any notable operational and strategic changes.
We intend to continue to analyze our investment in Linksys to determine whether any further impairment is appropriate.
If any further decline in fair value is determined to be other-than-temporary, we will adjust the carrying value of the investment to its fair value and record the impairment expense in our consolidated statements of income.
The cost basis of the investment is not adjusted for subsequent recoveries in fair value.
We may experience additional volatility to our statements of operations due to the underlying operating results of Linksys or impairments of our Linksys investment.
This volatility could be material to our results in any given quarter and may cause our stock price to decline.
more stringent than in the United States.
The criteria by which our corporate
For example, in 2023, California passed three separate climate bills governing disclosure of greenhouse gas emissions data, climate-related financials risks and details around emissions-related claims and carbon offsets.
In addition, the SEC has also proposed a draft rule that requires climate disclosures in financial filings.
Additionally, fluctuations in the exchange rate of the Canadian dollar may negatively impact our development plans in Burnaby, Canada.
In February 2023, our board of directors approved an extension of the Repurchase Program to February 29, 2024.
As of December 31, 2023, $529.1 million remained available for future share repurchases under the Repurchase Program.
In January 2024, our board of directors approved a $500.0 million increase in the authorized stock repurchase amount under the Repurchase Program, bringing the aggregate amount authorized to be repurchased to $7.25 billion of our outstanding common stock.
In February 2024, our board of directors approved an extension of the Repurchase Program to February 28, 2025.
Moreover, there has been recent turmoil in the global banking system.
For example, in March 2023, Silicon Valley Bank (“SVB”) was put into receivership by the Federal Deposit Insurance Corporation and subsequently sold.
Other banks at risk of failure have been subsequently sold, including First Republic Bank in May 2023, and there is concern that more banks could be at risk of the same fate.
Although we only had an immaterial amount of our cash directly at SVB, there is no guarantee that the federal government would guarantee all depositors as they did with SVB depositors in the event of further bank closures.
Continued instability in the global banking system may negatively impact us or our customers, including our customers’ ability to pay for our platform, and adversely impact our business and financial condition.
Moreover, events such as the closure of SVB, in addition to global macroeconomic conditions discussed above, may cause further turbulence and uncertainty in the capital markets and economy.
An excerpt. Shown here: 40 of 151 rewritten, 40 of 61 added and all 40 removed. The counts are complete. For every sentence, read Item 1A. Risk Factors in the FY2024 filing and the FY2023 filing.
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
220 rewritten, 116 added, 71 removed, 286 unchanged
*•macroeconomic, geopolitical factors and other disruption on our manufacturing or sales, including [added: the transition in administrations, tariffs or other trade disruptions,] public health issues, [removed: wars and] [added: wars,] natural [removed: disasters;*][added: disasters and economic growth;*]
*•our ability to successfully anticipate market [removed: changes] [added: changes, including those] related to cloud-based solutions and to sell, support and meet service level agreements related to cloud-based solutions;*
*•the effect of backlog from [added: current or] prior quarters, including its effect on growth of in-quarter billings and revenue;*
- *trends in revenue, cost of revenue and gross margin, including expectations regarding product [removed: revenue and] [added: revenue,] service revenue [removed: growth;*][added: and inventory related charges;*]
- *trends in our operating [removed: expenses,] [added: expense,] including sales and marketing expense, research and development expense, general and administrative expense, and expectations regarding these expenses;*
*•expected impact of plans and strategy for the acceleration of our [added: data center footprint and our] points of presence [removed: (“PoP”)] deployment;*
*•expectations that our operating [removed: expenses] [added: expense] will increase year over year in absolute dollars during [removed: 2024;*][added: 2025;*]
[removed: *•expectations regarding uncertain] [added: *•uncertain] tax benefits and our effective domestic and global tax rates, the impact of interpretations of or changes to tax law, and the timing of tax payments;*
*•expectations regarding spending related to real estate [added: assets,] acquisitions and development, including data [removed: center,] [added: centers and points of presence,] office building and warehouse investments, as well as other capital expenditures and to the impact on free cash flow and expenses;*
- *estimates of a range of [removed: 2024] [added: 2025] spending on capital expenditures;*
Fortinet is a leader in [removed: cybersecurity and] [added: cybersecurity, driving] the convergence of networking and security.
Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified SASE and AI-driven security [removed: operations to deliver cybersecurity where our customers need it.][added: operations.]
As of December 31, [removed: 2023,] [added: 2024, our end-customers were located in] over [added: 100 countries and included enterprises across] a [removed: half million customers trusted our solutions,] [added: wide variety of market verticals,] including [removed: enterprises such as in the] financial services, [removed: retail] [added: retail, healthcare] and operational technology market verticals, communication and security service providers, [removed: government organizations] and [removed: small and medium-sized businesses.][added: government organizations.]
As a global company headquartered in Sunnyvale, [removed: California with a large international customer base, the majority of] [added: California,] our research and development is [added: centered] in the United States and Canada with a global footprint of support and centers of excellence around the world.
As of December 31, [removed: 2023,] [added: 2024,] we held [removed: 957] [added: 1,034] U.S. patents and [removed: 1,299] [added: 1,378] global patents and we [removed: are] [added: have been] recognized in over [removed: 80] [added: 140] enterprise analyst reports demonstrating both our vision and execution across [removed: networking and] security [added: and networking] products.
[removed: FortiOS is] [added: - Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via FortiOS,] our networking and security operating system that is [removed: consistent across] [added: the foundation of] our [removed: firewalls and secure connectivity solutions] [added: Fortinet Security Fabric platform] and supports over 30 functions that can be delivered via a physical, virtual, cloud or SaaS solution.
When delivered [removed: via] [added: through] our network firewall appliances, functionality is accelerated through our proprietary ASIC technology.
These proprietary ASICs, [removed: combined with off-the-shelf CPUs and ASICs,] allow our systems to scale, run multiple applications at higher performance, lower power consumption and perform more processor-intensive operations, such as inspecting encrypted traffic, including streaming video.
[removed: The Network Firewall solution consists] [added: Our network firewall offerings consist] of [added: a] FortiGate data [removed: centers,] [added: center,] hyperscale and distributed firewalls, as well as encrypted applications (SSL inspection, [removed: Virtual Private Network] [added: virtual private network] and [added: IPsec connectivity).]
Our ability to converge networking and security also enables the ethernet to become an extension of [removed: a company’s] [added: our customers’] security infrastructure through FortiSwitch and FortiLink.
[removed: The] [added: Our] Secure Connectivity solution includes FortiSwitch [removed: Secure Ethernet Switches,] [added: secure ethernet switches,] FortiAP [removed: Wireless Local Area Network Access Points] [added: wireless local area network access points] and FortiExtender 5G [removed: Connectivity Gateways, among other products.][added: connectivity gateways.]
The Fortinet Unified SASE solution [removed: is] [added: includes] a single-vendor SASE solution that includes [removed: Firewall,] [added: firewall,] SD-WAN, [removed: Secure Web Gateway, Cloud Access Services Broker, Data Loss Prevention, Zero Trust Network Access and] [added: secure web gateway,] cloud [removed: security, including Web Application Firewalls, Virtualized Firewalls] [added: access services broker, DLP] and [removed: Cloud-Native Firewalls, among other products.][added: zero trust network access to deliver flexible secure access for all users.]
[removed: FortiGuard Labs] [added: FortiGuard Labs] is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize machine learning and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers.
[removed: FortiGuard] [added: FortiGuard and Other] Security [removed: Services] [added: Services] are a suite of AI-powered security capabilities that are natively integrated as part of the Fortinet Security Fabric to deliver coordinated detection and enforcement across the entire attack surface.
[removed: FortiCare] [added: FortiCare] Technical Support [removed: Service] [added: Service] is a per-device [added: technical] support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet capabilities.
Global technical support is offered 24x7 with flexible add-ons, including enhanced SLAs and [removed: premium] [added: priority] hardware replacement through in-country [added: and local] depots.
We offer three per-device support options tailored to the needs of our enterprise customers: FortiCare [removed: Premium,] [added: Elite,] FortiCare [removed: Elite] [added: Premium] and FortiCare Essential.
The FortiCare Elite service aims to provide [added: a] 15-minute response [removed: times] [added: time] for key product families.
- Total revenue was [removed: $5.30] [added: $5.96] billion in [removed: 2023,] [added: 2024,] an increase of [removed: 20%] [added: 12%] compared to [removed: $4.42] [added: $5.30] billion in [removed: 2022.][added: 2023.]
- Product revenue was [removed: $1.93] [added: $1.91] billion in [removed: 2023, an increase] [added: 2024, a decrease] of [removed: 8%] [added: 1%] compared to [removed: $1.78] [added: $1.93] billion in [removed: 2022.][added: 2023.]
- Service revenue was [removed: $3.38] [added: $4.05] billion in [removed: 2023,] [added: 2024,] an increase of [removed: 28%] [added: 20%] compared to [removed: $2.64] [added: $3.38] billion in [removed: 2022.][added: 2023.]
- Total gross profit was [removed: $4.07] [added: $4.80] billion in [removed: 2023,] [added: 2024,] an increase of [removed: 22%] [added: 18%] compared to [removed: $3.33] [added: $4.07] billion in [removed: 2022.][added: 2023.]
- Operating income was [removed: $1.24] [added: $1.80] billion in [removed: 2023,] [added: 2024,] an increase of [removed: 28%] [added: 45%] compared to [removed: $969.6 million] [added: $1.24 billion] in [removed: 2022.][added: 2023.]
- Cash, cash equivalents, [added: short-term and long-term] investments and marketable equity securities were [removed: $2.44] [added: $4.07] billion as of December 31, [removed: 2023,] [added: 2024,] an increase of [removed: $183.9 million,] [added: $1.63 billion,] or [removed: 8%,] [added: 67%,] from December 31, [removed: 2022.][added: 2023.]
[removed: - Long-term] [added: As of December 31, 2024, the long-term] debt, net of unamortized discount and debt issuance costs, was [removed: $992.3 million and $990.4 million as of December 31, 2023 and 2022, respectively.][added: $994.3 million.]
Short-term deferred revenue was [removed: $2.85] [added: $3.28] billion as of December 31, [removed: 2023,] [added: 2024,] an increase of [removed: $499.4] [added: $427.5] million, or [removed: 21%,] [added: 15%,] from December 31, [removed: 2022.][added: 2023.]
- Cash flows from operating activities were [removed: $1.94] [added: $2.26] billion in [removed: 2023,] [added: 2024,] an increase of [removed: $204.9] [added: $322.6] million, or [removed: 12%,] [added: 17%,] compared to [removed: 2022.][added: 2023.]
In [removed: 2023,] [added: 2024,] the Americas region, the Europe, Middle East and Africa (“EMEA”) region and the Asia Pacific (“APAC”) region contributed 41%, [removed: 39%] [added: 40%] and [removed: 20%] [added: 19%] of our total revenue, respectively, and increased [removed: 22%, 23%] [added: 12%, 16%] and [removed: 12%] [added: 6%] compared to [removed: 2022,] [added: 2023,] respectively.
Service revenue [removed: growth of 28%] [added: grew 20%] in [removed: 2023 was] [added: 2024 compared to 2023,] primarily driven by the strength of our security subscription revenue, which grew [removed: 33%.][added: 22% in 2024 compared to 2023.]
The increase was primarily due to the recognition of [added: service] revenue from our growing deferred revenue balance related to FortiGuard and other security subscriptions delivered to on-premise and cloud-based [removed: environments.][added: environments and strength in unified SASE and SecOps.]
*•expansions and other changes to our real property holdings and development;*
As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies.
We were also ranked #7 in the Forbes Most Trusted Companies list in 2024.
Our competitive differentiation lies in our core technologies, which together provide performance, security, flexibility and integration across diverse environments.
- FortiOS—FortiOS enables the convergence of security and networking to enforce consistent security policies across form factors and edges.
As the foundation of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and analytics for comprehensive network visibility and control at scale.
To further validate our strategy,
FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, SD-WAN, SSE, SASE Platforms and Wired and Wireless LAN.
- FortiASIC—Our ASIC-based SPUs increase the speed, scale, efficiency and value of our solutions while improving user experience, reducing footprint and power requirements.
From branch and campus to data center solutions, SPU-powered Fortinet appliances deliver superior Security Compute Ratings versus industry alternatives.
- FortiCloud—Our organically built global cloud infrastructure, powered by FortiStack, which is our SaaS platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all layers, provides customers with global reach, flexible connectivity, and cost savings.
- FortiAI—Our AI innovations encompass generative AI, big data AI for threat intelligence to process and analyze trillions of events using AI/ML, network operations AI for self-healing networks and automated network orchestration, automation and response, and AI for LLM leakage to protection against data leakage into LLMs.
Our GenAI assists security teams to make better decisions, rapidly respond to threats and save time on even the most complex tasks.
FortiAI is seamlessly integrated into the user experience of several of our products, including FortiAnalyzer, FortiSIEM and FortiSOAR, to help optimize threat investigation and response, SIEM queries, SOAR playbook creation, among other functions.
- FortiEndpoint—FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and XDR, into a single agent.
It simplifies management and enhances visibility while reducing costs and complexity.
The solution gives IT teams the visibility and control they need, while security teams benefit from automated threat detection and response.
This minimizes the need for manual intervention and provides faster remediation of threats across all environments.
- OT Security—The Fortinet Security Fabric enables security for converged IT/OT ecosystems.
It also provides an OT Security Platform with features and products to extend Security Fabric capabilities to OT networks in factories, plants, remote locations and ships.
To help alleviate security risks across the organization, we have continued to enhance our OT Security Platform offerings.
These innovations range from edge products to NOC and SOC tools and services to provide effective and efficient networking and cybersecurity performance and operation.
These competitive differentiators allow us to provide CIOs, CISOs, CTOs, and their organizations with an integrated AI-driven cybersecurity platform with over 50 products across three solution pillars.
- Unified Secure Access Service Edge (SASE)—As applications move to the cloud and hybrid workforce is now the norm, enabling secure access for users with zero trust framework becomes important.
We are one of the few vendors to deliver consistent convergence and AI-powered security across Secure SD-WAN and SSE to enable a single-vendor SASE framework with a cloud-centric architecture powered by FortiOS.
Our global and scalable cloud network includes 150+ points of presence to deliver the seamless secure access experience.
Given this, we are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform.
Additionally, we offer a full suite of comprehensive, integrated cloud security solutions that enable customers to secure their applications from code to cloud.
Our solutions include application security that includes our web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application protection and code security.
We deliver a holistic approach to cloud security, offering a single unified platform for cloud security and secure CI/CD application development needs, consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and multi-clouds, and delivering AI-driven security across integrated solutions
with visibility and context across hybrid and multi-cloud.
Additionally, we also offer flexible consumption licensing programs that enable organizations to dynamically optimize their cloud security needs and investments as well as readily meet their cloud minimum spend commitment obligations with Cloud Service Providers.
- AI-Driven Security Operations (SecOps)—Our AI-Driven SecOps portfolio provides a comprehensive suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric.
At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that provides built-in SIEM, SOAR, XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control.
FortiSIEM delivers robust security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response.
This solution set also includes FortiEDR, FortiXDR, FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications.
To bolster their security posture, organizations contending with staff shortages can tap into FortiGuard services, including SOCaaS, MDR, Security Posture Assessment and Incident Response.
Finally, FortiAI generative AI assistance streamlines operations, helping security teams stay ahead of an ever-evolving threat landscape.
Using millions of global network sensors, FortiGuard Labs monitors the worldwide attack surface and employs AI to mine that data for new threats.
In addition to FortiCare device level services, Advanced Support service options are available per account.
*•real estate investments, management of future growth including expansions and enhancements of current properties;*
*•instability in the global banking system;*
- Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via our network firewall and our switches, access points and other secure connectivity solutions.
IPsec connectivity).
- Unified Secure Access Service Edge (SASE)—As applications move to the cloud and work from anywhere becomes established, cloud delivery is needed to enable secure access to applications on any cloud.
These functions are delivered through our FortiOS operating systems, which can deploy the full SASE stack through the cloud or on our ASIC-driven appliances.
All functions can be managed through a unified management console.
- Security Operations (SecOps)—Fortinet’s Security Operations solutions comply with the NIST cybersecurity framework of identify, protect, detect, respond and recover, and are delivered as a platform that automates detection and response to accelerate discovery and remediation.
The SecOps solution includes FortiAI generative AI assistant, FortiSIEM Security Information and Event Management, FortiSOAR Security Orchestration, Automation and Response, FortiEDR Endpoint Detection and Response, FortiXDR Extended Detection and Response, FortiMDR Managed Detection and Response Service, FortiNDR Network Detection and Response, FortiRecon Digital Risk Protection, FortiDeceptor Deception technology, FortiGuard SoCaaS, FortiSandbox Sandboxing Services and FortiGuard Incident Response Services, among other products.
We also offer training services to our end-customers and channel partners through our training team and authorized training partners.
We have also implemented a training certification program, NSE, to help ensure an understanding of our products and services.
Since 2020, Fortinet has also offered a number of free online training courses to help address prevalent industry-wide cybersecurity skills gaps and shortages.
Financial Highlights
- In 2023, we repurchased 27.2 million shares of common stock under the Repurchase Program for an aggregate purchase price of $1.50 billion, which excludes a $10.9 million accrual related to the 1% excise tax imposed by the Inflation Reduction Act of 2022.
In 2022, we repurchased 36.0 million shares of common stock for a total purchase price of $1.99 billion.
- Deferred revenue was $5.74 billion as of December 31, 2023, an increase of $1.09 billion, or 24%, from December 31, 2022.
Our revenue growth was driven primarily by service revenue.
Product revenue growth was impacted by an elevated cyber threat landscape, the convergence of security and networking, the impact of certain historical pricing actions, improving supply chain dynamics and changes in the backlog balance.
Product revenue growth rates decreased from 42% in 2022 to 8% in 2023 partially due to overall softening macroeconomic conditions.
We expect that product revenue growth rates will continue to be impacted by overall macroeconomic conditions in 2024.
Service revenue growth has accelerated over the past three years from 24% in 2021, to 26% in 2022, to 28% in 2023.
Security subscriptions outpaced technical support growth due to strength in secure networking subscriptions, SecOps and SASE.
While service revenue is expected to grow, we anticipate that the growth rates will be impacted by overall macroeconomic conditions in 2024.
Our days sales outstanding remained flat at 89 days for the years ended December 31, 2023 and 2022, primarily due to the sales linearity and certain geographies where extended payment terms are more prevalent.
The accounts receivable allowance for credit losses was $8.2 million as of December 31, 2023, an increase of $4.6 million compared to $3.6 million as of December 31, 2022, primarily due to an increase in past due invoices over 60 and 90 days.
discussed above and others identified in Part I, Item 1A “Risk Factors” in this Form 10-K.
We have also recognized revenue from customers who deploy our products in a bring-your-own-license (“BYOL”) arrangements at cloud service providers or at private clouds.
In a BYOL arrangement, a customer purchases a software license through our channel partners and deploys the software in a cloud provider’s environment, in third-party clouds or in their private cloud.
Deferred revenue was $5.74 billion as of December 31, 2023, an increase of $1.09 billion, or 24%, from December 31, 2022.
There are several
During 2023, our billings and product revenue fell below our expectations due to a slowdown in secure networking growth, along with challenges in sales execution and marketing programs.
In addition, we believe secure networking growth in the near term may be below historical growth rates.
In response to the slowdown in the secure networking market, we plan to shift our marketing and sales teams’ focus towards the faster growing SecOps and Unified SASE markets over the next several quarters, while maintaining our continued focus on leading innovation in secure networking and the convergence of security and networking.
We anticipate limited near-term growth in the secure networking market and shifting sales and marketing focus may result in certain risks, including go-to-market challenges, increased sales turnover and other execution challenges.
Our backlog has fluctuated over past quarters and any decrease in growth or negative growth of in-quarter billings and revenue may not be reflected by our aggregate billings and revenue.
As we have fulfilled, shipped and billed during a quarter to satisfy backlog, this has increased our aggregate billings and revenue during any particular quarter, and as the supply chain challenges normalize, the growth comparisons versus prior quarters where backlog contributed more to billings have become more challenging.
| Less: Adjustment due to adoption of ASU 2021-08 | | | — | | | | | | — | | | | | | (4.3) | | |
expenses, depreciation of property and equipment and facility-related expenses.
apply to taxable income in effect for the years in which those tax assets and liabilities are expected to be realized or settled.
| Product | | | $ | 1,927.3 | | | | | 36 | | % | | | | $ | 1,780.5 | | | | | 40 | | % | | | | $ | 146.8 | | | | | 8 | | % |
An excerpt. Shown here: 40 of 220 rewritten, 40 of 116 added and 40 of 71 removed. The counts are complete. For every sentence, read Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in the FY2024 filing and the FY2023 filing.
Item 7A. Quantitative and Qualitative Disclosures about Market Risk
5 rewritten, 0 added, 6 removed, 21 unchanged
[added: To minimize this risk, we maintain our] portfolio of cash, cash equivalents, investments and marketable equity securities in a variety of securities, including commercial paper, corporate debt securities, U.S. government and agency securities, certificates of deposit and term deposits, money market funds, municipal bonds and marketable equity securities.
A 10% decrease in interest rates would have resulted in a decrease of [removed: $12.0] [added: $15.5] million in our interest income in [removed: 2023,] [added: 2024,] and would have resulted in an insignificant decrease in our interest income in [removed: 2022] [added: 2023] and [removed: 2021][added: 2022.]
We record changes in the fair value of forward exchange contracts related to balance sheet accounts in other [removed: expense—net] [added: income (expense)—net] in the consolidated statements of income.
We recognized an expense of [removed: $7.0] [added: $16.9] million in [removed: 2023] [added: 2024] due to foreign currency transaction losses.
For foreign currency exchange rate risk, a 10% increase or decrease of foreign currency exchange rates against the U.S. dollar with all other variables held constant would have resulted in a $14.2 million change in the value of our foreign currency cash balances as of December 31, [removed: 2023.][added: 2024.]
To minimize this risk, we maintain our
On March 5, 2021, we issued $1.0 billion aggregate principal amount of senior notes, consisting of $500.0 million aggregate principal amount of 1.0% notes due March 15, 2026 and $500.0 million aggregate principal amount of 2.2% notes due March 15, 2031.
We carry the senior notes at face value less unamortized discount on our consolidated balance sheets.
As the senior notes bear interest at a fixed rate, we have no financial statement risk associated with changes in interest rates.
Refer to Note 11.
Debt in Part II, Item 8 of this Annual Report on Form 10-K.
Item 1. Business
54 rewritten, 75 added, 22 removed, 105 unchanged
Fortinet is a leader in [removed: cybersecurity and] [added: cybersecurity, driving] the convergence of networking and security.
Our integrated platform, the Fortinet Security Fabric, spans secure networking, unified Secure Access Service Edge (“SASE”) and [removed: AI-driven] [added: artificial intelligence (“AI”)-driven] security operations [removed: to deliver cybersecurity where our customers need it.][added: (“SecOps”).]
As of December 31, [removed: 2023,] [added: 2024, our end-customers were located in] over [added: 100 countries and included enterprises across] a [removed: half million customers trusted our solutions,] [added: wide variety of market verticals,] including [removed: enterprises such as in the] financial services, [removed: retail] [added: retail, healthcare] and operational technology [added: (“OT”)] market verticals, communication and security service providers, [removed: government organizations] and [removed: small and medium-sized businesses.][added: government organizations.]
As a global company headquartered in Sunnyvale, [removed: California with a large international customer base, the majority of] [added: California,] our research and development is [added: centered] in the United States and Canada with a global footprint of support and centers of excellence around the world.
As of December 31, [removed: 2023,] [added: 2024,] we held [removed: 957] [added: 1,034] U.S. patents and [removed: 1,299] [added: 1,378] global patents and we [removed: are] [added: have been] recognized in over [removed: 80] [added: 140] enterprise analyst reports demonstrating both our vision and execution across [removed: networking and] security [added: and networking] products.
[removed: FortiOS is] [added: - Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via FortiOS,] our networking and security operating system that is [removed: consistent across] [added: the foundation of] our [removed: firewalls and secure connectivity solutions] [added: Fortinet Security Fabric platform] and supports over 30 functions that can be delivered via a physical, virtual, cloud or [removed: Software] [added: software] as a [removed: Service (“SaaS”)] [added: SaaS] solution.
When delivered [removed: via] [added: through] our network firewall appliances, functionality is accelerated through our proprietary [removed: Application-Specific Integrated Circuits (“ASIC”)] [added: ASIC] technology.
These proprietary ASICs, [removed: combined with off-the-shelf central processing units (“CPUs”) and ASICs,] allow our systems to scale, run multiple applications at higher performance, lower power consumption and perform more processor-intensive operations, such as inspecting encrypted traffic, including streaming video.
[removed: The Network Firewall solution consists] [added: Our network firewall offerings consist] of [added: a] FortiGate data [removed: centers,] [added: center,] hyperscale and distributed firewalls, as well as encrypted applications (secure sockets layer (“SSL”) inspection, [removed: Virtual Private Network] [added: virtual private network] and [removed: IPsec] [added: Internet Protocol Security (“IPsec”)] connectivity).
Our ability to converge networking and security also enables the ethernet to become an extension of [removed: a company’s] [added: our customers’] security infrastructure through FortiSwitch and FortiLink.
Our wireless [removed: local area network (“LAN”)] [added: LAN] solution leverages secure networking to provide secure wireless access for the enterprise LAN edge.
[removed: The] [added: Our] Secure Connectivity solution includes FortiSwitch [removed: Secure Ethernet Switches,] [added: secure ethernet switches,] FortiAP [removed: Wireless Local Area Network Access Points] [added: wireless local area network access points] and FortiExtender 5G [removed: Connectivity Gateways, among other products.][added: connectivity gateways.]
The Fortinet Unified SASE solution [removed: is] [added: includes] a single-vendor SASE solution that includes [removed: Firewall,] [added: firewall,] SD-WAN, [removed: Secure Web Gateway, Cloud Access Services Broker,] [added: secure web gateway, cloud access services broker,] Data Loss [removed: Prevention, Zero Trust Network Access and cloud security, including Web Application Firewalls, Virtualized Firewalls] [added: Prevention (“DLP”)] and [removed: Cloud-Native Firewalls, among other products.][added: zero trust network access to deliver flexible secure access for all users.]
[removed: FortiGuard Labs] [added: FortiGuard Labs] is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize machine learning and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers.
FortiGuard [added: and Other] Security Services are a suite of AI-powered security capabilities that are natively integrated as part of the Fortinet Security Fabric to deliver coordinated detection and enforcement across the entire attack surface.
FortiCare Technical Support Service is a per-device [added: technical] support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet capabilities.
Global technical support is offered 24x7 with flexible add-ons, including enhanced [removed: Service Level Agreements] [added: service-level agreements] (“SLAs”) and [removed: premium] [added: priority] hardware replacement through [removed: in-][added: in-country and local depots.]
We offer three per-device support options tailored to the needs of our enterprise customers: FortiCare [removed: Premium,] [added: Elite,] FortiCare [removed: Elite] [added: Premium] and FortiCare Essential.
The FortiCare Elite service aims to provide [added: a] 15-minute response [removed: times] [added: time] for key product families.
During the year ended December 31, [removed: 2023,] [added: 2024,] we generated total revenue of [removed: $5.30] [added: $5.96] billion and net income of [removed: $1.15] [added: $1.75] billion.
See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, [removed: 2023] [added: 2024] and [removed: 2022] [added: 2023] and our consolidated statements of income, comprehensive income, equity (deficit), and cash flows for each of the three years ended December 31, [removed: 2023, 2022] [added: 2024, 2023] and [removed: 2021.][added: 2022.]
[removed: Fortinet was] [added: We were] founded with the mission of providing a converged networking and security approach that empowers organizations to adopt new technologies without worrying about how it would impact their ability to manage and secure their environments.
[removed: Customers] [added: Depending on the solution or form factor purchased, customers] may also access our products via the cloud through [removed: certain] [added: our data centers and PoPs, third-party colocations and] cloud providers such as Amazon Web Services, Microsoft Azure and Google Cloud.
Often, our customers also purchase our FortiGuard [added: and other] security subscription services and FortiCare technical support services.
Refer to Note 16 Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers [removed: that] accounted for 10% or more of our revenue or net accounts receivable.
In certain cases, we sell directly to large service [removed: providers and] [added: providers,] major systems [removed: integrators.][added: integrators and large end users.]
We work with many technology distributors, including Arrow Electronics, Inc., Exclusive, Ingram [removed: Micro] [added: Micro,] and TD [removed: Synnex (formerly Tech Data Corporation and Synnex Corporation, separately).][added: Synnex.]
In addition, we provide our cloud-based subscription offerings through Fortinet-owned data [removed: centers,] [added: centers and PoPs,] as well as data centers operated under [removed: co-location] [added: colocation] arrangements globally, and via public cloud providers.
We use a combination of internal marketing professionals and [removed: a] [added: our] network of regional and global channel partners.
Our current manufacturing partners include [removed: ADLINK Technology, Inc. (“ADLINK”),] [added: Accton Technology (“Accton”),] IBASE Technology, Inc. (“IBASE”), Micro-Star International Co. (“Micro-Star”), Senao Networks, Inc. (“Senao”), Wistron Corporation (“Wistron”), and a number of other manufacturers.
Approximately [removed: 95%] [added: 88%] of our hardware is manufactured in Taiwan.
Some of the components important to our business, including certain [removed: CPUs] [added: Central Processing Units (“CPUs”)] from Intel Corporation (“Intel”) and Advanced Micro Devices, Inc. (“AMD”), network and wireless chips from Broadcom Inc. (“Broadcom”), Marvell Technology Group Ltd. (“Marvell”), Qualcomm Incorporated (“Qualcomm”) and Intel and memory devices from Intel, Micron Technology (“Micron”), ADATA Technology Co., Ltd. (“ADATA”), Toshiba Corporation (“Toshiba”), Samsung Electronics Co., Ltd. (“Samsung”), and Western Digital Technologies, Inc. (“Western Digital”), are available from limited or sole sources of supply.
Our success in designing, developing, manufacturing and selling new or enhanced products will depend on a variety of factors, including identification of market demand for new products or new features, components selection, timely implementation of product design and development, product performance, quality, ease of use, costs of development, bill of materials, [added: delivery models,] effective manufacturing and assembly processes and sales and marketing.
We periodically have discussions with third parties regarding licensing [removed: Fortinet’s] [added: our] intellectual property (“IP”) and have sometimes taken legal action against competitors to protect our IP, and as a result third parties have paid us fees in return for licenses or covenants-not-to-sue related to Fortinet IP.
As of December 31, [removed: 2023,] [added: 2024,] we had [removed: 1,299] [added: 1,034] U.S. and [removed: foreign-issued] [added: 1,378 global] patents and [removed: 252] [added: 451] pending U.S. and foreign patent applications.
[removed: We generally enter into confidentiality] agreements with our employees, consultants, vendors and customers, and generally limit access to and distribution of our proprietary information.
In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws [added: of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.]
We are subject to regulation by various federal, state, regional, local and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, [removed: security,] [added: security and security certifications,] product safety, product labeling, environmental laws, consumer protection laws, anti-bribery laws, data privacy laws, import and export [removed: controls, federal] [added: controls and tariffs,] securities laws and tax laws and regulations.
Many of the laws and regulations that are or may be applicable to our business are changing or being tested in courts and could be interpreted in ways that could adversely impact our [removed: business.][added: business and additional laws and regulations applicable to our business may be enacted.]
Among others, our competitors include [removed: Aruba Networks, Inc. (“Aruba”),] Check Point Software Technologies Ltd. (“Check Point”), Cisco Systems, Inc. (“Cisco”), CrowdStrike Holdings, Inc. (“CrowdStrike”), F5 Networks, Inc. (“F5 Networks”), [added: Hewlett-Packard Enterprise (“HPE”),] Huawei Technologies Co., Ltd. (“Huawei”), Juniper Networks, Inc. (“Juniper”), [added: Microsoft Corporation (“Microsoft”), Netskope Inc. (“Netskope”),] Palo Alto Networks, Inc. (“Palo Alto Networks”), SonicWALL, Inc. (“SonicWALL”), Sophos Group Plc [removed: (“Sophos”), VMware, Inc. (“VMware”)] [added: (“Sophos”)] and Zscaler, Inc. (“Zscaler”).
As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies.
We were also ranked #7 in the Forbes Most Trusted Companies list in 2024.
Our competitive differentiation lies in our core technologies, which together provide performance, security, flexibility and integration across diverse environments.
- FortiOS—FortiOS enables the convergence of security and networking to enforce consistent security policies across form factors and edges.
As the foundation of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and analytics for comprehensive network visibility and control at scale.
To further validate our strategy, FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, Software-Defined Wide-Area Network (“SD-WAN”), Security Service Edge (“SSE”), SASE Platforms and Wired and Wireless Local Area Network (“LAN”).
- FortiASIC—Our Application-Specific Integrated Circuit (“ASIC”)-based security processing units (“SPUs”) increase the speed, scale, efficiency and value of our solutions while improving user experience, reducing footprint and power requirements.
From branch and campus to data center solutions, SPU-powered Fortinet appliances deliver superior Security Compute Ratings versus industry alternatives.
- FortiCloud—Our organically built global cloud infrastructure, powered by FortiStack which is our secure software as a service (“SaaS”) platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all layers, provides customers with global reach, flexible connectivity, and cost savings.
- FortiAI—Our AI innovations encompass generative AI (“GenAI”), big data AI for threat intelligence to process and analyze trillions of events using AI/Machine Learning (“ML”), network operations AI for self-healing networks and automated network orchestration, automation and response, and AI for Large Language Model (“LLM”) leakage to protection against data leakage into LLMs.
Our GenAI assists security teams to make better decisions, rapidly respond to threats and save time on even the most complex tasks.
FortiAI is seamlessly integrated into the user experience of several of our products, including FortiAnalyzer, FortiSIEM and FortiSOAR, to help optimize threat investigation and response, Security information and event management (“SIEM”) queries, Security, orchestration, automation, and response (“SOAR”) playbook creation, among other functions.
- FortiEndpoint—FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and extended detection and response (“XDR”), into a single agent.
It simplifies management and enhances visibility while reducing costs and complexity.
The solution gives IT teams the visibility and control they need, while security teams benefit from automated threat detection and response.
This minimizes the need for manual intervention and provides faster remediation of threats across all environments.
- OT Security—The Fortinet Security Fabric enables security for converged IT/OT ecosystems.
It also provides an OT Security Platform with features and products to extend Security Fabric capabilities to OT networks in factories, plants, remote locations and ships.
To help alleviate security risks across the organization, we have continued to enhance our OT Security Platform offerings.
These innovations range from edge products to Network Operations Center (“NOC”) and Security Operations Center (“SOC”) tools and services to provide effective and efficient networking and cybersecurity performance and operation.
These competitive differentiators allow us to provide Chief Information Officer (“CIO”)s, Chief Information Security Officer (“CISO”)s, Chief Technology Officer (“CTO”)s, and their organizations with an integrated AI-driven cybersecurity platform with over 50 products across three solution pillars.
- Unified Secure Access Service Edge (SASE)—As applications move to the cloud and hybrid workforce is now the norm, enabling secure access for users with zero trust framework becomes important.
We are one of the few vendors to deliver consistent convergence and AI-powered security across Secure SD-WAN and SSE to enable a single-vendor SASE framework with a cloud-centric architecture powered by FortiOS.
Our global and scalable cloud network includes 150+ points of presence to deliver the seamless secure access experience.
Given this, we are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform.
Additionally, we offer a full suite of comprehensive, integrated cloud security solutions that enable customers to secure their applications from code to cloud.
Our solutions include application security that includes our web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application protection and code security.
We deliver a holistic approach to cloud security, offering a single unified platform for cloud security and secure Continuous Integration/Continuous Delivery (“CI/CD”) application development needs, consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and multi-clouds, and delivering AI-driven security across integrated solutions with visibility and context across hybrid and multi-cloud.
Additionally, we also offer flexible consumption licensing programs that enable organizations to dynamically optimize their cloud security needs and investments as well as readily meet their cloud minimum spend commitment obligations with Cloud Service Providers.
- AI-Driven Security Operations (SecOps)—Our AI-Driven SecOps portfolio provides a comprehensive suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric.
At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that provides built-in SIEM, SOAR, XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control.
FortiSIEM delivers robust security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response.
This solution set also includes FortiEDR, FortiXDR, FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications.
To bolster their security posture, organizations contending with staff shortages can tap into FortiGuard services, including SOC-as-a-Service (“SOCaaS”), Managed detection and response (“MDR”), Security Posture Assessment and Incident Response.
Finally, FortiAI generative AI assistance streamlines operations, helping security teams stay ahead of an ever-evolving threat landscape.
Using millions of global network sensors, FortiGuard Labs monitors the worldwide attack surface and employs AI to mine that data for new threats.
In addition to FortiCare device level services, Advanced Support service options are available per account.
These services are available for regional account support in three options: Core, Pro and Pro Plus, and can be globalized at the Pro and Pro Plus levels.
Advanced Support brings support directly to each account, helping account holders to make their operations more effective and to plan and manage their solution lifecycle.
Additionally, we are committed to addressing the cybersecurity skills shortage through training and certification programs for customers, partners and employees.
- Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via our network firewall and our switches, access points and other secure connectivity solutions.
- Unified Secure Access Service Edge (SASE)—As applications move to the cloud and work from anywhere becomes established, cloud delivery is needed to enable secure access to applications on any cloud.
These functions are delivered through our FortiOS operating systems, which can deploy the full SASE stack through the cloud or on our ASIC-driven appliances.
All functions can be managed through a unified management console.
- Security Operations (SecOps)—Fortinet’s Security Operations solutions comply with the National Institute of Standards and Technology (“NIST”) cybersecurity framework of identify, protect, detect, respond and recover, and are delivered as a platform that automates detection and response to accelerate discovery and remediation.
The SecOps solution includes FortiAI generative AI assistant, FortiSIEM Security Information and Event Management, FortiSOAR Security Orchestration, Automation and Response, FortiEDR Endpoint Detection and Response, FortiXDR Extended Detection and Response, FortiMDR Managed Detection and Response Service, FortiNDR Network Detection and Response, FortiRecon Digital Risk Protection, FortiDeceptor Deception technology, FortiGuard SoCaaS, FortiSandbox Sandboxing Services and FortiGuard Incident Response Services, among other products.
country depots.
We also offer training services to our end-customers and channel partners through our training team and authorized training partners.
We have also implemented a training certification program, Network Security Expert (“NSE”), to help ensure an understanding of our products and services.
Since 2020, Fortinet has also offered a number of free online training courses to help address prevalent industry-wide cybersecurity skills gaps and shortages.
of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States.
functionality into existing products in a manner that discourages users from purchasing our products.
As a global company, much of our success is rooted in the diversity of our teams and our commitment to diversity, equity and inclusion (“DEI”).
We value diversity at all levels and continue to focus on enhancing our DEI initiatives across our workforce.
Environmental, Social and Governance
Our senior leadership sponsors the integration of CSR priorities throughout our business operations.
In addition, our CSR team, along with our internal cross-functional employee CSR Committee, engage with internal and external stakeholders to lead CSR execution, communications and disclosure.
We are engaged on a
decarbonization path to reach net zero for our Scope 1 and Scope 2 emissions by 2030, and formally signed on to the Science-Based Target Initiative commitment in September 2022.
We continued to expand partnerships with educational institutions and now have over 650 Authorized Academic Partners in 99 countries or territories across the world.
Internally, we continue to foster a culture of diversity and inclusion through our DEI Council, which meets quarterly, Employee Resource Groups and various campaigns and activities that engage our broader workforce.
Our board of directors regularly reviews our governance practices.
An excerpt. Shown here: 40 of 54 rewritten, 40 of 75 added and all 22 removed. The counts are complete. For every sentence, read Item 1. Business in the FY2024 filing and the FY2023 filing.
Cover and table of contents
41 rewritten, 14 added, 6 removed, 95 unchanged
For the year ended December 31, [removed: 2023][added: 2024]
The aggregate market value of voting stock held by non-affiliates of the registrant, as of June 30, [removed: 2023,] [added: 2024,] the last business day of the registrant’s most recently completed second quarter, was [removed: $38,472,948,871] [added: $31,496,083,015] (based on the closing price for shares of the registrant’s common stock as reported by The Nasdaq Global Select Market on that date).
As of February [removed: 22, 2024,] [added: 18, 2025,] there were [removed: 763,030,948] [added: 768,974,062] shares of the registrant’s common stock outstanding.
Portions of the registrant’s definitive Proxy Statement relating to its [removed: 2024] [added: 2025] Annual Meeting of Stockholders (“Proxy Statement”) are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated.
| | | | [Risk Factor [removed: Summary](#i980f0e0da2e545ad8a4174683b30b0d6_10)] [added: Summary](#i534f17d0e8de499a94e79a163c06da17_10)] | | | [removed: [1](#i980f0e0da2e545ad8a4174683b30b0d6_10)] [added: [1](#i534f17d0e8de499a94e79a163c06da17_10)] | | |
| Item 1. | | | [removed: [Business](#i980f0e0da2e545ad8a4174683b30b0d6_16)] [added: [Business](#i534f17d0e8de499a94e79a163c06da17_16)] | | | [removed: [3](#i980f0e0da2e545ad8a4174683b30b0d6_16)] [added: [3](#i534f17d0e8de499a94e79a163c06da17_16)] | | |
| Item 1A. | | | [Risk [removed: Factors](#i980f0e0da2e545ad8a4174683b30b0d6_19)] [added: Factors](#i534f17d0e8de499a94e79a163c06da17_19)] | | | [removed: [8](#i980f0e0da2e545ad8a4174683b30b0d6_19)] [added: [11](#i534f17d0e8de499a94e79a163c06da17_19)] | | |
| Item 1B. | | | [Unresolved Staff [removed: Comments](#i980f0e0da2e545ad8a4174683b30b0d6_22)] [added: Comments](#i534f17d0e8de499a94e79a163c06da17_22)] | | | [removed: [43](#i980f0e0da2e545ad8a4174683b30b0d6_22)] [added: [46](#i534f17d0e8de499a94e79a163c06da17_22)] | | |
| Item 2. | | | [removed: [Properties](#i980f0e0da2e545ad8a4174683b30b0d6_25)] [added: [Properties](#i534f17d0e8de499a94e79a163c06da17_28)] | | | [removed: [45](#i980f0e0da2e545ad8a4174683b30b0d6_25)] [added: [49](#i534f17d0e8de499a94e79a163c06da17_28)] | | |
| Item 3. | | | [Legal [removed: Proceedings](#i980f0e0da2e545ad8a4174683b30b0d6_28)] [added: Proceedings](#i534f17d0e8de499a94e79a163c06da17_31)] | | | [removed: [46](#i980f0e0da2e545ad8a4174683b30b0d6_28)] [added: [49](#i534f17d0e8de499a94e79a163c06da17_31)] | | |
| Item 4. | | | [Mine Safety [removed: Disclosures](#i980f0e0da2e545ad8a4174683b30b0d6_31)] [added: Disclosures](#i534f17d0e8de499a94e79a163c06da17_34)] | | | [removed: [46](#i980f0e0da2e545ad8a4174683b30b0d6_31)] [added: [49](#i534f17d0e8de499a94e79a163c06da17_34)] | | |
| Item 5. | | | [Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#i980f0e0da2e545ad8a4174683b30b0d6_37)] [added: Securities](#i534f17d0e8de499a94e79a163c06da17_40)] | | | [removed: [46](#i980f0e0da2e545ad8a4174683b30b0d6_37)] [added: [50](#i534f17d0e8de499a94e79a163c06da17_40)] | | |
| Item 6. | | | [removed: [\[Reserved\]](#i980f0e0da2e545ad8a4174683b30b0d6_43)] [added: [\[Reserved\]](#i534f17d0e8de499a94e79a163c06da17_46)] | | | [removed: [48](#i980f0e0da2e545ad8a4174683b30b0d6_43)] [added: [52](#i534f17d0e8de499a94e79a163c06da17_46)] | | |
| Item 7. | | | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#i980f0e0da2e545ad8a4174683b30b0d6_46)] [added: Operations](#i534f17d0e8de499a94e79a163c06da17_49)] | | | [removed: [49](#i980f0e0da2e545ad8a4174683b30b0d6_46)] [added: [53](#i534f17d0e8de499a94e79a163c06da17_49)] | | |
| Item 7A. | | | [Quantitative and Qualitative Disclosures about Market [removed: Risk](#i980f0e0da2e545ad8a4174683b30b0d6_58)] [added: Risk](#i534f17d0e8de499a94e79a163c06da17_61)] | | | [removed: [66](#i980f0e0da2e545ad8a4174683b30b0d6_58)] [added: [72](#i534f17d0e8de499a94e79a163c06da17_61)] | | |
| Item 8. | | | [Financial Statements and Supplementary [removed: Data](#i980f0e0da2e545ad8a4174683b30b0d6_61)] [added: Data](#i534f17d0e8de499a94e79a163c06da17_64)] | | | [removed: [68](#i980f0e0da2e545ad8a4174683b30b0d6_61)] [added: [73](#i534f17d0e8de499a94e79a163c06da17_64)] | | |
| Item 9. | | | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#i980f0e0da2e545ad8a4174683b30b0d6_154)] [added: Disclosure](#i534f17d0e8de499a94e79a163c06da17_163)] | | | [removed: [107](#i980f0e0da2e545ad8a4174683b30b0d6_154)] [added: [113](#i534f17d0e8de499a94e79a163c06da17_163)] | | |
| Item 9A. | | | [Controls and [removed: Procedures](#i980f0e0da2e545ad8a4174683b30b0d6_157)] [added: Procedures](#i534f17d0e8de499a94e79a163c06da17_166)] | | | [removed: [107](#i980f0e0da2e545ad8a4174683b30b0d6_157)] [added: [113](#i534f17d0e8de499a94e79a163c06da17_166)] | | |
| Item 9B. | | | [Other [removed: Information](#i980f0e0da2e545ad8a4174683b30b0d6_160)] [added: Information](#i534f17d0e8de499a94e79a163c06da17_169)] | | | [removed: [109](#i980f0e0da2e545ad8a4174683b30b0d6_160)] [added: [115](#i534f17d0e8de499a94e79a163c06da17_169)] | | |
| Item 9C. | | | [Disclosure Regarding Foreign Jurisdictions that Prevents [removed: Inspections](#i980f0e0da2e545ad8a4174683b30b0d6_163)] [added: Inspections](#i534f17d0e8de499a94e79a163c06da17_175)] | | | [removed: [109](#i980f0e0da2e545ad8a4174683b30b0d6_163)] [added: [115](#i534f17d0e8de499a94e79a163c06da17_175)] | | |
| Item 10. | | | [Directors, Executive Officers and Corporate [removed: Governance](#i980f0e0da2e545ad8a4174683b30b0d6_169)] [added: Governance](#i534f17d0e8de499a94e79a163c06da17_181)] | | | [removed: [109](#i980f0e0da2e545ad8a4174683b30b0d6_169)] [added: [116](#i534f17d0e8de499a94e79a163c06da17_181)] | | |
| Item 11. | | | [Executive [removed: Compensation](#i980f0e0da2e545ad8a4174683b30b0d6_172)] [added: Compensation](#i534f17d0e8de499a94e79a163c06da17_184)] | | | [removed: [109](#i980f0e0da2e545ad8a4174683b30b0d6_172)] [added: [116](#i534f17d0e8de499a94e79a163c06da17_184)] | | |
| Item 12. | | | [Security Ownership of Certain Beneficial Owners and Management and Related Stockholder [removed: Matters](#i980f0e0da2e545ad8a4174683b30b0d6_175)] [added: Matters](#i534f17d0e8de499a94e79a163c06da17_187)] | | | [removed: [109](#i980f0e0da2e545ad8a4174683b30b0d6_175)] [added: [116](#i534f17d0e8de499a94e79a163c06da17_187)] | | |
| Item 13. | | | [Certain Relationships and Related Transactions, and Director [removed: Independence](#i980f0e0da2e545ad8a4174683b30b0d6_178)] [added: Independence](#i534f17d0e8de499a94e79a163c06da17_190)] | | | [removed: [110](#i980f0e0da2e545ad8a4174683b30b0d6_178)] [added: [116](#i534f17d0e8de499a94e79a163c06da17_190)] | | |
| Item 14. | | | [Principal Accounting Fees and [removed: Services](#i980f0e0da2e545ad8a4174683b30b0d6_181)] [added: Services](#i534f17d0e8de499a94e79a163c06da17_193)] | | | [removed: [110](#i980f0e0da2e545ad8a4174683b30b0d6_181)] [added: [116](#i534f17d0e8de499a94e79a163c06da17_193)] | | |
| Item 15. | | | [Exhibits and Financial Statement [removed: Schedules](#i980f0e0da2e545ad8a4174683b30b0d6_187)] [added: Schedules](#i534f17d0e8de499a94e79a163c06da17_199)] | | | [removed: [111](#i980f0e0da2e545ad8a4174683b30b0d6_187)] [added: [117](#i534f17d0e8de499a94e79a163c06da17_199)] | | |
| Item 16. | | | [Form 10-K [removed: Summary](#i980f0e0da2e545ad8a4174683b30b0d6_199)] [added: Summary](#i534f17d0e8de499a94e79a163c06da17_214)] | | | [removed: [114](#i980f0e0da2e545ad8a4174683b30b0d6_199)] [added: [120](#i534f17d0e8de499a94e79a163c06da17_214)] | | |
- Adverse economic conditions, such as a possible economic downturn or recession, and possible impacts of inflation or stagflation, [removed: increasing] [added: tariffs] or [removed: decreasing] [added: other trade disruptions, changing] interest rates, [removed: instability] [added: changes] in [removed: the global banking system] [added: government spending] or [added: regulation or] reduced information technology [added: (“IT”)] spending, including firewall spending, may adversely impact our business.
- As a result of supply chain disruptions in previous periods, we increased our purchase order commitments in previous periods and, [removed: as a result,] [added: were in some instances required to and] may [added: in the future] be required to accept or pay for components and finished goods regardless of our level of sales in a particular period, which may negatively [added: or unpredictably] impact our operating results and financial condition.
- Our billings, revenue, and free cash flow growth may slow [removed: further] or may not [removed: continue,] [added: continue to grow,] and our operating margins may decline.
- Our real estate [removed: investments,] [added: assets,] including construction, acquisitions, [removed: sales, or strategy changes,] [added: leasing activity,] and ongoing maintenance and management of office buildings, warehouses, data centers and points of [removed: presence,] [added: presence (“PoPs”),] as well as data center expansions or enhancements, could involve significant risks to our business.
- Any weakness in sales strategy, [removed: productivity] [added: productivity, personnel] and execution could negatively impact our results of operations.
- We rely on third-party channel partners for substantially all of our billings, [removed: revenue] [added: revenue,] and a small number of distributors represents a large percentage of our revenue and accounts receivable.
- Reliance on a concentration of shipments at the end of the quarter [added: or changes in shipping terms] could cause our billings and revenue to fall below expected levels.
- We rely significantly on revenue from FortiGuard [added: and other] security [removed: subscription] [added: subscriptions] and FortiCare technical support services, and revenue from these services may decline or fluctuate.
- A portion of our revenue is generated by sales to government organizations and other customers, which are subject to a number of regulatory requirements, [added: their own supply chain constraints and contractual requirements,] challenges and risks.
- We order components from third-party manufacturers based on our forecasts of future demand and targeted inventory levels, which exposes us to the risk of [removed: both] product shortages, may result in lost [removed: sales and] [added: sales,] higher [removed: expenses, including excess] [added: expenses and] inventory [added: excesses which may lead to inventory] charges and costs related to future purchase commitments, [removed: and may require] [added: possibly requiring] us to sell our products at discounts or offer various other incentives.
- We depend on third parties to provide various components for our products and build our products and are susceptible to manufacturing delays, capacity [removed: constraints and] [added: constraints,] cost [removed: increases.][added: increases, and changes in the geopolitical environment.]
- We are susceptible to defects or [removed: vulnerabilities] [added: vulnerabilities, including critical vulnerabilities,] in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or [removed: vulnerabilities] [added: vulnerabilities, including critical vulnerabilities,] in our products or [removed: services or the] [added: services,] failure of our products or services to detect or prevent a security [removed: incident,] [added: incident] or [removed: the] [added: to cause a disruption to operations,] failure [added: of our customers] to [added: implement preventative actions such as updates to one of our deployed solutions or failure to] help secure our [removed: customers or] [added: customers, could] cause our products or services to allow unauthorized access to our [removed: customers network, could] [added: customers’ networks and] harm our operational results and reputation more significantly as compared to [removed: certain] other [removed: companies given we are a security company.][added: companies.]
- [removed: Investors’] [added: Investors’, activists’] and regulators’ expectations of our [added: investments and] performance relating to environmental, social and governance factors may impose additional costs and expose us to new risks.
For the Year Ended December 31, 2024
| Item 1C. | | | [Cybersecurity](#i534f17d0e8de499a94e79a163c06da17_25) | | | [46](#i534f17d0e8de499a94e79a163c06da17_25) | | |
| | | | [Exhibit Index](#i534f17d0e8de499a94e79a163c06da17_211) | | | [118](#i534f17d0e8de499a94e79a163c06da17_211) | | |
| | | | [Signatures](#i534f17d0e8de499a94e79a163c06da17_217) | | | [121](#i534f17d0e8de499a94e79a163c06da17_217) | | |
- Our backlog may fluctuate over quarters.
If we experience supply chain shortages and cannot fulfill orders or if customers cancel or delay delivery of orders, our backlog may be affected, which will negatively impact our aggregate backlog to billings conversion and revenue in such quarter.
A reduction to backlog increases our aggregate billings and revenue during the quarter when delivered.
- As the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings.
For the fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates.
Our Product Security Incident Response
Team publicly posts on our FortiGuard Labs website known product vulnerabilities, including critical vulnerabilities, and methods for customers to mitigate the risk of vulnerabilities.
However, there can be no assurance that such posts will be sufficiently timely, accurate or complete or that those customers will see such posts or take steps to mitigate the risk of vulnerabilities, and certain customers may be negatively impacted.
- If our internal enterprise IT networks, our operational networks, our research and development (“R&D”) networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted.
- Global economic uncertainty can weaken and harm our financial position.
| Item 1C. | | | [C](#i980f0e0da2e545ad8a4174683b30b0d6_549755815465)[ybersecurity](#i980f0e0da2e545ad8a4174683b30b0d6_549755815465) | | | [43](#i980f0e0da2e545ad8a4174683b30b0d6_549755815465) | | |
| | | | [Exhibit Index](#i980f0e0da2e545ad8a4174683b30b0d6_196) | | | [112](#i980f0e0da2e545ad8a4174683b30b0d6_196) | | |
| | | | [Signatures](#i980f0e0da2e545ad8a4174683b30b0d6_202) | | | [115](#i980f0e0da2e545ad8a4174683b30b0d6_202) | | |
- Our backlog has fluctuated over past quarters and any decrease in growth or negative growth of in-quarter billings and revenue may not be reflected by our aggregate billings and revenue.
As we have fulfilled, shipped and billed during a quarter to satisfy backlog, this has increased our aggregate billings and revenue during any particular quarter, and as the supply chain challenges normalize, the growth comparisons versus prior quarters where backlog contributed more to billings have become more challenging.
In addition, any additional future impairment of the value of our investment in Linksys Holdings, Inc. (“Linksys”) could negatively affect our financial condition and results of operations.
An excerpt. Shown here: 40 of 41 rewritten, all 14 added and all 6 removed. The counts are complete. For every sentence, read Cover and table of contents in the FY2024 filing and the FY2023 filing.
Item 1C. Cybersecurity
15 rewritten, 8 added, 1 removed, 23 unchanged
Our board of directors recognizes the critical importance of maintaining the trust and confidence of our customers, end users, business partners, [added: governmental entities,] stockholders and employees.
[added: In general, we seek to address cybersecurity risks through a broad, cross-functional approach that is focused on] preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
[removed: The] [added: Historically, the] Audit Committee of our board of directors (the “Audit Committee”) [removed: is] [added: was] responsible for reviewing with management our cybersecurity and other information technology risks, controls and processes, including the processes used to prevent or mitigate cybersecurity risks and respond to cybersecurity events.
Our executives with responsibility over [removed: cybersecurity] [added: cybersecurity, including our Chief Information Security Officer,] provide quarterly reports to the [removed: Audit] [added: Cybersecurity] Committee as well as to the Chief Executive Officer and other members of our senior management as appropriate.
[removed: These] [added: The quarterly] reports [added: to the Cybersecurity Committee] include updates on [removed: our] cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program and the emerging threat landscape.
Our [added: cybersecurity] program is regularly evaluated by internal and external experts with the results of those reviews reported to senior management and the [removed: Audit] [added: Cybersecurity] Committee.
We also actively engage with key [removed: vendors,] [added: vendors] and intelligence and law enforcement communities as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures.
The [removed: Audit] [added: Cybersecurity] Committee also receives prompt and timely information regarding any cybersecurity threat or incident that meets established reporting thresholds, as well as ongoing updates regarding any such threat or incident until it has been mitigated, resolved or otherwise addressed.
For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see our risk factors, including our risk factor titled [removed: *“If] [added: *“If] our internal enterprise IT networks, on which we conduct internal business and interface externally, our operational networks, through which we connect to customers, vendors and partners systems and provide services, or our research and development networks, our back-end labs and cloud stacks hosted in our data [removed: centers,] [added: centers or PoPs,] colocation vendors or public cloud providers, through which we research, develop and host products and services, are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely [removed: impacted.”*][added: impacted.”*]
Governance: As discussed in more detail above under the heading, “Governance,” our board of directors’ oversight of cybersecurity risk management is supported by the [removed: Audit] [added: Cybersecurity] Committee, which regularly interacts with executives with responsibility for cybersecurity, our Chief Executive Officer, Chief Technology Officer and President, Chief Financial Officer, Chief Operating Officer/General [removed: Counsel] [added: Counsel, our CISO,] and other members of management.
Management is promptly updated regarding any significant security events and the [removed: Audit] [added: Cybersecurity] Committee regularly reviews updates from our [added: CISO,] information security and product security leaders about cyber threat response preparedness, security controls and procedures, security program maturity milestones, risk and approaches to risk mitigation and the current and emerging threat landscape.
In addition, all members of our board of directors receive management’s cybersecurity updates to the [removed: Audit] [added: Cybersecurity] Committee as part of their regular attendance at meetings of our board of directors.
Incident Response and Recovery Planning: We have established and [removed: maintains] [added: maintain] broad incident response and recovery plans that help enable its effective and orderly management of, and response to, any identified security incidents, including escalation and internal and external-notification steps, allowing the incident response team to respond in a timely manner and enlist appropriate personnel and third-party experts.
Education and Awareness: We provide regular, mandatory training for personnel and contractors regarding cybersecurity threats as a means to equip [removed: Fortinet] [added: our] personnel with effective tools to address cybersecurity threats and to communicate [removed: Fortinet’s] [added: our] evolving information security policies, standards, processes and practices.
The results of such assessments, audits and reviews are reported to the [removed: Audit] [added: Cybersecurity] Committee and our board of directors and to our management, and we adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
As a global cybersecurity provider, cybersecurity risk management is integral to our company.
However, due to the importance of cybersecurity to our company, in July 2024, our board of directors formed Cybersecurity Committee of our board of directors (the “Cybersecurity
Committee”), which is solely dedicated to cybersecurity risk management.
Each member of our board of directors is invited to attend all meetings of the committees of our board of directors, including the Cybersecurity Committee, and thus all of the members of our board of directors are apprised of cybersecurity developments.
Our CISO is primarily responsible for our cybersecurity risk management program and partners with our legal team on data privacy matters at the management level.
Our CISO, Dr. Carl Windsor, has over 25 years of experience in various technology and cybersecurity leadership positions, including over 18 years at our company driving product security and strategy and reports to the board Cybersecurity Committee.
The CISO’s leadership team members are all seasoned information security professionals, covering a wide range of security disciplines, who have worked at some of the largest well-known brand names and are experts in their fields.
Our CISO monitors, and participates in, our various cybersecurity policies and procedures, and our cybersecurity team regularly updates our CISO on the current status.
In general, we seek to address cybersecurity risks through a broad, cross-functional approach that is focused on
Item 2. Properties
12 rewritten, 7 added, 3 removed, 5 unchanged
Our corporate headquarters is located in Sunnyvale, [removed: California] [added: California,] and comprises approximately 395,000 square feet of building space on 21 acres of [removed: land.][added: land and includes space for future development of PoPs.]
Along with our corporate headquarters, as of December 31, [removed: 2023,] [added: 2024,] we operated the following facilities:
| [removed: Burnaby] [added: Burnaby, Calgary] and Ottawa, Canada | | | | | | [removed: 560,000] [added: 680,000] | | | | | | [removed: Datacenter operations,] [added: Data center, PoP,] support functions and research and development | | |
| Union City, California | | | | | | [removed: 350,000] [added: 770,000] | | | | | | [removed: Manufacturing assembly] [added: Warehousing, operations,] and [removed: operations] [added: PoP] | | |
| Plano & Frisco, Texas | | | | | | 130,000 | | | | | | Office space and [removed: datacenter operations] [added: data center] | | |
| Torija, Spain | | | | | | 120,000 | | | | | | [removed: Future development of datacenter operations] [added: Data center] | | |
| Chicago, Illinois | | | | | | [removed: 100,000] [added: 114,000] | | | | | | Office space and [removed: retail] [added: PoP] | | |
| Valbonne, France | | | | | | 70,000 | | | | | | Sales and support functions [added: and PoP] | | |
We maintain additional leased offices throughout the world, predominantly used as sales and support [removed: offices,] [added: offices] and [added: PoPs, and] leased data center spaces throughout the world operated under [removed: co-location] [added: colocation] arrangements.
We believe that our existing properties [added: are sufficient and suitable to meet our current needs.]
We intend to expand our facilities, develop unoccupied space, or add new facilities to support our future growth and enter new product markets, and we believe that suitable additional [removed: or alternative] space will be available or can be developed as needed to accommodate ongoing operations and any such growth.
For information regarding the geographical location of our property and equipment, refer to Note 16 [removed: to] [added: of] our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.
In January 2024, we purchased an additional 480,000 square feet of building space in Santa Clara, California, which is located in close proximity to our corporate headquarters and includes space for future development of a data center.
Refer to Note 17.
Subsequent Events, in Part II, Item 8 of this Annual Report on Form-10K for the February 2025 signing of a definitive agreement subject to regulatory approval for an additional 540,000 square feet of building space in Frankfurt, Germany.
| Atlanta, Georgia | | | | | | 226,000 | | | | | | Sales and support functions and PoP | | |
| Sunnyvale, California | | | | | | 97,000 | | | | | | Development | | |
| McMahons Point, Australia | | | | | | 40,000 | | | | | | Office space and PoP | | |
| New York, New York | | | | | | 40,000 | | | | | | Sales and support functions and PoP | | |
Refer to Note 17, Subsequent Events, in Part II, Item 8 of this Annual Report on Form 10-K for the January 2024 purchase of an additional 480,000 square feet in Santa Clara, CA which is located in close proximity to corporate headquarters.
We also own additional building space in Sunnyvale and Union City, California, and Sydney, Australia, for future development of approximately 450,000 square feet in the aggregate.
are sufficient and suitable to meet our current needs.
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
10 rewritten, 5 added, 12 removed, 27 unchanged
As of February [removed: 22, 2024,] [added: 18, 2025,] there were [removed: 45] [added: 50] holders of record of our common stock.
*This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities [removed: and] Exchange Act of 1934* (*the “Exchange Act”), or incorporated by reference into any filing of Fortinet under the Securities Act of 1933, as amended (the “Securities Act”), or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.*
[removed: ][added: ]
| | | | | | | December [removed: 2018] [added: 2019] * | | | | | | December [removed: 2019] [added: 2020] | | | | | | December [removed: 2020] [added: 2021] | | | | | | December [removed: 2021] [added: 2022] | | | | | | December [removed: 2022] [added: 2023] | | | | | | December [removed: 2023] [added: 2024] | | |
| * Assumes that $100 was invested on December 31, [removed: 2018] [added: 2019] in stock or index, including reinvestment of dividends. Stockholder returns over the indicated period should not be considered indicative of future stockholder returns. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
In January 2016, our board of directors approved our Share Repurchase [removed: Program (the “Repurchase Program”),] [added: Program,] which authorized the repurchase of up to $200.0 million of our outstanding common stock through December 31, 2017.
From 2016 through [removed: 2022,] [added: 2023,] our board of directors approved increases to our Repurchase Program by various amounts and extended the term to February [removed: 28, 2023.][added: 29, 2024.]
In [removed: April 2023 and July 2023,] [added: October 2024,] our board of directors approved [added: a] $1.0 billion [removed: and $500.0 million increases] [added: increase] in the authorized stock repurchase amount under the Repurchase [removed: Program, respectively,] [added: Program and extended the term of the Repurchase Program to February 28, 2026,] bringing the aggregate amount authorized to be repurchased to [removed: $6.75 billion.][added: $8.25 billion of our outstanding common stock through February 28, 2026.]
The Repurchase Program does not require us to purchase a minimum number of shares, and may be [removed: suspended, modified or discontinued at any time without prior notice.]
As of [removed: February 23,] [added: December 31,] 2024, approximately [removed: $1.03] [added: $2.03] billion remained available for future share [removed: repurchases.][added: repurchases under the Repurchase Program.]
| Fortinet, Inc. | | | | | | $ | 100 | | | | | $ | 139 | | | | | $ | 337 | | | | | $ | 229 | | | | | $ | 274 | | | | | $ | 442 | |
| S&P 500 Index | | | | | | $ | 100 | | | | | $ | 116 | | | | | $ | 148 | | | | | $ | 119 | | | | | $ | 148 | | | | | $ | 182 | |
| NASDAQ Computer | | | | | | $ | 100 | | | | | $ | 150 | | | | | $ | 207 | | | | | $ | 133 | | | | | $ | 221 | | | | | $ | 301 | |
suspended, modified or discontinued at any time without prior notice.
There were no repurchases of common stock during the three months ended December 31, 2024.
| Fortinet, Inc. | | | | | | $ | 100 | | | | | $ | 152 | | | | | $ | 211 | | | | | $ | 510 | | | | | $ | 347 | | | | | $ | 416 | |
| S&P 500 Index | | | | | | $ | 100 | | | | | $ | 129 | | | | | $ | 150 | | | | | $ | 190 | | | | | $ | 153 | | | | | $ | 190 | |
| NASDAQ Computer | | | | | | $ | 100 | | | | | $ | 150 | | | | | $ | 225 | | | | | $ | 311 | | | | | $ | 200 | | | | | $ | 332 | |
In February 2023, our board of directors approved an extension of the Repurchase Program to February 29, 2024.
The following table provides information with respect to the shares of common stock we repurchased under the Repurchase Program during the three months ended December 31, 2023 (in millions, except average price paid per share amounts):
| | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Period | | | | | | Total Number of Shares Purchased | | | | | | Average Price Paid per Share | | | | | | Total Number of Shares Purchased as Part of Publicly Announced Plan or Program | | | | | | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Plans or Programs | | |
| October 1 - October 31, 2023 | | | | | | 7.7 | | | | | | $ | 57.43 | | | | | 7.7 | | | | | | $ | 980.0 | |
| November 1 - November 30, 2023 | | | | | | 9.1 | | | | | | $ | 49.75 | | | | | 9.1 | | | | | | $ | 529.1 | |
| December 1 - December 31, 2023 | | | | | | — | | | | | | $ | — | | | | | — | | | | | | $ | 529.1 | |
| Total | | | | | | 16.8 | | | | | | $ | 53.29 | | | | | 16.8 | | | | | | | | |
Item 8. Financial Statements and Supplementary Data
438 rewritten, 223 added, 153 removed, 738 unchanged
| [Report of Independent Registered Public Accounting [removed: Firm](#i980f0e0da2e545ad8a4174683b30b0d6_64)] [added: Firm](#i534f17d0e8de499a94e79a163c06da17_67)] (PCAOB ID No.34) | | | [removed: [69](#i980f0e0da2e545ad8a4174683b30b0d6_64)] [added: [74](#i534f17d0e8de499a94e79a163c06da17_67)] | | |
| [Consolidated Balance Sheets as of December 31, [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_67)[3](#i980f0e0da2e545ad8a4174683b30b0d6_67)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_70)[4](#i534f17d0e8de499a94e79a163c06da17_70)] [and [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_67)[2](#i980f0e0da2e545ad8a4174683b30b0d6_67)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_70)[3](#i534f17d0e8de499a94e79a163c06da17_70)] | | | [removed: [71](#i980f0e0da2e545ad8a4174683b30b0d6_67)] [added: [76](#i534f17d0e8de499a94e79a163c06da17_70)] | | |
| [Consolidated Statements of Income for the [removed: year](#i980f0e0da2e545ad8a4174683b30b0d6_70)[s](#i980f0e0da2e545ad8a4174683b30b0d6_70) [ended] [added: years ended] December 31, [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_70)[3](#i980f0e0da2e545ad8a4174683b30b0d6_70)[, 202](#i980f0e0da2e545ad8a4174683b30b0d6_70)[2](#i980f0e0da2e545ad8a4174683b30b0d6_70)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_73)[4](#i534f17d0e8de499a94e79a163c06da17_73)[, 202](#i534f17d0e8de499a94e79a163c06da17_73)[3](#i534f17d0e8de499a94e79a163c06da17_73)] [and [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_70)[1](#i980f0e0da2e545ad8a4174683b30b0d6_70)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_73)[2](#i534f17d0e8de499a94e79a163c06da17_73)] | | | [removed: [72](#i980f0e0da2e545ad8a4174683b30b0d6_70)] [added: [77](#i534f17d0e8de499a94e79a163c06da17_73)] | | |
| [Consolidated Statements of Comprehensive Income for the [removed: year](#i980f0e0da2e545ad8a4174683b30b0d6_73)[s](#i980f0e0da2e545ad8a4174683b30b0d6_73) [ended] [added: years ended] December 31, [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_73)[3](#i980f0e0da2e545ad8a4174683b30b0d6_73)[, 202](#i980f0e0da2e545ad8a4174683b30b0d6_73)[2](#i980f0e0da2e545ad8a4174683b30b0d6_73)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_76)[4](#i534f17d0e8de499a94e79a163c06da17_76)[, 202](#i534f17d0e8de499a94e79a163c06da17_76)[3](#i534f17d0e8de499a94e79a163c06da17_76)] [and [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_73)[1](#i980f0e0da2e545ad8a4174683b30b0d6_73)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_76)[2](#i534f17d0e8de499a94e79a163c06da17_76)] | | | [removed: [73](#i980f0e0da2e545ad8a4174683b30b0d6_73)] [added: [78](#i534f17d0e8de499a94e79a163c06da17_76)] | | |
| [Consolidated Statements of Equity (Deficit) for the [removed: year](#i980f0e0da2e545ad8a4174683b30b0d6_76)[s](#i980f0e0da2e545ad8a4174683b30b0d6_76) [ended] [added: years ended] December 31, [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_76)[3](#i980f0e0da2e545ad8a4174683b30b0d6_76)[, 202](#i980f0e0da2e545ad8a4174683b30b0d6_76)[2](#i980f0e0da2e545ad8a4174683b30b0d6_76)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_79)[4](#i534f17d0e8de499a94e79a163c06da17_79)[, 202](#i534f17d0e8de499a94e79a163c06da17_79)[3](#i534f17d0e8de499a94e79a163c06da17_79)] [and [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_76)[1](#i980f0e0da2e545ad8a4174683b30b0d6_76)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_79)[2](#i534f17d0e8de499a94e79a163c06da17_79)] | | | [removed: [74](#i980f0e0da2e545ad8a4174683b30b0d6_76)] [added: [79](#i534f17d0e8de499a94e79a163c06da17_79)] | | |
| [Consolidated Statements of Cash Flows for the [removed: year](#i980f0e0da2e545ad8a4174683b30b0d6_79)[s](#i980f0e0da2e545ad8a4174683b30b0d6_79) [ended] [added: years ended] December 31, [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_79)[3](#i980f0e0da2e545ad8a4174683b30b0d6_79)[, 202](#i980f0e0da2e545ad8a4174683b30b0d6_79)[2](#i980f0e0da2e545ad8a4174683b30b0d6_79)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_82)[4](#i534f17d0e8de499a94e79a163c06da17_82)[, 202](#i534f17d0e8de499a94e79a163c06da17_82)[3](#i534f17d0e8de499a94e79a163c06da17_82)] [and [removed: 202](#i980f0e0da2e545ad8a4174683b30b0d6_79)[1](#i980f0e0da2e545ad8a4174683b30b0d6_79)] [added: 202](#i534f17d0e8de499a94e79a163c06da17_82)[2](#i534f17d0e8de499a94e79a163c06da17_82)] | | | [removed: [75](#i980f0e0da2e545ad8a4174683b30b0d6_79)] [added: [80](#i534f17d0e8de499a94e79a163c06da17_82)] | | |
| [Notes to Consolidated Financial [removed: Statements](#i980f0e0da2e545ad8a4174683b30b0d6_82)] [added: Statements](#i534f17d0e8de499a94e79a163c06da17_85)] | | | [removed: [76](#i980f0e0da2e545ad8a4174683b30b0d6_82)] [added: [81](#i534f17d0e8de499a94e79a163c06da17_85)] | | |
We have audited the accompanying consolidated balance sheets of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] the related consolidated statements of income, comprehensive income, equity (deficit), and cash flows, for each of the three years in the period ended December 31, [removed: 2023,] [added: 2024,] and the related notes (collectively referred to as the “financial statements”).
In our opinion, the financial statements present fairly, in all material respects, the financial position of the Company as of December 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] and the results of its operations and its cash flows for each of the three years in the period ended December 31, [removed: 2023,] [added: 2024,] in conformity with accounting principles generally accepted in the United States of America.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of December 31, [removed: 2023,] [added: 2024,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by the Committee of Sponsoring Organizations of the Treadway Commission and our report dated February [removed: 23, 2024,] [added: 21, 2025,] expressed an unqualified opinion on the Company’s internal control over financial reporting.
We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the [removed: U.S.] [added: US] federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
[removed: Litigation] [added: Revenue] – Refer to [removed: Notes] [added: Note] 1 and [removed: 12] [added: Note 2] to the financial statements
| | | | December 31, [removed: 2023] [added: 2024] | | | | | | December 31, [removed: 2022] [added: 2023] | | |
| Cash and cash equivalents | | | $ | [removed: 1,397.9] [added: 2,875.9] | | | | | $ | [removed: 1,682.9] [added: 1,397.9] | |
| Short-term investments | | | [removed: 1,021.5] [added: 1,126.4] | | | | | | [removed: 502.6] [added: 1,021.5] | | |
| Marketable equity securities | | | [removed: 21.0] [added: 64.2] | | | | | | [removed: 25.5] [added: 21.0] | | |
| Accounts receivable—Net of allowance for credit losses of [removed: $8.2] [added: $5.9] million and [removed: $3.6] [added: $8.2] million at December 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] respectively | | | [removed: 1,402.0] [added: 1,463.4] | | | | | | [removed: 1,261.7] [added: 1,402.0] | | |
| Inventory | | | [removed: 484.8] [added: 315.5] | | | | | | [removed: 264.6] [added: 484.8] | | |
| Prepaid expenses and other current assets | | | [removed: 101.1] [added: 126.1] | | | | | | [removed: 73.1] [added: 101.1] | | |
| Total current assets | | | [removed: 4,428.3] [added: 5,971.5] | | | | | | [removed: 3,810.4] [added: 4,428.3] | | |
| PROPERTY AND EQUIPMENT—NET | | | [removed: 1,044.4] [added: 1,349.5] | | | | | | [removed: 898.5] [added: 1,044.4] | | |
| DEFERRED CONTRACT COSTS | | | [removed: 605.6] [added: 622.9] | | | | | | [removed: 518.2] [added: 605.6] | | |
| DEFERRED TAX ASSETS | | | [removed: 868.8] [added: 1,335.6] | | | | | | [removed: 569.4] [added: 868.8] | | |
| GOODWILL | | | [removed: 126.5] [added: 235.4] | | | | | | [removed: 128.0] [added: 126.5] | | |
| OTHER INTANGIBLE ASSETS—NET | | | [removed: 35.3] [added: 115.0] | | | | | | [removed: 56.0] [added: 35.3] | | |
| OTHER ASSETS | | | [removed: 150.0] [added: 133.2] | | | | | | [removed: 202.0] [added: 150.0] | | |
| [removed: TOTAL ASSETS] [added: Total assets] | | | $ | [added: 9,763.1 | | | | | $ |] 7,258.9 | | | | | $ | 6,228.0 | |
| LIABILITIES AND STOCKHOLDERS’ [removed: DEFICIT] [added: EQUITY (DEFICIT)] | | | | | | | | | | | |
| Accounts payable | | | $ | [removed: 204.3] [added: 190.9] | | | | | $ | [removed: 243.4] [added: 204.3] | |
| Accrued liabilities | | | [removed: 423.7] [added: 337.9] | | | | | | [removed: 266.3] [added: 423.7] | | |
| Accrued payroll and compensation | | | [removed: 242.3] [added: 255.7] | | | | | | [removed: 219.4] [added: 242.3] | | |
| Deferred revenue | | | [removed: 2,848.7] [added: 3,276.2] | | | | | | [removed: 2,349.3] [added: 2,848.7] | | |
| Total current liabilities | | | [removed: 3,719.0] [added: 4,060.7] | | | | | | [removed: 3,078.4] [added: 3,719.0] | | |
| DEFERRED REVENUE | | | [removed: 2,886.3] [added: 3,084.7] | | | | | | [removed: 2,291.0] [added: 2,886.3] | | |
| LONG-TERM DEBT | | | [removed: 992.3] [added: 994.3] | | | | | | [removed: 990.4] [added: 992.3] | | |
| OTHER LIABILITIES | | | [removed: 124.7] [added: 129.6] | | | | | | [removed: 149.8] [added: 124.7] | | |
| Total liabilities | | | [removed: 7,722.3] [added: 8,269.3] | | | | | | [removed: 6,509.6] [added: 7,722.3] | | |
| STOCKHOLDERS’ [removed: DEFICIT:] [added: EQUITY (DEFICIT):] | | | | | | | | | | | |
| Common stock, $0.001 par value—1,500.0 shares authorized; [removed: 761.0] [added: 767.0] shares and [removed: 781.5] [added: 761.0] shares issued and outstanding at December 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] respectively | | | 0.8 | | | | | | 0.8 | | |
| Additional paid-in capital | | | [removed: 1,416.4] [added: 1,636.2] | | | | | | [removed: 1,284.2] [added: 1,416.4] | | |
The Company’s contracts with customers often include multiple performance obligations, such as hardware, software license, security subscription, technical support services, cloud and other services, which are generally capable of being distinct and accounted for as separate performance obligations.
Pursuant to accounting principles generally accepted in the United States of America, the Company is required to evaluate whether each performance obligation represents goods and services that are distinct for purposes of determining the amount and timing of revenue recognition.
A good or service is distinct where the customer can benefit from the product without the services and the services are separately identifiable within a contract, and the transfer of the good or service is separately identifiable from other promises in the contract.
The evaluation of performance obligations can require significant judgment in certain contracts and could change the amount of revenue recognized in a given period.
We identified the evaluation of performance obligations in certain contracts as a critical audit matter because of the significant judgment management makes in evaluating such contracts and the impact of such judgment on the amount of revenue recognized in a particular period.
This required a high degree of auditor judgment and an increased extent of testing.
Our audit procedures related to the Company's identification and evaluation of performance obligations within certain contracts and the resulting impact on the pattern and timing of revenue recognition included the following, among others:
- We assessed management’s significant accounting policies related to revenue recognition for compliance with Accounting Standards Codification 606, Revenue from Contracts with Customers.
- We evaluated the design and tested the operating effectiveness of internal controls over review of contracts, including those over the identification and evaluation of contract terms and conditions and the resulting impact on revenue recognition.
- We selected a sample of certain contracts and performed the following:
- Obtained and read the related contract documents and evaluated whether management had properly identified the contract terms and conditions.
- Assessed management’s evaluation of the impact of the performance obligations on the pattern and timing of revenue recognition.
February 21, 2025
| TOTAL ASSETS | | | $ | 9,763.1 | | | | | $ | 7,258.9 | |
| GAIN ON BARGAIN PURCHASE | | | 106.3 | | | | | | — | | | | | | — | | |
| Net income | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | 1,745.2 | | | | | | — | | | | | | 1,745.2 | | |
| BALANCE—December 31, 2024 | | | 767.0 | | | | | | $ | 0.8 | | | | | $ | 1,636.2 | | | | | $ | (26.1) | | | | | $ | (117.1) | | | | | $ | — | | | | | $ | 1,493.8 | |
| Net income including non-controlling interests | | | $ | 1,745.2 | | | | | $ | 1,147.8 | | | | | $ | 856.6 | |
| Gain on bargain purchase | | | (106.3) | | | | | | — | | | | | | — | | |
We do not own manufacturing activities in China.
Subsequently, we recognize our proportionate share of the
The excess of the purchase price over the fair
The tax benefits recognized
of products, gross margin objectives, pricing practices, geographies and the term of a service contract.
Recently Adopted Accounting Standards
Refer to Note 16.
Segment Information.
disaggregation of rate reconciliation categories and income taxes paid by jurisdiction.
*Income Statement*
In November 2024, the FASB issued ASU 2024-03, Income Statement—Reporting Comprehensive Income—Expense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses (ASU 2024-03), and in January 2025, the FASB issued ASU No. 2025-01, Income Statement—Reporting Comprehensive Income—Expense Disaggregation Disclosures (Subtopic 220-40): Clarifying the Effective Date, which clarified the effective date of ASU 2024-03.
ASU 2024-03 enhances the disclosures required for expense disaggregation in our annual and interim consolidated financial statements.
The amendments are effective for our annual reporting period beginning fiscal 2027, with early adoption permitted, and can be applied prospectively or retrospectively.
| | | | 2024 | | | | | | 2023 | | | | | | 2022 | | |
| Product | | | $ | 1,908.7 | | | | | $ | 1,927.3 | | | | | $ | 1,780.5 | |
| | | | December 31, 2024 | | | | | | | | | | | | | | | | | | | | |
| U.S. government and agency securities | | | $ | 469.1 | | | | | $ | 0.4 | | | | | $ | — | | | | | $ | 469.5 | |
| Commercial paper | | | 428.7 | | | | | | 0.2 | | | | | | (0.2) | | | | | | 428.7 | | |
| Corporate debt securities | | | 166.4 | | | | | | 0.1 | | | | | | (0.1) | | | | | | 166.4 | | |
| Total available-for-sale investments | | | $ | 1,126.0 | | | | | $ | 0.7 | | | | | $ | (0.3) | | | | | $ | 1,126.4 | |
| | | | December 31, 2024 | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | |
| --- | --- | --- | --- | --- | --- |
The Company is involved in disputes, litigation, and other legal actions in the normal course of business.
Claims from third parties may result in a requirement to pay substantial damages.
The Company accrues for a loss contingency if a loss is probable, and the amount of the loss can be reasonably estimated.
These accruals are generally based on a range of possible outcomes that require significant management judgement.
Given the inherent uncertainty of the outcome of current matters, auditing litigation contingencies required a high degree of auditor judgment and an increased extent of effort when performing audit procedures.
Our audit procedures related to litigation contingencies included the following, among others:
- We tested the effectiveness of controls over management’s litigation contingency accrual analysis and assessment of matters
with potential impact.
- We obtained and evaluated legal letters from internal and external legal counsel, and we discussed the pending litigation matters with internal legal counsel.
- We made inquiries with management to obtain an understanding of litigation matters that the Company is currently undergoing.
- We read available court documents for litigation matters to search for contradictory information.
- We read Board of Directors meeting minutes to search for contradictory information.
- We evaluated the assumptions used by the Company to estimate the litigation contingency, including corroborating the assumptions with internal legal counsel.
February 23, 2024
| LONG-TERM INVESTMENTS | | | — | | | | | | 45.5 | | |
| BALANCE—December 31, 2020 | | | 812.7 | | | | | | $ | 0.8 | | | | | $ | 1,206.6 | | | | | $ | 0.7 | | | | | $ | (352.1) | | | | | $ | — | | | | | $ | 856.0 | |
| Recognition of non-controlling interests upon business combination | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | 17.8 | | | | | | 17.8 | | |
| Net income | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | 606.8 | | | | | | (0.1) | | | | | | 606.7 | | |
| Proceeds from long-term borrowings, net of discount and underwriting fees | | | — | | | | | | — | | | | | | 989.4 | | |
| Payments for debt issuance costs | | | — | | | | | | — | | | | | | (2.4) | | |
| Payments of debt assumed in connection with business combination | | | — | | | | | | — | | | | | | (19.5) | | |
The amounts previously reported as Income tax liabilities are included in Other liabilities.
Prior periods have been reclassified to conform with current period presentation.
As of December 31, 2022, our investment in Linksys was our only equity method investment.
These
are provided.
improve reportable segment disclosure requirements, primarily through enhanced disclosures about significant expenses.
| | | | December 31, 2022 | | | | | | | | | | | | | | | | | | | | |
| Commercial paper | | | 26.5 | | | | | | — | | | | | | (0.1) | | | | | | 26.4 | | |
| Corporate debt securities | | | 293.0 | | | | | | — | | | | | | (4.1) | | | | | | 288.9 | | |
| Municipal Bonds | | | 5.1 | | | | | | — | | | | | | (0.1) | | | | | | 5.0 | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | December 31, 2022 | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| U.S. government and agency securities | | | $ | 3.9 | | | | | $ | (0.1) | | | | | $ | 189.8 | | | | | $ | (4.3) | | | | | $ | 193.7 | | | | | $ | (4.4) | |
| Commercial paper | | | 26.4 | | | | | | (0.1) | | | | | | — | | | | | | — | | | | | | 26.4 | | | | | | (0.1) | | |
| Corporate debt securities | | | 90.5 | | | | | | (0.8) | | | | | | 190.0 | | | | | | (3.3) | | | | | | 280.5 | | | | | | (4.1) | | |
| Municipal Bonds | | | 5.0 | | | | | | (0.1) | | | | | | — | | | | | | — | | | | | | 5.0 | | | | | | (0.1) | | |
| Total available-for-sale investments | | | $ | 125.8 | | | | | $ | (1.1) | | | | | $ | 379.8 | | | | | $ | (7.6) | | | | | $ | 505.6 | | | | | $ | (8.7) | |
An excerpt. Shown here: 40 of 438 rewritten, 40 of 223 added and 40 of 153 removed. The counts are complete. For every sentence, read Item 8. Financial Statements and Supplementary Data in the FY2024 filing and the FY2023 filing.
Item 9A. Controls and Procedures
7 rewritten, 5 added, 1 removed, 27 unchanged
Based on that evaluation, our chief executive officer and chief financial officer concluded that our disclosure controls and procedures were effective as of December 31, [removed: 2023] [added: 2024] to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized and reported within the time periods specified in SEC rules and forms, and that such information is accumulated and communicated to our management, including our Chief Executive Officer and Chief Financial Officer, as appropriate, to allow timely decisions regarding required disclosure.
Based on this evaluation, management concluded that our internal control over financial reporting was effective as of December 31, [removed: 2023.][added: 2024.]
The effectiveness of our internal control over financial reporting as of December 31, [removed: 2023] [added: 2024] has been audited by Deloitte & Touche LLP, an independent registered public accounting firm, as stated in its report, which appears in this Item under the heading “Report of Independent Registered Public Accounting Firm.”
There were no [added: other] changes in our internal controls over financial reporting (as defined in Rules 13a-15(f) or 15d-15(f) under the Exchange Act) during [removed: 2023] [added: 2024] that have materially affected, or are reasonably likely to materially affect, our internal controls over financial reporting.
We have audited the internal control over financial reporting of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, [removed: 2023,] [added: 2024,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).
In our opinion, the Company maintained, in all material respects, effective internal control over financial reporting as of December 31, [removed: 2023,] [added: 2024,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by COSO.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year ended December 31, [removed: 2023,] [added: 2024,] of the Company and our report dated February [removed: 23, 2024] [added: 21, 2025,] expressed an unqualified opinion on those financial statements.
As permitted by applicable SEC guidance, management has excluded Lacework, a privately held data-driven cloud security company, Next DLP, a privately held data security company, and Perception Point, a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024, because Lacework, Next DLP and Perception Point were acquired by us in business combinations during the fiscal year ended December 31, 2024.
Lacework, Next DLP and Perception Point revenues represented approximately 0.5%, less than 0.1% and less than 0.1% of our consolidated total revenue, respectively, for the year ended December 31, 2024.
As described in “Management’s Report on Internal Control over Financial Reporting”, management excluded from its assessment the internal control over financial reporting at Lacework, Inc. (“Lacework”), a privately held data-driven cloud security company, Next DLP Holdings Limited (“Next DLP”), a privately held data security company, and Perception Point, Ltd. (“Perception Point”), a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024.
Lacework, Next DLP, and Perception Point revenues represented approximately 0.5%, less than 0.1%, and less than 0.1%, respectively, of the Company’s consolidated total revenue for the year ended December 31, 2024.
February 21, 2025
February 23, 2024
Item 9B. Other Information
10 rewritten, 9 added, 1 removed, 2 unchanged
On [removed: November 13, 2023, Patrice Perche,] [added: December 9, 2024, Ken Xie,] our Chief [removed: Revenue] [added: Executive] Officer and [removed: Executive Vice President] [added: one] of [removed: Support,] [added: our directors,] entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 [removed: (the “Perche Plan”)] under the Exchange Act for the sale of shares of our common [removed: stock.][added: stock (the “Ken Xie Plan”) during an open trading window in accordance with our insider trading policy.]
The [removed: Perche] [added: Neukom] Plan [removed: was entered into during an open trading window in accordance with our insider trading policy and] is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The [removed: Perche] [added: Ken Xie] Plan provides for the potential sale by [removed: Patrice Perche] [added: Mr. Xie] of up to (a) [removed: 141,981] [added: 734,880] shares of our common stock, [removed: including] [added: issued] upon the vesting and settlement of RSUs and PSUs for shares of our common [removed: stock,] [added: stock] and [added: the exercise of vested options to purchase shares of our common stock and] (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and [removed: settlement,] [added: settlement of RSUs and PSUs,] in each case, at the market price, all between March [removed: 4, 2024] [added: 10, 2025] and [removed: June 1, 2025.][added: May 6, 2026.]
[removed: On December 6, 2023, Judith Sim,] [added: Goldman,] one of [added: our] directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 [removed: (the “Sim Plan”)] under the Exchange Act for the sale of shares of our common [removed: stock.][added: stock (the “Goldman Plan”) during an open trading window in accordance with our insider trading policy.]
The [removed: Sim] [added: Goldman] Plan [removed: was entered into during an open trading window in accordance with our insider trading policy and] is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
Each of the [removed: Perche] [added: Neukom Plan, Goldman Plan, Ken Xie] Plan and [removed: the Sim] [added: Michael Xie] Plan [removed: (together,] [added: (each, a “10b5-1 Plan,” and together,] the “10b5-1 Plans”) includes a representation from [removed: Patrice Perche] [added: each of Mr. Neukom, Mr. Goldman, Mr. Ken Xie] and [removed: Judith Sim (as applicable)] [added: Mr. Michael Xie, respectively,] to the broker administering the plan that [removed: none of them] [added: they] were [added: not] in possession of any material nonpublic information regarding us or the securities subject to the [added: respective] 10b5-1 [removed: Plans] [added: Plan] at the time the [added: respective] 10b5-1 [removed: Plans] [added: Plan] were entered into.
A similar representation was made to us in connection with the adoption of [removed: the] [added: each] 10b5-1 [removed: Plans] [added: Plan] under our insider trading policy.
In making those representations, there is no assurance with respect to any material nonpublic information of which [removed: Patrice Perche] [added: Mr. Neukom, Mr. Goldman, Mr. Ken Xie] and [removed: Judith Sim] [added: Mr. Michael Xie, as applicable,] were unaware, or with respect to any material nonpublic information acquired by [removed: Patrice Perche] [added: Mr. Neukom, Mr. Goldman, Mr. Ken Xie] and [removed: Judith Sim] [added: Mr. Michael Xie] or [removed: us] [added: us, as applicable,] after the date of each such representation.
Once executed, transactions under the [removed: Sim Plan] [added: 10b5-1 Plans] will be disclosed publicly through Form 4 and/or Form 144 filings with the SEC in accordance with applicable securities laws, rules and regulations.
Except as may be required by law, we do not undertake any obligation to update or report any modification, termination, or other activity under current or future Rule 10b5-1 plans that may be adopted by [removed: Patrice Perche] [added: Mr. Neukom, Mr. Goldman, Mr. Ken Xie] or [removed: Judith Sim] [added: Mr. Michael Xie] or our other officers or directors, or their affiliated entities.
On December 9, 2024, William H.
Neukom, one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the purchase of shares of our common stock (the “Neukom Plan”) during an open trading window in accordance with our insider trading policy.
The Neukom Plan provides for the potential purchase by Mr. Neukom of up to $35,000 worth of shares of our common stock per at the market price, on five dates between March 6, 2025 and March 6, 2026, as specified in the Neukom Plan.
On December 9, 2024, Kenneth A.
The Goldman Plan provides for the potential sale by Mr. Goldman of up to 3,000 shares of our common stock, issued upon the exercise of vested options to purchase shares of our common stock, at the market price, so long as the market price is equal to or greater than $95.00 per share, between March 10, 2025 and March 10, 2026.
The Ken Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
On December 10, 2024, Michael Xie, our Chief Technology Officer and one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Michael Xie Plan”) during an open trading window in accordance with our insider trading policy.
The Michael Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The Michael Xie Plan provides for the potential sale by Mr. Xie of up to (a) 624,285 shares of our common stock, issued upon the vesting and settlement of RSUs for shares of our common stock and the exercise of vested options to purchase shares of our common stock and (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and settlement of RSUs and PSUs, in each case, at the market price, all between March 11, 2025 and May 6, 2026.
The Sim Plan provides for the potential sale by Judith Sim of up to 20,637 shares of our common stock between March 6, 2024 and March 8, 2025.
Item 10. Directors, Executive Officers and Corporate Governance
1 rewritten, 5 added, 0 removed, 3 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Insider Trading Policy
We have adopted an Insider Trading Policy that governs the purchase, sale and/or other dispositions of our securities by directors, officers and employees.
Our Insider Trading Policy also provides that we will not transact in any of our own securities unless in compliance with U.S. securities laws.
We believe that our Insider Trading Policy is reasonably designed to promote compliance with insider trading laws, rules and regulations, and the Nasdaq listing standards applicable to us.
A copy of our Insider Trading Policy is filed as Exhibit 19.1 to this Annual Report on Form 10-K.
Item 11. Executive Compensation
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 13. Certain Relationships and Related Transactions, and Director Independence
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 14. Principal Accounting Fees and Services
1 rewritten, 0 added, 0 removed, 1 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 15. Exhibits and Financial Statement Schedules
25 rewritten, 1 added, 3 removed, 68 unchanged
| [removed: [4.1](http://www.sec.gov/Archives/edgar/data/1262039/000119312509220527/dex41.htm)] [added: [4.1](https://www.sec.gov/Archives/edgar/data/1262039/000119312509220527/dex41.htm)] | | | | | | Specimen common stock certificate of the Company | | | | | | Registration Statement on Form S-l, as amended (File No. 333-161190) | | | | | | November 2, 2009 | | | | | | 4.1 | | |
| [removed: [4.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex42_20231231xk.htm)*] [added: [4.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex42_20241231xk.htm)*] | | | | | | Description of Securities Registered Pursuant to Section 12 of the Exchange Act | | | | | | | | | | | | | | | | | | | | |
| [removed: [10.1](http://www.sec.gov/Archives/edgar/data/1262039/000119312509169817/dex101.htm)†] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000119312509169817/dex101.htm)†] | | | | | | Forms of Indemnification Agreement between the Company and its directors and officers | | | | | | Registration Statement on Form S-l (File No. 333-161190) | | | | | | August 10, 2009 | | | | | | 10.1 | | |
| [removed: [10.2](http://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex101amendedandre.htm)†] [added: [10.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex101amendedandre.htm)†] | | | | | | Amended and Restated 2009 Equity Incentive Plan | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August 1, 2019 | | | | | | 10.1 | | |
| [removed: [10.3](http://www.sec.gov/Archives/edgar/data/1262039/000126203912000013/ftnt-ex105_20111231xk.htm)†] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1262039/000126203912000013/ftnt-ex105_20111231xk.htm)†] | | | | | | Forms of stock option agreement under Amended and Restated 2009 Equity Incentive Plan | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | February 28, 2012 | | | | | | 10.5 | | |
| [removed: [10.4](http://www.sec.gov/Archives/edgar/data/1262039/000126203913000044/fortinet_20130630x10-qex991.htm)†] [added: [10.4](https://www.sec.gov/Archives/edgar/data/1262039/000126203913000044/fortinet_20130630x10-qex991.htm)†] | | | | | | Form of performance stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August 6, 2013 | | | | | | 99.1 | | |
| [removed: [10.5](http://www.sec.gov/Archives/edgar/data/1262039/000126203915000009/ftnt-ex107_20141231xk.htm)†] [added: [10.5](https://www.sec.gov/Archives/edgar/data/1262039/000126203915000009/ftnt-ex107_20141231xk.htm)†] | | | | | | Forms of restricted stock unit award and performance stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Forms) | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | March 2, 2015 | | | | | | 10.7 | | |
| [removed: [10.9](http://www.sec.gov/Archives/edgar/data/1262039/000126203913000055/fortinet_20130930x10-qex101.htm)†] [added: [10.9](https://www.sec.gov/Archives/edgar/data/1262039/000126203913000055/fortinet_20130930x10-qex101.htm)†] | | | | | | Fortinet, Inc. Cash and Equity Incentive Plan | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | November 5, 2013 | | | | | | 10.1 | | |
| [removed: [10.10](http://www.sec.gov/Archives/edgar/data/1262039/000126203915000024/ftnt-ex101_20150630xqxcoca.htm)†] [added: [10.10](https://www.sec.gov/Archives/edgar/data/1262039/000126203915000024/ftnt-ex101_20150630xqxcoca.htm)†] | | | | | | Form of Change of Control Agreement between the Company and its directors | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August 4, 2015 | | | | | | 10.1 | | |
| [removed: [10.11](http://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex102changeofctrl.htm)†] [added: [10.11](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000037/ftnt-ex101amendedandrestat.htm)†] | | | | | | Amended and Restated Change of Control Severance Agreement, effective as of August 7, [removed: 2019,] [added: 2024,] between the Company and Ken Xie | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August [removed: 1, 2019] [added: 8, 2024] | | | | | | [removed: 10.2] [added: 10.1] | | |
| [removed: [10.12](http://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex103changeofctrl.htm)†] [added: [10.12](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000037/ftnt-ex102amendedandrestat.htm)†] | | | | | | Amended and Restated Change of Control Severance Agreement, effective as of August 7, [removed: 2019,] [added: 2024,] between the Company and Michael Xie | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August [removed: 1, 2019] [added: 8, 2024] | | | | | | [removed: 10.3] [added: 10.2] | | |
| [removed: [10.13](http://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex104changeofctrl.htm)†] [added: [10.13](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000037/ftnt-ex103amendedandrestat.htm)†] | | | | | | Amended and Restated Change of Control Severance Agreement, effective as of August 7, [removed: 2019,] [added: 2024,] between the Company and John Whittle | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August [removed: 1, 2019] [added: 8, 2024] | | | | | | [removed: 10.4] [added: 10.3] | | |
| [removed: [10.14](http://www.sec.gov/Archives/edgar/data/1262039/000119312509169817/dex1010.htm)†] [added: [10.14](https://www.sec.gov/Archives/edgar/data/1262039/000119312509169817/dex1010.htm)†] | | | | | | Offer Letter, dated as of October 23, 2006, by and between the Company and John Whittle | | | | | | Registration Statement on Form S-l, as amended (File No. 333-161190) | | | | | | August 10, 2009 | | | | | | 10.10 | | |
| [removed: [10.15](http://www.sec.gov/Archives/edgar/data/1262039/000126203918000009/ftnt-ex1022_20171231xk.htm)†] [added: [10.15](https://www.sec.gov/Archives/edgar/data/1262039/000126203918000009/ftnt-ex1022_20171231xk.htm)†] | | | | | | Offer Letter, dated as of April 3, 2014, by and between the Company and Keith Jensen | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | February 26, 2018 | | | | | | 10.22 | | |
| [removed: [10.16](http://www.sec.gov/Archives/edgar/data/1262039/000126203919000023/ftnt-ex105changeofctrl.htm)†] [added: [10.16](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000037/ftnt-ex104amendedandrestat.htm)†] | | | | | | Amended and Restated Change of Control Severance Agreement, effective as of August 7, [removed: 2019,] [added: 2024,] between the Company and Keith Jensen | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August [removed: 1, 2019] [added: 8, 2024] | | | | | | [removed: 10.5] [added: 10.4] | | |
| [removed: [10.](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)[19](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)†] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)[7](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)†] | | | | | | Form of performance stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | May 8, 2023 | | | | | | 10.1 | | |
| [removed: [10.](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)[20](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)†] [added: [10.](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)[18](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)†] | | | | | | Form of restricted stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Form) | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | May 8, 2023 | | | | | | 10.2 | | |
| [removed: [21.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex211_20231231xk.htm)*] [added: [21.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex211_20241231xk.htm)*] | | | | | | List of subsidiaries | | | | | | | | | | | | | | | | | | | | |
| [removed: [23.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex231_20231231xk.htm)*] [added: [23.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex231_20241231xk.htm)*] | | | | | | Consent of Independent Registered Public Accounting Firm | | | | | | | | | | | | | | | | | | | | |
| [removed: [24.1](#i980f0e0da2e545ad8a4174683b30b0d6_202)*] [added: [24.1](#i534f17d0e8de499a94e79a163c06da17_217)*] | | | | | | Power of Attorney (incorporated by reference to the signature page of this Annual Report on Form 10-K) | | | | | | | | | | | | | | | | | | | | |
| [removed: [31.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex311_20231231xk.htm)*] [added: [31.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex311_20241231xk.htm)*] | | | | | | Certification of Chief Executive Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| [removed: [31.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex312_20231231xk.htm)*] [added: [31.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex312_20241231xk.htm)] | | | | | | Certification of Chief Financial Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| [removed: [32.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex321_20231231xk.htm)] [added: [32.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex321_20241231xk.htm)] | | | | | | Certifications of Chief Executive Officer and Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| [removed: [97.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex971_20231231xk.htm)*] [added: [97.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000014/ftnt-ex971_20231231xk.htm)] | | | | | | Compensation Recovery Policy | | | | | | [added: Annual Report on Form 10-K (File No. 001-34511)] | | | | | | [added: February 6, 2024] | | | | | | [added: 97.1] | | |
| 104* | | | | | | Cover Page Interactive Data File - the cover page from the Company’s Annual Report on Form 10-K for the year ended December 31, [removed: 2023] [added: 2024] is formatted in inline XBRL. | | | | | | | | | | | | | | | | | | | | |
| [1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex191insidertradingpo.htm)[9.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex191insidertradingpo.htm)* | | | | | | Insider Trading Policy | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [10.17](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000010/patricepercheemploymentagr.htm)† | | | | | | Employment Agreement, dated as of January 24, 2018, between Fortinet UK Limited and Patrice Perche | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | February 24, 2023 | | | | | | 10.17 | | |
| [10.18](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000010/ftnt-pperchechangeofctrlse.htm)† | | | | | | Change of Control Severance Agreement, effective as of February 21, 2023, between the Company and Patrice Perche | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | February 24, 2023 | | | | | | 10.18 | | |
Item 16. Form 10-K summary
12 rewritten, 18 added, 0 removed, 40 unchanged
| Date: February [removed: 23, 2024] [added: 21, 2025] | | | | | | | | |
| | | | | | | (Duly Authorized Officer and Principal Financial [removed: Officer and Principal Accounting] Officer) | | |
| /s/ Ken Xie | | | | | | Chief Executive Officer and Chairman | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Keith Jensen | | | | | | Chief Financial Officer | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| Keith Jensen | | | | | | (Principal Financial [removed: Officer and Principal Accounting] Officer) | | | | | | | | |
| /s/ Michael Xie | | | | | | President, Chief Technology Officer and Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Kenneth A. Goldman | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Ming Hsieh | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Jean Hu | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ William H. Neukom | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Judith Sim | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| /s/ Admiral James Stavridis | | | | | | Director | | | | | | February [removed: 23, 2024] [added: 21, 2025] | | |
| Date: February 21, 2025 | | | | | | | | |
| | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Date: February 21, 2025 | | | | | | | | |
| FORTINET, INC. | | | | | | | | |
| | | | | | | | | |
| | | | By: | | | /s/ Christiane Ohlgart | | |
| | | | | | | Christiane Ohlgart, Chief Accounting Officer | | |
| | | | | | | (Duly Authorized Officer and Principal Accounting Officer) | | |
| /s/ Christiane Ohlgart | | | | | | Principal Accounting Officer | | | | | | February 21, 2025 | | |
| Christiane Ohlgart | | | | | | | | | | | | | | |
| /s/ Janet Napolitano | | | | | | Director | | | | | | February 21, 2025 | | |
| Janet Napolitano | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | |
| /s/ Maggie Wilderotter | | | | | | Director | | | | | | February 21, 2025 | | |
| Maggie Wilderotter | | | | | | | | | | | | | | |