Palo Alto Networks 10-K 2019-07-31
Filed 2019-09-09. 21 sections, 496K characters. Original on sec.gov · Markdown · JSON
Cover and table of contents
10-K 1 panw-7312019x10k.htm 10-K
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
(Mark One)
| x | ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the fiscal year ended July 31, 2019
or
| ¨ | TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the transition period from to
Commission File Number 001-35594
Palo Alto Networks, Inc.
(Exact name of registrant as specified in its charter)
| Delaware | 20-2530195 |
| (State or other jurisdiction of incorporation or organization) | (I.R.S. Employer Identification No.) |
| 3000 Tannery Way Santa Clara, California 95054 (Address of principal executive offices, including zip code) |
(408) 753-4000
(Registrant’s telephone number, including area code)
Securities registered pursuant to Section 12(b) of the Act:
| Title of each class | Trading Symbol(s) | Name of each exchange on which registered | ||
| Common stock, $0.0001 par value per share | PANW | New York Stock Exchange |
Securities registered pursuant to Section 12(g) of the Act:
None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes x No ¨
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ¨ No x
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes x No ¨
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes x No ¨
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
| Large accelerated filer | x | Accelerated filer | ¨ |
| Non-accelerated filer | ¨ | Smaller reporting company | ¨ |
| Emerging growth company | ¨ |
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ¨
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ¨ No x
The aggregate market value of voting stock held by non-affiliates of the registrant was $19,595,846,244 as of January 31, 2019, the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the New York Stock Exchange on such date). Shares of common stock held by each executive officer, director, and holder of 5% or more of the outstanding common stock have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.
On August 23, 2019, 96,990,480 shares of the registrant’s common stock, $0.0001 par value, were outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, 2019.
TABLE OF CONTENTS
- 2 -
PART I
SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS
This Annual Report on Form 10-K, including the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. The words “believe,” “may,” “will,” “potentially,” “estimate,” “continue,” “anticipate,” “intend,” “could,” “would,” “project,” “plan,” “expect,” and similar expressions that convey uncertainty of future events or outcomes are intended to identify forward-looking statements.
These forward-looking statements include, but are not limited to, statements concerning the following:
| • | expectations regarding drivers of and factors affecting growth in our business; |
| • | the performance advantages of our products and subscription and support offerings and the potential benefits to our customers; |
| • | trends in and expectations regarding billings, revenue (including our revenue mix), costs of revenue, gross margin, cash flows, interest expense, operating expenses (including future share-based compensation expense), income taxes, investment plans and liquidity; |
| • | our ability to and expectation that we will continue to grow our installed end-customer base; |
| • | expected recurring revenues resulting from expected growth in our installed base and increased adoption of our products and cloud-based subscription services; |
| • | our expectations regarding future investments in research and development, customer support, and in our sales force, including expectations regarding growth in our sales headcount; |
| • | our ability to develop or acquire new product, subscription, and support offerings, improve our existing product, subscription, and support offerings, and increase the value of our product, subscription, and support offerings, including through deployment of new capabilities via security applications developed by third parties; |
| • | our expectation that we will continue to expand internationally; |
| • | our expectation that we will continue to renew existing contracts and increase sales to our existing customer base; |
| • | seasonal trends in our results of operations; |
| • | expected impact of the adoption of certain recent accounting pronouncements and the anticipated timing of adopting such standards; |
| • | our expectation that we will expand our facilities or add new facilities as we add employees and enter new geographic markets and expectations related to charges incurred in connection with exiting our former headquarter facilities; |
| • | our plans to use the upfront cash reimbursement received from our landlords against future rental payments; |
| • | the sufficiency of our cash flow from operations with existing cash and cash equivalents to meet our cash needs for the foreseeable future; |
| • | future investments in product development, subscriptions, or technologies, and any related delays in the development or release of new product and subscription offerings; |
| • | our ability to successfully acquire and integrate companies and assets; |
| • | expectations and intentions with respect to the products and technologies that we acquire and introduce; |
| • | the timing and amount of capital expenditures and share repurchases; |
| • | our plans to acquire Zingbox, Inc. (“Zingbox”); the timing of when the Zingbox acquisition will be completed; the finalization of the accounting for the Zingbox acquisition; the expected benefit of the Zingbox acquisition to us and our customers; the expected impact of the acquisition on our offerings; and |
| • | other statements regarding our future operations, financial condition and prospects, and business strategies. |
These forward-looking statements are subject to a number of risks, uncertainties, and assumptions, including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of
- 3 -
these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur, and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements. We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.
Item 1. BUSINESS
General
We were incorporated in 2005 as Palo Alto Networks, Inc., a Delaware corporation. Our corporate headquarters are located in Santa Clara, California.
We have pioneered the next generation of security through our innovative platform that empowers enterprises, service providers, and government entities to secure their organizations by safely enabling applications and data running in their networks, on their endpoints, and in the cloud, and by preventing breaches that stem from targeted cyberattacks. Our platform uses an innovative traffic classification engine that identifies network traffic by application, user, and content and provides consistent security across the network, endpoint, and cloud. Accordingly, our platform enables our end-customers to pursue transformative digital initiatives, like public cloud and mobility, that grow their business, while maintaining the visibility and control needed to protect their valued data and critical control systems. We believe the architecture of our platform offers superior performance compared to legacy approaches and reduces the total cost of ownership for organizations by simplifying their security operations and infrastructure and eliminating the need for multiple, stand-alone hardware and software security products, and consists of three primary areas of security capabilities.
Secure the Enterprise:
| • | Secure the network through our Next-Generation Firewalls, available as physical appliances, virtual appliances called VM-Series, or a cloud-delivered service called Prisma Access (formerly GlobalProtect cloud service), and Panorama management delivered as an appliance or as a virtual machine for the public or private cloud. This also includes security services such as WildFire, Threat Prevention, URL Filtering, GlobalProtect, and DNS Security that are delivered as SaaS subscriptions to our Next-Generation Firewalls. |
| • | Secure the endpoints through our Traps advanced endpoint protection software, delivered as a light-weight software agent with cloud or on-premise management capabilities. |
Secure the Cloud:
| • | Secure the cloud through our Prisma cloud security offerings, such as Prisma Public Cloud (formerly RedLock) for security and compliance in public clouds, Prisma Access (formerly GlobalProtect cloud service) for securing user access, Prisma SaaS (formerly Aperture) for protecting SaaS applications, VM-Series for in-line network security in public and private clouds, Traps for host-based public cloud infrastructure protection, and Twistlock for protecting containers in public and private clouds, as well as PureSec for protecting serverless functions in public clouds. |
Secure the Future:
| • | Secure the future of security operations through our Cortex platform, which includes Cortex XDR (formerly Magnifier) for detection and response, Cortex Data Lake (formerly Logging Service) to collect and integrate security data for analytics, Demisto for security orchestration, automation, and response (“SOAR”), and AutoFocus for threat intelligence. These products are delivered as software or SaaS subscriptions. |
Product, Subscription, and Support Offerings
Our platform is available in the form of the product, subscription, and support offerings described below.
Firewall Appliances and Software. All of our firewall appliances and software incorporate our PAN-OS operating system and come with the same rich set of features ensuring consistent operation across our entire product line. These features include: App-ID, User-ID, site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-220, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7080, which is designed for large scale data centers and service provider use. Our firewall appliances come in a physical form factor as well as in a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments.
Panorama. Panorama is our centralized security management solution for global control of all of our firewall appliances and software deployed on an end-customer’s network as well as in their instances in public or private cloud environments as a virtual
- 4 -
appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the appliances, software, and virtual systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, GlobalProtect clients, dynamic content updates, and software licenses. Panorama offers the ability to view logs and run reports from all managed appliances and software without the need to forward the logs and to report on aggregate user activity for all users, including mobile users. Panorama reliably expands the log storage for long-term event investigation and analysis through high-availability features for central management.
Virtual System Upgrades. Virtual System Upgrades are available as extensions to the Virtual System capacity that ships with our physical appliances. Virtual Systems provide a mechanism to support multiple distinct security policies and administrative access for tenants on the same hardware device, which is applicable to our large enterprise and service provider end-customers.
Subscription Offerings. We offer a number of subscriptions as part of our platform. Of these subscription offerings, Threat Prevention Subscription, URL Filtering Subscription, WildFire Subscription, GlobalProtect Subscription, and DNS Security Subscription are sold as options to our firewall appliances and software, whereas VM-Series, Traps, AutoFocus, Prisma Access (formerly GlobalProtect cloud service), Prisma Public Cloud (formerly RedLock), Prisma SaaS (formerly Aperture), Cortex XDR (formerly Magnifier), Cortex Data Lake (formerly Logging Service), and Demisto are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:
| • | Threat Prevention Subscription. This subscription provides the intrusion detection and prevention capabilities of our platform. Our threat prevention engine blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability, and spyware “phone home” signatures. |
| • | URL Filtering Subscription. This subscription provides the uniform resource locator (“URL”) filtering capabilities of our platform. The URL filtering database consists of millions of URLs across many categories and is designed to monitor and control employee web surfing activities. The on-appliance URL database can be augmented to suit the traffic patterns of the local user community with a custom URL database. URLs that are not categorized by the local URL database can be pulled into a separate, cache-based URL database from a very extensive, cloud-based URL database. |
| • | WildFire Subscription. This cloud-based or appliance-based subscription provides protection against targeted malware and advanced persistent threats, and provides a near real-time analysis engine for detecting previously unseen malware. The core component of this subscription is a sandbox environment that can operate on an end-customers’ private cloud or our public cloud where files can be run and monitored for more than 100 behavioral characteristics that identify the file as malware. Once identified, preventive measures are automatically generated and delivered to all subscribed devices. By providing this as a cloud-based subscription, all of our end-customers benefit from malware found on any network. |
| • | GlobalProtect Subscription. This appliance-based subscription provides protection for mobile users of both traditional laptop devices and mobile devices. It expands the boundaries of the physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Windows and Apple laptops as well as mobile devices, such as Android phones and tablets and Apple iPhones and iPads, will stay connected to the corporate network whenever they are on a network of any kind. As a result, they are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location. |
| • | VM-Series Subscription. VM-Series, the software form factor of our Next-Generation Firewall, is offered as both a perpetual license as well as a term-based subscription. The VM-Series provides all of the same security capabilities of our hardware appliances, but is delivered as a software package that can be deployed on VMware’s NSX and ESXi, Microsoft’s Hyper-V, and Red Hat KVM hypervisors, as well as natively in Amazon Web Services (“AWS”) cloud, Microsoft Azure cloud (“Azure”), and Google Cloud Platform (“GCP”). |
| • | Traps Endpoint Protection Subscription. This subscription provides protection for endpoints against cyberattacks that aim to run malicious code or exploit software vulnerabilities. It prevents known and previously unknown attacks through its unique capability of stopping the underlying exploit techniques and can prevent cyberattacks without relying on prior knowledge of the attack. Through its local machine learning engine, it can prevent cyberattacks that rely on malware, including continuously learning via its integration with WildFire. Traps offers the unique Behavioral Threat Protection engine intended to stop the most sophisticated attacks by examining multiple behaviors together to uncover and stop threats. |
- 5 -
| • | AutoFocus Subscription. This cloud-based subscription provides threat intelligence capabilities to our end-customers’ security operations teams. Indicators of compromise and anomalies that occur on an end-customer’s network can be correlated with similar data that has been centrally collected from among all our participating end-customers. This offers our end-customers priority alerts, deep attack context, and high-fidelity threat intelligence across millions of malware samples and tens of billions of file artifacts. |
| • | DNS Security Service Subscription. This cloud-based subscription uses machine learning to proactively block malicious domains and stops attacks in progress. It offers firewalls with access to DNS signatures generated using advanced predictive analysis and machine learning using malicious domain data from a growing threat intelligence sharing community. |
| • | Prisma Access (formerly GlobalProtect Cloud Service) Subscription. This cloud-based subscription enables our end-customers to utilize the preventive capabilities of our Security Operating Platform to secure remote offices and mobile users, providing consistent protection across globally distributed network and cloud environments without the need for firewall appliances or software in the remote locations. With this offering, our end-customers can quickly and easily add or remove remote locations and users, and establish and adjust security policies as needed, using a multi-tenant, cloud-based security infrastructure that we operate on their behalf. |
| • | Prisma Public Cloud (formerly RedLock) Subscription. This cloud-based subscription provides comprehensive visibility and threat detection across our end-customers’ public cloud environments. |
| • | Prisma SaaS (formerly Aperture) Subscription. This cloud-based subscription provides content control for IT-sanctioned SaaS applications. It offers end-customers the capability to safely use these SaaS applications and avert risks associated with improper sharing of confidential data and risks associated with sharing of malicious content. |
| • | Cortex Data Lake (formerly Logging Service) Subscription. This cloud-based subscription allows our end-customers to collect large amounts of context-rich data generated by our security offerings, including those of our Next-Generation Firewalls, Prisma Access (formerly GlobalProtect cloud service) subscription, and Traps, without needing to plan for local processing power and storage. |
| • | Cortex XDR (formerly Magnifier) Subscription. This cloud-based subscription enables organizations to identify and stop the most sophisticated attacks by applying AI and machine learning to rich network, endpoint, and cloud data. |
| • | Demisto. Available as a cloud-based subscription or on-premises appliance, Demisto is a comprehensive SOAR platform that combines playbook orchestration, incident management, and real-time collaboration to serve security teams across the incident lifecycle. With Demisto, security teams can standardize processes, automate repeatable tasks and manage incidents across their security product stack to improve response time and analyst productivity. |
Support. We offer Standard Support, Premium Support, and four-hour Premium Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer an annual subscription-based Service Account Management (“SAM”) service that provides support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for both hardware and software in order to receive ongoing security updates, PAN-OS upgrades, bug fixes, and repair. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.
Professional Services. Professional services are delivered directly and through our authorized channel partners and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, configuration, and firewall migrations, as well as Prisma and Cortex deployments. Our education services provide online and classroom-style training and are also primarily delivered through our authorized training partners.
Technology
We combine our proprietary hardware and software architecture to provide a comprehensive security platform. Our Next-Generation Firewall integrates application visibility and control and is comprised of three identification technologies: App-ID, User-ID, and Content-ID. These technologies allow organizations to enable the secure use of applications while managing the inherent risks of doing so. These fine-grained policy management and enforcement capabilities are delivered at low latency, multi-gigabit performance through our innovative single-pass, parallel processing (“SP3”) architecture.
App-ID. App-ID is our application classification engine that uses multiple identification techniques to determine the exact identity of applications traversing the network. App-ID is the foundational classification engine that provides the core traffic classification to all other functions in our platform. The App-ID classification is used to invoke other security functions.
- 6 -
App-ID uses a series of classification techniques to accurately identify an application. When traffic first enters the network, App-ID applies an initial policy check based on Internet Protocol (“IP”) and port. Signatures are then applied to the traffic to identify the application based on application properties and related transaction characteristics. If the traffic is encrypted and a decryption policy is in place, the application is first decrypted, then application signatures are applied. Additional context-based signature analysis is then performed to identify known protocols that may be hiding other applications. Encrypted traffic that was decrypted is then re-encrypted before being sent back into the network. For evasive applications that cannot be identified through advanced signature and protocol analysis, heuristics or behavioral analysis are used to determine the identity of the application. When an application is accurately identified during this series of successive techniques, the policy check determines how to treat the application and associated functions. The policy check can block the application, allow it and scan for threats, inspect it for unauthorized file transfer and data patterns, or shape its use of network resources by applying a quality-of-service policy.
App-ID consistently classifies all network traffic, including business applications, consumer applications, and network protocols, across all ports. Consequently, there is no need to perform a series of signature checks to look for an application that is thought to be on the network. App-ID continually monitors the state of the application to determine if the application changes. Our platform allows only those applications within the policy to enter the network, while all other applications are blocked.
Internally developed or custom applications can be managed using either an application override or custom App-IDs. End-customers can use either of these mechanisms to apply the same level of control over their internal or custom applications that they apply to common applications. Because the application landscape is constantly changing, our research teams are constantly updating our App-ID classification engine. We deliver updated App-IDs automatically to our end-customers through our weekly update service.
User-ID. User-ID integrates our platform with a wide range of enterprise user directories and technologies, including Active Directory, eDirectory, Open LDAP, Citrix Terminal Server, Microsoft Exchange, Microsoft Terminal Server, and ZENworks. A network-based, User-ID agent communicates with the domain controllers, directories, or supported enterprise applications, mapping information such as user, role, and current IP address to the firewall, making the policy integration transparent. In cases where user repository information does not include the current IP address of the user, a transparent, captive portal authentication or challenge/response mechanism can be used to tie users into the security policy. In cases where a user repository or application is in place that already has knowledge of users and their current IP address, a standards-based application programming interface (“API”) can be used to tie the repository to our platform.
Content-ID. Content-ID is a collection of technologies that enables many of our subscription offerings. Content-ID combines a real-time threat prevention engine, a cloud-based analysis service, and a comprehensive URL categorization database to limit unauthorized data and file transfers, detect and block a wide range of threats, and control non-work related web surfing.
The threat prevention engine blocks several common types of attacks, including vulnerability exploits, buffer overflows, and port scans from compromising and damaging enterprise information resources. It includes mechanisms such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability, and spyware “phone home” signatures.
Our cloud-based threat analysis service, WildFire, provides a near real-time analysis engine for detecting previously unseen targeted malware. The core component of WildFire is a sandbox environment that can be deployed in a customer’s private cloud or on our cloud where files can be run and monitored for more than 100 behavioral characteristics that identify the file as malware. Once identified, signatures are automatically generated and delivered to all end-customers that subscribe to the WildFire service. By providing WildFire as a cloud-based service, all of our end-customers benefit from malware found on any network or endpoint. Refer to the “WildFire” section below for a more detailed discussion of our WildFire technology.
Our URL filtering database consists of millions of URLs across many categories and is designed to monitor and control employee web surfing activities. The on-appliance URL database can be augmented to suit the traffic patterns of the local user community with a custom URL database. URLs that are not categorized by the local URL database can be pulled into an on-appliance data cache from a very extensive, cloud-based URL database. The data filtering features in our platform enable policies that reduce the risks associated with the transfer of unauthorized files and data. This can be achieved by blocking files by type, by controlling sensitive data, such as credit card and social security numbers in application content or attachments, and by controlling file transfers within applications.
SP3. SP3 is our proprietary software and hardware architecture that is comprised of two elements: single-pass software and parallel processing hardware.
Our single-pass software accomplishes two key functions in our platform. First, it performs operations once per packet. As a packet is processed, the networking functions, the policy lookup, the application identification and decoding, and the signature matching for any and all threats and content are all performed simultaneously. This significantly reduces the amount of processing required to perform multiple functions in one security device. Second, the content scanning step is stream-based and uses uniform signature matching to detect and block threats. Instead of using multiple scanning passes and file proxies, which require download prior to scanning, our single-pass software scans content once in a stream-based fashion to minimize latency. This results in very high
- 7 -
throughput and low latency, even with all security functions active. It also offers a single, fully integrated policy, thus enabling easier management of security.
Our parallel processing hardware is designed to optimize single-pass software performance through the use of separate data and control planes, which means that heavy utilization of one does not negatively impact the performance of the other. Our hardware also uses discrete, specialized processing groups to perform critical functions. On the data plane, this includes functions such as networking, policy enforcement, encryption and decryption, decompression, and content scanning. On the control plane, this includes configuration management, logging, and reporting.
We believe that the combination of single-pass software and parallel processing hardware is unique in the enterprise security industry and allows our platform to safely enable applications and prevent cyberthreats at very high levels of performance and throughput.
PAN-OS Operating System. Our PAN-OS operating system provides the foundation for our security platform and contains App-ID, User-ID, and Content-ID. PAN-OS performs the core functions of our platform while also providing the networking, security, and management functions needed for implementation. The PAN-OS networking functions include dynamic routing, switching, high availability, and VPN support, which enables deployment into a broad range of networking environments.
We have the ability to enable a series of virtual firewall instances or virtual systems. Each virtual system is an independent (virtual) firewall within the device that is managed separately and cannot be accessed or viewed by any other administrator of any other virtual system. This capability allows enterprises and service providers to separate firewall instances in departmental and multi-tenant managed services scenarios.
The security functions in PAN-OS are implemented in a single security policy and include application, application function, user, group, port, and service-based elements. Policy responses can range from open (allow but monitor for activity), to moderate (enabling certain applications or functions), to closed (deny). The tight integration of application control, users, and groups, and the ability to scan the allowed traffic for a wide range of threats minimizes the number of policies.
PAN-OS also includes attack protection capabilities, such as blocking invalid or malformed packets, IP defragmentation, Transmission Control Protocol (“TCP”) reassembly, and network traffic normalization. PAN-OS eliminates invalid and malformed packets, while TCP reassembly and IP defragmentation is performed to ensure the utmost accuracy and protection despite any attack evasion techniques.
WildFire. WildFire is our cloud-based malware analysis environment that offers a completely new approach to cybersecurity. Through native integration with our Next-Generation Firewall, the service brings advanced threat detection and prevention to every system deployed throughout the network, automatically sharing protections with all WildFire subscribers globally.
The service offers a unified, hybrid cloud architecture deployed via either a Palo Alto Networks run cloud, a private cloud appliance that maintains all data on the local network, or a combination of the two. This allows us to perform dynamic analysis of suspicious content in a cloud-based virtual environment to discover unknown threats, automatic creation and enforcement of best-in-class, content-based malware protections, and link detection in email, proactively blocking access to malicious websites.
Advanced attacks are not point-in-time events. Adversaries deliver attacks persistently, often using non-standard ports, protocols or encryption for subsequent attack stages. Like our Next-Generation Firewall, WildFire provides complete visibility into unknown threats within all traffic across thousands of applications, including Web traffic, email protocols (SMTP, IMAP, POP), and FTP, regardless of ports or encryption (SSL).
Once WildFire discovers a new threat, the service automatically generates protections across the attack lifecycle, blocking malicious files and command-and-control traffic. Uniquely, many of these protections are content-based, not relying on easily changed attributes such as hash, filename or URL, allowing the service to block the initial malware and future variants without any additional action or analysis. WildFire informs the protection of our other security services, blocking threats in-line through Threat Prevention (anti-malware, DNS, command-and-control), Web Security (malicious URLs in PAN-DB), and GlobalProtect (anti-malware for mobile devices).
Traps. Traps is our Advanced Endpoint Protection product that prevents advanced attacks originating from either exploits or malicious executables before any malicious activity can successfully run, regardless of software patches in place. If an attack attempt is made, Traps will immediately block the technique or techniques, terminate the process, and notify both the user and the administrator that an attack was thwarted. Whenever a block does occur, Traps will collect detailed forensics, including the offending process, the memory state when it was prevented, and many other details that are reported to the Endpoint Security Manager (“ESM”).
The Traps agent injects itself into each process as it is started. When an attacker attempts to exploit a software vulnerability, the Traps protection modules cause the exploit attempt to fail because Traps has already made the process impervious to those techniques. When the attempt is prevented, the Traps agent kills the process and reports all of the details to the ESM.
Traps policy is configured to protect over 100 processes - each one with dozens of proprietary exploit prevention modules (“EPMs”). However, unlike other products, Traps is not limited to protecting only those processes or applications. Our end-customers
- 8 -
use Traps to protect all manner of processes and applications by simply adding them to the policy configuration. Processes that have been run on the endpoint automatically show up in the ESM console, making it easy to protect those processes with the click of a button. This is especially useful for those end-customers running industry-specific applications. In addition to protecting workstations, laptops, and servers, Traps can protect point-of-sale (“POS”) systems, automated teller machines (“ATMs”), supervisory control and data acquisition (“SCADA”), and any other applications from exploitation.
Certifications. Many of our products have been awarded Federal Information Processing Standard (“FIPS”) 140-2 Level 2, Common Criteria/National Information Assurance Partnership (“NIAP”) Evaluation Assurance Level (“EAL”) 2, Common Criteria/NIAP EAL4+, Network Equipment-Building System (“NEBS”), and ICSA Firewall certifications.
Research and Development
Our research and development effort is focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security market. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. In addition to our focus on hardware and software, our research and development team is focused on research into applications and threats, which allows us to respond to the rapidly changing application and threat landscape. We supplement our own research and development effort with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2019, we introduced several new offerings, including: PAN-OS 9.0, with over 60 new features; our DNS Security Service and Cortex XDR subscriptions; and Prisma, our cloud security suite that secures public cloud environments, SaaS applications, internet access, mobile users, and remote locations through a cloud-based architecture. Additionally, we acquired RedLock Inc. (“RedLock”), which expanded our security capabilities for the public cloud with the addition of RedLock’s cloud security analytics technology, Demisto, Inc. (“Demisto”), which expanded the functionality of our platform with the addition of Demisto’s SOAR product, and PureSec Ltd. (“PureSec”) and Twistlock Ltd. (“Twistlock”), which extend our Prisma cloud security strategy with the addition of PureSec’s security for serverless applications and Twistlock’s container security capabilities.
We plan to continue to significantly invest in our research and development effort as we evolve and extend the capabilities of our platform.
Intellectual Property
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.
We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to and use of our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully asserted in the future or may be invalidated, circumvented or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their proprietary technology or other rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.
Competition
We operate in the intensely competitive enterprise security market that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into three categories:
| • | large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”) and Juniper Networks, Inc. (“Juniper”), or those that have acquired, or may acquire, large network and endpoint security vendors and have the technical and financial resources to bring competitive solutions to the market; |
- 9 -
| • | independent security vendors such as Symantec Corporation (“Symantec”), Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), and FireEye, Inc. (“FireEye”) that offer a mix of network and endpoint security products; and |
| • | small and large companies that offer point solutions and/or cloud security services that compete with some of the features present in our platform. |
As our market grows, it will attract more highly specialized vendors as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
| • | product features, reliability, performance, and effectiveness; |
| • | product line breadth, diversity, and applicability; |
| • | product extensibility and ability to integrate with other technology infrastructures; |
| • | price and total cost of ownership; |
| • | adherence to industry standards and certifications; |
| • | strength of sales and marketing efforts; and |
| • | brand awareness and reputation. |
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our platform, the ease of integration of our products with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
Sales, Customer Support and Marketing
Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our platform for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise perimeter, the enterprise data center, and the distributed enterprise perimeter. Our end-customer deployments typically involve at least one pair of our products along with one or more of our subscriptions, depending on size, security needs and requirements, and network complexity. No single end-customer accounted for more than 10% of our total revenue in fiscal 2019, 2018, or 2017.
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30-90 days written notice prior to the renewal date, and payment to us from the channel partner within 30-45 calendar days of the date we issue an invoice for such sales. For fiscal 2019, 74.6% of our total revenue was derived from sales to four distributors.
We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We expect to continue to grow our sales headcount in all of our principal markets and expand our presence into countries where we currently do not have a direct sales presence.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To ensure optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2019, we had more than 5,200 channel partners.
Customer Support. Our customer support organization is responsible for delivering support, professional, and educational services directly to our channel partners and to end-customers. We leverage the capabilities of our channel partners and train them in
- 10 -
the delivery of support, professional, and educational services to ensure these services are locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our platform and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand, field, communications, including analyst relations and public relations, digital and analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate web site and partner portal, trade shows and conferences, press, analyst, and customer relations, and customer awareness. Every year we organize our end-customer conference “Ignite.” We also publish major market research papers such as the “Application Usage and Threat Report” and the “Cloud Threat Forecast Report,” which are based on the application and cyberthreat landscape of our end-customers. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront shortly after fulfillment of an order and are included in deferred revenue. Timing of revenue recognition for subscription and support offerings may vary depending on the contractual period or when the subscription and support offerings are rendered. Products are shipped and billed shortly after receipt of an order. The majority of our product revenue comes from orders that are received and shipped in the same quarter. As such, we do not believe that our product backlog at any particular time is meaningful and it is not necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth occurring in our fiscal second and fourth quarters.
Manufacturing
We outsource the manufacturing of our security products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
The component parts within our products are either sourced by our manufacturing partners or by various component suppliers. We do not have any long-term manufacturing contracts that guarantee us any fixed capacity or pricing, which could increase our exposure to supply shortages or price fluctuations related to raw materials.
Employees
As of July 31, 2019, we had 7,014 employees. Competition for qualified personnel in our industry is intense, and we believe that our future success depends in part on our continued ability to hire, motivate, and retain such personnel.
Available Information
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only.
- 11 -
Item 1A. RISK FACTORS
Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected and the market price of our common stock could decline.
Risks Related to Our Business and Our Industry
Our business and operations have experienced rapid growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected.
We have experienced rapid growth and increased demand for our products and subscriptions over the last few years. As a result, our employee headcount has increased significantly, and we expect it to continue to grow over the next year. For example, from the end of fiscal 2018 to the end of fiscal 2019, our headcount increased from 5,348 to 7,014 employees. In addition, as we have grown, our number of end-customers has also increased significantly, and we have increasingly managed more complex deployments of our products and subscriptions with larger end-customers. The growth and expansion of our business and product, subscription, and support offerings places a significant strain on our management, operational, and financial resources. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner.
We may not be able to successfully implement or scale improvements to our systems, processes, and controls in an efficient or timely manner. In addition, our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud. We may also experience difficulties in managing improvements to our systems, processes, and controls or in connection with third-party software licensed to help us with such improvements. Any future growth would add complexity to our organization and require effective coordination throughout our organization. Failure to manage any future growth effectively could result in increased costs, disrupt our existing end-customer relationships, reduce demand for or limit us to smaller deployments of our platform, or harm our business performance and operating results.
Our operating results may vary significantly from period to period and be unpredictable, which could cause the market price of our common stock to decline.
Our operating results, in particular, our revenues, gross margins, operating margins, and operating expenses, have historically varied from period to period, and even though we have experienced growth, we expect variation to continue as a result of a number of factors, many of which are outside of our control and may be difficult to predict, including:
| • | our ability to attract and retain new end-customers or sell additional products and subscriptions to our existing end-customers; |
| • | the budgeting cycles, seasonal buying patterns, and purchasing practices of our end-customers; |
| • | changes in end-customer, distributor or reseller requirements, or market needs; |
| • | price competition; |
| • | the timing and success of new product and service introductions by us or our competitors or any other change in the competitive landscape of our industry, including consolidation among our competitors or end-customers and strategic partnerships entered into by and between our competitors; |
| • | changes in the mix of our products, subscriptions, and support, including changes in multi-year subscriptions and support; |
| • | our ability to successfully and continuously expand our business domestically and internationally; |
| • | changes in the growth rate of the enterprise security market; |
| • | deferral of orders from end-customers in anticipation of new products or product enhancements announced by us or our competitors; |
| • | the timing and costs related to the development or acquisition of technologies or businesses or strategic partnerships; |
| • | lack of synergy or the inability to realize expected synergies, resulting from acquisitions or strategic partnerships; |
| • | our inability to execute, complete or integrate efficiently any acquisitions that we may undertake; |
| • | increased expenses, unforeseen liabilities, or write-downs and any impact on our operating results from any acquisitions we consummate; |
- 12 -
| • | our ability to increase the size and productivity of our distribution channel; |
| • | decisions by potential end-customers to purchase security solutions from larger, more established security vendors or from their primary network equipment vendors; |
| • | changes in end-customer penetration or attach and renewal rates for our subscriptions; |
| • | timing of revenue recognition and revenue deferrals; |
| • | our ability to manage production and manufacturing related costs, global customer service organization costs, inventory excess and obsolescence costs, and warranty costs; |
| • | insolvency or credit difficulties confronting our end-customers, which could adversely affect their ability to purchase or pay for our products and subscription and support offerings, or confronting our key suppliers, including our sole source suppliers, which could disrupt our supply chain; |
| • | any disruption in our channel or termination of our relationships with important channel partners, including as a result of consolidation among distributors and resellers of security solutions; |
| • | our inability to fulfill our end-customers’ orders due to supply chain delays or events that impact our manufacturers or their suppliers; |
| • | the cost and potential outcomes of litigation, which could have a material adverse effect on our business; |
| • | seasonality or cyclical fluctuations in our markets; |
| • | future accounting pronouncements or changes in our accounting policies, including the impact of the adoption and implementation of the Financial Accounting Standards Board’s new standard regarding revenue recognition; |
| • | increases or decreases in our expenses caused by fluctuations in foreign currency exchange rates, as an increasing amount of our expenses is incurred and paid in currencies other than the U.S. dollar; |
| • | political, economic and social instability caused by the referendum in June 2016, in which voters in the United Kingdom (the “U.K.”) approved an exit from the European Union (the “E.U.”) and the U.K. government subsequently notified the E.U. of its withdrawal, which is commonly referred to as “Brexit,” continued hostilities in the Middle East, terrorist activities, and any disruption these events may cause to the broader global industrial economy; and |
| • | general macroeconomic conditions, both domestically and in our foreign markets that could impact some or all regions where we operate. |
Any one of the factors above, or the cumulative effect of some of the fa
Showing the first 8K of 131K characters. Open the full section
Item 1B. UNRESOLVED STAFF COMMENTS
Not applicable.
Item 2. PROPERTIES
Our corporate headquarters is located in Santa Clara, California where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2028, with options to extend the lease terms through July 2046. We also lease a total of approximately 422,000 square feet of space at two other locations in Santa Clara, which collectively served as our previous corporate headquarters through August 2017, when we relocated to our current campus. Approximately 122,000 square feet of our previous corporate headquarters space is being sublet, and the remaining 300,000 square feet of space is being actively marketed for sublease. The leases for our previous corporate headquarters expire in April 2021 and July 2023. We also lease space for personnel in Israel. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 11. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases.
We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be
- 33 -
available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.
Item 3. LEGAL PROCEEDINGS
The information set forth under the “Litigation” subheading in Note 11. Commitments and Contingencies of Notes to Consolidated Financial Statements in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.
Item 4. MINE SAFETY DISCLOSURES
Not applicable.
- 34 -
PART II
Item 5. MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
Market Information
Our common stock, $0.0001 par value per share, began trading on the NYSE on July 20, 2012, where its prices are quoted under the symbol “PANW.”
Holders of Record
As of August 23, 2019, there were 83 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.
Securities Authorized for Issuance under Equity Compensation Plans
See Part III, Item 12 “Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters” of this Annual Report on Form 10-K for more information regarding securities authorized for issuance.
Recent Sale of Unregistered Securities
There were no sales of unregistered securities during fiscal 2019 other than those transactions previously reported on our Current Reports on Form 8-K.
Purchases of Equity Securities by the Issuer and Affiliated Purchasers
On February 26, 2019, we announced that our board of directors authorized a $1.0 billion share repurchase program which will be funded from available working capital. Repurchases may be made at management’s discretion from time to time on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. The repurchase authorization will expire on December 31, 2020, and may be suspended or discontinued at any time. There were no shares repurchased under our share repurchase program during the three months ended July 31, 2019. As of July 31, 2019, $1.0 billion remained available for future share repurchases under our repurchase program.
Between May 1, 2019 and May 31, 2019, June 1, 2019 and June 30, 2019, and July 1, 2019 and July 31, 2019, shares of restricted common stock were delivered by certain employees upon vesting of equity awards to satisfy tax withholding requirements. The average value of shares delivered to satisfy tax withholding requirements during these periods was $223.69, $200.09, and $222.26, respectively. The number of shares delivered to satisfy tax withholding requirements in these periods was not significant.
Stock Price Performance Graph
This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.
This performance graph compares the cumulative total return on our common stock with that of the NYSE Composite Index and the NYSE Arca Tech 100 Index for the five years ended July 31, 2019. This performance graph assumes $100 was invested on July 31, 2014, in each of the common stock of Palo Alto Networks, Inc., the NYSE Composite Index, and the NYSE Arca Tech 100 Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.
- 35 -

| Company/Index | 7/31/2014 | 7/31/2015 | 7/31/2016 | 7/31/2017 | 7/31/2018 | 7/31/2019 | |||||||||||||||||
| Palo Alto Networks, Inc. | $ | 100.00 | $ | 229.82 | $ | 161.87 | $ | 162.97 | $ | 245.19 | $ | 280.16 | |||||||||||
| NYSE Composite Index | $ | 100.00 | $ | 101.45 | $ | 100.55 | $ | 111.57 | $ | 120.85 | $ | 121.82 | |||||||||||
| NYSE Arca Tech 100 Index | $ | 100.00 | $ | 110.96 | $ | 112.07 | $ | 138.23 | $ | 172.60 | $ | 185.71 |
- 36 -
Item 6. SELECTED FINANCIAL DATA
The selected consolidated statement of operations data for fiscal 2019, 2018, and 2017 and consolidated balance sheet data as of July 31, 2019 and 2018 are derived from our audited consolidated financial statements included elsewhere in this Annual Report on Form 10-K. The selected consolidated statement of operations data for fiscal 2016 and 2015 and consolidated balance sheet data as of July 31, 2017, 2016, and 2015 are derived from audited financial statements not included in this Annual Report on Form 10-K. Our historical results are not necessarily indicative of the results that may be expected in the future. The selected consolidated financial data below should be read in conjunction with the section entitled “Management’s Discussion and Analysis of Financial Condition and Results of Operations” included in Part II, Item 7 of this Annual Report on Form 10-K and our consolidated financial statements and related notes included in Part II, Item 8 of this Annual Report on Form 10-K.
| Year Ended July 31, | |||||||||||||||||||
| 2019 | 2018 | 2017 | 2016 | 2015 | |||||||||||||||
| (in millions) | |||||||||||||||||||
| Selected Consolidated Statements of Operations Data: | |||||||||||||||||||
| Total revenue(1) | $ | 2,899.6 | $ | 2,273.6 | $ | 1,755.1 | $ | 1,378.5 | $ | 928.1 | |||||||||
| Total gross profit(1) | 2,091.2 | 1,628.5 | 1,278.7 | 1,008.5 | 676.6 | ||||||||||||||
| Operating loss(1) | (54.1 | ) | (104.2 | ) | (165.8 | ) | (157.3 | ) | (99.8 | ) | |||||||||
| Net loss(1) | $ | (81.9 | ) | $ | (122.2 | ) | $ | (203.0 | ) | $ | (192.7 | ) | $ | (131.3 | ) | ||||
| Net loss per share, basic and diluted(1) | $ | (0.87 | ) | $ | (1.33 | ) | $ | (2.24 | ) | $ | (2.21 | ) | $ | (1.61 | ) | ||||
| Weighted-average shares used to compute net loss per share, basic and diluted | 94.5 | 91.7 | 90.6 | 87.1 | 81.6 |
| July 31, | |||||||||||||||||||
| 2019 | 2018 | 2017 | 2016 | 2015 | |||||||||||||||
| (in millions) | |||||||||||||||||||
| Selected Consolidated Balance Sheet Data: | |||||||||||||||||||
| Cash and cash equivalents | $ | 961.4 | $ | 2,506.9 | $ | 744.3 | $ | 734.4 | $ | 375.8 | |||||||||
| Investments | 2,417.1 | 1,444.0 | 1,420.0 | 1,204.0 | 952.0 | ||||||||||||||
| Working capital(1)(2) | 1,611.5 | 2,036.8 | 818.1 | 927.2 | 79.3 | ||||||||||||||
| Total assets(1) | 6,592.2 | 5,948.9 | 3,538.5 | 2,858.2 | 2,026.1 | ||||||||||||||
| Total deferred revenue(1) | 2,888.7 | 2,279.3 | 1,692.4 | 1,240.8 | 713.7 | ||||||||||||||
| Convertible senior notes, net(2) | 1,430.0 | 1,920.1 | 524.7 | 500.2 | 476.8 | ||||||||||||||
| Common stock and additional paid-in capital | 2,490.9 | 1,967.4 | 1,599.7 | 1,515.5 | 988.7 | ||||||||||||||
| Total stockholders’ equity(1) | $ | 1,586.3 | $ | 1,160.3 | $ | 927.8 | $ | 894.9 | $ | 559.7 |
| (1) | The amounts for fiscal 2018 and 2017 have been adjusted due to our adoption of the new revenue recognition standard. Fiscal years prior to 2017 have not been adjusted. Refer to Note 1. Description of Business and Summary of Significant Accounting Policies in Part II, Item 8 of this Annual Report on Form 10-K for more information. |
| (2) | The net carrying amount of the 2019 Notes was classified as a current liability in our consolidated balance sheets as of July 31, 2018, and July 31, 2015, and was classified as a long-term liability for all other prior periods presented. None of the 2019 Notes remained outstanding as of July 31, 2019. The net carrying amount of the 2023 Notes was classified as a long-term liability as of July 31, 2019 and July 31, 2018. Refer to Note 10. Debt in Part II, Item 8 of this Annual Report on Form 10-K for more information on the Notes. |
- 37 -
Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS
The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.
Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:
| • | Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A. |
| • | Key Financial Metrics. A summary of our GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance. |
| • | Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2019 to 2018 and fiscal 2018 to 2017. |
| • | Liquidity and Capital Resources. An analysis of changes in our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs. |
| • | Contractual Obligations and Commitments. An overview of our contractual obligations, contingent liabilities, commitments, and off-balance sheet arrangements outstanding as of July 31, 2019, including expected payment schedules. |
| • | Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments. |
| • | Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future. |
Overview
We have pioneered the next generation of security through our innovative platform that empowers enterprises, service providers, and government entities to secure their organizations by safely enabling applications and data running in their networks, on their endpoints, and in the cloud, and by preventing breaches that stem from targeted cyberattacks. Our platform uses an innovative traffic classification engine that identifies network traffic by application, user, and content and provides consistent security across the network, endpoint, and cloud. Accordingly, our platform enables our end-customers to pursue transformative digital initiatives, like public cloud and mobility, that grow their business, while maintaining the visibility and control needed to protect their valued data and critical control systems. We believe the architecture of our platform offers superior performance compared to legacy approaches and reduces the total cost of ownership for organizations by simplifying their security operations and infrastructure and eliminating the need for multiple, stand-alone hardware and software security products, and consists of three primary areas of security capabilities.
Secure the Enterprise:
| • | Secure the network through our Next-Generation Firewalls, available as physical appliances, virtual appliances called VM-Series, or a cloud-delivered service called Prisma Access (formerly GlobalProtect cloud service), and Panorama management delivered as an appliance or as a virtual machine for the public or private cloud. This also includes security services such as WildFire, Threat Prevention, URL Filtering, GlobalProtect, and DNS Security that are delivered as SaaS subscriptions to our Next-Generation Firewalls. |
| • | Secure the endpoints through our Traps advanced endpoint protection software, delivered as a light-weight software agent with cloud or on-premise management capabilities. |
Secure the Cloud:
| • | Secure the cloud through our Prisma cloud security offerings, such as Prisma Public Cloud (formerly RedLock) for security and compliance in public clouds, Prisma Access (formerly GlobalProtect cloud service) for securing user access, Prisma SaaS (formerly Aperture) for protecting SaaS applications, VM-Series for in-line network security in public and private clouds, Traps for host-based public cloud infrastructure protection, and Twistlock for protecting containers in public and private clouds, as well as PureSec for protecting serverless functions in public clouds. |
- 38 -
Secure the Future:
| • | Secure the future of security operations through our Cortex platform, which includes Cortex XDR (formerly Magnifier) for detection and response, Cortex Data Lake (formerly Logging Service) to collect and integrate security data for analytics, Demisto for security orchestration, automation, and response (“SOAR”), and AutoFocus for threat intelligence. These products are delivered as software or SaaS subscriptions. |
For fiscal 2019, 2018, and 2017, total revenue was $2.9 billion, $2.3 billion, and $1.8 billion, respectively, representing year-over-year growth of 27.5% for fiscal 2019 and 29.5% for fiscal 2018. Our growth reflects the increased adoption of our hybrid SaaS revenue model, which consists of product, subscriptions, and support. We believe this model will enable us to benefit from recurring revenues as we continue to grow our installed end-customer base. As of July 31, 2019, we had end-customers in over 150 countries. Our end-customers represent a broad range of industries including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications, and include some of the largest Fortune 100 and Global 2000 companies in the world. We maintain a field sales force that works closely with our channel partners in developing sales opportunities. We use a two-tiered, indirect fulfillment model whereby we sell our products, subscriptions, and support to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers.
Our product revenue grew to $1.1 billion or 37.8% of total revenue for fiscal 2019, representing year-over-year growth of 24.6%. Product revenue is generated from sales of our appliances, primarily our Next-Generation Firewall, which is available in physical and virtualized form. Our Next-Generation Firewall incorporates our proprietary PAN-OS operating system, which provides a consistent set of capabilities across our entire product line. Our products are designed for different performance requirements throughout an organization, ranging from our PA-220, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7080, which is especially suited for very large enterprise deployments and service provider customers. The same firewall functionality that is delivered in our physical appliances is also available in our VM-Series virtual firewalls, which secure virtualized and cloud-based computing environments.
Our subscription and support revenue grew to $1.8 billion or 62.2% of total revenue for fiscal 2019, representing year-over-year growth of 29.4%. Our subscriptions provide our end-customers with real-time access to the latest antivirus, intrusion prevention, web filtering, and modern malware prevention capabilities across the network, endpoints, and the cloud. When end-customers purchase our physical or virtual firewall appliances, they typically purchase support in order to receive ongoing security updates, upgrades, bug fixes, and r
Showing the first 8K of 83K characters. Open the full section
Item 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK
Foreign Currency Exchange Risk
Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenses are incurred outside of the United States and are denominated in foreign currencies and are subject to fluctuations due to changes in foreign currency exchange rates, particularly changes in the euro, British pound, Singapore dollar, Israeli shekel, and Japanese yen. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. The effect of an immediate 10% adverse change in foreign exchange rates on monetary assets and liabilities at July 31, 2019 would not be material to
- 53 -
our financial condition or results of operations. As of July 31, 2019, foreign currency transaction gains and losses and exchange rate fluctuations have not been material to our financial statements. We enter into foreign currency derivative contracts with maturities of 15 months or less which we designate as cash flow hedges to manage the foreign currency exchange rate risk associated with our foreign currency denominated expenditures. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results. Refer to Note 5. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.
As our international operations grow, our risks associated with fluctuation in currency rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in currency exchange rates, which could negatively affect our financial condition and operating results” in Part 1, Item 1A of this Annual Report on Form 10-K.
Interest Rate Risk
The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Some of the securities we invest in are subject to interest risk. To minimize this risk, we maintain our portfolio of cash, cash equivalents, and short-term investments in a variety of securities, including commercial paper, money market funds, U.S. government and agency securities, and corporate debt securities. Due to the short duration and conservative nature of our investment portfolio, a movement of 10% in market interest rates would not have a material impact on our operating results and the total value of the portfolio. The effect of an immediate 10% change in interest rates at July 31, 2019 would not have been material to our operating results and the total value of the portfolio assuming consistent investment levels.
Market Risk and Market Interest Risk
In July 2018, we issued $1.7 billion aggregate principal amount of 0.75% Convertible Senior Notes due 2023 (the “2023 Notes”). We carry these instruments at face value less unamortized discount and unamortized issuance costs on our consolidated balance sheets. As these instruments have a fixed annual interest rate, we have no financial and economic interest exposure associated with changes in interest rates. However, the fair value of fixed rate instruments fluctuates when interest rates change, and additionally, in the case of either series of Notes, when the market price of our common stock fluctuates.
- 54 -
Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA
INDEX TO CONSOLIDATED FINANCIAL STATEMENTS
- 55 -
REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on the Financial Statements
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2019 and 2018, the related consolidated statements of operations, comprehensive loss, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2019, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2019 and 2018, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2019, in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2019, based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) and our report dated September 9, 2019 expressed an unqualified opinion thereon.
Adoption of New Accounting Standard
As discussed in Note 1 to the consolidated financial statements, the Company changed its method of accounting for revenue from contracts with customers in the year ended July 31, 2019 due to the adoption of ASU No. 2014‑09, Revenue from Contracts with Customers, as amended. See below for discussion of our related critical audit matter.
Basis for Opinion
These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.
Critical Audit Matters
The critical audit matters communicated below are matters arising from the current period audit of the financial statements that were communicated or required to be communicated to the audit committee and that: (1) relate to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective, or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matters below, providing separate opinions on the critical audit matters or on the accounts or disclosures to which they relate.
- 56 -
| Revenue Recognition | ||
| Description of the Matter | As described in Note 1 to the consolidated financial statements, the Company adopted ASU No. 2014‑09, Revenue from Contracts with Customers, as amended, in the year ended July 31, 2019. The Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was challenging, specifically related to the effort required to analyze the effect of ASU No. 2014‑09 on the Company’s various product offerings as part of the Company’s implementation using the full retrospective method of adoption, as well as ongoing accounting. This included the identification and determination of the distinct performance obligations and the timing of revenue recognition. For example, there were nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition. | |
| How We Addressed the Matter in Our Audit | We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. Among the procedures we performed to test the identification and determination of the distinct performance obligations and the timing of revenue recognition, we read the executed contract and purchase order to understand the contract, identified the performance obligation(s), determined the distinct performance obligations, and evaluated the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition. | |
| Business Combinations | ||
| Description of the Matter | As of July 31, 2019, the Company completed the acquisition of Demisto, Inc. for net consideration of $474.2 million, the acquisition of RedLock Inc. for net consideration of $158.2 million, and the acquisition of Twistlock Ltd. for net consideration of $378.1 million. As discussed in Note 6 to the consolidated financial statements, the Company accounted for these acquisitions as business combinations. Auditing the accounting for acquisitions was complex due to the significant estimation uncertainty in determining the fair values of identified intangible assets, which primarily consisted of |
Showing the first 8K of 175K characters. Open the full section
Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE
Not applicable.
- 99 -
Item 9A. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15 under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.
Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2019, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Management’s Annual Report on Internal Control over Financial Reporting
For “Management’s Annual Report on Internal Control Over Financial Reporting” see the report under Part II, Item 8 of this Annual Report on Form 10-K, which report is incorporated herein by reference.
For the “Report of Independent Registered Public Accounting Firm,” see the report under Part II, Item 8 of this Annual Report on Form 10-K, which report is incorporated herein by reference.
Changes in Internal Control over Financial Reporting
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the quarter ended July 31, 2019 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
Item 9B. OTHER INFORMATION
Not applicable.
- 100 -
PART III
Item 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE
The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our 2019 annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, 2019, and is incorporated in this report by reference.
Item 11. EXECUTIVE COMPENSATION
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 12. SECURITY OWNERSHIP OF CERTAIN BENEFICIAL OWNERS AND MANAGEMENT AND RELATED STOCKHOLDER MATTERS
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 13. CERTAIN RELATIONSHIPS AND RELATED TRANSACTIONS, AND DIRECTOR INDEPENDENCE
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 14. PRINCIPAL ACCOUNTANT FEES AND SERVICES
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
- 101 -
PART IV
Item 15. EXHIBITS AND FINANCIAL STATEMENT SCHEDULES
Documents filed as part of this Annual Report on Form 10-K are as follows:
| 1. | Consolidated Financial Statements |
Our Consolidated Financial Statements are listed in the “Index to Consolidated Financial Statements” under Part II, Item 8 of this Annual Report on Form 10-K.
| 2. | Financial Statement Schedules |
Financial statement schedules have been omitted because they are not required, not applicable, not present in amounts sufficient to require submission of the schedule, or the required information is shown in the Consolidated Financial Statements or the notes thereto.
| 3. | Exhibits |
The following documents are incorporated by reference or are filed with this Annual Report on Form 10-K, in each case as indicated therein (numbered in accordance with Item 601 of Regulation S-K).
EXHIBIT INDEX
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||
| Form | File No. | Exhibit | Filing Date | |||||||
| 3.1 | Restated Certificate of Incorporation of the Registrant. | 10-K | 001-35594 | 3.1 | October 4, 2012 | |||||
| 3.2 | Amended and Restated Bylaws of the Registrant. | 8-K | 001-35594 | 3.1 | September 14, 2018 | |||||
| 3.3 | Certificate of Change of Location of Registered Agent and/or Registered Office. | 8-K | 001-35594 | 3.1 | August 30, 2016 | |||||
| 4.1 | Warrant to Purchase Stock by Juniper Networks, Inc. | 8-K | 001-35594 | 4.1 | June 4, 2014 | |||||
| 4.2 | Indenture between the Registrant and U.S. Bank National Association, dated as of June 30, 2014. | 8-K | 001-35594 | 4.1 | July 1, 2014 | |||||
| 4.3 | Indenture between the Registrant and U.S. Bank National Association, dated as of July 12, 2018. | 8-K | 001-35594 | 4.1 | July 13, 2018 | |||||
| 4.4 | Form of Global 0.75% Convertible Senior Note due 2023 (included in Exhibit 4.3). | 8-K | 001-35594 | 4.2 | July 13, 2018 | |||||
| 4.5 | Description of Registrant’s Securities. | |||||||||
| 10.1* | Form of Indemnification Agreement between the Registrant and its directors and officers. | S-1/A | 333-180620 | 10.1 | July 9, 2012 | |||||
| 10.2* | 2005 Equity Incentive Plan and related form agreements under 2005 Equity Incentive Plan. | S-1/A | 333-180620 | 10.2 | July 9, 2012 | |||||
| 10.3* | 2012 Equity Incentive Plan and related form agreements under 2012 Equity Incentive Plan, as amended. | 10-Q | 001-35594 | 10.1 | February 27, 2019 | |||||
| 10.4* | 2012 Employee Stock Purchase Plan and related form agreements under 2012 Employee Stock Purchase Plan, as amended and restated. | 10-K | 001-35594 | 10.4 | September 7, 2017 | |||||
| 10.5* | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | S-8 | 333-227901 | 99.1 | October 19, 2018 | |||||
| 10.6* | Demisto, Inc. 2015 Stock Option Plan, as amended. | S-8 | 333-230663 | 99.1 | April 1, 2019 | |||||
| 10.7* | Twistlock Ltd. Amended and Restated 2015 Share Option Plan. | S-8 | 333-232672 | 99.1 | July 16, 2019 | |||||
- 102 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||
| Form | File No. | Exhibit | Filing Date | |||||||
| 10.8* | Employee Incentive Compensation Plan, as amended and restated. | 10-Q | 001-35594 | 10.2 | November 25, 2014 | |||||
| 10.9* | Clawback Policy, adopted as of August 29, 2017. | 10-Q | 001-35594 | 10.3 | November 21, 2017 | |||||
| 10.10* | Executive Incentive Plan effective December 8, 2017. | 10-Q | 001-35594 | 10.2 | February 27, 2018 | |||||
| 10.11* | Letter Agreement between the Registrant and Nir Zuk, dated December 19, 2011. | S-1 | 333-180620 | 10.8 | April 6, 2012 | |||||
| 10.12* | Amended Offer Letter between the Registrant and René Bonvanie, dated July 10, 2019. | 8-K | 001-35594 | 10.1 | July 11, 2019 | |||||
| 10.13* | Offer Letter between the Registrant and Frank Calderoni, dated February 24, 2016. | 8-K | 001-35594 | 10.1 | February 25, 2016 | |||||
| 10.14* | Offer Letter between the Registrant and Mary Pat McCarthy, dated October 13, 2016. | 8-K | 001-35594 | 10.1 | October 24, 2016 | |||||
| 10.15* | Offer Letter between the Registrant and Sridhar Ramaswamy, dated August 29, 2017. | 8-K | 001-35594 | 10.1 | August 31, 2017 | |||||
| 10.16* | Offer Letter between the Registrant and Kathleen Bonanno, dated November 17, 2017. | 8-K | 001-35594 | 10.1 | November 20, 2017 | |||||
| 10.17* | Offer Letter between the Registrant and Jean Compeau, dated February 22, 2018. | 8-K | 001-35594 | 10.1 | February 26, 2018 | |||||
| 10.18* | New Offer Letter between the Registrant and Mark D. McLaughlin, dated May 31, 2018. | 8-K | 001-35594 | 10.1 | June 4, 2018 | |||||
| 10.19* | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | 8-K | 001-35594 | 10.2 | June 4, 2018 | |||||
| 10.20* | Offer Letter between the Registrant and Amit K. Singh, dated October 11, 2018. | 8-K | 001-35594 | 10.1 | October 15, 2018 | |||||
| 10.21* | Confirmatory Employment Letter between the Registrant and Lee Klarich, dated December 19, 2011. | 10-Q | 001-35594 | 10.4 | November 30, 2018 | |||||
| 10.22* | Offer Letter between the Registrant and Lorraine Twohill, dated April 10, 2019. | 8-K | 001-35594 | 10.1 | April 15, 2019 | |||||
| 10.23* | Offer Letter between the Registrant and Rt Hon Sir John Key, dated April 10, 2019. | 8-K | 001-35594 | 10.2 | April 15, 2019 | |||||
| 10.24 | Lease between the Registrant and Santa Clara Office Partners LLC, dated October 20, 2010, as amended. | S-1 | 333-180620 | 10.14 | April 6, 2012 | |||||
| 10.25 | Amendment No. 2 to Lease between the Registrant and Santa Clara Office Partners LLC, dated July 2, 2013. | 10-K | 001-35594 | 10.17 | September 25, 2013 | |||||
| 10.26 | Lease between the Registrant and SI 34 LLC, dated September 17, 2012. | 10-K | 001-35594 | 10.16 | October 4, 2012 | |||||
| 10.27 | Lease between the Registrant and SI 34 LLC, dated September 17, 2012. | 10-K | 001-35594 | 10.17 | October 4, 2012 | |||||
| 10.28** | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | 10-Q | 001-35594 | 10.1 | May 30, 2019 | |||||
| 10.29 | Settlement, Release and Cross-License Agreement, dated May 27, 2014, by and between the Registrant and Juniper Networks, Inc. | 8-K | 001-35594 | 10.1 | May 28, 2014 | |||||
- 103 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||
| Form | File No. | Exhibit | Filing Date | |||||||
| 10.30 | Share Purchase Agreement between the Registrant, Cyvera Ltd., Palo Alto Networks Holding B.V., the shareholders of Cyvera Ltd. and Shareholder Representative Services LLC, dated March 22, 2014. | 10-Q | 001-35594 | 10.1 | June 3, 2014 | |||||
| 10.31 | Amendment No. 1 to the Share Purchase Agreement between the Registrant, Cyvera Ltd., Palo Alto Networks Holding B.V., the shareholders of Cyvera Ltd. and Shareholder Representative Services LLC, dated April 9, 2014. | 10-Q | 001-35594 | 10.2 | June 3, 2014 | |||||
| 10.32 | Purchase Agreement, dated June 24, 2014, by and among the Registrant and J.P. Morgan Securities LLC, RBC Capital Markets, LLC and Citigroup Global Markets Inc., as representatives of the initial purchasers named therein. | 8-K | 001-35594 | 10.1 | June 26, 2014 | |||||
| 10.33 | Form of Convertible Note Hedge Confirmation. | 8-K | 001-35594 | 10.2 | June 26, 2014 | |||||
| 10.34 | Form of Warrant Confirmation. | 8-K | 001-35594 | 10.3 | June 26, 2014 | |||||
| 10.35 | Purchase Agreement, dated July 10, 2018, by and among the Registrant and Citigroup Global Markets Inc. and Wells Fargo Securities, LLC, as representatives of the several Initial Purchasers named therein. | 8-K | 001-35594 | 10.1 | July 13, 2018 | |||||
| 10.36 | Form of Convertible Note Hedge Confirmation. | 8-K | 001-35594 | 10.2 | July 13, 2018 | |||||
| 10.37 | Form of Warrant Confirmation. | 8-K | 001-35594 | 10.3 | July 13, 2018 | |||||
| 10.38 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.29 | September 17, 2015 | |||||
| 10.39 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.30 | September 17, 2015 | |||||
| 10.40 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.31 | September 17, 2015 | |||||
| 10.41 | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | 8-K | 001-35594 | 10.1 | October 19, 2015 | |||||
| 10.42 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.2 | November 24, 2015 | |||||
| 10.43 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.3 | November 24, 2015 | |||||
| 10.44 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.1 | November 22, 2016 | |||||
| 10.45 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.2 | November 22, 2016 | |||||
| 10.46 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.3 | November 22, 2016 | |||||
| 10.47 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.1 | March 1, 2017 | |||||
- 104 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||
| Form | File No. | Exhibit | Filing Date | |||||||
| 10.48 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.2 | March 1, 2017 | |||||
| 10.49 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.3 | March 1, 2017 | |||||
| 10.50 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.40 | September 7, 2017 | |||||
| 10.51 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.41 | September 7, 2017 | |||||
| 10.52 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.42 | September 7, 2017 | |||||
| 10.53 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.5 | November 21, 2017 | |||||
| 10.54 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III G LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.6 | November 21, 2017 | |||||
| 10.55 | Amendment No. 5 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.7 | November 21, 2017 | |||||
| 10.56 | Credit Agreement, dated as of September 4, 2018, by and among the Registrant, the lenders from time to time party thereto and Citibank, N.A., as administrative agent. | 8-K | 001-35594 | 10.1 | September 6, 2018 | |||||
| 21.1 | List of subsidiaries of the Registrant. | |||||||||
| 23.1 | Consent of Independent Registered Public Accounting Firm. | |||||||||
| 24.1 | Power of Attorney (contained in the signature page to this Annual Report on Form 10-K). | |||||||||
| 31.1 | Certification of the Chief Executive Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. | |||||||||
| 31.2 | Certification of the Chief Financial Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. | |||||||||
| 32.1† | Certification of Chief Executive Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | |||||||||
| 32.2† | Certification of Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | |||||||||
| 101.INS | XBRL Instance Document. | |||||||||
| 101.SCH | XBRL Taxonomy Schema Linkbase Document. | |||||||||
| 101.CAL | XBRL Taxonomy Calculation Linkbase Document. | |||||||||
| 101.DEF | XBRL Taxonomy Definition Linkbase Document. | |||||||||
| 101.LAB | XBRL Taxonomy Labels Linkbase Document. | |||||||||
| 101.PRE | XBRL Taxonomy Presentation Linkbase Document. |
- 105 -
| * | Indicates a management contract or compensatory plan or arrangement. |
| ** | Certain portions of this exhibit have been omitted as the Registrant has determined (i) the omitted information is not material and (ii) the omitted information would likely cause harm to the Registrant if publicly disclosed. |
| † | The certifications attached as Exhibit 32.1 and Exhibit 32.2 that accompany this Annual Report on Form 10-K, are not deemed filed with the Securities and Exchange Commission and are not to be incorporated by reference into any filing of the Registrant under the Securities Act of 1933, as amended, or the Securities Exchange Act of 1934, as amended, whether made before or after the date of this Annual Report on Form 10-K, irrespective of any general incorporation language contained in such filing. |
- 106 -
SIGNATURES
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on September 9, 2019.
| PALO ALTO NETWORKS, INC. | |
| By: | /s/ NIKESH ARORA |
| Nikesh Arora | |
| Chairman and Chief Executive Officer |
- 107 -
POWER OF ATTORNEY
KNOW ALL THESE PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Nikesh Arora, Kathleen Bonanno, and Jean Compeau, and each of them, as his or her true and lawful attorney-in-fact and agent, with full power of substitution and resubstitution, for him or her and in his or her name, place and stead, in any and all capacities, to sign any and all amendments to this Annual Report on Form 10-K, and to file the same, with all exhibits thereto, and other documents in connection therewith, with the Securities and Exchange Commission, granting unto said attorneys-in-fact and agents, and each of them, full power and authority to do and perform each and every act and thing requisite and necessary to be done in connection therewith, as fully to all intents and purposes as he or she might or could do in person, hereby ratifying and confirming all that said attorneys-in-fact and agents, or any of them, or their, his or her substitutes, may lawfully do or cause to be done by virtue thereof.
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrant and in the capacities and on the dates indicated:
| Signature | Title | Date | ||
| /s/ NIKESH ARORA | Chairman, Chief Executive Officer and Director (Principal Executive Officer) | September 9, 2019 | ||
| Nikesh Arora | ||||
| /s/ KATHLEEN BONANNO | Chief Financial Officer (Principal Financial Officer) | September 9, 2019 | ||
| Kathleen Bonanno | ||||
| /s/ JEAN COMPEAU | Chief Accounting Officer (Principal Accounting Officer) | September 9, 2019 | ||
| Jean Compeau | ||||
| /s/ MARK D. MCLAUGHLIN | Vice Chairman and Director | September 9, 2019 | ||
| Mark D. McLaughlin | ||||
| /s/ NIR ZUK | Chief Technical Officer and Director | September 9, 2019 | ||
| Nir Zuk | ||||
| /s/ FRANK CALDERONI | Director | September 9, 2019 | ||
| Frank Calderoni | ||||
| /s/ ASHEEM CHANDNA | Director | September 9, 2019 | ||
| Asheem Chandna | ||||
| /s/ JOHN M. DONOVAN | Director | September 9, 2019 | ||
| John M. Donovan | ||||
| /s/ CARL ESCHENBACH | Director | September 9, 2019 | ||
| Carl Eschenbach | ||||
| /s/ JAMES J. GOETZ | Director | September 9, 2019 | ||
| James J. Goetz | ||||
| /s/ RT HON SIR JOHN KEY | Director | September 9, 2019 | ||
| Rt Hon Sir John Key | ||||
| /s/ MARY PAT MCCARTHY | Director | September 9, 2019 | ||
| Mary Pat McCarthy | ||||
| /s/ SRIDHAR RAMASWAMY | Director | September 9, 2019 | ||
| Sridhar Ramaswamy | ||||
| /s/ LORRAINE TWOHILL | Director | September 9, 2019 | ||
| Lorraine Twohill | ||||
| /s/ DANIEL J. WARMENHOVEN | Director | September 9, 2019 | ||
| Daniel J. Warmenhoven |
- 108 -