Item 1. BUSINESS
43K characters. Original on sec.gov · Markdown
Item 1. BUSINESS
General
Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
We empower enterprises, service providers, and government entities to secure all users, applications, data, networks and devices with comprehensive visibility and context continuously across all locations. We deliver cybersecurity products covering a broad range of use cases, enabling our end-customers to secure their networks, remote workforce, access to the service edge, branch locations, public and private clouds, and to advance their Security Operations Centers (“SOC”). We believe our portfolio offers advanced prevention and security, while reducing the total cost of ownership for organizations by improving operational efficiency and eliminating the need for siloed point products. We do this with solutions focused on delivering value in three fundamental areas:
Secure the Enterprise:
- Secure the network through our ML-powered Next-Generation Firewalls, available in a number of form factors, including physical, virtual and containerized appliances, as well as a cloud-delivered service, with Panorama management available as an appliance or as a virtual machine for the public or private cloud. This also includes security services such as Threat Prevention, WildFire, URL Filtering, DNS Security, IoT Security, GlobalProtect, SD-WAN and Data Loss Prevention that are delivered as SaaS subscriptions to our ML-powered Next-Generation Firewalls.
Secure the Cloud:
- Secure the cloud through our Prisma security offerings, such as Prisma Cloud, the industry’s most comprehensive Cloud Native Security Platform (“CNSP”), protecting applications, data and the entire cloud native technology stack, throughout the full development lifecycle and across multi- and hybrid- cloud environments, Prisma SaaS for protecting SaaS applications, Prisma Access, a comprehensive Secure Access Service Edge (“SASE”) offering, that, together with CloudGenix SD-WAN, securing SD-WAN to enable the cloud delivered branch, and VM-Series and CN-Series for in-line network security in multi- and hybrid- cloud environments.
Secure the Future:
- Secure the future of security operations through our Cortex security offerings, which includes Cortex XDR for prevention, detection and response, Cortex XSOAR for security orchestration, automation and response (“SOAR”), AutoFocus for threat intelligence, and Cortex Data Lake to collect and integrate security data for analytics. These products are delivered as software or SaaS subscriptions.
Impact of COVID-19 on our Business
We are actively monitoring, evaluating and responding to developments relating to COVID-19, which has and is expected to result in continued significant global social and business disruption. While we instituted a global work-from-home policy beginning in March 2020, we did not incur significant disruptions in our work operations during fiscal 2020. We are conducting business as usual with restrictions to employee travel and transitioning of in-person marketing events to virtual formats, among other modifications. These changes will substantially remain in effect in the first quarter of fiscal 2021 and are likely to extend to future quarters. We will continue to actively monitor the situation and will make further changes to our business operations as may be required by federal, state or local authorities or that we determine are in the best interests of our employees, end-customers, partners, suppliers and stockholders. Our focus remains on the safety of our employees, striving to protect the health and well-being of the communities in which we operate, and providing technology to our employees, end-customers and partners to help them do their best work while remote.
Although some end-customers adopted Prisma Access as their secure work-from-home solution for the longer term, COVID-19 may curtail our end-customers' spending and could lead them to delay or defer purchasing decisions, and lengthen sales cycles and payment terms, which could materially adversely impact our business, results of operations and overall financial performance. Also, certain of our end-customers or partners may be or may become credit or cash constrained making it difficult for them to fulfill their payment obligations to us. The extent of the impact of COVID-19 on our operational and financial performance will depend on developments, including the duration and spread of the virus, impact on our end-customers’ spending, volume of sales and length of our sales cycles, impact on our partners, suppliers and employees, actions that may be taken by governmental authorities and other factors identified in Part I, Item 1A "Risk Factors" in this Form 10-K. Given the dynamic nature of these circumstances, the full impact of COVID-19 on our ongoing business, results of operations and overall financial performance cannot be reasonably estimated at this time.
- 4 -
Product, Subscription, and Support Offerings
Our products are available in the form of the product, subscription, and support offerings described below.
Firewall Appliances and Software. All of our firewall appliances and software incorporate our PAN-OS operating system and come with the same rich set of features ensuring consistent operation across our entire product line. These features include: App-ID, User-ID, Content-ID, site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-220, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7080, which is designed for large scale data centers and service provider use. Our firewall appliances come in a physical form factor, in a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments, as well as in a containerized form factor, called CN-Series.
Panorama. Panorama is our centralized security management solution for global control of all of our firewall appliances and software deployed on an end-customer’s network, as well as in their instances in public or private cloud environments as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the appliances, software, virtual and containerized systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses. Panorama offers network security monitoring through the ability to view logs and run reports from all managed appliances and software in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.
Virtual System Upgrades**.** Virtual System Upgrades are available as extensions to the Virtual System capacity that ships with our physical appliances. Virtual Systems provide a mechanism to support multiple distinct security policies and administrative access for tenants on the same hardware device, which is applicable to our large enterprise and service provider end-customers.
Subscription Offerings**.** We offer a number of subscriptions as part of our portfolio. Of these subscription offerings, Threat Prevention, WildFire, URL Filtering, DNS Security, IoT Security, GlobalProtect, SD-WAN and Data Loss Prevention are sold as options to our firewall appliances and software, whereas AutoFocus, Prisma Access (formerly GlobalProtect cloud service), CloudGenix SD-WAN, Prisma Cloud (formerly Redlock Inc. (“RedLock”), Twistlock LTD. (“Twistlock”), PureSec Ltd. (“PureSec”) and Aporeto Inc. (“Aporeto”)), Prisma SaaS (formerly Aperture), Cortex Data Lake (formerly Logging Service), Cortex XDR (formerly Cortex XDR and Traps) and Cortex XSOAR (formerly Demisto Inc. (“Demisto”)) are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:
Secure the Enterprise:
-
Threat Prevention.** This subscription provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows to manage popular open-source signature formats to extend our leading coverage.
-
WildFire.** This cloud-based or appliance-based subscription provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. The core component of this subscription is a sandbox environment that can operate on an end-customers’ private cloud or our public cloud, where files can be run and monitored for more than 100 behavioral characteristics that identify the file as malware. A machine learning module derived from the cloud sandbox environment is now delivered in-line on the ML-powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity. Once identified, whether in the cloud or in-line, preventive measures are automatically generated and delivered to all subscribed devices in seconds or less. By providing this as a cloud-based subscription, all of our end-customers benefit from malware found on any of our end-customer’s networks.
-
URL Filtering.** This subscription provides the uniform resource locator (“URL”) filtering capabilities of our portfolio. Our cloud-based URL filtering database consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats such as phishing, malware, and command-and-control. The curated on-appliance URL database can be augmented to suit the traffic patterns of the local user community with a custom URL database. Our cloud-delivered service features network-based phishing protection, including a machine learning module delivered inline on our ML-powered Next-Generation Firewalls. These machine learning techniques can detect and stop never before seen threats and evasive phishing before they reach users or endpoints. Native integration with our ML-
- 5 -
powered Next-Generation Firewalls eliminates the need for customers to deploy and manage their web security separately from network security.
-
DNS Security.** This cloud-based subscription uses machine learning to proactively block malicious domains and stops attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be by-passed. It allows firewalls access to DNS signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture.
-
IoT Security.** IoT Security is a new subscription on our ML-powered Next-Generation Firewalls with backward compatibility to older versions of PAN-OS. Using machine learning and our App-ID technology, it can accurately identify and classify various IoT and operational technology (“OT”) devices including never-been-seen-before devices, mission critical OT devices and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our ML-powered Next-Generation Firewalls. Our existing subscription-based security services have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.
-
GlobalProtect.** This appliance-based subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets and phones will stay connected to the corporate network when they are on a network of any kind and as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.
-
SD-WAN.** Our SD-WAN subscription is now integrated with PAN-OS, so that our end-customers can get the security features of our PAN-OS ML-powered Next Generation Firewall together with SD-WAN functionality. The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.
-
Data Loss Prevention.** Our Enterprise Data Loss Prevention service is a cloud service that provides consistent, reliable protection of sensitive data, such as personally identifiable information (PII) and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including GDPR, CCPA, PCI DSS, HIPAA, and others.
Secure the Cloud:
-
Prisma Cloud.** Prisma Cloud is the industry’s most comprehensive CNSP, securing public clouds and cloud native applications. Prisma Cloud delivers cloud security posture management and a cloud workload protection platform that provides comprehensive visibility and threat detection across an organization's hybrid, multi-cloud infrastructure.
-
Prisma SaaS.** Prisma SaaS is a multi-mode, cloud access security broker service that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored across the supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications.
-
Prisma Access.** This cloud-based subscription enables our end-customers to utilize the preventive capabilities of our portfolio to secure remote offices and mobile users, providing consistent protection across globally distributed network and cloud environments without the need for firewall appliances or software in the remote locations. With this offering, our end-customers can quickly and easily add or remove remote locations and users, and establish and adjust security policies as needed, using a multi-tenant, cloud-based security infrastructure that we operate on their behalf.
-
CloudGenix SD-WAN**. Our CloudGenix SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Unlike legacy SD-WAN solutions that introduce cost and complexity, Our CloudGenix
- 6 -
SD-WAN ensures exceptional user experience with app defined policies and simplifies network and security operations using machine learning and automation.
Secure the Future:
-
Cortex XDR.** This cloud-based subscription enables organizations to identify and stop the most sophisticated attacks by applying AI and machine learning to context rich network, endpoint, and cloud data, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR is comprised of XDR Prevent and XDR Pro. XDR Prevent delivers enterprise class endpoint security focused on preventing attacks. XDR Pro encompasses endpoint detection and response (“EDR”) and cross-data source analytics including network and identity data. These capabilities build on each other, such that a customer can start with XDR Prevent, then upgrade to XDR Pro for EDR and then upgrade to XDR Pro for cross-data source analytics.
-
Cortex XSOAR.** Available as a cloud-based subscription or an on-premises appliance, Cortex XSOAR is the industry’s first extended SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR is powered by our machine learning bot, DBot, which ingests information about indicators to determine if they are malicious. It learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations.
-
AutoFocus.** This cloud-based subscription provides threat intelligence capabilities to our end-customers’ security operations teams. Indicators of compromise and anomalies that occur on an end-customer’s network can be correlated with similar data that has been centrally collected from all our participating end-customers. This offers our end-customers priority alerts, deep attack context, and high-fidelity threat intelligence across millions of malware samples and tens of billions of file artifacts. This includes a direct pipeline to actionable intelligence from Unit 42, our threat research team. AutoFocus can inform users if adversaries and campaigns discovered by Unit 42 have targeted the end-user’s network, or similar networks.
-
Cortex Data Lake.** This cloud-based subscription allows our customers to collect large amounts of context-rich enhanced network logs generated by our security offerings, including those of our ML-powered Next-Generation Firewalls, Prisma Access subscription, and Cortex XDR subscription, without needing to plan for local data storage.
Support. We offer Standard Support, Premium Support, four-hour Premium Support and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer an annual subscription-based Service Account Management (“SAM”) service that provides support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for both hardware and software in order to receive ongoing security updates, PAN-OS upgrades, bug fixes, and repair. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.
Professional Services. Professional services are delivered directly by us and through our authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, configuration, and firewall migrations, as well as Prisma and Cortex deployments. Our education services provide online and in-classroom training and are also primarily delivered through our authorized training partners.
Technology
We provide comprehensive and integrated cybersecurity solutions with a portfolio that eliminates the need for siloed security products.
ML-powered Next-Generation Firewall. Our ML-powered Next-Generation Firewalls embed machine learning in the core of the firewall, empowering our customers to stay ahead of new emerging threats, see and secure their entire enterprise, including IoT, and support speed and error reduction with automatic policy recommendations. Our ML-Powered Next-Generation Firewalls extend visibility and security to all devices connecting to an end-user’s network, including unmanaged IoT devices without the need to deploy additional sensors. Our ML-powered Next-Generation Firewalls inspect all traffic defined by the end-users policies, including all applications, threats, and content, and tie that traffic to the user, regardless of location or device type. The user, application, devices and content—the elements that run a business—become integral components of an enterprise's security policy via our User-ID, App-ID, Device-ID and Content-ID technology. As a result, security aligns with business policies as well as write rules that are easy to understand and maintain. Our ML-powered Next-Generation Firewalls can be deployed in multiple form factors, including hardware, software and cloud service, all managed centrally.
- 7 -
Prisma Access. Prisma Access is a SASE technology that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world in 76 countries, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic.
Delivering protection at scale, Prisma Access provides global coverage so teams do not have to worry about sizing and deploying hardware firewalls at the branch. Prisma Access uses Cortex Data Lake for centralized analysis, reporting, and forensics.
CloudGenix SD-WAN**.** CloudGenix SD-WAN provides deep application visibility, with Layer 7 intelligence for network policy creation and traffic engineering, ensuring exceptional user experience by enabling network teams to deliver Service Level Agreements (“SLA”s) for all apps including Cloud, SaaS and Unified communication as a Service (“UCaaS”). Machine learning and data science methodologies automate operations and problems avoidance to simplify network operations and reduce network trouble tickets.
Prisma Cloud. Prisma Cloud is a unified CNSP with broad security and compliance coverage for the entire cloud across hybrid and multi-cloud environments. Prisma Cloud protects cloud native applications and data spanning hosts, containers, serverless deployments, storage, and other platform as a Service (“PaaS”) offerings across cloud platforms. It dynamically discovers resources as they are deployed and correlates data cloud services (resource configurations, flow logs, audit logs, host and container logs, etc.) to provide security and compliance insights for cloud applications. It uses machine learning to profile user, workload, and app behaviors to prevent advanced threats.
Prisma Cloud integrates with continuous integration and continuous development (“CI/CD”) tool chains to provide full lifecycle vulnerability management, infrastructure-as-code scanning, runtime defense, and cloud native firewalling. With a comprehensive library of compliance frameworks, it vastly simplifies the task of maintaining compliance. Prisma Cloud provides this through deep context-sharing that spans infrastructure, PaaS, users, development platforms, data, and application workloads. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities.
Prisma SaaS. Prisma SaaS enables safe cloud adoption by providing visibility, compliance controls, and security for cloud applications and sensitive data. It helps minimize the use of shadow IT, secure access to corporate SaaS applications and mitigate the risk of a data breach in the cloud.
Cortex XDR. Cortex XDR is an industry recognized extended detection and response offering that integrates endpoint, network, and cloud data to stop sophisticated attacks. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, reducing investigation time eighty eight percent compared to manual processes.
Cortex XSOAR. Cortex XSOAR improves SOC efficiency with an industry recognized extended SOAR offering. Security leaders can transform every aspect of their operations with a comprehensive, unified approach to case management, automation, real-time collaboration, and threat intelligence management. Cortex XSOAR enables security teams to manage alerts across all sources, standardize any processes with playbooks, take action on threat intelligence, and automate response for every security use case, and use of which has resulted, for many of our customers, in significantly faster SOC response times and a significant reduction in alerts to the SOC which require human intervention.
Certifications. Many of our products have been awarded Federal Information Processing Standard (“FIPS”) 140-2 Level 2, Common Criteria/National Information Assurance Partnership (“NIAP”) Evaluation Assurance Level **(“**EAL”) 2, Common Criteria/NIAP EAL4+, Network Equipment-Building System (“NEBS”), and ICSA Firewall certifications.
Research and Development
Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security market. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. In addition to our focus on hardware and software, our research and development team is focused on research into applications and threats, which allows us to respond to the rapidly changing application and threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2020, we introduced several new offerings, including: PAN-OS 10.0 with over 70 new features; our new ML-powered Next-Generation Firewalls; and our Cortex XSOAR solution that redefines security orchestration and automation with integrated threat intelligence management. Additionally, we acquired productive investments that fit well within our long-term strategy. For example, we acquired Zingbox, Inc. (“Zingbox”), which we believe will accelerate our delivery of IoT security through our ML-powered Next-Generation Firewall and Cortex products, Aporeto, which we believe will strengthen our cloud-native security platform capabilities delivered by Prisma Cloud and CloudGenix Inc. (“CloudGenix”), which we believe will strengthen our SASE offering.
We plan to continue to significantly invest in our research and development effort as we evolve and extend the capabilities of our portfolio.
- 8 -
Intellectual Property
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.
We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to and use of our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully asserted in the future or may be invalidated, circumvented or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their proprietary technology or other rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.
Competition
We operate in the intensely competitive enterprise security market that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into five categories:
-
large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”) or those that have acquired, or may acquire, large network and endpoint security vendors and have the technical and financial resources to bring competitive solutions to the market;
-
independent security vendors such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), and Zscaler, Inc. (“Zscaler”) that offer a mix of network and endpoint security products;
-
startups and single-vertical vendors that offer independent or emerging solutions in network;
-
public cloud vendors and startups that offer solutions for cloud security (private, public and hybrid cloud); and
-
large and small companies, such as Crowdstrike, Inc (“Crowdstrike”) that offer solutions for security operations and endpoint security.
As our market grows, it will attract more highly specialized vendors as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
-
product features, reliability, performance, and effectiveness;
-
product line breadth, diversity, and applicability;
-
product extensibility and ability to integrate with other technology infrastructures;
-
price and total cost of ownership;
-
adherence to industry standards and certifications;
-
strength of sales and marketing efforts; and
-
brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our products with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
Sales, Customer Support and Marketing
Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of products for a
- 9 -
variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise perimeter, the enterprise data center, and the distributed enterprise perimeter. Our end-customer deployments typically involve at least one pair of our products along with one or more of our subscriptions, depending on size, security needs and requirements, and network complexity. No single end-customer accounted for more than 10% of our total revenue in fiscal 2020, 2019, or 2018.
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30-90 days written notice prior to the renewal date, and payment to us from the channel partner within 30-45 calendar days of the date we issue an invoice for such sales. For fiscal 2020, 68.8% of our total revenue was derived from sales to four distributors.
We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We expect to continue to grow our sales headcount in all of our principal markets and expand our presence into countries where we currently do not have a direct sales presence.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To ensure optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2020, we had more than 5,600 channel partners.
Customer Support. Our customer support organization is responsible for delivering support, professional, and educational services directly to our channel partners and to end-customers. We leverage the capabilities of our channel partners and train them in the delivery of support, professional, and educational services to ensure these services are locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand, field, communications, including analyst relations and digital and analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate web site and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize our end-customer conference “Ignite.” We also publish threat intelligence research such as the Unit 42 Cloud Threat Report and the Unit 42 IoT Threat Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront shortly after fulfillment of an order and are included in deferred revenue. Timing of revenue recognition for subscription and support offerings may vary depending on the contractual period or when the subscription and support offerings are rendered. Products are shipped and billed shortly after receipt of an order. The majority of our product revenue comes from orders that are received and shipped in the same quarter. As such, we do not believe that our product backlog at any particular time is meaningful and it is not necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth occurring in our fiscal second and fourth quarters.
Manufacturing
We outsource the manufacturing of our security products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
- 10 -
The component parts within our products are either sourced by our manufacturing partners or by various component suppliers. We do not have any long-term manufacturing contracts that guarantee us any fixed capacity or pricing, which could increase our exposure to supply shortages or price fluctuations related to raw materials.
Employees
As of July 31, 2020, we had 8,014 employees. Competition for qualified personnel in our industry is intense, and we believe that our future success depends in part on our continued ability to hire, motivate, and retain such personnel.
Available Information
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our web site as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only.
- 11 -
Previous: Cover and table of contents · Next: Item 1A. RISK FACTORS