Item 1. BUSINESS
58K characters. Original on sec.gov · Markdown
Item 1. BUSINESS
General
Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
We empower enterprises, service providers, and government entities to secure all users, applications, data, networks, clouds and devices with comprehensive visibility and context continuously across all locations. We deliver cybersecurity products covering a broad range of use cases, enabling our end-customers to secure their networks, remote and hybrid workforces, branch locations, and public and private clouds, and to advance their Security Operations Centers (“SOC”). We believe our portfolio offers advanced prevention and security, while reducing the total cost of ownership for organizations by improving operational efficiency and eliminating the need for siloed point products. We do this with solutions focused on delivering value in five fundamental areas:
Zero Trust Network Security:
- Enabling zero trust network security through our ML-Powered Next-Generation Firewalls, available in a number of form factors, including physical, virtual, and containerized appliances, as well as a cloud-delivered service. This also includes our add-on Cloud-Delivered Security Services, such as Threat Prevention, WildFire, URL Filtering, Advanced URL Filtering, DNS Security, IoT Security, GlobalProtect, SD-WAN, Enterprise Data Loss Prevention (“Enterprise DLP”), SaaS Security API and SaaS Security Inline that secure content, applications, users, and devices across our ML-Powered Next-Generation Firewalls, Prisma, and Cortex product lines, to enable best-in-class security across a broad range of applications. Panorama, our network security management solution, available as hardware or virtual machine, can centrally manage all of our firewalls irrespective of their form factor, location, or scale.
Cloud Security:
- Enabling cloud security through our Prisma security offerings. Prisma Cloud, the industry’s most comprehensive Cloud Native Security Platform (“CNSP”), secures multi- and hybrid-cloud environments and cloud native applications, integrating security across the full deployment lifecycle. VM-Series and CN-Series enforce in-line network security in multi- and hybrid-cloud environments.
Secure Access Service Edge:
- Prisma Access, the industry’s most complete cloud-delivered security platform, together with Prisma SD-WAN, SaaS Security API and SaaS Security Inline, provide a comprehensive Secure Access Service Edge (“SASE”) offering that is used to secure remote workforces and enable the cloud-delivered branch.
Security Analytics and Automation:
- Delivering the next generation of endpoint security, security analytics and security automation solutions through our Cortex portfolio. These include our industry-leading extended detection and response platform Cortex XDR to prevent, detect, and respond to complex cybersecurity attacks, Cortex XSOAR for security orchestration, automation, and response (“SOAR”), Cortex Xpanse for attack surface management (“ASM”) and Cortex Data Lake allowing our customers to collect and analyze large amounts of context-rich data across endpoints, networks, and clouds. These products are delivered as software or SaaS subscriptions.
Threat Intelligence and Security Consulting (Unit 42):
- Enabling security teams with up-to-date threat intelligence and deep cybersecurity expertise before, during and after attacks through our Unit 42 threat research and security consulting team. Unit 42 offers incident response, risk management, board advisory and proactive cybersecurity assessment services.
Impact of COVID-19 on Our Business
We are actively monitoring, evaluating, and responding to developments relating to COVID-19, which has resulted in, and is expected to continue to result in significant global, social, and business disruption. While we instituted a global work-from-home policy beginning in March 2020, which has been modified to provide employees with the choice to work in certain of our offices when and as they feel comfortable, we did not incur significant disruptions in our work operations during fiscal 2021. We are conducting business as usual with restrictions to employee travel, and we have transitioned in-person marketing events to virtual formats, among other modifications. We expect these changes will substantially remain in effect in the first quarter of fiscal 2022 and could extend to future quarters. We will continue to actively monitor the situation, including progress made through vaccinations, and we will make further changes to our business operations as may be required by federal, state, or local authorities and that we determine are in the best interests of our employees, end-customers, partners, suppliers, and stockholders. Our focus remains on the safety of our employees, and we strive to protect the health and well-being of the communities in which we operate, in part, by providing technology to our employees, end-customers, and partners to help them do their best work while remote.
Although some end-customers adopted Prisma Access as their secure work-from-home solution for the longer term, COVID-19
- 4 -
has affected our end-customers’ spending and could lead them to delay or defer purchasing decisions, and lengthen sales cycles and payment terms, which could materially adversely impact our business, results of operations, and overall financial performance. Also, certain of our end-customers or partners may be or may become credit or cash constrained, making it difficult for them to fulfill their payment obligations to us. The extent of the impact of COVID-19 on our operational and financial performance will depend on developments, including the duration and spread of the virus and its variants, impact on our end-customers’ spending, volume of sales and length of our sales cycles, impact on our partners, suppliers, and employees, actions that may be taken by governmental authorities, and other factors identified in Part I, Item 1A “Risk Factors” in this Form 10-K. Given the dynamic nature of these circumstances, the full impact of COVID-19 on our ongoing business, results of operations and overall financial performance cannot be reasonably estimated at this time.
Product, Subscription, and Support Offerings
Our products are available in the form of the product, subscription, and support offerings described below.
Products
Firewall Appliances and Software. All of our firewall appliances and software incorporate our PAN-OS operating system and come with the same rich set of features ensuring consistent operation across our entire product line. These features include: App-ID, User-ID, Content-ID, Device-ID, site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7080, which is designed for large-scale data centers and service provider use. Our firewall appliances come in a physical form factor, and in a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments, as well as in a containerized form factor, called CN-Series.
Panorama. Panorama is our centralized security management solution for global control of all of our firewall appliances and software deployed on an end-customer’s network, as well as in their instances in public or private cloud environments, as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the appliances, software, virtual and containerized systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses. Panorama offers network security monitoring through the ability to view logs and run reports from all managed appliances and software in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.
Virtual System Upgrades**.** Virtual System Upgrades are available as extensions to the Virtual System capacity that ships with our physical appliances. Virtual Systems provide a mechanism to support multiple distinct security policies and administrative access for tenants on the same hardware device, which is applicable to our large enterprise and service provider end-customers.
Subscriptions
We offer a number of subscriptions as part of our portfolio. Of these subscription offerings, cloud-delivered security services like Threat Prevention, WildFire, URL Filtering, Advanced URL Filtering, DNS Security, IoT Security, SaaS Security Inline, GlobalProtect, SD-WAN and Enterprise DLP are sold as options to our firewall appliances and software, whereas Prisma Cloud (formerly Redlock Inc. (“RedLock”), Twistlock Ltd. (“Twistlock”), PureSec Ltd. (“PureSec”), Aporeto Inc. (“Aporeto”)), Prisma Access, Prisma SD-WAN (formerly CloudGenix SD-WAN), SaaS Security API (formerly Prisma SaaS), Cortex XDR (formerly Traps), Cortex XSOAR (formerly Demisto Inc. (“Demisto”)), Cortex Xpanse and Cortex Data Lake are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:
Zero Trust Network Security:
-
Threat Prevention.** This subscription provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows to manage popular open-source signature formats to extend our leading coverage.
-
WildFire.** This cloud-based or appliance-based subscription provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. The core component of this subscription goes beyond traditional sandbox environments and can operate on an end-customers’ local environment, private cloud or our public cloud. WildFire combines dynamic and
- 5 -
static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. A machine learning module derived from the cloud sandbox environment is now delivered in-line on the ML-Powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity. Once identified, whether in the cloud or in-line, preventive measures are automatically generated and delivered in seconds or less across networks, clouds, endpoints, or wherever WildFire-enabled sensors are deployed. By providing this as a cloud-based subscription, all of our end-customers benefit from malware found on any of our end-customers’ networks.
-
URL Filtering.** This subscription provides the uniform resource locator (“URL”) filtering capabilities of our portfolio. Our cloud-based URL filtering database consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats such as phishing, malware, and command-and-control. The curated on-appliance URL database can be augmented to suit the traffic patterns of the local user community with a custom URL database. Native integration with our ML-Powered Next-Generation Firewalls eliminates the need for customers to deploy and manage their web security separately from network security.
-
Advanced URL Filtering**. This subscription builds on all of the capabilities of URL Filtering, adding the industry’s first in-line ML-powered web protection engine. It delivers real-time detection and prevention of unknown, evasive, and targeted web-based threats such as phishing, malware, and command-and-control. While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the first offering to protect patient zero from unknown fileless and file-based web attacks in real-time.
-
DNS Security.** This cloud-based subscription uses machine learning to proactively block malicious domains and stops attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed. It allows firewalls access to DNS signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture. It includes industry-first protections against multiple emerging DNS-based network attacks.
-
IoT Security.** IoT Security is a new subscription on our ML-Powered Next-Generation Firewalls with backward compatibility to older versions of PAN-OS. Using machine learning and our App-ID technology, it can accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission critical OT devices and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our ML-Powered Next-Generation Firewalls. Our existing subscription-based security services have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.
-
SaaS Security API.** SaaS Security API (formerly Prisma SaaS) is a multi-mode, cloud access security broker service that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored across the supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated cloud access security broker (“CASB”).
-
SaaS Security Inline.** SaaS Security Inline is a new subscription on our ML-Powered Next Generation Firewalls that adds an in-line service to automatically gain visibility and control over the tens of thousands of known and new sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. It provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time with best-in-class security. The solution is easy to deploy being natively integrated on our range of ML-Powered Next-Generation Firewalls, eliminating the architectural complexity of traditional CASB products, while offering the lowest total cost of ownership. It can be combined with SaaS Security API (formerly Prisma SaaS) as a complete integrated CASB.
-
GlobalProtect**. This appliance-based subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets and phones will stay connected to the corporate network when they are on a network of any kind and, as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.
-
SD-WAN.** Our SD-WAN subscription is now integrated with PAN-OS, so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality. The SD-WAN
- 6 -
overlay supports dynamic, intelligent path selection based on the applications, services and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.
- Enterprise DLP.** Our data loss prevention service is a cloud service that provides consistent, reliable protection of sensitive data, such as personally identifiable information (“PII”) and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including GDPR, CCPA, PCI DSS, HIPAA, and others.
Cloud Security:
- Prisma Cloud.** Prisma Cloud is the industry’s most comprehensive CNSP, securing public clouds and cloud native applications. Prisma Cloud delivers cloud security posture management, cloud workload protection platform, cloud network security, and cloud infrastructure entitlement management capabilities that provide comprehensive visibility and protection across an organization’s hybrid, multi-cloud infrastructure.
Secure Access Service Edge:
-
Prisma Access**. Prisma Access consolidates more point-products into a single converged cloud-delivered platform than any competing solution, transforming network security and allowing organizations to enable secure hybrid workforces. Unlike competing platforms, only Prisma Access protects all application traffic with complete, best-in-class security while ensuring an exceptional user experience with industry-leading service-level agreements (“SLA”s).
-
Prisma SD-WAN**. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Unlike legacy SD-WAN solutions that introduce cost and complexity, our Prisma SD-WAN ensures exceptional user experience with application-defined policies and simplifies network and security operations using machine learning and automation.
Security Analytics and Automation:
-
Cortex XDR.** This cloud-based subscription enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning across all data, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics, including network, cloud and identity data. These capabilities build on each other such that a customer can start with XDR Prevent, then upgrade to XDR Pro for EDR or XDR Pro for cross-data analytics.
-
Cortex XSOAR.** Available as a cloud-based subscription or an on-premises appliance, Cortex XSOAR is the industry’s most comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks and manage incidents across their security product stack to improve response time and analyst productivity. It learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations.
-
Cortex Xpanse.** This cloud-based subscription provides attack surface management, which is the ability for an organization to identify what an attacker would see amongst all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Finally, Cortex Xpanse continuously identifies Internet assets, risky services or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence.
-
Cortex Data Lake.** This cloud-based subscription allows our customers to collect and analyze large amounts of context-rich network security data. This includes collection of enhanced network logs generated by our security offerings, including those of our ML-Powered Next-Generation Firewalls and Prisma Access subscription, eliminating the need to plan for local data storage.
Support
Customer Support. We offer Standard Support, Premium Support, Four-Hour Premium Support and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Service Account
- 7 -
Management (“SAM”) to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software and certain cloud offerings in order to receive ongoing security updates, PAN-OS upgrades, bug fixes, and repair. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.
Threat Intelligence and Cyber Security Consulting. Unit 42 brings together our world-renowned threat researchers with an elite team of security consultants (formerly Crypsis) to create an intelligence-driven, response-ready organization. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. As threats escalate, Unit 42 is available to advise customers on the latest risks, assess their readiness, and help them recover when they are victim of a cybersecurity breach. Unit 42 Security Consultants serve as a trusted partner with state-of-the-art cyber risk expertise and incident response capabilities, helping customers focus on their business before, during, and after a breach.
Professional Services. Professional services are delivered directly by us and through our authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations, as well as Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as online and in-classroom training, which are primarily delivered through our authorized training partners.
Technology
We provide comprehensive and integrated cybersecurity solutions with a portfolio that eliminates the need for siloed security products.
ML-Powered Next-Generation Firewall. Our ML-Powered Next-Generation Firewalls embed machine learning in the core of the firewall, empowering our customers to stay ahead of new emerging threats, see and secure their entire enterprise, including IoT, and support speed and error reduction with automatic policy recommendations. Our ML-Powered Next-Generation Firewalls extend visibility and security to all devices connecting to an end-user’s network, including unmanaged IoT devices without the need to deploy additional sensors. Our ML-Powered Next-Generation Firewalls inspect all traffic defined by the end-users policies, including all applications, threats, and content, and tie that traffic to the user, regardless of location or device type. The user, application, devices and content—the elements that run a business—become integral components of an enterprise’s security policy via our User-ID, App-ID, Device-ID and Content-ID technology. As a result, security aligns with business policies, as well as writes rules that are easy to understand and maintain. Our ML-Powered Next-Generation Firewalls can be deployed in multiple form factors, including hardware, software and cloud service, all managed centrally.
Prisma Access. Prisma Access is a SASE technology that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world in 77 countries, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic.
Delivering protection at scale, Prisma Access provides global coverage so teams do not have to worry about sizing and deploying hardware firewalls at the branch. Prisma Access uses Cortex Data Lake for centralized analysis, reporting, and forensics.
Prisma SD-WAN**.** Prisma SD-WAN is the industry’s first next-generation SD-WAN solution that makes the secure cloud-delivered branch possible, delivering an ROI of up to 243%. Unlike legacy SD-WAN solutions that introduce cost and complexity, Prisma SD-WAN ensures exceptional user experience with application-defined policies and simplifies network and security operations using machine learning and AI.
Prisma Cloud. Prisma Cloud is a unified CNSP with broad security and compliance coverage for the entire cloud across hybrid and multi-cloud environments. Prisma Cloud protects cloud native applications spanning hosts, containers, serverless architectures and other platform as a service (“PaaS”) offerings across cloud platforms. It dynamically discovers public cloud resources as they are deployed and correlates data cloud services (resource configurations, flow logs, audit logs, host and container logs, etc.) to provide security and compliance insights for cloud applications. It uses machine learning to profile user, workload, and application behaviors to identify and prevent advanced threats.
Prisma Cloud integrates with continuous integration and continuous development (“CI/CD”) tool chains to provide full lifecycle vulnerability management, compliance, infrastructure-as-code scanning, and runtime defense. With a comprehensive library of compliance frameworks, it vastly simplifies the task of maintaining compliance. Prisma Cloud provides this through deep context-sharing that spans infrastructure, PaaS, users, development platforms, data, and application workloads. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities and security issues.
- 8 -
SaaS Security. SaaS Security enables safe cloud adoption by providing visibility, compliance controls, and security for cloud applications and sensitive data. It helps minimize the use of shadow IT, secure access to corporate SaaS applications and mitigate the risk of a data breach in the cloud. SaaS Security is an integrated CASB and includes SaaS Security API and SaaS Security Inline.
Cortex XDR. Cortex XDR is an industry-recognized extended detection and response offering that integrates endpoint, network, and cloud data to stop sophisticated attacks. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, reducing investigation time by 88% compared to manual processes.
Cortex XSOAR. Cortex XSOAR improves SOC efficiency with an industry-recognized extended SOAR offering. Security leaders can transform every aspect of their operations with a comprehensive, unified approach to case management, automation, real-time collaboration, and threat intelligence management. Cortex XSOAR enables security teams to manage alerts across all sources, standardize any processes with playbooks, take action on threat intelligence, and automate response for every security use case, and use of which has resulted, for many of our customers, in significantly faster SOC response times and a significant reduction in alerts to the SOC which require human intervention.
Cortex Xpanse. Cortex Xpanse is an attack surface management platform that provides an attacker’s view of your enterprise. Cortex Xpanse gives a complete and accurate inventory of an organization’s global Internet-facing assets and misconfigurations, allowing them to continuously discover, evaluate, and mitigate an external attack surface, flag risky communications, evaluate supplier risk or assess the security of merger and acquisition targets. With Cortex Xpanse, enterprises are armed with complete asset inventories in order to reduce risk from vulnerabilities and improve mean time to discover and respond. Audit and Compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.
Certifications. Many of our products have been awarded Federal Information Processing Standard (“FIPS”) 140-2 Level 2, Common Criteria/National Information Assurance Partnership (“NIAP”) Evaluation Assurance Level (“EAL”) 2, Common Criteria/NIAP EAL4+, Network Equipment-Building System (“NEBS”), and ICSA Firewall certifications.
Research and Development
Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security industry. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. In addition to our focus on hardware and software, our research and development team is focused on research into applications and threats, which allows us to respond to the rapidly changing application and threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2021, we introduced several new offerings, including: Cortex XDR 2.5, Next Generation SD-WAN, Prisma Cloud 2.0, Enterprise DLP, 5G Security, IoT Healthcare Security, Prisma Access 2.0 and Complete Zero Trust Network Security. Additionally, we acquired productive investments that fit well within our long-term strategy. For example, we acquired the Crypsis Group (“Crypsis”), which we expect will expand our incident response capabilities and strengthen our Cortex strategy; we acquired Sinefa Group, Inc. (“Sinefa”), which we expect will extend our Prisma Access offering; we acquired Expanse Inc. (“Expanse”), which we expect will enrich our Cortex offerings and provide organizations an integrated view of the enterprise to combine external, internal, and threat data; and we acquired Bridgecrew Inc. (“Bridgecrew”), which we expect will expand our Prisma Cloud offering to deliver security across the full application lifecycle.
We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.
Intellectual Property
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.
We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to and use of our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully
- 9 -
asserted in the future or may be invalidated, circumvented or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their proprietary technology or other rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.
Government Regulation
We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
Competition
We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into five categories:
-
large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”) or those that have acquired, or may acquire, large network and endpoint security vendors and have the technical and financial resources to bring competitive solutions to the market;
-
independent security vendors such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), and Zscaler, Inc. (“Zscaler”) that offer a mix of network and endpoint security products;
-
startups and single-vertical vendors that offer independent or emerging solutions across various areas of security;
-
public cloud vendors and startups that offer solutions for cloud security (private, public and hybrid cloud); and
-
large and small companies, such as Crowdstrike, Inc (“Crowdstrike”) that offer solutions for security operations and endpoint security.
As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
-
product features, reliability, performance, and effectiveness;
-
product line breadth, diversity, and applicability;
-
product extensibility and ability to integrate with other technology infrastructures;
-
price and total cost of ownership;
-
adherence to industry standards and certifications;
-
strength of sales and marketing efforts; and
-
brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our products with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
Sales, Customer Support and Marketing
Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of products for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise perimeter, the enterprise data center, and the distributed enterprise perimeter. Our end-customer deployments typically involve at least one pair of our products along with one or more of our subscriptions, depending on size, security needs and requirements, and network complexity. No single end-customer accounted for more than 10% of our total revenue in fiscal 2021, 2020, or 2019.
- 10 -
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2021, 56.0% of our total revenue was derived from sales to three distributors.
We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2021, we had more than 5,900 channel partners.
Customer Support. Our customer support organization is responsible for delivering support, professional, and educational services directly to our channel partners and to end-customers. We leverage the capabilities of our channel partners and train them in the delivery of support, professional, and educational services to enable these services to be locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand, field, communications, including analyst relations and digital and analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize our end-customer conference “Ignite.” We also publish threat intelligence research such as the Unit 42 Cloud Threat Report and the Unit 42 IoT Threat Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront shortly after fulfillment and are included in deferred revenue. Timing of revenue recognition for subscription and support offerings may vary depending on the contractual period or when the subscription and support offerings are rendered. Products are shipped and billed shortly after receipt of an order. However, insufficient supply and inventory may delay our product shipments. The majority of our product revenue comes from orders that are received and shipped in the same quarter. As such, we do not believe that our product backlog at any particular time is meaningful and it is not necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth occurring in our fiscal second and fourth quarters.
Manufacturing
We outsource the manufacturing of our security products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
The component parts within our products are either sourced by our manufacturing partners or by various component suppliers. We do not have any long-term manufacturing contracts that guarantee us any fixed capacity or pricing, which could increase our exposure to supply shortages or price fluctuations related to raw materials.
- 11 -
Human Capital
We believe our ongoing success depends on our employees. Development and investment in our people have always been central to who we are, and will continue to be so. Our People Strategy is a comprehensive approach to source, hire, onboard, integrate, develop, engage and reward employees. With a global workforce of 10,473 (as of July 31, 2021), we take our People Strategy seriously and manage it as a critical element of our overall company strategy.
Source & Hire. Sourcing and hiring diverse talent and setting them free to create and execute is central to our approach to our people. Our talent acquisition team utilizes a number of methods to find subject experts in their respective fields, including the use of a variety of channels that focus on reaching diverse and underserved communities. Our university relations team partners with hundreds of academic institutions, including colleges and universities that focus on serving underrepresented populations, to provide career pathways for early-in-career candidates. We also encourage current employees to provide qualified referrals. Through our License-to-Hire program, we ensure that hiring managers are trained to recruit, that they are made aware of potential unconscious biases and interview for the values and competencies that we believe enhance our culture. We have diverse interview panels to deliver a quality interview experience to a diverse slate of candidates.
Onboard & Integrate. We believe that a positive onboarding experience is foundational to positive employee engagement and rapid productivity. During the COVID-19 pandemic, we built and utilized virtual learning platforms and employee communication channels to provide new employees with inspirational, often personalized, onboarding experiences. Onboarding is a journey of integration that extends through the first year at Palo Alto Networks for every employee. In addition, we have built specialist learning tracks for interns and new graduates that have been recognized as best in class externally. As part of our merger and acquisition strategy, we have also established a robust integration program with the goal to enable individuals joining our teams to feel part of our culture at speed.
Develop & Motivate. FLEXLearn is our unique approach to personalized employee development. FLEXLearn is a learning experience platform that provides employees with a path based on their needs, interests, style, and career journey. Development information about core business elements, professional skill sets, working in a distributed environment, as well as required compliance training, such as Code of Conduct, anti-discrimination, anti-harassment, and anti-bribery training, is also deployed through the FLEXLearn platform. In addition, FLEXLearn provides employees with events and activities that motivate and spark critical thinking, on topics ranging from inclusion, to well-being and collaboration. As of July 31, 2021, 99.5% of our employees had completed Code of Conduct and Business Ethics training. On average, employees had completed 12 hours of development through the FLEXLearn platform during fiscal 2021.
Engage & Reward. We conduct weekly executive listening sessions and frequent “pulse surveys” to better understand employee engagement, sentiment well-being, and latterly, the agility to transition to a distributed work model. Many of these sessions have informed our holistic People Strategy through programs like FLEXWORK, Inclusion and Diversity, and Internal Mobility.
Employee sentiment has continued to be highly positive. In February 2021, we conducted an anonymous global employee engagement survey. The response rate was 92% representing all functions and geographies. The overall engagement score was 81%. Employees indicated a strong sense of belonging, confidence in leadership, and an understanding of how their work contributes to the Company’s goals. Outcomes from the survey are being used to develop company-wide and function-specific action plans.
In addition to a comprehensive compensation and diverse benefits program, we believe in an always-on feedback and rewards philosophy. From recurring 1:1 sessions and quarterly performance feedback to use of our Cheers for Peers peer recognition program, employees get continuous input about the value they bring to the organization.
Inclusion & Diversity. We are intentional about including diverse points of view, perspectives, experiences, backgrounds and ideas in our decision-making processes. We deeply believe that true diversity exists when we have representation of all ethnicities, genders, orientations and identities, and cultures in our workforce. Our Inclusion and Diversity (“I&D”) programs continue to advance those visions. The diversity of our board of directors, with women representing 33% of our board (as of July 31, 2021), is an example of that vision in action. We have eight employee network groups (“ENG”s) which are employee-led groups that play a vital role in building understanding and awareness. Over 25% of our global workforce was involved in at least one ENG as of July 31, 2021. Our ENGs are provided with a budget to fund activities for their communities, we involve our ENGs in listening sessions with executive teams and we work in partnership to develop our annual I&D plans, because we believe involvement is critical. Our I&D philosophy is fully embedded in our talent acquisition, learning and development and rewards and recognition programs.
FLEXWORK. Throughout the COVID-19 pandemic, while prioritizing the health and safety of our employees, we have learned how to collaborate in a distributed work reality and to create opportunities for employees to maintain a sense of belonging and focus on well-being. The pivot to a distributed work model presented an opportunity to re-examine how and where we work going forward past the pandemic. Moving into the future we aim to disrupt the nature of work. Our philosophy is simple: place our employees at the center of their working life by providing employees flexibility, personalization, and choice regarding how they work, the benefits they choose, the way they consume learning and, where possible, where they work. We truly believe that the more our
- 12 -
employees have choice, the more engaged they will be. This theory has proven out in both the productivity and positive sentiment achieved across the months of the pandemic.
FLEXWORK adds even more opportunity to scale our efforts to improve Inclusion and Diversity. It further enables us to recognize each individual as unique, with their own priorities and needs, and gives the employee greater agency to personalize their decisions and utilize our programs and initiatives to meet those interests and desires.
The change to the nature of work won’t happen in isolation as other organizations must make similar transitions. We created the FLEXWORK Coalition, a group of over 800 companies that have joined discussion sessions about the nature of work. Our company leads these conversations, bringing in expert speakers and case studies to guide other company transformations.
Environmental, Social & Governance
We recognize our duty to address environmental, social and governance (“ESG”) practices. From our Climate Commitment and our social impact programs to our Supplier Responsibility initiatives and Code of Business Conduct and Ethics, we value the opportunity to have meaningful outcomes that reinforce our intention to respect our planet, uplift our communities and advance our industry.
Environmental. We recognize climate change is a global crisis and are committed to doing our part to reduce environmental impacts by setting clear goals, engaging in coalitions and collaborating across our value chain. In February 2021, we declared a set of climate commitments. Aligned to the Paris Agreement, we set a goal to be carbon neutral by 2030 and outlined three strategies to reach that goal: utilize 100% renewable energy, reduce our greenhouse gas (“GHG”) emissions using guidance established by the Science Based Targets initiative and to offset remaining emissions by investing in quality carbon offset programs. We committed to being transparent about our progress over time through annual reporting.
Social. In addition to our FLEXWORK People Strategy described in the section titled “Human Capital” above, we prioritized the health and safety of our employees during the COVID-19 pandemic. Through the deployment of our Global Supplier Code of Conduct, we continued to reach across our supply chain to communicate our expectations regarding labor standards, business practices and workplace health and safety conditions. During fiscal 2021, we became an affiliate member of the Responsible Business Alliance and published a Supplier Diversity statement to advance our supplier responsibility programs. We value our role as a good corporate citizen and scaled our social impact programs in fiscal 2021, focusing on helping colleagues and communities impacted by the COVID-19 pandemic through charitable donations, employee giving and volunteer programs. We also expanded our cybersecurity education programs to help youth protect their digital way of life and to prepare diverse adults for careers in cybersecurity.
Governance. Integrity is one of our core values. Our corporate behavior and leadership practices model ethical decision making. Employees and suppliers are informed about our governance expectations through our Codes of Conduct, compliance training programs and ongoing communications. As of July 31, 2021, 99.5% of our employees had completed Code of Conduct and Business Ethics training. Reinforcing the importance of our ESG performance, the charter of the Nominating and Governance Committee of the board of directors includes the primary oversight of ESG.
Available Information
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only.
- 13 -
Previous: Cover and table of contents · Next: Item 1A. RISK FACTORS