Item 1. BUSINESS
54K characters. Original on sec.gov · Markdown
Item 1. BUSINESS
General
Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by industry leading artificial intelligence and automation. We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications and infrastructure with zero trust principles. Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products. Our company focuses on delivering value in five fundamental areas:
Network Security:
- Our network security platform, which includes our ML-Powered Next-Generation Firewalls, available in a number of form factors, including physical, virtual, and containerized appliances, as well as a cloud-delivered service, has been recognized as a leader in the industry. Our network security platform also includes our Cloud-Delivered Security Services, such as Threat Prevention, Advanced Threat Prevention, WildFire®, Advanced URL Filtering, DNS Security, IoT Security, GlobalProtect™, SD-WAN, Enterprise Data Loss Prevention (“Enterprise DLP”), AIOps, SaaS Security API, and SaaS Security Inline. Through these add-on security services, our customers are able to secure their content, applications, users, and devices across our network security platform as well as the Prisma® and Cortex® product lines. Panorama™, our network security management solution, available as hardware or virtual machine, can centrally manage our network security platform irrespective of form factor, location, or scale.
Secure Access Service Edge:
- Prisma Access is our next-generation Zero Trust Network Access (“ZTNA”) platform that provides secure network access for all employees with unified policy management and continuous threat inspection. We have recently introduced ZTNA 2.0, which addresses major shortcomings in the first-generation ZTNA products in the industry (which we refer to as ZTNA 1.0). Prisma Access delivers granular least-privileged access along with continuous trust verification and security inspection, and protects security for all applications and data across the enterprise infrastructure. Prisma Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor Secure Access Service Edge (“SASE”) offering that is used to secure remote workforces and enable the cloud-delivered branch.
Cloud Security:
- We enable cloud native security through our Prisma Cloud platform. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures hybrid and multi-cloud environments for applications, data, and the entire cloud native technology stack across the full development lifecycle; from code to runtime. For inline network security on multi and hybrid-cloud environments, we also offer our VM-Series and CN-Series Firewall offerings.
Security Operations:
- We deliver the next generation of endpoint security, security analytics and security automation solutions through our Cortex portfolio. These include our industry-leading extended detection and response platform Cortex XDR® to prevent, detect, and respond to complex cybersecurity attacks, Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), Cortex Xpanse® for attack surface management (“ASM”), and Cortex Data Lake allowing our customers to collect and analyze large amounts of context-rich data across endpoints, networks, and clouds. These products are delivered as software subscriptions or SaaS subscriptions.
Threat Intelligence and Security Consulting (Unit 42):
- We enable security teams with up-to-date threat intelligence and deep cybersecurity expertise before, during and after attacks through our Unit 42 threat research and security consulting team. Unit 42 offers incident response, risk management, board advisory, and proactive cybersecurity assessment services.
- 4 -
Product, Subscription, and Support
Our products are available in the form of the product, subscription, and support offerings described below.
Products
Firewall Appliances and Software. Our ML-Powered Next Generation Firewalls embed machine learning in the core of the firewall and employ inline deep learning in the cloud, empowering our customers to stop zero-day threats in real time, see and secure their entire enterprise including IoT, and reduce errors with automatic policy recommendations. All of our firewall appliances and software incorporate our PAN-OS® operating system and come with the same rich set of features ensuring consistent operation across our entire product line. The content, applications, users, and devices—the elements that run a business—become integral components of an enterprise’s security policy via our Content-ID™, App-ID™, User-ID™, and Device-ID technology. In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and branch offices, to our top-of-the-line PA-7080, which is designed for large-scale data centers and service provider use. Our firewall appliances come in a physical form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments. We also offer Cloud NGFW, a managed next-generation firewall (“NGFW”) offering, to secure customers’ applications on Amazon Web Services (“AWS”).
Panorama. Panorama is our centralized security management solution for global control of all of our firewall appliances and software deployed on a customer’s network, as well as in their instances in public or private cloud environments. Panorama can be deployed as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the appliances, software, virtual and containerized systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses. Panorama offers network security monitoring through the ability to view logs and run reports from all managed appliances and software in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.
Virtual System Upgrades**.** Virtual System Upgrades are available as extensions to the Virtual System capacity that ships with our physical appliances. Virtual Systems provide a mechanism to support multiple distinct security policies and administrative access for tenants on the same hardware device, which is applicable to our large enterprise and service provider customers.
Subscriptions
We offer a number of subscriptions as part of our portfolio. Of these subscription offerings, cloud-delivered security services like Threat Prevention, Advanced Threat Prevention, WildFire, Advanced URL Filtering, DNS Security, IoT Security, SaaS Security Inline, GlobalProtect, SD-WAN, Enterprise DLP and AIOps are sold as options to our firewall appliances and software, whereas Prisma Cloud, Prisma Access, Prisma SD-WAN, SaaS Security API, Cortex XDR, Cortex XSOAR, Cortex Xpanse and Cortex Data Lake are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:
Cloud-delivered Security Services:
-
Threat Prevention.** This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows to manage popular open-source signature formats to extend our leading coverage.
-
Advanced Threat Prevention**. This cloud-delivered security service builds on all of the capabilities of Threat Prevention, adding the industry’s first Inline Deep Learning protection engine for Command-and-Control (“C2”). It delivers real-time detection and prevention of unknown, evasive, and targeted C2 communications over HTTP, unknown-TCP, unknown-UDP and encrypted over SSL. Advanced Threat Prevention is the first offering to protect patient zero from unknown command and control in real-time.
- 5 -
-
WildFire.** This cloud-delivered security service (which can also be delivered as an appliance) provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. The core component of this subscription goes beyond traditional sandbox environments and can operate on an end-customers’ local environment, private cloud or our public cloud. WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. A machine learning module derived from the cloud sandbox environment is now delivered inline on the ML-Powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity. Once identified, whether in the cloud or inline, preventive measures are automatically generated and delivered in seconds or less across networks, clouds, endpoints, or wherever WildFire-enabled sensors are deployed. By providing this as a cloud-based subscription, all of our end-customers benefit from malware found on any of our end-customers’ networks.
-
Advanced URL Filtering**. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. It delivers real-time detection and prevention of unknown, evasive, and targeted web-based threats such as phishing, malware, and command-and-control. While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the industry’s first inline web protection engine capable of detecting never-before-seen web-based threats and preventing them in real-time. In addition, it includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats such as phishing, malware, and command-and-control.
-
DNS Security.** This cloud-delivered security service uses machine learning to proactively block malicious domains and stops attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed. It allows firewalls access to DNS signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture. It offers comprehensive DNS attack coverage and includes industry-first protections against multiple emerging DNS-based network attacks.
-
IoT Security.** IoT Security is a cloud-delivered security service on our ML-Powered Next-Generation Firewalls with backward compatibility to older versions of PAN-OS. Using machine learning and our App-ID technology, it can accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission critical OT devices and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our ML-Powered Next-Generation Firewalls. Our existing subscription-based security services have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.
-
SaaS Security API.** SaaS Security API (formerly Prisma SaaS) is a multi-mode, cloud access security broker service that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored across the supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated cloud access security broker (“CASB”).
-
SaaS Security Inline.** SaaS Security Inline is a recent cloud-delivered security service on our ML-Powered Next Generation Firewalls that adds an inline service to automatically gain visibility and control over the tens of thousands of known and new sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. It provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time with best-in-class security. The solution is easy to deploy being natively integrated on our range of ML-Powered Next-Generation Firewalls, eliminating the architectural complexity of traditional CASB products, while offering low total cost of ownership. It can be combined with SaaS Security API as a complete integrated CASB.
-
GlobalProtect**. This appliance-based subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets and phones will stay connected to the corporate network when they are on a network of any kind and, as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.
- 6 -
-
SD-WAN.** Our SD-WAN subscription is integrated with PAN-OS, so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality. The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.
-
Enterprise DLP.** This cloud-delivered security service provides consistent, reliable protection of sensitive data, such as personally identifiable information (“PII”) and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including GDPR, CCPA, PCI DSS, HIPAA, and others.
-
AIOps for NGFW:** AIOps for NGFW is a new cloud-delivered security service available on ML-Powered Next-Generation Firewalls and Panorama that run on PAN‑OS 10.0 and above, and is available in both free and licensed premium versions. AIOps for NGFW redefines firewall operational experience by empowering security teams to proactively strengthen security posture and resolve firewall disruptions. AIOps for NGFW provides continuous best practice recommendations powered by machine learning (“ML”) based on industry standards, security policy context, and advanced telemetry data collected from all Palo Alto Networks® firewalls to improve security posture. It also intelligently predicts firewall health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.
Cloud Security:
- Prisma Cloud.** Prisma Cloud is a comprehensive CNAPP, securing both cloud native and lift-and-shift applications across hybrid- and multi-cloud environments. With broad security and compliance coverage and a flexible agentless, as well as agent-based, architecture, Prisma Cloud protects cloud-native applications spanning hosts, containers, serverless architectures and other platform as a service (“PaaS”) offerings across cloud platforms. It dynamically discovers public cloud resources as they are deployed and correlates cloud data services (resource configurations, flow logs, audit logs, host and container logs, etc.) to provide timely security and compliance insights for cloud applications. The platform uses machine learning to profile user, workload, and application behaviors to identify and prevent advanced threats.
For security and development and operations teams, Prisma Cloud removes the impedance mismatch between security and cloud-driven agility by integrating with continuous integration and continuous development (“CI/CD”) tool chains to provide full lifecycle vulnerability management, compliance, infrastructure-as-code scanning, and runtime defense. With a comprehensive library of compliance frameworks, it vastly simplifies the task of maintaining compliance. Prisma Cloud accomplishes this through deep context-sharing that spans infrastructure, PaaS, users, development platforms, data, and application workloads. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities and security issues.
Prisma Cloud delivers cloud security posture management, cloud workload protection platform, cloud network security, cloud code security, and cloud identity security capabilities that provide continuous visibility and protection across an organization’s hybrid, and multi-cloud infrastructure.
Secure Access Service Edge:
-
Prisma Access**. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates more point-products into a single converged cloud-delivered offering than any competing solution, transforming network security and allowing organizations to enable secure hybrid workforces. Unlike competing solutions, only Prisma Access protects all application traffic with complete, best-in-class security while ensuring an exceptional user experience with industry-leading service-level agreements (“SLA”s).
-
Prisma SD-WAN**. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional Multiprotocol Label Switching (“MPLS”) based WAN architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver an exceptional user experience. Unlike legacy SD-WAN solutions that introduce cost and complexity, our Prisma SD-WAN ensures an excellent user experience with application-defined policies and simplifies network and security operations using machine learning and automation.
- 7 -
Security Operations:
-
Cortex XDR.** This cloud-based subscription enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning across all data, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics, including network, cloud and identity data. These capabilities build on each other such that a customer can start with XDR Prevent, then upgrade to XDR Pro for endpoints or XDR Pro for cross-data analytics. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes.
-
Cortex XSOAR.** Available as a cloud-based subscription or an on-premises appliance, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks and manage incidents across their security product stack to improve response time and analyst productivity. It learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in SOC alerts which require human intervention.
-
Cortex Xpanse.** This cloud-based subscription provides attack surface management, which is the ability for an organization to identify what an attacker would see amongst all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.
-
Cortex Data Lake.** This cloud-based subscription allows our customers to collect and analyze large amounts of context-rich network security data. This includes a collection of enhanced network logs generated by our security offerings, including those of our ML-Powered Next-Generation Firewalls and Prisma Access subscription, eliminating the need to plan for local data storage.
Support
Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, Four-Hour Premium Support and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers (“CSM”) to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software and certain cloud offerings in order to receive ongoing security updates, PAN-OS upgrades, bug fixes, and repair. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.
Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers focus on their business before, during, and after a breach.
Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.
- 8 -
Research and Development
Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security industry. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. In addition to our focus on hardware and software, our research and development team is focused on research into applications and threats, which allows us to respond to the rapidly changing application and threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2022, we introduced several new offerings, including: Prisma Cloud 3.0, Prisma Access 3.0, AIOps for NGFW, PAN-OS 10.2, and Cloud NGFW for AWS. Additionally, we acquired productive investments that fit well within our long-term strategy.
We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.
Intellectual Property
Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.
We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to and use of our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully asserted in the future or may be invalidated, circumvented or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their intellectual property rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.
Government Regulation
We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
Competition
We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into five categories:
-
large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), or those that have acquired, or may acquire, large network and endpoint security vendors and have the technical and financial resources to bring competitive solutions to the market;
-
independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), and Zscaler, Inc. (“Zscaler”), that offer a mix of network and endpoint security products;
-
startups and single-vertical vendors that offer independent or emerging solutions across various areas of security;
-
public cloud vendors and startups that offer solutions for cloud security (private, public and hybrid cloud); and
-
large and small companies, such as Crowdstrike, Inc. (“Crowdstrike”), that offer solutions for security operations and endpoint security.
- 9 -
As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
-
product features, reliability, performance, and effectiveness;
-
product line breadth, diversity, and applicability;
-
product extensibility and ability to integrate with other technology infrastructures;
-
price and total cost of ownership;
-
adherence to industry standards and certifications;
-
strength of sales and marketing efforts; and
-
brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our products with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
Sales, Marketing, Services and Support
Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of products for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise perimeter, the enterprise data center, and the distributed enterprise perimeter. Our end-customer deployments typically involve at least one pair of our products along with one or more of our subscriptions, depending on size, security needs and requirements, and network complexity. No single end-customer accounted for more than 10% of our total revenue in fiscal 2022, 2021, or 2020.
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2022, 53.6% of our total revenue was derived from sales to three distributors.
We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2022, we had more than 6,700 channel partners.
Global Customer Success. Our Global Customer Success (“GCS”) organization is responsible for delivering professional, educational and support services directly to our channel partners and to end-customers. We leverage the capabilities of our channel partners and train them in the delivery of professional, educational and support services to enable these services to be locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.
- 10 -
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research such as the Unit 42 Cloud Threat Report and the Unit 42 IoT Threat Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront upon fulfillment and are included in deferred revenue. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. We expect backlog related to subscription and support offerings will change from period to period for various reasons, including the timing and duration of customer orders and varying billing cycles of those orders. Products are billed upon shipment. The majority of our product revenue comes from orders that are received and shipped in the same quarter. However, insufficient supply and inventory may delay our hardware product shipments. As such, we do not believe that our product backlog at any particular time is necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.
Manufacturing
We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.
Human Capital
We believe our ongoing success depends on our employees. Development and investment in our people is central to who we are, and will continue to be so. With a global workforce of 12,561 as of July 31, 2022, we take our People Strategy and FLEXWORK philosophy seriously and care for our employees. This is a critical element of our overall company strategy. Our People Strategy is a comprehensive approach to source, hire, onboard, integrate, develop, engage and reward employees.
FLEXWORK. Throughout the COVID-19 pandemic, while prioritizing the health and safety of our employees, we have learned how to collaborate in a distributed hybrid work reality and to create opportunities for employees to maintain a sense of belonging and focus on well-being. In the future, we aim to continue to disrupt the nature of work. Our philosophy is simple: place our employees at the center of their working life by providing employees flexibility, personalization, and choice regarding how they work, the benefits they choose, the way they consume learning and, where possible, where and when they work. We believe that the more our employees have choice and demonstrate mutual trust and respect, the more engaged they will be.
FLEXWORK adds even more opportunity to scale our efforts to improve Inclusion and Diversity (“I&D”). It further enables us to recognize each individual as unique, with their own priorities and needs, and gives the employee greater agency to personalize their decisions and utilize our programs and initiatives to meet those interests and desires.
Source & Hire. Sourcing and hiring diverse talent and enabling them to create and execute is central to our comprehensive approach to talent acquisition, which we refer to as “The Way We Hire.” Our talent acquisition team utilizes a number of methods to find subject experts in their respective fields, including the use of a variety of channels that focus on reaching underrepresented talents. Our university relations team partners with hundreds of academic institutions, including colleges and universities that focus on serving diverse populations, to provide career pathways for early-in-career candidates. We also encourage current employees to provide qualified referrals, and to utilize our internal mobility program to grow their careers. We equip hiring managers with training so that they are made aware of potential unconscious biases and interview for the values and competencies that we believe enhance our culture. We have diverse interview panels to deliver a quality interview experience to a diverse slate of candidates.
- 11 -
Onboard & Integrate. We believe that a positive onboarding experience is foundational to our employees thriving and therefore to rapid productivity. During the COVID-19 pandemic, we built and utilized virtual learning platforms and employee communication channels to provide new employees with inspirational, often personalized, onboarding experiences. Onboarding is a journey of integration that extends through the first year at Palo Alto Networks for every employee. In addition, we have built specialist learning tracks for interns and new graduates that have been recognized as best in class externally. As part of our merger and acquisition strategy, we have also established a robust integration program with the goal to enable individuals joining our teams to feel part of our culture at speed.
Develop & Motivate. FLEXLearn is our unique approach to personalized employee development. FLEXLearn is a learning experience platform that provides employees with a path based on their needs, interests, style, and career journey. Through FLEXLearn, employees have full agency to direct their growth at their pace and choosing. Development information about core business elements, professional skill sets, working in a distributed hybrid environment, as well as required company-wide compliance training, such as Code of Conduct, privacy and security, anti-discrimination, anti-harassment, and anti-bribery training, is also deployed through the FLEXLearn platform for all employees. In addition, FLEXLearn provides employees with events and activities that motivate and spark critical thinking, on topics ranging from inclusion, to well-being and collaboration. On average, employees had completed 16 hours of development through the FLEXLearn platform during fiscal 2022.
Engage & Reward. We conduct regular executive listening sessions and “pulse surveys” to better understand employee engagement, sentiment, well-being, and the ability to transition to a distributed work model. Many of these sessions have informed our holistic People Strategy, our FLEXWORK philosophy, I&D strategies, and Internal Mobility program.
Employee sentiment has continued to be highly positive. We continue to use insights from an anonymous global employee engagement survey we conducted in 2021 to execute action plans that reinforce our culture of engagement. Our internal pulse surveys and other feedback mechanisms, including insights from external employee sentiment sources and employer brand recognition, indicate that employees have a strong sense of belonging, confidence in leadership, and an understanding of how their work contributes to the Company’s goals.
In addition to a comprehensive compensation and diverse benefits program, we believe in an always-on feedback and rewards philosophy. From recurring 1:1 sessions and quarterly performance feedback to use of our Cheers for Peers peer recognition program, employees get continuous input about the value they bring to the organization.
Inclusion & Diversity. We are intentional about including diverse points of view, perspectives, experiences, backgrounds and ideas in our decision-making processes. We deeply believe that true diversity exists when we have representation of all ethnicities, genders, orientations and identities, and cultures in our workforce. Our I&D programs continue to advance those visions. The diversity of our board of directors, with women representing 33% of our board as of July 31, 2022, is an example of that vision in action. We have nine employee network groups (“ENG”s) which are employee-led groups that play a vital role in building understanding and awareness. Over 26% of our global workforce was involved in at least one ENG as of July 31, 2022. Our ENGs are provided with a budget to fund activities for their communities and to make charitable grants to organizations advancing their causes. We involve our ENGs in listening sessions with executive teams and we work in partnership to develop our annual I&D plans, because we believe involvement is critical. Our I&D philosophy is fully embedded in our talent acquisition, learning and development and rewards and recognition programs.
Environmental, Social & Governance
We recognize our duty to address environmental, social and governance (“ESG”) practices. From our Climate Commitment and our social impact programs to our Supplier Responsibility initiatives and Code of Business Conduct and Ethics, we value the opportunity to have meaningful outcomes that reinforce our intention to respect our planet, uplift our communities and advance our industry.
Environmental. We recognize climate change is a global crisis and are committed to doing our part to reduce environmental impacts. Aligned to the Climate Commitments we declared in February 2021, we remain committed to utilizing 100% renewable energy, reducing our greenhouse gas (“GHG”) emissions and working across our value chain, and with coalitions, to achieve these goals by 2030. During fiscal 2022, we conducted a comprehensive analysis of our global environmental footprint and developed Science Based Targets aligned to a warming scenario of 1.5° Celsius. We joined The Climate Pledge during fiscal 2022 demonstrating our eagerness to engage in coalitions to advocate for climate action. We are committed to being transparent about our progress over time through annual reporting.
- 12 -
Social. In addition to our FLEXWORK People Strategy described in the section titled “Human Capital” above, we prioritized the health and safety of our employees during the COVID-19 pandemic. Through the deployment of our Global Supplier Code of Conduct, we continued to reach across our supply chain to communicate our expectations regarding labor standards, business practices and workplace health and safety conditions. During fiscal 2022, we maintained our affiliate membership in the Responsible Business Alliance and maintained our commitment to Supplier Diversity. We value our role as a good corporate citizen and in fiscal 2022 continued to execute our social impact programs. In addition to ongoing efforts to help colleagues and communities impacted by the COVID-19 pandemic , we invested in education programs, scholarships, diversity and basic needs. We expanded our work to provide cybersecurity curriculum to schools, universities and nonprofit organizations to help youth protect their digital way of life and to prepare diverse adults for careers in cybersecurity. Employees continued to participate in our giving, matching and volunteer programs to make impacts in their local communities.
Governance. Integrity is one of our core values. Our corporate behavior and leadership practices model ethical decision making. Employees and suppliers are informed about our governance expectations through our Codes of Conduct, compliance training programs and ongoing communications. Our board of directors is governed by Corporate Governance Guidelines, which are amended from time to time to incorporate best practices in corporate governance. Reinforcing the importance of our ESG performance, the charter of the ESG and Nominating Committee of the board of directors includes the primary oversight of ESG.
Available Information
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.
- 13 -
Previous: Cover and table of contents · Next: Item 1A. RISK FACTORS