Palo Alto Networks 10-K 2023-07-31

Filed 2023-09-01. 23 sections, 502K characters. Original on sec.gov · Markdown · JSON

What changed since the 2022-07-31 10-KNew, removed and reworded risk factor headings, then every item sentence by sentence.

Cover and table of contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549


FORM 10-K


(Mark One)

☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the fiscal year ended July 31, 2023

or

☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from to

Commission File Number 001-35594

Palo Alto Networks, Inc.

(Exact name of registrant as specified in its charter)

Delaware20-2530195
(State or other jurisdiction of incorporation or organization)(I.R.S. Employer Identification No.)

3000 Tannery Way

Santa Clara, California 95054

(Address of principal executive offices, including zip code)

(408) 753-4000

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each classTrading Symbol(s)Name of each exchange on which registered
Common stock, $0.0001 par value per sharePANWThe Nasdaq Stock Market LLC (Nasdaq Global Select Market)

Securities registered pursuant to Section 12(g) of the Act:

None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer☒Accelerated filer☐
Non-accelerated filer☐Smaller reporting company☐
Emerging growth company☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒

The aggregate market value of voting stock held by non-affiliates of the registrant was $47,351,509,692 as of January 31, 2023, the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date). Shares of common stock held by each executive officer and director have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.

On August 18, 2023, 308,594,604 shares of the registrant’s common stock, $0.0001 par value, were outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s 2023 annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, 2023.

Table Of Contents

Page
PART I
Item 1.Business4
Item 1A.Risk Factors14
Item 1B.Unresolved Staff Comments35
Item 2.Properties35
Item 3.Legal Proceedings35
Item 4.Mine Safety Disclosures35
PART II
Item 5.Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities36
Item 6.[Reserved]37
Item 7.Management’s Discussion and Analysis of Financial Condition and Results of Operations38
Item 7A.Quantitative and Qualitative Disclosures About Market Risk51
Item 8.Financial Statements and Supplementary Data52
Item 9.Changes in and Disagreements with Accountants on Accounting and Financial Disclosure92
Item 9A.Controls and Procedures92
Item 9B.Other Information93
Item 9C.Disclosure Regarding Foreign Jurisdictions That Prevent Inspections93
PART III
Item 10.Directors, Executive Officers and Corporate Governance94
Item 11.Executive Compensation94
Item 12.Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters94
Item 13.Certain Relationships and Related Transactions, and Director Independence94
Item 14.Principal Accountant Fees and Services94
PART IV
Item 15.Exhibits and Financial Statement Schedules95
Item 16.Form 10-K Summary99
Signatures100

- 2 -

Part I

SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS

This Annual Report on Form 10-K, including the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. The words “believe,” “may,” “will,” “potentially,” “estimate,” “continue,” “anticipate,” “intend,” “could,” “would,” “project,” “plan,” “expect,” and similar expressions that convey uncertainty of future events or outcomes are intended to identify forward-looking statements.

These forward-looking statements include, but are not limited to, statements concerning the following:

  • expectations regarding drivers of and factors affecting growth in our business;

  • statements regarding trends in billings, our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;

  • expected recurring revenues resulting from growth in our end-customers and increased adoption of our products and cloud-delivered security solutions;

  • our expectations regarding future investments in research and development and product development, customer support, in our employees and in our sales force, including expectations regarding growth in our sales headcount;

  • our expectation that we will continue to expand our global presence;

  • expectations regarding our revenues, including the seasonality and cyclicality from quarter to quarter;

  • our expectation that we will expand our facilities or add new facilities as we add employees and enter new geographic markets;

  • our expectation that we will increase our customer financing activities;

  • the sufficiency of our cash flow from operations with existing cash, cash equivalents, and investments to meet our cash needs for the foreseeable future;

  • our ability to successfully acquire and integrate companies and assets and our expectations and intentions with respect to the products and technologies that we acquire and introduce;

  • the timing and amount of capital expenditures and share repurchases; and

  • other statements regarding our future operations, financial condition and prospects, and business strategies.

These forward-looking statements are subject to a number of risks, uncertainties, and assumptions, including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur, and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements. We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.

- 3 -

Item 1. Business

General

Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.

We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by industry-leading artificial intelligence and automation. We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications, and infrastructure with zero trust principles. Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products. Our company focuses on delivering value in four fundamental areas:

Network Security:

  • Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, as well as a cloud-delivered Secure Access Service Edge (“SASE”). Prisma® Access, our Security Services Edge (“SSE”) solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and enable the cloud-delivered branch. We have been recognized as a leader in network firewalls, SSE, and SD-WAN. Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, DNS Security, IoT/OT Security, GlobalProtect®, Enterprise Data Loss Prevention (“Enterprise DLP”), Artificial Intelligence for Operations (“AIOps”), SaaS Security API, and SaaS Security Inline. Through these add-on security services, our customers are able to secure their content, applications, users, and devices across their entire organization. Panorama®, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.

Cloud Security:

  • We enable cloud-native security through our Prisma Cloud platform. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, and the entire cloud native technology stack across the full development lifecycle; from code to runtime. For inline network security on multi- and hybrid-cloud environments, we also offer our VM-Series and CN-Series Firewall offerings.

Security Operations:

  • We deliver the next generation of security automation, security analytics, endpoint security, and attack surface management solutions through our Cortex portfolio. These include Cortex XSIAM, our AI security automation platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity attacks on the endpoint, Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), and Cortex XpanseTM for attack surface management (“ASM”). These products are delivered as SaaS or software subscriptions.

Threat Intelligence and Security Consulting (Unit 42):

  • Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers proactively manage cyber risk. Our consultants serve as trusted advisors to our customers by assessing and testing their security controls against the right threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.

- 4 -

Product, Subscription, and Support

Our customer offerings are available in the form of the product, subscription, and support offerings described below:

PRODUCTS

Hardware and software firewalls. Our ML-Powered Next Generation Firewalls embed machine learning in the core of the firewall and employ inline deep learning in the cloud, empowering our customers to stop zero-day threats in real time, see and secure their entire enterprise including IoT, and reduce errors with automatic policy recommendations. All of our hardware and software firewalls incorporate our PAN-OS® operating system and come with the same rich set of features, ensuring consistent operation across our entire product line. The content, applications, users, and devices—the elements that run a business—become integral components of an enterprise’s security policy via our Content-ID™, App-ID™, User-ID™, and Device-ID technologies. In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and branch offices, to our top-of-the-line PA-7080, which is designed for large-scale data centers and service provider use. Our firewalls come in a hardware form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments. We also offer Cloud NGFW, a managed next-generation firewall (“NGFW”) offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).

SD-WAN. Our SD-WAN is integrated with PAN-OS so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality. The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services, and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.

Panorama. Panorama is our centralized security management solution for global control of our network security platform. Panorama can be deployed as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the network security systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses. Panorama offers network security monitoring through the ability to view logs and run reports for our network security platform in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.

SUBSCRIPTIONS

We offer a number of subscriptions as part of our network security platform. Of these subscription offerings, cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, DNS Security, IoT/OT Security, SaaS Security Inline, GlobalProtect, Enterprise DLP, and AIOps, are sold as options to our hardware and software firewalls, whereas SaaS Security API, Prisma Access, Prisma SD-WAN, Prisma Cloud, Cortex XSIAM, Cortex XDR, Cortex XSOAR, and Cortex Xpanse are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:

Cloud-delivered security services:

  • Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms—such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows—to manage popular open-source signature formats to extend our coverage. In addition, it offers inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the first offering to protect patient zero from unknown command and control in real-time.

- 5 -

  • Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. A machine learning module derived from the cloud sandbox environment is now delivered inline on the ML-Powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity. In addition, Advanced WildFire defeats highly evasive modern malware at scale with a new infrastructure and patented analysis techniques, including intelligent runtime memory analysis, dependency emulation, malware family fingerprinting, and more. Once identified, whether in the cloud or inline, preventive measures are automatically generated and delivered in seconds or less to our network security platform.

  • Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. It delivers real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing, malware, and C2. While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the industry’s first inline web protection engine capable of detecting never-before-seen web-based threats and preventing them in real-time. In addition, it includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.

  • DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed. It allows our network security platform access to DNS signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture. It offers comprehensive DNS attack coverage and includes industry-first protections against multiple emerging DNS-based network attacks.

  • IoT/OT Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission-critical OT devices, and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our network security platform. Other subscriptions have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.

  • SaaS Security API. SaaS Security API (formerly Prisma SaaS) is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated CASB.

  • SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and new sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. It provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time with best-in-class security. The solution is easy to deploy being natively integrated on network security platform, eliminating the architectural complexity of traditional CASB products, while offering low total cost of ownership. It can be combined with SaaS Security API as a complete integrated CASB.

  • GlobalProtect. This subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and, as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.

*•*Enterprise DLP. This cloud-delivered security service provides consistent, reliable protection of sensitive data, such as personally identifiable information (“PII”) and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including GDPR, CCPA, PCI DSS, HIPAA, and others.

- 6 -

  • AIOps: AIOps is available in both free and licensed premium versions. AIOps redefines network operational experience by empowering security teams to proactively strengthen security posture and resolve network disruptions. AIOps provides continuous best practice recommendations powered by machine learning (“ML”) based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture. It also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.

Secure Access Service Edge:

  • Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point-products into a single converged cloud-delivered offering, transforming network security and allowing organizations to enable secure hybrid workforces. Prisma Access protects all application traffic with complete, best-in-class security while ensuring an exceptional user experience with industry-leading service-level agreements (“SLA”s).

  • Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional Multiprotocol Label Switching (“MPLS”) based WAN architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver an exceptional user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using machine learning and automation.

Cloud Security:

  • Prisma Cloud. Prisma Cloud is a comprehensive Cloud-Native Application Protection Platform (“CNAPP”), securing both cloud-native and lift-and-shift applications across multi- and hybrid-cloud environments. With broad security and compliance coverage and a flexible agentless, as well as agent-based, architecture, Prisma Cloud protects cloud-native applications across their lifecycle from code to cloud. The platform helps developers prevent risks as they code and build the application, secures the software supply chain and the continuous integration and continuous development (“CI/CD”) pipeline, and provides complete visibility and real-time protection for applications in the cloud.

With its code-to-cloud security capabilities, Prisma Cloud uniquely stitches together a complete security picture by tracing back thousands of cloud risks and vulnerabilities that occur in the application runtime to their origin in the code-and-build phase of the application. The platform enables organizations to “shift security left” and fix issues at the source (in code) before they proliferate as a large number of risks in the cloud. The contextualized visibility to alerts, attack paths, and vulnerabilities delivered by Prisma Cloud facilitates collaboration between security and development teams to drive down risks and deliver better security outcomes. The context helps security teams block attacks in the cloud runtime and developers fix risks in source code.

A comprehensive library of compliance frameworks included in Prisma Cloud vastly simplifies the task of maintaining compliance. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities and security issues.

With a flexible, integrated platform that enables customers to license and activate cloud security capabilities that match their need, Prisma Cloud helps secure organizations at every stage in their cloud adoption journey. The platform enables security teams to consolidate multiple products that address individual risks with an integrated solution that also delivers best-in-class capabilities. Including the recently launched CI/CD security module, Prisma Cloud’s code-to-cloud CNAPP delivers comprehensive protection for applications and their code, infrastructure (workloads, network, and storage), data, APIs, and associated identities.

Security Operations:

*•*Cortex XSIAM. This cloud-based subscription is the AI security automation platform for the modern SOC, harnessing the power of AI to radically improve security outcomes and transform security operations. Cortex XSIAM customers can consolidate multiple products into a single unified platform, including EDR, XDR, SOAR, ASM, user behavior analytics (“UBA”), threat intelligence platform (“TIP”), and security information and event management (“SIEM”). Using a security-specific data model and applying AI, Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.

- 7 -

  • Cortex XDR. This cloud-based subscription enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics, including network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes.

  • Cortex XSOAR. Available as a cloud-based subscription or an on-premises appliance, Cortex XSOAR is a comprehensive security orchestration automation and response (“SOAR”) offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. It learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.

  • Cortex Xpanse. This cloud-based subscription provides attack surface management (“ASM”), which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.

SUPPORT

Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers (“CSM”) to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and certain cloud offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.

Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers focus on their business before, during, and after a breach.

Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.

- 8 -

RESEARCH AND DEVELOPMENT

Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security industry. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. Our scale and position in multiple areas of the security market enable us to leverage core competencies across hardware, software, and SaaS and also share expertise and research around threats, which allows us to respond to the rapidly changing threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.

We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2023, we introduced several new offerings, including: Cortex XSIAM 1.0, major updates to Prisma Cloud (including three new security modules), Prisma Access 4.0, PAN-OS 11.0, Cloud NGFW for AWS, and Cloud NGFW for Azure. Additionally, we acquired productive investments that fit well within our long-term strategy. For example, we acquired Cider Security Ltd. (“Cider”), which we expect will support our Prisma Cloud’s platform approach to securing the entire application security lifecycle from code to cloud.

We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.

INTELLECTUAL PROPERTY

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.

We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to, and use of, our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers, and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully asserted in the future or may be invalidated, circumvented, or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their intellectual property rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.

GOVERNMENT REGULATION

We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.

COMPETITION

We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:

  • large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), Microsoft, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;

  • independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), Crowdstrike, Inc. (“Crowdstrike”), and Zscaler, Inc. (“Zscaler”), that offer a mix of security products;

- 9 -

  • startups and point-product vendors that offer independent or emerging solutions across various areas of security; and

  • public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).

As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.

The principal competitive factors in our market include:

  • product features, reliability, performance, and effectiveness;

  • product line breadth, diversity, and applicability;

  • product extensibility and ability to integrate with other technology infrastructures;

  • price and total cost of ownership;

  • adherence to industry standards and certifications;

  • strength of sales and marketing efforts; and

  • brand awareness and reputation.

We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.

SALES, MARKETING, SERVICES, AND SUPPORT

Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise network, the enterprise data center, cloud locations, and branch or remote locations. No single end-customer accounted for more than 10% of our total revenue in fiscal 2023, 2022, or 2021.

Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2023, 49.7% of our total revenue was derived from sales to three distributors.

We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.

Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, including leveraging cloud service provider marketplaces. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.

Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.

Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2023, we had more than 7,100 channel partners.

Global Customer Success. Our Global Customer Success (“GCS”) organization is responsible for delivering professional, educational, and support services directly to our channel partners and end-customers. We leverage the capabilities of our channel partners and train them in the delivery of professional, educational, and support services to enable these services to be locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.

- 10 -

Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Cloud Threat Report and the Unit 42 Network Threat Trends Research Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.

Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront upon fulfillment and are included in deferred revenue. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. We expect backlog related to subscription and support offerings will change from period to period for various reasons, including the timing and duration of customer orders and varying billing cycles of those orders. Products are billed upon hardware shipment or delivery of software license. The majority of our product revenue comes from orders that are received and shipped in the same quarter. However, insufficient supply and inventory may delay our hardware product shipments. As such, we do not believe that our product backlog at any particular time is necessarily indicative of our future operating results.

Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.

MANUFACTURING

We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.

The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.

HUMAN CAPITAL

We believe our ongoing success depends on our employees. Development and investment in our people is central to who we are, and will continue to be so. With a global workforce of 13,948 as of July 31, 2023, our People Strategy is a critical element of our overall company strategy. Our People Strategy is a comprehensive approach to source, hire, onboard, develop, engage, and reward employees. Our approach is grounded on core tenants: respect each employee as an individual, demonstrate fairness and equity in all we do, facilitate flexibility, personalization, and choice whenever possible, and nurture a culture where employees are supported in doing the best work of their careers. Our values of disruption, execution, collaboration, inclusion, and integrity were co-created with employees and serve as the foundation of our culture.

Source & Hire. Sourcing diverse talent who possess the skills and capabilities to execute and add value to our culture form the cornerstone of our comprehensive approach to talent acquisition—a philosophy we call “The Way We Hire.” We utilize an array of methods to identify subject matter experts in their respective fields, emphasizing sourcing channels that connect us with underrepresented talents.

In an effort to foster career growth within Palo Alto Networks, we prioritize internal mobility. This allows current employees to progress either through a traditional career path or by exploring roles across various business functions, often culminating in promotions. We encourage existing employees to refer qualified individuals for our open positions, thus leveraging the collective networks of our team to attract a diverse range of expertise and perspectives.

We have made strides to understand job requirements and implement structured interviewing practices to identify candidates of the highest quality. By conducting thorough job analyses and creating success profiles, we have developed a deeper understanding of what is required for success in critical roles. We equip our hiring managers with essential training to identify and mitigate potential unconscious biases. Our interviewing process emphasizes values and competencies that we believe enhance our culture. This commitment extends to conducting interviews with diverse panelists and providing a balanced evaluation and quality interview experience for a diverse slate of candidates. We remain steadfast in our commitment to fairness, bias reduction, and equal opportunities for all potential hires.

- 11 -

A key to our hiring process is the Global Hiring Committees, introduced in fiscal 2023. These committees play a significant role in elevating our hiring standards by promoting shared understanding, reducing biases, enhancing objectivity, and ensuring the recruitment of diverse talent. The Committees foster effective collaboration using a common language and consensus-driven decision-making.

Onboard & Develop. We believe that each member of our workforce is unique, and that their integration into Palo Alto Networks and their career journey involve unique needs, interests, and goals. That is why our development programs are grounded on individualization, flexibility, and choice. From onboarding to ongoing development, our FLEXLearn philosophy offers multiple paths to assess, develop, and grow.

Our onboarding experience starts with “pre-boarding.” Before an employee’s start date, they are provided access to foundational tools to help them prepare to join Palo Alto Networks. We view pre-boarding as fundamental to introducing new employees to our culture, building trust, and facilitating rapid productivity. Welcome Day is a combination of in-person, virtual learning platforms and communication channels that provide new employees with inspirational, often personalized, onboarding experiences that carry on through the first year of employment. We have specialized learning tracks for interns and new graduates that have been recognized as best in class externally to support early-in-career individuals in acclimating to our culture as they progress on their career journey. As part of our merger and acquisition strategy, we have also established a robust integration program with the goal to enable individuals joining our teams to feel part of our culture at speed.

Following onboarding, there are a variety of ways that employees can assess their interests and skills, build a development plan specific to those insights, and continue to grow. Our development initiatives are delivered to employees through a comprehensive platform, FLEXLearn. The platform contains curated content and programs, such as assessment instruments, thousands of courses, workshops, and mentoring and coaching services. Leaders and executives also have access to specialized learning tracks that help them strategize, mobilize, and deliver maximum personal and team performance. Employees have full agency to direct their growth at their pace and choosing. Development information about core business elements, working in a distributed hybrid environment, as well as required company-wide compliance training, such as Code of Conduct, privacy and security, anti-discrimination, anti-harassment, and anti-bribery training, is also deployed through the FLEXLearn platform for all employees. In addition, FLEXLearn provides employees with events and activities that motivate and spark critical thinking, on topics ranging from inclusion to well-being and collaboration. On average, employees had completed 33 hours of development through the FLEXLearn platform during fiscal 2023.

Engage & Reward. We aim to foster engagement through a multifaceted approach to collect, understand, and act on employee feedback. Our comprehensive communication and listening strategy utilizes in-person and technology-enabled channels. We share and collect information through corporate and functional “All Hands” meetings, including several meetings specifically focused on employee-centered topics in an “Ask Me Anything” format. Digital Displays across our sites, our intranet platform, monthly and weekly email communications, and an active Slack platform provide a regular flow of information to and between employees and leadership. In addition to these channels that reach large audiences, we conduct regular executive listening sessions, including small group convenings with our CEO and other C-suite leaders, and ad-hoc pulse surveys to better understand employee engagement, sentiment, well-being, and the ability to transition to a hybrid work model.

Employee sentiment is also collected from external sources, such as web platforms that crowdsource feedback. Employees provide commentary to platforms such as Glassdoor, Comparably, and others and insights from those platforms are used to measure engagement. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as a “most loved workplace” (2021, 2022, and 2023). Palo Alto Networks has been recognized by Glassdoor, Comparably, Human Rights Campaign, Disability Index, and others as an employer of choice. Our CEO has also earned a 92% employee approval rating on Glassdoor, a top percentile score.

In addition to a comprehensive compensation and diverse benefits program, we believe in an always-on feedback and rewards philosophy. From recurring 1:1 sessions, quarterly performance feedback, semi-annual performance reviews to use of our Cheers for Peers peer recognition program, employees get continuous input about the value they bring to the organization.

These engagement and recognition strategies have informed our holistic People Strategy, including our Inclusion and Diversity (“I&D”) initiatives and Internal Mobility program. Based on the outcomes from external sources, insights from internal sources, our modest attrition rate (compared to market trends), and strong participation in our Internal Mobility program, we believe employees at Palo Alto Networks feel engaged and rewarded.

Inclusion & Diversity. We are intentional about including diverse points of view, perspectives, experiences, backgrounds, and ideas in our decision-making processes. We deeply believe that true diversity exists when we have representation of all ethnicities, genders, orientations and identities, and cultures in our workforce. Our corporate I&D programs focus on five principles—our workforce should feel psychologically safe, they should understand, listen, and support one another, and they should elevate others. These principles are the foundation of our approach to I&D, which we call P.U.L.S.E.

- 12 -

We have eleven employee network groups (“ENG”s) that play a vital role in building understanding and awareness. Over 29% of our global workforce was involved in at least one ENG as of July 31, 2023. ENGs are also allocated funding to make charitable grants to organizations advancing their causes. We involve our ENGs in listening sessions with executive teams and we work in partnership to develop our annual I&D plans because we believe involvement is critical.

Our I&D philosophy is fully embedded in our talent acquisition, learning and development, performance elevation, and rewards and recognition programs. The diversity of our board of directors, with women representing 40% of our board as of July 31, 2023, is an example of our commitment to inclusion and diversity.

ENVIRONMENTAL, SOCIAL, AND GOVERNANCE

We recognize our duty to address environmental, social, and governance (“ESG”) practices. From our science-based approach to emissions reductions and our social impact programs to our Supplier Responsibility initiatives and Code of Business Conduct and Ethics, we value the opportunity to have meaningful outcomes that reinforce our intention to respect our planet, uplift our communities, and advance our industry.

Environmental. We recognize climate change is a global crisis and are committed to doing our part to reduce environmental impacts. We remain committed to our goals of utilizing 100% renewable energy by 2030, reducing our greenhouse gas (“GHG”) emissions and working across our value chain, and with coalitions, to address climate change. We made progress towards our goals in fiscal 2023 through several milestones. We engaged with a local utility provider to power our Santa Clara, California headquarters with 100% renewable energy effective January 1, 2023. Our near-term scope 1, 2, and 3 emissions reduction goals, aligned to a warming scenario of 1.5° Celsius, were verified by the Science Based Targets initiative. We were recognized by Carbon Disclosure Project (“CDP”) as an “A-List” company and a “Supplier Engagement Leader.” We remain committed to being transparent about our progress over time through annual reporting.

Social. In addition to our People Strategy described in the section titled “Human Capital” above, we prioritized the health and safety of our global workforce. Through the deployment of our Global Supplier Code of Conduct, we continued to reach across our supply chain to communicate our expectations regarding labor standards, business practices, and workplace health and safety conditions. During fiscal 2023, we maintained our affiliate membership in the Responsible Business Alliance and maintained our commitment to Supplier Diversity. We value our role as a good corporate citizen and in fiscal 2023 continued to execute our social impact programs. We made charitable grants to support organizations providing services in our core funding areas of education, including academic scholarships, diversity, and basic needs. We expanded our work to provide cybersecurity curriculum to schools, universities, and nonprofit organizations to help individuals of all ages protect their digital way of life and to prepare diverse adults for careers in cybersecurity. Employees continued to participate in our giving, matching, and volunteer programs to make impacts in their local communities.

Governance. Integrity is one of our core values. Our corporate behavior and leadership practices model ethical decision-making. All employees are informed about our governance expectations through our Codes of Conduct, compliance training programs, and ongoing communications. Our board of directors is governed by Corporate Governance Guidelines, which are amended from time to time to incorporate best practices in corporate governance. Reinforcing the importance of our ESG performance, the charter of the ESG and Nominating Committee of the board of directors includes the primary oversight of ESG.

AVAILABLE INFORMATION

Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.

We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.

- 13 -

Item 1A. Risk Factors

Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected, and the market price of our common stock could decline. In addition, the impacts of any worsening of the economic environment may exacerbate the risks described below, any of which could have a material impact on us.

Risk Factor Summary

Our business is subject to numerous risks and uncertainties. These risks include, but are not limited to, the following:

  • Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.

  • Our business and operations have experienced growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected.

  • Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.

  • Our operating results may vary significantly from period to period, which makes our results difficult to predict and could cause our results to fall short of expectations, and such results may not be indicative of future performance.

  • Seasonality may cause fluctuations in our revenue.

  • If we are unable to sell new and additional product, subscription, and support offerings to our end-customers, especially to large enterprise customers, our future revenue and operating results will be harmed.

  • We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.

  • The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.

  • We rely on our channel partners to sell substantially all of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.

  • We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.

  • A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.

  • We face intense competition in our market and we may lack sufficient financial or other resources to maintain or improve our competitive position.

  • We may acquire other businesses, which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.

  • If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.

  • Issues in the development and deployment of Artificial Intelligence (“AI”) may result in reputational harm and legal liability and could adversely affect our results of operations.

  • A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.

  • Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.

  • Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.

  • Claims by others that we infringe their intellectual property rights could harm our business.

- 14 -

  • Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.

  • Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.

  • We license technology from third parties, and our inability to maintain those licenses could harm our business.

  • Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers.

  • Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.

  • Because some of the key components in our hardware products come from limited sources of supply, we are susceptible to supply shortages or supply changes, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.

  • If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.

  • We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations.

  • We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.

  • We face risks associated with having operations and employees located in Israel.

  • We are subject to governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.

  • Our actual or perceived failure to adequately protect personal data could have a material adverse effect on our business.

  • We may have exposure to greater than anticipated tax liabilities.

  • If our estimates or judgments relating to our critical accounting policies are based on assumptions that change or prove to be incorrect, our operating results could fall below our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock.

  • We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and,

Showing the first 8K of 119K characters. Open the full section

Item 1B. Unresolved Staff Comments

Not applicable.

Item 2. Properties

Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2028, with options to extend the lease terms through July 2046. We also lease space for personnel around the world, including Israel and India. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 11. Leases in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases. Additionally, we own 10.4 acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future expansion, the speed of which development has been slowed due to the current environment.

We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.

Item 3. Legal Proceedings

The information set forth under the “Litigation” subheading in Note 12. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.

Item 4. Mine Safety Disclosures

Not applicable.

- 35 -

Part II

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Market Information

Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.” Prior to October 22, 2021, our common stock traded on the New York Stock Exchange (“NYSE”) under the symbol “PANW.”

Holders of Record

As of August 18, 2023, there were 414 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.

Dividend Policy

We have never declared or paid, and do not anticipate declaring or paying in the foreseeable future, any cash dividends on our capital stock. Any future determination as to the declaration and payment of dividends, if any, will be at the discretion of our board of directors, subject to applicable laws, and will depend on then existing conditions, including our financial condition, operating results, contractual restrictions, capital requirements, business prospects, and other factors our board of directors may deem relevant.

Securities Authorized for Issuance under Equity Compensation Plans

See Part III, Item 12 “Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters” of this Annual Report on Form 10-K for more information regarding securities authorized for issuance.

Recent Sales of Unregistered Equity Securities

During the three months ended July 31, 2023, we issued a total of 3,569 shares of our unregistered common stock in connection with certain of our acquisitions (the “Transactions”).

The Transactions did not involve any underwriters, any underwriting discounts or commissions, or any public offering. The issuances of the securities pursuant to the Transactions were exempt from registration under the Securities Act of 1933, as amended (the “Act”) by virtue of Section 4(a)(2) of the Act and Rule 506 of Regulation D promulgated thereunder.

Purchases of Equity Securities by the Issuer and Affiliated Purchasers

In February 2019, we announced that our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital. In December 2020, August 2021, and August 2022, we announced additional $700.0 million, $676.1 million, and $915.0 million increases to this share repurchase program, respectively, bringing the total authorization to $3.3 billion, with $750.0 million remaining as of July 31, 2023. The expiration date of this repurchase authorization was extended to December 31, 2023, and our repurchase program may be suspended or discontinued at any time. Repurchases under our program are to be made at management’s discretion on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. During the three months ended July 31, 2023, we did not repurchase any shares pursuant to our share repurchase program.

- 36 -

Between June 1, 2023 and June 30, 2023 and July 1, 2023 and July 31, 2023, shares of restricted stock were delivered by certain employees upon vesting of equity awards to satisfy tax withholding requirements. The average value of shares delivered to satisfy tax withholding requirements during these periods were $246.53 per share and $243.33 per share, respectively. The number of shares delivered to satisfy tax withholding requirements during these periods was not significant.

Stock Price Performance Graph

This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.

This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index for the five years ended July 31, 2023. This performance graph assumes $100 was invested on July 31, 2018, in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.

Palo Alto Networks, Inc. Comparison of Total Return Performance

4855

Company/Index7/31/20187/31/20197/31/20207/31/20217/31/20227/31/2023
Palo Alto Networks, Inc.$100.00$114.26$129.08$201.28$251.74$378.23
Nasdaq 100 Index$100.00$109.74$154.04$212.86$185.61$227.88
S&P 500 Index$100.00$107.99$120.90$164.96$157.31$177.78
S&P 500 Information Technology Index$100.00$115.72$160.75$225.10$212.69$269.79

Item 6. [Reserved]

- 37 -

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations

The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.

Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:

  • Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A.

  • Key Financial Metrics. A summary of our U.S. GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance.

  • Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2023 to fiscal 2022. For discussion and analysis related to our financial results comparing fiscal 2022 to 2021, refer to Part II, Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2022, which was filed with the Securities and Exchange Commission on September 6, 2022.

  • Liquidity and Capital Resources. An analysis of changes on our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs.

  • Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments.

Overview

We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by industry-leading artificial intelligence and automation. We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications, and infrastructure with zero trust principles. Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products. Our company focuses on delivering value in four fundamental areas:

Network Security:

  • Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, as well as a cloud-delivered Secure Access Service Edge (“SASE”). Prisma® Access, our Security Services Edge (“SSE”) solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and enable the cloud-delivered branch. We have been recognized as a leader in network firewalls, SSE, and SD-WAN. Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, DNS Security, IoT/OT Security, GlobalProtect®, Enterprise Data Loss Prevention (“Enterprise DLP”), Artificial Intelligence for Operations (“AIOps”), SaaS Security API, and SaaS Security Inline. Through these add-on security services, our customers are able to secure their content, applications, users, and devices across their entire organization. Panorama®, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.

Cloud Security:

  • We enable cloud-native security through our Prisma Cloud platform. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, and the entire cloud native technology stack across the full development lifecycle; from code to runtime. For inline network security on multi- and hybrid-cloud environments, we also offer our VM-Series and CN-Series Firewall offerings.

- 38 -

Security Operations:

  • We deliver the next generation of security automation, security analytics, endpoint security, and attack surface management solutions through our Cortex portfolio. These include Cortex XSIAM, our AI security automation platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity attacks on the endpoint, Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), and Cortex XpanseTM for attack surface management (“ASM”). These products are delivered as SaaS or software subscriptions.

Threat Intelligence and Security Consulting (Unit 42):

  • Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers proactively manage cyber risk. Our consultants serve as trusted advisors to our customers by assessing and testing their security controls against the right threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.

For fiscal 2023 and 2022, total revenue was $6.9 billion and $5.5 billion, respectively, representing year-over-year growth of 25.3%. Our growth reflects the increased adoption of our portfolio, which consists of product, subscriptions, and support. We believe our portfolio will enable us to benefit from recurring revenues and new revenues as we continue to grow our end-customer base. As of July 31, 2023, we had end-customers in over 180 countries. Our end-customers represent a broad range of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications, and include almost all of the Fortune 100 companies and a majority of the Global 2000 companies. We maintain a field sales force that works closely with our channel partners in developing sales opportunities. We primarily use a two-tiered, indirect fulfillment model whereby we sell our products, subscriptions, and support to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers.

Our product revenue grew to $1.6 billion or 22.9% of total revenue for fiscal 2023, representing year-over-year growth of 15.8%. Product revenue is derived from sales of our appliances, primarily our ML-Powered Next-Generation Firewall. Product revenue also includes revenue derived from software licenses of Panorama, SD-WAN, and the VM-Series. Our ML-Powered Next-Generation Firewall incorporates our PAN-OS operating system, which provides a consistent set of capabilities across our entire network security product line. Our appliances and software licenses include a broad set of built-in networking and security features and functionalities. Our products are designed for different performance requirements throughout an organization, ranging from our PA-410, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7080, which is designed for large-scale data centers and service provider use. The same firewall functionality that is delivered in our physical appliances is also available in our VM-Series virtual firewalls, which secure virtualized and cloud-based computing environments, and in our CN-Serie

Showing the first 8K of 76K characters. Open the full section

Item 7A. Quantitative and Qualitative Disclosures About Market Risk

Foreign Currency Exchange Risk

Our sales contracts are denominated in U.S. dollars. A portion of our operating expenditures are incurred outside of the United States and are denominated in foreign currencies and are subject to fluctuations due to changes in foreign currency exchange rates. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. The effect of an immediate 10% adverse change in foreign exchange rates on monetary assets and liabilities at July 31, 2023 would not be material to our financial condition or results of operations. As of July 31, 2023, foreign currency transaction gains and losses and exchange rate fluctuations have not been material to our consolidated financial statements. We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our foreign currency denominated operating expenditures. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results. Refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.

As our international operations grow, our risks associated with fluctuations in foreign currency exchange rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products and services to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.” in Part 1, Item 1A of this Annual Report on Form 10-K.

Interest Rate Risk

The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Most of the securities we invest in are subject to interest rate risk. To minimize this risk, we maintain a diversified portfolio of cash, cash equivalents, and investments, consisting only of investment-grade securities. To assess the interest rate risk, we performed a sensitivity analysis to determine the impact a change in interest rates would have on the value of the investment portfolio. Based on investment positions as of July 31, 2023, a hypothetical 100 basis point increase in interest rates across all maturities would result in a $55.5 million decline in the fair market value of the portfolio. Such losses would only be realized if we sold the investments prior to maturity. Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a $55.5 million increase in the fair market value of the portfolio.

In June 2020, we issued $2.0 billion aggregate principal amount of 0.375% Convertible Senior Notes due 2025 (the “2025 Notes”). We carry these instruments at face value less unamortized issuance costs on our consolidated balance sheets. As these instruments have a fixed annual interest rate, we have no financial and economic exposure associated with changes in interest rates. However, the fair value of fixed rate debt instruments fluctuates when interest rates change, and additionally, in the case of the 2025 Notes, when the market price of our common stock fluctuates.

- 51 -

Item 8. Financial Statements and Supplementary Data

Index To Consolidated Financial Statements

Page
Reports of Independent Registered Public Accounting Firm (PCAOB ID: 42)53
Consolidated Balance Sheets56
Consolidated Statements of Operations57
Consolidated Statements of Comprehensive Income (Loss)58
Consolidated Statements of Stockholders’ Equity59
Consolidated Statements of Cash Flows60
Notes to Consolidated Financial Statements62

- 52 -

Report of Independent Registered Public Accounting Firm

To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.

Opinion on the Financial Statements

We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2023 and 2022, the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2023, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2023 and 2022, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2023, in conformity with U.S. generally accepted accounting principles.

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2023, based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) and our report dated September 1, 2023 expressed an unqualified opinion thereon.

Basis for Opinion

These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.

Critical Audit Matter

The critical audit matter communicated below is a matter arising from the current period audit of the financial statements that was communicated or required to be communicated to the audit committee and that: (1) relates to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective, or complex judgments. The communication of the critical audit matter does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matter below, providing a separate opinion on the critical audit matter or on the accounts or disclosures to which it relates.

- 53 -

REVENUE RECOGNITION

Description of the MatterAs described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition.
How We Addressed the Matter in Our AuditWe obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and purchase order to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition.

/s/ Ernst & Young LLP

We have served as the Company’s auditor since 2009.

San Jose, California September 1, 2023

- 54 -

Report of Independent Registered Public Accounting Firm

To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.

Opinion on Internal Control Over Financial Reporting

We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, 2023, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria). In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, 2023, based on the COSO criteria.

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, 2023 and 2022, the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period

Showing the first 8K of 177K characters. Open the full section

Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure

Not applicable.

Item 9A. Controls and Procedures

Evaluation of Disclosure Controls and Procedures

Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15 under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.

Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2023, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.

Management’s Annual Report on Internal Control over Financial Reporting

Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rules 13a-15(f) under the Exchange Act. Our management assessed the effectiveness of our internal control over financial reporting as of July 31, 2023, based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework). Based on that assessment, management concluded that, as of July 31, 2023, our internal control over financial reporting was effective.

The effectiveness of our internal control over financial reporting as of July 31, 2023 has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their report which is included in Part II, Item 8 of this Annual Report on Form 10-K.

Changes in Internal Control over Financial Reporting

There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the quarter ended July 31, 2023 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

- 92 -

Item 9B. Other Information

Trading Plans of Directors and Executive Officers

Set forth below is certain information regarding Rule 10b5-1 trading plans adopted by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal 2023. The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).

NameTitleDate Plan Was AdoptedExpiration DateTotal Amount of Common Stock to be Sold Under the Plan
Nikesh AroraChairman and Chief Executive OfficerJune 8, 2023August 30, 2024 or when all shares have been sold2,000,000
William “BJ” Jenkins, Jr.PresidentMay 26, 2023June 29, 2024 or when all shares have been sold13,000

No other officers or directors, as defined in Rule 16a-1(f), adopted, modified and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal 2023.

Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections

Not applicable.

- 93 -

Part III

Item 10. Directors, Executive Officers and Corporate Governance

The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our 2023 annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, 2023 and is incorporated herein by reference.

Item 11. Executive Compensation

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 13. Certain Relationships and Related Transactions, and Director Independence

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 14. Principal Accountant Fees and Services

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

- 94 -

Part IV

Item 15. Exhibits and Financial Statement Schedules

Documents filed as part of this Annual Report on Form 10-K are as follows:

**1.**Consolidated Financial Statements

Our Consolidated Financial Statements are listed in the “Index to Consolidated Financial Statements” under Part II, Item 8 of this Annual Report on Form 10-K.

**2.**Financial Statement Schedules

Financial statement schedules have been omitted because they are not required, not applicable, not present in amounts sufficient to require submission of the schedule, or the required information is shown in the Consolidated Financial Statements or the notes thereto.

**3.**Exhibits

The following documents are incorporated by reference or are filed with this Annual Report on Form 10-K, in each case as indicated therein (numbered in accordance with Item 601 of Regulation S-K).

Exhibit Index

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
3.1Restated Certificate of Incorporation of the Registrant.10-K001-355943.1October 4, 2012
3.2Amended and Restated Bylaws of the Registrant.8-K001-355943.1May 23, 2022
3.3Certificate of Change of Location of Registered Agent and/or Registered Office.8-K001-355943.1August 30, 2016
4.1Indenture between the Registrant and U.S. Bank National Association, dated as of June 8, 2020.8-K001-355944.1June 8, 2020
4.2Form of Global 0.375% Convertible Senior Note due 2025 (included in Exhibit 4.1).8-K001-355944.2June 8, 2020
4.3Description of Registrant’s Securities.
10.1*Form of Indemnification Agreement between the Registrant and its directors and officers.S-1/A333-18062010.1July 9, 2012
10.2*2012 Equity Incentive Plan and related form agreements.10-Q001-3559410.2November 26, 2019
10.3*Form of 2012 Equity Incentive Plan Performance-Based Restricted Stock Unit Award Agreement.10-Q001-3559410.4November 19, 2021
10.4*2021 Equity Incentive Plan.S-8333-26893099.1December 21, 2022
10.5*Form of 2021 Equity Incentive Plan Global Stock Option Award Agreement.S-8333-26169799.2December 16, 2021
10.6*Form of 2021 Equity Incentive Plan Global Restricted Stock Unit Award Agreement.S-8333-26169799.3December 16, 2021
10.7*2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements.10-K001-3559410.7September 6, 2022
10.8*RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended.S-8333-22790199.1October 19, 2018

- 95 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.9*Aporeto, Inc. Amended and Restated 2015 Stock Option and Grant Plan.S-8333-23585499.1January 8, 2020
10.10*CloudGenix Inc. 2013 Equity Incentive Plan.S-8333-23801499.1May 5, 2020
10.11*Crypsis Group Holdings, LLC 2017 Equity Incentive Plan.S-8333-24938799.1October 8, 2020
10.12*Sinefa Group, Inc. 2020 Stock Plan.S-8333-25142399.1December 17, 2020
10.13*Expanse Holding Company, Inc. Amended and Restated 2012 Stock Incentive PlanS-8333-25142599.1December 17, 2020
10.14*Gamma Networks, Inc. 2018 Stock Option and Grant Plan.S-8333-25932799.1September 3, 2021
10.15*Bridgecrew, Inc. 2019 Stock Incentive Plan.S-8333-25404299.1March 9, 2021
10.16*Cider Security Ltd. 2020 Equity Incentive Plan.S-8333-26893199.1December 21, 2022
10.17*US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan.S-8333-26893199.2December 21, 2022
10.18*Employee Incentive Compensation Plan, as amended and restated.10-Q001-3559410.2November 25, 2014
10.19*Clawback Policy, adopted as of August 29, 2017.10-Q001-3559410.3November 21, 2017
10.20*Amended and Restated Outside Director Compensation Policy (last amended February 16, 2022).10-Q001-3559410.4February 23, 2022
10.21*Continued Service Policy.10-Q001-3559410.3May 20, 2022
10.22*Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 202210-K001-3559410.23September 6, 2022
10.23*Employment Agreement between Palo Alto Networks (Israel Analytics) Ltd. and Nir Zuk, dated August 18, 2020.10-Q001-3559410.1November 19, 2020
10.24*Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018.8-K001-3559410.2June 4, 2018
10.25*Offer Letter between the Registrant and Josh Paul, dated August 5, 2021.8-K001-3559410.1September 8, 2021
10.26*Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011.10-Q001-3559410.4November 30, 2018
10.27*Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021.8-K001-3559410.1March 19, 2021
10.28*Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022.10-Q001-3559410.1May 20, 2022
10.29*Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021.8-K001-3559410.1August 12, 2021

- 96 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.30*Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022.10-Q001-3559410.2May 20, 2022
10.31*Form of Offer Letter between the Registrant and its directors.10-K001-3559410.27September 3, 2021
10.32**Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019.10-Q001-3559410.1May 30, 2019
10.33Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021.10-K001-3559410.29September 3, 2021
10.34Form of Convertible Note Hedge Confirmation.8-K001-3559410.2June 8, 2020
10.35Form of Warrant Confirmation.8-K001-3559410.3June 8, 2020
10.36Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.29September 17, 2015
10.37Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.30September 17, 2015
10.38Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.31September 17, 2015
10.39Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015.8-K/A001-3559410.1October 19, 2015
10.40Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015.10-Q001-3559410.2November 24, 2015
10.41Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015.10-Q001-3559410.3November 24, 2015
10.42Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.1November 22, 2016
10.43Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.2November 22, 2016
10.44Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.3November 22, 2016
10.45Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.1March 1, 2017
10.46Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.2March 1, 2017
10.47Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.3March 1, 2017

- 97 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.48Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017.10-K001-3559410.40September 7, 2017
10.49Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017.10-K001-3559410.41September 7, 2017
10.50Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017.10-K001-3559410.42September 7, 2017
10.51Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017.10-Q001-3559410.5November 21, 2017
10.52Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III G LLC, dated September 29, 2017.10-Q001-3559410.6November 21, 2017
10.53Amendment No. 5 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017.10-Q001-3559410.7November 21, 2017
10.54Credit Agreement, dated as of April 13, 2023 among the Registrant, the lenders party thereto and Wells Fargo, National Association, as administrative agent.8-K001-3559410.1April 19, 2023
21.1List of subsidiaries of the Registrant.
23.1Consent of Independent Registered Public Accounting Firm.
24.1Power of Attorney (contained in the signature page to this Annual Report on Form 10-K).
31.1Certification of the Chief Executive Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002.
31.2Certification of the Chief Financial Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002.
32.1†Certification of Chief Executive Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
32.2†Certification of Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
101.INSXBRL Instance Document.
101.SCHXBRL Taxonomy Schema Linkbase Document.
101.CALXBRL Taxonomy Calculation Linkbase Document.
101.DEFXBRL Taxonomy Definition Linkbase Document.
101.LABXBRL Taxonomy Labels Linkbase Document.
101.PREXBRL Taxonomy Presentation Linkbase Document.

- 98 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
104Cover Page Interactive Data File (formatted as inline XBRL and contained in Exhibit 101)
  • Indicates a management contract or compensatory plan or arrangement.

** Certain portions of this exhibit have been omitted as the Registrant has determined (i) the omitted information is not material and (ii) the omitted information would likely cause harm to the Registrant if publicly disclosed.

† The certifications attached as Exhibit 32.1 and Exhibit 32.2 that accompany this Annual Report on Form 10-K, are not deemed filed with the Securities and Exchange Commission and are not to be incorporated by reference into any filing of the Registrant under the Securities Act of 1933, as amended, or the Securities Exchange Act of 1934, as amended, whether made before or after the date of this Annual Report on Form 10-K, irrespective of any general incorporation language contained in such filing.

Item 16. Form 10-K Summary

Not applicable.

- 99 -

Signatures

Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on September 1, 2023.

PALO ALTO NETWORKS, INC.
By:/s/ NIKESH ARORA
Nikesh Arora
Chairman and Chief Executive Officer

- 100 -

Power of Attorney

KNOW ALL THESE PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Nikesh Arora, Dipak Golechha, and Josh Paul, and each of them, as his or her true and lawful attorney-in-fact and agent, with full power of substitution and resubstitution, for him or her and in his or her name, place and stead, in any and all capacities, to sign any and all amendments to this Annual Report on Form 10-K, and to file the same, with all exhibits thereto, and other documents in connection therewith, with the Securities and Exchange Commission, granting unto said attorneys-in-fact and agents, and each of them, full power and authority to do and perform each and every act and thing requisite and necessary to be done in connection therewith, as fully to all intents and purposes as he or she might or could do in person, hereby ratifying and confirming all that said attorneys-in-fact and agents, or any of them, or their, his or her substitutes, may lawfully do or cause to be done by virtue thereof.

Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrant and in the capacities and on the dates indicated:

SignatureTitleDate
/s/ NIKESH ARORAChairman, Chief Executive Officer and Director (Principal Executive Officer)September 1, 2023
Nikesh Arora
/s/ DIPAK GOLECHHAChief Financial Officer (Duly Authorized Officer and Principal Financial Officer)September 1, 2023
Dipak Golechha
/s/ JOSH PAULChief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer)September 1, 2023
Josh Paul
/s/ NIR ZUKChief Technology Officer and DirectorSeptember 1, 2023
Nir Zuk
/s/ APARNA BAWADirectorSeptember 1, 2023
Aparna Bawa
/s/ JOHN M. DONOVANDirectorSeptember 1, 2023
John M. Donovan
/s/ CARL ESCHENBACHDirectorSeptember 1, 2023
Carl Eschenbach
/s/ DR. HELENE D. GAYLEDirectorSeptember 1, 2023
Dr. Helene D. Gayle
/s/ JAMES J. GOETZDirectorSeptember 1, 2023
James J. Goetz
/s/ RT HON SIR JOHN KEYDirectorSeptember 1, 2023
Rt Hon Sir John Key
/s/ MARY PAT MCCARTHYDirectorSeptember 1, 2023
Mary Pat McCarthy
/s/ LORRAINE TWOHILLDirectorSeptember 1, 2023
Lorraine Twohill

- 101 -