Item 1. Business

56K characters. Original on sec.gov · Markdown

Item 1. Business

General

Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.

We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by industry-leading artificial intelligence and automation. We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications, and infrastructure with zero trust principles. Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products. Our company focuses on delivering value in four fundamental areas:

Network Security:

  • Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, as well as a cloud-delivered Secure Access Service Edge (“SASE”). Prisma® Access, our Security Services Edge (“SSE”) solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and enable the cloud-delivered branch. We have been recognized as a leader in network firewalls, SSE, and SD-WAN. Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, DNS Security, IoT/OT Security, GlobalProtect®, Enterprise Data Loss Prevention (“Enterprise DLP”), Artificial Intelligence for Operations (“AIOps”), SaaS Security API, and SaaS Security Inline. Through these add-on security services, our customers are able to secure their content, applications, users, and devices across their entire organization. Panorama®, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.

Cloud Security:

  • We enable cloud-native security through our Prisma Cloud platform. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, and the entire cloud native technology stack across the full development lifecycle; from code to runtime. For inline network security on multi- and hybrid-cloud environments, we also offer our VM-Series and CN-Series Firewall offerings.

Security Operations:

  • We deliver the next generation of security automation, security analytics, endpoint security, and attack surface management solutions through our Cortex portfolio. These include Cortex XSIAM, our AI security automation platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity attacks on the endpoint, Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), and Cortex XpanseTM for attack surface management (“ASM”). These products are delivered as SaaS or software subscriptions.

Threat Intelligence and Security Consulting (Unit 42):

  • Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers proactively manage cyber risk. Our consultants serve as trusted advisors to our customers by assessing and testing their security controls against the right threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.

- 4 -

Product, Subscription, and Support

Our customer offerings are available in the form of the product, subscription, and support offerings described below:

PRODUCTS

Hardware and software firewalls. Our ML-Powered Next Generation Firewalls embed machine learning in the core of the firewall and employ inline deep learning in the cloud, empowering our customers to stop zero-day threats in real time, see and secure their entire enterprise including IoT, and reduce errors with automatic policy recommendations. All of our hardware and software firewalls incorporate our PAN-OS® operating system and come with the same rich set of features, ensuring consistent operation across our entire product line. The content, applications, users, and devices—the elements that run a business—become integral components of an enterprise’s security policy via our Content-ID™, App-ID™, User-ID™, and Device-ID technologies. In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service (“QoS”). Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and branch offices, to our top-of-the-line PA-7080, which is designed for large-scale data centers and service provider use. Our firewalls come in a hardware form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as VMware, Inc. (“VMware”), Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Google, Inc. (“Google”), and in Kernel-based Virtual Machine (“KVM”)/OpenStack environments. We also offer Cloud NGFW, a managed next-generation firewall (“NGFW”) offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).

SD-WAN. Our SD-WAN is integrated with PAN-OS so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality. The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services, and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.

Panorama. Panorama is our centralized security management solution for global control of our network security platform. Panorama can be deployed as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the network security systems under management. Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses. Panorama offers network security monitoring through the ability to view logs and run reports for our network security platform in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.

SUBSCRIPTIONS

We offer a number of subscriptions as part of our network security platform. Of these subscription offerings, cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, DNS Security, IoT/OT Security, SaaS Security Inline, GlobalProtect, Enterprise DLP, and AIOps, are sold as options to our hardware and software firewalls, whereas SaaS Security API, Prisma Access, Prisma SD-WAN, Prisma Cloud, Cortex XSIAM, Cortex XDR, Cortex XSOAR, and Cortex Xpanse are sold on a per-user, per-endpoint, or capacity-based basis. Our subscription offerings include:

Cloud-delivered security services:

  • Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms—such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows—to manage popular open-source signature formats to extend our coverage. In addition, it offers inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the first offering to protect patient zero from unknown command and control in real-time.

- 5 -

  • Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. A machine learning module derived from the cloud sandbox environment is now delivered inline on the ML-Powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity. In addition, Advanced WildFire defeats highly evasive modern malware at scale with a new infrastructure and patented analysis techniques, including intelligent runtime memory analysis, dependency emulation, malware family fingerprinting, and more. Once identified, whether in the cloud or inline, preventive measures are automatically generated and delivered in seconds or less to our network security platform.

  • Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. It delivers real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing, malware, and C2. While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the industry’s first inline web protection engine capable of detecting never-before-seen web-based threats and preventing them in real-time. In addition, it includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.

  • DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed. It allows our network security platform access to DNS signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture. It offers comprehensive DNS attack coverage and includes industry-first protections against multiple emerging DNS-based network attacks.

  • IoT/OT Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission-critical OT devices, and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our network security platform. Other subscriptions have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.

  • SaaS Security API. SaaS Security API (formerly Prisma SaaS) is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated CASB.

  • SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and new sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. It provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time with best-in-class security. The solution is easy to deploy being natively integrated on network security platform, eliminating the architectural complexity of traditional CASB products, while offering low total cost of ownership. It can be combined with SaaS Security API as a complete integrated CASB.

  • GlobalProtect. This subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and, as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.

*•*Enterprise DLP. This cloud-delivered security service provides consistent, reliable protection of sensitive data, such as personally identifiable information (“PII”) and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including GDPR, CCPA, PCI DSS, HIPAA, and others.

- 6 -

  • AIOps: AIOps is available in both free and licensed premium versions. AIOps redefines network operational experience by empowering security teams to proactively strengthen security posture and resolve network disruptions. AIOps provides continuous best practice recommendations powered by machine learning (“ML”) based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture. It also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.

Secure Access Service Edge:

  • Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point-products into a single converged cloud-delivered offering, transforming network security and allowing organizations to enable secure hybrid workforces. Prisma Access protects all application traffic with complete, best-in-class security while ensuring an exceptional user experience with industry-leading service-level agreements (“SLA”s).

  • Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional Multiprotocol Label Switching (“MPLS”) based WAN architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver an exceptional user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using machine learning and automation.

Cloud Security:

  • Prisma Cloud. Prisma Cloud is a comprehensive Cloud-Native Application Protection Platform (“CNAPP”), securing both cloud-native and lift-and-shift applications across multi- and hybrid-cloud environments. With broad security and compliance coverage and a flexible agentless, as well as agent-based, architecture, Prisma Cloud protects cloud-native applications across their lifecycle from code to cloud. The platform helps developers prevent risks as they code and build the application, secures the software supply chain and the continuous integration and continuous development (“CI/CD”) pipeline, and provides complete visibility and real-time protection for applications in the cloud.

With its code-to-cloud security capabilities, Prisma Cloud uniquely stitches together a complete security picture by tracing back thousands of cloud risks and vulnerabilities that occur in the application runtime to their origin in the code-and-build phase of the application. The platform enables organizations to “shift security left” and fix issues at the source (in code) before they proliferate as a large number of risks in the cloud. The contextualized visibility to alerts, attack paths, and vulnerabilities delivered by Prisma Cloud facilitates collaboration between security and development teams to drive down risks and deliver better security outcomes. The context helps security teams block attacks in the cloud runtime and developers fix risks in source code.

A comprehensive library of compliance frameworks included in Prisma Cloud vastly simplifies the task of maintaining compliance. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities and security issues.

With a flexible, integrated platform that enables customers to license and activate cloud security capabilities that match their need, Prisma Cloud helps secure organizations at every stage in their cloud adoption journey. The platform enables security teams to consolidate multiple products that address individual risks with an integrated solution that also delivers best-in-class capabilities. Including the recently launched CI/CD security module, Prisma Cloud’s code-to-cloud CNAPP delivers comprehensive protection for applications and their code, infrastructure (workloads, network, and storage), data, APIs, and associated identities.

Security Operations:

*•*Cortex XSIAM. This cloud-based subscription is the AI security automation platform for the modern SOC, harnessing the power of AI to radically improve security outcomes and transform security operations. Cortex XSIAM customers can consolidate multiple products into a single unified platform, including EDR, XDR, SOAR, ASM, user behavior analytics (“UBA”), threat intelligence platform (“TIP”), and security information and event management (“SIEM”). Using a security-specific data model and applying AI, Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.

- 7 -

  • Cortex XDR. This cloud-based subscription enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics, including network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes.

  • Cortex XSOAR. Available as a cloud-based subscription or an on-premises appliance, Cortex XSOAR is a comprehensive security orchestration automation and response (“SOAR”) offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. It learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.

  • Cortex Xpanse. This cloud-based subscription provides attack surface management (“ASM”), which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.

SUPPORT

Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center (“ASC”) typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers (“CSM”) to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and certain cloud offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.

Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers focus on their business before, during, and after a breach.

Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.

- 8 -

RESEARCH AND DEVELOPMENT

Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security industry. Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs. Our scale and position in multiple areas of the security market enable us to leverage core competencies across hardware, software, and SaaS and also share expertise and research around threats, which allows us to respond to the rapidly changing threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.

We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2023, we introduced several new offerings, including: Cortex XSIAM 1.0, major updates to Prisma Cloud (including three new security modules), Prisma Access 4.0, PAN-OS 11.0, Cloud NGFW for AWS, and Cloud NGFW for Azure. Additionally, we acquired productive investments that fit well within our long-term strategy. For example, we acquired Cider Security Ltd. (“Cider”), which we expect will support our Prisma Cloud’s platform approach to securing the entire application security lifecycle from code to cloud.

We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.

INTELLECTUAL PROPERTY

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation regarding patent and other intellectual property rights. In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation. We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products.

We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to, and use of, our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers, and partners, and our software is protected by U.S. and international copyright laws. Despite our efforts to protect our intellectual property rights, our rights may not be successfully asserted in the future or may be invalidated, circumvented, or challenged. In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States. See “Risk Factors-Claims by others that we infringe their intellectual property rights could harm our business,” “Risk Factors-Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us,” and “Legal Proceedings” below for additional information.

GOVERNMENT REGULATION

We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.

COMPETITION

We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:

  • large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), Microsoft, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;

  • independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), Crowdstrike, Inc. (“Crowdstrike”), and Zscaler, Inc. (“Zscaler”), that offer a mix of security products;

- 9 -

  • startups and point-product vendors that offer independent or emerging solutions across various areas of security; and

  • public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).

As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.

The principal competitive factors in our market include:

  • product features, reliability, performance, and effectiveness;

  • product line breadth, diversity, and applicability;

  • product extensibility and ability to integrate with other technology infrastructures;

  • price and total cost of ownership;

  • adherence to industry standards and certifications;

  • strength of sales and marketing efforts; and

  • brand awareness and reputation.

We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.

SALES, MARKETING, SERVICES, AND SUPPORT

Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise network, the enterprise data center, cloud locations, and branch or remote locations. No single end-customer accounted for more than 10% of our total revenue in fiscal 2023, 2022, or 2021.

Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2023, 49.7% of our total revenue was derived from sales to three distributors.

We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Google’s Cloud Platform Marketplace under a usage-based licensing model.

Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, including leveraging cloud service provider marketplaces. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.

Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.

Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and resellers that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2023, we had more than 7,100 channel partners.

Global Customer Success. Our Global Customer Success (“GCS”) organization is responsible for delivering professional, educational, and support services directly to our channel partners and end-customers. We leverage the capabilities of our channel partners and train them in the delivery of professional, educational, and support services to enable these services to be locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.

- 10 -

Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Cloud Threat Report and the Unit 42 Network Threat Trends Research Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.

Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront upon fulfillment and are included in deferred revenue. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. We expect backlog related to subscription and support offerings will change from period to period for various reasons, including the timing and duration of customer orders and varying billing cycles of those orders. Products are billed upon hardware shipment or delivery of software license. The majority of our product revenue comes from orders that are received and shipped in the same quarter. However, insufficient supply and inventory may delay our hardware product shipments. As such, we do not believe that our product backlog at any particular time is necessarily indicative of our future operating results.

Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.

MANUFACTURING

We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.

The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.

HUMAN CAPITAL

We believe our ongoing success depends on our employees. Development and investment in our people is central to who we are, and will continue to be so. With a global workforce of 13,948 as of July 31, 2023, our People Strategy is a critical element of our overall company strategy. Our People Strategy is a comprehensive approach to source, hire, onboard, develop, engage, and reward employees. Our approach is grounded on core tenants: respect each employee as an individual, demonstrate fairness and equity in all we do, facilitate flexibility, personalization, and choice whenever possible, and nurture a culture where employees are supported in doing the best work of their careers. Our values of disruption, execution, collaboration, inclusion, and integrity were co-created with employees and serve as the foundation of our culture.

Source & Hire. Sourcing diverse talent who possess the skills and capabilities to execute and add value to our culture form the cornerstone of our comprehensive approach to talent acquisition—a philosophy we call “The Way We Hire.” We utilize an array of methods to identify subject matter experts in their respective fields, emphasizing sourcing channels that connect us with underrepresented talents.

In an effort to foster career growth within Palo Alto Networks, we prioritize internal mobility. This allows current employees to progress either through a traditional career path or by exploring roles across various business functions, often culminating in promotions. We encourage existing employees to refer qualified individuals for our open positions, thus leveraging the collective networks of our team to attract a diverse range of expertise and perspectives.

We have made strides to understand job requirements and implement structured interviewing practices to identify candidates of the highest quality. By conducting thorough job analyses and creating success profiles, we have developed a deeper understanding of what is required for success in critical roles. We equip our hiring managers with essential training to identify and mitigate potential unconscious biases. Our interviewing process emphasizes values and competencies that we believe enhance our culture. This commitment extends to conducting interviews with diverse panelists and providing a balanced evaluation and quality interview experience for a diverse slate of candidates. We remain steadfast in our commitment to fairness, bias reduction, and equal opportunities for all potential hires.

- 11 -

A key to our hiring process is the Global Hiring Committees, introduced in fiscal 2023. These committees play a significant role in elevating our hiring standards by promoting shared understanding, reducing biases, enhancing objectivity, and ensuring the recruitment of diverse talent. The Committees foster effective collaboration using a common language and consensus-driven decision-making.

Onboard & Develop. We believe that each member of our workforce is unique, and that their integration into Palo Alto Networks and their career journey involve unique needs, interests, and goals. That is why our development programs are grounded on individualization, flexibility, and choice. From onboarding to ongoing development, our FLEXLearn philosophy offers multiple paths to assess, develop, and grow.

Our onboarding experience starts with “pre-boarding.” Before an employee’s start date, they are provided access to foundational tools to help them prepare to join Palo Alto Networks. We view pre-boarding as fundamental to introducing new employees to our culture, building trust, and facilitating rapid productivity. Welcome Day is a combination of in-person, virtual learning platforms and communication channels that provide new employees with inspirational, often personalized, onboarding experiences that carry on through the first year of employment. We have specialized learning tracks for interns and new graduates that have been recognized as best in class externally to support early-in-career individuals in acclimating to our culture as they progress on their career journey. As part of our merger and acquisition strategy, we have also established a robust integration program with the goal to enable individuals joining our teams to feel part of our culture at speed.

Following onboarding, there are a variety of ways that employees can assess their interests and skills, build a development plan specific to those insights, and continue to grow. Our development initiatives are delivered to employees through a comprehensive platform, FLEXLearn. The platform contains curated content and programs, such as assessment instruments, thousands of courses, workshops, and mentoring and coaching services. Leaders and executives also have access to specialized learning tracks that help them strategize, mobilize, and deliver maximum personal and team performance. Employees have full agency to direct their growth at their pace and choosing. Development information about core business elements, working in a distributed hybrid environment, as well as required company-wide compliance training, such as Code of Conduct, privacy and security, anti-discrimination, anti-harassment, and anti-bribery training, is also deployed through the FLEXLearn platform for all employees. In addition, FLEXLearn provides employees with events and activities that motivate and spark critical thinking, on topics ranging from inclusion to well-being and collaboration. On average, employees had completed 33 hours of development through the FLEXLearn platform during fiscal 2023.

Engage & Reward. We aim to foster engagement through a multifaceted approach to collect, understand, and act on employee feedback. Our comprehensive communication and listening strategy utilizes in-person and technology-enabled channels. We share and collect information through corporate and functional “All Hands” meetings, including several meetings specifically focused on employee-centered topics in an “Ask Me Anything” format. Digital Displays across our sites, our intranet platform, monthly and weekly email communications, and an active Slack platform provide a regular flow of information to and between employees and leadership. In addition to these channels that reach large audiences, we conduct regular executive listening sessions, including small group convenings with our CEO and other C-suite leaders, and ad-hoc pulse surveys to better understand employee engagement, sentiment, well-being, and the ability to transition to a hybrid work model.

Employee sentiment is also collected from external sources, such as web platforms that crowdsource feedback. Employees provide commentary to platforms such as Glassdoor, Comparably, and others and insights from those platforms are used to measure engagement. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as a “most loved workplace” (2021, 2022, and 2023). Palo Alto Networks has been recognized by Glassdoor, Comparably, Human Rights Campaign, Disability Index, and others as an employer of choice. Our CEO has also earned a 92% employee approval rating on Glassdoor, a top percentile score.

In addition to a comprehensive compensation and diverse benefits program, we believe in an always-on feedback and rewards philosophy. From recurring 1:1 sessions, quarterly performance feedback, semi-annual performance reviews to use of our Cheers for Peers peer recognition program, employees get continuous input about the value they bring to the organization.

These engagement and recognition strategies have informed our holistic People Strategy, including our Inclusion and Diversity (“I&D”) initiatives and Internal Mobility program. Based on the outcomes from external sources, insights from internal sources, our modest attrition rate (compared to market trends), and strong participation in our Internal Mobility program, we believe employees at Palo Alto Networks feel engaged and rewarded.

Inclusion & Diversity. We are intentional about including diverse points of view, perspectives, experiences, backgrounds, and ideas in our decision-making processes. We deeply believe that true diversity exists when we have representation of all ethnicities, genders, orientations and identities, and cultures in our workforce. Our corporate I&D programs focus on five principles—our workforce should feel psychologically safe, they should understand, listen, and support one another, and they should elevate others. These principles are the foundation of our approach to I&D, which we call P.U.L.S.E.

- 12 -

We have eleven employee network groups (“ENG”s) that play a vital role in building understanding and awareness. Over 29% of our global workforce was involved in at least one ENG as of July 31, 2023. ENGs are also allocated funding to make charitable grants to organizations advancing their causes. We involve our ENGs in listening sessions with executive teams and we work in partnership to develop our annual I&D plans because we believe involvement is critical.

Our I&D philosophy is fully embedded in our talent acquisition, learning and development, performance elevation, and rewards and recognition programs. The diversity of our board of directors, with women representing 40% of our board as of July 31, 2023, is an example of our commitment to inclusion and diversity.

ENVIRONMENTAL, SOCIAL, AND GOVERNANCE

We recognize our duty to address environmental, social, and governance (“ESG”) practices. From our science-based approach to emissions reductions and our social impact programs to our Supplier Responsibility initiatives and Code of Business Conduct and Ethics, we value the opportunity to have meaningful outcomes that reinforce our intention to respect our planet, uplift our communities, and advance our industry.

Environmental. We recognize climate change is a global crisis and are committed to doing our part to reduce environmental impacts. We remain committed to our goals of utilizing 100% renewable energy by 2030, reducing our greenhouse gas (“GHG”) emissions and working across our value chain, and with coalitions, to address climate change. We made progress towards our goals in fiscal 2023 through several milestones. We engaged with a local utility provider to power our Santa Clara, California headquarters with 100% renewable energy effective January 1, 2023. Our near-term scope 1, 2, and 3 emissions reduction goals, aligned to a warming scenario of 1.5° Celsius, were verified by the Science Based Targets initiative. We were recognized by Carbon Disclosure Project (“CDP”) as an “A-List” company and a “Supplier Engagement Leader.” We remain committed to being transparent about our progress over time through annual reporting.

Social. In addition to our People Strategy described in the section titled “Human Capital” above, we prioritized the health and safety of our global workforce. Through the deployment of our Global Supplier Code of Conduct, we continued to reach across our supply chain to communicate our expectations regarding labor standards, business practices, and workplace health and safety conditions. During fiscal 2023, we maintained our affiliate membership in the Responsible Business Alliance and maintained our commitment to Supplier Diversity. We value our role as a good corporate citizen and in fiscal 2023 continued to execute our social impact programs. We made charitable grants to support organizations providing services in our core funding areas of education, including academic scholarships, diversity, and basic needs. We expanded our work to provide cybersecurity curriculum to schools, universities, and nonprofit organizations to help individuals of all ages protect their digital way of life and to prepare diverse adults for careers in cybersecurity. Employees continued to participate in our giving, matching, and volunteer programs to make impacts in their local communities.

Governance. Integrity is one of our core values. Our corporate behavior and leadership practices model ethical decision-making. All employees are informed about our governance expectations through our Codes of Conduct, compliance training programs, and ongoing communications. Our board of directors is governed by Corporate Governance Guidelines, which are amended from time to time to incorporate best practices in corporate governance. Reinforcing the importance of our ESG performance, the charter of the ESG and Nominating Committee of the board of directors includes the primary oversight of ESG.

AVAILABLE INFORMATION

Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.

We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.

- 13 -

Previous: Cover and table of contents · Next: Item 1A. Risk Factors