10-K comparison

Palo Alto Networks (PANW) 10-K risk factor changes: FY2024 vs FY2023

The 2024-07-31 10-K against the 2023-07-31 one, compared heading by heading and sentence by sentence.

Item 1A57 rewritten38 added13 removed531 unchanged

All filing items848 rewritten491 added282 removed2,227 unchanged

Read the changesGo to Item 1A

Palo Alto Networks Form 10-K, every itemFY2024, filed 6 September 2024, against FY2023, filed 1 September 2023FY2024 on sec.govFY2023 on sec.govRead this filingJSON

Summary

counted, not written

New Item 1A headings (2)

  1. If we are unable to attract new customers, our future results of operations could be harmed.
  2. We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.

Removed Item 1A headings (1)

  1. Our actual or perceived failure to adequately protect personal data could have a material adverse effect on our business.
Reworded Item 1A headings (1)
  1. We may have exposure to [added: tax liabilities that are] greater than [removed: anticipated tax liabilities.][added: anticipated.]

A heading is new when no FY2023 heading matches it after ignoring case and punctuation, and reworded when it shares at least 60 percent of its words with one that went away. All current risk factor headings.

Sentences by item

24 items, with every count and a link to each item that changed

Underlined words on a shaded ground are new in FY2024; struck-through words were in FY2023. Sentences that are wholly new or wholly gone are labelled rather than marked.

Item 1A. Risk Factors

57 rewritten, 38 added, 13 removed, 531 unchanged

Rewritten

- Issues in the development and deployment of [removed: Artificial Intelligence (“AI”)] [added: AI] may result in reputational harm and legal liability and could adversely affect our results of operations.

Rewritten

- We may have exposure to [added: tax liabilities that are] greater than [removed: anticipated tax liabilities.][added: anticipated.]

Rewritten

- Our reputation and/or business could be negatively impacted by [removed: environmental, social, and governance (“ESG”)] [added: ESG] matters and/or our reporting of such matters.

Rewritten

Military actions or armed conflict, including [added: the hostilities in Israel and the surrounding region,] Russia’s invasion of Ukraine and any related political or economic responses and counter-responses, and uncertainty about, or changes in, government and trade relationships, policies, and treaties could also lead to worsening economic and market conditions and geopolitical environment.

Rewritten

In response to Russia’s invasion of Ukraine, the United States, along with the European [removed: Union,] [added: Union (the “E.U.”)] has imposed restrictive sanctions on Russia, Russian entities, and Russian citizens (“Sanctions on Russia”).

Rewritten

For example, from the end of fiscal [removed: 2022] [added: 2023] to the end of fiscal [removed: 2023,] [added: 2024,] our headcount increased from [removed: 12,561 to] 13,948 [added: to 15,289] employees.

Rewritten

We have experienced revenue growth rates of [removed: 25.3%] [added: 16.5%] and [removed: 29.3%] [added: 25.3%] in fiscal [removed: 2023] [added: 2024] and fiscal [removed: 2022,] [added: 2023,] respectively.

Rewritten

In addition, we have incurred losses in fiscal years prior to fiscal [removed: 2023 and, as a result, we had an accumulated deficit of $1.2 billion as of July 31,] 2023.

Rewritten

Our future success depends, in part, on our ability to expand the deployment of our portfolio with existing end-customers, especially large enterprise customers, [added: including through our platformization strategy,] and create demand for our new offerings, The rate at which our end-customers purchase additional products, subscriptions, and support depends on a number of factors, including the perceived need for additional security products, including subscription and support offerings, as well as general economic conditions.

Rewritten

Subscription and support revenue accounts for a significant portion of our revenue, comprising [removed: 77.1%] [added: 80.0%] of total revenue in fiscal [removed: 2023, 75.2%] [added: 2024, 77.1%] of total revenue in fiscal [removed: 2022,] [added: 2023,] and [removed: 73.7%] [added: 75.2%] of total revenue in fiscal [removed: 2021.][added: 2022.]

Rewritten

For fiscal [removed: 2023, three] [added: 2024, four] distributors individually represented 10% or more of our total revenue and in the aggregate represented [removed: 49.7%] [added: 59.0%] of our total revenue.

Rewritten

As of July 31, [removed: 2023,] [added: 2024,] two distributors individually represented 10% or more of our gross accounts receivable and in the aggregate represented [removed: 37.6%] [added: 31.5%] of our gross accounts receivable.

Rewritten

- large companies that incorporate security features in their products, such as Cisco, Microsoft, [added: Alphabet] or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;

Rewritten

- independent security vendors, such as Check Point, Fortinet, [removed: Crowdstrike, and] [added: CrowdStrike,] Zscaler, [added: and Wiz,] that offer a mix of security products;

Rewritten

If we are unsuccessful at integrating past or future acquisitions in a timely manner, or the [removed: technologies and] [added: technologies, products, or] operations associated with such acquisitions, into our company, our revenue and operating results could be adversely affected.

Rewritten

We may not successfully evaluate or utilize the acquired [removed: technology] [added: technology, products,] or personnel, realize anticipated synergies from the acquisition, or accurately forecast the financial impact of an acquisition transaction and integration of such acquisition, including accounting charges and any potential impairment of goodwill and intangible assets recognized in connection with such acquisitions.

Rewritten

AI presents challenges and risks that could affect our products and solutions, and [removed: therefore] [added: the operations of] our business.

Rewritten

These [removed: potential issues] [added: efforts] could subject us to regulatory risk, legal liability, including under new proposed legislation regulating AI in jurisdictions such as the [removed: EU] [added: E.U.] and regulations being considered in other jurisdictions, [removed: and] [added: or] brand or reputational harm.

Rewritten

Additionally, defects [added: or vulnerabilities] may cause our products or subscriptions to [added: become temporarily unavailable, to] be vulnerable to security attacks, cause them to fail to help secure networks, or temporarily interrupt end-customers’ networking [removed: traffic.][added: traffic, or the availability of other information technology infrastructure or systems.]

Rewritten

Furthermore, defects or errors in [removed: our subscription updates] [added: products] or [removed: our] [added: software or updates to those] products [added: or software] could result in a failure to effectively update end-customers’ hardware and cloud-based [removed: products.][added: products or otherwise cause problems in our customers hardware, networks or information technology infrastructure or systems.]

Rewritten

[removed: Our] [added: The] data [removed: centers] [added: centers, networks,] and [removed: networks] [added: cloud infrastructure that we use to deliver our products and services] may experience technical failures and downtime or may fail to meet the increased requirements of a growing installed end-customer base, any of which could temporarily or permanently expose our end-customers’ networks, leaving their networks unprotected against the latest security threats.

Rewritten

Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to [added: comprehensively] protect our technology or products and subscriptions.

Rewritten

Although we [added: take reasonable steps to] monitor our use of open source software to avoid subjecting our products and subscriptions to conditions we do not intend, the terms of many open source licenses have not been interpreted by United States courts, and there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability to commercialize our products and subscriptions.

Rewritten

Our [added: substantial] reliance on [removed: these] [added: Flex, as well as other] manufacturing partners [removed: reduces our control over the manufacturing process and exposes] [added: subjects] us to [added: potential concentration] risks, [removed: including] [added: such as] reduced control over [added: the manufacturing process,] quality assurance, product costs, product supply, [removed: timing,] and [removed: transportation risk.][added: timing.]

Rewritten

As a result, our costs have increased and we have raised, and may be required to further raise, prices on our hardware [removed: products, all of which could severely impair our ability to fulfill orders.][added: products.]

Rewritten

In [removed: addition,] [added: the past,] we [removed: continue to experience] [added: experienced] supply chain disruption and have incurred increased costs resulting from inflationary pressures.

Rewritten

- political, economic, and social uncertainty around the world, health risks such as epidemics and pandemics like COVID-19, macroeconomic [removed: challenges in Europe,] [added: challenges,] terrorist activities, Russia’s invasion of Ukraine, tensions between China and Taiwan, [added: the hostilities in Israel] and [added: the surrounding region, and] continued hostilities in the Middle East;

Rewritten

- non-compliance with U.S. and foreign laws, including antitrust regulations, anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the [removed: U.K.] [added: United Kingdom (“U.K.”)] Bribery Act, U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices.

Rewritten

In addition, increased international sales in the future, including through our channel partners and other [removed: partnerships,] [added: partnerships or as a result of our acquisitions,] may result in foreign currency denominated sales, increasing our foreign currency risk.

Rewritten

As of July 31, [removed: 2023,] [added: 2024,] the total notional amount of our outstanding foreign currency forward contracts was [removed: $957.5 million.][added: $1.2 billion.]

Rewritten

The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be [removed: limited,] [added: limited] and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results.

Rewritten

In addition, many of our employees in Israel are obligated to perform annual reserve duty in the Israeli military and are subject to being called for active duty under emergency [removed: circumstances.][added: circumstances, which has occurred as a result of hostilities in Israel and the surrounding region.]

Rewritten

These laws and regulations are also subject to [removed: frequent] [added: frequent, inconsistent] and unexpected [removed: changes, new] [added: changes; new, modified] or additional laws or regulations may be [removed: adopted,] [added: adopted;] and rulings that invalidate prior [added: laws, regulations, or interpretations of such] laws or regulations may be issued.

Rewritten

For example, we are subject to the E.U. General Data Protection Regulation (“E.U. GDPR”) and the U.K. General Data Protection Regulation [removed: (‘U.K.] [added: (“U.K.] GDPR,” and collectively the “GDPR”), both of which impose stringent data protection requirements, provide for costly penalties for noncompliance (up to the greater of (a) €20 million under the “E.U. GDPR” or £17.5 million under the “U.K. GDPR,” and (b) 4% of annual worldwide turnover), and confer the right upon data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations.

Rewritten

The regulatory environment applicable to the handling of European residents’ personal data, and our actions taken in response, may cause us to assume additional liabilities or incur additional [removed: costs, including in the event we self-certify to the EU-U.S. DPF.][added: costs.]

Rewritten

Moreover, much like with Schrems II, we anticipate future legal challenges to the approved data transfer mechanisms between Europe and the United States, including a challenge to the [removed: EU-U.S.] [added: E.U.-U.S.] DPF.

Rewritten

Any such [removed: enforcement actions] [added: claims] could result in substantial [removed: costs] [added: costs, ongoing remedial, audit] and [added: reporting obligations, and] diversion of resources, and distract management and technical personnel.

Rewritten

These potential liabilities and enforcement actions could also have an overall negative [removed: affect] [added: effect] on our business, operating results, and financial condition.

Rewritten

New legislation affecting the scope of personal data and personal information where we or our customers and partners have operations, especially relating to classification of Internet Protocol (“IP”) addresses, machine identification, [removed: AI,] [added: AI and machine learning,] location data, and other information, may limit or inhibit our ability to operate or expand our business, including limiting strategic partnerships that may involve the sharing or uses of data, and may require significant expenditures and efforts in order to comply.

Rewritten

We may have exposure to [added: tax liabilities that are] greater than [removed: anticipated tax liabilities.][added: anticipated.]

New in FY2024

- If we are unable to attract new customers, our future results of operations could be harmed.

New in FY2024

- We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.

New in FY2024

If we are unable to attract new customers, our future results of operations could be harmed.

New in FY2024

To increase our revenue and maintain profitability, we must add new customers.

New in FY2024

To do so, we must successfully convince prospective customers of the value of adopting our solutions.

New in FY2024

We are engaging in costly marketing and sales efforts to accelerate platformization and attract new customers, which may fail or may not be as successful as intended or at all.

New in FY2024

Additionally, prospective customers’ decisions to purchase our solutions depend on a variety of factors, many of which are out of our control.

New in FY2024

These factors significantly impact our ability to add new customers and increase the time, resources and sophistication required to do so.

New in FY2024

For example, prospective customers may face real or perceived switching costs when switching to our solutions from legacy security vendors and products.

New in FY2024

Deployment of our solutions may require a significant commitment of resources from our customers.

New in FY2024

Any deterioration in general economic conditions, including as a result of the geopolitical environment or inflation (as well as government policies such as raising interest rates in response to inflation), have in the past caused, and may in the future cause, our current and prospective customers to delay or cut their overall security and IT operations spending.

New in FY2024

If our efforts to attract new customers are not successful, our sales may not grow as quickly as anticipated, or at all, and our business, operating results, and financial condition will be harmed.

New in FY2024

We are also incorporating AI into the operations of our business.

New in FY2024

The AI that is being incorporated into our products, solutions, and business operation tools may not be successful or beneficial, and instead may cause technical, legal or ethical problems or result in increased costs.

New in FY2024

The investments that we are making across our business in AI reflect our ongoing efforts to innovate and provide products and services that are useful to our customers, as well as provide efficiencies in our business.

New in FY2024

Such investments ultimately may not be commercially viable or may not result in an adequate return of capital and we may incur unanticipated liabilities.

New in FY2024

For example, in April 2024, we became aware of a command injection vulnerability in the GlobalProtect feature of certain versions of our PAN-OS software.

New in FY2024

To remediate the matter, we published a security advisory to advise customers, provided software updates for affected PAN-OS versions, and are actively engaged in customer outreach, support and remediation efforts for potentially impacted customers.

New in FY2024

Any such technical failure, downtime or failures in general may temporarily or permanently disable our end-customers’ networks, information technology infrastructure or other systems, or expose our end-customers’ networks to attacks from security threats.

New in FY2024

For example, on January 31, 2024, in the Centripetal Networks, Inc. lawsuit against us, a jury returned a verdict of non-willful infringement with a lump sum amount of $151.5 million, plus statutory interest, for which we have accrued $184.4 million for the verdict amount and estimated interest as of July 31, 2024.

New in FY2024

Additional examples of patent infringement cases have been disclosed in Note 12.

New in FY2024

Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K.

New in FY2024

We have business operations in Israel and intend to continue growing our presence in Israel.

New in FY2024

Our operations in Israel could be disrupted by political instability, civil unrest, terrorist attacks, acts of violence, acts of war, or other military actions, including the hostilities in Israel and the surrounding region.

New in FY2024

We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.

New in FY2024

In addition, with respect to the personal data that we process on behalf of our customers, we self-certified to the E.U.-U.S. Data Privacy Framework (“E.U.-U.S. DPF”), which has been approved for transfers of personal data subject to the GDPR to the United States.

New in FY2024

The E.U.-U.S. DPF has been recognized as adequate under the E.U. law to allow transfers of personal data from the E.U. to companies in the U.S. that have self-certified to the framework.

New in FY2024

However, the E.U.-U.S. DPF may be subject to legal challenge, which could cause the legal requirements for data transfers from the E.U. to be uncertain.

New in FY2024

These include laws enacted in at least 19 states, and six other states have active privacy bills pending in state legislative processes.

New in FY2024

We and our customers may face risk of enforcement actions by regulators or data protection authorities, private litigation and adverse publicity including reputational damage and loss of customer confidence for alleged violations of any of the foregoing obligations.

New in FY2024

The amount and scope of insurance we maintain may not cover all types of claims that may arise.

New in FY2024

For example, beginning in fiscal 2023, we were required to capitalize and amortize research and development expenses as required by the Tax Cuts and Jobs Act.

New in FY2024

As a result of this change and our increased profitability, we have paid significantly more U.S. cash taxes during fiscal 2024 and we expect our cash tax payments to increase in future periods.

New in FY2024

In addition, we are or may become subject to various new and proposed climate-related and other sustainability-related laws and regulations, including, for example, the E.U.’s Corporate Sustainability Reporting Directive.

New in FY2024

Additional regulation may require us to incur significant additional costs associated with increased compliance burdens, including the implementation of additional internal controls processes and procedures, and impose increased oversight obligations on our management and board of directors, as well as require us to retain third-party experts.

New in FY2024

Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, fines or litigation, which could negatively impact our business, operating results or financial condition.

New in FY2024

On August 15, 2024, our board of directors authorized a $500.0 million increase to our share repurchase program, bringing the total remaining authorization for future share repurchases to $1.0 billion.

New in FY2024

\- 35 \-

Dropped from FY2023

\- 14 \-

Dropped from FY2023

- Our actual or perceived failure to adequately protect personal data could have a material adverse effect on our business.

Dropped from FY2023

- Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.

Dropped from FY2023

To respond to this demand, our customer financing activities have increased and will likely continue to increase in the future.

Dropped from FY2023

As a result of various of our acquisitions, including Cider, Cyber Secdo Ltd. (“Secdo”), PureSec Ltd. (“PureSec”), and Twistlock Ltd. (“Twistlock”), we have offices and employees located in Israel.

Dropped from FY2023

Accordingly, political, economic, and military conditions in Israel directly affect our operations, including the recent political unrest in Israel.

Dropped from FY2023

Our actual or perceived failure to adequately protect personal data could have a material adverse effect on our business.

Dropped from FY2023

In the future, we may self-certify to the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), which has been approved for transfers of personal data subject to the GDPR to the United States and requires public disclosures of adherence to data protection principles and the submission of jurisdiction to European regulatory authorities.

Dropped from FY2023

Following the “Schrems II” decision by the Court of Justice of the European Union, transfers of personal data to recipients in third countries are also subject to additional assessments and safeguards beyond the implementation of approved transfer mechanisms.

Dropped from FY2023

The decision imposed a requirement for companies to carry out an assessment of the laws and practices governing access to personal data in the third country to ensure an essentially equivalent level of data protection to that afforded in the E.U.

Dropped from FY2023

Additionally, we and our customers may face risk of enforcement actions by data protection authorities in Europe relating to personal data transfers to us and by us from Europe.

Dropped from FY2023

These include laws enacted in at least ten states, which all go into effect by January 1, 2026.

Dropped from FY2023

In addition, we also entered into warrant transactions in connection with our 2023 Notes (together with the 2025 Warrants, the “Warrants”).

An excerpt. Shown here: 40 of 57 rewritten, all 38 added and all 13 removed. The counts are complete. For every sentence, read Item 1A. Risk Factors in the FY2024 filing and the FY2023 filing.

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations

143 rewritten, 66 added, 32 removed, 316 unchanged

Rewritten

- Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal [removed: 2023] [added: 2024] to fiscal [removed: 2022.][added: 2023.]

Rewritten

For discussion and analysis related to our financial results comparing fiscal [removed: 2022] [added: 2023] to [removed: 2021,] [added: 2022,] refer to Part II, Item 7.

Rewritten

Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal [removed: 2022,] [added: 2023,] which was filed with the Securities and Exchange Commission on September [removed: 6, 2022.][added: 1, 2023.]

Rewritten

Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by [removed: industry-leading artificial intelligence] [added: AI] and automation.

Rewritten

- Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, [added: AI Runtime Security,] as well as a cloud-delivered [removed: Secure Access Service Edge (“SASE”).][added: SASE.]

Rewritten

Prisma® Access, our [removed: Security Services Edge (“SSE”)] [added: SSE] solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and [added: securely] enable the cloud-delivered branch.

Rewritten

Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, [added: Advanced] DNS Security, IoT/OT Security, GlobalProtect®, Enterprise [removed: Data Loss Prevention (“Enterprise DLP”), Artificial Intelligence for Operations (“AIOps”),] [added: DLP, AIOps,] SaaS [removed: Security API,] [added: Security,] and [removed: SaaS Security Inline.][added: AI Access Security.]

Rewritten

[removed: Panorama®,] [added: Strata Cloud Manager,] our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.

Rewritten

As a comprehensive [removed: Cloud Native Application Protection Platform (“CNAPP”),] [added: CNAPP,] Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, [added: GenAI ecosystem,] and the entire cloud native technology stack across the full development [removed: lifecycle;] [added: lifecycle,] from code to [removed: runtime.][added: cloud.]

Rewritten

[removed: For] [added: We also offer our VM-Series and CN-Series virtual firewalls for] inline network security on multi- and hybrid-cloud [removed: environments, we also offer our VM-Series and CN-Series Firewall offerings.][added: environments.]

Rewritten

- We deliver the next generation of security [removed: automation,] [added: operations capabilities that combine] security analytics, endpoint security, [added: automation,] and [removed: attack surface management] [added: ASM] solutions through our Cortex [removed: portfolio.][added: platform.]

Rewritten

These include Cortex XSIAM, our [removed: AI] [added: AI-driven] security [removed: automation] [added: operations] platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity [removed: attacks on the endpoint,] [added: attacks,] Cortex XSOAR® for [removed: security orchestration, automation, and response (“SOAR”),] [added: SOAR,] and Cortex XpanseTM for [removed: attack surface management (“ASM”).][added: ASM.]

Rewritten

Threat Intelligence and [removed: Security Consulting] [added: Advisory Services] (Unit 42):

Rewritten

- Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers [removed: proactively] manage cyber risk.

Rewritten

For fiscal [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] total revenue was [removed: $6.9] [added: $8.0] billion and [removed: $5.5] [added: $6.9] billion, respectively, representing year-over-year growth of [removed: 25.3%.][added: 16.5%.]

Rewritten

As of July 31, [removed: 2023,] [added: 2024,] we had end-customers in over 180 countries.

Rewritten

Our product revenue grew to $1.6 billion or [removed: 22.9%] [added: 20.0%] of total revenue for fiscal [removed: 2023,] [added: 2024,] representing year-over-year growth of [removed: 15.8%.][added: 1.6%.]

Rewritten

Product revenue also includes revenue derived from software licenses of [removed: Panorama,] [added: Panorama®,] SD-WAN, and the VM-Series.

Rewritten

Our products are designed for different performance requirements throughout an organization, ranging from our PA-410, which is designed for small organizations and remote or branch offices, to our top-of-the-line [removed: PA-7080,] [added: PA-7500,] which is designed for large-scale data centers and service provider use.

Rewritten

Our subscription and support revenue grew to [removed: $5.3] [added: $6.4] billion or [removed: 77.1%] [added: 80.0%] of total revenue for fiscal [removed: 2023,] [added: 2024,] representing year-over-year growth of [removed: 28.4%.][added: 20.9%.]

Rewritten

Our subscriptions provide our end-customers with near real-time access to the latest antivirus, intrusion prevention, web filtering, modern malware prevention, data loss prevention, [added: CASB] and [removed: cloud access] [added: AI] security [removed: broker] capabilities across the network, endpoints, and the cloud.

Rewritten

When [removed: end-customers] [added: customers] purchase our physical, virtual, or container firewall appliances, or certain cloud offerings, they typically purchase support in order to receive ongoing security updates, upgrades, bug fixes, and repairs.

Rewritten

In addition to the subscriptions purchased with these appliances, [removed: end-customers] [added: customers] may also purchase other subscriptions on a per-user, per-endpoint, or capacity-based basis.

Rewritten

We believe that the growth of our business and our short-term and long-term success are dependent upon many factors, including our ability to extend our technology leadership, grow our base of end-customers, expand deployment of our portfolio and support offerings within existing end-customers, [removed: and] focus on end-customer [removed: satisfaction.][added: satisfaction, and address any product vulnerabilities.]

Rewritten

Worsening economic conditions, including inflation, higher interest rates, slower growth, fluctuations in foreign exchange rates, [added: supply chain disruptions,] and other conditions, may adversely affect our results of operations and financial performance.

Rewritten

We are [added: also] monitoring the [added: impact of inflationary pressures and the] tensions between China and Taiwan, and between the U.S. and China, which could have an adverse impact on our business or results of operations in future periods.

Rewritten

| | | | [added: 2024 | | | | | |] 2023 | | | | | | 2022 | | |

Rewritten

| Total deferred revenue | | | $ | [removed: 9,296.4] [added: 11,480.5] | | | | | $ | [removed: 6,994.0] [added: 9,296.4] | |

Rewritten

| Cash, cash equivalents, and investments | | | $ | [removed: 5,437.9] [added: 6,752.0] | | | | | $ | [removed: 4,686.4] [added: 5,437.9] | |

Rewritten

| | | | [removed: 2023] [added: 2024] | | | | | | [removed: 2022] [added: 2023] | | | | | | [removed: 2021] [added: 2022] | | |

Rewritten

| Total revenue | | | $ | [removed: 6,892.7] [added: 8,027.5] | | | | | $ | [removed: 5,501.5] [added: 6,892.7] | | | | | $ | [removed: 4,256.1] [added: 5,501.5] | |

Rewritten

| Total revenue year-over-year percentage increase | | | [removed: 25.3] [added: 16.5] | | % | | | | [removed: 29.3] [added: 25.3] | | % | | | | [removed: 24.9] [added: 29.3] | | % |

Rewritten

| Gross margin | | | [removed: 72.3] [added: 74.3] | | % | | | | [removed: 68.8] [added: 72.3] | | % | | | | [removed: 70.0] [added: 68.8] | | % |

Rewritten

| Operating income (loss) | | | $ | [removed: 387.3] [added: 683.9] | | | | | $ | [removed: (188.8)] [added: 387.3] | | | | | $ | [removed: (304.1)] [added: (188.8)] | |

Rewritten

| Operating margin | | | [removed: 5.6] [added: 8.5] | | % | | | | [removed: (3.4)] [added: 5.6] | | % | | | | [removed: (7.1)] [added: (3.4)] | | % |

Rewritten

| Billings | | | $ | [removed: 9,194.4] [added: 10,208.1] | | | | | $ | [removed: 7,471.5] [added: 9,194.4] | | | | | $ | [removed: 5,452.2] [added: 7,471.5] | |

Rewritten

| Billings year-over-year percentage increase | | | [removed: 23.1] [added: 11.0] | | % | | | | [removed: 37.0] [added: 23.1] | | % | | | | [removed: 26.7] [added: 37.0] | | % |

Rewritten

| Cash flow provided by operating activities | | | $ | [removed: 2,777.5] [added: 3,257.6] | | | | | $ | [removed: 1,984.7] [added: 2,777.5] | | | | | $ | [removed: 1,503.0] [added: 1,984.7] | |

Rewritten

| Free cash flow (non-GAAP) | | | $ | [removed: 2,631.2] [added: 3,100.8] | | | | | $ | [removed: 1,791.9] [added: 2,631.2] | | | | | $ | [removed: 1,387.0] [added: 1,791.9] | |

Rewritten

We [removed: consider] [added: have considered] billings to be a key metric used by management to manage our business.

New in FY2024

- Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future.

New in FY2024

A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products.

New in FY2024

We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate.

New in FY2024

Our platformization strategy combines various products and services into a tightly integrated architecture and makes security faster, less complex, and more cost-effective.

New in FY2024

We focus on delivering value in four sectors of the cybersecurity industry:

New in FY2024

Strata Cloud Manager includes the Strata Copilot which provides a natural language interface to simplify and accelerate platform management.

New in FY2024

- We deliver scalable and comprehensive security across the cloud application development lifecycle through our Code to CloudTM platform, Prisma Cloud.

New in FY2024

Additionally, Unit 42 offers managed detection and response and managed threat hunting services.

New in FY2024

During fiscal 2024, we introduced several new offerings, including: Prisma Cloud Darwin release with newly integrated Code to Cloud intelligence capabilities, PAN-OS 11.2 Quasar, Cortex XSIAM 2.0, new Cortex XSIAM features, Prisma SASE 3.0, and Precision AITM.

New in FY2024

For example, in December 2023, we acquired Dig, which we expect will enhance our Prisma Cloud capabilities with a DSPM solution that is intended to provide customers with visibility into, and secure data stored across, their multi-cloud environments; and we acquired Talon, which will support Prisma SASE’s approach to provide secure access to business applications for unmanaged and personal devices with an enterprise browser.

New in FY2024

In May 2024, we announced an expanded partnership with International Business Machines Corporation (“IBM”) to deliver AI-powered security outcomes for customers, as part of which we agreed to acquire IBM's QRadar SaaS assets, including QRadar intellectual property rights, customer relationships and customer contracts.

New in FY2024

On August 31, 2024, we completed the acquisition of IBM’s QRadar SaaS assets and we expect the acquisition will help accelerate the growth of our Cortex XSIAM business.

New in FY2024

The hostilities in Israel and the surrounding region have increased the levels of economic and political uncertainty.

New in FY2024

While we have business operations in Israel, and intend to continue growing our presence in Israel, we currently do not expect significant business disruption.

New in FY2024

We are actively monitoring, evaluating, and responding to the developing situation.

New in FY2024

| | | | 2024 | | | | | | 2023 | | |

New in FY2024

There are inherent limitations in using billings to evaluate our operating results as the variability in payment terms may cause fluctuation in billings.

New in FY2024

Beginning in the first fiscal quarter of 2025, billings will no longer be a key financial metric and will no longer be reported.

New in FY2024

| Total revenue | | | $ | 8,027.5 | | | | | $ | 6,892.7 | | | | | $ | 5,501.5 | |

New in FY2024

| Billings | | | $ | 10,208.1 | | | | | $ | 9,194.4 | | | | | $ | 7,471.5 | |

New in FY2024

| Free cash flow (non-GAAP) | | | $ | 3,100.8 | | | | | $ | 2,631.2 | | | | | $ | 1,791.9 | |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | 2022 | | |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

| Europe, the Middle East, and Africa (“EMEA”) | | | 1,602.0 | | | | | | 1,359.6 | | | | | | 242.4 | | | | | | 17.8 | | % | | | | 1,359.6 | | | | | | 1,055.8 | | | | | | 303.8 | | | | | | 28.8 | | % |

New in FY2024

| Asia Pacific and Japan (“APAC”) | | | 942.6 | | | | | | 813.2 | | | | | | 129.4 | | | | | | 15.9 | | % | | | | 813.2 | | | | | | 643.1 | | | | | | 170.1 | | | | | | 26.5 | | % |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

Cost of product revenue decreased for fiscal 2024 compared to fiscal 2023 primarily due to decreased demand for our prior generation of hardware products and lower costs largely driven by an easing of supply chain challenges, partially offset by a change in mix shift within our new generation hardware products.

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

| | | | 2024 | | | | | | | | | | | | 2023 | | | | | | | | | | | | 2022 | | | | | | | | |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

The remaining increase in research and development expense was further driven by increased shared costs.

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

General and administrative expenses increased for fiscal 2024 compared to fiscal 2023 primarily due to litigation-related charges of $204.4 million in fiscal 2024.

New in FY2024

Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information.

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

New in FY2024

Interest expense decreased for fiscal 2024 compared to fiscal 2023 primarily due to maturity of our 2023 Notes in July 2023 and early conversion of our 2025 Notes in fiscal 2024.

New in FY2024

\- 51 \-

New in FY2024

| | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | | | | | 2023 | | | | | | 2022 | | | | | | Change | | | | | | | | |

Dropped from FY2023

We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications, and infrastructure with zero trust principles.

Dropped from FY2023

Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products.

Dropped from FY2023

Our company focuses on delivering value in four fundamental areas:

Dropped from FY2023

We have been recognized as a leader in network firewalls, SSE, and SD-WAN.

Dropped from FY2023

- We enable cloud-native security through our Prisma Cloud platform.

Dropped from FY2023

\- 38 \-

Dropped from FY2023

During fiscal 2023, we introduced several new offerings, including: Cortex XSIAM 1.0, major updates to Prisma Cloud (including three new security modules), Prisma Access 4.0, PAN-OS 11.0, Cloud NGFW for AWS, and Cloud NGFW for Azure.

Dropped from FY2023

For example, in December 2022, we acquired Cider, which we expect will support our Prisma Cloud’s platform approach to securing the entire application security lifecycle from code to cloud.

Dropped from FY2023

\- 39 \-

Dropped from FY2023

We continue to experience supply chain disruption and incur increased costs resulting from inflationary pressures.

Dropped from FY2023

We believe billings provides investors with an important indicator of the health and visibility of our business because it includes subscription and support revenue, which is recognized ratably over the contractual service period, and product revenue, which is recognized at the time of hardware shipment or delivery of software license, provided that all other conditions for revenue recognition have been met.

Dropped from FY2023

We consider billings to be a useful metric for management and investors, particularly if we continue to experience increased sales of subscriptions and strong renewal rates for subscription and support offerings, and as we monitor our near-term cash flows.

Dropped from FY2023

While we believe that billings provides useful information to investors and others in understanding and evaluating our operating results in the same manner as our management, it is important to note that other companies, including companies in our industry, may not use billings, may calculate billings differently, may have different billing frequencies, or may use other financial measures to evaluate their performance, all of which could reduce the usefulness of billings as a comparative measure.

Dropped from FY2023

\- 40 \-

Dropped from FY2023

\- 41 \-

Dropped from FY2023

\- 42 \-

Dropped from FY2023

| EMEA | | | 1,359.6 | | | | | | 1,055.8 | | | | | | 303.8 | | | | | | 28.8 | | % | | | | 1,055.8 | | | | | | 817.3 | | | | | | 238.5 | | | | | | 29.2 | | % |

Dropped from FY2023

| APAC | | | 813.2 | | | | | | 643.1 | | | | | | 170.1 | | | | | | 26.5 | | % | | | | 643.1 | | | | | | 501.3 | | | | | | 141.8 | | | | | | 28.3 | | % |

Dropped from FY2023

Cost of product revenue decreased for fiscal 2023 compared to fiscal 2022 due to a favorable hardware product mix.

Dropped from FY2023

General and administrative expenses increased for fiscal 2023 compared to fiscal 2022 primarily due to increased personnel costs, which grew $23.2 million, largely due to share-based compensation related to our recent acquisitions and headcount growth.

Dropped from FY2023

The increase in general and administrative expense was further driven by slightly higher reserves due to increased receivables as a result of our business growth.

Dropped from FY2023

Interest expense remained relatively flat for fiscal 2023 compared to fiscal 2022.

Dropped from FY2023

Our valuation allowance has caused, and may continue to cause, disproportionate relationships between our overall effective tax rate and other jurisdictional measures.

Dropped from FY2023

We regularly evaluate the need for a valuation allowance.

Dropped from FY2023

Due to recent profitability, a reversal of our valuation allowance in certain jurisdictions in the foreseeable future is reasonably possible.

Dropped from FY2023

Our provision for income taxes for fiscal 2023 was primarily due to U.S. federal and state income taxes, withholding taxes, and foreign income taxes.

Dropped from FY2023

Our effective tax rate varied for fiscal 2023 compared to fiscal 2022, primarily due to our profitability in fiscal 2023 and an increase in U.S. taxes driven by capitalization of research and development expenditures with no offsetting deferred benefit due to our valuation allowance.

Dropped from FY2023

This increase was offset by releases of uncertain tax positions during fiscal 2023 resulting from tax settlements.

Dropped from FY2023

In July 2018, we issued the 2023 Notes with an aggregate principal amount of $1.7 billion.

Dropped from FY2023

The 2023 Notes were converted prior to or settled on the maturity date of July 1, 2023.

Dropped from FY2023

The expiration date of this repurchase authorization was extended to December 31, 2023, and our repurchase program may be suspended or discontinued at any time.

Dropped from FY2023

We have entered into various non-cancelable operating leases primarily for our facilities with original lease periods expiring through the year ending July 31, 2033, with the most significant leases relating to our corporate headquarters in Santa Clara, California.

An excerpt. Shown here: 40 of 143 rewritten, 40 of 66 added and all 32 removed. The counts are complete. For every sentence, read Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in the FY2024 filing and the FY2023 filing.

Item 7A. Quantitative and Qualitative Disclosures About Market Risk

6 rewritten, 3 added, 1 removed, 19 unchanged

Rewritten

[removed: The effect of an immediate] [added: A hypothetical] 10% [removed: adverse] change in foreign exchange rates on monetary assets and liabilities [removed: at July 31, 2023] would not be material to our financial condition or results of [removed: operations.][added: operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, 2024.]

Rewritten

[removed: As of July 31, 2023,] [added: Foreign currency remeasurement gains and losses and] foreign currency transaction gains and losses [removed: and exchange rate fluctuations] have not [removed: been material] [added: had a significant impact] to our consolidated financial statements.

Rewritten

The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and [removed: operating results.][added: results of operations.]

Rewritten

Based on investment positions as of July 31, [removed: 2023,] [added: 2024,] a hypothetical 100 basis point increase in interest rates across all maturities would result in a [removed: $55.5] [added: $97.8] million decline in the fair market value of the portfolio.

Rewritten

Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a [removed: $55.5] [added: $97.8] million increase in the fair market value of the portfolio.

Rewritten

In June 2020, we issued $2.0 billion aggregate principal amount of [removed: 0.375% Convertible Senior Notes due] [added: the] 2025 [removed: (the “2025 Notes”).][added: Notes.]

New in FY2024

We also enter into foreign currency derivative contracts that are not designated as hedging instruments to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies.

New in FY2024

These foreign currency derivative contracts reduce but do not entirely eliminate the effect of foreign exchange rate fluctuations.

New in FY2024

\- 57 \-

Dropped from FY2023

\- 51 \-

Item 1. Business

83 rewritten, 71 added, 49 removed, 205 unchanged

Rewritten

Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by [removed: industry-leading] artificial intelligence [added: (“AI”)] and automation.

Rewritten

- Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, [added: AI Runtime Security,] as well as a cloud-delivered Secure Access Service Edge (“SASE”).

Rewritten

Prisma® Access, our Security Services Edge (“SSE”) solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and [added: securely] enable the cloud-delivered branch.

Rewritten

Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, [added: Advanced] DNS Security, IoT/OT Security, GlobalProtect®, Enterprise Data Loss Prevention (“Enterprise DLP”), [removed: Artificial Intelligence] [added: AI] for [added: IT] Operations (“AIOps”), SaaS [removed: Security API,] [added: Security,] and [removed: SaaS Security Inline.][added: AI Access Security.]

Rewritten

[removed: Panorama®,] [added: Strata Cloud Manager,] our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.

Rewritten

As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, [added: generative AI (“GenAI”) ecosystem,] and the entire cloud native technology stack across the full development [removed: lifecycle;] [added: lifecycle,] from code to [removed: runtime.][added: cloud.]

Rewritten

[removed: For] [added: We also offer our VM-Series and CN-Series virtual firewalls for] inline network security on multi- and hybrid-cloud [removed: environments, we also offer our VM-Series and CN-Series Firewall offerings.][added: environments.]

Rewritten

- We deliver the next generation of security [removed: automation,] [added: operations capabilities that combine] security analytics, endpoint security, [added: automation,] and attack surface management [added: (“ASM”)] solutions through our [removed: Cortex portfolio.][added: Cortex® platform.]

Rewritten

These include Cortex [removed: XSIAM,] [added: XSIAM®,] our [removed: AI] [added: AI-driven] security [removed: automation] [added: operations] platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity [removed: attacks on the endpoint,] [added: attacks,] Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), and Cortex [removed: XpanseTM] [added: Xpanse®] for [removed: attack surface management (“ASM”).][added: ASM.]

Rewritten

These products are delivered as [removed: SaaS] [added: software as a service (“SaaS”)] or software subscriptions.

Rewritten

Threat Intelligence and [removed: Security Consulting] [added: Advisory Services] (Unit 42):

Rewritten

- Unit [removed: 42] [added: 42®] brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers [removed: proactively] manage cyber risk.

Rewritten

Hardware and software firewalls. Our ML-Powered Next Generation Firewalls embed machine learning in the core of the firewall and employ inline deep learning in the cloud, empowering our customers to stop zero-day threats in real time, see and secure their entire enterprise including [removed: IoT,] [added: Internet of Things (“IoT”),] and reduce errors with automatic policy recommendations.

Rewritten

In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and [removed: Quality-of-Service (“QoS”).][added: Quality-of-Service.]

Rewritten

Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and branch offices, to our top-of-the-line [removed: PA-7080,] [added: PA-7500 Series,] which is designed for large-scale data centers and service [removed: provider use.][added: providers.]

Rewritten

Our firewalls come in a hardware form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as [removed: VMware, Inc. (“VMware”),] [added: Broadcom Inc.,] Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and [removed: Google,] [added: Alphabet] Inc. [removed: (“Google”),] [added: (“Alphabet”),] and in Kernel-based Virtual Machine [removed: (“KVM”)/OpenStack] [added: /OpenStack] environments.

Rewritten

Of these subscription offerings, cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, [added: Advanced] DNS Security, IoT/OT Security, SaaS Security Inline, GlobalProtect, Enterprise DLP, [removed: and] AIOps, [added: and AI Runtime Security] are sold as options to our hardware and software firewalls, whereas SaaS Security API, [added: AI Access Security,] Prisma Access, Prisma SD-WAN, [added: Strata Cloud Manager,] Prisma Cloud, Cortex XSIAM, Cortex XDR, Cortex XSOAR, and Cortex Xpanse are sold on a per-user, per-endpoint, or capacity-based [removed: basis.][added: basis—and they can be activated by customers with or without our firewalls.]

Rewritten

Advanced Threat Prevention is the first offering to protect [removed: patient zero] [added: the enterprise] from unknown command and control in real-time.

Rewritten

- [removed: DNS] [added: Advanced DNS] Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress.

Rewritten

It allows our network security platform access to [removed: DNS] [added: Domain Name System (“DNS”)] signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part.

Rewritten

It offers comprehensive DNS attack coverage and includes industry-first protections against multiple emerging DNS-based network [removed: attacks.][added: attacks, including real-time analysis of DNS response to prevent DNS hijacking.]

Rewritten

[removed: *•*Enterprise] [added: - Enterprise] DLP. This cloud-delivered security service provides consistent, reliable protection of sensitive data, such as personally identifiable information [removed: (“PII”)] and intellectual property, for all traffic types, applications, and users.

Rewritten

It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including [removed: GDPR, CCPA, PCI DSS, HIPAA,] [added: the E.U. General Data Protection Regulation, the California Consumer Privacy Act, the Payment Card Industry Data Security Standard , HIPAA (Health Insurance Portability] and [added: Accountability Act) requirements, and] others.

Rewritten

AIOps provides continuous best practice recommendations powered by machine learning [removed: (“ML”)] based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture.

Rewritten

Prisma SD-WAN enables organizations to replace traditional Multiprotocol Label Switching [removed: (“MPLS”)] based WAN architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost.

Rewritten

- Prisma Cloud. Prisma Cloud is a comprehensive [removed: Cloud-Native Application Protection Platform (“CNAPP”),] [added: CNAPP,] securing both cloud-native and lift-and-shift applications across multi- and hybrid-cloud environments.

Rewritten

The platform helps developers prevent risks as they code and build the application, secures the software supply chain and the continuous integration and continuous development (“CI/CD”) pipeline, and provides complete visibility and real-time protection for applications [added: running] in the cloud.

Rewritten

With its code-to-cloud security capabilities, Prisma Cloud [removed: uniquely stitches together] [added: creates] a complete security picture by tracing back thousands of cloud risks and vulnerabilities that occur in the application runtime to their origin in the code-and-build phase of the application.

Rewritten

[removed: Including the recently launched CI/CD security module,] Prisma Cloud’s code-to-cloud CNAPP delivers comprehensive protection for applications and their code, infrastructure (workloads, network, and storage), data, APIs, and associated identities.

Rewritten

[removed: *•*Cortex] [added: - Cortex] XSIAM. This cloud-based [removed: subscription is the AI] [added: AI-driven] security [removed: automation] [added: operations] platform for the modern [removed: SOC, harnessing] [added: SOC harnesses] the power of AI to radically improve security outcomes and transform security operations.

Rewritten

Cortex XSIAM customers can consolidate multiple products into a single unified [removed: platform, including EDR, XDR, SOAR, ASM, user behavior analytics (“UBA”), threat intelligence] platform [removed: (“TIP”), and] [added: that delivers] security information and event [added: management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence] management [removed: (“SIEM”).][added: (“TIM”), identity threat detection and response, and CDR.]

Rewritten

[removed: Using a security-specific data model and applying AI,] Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.

Rewritten

XDR Pro extends endpoint detection and response (“EDR”) to include cross-data [removed: analytics, including] [added: analytics for] network, cloud, and identity data.

Rewritten

- Cortex XSOAR. Available as a [added: stand-alone] cloud-based [removed: subscription or] [added: subscription,] an on-premises appliance, [added: or delivered natively through] Cortex [added: XSIAM, Cortex] XSOAR is a comprehensive [removed: security orchestration automation and response (“SOAR”)] [added: SOAR] offering that unifies playbook automation, case management, real-time collaboration, and [removed: threat intelligence management] [added: TIM] to serve security teams across the incident lifecycle.

Rewritten

[removed: It] [added: Cortex XSOAR] learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations.

Rewritten

- Cortex Xpanse. [removed: This] [added: Available as a stand-alone] cloud-based subscription [added: and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse] provides [removed: attack surface management (“ASM”),] [added: ASM,] which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets.

Rewritten

Our channel partners that operate a Palo Alto Networks Authorized Support Center [removed: (“ASC”)] typically deliver level-one and level-two support.

Rewritten

We also offer a service offering called Focused Services that includes Customer Success Managers [removed: (“CSM”)] to provide support for end-customers with unique or complex support requirements.

Rewritten

Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers [removed: focus on their business before, during,] [added: build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed] and [removed: after a breach.][added: confidence.]

Rewritten

Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation [removed: regarding] [added: based on allegations of] patent [removed: and] [added: infringement or] other [added: violations of] intellectual property rights.

New in FY2024

A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products.

New in FY2024

We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate.

New in FY2024

Our platformization strategy combines various products and services into a tightly integrated architecture and makes security faster, less complex, and more cost-effective.

New in FY2024

We focus on delivering value in four sectors of the cybersecurity industry:

New in FY2024

Strata Cloud Manager includes the Strata Copilot which provides a natural language interface to simplify and accelerate platform management.

New in FY2024

- We deliver scalable and comprehensive security across the cloud application development lifecycle through our Code to CloudTM platform, Prisma Cloud.

New in FY2024

Additionally, Unit 42 offers managed detection and response and managed threat hunting services.

New in FY2024

Many of our existing deployments continue using Panorama as the security management solution, while new deployments benefit from using Strata Cloud Manager instead for managing network security estate—including our Next-Generation Firewalls and SASE—with a cloud-based, unified management interface.

New in FY2024

- AI Access Security. GenAI applications can inadvertently expose sensitive company data, such as intellectual property, trade secrets, source code, financial records and customer information, leading to significant business and compliance risks.

New in FY2024

In addition, public GenAI tools can be exploited to spread malware and compromise cybersecurity defenses.

New in FY2024

AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies and visualize insights across multiple GenAI-specific attributes.

New in FY2024

It prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.

New in FY2024

With native SASE integration, Prisma Access Browser extends Zero Trust to any device—managed or unmanaged—in minutes.

New in FY2024

Prisma Access delivers exceptional user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management.

New in FY2024

With these capabilities, Prisma Access delivers an optimized digital experience and application performance to end users.

New in FY2024

AI Runtime Security:

New in FY2024

- AI applications and large language model (“LLM”) models challenge traditional security.

New in FY2024

Increasingly sophisticated attacks on AI ecosystems require protection from AI applications, models and datasets.

New in FY2024

AI Runtime Security continuously monitors AI applications, models and datasets for potential threats and anomalies.

New in FY2024

It quickly adjusts to evolving attack techniques and detects suspicious activities in real time.

New in FY2024

It shields customers’ AI application ecosystem from AI-specific and conventional network attacks by leveraging real-time, AI-powered security.

New in FY2024

Strata Cloud Manager:

New in FY2024

- Strata Cloud Manager enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE environment—from the cloud, via one unified management interface.

New in FY2024

In addition to getting complete visibility, with Strata Cloud Manager, customers can predict and prevent network health issues, strengthen security, and configure and manage their entire network security estate.

New in FY2024

Strata Copilot, a part of Strata Cloud Manager, helps security teams quickly and easily find, understand and address threats leveraging the power and simplicity of natural language.

New in FY2024

Prisma Cloud does this by consolidating multiple code and cloud security technologies such as Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Discovery and Exposure Management into a single unified platform.

New in FY2024

Further, the Code to Cloud Platform is positioned to secure AI-powered applications for enterprises.

New in FY2024

In March 2024, we announced limited general availability of data security posture management (“DSPM”) capabilities and in May 2024, we released the early preview of AI security posture management (“AI-SPM”) capabilities to our customers.

New in FY2024

These features were made available to all customers in our August 2024 software release.

New in FY2024

Prisma Cloud customers can activate them within the platform to discover, classify, protect, and govern AI-powered applications.

New in FY2024

DSPM and AI-SPM together provide visibility into the entire GenAI ecosystem, identify LLM vulnerabilities, prioritize misconfiguration risks, reduce the risk of data exposure, and surface compliance violations.

New in FY2024

The native integration of Prisma Cloud with Cortex XSIAM is further expanded with the recent addition of cloud detection and response (“CDR”) capabilities, providing a broader context to protect, detect, and respond to advanced cloud threats.

New in FY2024

It also brings together cloud security and security operations teams, fostering strong collaboration.

New in FY2024

CDR is the latest addition to Cortex XSIAM and XDR that addresses the growing need for security teams to respond to cloud threats with purpose-built SOC tools that seamlessly integrate with their security programs.

New in FY2024

Cortex XSIAM integrates these capabilities into a single, converged platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation.

New in FY2024

Our engineering team has deep networking security, cloud security, endpoint security, security operations, and incident response expertise as well as expertise in AI and machine learning capabilities that are applied across these areas.

New in FY2024

During fiscal 2024, we introduced several new offerings, including: Prisma Cloud Darwin release with newly integrated Code to Cloud intelligence capabilities, PAN-OS 11.2 Quasar, Cortex XSIAM 2.0, new Cortex XSIAM features, Prisma SASE 3.0, and Precision AITM.

New in FY2024

For example, in December 2023, we acquired Dig Security Solutions Ltd. ("Dig"), which we expect will enhance our Prisma Cloud capabilities with a DSPM solution; and we acquired Talon Cyber Security Ltd. (“Talon”), which will support Prisma SASE’s approach to provide secure access to business applications for unmanaged and personal devices with an enterprise browser.

New in FY2024

We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights.

New in FY2024

We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect and control the use of our proprietary technology and intellectual property rights.

Dropped from FY2023

We are a leading provider of zero trust solutions, starting with next-generation zero trust network access to secure today’s remote hybrid workforces and extending to securing all users, applications, and infrastructure with zero trust principles.

Dropped from FY2023

Our security solutions are designed to reduce customers’ total cost of ownership by improving operational efficiency and eliminating the need for siloed point products.

Dropped from FY2023

Our company focuses on delivering value in four fundamental areas:

Dropped from FY2023

We have been recognized as a leader in network firewalls, SSE, and SD-WAN.

Dropped from FY2023

- We enable cloud-native security through our Prisma Cloud platform.

Dropped from FY2023

Panorama controls the security, network address translation (“NAT”), QoS, policy-based forwarding, decryption, application override, captive portal, and distributed denial of service/denial of service (“DDoS/DoS”) protection aspects of the network security systems under management.

Dropped from FY2023

Panorama centrally manages device software and associated updates, including SSL-VPN clients, SD-WAN, dynamic content updates, and software licenses.

Dropped from FY2023

Panorama offers network security monitoring through the ability to view logs and run reports for our network security platform in one location without the need to forward the logs and reliably expands log storage for long-term event investigation and analysis.

Dropped from FY2023

A machine learning module derived from the cloud sandbox environment is now delivered inline on the ML-Powered Next-Generation Firewalls to identify the majority of unknown threats without cloud connectivity.

Dropped from FY2023

Our engineering team has deep networking, endpoint, and security expertise and works closely with end-customers to identify their current and future needs.

Dropped from FY2023

During fiscal 2023, we introduced several new offerings, including: Cortex XSIAM 1.0, major updates to Prisma Cloud (including three new security modules), Prisma Access 4.0, PAN-OS 11.0, Cloud NGFW for AWS, and Cloud NGFW for Azure.

Dropped from FY2023

For example, we acquired Cider Security Ltd. (“Cider”), which we expect will support our Prisma Cloud’s platform approach to securing the entire application security lifecycle from code to cloud.

Dropped from FY2023

In particular, leading companies in the enterprise security industry have extensive patent portfolios and are regularly involved in both offensive and defensive litigation.

Dropped from FY2023

We continue to grow our patent portfolio and own intellectual property and related intellectual property rights around the world that relate to our products, services, research and development, and other activities, and our success depends in part upon our ability to protect our core technology and intellectual property.

Dropped from FY2023

We actively seek to protect our global intellectual property rights and to deter unauthorized use of our intellectual property by controlling access to, and use of, our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, end-customers, and partners, and our software is protected by U.S. and international copyright laws.

Dropped from FY2023

In addition, the laws of various foreign countries where our offerings are distributed may not protect our intellectual property rights to the same extent as laws in the United States.

Dropped from FY2023

See “Risk Factors-*Claims by others that we infringe their intellectual property rights could harm our business*,” “Risk Factors-*Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us*,” and “Legal Proceedings” below for additional information.

Dropped from FY2023

Source & Hire. Sourcing diverse talent who possess the skills and capabilities to execute and add value to our culture form the cornerstone of our comprehensive approach to talent acquisition—a philosophy we call “The Way We Hire.” We utilize an array of methods to identify subject matter experts in their respective fields, emphasizing sourcing channels that connect us with underrepresented talents.

Dropped from FY2023

In an effort to foster career growth within Palo Alto Networks, we prioritize internal mobility.

Dropped from FY2023

This allows current employees to progress either through a traditional career path or by exploring roles across various business functions, often culminating in promotions.

Dropped from FY2023

We encourage existing employees to refer qualified individuals for our open positions, thus leveraging the collective networks of our team to attract a diverse range of expertise and perspectives.

Dropped from FY2023

We have made strides to understand job requirements and implement structured interviewing practices to identify candidates of the highest quality.

Dropped from FY2023

By conducting thorough job analyses and creating success profiles, we have developed a deeper understanding of what is required for success in critical roles.

Dropped from FY2023

We equip our hiring managers with essential training to identify and mitigate potential unconscious biases.

Dropped from FY2023

This commitment extends to conducting interviews with diverse panelists and providing a balanced evaluation and quality interview experience for a diverse slate of candidates.

Dropped from FY2023

We remain steadfast in our commitment to fairness, bias reduction, and equal opportunities for all potential hires.

Dropped from FY2023

A key to our hiring process is the Global Hiring Committees, introduced in fiscal 2023.

Dropped from FY2023

These committees play a significant role in elevating our hiring standards by promoting shared understanding, reducing biases, enhancing objectivity, and ensuring the recruitment of diverse talent.

Dropped from FY2023

The Committees foster effective collaboration using a common language and consensus-driven decision-making.

Dropped from FY2023

Our development initiatives are delivered to employees through a comprehensive platform, FLEXLearn.

Dropped from FY2023

Development information about core business elements, working in a distributed hybrid environment, as well as required company-wide compliance training, such as Code of Conduct, privacy and security, anti-discrimination, anti-harassment, and anti-bribery training, is also deployed through the FLEXLearn platform for all employees.

Dropped from FY2023

In addition, FLEXLearn provides employees with events and activities that motivate and spark critical thinking, on topics ranging from inclusion to well-being and collaboration.

Dropped from FY2023

Our comprehensive communication and listening strategy utilizes in-person and technology-enabled channels.

Dropped from FY2023

We share and collect information through corporate and functional “All Hands” meetings, including several meetings specifically focused on employee-centered topics in an “Ask Me Anything” format.

Dropped from FY2023

Digital Displays across our sites, our intranet platform, monthly and weekly email communications, and an active Slack platform provide a regular flow of information to and between employees and leadership.

Dropped from FY2023

In addition to these channels that reach large audiences, we conduct regular executive listening sessions, including small group convenings with our CEO and other C-suite leaders, and ad-hoc pulse surveys to better understand employee engagement, sentiment, well-being, and the ability to transition to a hybrid work model.

Dropped from FY2023

Employee sentiment is also collected from external sources, such as web platforms that crowdsource feedback.

Dropped from FY2023

Employees provide commentary to platforms such as Glassdoor, Comparably, and others and insights from those platforms are used to measure engagement.

Dropped from FY2023

We deeply believe that true diversity exists when we have representation of all ethnicities, genders, orientations and identities, and cultures in our workforce.

Dropped from FY2023

These principles are the foundation of our approach to I&D, which we call P.U.L.S.E.

An excerpt. Shown here: 40 of 83 rewritten, 40 of 71 added and 40 of 49 removed. The counts are complete. For every sentence, read Item 1. Business in the FY2024 filing and the FY2023 filing.

Cover and table of contents

32 rewritten, 10 added, 3 removed, 83 unchanged

Rewritten

For the fiscal year ended July 31, [removed: 2023][added: 2024]

Rewritten

The aggregate market value of voting stock held by non-affiliates of the registrant was [removed: $47,351,509,692] [added: approximately $108.1 billion] as of January 31, [removed: 2023,] [added: 2024,] the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date).

Rewritten

On August [removed: 18, 2023, 308,594,604] [added: 19, 2024, 325.6 million] shares of the registrant’s common stock, $0.0001 par value, were outstanding.

Rewritten

Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s [removed: 2023] [added: 2024] annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, [removed: 2023.][added: 2024.]

Rewritten

| Item 1. | | | [removed: [Business](#i8a1fb889ef014ec6885c8e58d3d08420_13)] [added: [Business](#id0a9ebb26d9d4578997f123b627a595a_13)] | | | [removed: [4](#i8a1fb889ef014ec6885c8e58d3d08420_13)] [added: [4](#id0a9ebb26d9d4578997f123b627a595a_13)] | | |

Rewritten

| Item 1A. | | | [Risk [removed: Factors](#i8a1fb889ef014ec6885c8e58d3d08420_52)] [added: Factors](#id0a9ebb26d9d4578997f123b627a595a_46)] | | | [removed: [14](#i8a1fb889ef014ec6885c8e58d3d08420_52)] [added: [15](#id0a9ebb26d9d4578997f123b627a595a_46)] | | |

Rewritten

| Item 1B. | | | [Unresolved Staff [removed: Comments](#i8a1fb889ef014ec6885c8e58d3d08420_55)] [added: Comments](#id0a9ebb26d9d4578997f123b627a595a_79)] | | | [removed: [35](#i8a1fb889ef014ec6885c8e58d3d08420_55)] [added: [36](#id0a9ebb26d9d4578997f123b627a595a_79)] | | |

Rewritten

| Item 2. | | | [removed: [Properties](#i8a1fb889ef014ec6885c8e58d3d08420_58)] [added: [Properties](#id0a9ebb26d9d4578997f123b627a595a_85)] | | | [removed: [35](#i8a1fb889ef014ec6885c8e58d3d08420_58)] [added: [39](#id0a9ebb26d9d4578997f123b627a595a_85)] | | |

Rewritten

| Item 3. | | | [Legal [removed: Proceedings](#i8a1fb889ef014ec6885c8e58d3d08420_61)] [added: Proceedings](#id0a9ebb26d9d4578997f123b627a595a_88)] | | | [removed: [35](#i8a1fb889ef014ec6885c8e58d3d08420_61)] [added: [39](#id0a9ebb26d9d4578997f123b627a595a_88)] | | |

Rewritten

| Item 4. | | | [Mine Safety [removed: Disclosures](#i8a1fb889ef014ec6885c8e58d3d08420_64)] [added: Disclosures](#id0a9ebb26d9d4578997f123b627a595a_91)] | | | [removed: [35](#i8a1fb889ef014ec6885c8e58d3d08420_64)] [added: [39](#id0a9ebb26d9d4578997f123b627a595a_91)] | | |

Rewritten

| Item 5. | | | [Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#i8a1fb889ef014ec6885c8e58d3d08420_70)] [added: Securities](#id0a9ebb26d9d4578997f123b627a595a_97)] | | | [removed: [36](#i8a1fb889ef014ec6885c8e58d3d08420_70)] [added: [40](#id0a9ebb26d9d4578997f123b627a595a_97)] | | |

Rewritten

| Item 6. | | | [removed: [\[Reserved\]](#i8a1fb889ef014ec6885c8e58d3d08420_73)] [added: [\[Reserved\]](#id0a9ebb26d9d4578997f123b627a595a_103)] | | | [removed: [37](#i8a1fb889ef014ec6885c8e58d3d08420_73)] [added: [42](#id0a9ebb26d9d4578997f123b627a595a_103)] | | |

Rewritten

| Item 7. | | | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#i8a1fb889ef014ec6885c8e58d3d08420_76)] [added: Operations](#id0a9ebb26d9d4578997f123b627a595a_106)] | | | [removed: [38](#i8a1fb889ef014ec6885c8e58d3d08420_76)] [added: [43](#id0a9ebb26d9d4578997f123b627a595a_106)] | | |

Rewritten

| Item 7A. | | | [Quantitative and Qualitative Disclosures About Market [removed: Risk](#i8a1fb889ef014ec6885c8e58d3d08420_160)] [added: Risk](#id0a9ebb26d9d4578997f123b627a595a_190)] | | | [removed: [51](#i8a1fb889ef014ec6885c8e58d3d08420_160)] [added: [57](#id0a9ebb26d9d4578997f123b627a595a_190)] | | |

Rewritten

| Item 8. | | | [Financial Statements and Supplementary [removed: Data](#i8a1fb889ef014ec6885c8e58d3d08420_163)] [added: Data](#id0a9ebb26d9d4578997f123b627a595a_193)] | | | [removed: [52](#i8a1fb889ef014ec6885c8e58d3d08420_163)] [added: [58](#id0a9ebb26d9d4578997f123b627a595a_193)] | | |

Rewritten

| Item 9. | | | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#i8a1fb889ef014ec6885c8e58d3d08420_289)] [added: Disclosure](#id0a9ebb26d9d4578997f123b627a595a_337)] | | | [removed: [92](#i8a1fb889ef014ec6885c8e58d3d08420_289)] [added: [96](#id0a9ebb26d9d4578997f123b627a595a_337)] | | |

Rewritten

| Item 9A. | | | [Controls and [removed: Procedures](#i8a1fb889ef014ec6885c8e58d3d08420_292)] [added: Procedures](#id0a9ebb26d9d4578997f123b627a595a_340)] | | | [removed: [92](#i8a1fb889ef014ec6885c8e58d3d08420_292)] [added: [96](#id0a9ebb26d9d4578997f123b627a595a_340)] | | |

Rewritten

| Item 9B. | | | [Other [removed: Information](#i8a1fb889ef014ec6885c8e58d3d08420_298)] [added: Information](#id0a9ebb26d9d4578997f123b627a595a_346)] | | | [removed: [93](#i8a1fb889ef014ec6885c8e58d3d08420_298)] [added: [97](#id0a9ebb26d9d4578997f123b627a595a_346)] | | |

Rewritten

| Item 9C. | | | [Disclosure Regarding Foreign Jurisdictions That Prevent [removed: Inspections](#i8a1fb889ef014ec6885c8e58d3d08420_301)] [added: Inspections](#id0a9ebb26d9d4578997f123b627a595a_349)] | | | [removed: [93](#i8a1fb889ef014ec6885c8e58d3d08420_301)] [added: [97](#id0a9ebb26d9d4578997f123b627a595a_349)] | | |

Rewritten

| Item 10. | | | [Directors, Executive [removed: Officers](#i8a1fb889ef014ec6885c8e58d3d08420_307) [and] [added: Officers and] Corporate [removed: Governance](#i8a1fb889ef014ec6885c8e58d3d08420_307)] [added: Governance](#id0a9ebb26d9d4578997f123b627a595a_355)] | | | [removed: [94](#i8a1fb889ef014ec6885c8e58d3d08420_307)] [added: [98](#id0a9ebb26d9d4578997f123b627a595a_355)] | | |

Rewritten

| Item 11. | | | [Executive [removed: Compensation](#i8a1fb889ef014ec6885c8e58d3d08420_310)] [added: Compensation](#id0a9ebb26d9d4578997f123b627a595a_358)] | | | [removed: [94](#i8a1fb889ef014ec6885c8e58d3d08420_310)] [added: [98](#id0a9ebb26d9d4578997f123b627a595a_358)] | | |

Rewritten

| Item 12. | | | [Security Ownership of Certain Beneficial Owners and Management and Related [removed: Stockholder](#i8a1fb889ef014ec6885c8e58d3d08420_313) [](#i8a1fb889ef014ec6885c8e58d3d08420_313)[Matters](#i8a1fb889ef014ec6885c8e58d3d08420_313)] [added: Stockholder Matters](#id0a9ebb26d9d4578997f123b627a595a_361)] | | | [removed: [94](#i8a1fb889ef014ec6885c8e58d3d08420_313)] [added: [98](#id0a9ebb26d9d4578997f123b627a595a_361)] | | |

Rewritten

| Item 13. | | | [Certain Relationships and Related Transactions, and Director [removed: Independence](#i8a1fb889ef014ec6885c8e58d3d08420_316)] [added: Independence](#id0a9ebb26d9d4578997f123b627a595a_364)] | | | [removed: [94](#i8a1fb889ef014ec6885c8e58d3d08420_316)] [added: [98](#id0a9ebb26d9d4578997f123b627a595a_364)] | | |

Rewritten

| Item 14. | | | [Principal Accountant Fees and [removed: Services](#i8a1fb889ef014ec6885c8e58d3d08420_319)] [added: Services](#id0a9ebb26d9d4578997f123b627a595a_367)] | | | [removed: [94](#i8a1fb889ef014ec6885c8e58d3d08420_319)] [added: [98](#id0a9ebb26d9d4578997f123b627a595a_367)] | | |

Rewritten

| Item 15. | | | [Exhibits and Financial Statement [removed: Schedules](#i8a1fb889ef014ec6885c8e58d3d08420_325)] [added: Schedules](#id0a9ebb26d9d4578997f123b627a595a_373)] | | | [removed: [95](#i8a1fb889ef014ec6885c8e58d3d08420_325)] [added: [99](#id0a9ebb26d9d4578997f123b627a595a_373)] | | |

Rewritten

| Item 16. | | | [Form 10-K [removed: Summary](#i8a1fb889ef014ec6885c8e58d3d08420_3258)] [added: Summary](#id0a9ebb26d9d4578997f123b627a595a_376)] | | | [removed: [99](#i8a1fb889ef014ec6885c8e58d3d08420_3258)] [added: [103](#id0a9ebb26d9d4578997f123b627a595a_376)] | | |

Rewritten

This Annual Report on Form 10-K, [removed: including] [added: including, without limitation,] the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934.

Rewritten

[removed: The] [added: Forward-looking statements generally can be identified by] words [added: such as “anticipate,”] “believe,” [removed: “may,” “will,” “potentially,” “estimate,”] “continue,” [removed: “anticipate,” “intend,”] “could,” [removed: “would,” “project,” “plan,”] [added: “estimate,”] “expect,” [added: “intend,” “may,” “plan,” “potentially,” “projects,” “will,” “will be,” “will continue,” “will likely result,” “would,”] and similar expressions that convey uncertainty of future events or [removed: outcomes are intended to identify forward-looking statements.][added: outcomes.]

Rewritten

- statements regarding [removed: trends in billings,] [added: expected profitability,] our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;

Rewritten

- [removed: our] expectations regarding future investments in research and development and product development, customer support, in our employees and in our sales force, including expectations regarding growth in our sales headcount;

Rewritten

- [removed: our expectation] [added: expectations] that we will continue to expand our global presence;

Rewritten

- the timing and amount of capital expenditures and share repurchases; [removed: and]

New in FY2024

| Item 1C. | | | [Cybersecurity](#id0a9ebb26d9d4578997f123b627a595a_82) | | | [37](#id0a9ebb26d9d4578997f123b627a595a_82) | | |

New in FY2024

| | | | [Signatures](#id0a9ebb26d9d4578997f123b627a595a_379) | | | [104](#id0a9ebb26d9d4578997f123b627a595a_379) | | |

New in FY2024

- expectations regarding the cybersecurity landscape;

New in FY2024

- expectations regarding our platformization strategy and related progress and opportunities;

New in FY2024

- expectations regarding annual recurring revenue and product development strategy;

New in FY2024

- expectations regarding artificial intelligence;

New in FY2024

- expectations regarding our strategic partnerships;

New in FY2024

- the performance advantages of our products and subscription and support offerings and the potential benefits to our customers;

New in FY2024

- the effects of worldwide economic and geopolitical conditions, including but not limited to hostilities in Israel and the surrounding region, inflation, interest rate levels, growth rates and other conditions, on our operating and financial results and performance;

New in FY2024

- the effects of litigation or regulatory developments involving us or affecting our industry; and

Dropped from FY2023

| | | | [Signatures](#i8a1fb889ef014ec6885c8e58d3d08420_328) | | | [100](#i8a1fb889ef014ec6885c8e58d3d08420_328) | | |

Dropped from FY2023

- our expectation that we will expand our facilities or add new facilities as we add employees and enter new geographic markets;

Dropped from FY2023

- our expectation that we will increase our customer financing activities;

Item 1B. Unresolved Staff Comments

0 rewritten, 1 added, 0 removed, 1 unchanged

New in FY2024

\- 36 \-

Item 1C. Cybersecurity

0 rewritten, 42 added, 0 removed, 0 unchanged

New section this year

New in FY2024

As a global cybersecurity provider, cybersecurity risk management is an integral part of our overall enterprise risk management program.

New in FY2024

We recognize the critical importance that a strong cybersecurity risk management program plays in maintaining the trust and confidence of our customers, end users, business partners, stockholders and employees.

New in FY2024

We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems, data, or information assets.

New in FY2024

Cybersecurity Risk Management and Strategy

New in FY2024

Our cybersecurity risk management program includes written policies, standards, and procedures for maintaining data privacy, product security and information security to mitigate cybersecurity risks, and to identify, evaluate and respond to cybersecurity threats, vulnerabilities and incidents.

New in FY2024

Our cybersecurity risk management program and strategy is implemented across several areas, which include, but are not limited to, the following:

New in FY2024

- Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information systems, data, and information assets.

New in FY2024

The organizational, administrative and technical measures we implement are based on recognized security frameworks established by the National Institute of Standards and Technology, security measures aligned with the ISO/IEC 27000 series of standards, and other generally recognized industry standards.

New in FY2024

The program is assessed regularly and in light of new and emerging cybersecurity risks.

New in FY2024

- Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to prevent and detect cybersecurity threats across the network, endpoint and cloud.

New in FY2024

We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run internal and external network scans at least weekly and after any meaningful change in our network configuration.

New in FY2024

We conduct regular application security assessments, including our assessments for internet-facing applications that collect, transmit, or display end user data.

New in FY2024

We also employ tooling in certain areas to help prevent deviations from policy.

New in FY2024

- Incident Response and Reporting. We maintain incident response and recovery protocols to enable prompt, effective and orderly identification, evaluation, management, and disposition of actual and potential security threats and incidents, including for purposes of escalation and internal and external-notification steps.

New in FY2024

We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, communications and accounting, that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition.

New in FY2024

This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product officer, chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”).

New in FY2024

The protocols also establish steps designed to publicly report and/or alert external stakeholders as and when required by applicable law or otherwise determined appropriate.

New in FY2024

- Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.

New in FY2024

This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic basis.

New in FY2024

- Risk and Readiness Assessments. We engage in at least quarterly assessments and testing of the effectiveness of our cybersecurity risk management program and incident response protocols that are designed to identify and evaluate vulnerabilities and weaknesses, address cybersecurity threats and test our readiness to respond to cybersecurity incidents.

New in FY2024

These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, and tabletop exercises.

New in FY2024

We regularly engage third parties to perform assessments on our cybersecurity measures, such as audits and independent reviews of our compliance with various security compliance standards, including those established by the American Institute of Certified Public Accountants, operating effectiveness and penetration tests.

New in FY2024

The results of such assessments are reported to management and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.

New in FY2024

- Awareness and Training. We provide regular training for educating employees about corporate policies and procedures and information security designed to provide our employees with knowledge of best practices and effective tools for safeguarding our data and assets and reducing security risks based on the human threat vector.

New in FY2024

Our information security compliance training, data protection training, and code of conduct training is mandatory for all employees.

New in FY2024

\- 37 \-

New in FY2024

- Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of directors’ has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee.

New in FY2024

As part of our cybersecurity risk management procedures, senior members of management and the Security Committee are informed regarding security events based on established reporting thresholds, and are provided ongoing updates regarding any such meaningful threat or incident.

New in FY2024

We have not identified any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially impacted or are reasonably likely to materially impact us, including our business strategy, results of operations, or financial condition, to date.

New in FY2024

However, we face ongoing and increasing cybersecurity risks, including from threat actors that are becoming more sophisticated and effective over time, and we can provide no assurance that there will not be incidents in the future or that past or future threats or incidents will not materially affect us, including our business strategy, results of operations, or financial conditions.

New in FY2024

For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “*A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.*”

New in FY2024

Cybersecurity Governance

New in FY2024

The Security Committee, which is composed of all of our independent directors, facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks.

New in FY2024

The Security Committee reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities.

New in FY2024

The Security Committee meets quarterly to review with our chief information security officer and other members of management, which may include our chief executive officer, chief product officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.

New in FY2024

Management is responsible for day-to-day risk management activities, including identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs.

New in FY2024

Our chief information security officer is responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” Our chief information security officer receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks.

New in FY2024

In addition, as described in further detail above under the heading “Cybersecurity Risk Management and Strategy,” a cross functional team is involved in assessing and managing the risks from cybersecurity threats and incidents, and reporting information about risks to the Security Committee.

New in FY2024

Our information security team consists of dedicated personnel who are experienced information systems security professionals and information security managers with many years of experience across a variety of technology sub-specialties.

New in FY2024

In particular, our chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 20 years, including having previously served as the chief security officer of two other publicly traded technology companies.

An excerpt. Shown here: all 0 rewritten, 40 of 42 added and all 0 removed. The counts are complete. For every sentence, read Item 1C. Cybersecurity in the FY2024 filing.

Item 4. Mine Safety Disclosures

0 rewritten, 1 added, 1 removed, 2 unchanged

New in FY2024

\- 39 \-

Dropped from FY2023

\- 35 \-

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

13 rewritten, 9 added, 6 removed, 19 unchanged

Rewritten

Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.” Prior to October 22, 2021, our common stock traded on the New York Stock Exchange [removed: (“NYSE”)] under the symbol “PANW.”

Rewritten

As of August [removed: 18, 2023,] [added: 19, 2024,] there were [removed: 414] [added: 502] holders of record of our common stock.

Rewritten

[removed: During] [added: Additionally, during] the three months ended July 31, [removed: 2023,] [added: 2024,] we issued a total of [removed: 3,569] [added: 12,841] shares of our unregistered common stock in connection with certain of our acquisitions (the [removed: “Transactions”).][added: “Transactions”).The Transactions did not involve any underwriters, any underwriting discounts or commissions, or any public offering.]

Rewritten

The issuances of the securities pursuant to the Transactions were exempt from registration under the Securities Act [removed: of 1933, as amended (the “Act”)] by virtue of Section 4(a)(2) of the Act and Rule 506 of Regulation D promulgated thereunder.

Rewritten

In December 2020, August 2021, [removed: and] August 2022, [added: and November 2023,] we announced additional $700.0 million, $676.1 million, [removed: and] $915.0 [added: million, and $316.7] million increases to this share repurchase program, respectively, bringing the total authorization to [removed: $3.3] [added: $3.6] billion, with [removed: $750.0] [added: $500.0] million remaining as of July 31, [removed: 2023.][added: 2024.]

Rewritten

The expiration date of this repurchase authorization was extended to December 31, [removed: 2023,] [added: 2024,] and our repurchase program may be suspended or discontinued at any time.

Rewritten

During the three months ended July 31, [removed: 2023,] [added: 2024,] we did not repurchase any shares pursuant to our share repurchase program.

Rewritten

Between [added: May 1, 2024 and May 31, 2024,] June 1, [removed: 2023] [added: 2024] and June 30, [removed: 2023] [added: 2024,] and July 1, [removed: 2023] [added: 2024] and July 31, [removed: 2023,] [added: 2024,] shares of restricted stock were delivered by certain employees upon vesting of equity awards to satisfy tax withholding requirements.

Rewritten

The average value of shares delivered to satisfy tax withholding requirements during these periods were [removed: $246.53] [added: $308.10] per [removed: share] [added: share, $317.02 per share,] and [removed: $243.33] [added: $330.89] per share, respectively.

Rewritten

This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index for the five years ended July 31, [removed: 2023.][added: 2024.]

Rewritten

This performance graph assumes $100 was invested on July 31, [removed: 2018,] [added: 2019,] in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index, and assumes the reinvestment of any dividends.

Rewritten

[removed: ![4855](https://www.sec.gov/Archives/edgar/data/1327567/000132756723000024/panw-20230731_g1.jpg)][added: ![4495](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panw-20240731_g1.jpg)]

Rewritten

| Company/Index | | | | | | [removed: 7/31/2018] [added: 7/31/2019] | | | | | | [removed: 7/31/2019] [added: 7/31/2020] | | | | | | [removed: 7/31/2020] [added: 7/31/2021] | | | | | | [removed: 7/31/2021] [added: 7/31/2022] | | | | | | [removed: 7/31/2022] [added: 7/31/2023] | | | | | | [removed: 7/31/2023] [added: 7/31/2024] | | |

New in FY2024

During the three months ended July 31, 2024, holders of the 2025 Notes converted $199.6 million in aggregate principal amount of the 2025 Notes, which we repaid in cash.

New in FY2024

We also issued 1.3 million shares of our unregistered common stock to the holders of the 2025 Notes for the conversion value in excess of the principal amount.

New in FY2024

These shares of our common stock were issued in reliance on the exemption from registration provided by Section 3(a)(9) of the Securities Act of 1933, as amended (the “Securities Act”).

New in FY2024

\- 40 \-

New in FY2024

\- 41 \-

New in FY2024

| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 112.97 | | | | | $ | 176.15 | | | | | $ | 220.31 | | | | | $ | 331.01 | | | | | $ | 430.03 | |

New in FY2024

| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 140.37 | | | | | $ | 193.97 | | | | | $ | 169.14 | | | | | $ | 207.66 | | | | | $ | 257.35 | |

New in FY2024

| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 111.96 | | | | | $ | 152.76 | | | | | $ | 145.67 | | | | | $ | 164.63 | | | | | $ | 201.10 | |

New in FY2024

| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 138.91 | | | | | $ | 194.51 | | | | | $ | 183.79 | | | | | $ | 233.14 | | | | | $ | 315.19 | |

Dropped from FY2023

The Transactions did not involve any underwriters, any underwriting discounts or commissions, or any public offering.

Dropped from FY2023

\- 36 \-

Dropped from FY2023

| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 114.26 | | | | | $ | 129.08 | | | | | $ | 201.28 | | | | | $ | 251.74 | | | | | $ | 378.23 | |

Dropped from FY2023

| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 109.74 | | | | | $ | 154.04 | | | | | $ | 212.86 | | | | | $ | 185.61 | | | | | $ | 227.88 | |

Dropped from FY2023

| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 107.99 | | | | | $ | 120.90 | | | | | $ | 164.96 | | | | | $ | 157.31 | | | | | $ | 177.78 | |

Dropped from FY2023

| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 115.72 | | | | | $ | 160.75 | | | | | $ | 225.10 | | | | | $ | 212.69 | | | | | $ | 269.79 | |

Item 6. [Reserved]

0 rewritten, 1 added, 1 removed, 0 unchanged

New in FY2024

\- 42 \-

Dropped from FY2023

\- 37 \-

Item 8. Financial Statements and Supplementary Data

435 rewritten, 226 added, 153 removed, 867 unchanged

Rewritten

| [Reports of Independent Registered Public Accounting [removed: Firm](#i8a1fb889ef014ec6885c8e58d3d08420_166)] [added: Firm](#id0a9ebb26d9d4578997f123b627a595a_196)] (PCAOB ID: 42) | | | [removed: [53](#i8a1fb889ef014ec6885c8e58d3d08420_166)] [added: [59](#id0a9ebb26d9d4578997f123b627a595a_196)] | | |

Rewritten

| [Consolidated Balance [removed: Sheets](#i8a1fb889ef014ec6885c8e58d3d08420_175)] [added: Sheets](#id0a9ebb26d9d4578997f123b627a595a_205)] | | | [removed: [56](#i8a1fb889ef014ec6885c8e58d3d08420_175)] [added: [62](#id0a9ebb26d9d4578997f123b627a595a_205)] | | |

Rewritten

| [Consolidated Statements of [removed: Operations](#i8a1fb889ef014ec6885c8e58d3d08420_178)] [added: Operations](#id0a9ebb26d9d4578997f123b627a595a_208)] | | | [removed: [57](#i8a1fb889ef014ec6885c8e58d3d08420_178)] [added: [63](#id0a9ebb26d9d4578997f123b627a595a_208)] | | |

Rewritten

| [Consolidated Statements of Comprehensive Income [removed: (Loss)](#i8a1fb889ef014ec6885c8e58d3d08420_181)] [added: (Loss)](#id0a9ebb26d9d4578997f123b627a595a_211)] | | | [removed: [58](#i8a1fb889ef014ec6885c8e58d3d08420_181)] [added: [64](#id0a9ebb26d9d4578997f123b627a595a_211)] | | |

Rewritten

| [Consolidated Statements of Stockholders’ [removed: Equity](#i8a1fb889ef014ec6885c8e58d3d08420_184)] [added: Equity](#id0a9ebb26d9d4578997f123b627a595a_223)] | | | [removed: [59](#i8a1fb889ef014ec6885c8e58d3d08420_184)] [added: [65](#id0a9ebb26d9d4578997f123b627a595a_223)] | | |

Rewritten

| [Consolidated Statements of Cash [removed: Flows](#i8a1fb889ef014ec6885c8e58d3d08420_187)] [added: Flows](#id0a9ebb26d9d4578997f123b627a595a_226)] | | | [removed: [60](#i8a1fb889ef014ec6885c8e58d3d08420_187)] [added: [66](#id0a9ebb26d9d4578997f123b627a595a_226)] | | |

Rewritten

| [Notes to Consolidated Financial [removed: Statements](#i8a1fb889ef014ec6885c8e58d3d08420_190)] [added: Statements](#id0a9ebb26d9d4578997f123b627a595a_229)] | | | [removed: [62](#i8a1fb889ef014ec6885c8e58d3d08420_190)] [added: [67](#id0a9ebb26d9d4578997f123b627a595a_229)] | | |

Rewritten

We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2023,] [added: 2024,] and the related notes (collectively referred to as the “consolidated financial statements”).

Rewritten

In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] and the results of its operations and its cash flows for each of the three years in the period ended July 31, [removed: 2023,] [added: 2024,] in conformity with U.S. generally accepted accounting principles.

Rewritten

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, [removed: 2023,] [added: 2024,] based on criteria established in Internal [removed: Control-Integrated] [added: Control—Integrated] Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 [removed: framework)] [added: framework),] and our report dated September [removed: 1, 2023] [added: 6, 2024] expressed an unqualified opinion thereon.

Rewritten

| *Description* *of the Matter* | | | As described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were [added: certain customer arrangements with] nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition. | | |

Rewritten

San [removed: Jose,] [added: Mateo,] California

Rewritten

We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, [removed: 2023,] [added: 2024,] based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria).

Rewritten

In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, [removed: 2023,] [added: 2024,] based on the COSO criteria.

Rewritten

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, [removed: 2023] [added: 2024] and [removed: 2022,] [added: 2023,] the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2023,] [added: 2024,] and the related notes and our report dated September [removed: 1, 2023] [added: 6, 2024] expressed an unqualified opinion thereon.

Rewritten

The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting included in the accompanying Management’s [added: Annual] Report on Internal Control over Financial Reporting.

Rewritten

| | | | [added: 2024 | | | | | |] 2023 | | | | | | 2022 | | |

Rewritten

| Cash and cash equivalents | | | $ | [added: 1,535.2 | | | | | $ |] 1,135.3 | | | | | $ | 2,118.5 | |

Rewritten

| Short-term investments | | | [removed: 1,254.7] [added: 1,043.6] | | | | | | [removed: 1,516.0] [added: 1,254.7] | | |

Rewritten

| Accounts receivable, net of allowance for credit losses of [removed: $7.8] [added: $7.5] and [removed: $8.9 at] [added: $7.8 as of] July 31, [removed: 2023] [added: 2024] and July 31, [removed: 2022,] [added: 2023,] respectively | | | [removed: 2,463.2] [added: 2,618.6] | | | | | | [removed: 2,142.5] [added: 2,463.2] | | |

Rewritten

| Short-term financing receivables, net | | | [removed: 388.8] [added: 725.9] | | | | | | [removed: 111.3] [added: 388.8] | | |

Rewritten

| Short-term deferred contract costs | | | [removed: 339.2] [added: 369.0] | | | | | | [removed: 317.7] [added: 339.2] | | |

Rewritten

| Prepaid expenses and other current assets | | | [removed: 466.8] [added: 557.4] | | | | | | [removed: 208.9] [added: 466.8] | | |

Rewritten

| Total current assets | | | [removed: 6,048.0] [added: 6,849.7] | | | | | | [removed: 6,414.9] [added: 6,048.0] | | |

Rewritten

| Property and equipment, net | | | [removed: 354.5] [added: 361.1] | | | | | | [removed: 357.8] [added: 354.5] | | |

Rewritten

| Operating lease right-of-use assets | | | [removed: 263.3] [added: 385.9] | | | | | | [removed: 242.0] [added: 263.3] | | |

Rewritten

| Long-term investments | | | [removed: 3,047.9] [added: 4,173.2] | | | | | | [removed: 1,051.9] [added: 3,047.9] | | |

Rewritten

| Long-term financing receivables, net | | | [removed: 653.3] [added: 1,182.1] | | | | | | [removed: 192.1] [added: 653.3] | | |

Rewritten

| Long-term deferred contract costs | | | [removed: 547.1] [added: 562.0] | | | | | | [removed: 550.1] [added: 547.1] | | |

Rewritten

| Goodwill | | | [removed: 2,926.8] [added: 3,350.1] | | | | | | [removed: 2,747.7] [added: 2,926.8] | | |

Rewritten

| Intangible assets, net | | | [removed: 315.4] [added: 374.9] | | | | | | [removed: 384.5] [added: 315.4] | | |

Rewritten

| Total assets | | | $ | [removed: 14,501.1] [added: 19,990.9] | | | | | $ | [removed: 12,253.6] [added: 14,501.1] | |

Rewritten

| Accounts payable | | | $ | [removed: 132.3] [added: 116.3] | | | | | $ | [removed: 128.0] [added: 132.3] | |

Rewritten

| Accrued compensation | | | [removed: 548.3] [added: 554.7] | | | | | | [removed: 461.1] [added: 548.3] | | |

Rewritten

| Accrued and other liabilities | | | [removed: 390.8] [added: 506.7] | | | | | | [removed: 399.2] [added: 390.8] | | |

Rewritten

| Deferred revenue | | | [removed: 4,674.6] [added: 5,541.1] | | | | | | [removed: 3,641.2] [added: 4,674.6] | | |

Rewritten

| Convertible senior notes, net | | | [removed: 1,991.5] [added: 963.9] | | | | | | [removed: 3,676.8] [added: 1,991.5] | | |

Rewritten

| Total current liabilities | | | [removed: 7,737.5] [added: 7,682.7] | | | | | | [removed: 8,306.3] [added: 7,737.5] | | |

Rewritten

| Long-term deferred revenue | | | [removed: 4,621.8] [added: 5,939.4] | | | | | | [removed: 3,352.8] [added: 4,621.8] | | |

Rewritten

| Long-term operating lease liabilities | | | [removed: 279.2] [added: 380.5] | | | | | | [removed: 276.1] [added: 279.2] | | |

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

September 6, 2024

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

San Mateo, California

New in FY2024

September 6, 2024

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| | | | 2024 | | | | | | 2023 | | |

New in FY2024

| Deferred tax assets | | | 2,399.0 | | | | | | 23.1 | | |

New in FY2024

| Other assets | | | 352.9 | | | | | | 321.7 | | |

New in FY2024

| Deferred tax liabilities | | | 387.7 | | | | | | 28.1 | | |

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| Net income (loss) | | | $ | 2,577.6 | | | | | $ | 439.7 | | | | | $ | (267.0) | |

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| Net income | | | — | | | | | | — | | | | | | — | | | | | | 2,577.6 | | | | | | 2,577.6 | | |

New in FY2024

| Other comprehensive income | | | — | | | | | | — | | | | | | 41.6 | | | | | | — | | | | | | 41.6 | | |

New in FY2024

| Settlement of convertible notes | | | 7.0 | | | | | | (2.6) | | | | | | — | | | | | | — | | | | | | (2.6) | | |

New in FY2024

| Settlement of note hedges | | | (7.0) | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | |

New in FY2024

| Settlement of warrants | | | 9.0 | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | |

New in FY2024

| Balance as of July 31, 2024 | | | 325.1 | | | | | | $ | 3,821.1 | | | | | $ | (1.6) | | | | | $ | 1,350.2 | | | | | $ | 5,169.7 | |

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| Net income (loss) | | | $ | 2,577.6 | | | | | $ | 439.7 | | | | | $ | (267.0) | |

New in FY2024

| Deferred income taxes | | | (2,033.7) | | | | | | 12.5 | | | | | | (3.1) | | |

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

Certain certificates of deposit, time deposits, and overnight sweep accounts recorded in cash and cash equivalents and short-term investments are stated at their carrying amounts, which approximate fair value due to their short maturities.

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

In the event the underlying hedged transactions do not occur, or it becomes probable that they will not occur within the defined hedge period, the gains or losses on these related cash flow hedges are recognized in other income, net on our consolidated statements of operations.

New in FY2024

We also enter into foreign currency derivative contracts to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies.

New in FY2024

These derivatives are not designated as hedging instruments for accounting purposes, and the related gains and losses are recorded in other income, net on our consolidated statements of operations.

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

We adopted the new debt guidance using the modified-retrospective approach.

New in FY2024

The adoption of this standard resulted in an increase to convertible senior notes, net of $444.3 million, a decrease to accumulated deficit of $266.7 million, a decrease to additional paid-in capital of $581.9 million, and a decrease to temporary equity of $129.1 million on August 1, 2021.

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

Recently Issued Accounting Pronouncements

New in FY2024

*Segment Reporting*

New in FY2024

In November 2023, the Financial Accounting Standards Board (“FASB”) issued authoritative guidance that expands annual and interim disclosure requirements for reportable segments, primarily through enhanced disclosures about significant segment expenses.

Dropped from FY2023

| | | | | | |

Dropped from FY2023

| --- | --- | --- | --- | --- | --- |

Dropped from FY2023

\- 52 \-

Dropped from FY2023

\- 53 \-

Dropped from FY2023

September 1, 2023

Dropped from FY2023

\- 54 \-

Dropped from FY2023

\- 55 \-

Dropped from FY2023

| | | | | | | | | | | | |

Dropped from FY2023

| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |

Dropped from FY2023

| Other assets | | | 344.8 | | | | | | 312.6 | | |

Dropped from FY2023

\- 56 \-

Dropped from FY2023

\- 57 \-

Dropped from FY2023

| Balance as of July 31, 2020 | | | 288.8 | | | | | | $ | 2,259.2 | | | | | $ | 10.5 | | | | | $ | (1,167.9) | | | | | $ | 1,101.8 | |

Dropped from FY2023

| Net loss | | | — | | | | | | — | | | | | | — | | | | | | (498.9) | | | | | | (498.9) | | |

Dropped from FY2023

| Other comprehensive loss | | | — | | | | | | — | | | | | | (20.4) | | | | | | — | | | | | | (20.4) | | |

Dropped from FY2023

| Issuance of common and restricted common stock in connection with acquisitions | | | 4.0 | | | | | | 340.7 | | | | | | — | | | | | | — | | | | | | 340.7 | | |

Dropped from FY2023

| Temporary equity reclassification | | | — | | | | | | (129.1) | | | | | | — | | | | | | — | | | | | | (129.1) | | |

Dropped from FY2023

| CONSOLIDATED STATEMENTS OF CASH FLOWS (In millions) | | | | | | | | | | | | | | | | | |

Dropped from FY2023

| Repayments of convertible senior notes attributable to debt discount | | | — | | | | | | — | | | | | | (0.1) | | |

Dropped from FY2023

| Payments for debt issuance costs | | | — | | | | | | — | | | | | | (0.2) | | |

Dropped from FY2023

| Restricted cash included in other assets | | | — | | | | | | — | | | | | | 0.5 | | |

Dropped from FY2023

Gains or losses related to non-designated derivative instruments are recognized in other income, net on our consolidated statements of operations for each period until the instrument matures, is terminated, is re-designated as a qualified cash flow hedge, or is sold.

Dropped from FY2023

| | | | July 31, 2022 | | | | | | | | | | | | | | | | | | | | |

Dropped from FY2023

| Certificates of deposit | | | $ | 155.3 | | | | | $ | — | | | | | $ | — | | | | | $ | 155.3 | |

Dropped from FY2023

| Certificates of deposit | | | $ | 116.5 | | | | | $ | — | | | | | $ | (0.1) | | | | | $ | 116.4 | |

Dropped from FY2023

| Corporate debt securities | | | 1,276.8 | | | | | | 1.3 | | | | | | (11.9) | | | | | | 1,266.2 | | |

Dropped from FY2023

| U.S. government and agency securities | | | 928.1 | | | | | | 0.1 | | | | | | (11.8) | | | | | | 916.4 | | |

Dropped from FY2023

| Non-U.S. government and agency securities | | | 17.6 | | | | | | — | | | | | | (0.2) | | | | | | 17.4 | | |

Dropped from FY2023

| Asset-backed securities | | | 173.4 | | | | | | 0.2 | | | | | | (1.1) | | | | | | 172.5 | | |

Dropped from FY2023

| Total available-for-sale investments | | | $ | 2,591.5 | | | | | $ | 1.6 | | | | | $ | (25.2) | | | | | $ | 2,567.9 | |

Dropped from FY2023

| Total | | | $ | 4,490.5 | | | | | $ | 4,454.0 | |

Dropped from FY2023

Our financing receivables portfolio primarily consists of high-quality investment-grade receivables as of July 31, 2023 and 2022.

Dropped from FY2023

| | | | Amount | | |

Dropped from FY2023

The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation.

Dropped from FY2023

| | | | Fair Value | | | | | | Estimated Useful Life | | |

Dropped from FY2023

Fiscal 2021

Dropped from FY2023

*Bridgecrew Inc.*

Dropped from FY2023

We expect the acquisition will expand our Prisma Cloud offering to deliver security across the full application lifecycle.

Dropped from FY2023

| Cash | | | $ | 155.9 | |

Dropped from FY2023

| Total | | | $ | 156.9 | |

An excerpt. Shown here: 40 of 435 rewritten, 40 of 226 added and 40 of 153 removed. The counts are complete. For every sentence, read Item 8. Financial Statements and Supplementary Data in the FY2024 filing and the FY2023 filing.

Item 9A. Controls and Procedures

6 rewritten, 2 added, 1 removed, 6 unchanged

Rewritten

Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule [removed: 13a-15] [added: 13a-15(e)] under the Securities Exchange Act of 1934, as amended (the “Exchange Act”).

Rewritten

Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, [removed: 2023,] [added: 2024,] our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.

Rewritten

Our management assessed the effectiveness of our internal control over financial reporting as of July 31, [removed: 2023,] [added: 2024,] based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework).

Rewritten

Based on that assessment, management concluded that, as of July 31, [removed: 2023,] [added: 2024,] our internal control over financial reporting was effective.

Rewritten

The effectiveness of our internal control over financial reporting as of July 31, [removed: 2023] [added: 2024] has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their report which is included in Part II, Item 8 of this Annual Report on Form 10-K.

Rewritten

There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the quarter ended July 31, [removed: 2023] [added: 2024] that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

New in FY2024

\- 96 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

Dropped from FY2023

\- 92 \-

Item 9B. Other Information

1 rewritten, 0 added, 7 removed, 1 unchanged

Rewritten

[removed: Set forth below is certain information regarding] [added: No directors or officers, as defined in] Rule [added: 16a-1(f), adopted, modified and/or terminated a “Rule] 10b5-1 trading [removed: plans adopted by our directors and officers (as] [added: arrangement” or a “non-Rule 10b5-1 trading arrangement,” as] defined in [removed: Rule 16a-1(f))] [added: Regulation S-K Item 408,] during the fourth quarter of fiscal [removed: 2023.][added: 2024.]

Dropped from FY2023

The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).

Dropped from FY2023

| | | | | | | | | | | | | | | | | | | | | | | | | | | |

Dropped from FY2023

| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |

Dropped from FY2023

| Name | | | | | | Title | | | | | | Date Plan Was Adopted | | | | | | Expiration Date | | | | | | Total Amount of Common Stock to be Sold Under the Plan | | |

Dropped from FY2023

| Nikesh Arora | | | | | | Chairman and Chief Executive Officer | | | | | | June 8, 2023 | | | | | | August 30, 2024 or when all shares have been sold | | | | | | 2,000,000 | | |

Dropped from FY2023

| William “BJ” Jenkins, Jr. | | | | | | President | | | | | | May 26, 2023 | | | | | | June 29, 2024 or when all shares have been sold | | | | | | 13,000 | | |

Dropped from FY2023

No other officers or directors, as defined in Rule 16a-1(f), adopted, modified and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal 2023.

Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections

0 rewritten, 2 added, 1 removed, 2 unchanged

New in FY2024

\- 97 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

Dropped from FY2023

\- 93 \-

Item 10. Directors, Executive Officers and Corporate Governance

1 rewritten, 0 added, 0 removed, 0 unchanged

Rewritten

The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our [removed: 2023] [added: 2024] annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, [removed: 2023] [added: 2024] and is incorporated herein by reference.

Item 14. Principal Accountant Fees and Services

0 rewritten, 2 added, 1 removed, 2 unchanged

New in FY2024

\- 98 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

Dropped from FY2023

\- 94 \-

Item 15. Exhibits and Financial Statement Schedules

58 rewritten, 12 added, 10 removed, 119 unchanged

Rewritten

| [removed: [3.1](http://www.sec.gov/Archives/edgar/data/1327567/000119312512415530/d405168dex31.htm)] [added: [3.1](https://www.sec.gov/Archives/edgar/data/1327567/000119312512415530/d405168dex31.htm)] | | | | | | Restated Certificate of Incorporation of the Registrant. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 3.1 | | | | | | October 4, 2012 | | | | | | | | |

Rewritten

| [removed: [3.2](http://www.sec.gov/Archives/edgar/data/1327567/000119312522157474/d274773dex31.htm)] [added: [3.2](https://www.sec.gov/Archives/edgar/data/1327567/000119312522157474/d274773dex31.htm)] | | | | | | Amended and Restated Bylaws of the Registrant. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 3.1 | | | | | | May 23, 2022 | | | | | | | | |

Rewritten

| [removed: [3.3](http://www.sec.gov/Archives/edgar/data/1327567/000132756716000057/ex31certificateofchangeofr.htm)] [added: [3.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000057/ex31certificateofchangeofr.htm)] | | | | | | Certificate of Change of Location of Registered Agent and/or Registered Office. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 3.1 | | | | | | August 30, 2016 | | | | | | | | |

Rewritten

| [removed: [4.](http://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)[1](http://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)] [added: [4.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)] | | | | | | Indenture between the Registrant and U.S. Bank National Association, dated as of June 8, 2020. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.1 | | | | | | June 8, 2020 | | | | | | | | |

Rewritten

| [removed: [4.](http://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)[2](http://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)] [added: [4.2](https://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm)] | | | | | | Form of Global 0.375% Convertible Senior Note due 2025 (included in Exhibit 4.1). | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.2 | | | | | | June 8, 2020 | | | | | | | | |

Rewritten

| [removed: [4](https://www.sec.gov/Archives/edgar/data/1327567/000132756723000024/panwex43q423.htm)[.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756723000024/panwex43q423.htm)] [added: [4.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756723000024/panwex43q423.htm)] | | | | | | Description of Registrant’s Securities. | | | | | | [added: 10-K] | | | | | | [added: 001-35594] | | | | | | [added: 4.3] | | | | | | [added: September 1, 2023] | | | | | | | | |

Rewritten

| [removed: [10.1](http://www.sec.gov/Archives/edgar/data/1327567/000119312512296699/d318373dex101.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000119312512296699/d318373dex101.htm)*] | | | | | | Form of Indemnification Agreement between the Registrant and its directors and officers. | | | | | | S-1/A | | | | | | 333-180620 | | | | | | 10.1 | | | | | | July 9, 2012 | | | | | | | | |

Rewritten

| [removed: [10.2](http://www.sec.gov/Archives/edgar/data/0001327567/000132756719000038/panwex102q1202012eip.htm)*] [added: [10.2](https://www.sec.gov/Archives/edgar/data/0001327567/000132756719000038/panwex102q1202012eip.htm)*] | | | | | | 2012 Equity Incentive Plan and related form agreements. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 26, 2019 | | | | | | | | |

Rewritten

| [removed: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000119312521359246/d170141dex991.htm)*] [added: [10.13](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] | | | | | | [removed: 2021] [added: Cider Security Ltd. 2020] Equity Incentive Plan. | | | | | | S-8 | | | | | | [removed: 333-268930] [added: 333-268931] | | | | | | 99.1 | | | | | | December 21, 2022 | | | | | | | | |

Rewritten

| [removed: [10.5](http://www.sec.gov/Archives/edgar/data/1327567/000119312521359246/d170141dex992.htm)*] [added: [10.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1052021eipoption.htm)*] | | | | | | Form of 2021 Equity Incentive Plan Global Stock Option Award Agreement. | | | | | | [removed: S-8] | | | | | | [removed: 333-261697] | | | | | | [removed: 99.2] | | | | | | [removed: December 16, 2021] | | | | | | | | |

Rewritten

| [removed: [10.6](https://www.sec.gov/Archives/edgar/data/1327567/000119312521359246/d170141dex993.htm)*] [added: [10.6](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1062021eiprsu.htm)*] | | | | | | Form of 2021 Equity Incentive Plan Global Restricted Stock Unit Award Agreement. | | | | | | [removed: S-8] | | | | | | [removed: 333-261697] | | | | | | [removed: 99.3] | | | | | | [removed: December 16, 2021] | | | | | | | | |

Rewritten

| [removed: [10.7](http://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex107q422espp.htm)*] [added: [10.7](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1072012employeestock.htm)*] | | | | | | 2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements. | | | | | | [removed: 10-K] | | | | | | [removed: 001-35594] | | | | | | [removed: 10.7] | | | | | | [removed: September 6, 2022] | | | | | | | | |

Rewritten

| [removed: [10.8](http://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] [added: [10.8](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] | | | | | | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | | | | | | S-8 | | | | | | 333-227901 | | | | | | 99.1 | | | | | | October 19, 2018 | | | | | | | | |

Rewritten

| [removed: [10.12](http://www.sec.gov/Archives/edgar/data/1327567/000119312520320091/d23873dex991.htm)*] [added: [10.9](https://www.sec.gov/Archives/edgar/data/1327567/000119312520320091/d23873dex991.htm)*] | | | | | | Sinefa Group, Inc. 2020 Stock Plan. | | | | | | S-8 | | | | | | 333-251423 | | | | | | 99.1 | | | | | | December 17, 2020 | | | | | | | | |

Rewritten

| [removed: [10.1](http://www.sec.gov/Archives/edgar/data/1327567/000119312520320099/d35944dex991.htm)[3](http://www.sec.gov/Archives/edgar/data/1327567/000119312520320099/d35944dex991.htm)*] [added: [10.10](https://www.sec.gov/Archives/edgar/data/1327567/000119312520320099/d35944dex991.htm)*] | | | | | | Expanse Holding Company, Inc. Amended and Restated 2012 Stock Incentive Plan | | | | | | S-8 | | | | | | 333-251425 | | | | | | 99.1 | | | | | | December 17, 2020 | | | | | | | | |

Rewritten

| [removed: [10.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521265618/d214080dex991.htm)[4](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521265618/d214080dex991.htm)*] [added: [10.11](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521265618/d214080dex991.htm)*] | | | | | | Gamma Networks, Inc. 2018 Stock Option and Grant Plan. | | | | | | S-8 | | | | | | 333-259327 | | | | | | 99.1 | | | | | | September 3, 2021 | | | | | | | | |

Rewritten

| [removed: [10.15](http://www.sec.gov/Archives/edgar/data/1327567/000119312521074955/d51651dex991.htm)*] [added: [10.12](https://www.sec.gov/Archives/edgar/data/1327567/000119312521074955/d51651dex991.htm)*] | | | | | | Bridgecrew, Inc. 2019 Stock Incentive Plan. | | | | | | S-8 | | | | | | 333-254042 | | | | | | 99.1 | | | | | | March 9, 2021 | | | | | | | | |

Rewritten

| [removed: [10.1](http://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)[6](http://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] [added: [10.14](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)*] | | | | | | [added: US Sub-Plan to] Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | [removed: 99.1] [added: 99.2] | | | | | | December 21, 2022 | | | | | | | | |

Rewritten

| [removed: [10.18](http://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] [added: [10.15](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] | | | | | | Employee Incentive Compensation Plan, as amended and restated. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 25, 2014 | | | | | | | | |

Rewritten

| [removed: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000008/panw-ex104q222.htm)[0](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000008/panw-ex104q222.htm)*] [added: [10.17](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000008/panw-ex104q222.htm)*] | | | | | | Amended and Restated Outside Director Compensation Policy (last amended February 16, 2022). | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.4 | | | | | | February 23, 2022 | | | | | | | | |

Rewritten

| [removed: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] [added: [10.21](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] | | | | | | Continued Service Policy. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | May 20, 2022 | | | | | | | | |

Rewritten

| [removed: [10.22](http://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] [added: [10.22](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] | | | | | | Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 2022 | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.23 | | | | | | September 6, 2022 | | | | | | | | |

Rewritten

| [removed: [10.2](https://www.sec.gov/Archives/edgar/data/0001327567/000132756720000041/panwex101q121.htm)[3](https://www.sec.gov/Archives/edgar/data/0001327567/000132756720000041/panwex101q121.htm)*] [added: [10.23](https://www.sec.gov/Archives/edgar/data/0001327567/000132756720000041/panwex101q121.htm)*] | | | | | | Employment Agreement between Palo Alto Networks (Israel Analytics) Ltd. and Nir Zuk, dated August 18, 2020. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | November 19, 2020 | | | | | | | | |

Rewritten

| [removed: [10.2](http://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)[4](http://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] [added: [10.24](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] | | | | | | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.2 | | | | | | June 4, 2018 | | | | | | | | |

Rewritten

| [removed: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)[5](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] [added: [10.25](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] | | | | | | Offer Letter between the Registrant and Josh Paul, dated August 5, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | September 8, 2021 | | | | | | | | |

Rewritten

| [removed: [10.27](http://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] [added: [10.27](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | March 19, 2021 | | | | | | | | |

Rewritten

| [removed: [10.28](http://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] [added: [10.28](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 20, 2022 | | | | | | | | |

Rewritten

| [removed: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1027q421directoroffe.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1027q421directoroffe.htm)*] [added: [10.31](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1027q421directoroffe.htm)*] | | | | | | Form of Offer Letter between the Registrant and its directors. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.27 | | | | | | September 3, 2021 | | | | | | | | |

Rewritten

| [removed: [10.3](http://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)[2](http://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] [added: [10.32](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] | | | | | | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 30, 2019 | | | | | | | | |

Rewritten

| [removed: [10.33](http://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] [added: [10.33](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] | | | | | | Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 3, 2021 | | | | | | | | |

Rewritten

| [removed: [10.34](http://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex102.htm)] [added: [10.34](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex102.htm)] | | | | | | Form of Convertible Note Hedge Confirmation. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.2 | | | | | | June 8, 2020 | | | | | | | | |

Rewritten

| [removed: [10.35](http://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm)] [added: [10.35](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm)] | | | | | | Form of Warrant Confirmation. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.3 | | | | | | June 8, 2020 | | | | | | | | |

Rewritten

| [removed: [10.36](http://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] [added: [10.36](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 17, 2015 | | | | | | | | |

Rewritten

| [removed: [10.37](http://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] [added: [10.37](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.30 | | | | | | September 17, 2015 | | | | | | | | |

Rewritten

| [removed: [10.38](http://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] [added: [10.38](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.31 | | | | | | September 17, 2015 | | | | | | | | |

Rewritten

| [removed: [10.39](http://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] [added: [10.39](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] | | | | | | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | | | | | | 8-K/A | | | | | | 001-35594 | | | | | | 10.1 | | | | | | October 19, 2015 | | | | | | | | |

Rewritten

| [removed: [10.40](http://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] [added: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)[0](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 24, 2015 | | | | | | | | |

Rewritten

| [removed: [10.41](http://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] [added: [10.41](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 24, 2015 | | | | | | | | |

Rewritten

| [removed: [10.42](http://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] [added: [10.42](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | November 22, 2016 | | | | | | | | |

Rewritten

| [removed: [10.43](http://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] [added: [10.43](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 22, 2016 | | | | | | | | |

New in FY2024

| [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1042021equityincenti.htm)* | | | | | | 2021 Equity Incentive Plan, as amended and restated on December 12, 2023. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

New in FY2024

\- 99 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| [10.16](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm) | | | | | | Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

New in FY2024

\- 100 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

\- 101 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

| [1](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex191insidertradingpol.htm)[9.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex191insidertradingpol.htm) | | | | | | Insider Trading Policy and Requirements for Trading Plans | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

New in FY2024

| [97.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex971compensationrecov.htm) | | | | | | Compensation Recovery Policy | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

New in FY2024

\- 102 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

Dropped from FY2023

| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

Dropped from FY2023

\- 95 \-

Dropped from FY2023

| [10.](http://www.sec.gov/Archives/edgar/data/1327567/000119312520003856/d850020dex991.htm)[9](http://www.sec.gov/Archives/edgar/data/1327567/000119312520003856/d850020dex991.htm)* | | | | | | Aporeto, Inc. Amended and Restated 2015 Stock Option and Grant Plan. | | | | | | S-8 | | | | | | 333-235854 | | | | | | 99.1 | | | | | | January 8, 2020 | | | | | | | | |

Dropped from FY2023

| [10.1](http://www.sec.gov/Archives/edgar/data/1327567/000119312520133786/d849861dex991.htm)[0](http://www.sec.gov/Archives/edgar/data/1327567/000119312520133786/d849861dex991.htm)* | | | | | | CloudGenix Inc. 2013 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-238014 | | | | | | 99.1 | | | | | | May 5, 2020 | | | | | | | | |

Dropped from FY2023

| [10.11](http://www.sec.gov/Archives/edgar/data/1327567/000119312520266352/d99009dex991.htm)* | | | | | | Crypsis Group Holdings, LLC 2017 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-249387 | | | | | | 99.1 | | | | | | October 8, 2020 | | | | | | | | |

Dropped from FY2023

| [10.17](http://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)* | | | | | | US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | 99.2 | | | | | | December 21, 2022 | | | | | | | | |

Dropped from FY2023

| [10.19](http://www.sec.gov/Archives/edgar/data/1327567/000132756717000035/panwex103q118_clawbackpoli.htm)* | | | | | | Clawback Policy, adopted as of August 29, 2017. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 21, 2017 | | | | | | | | |

Dropped from FY2023

\- 96 \-

Dropped from FY2023

\- 97 \-

Dropped from FY2023

\- 98 \-

An excerpt. Shown here: 40 of 58 rewritten, all 12 added and all 10 removed. The counts are complete. For every sentence, read Item 15. Exhibits and Financial Statement Schedules in the FY2024 filing and the FY2023 filing.

Item 16. Form 10-K Summary

13 rewritten, 5 added, 3 removed, 39 unchanged

Rewritten

Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on September [removed: 1, 2023.][added: 6, 2024.]

Rewritten

| /s/ NIKESH ARORA | | | | | | Chairman, Chief Executive Officer and Director (Principal Executive Officer) | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ DIPAK GOLECHHA | | | | | | Chief Financial Officer (Duly Authorized Officer and Principal Financial Officer) | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ JOSH PAUL | | | | | | Chief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer) | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ NIR ZUK | | | | | | Chief Technology Officer and Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ APARNA BAWA | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ JOHN M. DONOVAN | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ CARL ESCHENBACH | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ DR. HELENE D. GAYLE | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ JAMES J. GOETZ | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ RT HON SIR JOHN KEY | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ MARY PAT MCCARTHY | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

Rewritten

| /s/ LORRAINE TWOHILL | | | | | | Director | | | | | | September [removed: 1, 2023] [added: 6, 2024] | | |

New in FY2024

\- 103 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

\- 104 \-

New in FY2024

[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)

New in FY2024

\- 105 \-

Dropped from FY2023

\- 99 \-

Dropped from FY2023

\- 100 \-

Dropped from FY2023

\- 101 \-