← Back to DGII filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Except as set forth below, there have been no material changes in our risk factors from those previously disclosed in Item 1A of Part I of our Annual Report on Form 10-K for the year ended September 30, 2025.
We depend on manufacturing relationships and a broad set of suppliers, some of whom provide us with limited-source components and parts, and disruptions in these relationships may cause damage to our customer relationships or otherwise negatively impact our business.
We procure all parts and certain services involved in the production of our products and subcontract most of our product manufacturing to outside firms that specialize in such services. Although most of the components of our products are available from multiple vendors, we have several single-source supplier relationships, either because alternative sources are not available or because the relationship is advantageous to us. Further, in recent years global supply chains have experienced stress due to a range of factors. This has impacted our own ability to procure certain inventory and services. These disruptions also caused us to order significant amounts of inventory as we were uncertain whether we would otherwise be able to procure necessary parts and components to meet customer needs. As a result, at times we held elevated levels of inventory compared to historical norms. The impacts of these circumstances driven by supply chain stress were material in some instances and it is possible additional material impacts could occur in the future. There can be no assurance that our suppliers will be able to meet our future requirements for products and components in a timely fashion. In addition, the availability of many of the components we need is dependent in part on our ability to provide our suppliers with accurate forecasts of our future requirements. Delays or lost revenue could be caused by other factors beyond our control, including late deliveries by vendors of components, or force majeure events. As an example of force majeure, a fire many years ago disrupted the operations at one of our contract manufacturers in Thailand. If we are required to identify alternative suppliers for any of our required components, qualification and pre-production periods could be lengthy and may cause an increase in component costs and delays in providing products to customers. Any extended interruption in the supply of any of the key components or the availability of manufacturing services that currently are obtained from limited sources could disrupt our operations and have a material adverse effect on our customer relationships and profitability.
We are dependent on third parties to manufacture our products which could have adverse impacts on our business if such manufacturers encounter operating restraints or if we do not properly forecast customer demand.
We are reliant on third parties to manufacture our products in countries such as Mexico, Thailand, Taiwan, Cambodia and China. The ability of these manufacturers to provide us with the timely provision of finished products is subject to a number of disruptions beyond their control such as, among others: the availability of components from suppliers, labor shortages, energy shortages such as those from time to time encountered in China, changes in government regulations, tensions with foreign governments or other factors. If we do not properly forecast customer demands for products any lengthening in lead times or disruptions in service could result in lost revenues and adversely impact our business, results of operation, financial condition and prospects.
We face risks associated with our international operations that could impair our ability to grow our revenue abroad as well as our overall financial condition.
Our future growth may be dependent in part upon our ability to increase sales in international markets. These sales are subject to a variety of risks, including fluctuations in currency exchange rates, tariffs, import restrictions and other trade barriers, geopolitical tensions, unexpected or very burdensome changes in regulatory requirements, longer accounts receivable payment cycles, potentially adverse tax consequences, and export license requirements. The impact of these risks is not able to be estimated and the circumstances associated with these risks is extremely fluid in the current macro-economic environment. In addition, we are subject to the risks inherent in conducting business internationally, including political and economic instability, military conflicts and unexpected changes in diplomatic and trade relationships. In many markets where we operate business and cultural norms are different than those in the United States and practices that may violate laws and regulations applicable to us like the Foreign Corrupt Practices Act ("FCPA") and the UK Anti-Bribery Act ("UKBA") are more commonplace. Although we have implemented policies and procedures with the intention of ensuring compliance with these laws and regulations, our employees, contractors and agents, as well as channel partners involved in our international sales, may take actions in violation of our policies. Many of our vendors and strategic business allies also have international operations and are subject to the
32
Table of Contents
above-described risks. Even if we are able to successfully manage the risks of international operations, our business may be adversely affected if one or more of our business relations are not able to successfully manage these risks. There can be no assurance that one or more of these factors will not have a material adverse effect on our business strategy and financial condition.
In addition to these risks, our offices and employees in foreign jurisdictions, including Australia, Belgium, Canada, China, France, Germany, Japan, Mexico, Poland, Spain, Singapore, Sweden and United Kingdom, create additional operational and compliance risks. Local labor, employment, tax and benefits laws may increase our operating costs, limit our ability to adjust staffing levels, or expose us to unexpected liabilities. Government inspections, audits, or investigations could disrupt operations or result in fines or penalties. Employees in these jurisdictions may also face heightened personal security, regulatory, or compliance risks. Evolving data‑security, cybersecurity, and data‑localization requirements in foreign jurisdictions may impose additional compliance obligations and operational constraints. Changes in U.S. relations with these foreign jurisdictions could also result in new restrictions that impair our ability to operate or support employees there.
Artificial intelligence (“AI”) tools may enable threat actors to discover and exploit vulnerabilities in our products and infrastructure, and to conduct more sophisticated attacks, faster than we are able to respond.
Frontier AI models offered by major developers, as well as various open-source models that are more difficult for governments to regulate, are increasingly capable of automating vulnerability discovery, accelerating the development of exploits, and identifying security weaknesses across complex product portfolios at a speed and scale that was not previously achievable. Nation-state actors and other sophisticated threat actors may also use these AI tools to enhance or automate additional attack vectors, including AI-generated phishing and social engineering campaigns, deepfake-based impersonation, and agentic AI systems capable of executing multi-stage attacks, such as ransomware or extortion campaigns, with limited human involvement. We believe this represents a material change in the threat environment facing many companies, including those like ours that develop and sell networked hardware and software products.
Our product portfolio includes devices across a range of patchability profiles. Some products support over-the-air updates; others require full firmware replacement; others depend on OEM licensees to develop and distribute patches to end customers; and a legacy population of devices cannot be fully remediated through software updates at all. Our reliance on OEM licensees and other third parties to develop, test, and distribute patches may also expose us to additional supply-chain risk, as AI tools may similarly accelerate the discovery and exploitation of vulnerabilities in third-party components and dependencies that are outside our direct control. In an environment where the window between vulnerability identification and active exploitation may be materially shorter than it has historically been, our ability to respond to newly discovered vulnerabilities across all affected products and internal systems within committed timeframes cannot be guaranteed.
Several of our management platforms are cloud-based and operate at a layer above individual devices, aggregating access across many devices and customers. A security incident affecting any one of these platforms could affect multiple enterprise customers simultaneously, which is categorically different in scope and consequence from a device-level vulnerability. Our incident response protocols, contractual commitments, and insurance coverage may not fully account for this concentration risk, and any resulting fines, penalties, or damages may not be fully covered by our insurance policies.
The volume of vulnerabilities identified across our product lines and internal systems may also increase materially as AI-assisted discovery tools become more widely available to both security researchers and malicious actors. Our ability to triage, assess, and remediate vulnerabilities at elevated volume while meeting existing customer service-level agreement (SLA) commitments and regulatory reporting obligations (such as the EU Cyber Resilience Act reporting requirements effective September 2026) may be constrained by available internal resources and the architectural limitations described above. If we are unable to respond to vulnerabilities at the pace the current threat environment demands, we may face increased costs, customer attrition, contractual liability, regulatory investigations or actions, litigation, regulatory penalties, loss of revenue or profits, loss of customers or sales, and reputational harm.
33
Table of Contents