← Back to FFIV filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
There have been no material changes to our risk factors from those described in Part I, Item 1A, "Risk Factors" of our Annual Report on Form 10-K for the fiscal year ended September 30, 2025, which was filed with the Securities and Exchange Commission on November 25, 2025, except for those set forth below.
Security vulnerabilities or control failures in our IT infrastructure or multicloud application delivery and security products and services as well as unforeseen product errors could have a material adverse impact on our business, results of operations, financial condition and reputation
In the ordinary course of business, we store sensitive data, including intellectual property, personal data, our proprietary business information and that of our customers, suppliers and business partners on our networks. In addition, we store sensitive data through cloud-based services that may be hosted by third parties and in data center infrastructure maintained by third parties. The secure maintenance of this information is critical to our operations and business strategy. Our IT infrastructure and those of our partners and customers are subject to the increasing threat of intrusions by a wide range of bad actors and malicious parties, including computer programmers, hackers or sophisticated nation-state and nation-state supported actors, or they may be compromised due to employee error or wrongful conduct, malfeasance, or other disruptions. Despite our security measures, and those of our third-party vendors, our IT infrastructure has experienced breaches or disruptions, including the Cyber Incident, and may be vulnerable in the future to breach, attacks or disruptions. If any breach or attack, including the Cyber Incident, compromises our IT infrastructure, creates system disruptions or slowdowns or exploits security vulnerabilities therein, the information stored on our networks or those of our customers could be accessed and modified, publicly disclosed, or lost or stolen, and we may be subject to liability to our customers, individuals, suppliers, business partners and others, and may suffer reputational and financial harm.
Our multicloud application delivery and security products and services are used by our customers to manage their critical applications and data. Bad actors and other malicious parties, have in the past and may attempt in the future to exploit security vulnerabilities and control weaknesses in our internal IT infrastructure or cloud environments that support our SaaS-based and managed solutions and services as well as our products that may be deployed in a customer environment. Despite our efforts to harden our IT infrastructure, our delivery and security products and services against these risks, those efforts may not be successful, and from time to time, those systems and products could be compromised. Threat actors can seek to exploit, among other things, known or unknown vulnerabilities and control weaknesses in technology included in our IT infrastructure, delivery and security products and services, and failure to quickly identify, patch or mitigate security vulnerabilities or strengthen security controls could render our IT infrastructure, delivery and security products and services susceptible to a cyber-attack which may subject the Company to liability to our customers, suppliers, business partners and others, as well as reputational and financial harm. Moreover, inadequate or incomplete security monitoring, logging, asset management, or internal reporting and escalation, or gaps in coverage of security tools in our environment, could impact our ability to detect and respond to threats early and efficiently, giving threat actors an opportunity to gain or maintain access to our environment undetected. Finally, we rely on a number of third parties who connect to our network or with whom we share data, to support our business and operations, and to the extent that these third parties have weaknesses or deficiencies in their security program or vulnerabilities, they present business, operational, reputational, financial and legal risk. If any one or more of these vendors' security is compromised, it could have similar consequences as if we experienced a security event ourselves.
30
Table of Contents
Our products may also contain undetected errors, defects, or vulnerabilities when first introduced or as new versions are released. We have experienced these issues in the past in connection with new products and product upgrades. Our products also must successfully operate with products from other vendors. As our products and customer IT infrastructures become increasingly complex, customers may also experience unforeseen errors in implementing our products into their IT environments or integrating them with other vendor products. We expect that these errors, defects, or vulnerabilities will be found from time to time in new or enhanced products after commencement of commercial shipments. Any of these may temporarily or permanently disable our end-customers’ networks, information technology infrastructure or other systems, or expose our end-customers’ networks to attacks or compromise from security threats. These problems may cause us to incur significant warranty and repair costs, divert the attention of our engineering personnel from our product development efforts, cause significant customer relations problems, result in legal claims or liability, and impact demand for our products and services. We may also be subject to liability claims for damages. We carry insurance policies covering these types of liabilities, but these policies may not provide sufficient protection should a claim be asserted. A material product liability claim may harm our business and results of operations.
Advances in AI capabilities, including increasingly sophisticated AI models and coding agents capable of autonomously creating, discovering and exploiting vulnerabilities and other security issues, are becoming more broadly accessible, including to nation-state actors and other well-resourced threat actors. These tools can enable faster identification and exploitation and more significant impact by threat actors, shortening the time to detect attacks and expanding the time and resources required to respond to them. These tools may be leveraged against the AI infrastructure of the Company and our third-party vendors, our multicloud application delivery and security products and services, and our other products. Threat actors may also target our AI models and supporting systems for our products and services in ways that we cannot yet anticipate.
Any errors, defects, control failures, or vulnerabilities in our products or IT infrastructure, including the Cyber Incident, could result in:
•expenditures of significant financial and product development resources in efforts to analyze, correct, eliminate, or work-around errors and defects or to address and eliminate vulnerabilities;
•remediation costs, such as liability for stolen assets or information, repairs or system damage;
•increased cybersecurity protection costs which may include systems and technology changes, training, and engagement of third party experts and consultants;
•increased insurance premiums;
•loss of existing or potential customers or channel partners;
•loss of proprietary information leading to lost competitive positioning and lost revenues;
•inaccessibility to certain data or systems necessary to operate the business;
•negative publicity and damage to our reputation;
•delayed or lost revenue;
•delay or failure to attain market acceptance or decrease in demand for our products and services;
•an increase in warranty claims compared with our historical experience, or an increased cost of servicing warranty claims, either of which would adversely affect our gross margins; and
•litigation, regulatory inquiries, or investigations that may be costly and harm our reputation.
Risks related to the development, deployment, and use of artificial intelligence ("AI") could give rise to legal and/or regulatory action, damage our reputation or otherwise materially harm our business
We currently incorporate AI technology in certain of our products and services and in our business operations and our research and development efforts in this area are ongoing. The development and deployment of AI involve inherent risks, technical challenges, and potential unintended consequences that could adversely affect our and our customers' adoption and use of these technologies. For example, AI solutions may use algorithms, datasets, or training methodologies that are incomplete, reflect biases, or contain other flaws or deficiencies.
31
Table of Contents
Additionally, AI technologies are complex and rapidly evolving, and we face significant competition in the market and from other companies regarding such technologies. There is a risk that AI technologies could automate or simplify functions currently performed by our application delivery and security solutions. If customers or investors believe that AI tools can replicate or replace aspects of our offerings, demand for our products and services could decline, and our competitive position could be weakened. Market sentiment regarding AI's potential to disrupt the application delivery and security industry could negatively affect our stock price and business, regardless of whether such disruption actually materializes or impacts our competitive position.
While we aim to develop and use AI responsibly and attempt to identify and mitigate ethical and legal issues presented by its use, we may be unsuccessful in identifying or resolving issues before they arise. The rapid pace of AI development and the emergence of new regulations require us to commit substantial resources to ensure our AI-enabled products and services meet evolving legal and technical standards. The AI-related legal and regulatory landscape remains uncertain and may be inconsistent from jurisdiction to jurisdiction. Our obligations to comply with the evolving legal and regulatory landscape could entail significant costs or limit our ability to incorporate certain AI capabilities into our offerings.
AI-related issues, deficiencies and/or failures could (i) give rise to legal and/or regulatory action, including with respect to proposed legislation regulating AI in jurisdictions such as the European Union and others, and as a result of new applications of existing data protection, privacy, intellectual property, and other laws; (ii) damage our reputation; or (iii) otherwise materially harm our business.