Check Point Software Technologies Ltd.
A maker of cybersecurity software, Check Point protects businesses, governments and home users from hackers, viruses and online attacks through products like its FireWall-1 and Quantum gateways, plus the consumer ZoneAlarm antivirus brand. Founded in 1993 in Israel by Gil Shwed, Marius Nacht and Shlomo Kramer, the company grew from Shwed's "stateful inspection" idea, developed while he served in the Israeli military's Unit 8200. Fun fact: the name plays on the software's role as a "check point" that inspects every piece of network traffic and decides what gets through.
20-F · Fiscal year ended Dec 31, 2025 · SEC filing ↗
The original filing sections are available below.
QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK We are exposed to market risks that result primarily from weak economic conditions in the markets in which we sell our products, and from changes in exchange rates or in interest rates. Interest Rate Risk Our exposure to…
QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK We are exposed to market risks that result primarily from weak economic conditions in the markets in which we sell our products, and from changes in exchange rates or in interest rates. Interest Rate Risk Our exposure to market risk for changes in interest rates relates primarily to our investment in fixed maturity marketable securities, and short-term bank deposits. Our marketable securities portfolio includes mainly government and government agencies debt instruments (U.S., European and other) and corporate debt instruments, which are exposed to changes in short-term interest rates. By policy, we limit the amount of credit exposure to any single debt issuer. Investments in both fixed rate and floating rate interest bearing securities carry a degree of interest rate risk. Fixed rate securities may have their fair market value impacted due to a rise or fall in interest rates, while floating rate securities may produce less income than predicted if interest rates fall. Due in part to these factors, our income from investments may change in the future in the event that interest rates fluctuate. The yield on new investments in our investment portfolio and our interest income was positively impacted by several years of rising interest rates. From the second half of 2024 interest rates started to fall as the Federal Reserve bank cut the Federal Funds Rate, and so did other central banks, which negatively affected the yield on new investments in our investment portfolio. As of December 31, 2025 securities representing 5% of our investments portfolios are rated as AAA; securities representing 42% of the portfolio are rated between AA- and AA+; securities representing 53% of the portfolio are rated between A- and A+; securities representing 1% of the portfolio are rated as BBB+ or below. The table below provides information regarding our investments in cash, cash equivalents, short-term bank deposits and marketable securities, as of December 31, 2025: Maturity Total Par Value Fair Value at Dec. 31, 2025 2026 2027 2028 2029 2030 (in millions) Marketable securities: Debt securities issued by the U.S. Treasury and other U.S. government agencies $ 177.6 $ 74.0 $ 98.2 $ 81.1 $ 44.4 $ 475.3 $ 474.3 Debt securities issued by other governments 9.4 11.7 10.8 7.0 - 38.9 39.3 Corporate debt securities 504.8 394.2 265.2 211.6 130.0 1,505.8 1,502.4 Cash 109.8 109.8 109.8 Short-term bank deposits 525.7 525.7 525.7 Cash equivalents: Money market funds 1,464.5 - - - - 1,464.5 1,464.5 Short term deposits 225.7 - - - - 225.7 225.7 Total $ 3,017.5 $ 479.9 $ 374.2 $ 299.7 $ 174.4 $ 4,345.7 $ 4,341.7 66 Foreign Currency Risk Most of our sales are denominated in U.S. dollars, and we incur majority of our expenses in U.S. dollar, Israeli Shekel and Euro currencies. According to the factors indicated in ASC 830, “Foreign Currency Matters”, our cash flow, sale price, sales market, expense, financing and inter-company transactions, and arrangement indicators, are predominantly denominated in U.S. dollars. In addition, the U.S. dollar is the primary currency of the economic environment in which we operate, and thus, the U.S. dollar is our functional and reporting currency. On our balance sheet, we convert into U.S. dollars all monetary accounts (principally liabilities) that are held in other currencies. For this conversion, we use the relevant foreign currency exchange rate at the balance sheet date. Any gain or loss that results from this conversion is reflected in the statement of income as financial income or financial expense, as appropriate. We measure and record non-monetary accounts in our balance sheet in U.S. dollars. For this measurement, we use the U.S. dollar value in effect at the date that the asset or liability was initially recorded in our balance sheet (the date of the transaction). We entered into forward contracts to hedge the foreign currency exchange impacts on assets and liabilities denominated in various foreign currencies. As of December 31, 2025, the total amount of outstanding forward contracts that did not qualify for hedge accounting was $196.0 million. These contracts were for a period of up to twelve months. The net amount of gains and losses recognized in “financial income, net” during 2025 was a gain of $30.3 million. During 2025, we entered into forward contracts to hedge against the risk of overall changes in foreign currency exchange rates on future cash flow from payments of payroll and related expenses denominated in Israeli Shekel and Euro. These contracts qualified for cash flow hedge accounting and as such the net amount of gains and losses of $29.1 million in gain was recognized when the related expenses were incurred, and classified in operating expenses during 2025. As of December 31 2025, the notional amount of outstanding forward contracts that qualified for cash flow hedge accounting was $328.8 million and their fair value gain amount was $29.8 million. Our operating expenses may be affected by fluctuations in the value of the U.S dollar as it relates to foreign currencies; with Israeli Shekel and Euro having the greatest potential impact. In managing our foreign exchange risk, we periodically enter into foreign exchange hedging contracts. Our goal is to mitigate the potential exposure with these contracts. By way of example, a 10% weakening in the value of the dollar relative to the currencies in which our operating expenses are denominated in 2025 would result in an increase in operating expenses of $79.5 million for the year ended December 31, 2025. This calculation assumes that each exchange rate would change in the same direction relative to the U.S. dollar.
Risk Factors An investment in our ordinary shares involves a high degree of risk. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become…
Risk Factors An investment in our ordinary shares involves a high degree of risk. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks materialize, our business, financial condition, results of operations and prospects could be materially harmed. In that event, the market price of our ordinary shares could decline and you could lose part or all of your investment. Risk Factors Summary The following is a summary of the principal risks that could materially and adversely affect our business, financial condition, operating results and growth prospects. Risks Related to Our Business and Our Market • If the market for information and network security solutions does not continue to grow, our business will be adversely affected. • We may not be able to successfully compete, which could adversely affect our business and results of operations. • If we fail to enhance our existing products, develop or acquire new and more technologically advanced products, or fail to successfully commercialize these products, our business and results of operations will suffer. • We may need to change our pricing models to compete successfully. • Our business, results of operations and financial condition are subject to, have been and may continue to be adversely affected by the risks of earthquakes, fire, floods, pandemics and other natural events, as well as manmade problems such as power disruptions or terrorism or war, such as the war between Israel, the U.S. and Iran and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen. • Prolonged economic uncertainties or downturns, globally or in certain regions or industries, could materially adversely affect our business. • If our products fail to protect against attacks and our customers experience security breaches, our reputation and business could be harmed. • Product defects may increase our costs and impair the market acceptance of our products and technology. • We are subject to risks relating to acquisitions. • We are dependent on a limited number of product families. • Competition for highly skilled personnel is intense. • Issues in the development and deployment of AI may results in reputational harm and legal liability and could adversely affect our results of operations. 3 Risks Related to Our Dependence on Third-Parties • We are dependent on a small number of distributors. • We purchase several key components and finished products from limited sources, and we are increasingly dependent on contract manufacturers for our hardware products. • We incorporate third-party technology in our products, which may make us dependent on the providers of these technologies and expose us to potential intellectual property claims. • Failures of the third party technology, third-party servers, cloud service providers, such as Amazon Web Services (“AWS”), and other third-party hardware, software and infrastructure on which we rely could adversely affect our business. Risks Related to Tax, Legal and Regulatory Matters • We are the defendants in various lawsuits and have been subject to tax disputes and governmental proceedings, which could adversely affect our business, results of operations and financial condition. • Uncertainties in the interpretation and application of worldwide tax reforms, complex tax laws and regulations could materially affect our tax obligations and effective tax rate. • Class action litigation due to stock price volatility or other factors could cause us to incur substantial costs and divert our management’s attention and resources. • We are subject to governmental export and import controls that could subject us to liability or impair our ability to compete in international markets. • Changes in government trade policies and international trade disputes that result in tariffs and other protectionist measures could adversely affect our business in the future. Risks Related to Our Intellectual Property • We may not be able to successfully protect our intellectual property rights, which could cause substantial harm to our business. • We incorporate open source technology in our products which may expose us to liability and have a material impact on our product development and sales. • If a third-party asserts that we are infringing its intellectual property, whether successful or not, it could subject us to costly and time-consuming litigation or expensive licenses, which could harm our business. • Due to the global nature of our business, we must comply with various anti-bribery regimes and any failure to do so could adversely affect our business. Other General Risks and Risks Related to Capitalization and Ownership of Our Ordinary Shares • We are exposed to various legal, business, political, economic, health-related and other risks associated with our international operations; these risks could increase our costs, reduce future growth opportunities and affect our results of operations. • Our actual or perceived failure to adequately protect personal data or customer data, or otherwise comply with data privacy and protection laws and regulations or other technology related regulations, could subject us to sanctions and damages and could harm our reputation and business. • Issues relating to our use of artificial intelligence and machine learning technologies, combined with an uncertain legal and regulatory environment, could materially and adversely affect our business, financial condition and results of operations. • Repaying and servicing our existing and future debt, including our outstanding convertible notes may require a significant amount of cash, and we may not have sufficient cash flow from our business to pay our indebtedness. • Our Convertible Notes may impact our financial results, result in the dilution of existing shareholders and create downward pressure on the price of our ordinary shares. • Our ability to pay cash upon conversion or repurchase of our outstanding Convertible Notes may be limited. • Our capped call transactions may affect the value of our ordinary shares. • We are subject to counterparty risk with respect to the capped call transactions. • Compliance with new and changing corporate governance and public disclosure requirements adds uncertainty to our compliance policies and increases our costs of compliance. 4 • A small number of shareholders own a substantial portion of our ordinary shares, and they may make decisions with which you or others may disagree. • Our cash balances and investment portfolio have been, and may continue to be, adversely affected by market conditions and interest rates. • Currency fluctuations may affect the results of our operations or financial condition. • Our information technology systems, networks and products and services have been, and may continue to be, subject to various security threats and cyber security incidents. • We depend on our executive officers and other key employees, and the loss of one or more of these employees or an inability to attract and retain other highly skilled employees could adversely affect our business, and we may not be able to successfully navigate the recent leadership changes while maintaining key aspects of our culture, which could have a significant negative effect on our existing business and our ability to pursue future plans. Risks Related to Our Operations in Israel • The ongoing war and hostilities and other potential political, economic and military instability in Israel, where our principal executive offices and our principal research and development facilities are located, may adversely affect our results of operations. • Our operations may be disrupted by the obligations of our personnel to perform military service. • We are subject to risks in connection with the development of our new campus in Tel Aviv, Israel • The tax benefits available to us require us to meet several conditions, and may be terminated or reduced in the future, which would increase our taxes. • Shareholder rights and responsibilities are, and will continue to be, governed by Israeli law which differs in some material respects from the rights and responsibilities of shareholders of U.S. companies. • Provisions of Israeli law and our articles of association may delay, prevent or make difficult an acquisition of us, prevent a change of control, and negatively impact our share price. • As a foreign private issuer we are not subject to the provisions of Regulation FD or U.S. proxy rules and are exempt from filing certain Exchange Act reports. • As a foreign private issuer whose shares are listed on the Nasdaq Global Select Market (“Nasdaq”), we may follow certain home country corporate governance practices instead of certain Nasdaq requirements. Risks Related to Our Business and Our Market If the market for information and network security solutions does not continue to grow, our business will be adversely affected The market for information and network security solutions may not continue to grow. Continued growth of this market will depend, in large part, upon: • the continued expansion of internet usage and the number of organizations adopting or expanding intranets; • the continued adoption of “cloud” infrastructure by organizations; • the ability of the infrastructures implemented by organizations to support an increasing number of users and services; • the continued development of new and improved services for implementation across the internet and between the internet and intranets; • the adoption of data security measures as it pertains to data encryption and data loss prevention technologies; • continued access to mobile APIs, APPs and application stores with Apple, Google and Microsoft; • government regulation of the internet and governmental and non-governmental requirements and standards with respect to data security privacy and data protection; and • economic, social, or political conditions, including conditions resulting from a decline in the macroeconomic environment, rising interest rates, exchange rate fluctuations, inflation, global pandemics , global supply chain disruptions and conditions resulting from geopolitical uncertainty and instability or war, including the war between Israel, the U.S. and Iran and its effects on the delivery of goods through the Strait of Hormuz, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen, and the Russia-Ukraine armed conflict and the tension between China and Taiwan. 5 In the last few years, global and regional economies around the world and financial markets have remained volatile largely as a result of economic and political uncertainty, the war and hostilities between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen, rising interest rates, inflation, terrorist groups in Yemen, which limited the movement of marine shipments to Israel through the Red Sea, the war in Ukraine, terrorism, governmental instability and other factors. During this period, many organizations have limited their expenditures and a significant portion of such organizations have remained reluctant to increase their expenditures. If these challenging macroeconomic conditions continue or worsen, our customers may reduce or postpone their technology spending, which could result in significant reductions in sales of our products, longer sales cycles, slower adoption of new technologies or increased price competition. Further, if the necessary infrastructure required to operate our industry or complementary products and services are not developed in a timely manner and, consequently, the enterprise security, data security, internet or intranet markets fail to grow or grow more slowly than we currently anticipate, our business, results of operations and financial condition may be materially adversely affected. Additional details are provided in “Item 4 – Information on Check Point”. We may not be able to successfully compete, which could adversely affect our business and results of operations The market for information and network security solutions is intensely competitive and we expect that competition will continue to increase in the future. Our competitors include Cisco Systems, Inc., Fortinet Inc., Palo Alto Networks, Inc. and SonicWall Inc. and other companies in the network security space. We also compete with several other companies, including Zscaler, Inc., Trellix, Trend Micro Inc., NortonLifeLock Inc., Lookout, Inc., Zimperium, Inc, CrowdStrike Holdings, Inc., SentinelOne, Inc., Sophos Group plc, Proofpoint, Inc., Broadcom, Inc., Mimecast Limited, Microsoft Corp., Netskope, Inc. and Abnormal Security Corp., with respect to specific products that we offer. In addition, there are hundreds of small and large companies that offer security products and services that we may compete with from time to time. Some of our current and potential competitors have various advantages over us, including longer operating histories; access to larger customer bases; significantly greater financial, technical and marketing resources; a broader portfolio of products, applications and services including AI and machine learning; and larger patent and intellectual property portfolios. As a result, they may be able to adapt better than we can to new or emerging technologies and changes in customer requirements, or to devote greater resources to the promotion and sale of their products. Furthermore, some of our competitors with more diversified product portfolios and larger customer bases may be better able to withstand a reduction in spending on information and network security solutions, as well as a general slowdown or recession in economic conditions in the markets in which they operate. In addition, some of our competitors have greater financial resources than we do, and they have offered, and in the future may offer, their products at lower prices than we do, or may bundle security products with their other offerings, which may cause us to lose sales or to reduce our prices in response to competition. With the introduction of new products and services and new market entrants, we expect competition to intensify in the future. Industry developments and evolving technology, such as AI, may also impact our competitive landscape and the factors required to compete effectively in current or prospective markets. For example, companies offering generative AI services with cybersecurity capabilities, including large language models represent an additional source of competition because they may currently or in the future serve as alternative cybersecurity systems. If we are not able to continue to compete with companies offering AI systems with cybersecurity features our business, results of operations and financial condition could be adversely affected. In addition, consolidation in the markets in which we compete may affect our competitive position. This is particularly true in circumstances where customers are seeking to obtain a broader set of products and services than we are able to provide. The markets in which we compete also include many niche competitors, generally smaller companies at a relatively early stage of operations, which are focused on specific internet and data security needs. These companies’ specialized focus may enable them to adapt better than we can to new or emerging technologies and changes in customer requirements in their specific areas of focus. In addition, some of these companies can invest relatively large resources on very specific technologies or customer segments. The effect of these companies’ activities in the market may result in price reductions, reduced gross margins and loss of market share, any of which will materially adversely affect our business, results of operations and financial condition. Further, vendors of operating system software, networking hardware or central processing units (“CPUs”), may enhance their products to include functionality that is currently provided by our products. The widespread inclusion of similar functionality to that which is offered by our solutions, as standard features of operating system software and networking hardware could significantly reduce the demand for our products, particularly if the quality of such functionality were comparable to that of our products. Furthermore, even if the network or application security functionality provided as standard features by operating systems software and networking hardware is more limited than that of our solutions, a significant number of customers may elect to accept more limited functionality in lieu of purchasing additional products. 6 We may not be able to continue competing successfully against our current and future competitors, and increased competition within the market may result in price reductions, reduced gross margins and operating margins, reduced net income, and loss of market share, any or all of which may materially adversely affect our business, results of operations and financial condition. For additional information, see “Item 4 – Information on Check Point”. If we fail to enhance our existing products, develop or acquire new and more technologically advanced products, or fail to successfully commercialize these products, our business and results of operations will suffer The information and network security industry is characterized by rapid technological advances, changes in customer requirements, frequent new product introductions and enhancements, and evolving industry standards in computer hardware and software technology. In particular, the markets for data security, internet and intranet applications are rapidly evolving. As a result, we must continually change and improve our products in response to changes in operating systems, application software, computer and communications hardware, networking software, programming tools, and computer language technology. We must also continually change our products in response to changes in network infrastructure requirements, including the expanding use of cloud computing. Further, we must continuously improve our products to protect our customers’ data and networks from evolving security threats. Our future results of operations will depend upon our ability to enhance our current products and to develop and introduce new products on a timely basis; to address the increasingly sophisticated needs of our customers; and to keep pace with technological developments, new competitive product offerings, and emerging industry standards. Our competitors’ introduction of products embodying new technologies and the emergence of new industry standards may render our existing products obsolete or unmarketable. While we have historically been successful in developing, acquiring, and marketing new products and product enhancements that respond to technological change and evolving industry standards, we may not be able to continue to do so. In addition, we may experience difficulties that could delay or prevent the successful development, introduction, and marketing of these products, as well as the integration of acquired products. Furthermore, our new products or product enhancements may not adequately meet the requirements of the marketplace or achieve market acceptance. In some cases, a new product or product enhancements may negatively affect sales of our existing products. If we do not respond adequately to the need to develop and introduce new products or enhancements of existing products in a timely manner in response to changing market conditions or customer requirements, our business, results of operations and financial condition may be materially adversely affected. For additional information, see “Item 4 – Information on Check Point” and under the caption “We may not be able to successfully compete, which could adversely affect our business and results of operations” in this “Item 3 – Key Information – Risk Factors”. We may need to change our pricing models to compete successfully The intense competition we face in the sales of our products and services and general economic and business conditions can put pressure on us to change our prices. If our competitors offer deep discounts on certain products or services or develop products that the marketplace considers more valuable, we may need to lower prices or offer other favorable terms in order to compete successfully. Any such changes may reduce margins and could adversely affect results of operations. Additionally, the increasing prevalence of cloud and SaaS delivery models offered by us and our competitors may unfavorably impact pricing in both our on-premises enterprise software business and our cloud business, as well as overall demand for our on-premises software product and service offerings, which could reduce our revenues and profitability. Our competitors may offer lower pricing on their support offerings, which could put pressure on us to further discount our product or support pricing. Our business, results of operations and financial condition are subject to, have been and may continue to be adversely affected by the risks of earthquakes, fire, floods, pandemics and other natural events, as well as manmade problems such as power disruptions or terrorism or war, such as the war between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen We operate our business primarily from Israel, and operate and sell our products worldwide. Our headquarters in the United States, as well as certain of our research and development operations, are located in the Silicon Valley area of Northern California, a region known for seismic activity. We also have significant operations in other regions that have experienced natural disasters. A significant natural disaster occurring at our facilities in Israel, in the United States or elsewhere, or where our channel partners are located, could have a material adverse impact on our business, results of operations and financial condition. In addition, acts of terrorism or war (including the war between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen, and the significant military action against Ukraine launched by Russia and any related political or economic responses and counter-responses or otherwise by various global actors or general effect on the global economy) have caused disruptions and could in the future cause disruptions to our or our customers’ businesses or the economy as a whole. Further, we rely on information technology systems to communicate among our workforce located worldwide. Any disruption to our internal communications, whether caused by a natural disaster, pandemics or by manmade problems, such as power disruptions or terrorism or war, could delay our research and development efforts. To the extent any of the foregoing causes disruptions or result in delays or cancellations of customer orders, our research and development efforts or the deployment of our products, our business and results of operations would be materially and adversely affected. 7 In addition, following the Russia-Ukraine armed conflict, the United States and other countries imposed economic sanctions and severe export control restrictions against Russia and Belarus, and the United States and other countries could impose wider sanctions and export restrictions and take other actions should the conflict further escalate, which affect our exports or sales into Russia and Belarus and create difficulties in business planning and forecasting due to the uncertainty of the impact of the war on aspects of our business, such as on our distributors, resellers and end-customers. As discussed elsewhere in these risk factors, additional worldwide trade protectionism may increase as a result of the trade policies of the U.S. administration and/or as a result of the global response to such policies. Our efforts to comply with any such measures may be costly and time consuming. We take precautions to ensure that we and our partners comply with all relevant sanctions-related regulations, any alleged or actual failure by us or our partners to comply with such laws and regulations could have negative consequences for us, including reputational harm, government investigations and penalties. The sanctions and other macroeconomic effects of the war or global trade protectionism may also result in the devaluation of the local currency and other inflationary effects. Prolonged economic uncertainties or downturns, globally or in certain regions or industries, could materially adversely affect our business Our business depends on our current and prospective customers’ ability and willingness to invest money in our products and security, which in turn is dependent upon their overall economic health and the strength of the broader macroeconomic environment. The negative economic conditions in the global economy or certain regions, including conditions resulting from financial and credit market fluctuations (including rising interest rates), exchange rate fluctuations, or inflation, and the potential for regional or global recessions could cause a decrease in corporate spending on cyber security software. Other matters that influence customer confidence and spending, such as, political unrest, public health crises, terrorist attacks, armed conflicts (such as the war between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen, and the ongoing conflict between Russia and Ukraine), rising energy costs, and natural disasters, could also negatively affect our customers’ spending on our products and services. The activities of certain terrorist groups in Yemen, have previously limited the movement of marine shipments to Israel through the Red Sea, and the armed conflict involving Russia and Ukraine has resulted in sanctions which restrict the selling of goods, services, or technology in affected regions. The instability in these regions could further exacerbate the macroeconomic impacts on a global scale. Negative economic conditions may cause existing and prospective customers to reduce their spending. Customers may delay or cancel cyber security projects or seek to lower their costs by renegotiating renewals or maintenance and support agreements. Further, customers or channel partners may be more likely to refrain from making payments and/or make late payments in worsening economic conditions. If the economic conditions of the general economy or industries in which we operate continue to worsen from present levels, our business, results of operation and financial condition could be adversely affected. If our products fail to protect against attacks and our customers experience security breaches, our reputation and business could be harmed Hackers and other malevolent actors are increasingly sophisticated, often affiliated with organized crime and operate large scale and complex attacks. In addition, their techniques change frequently and generally are not recognized until launched against a target. If we fail to identify and respond to new and increasingly complex methods of attack and to update our products to detect or prevent such threats in time to protect our customers’ high-value business data, our business and reputation will suffer. In addition, an actual or perceived security breach or theft of the confidential data of one of our customers, regardless of whether the breach is attributable to the failure of our products, could adversely affect the market’s perception of our security products. Despite our best efforts, there is no guarantee that our products will be free of flaws or vulnerabilities, and even if we discover these weaknesses, we may not be able to correct them promptly, if at all. Our customers may also misuse our products, or may not properly configure or securely deploy our products, which could result in a breach or theft of business data. Product defects may increase our costs and impair the market acceptance of our products and technology Our products are complex and must meet stringent quality requirements. They may contain undetected hardware or software errors or defects, especially when new or acquired products are introduced or when new versions are released. In particular, the personal computer hardware environment is characterized by a wide variety of non-standard configurations that make pre-release testing for programming or compatibility errors very difficult and time-consuming. We may need to divert the attention of our engineering personnel from our research and development efforts to address instances of errors or defects. 8 Our products are used to deploy and manage internet security and protect information, which may be critical to organizations. As a result, the sale and support of our products entails the risk of product liability and related claims. We do not know whether, in the future, we will be subject to liability claims or litigation for damages related to product errors, or will experience delays as a result of these errors. Our sales agreements and product licenses typically contain provisions designed to limit our exposure to potential product liability or related claims. In selling our products, we rely primarily on “shrink wrap” licenses that are not signed by the end user, and for this and other reasons, these licenses may be unenforceable under the laws of some jurisdictions. As a result, the limitation of liability provisions contained in these licenses may not be effective. Although we maintain product liability insurance for most of our products, the coverage limits of these policies may not provide sufficient protection against an asserted claim. If litigation were to arise, it could, regardless of its outcome, result in substantial expense to us, significantly divert the efforts of our technical and management personnel, and disrupt or otherwise severely impact our relationships with current and potential customers. In addition, if any of our products fail to meet specifications or have reliability, quality or compatibility problems, our reputation could be damaged significantly and customers might be reluctant to buy our products, which could result in a decline in revenues, a loss of existing customers, and difficulty attracting new customers. We are subject to risks relating to acquisitions We have made acquisitions in the past, including the acquisitions of Cyclops Security Ltd. and Cyata Security Ltd. in February of 2026, the talent of Rotate Ltd. in February of 2026, Lakera AI AG and Veriti Security Ltd. in October and June of 2025, respectively. Cyberint Technologies Ltd. in 2024, Perimeter 81 Ltd., Atmosec Ltd. and rmsource, Inc. in 2023, Spectral Cyber Technologies Ltd in 2022 and Avanan, Inc. in 2021, and we may make additional acquisitions in the future. The pursuit of acquisitions may divert the attention of management and cause us to incur various expenses in identifying, investigating, and pursuing suitable acquisitions, whether or not they are consummated. Competition within our industry for acquisitions of businesses, technologies, assets and product lines has been, and may in the future continue to be, intense. As such, even if we are able to identify an acquisition that we would like to consummate, we may not be able to complete the acquisition on commercially reasonable terms or because the target is acquired by another company. Furthermore, in the event that we are able to identify and consummate any future acquisitions, we could: • issue equity securities which would dilute the current shareholders’ percentage of ownership; • incur substantial debt; • assume contingent liabilities; or • expend significant cash. These financing activities or expenditures could harm our business, results of operations and financial condition or the price of our ordinary shares. Alternatively, due to difficulties in the capital and credit markets, we may be unable to secure capital on acceptable terms, or at all, to complete acquisitions. In addition, we may not be able to integrate acquired personnel, operations, and technologies successfully or effectively manage the combined business following the completion of any future acquisition. Additionally, such integration may impact our revenue and operating results. We may also not achieve the anticipated benefits from the acquired businesses due to a number of factors, including: • unanticipated costs, liabilities or compliance issues associated with the acquisition; • incurrence of acquisition-related costs; • diversion of management’s attention from other business concerns; • harm to our existing business relationships with manufacturers, distributors and customers as a result of the acquisition; • the potential loss of key employees; • use of resources that are needed in other parts of our business; • use of substantial portions of our available cash to consummate the acquisition; or • unrealistic goals or projections for the acquisition. Moreover, even if we do obtain benefits from acquisitions in the form of increased sales and earnings, there may be a delay between the time when the expenses associated with an acquisition are incurred and the time when we recognize such benefits. 9 We are dependent on a limited number of product families Currently, we derive the majority of our revenues from sales of integrated appliances and internet security products, as well as related revenues from security subscriptions and from software updates and maintenance. We expect that this concentration of revenues from a small number of product families will continue for the foreseeable future. Endpoint security products and associated software updates, maintenance, and security subscriptions represent an additional revenue source as well as our cloud initiatives. Our future growth depends heavily on our ability to effectively develop and sell new and acquired products as well as add new features to existing products. For more details, see “Item 4 – Information on Check Point” and “Item 5 – Operating and Financial Review and Prospects”. Competition for highly skilled personnel is intense We compete in a market marked by rapidly changing technologies and an evolving competitive landscape. In order for us to successfully compete and grow, we must attract, recruit, retain and develop personnel, at an appropriate cost, with requisite qualifications to provide expertise across the entire spectrum of our intellectual capital and business needs. In recent years, the industry has experienced record growth and activity and as a result, the high-tech industry in Israel has experienced significant levels of employee attrition and is currently facing a shortage of skilled human capital including in the areas of AI and machine learning. Similar competition for highly skilled personnel exists in the U.S. and in other markets in which we operate. Failure to retain or attract qualified personnel, at an appropriate cost, could have a material adverse effect on our business, financial condition and results of operations. Issues in the development and deployment of AI may result in reputational harm and legal liability and could adversely affect our results of operations We have incorporated, and are continuing to develop and deploy, AI into many of our products and solutions, including services that support our products and solutions. We are also incorporating AI into the operations of our business. AI presents challenges and risks that could affect our products and solutions, and the operations of our business. For example, AI algorithms may have flaws, and datasets used to train models may be insufficient or contain biased information. The AI that is being incorporated into our products, solutions, and business operation tools may not be successful or beneficial, and instead may cause technical, legal or ethical problems or result in increased costs. The investments that we are making across our business in AI reflect our ongoing efforts to innovate and provide products and services that are useful to our customers, as well as provide efficiencies in our business. Such investments ultimately may not be commercially viable or may not result in an adequate return of capital and we may incur unanticipated liabilities. These efforts could subject us to regulatory risk, legal liability, including under legislation regulating AI in jurisdictions such as the E.U. and laws and regulations being considered in other jurisdictions, or brand or reputational harm. The rapid evolution of AI, including potential government regulation of AI, requires us to invest significant resources to develop, test, and maintain AI in our products and services in a manner that meets evolving requirements and expectations. The rules and regulations adopted by policymakers over time may require us to make changes to our business practices. Developing, testing, and deploying AI systems may also increase the cost profile of our offerings due to the nature of the computing costs involved in such systems. The intellectual property ownership and license rights surrounding AI technologies, as well as data protection laws related to the use and development of AI, are currently not fully addressed by courts or regulators. The use or adoption of AI technologies in our products may result in exposure to claims by third parties of copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties. The evolving legal, regulatory, and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringing use. Risks Related to Our Dependence on Third-Parties We are dependent on a small number of distributors We derive our sales primarily through indirect channels. During 2025, 2024 and 2023, we derived approximately 57%, 56% and 56%, respectively, of our sales from our ten largest distributors. In each of 2025, 2024 and 2023, our three largest distributors accounted for approximately 39%, 39% and 40%, respectively, of our sales. We expect that a small number of distributors will continue to generate a significant portion of our sales. Furthermore, there has been an industry trend toward consolidation among distributors, and we expect this trend to continue in the near future which could further increase our reliance on a small number of distributors for a significant portion of our sales. If these distributors reduce the amount of their purchases from us for any reason, including because they choose to focus their efforts on the sales of the products of our competitors, our business, results of operations and financial condition could be materially adversely affected. 10 Our future success is highly dependent upon our ability to establish and maintain successful relationships with our distributors. In addition, we rely on these entities to provide many of the training and support services for our products and equipment. Accordingly, our success depends in large part on the effective performance of these distributors. Recruiting and retaining qualified distributors and training them in our technology and products requires significant time and resources. Further, we have no minimum purchase commitments with any of our distributors, and our contracts with these distributors do not prohibit them from offering products or services that compete with ours. Our competitors may be effective in providing incentives to existing and potential distributors to favor their products or to prevent or reduce sales of our products. Our distributors may choose not to offer our products exclusively or at all. Our failure to establish and maintain successful relationships with distributors would likely materially adversely affect our business, results of operations and financial condition. We purchase several key components and finished products from limited sources, and we are increasingly dependent on contract manufacturers for our hardware products Many components, subassemblies, and modules necessary for the manufacture or integration of our hardware products are obtained from a limited group of suppliers. The majority of our hardware is manufactured in Taiwan. Any increase in the tension between China and Taiwan, could adversely affect our manufacturing operations in Taiwan. Although we do not manufacture in China, some of our component parts are sourced from China. Our reliance on sole or limited suppliers, particularly foreign suppliers, and our reliance on subcontractors involves several risks, including a potential inability to obtain an adequate supply of required components, subassemblies, or modules and limited control over pricing, quality, and timely delivery of components, subassemblies or modules. Such risks could become exacerbated to the extent such suppliers and subcontractors are materially disrupted by quarantines, factory slowdowns or shutdowns and border closings, as well as travel restrictions. For example, global supply chain disruptions associated with geopolitical events, such as the war between the U.S., Israel and Iran and its effects on the delivery of goods through the Strait of Hormuz, and silicon industry impacted the availability of raw products and resulted in prolonged shipping and delivery times. Availability of specific components continues to impact the global supply chain, mainly impacting lead times. Demand is increasing supply requirements and the fast growing technology innovation can impact the availability and manufacturers’ capacity. For example, there is currently a worldwide shortage of semiconductor, memory and other electronic components driven by the proliferation of AI infrastructure and the high energy demands of such production. Our products are dependent upon some of these components and a continued shortage or increased prices drive by global semiconductor shortages may negatively impact our business by increasing lead times and prices from our suppliers, which could adversely affect our results of operations. Any material supply chain disruption could negatively impact our business, financial condition and results of operations. Although we have been successful in the past, replacing suppliers may be difficult and it is possible it could result in an inability or delay in producing designated hardware products. Managing our supplier and contractor relationships is particularly difficult during time periods in which we introduce new products and during time periods in which demand for our products is increasing, especially if demand increases more quickly than we expect. We also have extended support contracts with these suppliers and have been dependent on their ability to perform over a period of years. We incorporate third-party technology in our products, which may make us dependent on the providers of these technologies and expose us to potential intellectual property claims Our products contain certain technology that we license from other companies. Third-party developers or owners of technologies may not be willing to enter into, or renew, license agreements with us regarding technologies that we may wish to incorporate in our products, either on acceptable terms or at all. If we cannot obtain licenses to these technologies, we may be at a disadvantage compared with our competitors who are able to license these technologies. In addition, when we do obtain licenses to third-party technologies that we did not develop, we may have little or no ability to determine in advance whether the technology infringes the intellectual property rights of others. In the event such third-party developers and owners are otherwise unable to provide such technology or services to us, our ability to provide our products and services could be disrupted. This includes mandated government shutdowns. Our suppliers and licensors may not be required or may not be able to indemnify us in the event that a claim of infringement is asserted against us, or they may be required to indemnify us only up to a maximum amount, above which we would be responsible for any further costs or damages. Any failure to obtain licenses to intellectual property or any exposure to liability as a result of incorporating third-party technology into our products could materially and adversely affect our business, results of operations and financial condition. Failures of the third-party technology, third-party servers, cloud service providers, such as AWS, and other third-party hardware, software and infrastructure on which we rely could adversely affect our business We rely on third-party technology, third-party servers, cloud service providers, such as AWS, and other third-party hardware, software and infrastructure to support our operations. The owners and operators of the data centers and cloud services with which we are engaged, and the other third parties on which we rely, do not guarantee uninterrupted or error-free technology, products or services. Problems faced by our third-party providers, including technological or business-related disruptions, could adversely impact our business and results of operations, including by adversely impacting our products and services. Our servers, data centers and other facilities are also vulnerable to damage or interruption from fires, natural disasters, terrorist attacks, power loss, telecommunications failures, pandemics or similar catastrophic events. Disruptions to these servers or facilities could interrupt our ability to provide our products and services and materially adversely affect our business and results of operations. 11 Risks Related to Tax, Legal and Regulatory Matters We are the defendants in various lawsuits and have been subject to tax disputes and governmental proceedings, which could adversely affect our business, results of operations and financial condition As a global company we are subject to taxation in Israel, the United States and various other countries. We attempt to utilize an efficient operating model and accordingly to pay taxes based on the laws in the countries in which we operate. Nonetheless, various tax authorities in different parts of the world may disagree with our operating sale model. This may lead to disputes and to tax assessments, which can have a negative effect on our tax liabilities. In addition, we are subject to the continuous examination by tax authorities around the world. It is possible that tax authorities may disagree with certain positions we have taken and any adverse outcome of such a review, investigation or audit could have a negative effect on our financial position and results of operations. We regularly assess the likelihood of adverse outcomes resulting from these examinations, and audits to determine the adequacy of our provision for income and other taxes, but the determination of our worldwide provision for income taxes and other tax liabilities requires significant judgment by management, and there are transactions where the ultimate tax determination is uncertain. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded in our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made. There can be no assurance that the outcomes from continuous examinations will not have an adverse effect on our business, financial condition and results of operations. In January 2023, the Israeli Tax Authority (the “ITA”) issued orders for the years 2016 through 2019 challenging our positions on several issues and, demanded the payment of additional taxes in the aggregate amount of NIS 536 million (approximately $158 million), not including an amount of NIS 476 million (approximately $140 million) related to expenses that will be deductible in future years, with respect of these four tax years (these amounts include interest and indexation up to the tax settlement’s payment date, i.e. 31 July 2025). On November 29, 2023, the Company filed an appeal to the District Court of Tel Aviv against these orders. In addition, the ITA has issued a tax assessment for the 2020 tax year in which it demanded the payment of additional taxes in the aggregate amount of NIS 94 million (approximately $28 million), not including an amount of NIS 106 million (approximately $31 million) related to expenses that will be deductible in future years, with respect to the 2020 tax year (these amounts include interest and indexation up to the tax settlement’s payment date, i.e. 31 July 2025). On December 31, 2023 we submitted a tax appeal against the 2020 tax assessment to the ITA. On July 15, 2025, the Company and the ITA entered into a settlement agreement under which the Company agreed to pay total additional taxes of NIS 223.2 million (approximately $66 million) in respect of the 2016–2020 tax years, which was ratified by the District Court of Tel Aviv on July 16, 2025. The Company settled the tax demand payment to the ITA on July 31, 2025. The settlement fully and finally resolves all tax matters between the Company and the ITA relating to the 2016-2020 tax years. We are the defendant in various other lawsuits, including employment-related litigation claims, construction claims and other legal proceedings in the normal course of our business. Litigation and governmental proceedings can be expensive, lengthy and disruptive to normal business operations, and can require extensive management attention and resources, regardless of their merit. While we currently intend to defend the aforementioned matters vigorously, we cannot predict the results of complex legal proceedings, and an unfavorable resolution of a lawsuit or proceeding could materially adversely affect our business, results of operations and financial condition. See also “Item 8 – Financial Information” under the caption “Legal Proceedings”. Uncertainties in the interpretation and application of worldwide tax reforms, complex tax laws and regulations could materially affect our tax obligations and effective tax rate On July 4, 2025, the One, Big, Beautiful Bill Act was enacted, which, among other changes to U.S. federal income tax law, permanently suspends the requirement to capitalize and amortize domestic research and development expenditures and permits such deductions on a current basis, and reinstates 100% bonus depreciation for certain qualified property. The Bill also allows to some extent an accelerated amortization of domestic research and development expenditures that had previously been amortized during the years 2022-2024. In addition, California recently enacted a temporary suspension on the use of California net operating loss carryforwards under certain conditions in the taxable years beginning in 2024, 2025 and 2026, and other state tax limitations may apply. The base erosion and profit shifting (“BEPS”) project undertaken by the Organisation for Economic Co-operation and Development (“OECD”) may have adverse consequences to our tax liabilities. The first pillar of BEPS’s project is focused on the allocation of taxing rights between countries for in-scope large multinational enterprises that sell goods and services into countries with minor or no local physical presence. We do not expect to be within the scope of Pillar One. 12 In December 2022, the Council of the European Union (“EU”) unanimously adopted the Directive on BEPS’s Pillar Two ensuring a global minimum tax rate of 15% for certain companies with an annual global turnover of at least €750 million, in the Union (the Directive). The OECD has also issued the Safe Harbours and Penalty Relief : Global Ani-Base Erosion Rules (“Pillar Two Rules”) and related guidance. EU Member States and other non-EU countries enacted legislation to integrate the provisions of the Directive and Pillar Two rules into their national laws by December 31, 2023 and the majority of those countries generally apply these provisions for fiscal years starting on or after December 31, 2023. On December 2025, the Israeli Knesset approved the Minimum Corporate Tax Law (Multinational Group), 2025 (the “Law”) which adopts BEPS’s Pillar Two Rules. The Law introduces a qualified domestic minimum top-up tax, pursuant to which multinational enterprise groups with annual global turnover of at least €750 million are subject to a minimum corporate tax rate of 15% on the Israeli Constituent Entity as defined under the OECD’s Pillar Two Rules. The Law enters into force with effective date of January 1, 2026. In parallel, as part of the Israeli Economic Program Law for the 2026 budget year, legislation to incentivize research and development activities (the “R&D Incentive Legislation”) was enacted on March 30, 2026 and entered into force as of January 1, 2026. The R&D Incentive Legislation introduces a tax credit, at varying rates based on specified thresholds, for qualifying research and development expenditures incurred in Israel by eligible Israeli companies that are part of multinational enterprise groups, subject to meeting defined eligibility criteria. The tax credit may be utilized to offset Israeli corporate income tax or the Israeli domestic minimum top-up tax. In addition, the R&D Incentive Legislation, subject to conditions as prescribed therein, provides that all or a portion of the unutilized R&D tax credit will be provided to eligible companies in the form of a cash grant upon the lapse of a period stipulated by the R&D Incentive Legislation, rather than being utilized solely as a tax credit. This mechanism is intended, among other things, to support the qualification of the incentive under the OECD Pillar Two framework. The implementation of the Israeli Pillar Two Law is expected to increase our reported tax expenses beginning in 2026. Based on the current Proposed R&D Incentive Legislation and its associated tax credit, and assuming enactment effective January 1, 2026, income tax expense is expected to increase, while the net cash impact is not expected to be material. However, the ultimate impact will depend on the final form of the proposed R&D Incentive Legislation, if and when enacted and the amount of tax credits approved thereunder. We are currently monitoring the local minimum corporate tax legislations in the relevant jurisdictions and awaiting further guidance on the Israeli Proposed R&D Incentive Legislation and its effective date. Indirect taxes, including digital service tax (“DST”) measures as unilaterally adopted by certain jurisdiction, could also adversely affect our tax obligations. These measures generally aim at securing taxation rights of the jurisdiction for the revenues/profits generated by the transnational e-commerce activities with customers who are resident in this specific jurisdiction. Current or future attempts to impose sales, income, or other taxes on e-commerce would likely increase the cost of doing business online and decrease the attractiveness of advertising and selling products over the internet and could lead to significant increases in internal costs necessary to capture data and collect and remit taxes. Finally, we are subject to audit by taxing authorities in several jurisdictions, and tax laws may be interpreted differently by the competent tax authorities and courts, which could lead to an increase of our tax burden and increased costs to us to comply with new laws and interpretations thereof and tax auditors. New taxes or reporting obligations could also result in additional costs necessary to collect the data required to assess these taxes and to remit them to the relevant tax authorities or to comply with these reporting obligations. Class action litigation due to stock price volatility or other factors could cause us to incur substantial costs and divert our management’s attention and resources In the past, following periods of volatility in the market price of a public company’s securities, securities class action litigation has often been instituted against that company. Companies such as ours in the technology industry are particularly vulnerable to this kind of litigation as a result of the volatility of their stock prices. We have been named as a defendant in this type of litigation in the past. Any litigation of this sort in the future could result in substantial costs and a diversion of management’s attention and resources. 13 We are subject to governmental export and import controls that could subject us to liability or impair our ability to compete in international markets Because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the U.S. only with the required export license or through an export license exception. If we were to fail to comply with U.S. export licensing requirements, U.S. customs regulations, U.S. economic sanctions, or other laws, we could be subject to substantial civil and criminal penalties, including fines, incarceration for responsible employees and managers, and the possible loss of export or import privileges. Obtaining the necessary export license for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities. Furthermore, U.S. export control laws and economic sanctions prohibit the shipment of certain products to U.S. embargoed or sanctioned countries, governments, and persons. Even though we take precautions to ensure that we comply with all relevant regulations, any failure by us or any partners to comply with such regulations could have negative consequences for us, including reputational harm, government investigations, and penalties. In addition, various countries regulate the import of certain encryption technology, including through import permit and license requirements, and have enacted laws that could limit our ability to distribute our products or could limit our end-customers’ ability to implement our products in those countries. Changes in our products or changes in export and import regulations for whatever reason may create delays in the introduction of our products into international markets, prevent our end-customers with international operations from deploying our products globally or, in some cases, prevent or delay the export or import of our products to certain countries, governments, or persons altogether. Any change in export or import regulations, economic sanctions or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons, or technologies targeted by such regulations or protectionist measures, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential end-customers with international operations. Any decreased use of our products or limitation on our ability to export to or sell our products in international markets would likely adversely affect our business, financial condition, and results of operations. Changes in government trade policies and international trade disputes that result in tariffs and other protectionist measures could adversely affect our business in the future The U.S. government and the current administration have made public statements and taken certain actions indicating significant changes in U.S. trade policy, including imposing new or increased tariffs on certain goods imported into the United States from Canada, Mexico and China. In response, a number of other countries have announced an intention to impose additional duties on imports from the United States. To date, our business has not been affected by such actions. However, changes in government trade policies and international trade disputes that result in tariffs and other protectionist measures could adversely affect our business in the future. Risks Related to Our Intellectual Property We may not be able to successfully protect our intellectual property rights, which could cause substantial harm to our business We seek to protect our proprietary technology by relying on a combination of statutory as well as common law copyright and trademark laws, trade secrets, confidentiality procedures and contractual provisions as indicated below in the section entitled “Proprietary Rights” in “Item 4 – Information on Check Point”. We have certain patents in the United States and in several other countries, as well as pending patent applications. We cannot assure you that pending patent applications will be issued, either at all or within the scope of the patent claims that we have submitted. In addition, someone else may challenge our patents and these patents may be found invalid. Furthermore, others may develop technologies that are similar to or better than ours, or may work around any patents issued to us. Despite our efforts to protect our proprietary rights, others may copy aspects of our products or obtain and use information that we consider proprietary. In addition, the laws of some foreign countries do not protect our proprietary rights to the same extent as the laws of the United States and Israel. Our efforts to protect our proprietary rights may not be adequate and our competitors may independently develop technology that is similar to our technology. In addition to patents, we rely on trade secret and other rights to protect our unpatented proprietary intellectual property and technology. Despite our efforts to protect our proprietary technologies and our intellectual property rights, unauthorized parties, including our employees, consultants, service providers or customers, may attempt to copy aspects of our products or obtain and use our trade secrets or other confidential information. We generally enter into confidentiality agreements with our employees, consultants, and other service providers, and generally limit access to and distribution of our proprietary information and proprietary technology through certain procedural safeguards. These agreements and arrangements may not effectively prevent unauthorized use or disclosure of our intellectual property or technology and may not provide an adequate remedy in the event of unauthorized use or disclosure of our intellectual property or technology. We cannot be certain that the steps taken by us will prevent misappropriation of our intellectual property or technology or infringement of our intellectual property rights. 14 If we are unable to secure, protect and enforce our intellectual property rights, such failure could harm our brand and adversely impact our business, financial condition and results of operations. We incorporate open source technology in our products which may expose us to liability and have a material impact on our product development and sales Some of our products utilize open source technologies. These technologies are licensed to us under varying license structures, including the General Public License. If we have improperly used, or in the future improperly use, software that is subject to such licenses with our products in such a way that our software becomes subject to the General Public License, we may be required to disclose our own source code to the public. This could enable our competitors to eliminate any technological advantage that our products may have over theirs. Any such requirement to disclose our source code or other confidential information related to our products could materially and adversely affect our competitive position and impact our business, results of operations and financial condition. If a third-party asserts that we are infringing its intellectual property, whether successful or not, it could subject us to costly and time-consuming litigation or expensive licenses, which could harm our business There is considerable patent and other intellectual property development activity in our industry. Our success depends, in part, upon our ability not to infringe upon the intellectual property rights of others. Our competitors, as well as a number of other entities and individuals, own or claim to own intellectual property relating to our industry. From time to time, third parties have brought, and continue to bring, claims that we are infringing upon their intellectual property rights, and we may be found to be infringing upon such rights. In addition, third-parties have in the past sent us correspondence claiming that we infringe upon their intellectual property, and in the future we may receive claims that our products infringe or violate their intellectual property rights. Furthermore, we may be unaware of the intellectual property rights of others that may cover some or all of our technology or products. Any claims or litigation could cause us to incur significant expenses and, if successfully asserted against us, could require that we pay substantial damages or royalty payments, prevent us from selling our products, or require that we comply with other unfavorable terms. In addition, we may decide to pay substantial settlement costs and/or licensing fees in connection with any claim or litigation, whether or not successfully asserted against us. Even if we were to prevail, any disputes or litigation regarding intellectual property matters could be costly and time-consuming and divert the attention of our management and key personnel from our business operations. As such, third-party claims with respect to intellectual property may increase our cost of goods sold and operating expenses, reduce the sales of our products, and may have a material and adverse effect on our business. Due to the global nature of our business, we must comply with various anti-bribery regimes and any failure to do so could adversely affect our business The global nature of our business creates various domestic and local regulatory challenges. The U.S. Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.K. Bribery Act 2010 (the “U.K. Bribery Act”), Chapter 9 (sub-chapter 5) of the Israeli Penal Law, 1977, the Israeli Prohibition on Money Laundering Law – 2000 (the “Israeli Anti-Bribery Laws”) and similar anti-bribery laws in other jurisdictions generally prohibit companies and their intermediaries from making improper payments to foreign government officials and other persons for the purpose of obtaining or retaining business. In addition, companies are required to maintain records that accurately and fairly represent their transactions and have an adequate system of internal accounting controls. Further, changes in laws could result in increased regulatory requirements and compliance costs which could adversely affect our business, financial condition and results of operations. As a result, we are exposed to a risk of violating anti-bribery laws in the countries where we operate. Although we have internal policies and procedures, including a code of ethics and proper business conduct, reasonably designed to promote compliance with anti-bribery laws, we cannot assure that our employees or other agents will not engage in prohibited conduct and render us responsible under the FCPA, the U.K. Bribery Act, the Israeli Anti-Bribery Laws or any similar anti-bribery laws in other jurisdictions. If we are found to be in violation of the FCPA, the U.K. Bribery Act, the Israeli Anti-Bribery Laws or other anti-bribery laws (either due to acts or inadvertence of our employees, or due to the acts or inadvertence of others), we could suffer criminal or civil penalties or other sanctions, which could have a material adverse effect on our business, results of operations, cash flows, financial condition, reputation and ability to win future business or maintain existing contracts. Other General Risks and Risks Related to the Ownership of Our Ordinary Shares We are exposed to various legal, business, political, economic, health-related and other risks associated with our international operations; these risks could increase our costs, reduce future growth opportunities and affect our results of operations We operate our business primarily from Israel, we sell our products worldwide, and we generate a significant portion of our revenue outside the United States. We intend to continue to expand our international operations, which will require significant management attention and financial resources. In order to continue to expand worldwide, we will need to establish additional operations, hire additional personnel and recruit additional channel partners internationally. To the extent that we are unable to do so effectively, our growth is likely to be limited and our business, results of operations and financial condition may be materially adversely affected. 15 Our international sales and operations subject us to many potential risks inherent in international business activities, including, but not limited to: • technology import and export license requirements; • costs of localizing our products for foreign countries, and the lack of acceptance of localized products in foreign countries; • varying economic and political instability or war, including the war between Israel, the U.S. and Iran and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen and the significant military action against Ukraine launched by Russia; • potential tariffs, sanctions, fines or other trade restrictions, including any political or economic responses and counter-responses or otherwise by various global actors to the significant military action against Ukraine launched by Russia, as well as the possibility of further international trade disputes that result in tariffs and other protectionist measures; • imposition of or increases in tariffs or other payments on our revenues in these markets; • greater difficulty in protecting intellectual property; • difficulties in managing our overseas subsidiaries and our international operations; • economic, social, or political conditions, including conditions resulting from a decline in the macroeconomic environment, rising interest rates, exchange rate fluctuations and inflation; • political instability and civil unrest which could discourage investment and complicate our dealings with governments; • widespread health emergencies or pandemic; • difficulties in complying with a variety of foreign laws and legal standards and changes in regulatory requirements; • expropriation and confiscation of assets and facilities; • difficulties in collecting receivables from foreign entities or delayed revenue recognition; • recruiting and retaining talented and capable employees; • differing labor standards; • increased tax rates; • potentially adverse tax consequences, including taxation of a portion of our revenues at higher rates than the tax rate that applies to us in Israel; • fluctuations in currency exchange rates and the impact of such fluctuations on our results of operations and financial position; and • the introduction of exchange controls and other restrictions by foreign governments. These difficulties could cause our revenues to decline, increase our costs or both. This is also specifically tied to currency exchange rates which have an impact on our financial statements based on currency rate fluctuations. Our actual or perceived failure to adequately protect personal data or customer data, or to otherwise comply with data privacy and protection laws and regulations or other technology related regulations, could subject us to sanctions and damages and could harm our reputation and business A variety of state, national, foreign, and international laws and regulations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data and customer data, and other areas in new and evolving technologies. These laws and regulations, as demonstrated by the examples below, continue to evolve. New or modified laws and regulations relating to these matters are proposed and implemented frequently and existing laws and regulations subject to new or different interpretations. Compliance with these laws and regulations can be costly and can delay or impede the development and offering of new products and services. 16 For example, the General Data Protection Regulation (“GDPR”) (which is applicable in both the EU and the UK), imposes stringent requirements for data processors and controllers. Such requirements include amongst other things, obligations to: i) provide data subjects with fulsome disclosures about the processing of personal information; ii) adhere to reasonable data retention limits; iii) comply with individual requests in relation to their personal data, including access and deletion requests; iv) ensure suitable security / protection of personal data and comply with mandatory notification requirements in the case of a data breach; v) adhere to elevated standards regarding valid consent in some specific cases of data processing; and vi) comply with stringent data transfer obligations, including in relation to international transfers of personal data. The GDPR also includes potentially severe penalties for failure to comply, inter alia, a fine up to 20 million EUR / 17.5 million GBP (as applicable) or up to 4% of the annual worldwide turnover, whichever is greater, which can be imposed. Compliance with these stringent requirements on privacy user notifications and data handling (both as they apply to us but also our customers) could increase our financial risk exposure, require us to adapt our business in order to comply with the GDPR requirements and incur additional costs. Additionally, the United States has various privacy laws with privacy laws now having been implemented in 19 US states. In some respects the laws across US states are harmonised but there remain points of difference and fragmented regulations increase the burden of compliance. In California, the California Consumer Privacy Act (“CCPA”) and California Privacy Rights Act (“CPRA”) provide data privacy rights for consumers and privacy-related operational requirements for companies. The CCPA and CPRA, and other US state laws are making it easier for certain individuals to opt-out of having their personal data processed and disclosed to third parties through various opt-out mechanisms, which could result in an increase to our operational costs to ensure compliance with such legal and regulatory requirements. Other jurisdictions have also enacted and strengthened data protection laws, which have increased the cost of complying with them for businesses. For example, Israel has enacted laws and regulations relating to privacy, data protection, and security, including Israeli Privacy Protection Law 5741-1981 and its associated regulations that have brought the Israeli regime closer to the GDPR, in particular with regard to enforcement with the law providing for administrative fines of up to 5% of global turnover. In Latin America, Brazil’s Lei Geral de Proteção de Dados (LGPD), one of the most impactful data protection laws in Latin America, is largely aligned to the GDPR. In China, Personal Information Protection Law of the People’s Republic of China (“PIPL”) applies and has parallels with the GDPR given that is has extra-territorial effect, applying to data processing activities in China and outside of China in certain circumstances. In Australia, the Privacy and Other Legislation Amendment Act 2024 (POLA) modernised Australia’s data privacy legislation and introducing GDPR‑style features, new enforcement powers, and expanded individual rights. In addition, the increasing use of artificial intelligence and AI-enabled tools in business operations, including by third-party service providers, may increase the risk that personal data is processed, disclosed or retained in ways that are inconsistent with applicable data protection laws or contractual obligations. Regulatory frameworks governing the use of AI and automated data processing are also evolving in multiple jurisdictions (for example in the EU through the EU AI Act), which may further increase our compliance costs and exposure to regulatory scrutiny, penalties and other liabilities, all of which could have a material adverse effect on our business and results of operations. Stringent privacy, data protection and security requirements in the GDPR, CCPA, and other laws and regulations (e.g., in those regulating AI) could decrease demand for our products and services, increase our costs, and impair our ability to maintain and grow our customer base and increase our revenue, We may face challenges in addressing these requirements and making necessary changes to our policies and practices, and may incur significant costs and expenses in an effort to do so. Moreover, because the interpretation and application of many laws, regulations, industry standards, contractual obligations and other actual and asserted obligations to which we are or may become subject relating to privacy, data protection, security, AI, and other new and evolving areas are uncertain, it is possible that these laws, regulations, industry standards, contractual obligations or other actual or asserted obligations to which we are or may become subject may be interpreted and applied in a manner that is inconsistent with our existing or future data processing practices or features of our products and services. Our actual or alleged failure to comply with applicable laws and regulations, or any other actual or asserted obligations relating to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data and customer data, could result in investigations, enforcement actions and other proceedings, significant penalties imposed or sought by a regulator or data subject, claims, demands, and litigation or other legal action or proceedings against us or our customers or suppliers, which could result in negative publicity, increased operating costs, restrictions upon our practices and damages, financial penalties and other liabilities, all of which could have a material adverse effect on our business and results of operations. Issues relating to our use of artificial intelligence and machine learning technologies, combined with an uncertain legal and regulatory environment, could materially and adversely affect our business, financial condition and results of operations. We have incorporated and may continue to incorporate artificial intelligence and machine learning solutions and features into our products or services, and otherwise within our business, and these solutions and features may become more important to our operations, including our product development, product demand, customer support and internal processes, or to our future growth over time. There can be no assurance that we will realize the desired or anticipated benefits from artificial intelligence and machine learning technologies, or at all, and we may fail to properly implement or market our artificial intelligence and machine learning solutions and features. Additionally, our artificial intelligence and machine learning solutions and features may expose us to additional claims, demands, and proceedings by private parties and regulatory authorities and subject us to legal liability as well as brand and reputational harm. For example, if artificial intelligence models used in our products or services are incorrectly designed, the data used to train them is incomplete or inadequate, or we do not have sufficient rights to use data on which such models rely, the performance of our artificial intelligence and machine learning solutions and features, as well as our reputation, could suffer or we could incur liability through the violation of contractual or regulatory obligations. The legal, regulatory, and policy environments around artificial intelligence and machine learning are evolving rapidly. For example, the EU Artificial Intelligence Act (the “AI Act”), which achieved approval by the European Council on February 2, 2024, and the European Parliament on March 13, 2024, imposes obligations on providers and users of artificial intelligence technologies. The AI Act may impact the development and adoption of our artificial intelligence and machine learning solutions in Europe. Additionally, several U.S. states have proposed, and in certain cases have enacted, legislation imposing obligations in connection with the development or use of, or otherwise regulating, artificial intelligence and machine learning technologies. Other countries also are contemplating laws regulating artificial intelligence and machine learning technologies. We may become subject to new legal and other obligations in connection with our use of artificial intelligence and machine learning, which could require us to make significant changes to our policies and practices, necessitating expenditure of significant time, expense, and other resources. 17 Repaying and servicing our existing and future debt, including our outstanding Convertible Notes may require a significant amount of cash, and we may not have sufficient cash flow from our business to pay our indebtedness. Our ability to make scheduled payments of the principal of the Convertible Notes depends on our future performance, which is subject to economic, financial, competitive, and other factors beyond our control. Our business may not generate cash flow from operations in the future sufficient to service our debt and make necessary capital expenditures. If we are unable to generate such cash flow, we may be required to adopt one or more alternatives, such as selling assets, restructuring debt, or obtaining additional debt financing or equity capital on terms that may be onerous or highly dilutive. Our ability to refinance any future indebtedness will depend on the capital markets and our financial condition at such time. We may not be able to engage in any of these activities or engage in these activities on desirable terms, which could result in a default on our debt obligations. In addition, our indebtedness, combined with our other financial obligations and contractual commitments, could have other important consequences. For example, it could: • make us more vulnerable to adverse changes in general economic, industry, and competitive conditions and adverse changes in government regulation; • limit our flexibility in planning for, or reacting to, changes in our business and our industry; • place us at a disadvantage compared to our competitors who have less debt; • limit our ability to borrow additional amounts to fund acquisitions, for working capital, and for other general corporate purposes; and • make an acquisition of our company less attractive or more difficult. Any of these factors could harm our business, results of operations, and financial condition. In addition, if we incur additional indebtedness, the risks related to our business and our ability to service or repay our indebtedness would increase. Our Convertible Notes may impact our financial results, result in the dilution of existing shareholders and create downward pressure on the price of our ordinary shares. In December 2025, we issued and sold $2.0 billion aggregate principal amount of 0.00% Convertible Senior Notes due 2030 (the “Convertible Notes”), in a private offering to qualified institutional buyers pursuant to Rule 144A under the Securities Act of 1933, as amended, all of which were outstanding as of December 31, 2025. Our Convertible Notes may affect our earnings per share figures, as accounting procedures may require that we include in our calculation of earnings per share the number of ordinary shares into which the Convertible Notes are convertible. The Convertible Notes may be converted under the conditions specified in the indenture governing the Convertible Notes (the “Indenture”). Upon conversion, we will satisfy our conversion obligation by paying cash up to the aggregate principal amount of the Convertible Notes being converted and by paying and/or delivering, as the case may be, ordinary shares or cash or a combination of cash and ordinary shares, at our election, in respect of the remainder, if any, of our conversion obligation in excess thereof. If our ordinary shares are issued to holders of the Convertible Notes upon conversion, it will cause dilution to our shareholders’ equity, and the market price of our ordinary shares may decrease due to the additional selling pressure in the market. We may determine in the future to repurchase all or portions of the outstanding Convertible Notes from time to time in accordance with applicable Securities and Exchange Commission (“SEC”) and other legal requirements and in consideration of market and other conditions. Any repurchases or exchanges of our outstanding Convertible Notes are likely to affect the market price of our ordinary shares. We expect that holders of any Convertible Notes that are repurchased or exchanged may enter into or unwind various derivatives with respect to our ordinary shares and/or purchase or sell our ordinary shares in the market to hedge their exposure in connection with these transactions. In addition, in connection with any repurchases of the Convertible Notes, the counterparties to the Capped Call (as defined below) or their respective affiliates may modify their hedge positions with respect to the Capped Call by entering into or unwinding various derivatives with respect to our ordinary shares and/or purchasing or selling our ordinary shares or other securities of ours in secondary market transactions. This activity could impact the market price of our ordinary shares at that time. 18 Our ability to pay cash upon conversion or repurchase of the Convertible Notes may be limited. If the last reported sale price of our ordinary shares on the trading day immediately preceding the business day immediately preceding December 15, 2028 is less than 110% of the conversion price, holders of the Convertible Notes have the right to require us to repurchase for cash all or any portion of their Convertible Notes on December 15, 2028 at a repurchase price equal to 100% of the principal amount of the Convertible Notes to be repurchased, plus accrued and unpaid “special interest” (as defined in the Indenture) to, but excluding, the repurchase date. Additionally, holders of the Convertible Notes have the right, subject to and under the terms of the Indenture to require us to repurchase all or a portion of their Convertible Notes upon the occurrence of a “fundamental change” before the maturity date, at a repurchase price equal to 100% of the principal amount of such Convertible Notes to be repurchased, plus accrued and unpaid special interest, if any. Our ability to repurchase the Convertible Notes upon any required repurchase event or to pay cash upon maturity or conversion of Convertible Notes may be limited by law, regulatory authority, or agreements governing our future indebtedness or cash liquidity constraints. In addition, we may not have enough available cash or be able to obtain financing at the time we are required to make repurchases of the Convertible Notes surrendered or Convertible Notes being converted. Our failure to repurchase the Convertible Notes at a time when the repurchase is required by the Indenture or to pay cash upon maturity or conversion of such Convertible Notes as required by the Indenture would constitute a default under the Indenture. A default under the Indenture or the fundamental change itself within the meaning of the Indenture could also lead to a default under agreements governing our future indebtedness. If the payments of the related indebtedness were to be accelerated after any applicable notice or grace periods, we may not have sufficient funds to repay the indebtedness and repurchase the Convertible Notes or to pay cash upon conversion of the Convertible Notes. Our capped call transactions may affect the value of our ordinary shares. In connection with the pricing of the Convertible Notes, we entered into privately-negotiated capped call transactions (“Capped Calls”) with certain financial institutions (the “option counterparties”). The Capped Calls are expected generally to reduce the potential dilution to our ordinary shares upon any conversion of the Convertible Notes and/or offset any cash payments we are required to make in excess of the principal amount of converted Convertible Notes, as the case may be, with such reduction and/or offset subject to a cap. The option counterparties and/or their respective affiliates may modify their hedge positions by entering into or unwinding various derivatives with respect to our ordinary shares and/or purchasing or selling our ordinary shares or other securities of ours in secondary market transactions prior to the maturity of the Convertible Notes (and are likely to do so following any conversion of the Convertible Notes, any repurchase of the Convertible Notes by us on any fundamental change repurchase date, any redemption date or any other date on which the Convertible Notes are retired by us, in each case, if we exercise the relevant election under the Capped Calls and in connection with any negotiated unwind or modification of the Capped Calls). This activity could cause or avoid an increase or a decrease in the market price of our ordinary shares. The potential effect, if any, of these transactions and activities on the trading price of our ordinary shares will depend in part on market conditions. Any of these activities could adversely affect the market price of our ordinary shares. We are subject to counterparty risk with respect to the capped call transactions. We are subject to the risk that any of the option counterparties may default under the Capped Calls. Our exposure to the credit risk of the option counterparties under the Capped Calls will not be secured by any collateral. Past global economic conditions, including recent increases in prevailing interest rates, have resulted in the actual or perceived failure or financial difficulties of many financial institutions. If an option counterparty becomes subject to insolvency proceedings, we will become an unsecured creditor in those proceedings with a claim equal to our exposure at that time under our transactions with them. Our exposure will depend on many factors. Generally, the increase in our exposure will be correlated to the increase in the market price and in the volatility of our ordinary shares. In addition, upon a default by any counterparty to any capped call transactions, we may suffer more dilution than we currently anticipate with respect to our ordinary shares. We can provide no assurances as to the financial stability or viability of the option counterparties. Compliance with new and changing corporate governance and public disclosure requirements adds uncertainty to our compliance policies and increases our costs of compliance Changing laws, regulations and standards relating to accounting, corporate governance and public disclosure, including the Sarbanes-Oxley Act of 2002, the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank”), new SEC regulations, amendments to the Israeli Companies Law and Nasdaq rules are creating increased compliance costs and uncertainty for companies like ours. These new or changed laws, regulations and standards may lack specificity and are subject to varying interpretations. The implementation of these laws and their application in practice may evolve over time as new guidance is provided by regulatory and governing bodies. This could result in continuing uncertainty regarding compliance matters and higher costs of compliance as a result of ongoing revisions to such governance standards. 19 In addition, continuing compliance with Section 404 of the Sarbanes-Oxley Act of 2002 and the related regulations regarding our required assessment of our internal control over financial reporting requires the commitment of significant financial and managerial resources and the report of an independent registered public accounting firm on the Company’s internal control over financial reporting. In connection with our Annual Report for fiscal 2025, our management assessed our internal control over financial reporting, and determined that our internal control over financial reporting was effective as of December 31, 2025, and our independent auditors have expressed an unqualified opinion over the effectiveness of our internal control over financial reporting as of December 31, 2025. However, we will undertake management assessments of our internal control over financial reporting in connection with each annual report, and any deficiencies uncovered by these assessments or any inability of our auditors to issue an unqualified report could harm our reputation and the price of our ordinary shares. A small number of shareholders own a substantial portion of our ordinary shares, and they may make decisions with which you or others may disagree As of February 28, 2026, our directors and executive officers owned approximately 23.96% of the voting power of our outstanding ordinary shares, or 25.43% of our outstanding ordinary shares if the percentage includes options currently exercisable or exercisable within 60 days of February 28, 2026 and RSUs and PSUs vesting within 60 days of February 28, 2026. The interests of these shareholders may differ from your interests and present a conflict. If these shareholders act together, they could exercise significant influence over our operations and business strategy. For example, although these shareholders hold considerably less than a majority of our outstanding ordinary shares, they may have sufficient voting power to influence matters requiring approval by our shareholders, including the election and removal of directors and the approval or rejection of mergers or other business combination transactions. In addition, this concentration of ownership may delay, prevent or deter a change in control, or deprive a shareholder of a possible premium for its ordinary shares as part of a sale of our company. Our cash balances and investment portfolio have been, and may continue to be, adversely affected by market conditions and interest rates We maintain substantial balances of cash and liquid investments, for purposes of general corporate purposes, which may include acquisitions, share repurchases and other purposes. Our cash, cash equivalents, short-term bank deposits and fixed-income marketable securities valued total of $4,342 million as of December 31, 2025. The performance of the debt capital markets affects the market values of funds that are held in marketable securities. These assets are subject to price fluctuations, changes in interest rates and credit spreads, market liquidity and various other factors, including, without limitation, rating agency upgrades / downgrades that may impair some or all of their value, or unexpected changes in the financial markets’ healthiness worldwide. We expect that market conditions will continue to fluctuate and the fair value of our investments may be affected accordingly. Moreover, in case we would like to liquidate some of our investments into cash – we are dependent on market conditions and liquidity opportunities, which may be impacted by economic, social, or political conditions, including, without limitation, conditions resulting from a decline in the macroeconomic environment, rising interest rates, exchange rate fluctuations, inflation, global pandemics, global supply chain disruptions and conditions resulting from geopolitical uncertainty and instability or wars. Financial income is an important component of our net income. The outlook for our financial income is dependent on many factors, some of which are beyond our control, and they include the future direction of interest rates, foreign exchange rates, amount of any share repurchases, acquisitions that we may execute and the amount of cash flows from operations that are available for investment. We rely on third-party money managers to manage the majority of our investment portfolio in a risk-controlled framework and subject to our investment policy. Our investment portfolio is invested primarily in fixed-income securities and short-term bank deposits, and is affected primarily by changes in interest rates and credit spreads. Interest rates are highly sensitive to many factors, including governmental monetary policies and domestic and international economic and political conditions, such as the wars and significant military actions around the globe and any related political or economic responses and counter-responses or otherwise by various global actors or general effect on the global economy. Any significant decline in our financial income or the value of our investments due to changes in interest rates, interest rate expectations, credit spreads, deterioration in the credit rating of the securities in which we have invested, or general market conditions, could have an adverse effect on our results of operations and financial condition. We generally buy and hold our fixed income securities, while limiting credit risk by setting a maximum concentration limit per issuer as well as setting minimum credit rating requirement. Our fixed income investment portfolio consists primarily of government bonds, securities issued by government agencies and corporate debentures. Although we believe that we generally adhere to conservative investment guidelines, a turmoil in the financial markets may result in impairments of the carrying value of our investment assets. We classify our investments in fixed maturity securities as available-for-sale. Changes in the fair value of investments classified as available-for-sale are not recognized as income during the period, but rather are recognized as a separate component of equity until realized. Realized losses in our investments portfolio may adversely affect our financial position and results. Had we reported the cumulative changes in the fair value of our fixed income securities as part of our income, our reported net income for the year ended December 31, 2025, would have increased by $10 million. 20 Currency fluctuations may affect the results of our operations or financial condition Our functional and reporting currency is the U.S. dollar. We generate a majority of our revenues and expenses in U.S. dollars. In 2025, we incurred approximately 42% of our expenses in foreign currencies, primarily Israeli Shekels and Euros. As such, changes in exchange rates may have a material adverse effect on our business, results of operations and financial condition. The exchange rates between the U.S. dollar and certain foreign currencies have fluctuated substantially in recent years and may continue to fluctuate substantially in the future. We expect that a majority of our revenues will continue to be generated in U.S. dollars for the foreseeable future and that a significant portion of our expenses, including payroll related costs, as well as capital and operating expenditures, will continue to be denominated in the currencies referred to above. The results of our operations may be adversely affected in relation to foreign exchange fluctuations. During 2025, we entered into forward contracts to hedge against some of the risk of foreign currency exchange rates fluctuations resulting in changes in future cash flow from payments of payroll and related expenses denominated in Israeli Shekels and Euros. As of December 31, 2025, our total outstanding forward contracts that hedge against these fluctuations in foreign currency exchange rates was $329 million. In addition, we entered into forward contracts to hedge the impact of fluctuations in exchange rates on assets and liabilities denominated in Israeli Shekels and other currencies. As of December 31, 2025, the total amount of outstanding forward contracts that did not qualify for hedge accounting, was $196 million. We may use derivative financial instruments, such as foreign exchange forward contracts, put and call options, and others, to mitigate the risk of fluctuations changes in foreign exchange rates on assets, cash flows receivables and payables denominated in certain currencies. We may not be able to purchase derivative instruments adequate to fully protect us from foreign currency exchange risks. Additionally, our hedging activities may also generate losses as a result of volatility in foreign currency markets. If foreign exchange markets continue to be volatile, such fluctuations in foreign exchange rates could materially and adversely affect our profit margins and results of operations in future periods. Also, the volatility in the foreign exchange markets may make it difficult to hedge our foreign currency exposures effectively. The imposition of exchange or price controls or other restrictions on the conversion of foreign currencies could also have a material adverse effect on our business, results of operations and financial condition. Changes in foreign exchange rates around the globe, could have an adverse impact on our business and results of operations. These changes may have an impact on some of our expenses which are paid in local currencies (non-US dollar), as well as an impact on our non-US customers which have their financials in non-US dollar currencies. Our information technology systems, networks and products and services have been, and may continue to be, subject to various security threats and cyber security incidents Our information technology systems, networks, products, and services have in the past and may in the future be subject to various security threats or cyber security incidents, including from computer malware, malicious code injection, ransomware, viruses, social engineering (including phishing attacks), denial of service or other attacks, human error, technical errors, employee theft or misuse and general hacking. For example, we regularly face attempts by others to gain unauthorized access, or to introduce malicious software to our information technology systems, and certain of these attempts have been successful. Additionally, malicious hackers have attempted and in the future likely will attempt to gain unauthorized access to, or sabotage, take control of or otherwise corrupt, our information technology systems, networks, processes, products and services. We are also a target of attempts to gain access to our network or data centers or those of our customers or end users, steal proprietary information related to our business, products, services, employees, and customers, or interrupt our information technology systems or networks or those of our customers or others. We may also be subject to increasing risks in connection with geopolitical events and conflicts, such as the war that began on February 28, 2026 between Israel, the United Stated and Iran resulting in Iran launching thousands of ballistic missiles and drones against civilian targets in Israel and against U.S. military bases and other civilian targets in several countries in the Persian Gulf, and Hezbollah, a terrorist organization based in Lebanon, launching hundreds of missiles and drones Israeli military sites and civilian targets in Northern Israel, the Russia-Ukraine and the war and hostilities between Israel and Hezbollah, Hamas and Yemen, including risks of a security breach or incident, ransomware, destructive malware, and distributed denial-of-service attacks, as well as fraud, spam and fake accounts, cyber attacks or other threats or illegal activity. Additionally, with many of our employees continuing to work remotely, we face an increased risk of attempted security breaches and incidents. 21 We also have incorporated machine learning and other artificial intelligence technologies into aspects of our products, services, and business, and may continue to incorporate additional artificial technologies into our products and services and otherwise in our business and operations in the future. The use of artificial intelligence technologies may create additional cyber security risks or increase cyber security risks and may result in security breaches or other types of cyber security incidents. Further, artificial intelligence technologies may be used in connection with certain cyber security attacks, resulting in heightened risks of security breaches and incidents. There also have been and may continue to be significant supply chain attacks (such as the attacks resulting from vulnerabilities in SolarWinds Orion and other widely-used software and technology infrastructure) and we cannot guarantee that our or our third-party providers’ systems have not been breached or compromised or that they do not contain exploitable defects, vulnerabilities, or bugs that could result in a security breach or incident of or impacting, or other disruption to, our information technology systems, networks, products or services, or those of third parties that support us and our platform. We have been impacted by security incidents of widely trusted third-party software and technology infrastructure, such as the SolarWinds Orion incident in December 2020. We have taken steps to protect our information technology systems, networks and products and services, but our security measures or those of our customers or third-party service providers could be insufficient and breached or otherwise compromised or disrupted, including as a result of third-party action, employee, customer or user errors, technological limitations, defects or vulnerabilities, malfeasance, fraud or malice on the part of employees or third parties, including state-sponsored organizations with significant financial and technological resources, or from failures in technological resources, failures to comply with policies or otherwise. We have been, and may in the future be, impacted by these threats and our internal controls and operations regarding security may not be effective in eliminating the risk of compromise of our information technology systems or networks or our products or services. While we seek to prevent, detect and investigate unauthorized attempts, attacks and other threats against our information technology systems, network and products and services, no set of security safeguards is infallible, and we remain at risk, including to additional known or unknown threats. We have experienced cyber security incidents of various kinds in the past and we may experience cyber security incidents in the future, and we cannot guarantee that any such incidents will not have a material adverse impact in the future. Any actual or perceived security breach or incident impacting us, our third-party service providers, or our customers or users, whether successful or unsuccessful, could result in reputational harm, governmental inquiries, investigations or other proceedings, penalties and significant costs, including those related to, for example, rebuilding internal systems, reduced inventory value, providing modifications to our products and services, defending against litigation, responding to regulatory inquiries or actions, paying damages, or taking other remedial steps, all of which could damage our reputation and reduce demand for our products and services. Further, we may be required or otherwise find it appropriate to expend significant resources, adapt our business activities and practices, or modify our operations or information technology in an effort to protect against security incidents and to mitigate, detect and remediate vulnerabilities, whether in connection with an actual or perceived security breach or incident or otherwise. We cannot be certain that our insurance coverage will be adequate for data security liabilities incurred and, that it will cover any indemnification claims against us relating to any incident, that insurance will continue to be available to us on economically reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have a material adverse effect on our business, including our financial condition, operating results, and reputation. We depend on our executive officers and other key employees, and the loss of one or more of these employees or an inability to attract and retain other highly skilled employees could adversely affect our business, and we may not be able to successfully navigate the recent leadership changes while maintaining key aspects of our culture, which could have a significant negative effect on our existing business and our ability to pursue future plans Our success depends largely upon the continued services of our executive officers and other key employees. There have been changes in the past, and there may be changes in the future, to our executive management team resulting from the hiring or departure of executives, which could disrupt our business. In December 2024, Nadav Zafrir became our new Chief Executive Officer and our founder and former Chief Executive Officer, Gil Shwed, transitioned into the role of Executive Chairman. In addition, in 2025 we announced the appointments of several senior management members. The loss of one or more of our executive officers or other key employees could adversely affect our business. Changes in our executive management team may also cause disruptions in, and adverse impacts to, our business. We also may not be able to successfully navigate the recent leadership changes while maintaining key aspects of our culture, which could have a significant negative effect on our existing business and our ability to pursue future plans. 22 Risks Related to Our Operations in Israel The ongoing war and other potential political, economic and military instability in Israel, where our principal executive offices and our principal research and development facilities are located, may adversely affect our results of operations We are incorporated under the laws of the State of Israel, and our principal executive offices and principal research and development facilities are located in Israel. Accordingly, political, economic and military conditions in and surrounding Israel may directly affect our business. Since the State of Israel was established in 1948, a number of armed conflicts have occurred between Israel and its Arab neighbors. Terrorist attacks and hostilities within Israel; and the war between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen, have also heightened these risks. In October 2023, Hamas terrorists infiltrated Israel’s southern border from the Gaza Strip and conducted a series of attacks on civilian and military targets. Hamas also launched extensive rocket attacks on Israeli population and industrial centers located along Israel’s border with the Gaza Strip and in other areas within the State of Israel. These attacks resulted in extensive deaths, injuries and kidnapping of civilians and soldiers. Following the attack, Israel’s security cabinet declared war against Hamas and a military campaign against these terrorist organizations commenced in parallel to their continued rocket and terror attacks. Following the attack by Hamas on Israel’s southern border, Hezbollah in Lebanon has also launched missile, rocket, and shooting attacks against Israeli military sites, troops, and Israeli towns in northern Israel. In response to these attacks, Israel’s security cabinet declared war against the Hezbollah in southern Lebanon. The Houthi movement, which controls parts of Yemen, launched missile, rocket, and shooting attacks against Israel and attacks on marine vessels traversing the Red Sea, which marine vessels were thought to either be in route towards Israel or to be partly owned by Israeli businessmen. It is possible that other terrorist organizations, including Palestinian military organizations in the West Bank, as well as other hostile countries will join the hostilities. On February 28, 2026, Israel and the United States launched a joint attack against Iran, targeting key officials and military commanders. Iran launched thousands of ballistic missiles and drones against civilian targets in Israel and against U.S. military bases and other civilian targets in several countries in the Persian Gulf , and Hezbollah launched hundreds of missiles and drones from Lebanon against Israeli military sites and civilian targets in Northern Israel. The intensity and duration of the current war between Israel, the U.S. and Iran, and the ongoing hostilities between Israel and Hezbollah, Hamas and Yemen are difficult to predict, as are such hostilities’ economic implications on our business and operations and on Israel's economy in general. Our principal place of business is located in Tel Aviv, Israel, and there can be no assurance that attacks launched will not reach our facilities, which could result in a significant disruption of our business. Further, these events may be intertwined with wider macroeconomic indications of a deterioration of Israel’s economic standing, that may involve an additional downgrade in Israel's credit rating by rating agencies, which may have an adverse effect on the Company and our ability to effectively conduct our operations. Any war or hostilities involving Israel, a significant increase in terrorism or the interruption or curtailment of trade between Israel and its present trading partners, a potential boycott of any Israeli products, or a significant downturn in the economic or financial condition of Israel, could materially adversely affect our operations. Ongoing and revived hostilities or other Israeli political or economic factors could materially adversely affect our business, results of operations and financial condition. In addition, there have been increased efforts by activists to cause companies and consumers to boycott Israeli goods based on Israeli government policies. Such actions, particularly if they become more widespread, may adversely impact our ability to sell our products. Our commercial insurance does not cover losses that may occur as a result of events associated with war and terrorism. Although the Israeli government currently covers the reinstatement value of direct damages that are caused by terrorist attacks or acts of war, we cannot be certain that such government coverage will be maintained or that it will sufficiently cover our potential damages. Uprisings and armed conflicts in various countries in the Middle East and North Africa are affecting the political stability of those countries. This instability may lead to deterioration of the political and trade relationships that exist between Israel and these countries. In addition, this instability may affect the global economy and marketplace, including as a result of changes in oil and gas prices. Beginning in 2023, governmental attempts to pursue a reform in Israel’s judicial system have prompted significant political tension in Israel. This controversy has prompted protests in Israel and triggered a considerable political debate. The proposed legislation has not become effective and its scope has not been fully determined. At this stage we cannot assess the potential business impact of these developments and their likely effect on our business, results of operation, and financial condition , but we continue to monitor the evolving government tensions. 23 Our operations may be disrupted by the obligations of our personnel to perform military service Many of our employees in Israel are obligated to perform annual military reserve duty in the Israel Defense Forces, in the event of a military conflict, could be called to active duty. Our operations could be disrupted by the absence of a significant number of our employees related to military service or the absence for extended periods of military service of one or more of our key employees. Military service requirements for our employees could materially adversely affect our business, results of operations and financial condition. We are subject to risks in connection with the development of our new campus in Tel Aviv, Israel In June 2025, our joint bid with Israel Canada (T.R.) Ltd. for the long-term prepaid lease of a land lot in Tel Aviv, Israel was approved as the winning bid. Our portion of the aggregate purchase price payable pursuant to the joint bid was NIS 500 million plus Israeli VAT (total net payment including unrecoverable taxes of approximately $160 million). We intend to develop the commercial portion of the land lot, a piece of land within walking distance from the Company’s current headquarters in Tel Aviv and connected by a park, to address our expansion plans for the coming years. We expect the construction of the new campus to be completed by 2032. The successful and timely completion of the new campus project is subject to numerous risks, many of which are beyond our control. These risks include construction delays, cost overruns and permitting and regulatory challenges. Any of these factors could increase the total cost of the project above our current expectations and delay the timing of its completion. In addition, the design and construction of a large-scale campus is inherently complex and may require us to make assumptions regarding future workforce size, space utilization, hybrid work environment, and operational needs. If these assumptions prove to be inaccurate, we may incur inefficiencies in the use of the campus, including underutilized or excess space. For example, changes in our business, including shifts toward remote or hybrid work arrangements, workforce reductions, or slower-than-expected growth, could result in a significant portion of the campus being unused or not fully utilized upon completion. The location of our new campus in Tel Aviv, Israel, is also subject to risks associated with the ongoing hostilities in the Middle East, and there can be no assurance that attacks launched will not reach our new campus or delay the construction and buildout of our campus. The tax benefits available to us require us to meet several conditions, and may be terminated or reduced in the future, which would increase our taxes For the year ended December 31, 2025, our effective tax rate was (12%). Our income tax benefit was primarily related to the settlement with the ITA and the adjustment of Israeli tax expenses due to the application of the lower statutory tax rate. We have benefited or currently benefit from a variety of government programs and tax benefits that generally carry conditions that we must meet in order to be eligible to obtain any benefit. Our income tax and the effective tax rate reflected in our financial statements increased beginning 2026 as a result of the recently enacted new corporate minimum tax law of 15% in Israel and other changes in the tax laws of the countries in which we operate or changes in the mix of countries where we generate profit. If we fail to meet the conditions upon which certain favorable tax treatment is based, we would not be able to claim future tax benefits and could be required to refund tax benefits already received. Any of the following could have a material effect on our overall effective tax rate: • Some programs may be discontinued, • We may be unable to meet the requirements for continuing to qualify for some programs, • These programs and tax benefits may be unavailable at their current levels, or • We may be required to refund previously recognized tax benefits if we are found to be in violation of the stipulated conditions. Additional details are provided in “Item 5 – Operating and Financial Review and Prospects” under the caption “Taxes on income”, in “Item 10 – Additional Information” under the caption “Israeli taxation, foreign exchange regulation and investment programs” and in Note 12 to our Consolidated Financial Statements. 24 Shareholder rights and responsibilities are, and will continue to be, governed by Israeli law which differs in some material respects from the rights and responsibilities of shareholders of U.S. companies The rights and responsibilities of the holders of our ordinary shares are governed by our articles of association and by Israeli law. These rights and responsibilities differ in some material respects from the rights and responsibilities of shareholders in U.S.- based corporations. In particular, a shareholder of an Israeli company has a duty to act in good faith and in a customary manner in exercising its rights and performing its obligations towards the company and other shareholders, and to refrain from abusing its power in the company, including, among other things, in voting at a general meeting of shareholders on matters such as amendments to a company’s articles of association, increases in a company’s authorized share capital, mergers and acquisitions and related party transactions requiring shareholder approval. In addition, a shareholder who is aware that it possesses the power to determine the outcome of a shareholder vote or to appoint or prevent the appointment of a director or executive officer in the company has a duty of fairness toward the company. There is limited case law available to assist in understanding the nature of this duty or the implications of these provisions. These provisions may be interpreted to impose additional obligations and liabilities on holders of our ordinary shares that are not typically imposed on shareholders of U.S. corporations. Provisions of Israeli law and our articles of association may delay, prevent or make difficult an acquisition of us, prevent a change of control, and negatively impact our share price Israeli corporate law regulates acquisitions of shares through tender offers and mergers, requires special approvals for transactions involving directors, officers or significant shareholders, and regulates other matters that may be relevant to these types of transactions. Furthermore, Israeli tax considerations may make potential acquisition transactions unappealing to us or to some of our shareholders. For example, Israeli tax law may subject a shareholder who exchanges his or her ordinary shares for shares in a foreign corporation, to taxation before disposition of the investment in the foreign corporation. These provisions of Israeli law may delay, prevent or make difficult an acquisition of our company, which could prevent a change of control and, therefore, depress the price of our shares. In addition, our articles of association contain certain provisions that may make it more difficult to acquire us, such as the provision which provides that our board of directors may issue preferred shares. These provisions may have the effect of delaying or deterring a change in control of us, thereby limiting the opportunity for shareholders to receive a premium for their shares and possibly affecting the price that some investors are willing to pay for our securities. As a foreign private issuer we are not subject to the provisions of Regulation FD or U.S. proxy rules and are exempt from filing certain Exchange Act reports As a foreign private issuer, we are exempt from a number of requirements under U.S. securities laws that apply to public companies that are not foreign private issuers. In particular, we are exempt from the rules and regulations under the Exchange Act related to the furnishing and content of proxy statements. In addition, we are not required under the Exchange Act to file annual and current reports and financial statements with the SEC as frequently or as promptly as U.S. domestic companies whose securities are registered under the Exchange Act and we are generally exempt from filing quarterly reports with the SEC under the Exchange Act. We are also exempt from the provisions of Regulation FD, which prohibits issuers from making selective disclosure of material nonpublic information to, among others, broker-dealers and holders of a company’s securities when it is reasonably foreseeable that the holder will trade in the company’s securities on the basis of the information. For so long as we qualify as a foreign private issuer, we are not required to comply with the proxy rules applicable to U.S. domestic companies, although pursuant to the Companies Law, we disclose the annual compensation of our five most highly compensated office holders (as defined under the Israeli Companies Law) on an individual basis, including in this Annual Report. As a foreign private issuer whose shares are listed on the Nasdaq Global Select Market, we may follow certain home country corporate governance practices instead of certain Nasdaq requirements As a foreign private issuer whose shares are listed on Nasdaq, we are permitted to follow certain home country corporate governance practices instead of certain requirements of the Nasdaq Stock Market Rules. For example, we follow our home country law, instead of the Nasdaq Stock Market Rules, which require that we obtain shareholder approval for the establishment or amendment of certain equity-based compensation plans and arrangements. Under Israeli law and practice, in general, the approval of the board of directors is required for the establishment or amendment of equity-based compensation plans and arrangements, unless the arrangement is for the benefit of a director or a controlling shareholder, in which case compensation committee or audit committee and shareholder approval are also required. A foreign private issuer that elects to follow a home country practice instead of Nasdaq requirements must submit to Nasdaq in advance a written statement from an independent counsel in such issuer’s home country certifying that the issuer’s practices are not prohibited by the home country’s laws. In addition, a foreign private issuer must disclose in its annual reports filed with the SEC each such requirement that it does not follow and describe the home country practice followed by the issuer instead of any such requirement. Accordingly, our shareholders may not be afforded the same protection as provided under Nasdaq’s corporate governance rules. 25
Check Point History and Development Founded over 30 years ago by Gil Shwed, Check Point has continued its mission to secure the digital world for everyone, everywhere. From Firewall-1, the first stateful firewall to dynamic security innovations and to the emergence of the Check…
Check Point History and Development Founded over 30 years ago by Gil Shwed, Check Point has continued its mission to secure the digital world for everyone, everywhere. From Firewall-1, the first stateful firewall to dynamic security innovations and to the emergence of the Check Point Platform powered by Artificial Intelligence (“AI”), Check Point has demonstrated its ability to defend against and prevent what is coming. Check Point secures organization’s AI transformation with unified security architecture of the Hybrid Mesh Networks, Workspace, Exposure Management and AI Security Platform. Through its Check Point Services product, Check Point provides comprehensive technical services to fulfill the cyber security needs of its global customers. Business Overview The Check Point Mission – Securing Our Customers’ AI Transformation We are constantly doing the hard work of getting our solutions ready to enable a secure AI transformation. Our solutions deliver leading protection across infrastructure, to make sure organizations are protected from AI-driven attacks. We continually modify and improve our security platform services by: • Regularly updating our security solutions to defend against the full spectrum of evolving threats. • Securing the entirely new AI-driven attack surfaces. Requiring purpose-built security capabilities. • Deeply integrating AI into our solutions to enable AI-first security teams. • Applying a comprehensive prevention-first approach to protect against the most sophisticated attacks. • Exploring and implementing novel AI security through ecosystem collaboration, and design partnership Check Point assists organizations in defending against AI-driven attacks, securing the new AI attack surfaces they are creating, and using AI to make security operations faster and simpler. To secure this transformation, organizations need a simpler and more unified approach to cybersecurity - one that protects networks, users, exposures, and AI systems as part of a single security strategy. This is the approach Check Point has established through the following four security pillars: 1. Hybrid Mesh Network Security Check Point provides a unified security and connectivity foundation across all environments - data centers, hybrid cloud, internet and perimeter gateways, and branch locations. 2. Workspace Security Check Point protects the workspace with unified, multi-layer security across devices, browsers, email, SaaS apps, and remote access, all managed from a single console. This enables seamless productivity with uncompromising protection - users stay safe, data stays secure, and business moves faster. 3. Exposure Management Check Point Exposure Management combines three core elements: First, threat intelligence powered by Check Point’s unique global telemetry. Second, smart vulnerability prioritization based on comprehensive internal and external asset discovery, with continuous detection of vulnerabilities and misconfigurations. Third, safe and actionable remediation, applying changes intelligently across existing security controls and reducing operational burden on security teams. 4. AI Security Our AI Security pillar combined with our prevention-first approach protects the full AI stack - from employee AI usage, to enterprise applications and agents, and the models, data, and infrastructure behind them. Together, these pillars provide a unified platform to secure our customers’ entire AI journey. 26 Our Strategy: A Platform Built on Four Pillars 1. Hybrid Mesh Network Security In the AI era, network security challenges are intensifying. Customer networks and applications are borderless and everywhere, expanding the attack surface, increasing the blast radius, and exposing gaps across fragmented security controls. We secure hybrid mesh environments through a unified, prevention-first foundation that spans data centers, hybrid cloud, branch, and Secure Access Service Edge (“SASE”), delivering leading security effectiveness as validated by NSS Labs. We provide consistent enforcement through a single AI-powered management and security control plane that delivers superior proactive prevention, hyperscale-grade security with an optimized user experience. Our security platform services include: • Check Point Firewall (Data Center, Perimeter, Branch): Our Gateways and firewalls provide comprehensive security beyond any Next Generation Firewall (“NGFW”) and are designed to manage the most complex security policy requirements and prevent the most sophisticated cyber-attacks. Our security gateways are powered by over 60 security services, including the industry’s complete range of security capabilities including firewalling, intrusion prevention, application control, anti-malware, anti-phishing, DNS security, as well as sandboxing and file sanitization of email and web documents. All of our security gateways receive immediate threat data from our ThreatCloud AI global threat intelligence system, which leads to increased catch-rate of the most sophisticated threats. • Check Point Maestro Hyperscale Firewall: This security platform delivers on-demand scalability for requirements that range from 30 Gbps to over 1 Terabits-per-second of threat prevention. Organizations of any size can benefit from Maestro’s intelligent load balancing firewall cluster design. • Firewall Software R82.10 (security operating system & software): All of our security gateways and firewalls share the same underlying security operating system. Our latest threat prevention and security management release, launched in December 2025 delivers top-rated threat prevention, cloud services, and performance acceleration for Check Point firewalls. This operating system provides security controls and management that are a foundational and integral part of today’s security infrastructure. R82.10 delivers over 20 new capabilities for enterprise customers including: - Supporting Safe AI Adoption: R82.10 strengthens oversight of AI-driven activity by detecting unauthorized Generative AI (“GenAI”) tools, expanding visibility into AI applications such as ChatGPT, Claude, Gemini, among others, and monitoring model context protocol (“MCP) usage to protect AI-powered workflows. - Strengthening Hybrid Mesh Network Security: Organizations gain more consistent protection across distributed environments with centralized internet access management for SASE and firewalls, simplified gateway-to-SASE connectivity, and improved identity and device posture validation to support “Zero Trust” framework at scale. - Taking a Prevention-First Approach to Modern Threats: R82.10, introduces phishing protection that works without HTTPS inspection, adaptive IPS to reduce alert fatigue, and new Threat Prevention Insights to highlight misconfigurations and posture gaps before attackers can exploit them. - Eliminating Silos with a Unified Security Platform: R82.10 expands our open-garden architecture with more than 250 integrations. These integrations allow organizations to apply endpoint posture signals from their existing providers directly within Check Point policies, improving identity-based controls and Zero Trust enforcement. • Check Point Spark Firewall: This family of security gateways and firewalls designed for small and medium businesses (“SMBs”) feature advanced threat prevention performance up to 5 Gbps threat prevention. These firewalls are easy to deploy and manage, and they integrate communication and security into an “all in one” solution. Spark security gateways provide protection focused on SMBs as well as Enterprises branch offices. • AI Powered Security Management: Our AI-powered unified security management control plane – improves security and optimizes operations through an agentic and autonomous platform, and AI-powered Policy management. 27 2. Workspace Security – Where Humans Meet AI Workspace Security Challenges AI is now embedded across the entire modern workspace: spanning browsers, SaaS applications, email, collaboration tools, and endpoints. While this proliferation is driving productivity, it is also enabling faster, highly personalized attacks powered by AI. At the same time, organizations are relying on disjointed security tools that lack integrated protection across the user environment. Without dedicated workspace security, AI itself becomes the largest insider risk, amplifying the potential for data leakage, misuse, and social engineering. Modern workspace security must evolve to meet these threats. It needs to protect users as they interact with AI‑driven tools and applications, prevent sensitive data exposure, and block highly targeted, AI‑generated phishing attacks, particularly through email, before they can cause harm. The Check Point offering – Workspace Security We offer services to protect the workspace through the deployment of remote-access enabled, unified, multi-layer security across devices, browsers, email, SaaS apps. With a single console to manage all features and built-in 360° threat prevention, organizations can achieve seamless productivity with uncompromised protection. Through the deployment of our security platform with workspace-optimized features such as browsers security, endpoint security, email security, and SaaS security, users and employees stay safe, data stays secure, and business moves faster. Our Workspace Security platform includes features such as: • Check Point Email Security: secures users’ email clients and gives protection for third-party providers such as Microsoft Office 365, Exchange, Google G, among others. • Check Point Endpoint Security: protects users’ PCs from ransomware, phishing, and malware, and minimizes breach impact with autonomous detection and response capability. • Check Point Mobile Security: protects employees’ mobile devices against malicious apps and network or operating systems attacks. • Check Point Browser Security: provides secure, fast, and private web browsing by inspecting all Secure Sockets Layer traffic directly on the endpoint. • Check Point XDR: provides extended detection, prevention, and response capabilities. Our strength and leadership in email security sets us apart. We are a recognized leader in the 2025 Gartner® Magic Quadrant™ for Email Security Platforms, reflecting both the maturity of our technology and the trust placed in us by the market. In 2025 alone, we added 20,000 new customers, underscoring our continued growth and relevance. We significantly elevate user protection through advanced AI capabilities, including GenAI‑driven security awareness training with personalized phishing simulations, as well as AI‑powered mailbox observations that proactively protect against malicious emails while reducing administrative overhead. In addition, we deliver a truly unified user experience, combined with a defense‑in‑depth approach to phishing, ensuring comprehensive protection across multiple layers rather than reliance on a single control. 28 3. AI Security- Securing the AI full stack AI is reshaping the cyber security threat landscape by introducing new risks as organizations rapidly implement AI applications, agents, and adopt the use of GenAI models. These risks include data leakage through the accidental inclusion of sensitive information in AI prompts or the uploading of sensitive data to GenAI or other tools, as well as AI threats such as jail breaking or model inversion and uncontrolled autonomy from agents acting beyond their scope. We established AI Security as a foundational pillar of our strategy in order to address these emerging and evolving threats. Our end-to-end AI security stack protects employee usage, enterprise applications and agents, and the models, data, and infrastructure that power them. • Check Point AI Workforce Security – delivers instant visibility into all sanctioned and shadow AI usage, preventing sensitive data exposure, and enabling safe productivity. • Check Point AI Agent Security – protects enterprise copilots, chatbots, and agentic systems from prompt injections, jailbreaks, and malicious output while applying real-time guardrails across AI interactions. • Check Point AI Red Teaming – provides continuous red-teaming, model robustness testing, and compliance readiness for the AI systems that increasingly drive business operations. Our platform is built from the ground up on security‑native AI models and prevention‑first intelligence, rather than retrofitted analytics. This foundation enables us to stop threats before they materialize, rather than reacting after the fact. 4. Threat Exposure Management – Stopping AI-Era Attacks Powered by the combined strengths of the recently acquired companies Cyberint Technologies Ltd. and Veriti Security Ltd., coupled with Check Point’s strong visibility, our Threat Exposure Management platform delivers real time situational awareness by unifying threat intelligence, dark web insights, attack surface visibility, exploitability context, and automated remediation. Using Gartner’s Continuous Threat Exposure Management (“CTEM”) framework, we correlate real‑world attacker behavior with enterprise assets to identify, prioritize, and remediate the exposures that matter most – before attackers can exploit them. Our security platforms are designed around three core elements: • Check Point Threat Intelligence - Leveraging Check Point’s extensive global visibility and decades of expertise, we map the attacker ecosystem – tracking active campaigns, exploited CVEs, and high‑risk IOCs, while learning from real‑world attacks. • Check Point Vulnerability Detection & Prioritization- Automatically discovering your attack surface, misconfigurations, and CVEs – across Check Point scanners and existing tools – we deliver a single, prioritized list of true risks enriched with intelligence and protection context. • Check Point Safe Remediation - Going beyond prioritization, we safely reconfigure existing security controls to close exposures and block threats with minimal operational friction. What Sets Us Apart • Strong intelligence depth, powered by Check Point’s leading visibility and advanced processing, delivering insights that matter. • End-to-end actionability, combining smart prioritization with automated, safe remediation – reducing mean time to remediate from days to hours and preparing organizations for an era of AI driven attacks. Overview of Check Point Services: Check Point offers its customers with end-to-end customized solutions to fortify defenses, optimize threat response, maximize their investment on products with advisory and professional services offering to elevate their cyber posture. 29 • Managed Services: Comprehensive support for Check Point and third-party systems, delivered with predefined Service Level Agreements (“SLAs”) for a fixed monthly fee. • Managed Detection and Response (“MDR/MPR”): A fully managed SecOps platform providing access to Check Point analysts, researchers, and incident response resources. • Incident Response Services: Structured services to address and mitigate security incidents efficiently. • Security Consulting Services Managed Services: Comprehensive support for Check Point and third-party systems, delivered with predefined Service Level Agreements (“SLAs”) for a fixed monthly fee. • Security Consulting Services: Expertise in threat exposure management, threat intelligence, and risk assessment. • Professional Services: End-to-end design, deployment, optimization, and operational support for Check Point solutions. • Training Services: Programs focused on security awareness and executive training to enhance organizational security maturity. • Flex Credits: Prepaid service credits offering one year of flexible access to a range of cyber security services. Check Point Technology Leadership in 2025 During 2025 we were endorsed by market analysts for our leadership position in 28 reports. Below are some of the highlight reviews: Gartner o Gartner® Magic Quadrant™ Leader for Hybrid Mesh Firewalls becoming the only vendor to be listed as a Leader for the 24th time, 2025 o Gartner® Magic Quadrant™ Challenger for Endpoint Protection Platforms, 2025 o Gartner® Magic Quadrant™ Leader for Email Security Platforms, 2025 Forrester o The Forrester Wave™: Enterprise Email Security, 2025 o The Forrester Wave™: Zero Trust Platform Providers, 2025 Frost & Sullivan o Frost & Sullivan® Radar Leader for Endpoint Security, 2025 o Frost & Sullivan® Radar Leader for Secure Access Service Edge, 2025 o Frost & Sullivan® Radar Leader for Managed Detection and Response (MDR), 2025 GigaOm o GigaOm® Radar Leader for CIEM Solutions V2.0 2025 o GigaOm® Radar Leader for Cloud Workload Security, 2025 o GigaOm® Radar Leader for Enterprise Firewall 2025 o GigaOm® Radar Leader for Extended Detection & Response (EDR) 2025 o GigaOm® Radar Leader for Zero Trust Network Access (ZTNA), 2025 o GigaOm® Radar Leader for Anti-Phishing, 2025 Miercom o For the fourth consecutive year, Check Point attained Secure Certification in Miercom Enterprise & Hybrid Mesh Firewall Benchmark Report 2025. Miercom lab tests showed 99.9% malware block rate against Zero+1 Day attacks, 99.7% of phishing attacks, and 98% intrusion prevention for high & critical threats. 30 Acquisition and other Corporate Information In February 2026, we acquired 100% of the share capital of Cyclops Security Ltd. a privately held Israeli company and a leader in Cyber Asset Attack Surface Management (“CAASM”). In February 2026, we acquired 100% of the share capital of Cyata Security Ltd. a privately held Israeli company specializing in discovering, understanding, and governing autonomous AI agents. In February 2026, we acquired the talent of Rotate Ltd., a privately held Israeli company to drive continued growth and momentum for Workspace solutions within the managed service providers (MSP) sector. In October 2025, we acquired 100% of the share capital of Lakera AI AG, a privately held Swiss company, a leading AI-native security platforms for Agentic AI applications. In June 2025, we acquired 100% of the share capital of Veriti Security Ltd., a privately held Israeli company and a provider of a fully automated, multi-vendor pre-emptive threat exposure and mitigation platform. In February 2025, we entered into a strategic partnership with Wiz Ltd. to address the growing challenges enterprises face securing hybrid cloud environments. This collaboration is intended to bridge the longstanding gap between cloud network security and Cloud Native Application Protection (“CNAPP”) through a deep technological integration and strategic business alliance, delivering an industry-leading unified, holistic security solution. In September 2024, we acquired 100% of the share capital of Cyberint Technologies Ltd., a privately held Israeli company that specializes in comprehensive external risk management solutions, including the detection and takedown of impersonating website, phishing and social media accounts, as well as stolen credentials and leaked data associated with organizations. In October 2023, we acquired 100% of the share capital of rmsource Inc., a privately held US-based company and a provider of managed security, cloud and IT services, to expand Infinity Global Services with new managed security services across networks, cloud and security operations. In September 2023, we acquired 100% of the share capital of Perimeter 81 Ltd., a privately held Israeli company and a leading provider of Zero Trust Network Access (ZTNA) and Secure Service Edge (SSE) software. In September 2023, we acquired 100% of the share capital of Atmosec Ltd., a privately held Israeli company that specializes in the rapid discovery and disconnection of malicious SaaS applications, preventing risky third-party SaaS communications, and rectifying SaaS misconfigurations. In February 2022, we acquired 100% of the share capital of Spectral Cyber Technologies Ltd., a privately held Israeli company and key innovator in developer-first security tools designed by developers for developers, to extend our cloud solution. In September 2021, we acquired 100% of the share capital of Avanan, Inc., a privately-held US-based company providing cloud email security, and the developer of a patented application-programming interface (API) solution to stop email threats before arriving to the inbox (inline), for both internal and external emails using AI based engines. Further details regarding the material events in the development of our business since the beginning of 2023 are provided in “Item 5 – Operating and Financial Review and Prospects” under the caption “Overview”. We incorporated as a company under the laws of the State of Israel in 1993 under the name of “Check Point Software Technologies Ltd.” Our registered office and principal place of business is located at 5 Shlomo Kaplan Street Tel Aviv 6789159, Israel. The telephone number of our registered office is 972-3-753-4555. Our company’s website is www.checkpoint.com. The contents of our website are not incorporated by reference into this Annual Report. This Annual Report is available on our website at www.checkpoint.com. If you would like to receive a printed copy via mail, please contact our Investor Relations department at [email protected]. The SEC also maintains an Internet site that contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC. The address of that website is www.sec.gov. Our agent for service of process in the United States is CT Corporation System, 818 West Seventh Street, Los Angeles, CA 90017 U.S.A.; Tel: 213-627-8252. 31 Revenues by Category of Activity The following table presents our revenues for the last three fiscal years by category of activity: Year Ended December 31, 2025 2024 2023 (in millions) Category of Activity: Products and licenses $ 548.2 $ 507.9 $ 497.4 Security subscriptions $ 1,219.0 $ 1,104.2 $ 981.2 Software updates and maintenance $ 958.2 $ 952.9 $ 936.1 Total revenues $ 2,725.4 $ 2,565.0 $ 2,414.7 For information regarding our revenue by geographic market, please refer to “Item 5 – Operating and Financial Review and Prospects” under the caption “Overview”. Sales and Marketing We primarily sell our products and services through a two-tier distribution model; distributors that sell to resellers and to service providers and Managed Security Service Providers (“MSSPs”), who sell to end-customers. We support our channel partners with a dedicated team of experienced sales professionals including account managers, channel managers and sales engineers. In 2024, we created a demand generation marketing organization focused on the development and conversion of prospect and customer marketing leads to high quality sales leads. In addition to corporate and demand generation marketing, Check Point marketing also includes marketing for products, partners, field promotions, digital promotions, and solutions-oriented thought leadership. In 2025, we continued to invest in sales and marketing resources. As of December 31, 2025, we had 3,066 employees and subcontractors in our sales and marketing organization, with a majority of them dedicated to presales and marketing support located in various jurisdictions. Support and Services We operate a worldwide technical services organization which provides a wide range of services including: (i) technical customer support programs and plans; (ii) professional services in implementing, upgrading and optimizing Check Point products, such as design planning and security implementation; and (iii) certification and educational training on Check Point products. Our technical assistance centers in the United States, Israel, Canada, Japan, India, China, and Australia offer support worldwide, 24-hour service, seven days per week. As of December 31, 2025, we had 1,168 employees and subcontractors in our technical services organization. Research and Product Development We believe that our future success will depend upon our ability to enhance our existing products, and to develop, acquire and introduce new products to address the increasingly sophisticated needs of our customers. As of December 31, 2025, we had 2,154 employees and subcontractors dedicated to research and development activities and quality assurance. Competition Information concerning competition is provided in “Item 3 – Key Information” under the caption “Risk Factors – Risks Related to Our Business and Our Market – We may not be able to successfully compete, which could adversely affect our business and results of operations”. Environmental, Social and Governance (“ESG”) Since our inception, Check Point’s mission has been to make the world a safer place. As a global cyber security provider, the Company views our long-term success as inherently linked to the success of our key stakeholders, and as such, ESG considerations are integrated into our business strategy and operations. 32 Social Standards: • Community – Check Point supports charitable giving and employee volunteering programs across the regions in which we operate. Our community engagement and giving policies are governed by the Corporate Responsibility Policy and the Social Investment and Volunteering Statement. • Human Resources – Human capital is a core asset of our Company. We are committed to promoting an engaging, supportive, and inclusive work environment, free from discrimination and harassment, where our employees can grow and learn together. Our human resources commitments, programs, and policies are governed and implemented through our Social Engagement Policy, Human Rights and Labor Policy, Training and Employee Development Policy, and Modern Slavery and Forced Labor Statement. In 2025, we continued to invest in the personal and professional development of our workforce, while ensuring that all voices, opinions, and outlooks are heard and fairly addressed. • Supply Chain – We uphold high social and human rights standards across our supply chain, with the goal of ensuring that the working conditions are safe and that all business operations are conducted ethically. Key suppliers and business partners are asked to comply with the standards of business, labor, environmental, and ethical conduct set out in our Supply Chain and Business Partner Code of Conduct, which is aligned with the Responsible Business Alliance (“RBA”) Code of Conduct guidelines. These standards are further supported by our Supply Chain s Policy. Environmental Standards: As a global company, we seek to promote a responsible relationship with the environment. It is our belief that our impact on the environment is predominately related to our products, services, and operations. Our Environmental Policy establishes the framework for compliance with environmental laws and regulations, as well as for identifying, assessing, and managing relevant climate change-related risks and opportunities to our business. Governance Standards: II. Corporate Governance – Relevant ESG governance considerations are integrated into our wider corporate governance structure, alongside our commitment to operating according to standards of responsible business conduct, ethical principles, and a strong corporate governance structure, ensuring that we maintain full accountability, integrity, and transparency in our business practices. Our corporate governance framework is upheld by our Corporate Governance Guidelines, which assist the director and committee members in fulfilling their oversight responsibilities. III. ESG Governance – The Nominating, Sustainability, and Corporate Governance Committee of the board is responsible for overseeing our ESG program, including oversight of relevant risks, policies, and programs, conducts ongoing management of ESG matters. IV. Ethics – Check Point maintains a comprehensive ethical compliance framework that is applicable to directors, officers, employees, and relevant third parties. Relevant policies and guidelines that guide our company’s ethics include: the Code of Ethics and Business Conduct, which establishes clear standards of behavior and conduct; Anti-Corruption, Bribery, and Money Laundering Policy; Insider Trading Policy; Privacy Policy; Responsible AI Policy; and Whistleblower Procedure. As a global cyber security company, information security and data protection are critical to our operations, supported by a global security framework aligned with recognized industry standards and best practices, including for governance of responsible artificial intelligence principles. Our annual ESG Report, which provides additional information on our ESG strategy, initiatives, and metrics, is available on our website at https://www.checkpoint.com/about-us/esg/. The ESG Report and the contents of the Company’s website are not incorporated by reference into this Annual Report. Proprietary Rights Check Point relies on a combination of copyright and trademark laws, trade secrets, confidentiality procedures and contractual provisions to protect its proprietary rights. Check Point relies on trade secrets and copyright laws to protect its software, documentation, and other written materials. Further, Check Point generally enters into confidentiality agreements with employees, consultants, customers and potential customers, and limits access and distribution of materials and information that the company considers proprietary. Check Point and its subsidiaries have 158 issued patents in the U.S. and in other regions and 16 pending patent applications worldwide. Our efforts to protect our patent rights and other proprietary rights may not be adequate and our competitors may independently develop technology that is similar. Additional details are provided in “Item 3 – Key Information” under the caption “Risk Factors – Risks Related to Our Business and Our Market – We may not be able to successfully protect our intellectual property rights”. 33 Effect of Government Regulation on our Business Information concerning regulation is provided in “Item 5 – Operating and Financial Review and Prospects” under the caption “Taxes on income” and in “Item 10 – Additional Information” under the caption “Israeli taxation, foreign exchange regulation and investment programs”. Organizational Structure We are organized under the laws of the State of Israel. We wholly own the subsidiaries listed below, directly or through other subsidiaries, unless otherwise specified in the footnotes below: NAME OF SUBSIDIARY COUNTRY OF INCORPORATION Check Point Software Technologies, Inc. United States of America (Delaware) Check Point Software (Canada) Technologies Inc. Canada Check Point Software Technologies (Japan) Ltd. Japan Check Point Software Technologies (Netherlands) B.V. Netherlands Check Point Holding (Singapore) PTE Ltd. Singapore Check Point Holding (Singapore) PTE Ltd. – Rep office Indonesia (1) Singapore Check Point Holding (Singapore) PTE Ltd. –US, NY Branch (2) Singapore Israel Check Point Software Technologies Ltd. China (3) China Check Point Holding AB (4) Sweden Check Point Software Technologies South Africa PTY. Ltd South Africa Check Point Software (Kenya) Limited Kenya Check Point Software Technologies B.V Nigeria Ltd. (5) Nigeria Check Point Serverless Security Ltd. (6) Israel Check Point Email Security Ltd. (7) Israel Avanan, Inc. United States of America (Delaware) Zone Labs, L.L.C. (8) United States of America (California) Check Point Software Technologies (Sweden) AB. (9) Sweden Check Point Software Technologies (Sweden) AB. – Dubai Branch (10) Sweden Lakera AI AG Switzerland Lakera Inc. (11) United States of America (Delaware) Veriti Security Ltd. (6) Israel Veriti Security Inc. (12) United States of America (Delaware) Cyata Security Ltd. Israel Cyata Security, Inc. (13) United States of America (Delaware) Cyclops Security Ltd. Israel Cyclops Security Inc. (14) United States of America (Delaware) Cyberint Singapore Pte Ltd. (15) Singapore Cyberint Inc. (15) United States (Delaware) (1) Representative office of Check Point Holding (Singapore) PTE Ltd. (2) Branch of Check Point Holding (Singapore) PTE Ltd. (3) Representative office of Check Point Software Technologies Ltd. (4) Subsidiary of Check Point Holding (Singapore) PTE Ltd. (former name: Protect Data AB) (5) Subsidiary of Check Point Holding (Singapore) PTE Ltd. and Check Point Yazilim Teknolojileri Pazarlama A.S. (6) Under intercompany merger process into Check Point Software Technologies Ltd. (7) Subsidiary of Avanan, Inc. (8) Subsidiary of Check Point Software Technologies Inc. (9) Subsidiary of Check Point Holding AB (10) Branch of Check Point Software Technologies (Sweden) AB. (11) Subsidiary of Lakera AI AG (12) Subsidiary of Veriti Security Ltd. (13) Subsidiary of Cyata Security Ltd. (14) Subsidiary of Cyclops Security Ltd. (15) Under intercompany merger or dissolution process. 34 Check Point Software Technologies (Netherlands) B.V. acts as a holding company. It wholly owns all or substantially all of the share capital of the principal operating subsidiaries listed below, unless otherwise indicated in the footnotes below: NAME OF SUBSIDIARY COUNTRY OF INCORPORATION Check Point Software Technologies S.A. Argentina Check Point Software Technologies (Australia) PTY Limited Australia Check Point Software Technologies (Austria) GmbH Austria Check Point Software Technologies Belarus LLC (1) Belarus Check Point Software Technologies (Belgium) Belgium Check Point Software Technologies (Brazil) LTDA Brazil Check Point Software Technologies (Hong Kong) Ltd. (Guangzhou office) (2) China Hong Kong SAR Check Point Software Technologies (Hong Kong) Ltd. (Shanghai office) (2) China Check Point Software Technologies (Czech Republic) s.r.o. Czech Republic Check Point Software Technologies (Denmark) ApS Denmark Check Point Software Technologies (Finland) Oy Finland Check Point Software Technologies Eurl France Check Point Software Technologies GmbH Germany Check Point Software Technologies (Greece) SA Greece Check Point Software Technologies (Hungary) Ltd. Hungary Check Point Software Technologies (Hong Kong) Limited Hong Kong Check Point Software Technologies India Private Limited India Check Point Software Technologies (Italia) S.r.l Italy Check Point Software Technologies Mexico S.A. de C.V. Mexico Check Point Software Technologies (Beijing) Co., Ltd. China Check Point Software Technologies (New Zealand) Limited New Zealand Check Point Software Technologies Norway A.S. Norway Check Point Software Technologies (Philippines) Inc. Philippines Check Point Software Technologies (Poland) Sp.z.o.o. Poland CPST (Portugal), Sociedade Unipessoal Lda. Portugal Check Point Software Technologies (RMN) SRL Romania Check Point Software Technologies (Russia) OOO Russia Check Point Software Technologies (Korea) Ltd. South Korea Check Point Software Technologies (Spain), S.A. Spain Check Point Software Technologies (Switzerland) AG Switzerland Check Point Software Technologies (Taiwan) Ltd. Taiwan Check Point Yazilim Teknolojileri Pazarlama A.S. Turkey Check Point Software Technologies (UK) Ltd. United Kingdom (1) Under dissolution process (2) Representative office of Check Point Software Technologies (Hong Kong) Ltd. 35 Property, Plants and Equipment As of December 31, 2025, we own our headquarters located in Tel Aviv, Israel and we lease offices in various locations throughout the world. The breakdown in the various geographies (excluding external data centers) is as follows: Location Space (square feet) Israel 380,784 *) Americas 110,427 Europe, Middle East and Africa 70,643 Asia Pacific 81,359 *) We acquired ownership of our international headquarters located in Tel Aviv, Israel pursuant to a pre-paid 49 year long-term lease on the land with the City of Tel Aviv – Jaffa. No additional payments are due under such long-term lease. Our international headquarters building contains approximately 332,000 square feet of office space. In addition, we lease approximately 48,000 square feet of additional space substantially all in Tel Aviv, Israel and around. In March 2025, we submitted a tender bid, together with Israel Canada (T.R.) Ltd., an Israeli company publicly traded on the Tel Aviv Stock Exchange (“Israel Canada”), for the long-term prepaid lease of a land lot in Tel Aviv, Israel, which is adjacent to our headquarters in Tel Aviv. The tender was conducted by the Tel Aviv-Jaffa Municipality and the Israel Electric Company Ltd., and in June 2025 our joint bid with Israel Canada for NIS 818 million (approximately $241 million) plus Israeli VAT, was approved as the winning bid. Our portion of the aggregate purchase price payable pursuant to the bid was NIS 500 million, plus Israeli VAT (total net payment including unrecoverable taxes was approximately $160 million). We intend to develop the commercial portion of the land lot, a piece of land within walking distance from the Company’s current headquarters in Tel Aviv and connected by a park, to address our expansion plans for the coming years. We expect significant investment to be associated with developing and building the commercial portion of the land. We currently expect the construction of the campus to be completed in 2032. Principal Capital Expenditures and Divestitures For more information regarding our principal capital expenditures currently in progress, see “Item 5 – Operating and Financial Review and Prospects” under the caption “Liquidity and Capital Resources”.
FINANCIAL REVIEW AND PROSPECTS For discussion related to our financial condition, changes in financial condition, and the results of operations for 2024 compared to 2023, refer to Part I, Item 5. Operating and Financial Review and Prospects, in our Annual Report on Form 20-F for…
FINANCIAL REVIEW AND PROSPECTS For discussion related to our financial condition, changes in financial condition, and the results of operations for 2024 compared to 2023, refer to Part I, Item 5. Operating and Financial Review and Prospects, in our Annual Report on Form 20-F for the fiscal year ended December 31, 2024, which was filed with the U.S. Securities and Exchange Commission on March 17, 2025 and which is hereby incorporated by reference. The following discussion and analysis is based on our consolidated financial statements including the related notes, and should be read in conjunction with them. Our consolidated financial statements are provided in “Item 18 – Financial Statements”. Overview We develop, market and support a wide range of products and services for IT security by offering a multilevel security architecture that defends enterprises’ cloud, network, mobile devices, Endpoints information and IOT solutions. Our solutions operate under a unified security architecture, Infinity, that enables end-to-end security with a single line of unified security gateways and allow a single agent for all endpoint security that can be managed from a single unified management console. This unified management allows for ease of deployment and centralized control and is supported by, and reinforced with, real-time threat intelligence and autonomous security updates. Our products and services are sold to enterprises, service providers, small and medium sized businesses and consumers. Our open platform framework allows customers to extend the capabilities of our products and services with third-party hardware and security software applications. Our products are sold, integrated and serviced by a network of channel partners worldwide. Our business is subject to the effects of general global economic conditions and, in particular, market conditions in the IT, internet security and data security industries. If general economic and industry conditions deteriorate, demand for our products could be adversely affected. Information concerning the effect of governmental regulation on our business is provided in “Item 5 – Operating and Financial Review and Prospects” under the caption “Taxes on income” and in “Item 10 – Additional Information” under the caption “Israeli taxation, foreign exchange regulation and investment programs”. 36 We derive our sales primarily through indirect channels. During each of 2025, 2024 and 2023, we derived approximately 57%, 56%, and 56%, respectively, of our sales from our ten largest channel partners. In 2025, 2024 and 2023, our three largest distributors accounted for approximately 39%, 39% and 40% respectively, of our sales. The following table presents the percentage of total consolidated revenues that we derive from sales in each of the regions shown: Year Ended December 31, 2025 2024 2023 Region: Americas, principally U.S. 42 % 42 % 43 % Europe, Middle East and Africa 46 % 47 % 46 % Asia-Pacific 12 % 11 % 11 % For information on the impact of foreign currency fluctuations, please refer to “Item 11 – Quantitative and Qualitative Disclosures about Market Risk – Foreign Currency Risk”. Critical Accounting Policies and Estimates Our consolidated financial statements are prepared in accordance with U.S. GAAP. These accounting principles require us to make certain estimates, judgments and assumptions. We believe that the estimates, judgments and assumptions that we make are reasonable based upon information available to us at the time that these estimates, judgments and assumptions were made. These estimates, judgments and assumptions can affect the reported amounts of assets and liabilities as of the date of the financial statements as well as the reported amounts of revenues and expenses during the periods presented. To the extent there are material differences between these estimates, judgments or assumptions and actual results, our consolidated financial statements will be affected. The accounting policies that reflect our more significant estimates, judgments and assumptions and which we believe are the most critical to aid in fully understanding and evaluating our reported financial results, include the following: • Revenue recognition; • Accounting for income taxes; and • Business combination. In many cases, the accounting treatment of a particular transaction is specifically dictated by U.S. GAAP and does not require management’s judgment in its application. There are also areas in which management’s judgment in selecting among available alternatives would not produce a materially different result. Our senior management has reviewed these critical accounting policies and related disclosures with the audit committee of our board of directors. You can see a summary of our significant accounting policies in Note 2 to our consolidated financial statements, as set forth in Item 18. Revenue recognition We derive our revenues mainly from sales of products and licenses, security subscriptions and software updates and maintenance. Our products are generally integrated with software that is essential to the functionality of the product. We sell our products primarily through channel partners including distributors, resellers, Original Equipment Manufacturers (“OEMs”), system integrators and Managed Security Service Providers (“MSSPs”), all of whom are considered end users. Security subscriptions provide customers with access to its suite of security solutions and is sold as a service. Software updates and maintenance provide customers with rights to unspecified software product upgrades released during the term of the agreement and include maintenance services to end-user customers, through primarily telephone access to technical support personnel as well as hardware support services. We recognize revenues under the core principle that transfer of control to our customers should be depicted in an amount reflecting the consideration we expect to receive in revenue. Therefore, we identify a contract with a customer, identify the performance obligations in the contract, determine the transaction price, allocate the transaction price to each performance obligation in the contract and recognize revenues when (or as) we satisfy a performance obligation. 37 We recognize revenues from sales of products and licenses, under Topic 606, upon shipment when control of the promised goods is transferred to the customer, or upon electronic transfer of the Certificate Key to the customer. We recognize revenues from security subscriptions and software updates and maintenance ratably over the term of the agreement due to the continuous transfer of control to the customer over the period and upon the transfer of services to the customers. Our arrangements typically contain multiple deliverables, such as products and licenses, security subscriptions and software updates and maintenance, which are generally capable of being distinct and accounted for as separate performance obligations. We evaluated the criteria to be distinct under Topic 606, and concluded that the products and the licenses were distinct and distinct in the context of the contract from the security subscription and the software updates and maintenance, as the customer can benefit from the products and licenses without the services and the services are separately identifiable within the arrangement. We allocate the transaction price to each performance obligation based on relative standalone selling price basis, by using the prices charged for a performance obligation when sold separately. Deferred revenues represent mainly the unrecognized revenue billed for security subscriptions and for software updates and maintenance. Such revenues are recognized ratably over the term of the related agreement. We recognize revenues net of estimated amounts that may be refunded for sales returns, rebates, stock rotations and other rights provided to customers on product and service related sales subject to varying limitations. We estimate and record these reductions based on our historical sales returns experience, analysis of credit memo data, rebate plans, stock rotation and other known factors. In each accounting period, we use judgments and estimates to determine potential future sales credits, returns and stock rotation, related to current period revenue. These estimates affect our “revenue” line item on our consolidated statements of income and affect our “deferred revenues” and “accrued expenses and other liabilities” on our consolidated balance sheets. Accounting for income tax We are subject to income taxes in Israel, the United States and numerous foreign jurisdictions. Significant judgment is required in evaluating our uncertain tax positions and determining our taxes. Although we believe our reserves are reasonable, no assurance can be given that the final tax outcome of these matters will not be different from that which is reflected in our historical income tax provisions and accruals. We adjust these reserves in light of changing facts and circumstances, such as the closing of a tax audit or the refinement of an estimate, or upon lapse of statute of limitations. To the extent that the final tax outcome of these matters is different than the amounts recorded, such differences will affect the provision for income taxes in the period in which such determination is made. Business combination We apply the provisions of ASC 805, Business Combinations and allocate the fair value of purchase consideration to the tangible assets acquired, liabilities assumed or incurred, and intangible assets acquired based on their estimated fair values. The excess of the fair value of purchase consideration over the fair values of these identifiable assets and liabilities is recorded as goodwill. When determining the fair values of assets acquired and liabilities assumed or incurred, management makes significant estimates and assumptions, especially with respect to intangible assets. Significant estimates in valuing certain intangible assets include, but are not limited to, future expected cash flows from acquired technology, and customer relationships from a market participant perspective, useful lives and discount rates. We also apply the provisions of ASU 2021-08, Business Combinations (Topic 805)(“ASU 2021-08”) which requires that we recognize and measure contract assets and contract liabilities acquired in a business combination in accordance with ASC 606, Revenue from Contracts with Customers (“ASC 606”) and that at the acquisition date, we account for related revenue contracts in accordance with ASC 606 as if we had originated the contracts. Management’s estimates of fair value are based upon assumptions believed to be reasonable, but which are inherently uncertain and unpredictable and, as a result, actual results may differ from estimates. 38 Results of Operations The following table presents information concerning our results of operations in 2025 and 2024: Year Ended December 31, 2025 2024 (in millions) Revenues: Products and licenses $ 548.2 $ 507.9 Security subscriptions 1,219.0 1,104.2 Software updates and maintenance 958.2 952.9 Total revenues 2,725.4 2,565.0 Operating expenses (*): Cost of products and licenses 105.8 97.8 Cost of security subscriptions 90.9 72.6 Cost of software updates and maintenance 132.6 123.9 Amortization of technology 32.5 25.0 Total cost of revenues 361.8 319.3 Research and development 456.7 394.9 Selling and marketing 947.0 862.9 General and administrative 128.8 111.9 Total operating expenses 1,894.3 1,689.0 Operating income 831.1 876.0 Financial income, net 114.0 96.1 Income before taxes on income (tax benefit) 945.1 972.1 Taxes on income (tax benefit) (111.8 ) 126.4 Net income $ 1,056.9 $ 845.7 39 (*) Including pre-tax charges for stock-based compensation, amortization of intangible assets and acquisition related expenses in the following items: Year Ended December 31, 2025 2024 (in millions) Amortization of intangible assets and acquisition related expenses Amortization of technology $ 32.5 $ 25.0 Research and development 4.6 6.5 Selling and marketing 40.1 40.3 Total amortization of intangible assets and acquisition related expenses $ 77.2 $ 71.8 Stock-based compensation Cost of products and licenses $ 0.6 $ 0.4 Cost of software updates and maintenance 13.5 8.2 Research and development 76.3 53.1 Selling and marketing 79.8 58.2 General and administrative 35.4 29.8 Total stock-based compensation $ 205.6 $ 149.7 The following table presents information concerning our results of operations as a percentage of revenues for the periods indicated: Year Ended December 31, 2025 2024 Revenues: Products and licenses 20 % 20 % Security subscriptions 45 43 Software updates and maintenance 35 37 Total revenues 100 % 100 % Operating expenses: Cost of products and licenses 4 4 Cost of security subscriptions 3 3 Cost of software updates and maintenance 5 5 Amortization of technology 1 1 Total cost of revenues 13 13 Research and development 17 15 Selling and marketing 35 34 General and administrative 5 4 Total operating expenses 70 66 Operating income 30 34 Financial income, net 5 4 Income before taxes on income (tax benefit) 35 38 Taxes on income (tax benefit) (4 ) 5 Net income 39 % 33 % 40 Revenues We derive our revenues mainly from the sale of products and licenses, security subscriptions and software updates and maintenance. Our revenues were $2,725 million in 2025 and $2,565 million in 2024. Total revenues in 2025 increased by 6% compared to 2024. Product and license revenues were $548 million in 2025 and $508 million in 2024. We continued to deliver increasingly more of our latest security offerings as subscriptions resulting in increased sales of our security subscription packages, including considerable demand for our emerging products portfolio and across all 3 pillars: Hybrid Mesh, Workspace and CTEM . As a result, security subscription revenues increased by $115 million, or 10%, from $1,104 million in 2024 to $1,219 million in 2025. Software updates and maintenance revenues increased by $5 million, or 1%, from $953 million in 2024 to $958 million in 2025, primarily as a result of renewals of existing and sales of new maintenance contracts and professional services. Cost of Revenues Total cost of revenues was $362 million in 2025 and $319 million in 2024. Cost of revenues includes cost of product and licenses, cost of security subscriptions and cost of software updates and maintenance and amortization of technology. Our cost of products and licenses includes mainly cost of software and hardware production, packaging and shipping. Our cost of security subscriptions is comprised of costs paid to third parties, hosting and infrastructure costs and cost of customer support related to these services. Our cost of software updates and maintenance include mainly the cost of post-sale customer support. Cost of products and licenses was $106 million in 2025 and $98 million in 2024. Cost of security subscriptions was $91 million in 2025 and $73 million in 2024. Cost of software updates and maintenance was $133 million in 2025 and $124 million in 2024. In 2025, amortization of technology was $33 million compared to $25 million in 2024. The increase in 2025 is attributed to the acquisitions made during 2025 and 2024. Research and Development Research and development expenses were $457 million in 2025 and $395 million in 2024, and represented 17% of revenues in 2025 and 15% of revenues in 2024. Research and development expenses consist primarily of salaries and other related expenses for personnel as well as the cost of our cloud infrastructure expenses. The $62 million increase in 2025 is primarily a result of an increase in compensation and related expenses for personnel , cloud infrastructure expenses and a $7 million expense related to currency exchange and hedging. The majority of our personnel engaged in research and development are located in Israel, where compensation-related expenses are paid in Israeli Shekels, while our research and development expenses are reported in U.S. dollars. Therefore, changes to the exchange rate between the Israeli Shekel and the U.S. dollar have affected and may in the future affect our research and development expenses. We have forward contracts to hedge against a certain portion of the exposure mentioned above. Selling and Marketing Selling and marketing expenses consist primarily of salaries, commissions, advertising, trade shows, seminars, public relations, co-op activities with partners, travel and other related expenses. Selling and marketing expenses were $947 million in 2025 and $863 million in 2024, which represented 35% of revenues in 2025 and 34% of revenues in 2024. The net increase of $84 million in selling and marketing costs in 2025 primarily stems from significant investments in partners and marketing programs. Our selling and marketing expenses worldwide are paid in local currencies and are reported in U.S. dollars. Therefore, changes to the exchange rates between the local currencies and the U.S. dollar have affected, and may in the future affect, our expense level. General and Administrative General and administrative expenses consist primarily of salaries and other related expenses for personnel, professional fees, insurance costs, legal and other expenses. General and administrative expenses were $129 million in 2025 and $112 million in 2024 , which represented 5% of revenues in 2025 and 4% of revenues in 2024. Operating Income Margin In 2025, our operating margin was 30% compared to 34% in 2024. The decrease in our operating margin was primarily due to an increase in our workforce related expenses, cloud expenses, stock-based compensation expenses and amortization of intangibles expenses in related to our acquisitions. We may experience future fluctuations or declines in operating margins from historical levels due to several factors, as described above in “Item 3 – Key Information” under the caption “Risk Factors – Risks Related to Our Business and Our Market”. Financial Income, Net Net financial income consists primarily of interest earned on cash equivalents, short-term deposits and marketable securities. Net financial income was $114 million in 2025 and $96 million in 2024. As we generally hold debt securities until maturity, our current portfolio’s yield is derived primarily from interest rates and the yield on securities at time of purchase. Since most of our investments are U.S. dollars denominated securities, our net financial income is heavily dependent on prevailing U.S. interest rates changes and the market expectations to such changes. The higher financial income is mainly due to higher reinvestment yield in our investment portfolios in 2025, as well as additional interest income on operational cash. Additionally, in December, 2025, we completed a $2,000 million Convertible Senior Note issuance, while the net cash received during the last month of the year contributed additional interest income. For further risk related to our portfolio see also Item 3, “Risk Factors – Risks Related to Our Business and Our Market – Our cash balances and investment portfolio have been, and may continue to be, adversely affected by market conditions and interest rates”. 41 Taxes on Income (tax benefit) Total taxes on income (tax benefit) were $(112) million in 2025 and $126 million in 2024. Our effective tax rate was (12)% in 2025 and 13% in 2024. See Note 12 to our consolidated financial statements for further information on our statutory rates. Additional details are provided in “Item 10 – Additional Information” under the caption “Israeli taxation, foreign exchange regulation and investment programs” and “Item 3 – Key Information” under the caption “The tax benefits available to us require us to meet several conditions, and may be terminated or reduced in the future, which would increase our taxes”. Net Income Net income increased by $211 million to $1,057 million in 2025 compared to $846 million in 2024. Liquidity and Capital Resources During 2025 and 2024, we financed our operations through cash generated from operations. Our total cash and cash equivalents, short-term investments and long-term interest bearing investments, were $4,342 million as of December 31, 2025 and $2,784 million as of December 31, 2024. Our cash and cash equivalents and short-term investments were $3,015 million as of December 31, 2025 and $1,372 million as of December 31, 2024. Our long-term interest bearing investments were $1,327 million as of December 31, 2025 and $1,412 million as of December 31,2024. The majority of our financial assets are held and managed through the parent company in Israel and our subsidiaries in Canada and the U.S. In December 2025, we issued and sold $2.0 billion aggregate principal amount of 0.00% Convertible Senior Notes due 2030 in a private offering to qualified institutional buyers pursuant to Rule 144A under the Securities Act (all of which were outstanding as of December 31, 2025). We generated net cash from operations of $1,199 million in 2025 and $1,052 million in 2024. Net cash from operations for 2025 and 2024 consisted primarily of net income adjusted for non-cash activity. The increase in our cash from operations includes benefit from balance sheet hedging transaction of $51 million, offset by one-time tax settlement payment of $66 million. Net cash used in investing activities was $680 million in 2025 compared to $24 million in 2024. In 2025, net cash used in investing activities increased compared to 2024, primarily due to higher investment in short term deposit and lease prepayment paid during 2025. Our net cash paid for acquisitions amounted to $273 million in 2025 and $186 million in 2024. Our capital expenditures amounted to $27 million in 2025 and $24 million in 2024, and consisted primarily of computer equipment, software and leasehold improvements. Net cash provided by financing activities was $752 million in 2025 and net cash used in financing activities was $1,060 million in 2024 . In 2025, net cash provided by financing activities was attributed primarily to the issuance of convertible senior notes in the amount of $1,780 net of issuance costs and net of purchased capped call. Net cash used in financing activities in 2025 and 2024 was also attributed to the repurchase of ordinary shares. Under the repurchase programs, we may purchase our ordinary shares from time to time, depending on market conditions, share price, trading volume and other factors. We repurchased ordinary shares in the amount of $1,400 million in 2025 and $1,300 million in 2024. We re-issued the repurchased shares to settle exercises of options and restricted share unit awards to our employees and directors. Proceeds from such activities were $393 million and $259 million in 2025 and 2024, respectively. Our investments in marketable securities are classified as AFS. AFS securities are carried at fair value, with the unrealized gains and losses, net of tax, recorded in other comprehensive income (loss). Amortization of premium, discount and interest is recorded in our consolidated statements of income. Our liquidity could be negatively affected by a decrease in demand for our products and services, or increase in employment costs. Also, if the financial system or the credit markets deteriorate or remain volatile, our investment portfolio may be impacted and the values and liquidity of our investments could be adversely affected. Our principal sources of liquidity consist of our cash and cash equivalents, short-term bank deposits and marketable securities (which aggregated $4,342 million as of December 31, 2025) and our cash flow from operations. We believe that these sources of liquidity will be sufficient to meet our normal operating requirements during the next 12 months and the foreseeable future and to fund capital expenditures. 42 Research and Development, Patents and Licenses, etc. Additional details are provided in this Item 5, under the caption “Results of Operations”. Trend Information Additional details are provided in this Item 5, under the caption “Results of Operations”.