← Back to RDWR filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
INFORMATION
A. [Reserved]
B. Capitalization
and Indebtedness
Not applicable.
C. Reasons
for the Offer and Use of Proceeds
Not applicable.
D. Risk
Factors
You should carefully consider the following risks before deciding
to purchase, hold or sell our ordinary shares. Our business, operating results, and financial condition could be seriously harmed due
to any of the following risks. The following risks are not the only risk factors faced by our Company. Additional risks and uncertainties
not presently known to us or that we currently deem immaterial may also affect our business. The trading price of our ordinary shares
could decline due to any of these risks. You should also refer to the other information contained or incorporated by reference in this
annual report before making any investment decision regarding our Company.
Summary of Risk Factors
The following constitutes a summary of the material risks relevant to an investment
in our Company:
Risks Related to Our Business and Our Industry
• Changing or severe global market and economic conditions could have a material adverse effect on our results of operations.
• We are highly dependent upon independent distributors to sell our solutions to customers. If our distributors do not succeed in selling our products and services, we may not be able to operate profitably.
• A shortage of components or manufacturing capacity could cause a delay in our ability to fulfill orders or increase our manufacturing costs, and any disruption in our supply chain could have a material adverse effect on our results of operations.
• We rely on a few vendors to provide our hardware platforms and components for the manufacture of our products.
• Our success depends on our ability to attract, train and retain highly qualified personnel.
• Competition in the market for cybersecurity and application delivery solutions and in our industry, in general, is intense. If we are unable to compete effectively, we may lose market share, and we may be unable to maintain profitability.
• We must develop new solutions and enhance existing solutions to remain competitive.
• Our reputation and business could be harmed based on real or perceived shortcomings, defects or vulnerabilities in our solutions or if our end-users experience security breaches, which could have a material adverse effect on our business, reputation and operating results.
• We use AI Technologies that present regulatory, litigation, and reputational risks that could materially and adversely affect our business, financial condition and results of operations.
• We face risks related to the rapidly evolving regulatory framework for AI Technologies.
8
• As a security provider, if our information technology systems and data, or those of our service providers and other contractors, are compromised by cyber-attackers or other malicious actors, or by a critical system failure, our reputation, financial condition and operating results could be materially adversely affected.
• Outages, interruptions, or delays in hosting services could impair the delivery of our cloud-based security services and harm our business.
• Our products must interoperate with operating systems, software applications and hardware that are developed by others and if we are unable to devote the necessary resources to ensure that our products interoperate with such software and hardware, we may fail to increase, or we may lose market share and we may experience a weakening demand for our products.
• Our global operations may expose us to additional risks.
• We have incurred net losses in the past and may incur losses in the future.
• A slowdown in the growth of the cybersecurity and application delivery solutions market would reduce our addressable market and solutions sales.
• If the market for our cloud-based solutions does not continue to develop and grow, we may incur capital and operating losses.
• Our solutions have long sales cycles, which may reduce the predictability of our financial performance.
• We may pursue acquisitions or other investments that could disrupt our business and harm our financial condition.
• Our business in countries with a history of corruption and transactions with foreign governments increases the risks associated with our international activities.
• Currency exchange rates and fluctuations of exchange rates could have a material adverse effect on our results of operations.
• Undetected defects and errors may increase our costs and impair the market acceptance of our products.
• Our business and operating results could suffer if third parties infringe upon our proprietary technology.
• Our products may infringe on the intellectual property rights of others.
9
• Laws, regulations and industry standards affecting our business are evolving, and unfavorable changes could harm our business.
• Some of our solutions contain “open source” and third-party software, and any failure to comply with the terms of one or more of these open source and third-party software licenses could negatively affect our business.
• The amount of intangible assets and goodwill on our books may in the future lead to significant impairment charges.
• Additional tax liabilities, including due to tax positions we have taken, could materially adversely affect our results of operations and financial condition.
• The enactment of legislation changing the United States’ taxation of international business activities could materially impact our financial condition and results of operations.
• Complications with the design or implementation of our new enterprise resource planning (“ERP”) system, or major disruptions or deficiencies of our other information technology systems, could adversely impact our business and operations.
• We rely on information technology systems to conduct our businesses, and failure to protect these systems against security breaches and otherwise to implement, integrate, upgrade and maintain such systems in working order could have a material adverse effect on our results of operations, cash flows or financial condition.
• Our business may be affected by sanctions, export controls and similar measures targeting Russia and other countries and territories, as well as other responses to Russia’s military conflict in Ukraine, including indefinite suspension of operations in Russia and dealings with Russian entities by many multi-national businesses across a variety of industries.
• Our disclosures and initiatives related to environmental, social and governance (ESG) matters, including those related to climate change and sustainability, expose us to numerous risks, including risks to our reputation, business, financial performance and growth.
• We have in the past, and may in the future, become subject to litigation or claims arising in or outside the ordinary course of business that could negatively affect our business operations and financial condition.
10
Risks Related to the Market for Our
Ordinary Shares
• The estate of the late Yehuda Zisapel, along with Nava Zisapel and Roy Zisapel, our President, Chief Executive Officer and a director, may exert significant influence in the election of our directors and over the outcome of other matters requiring shareholder approval.
• Provisions of our Articles of Association and Israeli law as well as the terms of our equity incentive plan could delay, prevent or make a change of control of us more difficult or costly, which could depress the price of our ordinary shares.
• Our share price has been volatile in the past and may be subject to volatility in the future.
• If we are characterized as a passive foreign investment company, our U.S. shareholders may suffer adverse tax consequences.
• If a U.S. person is treated as owning at least 10% of our ordinary shares, such holder may be subject to adverse U.S. federal income tax consequences.
• We are a foreign private issuer and, as a result, we are subject to reporting obligations and corporate governance practices that, to some extent, are more lenient than those of a U.S. domestic public company whose shares are listed on Nasdaq.
Risks Related to Operations in Israel
• Political, economic and military instability in the Middle East or Israel may harm our business.
• The tax benefits we may receive in connection with our preferred enterprise program require us to satisfy prescribed conditions and may be terminated or reduced in the future. This would increase taxes and decrease our net profit.
• We have obtained benefits from the Israeli Innovation Authority that subject us to ongoing restrictions.
• It may be difficult to enforce a U.S. judgment against us or our officers and directors and to assert U.S. securities laws claims in Israel.
• Your rights and responsibilities as a shareholder will be governed by Israeli law, which may differ in some respects from the rights and responsibilities of shareholders of U.S. companies.
11
Risks Related to Our Business and Our Industry
Changing or severe global market and economic
conditions could have a material adverse effect on our results of operations.
Our business is affected by global market and economic conditions,
uncertainties and downturns, including as a result of instability in the Middle East (see the risk factor below titled “Political,
economic and military instability in the Middle East or Israel may harm our business”), the tensions between China and Taiwan, export
controls recently imposed by the United States with respect to, among other things, graphics processing units (GPUs), and central banks
in the markets in which we operate that have tightened their monetary policies and, until recently, raised interest rates, which may impact
current and anticipated market demand for our solutions. Uncertainties about current global market and economic conditions continue
to pose a risk as our current or prospective customers may postpone or reduce demand and spending priorities in response to such uncertainties.
This could result in, among other things, a reduction in our revenues or a failure to achieve anticipated revenue growth, longer sales
cycles, and slower adoption of new technologies, as well as downward pressure on the price of our solutions. Other macro conditions may
have other adverse effects on the global markets and economy, which are difficult to predict, such as disruptions of the global supply
chain and energy markets, instability of any bank with which we maintain a commercial relationship, inflation pressures, rising interest
rates or a period of elevated interest rates or impacts from tariffs or other trade restrictions. Each of the above events could have
a material adverse effect on our business, operating results, and financial condition.
We are highly dependent upon independent distributors
to sell our solutions to customers. If our distributors do not succeed in selling our products and services, we may not be able
to operate profitably.
Our growth strategy depends upon, among other things, increasing
sales of our solutions, both directly and indirectly through our different distribution channels. We
sell our solutions primarily to independent distributors, including value added resellers (VARs), original equipment manufacturers (OEMs)
and global system integrators (GSIs), and are highly dependent upon these distributors’ active marketing and sales efforts. Our
distribution agreements with our distributors generally are non-exclusive, ranging in duration with no renewal obligation on the part
of our distributors. Our distribution agreements also typically do not prevent our distributors from selling products and services of
our competitors and do not contain minimum sales or marketing performance requirements. As a result, our distributors may give higher
priority to products and services of our competitors or their own products, thereby reducing their efforts to sell our products and services.
In addition, we may not be able to maintain our existing distribution relationships, and we may not be successful in replacing them on
a timely basis, or at all. We may also need to develop new distribution channels for new products and services, and we may not succeed
in doing so. Any changes in our distributor relationships or distribution channels, including a termination or other disruption of our
commercial relationship with our distributors or our inability to establish distribution channels for new products and services, could
impair our ability to sell our products and services and have a material adverse effect on our business, financial condition and results
of operations.
A shortage of components or manufacturing capacity
could cause a delay in our ability to fulfill orders or increase our manufacturing costs, and any disruption in our supply chain could
have a material adverse effect on our results of operations.
Our ability to meet customer demands depends in part on our ability
to obtain timely deliveries of parts from our suppliers and contract manufacturers. We cannot assure you that we will not encounter supply
and fulfilment issues in the future and certain components are presently available to us only from limited sources (see the risk factor
below titled “We rely on a few vendors to provide our hardware platforms and components for the manufacture of our products” and
the discussion under Item 4.B “Business Overview—Manufacturing and Suppliers”). We may not be able to diversify sources
in a timely and cost-effective manner, which could harm our ability to deliver products to customers and adversely impact present and
future sales and profitability.
We may experience a shortage of certain component parts as a result
of our own manufacturing issues, manufacturing issues at our suppliers or contract manufacturers, capacity problems or transportation
and freight carriers issues experienced by our suppliers or contract manufacturers, or strong demand in the industry for those parts,
especially if there is growth in the overall economy. If there is growth in the economy, such growth is likely to create greater pressures
on us and our suppliers to accurately project overall component demand and component demands within specific product categories and to
establish optimal component levels. If shortages or delays persist, such as due to the worldwide chipset shortage, the price of these
components may increase, or the components may not be available at all.
12
We may also encounter shortages if we do not accurately anticipate
our needs. We may not be able to secure enough components at reasonable prices or of acceptable quality to build new products in a timely
manner in the quantities or configurations needed. Accordingly, our revenues and gross margins could be materially and adversely affected
until other sources can be developed.
In addition, our operating results could be materially and adversely
affected if we anticipate greater demand than what transpires, and we commit to purchasing more components than we actually need. We see
this specifically with respect to dated components, which we need to order in large quantities due to manufacturing stoppage. Due to technology
advancements, we are required from time to time to make “last buy” type of stock purchases of such dated components for our
products.
Any disruption in our supply chain, such as disruptions resulting
from failure in telecommunication systems; acts of war, terrorism, cyber-attacks or natural disasters, including major environmental or
public health concerns, such as the COVID-19 pandemic; lack of skilled labor; the disruption of transportation networks; and adverse weather
conditions, could have a material adverse effect on our business, financial condition and results of operations.
We rely on a few vendors to provide our hardware
platforms and components for the manufacture of our products.
We primarily rely on a few original design manufacturers (“ODMs”),
for the manufacture and supply of our hardware platforms, with approximately 81% of our direct product costs in 2025 related to these
vendors. If we are unable to continue to do business with these ODMs and/or other components vendors on acceptable terms or should any
of these ODMs and/or components vendors cease to supply us with such platforms or components for any reason, we may not be able to identify
and integrate an alternative source of supply in a timely fashion or at the same costs. Any transition to one or more alternate manufacturers
could result in delays, operational problems and increased costs, and may limit our ability to deliver our products to our customers on
time during such a transition period, any of which could have a material adverse effect on our business, financial condition and results
of operations.
Our success depends on our ability to attract,
train and retain highly qualified personnel.
Our products and services require sophisticated technology, marketing
and sales expertise. Accordingly, we need highly trained research and development, sales, marketing, technical, customer support, operations
and IT personnel. Competition for such qualified personnel, especially in the cybersecurity domain, is intense. In particular, while there
has been intense competition for such qualified personnel in the Israeli high-tech industry historically, the industry experienced record
growth and activity in the past few years, which contributed to significant levels of employee attrition. The Israeli high-tech industry
still faces a shortage of skilled human capital, including qualified personnel in the cybersecurity domain. Additionally, we may be unable
to hire or retain talent who are trained in artificial intelligence (AI) or generative artificial intelligence (Gen AI), machine learning
and advanced algorithms, to keep pace with the rapid and continuous technological changes in our industry. While we utilize non-competition agreements
with our employees as a means of improving our employee retention, we may be unable to enforce these agreements under applicable laws.
In light of the foregoing, we may not be able to hire or retain sufficient personnel to support our business operations or, if we do,
we may be required to offer increased compensation to attract such employees, which could have a material adverse effect on our business,
financial condition and results of operations.
Competition in the market for
cybersecurity and application delivery solutions and in our industry, in general, is intense. If we are unable to compete effectively,
we may lose market share, and we may be unable to maintain profitability.
The cybersecurity and application delivery solutions marketplace
is highly competitive and has very few barriers to entry, particularly in our focus areas. We expect competition to intensify in the future,
including as a result of the integration of AI technologies into the markets in which we compete, and we may lose market share if we are
unable to compete effectively.
13
Most of our competitors have greater financial, personnel
and other resources than we have, which may limit our ability to effectively compete with them. We expect to continue to face additional
competition as new participants enter the market or extend their portfolios into related technologies. Current and future participants
may also be able to respond more quickly to new or emerging technologies and changes in customer demands and to devote greater resources
to the development, promotion and sale of their products than we can. Larger companies with substantial resources, brand recognition and
sales channels may form consolidation and alliances with or acquire competing cybersecurity and application delivery solutions and emerge
as significant competitors.
Competition may result in lower prices or reduced demand
for our solutions and a corresponding reduction in our ability to recover our costs, which may impair our ability to achieve, maintain
and increase profitability. Furthermore, the dynamic market environment poses a challenge in predicting market trends and expected growth.
We cannot assure you that we will be able to implement our business strategy in a manner that will allow us to be competitive. If any
of our competitors offer products or services that are more competitive than ours, we could lose market share and our business, financial
condition and results of operations could be materially and adversely affected as a result.
We must develop new solutions and enhance
existing solutions to remain competitive.
The cybersecurity market is experiencing rapid technological
shifts driven by accelerated Digital Transformation and Generative/Agentic AI. These advancements enable adversaries to create targeted
exploits and accelerate cyberattack deployment. In addition, evolving network infrastructures, application architectures, development
methodologies, and stringent compliance mandates further complicate the landscape. The active and evolving cyber threat environment is
also intensified by weaponized AI tools. To address these challenges effectively, we must focus on several critical areas:
• Enhancing Core Product Performance: Increasing throughput, capacity, algorithmic coverage, and efficiency to manage the growing velocity and complexity of attacks.
• Adapting to Infrastructure Changes: Providing relevant solutions for Generative/Agentic AI, multi-cloud and hybrid cloud environments in response to fundamental shifts in customers’ data centers and application/data locations.
• Innovating Modern Application Security: Developing new solutions to address changes in application deployment frameworks, workflows, API usage, account takeover attacks, browser security, supply chain threats, and edge delivery technologies.
• Expanding Security Coverage: Extending protection to API, LLM, client-side, edge, DNS, cloud-native, business logic, encrypted/web DDoS, and AI-driven attacks, including those using natural language processing and automated methods.
• Service Enhancements: Increasing support/service delivery to accommodate rising customer demands and infrastructure scale. Expanding our managed security services for the cloud and through the cloud – organically and inorganically.
• Compliance and Regulatory Adaptation: Meeting new regulations related to publicly exposed services and sensitive data validation.
Our future success also hinges on our ability to accurately identify
market trends and anticipate evolving customer needs, invest in research and development, including acquiring complementary solutions,
timely develop, introduce, and support relevant new solutions and enhancements, and achieve market acceptance of these offerings.
14
In order to meet these challenges and remain competitive
in the market, we have introduced, and must continue to introduce, new solutions and enhancements to our existing solutions. Accordingly,
our future success will depend, to a substantial extent, on our ability to accurately and timely identify market trends and anticipate
changing market requirements and needs; to invest (including through acquisition of complimentary solutions) in research and development
and timely develop, introduce and support relevant and desired new solutions and enhancements; and to gain market acceptance of our offerings.
There can be no assurances that our continued investment in research and development, including associated capital expenditures, will
ultimately allow us to remain competitive in our industry or otherwise result in successful solutions that generate expected sales and
support our growth. In addition, diversifying our solution portfolio might expose us to direct competition with new players and might
require additional investments in the associated sales and marketing practices.
If our research and development efforts do not lead to
a corresponding increase in our revenues, if we fail to timely develop and deploy new solutions and enhancements to our existing solutions,
or if we fail to gain market acceptance of our new solutions or enhanced solutions, our business, operating results, and financial condition
could be materially adversely affected.
Our reputation and business could be
harmed based on real or perceived shortcomings, defects or vulnerabilities in our solutions or if our end-users experience security breaches,
which could have a material adverse effect on our business, reputation and operating results.
Any errors, defects, or misconfigurations could cause
our solutions to not meet specifications, be vulnerable to security attacks or fail to secure networks or applications, which could negatively
impact customer operations and consequently harm our business and reputation. In addition, we may suffer significant adverse publicity
and reputational harm and become subject to regulatory and litigation claims if our solutions are associated, or are believed to be associated
with, or fail to reasonably protect against, a security attack or a breach at a high-profile customer, a significant customer base or
a significant business partner. Many of our customers and business partners are themselves highly regulated entities, which may result
in enhanced scrutiny of our security program and controls in the event of a significant cybersecurity incident. Moreover, any actual or
perceived cyber-attack, other security breach, exposure or theft of our or our customers’ data, regardless of whether the breach
or theft is attributable to the failure of our solutions, could:
• adversely affect the market’s perception of our security solutions;
• cause current or potential customers to look to our competitors for alternatives;
• require us to expend significant financial resources to analyze, correct or eliminate any vulnerabilities; and
• lead to investigations, litigation, fines and penalties, any of which could have a material adverse effect on our operations, financial condition and reputation.
Cyber-attackers or other malicious actors are increasingly
sophisticated, may be state actors or affiliated with organized crime, and may operate large-scale and complex automated attacks. In addition,
the techniques they use to access or sabotage networks or applications or to disrupt operations (for example, via ransomware) change frequently
and generally are not recognized until launched against a target. As a result, our solutions may be unable to anticipate these techniques
and provide timely or effective protection to our end-users’ networks or applications, particularly due to the increased use by
attackers of tools and techniques that are designed to circumvent security controls, to avoid detection and to remove or obfuscate evidence.
The global marketplace also expects actors to increasingly develop innovative attack methodologies utilizing AI as well as new tools to
identify and exploit vulnerabilities from both technical and social engineering perspectives. In addition, continued remote and hybrid
working arrangements at our Company (and at many third-party providers), such as those that evolved during the COVID-19 pandemic and continued
after the pandemic, also increase cybersecurity risks due to the challenges associated with managing remote computing assets and the security
vulnerabilities that are present in many non-corporate and home networks. We may acquire companies or enter into information technology
system integrations with companies that have cybersecurity vulnerabilities or unsophisticated security measures, which would expose us
to increased risks. In addition, we cannot comprehensively identify all misconfigurations, “bugs” or vulnerabilities in proprietary
or third-party systems or software used by our business, or guarantee that patches or compensating controls will be applied before vulnerabilities
can be exploited by a threat actor. If we fail to identify and respond to new and increasingly complex methods of attack or to update
our solutions to detect or prevent such threats in time to protect our end-users’ critical business data, the integrity of our solutions
and reputation, as well as our business and operating results, could suffer.
15
Furthermore, security breaches or defects in our solutions
could result in loss or alteration of, or unauthorized access to, data of customers, employees, business partners and others, including
personally identifiable information, as well as proprietary information belonging to our business such as trade secrets, and compromise
our customers’ networks and applications that are secured by our physical and cloud solutions. Moreover, any use or integration
of generative or other AI in our, or any third party’s, operations, products or services will pose new and/or unknown cybersecurity
risks and challenges. AI tools and applications have created a new attack vector to infect unsuspecting users with malware, such as ransomware
and data extraction routines. If such a security breach results in the disruption or loss of availability, integrity or confidentiality
of customers’ data, we could incur significant liability to our customers and to businesses or individuals whose information was
being handled by our customers, in addition to liability imposed by regulatory agencies. There can be no assurance that limitation of
liability, indemnification or other protective provisions that we attempt to include in our contracts would be applicable, enforceable
or adequate in connection with a security breach, or would otherwise protect us from any such liabilities or damages with respect to any
particular claim.
There is no guarantee that our solutions will be free
of flaws or vulnerabilities. Our end-users may also misuse our solutions, which could result in vulnerabilities to a breach or theft of
business data. Furthermore, there can be no assurance that our cybersecurity risk management program and processes, including our policies,
controls, or procedures, will be fully implemented, complied with or effective in protecting our information technology systems and confidential
information.
We use AI Technologies that present
regulatory, litigation, and reputational risks that could materially and adversely affect our business, financial condition and results
of operations.
We use various AI Technologies throughout our business, and are
making significant investments in this area. For example, we use AI Technologies to serve some of our cloud customers.
There are significant risks involved in developing, maintaining
and deploying AI Technologies. In particular, if the models underlying our AI Technologies are incorrectly designed or implemented; trained
or reliant on incomplete, inadequate, inaccurate, biased or otherwise poor quality data, or on data to which we do not have sufficient
rights or in relation to which we and/or the providers of such data have not implemented sufficient legal compliance measures; used without
sufficient oversight and governance; and/or adversely impacted by unforeseen defects, technical challenges, cybersecurity threats or material
performance issues, the performance of our products, services and business, as well as our reputation, could suffer, or we could incur
liability resulting from the violation of laws or contracts to which we are a party or civil claims.
16
With respect to our products or services that incorporate AI Technologies,
the market for such products and services is rapidly evolving. We cannot be sure that the market will continue to grow or that it will
grow in ways we anticipate. In addition, market acceptance and consumer perceptions of products and services that incorporate AI Technologies
is uncertain. Our failure to successfully develop and commercialize our products or services involving AI Technologies could depress the
market price of our ordinary shares and impair our ability to raise capital, expand our business, provide, improve and diversify our product
offerings, efficiently manage our operating expenses; and respond effectively to competitive developments.
In particular, we are working to incorporate Gen AI into our solutions
and internal business practices. There is a risk that Gen AI could produce inaccurate or misleading content or other discriminatory or
unexpected results or behaviors, such as hallucinatory behavior that can generate irrelevant, nonsensical, or factually incorrect results,
all of which could harm our reputation, business, or customer relationships. While we take measures designated to ensure the accuracy
of such AI generated content, those measures may not always be successful, and in some cases, we may need to rely on end users to report
such inaccuracies.
Further, if we are deemed to not have sufficient rights to the
data we use to train our Gen AI, we may be subject to litigation by the owners of the content or other materials that comprise such data,
similar to the litigation that is currently pending in various U.S. courts against other developers of Gen AI, and in which the outcome
of such litigation is uncertain.
We may not be successful in our ongoing development and maintenance
of these technologies in the face of novel and evolving technical, reputational and market factors. Our efforts to develop proprietary
AI models could increase our operating costs. Our ability to develop proprietary AI models may be limited by our access to processing
infrastructure or training data, and we may be dependent on third-party providers for such resources.
We face significant competition from other companies in our industry
in relation to the development and deployment of AI Technologies. Those other companies may develop AI Technologies that are similar or
superior to ours and/or are more cost-effective and/or quicker to develop, deploy and maintain. Any inability to develop, offer or deploy
new AI Technologies as effectively, as quickly and/or as cost-efficiently as our competitors could have a materially adverse impact on
our operating results, customer relationships and growth.
Further, our ability to continue to develop or use such technologies
may be dependent on access to specific third-party software, services and infrastructure, such as processing hardware, and we cannot control
the availability or pricing of such third-party software and infrastructure, especially in a highly competitive environment.
17
We face risks related to the rapidly evolving regulatory framework
for AI Technologies.
The regulatory framework for AI Technologies is rapidly
evolving as government bodies and agencies in many geographical jurisdictions have introduced or are currently considering additional
laws and regulations. Additionally, existing laws and regulations may be interpreted in ways that would affect the operation of our AI
technologies, or could be rescinded or amended as new administrations take differing approaches to evolving AI technologies. As a result,
implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot determine
the impact future laws, regulations, standards, or market perception of their requirements may have on our business and may not always
be able to anticipate how to respond to these laws or regulations. Already, certain existing legal regimes (e.g., relating to data privacy)
regulate certain aspects of AI technologies, and new laws regulating AI technologies have either entered into force or are expected to
enter into force in the near future.
For example, in Europe, on August 1, 2024, the EU Artificial
Intelligence Act (the “EU AI Act”) entered into force, and establishes a comprehensive, risk-based governance framework for
AI in the EU market. It is possible that additional new laws and regulations will be adopted in the United States and other jurisdictions,
or that existing laws and regulations, including competition and antitrust laws, may be interpreted in ways that would limit our ability
to use AI technologies for our business, or require us to change the way we use AI technologies in a manner that negatively affects the
performance of our products, services, and business and the way in which we use AI technologies. We may need to expend resources to adjust
our products or services in certain jurisdictions if the laws, regulations, or decisions are not consistent across jurisdictions. Further,
the cost to comply with such laws, regulations, or decisions and/or guidance interpreting existing laws, could be significant and would
increase our operating expenses (such as by imposing additional reporting obligations regarding our use of AI technologies). Such an increase
in operating expenses, as well as any actual or perceived failure to comply with such laws and regulations, could adversely affect our
business and operating results.
It is also possible that the AI technologies we use may,
or may be viewed as, having unintended biases or discriminatory outcomes, exposing us to risks that we have discriminated against persons
belonging to a protected class. Any resulting investigation or litigation could have an adverse impact on our results of operations due
to the associated costs and any related fines, and could also have an adverse impact on our customer relationships.
As a security provider, if our information
technology systems and data, or those of our service providers and other contractors, are compromised by cyber-attackers or other malicious
actors, or by a critical system failure, our reputation, financial condition and operating results could be materially adversely affected.
We will not succeed with our application and network security
solutions unless the marketplace is confident that we provide effective cybersecurity protection. We provide security solutions, and as
a result, we have been, and continue to be, an attractive target of cyber-attacks and other security incidents, which we have experienced
from time to time, that threaten the confidentiality, integrity and availability of our computer and information technology at our computer
and information technology systems and network environment. We are subject to many different types of attacks, including, among others,
malware, viruses and attachments to e-mails, web application attacks, DDoS attacks, and other disruptive activities of individuals or
groups, all of which are designed to impede the performance of our solutions, penetrate our network security or the security of our cloud
platform or our internal systems, misappropriate proprietary and other important data and personal information we process or maintain
and/or cause other interruptions to our services. We and certain of our third-party providers regularly experience cyberattacks and other
incidents, and we expect such attacks and incidents to continue in varying degrees. While to date no attacks or incidents have had a material
impact on our operations or results, we cannot guarantee that material incidents will not occur in the future. We expect cyberattacks
to accelerate on a global basis in both frequency and magnitude, as threat actors are increasingly sophisticated in using techniques and
tools – including AI – that can circumvent controls, evade detection and remove forensic evidence. As a result, we may be
unable to detect, investigate, remediate or recover from future attacks or incidents, or to avoid a material adverse impact on our information
technology systems, confidential information or business. Furthermore, third parties may attempt to illegally induce employees or customers
into disclosing our proprietary information or otherwise compromising the security of our internal networks, systems or physical facilities
in order to gain access to our data or our customers’ data. An actual or perceived breach of security in our internal systems
could adversely affect the integrity and market perception of our solutions. Furthermore, the costs to eliminate or address security threats
and vulnerabilities before or after a cyber-security incident and any resulting regulatory or litigation actions could be significant.
18
We rely on third-party service providers to supply physical
hosting, cloud environments, and specific support technologies in order to deliver and support our security solutions, in addition to
internal functions, such as human resources, finance, and electronic communications, all of which are designed to enable us to conduct,
monitor, and/or protect our business, operations, systems, and data assets. Such third-party service providers have from time to time
been subject to, and continue to be subject to, cyber-attacks, malicious actors, and other security incidents. While we periodically evaluate
the internal security posture of each third-party service provider to determine their level of compliance, we may not be able to detect
any breach in the first instance it occurs. These risks may impact the integrity and availability of our solutions and may expose us to
legal and reputational liability.
Any significant system failure, accident, attack or security
breach could have a material adverse effect on our business, financial condition and results of operations. Remediation efforts or system
redundancy or other continuity measures may be ineffective or inadequate and could result in interruptions, delays or cessation of service
and loss of existing or potential customers. There can be no assurance that limitation of liability, indemnification or other protective
provisions in our contracts would be applicable, enforceable, or adequate in connection with a security breach, or would otherwise protect
us from any such liabilities or damages with respect to any particular litigation (including class actions), reputational impacts, and
the loss of partners, collaborators and customers. Additionally, our professional, product, and cyber liability insurance coverages may
only cover certain liabilities in connection with a security breach or other security incident and may not adequately cover all liabilities
actually incurred, and we cannot assure you that insurance will continue to be available to us on commercially reasonable terms, if at
all, or that any insurer will not deny coverage as to any future claim.
In addition, any such security breach could disrupt or
impair our ability to operate our business, including our ability to provide maintenance and support services to our customers. If this
happens, our revenues could decline and our reputation and business could suffer.
Outages, interruptions, or delays in
hosting services could impair the delivery of our cloud-based security services and harm our business.
We offer infrastructure that supports our DDoS Protection
services, web application firewall (WAF) and bot management cloud-based services. In addition, we provide other services through the cloud,
such as Content Delivery Network (CDN). Despite precautions taken within our own internal network and at these third-party facilities,
the occurrence of a natural disaster or an act of terrorism or other unanticipated problems could result in lengthy interruptions in our
services.
The cloud-based security services that we provide are
operated from a network of third-party facilities that host the software and systems that operate these security services. Any damage
to, failure of, or significant disruptions (for example, due to ransomware) to, our internal systems or systems at third-party hosting
facilities could result in outages or interruptions in our cloud-based services. Outages or interruptions in our cloud-based security
services, whether as a result of impacts to our or our third-party hosting facilities or otherwise, may cause our customers to experience
cyber-attacks and to believe that our cloud-based security services are unreliable, cause us to issue credits or pay penalties or damages,
cause customers to terminate their subscriptions, and adversely affect our reputation and renewal rates and our ability to attract new
customers, ultimately harming our business and results of operations.
19
Our products must interoperate with operating systems, software
applications and hardware that are developed by others and if we are unable to devote the necessary resources to ensure that our products
interoperate with such software and hardware, we may fail to increase, or we may lose market share and we may experience a weakening demand
for our products.
Our products must interoperate with our customers’
existing infrastructure, including their networks, servers, software and operating systems, which may be manufactured by a wide variety
of vendors and original equipment manufacturers. As a result, when problems occur in a network, it may be difficult to identify the source
of the problem. The occurrence of software or hardware problems, whether caused by our products or another vendor’s products, may
result in the delay or loss of market acceptance of our products. In addition, when new or updated versions of our end-customers’
software operating systems or applications are introduced, we must sometimes develop updated versions of our software so that our products
will interoperate properly. We may not accomplish these development efforts quickly, cost-effectively or at all. These development efforts
require capital investment and the devotion of engineering resources. If we fail to maintain compatibility with these applications, our
end-customers may not be able to adequately utilize our products, and we may, among other consequences, fail to increase, or we may lose
market share and experience a weakening in demand for our products, which would adversely affect our business, operating results and financial
condition.
Our global operations may expose us
to additional risks.
We currently offer our solutions in over 80 countries.
For the years ended December 31, 2025 and 2024, our sales outside North, Central and South America represented approximately 59% and 57%,
respectively, of our total sales. We also rely on third-party service providers around the world to supply physical hosting and cloud
environments in order to deliver and support our cloud-based services. Our global business operations involve varying degrees of risk
and uncertainty inherent in doing business in so many different jurisdictions. Such risks include, among others: difficulties and costs
of staffing and managing foreign operations; the possibility of unfavorable circumstances and additional compliance costs arising from
host country laws or regulations, including unexpected changes in the interpretations thereof and reduced protection for intellectual
property rights in some countries; partial or total expropriation; export duties and quotas; local tax exposure; economic or political
instability, including as a result of insurrection, war, natural disasters, and major environmental, climate or public health concerns,
such as the COVID-19 pandemic; differences in business practices; recessionary environments in multiple foreign markets; and damage to,
or failure of, systems at third-party hosting facilities around the word resulting in outages or interruptions in our cloud-based services.
We cannot be certain that the foregoing factors will not have a material adverse effect on our future revenues and, as a result, on our
business, operating results, and financial condition.
We have incurred net losses in the
past and may incur losses in the future.
Although we reported net income in 2025 and 2024, we incurred
net losses in 2023. Although we recorded an operating
income of $11.4 million in 2025, in 2024 and 2023 we recorded an operating loss of $3.9 million and $31.7 million, respectively, and in
2023 we recorded a net loss of $21.6 million. Our ability to maintain or increase profitability in the future depends in part on the following
factors: the economic health of the global economy, including geopolitical tensions; record levels of inflation and rising interest rates
or a period of elevated interest rates; fluctuations in currency exchange rates, particularly
volatility in the NIS/USD exchange rate; impacts from tariffs or other trade restrictions; changes in technology trends in our market
and other industries in which we currently or may in the future operate; our ability to develop and manufacture new products and technologies
and deliver new solutions in a timely manner; the competitive position of our products and services; the continued acceptance of our solutions
by our customers and in the industries that we serve; and our ability to manage expenses. In the future, it may be necessary to undertake
cost reduction initiatives to be profitable, which could lead to a deterioration of our competitive position. Any difficulties that we
encounter as we reduce our costs could negatively impact our results of operations and cash flows. Our
revenues may not increase or may grow at a lower rate than we have experienced in the past several years or may even decline, which would
negatively impact our results of operations and cash flows. We cannot assure you that we will continue to be profitable.
20
We may increase our operating expenses in future periods.
Our decision to increase operating expenses and the scope of such increases depends upon several factors, including the market situation
and the effectiveness of our past expenditures. We may continue to make additional expenditures in anticipation of generating higher revenues,
which we may not realize, if at all, until sometime in the future. This could cause reductions in our profitability or lead to losses.
Additionally, a failure of any acquisition or product development initiative to produce increased revenues could have a material adverse
effect on our operations and profitability.
A slowdown in the growth of the cybersecurity
and application delivery solutions market would reduce our addressable market and solutions sales.
The cybersecurity and application delivery market in which we operate
is rapidly evolving, and we cannot assure you that it will continue to develop and grow. In addition, we cannot assure you that our solutions
and technology will keep pace with the changes to this market. Market acceptance of cybersecurity and application delivery solutions may
be inhibited by, among other factors, a lack of anticipated congestion and strain on existing network infrastructures and the availability
of alternative solutions. If demand for cybersecurity and application delivery solutions does not continue to grow, or grows at a slower
pace than expected, we may not be able to sell enough of our solutions to maintain or increase our profitability.
If the market for our cloud-based solutions
does not continue to develop and grow, we may incur capital and operating losses.
As we continue to expand our cloud-based solution offerings, our
investments, both capital and operational, in our cloud business increase. We cannot assure you that sales of our cloud-based solutions
will continue to develop and grow. In addition, we cannot assure you that our services and technology will keep pace with the changes
in this market. Specifically, the emergence of alternative solutions, such as those offered by Amazon Web Services, Inc. (AWS), Microsoft
Azure or Google’s public cloud, may negatively affect sales of our solutions. We recognize a significant portion of revenue from
subscriptions over the term of the relevant subscription period, and as a result, downturns or upturns in sales are not immediately reflected
in full in our results of operations.
Our solutions have long sales cycles, which
may reduce the predictability of our financial performance.
Our solutions are technologically complex and are typically intended
for use in applications that may be critical to the business of our customers. As a result, our pre-sales process can be subject to delays
associated with customers’ budgetary constraints and lengthy approval and procurement processes. The sales cycles of our solutions
to large customers can last for as long as 12 months (and in some cases even longer, for example, with carrier customers) from initial
presentation to sale. Long sales cycles result in a delay to our generation of revenue. Long sales cycles also subject us to risks not
usually encountered in short sales cycles, including our customers’ budgetary constraints and internal acceptance reviews and processes
prior to purchase. In addition, orders expected in one quarter have in the past on several occasions, and could in the future, shift to
another because of the timing of our customers’ procurement decisions. Furthermore, customers may defer orders in anticipation of
new solutions or product enhancements introduced by us or by our competitors. These factors complicate our planning processes and reduce
the predictability of our financial performance.
21
We may pursue acquisitions or other investments
that could disrupt our business and harm our financial condition.
As part of our business strategy, we may invest in or acquire complimentary
businesses, technologies or assets or enter into joint ventures or other strategic relationships with third parties. Past acquisitions
have caused, and future acquisitions may cause, us to assume liabilities, incur acquisition-related costs, incur amortization expenses
or realize write-offs on assets no longer being used or phased out. In addition, the future valuation of these acquisitions may decrease
from the market price paid by us, which could result in the impairment of our goodwill and other intangible assets associated with the
relevant acquired assets. Moreover, our operation of any acquired or merged businesses, technologies or assets could involve numerous
risks, including:
• post-merger integration problems resulting from the combination of any acquired operations with our own operations or from the combination of two or more operations into a new unified entity;
• diversion of management’s attention from our core business;
• substantial expenditures, which could divert funds from other corporate uses;
• entering markets in which we have little or no experience;
• loss of key employees of the acquired operations; and
• known or unknown contingent liabilities, including, but not limited to, tax and litigation costs.
We cannot be certain that any past or future acquisitions or mergers
will be successful. If the operation of the business of any future acquisitions or mergers disrupts our operations, our results of operations
may be adversely affected, and even if we successfully integrate the acquired business with our own, we may not receive the intended benefits
of the acquisition. In addition, our pursuit of potential acquisitions may divert our management’s attention from our core business
and require considerable cash outlays at the expense of our existing operations, whether or not such transactions are consummated. A failure
of any acquisitions or product developments to produce increased revenues could have a material adverse effect on our operations and profitability.
Our business in countries with a history
of corruption and transactions with foreign governments increases the risks associated with our international activities.
As we operate and sell internationally, we are subject
to the Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.K. Bribery Act of 2010 (the “UK Bribery
Act”) and other laws that prohibit improper payments or offers of payments to foreign governments and their officials and political
parties for the purpose of obtaining or retaining business. We have operations, deal with and make sales to governmental customers in
countries known to experience corruption, particularly certain emerging countries in Eastern Europe, South and Central America, East Asia,
Africa and the Middle East. Our activities in these countries create the risk of unauthorized payments or offers of payments by one of
our employees, consultants, channel partners or sales agents that could be in violation of various anti-corruption laws, even though these
parties may not be under our control. The safeguards we have implemented or may implement in the future to prevent these practices by
our employees, consultants, channel partners and sales agents may prove to be less than effective, and our employees, consultants, channel
partners or sales agents may engage in conduct for which we might be held responsible. Violations of the FCPA, the UK Bribery Act or other
anti-corruption laws may result in severe criminal or civil sanctions, including suspension or debarment from government contracting,
and we may be subject to other liabilities, which could negatively affect our business, operating results, and financial condition.
22
Currency exchange rates and fluctuations of
exchange rates could have a material adverse effect on our results of operations.
We are impacted by exchange rates and fluctuations thereof in a
number of ways, including:
• A large portion of our expenses in Israel, principally salaries and related personnel expenses, are paid in NIS, whereas most of our revenues are generated in U.S. dollars. When the U.S. dollar is weak, our foreign currency-denominated expenses will be higher, whereas if the U.S. dollar is strong, our foreign currency-denominated expenses will be lower. If the NIS strengthens against the U.S. dollar, the dollar value of our Israeli expenses will increase and may have a material adverse effect on our business, operating results, and financial condition;
• A portion of our international sales are denominated in currencies other than U.S. dollars, such as euros, thereby exposing us to currency fluctuations in such international sales transactions;
• We incur expenses in several other currencies in connection with our operations in Europe and Asia. Devaluation of the U.S. dollar relative to such local currencies causes our operational expenses to increase; and
• The majority of our international sales are denominated in U.S. dollars. Accordingly, devaluation in the local currencies of our customers relative to the U.S. dollar could cause our customers to decrease orders or default on payment.
Undetected defects and errors may increase our
costs and impair the market acceptance of our products.
Our products have occasionally contained, and may in the future
contain, undetected defects or errors, especially when first introduced or when new versions are released, due to defects or errors that
we fail to detect, including in components supplied to us by third parties. These defects or errors may be found after the commencement
of commercial shipments. In addition, because our customers integrate our products into their networks with products from other vendors,
it may be difficult to identify the product that has caused the problem in the network. Regardless of the source of these defects or errors,
we will then need to divert the attention of our engineering personnel from our product development efforts to detect and correct these
errors and defects. We cannot assure you whether we will incur significant warranty or repair costs, be subject to liability claims for
material damages related to product errors or defects or experience any material lags or delays as a result thereof in the future. Any
insurance coverage that we maintain may also not provide sufficient protection should a claim be asserted. Moreover, the occurrence of
errors and defects, whether caused by our products or the components supplied by another vendor, may result in significant customer relations
problems and injure our reputation, thereby impairing the market acceptance of our products.
23
Our business and operating results could suffer
if third parties infringe upon our proprietary technology.
Our success depends, in part, upon the protection of our proprietary
software installed in our products, our trade secrets and trademarks. We seek to protect our intellectual property rights through a combination
of trademark and patent law, trade secret protection, confidentiality agreements, and other contractual arrangements with our employees,
affiliates, distributors, and others. In the United States and several other countries, we have registered or acquired trademarks. In
addition, we have registered patents in the U.S. and other jurisdictions and have pending patent applications and provisional patents
in connection with several of our products’ features.
The protective steps we have taken may be inadequate to deter infringement
upon our intellectual property rights or misappropriation of our proprietary information. We may be unable to detect the unauthorized
use of our proprietary technology or take appropriate steps to enforce our intellectual property rights. Effective trademark, patent and
trade secret protection may not be available in every country in which we offer, or intend to offer, our products. In addition, our competitors
may independently develop technologies that are substantially equivalent or superior to our technology. Any licenses for intellectual
property that might be required for our services or products may not be available on reasonable terms. Failure to adequately protect our
intellectual property rights could devalue our proprietary content, impair our ability to compete effectively, and eventually harm our
operating results. Furthermore, defending our intellectual property rights, either by way of initiating intellectual property litigation
or defending such, could result in the expenditure of significant financial and managerial resources. Moreover, any adverse outcome of
litigation proceedings could impact the value of our proprietary technology and have additional significant financial impacts, which may
harm our operating results.
Our products may infringe on the intellectual
property rights of others.
Third parties may assert claims that we have violated a patent,
trademark, copyright or other proprietary intellectual property right belonging to them. As is characteristic of our industry, there can
be no assurance that our products do not or will not infringe the proprietary rights of third parties, that third parties will not claim
infringement by us with respect to patents or other proprietary rights, or that we would prevail in any such proceedings. We have received
in the past, and may receive in the future, communications asserting that the technology used in some of our products requires third-party
licenses. Any infringement claims, whether or not meritorious, could result in significant costly litigation or arbitration and divert
the attention of technical and management personnel. Any adverse outcome in litigation alleging infringement could require us to develop
non-infringing technology or enter into royalty or licensing agreements. If, in such situations, we are unable to obtain licenses on acceptable
terms, we may be prevented from manufacturing or selling products that infringe such intellectual property of a third party. An unfavorable
outcome or settlement regarding one or more of these matters could have a material adverse effect on our business, reputation and operating
results.
Laws, regulations and industry standards affecting
our business are evolving, and unfavorable changes could harm our business.
We are required to comply with stringent, complex and evolving
laws, rules, regulations and standards in many jurisdictions, as well as contractual obligations, relating to data privacy and security
because we receive, store, use and otherwise process personal information from our employees, customers, the employees of our customers
and our end users. Laws, regulations and industry standards that apply to our business are becoming more prevalent and constantly
evolving, particularly in the area of data and cybersecurity. We may be impacted by changes in privacy-related and cybersecurity-related
regulations governing the collection, use, retention, sharing and security of personal data that we collect, utilize, or otherwise process
from our customers and/or visitors to their websites and others. Complying with a diverse range of privacy and cybersecurity requirements
could cause us to incur substantial costs or require us to change our business practices in a manner adverse to our business. Any failure,
or perceived failure, by us to comply with any privacy or cybersecurity-related laws, government regulations or directives, or industry
self-regulatory principles could result in damage to our reputation or proceedings or actions against us by governmental entities or others,
which could potentially have an adverse effect on our business.
24
Given the global nature of our operations, we are subject to a variety of local, state,
national, and international laws and directives and regulations related to privacy and data protection, data security, data storage and
retention, data transfer and deletion, and technology protection. These laws may include, among others, the following:
• The European General Data Protection Regulation (“GDPR”).
• UK General Data Protection Regulation and the UK Data Protection Act 2018 (“UK DP Laws”).
• EU laws and directives, including the Digital Operational Resilience Act (“DORA”), the Digital Services Act, the Network and Information Security Directive II and the Cyber Resilience Act (“CRA”).
• U.S. state and federal laws, including the California Consumer Privacy Act (“CCPA”) and follow-on legislation in the California Privacy Rights Act (“CPRA”).
For example, in the European Economic Area (EEA), we are subject to the
GDPR and in the United Kingdom we are subject to the United Kingdom data protection regime consisting primarily of the UK DP Laws, in
each case in relation to our collection, control, processing, sharing, disclosure and other use of data relating to an identifiable living
individual (personal data). The GDPR, and national implementing legislation in EEA member states and the United Kingdom, impose a strict
data protection compliance regime. GDPR and UK DP Laws can expose us to enforcement actions and investigations by regulatory authorities
and potentially result in regulatory penalties and significant legal liability, if our information technology security efforts fail and
if we fail to disclose any material cybersecurity incident in an adequate and timely manner. Accordingly, a data security breach or privacy
violation that leads to unauthorized access to, disclosure or modification of personal information, that prevents access to personal information
or materially compromises the privacy, security, or confidentiality of the personal information, could result in fines, increased costs
or loss of revenue. Our compliance with GDPR and UK DP Laws, as well as other data privacy and cybersecurity laws around the world, evolving
regulations of cloud computing, cross-border data transfer restrictions and other domestic or foreign regulations, has required and will
continue to require us to invest significant resources in compliance and compliance-related areas.
25
Furthermore, laws, regulations and industry standards are subject
to constant and, at times, drastic changes that, particularly in the case of industry standards, may arrive with little or no notice,
and these could either help or hurt the demand for our solutions. If we are unable to adapt our solutions to changing laws, regulations
and industry standards in a timely manner, or if our solutions fail to assist our customers with their compliance initiatives, our customers
may lose confidence in our solutions and could switch to competing solutions. Recent legal developments in Europe have created complexity
and uncertainty regarding transfers of personal data from the EEA and the United Kingdom to the United States. These recent developments
may require us to review and amend the legal mechanisms by which we make and/or receive personal data transfers to or in the U.S. Such
legal developments also cause us to look at our operations and review our data flows to ensure we can continue to meet clients’
increasing requests for data to remain in-country or in-region. Further, the GDPR is also subject to change, and it is possible that it
may be interpreted and applied in a manner that is inconsistent with our practices and our efforts to comply with the evolving data protection
rules may be unsuccessful. For example, the European Data Protection Board continues to release guidelines for industries and impose
fines related to the GDPR, some of which have been very significant, including proposed amendments to the GDPR in November 2025. At the
same time, if, contrary to this trend, regulations and standards related to cybersecurity are changed in a manner that makes them less
onerous, our customers may view government and industry regulatory compliance as less critical to their businesses, and our customers
may purchase fewer of our solutions, or none at all. In either case, our sales and financial results would be negatively impacted and
could be materially adversely affected.
Additionally, if third parties we work with, such as sub-processors,
vendors or developers, violate applicable laws or regulations, contractual obligations or our policies - or if it is perceived that such
violations have occurred - such actual or perceived violations may also have an adverse effect on our business. Further, any significant
change to applicable laws, regulations or industry practices regarding the collection, use, retention, security, disclosure or other processing
of users’ content, or regarding the manner in which the express or implied consent of users for the collection, use, retention or
other processing of such content is obtained, could increase our costs and require us to modify our network, products and features, possibly
in a material manner, which we may be unable to complete, and may limit our ability to store and process customer data or develop new
products and features.
For more information, see Item
4.B. "Business Overview – Government Regulations – Data Privacy and Data Protection."
Some of our solutions contain “open
source” and third-party software, and any failure to comply with the terms of one or more of these open source and third-party software
licenses could negatively affect our business.
Some of our products utilize open source technologies.
Some open source software licenses require users who distribute or make available as a service open source software as part of their own
software product to publicly disclose all or part of the source code of the users’ software product or to make available any derivative
works of the open source code on unfavorable terms or at no cost. We cannot be sure that all open source software is submitted for approval
prior to use in our products and while we scan the open-source software that we use in our products and patch discovered vulnerabilities,
we have no assurance that they will be free from vulnerabilities or malicious code. The use of open-source software in our solutions may
expose us, and our customers using our solutions, to additional vulnerabilities and security breaches, which may result in significant
adverse impacts to us and our customers. In addition, open source license terms may be ambiguous and many of the risks associated with
use of open source software cannot be eliminated, and could, if not properly addressed, negatively affect our business. We may face
ownership claims from third parties over, or seeking to enforce the license terms applicable to, such open source software, including
by demanding the release of the open source software, derivative works or our proprietary source code. Any such requirement to disclose
our source code or other confidential information related to our products could materially and adversely affect our competitive position
and may adversely impact our business, results of operations and financial condition. In addition, if the license terms for the open source
code change, we may be forced to re-engineer our software or incur additional costs.
In addition, some of our solutions include other
software or intellectual property licensed from third parties. This exposes us to risks over which we may have little or no control. There
can be no assurance that the licenses from such third-party licensors will continue to be available to us on acceptable terms, if at all.
In addition, while we believe we are compliant with the terms of our third-party licenses, such licensors may still assert that we are
in breach of the terms of a license, which could give such licensors the right to terminate a license or seek damages from us, or both.
Our inability to maintain such licenses or the need to engage in litigation regarding these matters, could result in delays in releases
of new products, and could otherwise disrupt our business, unless and until equivalent technology can be identified, licensed, or developed
at substantially the same costs to us.
26
The amount of intangible assets and goodwill
on our books may in the future lead to significant impairment charges.
The amount of goodwill and intangible assets on our consolidated
balance sheets was, as of December 31, 2025, approximately $75.8 million, compared to $79.8 million as of December 31, 2024. We regularly
review our intangible and tangible assets, including goodwill, for impairment. Goodwill is subject to impairment review at least annually,
and other intangible assets are reviewed for impairment when there is an indication that impairment may have occurred. Impairment testing
has led to, and may in the future lead to, significant impairment charges.
Additional tax liabilities, including due
to tax positions we have taken, could materially adversely affect our results of operations and financial condition.
We operate our business in various countries, and we attempt
to utilize an efficient operating model to optimize our tax payments based on the laws in the countries in which we operate. This can
cause disputes between us and various tax authorities in the countries in which we operate, whether due to tax positions that we have
taken in various tax returns we have filed or due to determinations we have made not to file tax returns in certain jurisdictions. In
particular, not all of our tax returns are final and may be subject to further audit and assessment by applicable tax authorities. There
can be no assurance that the applicable tax authorities will accept our tax positions, and, if they do not, we may be required to pay
additional taxes. In the past few years, certain tax authorities who have audited our tax returns have rejected our tax positions, and
we cannot be sure that our positions will be accepted, and we may end up paying additional taxes, whether as a result of litigation, if
instituted, or settlement negotiations. Our reserves, which are based on various assumptions and estimates, may prove to be insufficient
and as such, our future results may be adversely affected.
In recent years, we have seen changes in tax laws resulting
in an increase in applicable tax rates, especially increased liabilities of corporations and limitations on the ability to benefit from
strategic tax planning, with these laws particularly focused on international corporations. Such legislative changes in one or more jurisdictions
in which we operate may have implications on our tax liability and may have a material adverse effect on our results of operations and
financial condition.
Moreover, in 2015, the Organization for Economic Co-operation
and Development (“OECD”) released various reports under its Base Erosion and Profit Shifting (“BEPS”) action plan
to reform international tax systems and prevent tax avoidance and aggressive tax planning. These actions aim to standardize and modernize
global corporate tax policy, including cross-border taxes, transfer-pricing documentation rules and nexus-based tax incentive practices
which in part are focused on challenges arising from the digitalization of the economy. The reports have a very broad scope including,
but not limited to, neutralizing the effects of hybrid mismatch arrangements, limiting base erosion involving interest deductions and
other financial payments, countering harmful tax practices, preventing the granting of treaty benefits in inappropriate circumstances
and imposing mandatory disclosure rules. It is the responsibility of OECD members to consider how the BEPS recommendations should be reflected
in their national legislation. Many countries are beginning to implement legislation and other guidance to align their international tax
rules with the OECD’s BEPS recommendations, for example, by signing up to the Multilateral Convention to Implement Tax Treaty Related
Measures to Prevent BEPS (“MLI”) which currently has been signed by over 100 jurisdictions, including Israel, who deposited
its instrument of ratification to implement the MLI on September 13, 2018.
27
The MLI implements some of the measures that the BEPS initiative
proposes to be transposed into existing treaties of participating states. Such measures include the inclusion in tax treaties of one,
or both, of a “limitation-on-benefit” (“LOB”) rule and a “principal purposes test” (“PPT”)
rule. The application of the LOB rule or the PPT rule could deny the availability of tax treaty benefits (such as a reduced rate of withholding
tax) under tax treaties. In addition, the OECD has been working on proposals, commonly referred to as “BEPS 2.0,” which would
make important changes to the international tax system, by allocating taxing rights in respect of certain profits of multinational enterprises
above a fixed profit margin to the jurisdictions within which they carry on business (subject to threshold rules) and imposing a
minimum effective tax rate on certain multinational enterprises. The rules for a global minimum tax have been implemented in a number
of jurisdictions with effect from 2024. There have been and are likely to be significant changes in the tax legislation of various OECD
jurisdictions during the period of implementation of BEPS or BEPS 2.0. In line with the above-mentioned global developments in international
taxation, the State of Israel has recently enacted the Law for the Taxation of Multinational Enterprise Groups – 2025, entered
into force on January 1, 2026, implementing key aspects of the OECD’s Pillar Two framework. In particular, the legislation introduces
a domestic minimum top-up tax (Qualified Domestic Minimum Top-Up Tax – QDMTT) generally applicable to Israeli entities that are
part of multinational enterprise groups with consolidated annual revenues of at least EUR 750 million, with the objective of ensuring
a minimum effective tax rate of 15% on profits attributable to activities in Israel and preventing the allocation of taxing rights to
foreign jurisdictions under the Income Inclusion Rule or the Undertaxed Profits Rule. It is noted that the Israeli Ministry of Finance
has published an additional draft legislation as part of its 2026 Economic Plan, proposing a revised incentive regime for research and
development activities in Israel, structured primarily as refundable or credit-based tax incentives designed to qualify under the OECD’s
“qualified” incentive criteria in a Pillar Two environment. The OECD continues to release additional guidance and the Company
intends to continue monitoring the new rules and country agreements. While certain BEPS initiatives are in the final stages of approval
and/or implementation, we cannot comprehensively predict their outcome or what impact they will have on our tax obligations and operations
or our financial statements, up to their final enactment in national and international legislation. Such legislative initiatives may materially
and adversely affect our plans to expand internationally and may negatively impact our financial condition, tax liability or results of
operations and could increase our administrative efforts.
The enactment of legislation changing the United
States’ taxation of international business activities could materially impact our financial condition and
results of operations.
Due to the expansion of our international business activities,
any changes in the U.S. taxation of such activities may increase our worldwide effective tax rate, and adversely affect our financial
condition and results of operations. For example, the Inflation Reduction Act of 2022 enacted in the United States introduced, among other
changes, a 15% corporate minimum tax on certain United States corporations and a 1% excise tax on certain stock redemptions by United
States corporations (which the U.S. Treasury indicated may also apply to certain stock redemptions by a foreign corporation funded by
certain United States affiliates). Significant changes or developments in U.S. laws and policies, such as laws and policies surrounding
international trade, foreign affairs, manufacturing and development and investment in the territories and countries where we or our customers
operate, can materially adversely affect our business, results of operations, and financial condition. The U.S. government has imposed
(in certain cases, subject to deferral) significant tariffs on imports from certain jurisdictions and indicated the likely imposition
of or significant increases in tariffs on goods imported into the United States from many other jurisdictions in the future, which could
lead to corresponding punitive actions by the countries with which the U.S. trades. Further the U.S. presidential administration has indicated
the intent to propose significant changes to the U.S. tax system. Many aspects of these potential proposals are unclear or undeveloped
and we are unable to predict which, if any, changes to the U.S. tax system will be enacted into law, and what effects any enacted legislation
might have on our tax liabilities. In addition, the U.S. presidential administration has indicated that the United States may impose retaliatory
measures with respect to jurisdictions that have, or are likely to, put in place tax rules that are extraterritorial or disproportionately
affect American companies. The likelihood of these changes being enacted or implemented is unclear. Further, other foreign governments
may enact tax laws in response to any changes in the U.S. taxation of international business activities that could result in further changes
to global taxation and materially affect our financial condition and results of operations. We are currently unable to predict whether
these or other changes will occur and, if so, the ultimate impact on our business. To the extent that such changes have a negative impact
on us, our suppliers or our consumers, including as a result of related uncertainty, these changes may materially and adversely impact
our business, financial condition, results of operations and cash flow.
28
Complications with the design or implementation
of our new ERP system, or major disruptions or deficiencies of our other information technology systems, could adversely impact our business
and operations.
We rely extensively on information systems and technology to
manage our business and summarize operating results. In January 2025, we have implemented a new cloud-based global ERP system. The new
ERP system implementation process has required, and will continue to require, the investment of significant personnel and financial resources.
Due to the new ERP system implementation process, we may experience delays, increased costs and other difficulties. Our reporting
timelines might be delayed, the effectiveness of our internal control over financial reporting could be adversely affected, and/or our
ability to assess those controls adequately could be delayed. In addition, any major disruptions or deficiencies in the design and implementation
of our other information technology systems, particularly those that impact our operations, could adversely affect our ability to run
our business.
In 2025, we also completed the migration of our on‑premises
data warehouse and business intelligence systems to a cloud‑based environment. This transition may expose us to risks inherent in
the use of cloud computing technologies. These risks include, among others, potential vulnerabilities arising from misconfigurations,
unauthorized access, data breaches, or service disruptions affecting cloud service providers. The reliance on third‑party technology
vendors increases exposure to operational and cybersecurity risks beyond our direct control. Furthermore, the use of cloud infrastructure
may expand the potential attack surface and heighten threats associated with data integrity, confidentiality, and regulatory compliance.
We continue to evaluate, monitor, and enhance our information security and vendor management programs to mitigate these risks; however,
we cannot assure you that such measures will be sufficient to prevent or detect all possible threats or incidents.
We rely on information technology systems
to conduct our businesses, and failure to protect these systems against security breaches and otherwise to implement, integrate, upgrade
and maintain such systems in working order could have a material adverse effect on our results of operations, cash flows or financial
condition.
The efficient operation of our businesses depends on our computer
hardware and software systems. For instance, we rely on information technology systems, including our new ERP system, to process customer
orders and invoices, manage accounts receivable collections, manage accounts payable processes, track costs and operations, calculate
revenues and expenses, monitor client relationships and accumulate financial results. Despite our implementation of industry-accepted
security measures and technology, our information technology systems are vulnerable to, and have been in the past subject to, computer
viruses, attempts to insert malicious codes, unauthorized access, phishing efforts, denial-of-service attacks and other cyber-attacks,
and we expect to be subject to similar attacks in the future as such attacks become more sophisticated and frequent. A breach of our information
technology systems could result in decreased performance, operational difficulties and increased costs, any of which could have a material
adverse effect on our business and operating results.
29
Our business may be affected by sanctions,
export controls and similar measures targeting Russia and other countries and territories, as well as other responses to Russia’s
military conflict in Ukraine, including indefinite suspension of operations in Russia and dealings with Russian entities by many multi-national
businesses across a variety of industries.
As a result of Russia’s military conflict in Ukraine, governmental
authorities in the United States, the European Union and the United Kingdom, among others, launched an expansion of coordinated sanctions
and export control measures, including, for example:
• blocking sanctions on some of the largest state-owned and private Russian financial institutions (and their subsequent removal from SWIFT);
• blocking sanctions against Russian and Belarusian individuals, including the Russian President, other politicians and those with government connections or involved in Russian military activities;
• blocking sanctions against persons operating in the technology sector of the Russian economy, including companies providing or receiving goods or services related to the Russian technology sector, and financial institutions conducting or facilitating significant transactions involving such parties;
• blocking sanctions against certain Russian businessmen and their businesses, some of which have significant financial and trade ties to the European Union;
• blocking of Russia’s foreign currency reserves and prohibition on secondary trading in Russian sovereign debt and certain transactions with the Russian Central Bank, National Wealth Fund and the Ministry of Finance of the Russian Federation;
• expansion of sectoral sanctions in various sectors of the Russian and Belarusian economies and the defense sector;
• United Kingdom sanctions introducing restrictions on providing loans to, and dealing in securities issued by, persons connected with Russia;
• restrictions on access to the financial and capital markets in the European Union, as well as prohibitions on aircraft leasing operations;
• sanctions prohibiting most commercial activities of U.S., U.K., and E.U. persons in the so-called People’s Republic of Donetsk and the so-called People’s Republic of Luhansk (and, with respect to the E.U., the areas of Kherson and Zaporizhzhia not controlled by the Ukrainian government), with all of these new restrictions largely tracking prior prohibitions relating to Crimea and Sevastopol;
• enhanced import and export controls and trade sanctions targeting Russia’s imports of technological goods, including E.U. and U.K. prohibitions on exporting a wide range of “industrial” goods to Russia (and on importing a large number of “revenue-generating” goods from Russia). The restrictions also include bans on the export of large numbers of “luxury” items to Russia (and in some cases also to Belarus), tighter controls on exports and reexports of dual-use items, stricter licensing policy with respect to issuing export licenses, and/or increased use of “end-use” controls to block or impose licensing requirements on exports, as well as higher import tariffs;
30
• closure of airspace to Russian aircraft;
• ban on imports of Russian oil, liquefied natural gas and coal to the United States;
• ban on imports of Russian fish, seafood, and preparations thereof, alcoholic beverages, non-industrial diamonds, and gold to the United States;
• a ban on “new investment” in the Russian Federation by a U.S. person, which may be interpreted broadly (with a similar prohibition also enacted by the United Kingdom);
• bans on the provision of certain professional services, including accounting, trust and corporate formation, auditing, and management consulting services, among others; and
• bans on the provision of services related to the worldwide maritime transportation of seaborne Russian oil, if purchased above a specific price cap.
As the conflict in Ukraine continues, there can be no certainty
regarding whether the governmental authorities in the United States, the European Union, the United Kingdom or other counties will impose
additional sanctions, export controls or other measures targeting Russia, Belarus or other territories. Furthermore, in retaliation against
new international sanctions and as part of measures to stabilize and support the volatile Russian financial and currency markets, the
Russian authorities also imposed significant currency control measures aimed at restricting the outflow of foreign currency and capital
from Russia, imposed various restrictions on transacting with non-Russian parties, banned exports of various products and imposed other
economic and financial restrictions.
Our business must be conducted in compliance with applicable economic
and trade sanctions laws and regulations, including those administered and enforced by the U.S. Department of Treasury’s Office
of Foreign Assets Control, the U.S. Department of State, the U.S. Department of Commerce, the United Nations Security Council and other
relevant governmental authorities. We must be ready to comply with the existing and any other potential additional measures imposed in
connection with the conflict in Ukraine. The imposition of such measures could adversely impact our business, including preventing us
from performing existing contracts, recognizing revenue, pursuing new business opportunities or receiving payment for products already
supplied or services already performed with customers.
In 2025 and 2024, 2% and 3% of our total revenues were from sales
to customers located in Russia, respectively. We continuously review and monitor our contractual relationships with suppliers and customers
to establish whether any of them are the target of the applicable sanctions. In the event that we identify a party with which we have
a business relationship that is the target of applicable sanctions, we would immediately activate a legal analysis of what gives rise
to the business relationship, including any contract, to estimate the most appropriate course of action to comply with the sanction regulations,
together with the impact of a contractual termination according to the applicable law, and then proceed as required by the regulatory
authorities. However, given the range of possible outcomes, the full costs, burdens, and limitations on our and our customer’s and
business partners’ businesses are currently unknown and may become significant.
Furthermore, even if an entity is not formally subject to sanctions,
customers and business partners of such entity may decide to reevaluate or cancel projects with such entity for reputational or other
reasons. As a result of the ongoing conflict in Ukraine, many U.S. and other multi-national businesses across a variety of industries,
including consumer goods and retail, food, energy, finance, media and entertainment, tech, travel and logistics, manufacturing and others,
have indefinitely suspended their operations and paused all commercial activities in Russia and Belarus. Depending on the extent
and breadth of sanctions, export controls and other measures that may be imposed in connection with the conflict in Ukraine, it is possible
that our business, financial condition, and results of operations could be materially and adversely affected.
31
Finally, any deterioration in relations between Taiwan and China
could lead to additional sanctions or export controls on China, on specific individuals or entities, or otherwise in the region which
could impact our ability to sell to certain of our customers, source components from China or other impacted countries, or otherwise negatively
impact our business.
Our disclosures and initiatives related to environmental,
social and governance (ESG) matters, including those related to climate change and sustainability, expose us to numerous risks,
including risks to our reputation, business, financial performance and growth.
There has been increasing public focus by investors, customers,
employees, policymakers, environmental activists, the media and governmental and nongovernmental organizations, as well as other stakeholders,
on a variety of ESG matters, which may increase costs (including but not limited to increased costs related to compliance, stakeholder
engagement, and contracting), impact our reputation, or otherwise affect our business performance. As we identify ESG topics for voluntary
disclosure, we have expanded and, in the future, may continue to expand, our voluntary disclosures in these areas. Statements about our
ESG initiatives and goals, and progress against those goals, may be based on standards for measuring progress that are still developing,
internal controls and processes that continue to evolve, and assumptions that are subject to change in the future. As a result, we cannot
guarantee that our approach will align with any particular stakeholder’s expectations or preferences. If our ESG-related data, processes
and reporting are incomplete or inaccurate, or if we fail to achieve progress with respect to our ESG goals on a timely basis, or at all,
our reputation, business, financial performance and growth could be adversely affected.
Moreover, various stakeholders have different, and at times conflicting
expectations. If we do not meet the evolving and varied expectations of our stakeholders with respect to ESG-related matters, we could
experience loss of customers or contracts, reputational harm, or other negative impacts on our business and results of operations. In
addition, proponents and opponents of ESG matters are increasingly resorting to activism, including litigation, to advance their perspectives,
which will be costly for us to address.
We have in the past, and may in the future,
become subject to litigation or claims arising in or outside the ordinary course of business that could negatively affect our business
operations and financial condition.
We have in the past, and may in the future, become subject to litigation
or claims arising in or outside the ordinary course of business that could negatively affect our business operations and financial condition,
including securities class actions and shareholder derivative actions, both of which are typically expensive to defend. Such claims and
litigation proceedings may be brought by third parties, including our competitors, advisors, service providers, partners or collaborators,
employees, shareholders, and governmental or regulatory bodies. Any claims and lawsuits, and the disposition of such claims and lawsuits,
could be time-consuming and expensive to resolve, divert management attention and resources, and lead to attempts on the part of other
parties to pursue similar claims. We may not be able to determine the amount of any potential losses and other costs we may incur due
to the inherent uncertainties of litigation and settlement negotiations. In the event we are required or decide to pay amounts in connection
with any claims or lawsuits, such amounts could be significant and could have a material adverse impact on our liquidity, business, financial
condition and results of operations. In addition, depending on the nature and timing of any such dispute, a resolution of a legal matter
could materially affect our future operating results, our cash flows or both. Additionally, we may be unable to maintain directors’
and officers’ liability insurance at satisfactory rates or adequate coverage amounts and may incur significant increases in insurance
costs.
32
Risks Related to the Market for Our Ordinary Shares
The estate of the late Yehuda Zisapel, along
with Nava Zisapel and Roy Zisapel, our President, Chief Executive Officer and a director, may exert significant influence in the election
of our directors and over the outcome of other matters requiring shareholder approval.
As of March 20, 2026, the estate of the late Yehuda Zisapel beneficially
owned approximately 2.5% of our outstanding ordinary shares, which is held in two equal parts by Roy Zisapel’s siblings (namely,
Carmi Zisapel and Adi Zisapel); Nava Zisapel beneficially owned approximately 6.9% of our outstanding ordinary shares; and their son,
Roy Zisapel (our President, Chief Executive Officer and a director), beneficially owned approximately 5.9% of our outstanding ordinary
shares (which includes one third of our outstanding ordinary shares of the estate of the late Yehuda Zisapel) (see Items 6.E “Share
Ownership” and 7.A “Major Shareholders”). As a result, if these shareholders act together, they could exert significant
influence on the election of our directors and on decisions by our shareholders on matters submitted to shareholder vote, including mergers,
consolidations and the sale of all or substantially all of our assets. This concentration of ownership of our ordinary shares could delay
or prevent proxy contests, mergers, tender offers, or other purchases of our ordinary shares that might otherwise give our shareholders
the opportunity to realize a premium over the then-prevailing market price for our ordinary shares. This concentration of ownership may
also adversely affect our share price.
Provisions of our Articles of Association and
Israeli law as well as the terms of our equity incentive plan could delay, prevent or make a change of control of us more difficult or
costly, which could depress the price of our ordinary shares.
The provisions in our Articles of Association relating to the election
of our directors in three staggered classes, the submission of shareholder proposals for shareholder meetings and the quorum requirement
for adjourned shareholder meetings may have the effect of delaying or making an unsolicited acquisition of our Company more difficult.
Israeli corporate and tax laws, including the ability of our Board of Directors to adopt a shareholder rights plan without shareholder
approval, may also have the effect of delaying, preventing or making an acquisition of us more difficult. For example, under the Companies
Law, upon the request of a creditor of either party to a proposed merger, an Israeli court may delay or prevent the merger if it concludes
that there is a reasonable concern that, as a result of the merger, the surviving company will be unable to satisfy the obligations of
any of the parties to the merger. In addition, our Key Employee Share Incentive Plan (1997), as amended (the “Share Incentive Plan”),
provides that, in the event of a “Hostile Takeover” (which is defined to include, among others, an unsolicited acquisition
of more than 20% of our outstanding shares), the vesting of all or a portion of our outstanding equity awards will accelerate, unless
otherwise determined by our Board of Directors (or a committee thereof). As a result, an acquisition of our Company that triggers the
said acceleration will be more costly to a potential acquirer. These provisions could cause our ordinary shares to trade at prices below
the price for which third parties might be willing to pay to gain control over us. Third parties who are otherwise willing to pay a premium
over prevailing market prices to gain control of us may be unwilling to do so because of these provisions.
33
Our share price has been volatile in the past
and may be subject to volatility in the future.
The market price for our ordinary shares, as well as the prices
of shares of other technology companies, has been volatile. For example, during 2025, the lowest closing price of our share was $19.43,
compared to the highest closing price of our share of $30.80 during the same year. The volatility of our share price may have a negative
impact on our financial performance as a result of its negative impact on employee retention. Numerous factors, many of which are beyond
our control, may cause the market price and trading volume of our ordinary shares to fluctuate significantly and decrease further, including:
• operating results that do not meet forecasts by securities analysts;
• announcements concerning us or our competitors;
• the introduction of new products and new industry standards;
• general market conditions and changes in market conditions in our industry;
• the general state of securities markets (particularly the technology sector);
• political, economic and other developments in the State of Israel, the U.S. and worldwide, including, for example, the Ukraine-Russia conflict and uncertainty and conflicts between Israel and Hamas, Israel and Hezbollah and Israel and Iran; and
• any of the events underlying any of the other risks or uncertainties set forth elsewhere in this annual report actually occurs.
If we are characterized as a passive foreign
investment company, our U.S. shareholders may suffer adverse tax consequences.
Generally, if for any taxable year, after applying certain “look
through” tax rules, (i) 75% or more of our gross income is passive income, or (ii) at least 50% of the fair market value of our
assets, averaged quarterly over our taxable year, are held for the production of, or produce, passive income, we would be characterized
as a passive foreign investment company (“PFIC”), for U.S. federal income tax purposes. If we are classified as a PFIC, our
U.S. shareholders could suffer adverse U.S. tax consequences, including having gain realized on the sale of our ordinary shares treated
as ordinary income, as opposed to capital gain income, and having potentially punitive interest charges apply to such gain. Similar rules
would apply to certain “excess distributions” made with respect to our ordinary shares.
For our taxable year ended December 31, 2025, we do not believe
that we should be classified as a PFIC. There can be no assurance, however, that the IRS will not challenge this treatment, and it is
possible that the IRS could attempt to treat us as a PFIC for 2025 and prior taxable years. The tests for determining PFIC status are
applied annually, and require a factual determination that depends on, among other things, the composition of our income, assets and activities
in each taxable year, and can only be made annually after the close of each taxable year. Furthermore, the aggregate value of our gross
assets is likely to be determined in part by reference to the trading price of our ordinary shares, which could fluctuate significantly.
We have a substantial balance of cash and other liquid investments, which are passive assets for purposes of the PFIC determination. Accordingly,
if our market capitalization declines significantly, it may make our classification as a PFIC more likely for the current or future taxable
years. Accordingly, there can be no assurance that we will not become a PFIC in future taxable years. U.S. shareholders should consult
with their U.S. tax advisors with respect to the U.S. tax consequences of investing in our ordinary shares. For a more detailed discussion
of the rules relating to PFICs and related tax consequences, please see the section of this annual report titled Item 10.E “Taxation—United
States Federal Income Tax Considerations.”
34
If a U.S. person is treated as owning at least
10% of our ordinary shares, such holder may be subject to adverse U.S. federal income tax consequences.
Depending upon the aggregate value and voting power of our ordinary
shares that U.S. persons are treated as owning (directly, indirectly, or constructively), we could be treated as a controlled foreign
corporation (a “CFC”). Additionally, because our group consists of one or more U.S. subsidiaries, certain of our non-U.S.
subsidiaries will be treated as CFCs, regardless of whether or not we are treated as a CFC. If a U.S. person is treated as owning (directly,
indirectly or constructively) at least 10% of the value or voting power of our ordinary shares, such person may be treated as a “U.S.
shareholder” with respect to each CFC in our group (if any), which may subject such person to adverse U.S. federal income tax consequences.
Specifically, a U.S. shareholder of a CFC may be required to annually report and include in its U.S. taxable income its pro rata share
of each CFC’s “Subpart F income,” “global intangible low-taxed income” and investments in U.S. property,
whether or not we make any distributions of profits or income of a CFC to such U.S. shareholder. If you are treated as a U.S. shareholder
of a CFC, failure to comply with these reporting obligations may subject you to significant monetary penalties and may prevent the statute
of limitations with respect to your U.S. federal income tax return for the year for which reporting was due from starting. Additionally,
a U.S. shareholder that is an individual would generally be denied certain tax deductions or indirect foreign tax credits that may otherwise
be allowable to a U.S. shareholder that is a U.S. corporation. We cannot provide any assurances that we will assist investors in determining
whether we or any of our non-U.S. subsidiaries are treated as CFCs or whether any investor is treated as a U.S. shareholder with respect
to any of such CFC, nor do we expect to furnish to any U.S. shareholders information that may be necessary to comply with the aforementioned
reporting and tax paying obligations. The United States Internal Revenue Service provided limited guidance on situations in which investors
may rely on publicly available alternative information to comply with their reporting and tax paying obligations with respect to foreign-controlled
CFCs. U.S. investors should consult their advisors regarding the potential application of these rules to their investment in our ordinary
shares.
We are a foreign private issuer and, as a result,
we are subject to reporting obligations and corporate governance practices that, to some extent, are more lenient than those of a U.S.
domestic public company whose shares are listed on Nasdaq.
We report under the Exchange Act as a Foreign Private Issuer (“FPI”).
Thus, we are exempt from certain provisions of the Exchange Act applicable to U.S. domestic public companies, which are more expansive
and require more frequent filings, including (i) the sections of the Exchange Act regulating the solicitation of proxies, consents or
authorizations in respect of a security registered under the Exchange Act and the content of proxy statements, (ii) the rules under Section
16 of the Exchange Act subjecting officers, directors to short-swing profit recovering and principal shareholders to reporting and short-swing
profit recovery and (iii) the rules under the Exchange Act requiring the filing with the SEC of quarterly reports on Form 10-Q containing
full unaudited financial statements and notes thereto and other specified information, and current reports on Form 8-K, which are due
upon the occurrence of specified significant events. In addition, FPIs are not required to file their annual reports on Form 20-F until
four months after the end of each fiscal year, while U.S. domestic issuers that are large accelerated filers like us are required to file
their annual reports on Form 10-K within 60 days after the end of each fiscal year. We are required to report certain material developments
in reports furnished on Form 6-K with the SEC, and we have furnished and intend to continue furnishing on Form 6-K our unaudited quarterly
financial information after the end of each fiscal quarter. FPIs are also exempt from Regulation FD, aimed at preventing issuers from
making selective disclosures of material information. As a result of the above, our shareholders may not have the same protections and/or
access to information afforded to shareholders of companies that are not FPIs.
35
As an FPI whose shares are listed on Nasdaq, we are also permitted
to follow certain home country corporate governance practices instead of certain requirements of the Nasdaq rules. We currently follow
home country practices in Israel in lieu of compliance with the Nasdaq requirements for (i) quorum requirements for an adjourned shareholders
meeting; (2) shareholder approval for adoption and material amendments to share incentive plans and (3) the distribution of annual and
interim reports, which requirements apply to a domestic U.S. issuer. For more information, see “Item 16G. Corporate Governance.”
While we otherwise follow all Nasdaq corporate governance requirements applicable to domestic companies, we may later decide to rely on
exemptions from certain of these requirements as an Israeli FPI. For instance, unlike the requirements of Nasdaq, there are currently
no mandatory corporate governance requirements in Israel that would require us to (i) have a majority of our board of directors be independent,
(ii) establish a nominating/governance committee, or (iii) hold regular executive sessions where only independent directors may be present.
Following our home country governance practices as opposed to the requirements that would otherwise apply to a U.S. company listed on
Nasdaq may provide less protection than is accorded to investors of domestic issuers.
We could lose our status as a “foreign private issuer”
under applicable securities laws and regulations if more than 50% of our outstanding voting securities were to become directly or indirectly
held of record by U.S. holders and any one of the following were true: (i) the majority of our directors or executive officers were U.S.
citizens or residents; (ii) more than 50% of our assets were located in the United States; or (iii) our business were administered principally
in the United States. If we were to lose our status as a “foreign private issuer” in the future, we would no longer be exempt
from the rules described above and, among other things, we would be required to file periodic reports and annual and quarterly financial
statements as if we were a company incorporated in the United States. If this were to happen, we would likely incur significant additional
legal, accounting, and other expenses and would likely have to divert significant management time and resources in order to comply with
U.S. domestic issuer requirements.
Risks Related to Operations in Israel
Political, economic and military instability
in the Middle East or Israel may harm our business.
We are incorporated under Israeli law, and our principal offices
and manufacturing and research and development facilities are located in Israel. In addition, the majority of our key employees, officers
and directors are residents of Israel. Accordingly, political, economic, and security conditions in Israel and the surrounding region
could directly affect our business, and our operations and financial results could be adversely affected in the event of any political
instability, terrorism, armed conflicts, or other hostilities in the Middle East or Israel, including the ongoing uncertainty with Iran,
Hezbollah and Hamas.
Israel continues to face heightened regional security risks, including the aftermath
of the October 7th attacks, ongoing military operations in Gaza, escalating hostilities with Hezbollah along the northern border with
Lebanon, and, most recently, with Iran. While a ceasefire between Israel and Lebanon (with respect to Hezbollah) was announced in November
2024, a ceasefire between Israel and Iran was announced in June 2025 and a ceasefire between Israel and Hamas was announced in October
2025, in February 2026, hostilities between Israel and Iran escalated again. In late February 2026, the United States, together with Israel,
launched a major joint military campaign of air and missile strikes against targets in Iran, which triggered a broad Iranian response
and contributed to significant regional instability, including, in early March 2026, resumed conflicts with Hezbollah and, in late
March 2026, resumed involvement of the Houthi movement through the launch of missile and drone attacks against Israel. The situation remains
highly fluid, and we are unable to predict if, when, or on what terms, this escalation will be resolved. These developments have
resulted in prolonged security alerts, disruptions to civilian and commercial activity, and increased geopolitical volatility. Any further
deterioration in the security situation, whether through expanded conflict, sustained rocket fire, cyberattacks, or regional escalation,
could adversely impact our workforce, facilities, supply chain, customer activity, and overall business continuity. Additionally, prolonged
instability may affect macroeconomic conditions in Israel, including currency volatility, inflationary pressures, supply chain limitations
and changes in government policy, any of which could materially and negatively affect our business, financial condition, and results of
operations.
36
Furthermore, some of our officers and employees are, unless exempt,
obligated to perform annual military reserve duty, depending upon their age and prior position in the army. They may also be subject
to being called to active duty at any time under emergency circumstances. For example, during 2025 and 2024, in connection with the
October 2023 war, approximately 3% of our total workforce was called to perform immediate military service, and additional employees may
be called as armed conflicts require. Such employees may be absent for an extended period of time. Our operations could be disrupted by
the absence, for a significant period, of one or more of these officers or other key employees due to military service, and any disruption
in our operations could harm our business.
Our commercial insurance does not cover losses that may occur as
a result of events associated with the security situation in the Middle East, including the October 2023 war, such as damages to our facilities
resulting in the disruption of our operations. Although the Israeli government currently covers the reinstatement value of direct damages
that are caused by terrorist attacks or acts of war, we cannot be assured that this government coverage will be maintained or will be
adequate in the event we submit a claim. We could be adversely affected by any major hostilities, including acts of terrorism as well
as cyber-attacks or any other hostilities involving or threatening Israel, the interruption or curtailment of trade between Israel and
its trading partners, a significant downturn in the economic or financial condition of Israel, or a significant increase in the rate of
inflation. For example, in September 2024, Moody’s Investors Service (Moody’s) downgraded the Government of Israel’s
foreign-currency and local-currency issuer ratings to BAA1 from A2, which is also the current rating, and in October 2024, S&P global
downgraded Israel long-term ratings to A from A+, which is also the current rating. Other global rating agencies may take similar actions.
Such downgrades might adversely affect the macroeconomic conditions in which we operate and also potentially deter foreign investment
in Israel or Israeli companies, which may, among other things, hinder our ability to raise additional funds, if deemed necessary by our
management and Board of Directors.
Furthermore, some neighboring countries, as well as certain companies,
organizations and movements, continue to participate in a boycott of Israeli firms and others doing business with Israel or with Israeli
companies. In the past several years, and with greater intensity commencing with the October 2023 war, there have been increased
efforts by activists, influenced by actions of international judicial bodies, to cause companies and consumers to boycott Israeli goods,
services, and academic research or restrict business with Israel, which could affect business operations. Similarly, Israeli companies
are limited in conducting business with entities from several countries. Restrictive laws, policies or practices directed towards Israel
or Israeli businesses could have an adverse impact on our operating results, financial condition or the expansion of our business.
Finally, prior to the October 2023 war, the Israeli government
began to pursue changes to Israel’s judicial system and has recently renewed its efforts to effect such changes. In response to
the foregoing developments, certain individuals, organizations, and institutions, both within and outside of Israel, voiced concerns that
such proposed changes, if adopted, may negatively impact the business environment in Israel, including by causing a downgrade to Israel’s
sovereign credit rating and Israel’s international standing. Such proposed changes may also lead to political instability or civil
unrest. If such changes to Israel’s judicial system are pursued by the government and approved by the parliament, this may have
an adverse effect on our business, results of operations, and ability to raise additional funds, if deemed necessary by our management
and Board of Directors.
37
The tax benefits we may receive in connection
with our preferred enterprise program require us to satisfy prescribed conditions and may be terminated or reduced in the future. This
would increase taxes and decrease our net profit.
We have in the past benefited, and currently benefit, from certain
government programs and tax benefits in Israel, including in connection with our preferred enterprise program (see under Item 10.E “Taxation—Israeli
Tax Considerations”). To remain eligible to obtain such tax benefits, we must continue to meet certain conditions. If we fail to
comply with these conditions in the future, the benefits we receive could be cancelled, and we may have to pay certain taxes. We cannot
guarantee that these programs and tax benefits will be continued in the future, at their current levels or at all. If these programs
and tax benefits are ended, our tax expenses and the resulting effective tax rate reflected in our financial statements may increase and
as such our business, financial condition and results of operations could be materially and adversely affected.
We have obtained benefits from the Israeli Innovation
Authority that subject us to ongoing restrictions.
We have in the past received, and in the future may apply for,
royalty-bearing or non-royalty bearing grants from the Israeli Innovation Authority (formerly known as the Office of the Chief Scientist
of the Israeli Ministry of Economy and Industry) (the “IIA”), for research and development programs that meet specified criteria
pursuant to the Law for the Encouragement of Research, Development and Technological Innovation in Industry, 1984 (formerly known as the
Law for Encouragement of Research and Development in Industry, 1984), and the regulations promulgated thereunder (the “Innovation
Law”). The terms of the IIA grants limit our ability to manufacture products outside of Israel or to transfer technologies in or
outside Israel if such products or technologies were developed using know-how developed with or based upon IIA grants. In addition, a
change of control in us and the acquisition of 5% or more of our ordinary shares by a non-Israeli may require notification to the IIA
and the provision of an undertaking to comply with the Innovation Law, some of the principal restrictions and penalties of which are the
transferability limits described above and elsewhere in this annual report.
It may be difficult to enforce a U.S. judgment
against us or our officers and directors and to assert U.S. securities laws claims in Israel.
We are incorporated under the laws of the State of Israel, our
corporate headquarters is located in Israel and several of our current officers and directors reside in Israel. Service of process upon
us, our Israeli subsidiary, our directors and officers and the Israeli experts, if any, named in this annual report, substantially all
of whom reside outside the United States, may be difficult to obtain within the United States. Furthermore, because a majority of our
assets and investments, and substantially all of our directors, officers and such Israeli experts are located outside the United States,
any judgment obtained in the United States against us or any of them may be difficult to collect within the United States and may not
be enforced by an Israeli court.
We have been informed by our legal counsel in Israel that it may
also be difficult to assert U.S. securities law claims in original actions instituted in Israel. Israeli courts may refuse to hear a claim
based on an alleged violation of U.S. securities laws if they determine that Israel is not the most appropriate forum to bring such a
claim. In addition, even if an Israeli court agrees to hear a claim, it may determine that Israeli law and not U.S. law is applicable
to the claim. There is little binding case law in Israel addressing these matters. If U.S. law is found to be applicable, the content
of applicable U.S. law must be proven as a fact, which can be a time-consuming and costly process. Certain matters of procedure
will also be governed by Israeli law.
38
Subject to specified time limitations and legal procedures, under
the rules of private international law currently prevailing in Israel, Israeli courts may enforce a U.S. judgment in a civil matter, including
a judgment based upon the civil liability provisions of the U.S. securities laws as well as a monetary or compensatory judgment in a non-civil
matter, only if the following key conditions are met:
• subject to limited exceptions, the judgment is final and non-appealable;
• the judgment was given by a court competent under the laws of the state of the court and is otherwise enforceable in such state;
• the judgment was rendered by a court competent under the rules of private international law applicable in Israel;
• the laws of the state in which the judgment was given provide for the enforcement of judgments of Israeli courts;
• adequate service of process has been effected and the defendant has had a reasonable opportunity to present his arguments and evidence;
• the judgment is enforceable under the laws of the State of Israel and its enforcement is not contrary to the law, public policy, security, or sovereignty of the State of Israel;
• the judgment was not obtained by fraud and does not conflict with any other valid judgment in the same matter between the same parties; and
• an action between the same parties in the same matter was not pending in any Israeli court at the time the lawsuit was instituted in the U.S. court.
Your rights and responsibilities as a shareholder
will be governed by Israeli law, which may differ in some respects from the rights and responsibilities of shareholders of U.S. companies.
The rights and responsibilities of the holders of our ordinary
shares are governed by our Articles of Association and Israeli law. These rights and responsibilities differ in some respects from the
rights and responsibilities of shareholders in typical U.S.-based corporations. For example, a shareholder of an Israeli company has a
duty to act in good faith toward the company and other shareholders and to refrain from abusing its power in the company, including, among
other things, in voting at the general meeting of shareholders on matters such as amendments to a company’s articles of association,
increases in a company’s authorized share capital, mergers and acquisitions and interested party transactions requiring shareholder
approval. In addition, a shareholder who knows that it possesses the power to determine the outcome of a shareholder vote or to appoint
or prevent the appointment of a director or executive officer in the company has a duty of fairness toward the company. There is limited
case law available to assist us in understanding the implications of these provisions that govern shareholders’ actions. These provisions
may be interpreted to impose additional obligations and liabilities on holders of our ordinary shares that are not typically imposed on
shareholders of U.S. corporations.
39