← Back to RDWR filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
INFORMATION ON THE COMPANY
A. History
and Development of the Company
Corporate History and Details
Radware Ltd. was organized in May 1996 as a corporation under the
laws of the State of Israel and commenced operations in 1997. Our principal executive offices are located at 22 Raoul Wallenberg Street,
Tel Aviv 6971917, Israel and our telephone number is 972-3-766-8666. Our website address is www.radware.com (information contained on
our website is not incorporated herein by reference and shall not constitute part of this annual report).
In addition, the SEC maintains a website that contains reports, proxy and information statements, and other information regarding
issuers that file electronically with the SEC: http://www.sec.gov.
Radware Inc., our wholly owned subsidiary in the United States,
which conducts the sales and marketing of our products and services primarily in the United States and Canada, is our authorized representative
and agent in the United States. The principal offices of Radware Inc. are located at 575 Corporate Dr., Lobby 2, Mahwah, New Jersey 07430
and its telephone number is 201-512-9771.
In September 1999, we conducted the initial public offering of
our ordinary shares that commenced trading on the Nasdaq.
In the past decade, we have made several acquisitions, including,
most recently, (i) in January 2026, we acquired Pynt, Inc., an API security testing company, and (ii) in February 2022, we acquired the
technology and operations of DC Security Ltd. (previously known as SecurityDAM Ltd. (“SecurityDAM”)), a related party who
was a cloud DDoS network operator that supplied us with scrubbing center services used for the provision of our cloud DDoS Protection
Service.
Recent Major Business Developments
For recent major product activities, see Item 4.B “Business
Overview—Our Solutions” under the captions “Recent Solution Offering Activities” and “Recent Partnerships
Activities.”
For a discussion of our capital expenditures and divestitures,
see Item 5.B “Liquidity and Capital Resources – Principal Capital Expenditures and Divestitures.”
B. Business
Overview
Overview
General
We are a provider of application security and delivery solutions
for multi-cloud environments. Our solutions secure the digital experience by providing infrastructure, application, and network protection
and availability services to companies globally. Our solutions are deployed by, among others, enterprises, carriers, and cloud service
providers.
40
Our solutions are offered in two main categories:
• Products – We offer a range of cloud-based security-as-a-service subscriptions, on-premises hardware and software products, and product subscriptions (or a combination of these) to our customers.
• Services – We offer managed services, professional services, technical support and training and certification to our customers and partners.
The sections below provide an overview of our key solutions and services according
to the above go-to-market targets.
Reportable Segments
The Company operates in two reportable segments:
• Radware’s Core Business – This segment consists of our core business operations, including our cloud security-as-a-service products, application and data centers security products and our application availability products.
• The Hawks’ Business – This segment consists of the operations of our two subsidiaries: SkyHawk (“CNP”) Security Ltd. (“SkyHawk Security”), which provides an agentless Cloud-native threat Detection and Response (“CDR”), combined with Cloud Infrastructure Entitlement Management (“CIEM”), Cloud Security Posture Management (“CSPM”) and Autonomous Purple Team for AWS Google Cloud and Azure, and EdgeHawk Security Ltd. (“EdgeHawk”), which is engaged in providing carrier security solutions by transforming routers and network nodes into security platforms. We refer to SkyHawk Security and EdgeHawk collectively as the “Hawks.”
In February 2026, we resolved to sell or cease the operations of Skyhawk Security.
For additional details regarding these two reportable segments,
see Item 5.A – “Operating Results” and Notes 2ad and 15 to our consolidated financial statements included elsewhere
in this annual report.
Our Products
The main categories of the products and
services we offer are as set forth below.
Our cloud-based
subscription offering consists of the following:
o Cloud DDoS Protection Service. Our Cloud DDoS Protection Service provides a full range of enterprise-grade DDoS protection services in the cloud. Based on our DDoS protection technology, it aims to offer organizations wide security coverage, accurate detection and short time to protect from today’s dynamic and evolving DDoS attacks. We offer a multi-vector DDoS attack detection and mitigation service, handling network-layer attacks, server-based attacks and application-layer DDoS attacks. Our Cloud DDoS Protection Service is offered in multiple deployment options to meet an organization’s specific needs:
o Always-On Cloud DDoS Protection Service. This service provides always-on protection where traffic is always routed through Radware’s cloud security scrubbing centers with no on-premise device required for detection and mitigation. This service is recommended for organizations that have applications hosted in the cloud or those that are not able to deploy an on-premise attack mitigation device in their data center.
41
o Always-On Hybrid Cloud DDoS Protection Service. This service integrates with our on-premise DDoS Protection device. The traffic is mitigated in the on-premise device and diverted through Radware’s cloud security scrubbing centers upon a large volumetric DDoS attack that aims to saturate the internet pipe. This service is recommended for organizations that place a high premium on the user experience and wish to avoid even the slightest possible downtime as a result of DDoS attacks.
o On-Demand Cloud DDoS Protection Service. This service protects against internet pipe saturation and is activated when the attack threatens to saturate the organization’s internet pipe. This service is recommended for organizations that are looking for the lowest cost solution and are less sensitive to real-time detection of DDoS attacks.
o On-Demand Cloud Hybrid DDoS Protection Service. The on-premise DefensePro device detects and mitigates all types of DDoS attacks in real-time, while volumetric DDoS attacks are diverted and mitigated in the cloud. This service is recommended for organizations that can deploy an on-premise device in their data centers.
We offer several Add-Ons to our Cloud DDoS
Protection Service:
o Cloud Web DDoS Protection. We offer our cloud customers an additional protection layer dedicated to detecting and mitigating application-layer DDoS attacks. Our Cloud Web DDoS Protection uses advanced L7 behavioral-based detection and mitigation techniques to block Web DDoS Tsunami attacks, offering protection against advanced HTTP/S floods that use randomization techniques to bypass traditional protections.
o Cloud Firewall as a Service. Our Cloud Firewall-as-a-Service (FWaaS) provides a cloud-based network firewall solution that helps offload unwanted traffic before it reaches the organization’s network, thereby improving network efficiency and providing consistent protection for the entire network. With no appliance to manage and IP blocking at scale, the service helps organizations manage their traffic in a more efficient and less human-intensive manner.
o Cloud Network Analytics. Our Cloud Network Analytics Service provides users with detailed, granular insight into network traffic, network services in use and more. The cloud network analytics service allows administrators to eliminate errors when planning network deployments and stay ahead of DDoS threats via early detection of network abuse and intrusion.
o AI SOC Xpert DDoS. Our AI SOC Xpert DDoS add-on delivers agentic AI–powered SOC capabilities that accelerate detection, analysis and mitigation of DDoS attacks. Leveraging real-time behavioral analytics, it automates root-cause analysis—reducing Mean Time to Resolve (MTTR) by up to 20 times —and provides one‑click, context-driven remediation. An intuitive AI assistant offers instant forensic insights and guidance, enabling SOC teams to operate more efficiently and effectively, improving their ability to protect the organization.
42
o Cloud Application Protection Services: Our Web Application and API Protection (WAAP) suite is a one stop shop for organization’s application security needs, providing WAF, API Security, bot management, Layer 7 DDoS (Web DDoS) mitigation, account takeover (ATO) protection and client-side protection. Our Cloud Application Protection Services are offered in three service plans. Each plan is designed to cater to different cybersecurity needs and risk exposure, as well as different levels of managed services:
o Standard Plan: Our Standard plan offers the industry benchmark protection level with several extra features and capabilities. It includes Radware’s Cloud WAF, API protection, zero-day attack protection, Basic Bot Protection, and 1Gbps of network DDoS protection, as well as our Service Level Agreement (SLA).
o Advanced Plan: Advanced plan takes application security to the next level by offering advanced protection capabilities for those that want to ensure they are well protected from more sophisticated and unknown attacks. The plan includes, on top of the Standard plan, Radware’s Advanced WAF with its path access protection engine that protects against more sophisticated unknown and zero-day attacks, AI-based Correlation Engine (Source Blocking), 10Gbps of network DDoS Protection, as well as JS supply chain mapping, monitoring, and attack detection for client-side protection. It also includes Radware’s intelligence feed – the ERT Active Attackers Feed (EAAF), and further support for onboarding and policy reviewing.
o Complete Plan: Radware’s Complete plan provides a security blanket for the customer's entire application environment – from client-side to server-side. This plan includes everything the Advanced plan has to offer, with the addition of Radware’s Bot Manager and its behavior-based multi-layered detection and mitigation, automated API discovery and API security policy generation, real-time API Business Logic Attack Protection, and client-side protection enforcement.
We offer several Add-Ons to our Cloud Application Protection Services:
o Cloud Web DDoS Protection. We offer an additional protection layer dedicated to detecting and mitigating application-layer DDoS attacks. Our Cloud Web DDoS Protection uses advanced L7 behavioral-based detection and mitigation techniques to block Web DDoS Tsunami attacks, offering protection against advanced HTTP/S floods that use randomization techniques to bypass traditional protections.
o CDN. For enterprises that wish to combine website delivery with their web application security, we offer a content delivery network (CDN) solution integrated directly into our Cloud Application Protection portal. Our CDN solution is based on the Amazon CloudFront CDN for a globally distributed footprint, enhanced performance, and DevOps-friendly usability.
o PCI DSS 4 Compliance. In addition to the WAF and API protection against business logic attacks, which are necessary for PCI DSS 4 compliance and included in our Cloud Application Protection service plans, the PCI DSS 4 add-on offers customers extended, specific client-side protection controls as required by PCI DSS 4 Sections 6.4.3 and 11.6.1.
o DNS as a Service (DNSaaS). Our DNSaaS provides comprehensive Domain Name System (DNS) management, which is essential for the seamless functioning of any online application. It's about safeguarding businesses’ digital presence and ensuring end-users a seamless experience.
43
o Load Balancer as a Service. Our Load Balancer as a Service (LBaaS) complements cloud application protection services with improved SLA and scalability while maintaining high availability and protecting all origin sites. It provides Active/Active traffic and user load balancing between origin sites.
o Threat Intelligence Service. Our Threat Intelligence services shed light on why certain IPs are flagged, providing insights and context in real-time. The actionable intelligence allows organization to confidently assess threats, enable informed decisions and proactively defend against threats before they escalate. Key features of the Threat Intelligence Services include:
◾ Actionable Data from Real Cyber Attacks
◾ Research into any suspicious IP address with IP insights and Open Proxys and Malware Data
◾ Reputation alert to ensure Network Security and Integrity by proactively informing of potential cyber-attacks originating from the organization's own network.
◾ Seamless REST API Integration to any environment, existing security workflows and systems
o AI SOC Xpert Application Protection. Our AI SOC Xpert for Application Protection strengthens defenses at the application layer with AI-driven support for both WAF and Bot management. It equips SOC teams to handle application traffic and malicious bot activity with greater visibility, faster investigation and precise remediation guidance. Key capabilities of the AI SOC Xpert for Application Protection include:
◾ AI-driven tuning recommendations to reduce false positives and streamline policy management
◾ Faster onboarding and structured investigation tools
◾ Visual dashboards that highlight incidents, anomalies and attack patterns
◾ Reduce alert fatigue and faster time to resolution across application and bot incidents
o LLM Firewall. Our new LLM Firewall solutions secures generative AI use with real-time AI-based protection at the prompt level. It stops threats before they reach the organization’s origin servers. The solution enforces enterprise-grade security and compliance by detecting risks like prompt injection, data leaks, harmful content, brand safety and usage policies in real time. The solution is model-agnostic, easy to onboard and secures AI use across platforms without disrupting workflows or innovation.
Our hardware and software products consist of
the following key products:
o DefensePro X Attack Mitigation Device. DefensePro® X, our real-time perimeter attack mitigation device, secures organizations against emerging network multivector and DDoS attack campaigns, IoT botnets, application vulnerability exploitation, malware and other types of cyberattacks. DefensePro X behavioral-based technology is designed to prevail over modern sophisticated attack tools and cybercriminals.
44
The DefensePro X lineup is combined with additional subscriptions
for Network and Application protection:
o Network Protection Subscription – Silver – includes ERT Security Update Subscription (SUS), ERT Active Attacker Feed (EAAF) and Location based mitigation (GeoIP) subscriptions.
o Network Protection Subscription – Gold – includes, on top of the Silver subscription, also ERT under attack service.
o Application Protection Subscription – Standard provides basic HTTPS protection and includes Transport Layer Security (TLS) acceleration module.
o Application Protection Subscription – Advance - provides advanced behavioral protection for encrypted flood attacks, TLS inspection, DNS protection, Advance Application-aware protection, and threat intelligence under attack.
o Alteon® Application Delivery Controller (ADC). Alteon is our application delivery and security solution that manages application traffic across cloud and data center locations, optimizing availability and performance. It provides advanced, end-to-end local and global load balancing capabilities for web, cloud and mobile-based applications. Alteon integrates multiple application protection services to provide protection against an array of cyber threats. Alteon’s analytics also provides insightful visibility so that IT managers can manage and guarantee application service level agreement (SLA) and stay ahead of cyberattacks.
We offer Alteon ADC in three different packages (available on each
of its models and throughput levels) to address different deployment scenarios and needs:
• Alteon Deliver Package. For applications that require high performance ADCs with advanced layer 4-7 ADC functionality.
• Alteon Perform Package. For deployments requiring performance optimization, advanced application performance monitoring, global server load balancing, link load balancing, automated/optimized ADC service operation, Alteon Advanced Analytics and Geolocation database updates. Provided on top of Alteon Deliver Package.
• Alteon Secure Package. For applications that require our most advanced protections, including an embedded WAF module, authentication gateway, bot management, and threat intelligence feeds (WAF SUS, ERT Active Attackers Feed). Provided on top of Alteon Perform Package.
We offer Alteon with a Global Elastic Licensing (GEL) solution,
a purchasing and deployment subscription that enables a high level of flexibility for ADC services across datacenters, private and public
clouds. GEL enables dynamic ADC capacity allocation and the ability to move that capacity across environments, without having to invest
separately in a dedicated ADC infrastructure for each and every location where an organization’s applications are deployed (e.g.,
on-premises, public cloud, etc.). This application delivery licensing model helps to eliminate planning risks in the purchase and deployment
of ADC services, enabling continuous investment protection of the ADC infrastructure throughout its lifecycle duration.
o Radware Kubernetes WAAP. Radware Kubernetes WAAP is a Web Application Firewall and API security solution for continuous integration and continuous delivery (CI/CD) environments orchestrated by Kubernetes. Our Kubernetes WAAP integrates with common software provisioning, testing and visibility tools in the CI/CD pipeline offering both IT security and DevOps personnel detailed insight down to the pod and container levels, and enables organizations to implement application and data security in on-premise and cloud-based implementations.
45
o Cyber Controller. Our Cyber Controller is a unified solution for management, configuration and attack lifecycle. The Cyber Controller provides enhanced security, increased visibility and an improved user experience via multiple security operation dashboards for a unified view into attack lifecycle and mitigation analysis for both inline and out-of-path DDoS deployments. Cyber Controller provides network analytics with comprehensive visibility of traffic statistics during peacetime and attack, and simplified management and configuration with unified visibility and control.
Cyber Controller supports several licenses according to each customer-managed
environment and customer needs.
o Cyber Controller Standard: Provides the network management tool and network monitoring tool for the Radware family of cybersecurity and application delivery solutions. It provides our customers immediate visibility to health, real-time status, performance and security of our products from one central, unified console. An analytics module provides an intuitive, customizable Graphical User Interface with granular forensic insights into application performance, denial-of-service and web application attacks.
o Cyber Controller X: In addition to the “Standard” license features, provides the ability to manage the DefensePro X product line using the new Cyber Controller X stream.
o Cyber Controller Plus: An add-on on top of either the “Standard” or “X” licenses, enabling orchestration, automation and out-of-path capabilities for attack life-cycle.
o Cyber Controller MSSP Portal: the MSSP Portal is designed to help service providers to deliver cyber security services while simultaneously reducing Total Cost of Ownership (TCO) and MTTR, and surpassing margin revenue targets. It provides end-customers with comprehensive insights into the status of their protected network, offering visibility into both peacetime and attack traffic. Additionally, our portal allows service providers to offer invaluable services such as self-operating capabilities to their customers, particularly for those with expertise in security operations. Leveraging the power of multitenancy, our MSSP portal enables service providers to efficiently manage multiple customers, ensuring seamless operations and optimal resource utilization.
46
Customer Services
We offer managed services, professional services, technical support
and training and certification to our customers and partners. Our key customer services consist of the following:
o Certainty Support Program. We offer technical support for all our products through our Certainty Support Program. Certainty support levels include:
o Basic. This level provides business day access, including weekends from 9 a.m. to 5 p.m. (local time) to technical support center services, and technical documentation, either via the Web, e-mail or direct phone support during working days. New software releases are available for units covered under the certainty support program.
o Standard. This level increases access to the technical support center 24/7/365 and adds next business day replacement of failed hardware and waives customer shipping costs.
o Advanced. This level increases the certainty support level standard to four hours’ replacement of failed hardware advanced replacement.
o Professional Services. Our professional services group is staffed by a global team of experts possessing extensive knowledge and experience in security and application delivery both in data centers and the cloud. The group offers a full range of services to design, implement, automate, and optimize our customer solutions. We offer the following key professional services:
o Design and Planning. This service plans and designs applications for future growth with Radware engineers. The service starts with a review of business goals, network optimization assessment and an overview of application architecture and security requirements to help create a comprehensive deployment plan that is tailored to organizational IT requirements.
o Application and Security Optimization Services. This service analyzes and reviews the current implementation and design and provides recommendations to help optimize the system and achieve business goals.
o Resident Engineer. Our Resident Engineer service is a proactive on-site engineer who performs operations, design and automation activities. From initial deployment to ongoing management and day-to-day operation, our Resident Engineer service decreases the time demands on our customers’ staff, allowing them to focus on their core business.
o Technical Account Manager. Our technical account manager is a proactive consultant that implements best practices, provides guidance and optimizes networking and application resources.
o ERT Service. Our ERT is a group of security experts available 24x7 for proactive security support services for customers facing a broad array of application and network-layer attacks, such as denial-of-service (DoS) attacks, malware outbreaks and application exploits. Powered by Radware Threat Research Center, ERT engineers combat common and emerging attacks on a daily basis, providing customers with industry-leading expertise, best practices and a deep knowledge of threats, attack tools, intelligence and mitigation technologies. These services include:
o ERT Managed Security Service. Our ERT offers a fully managed application- and network-security service. The service covers a broad range of attack types from different forms of DDoS to a variety of application attacks against our customers’ servers or data centers. It includes immediate response, onboarding, consulting, remote management, and reporting.
o ERT Under-Attack Service. The ERT under-attack service offers 24x7 access to a security expert within 10 minutes. The ERT engineer will take the lead, fight off attacks and provide postmortem analysis of security events. The ERT under-attack service lets organizations know there is someone to rely on, guaranteeing support throughout the attack life cycle from the moment it begins. The ERT experts are available 24x7 and assist large enterprises worldwide with complex multi-vector attacks against their networks, data centers and application services.
47
Recent Solution Offering
Activities
During 2025, our key solution offering activities consisted of
the following:
• We have announced a new solution, LLM Firewall, to secure applications that deploy generative AI models. The LLM Firewall is an add-on to all tiers of our Cloud Application Protection Services, and the first phase of our broader agentic AI protection solution for enterprises. LLM Firewall is designed to help address the growing security concerns around integrated LLM modules in applications and to protect the LLM prompt and response against attacks and abuse. It is designed to secure generative AI use with real-time, AI-based protection at the prompt level, stopping threats before they reach the LLM model. Fully model-agnostic and easy to integrate, it is designed to secure AI use across platforms without disrupting workflows or innovation.
• We have expanded our Threat Intelligence Services with the launch of Telegram Claimed Attacks Report and TLS Fingerprint Reputation Feed. The subscription-based cloud services work in real-time, designed to provide global threat intelligence and visibility, thereby helping security teams to anticipate and neutralize emerging cyber threats before they materialize. In the face of escalating cyberthreats, these reports offer additional preemptive protection to strengthen cyber defenses and improve security posture with minimal operational effort.
• We have expanded our AI SOC Xpert capabilities to cover new use cases to drive efficiencies. AI SOC Xpert now delivers root cause analysis, timeline, and incident context within minutes across both DDoS and bot attacks, providing analysts with the clarity they need to understand what happened and respond with speed and confidence, automatically and at scale. Whereas analysts previously relied on manual correlation or switching between tools, they can now access new dashboards for Application Protection and On-Premises DDoS Protection, along with significant AI enhancements to Cloud DDoS Protection. This unified view of what happened, why it matters, and how to respond reduces investigation fatigue and helps teams act faster under pressure thus reducing MTTR.
• We have launched new cloud security service center in Tel Aviv, Israel (the new Tel Aviv facility marks our second cloud security center in Israel), in Bogota, Colombia, Chennai and Mumbai, India, Nairobi, Kenya, and Lima, Peru. These new service centers are part of our global cloud security network, comprising more than 50 centers worldwide with a total attack mitigation capacity of over 15Tbps.
• We have partnered with SUSE SA, a global provider of open-source enterprise solutions, to offer service providers and enterprises a full stack, cloud-native Kubernetes security solution designed to achieve low latency, high availability, and regulatory compliant outcomes. The collaboration brings together our Kubernetes Web Application and API Protection (KWAAP) with SUSE's Rancher Prime and Edge platforms. The combined solution is designed to create a modular, open, and certified solution for securing distributed workloads at scale—from core data centers to the edge.
48
Our Competitive Strengths
Our solutions incorporate proprietary and innovative cybersecurity
and application delivery technologies that help our customers to secure the digital experience for users of business-critical applications.
We believe our competitive strengths are based on several elements, including the following:
• Innovation, Proprietary Technologies, and Thought Leadership. We are offering innovative solutions in our domain. We were one of the first companies to offer hybrid attack mitigation solutions; behavioral DDoS attacks detection with automated real-time signature creation for attack mitigation; device fingerprinting technology implementation for Bot-based attacks detection; auto-policy generation for our WAF solution; protection against encrypted attacks without opening the sessions for DDoS protection; AI to detect attacks targeting workloads in public clouds; and Generative AI to help SOC teams act faster under pressure thus reducing MTTR significantly. We believe this has given us significant expertise, know-how, and leadership in the market for cyber-attack mitigation solutions, and we take part in many technology communities, standard organizations, and open source projects. At the same time, we continue to invest in research and development of cybersecurity and application delivery technologies in order to introduce new and innovative solutions, which are supported and protected by multiple patents and proprietary rights.
• Automation. We are offering automated attack detection and mitigation solutions that reduce the total cost of ownership of cybersecurity solutions, including behavioral analysis technology to detect zero-day DDoS attacks; automated real-time signature creation for DDoS attacks mitigation; intent-based behavioral analysis and machine learning (or “ML”) models to detect automated Bot attacks; and machine learning (positive security model) to detect zero-day web application attacks.
• Wide attacks coverage. Our solutions offer a wide coverage against attacks, including mitigation of all five generations of Bot attacks; negative and positive security models to defend against known (OWASP top-10) and zero-day web application attacks (standard solutions typically cover OWASP top-10 attacks only); and advanced DDoS attacks protection such as DNS flood attacks, burst floods, SSL flood attacks, IoT botnets and encrypted Web DDoS attacks.
• Industry Awards. We gained multiple industry awards during 2025, including the following:
• Quadrant Knowledge Solutions – 2025 DDoS Mitigation SPARK Matrix™ – Leader
• Quadrant Knowledge Solutions – 2025 WAF SPARK Matrix™– Leader
• Quadrant Knowledge Solutions – 2025 Bot Management SPARK Matrix™ – Leader
• KuppingerCole - Leadership Compass Report for Web Application and API Protection 2025 – Overall and Innovation Leader
• Forrester - The Forrester Wave™: Web Application Firewall Solutions, Q1 2025 – Strong Performer
• Gartner Peer Insights - Voice of the Customer for Cloud Web Application and API Protection Report 2025 – Strong Performer
We are not responsible for the determinations of any of these awards
or the entities or publications that award them.
49
Our Growth Strategy
Our growth strategy is based on several key elements:
• Focus on cloud and application security. We aim to offer superior cloud services and application security solutions for our customers, and plan to continue to innovate and provide advanced security capabilities helping enterprises and businesses to keep up with emerging cyber threats and growing compliance and regulation requirements. We also offer managed services for our customers who lack security expertise in network and application security domains.
• Increase our market footprint. We believe that a significant market opportunity exists to sell our solutions with the complementary products and services provided by other organizations with whom we wish to collaborate. To that end, we have already established strategic relationships with various third parties, including leading global-class partners, such as Cisco and Check Point, which provide critical access to certain large customers allowing us to sell our solutions. In addition, we intend to further increase our market footprint through collaboration with leading partners.
• Expand our footprint in the medium sized enterprise market. The needs of the mid-market enterprises regarding the management of cybersecurity risks are substantially similar to the needs of the large enterprise market, but their capacity and access to skilled talent are more limited. We believe that our fully managed cloud security services can be a great fit for this market, and we intend to further expand our market footprint in this segment.
• Pursue acquisitions and investments. In order to achieve our business objectives, we may evaluate and pursue the acquisition of, or significant investments in, other complementary companies, technologies, products, and/or businesses that enable us to enhance and increase our technological capabilities and expand our product and service offerings.
Sales and Marketing
Sales. We market
and sell our products and services primarily through indirect sales channels that consist of distributors and resellers located in North,
Central and South America, Europe, Africa, Asia, and Australia. In addition, we generate direct sales to selected customers mainly in
the United States. Our direct sales channels are supported by our sales and marketing managers who are also responsible for recruiting
potential distributors and resellers and for initiating and managing marketing projects in their assigned regions. The sales managers
are supported by our internal sales support staff that help generate and qualify leads for the sales managers. We have subsidiaries and
representative offices and branches in multiple countries to cover the above mentioned regions (see Item 4.C “Organizational Structure”),
to promote and market our products and services and provide customer support in their respective regions.
Marketing. Our marketing
strategy is to enhance brand recognition and maintain our reputation as a provider of technologically advanced, quality cybersecurity
and application delivery solutions to help drive demand for our products and services. We seek to build upon our marketing and branding
efforts globally to achieve greater worldwide sales and leverage sophisticated digital platforms and activity to scale our presence globally.
Our marketing initiatives are principally directed at developing brand awareness, optimizing our digital presence, searchability and awareness,
generating qualified leads and providing sales and marketing tools to our distributors/resellers to promote sales. We participate in major
trade shows and virtual events, regionally based events/seminars and offer support to our distributors and resellers who participate in
these events. We also participate in our partners’ events, such as Cisco Live and Checkpoint Experience, to promote our solutions
within their audiences. Additionally, we focus on our customer base to deliver an integrated Customer 360 experience including regular
communications, facilitating support and training needs, maximizing customer lifetime value and developing customer advocacy. We also
invest in online and search engine advertising campaigns, public relations, and regionalized field marketing campaigns. In addition to
our independent marketing efforts, we invest in joint marketing efforts with our distributors, OEMs, VARs, GSIs, and other companies that
have formed strategic alliances with us.
50
Customers and End-Users
With the exception of our limited direct sales to selected customers,
we sell our products and services through distributors or resellers who then sell our products and services to end-users.
We have a globally diversified end-user base, consisting of corporate
enterprises, including banks, insurance companies, manufacturing, retail companies, media companies, government agencies and utilities,
and service providers, such as telecommunication carriers, internet service providers, cloud service providers, and application service
providers. Customers in these different vertical markets deploy Radware products for availability, performance and security of their applications.
In 2025, approximately 41% of our revenues were generated from
sales in North, Central and South America (principally in the United States), 37% were in Europe, the Middle East and Africa (EMEA) and
22% in Asia-Pacific, compared to 43%, 34% and 23%, respectively, in 2024, and 40%, 37% and 23%, respectively, in 2023. Other than the
United States, which accounted for 31% of our total revenues in 2025, no other single country accounted for more than 10% of our revenues
for 2025, 2024, and 2023.
In 2025, approximately 63% of our revenues derived from product
sales, and 37% derived from service sales, compared to 57% and 43%, respectively, in 2024 and 56% and 44%, respectively, in 2023.
In 2025, approximately 77% of our revenues derived from the enterprise
market and 23% derived from the carrier market, compared to approximately 79% and 21%, respectively, in 2024, and 77% and 23%, respectively,
in 2023.
As of December 31, 2025, 2024, and 2023, no single customer accounted
for more than 10% of our revenues.
For additional details regarding the breakdown of our revenues
by geographical distribution and by activity, see Item 5.A – “Operating Results.”
Seasonality
Our quarterly operating results have been, and are likely to continue
to be, influenced by seasonal fluctuations in our sales and by seasonal purchasing patterns of some of our customers. Our operating results
in the fourth quarter tend to be higher than other quarters as some of our customers tend to make greater capital and operational expenditures
as well as expenditures relating to service renewals towards the end of their own fiscal years, thereby increasing orders for our products,
support and subscription services in the fourth quarter.
51
Customer Support Services
Our technical support team, which consisted of 409 employees worldwide
as of December 31, 2025, supports our sales force during the sales process, assists our customers, resellers and distributors with the
initial installation, set-up and ongoing support of our products, and trains them on how to best use our solutions. The technical support
team also assists with service onboarding processes and provides training to end-users of our services. In addition, our technical team
trains and certifies our distributors and resellers to provide limited technical support in each of the geographical areas in which our
products are sold and is directly responsible for remote support. Our Certainty Support Program offerings allow customers to automatically
obtain new software versions of their products and obtain optimized performance by purchasing any of the following optional offerings:
extended warranty, software updates, 24x7 help-desk (directly to our customers and through our distributors), on-site support and unit
replacement. Some of our on-site services are provided by third-party contractors.
Research and Development
We invest in research and development to expand and enhance the
features of our existing solutions, to develop new solutions and features and to improve our existing technologies and features. We believe
that our future success is dependent upon our ability to maintain our technological expertise, enhance our existing solutions and introduce,
on a timely basis, new commercially viable solutions that will address the needs of our customers. Accordingly, we intend to continue
devoting a significant portion of our personnel and financial resources to research and development. In order to identify market needs
and to define appropriate product specifications, as part of the product development process we seek to maintain close relationships with
current and potential distributors, customers and vendors in related industry sectors.
As of December 31, 2025, our research and development staff consisted
of 406 employees and 68 subcontractors. Research and development activities take place mainly at our facilities in Israel; Bangalore,
India; Vancouver, Canada; and North Carolina, United States. We employ established procedures for the required management, development
and quality assurance of our new product developments. Our research and development organization is divided into Application Security,
Infrastructure Security, Application Delivery, Management and Control, Cloud Services, and Chief Technology Officer groups. Within
those groups the organization is divided according to our existing product solutions. Each product group is headed by a group leader
and includes team leaders and engineers. Each group has a dedicated quality assurance team. In addition, we have an infrastructure
department responsible for the development of our platforms that are the basis for all products, serving all product groups, which consist
of a senior group leader, group leaders, team leaders, and engineers. The heads of all research and development divisions report to either
the Chief Operating Officer or the Chief Technology Officer.
See also below under “Government Regulations – Israeli
Innovation Authority.”
Manufacturing and Suppliers
Our quality assurance testing, final integration, packaging, and
shipping operations as well as part of our final assembly activities are primarily performed at our facility in Jerusalem, Israel. All
our products are Underwriters Laboratories (UL), conformité européenne (CE), Federal Communications Commission (FCC) and
ISO 9001:2008 compliant and some of them have also achieved industry certifications.
We rely to a large extent on third-party manufacturing vendors
to provide our finished products. In this respect, these vendors primarily provide us with design and manufacturing assembly services
in order to deliver the finished goods while we perform the final integration of the products. All components and subassemblies included
in our products are supplied to the manufacturing vendors by several suppliers and subcontractors. Each of the manufacturing vendors monitors
each stage of the components production process, including the selection of components and subassembly suppliers. Thereafter, each of
the manufacturing vendors makes the final assembly in their own facility. Our primary manufacturing vendors are ISO 9001 certified, indicating
that each of their manufacturing processes adheres to established quality standards.
52
We primarily rely on two ODMs to manufacture and to supply our
hardware platforms. In 2025, approximately 50% of our direct product costs were from one of these vendors and 31% were from the other
vendor. Additionally, we rely on four other vendors, which, together with the two ODMs noted above, made up 95% of our direct product
costs in 2025.
We conduct a business continuity plan (BCP) with all our vendors to ensure an immediate
recovery in case of crisis that might jeopardize the supply of our products and services. For example, in light of the heightened regional
security risks affecting Israel, including the aftermath of the October 7 attacks, ongoing military operations in Gaza, renewed hostilities
along the northern border with Lebanon involving Hezbollah, and escalating tensions and periodic direct confrontations between Israel
and Iran, we have implemented contingency measures designed to mitigate potential disruptions to our operations and supply chain. These
measures include maintaining alternative logistics global routes, coordinating closely with our ODM vendors and global partners, and ensuring
operational redundancy across multiple locations to support uninterrupted service to our customers worldwide.
In this respect, we have been certified during 2021 for ISO 22301
(Business Continuity Management System). Furthermore, in order to minimize potential delays in product supplies by certain of our ODMs
whose lead time had been significantly extended due to the worldwide chipset shortage, we had paid expedite fees to several components
manufacturers. However, if we are unable to continue to acquire those platforms or components from these platform manufacturers and vendors
on acceptable terms, or should any of these suppliers cease to supply us, on a timely basis, with such platforms or components for any
reason, we may not be able to identify and integrate an alternative source of supply in a timely fashion or at the same costs. Any transition
to one or more alternate suppliers would likely result in delays, operational problems, and increased costs, and may limit our ability
to deliver our products to our customers on time for such transition period, although we believe we have levels of inventory that will
assist us to transition to alternate suppliers smoothly.
Proprietary Rights
We rely on a combination of patent, trademark and trade secret
laws, as well as confidentiality agreements and other contractual arrangements with our employees, distributors and others to protect
our technology.
We hold various patents in, and have pending patent and provisional
patent applications, in the United States and other jurisdictions to protect various aspects of our technology. These applications may
not result in any patent being issued, and, even if issued, the patents may not provide adequate protection against competitive technology
and may not be held valid and enforceable if challenged. In addition, other parties may assert rights as inventors of the underlying
technologies, which could limit our ability to fully exploit the rights conferred by any patent that we receive. For the risks and uncertainties
associated with protecting our technology, see in Item 3.D “Risk Factors" under "Our business and operating results could suffer
if third parties infringe upon our proprietary technology" and "Our products may infringe on the intellectual property rights of others."
53
Competition
The cybersecurity and application delivery market is highly fragmented
and competitive, and we expect competition to intensify in the future.
Our principal competitors are:
• DDoS Mitigation: Akamai Technologies, Inc. (“Akamai”), Imperva Inc. (“Imperva”), Netscout Systems, Inc. and Cloudflare, Inc.
• Web Application Firewalls and Bot Management: Akamai, Imperva, Cloudflare, Inc., F5 Networks, Inc. (“F5”), and AWS.
• Application Delivery: F5, A10 Networks, Inc., and Citrix Systems, Inc.
We expect to continue to face additional competition as new
participants enter the market or extend their portfolios into related technologies. Larger companies with substantial resources, brand
recognition and sales channels may also form consolidation and alliances with or acquire competing providers of application delivery or
application and network security solutions and emerge as significant competitors. We also expect competition to intensify in the future
as a result of the integration of AI technologies into the markets in which we compete, whether by existing or new market entrants.
We continue seeing new types of competitors from within the
public cloud providers – as more companies rely on these environments to host their services and applications, these vendors start
providing cybersecurity solutions that are typically relatively basic and customized for their own environment. As we see more and
more companies relying on more than one public cloud vendor, we expect to see additional competitors and rapid evolution of solutions
and offerings.
An increase in competition may lower prices and reduce demand
and margins as well as increase costs associated with sales and marketing to maintain or increase market share; which, in turn, may impair
our ability to increase profitability. Furthermore, the dynamic market environment poses a challenge in predicting market trends and expected
growth. We believe that our products and services have several competitive advantages in performance and accuracy and that our future
success will depend primarily on our continued ability to provide more technologically advanced and cost-effective application delivery
and cybersecurity solutions, and more responsive customer service and support, than our competitors. However, we cannot assure you that
all products and services we offer in our portfolio will compete successfully with similar competitor solutions. See also above under
“Business Overview.”
Government Regulations
Data Privacy and Data Protection
Our activities in the cybersecurity market require that we comply
with laws and regulations in the area of data privacy and data protection governing the collection, use, retention, sharing and security
of personal data. Virtually every jurisdiction in which we operate has established its own legal framework relating to privacy, data protection,
and information security matters with which we and/or our customers must comply. Laws and regulations in these jurisdictions apply broadly
to the collection, use, storage, retention, disclosure, security, transfer, and other processing of data that identifies or may be used
to identify or locate an individual. Some countries and regions have passed legislation that imposes significant obligations in connection
with privacy, data protection, and information security.
54
Europe and UK
In the EEA, we are subject to the GDPR and in the United Kingdom
we are subject to UK DP Laws, in each case in relation to our collection, control, processing, sharing, disclosure and other use of data
relating to an identifiable living individual (personal data). The GDPR, and national implementing legislation in EEA member states and
the United Kingdom, impose a strict data protection compliance regime, including restrictions on cross-border data transfers.
The DORA, which came into effect in the European Union in January
2025, requires additional security, resiliency, and governance controls for financial institutions and their third-party service providers.
These controls require service providers to perform extensive security testing, security incident reporting, and detailed reviews of sub-processors
used to deliver their service. In addition to the cost of maintaining the DORA control requirements, the DORA regulations include a schedule
of fees and fines for non-compliance. The EU has also enacted legislation that would regulate non-personal data and establish new cybersecurity
standards, and other countries, including the U.K., may similarly do so in the future. For example, the EU’s Digital Services Act
imposes certain content moderation, notice and transparency obligations on digital platforms and intermediaries and certain data. Additionally,
the EU’s Network and Information Security Directive II, adopted in 2023, regulates resilience and incident response capabilities
of entities operating in a number of sectors, including the digital infrastructure sector and provides for EU member states to have issued
implementing legislation by October 2024. The EU has also enacted the CRA which, among other things, sets cybersecurity standards and
incident reporting requirements for hardware and software products in the EU market.
United States
In the United States, there are numerous federal, state
and local data privacy and security laws, rules and regulations governing the collection, sharing, use, retention, disclosure, security,
transfer, storage and other processing of personal information, including federal and state data privacy and security laws, data breach
notification laws and data disposal laws. For example, at the federal level, we are (or may become) subject to, among other laws and regulations,
the rules and regulations promulgated under the authority of the Federal Trade Commission (“FTC”) (which has the authority
to regulate and enforce against unfair or deceptive acts or practices in or affecting commerce, including acts and practices with respect
to data privacy and security), as well as the Electronic Communication Privacy Act, the Computer Fraud and Abuse Act, the Health Insurance
Portability and Accountability Act (“HIPAA”), the FTC’s Health Breach Notification Rule and the Gramm Leach Bliley Act
(and its implementing regulations). The U.S. Congress also has considered, is currently considering, and may in the future consider, various
proposals for comprehensive federal data privacy and security legislation, to which we may become subject if passed. Requirements for
compliance under HIPAA are also subject to change, as the U.S. Department of Health and Human Services Office of Civil Rights issued a
proposed rule that would amend certain security compliance requirements for covered entities and business associates. Further, the
U.S. Department of Justice issued a final rule entitled, “Access to U.S. Sensitive Personal Data and Government-Related Data by
Countries of Concern or Covered Persons,” codified at 28 CFR part 202 (“Bulk Transfer Rule”). The Bulk Transfer Rule
prohibits and restricts bulk transfers of sensitive personal data (including genetic and health data) to countries of concern, such as
China, Russia, and Iran to prevent access by foreign adversaries. It restricts our ability to engage in certain cross-border transactions
involving genomic or biological samples and related data, which may increase compliance costs, lead to increased regulatory scrutiny or
liability, and may require additional contractual negotiations, which may adversely impact our business, financial condition, and operating
results.
55
At the state level, we are subject to laws and regulations
relating to cybersecurity and data privacy, such as the CCPA. The CCPA broadly defines personal information and gives California residents
expanded privacy rights and protections, such as affording them the right to access and request deletion of their information and to opt
out of certain sharing and sales of personal information. The CCPA requires companies to implement reasonable security procedures and
provides for severe civil penalties and statutory damages for violations and a private right of action for certain data breaches that
result in the loss of unencrypted personal information. This private right of action increases the likelihood of, and risks associated
with, data breach litigation. In addition, some of these laws (including the CCPA), along with other standalone health privacy laws, subject
health-related information to additional safeguards and disclosures and some specifically regulate consumer health data, such as the Washington
My Health My Data Act, Nevada’s Consumer Health Data Privacy Law, and Connecticut’s amendments to its privacy law to address
health data. Numerous other states have also enacted, or are in the process of enacting or considering, comprehensive state-level data
privacy and security laws and information-specific, rules and regulations that share similarities with the CCPA and may be applicable
to our operations. Moreover, laws in all 50 U.S. states require businesses to provide notice under certain circumstances to consumers
whose personal information has been subject to unauthorized access or acquisition as a result of a data breach. Notifications or other
public disclosure or dissemination of information related to any actual or perceived security incident could impact our reputation, harm
customer confidence, hurt our expansion into new markets or cause us to lose existing customers. Additional possible consequences for
non-compliance with these various state laws include enforcement actions in response to rules and regulations promulgated under the authority
of federal agencies, state attorneys general and legislatures and consumer protection agencies.
AI Laws
In addition, our use of AI Technologies is facing increasing regulatory
scrutiny (see the risk factor in Item 3.D. above titled “We face risks related to the rapidly evolving regulatory framework for
AI Technologies.”).
Environmental and Security
Management Regulations
Our activities in Europe require that we comply with European Union
Directives with respect to product quality assurance standards and environmental standards. The Restriction of Hazardous Substances (RoHS)
and RoHS II Directives require products sold in Europe to meet certain design specifications, which exclude the use of hazardous substances. Directive
2002/96/EC on Waste Electrical and Electronic Equipment (known as the “WEEE” Directive) requires producers of electrical and
electronic equipment to register in different European countries and to provide collection and recycling facilities for used products. We
believe we are currently in compliance with the RoHS and WEEE regulations, ISO 14001 standards (regarding Environmental Management Systems),
ISO/IEC 27001:2013 and ISO 27032: 2012 standards (both in regard to Information Security Management System), ISO 28000 (Supply Chain Security
management) and OHSAS 18001:2007 (Occupational Health and Safety Management).
Israeli Innovation Authority
From time to time, eligible participants may receive grants under
programs of the IIA. This governmental support is conditioned upon the participant’s ability to comply with certain applicable requirements
and conditions specified in the IIA’s programs and the Innovation Law.
Under the Innovation Law, research and development programs that
meet specified criteria and are approved by the Research Committee of the IIA are eligible for grants usually of up to 55% of certain
approved expenditures of such programs, as determined by said committee.
56
The Innovation Law provides that know-how developed under an approved
research and development program or rights associated with such know-how (1) may not be transferred to third parties in Israel without
the approval of the IIA (such approval is not required for the sale or export of any products resulting from such research or development)
and (2) may not be transferred to any third parties outside Israel, except in certain special circumstances and subject to the IIA’s
prior approval, which approval, if any, may generally be obtained, subject to payment of a transfer fee pursuant to which the grant recipient
pays to the IIA a portion of the sale price paid in consideration for such IIA-funded know-how; or a portion of the consideration paid
in respect of licensing the IIA-funded know-how, as the case may be (according to certain formulas, which may result in repayment of up
to 600% of the grant amounts plus interest). Under certain circumstances, such as in the event that the grant recipient receives know-how
from a third party in exchange for its IIA-funded know-how, such transfer fee may not apply.
The Innovation Law imposes reporting requirements with respect
to certain changes in the ownership of a grant recipient. The law requires the grant recipient and its controlling shareholders and foreign
interested parties to notify the IIA of any change in control of the recipient or a change in the holdings of the means of control of
the recipient and requires a non-Israel interested party to undertake to the IIA to comply with the Innovation Law. In addition,
the rules of the IIA may require additional information or representations in respect of certain of such events. For this purpose, “control”
is defined as the ability to direct the activities of a company other than any ability arising solely from serving as an officer or director
of the company. A person is presumed to have control if such person holds 50% or more of the means of control of a company. “Means
of control” refers to voting rights or the right to appoint directors or the chief executive officer. An “interested party”
of a company includes a holder of 5% or more of its outstanding share capital or voting rights, its chief executive officer and directors,
someone who has the right to appoint its chief executive officer or at least one director, and a company with respect to which any of
the foregoing interested parties owns 25% or more of the outstanding share capital or voting rights or has the right to appoint 25% or
more of the directors. Accordingly, any non-Israeli who acquires 5% or more of our ordinary shares will be required to notify us that
it has become an interested party and needs to sign an undertaking to comply with the Innovation Law.
The Israeli authorities have indicated in the past that the government
may further reduce or abolish the IIA grants in the future. Even if these grants are maintained, we cannot presently predict what
would be the amounts of future grants, if any, that we might receive.
In 2025, 2024, and 2023, we were qualified to participate in projects
funded by the IIA to develop generic technology relevant to the development of our products. We were eligible to receive grants constituting
between 30% and 55% of certain research and development expenses relating to these projects. The grants under these projects are not required
to be repaid by way of royalties.
In addition, one of our Israeli subsidiaries received royalty-bearing
grants from the IIA for an approved research and development project. The grants under this project, which amounted to $0.4 million for
the year ended December 31, 2025, are required to be repaid based on revenues from the sale of products incorporating or based upon know-how
developed, in whole or in part with the grants.
Research and development grants deducted from research and development
expenses, net amounted to $0.3 million, $0.04 million, and $0.4 million for the years ended December 31, 2025, 2024, and 2023, respectively.
Environmental, Social and Governance Matters
At Radware, we aim to help customers protect
their critical applications and secure their digital experiences. As we pursue this goal, we recognize our responsibility to promote socially
and environmentally responsible economic growth through, and in the best interest of our business practices. In order to promote this
corporate responsibility and sustainability approach, we have implemented, and will continue to implement, various ESG principles and
activities into our daily business practices, including, but not limited to, those summarized below.
57
Our most recent ESG Report is available
at www.radware.com/corporategovernance (information contained on our website, including in our ESG report, is not incorporated herein
by reference and shall not constitute part of this annual report).
Environmental
We aim to build a more sustainable world through the products,
services, and solutions we offer and the way we operate. This means, among other things, that we aim to operate our business in a manner
that meets or exceeds all environmental laws and compliance guidelines and strive to improve our environmental performance across our
entire supply chain.
While we continue to develop a program that recognizes our environmental
impact, we have already implemented various activities to measure and foster our environmental focus, including the following highlights:
• We have implemented key performance indicators (KPIs), which set quantitative reduction goals for the use of water, power and paper;
• We work with our suppliers to maintain compliance with various environmental laws and guidelines, such as RoHS and WEEE in the EU, and adopted our Conflict Minerals Policy available at www.radware.com/corporategovernance/conflictminerals (information contained on our website, including in our Conflict Minerals Policy, is not incorporated herein by reference and shall not constitute part of this annual report), which outlines our practices and procedures with respect to responsible sourcing of minerals from conflict-affected and high-risk areas; and
• Our corporate headquarters in Tel Aviv, Israel, as well as our training rooms in Tel Aviv are designed in the “TED” style to serve as multifunctional work spaces while the operations room utilizes NVX video technology in order to minimize the amount of copper wiring required to function and travel. At our headquarters, we offer EV charging stations to our employees and visitors, and where applicable according to local requirements, we offer recycling and properly dispose of e-waste.
Social
We believe that the foundation of our success lies in our diverse,
engaged, and motivated workforce, and we continuously advocate for our team by creating a work environment in which our employees can
thrive in the spirit of productivity and development. This means, among other things, that we aim to operate our business in a manner
that promotes a work environment that is free of discrimination on the basis of any protected characteristics and harassment and otherwise
attends to our employees’ wellbeing.
58
While we continue to develop a program that recognizes our social
impact, we have already implemented various activities to measure and foster our focus on social impact, including the following highlights:
• We are an equal-opportunity employer and make employment decisions based on a person’s qualifications and our business needs. This is demonstrated by our Human Rights and Labor Standards Policy;
• Our corporate policy maintains zero tolerance for harassment, sexual harassment, and discrimination against individuals on the basis of any protected characteristics, and it imposes significant consequences for behavior deemed to create a hostile work environment. This is demonstrated by our Code of Conduct and Ethics as well as our Human Rights and Labor Standards Policy;
• We offer what we believe is an attractive mix of compensation and benefit plans to support our employees’ and their families’ physical, mental, and financial well-being. This includes allowing the majority of our employees to have a direct ownership interest in Radware by participating in our equity-based incentive plans; and
• We are focused on maintaining a healthy, safe, and secure work environment that protects our employees and the public from harm. This is demonstrated by the measures we implemented in order to overcome the challenges presented by the COVID-19 pandemic. We implemented a hybrid work model, which enables our employees to work partly remote and partly in the office. We believe that this flexibility drives increased job satisfaction while addressing the major challenges of remote work, such as isolation and lack of community.
Governance
As part of our sustainable and other ESG operations policies, we
aim to conduct our corporate governance and build corporate behavior mechanisms to align with the interest of all our stakeholders. This
means, among other things, that we developed and strive to maintain a strong set of corporate values that will inspire ethical behavior
across all decision-making processes, and a management and control system so that ethics and security issues are given their due weight.
This includes the following highlights:
• Corporate Governance and Board Practices: Our corporate governance policies and practices are designed to foster effective board oversight in service of the long-term interests of our shareholders. A majority of the members of our Board of Directors qualify as “independent directors” under the Nasdaq rules. The Audit, Compensation and Nomination and Corporate Governance Committees of our Board of Directors, which are charged with significant functions in our risk oversight, compensation and corporate governance philosophy, respectively, all currently consist of three members, all of whom qualify as “independent directors” under the Nasdaq rules. For further details on our corporate governance, as well as our Board of Directors and its committees’ roles and practices, see Items 6.C “Board Practices” and 16G “Corporate Governance.”
• Ethical Business Conduct: All our directors, officers, consultants, service providers and employees are expected to conduct themselves in accordance with our Code of Conduct and Ethics available at http://www.radware.com/corporategovernance/ (information contained on our website, including in our Code of Conduct and Ethics, is not incorporated herein by reference and shall not constitute part of this annual report). Our Code of Conduct and Ethics is intended to promote various elements of ethical business conduct, such as compliance with laws; avoiding conflict of interests and personal exploitation of corporate opportunities; fair dealing; confidentiality of information; and other policies and guidelines in connection with insider trading and anti-corruption laws and policies.
59
C. Organizational
Structure
We have a wholly owned subsidiary in the United States, Radware
Inc., which conducts the sales and marketing of our products and services primarily in the United States and Canada. We also have several
other wholly owned subsidiaries worldwide handling primarily local sales and marketing, support and promotion activities. Our subsidiaries
include (unless otherwise indicated, all subsidiaries are wholly owned, directly or indirectly):
Name of Subsidiary Place of Incorporation
Radware Inc. New Jersey, United States
Radware UK Limited United Kingdom
Radware France France
Radware Srl Italy
Radware GmbH Germany
Nihon Radware KK Japan
Radware Australia Pty. Ltd. Australia
Radware Singapore Pte. Ltd. Singapore
Radware Korea Ltd. Korea
Radware Canada Inc. Canada
Radware India Pvt. Ltd. India
Kaalbi Technologies Limited Ltd. India
Radware (India) Cyber Security Solutions Private Limited India
Radware China Ltd. 睿伟网络科技(上海)有限公司 China
Radware (Hong Kong) Limited Hong Kong
Radyoos Media Ltd.* Israel
Radware Iberia, S.L.U. Spain
Edgehawk Security Ltd. Israel
SkyHawk (CNP) Security Ltd.** Israel
SkyHawk Security, Inc.*** Delaware, United States
CSR Cloud Security Ltd. Israel
Radware (Colombia) S.A.S. Colombia
Pynt, Inc. Delaware, United States
Overcast Security Ltd.*** Israel
Radware Canada Holdings Inc.*** Canada
* We own approximately 91.0% of this subsidiary, which ceased its activities in 2017.
** We own approximately 76.2% of this subsidiary.
*** Indirect subsidiary.
60
The late Yehuda Zisapel, one of our co-founders and shareholders,
was the father of Roy Zisapel, our President, Chief Executive Officer and director. Either the heirs of the late Yehuda Zisapel
(namely, Roy Zisapel, Carmi Zisapel and Adi Zisapel, to which we sometime refer in this annual report as the heirs of the late Yehuda
Zisapel), the heirs of his late brother, Zohar Zisapel (namely, Michael Zisapel and Klil Zisapel, to which we sometime refer in this annual
report as the heirs of the late Zohar Zisapel), and Nava Zisapel, the mother of Roy Zisapel, or all of them together, are founders, directors
and/or shareholders of several other companies which, together with our Company and our subsidiaries listed above, are known as the RAD-Bynet
Group. These companies include, among others:
AB-NET Communications Ltd. Binat Business Ltd. BYNET Data Communications Ltd.* Bynet Data Centers Ltd. CloudRide Ltd.* BYNET Electronics Ltd.* BYNET SEMECH (outsourcing) Ltd.* Bynet Software Systems Ltd. Bynet System Applications Ltd.* Ceragon Networks Ltd. Internet Binat Ltd.* Packetlight Networks Ltd. RAD-Bynet Properties and Services (1981) Ltd.* Radbit Computers, Inc. RADCOM Ltd. RAD Data Communications Ltd.* RADWIN Ltd. DC Protection Ltd. (previously known as SecurityDAM Ltd.)
*Denotes a RAD-Bynet Group company with which we currently transact business.
The heirs of the late Yehuda Zisapel and the heirs of the late
Zohar Zisapel also hold shares in Carteav Ltd., Tupaia Ltd. and Radiflow Ltd., start-up companies that are not considered part of the
RAD-Bynet group.
The RAD-Bynet Group also includes several other holdings, real
estate companies, and biotech and pharmaceutical companies, and the above list does not constitute a complete list of all entities within
the RAD-Bynet Group or of all the holdings of the heirs of the late Yehuda Zisapel, the heirs of the late Zohar Zisapel and Nava Zisapel.
Members of the RAD-Bynet Group are actively engaged in designing,
manufacturing, marketing, and supporting data communications products and services, none of which currently compete with our products.
Some of the products of members of the RAD-Bynet Group are complementary to, and may be used in connection with, our products and services.
See also Item 7.B “Related Party Transactions.”
D. Property,
Plants and Equipment
General. We operate from
leased premises mainly in Tel Aviv, Jerusalem and Ramat Gan in Israel and New Jersey in the United States. We also lease premises in several
locations in Europe, North America, South America and Asia-Pacific for the activities of our subsidiaries, representative offices and
branches. Our aggregate annual rent expenses under these leases were approximately $5.4 million in 2025.
61
We believe that the following offices and facilities are suitable
and adequate for our operations as currently conducted and as currently foreseen. In the event that additional or substitute offices and
facilities are required, we believe that we could obtain such offices and facilities at commercially reasonable rates.
Israel. Our headquarters
and principal administrative, finance, research and development and marketing operations are located in approximately 108,000 square feet
of leased office space in Tel Aviv, Israel, in two buildings: one building, consisting of approximately 40,000 square feet, plus storage
and parking space, and the second building, consisting of approximately 68,000 square feet, plus parking spaces. Both buildings have leases
that expire in June 2030 and are leased from, among others, affiliated companies owned by the heirs of the late Yehuda Zisapel, Nava Zisapel
and/or the heirs of the late Zohar Zisapel, as applicable. For more information, see Item 7.B “Related Party Transactions.”
In addition, we lease approximately 3,600 square feet of space
in Jerusalem, Israel, for development facilities from an affiliated company owned by the heirs of the late Yehuda Zisapel and Nava Zisapel.
The lease expires in July 2028. We also lease approximately 8,000 square feet for manufacturing facilities in Jerusalem, Israel, from
an affiliated company owned by the heirs of the late Yehuda Zisapel, Nava Zisapel and the heirs of the late Zohar Zisapel. The lease expires
in August 2028. For more information, see Item 7.B “Related Party Transactions.”
We also lease approximately 6,600 square feet of space in Ramat
Gan, for operations of one of our subsidiaries. The lease expires in September 2026.
Other locations. In the
United States, we lease approximately 16,900 square feet of property in Mahwah, New Jersey, consisting of approximately 12,700 square
feet of office space and 4,200 square feet of warehouse space from a company controlled by the heirs of the late Yehuda Zisapel, Nava
Zisapel and the heirs of the late Zohar Zisapel. The lease expires in March 2031. For more information, see Item 7.B “Related Party
Transactions.”
We lease approximately 3,850 square feet of property for our research
and development facilities in North Carolina, the lease for which will expire in March 2026.
We also lease facilities for the operation of our subsidiaries
and representative offices in several locations in Europe, North America, South America, and Asia-Pacific, all from unrelated third parties.