Radware Ltd.
A maker of cybersecurity and application-delivery gear, Radware builds products like Alteon that keep websites fast and shield them from attacks such as DDoS, bots, and web threats. Founded in 1997 in Israel, it grew out of the RAD Group, the tech conglomerate created by brothers Yehuda and Zohar Zisapel — its name pairs "RAD" with a nod to software and hardware. Radware stays rooted in the Zisapel family, with Roy Zisapel running it as CEO since day one.
20-F · Fiscal year ended Dec 31, 2025 · SEC filing ↗
The original filing sections are available below.
QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK General We are exposed to market risk, including fluctuations in interest rates and foreign currency exchange rates. Our primary market risk exposure occurs because we generate a portion of our revenues in foreign curren…
QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK General We are exposed to market risk, including fluctuations in interest rates and foreign currency exchange rates. Our primary market risk exposure occurs because we generate a portion of our revenues in foreign currencies, mainly in euros and incur a portion of our expenses in foreign currencies, mainly in NIS, but also in euros and other foreign currencies. As more fully described below, commencing in 2022, we engaged in currency-hedging transactions intended to reduce the effect of fluctuations in foreign currency exchange rates on our financial condition and results of operations. However, there can be no assurance that any such hedging transactions will materially reduce the effect of fluctuations in foreign currency exchange rates on such results. In addition, as of December 31, 2025, we had cash and cash equivalents, including short-term and long-term bank deposits and short- and long-term marketable securities, of $460.6 million. As of that date, approximately 85% of our cash, cash equivalents, bank deposits and marketable securities are held by Radware Ltd. in Israeli or U.S. financial institutions. The majority of our cash and cash equivalents, and short- and long-term bank deposits are invested in banks in Israel and, to a smaller extent, in banks in the United States. The Israeli bank deposits are not insured, while the deposits made in the United States in excess of insured limits are not otherwise insured. If one or more of these financial institutions were to become insolvent, the loss of these investments would have a material adverse effect on our financial condition. Exposure to Interest Rate Fluctuations As of December 31, 2025, approximately 19% of our cash throughout the world was invested in fixed-income securities which are affected by changes in interest rates. Interest rates are highly sensitive to many factors, including governmental monetary policies and domestic and international economic and political conditions. These securities are readily available for sale and are treated as such in our financial statements. Consequently, our investments are exposed to risks relating to a fluctuation in interest rates, which may affect our interest income and the fair market value of our investments. This is because an increase in market interest rates could have an adverse effect on the value of our investment portfolio, for example, by decreasing the fair values of the fixed income securities that comprise a substantial majority of our investment portfolio. Similarly, in a declining interest rate environment, borrowers may seek to refinance their borrowings at lower rates and, accordingly, prepay or redeem securities held earlier than initially expected. This action may cause us to reinvest the redeemed proceeds in lower yielding investments. Our investments portfolio consists primarily of investments in foreign banks and government debentures, corporate debentures, U.S. government and bank deposits. As of December 31, 2025, approximately 19% of our portfolio was invested in corporate debentures, 0.4% in foreign banks and government debentures and the rest of the funds were invested in bank deposits and money market funds. Although we believe that we generally adhere to conservative investment guidelines, the continuing turmoil in the financial markets may result in impairments of the carrying value of our investment assets. Realized losses in our investments portfolio may adversely affect our financial condition and results. Any significant decline in our investment income or the value of our investments as a result of falling interest rates, deterioration in the credit of the securities in which we have invested, or general market conditions could have an adverse effect on our results of operations and financial condition. We currently have no debt. 123 Exposure to Currency Fluctuations Approximately 87% of our sales in 2025 were denominated in dollars or are dollar-linked, and we incur most of our expenses in dollars, NIS, and euros. We believe that the dollar is the primary currency of the economic environment in which we operate. Thus, our functional and reporting currency is the dollar, and monetary accounts maintained in currencies other than the dollar are re-measured into U.S. dollars in accordance with ASC 830 “Foreign Currency Matters.” Changes in currency exchange rates between our functional currency and the currency in which a transaction is denominated are included in our results of operations as financial income (expense) in the period in which the currency exchange rates change. We monitor our foreign currency exposure and periodically use currency forward contracts to mitigate the impact of fluctuations in USD/NIS exchange rates on our forecasted cash flows. As of December 31, 2025, we had outstanding currency forward contracts totaling approximately $7.8 million to hedge a portion of our anticipated NIS‑denominated expenses through March 31, 2026. For 2026, however, we have hedged only a very limited portion of our anticipated exposure. Consequently, we expect that the continued weakening of the U.S. dollar relative to the shekel during 2026 will materially increase our NIS‑denominated operating costs. This trend is expected to have a significant adverse effect on our results of operations and, in turn, negatively impact our net income for the year. Our revenues and expenses may be affected by fluctuations in the value of the dollar as it relates to foreign currencies, mainly the NIS and Euro. For example, if there were no changes in the average exchange rates of the dollar relative to the NIS and Euro in 2025 compared to the average exchange rates in 2024, our revenues would have been lower in an amount of $1.4 million, and our expenses would have been lower by an amount of $2.6 million. Assuming our revenues and expenses in 2025 remain at the same level and with the same currency mix as in 2025, a 10% weakening in the value of the dollar relative to all currencies in which we operate would result in an increase in revenues of approximately $3.7 million and an increase in our expenses of $13.7 million. The following table presents information about the changes in the exchange rates of the U.S. dollar relative to the NIS and Euro: U.S. dollar against: Year ended December 31, NIS Euro 2021 (3.3 )% 8.4 % 2022 13.2 % 6.1 % 2023 3.1 % (3.6 )% 2024 0.6 % 6.3 % 2025 (12.5 )% (11.3 )% 124
INFORMATION A. [Reserved] B. Capitalization and Indebtedness Not applicable. C. Reasons for the Offer and Use of Proceeds Not applicable. D. Risk Factors You should carefully consider the following risks before deciding to purchase, hold or sell our ordinary shares. Our business…
INFORMATION A. [Reserved] B. Capitalization and Indebtedness Not applicable. C. Reasons for the Offer and Use of Proceeds Not applicable. D. Risk Factors You should carefully consider the following risks before deciding to purchase, hold or sell our ordinary shares. Our business, operating results, and financial condition could be seriously harmed due to any of the following risks. The following risks are not the only risk factors faced by our Company. Additional risks and uncertainties not presently known to us or that we currently deem immaterial may also affect our business. The trading price of our ordinary shares could decline due to any of these risks. You should also refer to the other information contained or incorporated by reference in this annual report before making any investment decision regarding our Company. Summary of Risk Factors The following constitutes a summary of the material risks relevant to an investment in our Company: Risks Related to Our Business and Our Industry • Changing or severe global market and economic conditions could have a material adverse effect on our results of operations. • We are highly dependent upon independent distributors to sell our solutions to customers. If our distributors do not succeed in selling our products and services, we may not be able to operate profitably. • A shortage of components or manufacturing capacity could cause a delay in our ability to fulfill orders or increase our manufacturing costs, and any disruption in our supply chain could have a material adverse effect on our results of operations. • We rely on a few vendors to provide our hardware platforms and components for the manufacture of our products. • Our success depends on our ability to attract, train and retain highly qualified personnel. • Competition in the market for cybersecurity and application delivery solutions and in our industry, in general, is intense. If we are unable to compete effectively, we may lose market share, and we may be unable to maintain profitability. • We must develop new solutions and enhance existing solutions to remain competitive. • Our reputation and business could be harmed based on real or perceived shortcomings, defects or vulnerabilities in our solutions or if our end-users experience security breaches, which could have a material adverse effect on our business, reputation and operating results. • We use AI Technologies that present regulatory, litigation, and reputational risks that could materially and adversely affect our business, financial condition and results of operations. • We face risks related to the rapidly evolving regulatory framework for AI Technologies. 8 • As a security provider, if our information technology systems and data, or those of our service providers and other contractors, are compromised by cyber-attackers or other malicious actors, or by a critical system failure, our reputation, financial condition and operating results could be materially adversely affected. • Outages, interruptions, or delays in hosting services could impair the delivery of our cloud-based security services and harm our business. • Our products must interoperate with operating systems, software applications and hardware that are developed by others and if we are unable to devote the necessary resources to ensure that our products interoperate with such software and hardware, we may fail to increase, or we may lose market share and we may experience a weakening demand for our products. • Our global operations may expose us to additional risks. • We have incurred net losses in the past and may incur losses in the future. • A slowdown in the growth of the cybersecurity and application delivery solutions market would reduce our addressable market and solutions sales. • If the market for our cloud-based solutions does not continue to develop and grow, we may incur capital and operating losses. • Our solutions have long sales cycles, which may reduce the predictability of our financial performance. • We may pursue acquisitions or other investments that could disrupt our business and harm our financial condition. • Our business in countries with a history of corruption and transactions with foreign governments increases the risks associated with our international activities. • Currency exchange rates and fluctuations of exchange rates could have a material adverse effect on our results of operations. • Undetected defects and errors may increase our costs and impair the market acceptance of our products. • Our business and operating results could suffer if third parties infringe upon our proprietary technology. • Our products may infringe on the intellectual property rights of others. 9 • Laws, regulations and industry standards affecting our business are evolving, and unfavorable changes could harm our business. • Some of our solutions contain “open source” and third-party software, and any failure to comply with the terms of one or more of these open source and third-party software licenses could negatively affect our business. • The amount of intangible assets and goodwill on our books may in the future lead to significant impairment charges. • Additional tax liabilities, including due to tax positions we have taken, could materially adversely affect our results of operations and financial condition. • The enactment of legislation changing the United States’ taxation of international business activities could materially impact our financial condition and results of operations. • Complications with the design or implementation of our new enterprise resource planning (“ERP”) system, or major disruptions or deficiencies of our other information technology systems, could adversely impact our business and operations. • We rely on information technology systems to conduct our businesses, and failure to protect these systems against security breaches and otherwise to implement, integrate, upgrade and maintain such systems in working order could have a material adverse effect on our results of operations, cash flows or financial condition. • Our business may be affected by sanctions, export controls and similar measures targeting Russia and other countries and territories, as well as other responses to Russia’s military conflict in Ukraine, including indefinite suspension of operations in Russia and dealings with Russian entities by many multi-national businesses across a variety of industries. • Our disclosures and initiatives related to environmental, social and governance (ESG) matters, including those related to climate change and sustainability, expose us to numerous risks, including risks to our reputation, business, financial performance and growth. • We have in the past, and may in the future, become subject to litigation or claims arising in or outside the ordinary course of business that could negatively affect our business operations and financial condition. 10 Risks Related to the Market for Our Ordinary Shares • The estate of the late Yehuda Zisapel, along with Nava Zisapel and Roy Zisapel, our President, Chief Executive Officer and a director, may exert significant influence in the election of our directors and over the outcome of other matters requiring shareholder approval. • Provisions of our Articles of Association and Israeli law as well as the terms of our equity incentive plan could delay, prevent or make a change of control of us more difficult or costly, which could depress the price of our ordinary shares. • Our share price has been volatile in the past and may be subject to volatility in the future. • If we are characterized as a passive foreign investment company, our U.S. shareholders may suffer adverse tax consequences. • If a U.S. person is treated as owning at least 10% of our ordinary shares, such holder may be subject to adverse U.S. federal income tax consequences. • We are a foreign private issuer and, as a result, we are subject to reporting obligations and corporate governance practices that, to some extent, are more lenient than those of a U.S. domestic public company whose shares are listed on Nasdaq. Risks Related to Operations in Israel • Political, economic and military instability in the Middle East or Israel may harm our business. • The tax benefits we may receive in connection with our preferred enterprise program require us to satisfy prescribed conditions and may be terminated or reduced in the future. This would increase taxes and decrease our net profit. • We have obtained benefits from the Israeli Innovation Authority that subject us to ongoing restrictions. • It may be difficult to enforce a U.S. judgment against us or our officers and directors and to assert U.S. securities laws claims in Israel. • Your rights and responsibilities as a shareholder will be governed by Israeli law, which may differ in some respects from the rights and responsibilities of shareholders of U.S. companies. 11 Risks Related to Our Business and Our Industry Changing or severe global market and economic conditions could have a material adverse effect on our results of operations. Our business is affected by global market and economic conditions, uncertainties and downturns, including as a result of instability in the Middle East (see the risk factor below titled “Political, economic and military instability in the Middle East or Israel may harm our business”), the tensions between China and Taiwan, export controls recently imposed by the United States with respect to, among other things, graphics processing units (GPUs), and central banks in the markets in which we operate that have tightened their monetary policies and, until recently, raised interest rates, which may impact current and anticipated market demand for our solutions. Uncertainties about current global market and economic conditions continue to pose a risk as our current or prospective customers may postpone or reduce demand and spending priorities in response to such uncertainties. This could result in, among other things, a reduction in our revenues or a failure to achieve anticipated revenue growth, longer sales cycles, and slower adoption of new technologies, as well as downward pressure on the price of our solutions. Other macro conditions may have other adverse effects on the global markets and economy, which are difficult to predict, such as disruptions of the global supply chain and energy markets, instability of any bank with which we maintain a commercial relationship, inflation pressures, rising interest rates or a period of elevated interest rates or impacts from tariffs or other trade restrictions. Each of the above events could have a material adverse effect on our business, operating results, and financial condition. We are highly dependent upon independent distributors to sell our solutions to customers. If our distributors do not succeed in selling our products and services, we may not be able to operate profitably. Our growth strategy depends upon, among other things, increasing sales of our solutions, both directly and indirectly through our different distribution channels. We sell our solutions primarily to independent distributors, including value added resellers (VARs), original equipment manufacturers (OEMs) and global system integrators (GSIs), and are highly dependent upon these distributors’ active marketing and sales efforts. Our distribution agreements with our distributors generally are non-exclusive, ranging in duration with no renewal obligation on the part of our distributors. Our distribution agreements also typically do not prevent our distributors from selling products and services of our competitors and do not contain minimum sales or marketing performance requirements. As a result, our distributors may give higher priority to products and services of our competitors or their own products, thereby reducing their efforts to sell our products and services. In addition, we may not be able to maintain our existing distribution relationships, and we may not be successful in replacing them on a timely basis, or at all. We may also need to develop new distribution channels for new products and services, and we may not succeed in doing so. Any changes in our distributor relationships or distribution channels, including a termination or other disruption of our commercial relationship with our distributors or our inability to establish distribution channels for new products and services, could impair our ability to sell our products and services and have a material adverse effect on our business, financial condition and results of operations. A shortage of components or manufacturing capacity could cause a delay in our ability to fulfill orders or increase our manufacturing costs, and any disruption in our supply chain could have a material adverse effect on our results of operations. Our ability to meet customer demands depends in part on our ability to obtain timely deliveries of parts from our suppliers and contract manufacturers. We cannot assure you that we will not encounter supply and fulfilment issues in the future and certain components are presently available to us only from limited sources (see the risk factor below titled “We rely on a few vendors to provide our hardware platforms and components for the manufacture of our products” and the discussion under Item 4.B “Business Overview—Manufacturing and Suppliers”). We may not be able to diversify sources in a timely and cost-effective manner, which could harm our ability to deliver products to customers and adversely impact present and future sales and profitability. We may experience a shortage of certain component parts as a result of our own manufacturing issues, manufacturing issues at our suppliers or contract manufacturers, capacity problems or transportation and freight carriers issues experienced by our suppliers or contract manufacturers, or strong demand in the industry for those parts, especially if there is growth in the overall economy. If there is growth in the economy, such growth is likely to create greater pressures on us and our suppliers to accurately project overall component demand and component demands within specific product categories and to establish optimal component levels. If shortages or delays persist, such as due to the worldwide chipset shortage, the price of these components may increase, or the components may not be available at all. 12 We may also encounter shortages if we do not accurately anticipate our needs. We may not be able to secure enough components at reasonable prices or of acceptable quality to build new products in a timely manner in the quantities or configurations needed. Accordingly, our revenues and gross margins could be materially and adversely affected until other sources can be developed. In addition, our operating results could be materially and adversely affected if we anticipate greater demand than what transpires, and we commit to purchasing more components than we actually need. We see this specifically with respect to dated components, which we need to order in large quantities due to manufacturing stoppage. Due to technology advancements, we are required from time to time to make “last buy” type of stock purchases of such dated components for our products. Any disruption in our supply chain, such as disruptions resulting from failure in telecommunication systems; acts of war, terrorism, cyber-attacks or natural disasters, including major environmental or public health concerns, such as the COVID-19 pandemic; lack of skilled labor; the disruption of transportation networks; and adverse weather conditions, could have a material adverse effect on our business, financial condition and results of operations. We rely on a few vendors to provide our hardware platforms and components for the manufacture of our products. We primarily rely on a few original design manufacturers (“ODMs”), for the manufacture and supply of our hardware platforms, with approximately 81% of our direct product costs in 2025 related to these vendors. If we are unable to continue to do business with these ODMs and/or other components vendors on acceptable terms or should any of these ODMs and/or components vendors cease to supply us with such platforms or components for any reason, we may not be able to identify and integrate an alternative source of supply in a timely fashion or at the same costs. Any transition to one or more alternate manufacturers could result in delays, operational problems and increased costs, and may limit our ability to deliver our products to our customers on time during such a transition period, any of which could have a material adverse effect on our business, financial condition and results of operations. Our success depends on our ability to attract, train and retain highly qualified personnel. Our products and services require sophisticated technology, marketing and sales expertise. Accordingly, we need highly trained research and development, sales, marketing, technical, customer support, operations and IT personnel. Competition for such qualified personnel, especially in the cybersecurity domain, is intense. In particular, while there has been intense competition for such qualified personnel in the Israeli high-tech industry historically, the industry experienced record growth and activity in the past few years, which contributed to significant levels of employee attrition. The Israeli high-tech industry still faces a shortage of skilled human capital, including qualified personnel in the cybersecurity domain. Additionally, we may be unable to hire or retain talent who are trained in artificial intelligence (AI) or generative artificial intelligence (Gen AI), machine learning and advanced algorithms, to keep pace with the rapid and continuous technological changes in our industry. While we utilize non-competition agreements with our employees as a means of improving our employee retention, we may be unable to enforce these agreements under applicable laws. In light of the foregoing, we may not be able to hire or retain sufficient personnel to support our business operations or, if we do, we may be required to offer increased compensation to attract such employees, which could have a material adverse effect on our business, financial condition and results of operations. Competition in the market for cybersecurity and application delivery solutions and in our industry, in general, is intense. If we are unable to compete effectively, we may lose market share, and we may be unable to maintain profitability. The cybersecurity and application delivery solutions marketplace is highly competitive and has very few barriers to entry, particularly in our focus areas. We expect competition to intensify in the future, including as a result of the integration of AI technologies into the markets in which we compete, and we may lose market share if we are unable to compete effectively. 13 Most of our competitors have greater financial, personnel and other resources than we have, which may limit our ability to effectively compete with them. We expect to continue to face additional competition as new participants enter the market or extend their portfolios into related technologies. Current and future participants may also be able to respond more quickly to new or emerging technologies and changes in customer demands and to devote greater resources to the development, promotion and sale of their products than we can. Larger companies with substantial resources, brand recognition and sales channels may form consolidation and alliances with or acquire competing cybersecurity and application delivery solutions and emerge as significant competitors. Competition may result in lower prices or reduced demand for our solutions and a corresponding reduction in our ability to recover our costs, which may impair our ability to achieve, maintain and increase profitability. Furthermore, the dynamic market environment poses a challenge in predicting market trends and expected growth. We cannot assure you that we will be able to implement our business strategy in a manner that will allow us to be competitive. If any of our competitors offer products or services that are more competitive than ours, we could lose market share and our business, financial condition and results of operations could be materially and adversely affected as a result. We must develop new solutions and enhance existing solutions to remain competitive. The cybersecurity market is experiencing rapid technological shifts driven by accelerated Digital Transformation and Generative/Agentic AI. These advancements enable adversaries to create targeted exploits and accelerate cyberattack deployment. In addition, evolving network infrastructures, application architectures, development methodologies, and stringent compliance mandates further complicate the landscape. The active and evolving cyber threat environment is also intensified by weaponized AI tools. To address these challenges effectively, we must focus on several critical areas: • Enhancing Core Product Performance: Increasing throughput, capacity, algorithmic coverage, and efficiency to manage the growing velocity and complexity of attacks. • Adapting to Infrastructure Changes: Providing relevant solutions for Generative/Agentic AI, multi-cloud and hybrid cloud environments in response to fundamental shifts in customers’ data centers and application/data locations. • Innovating Modern Application Security: Developing new solutions to address changes in application deployment frameworks, workflows, API usage, account takeover attacks, browser security, supply chain threats, and edge delivery technologies. • Expanding Security Coverage: Extending protection to API, LLM, client-side, edge, DNS, cloud-native, business logic, encrypted/web DDoS, and AI-driven attacks, including those using natural language processing and automated methods. • Service Enhancements: Increasing support/service delivery to accommodate rising customer demands and infrastructure scale. Expanding our managed security services for the cloud and through the cloud – organically and inorganically. • Compliance and Regulatory Adaptation: Meeting new regulations related to publicly exposed services and sensitive data validation. Our future success also hinges on our ability to accurately identify market trends and anticipate evolving customer needs, invest in research and development, including acquiring complementary solutions, timely develop, introduce, and support relevant new solutions and enhancements, and achieve market acceptance of these offerings. 14 In order to meet these challenges and remain competitive in the market, we have introduced, and must continue to introduce, new solutions and enhancements to our existing solutions. Accordingly, our future success will depend, to a substantial extent, on our ability to accurately and timely identify market trends and anticipate changing market requirements and needs; to invest (including through acquisition of complimentary solutions) in research and development and timely develop, introduce and support relevant and desired new solutions and enhancements; and to gain market acceptance of our offerings. There can be no assurances that our continued investment in research and development, including associated capital expenditures, will ultimately allow us to remain competitive in our industry or otherwise result in successful solutions that generate expected sales and support our growth. In addition, diversifying our solution portfolio might expose us to direct competition with new players and might require additional investments in the associated sales and marketing practices. If our research and development efforts do not lead to a corresponding increase in our revenues, if we fail to timely develop and deploy new solutions and enhancements to our existing solutions, or if we fail to gain market acceptance of our new solutions or enhanced solutions, our business, operating results, and financial condition could be materially adversely affected. Our reputation and business could be harmed based on real or perceived shortcomings, defects or vulnerabilities in our solutions or if our end-users experience security breaches, which could have a material adverse effect on our business, reputation and operating results. Any errors, defects, or misconfigurations could cause our solutions to not meet specifications, be vulnerable to security attacks or fail to secure networks or applications, which could negatively impact customer operations and consequently harm our business and reputation. In addition, we may suffer significant adverse publicity and reputational harm and become subject to regulatory and litigation claims if our solutions are associated, or are believed to be associated with, or fail to reasonably protect against, a security attack or a breach at a high-profile customer, a significant customer base or a significant business partner. Many of our customers and business partners are themselves highly regulated entities, which may result in enhanced scrutiny of our security program and controls in the event of a significant cybersecurity incident. Moreover, any actual or perceived cyber-attack, other security breach, exposure or theft of our or our customers’ data, regardless of whether the breach or theft is attributable to the failure of our solutions, could: • adversely affect the market’s perception of our security solutions; • cause current or potential customers to look to our competitors for alternatives; • require us to expend significant financial resources to analyze, correct or eliminate any vulnerabilities; and • lead to investigations, litigation, fines and penalties, any of which could have a material adverse effect on our operations, financial condition and reputation. Cyber-attackers or other malicious actors are increasingly sophisticated, may be state actors or affiliated with organized crime, and may operate large-scale and complex automated attacks. In addition, the techniques they use to access or sabotage networks or applications or to disrupt operations (for example, via ransomware) change frequently and generally are not recognized until launched against a target. As a result, our solutions may be unable to anticipate these techniques and provide timely or effective protection to our end-users’ networks or applications, particularly due to the increased use by attackers of tools and techniques that are designed to circumvent security controls, to avoid detection and to remove or obfuscate evidence. The global marketplace also expects actors to increasingly develop innovative attack methodologies utilizing AI as well as new tools to identify and exploit vulnerabilities from both technical and social engineering perspectives. In addition, continued remote and hybrid working arrangements at our Company (and at many third-party providers), such as those that evolved during the COVID-19 pandemic and continued after the pandemic, also increase cybersecurity risks due to the challenges associated with managing remote computing assets and the security vulnerabilities that are present in many non-corporate and home networks. We may acquire companies or enter into information technology system integrations with companies that have cybersecurity vulnerabilities or unsophisticated security measures, which would expose us to increased risks. In addition, we cannot comprehensively identify all misconfigurations, “bugs” or vulnerabilities in proprietary or third-party systems or software used by our business, or guarantee that patches or compensating controls will be applied before vulnerabilities can be exploited by a threat actor. If we fail to identify and respond to new and increasingly complex methods of attack or to update our solutions to detect or prevent such threats in time to protect our end-users’ critical business data, the integrity of our solutions and reputation, as well as our business and operating results, could suffer. 15 Furthermore, security breaches or defects in our solutions could result in loss or alteration of, or unauthorized access to, data of customers, employees, business partners and others, including personally identifiable information, as well as proprietary information belonging to our business such as trade secrets, and compromise our customers’ networks and applications that are secured by our physical and cloud solutions. Moreover, any use or integration of generative or other AI in our, or any third party’s, operations, products or services will pose new and/or unknown cybersecurity risks and challenges. AI tools and applications have created a new attack vector to infect unsuspecting users with malware, such as ransomware and data extraction routines. If such a security breach results in the disruption or loss of availability, integrity or confidentiality of customers’ data, we could incur significant liability to our customers and to businesses or individuals whose information was being handled by our customers, in addition to liability imposed by regulatory agencies. There can be no assurance that limitation of liability, indemnification or other protective provisions that we attempt to include in our contracts would be applicable, enforceable or adequate in connection with a security breach, or would otherwise protect us from any such liabilities or damages with respect to any particular claim. There is no guarantee that our solutions will be free of flaws or vulnerabilities. Our end-users may also misuse our solutions, which could result in vulnerabilities to a breach or theft of business data. Furthermore, there can be no assurance that our cybersecurity risk management program and processes, including our policies, controls, or procedures, will be fully implemented, complied with or effective in protecting our information technology systems and confidential information. We use AI Technologies that present regulatory, litigation, and reputational risks that could materially and adversely affect our business, financial condition and results of operations. We use various AI Technologies throughout our business, and are making significant investments in this area. For example, we use AI Technologies to serve some of our cloud customers. There are significant risks involved in developing, maintaining and deploying AI Technologies. In particular, if the models underlying our AI Technologies are incorrectly designed or implemented; trained or reliant on incomplete, inadequate, inaccurate, biased or otherwise poor quality data, or on data to which we do not have sufficient rights or in relation to which we and/or the providers of such data have not implemented sufficient legal compliance measures; used without sufficient oversight and governance; and/or adversely impacted by unforeseen defects, technical challenges, cybersecurity threats or material performance issues, the performance of our products, services and business, as well as our reputation, could suffer, or we could incur liability resulting from the violation of laws or contracts to which we are a party or civil claims. 16 With respect to our products or services that incorporate AI Technologies, the market for such products and services is rapidly evolving. We cannot be sure that the market will continue to grow or that it will grow in ways we anticipate. In addition, market acceptance and consumer perceptions of products and services that incorporate AI Technologies is uncertain. Our failure to successfully develop and commercialize our products or services involving AI Technologies could depress the market price of our ordinary shares and impair our ability to raise capital, expand our business, provide, improve and diversify our product offerings, efficiently manage our operating expenses; and respond effectively to competitive developments. In particular, we are working to incorporate Gen AI into our solutions and internal business practices. There is a risk that Gen AI could produce inaccurate or misleading content or other discriminatory or unexpected results or behaviors, such as hallucinatory behavior that can generate irrelevant, nonsensical, or factually incorrect results, all of which could harm our reputation, business, or customer relationships. While we take measures designated to ensure the accuracy of such AI generated content, those measures may not always be successful, and in some cases, we may need to rely on end users to report such inaccuracies. Further, if we are deemed to not have sufficient rights to the data we use to train our Gen AI, we may be subject to litigation by the owners of the content or other materials that comprise such data, similar to the litigation that is currently pending in various U.S. courts against other developers of Gen AI, and in which the outcome of such litigation is uncertain. We may not be successful in our ongoing development and maintenance of these technologies in the face of novel and evolving technical, reputational and market factors. Our efforts to develop proprietary AI models could increase our operating costs. Our ability to develop proprietary AI models may be limited by our access to processing infrastructure or training data, and we may be dependent on third-party providers for such resources. We face significant competition from other companies in our industry in relation to the development and deployment of AI Technologies. Those other companies may develop AI Technologies that are similar or superior to ours and/or are more cost-effective and/or quicker to develop, deploy and maintain. Any inability to develop, offer or deploy new AI Technologies as effectively, as quickly and/or as cost-efficiently as our competitors could have a materially adverse impact on our operating results, customer relationships and growth. Further, our ability to continue to develop or use such technologies may be dependent on access to specific third-party software, services and infrastructure, such as processing hardware, and we cannot control the availability or pricing of such third-party software and infrastructure, especially in a highly competitive environment. 17 We face risks related to the rapidly evolving regulatory framework for AI Technologies. The regulatory framework for AI Technologies is rapidly evolving as government bodies and agencies in many geographical jurisdictions have introduced or are currently considering additional laws and regulations. Additionally, existing laws and regulations may be interpreted in ways that would affect the operation of our AI technologies, or could be rescinded or amended as new administrations take differing approaches to evolving AI technologies. As a result, implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot determine the impact future laws, regulations, standards, or market perception of their requirements may have on our business and may not always be able to anticipate how to respond to these laws or regulations. Already, certain existing legal regimes (e.g., relating to data privacy) regulate certain aspects of AI technologies, and new laws regulating AI technologies have either entered into force or are expected to enter into force in the near future. For example, in Europe, on August 1, 2024, the EU Artificial Intelligence Act (the “EU AI Act”) entered into force, and establishes a comprehensive, risk-based governance framework for AI in the EU market. It is possible that additional new laws and regulations will be adopted in the United States and other jurisdictions, or that existing laws and regulations, including competition and antitrust laws, may be interpreted in ways that would limit our ability to use AI technologies for our business, or require us to change the way we use AI technologies in a manner that negatively affects the performance of our products, services, and business and the way in which we use AI technologies. We may need to expend resources to adjust our products or services in certain jurisdictions if the laws, regulations, or decisions are not consistent across jurisdictions. Further, the cost to comply with such laws, regulations, or decisions and/or guidance interpreting existing laws, could be significant and would increase our operating expenses (such as by imposing additional reporting obligations regarding our use of AI technologies). Such an increase in operating expenses, as well as any actual or perceived failure to comply with such laws and regulations, could adversely affect our business and operating results. It is also possible that the AI technologies we use may, or may be viewed as, having unintended biases or discriminatory outcomes, exposing us to risks that we have discriminated against persons belonging to a protected class. Any resulting investigation or litigation could have an adverse impact on our results of operations due to the associated costs and any related fines, and could also have an adverse impact on our customer relationships. As a security provider, if our information technology systems and data, or those of our service providers and other contractors, are compromised by cyber-attackers or other malicious actors, or by a critical system failure, our reputation, financial condition and operating results could be materially adversely affected. We will not succeed with our application and network security solutions unless the marketplace is confident that we provide effective cybersecurity protection. We provide security solutions, and as a result, we have been, and continue to be, an attractive target of cyber-attacks and other security incidents, which we have experienced from time to time, that threaten the confidentiality, integrity and availability of our computer and information technology at our computer and information technology systems and network environment. We are subject to many different types of attacks, including, among others, malware, viruses and attachments to e-mails, web application attacks, DDoS attacks, and other disruptive activities of individuals or groups, all of which are designed to impede the performance of our solutions, penetrate our network security or the security of our cloud platform or our internal systems, misappropriate proprietary and other important data and personal information we process or maintain and/or cause other interruptions to our services. We and certain of our third-party providers regularly experience cyberattacks and other incidents, and we expect such attacks and incidents to continue in varying degrees. While to date no attacks or incidents have had a material impact on our operations or results, we cannot guarantee that material incidents will not occur in the future. We expect cyberattacks to accelerate on a global basis in both frequency and magnitude, as threat actors are increasingly sophisticated in using techniques and tools – including AI – that can circumvent controls, evade detection and remove forensic evidence. As a result, we may be unable to detect, investigate, remediate or recover from future attacks or incidents, or to avoid a material adverse impact on our information technology systems, confidential information or business. Furthermore, third parties may attempt to illegally induce employees or customers into disclosing our proprietary information or otherwise compromising the security of our internal networks, systems or physical facilities in order to gain access to our data or our customers’ data. An actual or perceived breach of security in our internal systems could adversely affect the integrity and market perception of our solutions. Furthermore, the costs to eliminate or address security threats and vulnerabilities before or after a cyber-security incident and any resulting regulatory or litigation actions could be significant. 18 We rely on third-party service providers to supply physical hosting, cloud environments, and specific support technologies in order to deliver and support our security solutions, in addition to internal functions, such as human resources, finance, and electronic communications, all of which are designed to enable us to conduct, monitor, and/or protect our business, operations, systems, and data assets. Such third-party service providers have from time to time been subject to, and continue to be subject to, cyber-attacks, malicious actors, and other security incidents. While we periodically evaluate the internal security posture of each third-party service provider to determine their level of compliance, we may not be able to detect any breach in the first instance it occurs. These risks may impact the integrity and availability of our solutions and may expose us to legal and reputational liability. Any significant system failure, accident, attack or security breach could have a material adverse effect on our business, financial condition and results of operations. Remediation efforts or system redundancy or other continuity measures may be ineffective or inadequate and could result in interruptions, delays or cessation of service and loss of existing or potential customers. There can be no assurance that limitation of liability, indemnification or other protective provisions in our contracts would be applicable, enforceable, or adequate in connection with a security breach, or would otherwise protect us from any such liabilities or damages with respect to any particular litigation (including class actions), reputational impacts, and the loss of partners, collaborators and customers. Additionally, our professional, product, and cyber liability insurance coverages may only cover certain liabilities in connection with a security breach or other security incident and may not adequately cover all liabilities actually incurred, and we cannot assure you that insurance will continue to be available to us on commercially reasonable terms, if at all, or that any insurer will not deny coverage as to any future claim. In addition, any such security breach could disrupt or impair our ability to operate our business, including our ability to provide maintenance and support services to our customers. If this happens, our revenues could decline and our reputation and business could suffer. Outages, interruptions, or delays in hosting services could impair the delivery of our cloud-based security services and harm our business. We offer infrastructure that supports our DDoS Protection services, web application firewall (WAF) and bot management cloud-based services. In addition, we provide other services through the cloud, such as Content Delivery Network (CDN). Despite precautions taken within our own internal network and at these third-party facilities, the occurrence of a natural disaster or an act of terrorism or other unanticipated problems could result in lengthy interruptions in our services. The cloud-based security services that we provide are operated from a network of third-party facilities that host the software and systems that operate these security services. Any damage to, failure of, or significant disruptions (for example, due to ransomware) to, our internal systems or systems at third-party hosting facilities could result in outages or interruptions in our cloud-based services. Outages or interruptions in our cloud-based security services, whether as a result of impacts to our or our third-party hosting facilities or otherwise, may cause our customers to experience cyber-attacks and to believe that our cloud-based security services are unreliable, cause us to issue credits or pay penalties or damages, cause customers to terminate their subscriptions, and adversely affect our reputation and renewal rates and our ability to attract new customers, ultimately harming our business and results of operations. 19 Our products must interoperate with operating systems, software applications and hardware that are developed by others and if we are unable to devote the necessary resources to ensure that our products interoperate with such software and hardware, we may fail to increase, or we may lose market share and we may experience a weakening demand for our products. Our products must interoperate with our customers’ existing infrastructure, including their networks, servers, software and operating systems, which may be manufactured by a wide variety of vendors and original equipment manufacturers. As a result, when problems occur in a network, it may be difficult to identify the source of the problem. The occurrence of software or hardware problems, whether caused by our products or another vendor’s products, may result in the delay or loss of market acceptance of our products. In addition, when new or updated versions of our end-customers’ software operating systems or applications are introduced, we must sometimes develop updated versions of our software so that our products will interoperate properly. We may not accomplish these development efforts quickly, cost-effectively or at all. These development efforts require capital investment and the devotion of engineering resources. If we fail to maintain compatibility with these applications, our end-customers may not be able to adequately utilize our products, and we may, among other consequences, fail to increase, or we may lose market share and experience a weakening in demand for our products, which would adversely affect our business, operating results and financial condition. Our global operations may expose us to additional risks. We currently offer our solutions in over 80 countries. For the years ended December 31, 2025 and 2024, our sales outside North, Central and South America represented approximately 59% and 57%, respectively, of our total sales. We also rely on third-party service providers around the world to supply physical hosting and cloud environments in order to deliver and support our cloud-based services. Our global business operations involve varying degrees of risk and uncertainty inherent in doing business in so many different jurisdictions. Such risks include, among others: difficulties and costs of staffing and managing foreign operations; the possibility of unfavorable circumstances and additional compliance costs arising from host country laws or regulations, including unexpected changes in the interpretations thereof and reduced protection for intellectual property rights in some countries; partial or total expropriation; export duties and quotas; local tax exposure; economic or political instability, including as a result of insurrection, war, natural disasters, and major environmental, climate or public health concerns, such as the COVID-19 pandemic; differences in business practices; recessionary environments in multiple foreign markets; and damage to, or failure of, systems at third-party hosting facilities around the word resulting in outages or interruptions in our cloud-based services. We cannot be certain that the foregoing factors will not have a material adverse effect on our future revenues and, as a result, on our business, operating results, and financial condition. We have incurred net losses in the past and may incur losses in the future. Although we reported net income in 2025 and 2024, we incurred net losses in 2023. Although we recorded an operating income of $11.4 million in 2025, in 2024 and 2023 we recorded an operating loss of $3.9 million and $31.7 million, respectively, and in 2023 we recorded a net loss of $21.6 million. Our ability to maintain or increase profitability in the future depends in part on the following factors: the economic health of the global economy, including geopolitical tensions; record levels of inflation and rising interest rates or a period of elevated interest rates; fluctuations in currency exchange rates, particularly volatility in the NIS/USD exchange rate; impacts from tariffs or other trade restrictions; changes in technology trends in our market and other industries in which we currently or may in the future operate; our ability to develop and manufacture new products and technologies and deliver new solutions in a timely manner; the competitive position of our products and services; the continued acceptance of our solutions by our customers and in the industries that we serve; and our ability to manage expenses. In the future, it may be necessary to undertake cost reduction initiatives to be profitable, which could lead to a deterioration of our competitive position. Any difficulties that we encounter as we reduce our costs could negatively impact our results of operations and cash flows. Our revenues may not increase or may grow at a lower rate than we have experienced in the past several years or may even decline, which would negatively impact our results of operations and cash flows. We cannot assure you that we will continue to be profitable. 20 We may increase our operating expenses in future periods. Our decision to increase operating expenses and the scope of such increases depends upon several factors, including the market situation and the effectiveness of our past expenditures. We may continue to make additional expenditures in anticipation of generating higher revenues, which we may not realize, if at all, until sometime in the future. This could cause reductions in our profitability or lead to losses. Additionally, a failure of any acquisition or product development initiative to produce increased revenues could have a material adverse effect on our operations and profitability. A slowdown in the growth of the cybersecurity and application delivery solutions market would reduce our addressable market and solutions sales. The cybersecurity and application delivery market in which we operate is rapidly evolving, and we cannot assure you that it will continue to develop and grow. In addition, we cannot assure you that our solutions and technology will keep pace with the changes to this market. Market acceptance of cybersecurity and application delivery solutions may be inhibited by, among other factors, a lack of anticipated congestion and strain on existing network infrastructures and the availability of alternative solutions. If demand for cybersecurity and application delivery solutions does not continue to grow, or grows at a slower pace than expected, we may not be able to sell enough of our solutions to maintain or increase our profitability. If the market for our cloud-based solutions does not continue to develop and grow, we may incur capital and operating losses. As we continue to expand our cloud-based solution offerings, our investments, both capital and operational, in our cloud business increase. We cannot assure you that sales of our cloud-based solutions will continue to develop and grow. In addition, we cannot assure you that our services and technology will keep pace with the changes in this market. Specifically, the emergence of alternative solutions, such as those offered by Amazon Web Services, Inc. (AWS), Microsoft Azure or Google’s public cloud, may negatively affect sales of our solutions. We recognize a significant portion of revenue from subscriptions over the term of the relevant subscription period, and as a result, downturns or upturns in sales are not immediately reflected in full in our results of operations. Our solutions have long sales cycles, which may reduce the predictability of our financial performance. Our solutions are technologically complex and are typically intended for use in applications that may be critical to the business of our customers. As a result, our pre-sales process can be subject to delays associated with customers’ budgetary constraints and lengthy approval and procurement processes. The sales cycles of our solutions to large customers can last for as long as 12 months (and in some cases even longer, for example, with carrier customers) from initial presentation to sale. Long sales cycles result in a delay to our generation of revenue. Long sales cycles also subject us to risks not usually encountered in short sales cycles, including our customers’ budgetary constraints and internal acceptance reviews and processes prior to purchase. In addition, orders expected in one quarter have in the past on several occasions, and could in the future, shift to another because of the timing of our customers’ procurement decisions. Furthermore, customers may defer orders in anticipation of new solutions or product enhancements introduced by us or by our competitors. These factors complicate our planning processes and reduce the predictability of our financial performance. 21 We may pursue acquisitions or other investments that could disrupt our business and harm our financial condition. As part of our business strategy, we may invest in or acquire complimentary businesses, technologies or assets or enter into joint ventures or other strategic relationships with third parties. Past acquisitions have caused, and future acquisitions may cause, us to assume liabilities, incur acquisition-related costs, incur amortization expenses or realize write-offs on assets no longer being used or phased out. In addition, the future valuation of these acquisitions may decrease from the market price paid by us, which could result in the impairment of our goodwill and other intangible assets associated with the relevant acquired assets. Moreover, our operation of any acquired or merged businesses, technologies or assets could involve numerous risks, including: • post-merger integration problems resulting from the combination of any acquired operations with our own operations or from the combination of two or more operations into a new unified entity; • diversion of management’s attention from our core business; • substantial expenditures, which could divert funds from other corporate uses; • entering markets in which we have little or no experience; • loss of key employees of the acquired operations; and • known or unknown contingent liabilities, including, but not limited to, tax and litigation costs. We cannot be certain that any past or future acquisitions or mergers will be successful. If the operation of the business of any future acquisitions or mergers disrupts our operations, our results of operations may be adversely affected, and even if we successfully integrate the acquired business with our own, we may not receive the intended benefits of the acquisition. In addition, our pursuit of potential acquisitions may divert our management’s attention from our core business and require considerable cash outlays at the expense of our existing operations, whether or not such transactions are consummated. A failure of any acquisitions or product developments to produce increased revenues could have a material adverse effect on our operations and profitability. Our business in countries with a history of corruption and transactions with foreign governments increases the risks associated with our international activities. As we operate and sell internationally, we are subject to the Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.K. Bribery Act of 2010 (the “UK Bribery Act”) and other laws that prohibit improper payments or offers of payments to foreign governments and their officials and political parties for the purpose of obtaining or retaining business. We have operations, deal with and make sales to governmental customers in countries known to experience corruption, particularly certain emerging countries in Eastern Europe, South and Central America, East Asia, Africa and the Middle East. Our activities in these countries create the risk of unauthorized payments or offers of payments by one of our employees, consultants, channel partners or sales agents that could be in violation of various anti-corruption laws, even though these parties may not be under our control. The safeguards we have implemented or may implement in the future to prevent these practices by our employees, consultants, channel partners and sales agents may prove to be less than effective, and our employees, consultants, channel partners or sales agents may engage in conduct for which we might be held responsible. Violations of the FCPA, the UK Bribery Act or other anti-corruption laws may result in severe criminal or civil sanctions, including suspension or debarment from government contracting, and we may be subject to other liabilities, which could negatively affect our business, operating results, and financial condition. 22 Currency exchange rates and fluctuations of exchange rates could have a material adverse effect on our results of operations. We are impacted by exchange rates and fluctuations thereof in a number of ways, including: • A large portion of our expenses in Israel, principally salaries and related personnel expenses, are paid in NIS, whereas most of our revenues are generated in U.S. dollars. When the U.S. dollar is weak, our foreign currency-denominated expenses will be higher, whereas if the U.S. dollar is strong, our foreign currency-denominated expenses will be lower. If the NIS strengthens against the U.S. dollar, the dollar value of our Israeli expenses will increase and may have a material adverse effect on our business, operating results, and financial condition; • A portion of our international sales are denominated in currencies other than U.S. dollars, such as euros, thereby exposing us to currency fluctuations in such international sales transactions; • We incur expenses in several other currencies in connection with our operations in Europe and Asia. Devaluation of the U.S. dollar relative to such local currencies causes our operational expenses to increase; and • The majority of our international sales are denominated in U.S. dollars. Accordingly, devaluation in the local currencies of our customers relative to the U.S. dollar could cause our customers to decrease orders or default on payment. Undetected defects and errors may increase our costs and impair the market acceptance of our products. Our products have occasionally contained, and may in the future contain, undetected defects or errors, especially when first introduced or when new versions are released, due to defects or errors that we fail to detect, including in components supplied to us by third parties. These defects or errors may be found after the commencement of commercial shipments. In addition, because our customers integrate our products into their networks with products from other vendors, it may be difficult to identify the product that has caused the problem in the network. Regardless of the source of these defects or errors, we will then need to divert the attention of our engineering personnel from our product development efforts to detect and correct these errors and defects. We cannot assure you whether we will incur significant warranty or repair costs, be subject to liability claims for material damages related to product errors or defects or experience any material lags or delays as a result thereof in the future. Any insurance coverage that we maintain may also not provide sufficient protection should a claim be asserted. Moreover, the occurrence of errors and defects, whether caused by our products or the components supplied by another vendor, may result in significant customer relations problems and injure our reputation, thereby impairing the market acceptance of our products. 23 Our business and operating results could suffer if third parties infringe upon our proprietary technology. Our success depends, in part, upon the protection of our proprietary software installed in our products, our trade secrets and trademarks. We seek to protect our intellectual property rights through a combination of trademark and patent law, trade secret protection, confidentiality agreements, and other contractual arrangements with our employees, affiliates, distributors, and others. In the United States and several other countries, we have registered or acquired trademarks. In addition, we have registered patents in the U.S. and other jurisdictions and have pending patent applications and provisional patents in connection with several of our products’ features. The protective steps we have taken may be inadequate to deter infringement upon our intellectual property rights or misappropriation of our proprietary information. We may be unable to detect the unauthorized use of our proprietary technology or take appropriate steps to enforce our intellectual property rights. Effective trademark, patent and trade secret protection may not be available in every country in which we offer, or intend to offer, our products. In addition, our competitors may independently develop technologies that are substantially equivalent or superior to our technology. Any licenses for intellectual property that might be required for our services or products may not be available on reasonable terms. Failure to adequately protect our intellectual property rights could devalue our proprietary content, impair our ability to compete effectively, and eventually harm our operating results. Furthermore, defending our intellectual property rights, either by way of initiating intellectual property litigation or defending such, could result in the expenditure of significant financial and managerial resources. Moreover, any adverse outcome of litigation proceedings could impact the value of our proprietary technology and have additional significant financial impacts, which may harm our operating results. Our products may infringe on the intellectual property rights of others. Third parties may assert claims that we have violated a patent, trademark, copyright or other proprietary intellectual property right belonging to them. As is characteristic of our industry, there can be no assurance that our products do not or will not infringe the proprietary rights of third parties, that third parties will not claim infringement by us with respect to patents or other proprietary rights, or that we would prevail in any such proceedings. We have received in the past, and may receive in the future, communications asserting that the technology used in some of our products requires third-party licenses. Any infringement claims, whether or not meritorious, could result in significant costly litigation or arbitration and divert the attention of technical and management personnel. Any adverse outcome in litigation alleging infringement could require us to develop non-infringing technology or enter into royalty or licensing agreements. If, in such situations, we are unable to obtain licenses on acceptable terms, we may be prevented from manufacturing or selling products that infringe such intellectual property of a third party. An unfavorable outcome or settlement regarding one or more of these matters could have a material adverse effect on our business, reputation and operating results. Laws, regulations and industry standards affecting our business are evolving, and unfavorable changes could harm our business. We are required to comply with stringent, complex and evolving laws, rules, regulations and standards in many jurisdictions, as well as contractual obligations, relating to data privacy and security because we receive, store, use and otherwise process personal information from our employees, customers, the employees of our customers and our end users. Laws, regulations and industry standards that apply to our business are becoming more prevalent and constantly evolving, particularly in the area of data and cybersecurity. We may be impacted by changes in privacy-related and cybersecurity-related regulations governing the collection, use, retention, sharing and security of personal data that we collect, utilize, or otherwise process from our customers and/or visitors to their websites and others. Complying with a diverse range of privacy and cybersecurity requirements could cause us to incur substantial costs or require us to change our business practices in a manner adverse to our business. Any failure, or perceived failure, by us to comply with any privacy or cybersecurity-related laws, government regulations or directives, or industry self-regulatory principles could result in damage to our reputation or proceedings or actions against us by governmental entities or others, which could potentially have an adverse effect on our business. 24 Given the global nature of our operations, we are subject to a variety of local, state, national, and international laws and directives and regulations related to privacy and data protection, data security, data storage and retention, data transfer and deletion, and technology protection. These laws may include, among others, the following: • The European General Data Protection Regulation (“GDPR”). • UK General Data Protection Regulation and the UK Data Protection Act 2018 (“UK DP Laws”). • EU laws and directives, including the Digital Operational Resilience Act (“DORA”), the Digital Services Act, the Network and Information Security Directive II and the Cyber Resilience Act (“CRA”). • U.S. state and federal laws, including the California Consumer Privacy Act (“CCPA”) and follow-on legislation in the California Privacy Rights Act (“CPRA”). For example, in the European Economic Area (EEA), we are subject to the GDPR and in the United Kingdom we are subject to the United Kingdom data protection regime consisting primarily of the UK DP Laws, in each case in relation to our collection, control, processing, sharing, disclosure and other use of data relating to an identifiable living individual (personal data). The GDPR, and national implementing legislation in EEA member states and the United Kingdom, impose a strict data protection compliance regime. GDPR and UK DP Laws can expose us to enforcement actions and investigations by regulatory authorities and potentially result in regulatory penalties and significant legal liability, if our information technology security efforts fail and if we fail to disclose any material cybersecurity incident in an adequate and timely manner. Accordingly, a data security breach or privacy violation that leads to unauthorized access to, disclosure or modification of personal information, that prevents access to personal information or materially compromises the privacy, security, or confidentiality of the personal information, could result in fines, increased costs or loss of revenue. Our compliance with GDPR and UK DP Laws, as well as other data privacy and cybersecurity laws around the world, evolving regulations of cloud computing, cross-border data transfer restrictions and other domestic or foreign regulations, has required and will continue to require us to invest significant resources in compliance and compliance-related areas. 25 Furthermore, laws, regulations and industry standards are subject to constant and, at times, drastic changes that, particularly in the case of industry standards, may arrive with little or no notice, and these could either help or hurt the demand for our solutions. If we are unable to adapt our solutions to changing laws, regulations and industry standards in a timely manner, or if our solutions fail to assist our customers with their compliance initiatives, our customers may lose confidence in our solutions and could switch to competing solutions. Recent legal developments in Europe have created complexity and uncertainty regarding transfers of personal data from the EEA and the United Kingdom to the United States. These recent developments may require us to review and amend the legal mechanisms by which we make and/or receive personal data transfers to or in the U.S. Such legal developments also cause us to look at our operations and review our data flows to ensure we can continue to meet clients’ increasing requests for data to remain in-country or in-region. Further, the GDPR is also subject to change, and it is possible that it may be interpreted and applied in a manner that is inconsistent with our practices and our efforts to comply with the evolving data protection rules may be unsuccessful. For example, the European Data Protection Board continues to release guidelines for industries and impose fines related to the GDPR, some of which have been very significant, including proposed amendments to the GDPR in November 2025. At the same time, if, contrary to this trend, regulations and standards related to cybersecurity are changed in a manner that makes them less onerous, our customers may view government and industry regulatory compliance as less critical to their businesses, and our customers may purchase fewer of our solutions, or none at all. In either case, our sales and financial results would be negatively impacted and could be materially adversely affected. Additionally, if third parties we work with, such as sub-processors, vendors or developers, violate applicable laws or regulations, contractual obligations or our policies - or if it is perceived that such violations have occurred - such actual or perceived violations may also have an adverse effect on our business. Further, any significant change to applicable laws, regulations or industry practices regarding the collection, use, retention, security, disclosure or other processing of users’ content, or regarding the manner in which the express or implied consent of users for the collection, use, retention or other processing of such content is obtained, could increase our costs and require us to modify our network, products and features, possibly in a material manner, which we may be unable to complete, and may limit our ability to store and process customer data or develop new products and features. For more information, see Item 4.B. "Business Overview – Government Regulations – Data Privacy and Data Protection." Some of our solutions contain “open source” and third-party software, and any failure to comply with the terms of one or more of these open source and third-party software licenses could negatively affect our business. Some of our products utilize open source technologies. Some open source software licenses require users who distribute or make available as a service open source software as part of their own software product to publicly disclose all or part of the source code of the users’ software product or to make available any derivative works of the open source code on unfavorable terms or at no cost. We cannot be sure that all open source software is submitted for approval prior to use in our products and while we scan the open-source software that we use in our products and patch discovered vulnerabilities, we have no assurance that they will be free from vulnerabilities or malicious code. The use of open-source software in our solutions may expose us, and our customers using our solutions, to additional vulnerabilities and security breaches, which may result in significant adverse impacts to us and our customers. In addition, open source license terms may be ambiguous and many of the risks associated with use of open source software cannot be eliminated, and could, if not properly addressed, negatively affect our business. We may face ownership claims from third parties over, or seeking to enforce the license terms applicable to, such open source software, including by demanding the release of the open source software, derivative works or our proprietary source code. Any such requirement to disclose our source code or other confidential information related to our products could materially and adversely affect our competitive position and may adversely impact our business, results of operations and financial condition. In addition, if the license terms for the open source code change, we may be forced to re-engineer our software or incur additional costs. In addition, some of our solutions include other software or intellectual property licensed from third parties. This exposes us to risks over which we may have little or no control. There can be no assurance that the licenses from such third-party licensors will continue to be available to us on acceptable terms, if at all. In addition, while we believe we are compliant with the terms of our third-party licenses, such licensors may still assert that we are in breach of the terms of a license, which could give such licensors the right to terminate a license or seek damages from us, or both. Our inability to maintain such licenses or the need to engage in litigation regarding these matters, could result in delays in releases of new products, and could otherwise disrupt our business, unless and until equivalent technology can be identified, licensed, or developed at substantially the same costs to us. 26 The amount of intangible assets and goodwill on our books may in the future lead to significant impairment charges. The amount of goodwill and intangible assets on our consolidated balance sheets was, as of December 31, 2025, approximately $75.8 million, compared to $79.8 million as of December 31, 2024. We regularly review our intangible and tangible assets, including goodwill, for impairment. Goodwill is subject to impairment review at least annually, and other intangible assets are reviewed for impairment when there is an indication that impairment may have occurred. Impairment testing has led to, and may in the future lead to, significant impairment charges. Additional tax liabilities, including due to tax positions we have taken, could materially adversely affect our results of operations and financial condition. We operate our business in various countries, and we attempt to utilize an efficient operating model to optimize our tax payments based on the laws in the countries in which we operate. This can cause disputes between us and various tax authorities in the countries in which we operate, whether due to tax positions that we have taken in various tax returns we have filed or due to determinations we have made not to file tax returns in certain jurisdictions. In particular, not all of our tax returns are final and may be subject to further audit and assessment by applicable tax authorities. There can be no assurance that the applicable tax authorities will accept our tax positions, and, if they do not, we may be required to pay additional taxes. In the past few years, certain tax authorities who have audited our tax returns have rejected our tax positions, and we cannot be sure that our positions will be accepted, and we may end up paying additional taxes, whether as a result of litigation, if instituted, or settlement negotiations. Our reserves, which are based on various assumptions and estimates, may prove to be insufficient and as such, our future results may be adversely affected. In recent years, we have seen changes in tax laws resulting in an increase in applicable tax rates, especially increased liabilities of corporations and limitations on the ability to benefit from strategic tax planning, with these laws particularly focused on international corporations. Such legislative changes in one or more jurisdictions in which we operate may have implications on our tax liability and may have a material adverse effect on our results of operations and financial condition. Moreover, in 2015, the Organization for Economic Co-operation and Development (“OECD”) released various reports under its Base Erosion and Profit Shifting (“BEPS”) action plan to reform international tax systems and prevent tax avoidance and aggressive tax planning. These actions aim to standardize and modernize global corporate tax policy, including cross-border taxes, transfer-pricing documentation rules and nexus-based tax incentive practices which in part are focused on challenges arising from the digitalization of the economy. The reports have a very broad scope including, but not limited to, neutralizing the effects of hybrid mismatch arrangements, limiting base erosion involving interest deductions and other financial payments, countering harmful tax practices, preventing the granting of treaty benefits in inappropriate circumstances and imposing mandatory disclosure rules. It is the responsibility of OECD members to consider how the BEPS recommendations should be reflected in their national legislation. Many countries are beginning to implement legislation and other guidance to align their international tax rules with the OECD’s BEPS recommendations, for example, by signing up to the Multilateral Convention to Implement Tax Treaty Related Measures to Prevent BEPS (“MLI”) which currently has been signed by over 100 jurisdictions, including Israel, who deposited its instrument of ratification to implement the MLI on September 13, 2018. 27 The MLI implements some of the measures that the BEPS initiative proposes to be transposed into existing treaties of participating states. Such measures include the inclusion in tax treaties of one, or both, of a “limitation-on-benefit” (“LOB”) rule and a “principal purposes test” (“PPT”) rule. The application of the LOB rule or the PPT rule could deny the availability of tax treaty benefits (such as a reduced rate of withholding tax) under tax treaties. In addition, the OECD has been working on proposals, commonly referred to as “BEPS 2.0,” which would make important changes to the international tax system, by allocating taxing rights in respect of certain profits of multinational enterprises above a fixed profit margin to the jurisdictions within which they carry on business (subject to threshold rules) and imposing a minimum effective tax rate on certain multinational enterprises. The rules for a global minimum tax have been implemented in a number of jurisdictions with effect from 2024. There have been and are likely to be significant changes in the tax legislation of various OECD jurisdictions during the period of implementation of BEPS or BEPS 2.0. In line with the above-mentioned global developments in international taxation, the State of Israel has recently enacted the Law for the Taxation of Multinational Enterprise Groups – 2025, entered into force on January 1, 2026, implementing key aspects of the OECD’s Pillar Two framework. In particular, the legislation introduces a domestic minimum top-up tax (Qualified Domestic Minimum Top-Up Tax – QDMTT) generally applicable to Israeli entities that are part of multinational enterprise groups with consolidated annual revenues of at least EUR 750 million, with the objective of ensuring a minimum effective tax rate of 15% on profits attributable to activities in Israel and preventing the allocation of taxing rights to foreign jurisdictions under the Income Inclusion Rule or the Undertaxed Profits Rule. It is noted that the Israeli Ministry of Finance has published an additional draft legislation as part of its 2026 Economic Plan, proposing a revised incentive regime for research and development activities in Israel, structured primarily as refundable or credit-based tax incentives designed to qualify under the OECD’s “qualified” incentive criteria in a Pillar Two environment. The OECD continues to release additional guidance and the Company intends to continue monitoring the new rules and country agreements. While certain BEPS initiatives are in the final stages of approval and/or implementation, we cannot comprehensively predict their outcome or what impact they will have on our tax obligations and operations or our financial statements, up to their final enactment in national and international legislation. Such legislative initiatives may materially and adversely affect our plans to expand internationally and may negatively impact our financial condition, tax liability or results of operations and could increase our administrative efforts. The enactment of legislation changing the United States’ taxation of international business activities could materially impact our financial condition and results of operations. Due to the expansion of our international business activities, any changes in the U.S. taxation of such activities may increase our worldwide effective tax rate, and adversely affect our financial condition and results of operations. For example, the Inflation Reduction Act of 2022 enacted in the United States introduced, among other changes, a 15% corporate minimum tax on certain United States corporations and a 1% excise tax on certain stock redemptions by United States corporations (which the U.S. Treasury indicated may also apply to certain stock redemptions by a foreign corporation funded by certain United States affiliates). Significant changes or developments in U.S. laws and policies, such as laws and policies surrounding international trade, foreign affairs, manufacturing and development and investment in the territories and countries where we or our customers operate, can materially adversely affect our business, results of operations, and financial condition. The U.S. government has imposed (in certain cases, subject to deferral) significant tariffs on imports from certain jurisdictions and indicated the likely imposition of or significant increases in tariffs on goods imported into the United States from many other jurisdictions in the future, which could lead to corresponding punitive actions by the countries with which the U.S. trades. Further the U.S. presidential administration has indicated the intent to propose significant changes to the U.S. tax system. Many aspects of these potential proposals are unclear or undeveloped and we are unable to predict which, if any, changes to the U.S. tax system will be enacted into law, and what effects any enacted legislation might have on our tax liabilities. In addition, the U.S. presidential administration has indicated that the United States may impose retaliatory measures with respect to jurisdictions that have, or are likely to, put in place tax rules that are extraterritorial or disproportionately affect American companies. The likelihood of these changes being enacted or implemented is unclear. Further, other foreign governments may enact tax laws in response to any changes in the U.S. taxation of international business activities that could result in further changes to global taxation and materially affect our financial condition and results of operations. We are currently unable to predict whether these or other changes will occur and, if so, the ultimate impact on our business. To the extent that such changes have a negative impact on us, our suppliers or our consumers, including as a result of related uncertainty, these changes may materially and adversely impact our business, financial condition, results of operations and cash flow. 28 Complications with the design or implementation of our new ERP system, or major disruptions or deficiencies of our other information technology systems, could adversely impact our business and operations. We rely extensively on information systems and technology to manage our business and summarize operating results. In January 2025, we have implemented a new cloud-based global ERP system. The new ERP system implementation process has required, and will continue to require, the investment of significant personnel and financial resources. Due to the new ERP system implementation process, we may experience delays, increased costs and other difficulties. Our reporting timelines might be delayed, the effectiveness of our internal control over financial reporting could be adversely affected, and/or our ability to assess those controls adequately could be delayed. In addition, any major disruptions or deficiencies in the design and implementation of our other information technology systems, particularly those that impact our operations, could adversely affect our ability to run our business. In 2025, we also completed the migration of our on‑premises data warehouse and business intelligence systems to a cloud‑based environment. This transition may expose us to risks inherent in the use of cloud computing technologies. These risks include, among others, potential vulnerabilities arising from misconfigurations, unauthorized access, data breaches, or service disruptions affecting cloud service providers. The reliance on third‑party technology vendors increases exposure to operational and cybersecurity risks beyond our direct control. Furthermore, the use of cloud infrastructure may expand the potential attack surface and heighten threats associated with data integrity, confidentiality, and regulatory compliance. We continue to evaluate, monitor, and enhance our information security and vendor management programs to mitigate these risks; however, we cannot assure you that such measures will be sufficient to prevent or detect all possible threats or incidents. We rely on information technology systems to conduct our businesses, and failure to protect these systems against security breaches and otherwise to implement, integrate, upgrade and maintain such systems in working order could have a material adverse effect on our results of operations, cash flows or financial condition. The efficient operation of our businesses depends on our computer hardware and software systems. For instance, we rely on information technology systems, including our new ERP system, to process customer orders and invoices, manage accounts receivable collections, manage accounts payable processes, track costs and operations, calculate revenues and expenses, monitor client relationships and accumulate financial results. Despite our implementation of industry-accepted security measures and technology, our information technology systems are vulnerable to, and have been in the past subject to, computer viruses, attempts to insert malicious codes, unauthorized access, phishing efforts, denial-of-service attacks and other cyber-attacks, and we expect to be subject to similar attacks in the future as such attacks become more sophisticated and frequent. A breach of our information technology systems could result in decreased performance, operational difficulties and increased costs, any of which could have a material adverse effect on our business and operating results. 29 Our business may be affected by sanctions, export controls and similar measures targeting Russia and other countries and territories, as well as other responses to Russia’s military conflict in Ukraine, including indefinite suspension of operations in Russia and dealings with Russian entities by many multi-national businesses across a variety of industries. As a result of Russia’s military conflict in Ukraine, governmental authorities in the United States, the European Union and the United Kingdom, among others, launched an expansion of coordinated sanctions and export control measures, including, for example: • blocking sanctions on some of the largest state-owned and private Russian financial institutions (and their subsequent removal from SWIFT); • blocking sanctions against Russian and Belarusian individuals, including the Russian President, other politicians and those with government connections or involved in Russian military activities; • blocking sanctions against persons operating in the technology sector of the Russian economy, including companies providing or receiving goods or services related to the Russian technology sector, and financial institutions conducting or facilitating significant transactions involving such parties; • blocking sanctions against certain Russian businessmen and their businesses, some of which have significant financial and trade ties to the European Union; • blocking of Russia’s foreign currency reserves and prohibition on secondary trading in Russian sovereign debt and certain transactions with the Russian Central Bank, National Wealth Fund and the Ministry of Finance of the Russian Federation; • expansion of sectoral sanctions in various sectors of the Russian and Belarusian economies and the defense sector; • United Kingdom sanctions introducing restrictions on providing loans to, and dealing in securities issued by, persons connected with Russia; • restrictions on access to the financial and capital markets in the European Union, as well as prohibitions on aircraft leasing operations; • sanctions prohibiting most commercial activities of U.S., U.K., and E.U. persons in the so-called People’s Republic of Donetsk and the so-called People’s Republic of Luhansk (and, with respect to the E.U., the areas of Kherson and Zaporizhzhia not controlled by the Ukrainian government), with all of these new restrictions largely tracking prior prohibitions relating to Crimea and Sevastopol; • enhanced import and export controls and trade sanctions targeting Russia’s imports of technological goods, including E.U. and U.K. prohibitions on exporting a wide range of “industrial” goods to Russia (and on importing a large number of “revenue-generating” goods from Russia). The restrictions also include bans on the export of large numbers of “luxury” items to Russia (and in some cases also to Belarus), tighter controls on exports and reexports of dual-use items, stricter licensing policy with respect to issuing export licenses, and/or increased use of “end-use” controls to block or impose licensing requirements on exports, as well as higher import tariffs; 30 • closure of airspace to Russian aircraft; • ban on imports of Russian oil, liquefied natural gas and coal to the United States; • ban on imports of Russian fish, seafood, and preparations thereof, alcoholic beverages, non-industrial diamonds, and gold to the United States; • a ban on “new investment” in the Russian Federation by a U.S. person, which may be interpreted broadly (with a similar prohibition also enacted by the United Kingdom); • bans on the provision of certain professional services, including accounting, trust and corporate formation, auditing, and management consulting services, among others; and • bans on the provision of services related to the worldwide maritime transportation of seaborne Russian oil, if purchased above a specific price cap. As the conflict in Ukraine continues, there can be no certainty regarding whether the governmental authorities in the United States, the European Union, the United Kingdom or other counties will impose additional sanctions, export controls or other measures targeting Russia, Belarus or other territories. Furthermore, in retaliation against new international sanctions and as part of measures to stabilize and support the volatile Russian financial and currency markets, the Russian authorities also imposed significant currency control measures aimed at restricting the outflow of foreign currency and capital from Russia, imposed various restrictions on transacting with non-Russian parties, banned exports of various products and imposed other economic and financial restrictions. Our business must be conducted in compliance with applicable economic and trade sanctions laws and regulations, including those administered and enforced by the U.S. Department of Treasury’s Office of Foreign Assets Control, the U.S. Department of State, the U.S. Department of Commerce, the United Nations Security Council and other relevant governmental authorities. We must be ready to comply with the existing and any other potential additional measures imposed in connection with the conflict in Ukraine. The imposition of such measures could adversely impact our business, including preventing us from performing existing contracts, recognizing revenue, pursuing new business opportunities or receiving payment for products already supplied or services already performed with customers. In 2025 and 2024, 2% and 3% of our total revenues were from sales to customers located in Russia, respectively. We continuously review and monitor our contractual relationships with suppliers and customers to establish whether any of them are the target of the applicable sanctions. In the event that we identify a party with which we have a business relationship that is the target of applicable sanctions, we would immediately activate a legal analysis of what gives rise to the business relationship, including any contract, to estimate the most appropriate course of action to comply with the sanction regulations, together with the impact of a contractual termination according to the applicable law, and then proceed as required by the regulatory authorities. However, given the range of possible outcomes, the full costs, burdens, and limitations on our and our customer’s and business partners’ businesses are currently unknown and may become significant. Furthermore, even if an entity is not formally subject to sanctions, customers and business partners of such entity may decide to reevaluate or cancel projects with such entity for reputational or other reasons. As a result of the ongoing conflict in Ukraine, many U.S. and other multi-national businesses across a variety of industries, including consumer goods and retail, food, energy, finance, media and entertainment, tech, travel and logistics, manufacturing and others, have indefinitely suspended their operations and paused all commercial activities in Russia and Belarus. Depending on the extent and breadth of sanctions, export controls and other measures that may be imposed in connection with the conflict in Ukraine, it is possible that our business, financial condition, and results of operations could be materially and adversely affected. 31 Finally, any deterioration in relations between Taiwan and China could lead to additional sanctions or export controls on China, on specific individuals or entities, or otherwise in the region which could impact our ability to sell to certain of our customers, source components from China or other impacted countries, or otherwise negatively impact our business. Our disclosures and initiatives related to environmental, social and governance (ESG) matters, including those related to climate change and sustainability, expose us to numerous risks, including risks to our reputation, business, financial performance and growth. There has been increasing public focus by investors, customers, employees, policymakers, environmental activists, the media and governmental and nongovernmental organizations, as well as other stakeholders, on a variety of ESG matters, which may increase costs (including but not limited to increased costs related to compliance, stakeholder engagement, and contracting), impact our reputation, or otherwise affect our business performance. As we identify ESG topics for voluntary disclosure, we have expanded and, in the future, may continue to expand, our voluntary disclosures in these areas. Statements about our ESG initiatives and goals, and progress against those goals, may be based on standards for measuring progress that are still developing, internal controls and processes that continue to evolve, and assumptions that are subject to change in the future. As a result, we cannot guarantee that our approach will align with any particular stakeholder’s expectations or preferences. If our ESG-related data, processes and reporting are incomplete or inaccurate, or if we fail to achieve progress with respect to our ESG goals on a timely basis, or at all, our reputation, business, financial performance and growth could be adversely affected. Moreover, various stakeholders have different, and at times conflicting expectations. If we do not meet the evolving and varied expectations of our stakeholders with respect to ESG-related matters, we could experience loss of customers or contracts, reputational harm, or other negative impacts on our business and results of operations. In addition, proponents and opponents of ESG matters are increasingly resorting to activism, including litigation, to advance their perspectives, which will be costly for us to address. We have in the past, and may in the future, become subject to litigation or claims arising in or outside the ordinary course of business that could negatively affect our business operations and financial condition. We have in the past, and may in the future, become subject to litigation or claims arising in or outside the ordinary course of business that could negatively affect our business operations and financial condition, including securities class actions and shareholder derivative actions, both of which are typically expensive to defend. Such claims and litigation proceedings may be brought by third parties, including our competitors, advisors, service providers, partners or collaborators, employees, shareholders, and governmental or regulatory bodies. Any claims and lawsuits, and the disposition of such claims and lawsuits, could be time-consuming and expensive to resolve, divert management attention and resources, and lead to attempts on the part of other parties to pursue similar claims. We may not be able to determine the amount of any potential losses and other costs we may incur due to the inherent uncertainties of litigation and settlement negotiations. In the event we are required or decide to pay amounts in connection with any claims or lawsuits, such amounts could be significant and could have a material adverse impact on our liquidity, business, financial condition and results of operations. In addition, depending on the nature and timing of any such dispute, a resolution of a legal matter could materially affect our future operating results, our cash flows or both. Additionally, we may be unable to maintain directors’ and officers’ liability insurance at satisfactory rates or adequate coverage amounts and may incur significant increases in insurance costs. 32 Risks Related to the Market for Our Ordinary Shares The estate of the late Yehuda Zisapel, along with Nava Zisapel and Roy Zisapel, our President, Chief Executive Officer and a director, may exert significant influence in the election of our directors and over the outcome of other matters requiring shareholder approval. As of March 20, 2026, the estate of the late Yehuda Zisapel beneficially owned approximately 2.5% of our outstanding ordinary shares, which is held in two equal parts by Roy Zisapel’s siblings (namely, Carmi Zisapel and Adi Zisapel); Nava Zisapel beneficially owned approximately 6.9% of our outstanding ordinary shares; and their son, Roy Zisapel (our President, Chief Executive Officer and a director), beneficially owned approximately 5.9% of our outstanding ordinary shares (which includes one third of our outstanding ordinary shares of the estate of the late Yehuda Zisapel) (see Items 6.E “Share Ownership” and 7.A “Major Shareholders”). As a result, if these shareholders act together, they could exert significant influence on the election of our directors and on decisions by our shareholders on matters submitted to shareholder vote, including mergers, consolidations and the sale of all or substantially all of our assets. This concentration of ownership of our ordinary shares could delay or prevent proxy contests, mergers, tender offers, or other purchases of our ordinary shares that might otherwise give our shareholders the opportunity to realize a premium over the then-prevailing market price for our ordinary shares. This concentration of ownership may also adversely affect our share price. Provisions of our Articles of Association and Israeli law as well as the terms of our equity incentive plan could delay, prevent or make a change of control of us more difficult or costly, which could depress the price of our ordinary shares. The provisions in our Articles of Association relating to the election of our directors in three staggered classes, the submission of shareholder proposals for shareholder meetings and the quorum requirement for adjourned shareholder meetings may have the effect of delaying or making an unsolicited acquisition of our Company more difficult. Israeli corporate and tax laws, including the ability of our Board of Directors to adopt a shareholder rights plan without shareholder approval, may also have the effect of delaying, preventing or making an acquisition of us more difficult. For example, under the Companies Law, upon the request of a creditor of either party to a proposed merger, an Israeli court may delay or prevent the merger if it concludes that there is a reasonable concern that, as a result of the merger, the surviving company will be unable to satisfy the obligations of any of the parties to the merger. In addition, our Key Employee Share Incentive Plan (1997), as amended (the “Share Incentive Plan”), provides that, in the event of a “Hostile Takeover” (which is defined to include, among others, an unsolicited acquisition of more than 20% of our outstanding shares), the vesting of all or a portion of our outstanding equity awards will accelerate, unless otherwise determined by our Board of Directors (or a committee thereof). As a result, an acquisition of our Company that triggers the said acceleration will be more costly to a potential acquirer. These provisions could cause our ordinary shares to trade at prices below the price for which third parties might be willing to pay to gain control over us. Third parties who are otherwise willing to pay a premium over prevailing market prices to gain control of us may be unwilling to do so because of these provisions. 33 Our share price has been volatile in the past and may be subject to volatility in the future. The market price for our ordinary shares, as well as the prices of shares of other technology companies, has been volatile. For example, during 2025, the lowest closing price of our share was $19.43, compared to the highest closing price of our share of $30.80 during the same year. The volatility of our share price may have a negative impact on our financial performance as a result of its negative impact on employee retention. Numerous factors, many of which are beyond our control, may cause the market price and trading volume of our ordinary shares to fluctuate significantly and decrease further, including: • operating results that do not meet forecasts by securities analysts; • announcements concerning us or our competitors; • the introduction of new products and new industry standards; • general market conditions and changes in market conditions in our industry; • the general state of securities markets (particularly the technology sector); • political, economic and other developments in the State of Israel, the U.S. and worldwide, including, for example, the Ukraine-Russia conflict and uncertainty and conflicts between Israel and Hamas, Israel and Hezbollah and Israel and Iran; and • any of the events underlying any of the other risks or uncertainties set forth elsewhere in this annual report actually occurs. If we are characterized as a passive foreign investment company, our U.S. shareholders may suffer adverse tax consequences. Generally, if for any taxable year, after applying certain “look through” tax rules, (i) 75% or more of our gross income is passive income, or (ii) at least 50% of the fair market value of our assets, averaged quarterly over our taxable year, are held for the production of, or produce, passive income, we would be characterized as a passive foreign investment company (“PFIC”), for U.S. federal income tax purposes. If we are classified as a PFIC, our U.S. shareholders could suffer adverse U.S. tax consequences, including having gain realized on the sale of our ordinary shares treated as ordinary income, as opposed to capital gain income, and having potentially punitive interest charges apply to such gain. Similar rules would apply to certain “excess distributions” made with respect to our ordinary shares. For our taxable year ended December 31, 2025, we do not believe that we should be classified as a PFIC. There can be no assurance, however, that the IRS will not challenge this treatment, and it is possible that the IRS could attempt to treat us as a PFIC for 2025 and prior taxable years. The tests for determining PFIC status are applied annually, and require a factual determination that depends on, among other things, the composition of our income, assets and activities in each taxable year, and can only be made annually after the close of each taxable year. Furthermore, the aggregate value of our gross assets is likely to be determined in part by reference to the trading price of our ordinary shares, which could fluctuate significantly. We have a substantial balance of cash and other liquid investments, which are passive assets for purposes of the PFIC determination. Accordingly, if our market capitalization declines significantly, it may make our classification as a PFIC more likely for the current or future taxable years. Accordingly, there can be no assurance that we will not become a PFIC in future taxable years. U.S. shareholders should consult with their U.S. tax advisors with respect to the U.S. tax consequences of investing in our ordinary shares. For a more detailed discussion of the rules relating to PFICs and related tax consequences, please see the section of this annual report titled Item 10.E “Taxation—United States Federal Income Tax Considerations.” 34 If a U.S. person is treated as owning at least 10% of our ordinary shares, such holder may be subject to adverse U.S. federal income tax consequences. Depending upon the aggregate value and voting power of our ordinary shares that U.S. persons are treated as owning (directly, indirectly, or constructively), we could be treated as a controlled foreign corporation (a “CFC”). Additionally, because our group consists of one or more U.S. subsidiaries, certain of our non-U.S. subsidiaries will be treated as CFCs, regardless of whether or not we are treated as a CFC. If a U.S. person is treated as owning (directly, indirectly or constructively) at least 10% of the value or voting power of our ordinary shares, such person may be treated as a “U.S. shareholder” with respect to each CFC in our group (if any), which may subject such person to adverse U.S. federal income tax consequences. Specifically, a U.S. shareholder of a CFC may be required to annually report and include in its U.S. taxable income its pro rata share of each CFC’s “Subpart F income,” “global intangible low-taxed income” and investments in U.S. property, whether or not we make any distributions of profits or income of a CFC to such U.S. shareholder. If you are treated as a U.S. shareholder of a CFC, failure to comply with these reporting obligations may subject you to significant monetary penalties and may prevent the statute of limitations with respect to your U.S. federal income tax return for the year for which reporting was due from starting. Additionally, a U.S. shareholder that is an individual would generally be denied certain tax deductions or indirect foreign tax credits that may otherwise be allowable to a U.S. shareholder that is a U.S. corporation. We cannot provide any assurances that we will assist investors in determining whether we or any of our non-U.S. subsidiaries are treated as CFCs or whether any investor is treated as a U.S. shareholder with respect to any of such CFC, nor do we expect to furnish to any U.S. shareholders information that may be necessary to comply with the aforementioned reporting and tax paying obligations. The United States Internal Revenue Service provided limited guidance on situations in which investors may rely on publicly available alternative information to comply with their reporting and tax paying obligations with respect to foreign-controlled CFCs. U.S. investors should consult their advisors regarding the potential application of these rules to their investment in our ordinary shares. We are a foreign private issuer and, as a result, we are subject to reporting obligations and corporate governance practices that, to some extent, are more lenient than those of a U.S. domestic public company whose shares are listed on Nasdaq. We report under the Exchange Act as a Foreign Private Issuer (“FPI”). Thus, we are exempt from certain provisions of the Exchange Act applicable to U.S. domestic public companies, which are more expansive and require more frequent filings, including (i) the sections of the Exchange Act regulating the solicitation of proxies, consents or authorizations in respect of a security registered under the Exchange Act and the content of proxy statements, (ii) the rules under Section 16 of the Exchange Act subjecting officers, directors to short-swing profit recovering and principal shareholders to reporting and short-swing profit recovery and (iii) the rules under the Exchange Act requiring the filing with the SEC of quarterly reports on Form 10-Q containing full unaudited financial statements and notes thereto and other specified information, and current reports on Form 8-K, which are due upon the occurrence of specified significant events. In addition, FPIs are not required to file their annual reports on Form 20-F until four months after the end of each fiscal year, while U.S. domestic issuers that are large accelerated filers like us are required to file their annual reports on Form 10-K within 60 days after the end of each fiscal year. We are required to report certain material developments in reports furnished on Form 6-K with the SEC, and we have furnished and intend to continue furnishing on Form 6-K our unaudited quarterly financial information after the end of each fiscal quarter. FPIs are also exempt from Regulation FD, aimed at preventing issuers from making selective disclosures of material information. As a result of the above, our shareholders may not have the same protections and/or access to information afforded to shareholders of companies that are not FPIs. 35 As an FPI whose shares are listed on Nasdaq, we are also permitted to follow certain home country corporate governance practices instead of certain requirements of the Nasdaq rules. We currently follow home country practices in Israel in lieu of compliance with the Nasdaq requirements for (i) quorum requirements for an adjourned shareholders meeting; (2) shareholder approval for adoption and material amendments to share incentive plans and (3) the distribution of annual and interim reports, which requirements apply to a domestic U.S. issuer. For more information, see “Item 16G. Corporate Governance.” While we otherwise follow all Nasdaq corporate governance requirements applicable to domestic companies, we may later decide to rely on exemptions from certain of these requirements as an Israeli FPI. For instance, unlike the requirements of Nasdaq, there are currently no mandatory corporate governance requirements in Israel that would require us to (i) have a majority of our board of directors be independent, (ii) establish a nominating/governance committee, or (iii) hold regular executive sessions where only independent directors may be present. Following our home country governance practices as opposed to the requirements that would otherwise apply to a U.S. company listed on Nasdaq may provide less protection than is accorded to investors of domestic issuers. We could lose our status as a “foreign private issuer” under applicable securities laws and regulations if more than 50% of our outstanding voting securities were to become directly or indirectly held of record by U.S. holders and any one of the following were true: (i) the majority of our directors or executive officers were U.S. citizens or residents; (ii) more than 50% of our assets were located in the United States; or (iii) our business were administered principally in the United States. If we were to lose our status as a “foreign private issuer” in the future, we would no longer be exempt from the rules described above and, among other things, we would be required to file periodic reports and annual and quarterly financial statements as if we were a company incorporated in the United States. If this were to happen, we would likely incur significant additional legal, accounting, and other expenses and would likely have to divert significant management time and resources in order to comply with U.S. domestic issuer requirements. Risks Related to Operations in Israel Political, economic and military instability in the Middle East or Israel may harm our business. We are incorporated under Israeli law, and our principal offices and manufacturing and research and development facilities are located in Israel. In addition, the majority of our key employees, officers and directors are residents of Israel. Accordingly, political, economic, and security conditions in Israel and the surrounding region could directly affect our business, and our operations and financial results could be adversely affected in the event of any political instability, terrorism, armed conflicts, or other hostilities in the Middle East or Israel, including the ongoing uncertainty with Iran, Hezbollah and Hamas. Israel continues to face heightened regional security risks, including the aftermath of the October 7th attacks, ongoing military operations in Gaza, escalating hostilities with Hezbollah along the northern border with Lebanon, and, most recently, with Iran. While a ceasefire between Israel and Lebanon (with respect to Hezbollah) was announced in November 2024, a ceasefire between Israel and Iran was announced in June 2025 and a ceasefire between Israel and Hamas was announced in October 2025, in February 2026, hostilities between Israel and Iran escalated again. In late February 2026, the United States, together with Israel, launched a major joint military campaign of air and missile strikes against targets in Iran, which triggered a broad Iranian response and contributed to significant regional instability, including, in early March 2026, resumed conflicts with Hezbollah and, in late March 2026, resumed involvement of the Houthi movement through the launch of missile and drone attacks against Israel. The situation remains highly fluid, and we are unable to predict if, when, or on what terms, this escalation will be resolved. These developments have resulted in prolonged security alerts, disruptions to civilian and commercial activity, and increased geopolitical volatility. Any further deterioration in the security situation, whether through expanded conflict, sustained rocket fire, cyberattacks, or regional escalation, could adversely impact our workforce, facilities, supply chain, customer activity, and overall business continuity. Additionally, prolonged instability may affect macroeconomic conditions in Israel, including currency volatility, inflationary pressures, supply chain limitations and changes in government policy, any of which could materially and negatively affect our business, financial condition, and results of operations. 36 Furthermore, some of our officers and employees are, unless exempt, obligated to perform annual military reserve duty, depending upon their age and prior position in the army. They may also be subject to being called to active duty at any time under emergency circumstances. For example, during 2025 and 2024, in connection with the October 2023 war, approximately 3% of our total workforce was called to perform immediate military service, and additional employees may be called as armed conflicts require. Such employees may be absent for an extended period of time. Our operations could be disrupted by the absence, for a significant period, of one or more of these officers or other key employees due to military service, and any disruption in our operations could harm our business. Our commercial insurance does not cover losses that may occur as a result of events associated with the security situation in the Middle East, including the October 2023 war, such as damages to our facilities resulting in the disruption of our operations. Although the Israeli government currently covers the reinstatement value of direct damages that are caused by terrorist attacks or acts of war, we cannot be assured that this government coverage will be maintained or will be adequate in the event we submit a claim. We could be adversely affected by any major hostilities, including acts of terrorism as well as cyber-attacks or any other hostilities involving or threatening Israel, the interruption or curtailment of trade between Israel and its trading partners, a significant downturn in the economic or financial condition of Israel, or a significant increase in the rate of inflation. For example, in September 2024, Moody’s Investors Service (Moody’s) downgraded the Government of Israel’s foreign-currency and local-currency issuer ratings to BAA1 from A2, which is also the current rating, and in October 2024, S&P global downgraded Israel long-term ratings to A from A+, which is also the current rating. Other global rating agencies may take similar actions. Such downgrades might adversely affect the macroeconomic conditions in which we operate and also potentially deter foreign investment in Israel or Israeli companies, which may, among other things, hinder our ability to raise additional funds, if deemed necessary by our management and Board of Directors. Furthermore, some neighboring countries, as well as certain companies, organizations and movements, continue to participate in a boycott of Israeli firms and others doing business with Israel or with Israeli companies. In the past several years, and with greater intensity commencing with the October 2023 war, there have been increased efforts by activists, influenced by actions of international judicial bodies, to cause companies and consumers to boycott Israeli goods, services, and academic research or restrict business with Israel, which could affect business operations. Similarly, Israeli companies are limited in conducting business with entities from several countries. Restrictive laws, policies or practices directed towards Israel or Israeli businesses could have an adverse impact on our operating results, financial condition or the expansion of our business. Finally, prior to the October 2023 war, the Israeli government began to pursue changes to Israel’s judicial system and has recently renewed its efforts to effect such changes. In response to the foregoing developments, certain individuals, organizations, and institutions, both within and outside of Israel, voiced concerns that such proposed changes, if adopted, may negatively impact the business environment in Israel, including by causing a downgrade to Israel’s sovereign credit rating and Israel’s international standing. Such proposed changes may also lead to political instability or civil unrest. If such changes to Israel’s judicial system are pursued by the government and approved by the parliament, this may have an adverse effect on our business, results of operations, and ability to raise additional funds, if deemed necessary by our management and Board of Directors. 37 The tax benefits we may receive in connection with our preferred enterprise program require us to satisfy prescribed conditions and may be terminated or reduced in the future. This would increase taxes and decrease our net profit. We have in the past benefited, and currently benefit, from certain government programs and tax benefits in Israel, including in connection with our preferred enterprise program (see under Item 10.E “Taxation—Israeli Tax Considerations”). To remain eligible to obtain such tax benefits, we must continue to meet certain conditions. If we fail to comply with these conditions in the future, the benefits we receive could be cancelled, and we may have to pay certain taxes. We cannot guarantee that these programs and tax benefits will be continued in the future, at their current levels or at all. If these programs and tax benefits are ended, our tax expenses and the resulting effective tax rate reflected in our financial statements may increase and as such our business, financial condition and results of operations could be materially and adversely affected. We have obtained benefits from the Israeli Innovation Authority that subject us to ongoing restrictions. We have in the past received, and in the future may apply for, royalty-bearing or non-royalty bearing grants from the Israeli Innovation Authority (formerly known as the Office of the Chief Scientist of the Israeli Ministry of Economy and Industry) (the “IIA”), for research and development programs that meet specified criteria pursuant to the Law for the Encouragement of Research, Development and Technological Innovation in Industry, 1984 (formerly known as the Law for Encouragement of Research and Development in Industry, 1984), and the regulations promulgated thereunder (the “Innovation Law”). The terms of the IIA grants limit our ability to manufacture products outside of Israel or to transfer technologies in or outside Israel if such products or technologies were developed using know-how developed with or based upon IIA grants. In addition, a change of control in us and the acquisition of 5% or more of our ordinary shares by a non-Israeli may require notification to the IIA and the provision of an undertaking to comply with the Innovation Law, some of the principal restrictions and penalties of which are the transferability limits described above and elsewhere in this annual report. It may be difficult to enforce a U.S. judgment against us or our officers and directors and to assert U.S. securities laws claims in Israel. We are incorporated under the laws of the State of Israel, our corporate headquarters is located in Israel and several of our current officers and directors reside in Israel. Service of process upon us, our Israeli subsidiary, our directors and officers and the Israeli experts, if any, named in this annual report, substantially all of whom reside outside the United States, may be difficult to obtain within the United States. Furthermore, because a majority of our assets and investments, and substantially all of our directors, officers and such Israeli experts are located outside the United States, any judgment obtained in the United States against us or any of them may be difficult to collect within the United States and may not be enforced by an Israeli court. We have been informed by our legal counsel in Israel that it may also be difficult to assert U.S. securities law claims in original actions instituted in Israel. Israeli courts may refuse to hear a claim based on an alleged violation of U.S. securities laws if they determine that Israel is not the most appropriate forum to bring such a claim. In addition, even if an Israeli court agrees to hear a claim, it may determine that Israeli law and not U.S. law is applicable to the claim. There is little binding case law in Israel addressing these matters. If U.S. law is found to be applicable, the content of applicable U.S. law must be proven as a fact, which can be a time-consuming and costly process. Certain matters of procedure will also be governed by Israeli law. 38 Subject to specified time limitations and legal procedures, under the rules of private international law currently prevailing in Israel, Israeli courts may enforce a U.S. judgment in a civil matter, including a judgment based upon the civil liability provisions of the U.S. securities laws as well as a monetary or compensatory judgment in a non-civil matter, only if the following key conditions are met: • subject to limited exceptions, the judgment is final and non-appealable; • the judgment was given by a court competent under the laws of the state of the court and is otherwise enforceable in such state; • the judgment was rendered by a court competent under the rules of private international law applicable in Israel; • the laws of the state in which the judgment was given provide for the enforcement of judgments of Israeli courts; • adequate service of process has been effected and the defendant has had a reasonable opportunity to present his arguments and evidence; • the judgment is enforceable under the laws of the State of Israel and its enforcement is not contrary to the law, public policy, security, or sovereignty of the State of Israel; • the judgment was not obtained by fraud and does not conflict with any other valid judgment in the same matter between the same parties; and • an action between the same parties in the same matter was not pending in any Israeli court at the time the lawsuit was instituted in the U.S. court. Your rights and responsibilities as a shareholder will be governed by Israeli law, which may differ in some respects from the rights and responsibilities of shareholders of U.S. companies. The rights and responsibilities of the holders of our ordinary shares are governed by our Articles of Association and Israeli law. These rights and responsibilities differ in some respects from the rights and responsibilities of shareholders in typical U.S.-based corporations. For example, a shareholder of an Israeli company has a duty to act in good faith toward the company and other shareholders and to refrain from abusing its power in the company, including, among other things, in voting at the general meeting of shareholders on matters such as amendments to a company’s articles of association, increases in a company’s authorized share capital, mergers and acquisitions and interested party transactions requiring shareholder approval. In addition, a shareholder who knows that it possesses the power to determine the outcome of a shareholder vote or to appoint or prevent the appointment of a director or executive officer in the company has a duty of fairness toward the company. There is limited case law available to assist us in understanding the implications of these provisions that govern shareholders’ actions. These provisions may be interpreted to impose additional obligations and liabilities on holders of our ordinary shares that are not typically imposed on shareholders of U.S. corporations. 39
INFORMATION ON THE COMPANY A. History and Development of the Company Corporate History and Details Radware Ltd. was organized in May 1996 as a corporation under the laws of the State of Israel and commenced operations in 1997. Our principal executive offices are located at 22 Ra…
INFORMATION ON THE COMPANY A. History and Development of the Company Corporate History and Details Radware Ltd. was organized in May 1996 as a corporation under the laws of the State of Israel and commenced operations in 1997. Our principal executive offices are located at 22 Raoul Wallenberg Street, Tel Aviv 6971917, Israel and our telephone number is 972-3-766-8666. Our website address is www.radware.com (information contained on our website is not incorporated herein by reference and shall not constitute part of this annual report). In addition, the SEC maintains a website that contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC: http://www.sec.gov. Radware Inc., our wholly owned subsidiary in the United States, which conducts the sales and marketing of our products and services primarily in the United States and Canada, is our authorized representative and agent in the United States. The principal offices of Radware Inc. are located at 575 Corporate Dr., Lobby 2, Mahwah, New Jersey 07430 and its telephone number is 201-512-9771. In September 1999, we conducted the initial public offering of our ordinary shares that commenced trading on the Nasdaq. In the past decade, we have made several acquisitions, including, most recently, (i) in January 2026, we acquired Pynt, Inc., an API security testing company, and (ii) in February 2022, we acquired the technology and operations of DC Security Ltd. (previously known as SecurityDAM Ltd. (“SecurityDAM”)), a related party who was a cloud DDoS network operator that supplied us with scrubbing center services used for the provision of our cloud DDoS Protection Service. Recent Major Business Developments For recent major product activities, see Item 4.B “Business Overview—Our Solutions” under the captions “Recent Solution Offering Activities” and “Recent Partnerships Activities.” For a discussion of our capital expenditures and divestitures, see Item 5.B “Liquidity and Capital Resources – Principal Capital Expenditures and Divestitures.” B. Business Overview Overview General We are a provider of application security and delivery solutions for multi-cloud environments. Our solutions secure the digital experience by providing infrastructure, application, and network protection and availability services to companies globally. Our solutions are deployed by, among others, enterprises, carriers, and cloud service providers. 40 Our solutions are offered in two main categories: • Products – We offer a range of cloud-based security-as-a-service subscriptions, on-premises hardware and software products, and product subscriptions (or a combination of these) to our customers. • Services – We offer managed services, professional services, technical support and training and certification to our customers and partners. The sections below provide an overview of our key solutions and services according to the above go-to-market targets. Reportable Segments The Company operates in two reportable segments: • Radware’s Core Business – This segment consists of our core business operations, including our cloud security-as-a-service products, application and data centers security products and our application availability products. • The Hawks’ Business – This segment consists of the operations of our two subsidiaries: SkyHawk (“CNP”) Security Ltd. (“SkyHawk Security”), which provides an agentless Cloud-native threat Detection and Response (“CDR”), combined with Cloud Infrastructure Entitlement Management (“CIEM”), Cloud Security Posture Management (“CSPM”) and Autonomous Purple Team for AWS Google Cloud and Azure, and EdgeHawk Security Ltd. (“EdgeHawk”), which is engaged in providing carrier security solutions by transforming routers and network nodes into security platforms. We refer to SkyHawk Security and EdgeHawk collectively as the “Hawks.” In February 2026, we resolved to sell or cease the operations of Skyhawk Security. For additional details regarding these two reportable segments, see Item 5.A – “Operating Results” and Notes 2ad and 15 to our consolidated financial statements included elsewhere in this annual report. Our Products The main categories of the products and services we offer are as set forth below. Our cloud-based subscription offering consists of the following: o Cloud DDoS Protection Service. Our Cloud DDoS Protection Service provides a full range of enterprise-grade DDoS protection services in the cloud. Based on our DDoS protection technology, it aims to offer organizations wide security coverage, accurate detection and short time to protect from today’s dynamic and evolving DDoS attacks. We offer a multi-vector DDoS attack detection and mitigation service, handling network-layer attacks, server-based attacks and application-layer DDoS attacks. Our Cloud DDoS Protection Service is offered in multiple deployment options to meet an organization’s specific needs: o Always-On Cloud DDoS Protection Service. This service provides always-on protection where traffic is always routed through Radware’s cloud security scrubbing centers with no on-premise device required for detection and mitigation. This service is recommended for organizations that have applications hosted in the cloud or those that are not able to deploy an on-premise attack mitigation device in their data center. 41 o Always-On Hybrid Cloud DDoS Protection Service. This service integrates with our on-premise DDoS Protection device. The traffic is mitigated in the on-premise device and diverted through Radware’s cloud security scrubbing centers upon a large volumetric DDoS attack that aims to saturate the internet pipe. This service is recommended for organizations that place a high premium on the user experience and wish to avoid even the slightest possible downtime as a result of DDoS attacks. o On-Demand Cloud DDoS Protection Service. This service protects against internet pipe saturation and is activated when the attack threatens to saturate the organization’s internet pipe. This service is recommended for organizations that are looking for the lowest cost solution and are less sensitive to real-time detection of DDoS attacks. o On-Demand Cloud Hybrid DDoS Protection Service. The on-premise DefensePro device detects and mitigates all types of DDoS attacks in real-time, while volumetric DDoS attacks are diverted and mitigated in the cloud. This service is recommended for organizations that can deploy an on-premise device in their data centers. We offer several Add-Ons to our Cloud DDoS Protection Service: o Cloud Web DDoS Protection. We offer our cloud customers an additional protection layer dedicated to detecting and mitigating application-layer DDoS attacks. Our Cloud Web DDoS Protection uses advanced L7 behavioral-based detection and mitigation techniques to block Web DDoS Tsunami attacks, offering protection against advanced HTTP/S floods that use randomization techniques to bypass traditional protections. o Cloud Firewall as a Service. Our Cloud Firewall-as-a-Service (FWaaS) provides a cloud-based network firewall solution that helps offload unwanted traffic before it reaches the organization’s network, thereby improving network efficiency and providing consistent protection for the entire network. With no appliance to manage and IP blocking at scale, the service helps organizations manage their traffic in a more efficient and less human-intensive manner. o Cloud Network Analytics. Our Cloud Network Analytics Service provides users with detailed, granular insight into network traffic, network services in use and more. The cloud network analytics service allows administrators to eliminate errors when planning network deployments and stay ahead of DDoS threats via early detection of network abuse and intrusion. o AI SOC Xpert DDoS. Our AI SOC Xpert DDoS add-on delivers agentic AI–powered SOC capabilities that accelerate detection, analysis and mitigation of DDoS attacks. Leveraging real-time behavioral analytics, it automates root-cause analysis—reducing Mean Time to Resolve (MTTR) by up to 20 times —and provides one‑click, context-driven remediation. An intuitive AI assistant offers instant forensic insights and guidance, enabling SOC teams to operate more efficiently and effectively, improving their ability to protect the organization. 42 o Cloud Application Protection Services: Our Web Application and API Protection (WAAP) suite is a one stop shop for organization’s application security needs, providing WAF, API Security, bot management, Layer 7 DDoS (Web DDoS) mitigation, account takeover (ATO) protection and client-side protection. Our Cloud Application Protection Services are offered in three service plans. Each plan is designed to cater to different cybersecurity needs and risk exposure, as well as different levels of managed services: o Standard Plan: Our Standard plan offers the industry benchmark protection level with several extra features and capabilities. It includes Radware’s Cloud WAF, API protection, zero-day attack protection, Basic Bot Protection, and 1Gbps of network DDoS protection, as well as our Service Level Agreement (SLA). o Advanced Plan: Advanced plan takes application security to the next level by offering advanced protection capabilities for those that want to ensure they are well protected from more sophisticated and unknown attacks. The plan includes, on top of the Standard plan, Radware’s Advanced WAF with its path access protection engine that protects against more sophisticated unknown and zero-day attacks, AI-based Correlation Engine (Source Blocking), 10Gbps of network DDoS Protection, as well as JS supply chain mapping, monitoring, and attack detection for client-side protection. It also includes Radware’s intelligence feed – the ERT Active Attackers Feed (EAAF), and further support for onboarding and policy reviewing. o Complete Plan: Radware’s Complete plan provides a security blanket for the customer's entire application environment – from client-side to server-side. This plan includes everything the Advanced plan has to offer, with the addition of Radware’s Bot Manager and its behavior-based multi-layered detection and mitigation, automated API discovery and API security policy generation, real-time API Business Logic Attack Protection, and client-side protection enforcement. We offer several Add-Ons to our Cloud Application Protection Services: o Cloud Web DDoS Protection. We offer an additional protection layer dedicated to detecting and mitigating application-layer DDoS attacks. Our Cloud Web DDoS Protection uses advanced L7 behavioral-based detection and mitigation techniques to block Web DDoS Tsunami attacks, offering protection against advanced HTTP/S floods that use randomization techniques to bypass traditional protections. o CDN. For enterprises that wish to combine website delivery with their web application security, we offer a content delivery network (CDN) solution integrated directly into our Cloud Application Protection portal. Our CDN solution is based on the Amazon CloudFront CDN for a globally distributed footprint, enhanced performance, and DevOps-friendly usability. o PCI DSS 4 Compliance. In addition to the WAF and API protection against business logic attacks, which are necessary for PCI DSS 4 compliance and included in our Cloud Application Protection service plans, the PCI DSS 4 add-on offers customers extended, specific client-side protection controls as required by PCI DSS 4 Sections 6.4.3 and 11.6.1. o DNS as a Service (DNSaaS). Our DNSaaS provides comprehensive Domain Name System (DNS) management, which is essential for the seamless functioning of any online application. It's about safeguarding businesses’ digital presence and ensuring end-users a seamless experience. 43 o Load Balancer as a Service. Our Load Balancer as a Service (LBaaS) complements cloud application protection services with improved SLA and scalability while maintaining high availability and protecting all origin sites. It provides Active/Active traffic and user load balancing between origin sites. o Threat Intelligence Service. Our Threat Intelligence services shed light on why certain IPs are flagged, providing insights and context in real-time. The actionable intelligence allows organization to confidently assess threats, enable informed decisions and proactively defend against threats before they escalate. Key features of the Threat Intelligence Services include: ◾ Actionable Data from Real Cyber Attacks ◾ Research into any suspicious IP address with IP insights and Open Proxys and Malware Data ◾ Reputation alert to ensure Network Security and Integrity by proactively informing of potential cyber-attacks originating from the organization's own network. ◾ Seamless REST API Integration to any environment, existing security workflows and systems o AI SOC Xpert Application Protection. Our AI SOC Xpert for Application Protection strengthens defenses at the application layer with AI-driven support for both WAF and Bot management. It equips SOC teams to handle application traffic and malicious bot activity with greater visibility, faster investigation and precise remediation guidance. Key capabilities of the AI SOC Xpert for Application Protection include: ◾ AI-driven tuning recommendations to reduce false positives and streamline policy management ◾ Faster onboarding and structured investigation tools ◾ Visual dashboards that highlight incidents, anomalies and attack patterns ◾ Reduce alert fatigue and faster time to resolution across application and bot incidents o LLM Firewall. Our new LLM Firewall solutions secures generative AI use with real-time AI-based protection at the prompt level. It stops threats before they reach the organization’s origin servers. The solution enforces enterprise-grade security and compliance by detecting risks like prompt injection, data leaks, harmful content, brand safety and usage policies in real time. The solution is model-agnostic, easy to onboard and secures AI use across platforms without disrupting workflows or innovation. Our hardware and software products consist of the following key products: o DefensePro X Attack Mitigation Device. DefensePro® X, our real-time perimeter attack mitigation device, secures organizations against emerging network multivector and DDoS attack campaigns, IoT botnets, application vulnerability exploitation, malware and other types of cyberattacks. DefensePro X behavioral-based technology is designed to prevail over modern sophisticated attack tools and cybercriminals. 44 The DefensePro X lineup is combined with additional subscriptions for Network and Application protection: o Network Protection Subscription – Silver – includes ERT Security Update Subscription (SUS), ERT Active Attacker Feed (EAAF) and Location based mitigation (GeoIP) subscriptions. o Network Protection Subscription – Gold – includes, on top of the Silver subscription, also ERT under attack service. o Application Protection Subscription – Standard provides basic HTTPS protection and includes Transport Layer Security (TLS) acceleration module. o Application Protection Subscription – Advance - provides advanced behavioral protection for encrypted flood attacks, TLS inspection, DNS protection, Advance Application-aware protection, and threat intelligence under attack. o Alteon® Application Delivery Controller (ADC). Alteon is our application delivery and security solution that manages application traffic across cloud and data center locations, optimizing availability and performance. It provides advanced, end-to-end local and global load balancing capabilities for web, cloud and mobile-based applications. Alteon integrates multiple application protection services to provide protection against an array of cyber threats. Alteon’s analytics also provides insightful visibility so that IT managers can manage and guarantee application service level agreement (SLA) and stay ahead of cyberattacks. We offer Alteon ADC in three different packages (available on each of its models and throughput levels) to address different deployment scenarios and needs: • Alteon Deliver Package. For applications that require high performance ADCs with advanced layer 4-7 ADC functionality. • Alteon Perform Package. For deployments requiring performance optimization, advanced application performance monitoring, global server load balancing, link load balancing, automated/optimized ADC service operation, Alteon Advanced Analytics and Geolocation database updates. Provided on top of Alteon Deliver Package. • Alteon Secure Package. For applications that require our most advanced protections, including an embedded WAF module, authentication gateway, bot management, and threat intelligence feeds (WAF SUS, ERT Active Attackers Feed). Provided on top of Alteon Perform Package. We offer Alteon with a Global Elastic Licensing (GEL) solution, a purchasing and deployment subscription that enables a high level of flexibility for ADC services across datacenters, private and public clouds. GEL enables dynamic ADC capacity allocation and the ability to move that capacity across environments, without having to invest separately in a dedicated ADC infrastructure for each and every location where an organization’s applications are deployed (e.g., on-premises, public cloud, etc.). This application delivery licensing model helps to eliminate planning risks in the purchase and deployment of ADC services, enabling continuous investment protection of the ADC infrastructure throughout its lifecycle duration. o Radware Kubernetes WAAP. Radware Kubernetes WAAP is a Web Application Firewall and API security solution for continuous integration and continuous delivery (CI/CD) environments orchestrated by Kubernetes. Our Kubernetes WAAP integrates with common software provisioning, testing and visibility tools in the CI/CD pipeline offering both IT security and DevOps personnel detailed insight down to the pod and container levels, and enables organizations to implement application and data security in on-premise and cloud-based implementations. 45 o Cyber Controller. Our Cyber Controller is a unified solution for management, configuration and attack lifecycle. The Cyber Controller provides enhanced security, increased visibility and an improved user experience via multiple security operation dashboards for a unified view into attack lifecycle and mitigation analysis for both inline and out-of-path DDoS deployments. Cyber Controller provides network analytics with comprehensive visibility of traffic statistics during peacetime and attack, and simplified management and configuration with unified visibility and control. Cyber Controller supports several licenses according to each customer-managed environment and customer needs. o Cyber Controller Standard: Provides the network management tool and network monitoring tool for the Radware family of cybersecurity and application delivery solutions. It provides our customers immediate visibility to health, real-time status, performance and security of our products from one central, unified console. An analytics module provides an intuitive, customizable Graphical User Interface with granular forensic insights into application performance, denial-of-service and web application attacks. o Cyber Controller X: In addition to the “Standard” license features, provides the ability to manage the DefensePro X product line using the new Cyber Controller X stream. o Cyber Controller Plus: An add-on on top of either the “Standard” or “X” licenses, enabling orchestration, automation and out-of-path capabilities for attack life-cycle. o Cyber Controller MSSP Portal: the MSSP Portal is designed to help service providers to deliver cyber security services while simultaneously reducing Total Cost of Ownership (TCO) and MTTR, and surpassing margin revenue targets. It provides end-customers with comprehensive insights into the status of their protected network, offering visibility into both peacetime and attack traffic. Additionally, our portal allows service providers to offer invaluable services such as self-operating capabilities to their customers, particularly for those with expertise in security operations. Leveraging the power of multitenancy, our MSSP portal enables service providers to efficiently manage multiple customers, ensuring seamless operations and optimal resource utilization. 46 Customer Services We offer managed services, professional services, technical support and training and certification to our customers and partners. Our key customer services consist of the following: o Certainty Support Program. We offer technical support for all our products through our Certainty Support Program. Certainty support levels include: o Basic. This level provides business day access, including weekends from 9 a.m. to 5 p.m. (local time) to technical support center services, and technical documentation, either via the Web, e-mail or direct phone support during working days. New software releases are available for units covered under the certainty support program. o Standard. This level increases access to the technical support center 24/7/365 and adds next business day replacement of failed hardware and waives customer shipping costs. o Advanced. This level increases the certainty support level standard to four hours’ replacement of failed hardware advanced replacement. o Professional Services. Our professional services group is staffed by a global team of experts possessing extensive knowledge and experience in security and application delivery both in data centers and the cloud. The group offers a full range of services to design, implement, automate, and optimize our customer solutions. We offer the following key professional services: o Design and Planning. This service plans and designs applications for future growth with Radware engineers. The service starts with a review of business goals, network optimization assessment and an overview of application architecture and security requirements to help create a comprehensive deployment plan that is tailored to organizational IT requirements. o Application and Security Optimization Services. This service analyzes and reviews the current implementation and design and provides recommendations to help optimize the system and achieve business goals. o Resident Engineer. Our Resident Engineer service is a proactive on-site engineer who performs operations, design and automation activities. From initial deployment to ongoing management and day-to-day operation, our Resident Engineer service decreases the time demands on our customers’ staff, allowing them to focus on their core business. o Technical Account Manager. Our technical account manager is a proactive consultant that implements best practices, provides guidance and optimizes networking and application resources. o ERT Service. Our ERT is a group of security experts available 24x7 for proactive security support services for customers facing a broad array of application and network-layer attacks, such as denial-of-service (DoS) attacks, malware outbreaks and application exploits. Powered by Radware Threat Research Center, ERT engineers combat common and emerging attacks on a daily basis, providing customers with industry-leading expertise, best practices and a deep knowledge of threats, attack tools, intelligence and mitigation technologies. These services include: o ERT Managed Security Service. Our ERT offers a fully managed application- and network-security service. The service covers a broad range of attack types from different forms of DDoS to a variety of application attacks against our customers’ servers or data centers. It includes immediate response, onboarding, consulting, remote management, and reporting. o ERT Under-Attack Service. The ERT under-attack service offers 24x7 access to a security expert within 10 minutes. The ERT engineer will take the lead, fight off attacks and provide postmortem analysis of security events. The ERT under-attack service lets organizations know there is someone to rely on, guaranteeing support throughout the attack life cycle from the moment it begins. The ERT experts are available 24x7 and assist large enterprises worldwide with complex multi-vector attacks against their networks, data centers and application services. 47 Recent Solution Offering Activities During 2025, our key solution offering activities consisted of the following: • We have announced a new solution, LLM Firewall, to secure applications that deploy generative AI models. The LLM Firewall is an add-on to all tiers of our Cloud Application Protection Services, and the first phase of our broader agentic AI protection solution for enterprises. LLM Firewall is designed to help address the growing security concerns around integrated LLM modules in applications and to protect the LLM prompt and response against attacks and abuse. It is designed to secure generative AI use with real-time, AI-based protection at the prompt level, stopping threats before they reach the LLM model. Fully model-agnostic and easy to integrate, it is designed to secure AI use across platforms without disrupting workflows or innovation. • We have expanded our Threat Intelligence Services with the launch of Telegram Claimed Attacks Report and TLS Fingerprint Reputation Feed. The subscription-based cloud services work in real-time, designed to provide global threat intelligence and visibility, thereby helping security teams to anticipate and neutralize emerging cyber threats before they materialize. In the face of escalating cyberthreats, these reports offer additional preemptive protection to strengthen cyber defenses and improve security posture with minimal operational effort. • We have expanded our AI SOC Xpert capabilities to cover new use cases to drive efficiencies. AI SOC Xpert now delivers root cause analysis, timeline, and incident context within minutes across both DDoS and bot attacks, providing analysts with the clarity they need to understand what happened and respond with speed and confidence, automatically and at scale. Whereas analysts previously relied on manual correlation or switching between tools, they can now access new dashboards for Application Protection and On-Premises DDoS Protection, along with significant AI enhancements to Cloud DDoS Protection. This unified view of what happened, why it matters, and how to respond reduces investigation fatigue and helps teams act faster under pressure thus reducing MTTR. • We have launched new cloud security service center in Tel Aviv, Israel (the new Tel Aviv facility marks our second cloud security center in Israel), in Bogota, Colombia, Chennai and Mumbai, India, Nairobi, Kenya, and Lima, Peru. These new service centers are part of our global cloud security network, comprising more than 50 centers worldwide with a total attack mitigation capacity of over 15Tbps. • We have partnered with SUSE SA, a global provider of open-source enterprise solutions, to offer service providers and enterprises a full stack, cloud-native Kubernetes security solution designed to achieve low latency, high availability, and regulatory compliant outcomes. The collaboration brings together our Kubernetes Web Application and API Protection (KWAAP) with SUSE's Rancher Prime and Edge platforms. The combined solution is designed to create a modular, open, and certified solution for securing distributed workloads at scale—from core data centers to the edge. 48 Our Competitive Strengths Our solutions incorporate proprietary and innovative cybersecurity and application delivery technologies that help our customers to secure the digital experience for users of business-critical applications. We believe our competitive strengths are based on several elements, including the following: • Innovation, Proprietary Technologies, and Thought Leadership. We are offering innovative solutions in our domain. We were one of the first companies to offer hybrid attack mitigation solutions; behavioral DDoS attacks detection with automated real-time signature creation for attack mitigation; device fingerprinting technology implementation for Bot-based attacks detection; auto-policy generation for our WAF solution; protection against encrypted attacks without opening the sessions for DDoS protection; AI to detect attacks targeting workloads in public clouds; and Generative AI to help SOC teams act faster under pressure thus reducing MTTR significantly. We believe this has given us significant expertise, know-how, and leadership in the market for cyber-attack mitigation solutions, and we take part in many technology communities, standard organizations, and open source projects. At the same time, we continue to invest in research and development of cybersecurity and application delivery technologies in order to introduce new and innovative solutions, which are supported and protected by multiple patents and proprietary rights. • Automation. We are offering automated attack detection and mitigation solutions that reduce the total cost of ownership of cybersecurity solutions, including behavioral analysis technology to detect zero-day DDoS attacks; automated real-time signature creation for DDoS attacks mitigation; intent-based behavioral analysis and machine learning (or “ML”) models to detect automated Bot attacks; and machine learning (positive security model) to detect zero-day web application attacks. • Wide attacks coverage. Our solutions offer a wide coverage against attacks, including mitigation of all five generations of Bot attacks; negative and positive security models to defend against known (OWASP top-10) and zero-day web application attacks (standard solutions typically cover OWASP top-10 attacks only); and advanced DDoS attacks protection such as DNS flood attacks, burst floods, SSL flood attacks, IoT botnets and encrypted Web DDoS attacks. • Industry Awards. We gained multiple industry awards during 2025, including the following: • Quadrant Knowledge Solutions – 2025 DDoS Mitigation SPARK Matrix™ – Leader • Quadrant Knowledge Solutions – 2025 WAF SPARK Matrix™– Leader • Quadrant Knowledge Solutions – 2025 Bot Management SPARK Matrix™ – Leader • KuppingerCole - Leadership Compass Report for Web Application and API Protection 2025 – Overall and Innovation Leader • Forrester - The Forrester Wave™: Web Application Firewall Solutions, Q1 2025 – Strong Performer • Gartner Peer Insights - Voice of the Customer for Cloud Web Application and API Protection Report 2025 – Strong Performer We are not responsible for the determinations of any of these awards or the entities or publications that award them. 49 Our Growth Strategy Our growth strategy is based on several key elements: • Focus on cloud and application security. We aim to offer superior cloud services and application security solutions for our customers, and plan to continue to innovate and provide advanced security capabilities helping enterprises and businesses to keep up with emerging cyber threats and growing compliance and regulation requirements. We also offer managed services for our customers who lack security expertise in network and application security domains. • Increase our market footprint. We believe that a significant market opportunity exists to sell our solutions with the complementary products and services provided by other organizations with whom we wish to collaborate. To that end, we have already established strategic relationships with various third parties, including leading global-class partners, such as Cisco and Check Point, which provide critical access to certain large customers allowing us to sell our solutions. In addition, we intend to further increase our market footprint through collaboration with leading partners. • Expand our footprint in the medium sized enterprise market. The needs of the mid-market enterprises regarding the management of cybersecurity risks are substantially similar to the needs of the large enterprise market, but their capacity and access to skilled talent are more limited. We believe that our fully managed cloud security services can be a great fit for this market, and we intend to further expand our market footprint in this segment. • Pursue acquisitions and investments. In order to achieve our business objectives, we may evaluate and pursue the acquisition of, or significant investments in, other complementary companies, technologies, products, and/or businesses that enable us to enhance and increase our technological capabilities and expand our product and service offerings. Sales and Marketing Sales. We market and sell our products and services primarily through indirect sales channels that consist of distributors and resellers located in North, Central and South America, Europe, Africa, Asia, and Australia. In addition, we generate direct sales to selected customers mainly in the United States. Our direct sales channels are supported by our sales and marketing managers who are also responsible for recruiting potential distributors and resellers and for initiating and managing marketing projects in their assigned regions. The sales managers are supported by our internal sales support staff that help generate and qualify leads for the sales managers. We have subsidiaries and representative offices and branches in multiple countries to cover the above mentioned regions (see Item 4.C “Organizational Structure”), to promote and market our products and services and provide customer support in their respective regions. Marketing. Our marketing strategy is to enhance brand recognition and maintain our reputation as a provider of technologically advanced, quality cybersecurity and application delivery solutions to help drive demand for our products and services. We seek to build upon our marketing and branding efforts globally to achieve greater worldwide sales and leverage sophisticated digital platforms and activity to scale our presence globally. Our marketing initiatives are principally directed at developing brand awareness, optimizing our digital presence, searchability and awareness, generating qualified leads and providing sales and marketing tools to our distributors/resellers to promote sales. We participate in major trade shows and virtual events, regionally based events/seminars and offer support to our distributors and resellers who participate in these events. We also participate in our partners’ events, such as Cisco Live and Checkpoint Experience, to promote our solutions within their audiences. Additionally, we focus on our customer base to deliver an integrated Customer 360 experience including regular communications, facilitating support and training needs, maximizing customer lifetime value and developing customer advocacy. We also invest in online and search engine advertising campaigns, public relations, and regionalized field marketing campaigns. In addition to our independent marketing efforts, we invest in joint marketing efforts with our distributors, OEMs, VARs, GSIs, and other companies that have formed strategic alliances with us. 50 Customers and End-Users With the exception of our limited direct sales to selected customers, we sell our products and services through distributors or resellers who then sell our products and services to end-users. We have a globally diversified end-user base, consisting of corporate enterprises, including banks, insurance companies, manufacturing, retail companies, media companies, government agencies and utilities, and service providers, such as telecommunication carriers, internet service providers, cloud service providers, and application service providers. Customers in these different vertical markets deploy Radware products for availability, performance and security of their applications. In 2025, approximately 41% of our revenues were generated from sales in North, Central and South America (principally in the United States), 37% were in Europe, the Middle East and Africa (EMEA) and 22% in Asia-Pacific, compared to 43%, 34% and 23%, respectively, in 2024, and 40%, 37% and 23%, respectively, in 2023. Other than the United States, which accounted for 31% of our total revenues in 2025, no other single country accounted for more than 10% of our revenues for 2025, 2024, and 2023. In 2025, approximately 63% of our revenues derived from product sales, and 37% derived from service sales, compared to 57% and 43%, respectively, in 2024 and 56% and 44%, respectively, in 2023. In 2025, approximately 77% of our revenues derived from the enterprise market and 23% derived from the carrier market, compared to approximately 79% and 21%, respectively, in 2024, and 77% and 23%, respectively, in 2023. As of December 31, 2025, 2024, and 2023, no single customer accounted for more than 10% of our revenues. For additional details regarding the breakdown of our revenues by geographical distribution and by activity, see Item 5.A – “Operating Results.” Seasonality Our quarterly operating results have been, and are likely to continue to be, influenced by seasonal fluctuations in our sales and by seasonal purchasing patterns of some of our customers. Our operating results in the fourth quarter tend to be higher than other quarters as some of our customers tend to make greater capital and operational expenditures as well as expenditures relating to service renewals towards the end of their own fiscal years, thereby increasing orders for our products, support and subscription services in the fourth quarter. 51 Customer Support Services Our technical support team, which consisted of 409 employees worldwide as of December 31, 2025, supports our sales force during the sales process, assists our customers, resellers and distributors with the initial installation, set-up and ongoing support of our products, and trains them on how to best use our solutions. The technical support team also assists with service onboarding processes and provides training to end-users of our services. In addition, our technical team trains and certifies our distributors and resellers to provide limited technical support in each of the geographical areas in which our products are sold and is directly responsible for remote support. Our Certainty Support Program offerings allow customers to automatically obtain new software versions of their products and obtain optimized performance by purchasing any of the following optional offerings: extended warranty, software updates, 24x7 help-desk (directly to our customers and through our distributors), on-site support and unit replacement. Some of our on-site services are provided by third-party contractors. Research and Development We invest in research and development to expand and enhance the features of our existing solutions, to develop new solutions and features and to improve our existing technologies and features. We believe that our future success is dependent upon our ability to maintain our technological expertise, enhance our existing solutions and introduce, on a timely basis, new commercially viable solutions that will address the needs of our customers. Accordingly, we intend to continue devoting a significant portion of our personnel and financial resources to research and development. In order to identify market needs and to define appropriate product specifications, as part of the product development process we seek to maintain close relationships with current and potential distributors, customers and vendors in related industry sectors. As of December 31, 2025, our research and development staff consisted of 406 employees and 68 subcontractors. Research and development activities take place mainly at our facilities in Israel; Bangalore, India; Vancouver, Canada; and North Carolina, United States. We employ established procedures for the required management, development and quality assurance of our new product developments. Our research and development organization is divided into Application Security, Infrastructure Security, Application Delivery, Management and Control, Cloud Services, and Chief Technology Officer groups. Within those groups the organization is divided according to our existing product solutions. Each product group is headed by a group leader and includes team leaders and engineers. Each group has a dedicated quality assurance team. In addition, we have an infrastructure department responsible for the development of our platforms that are the basis for all products, serving all product groups, which consist of a senior group leader, group leaders, team leaders, and engineers. The heads of all research and development divisions report to either the Chief Operating Officer or the Chief Technology Officer. See also below under “Government Regulations – Israeli Innovation Authority.” Manufacturing and Suppliers Our quality assurance testing, final integration, packaging, and shipping operations as well as part of our final assembly activities are primarily performed at our facility in Jerusalem, Israel. All our products are Underwriters Laboratories (UL), conformité européenne (CE), Federal Communications Commission (FCC) and ISO 9001:2008 compliant and some of them have also achieved industry certifications. We rely to a large extent on third-party manufacturing vendors to provide our finished products. In this respect, these vendors primarily provide us with design and manufacturing assembly services in order to deliver the finished goods while we perform the final integration of the products. All components and subassemblies included in our products are supplied to the manufacturing vendors by several suppliers and subcontractors. Each of the manufacturing vendors monitors each stage of the components production process, including the selection of components and subassembly suppliers. Thereafter, each of the manufacturing vendors makes the final assembly in their own facility. Our primary manufacturing vendors are ISO 9001 certified, indicating that each of their manufacturing processes adheres to established quality standards. 52 We primarily rely on two ODMs to manufacture and to supply our hardware platforms. In 2025, approximately 50% of our direct product costs were from one of these vendors and 31% were from the other vendor. Additionally, we rely on four other vendors, which, together with the two ODMs noted above, made up 95% of our direct product costs in 2025. We conduct a business continuity plan (BCP) with all our vendors to ensure an immediate recovery in case of crisis that might jeopardize the supply of our products and services. For example, in light of the heightened regional security risks affecting Israel, including the aftermath of the October 7 attacks, ongoing military operations in Gaza, renewed hostilities along the northern border with Lebanon involving Hezbollah, and escalating tensions and periodic direct confrontations between Israel and Iran, we have implemented contingency measures designed to mitigate potential disruptions to our operations and supply chain. These measures include maintaining alternative logistics global routes, coordinating closely with our ODM vendors and global partners, and ensuring operational redundancy across multiple locations to support uninterrupted service to our customers worldwide. In this respect, we have been certified during 2021 for ISO 22301 (Business Continuity Management System). Furthermore, in order to minimize potential delays in product supplies by certain of our ODMs whose lead time had been significantly extended due to the worldwide chipset shortage, we had paid expedite fees to several components manufacturers. However, if we are unable to continue to acquire those platforms or components from these platform manufacturers and vendors on acceptable terms, or should any of these suppliers cease to supply us, on a timely basis, with such platforms or components for any reason, we may not be able to identify and integrate an alternative source of supply in a timely fashion or at the same costs. Any transition to one or more alternate suppliers would likely result in delays, operational problems, and increased costs, and may limit our ability to deliver our products to our customers on time for such transition period, although we believe we have levels of inventory that will assist us to transition to alternate suppliers smoothly. Proprietary Rights We rely on a combination of patent, trademark and trade secret laws, as well as confidentiality agreements and other contractual arrangements with our employees, distributors and others to protect our technology. We hold various patents in, and have pending patent and provisional patent applications, in the United States and other jurisdictions to protect various aspects of our technology. These applications may not result in any patent being issued, and, even if issued, the patents may not provide adequate protection against competitive technology and may not be held valid and enforceable if challenged. In addition, other parties may assert rights as inventors of the underlying technologies, which could limit our ability to fully exploit the rights conferred by any patent that we receive. For the risks and uncertainties associated with protecting our technology, see in Item 3.D “Risk Factors" under "Our business and operating results could suffer if third parties infringe upon our proprietary technology" and "Our products may infringe on the intellectual property rights of others." 53 Competition The cybersecurity and application delivery market is highly fragmented and competitive, and we expect competition to intensify in the future. Our principal competitors are: • DDoS Mitigation: Akamai Technologies, Inc. (“Akamai”), Imperva Inc. (“Imperva”), Netscout Systems, Inc. and Cloudflare, Inc. • Web Application Firewalls and Bot Management: Akamai, Imperva, Cloudflare, Inc., F5 Networks, Inc. (“F5”), and AWS. • Application Delivery: F5, A10 Networks, Inc., and Citrix Systems, Inc. We expect to continue to face additional competition as new participants enter the market or extend their portfolios into related technologies. Larger companies with substantial resources, brand recognition and sales channels may also form consolidation and alliances with or acquire competing providers of application delivery or application and network security solutions and emerge as significant competitors. We also expect competition to intensify in the future as a result of the integration of AI technologies into the markets in which we compete, whether by existing or new market entrants. We continue seeing new types of competitors from within the public cloud providers – as more companies rely on these environments to host their services and applications, these vendors start providing cybersecurity solutions that are typically relatively basic and customized for their own environment. As we see more and more companies relying on more than one public cloud vendor, we expect to see additional competitors and rapid evolution of solutions and offerings. An increase in competition may lower prices and reduce demand and margins as well as increase costs associated with sales and marketing to maintain or increase market share; which, in turn, may impair our ability to increase profitability. Furthermore, the dynamic market environment poses a challenge in predicting market trends and expected growth. We believe that our products and services have several competitive advantages in performance and accuracy and that our future success will depend primarily on our continued ability to provide more technologically advanced and cost-effective application delivery and cybersecurity solutions, and more responsive customer service and support, than our competitors. However, we cannot assure you that all products and services we offer in our portfolio will compete successfully with similar competitor solutions. See also above under “Business Overview.” Government Regulations Data Privacy and Data Protection Our activities in the cybersecurity market require that we comply with laws and regulations in the area of data privacy and data protection governing the collection, use, retention, sharing and security of personal data. Virtually every jurisdiction in which we operate has established its own legal framework relating to privacy, data protection, and information security matters with which we and/or our customers must comply. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, retention, disclosure, security, transfer, and other processing of data that identifies or may be used to identify or locate an individual. Some countries and regions have passed legislation that imposes significant obligations in connection with privacy, data protection, and information security. 54 Europe and UK In the EEA, we are subject to the GDPR and in the United Kingdom we are subject to UK DP Laws, in each case in relation to our collection, control, processing, sharing, disclosure and other use of data relating to an identifiable living individual (personal data). The GDPR, and national implementing legislation in EEA member states and the United Kingdom, impose a strict data protection compliance regime, including restrictions on cross-border data transfers. The DORA, which came into effect in the European Union in January 2025, requires additional security, resiliency, and governance controls for financial institutions and their third-party service providers. These controls require service providers to perform extensive security testing, security incident reporting, and detailed reviews of sub-processors used to deliver their service. In addition to the cost of maintaining the DORA control requirements, the DORA regulations include a schedule of fees and fines for non-compliance. The EU has also enacted legislation that would regulate non-personal data and establish new cybersecurity standards, and other countries, including the U.K., may similarly do so in the future. For example, the EU’s Digital Services Act imposes certain content moderation, notice and transparency obligations on digital platforms and intermediaries and certain data. Additionally, the EU’s Network and Information Security Directive II, adopted in 2023, regulates resilience and incident response capabilities of entities operating in a number of sectors, including the digital infrastructure sector and provides for EU member states to have issued implementing legislation by October 2024. The EU has also enacted the CRA which, among other things, sets cybersecurity standards and incident reporting requirements for hardware and software products in the EU market. United States In the United States, there are numerous federal, state and local data privacy and security laws, rules and regulations governing the collection, sharing, use, retention, disclosure, security, transfer, storage and other processing of personal information, including federal and state data privacy and security laws, data breach notification laws and data disposal laws. For example, at the federal level, we are (or may become) subject to, among other laws and regulations, the rules and regulations promulgated under the authority of the Federal Trade Commission (“FTC”) (which has the authority to regulate and enforce against unfair or deceptive acts or practices in or affecting commerce, including acts and practices with respect to data privacy and security), as well as the Electronic Communication Privacy Act, the Computer Fraud and Abuse Act, the Health Insurance Portability and Accountability Act (“HIPAA”), the FTC’s Health Breach Notification Rule and the Gramm Leach Bliley Act (and its implementing regulations). The U.S. Congress also has considered, is currently considering, and may in the future consider, various proposals for comprehensive federal data privacy and security legislation, to which we may become subject if passed. Requirements for compliance under HIPAA are also subject to change, as the U.S. Department of Health and Human Services Office of Civil Rights issued a proposed rule that would amend certain security compliance requirements for covered entities and business associates. Further, the U.S. Department of Justice issued a final rule entitled, “Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons,” codified at 28 CFR part 202 (“Bulk Transfer Rule”). The Bulk Transfer Rule prohibits and restricts bulk transfers of sensitive personal data (including genetic and health data) to countries of concern, such as China, Russia, and Iran to prevent access by foreign adversaries. It restricts our ability to engage in certain cross-border transactions involving genomic or biological samples and related data, which may increase compliance costs, lead to increased regulatory scrutiny or liability, and may require additional contractual negotiations, which may adversely impact our business, financial condition, and operating results. 55 At the state level, we are subject to laws and regulations relating to cybersecurity and data privacy, such as the CCPA. The CCPA broadly defines personal information and gives California residents expanded privacy rights and protections, such as affording them the right to access and request deletion of their information and to opt out of certain sharing and sales of personal information. The CCPA requires companies to implement reasonable security procedures and provides for severe civil penalties and statutory damages for violations and a private right of action for certain data breaches that result in the loss of unencrypted personal information. This private right of action increases the likelihood of, and risks associated with, data breach litigation. In addition, some of these laws (including the CCPA), along with other standalone health privacy laws, subject health-related information to additional safeguards and disclosures and some specifically regulate consumer health data, such as the Washington My Health My Data Act, Nevada’s Consumer Health Data Privacy Law, and Connecticut’s amendments to its privacy law to address health data. Numerous other states have also enacted, or are in the process of enacting or considering, comprehensive state-level data privacy and security laws and information-specific, rules and regulations that share similarities with the CCPA and may be applicable to our operations. Moreover, laws in all 50 U.S. states require businesses to provide notice under certain circumstances to consumers whose personal information has been subject to unauthorized access or acquisition as a result of a data breach. Notifications or other public disclosure or dissemination of information related to any actual or perceived security incident could impact our reputation, harm customer confidence, hurt our expansion into new markets or cause us to lose existing customers. Additional possible consequences for non-compliance with these various state laws include enforcement actions in response to rules and regulations promulgated under the authority of federal agencies, state attorneys general and legislatures and consumer protection agencies. AI Laws In addition, our use of AI Technologies is facing increasing regulatory scrutiny (see the risk factor in Item 3.D. above titled “We face risks related to the rapidly evolving regulatory framework for AI Technologies.”). Environmental and Security Management Regulations Our activities in Europe require that we comply with European Union Directives with respect to product quality assurance standards and environmental standards. The Restriction of Hazardous Substances (RoHS) and RoHS II Directives require products sold in Europe to meet certain design specifications, which exclude the use of hazardous substances. Directive 2002/96/EC on Waste Electrical and Electronic Equipment (known as the “WEEE” Directive) requires producers of electrical and electronic equipment to register in different European countries and to provide collection and recycling facilities for used products. We believe we are currently in compliance with the RoHS and WEEE regulations, ISO 14001 standards (regarding Environmental Management Systems), ISO/IEC 27001:2013 and ISO 27032: 2012 standards (both in regard to Information Security Management System), ISO 28000 (Supply Chain Security management) and OHSAS 18001:2007 (Occupational Health and Safety Management). Israeli Innovation Authority From time to time, eligible participants may receive grants under programs of the IIA. This governmental support is conditioned upon the participant’s ability to comply with certain applicable requirements and conditions specified in the IIA’s programs and the Innovation Law. Under the Innovation Law, research and development programs that meet specified criteria and are approved by the Research Committee of the IIA are eligible for grants usually of up to 55% of certain approved expenditures of such programs, as determined by said committee. 56 The Innovation Law provides that know-how developed under an approved research and development program or rights associated with such know-how (1) may not be transferred to third parties in Israel without the approval of the IIA (such approval is not required for the sale or export of any products resulting from such research or development) and (2) may not be transferred to any third parties outside Israel, except in certain special circumstances and subject to the IIA’s prior approval, which approval, if any, may generally be obtained, subject to payment of a transfer fee pursuant to which the grant recipient pays to the IIA a portion of the sale price paid in consideration for such IIA-funded know-how; or a portion of the consideration paid in respect of licensing the IIA-funded know-how, as the case may be (according to certain formulas, which may result in repayment of up to 600% of the grant amounts plus interest). Under certain circumstances, such as in the event that the grant recipient receives know-how from a third party in exchange for its IIA-funded know-how, such transfer fee may not apply. The Innovation Law imposes reporting requirements with respect to certain changes in the ownership of a grant recipient. The law requires the grant recipient and its controlling shareholders and foreign interested parties to notify the IIA of any change in control of the recipient or a change in the holdings of the means of control of the recipient and requires a non-Israel interested party to undertake to the IIA to comply with the Innovation Law. In addition, the rules of the IIA may require additional information or representations in respect of certain of such events. For this purpose, “control” is defined as the ability to direct the activities of a company other than any ability arising solely from serving as an officer or director of the company. A person is presumed to have control if such person holds 50% or more of the means of control of a company. “Means of control” refers to voting rights or the right to appoint directors or the chief executive officer. An “interested party” of a company includes a holder of 5% or more of its outstanding share capital or voting rights, its chief executive officer and directors, someone who has the right to appoint its chief executive officer or at least one director, and a company with respect to which any of the foregoing interested parties owns 25% or more of the outstanding share capital or voting rights or has the right to appoint 25% or more of the directors. Accordingly, any non-Israeli who acquires 5% or more of our ordinary shares will be required to notify us that it has become an interested party and needs to sign an undertaking to comply with the Innovation Law. The Israeli authorities have indicated in the past that the government may further reduce or abolish the IIA grants in the future. Even if these grants are maintained, we cannot presently predict what would be the amounts of future grants, if any, that we might receive. In 2025, 2024, and 2023, we were qualified to participate in projects funded by the IIA to develop generic technology relevant to the development of our products. We were eligible to receive grants constituting between 30% and 55% of certain research and development expenses relating to these projects. The grants under these projects are not required to be repaid by way of royalties. In addition, one of our Israeli subsidiaries received royalty-bearing grants from the IIA for an approved research and development project. The grants under this project, which amounted to $0.4 million for the year ended December 31, 2025, are required to be repaid based on revenues from the sale of products incorporating or based upon know-how developed, in whole or in part with the grants. Research and development grants deducted from research and development expenses, net amounted to $0.3 million, $0.04 million, and $0.4 million for the years ended December 31, 2025, 2024, and 2023, respectively. Environmental, Social and Governance Matters At Radware, we aim to help customers protect their critical applications and secure their digital experiences. As we pursue this goal, we recognize our responsibility to promote socially and environmentally responsible economic growth through, and in the best interest of our business practices. In order to promote this corporate responsibility and sustainability approach, we have implemented, and will continue to implement, various ESG principles and activities into our daily business practices, including, but not limited to, those summarized below. 57 Our most recent ESG Report is available at www.radware.com/corporategovernance (information contained on our website, including in our ESG report, is not incorporated herein by reference and shall not constitute part of this annual report). Environmental We aim to build a more sustainable world through the products, services, and solutions we offer and the way we operate. This means, among other things, that we aim to operate our business in a manner that meets or exceeds all environmental laws and compliance guidelines and strive to improve our environmental performance across our entire supply chain. While we continue to develop a program that recognizes our environmental impact, we have already implemented various activities to measure and foster our environmental focus, including the following highlights: • We have implemented key performance indicators (KPIs), which set quantitative reduction goals for the use of water, power and paper; • We work with our suppliers to maintain compliance with various environmental laws and guidelines, such as RoHS and WEEE in the EU, and adopted our Conflict Minerals Policy available at www.radware.com/corporategovernance/conflictminerals (information contained on our website, including in our Conflict Minerals Policy, is not incorporated herein by reference and shall not constitute part of this annual report), which outlines our practices and procedures with respect to responsible sourcing of minerals from conflict-affected and high-risk areas; and • Our corporate headquarters in Tel Aviv, Israel, as well as our training rooms in Tel Aviv are designed in the “TED” style to serve as multifunctional work spaces while the operations room utilizes NVX video technology in order to minimize the amount of copper wiring required to function and travel. At our headquarters, we offer EV charging stations to our employees and visitors, and where applicable according to local requirements, we offer recycling and properly dispose of e-waste. Social We believe that the foundation of our success lies in our diverse, engaged, and motivated workforce, and we continuously advocate for our team by creating a work environment in which our employees can thrive in the spirit of productivity and development. This means, among other things, that we aim to operate our business in a manner that promotes a work environment that is free of discrimination on the basis of any protected characteristics and harassment and otherwise attends to our employees’ wellbeing. 58 While we continue to develop a program that recognizes our social impact, we have already implemented various activities to measure and foster our focus on social impact, including the following highlights: • We are an equal-opportunity employer and make employment decisions based on a person’s qualifications and our business needs. This is demonstrated by our Human Rights and Labor Standards Policy; • Our corporate policy maintains zero tolerance for harassment, sexual harassment, and discrimination against individuals on the basis of any protected characteristics, and it imposes significant consequences for behavior deemed to create a hostile work environment. This is demonstrated by our Code of Conduct and Ethics as well as our Human Rights and Labor Standards Policy; • We offer what we believe is an attractive mix of compensation and benefit plans to support our employees’ and their families’ physical, mental, and financial well-being. This includes allowing the majority of our employees to have a direct ownership interest in Radware by participating in our equity-based incentive plans; and • We are focused on maintaining a healthy, safe, and secure work environment that protects our employees and the public from harm. This is demonstrated by the measures we implemented in order to overcome the challenges presented by the COVID-19 pandemic. We implemented a hybrid work model, which enables our employees to work partly remote and partly in the office. We believe that this flexibility drives increased job satisfaction while addressing the major challenges of remote work, such as isolation and lack of community. Governance As part of our sustainable and other ESG operations policies, we aim to conduct our corporate governance and build corporate behavior mechanisms to align with the interest of all our stakeholders. This means, among other things, that we developed and strive to maintain a strong set of corporate values that will inspire ethical behavior across all decision-making processes, and a management and control system so that ethics and security issues are given their due weight. This includes the following highlights: • Corporate Governance and Board Practices: Our corporate governance policies and practices are designed to foster effective board oversight in service of the long-term interests of our shareholders. A majority of the members of our Board of Directors qualify as “independent directors” under the Nasdaq rules. The Audit, Compensation and Nomination and Corporate Governance Committees of our Board of Directors, which are charged with significant functions in our risk oversight, compensation and corporate governance philosophy, respectively, all currently consist of three members, all of whom qualify as “independent directors” under the Nasdaq rules. For further details on our corporate governance, as well as our Board of Directors and its committees’ roles and practices, see Items 6.C “Board Practices” and 16G “Corporate Governance.” • Ethical Business Conduct: All our directors, officers, consultants, service providers and employees are expected to conduct themselves in accordance with our Code of Conduct and Ethics available at http://www.radware.com/corporategovernance/ (information contained on our website, including in our Code of Conduct and Ethics, is not incorporated herein by reference and shall not constitute part of this annual report). Our Code of Conduct and Ethics is intended to promote various elements of ethical business conduct, such as compliance with laws; avoiding conflict of interests and personal exploitation of corporate opportunities; fair dealing; confidentiality of information; and other policies and guidelines in connection with insider trading and anti-corruption laws and policies. 59 C. Organizational Structure We have a wholly owned subsidiary in the United States, Radware Inc., which conducts the sales and marketing of our products and services primarily in the United States and Canada. We also have several other wholly owned subsidiaries worldwide handling primarily local sales and marketing, support and promotion activities. Our subsidiaries include (unless otherwise indicated, all subsidiaries are wholly owned, directly or indirectly): Name of Subsidiary Place of Incorporation Radware Inc. New Jersey, United States Radware UK Limited United Kingdom Radware France France Radware Srl Italy Radware GmbH Germany Nihon Radware KK Japan Radware Australia Pty. Ltd. Australia Radware Singapore Pte. Ltd. Singapore Radware Korea Ltd. Korea Radware Canada Inc. Canada Radware India Pvt. Ltd. India Kaalbi Technologies Limited Ltd. India Radware (India) Cyber Security Solutions Private Limited India Radware China Ltd. 睿伟网络科技(上海)有限公司 China Radware (Hong Kong) Limited Hong Kong Radyoos Media Ltd.* Israel Radware Iberia, S.L.U. Spain Edgehawk Security Ltd. Israel SkyHawk (CNP) Security Ltd.** Israel SkyHawk Security, Inc.*** Delaware, United States CSR Cloud Security Ltd. Israel Radware (Colombia) S.A.S. Colombia Pynt, Inc. Delaware, United States Overcast Security Ltd.*** Israel Radware Canada Holdings Inc.*** Canada * We own approximately 91.0% of this subsidiary, which ceased its activities in 2017. ** We own approximately 76.2% of this subsidiary. *** Indirect subsidiary. 60 The late Yehuda Zisapel, one of our co-founders and shareholders, was the father of Roy Zisapel, our President, Chief Executive Officer and director. Either the heirs of the late Yehuda Zisapel (namely, Roy Zisapel, Carmi Zisapel and Adi Zisapel, to which we sometime refer in this annual report as the heirs of the late Yehuda Zisapel), the heirs of his late brother, Zohar Zisapel (namely, Michael Zisapel and Klil Zisapel, to which we sometime refer in this annual report as the heirs of the late Zohar Zisapel), and Nava Zisapel, the mother of Roy Zisapel, or all of them together, are founders, directors and/or shareholders of several other companies which, together with our Company and our subsidiaries listed above, are known as the RAD-Bynet Group. These companies include, among others: AB-NET Communications Ltd. Binat Business Ltd. BYNET Data Communications Ltd.* Bynet Data Centers Ltd. CloudRide Ltd.* BYNET Electronics Ltd.* BYNET SEMECH (outsourcing) Ltd.* Bynet Software Systems Ltd. Bynet System Applications Ltd.* Ceragon Networks Ltd. Internet Binat Ltd.* Packetlight Networks Ltd. RAD-Bynet Properties and Services (1981) Ltd.* Radbit Computers, Inc. RADCOM Ltd. RAD Data Communications Ltd.* RADWIN Ltd. DC Protection Ltd. (previously known as SecurityDAM Ltd.) *Denotes a RAD-Bynet Group company with which we currently transact business. The heirs of the late Yehuda Zisapel and the heirs of the late Zohar Zisapel also hold shares in Carteav Ltd., Tupaia Ltd. and Radiflow Ltd., start-up companies that are not considered part of the RAD-Bynet group. The RAD-Bynet Group also includes several other holdings, real estate companies, and biotech and pharmaceutical companies, and the above list does not constitute a complete list of all entities within the RAD-Bynet Group or of all the holdings of the heirs of the late Yehuda Zisapel, the heirs of the late Zohar Zisapel and Nava Zisapel. Members of the RAD-Bynet Group are actively engaged in designing, manufacturing, marketing, and supporting data communications products and services, none of which currently compete with our products. Some of the products of members of the RAD-Bynet Group are complementary to, and may be used in connection with, our products and services. See also Item 7.B “Related Party Transactions.” D. Property, Plants and Equipment General. We operate from leased premises mainly in Tel Aviv, Jerusalem and Ramat Gan in Israel and New Jersey in the United States. We also lease premises in several locations in Europe, North America, South America and Asia-Pacific for the activities of our subsidiaries, representative offices and branches. Our aggregate annual rent expenses under these leases were approximately $5.4 million in 2025. 61 We believe that the following offices and facilities are suitable and adequate for our operations as currently conducted and as currently foreseen. In the event that additional or substitute offices and facilities are required, we believe that we could obtain such offices and facilities at commercially reasonable rates. Israel. Our headquarters and principal administrative, finance, research and development and marketing operations are located in approximately 108,000 square feet of leased office space in Tel Aviv, Israel, in two buildings: one building, consisting of approximately 40,000 square feet, plus storage and parking space, and the second building, consisting of approximately 68,000 square feet, plus parking spaces. Both buildings have leases that expire in June 2030 and are leased from, among others, affiliated companies owned by the heirs of the late Yehuda Zisapel, Nava Zisapel and/or the heirs of the late Zohar Zisapel, as applicable. For more information, see Item 7.B “Related Party Transactions.” In addition, we lease approximately 3,600 square feet of space in Jerusalem, Israel, for development facilities from an affiliated company owned by the heirs of the late Yehuda Zisapel and Nava Zisapel. The lease expires in July 2028. We also lease approximately 8,000 square feet for manufacturing facilities in Jerusalem, Israel, from an affiliated company owned by the heirs of the late Yehuda Zisapel, Nava Zisapel and the heirs of the late Zohar Zisapel. The lease expires in August 2028. For more information, see Item 7.B “Related Party Transactions.” We also lease approximately 6,600 square feet of space in Ramat Gan, for operations of one of our subsidiaries. The lease expires in September 2026. Other locations. In the United States, we lease approximately 16,900 square feet of property in Mahwah, New Jersey, consisting of approximately 12,700 square feet of office space and 4,200 square feet of warehouse space from a company controlled by the heirs of the late Yehuda Zisapel, Nava Zisapel and the heirs of the late Zohar Zisapel. The lease expires in March 2031. For more information, see Item 7.B “Related Party Transactions.” We lease approximately 3,850 square feet of property for our research and development facilities in North Carolina, the lease for which will expire in March 2026. We also lease facilities for the operation of our subsidiaries and representative offices in several locations in Europe, North America, South America, and Asia-Pacific, all from unrelated third parties.
AND FINANCIAL REVIEW AND PROSPECTS Our discussion and analysis of our financial condition and results of operation are based upon our consolidated financial statements, which have been prepared in accordance with U.S. GAAP. Our operating and financial review and prospects should…
AND FINANCIAL REVIEW AND PROSPECTS Our discussion and analysis of our financial condition and results of operation are based upon our consolidated financial statements, which have been prepared in accordance with U.S. GAAP. Our operating and financial review and prospects should be read in conjunction with our financial statements, accompanying notes thereto and other financial information appearing elsewhere in this annual report. 62 A. Operating Results Overview General We are a provider of application security and delivery solutions for multi-cloud environments. Our solutions secure the digital experience by providing infrastructure, application, and network protection and availability services to companies globally. Our solutions are deployed by, among others, enterprises, carriers, and cloud service providers. We began sales in 1997, and currently have 26 local offices, subsidiaries or branches globally across Asia-Pacific, Europe, and North, Central and South America. Most of our revenues are generated in dollars or are dollar-linked, and the majority of our expenses are incurred in dollars. As such, the dollar is our functional currency. Our consolidated financial statements are prepared in dollars and in accordance with U.S. GAAP. Our revenues are derived from sales of our solutions: • We recognize physical and software product revenues when control of the product is transferred to the customer (i.e., when our performance obligation is satisfied), which typically occurs at shipment, and we recognize revenues from cloud subscriptions, as part of the product revenues, ratably over the subscription period. • Revenues from post-contract customer support (PCS), which mainly represents help-desk support and unit repairs or replacements, professional services, and ERT services, are recognized ratably over the contract or subscription period, which is typically between one year and three years. Most of our sales are through channels such as resellers and distributors. Our revenues are also attributed to geographic areas based on the location of the end-users. In the years ended December 31, 2025, 2024, and 2023, revenues derived from sales of the Company’s products and product subscriptions constituted approximately 63%, 57%, and 56%, respectively, of our total revenues, with the remaining revenues being derived from services. Results of Operations The following discussion of our results of operations for the years ended December 31, 2025, 2024, and 2023, including the following tables, which present selected financial information in dollars and as a percentage of total revenues, are based upon our consolidated statements of operations contained in our financial statements for those periods, and the related notes, included in this annual report. 63 The following table sets forth, for the periods indicated, certain financial data concerning our consolidated operating results: 2025 2024 2023 (US $ in thousands) Revenues: Products 189,582 155,437 145,541 Services 112,268 119,443 115,751 $ 301,850 $ 274,880 $ 261,292 Cost of revenues: Products 49,033 42,178 41,450 Services 9,306 11,074 10,260 58,339 53,252 51,710 Gross profit 243,511 221,628 209,582 Operating expenses, net: Research and development, net 78,981 74,723 82,617 Sales and marketing 127,586 122,450 126,237 General and administrative 25,536 28,342 32,408 Total operating expenses, net 232,103 225,515 241,262 Operating profit (loss) 11,408 (3,887 ) (31,680 ) Financial income, net 17,899 16,552 13,927 Income (loss) before taxes on income 29,307 12,665 (17,753 ) Taxes on income 9,050 6,627 3,837 Net income (loss) 20,257 6,038 (21,590 ) The following table sets forth, for the periods indicated, certain financial data expressed as a percentage of our total revenues: 2025 2024 2023 Revenues: Products 63 % 57 % 56 % Services 37 43 44 100 100 100 Cost of Revenues: Products 16 15 16 Services 3 4 4 19 19 20 Gross profit 81 81 80 Operating expenses, net: Research and development, net 26 27 32 Sales and marketing 42 45 48 General and administrative 9 10 12 Total operating expenses, net 77 82 92 Operating profit (loss) 4 (1 ) (12 ) Financial income, net 6 6 5 Income (loss) before taxes on income 10 5 (7 ) Taxes on income (3 ) (2 ) (1 ) Net income (loss) 7 % 2 % (8 )% 64 Comparison of Years Ended December 31, 2025, 2024, and 2023. Revenues. Our revenues are derived from sales of our solutions. Revenues from physical products and software-based products are recognized when control of the promised goods is transferred to the customer, either upon shipment or when the product is delivered, depending on the commercial terms of each transaction. Revenues from cloud subscriptions are recognized ratably over the subscription period. Revenues from post-contract customer support, which represent mainly help-desk support, unit repairs or replacements, professional services and ERT services are recognized ratably over the contract period. For additional details regarding the manner in which we recognize revenues, see the discussion under the caption “Critical Accounting Estimates – Revenue Recognition” below. The following table provides a breakdown of our consolidated revenues by type of revenues both in dollars and as a percentage of total revenues for the past three fiscal years, as well as the percentage change between such periods: (US$ in thousands, except percentages) 2025 2024 2023 % Change 2025 vs. 2024 % Change 2024 vs. 2023 Products 189,582 63 % 155,437 57 % 145,541 56 % 22 % 7 % Services 112,268 37 % 119,443 43 % 115,751 44 % (6 )% 3 % Total 301,850 100 % 274,880 100 % 261,292 100 % 10 % 5 % The following table shows a breakdown of our consolidated revenues by geographical distribution both in dollars and as a percentage of total revenues for the past three fiscal years, as well as the percentage change between such periods: (US$ in thousands, except percentages) 2025 2024 2023 % Change 2025 vs. 2024 % Change 2024 vs. 2023 North, Central and South America (principally the United States)(*) 124,530 41 % 117,740 43 % 103,435 40 % 6 % 14 % EMEA (Europe, the Middle East and Africa) 111,253 37 % 94,075 34 % 96,488 37 % 18 % (3 )% Asia-Pacific 66,067 22 % 63,065 23 % 61,369 23 % 5 % 3 % Total 301,850 100 % 274,880 100 % 261,292 100 % 10 % 5 % (*) For the years ended December 31, 2025, 2024, and 2023, our revenues from the United States were $92.7 million, $83.4 million, and $73.0 million, respectively, representing 31%, 31%, and 28% of total revenues for these years, respectively. 65 Revenues in 2025 were $301.8 million compared with revenues of $274.9 million in 2024, an increase of 10%. The increase in revenues was primarily attributable to sustained momentum in our cloud security portfolio and the continued strong performance of DefenseProX, supported by both new customer wins and product refresh cycles. These factors contributed to robust growth in the EMEA region, where revenues increased 18% year-over-year. Revenues in 2024 were $274.9 million compared with revenues of $261.3 million in 2023, an increase of 5%. The increase in revenue was primarily attributed to the growing demand for our cloud-based solutions, especially our cloud security products, the successful DefensePro X refresh, and the increased contribution from our OEM partnerships, fueling a growth in the Americas, where revenue increased 14% year-over-year. In 2025, our product revenues were $189.6 million, an increase of 22% compared to $155.5 million in 2024. The increase in product revenues was primarily attributable to continued growth in demand for our cloud‑based DDoS protection and cloud application protection subscription products, as well as higher hardware sales across our DDoS and Alteon product lines in the EMEA region. This performance reflects both new customer acquisitions and ongoing product refresh cycles. In 2024, our product revenues were $155.5 million, an increase of 7% compared to $145.5 million in 2023. The increase in revenues is attributed primarily to an increase in our cloud DDoS protection and cloud application protection subscription products revenues, the growing demand for our cloud-based solutions, and an increase in our DefensePro X product revenues, primarily due to the successful DefensePro X refresh. In 2025, our service revenues were $112.3 million, a decrease of 6% compared to $119.4 million in 2024. The decrease in service revenues was primarily attributable to lower revenues from support services, reflecting our continued transition toward cloud‑based and subscription‑based offerings. In 2024, our service revenues were $119.4 million, an increase of 3% compared to $115.8 million in 2023. The increase in service revenues was mainly attributed to the increase in revenues from support services for our on-premises devices and an increase in our managed services revenues. During 2025, our revenues from the enterprise market increased by 7% to $232.0 million from $216.5 million in 2024, and revenues from the carrier market increased by 20% to $69.9 million from $58.4 million in 2024. During 2024, our revenues from the enterprise market increased by 8% to $216.5 million from $201.2 million in 2023, and revenues from the carrier market decreased by 3% to $58.4 million from $60.1 million in 2023. 66 Our revenues in North, Central and South America increased in 2025 by 6% compared to 2024. Revenues in the Asia-Pacific region increased in 2025 by 5% compared to 2024 and revenues in EMEA region increased in 2025 by 18% compared to 2024. Revenue growth in the North, Central and South America and Asia‑Pacific regions was primarily driven by a significant increase in revenues from our cloud security subscription products, partially offset by lower revenues from hardware products and support services. Revenue growth in the EMEA region was primarily attributable to a significant increase in revenues from our cloud security subscription products, as well as higher hardware product revenues across our DDoS and Alteon product lines. Our revenues in North, Central and South America increased in 2024 by 14% compared to 2023. Revenues in the Asia-Pacific region increased in 2024 by 3% compared to 2023. The growth in our North, Central and South America and Asia-Pacific regions revenues was mainly attributed to an increase in our cloud security subscription products revenues and our DefensePro X product revenues. Revenues from the EMEA region decreased in 2024 by 2% compared to 2023. The decrease in our EMEA region was mainly attributed to a decrease in sales of our hardware-based products, partially offset by an increase in customer services revenues. Cost of Revenues. Cost of revenues refers to both products and services revenues and consists primarily of the cost of circuit boards and other components required for the assembly of our products, salaries and related personnel expenses for those engaged in the final assembly, and in providing support and maintenance service of our products, license and hosting fees paid to third parties, fees paid to managed security service providers (related parties), inventory write-offs, amortization of acquired technology and other overhead costs. The following table sets forth a breakdown of our cost of revenues between products and services for the periods indicated, in absolute figures and as a percentage of the relative product and services revenues: (US$ in thousands, except percentages) 2025 2024 2023 Cost of Products 49,033 25.9 % 42,178 27.1 % 41,450 28.5 % Cost of Services 9,306 8.3 % 11,074 9.3 % 10,260 8.9 % Total 58,339 19.3 % 53,252 19.4 % 51,710 19.8 % Cost of products as a percentage of product revenues in 2025 was 25.9%, compared to 27.1% in 2024. Cost of products in both 2025 and 2024 included amortization of intangible assets of $4.0 million. Our cost of products as a percentage of product revenues, excluding amortization of intangible assets, represented approximately 23.8% of product revenues in 2025, compared to 24.6% in 2024. Excluding amortization of intangible assets, the decrease in cost of products as a percentage of product revenues was mainly attributed to the increase in our products revenues. 67 Cost of services as a percentage of service revenues in 2025 was 8.3% compared to 9.3% in 2024. Cost of products as a percentage of product revenues in 2024 was 27.1%, compared to 28.5% in 2023. Cost of products in both 2024 and 2023 included amortization of intangible assets of $4.0 million. Our cost of products as a percentage of product revenues, excluding amortization of intangible assets, represented approximately 24.6% of product revenues in 2024, compared to 25.7% in 2023. Excluding amortization of intangible assets, the decrease in cost of products as a percentage of product revenues was mainly attributed to the increase in our products revenues. Cost of services as a percentage of service revenues in 2024 was 9.3% compared to 8.9% in 2023. Operating Expenses. The following table sets forth a breakdown of our operating expenses, net for the periods indicated as well as the percentage change between such periods: (US$ in thousands, except percentages) 2025 2024 2023 % Change 2025 vs. 2024 % Change 2024 vs. 2023 Research and development, net $ 78,981 $ 74,723 $ 82,617 6 % (10 )% Sales and marketing 127,586 122,450 126,237 4 % (3 )% General and administrative 25,536 28,342 32,408 (10 )% (13 )% Total $ 232,103 $ 225,515 $ 241,262 3 % (7 )% Operating expenses increased by 3% to $232.1 million in 2025, compared to $225.5 million in 2024. The $6.6 million increase was primarily attributable to a $4.0 million rise in personnel‑related costs, driven mainly by higher average headcount year‑over‑year and the impact of the depreciation of the U.S. dollar relative to the NIS. Additional contributors included a $2.4 million increase in payments to subcontractors and finder fees, a $1.7 million increase in hosting‑related expenses, and a $2.1 million increase in sales‑event and marketing‑related expenditures. These increases were partially offset by a $2.2 million decrease in share‑based compensation expense, as well as reductions of $0.7 million in office‑related expenses and $0.7 million in the revaluation of contingent consideration and other general and administrative costs. Our operating expenses decreased by 7% in 2024 to $225.5 million from $241.3 million in 2023. The decrease of $15.8 million was primarily attributed to a decrease of $7.9 million in share-based compensation expenses and a decrease of $5.8 million in personnel costs and related expenses, mainly due to a decrease in average headcount compared to the previous year, partially offset by an increase in incentive commissions due to better sales performances in 2024, as well as a decrease of $1.1 million in fees paid to subcontractors and a decrease of $1.0 million in marketing costs. Research and Development Expenses, Net. Research and development (“R&D”), expenses, net consist primarily of salaries and related personnel expenses, costs of subcontractors, and prototype expenses related to the design, development, quality assurance and enhancement of our solutions, and depreciation of equipment purchased for the development and testing processes. All R&D costs are expensed as incurred. We believe that continued investment in R&D is critical to attaining our strategic product objectives. 68 R&D expenses, net, were $79.0 million in 2025, an increase of $4.3 million, or 6%, compared with R&D expenses, net of $74.7 million in 2024. This increase was primarily attributable to: (1) a $2.9 million increase in personnel‑related expenses, mainly reflecting higher average headcount compared to the prior year and the impact of the weakening of the U.S. dollar relative to the NIS; (2) a $1.3 million increase in amounts paid to subcontractors; and (3) a $0.4 million increase in hosting fees, partially offset by a $0.4 million decrease in share‑based compensation expenses (see also “Share‑based compensation expenses” below). R&D expenses, net, were $74.7 million in 2024, a decrease of $7.9 million, or 10%, compared with R&D expenses, net of $82.6 million in 2023. This decrease was primarily a result of: (1) a $5.2 million decrease in personnel costs, mainly due to a decrease in average headcount compared to the previous year, (2) a $1.1 million decrease in amounts paid to subcontractors, and (3) a decrease of $2.4 million in share-based compensation expenses (see also “Share-based compensation expenses” below), partially offset by a $0.7 million increase in hosting fees. Sales and Marketing Expenses. Sales and marketing expenses consist primarily of salaries, commissions, and related personnel expenses for those engaged in the sales and marketing of our products and services, operational costs of our offices that are located outside Israel and are engaged in the promotion, marketing and support of our solutions, in addition to the related trade shows, advertising, promotions, website maintenance, and public relations expenses, and amortization of intangible assets. Sales and marketing expenses were $127.6 million in 2025, an increase of $5.1 million, or 4%, compared with sales and marketing expenses of $122.5 million in 2024. This increase was primarily attributable to: (1) a $2.1 million increase in sales‑events and marketing‑related expenses; (2) a $1.3 million increase in hosting fees, reflecting greater reliance on cloud‑based infrastructure to support sales enablement tools, customer trials, and other selling activities; (3) a $1.1 million increase in amounts paid to subcontractors and finder fees; and (4) a $1.2 million increase in share‑based compensation expenses (see also “Share‑based compensation expenses” below), partially offset by a $0.5 million decrease in office‑related costs. Sales and marketing expenses were $122.5 million in 2024, a decrease of $3.7 million, or 3%, compared with sales and marketing expenses of $126.2 million in 2023. This decrease was mainly related to a decrease of $1.0 million in personnel costs, due to a decrease in average headcount compared to the previous year, partially offset by an increase in sales incentive commissions, a decrease of $1.7 million in share-based compensation expenses (see also “Share-based compensation expenses” below) and a decrease of $1.0 million in marketing related costs. General and Administrative Expenses. General and administrative expenses consist primarily of salaries and related personnel expenses for executive, accounting, and administrative personnel, professional fees (which include legal, audit and additional consulting fees), bad debt expenses, acquisition related costs, and other general corporate expenses. General and administrative expenses were $25.5 million in 2025, a decrease of $2.8 million, or 10%, compared to a general and administrative expenses of $28.3 million in 2024. The decrease in general and administrative expenses in 2025 was primarily attributable to: (1) a $3.0 million decrease in share‑based compensation expenses (see also “Share‑based compensation expenses” below); (2) a $0.2 million decrease in professional fees; (3) a $0.5 million decrease related to the revaluation of contingent consideration recorded in connection with the acquisition of the SecurityDAM; and (4) a $0.3 million decrease in other general and administrative expenses. These decreases were partially offset by a $1.2 million increase in personnel‑related expenses. 69 General and administrative expenses were $28.3 million in 2024, a decrease of $4.1 million, or 13%, compared to a general and administrative expenses of $32.4 million in 2023. The decrease in general and administrative expenses in 2024 was primarily due to (1) a $3.8 million decrease in share-based compensation expenses (see also “Share-based compensation expenses” below), and (2) a decrease of $0.4 million related to revaluation of contingent consideration recorded as part of the acquisition of the business of SecurityDAM. For a discussion of the impact of foreign currency fluctuations on our business, see Item 11 “Quantitative and Qualitative Disclosures about Market Risk.” Share-based compensation expenses. Our expenses also include the recognition of share-based compensation, which is allocated among cost of sales, research, and development expenses, sales and marketing expenses and general and administrative expenses, based on the division in which the recipient of the option grant is employed. The share-based compensation is amortized to operating expenses over the requisite service period of the individual options. The following tables summarize the share options and restricted share units (RSUs) that were granted during the years 2025, 2024 and 2023, and their weighted average grant-date fair value: Share options: 2025 2024 2023 Grants 120,000 299,856 331,899 Weighted-average grant-date fair value 7.83 6.11 5.48 RSUs: 2025 2024 2023 Grants 1,077,315 1,517,180 1,390,718 Weighted-average grant-date fair value 26.02 21.49 15.82 Share-based compensation expenses in 2025 totaled $24.0 million, a decrease of $2.0 million, or 8%, compared with expenses of $26.0 million in 2024. The decrease in our share‑based compensation expenses in 2025 was primarily attributable to a $3.0 million decrease in general and administrative expenses, reflecting lower expenses associated with equity‑based grants made to our Chief Executive Officer in previous years, and a $0.4 million decrease in research and development expenses, mainly due to lower grants made in 2025 compared to 2024. These decreases were partially offset by a $1.2 million increase in sales and marketing expenses, primarily reflecting higher equity‑based grants awarded to our new U.S. sales leadership team. 70 Share-based compensation expenses in 2024 totaled $26.0 million, a decrease of $8.0 million, or 24%, compared with expenses of $34.0 million in 2023. The decrease in our share-based compensation expenses in 2024 was mainly due to RSU grants made at a lower weighted-average price granted towards the end of 2023, which resulted in recording lower expenses in 2024 and lower expenses from the equity-based grants made to our Chief Executive Officer during 2022. Financial Income, Net. Financial income, net consists primarily of interest earned on short- and long-term bank deposits, amortization of premiums, accretion of discounts, interest and dividends earned on investments in marketable securities, gain from the sale of marketable securities and from income and expenses from the translation of monetary balance sheet items denominated in non-dollar currencies. Financial income, net was $17.9 million in 2025, compared with $16.6 million in 2024. The net increase of $1.3 million was primarily attributable to higher average interest rates on our bank deposits, which generated a $3.4 million increase in interest income and gains from investments and bank deposits. These increases were partially offset by a $2.0 million decline in foreign currency exchange gains, principally reflecting the revaluation of balance sheet items denominated in foreign currencies.. Financial income, net was $16.6 million in 2024, compared with $13.9 million in 2023. The net increase of $2.7 million was primarily due to higher average interest rates on our bank deposits, which resulted in a $3.9 million increase in interest income and gains from our investments and bank deposits, partially offset by a $1.4 million decrease in foreign currency exchange gains, mainly due to revaluation of balance sheet items stated in foreign currencies. Income Taxes. Israeli companies are generally subject to corporate tax on their taxable income at the rate of 23% for the 2025, 2024, and 2023 tax years. We elected to apply the Preferred Enterprise regime under the Law for the Encouragement of Capital Investment, 1959 (the “Investments Law”) as of the 2014 tax year. The election is irrevocable. Under the Preferred Enterprise regime, a preferred income of an enterprise located in the center of Israel is subject to a tax rate of 16%. Pursuant to Amendment 73 to the Investments Law adopted in 2017, a company located in the center of Israel that meets the conditions for “Preferred Technological Enterprises” is subject to a tax rate of 12%. We believe we meet those conditions. We operate our business in various countries and attempt to utilize an efficient operating model to optimize our tax payments based on the laws in the countries in which we operate. This can cause disputes between us and various tax authorities in different parts of the world. In 2025, we recorded pre-tax income of $29.3 million compared to pre-tax income of $12.7 million in 2024, and our tax expenses were $9.1 million in 2025, an increase of $2.5 million, or 38%, compared with tax expenses of $6.6 million in 2024. The increase in tax expenses was mainly attributed to the increase of 130% in our pre-tax income compared to the previous year. In 2025, Radware Ltd. was subject to a routine examination by the Israel Tax Authority with respect to its tax returns for the 2019–2022 tax years. In December 2025, Radware Ltd. entered into a settlement agreement with the Israel Tax Authority, thereby concluding the examination. We have previously recorded adequate tax provisions to fully cover the obligations arising from the settlement. Accordingly, the audit findings and related agreement did not have a material impact on our consolidated statements of operations or overall tax expense. 71 In 2024, we recorded pre-tax income of $12.7 million as compared to pre-tax loss of $17.8 million in 2023, and our tax expenses were $6.6 million in 2024, an increase of $2.8 million, or 73%, compared with tax expenses of $3.8 million in 2023. The increase in tax expenses was mainly attributed to the increase in our pre-tax income compared to the previous year and to an increase in our uncertain tax positions provision. For additional disclosure and explanations regarding our income taxes, including the Preferred Technology Enterprise program, see Note 14 to our consolidated financial statements included elsewhere in this annual report and Item 10.E “Taxation—Israeli Tax Considerations.” Reportable Segments The Company operates in two reportable segments: • Radware’s Core Business – This segment consists of our core business operations, including our cloud security as-a-service products, application and data centers security products and our application availability products; and • The Hawks’ Business – This segment consists of the operations of our two subsidiaries: SkyHawk Security, a spinoff of our former cloud native protector business, which now provides an agentless CDR, combined with CIEM, Cloud Security Posture Management CSPM and Autonomous Purple Team for AWS Google Cloud and Azure, and EdgeHawk, which is engaged in transforming routers and network nodes into security platforms. In February 2026, we resolved to sell or cease the operations of Skyhawk Security. The following tables set forth, for the periods indicated, certain financial data concerning our reportable segments (U.S. dollars in thousands): Year ended December 31, 2025 Radware Core Hawks Total Revenues $ 301,222 $ 628 $ 301,850 Operating income (loss) $ 24,712 $ (13,304 ) $ 11,408 Year ended December 31, 2024 Radware Core Hawks Total Revenues $ 274,384 $ 496 $ 274,880 Operating income (loss) $ 9,749 $ (13,636 ) $ (3,887 ) Year ended December 31, 2023 Radware Core Hawks Total Revenues $ 260,322 $ 970 $ 261,292 Operating loss $ (16,802 ) $ (14,878 ) $ (31,680 ) 72 Revenues of the Hawks’ reportable segment were immaterial during the years ended December 31, 2023 through December 31, 2025; therefore, there is no separate discussion about revenues of each segment during those years. For a discussion about the revenues on a consolidated basis, see Item 5.A “Operating Results.” Operating expenses of the Hawks’ business consist primarily of salaries and related personnel expenses, costs of subcontractors, agent fees and share-based compensation expenses. Operating loss of the Hawks’ business was $13.3 million in 2025, $13.6 million in 2024 and $14.9 million in 2023. The decrease of $0.3 million in the operating loss of the Hawks’ segment in 2025 compared to 2024 was primarily due to a $1.3 million decrease in share‑based compensation expense, reflecting lower equity‑grant activity at SkyHawk Security in 2025, partially offset by a $1.0 million increase in personnel‑related costs, mainly attributable to higher average headcount compared to the prior year and the impact of the depreciation of the U.S. dollar relative to the NIS. The decrease of $1.3 million in the operating loss of the Hawks’ segment in 2024 compared to 2023 was primarily a result of a decrease of $1.3 million in the share-based compensation expenses and a decrease of $0.5 million in costs of subcontractors and agents. The decrease in expenses was partially offset by a decrease of $0.5 million in the segment’s revenues. Operating expenses of the Radware core business segment consist primarily of salaries and related personnel expenses including commissions paid to our sales team, marketing related expenses, hosting services fees, rent and office maintenance fees, professional services, costs of subcontractors and share-based compensation expenses. The operating income of the Radware core business segment was $24.7 million in 2025, compared to operating income of $9.7 million in 2024 and operating loss of $16.8 million in 2023. The increase of $15.0 million in the operating income in 2025 compared to 2024 was primarily a result of the increase of $26.8 million in the Radware core segment’s revenues, partially offset by an increase of $6.6 million in the segment operational expenses, mainly due to a $3.0 million increase in personnel‑related costs, driven mainly by higher average headcount year‑over‑year and the impact of the depreciation of the U.S. dollar relative to the NIS. Additional contributors included a $2.4 million increase in payments to subcontractors and finder fees, a $1.7 million increase in hosting‑related expenses, and a $2.1 million increase in sales‑event and marketing‑related expenditures. These increases were partially offset by a $1.1 million decrease in share‑based compensation expense, as well as reductions of $0.7 million in office‑related expenses and $0.7 million in the revaluation of contingent consideration and other general and administrative costs. 73 The operating income of the Radware core business segment was $9.7 million in 2024, compared to operating loss of $16.8 million in 2023 and operating income of $8.4 million in 2022. The change of $26.5 million in the operating income (loss) in 2024 compared to 2023 was primarily a result of the increase of $14.1 million in the Radware core segment’s revenues, and a $5.1 million decrease in salaries and related personnel costs, mainly due to the decrease in average headcount compared to the previous year, and a decrease of $6.7 million in share-based compensation expenses, mainly due to RSU grants made at a lower weighted-average price granted towards the end of 2023, which resulted in lower expenses in 2024, and lower expenses from the equity-based grants made to our Chief Executive Officer during 2022. For additional details regarding these two reportable segments, see below and Notes 2ad and 15 to our consolidated financial statements included elsewhere in this annual report. Currency Fluctuations and Inflation Our financial results may be negatively impacted by foreign currency fluctuations and inflation. Information required by this section is set forth in Item 11 “Quantitative and Qualitative Disclosures about Market Risk” and in Item 3.D “Risk Factors—Currency exchange rates and fluctuations of exchange rates could have a material adverse effect on our results of operations.” Impact of Governmental Policies For information on the impact of governmental policies on our operations, see Item 4.B “Business Overview—Government Regulations,” Item 3.D “Risk Factors—Laws, regulations and industry standards affecting our business are evolving, and unfavorable changes could harm our business,” and Item 3.D “Risk Factors—Risks Related to Operations in Israel.” Related Parties We have entered into a number of agreements for the lease of real property and the purchase of certain products and services from certain companies, of which the heirs of the late Yehuda Zisapel, the heirs of the late Zohar Zisapel, and/or Nava Zisapel are co-founders, directors and/or shareholders, which form part of the RAD-Bynet Group. In February 2022, we also acquired the technology and operations of SecurityDAM, one of these RAD-Bynet Group entities. The heirs of the late Yehuda Zisapel, including his son, Roy Zisapel, our President and Chief Executive Officer and a director, hold all of the outstanding shares of SecurityDAM. Roy Zisapel also serves as a director of RAD Data Communications Ltd., Bynet Electronics Ltd., AB-NET Communications Ltd. and its wholly owned subsidiary, Bynet Data Centers Ltd., Bynet Data Communications Ltd. (and its wholly owned subsidiary RAD Negev Ltd.), and other companies in the RAD-Bynet Group. We have also entered into a number of agreements for the purchase of certain products and services from several companies, in which Yuval Cohen, Chairperson of our Board of Directors, or Fortissimo Capital (in which Mr. Cohen is the founder and managing partner), are shareholders and/or serve as directors. We refer to such companies as the “Fortissimo Portfolio Companies.” We believe that the terms of the transactions in which we have entered with these member entities of the RAD-Bynet Group or with any of the Fortissimo Portfolio Companies are not different in any material respect from terms we could obtain from third parties not associated or affiliated with us and are beneficial to us and no less favorable to us than terms that might be available to us from third parties. The pricing of the transactions was determined based on negotiations between the parties. Members of our management reviewed the pricing of the agreements and confirmed that they were not different in any material respect than that which could have been obtained from third parties not associated or affiliated with us. For more details about these transactions, see below under Item 7.B “Related Party Transactions.” 74 B. Liquidity and Capital Resources General In the past several years, we have financed our operations primarily through cash generated by operations. Cash and cash equivalents, short- and long-term bank deposits and short- and long-term marketable securities were $460.6 million on December 31, 2025, compared with $419.7 million and $363.7 million on December 31, 2024 and 2023, respectively. Principal Capital Expenditures and Divestitures Capital expenditures were $8.5 million, $5.3 million, and $5.4 million for the years ended December 31, 2025, 2024, and 2023, respectively. These expenditures were mainly comprised of investments in computers and peripheral equipment, lab equipment and testing tools, office furniture and equipment and leasehold improvements. In 2026, we anticipate that the majority of our capital expenditures will be primarily for additional infrastructure to support our cloud-based solutions and for R&D testing, lab equipment and computers. We did not have any principal divestitures in the past three years. Working Capital and Cash Flows The following table presents the major components of net cash flows used in and provided by operating, investing, and financing activities for the periods presented (dollars in thousands): 2025 2024 2023 Net cash provided by (used in) operating activities $ 50,091 $ 71,609 $ (3,500 ) Net cash provided by (used in) investing activities (30,070 ) (39,520 ) 92,779 Net cash used in financing activities (13,657 ) (3,913 ) (64,926 ) Net cash provided by (used in) operating activities for 2025, 2024 and 2023 was $50.1 million, $71.6 million, and $(3.5) million, respectively. Our net income (loss) in 2025, 2024, and 2023 was $20.3 million, $6.0 million, and $(21.6) million, respectively. The change resulted primarily from a decrease of $2.0 million in share-based compensation, a $21.6 million decrease in trade receivables, an $11.1 million decrease of accrued interest on bank deposits and a decrease of $4.4 million in other assets. All offset by an increase of $14.2 million in net income, an increase of $1.3 million in deferred revenues, and a $1.7 million increase in lease liabilities, net. 75 Net cash provided by operating activities was $71.6 million for the year ended December 31, 2024, compared to net cash used in operating activities of $3.5 million for the year ended December 31, 2023. The change resulted primarily from an increase of $27.6 million in net income, an increase of $14.7 million in other payables and accrued expenses, an increase of $20.5 million in deferred revenues, an increase of $6.6 million in accrued interest on bank deposits, an increase of $5.6 million in inventories, an increase of $3.4 million in trade payables, and a $6.0 million increase in trade receivables. These increases were partially offset by a decrease of $8.0 million in share-based compensation and a $2.2 million decrease in amortization of premium, accretion of discounts and accrued interest on marketable securities. Net cash used in investing activities was $30.1 million for the year ended December 31, 2025, compared to net cash used in investing activities of $39.5 million for the year ended December 31, 2024. The change was primarily due to a net decrease of $16.1 million in investments in short-term, long-term and other deposits offset by a net increase of $3.3 million in capital and increase in proceeds from marketable securities in the amount of $3.3 million. Net cash used in investing activities was $39.5 million for the year ended December 31, 2024, compared to net cash provided by investing activities of $92.8 million for the year ended December 31, 2023. The change was primarily due to a net increase of $134.1 million in investments in short-term, long-term and other deposits. Net cash used in financing activities was $13.7 million for the year ended December 31, 2025, an increase of $9.7 million compared to net cash used in financing activities of $3.9 million for the year ended December 31, 2024. The increase in net cash used in financing activities was mainly attributed to the $10.5 million in repurchase of our ordinary shares during 2025. Net cash used in financing activities was $3.9 million for the year ended December 31, 2024, a decrease of $61.0 million compared to net cash used in financing activities of $64.9 million for the year ended December 31, 2023. The decrease in net cash used in financing activities was mainly attributed to the decrease of $62.4 million in repurchase of our ordinary shares, partially offset by a $1.0 million increase in the contingent consideration paid to SecurityDAM. Cash, Cash Equivalents and Marketable Securities As of December 31, 2025, we had cash and cash equivalents, including short- and long-term bank deposits and short- and long-term marketable securities, of $460.6 million, compared to $419.7 million as of December 31, 2024 and $363.7 million as of December 31, 2023. As of December 31, 2025, all of our short- and long-term bank deposits were deposited in Israel with major Israeli banks, which are all rated ilAAA, as determined by S&P’s Maalot. As of December 31, 2025, the longest contractual duration of any of our bank deposits was 3.0 years, the weighted-average duration of our deposits was 1.89 years, and the weighted average time to maturity was 1.06 years. Our marketable securities portfolio includes investments in debt securities of corporations, debt securities of U.S. government and in foreign banks and government debentures. The financial institutions that hold our marketable securities are major U.S. financial institutions, located in the United States. As of December 31, 2025, 98% of our marketable securities portfolio was invested in debt securities of corporations and 2% in financial institutions. From a geographic perspective, 89% of our marketable securities portfolio was invested in debt securities of U.S. issuers, 5% was invested in debt securities of European issuers and 6% was invested in debt securities of other geographic-located issuers. As of December 31, 2025, 82% of our marketable securities portfolio was rated A- or higher and 18% was rated BBB+, as determined by S&P. 76 There are no material legal restrictions, taxes, or other costs associated with transferring our funds held in U.S. financial institutions to Israeli financial institutions, and we have access to all of our cash as needed for our operations. Although we have various subsidiaries throughout the world, there are no material legal, tax, or other cost impediments to our transferring cash to these subsidiaries for operations as and when needed or to such subsidiaries transferring cash to us to meet our own cash obligations. Further, we believe we generate sufficient cash from our Israeli operations to fund our operating and capital requirements and, therefore, do not need or intend to repatriate any of the earnings of our foreign subsidiaries. Other Material Contractual Obligations The following table summarizes our material contractual obligations as of December 31, 2025 and the effect those commitments are expected to have on our liquidity and cash flow. Payments Due by Period (US $ in thousands) Contractual obligations Total Less than 1 year* 1-3 years 3-5 years More than 5 years Operating leases (1) 18,011 5,315 8,237 4,459 - Total contractual cash obligations (2) 18,011 5,315 8,237 4,459 - * Become due during 2026. (1) Consists of outstanding operating leases for the Company’s facilities. The lease agreements expire in the years 2025 to 2030, although certain of our leases have renewal options. (2) Severance payments of $5.2 million are payable only upon termination, retirement, or death of the respective employee, and there is no obligation for benefits accrued prior to 2007 if the employee voluntarily resigns. Since we are unable to reasonably estimate the timing of settlement, such payments are not included in the table. See also Note 2(x) of our consolidated financial statements. Market Risk We are exposed to market risk, including fluctuations in interest rates and foreign currency exchange rates. Additional information about market risk is set forth in Item 11 “Quantitative and Qualitative Disclosures about Market Risk.” Outlook Our capital requirements depend on numerous factors, including market acceptance of our products and services and the resources we allocate to our operating expenses. Since our inception, we have experienced substantial increases in our expenditures consistent with growth in our operations and personnel, and we may increase our expenditures in the foreseeable future in order to execute our strategy. We anticipate that operating activities as well as capital expenditures will demand the use of our cash resources. We believe that our cash balances will provide sufficient cash resources to finance our operations and the projected marketing and sales activities and research and development efforts and other elements of our strategy for a period of no less than the next 12 months. 77 C. Research and Development, Patents and Licenses, etc. In order to accommodate the rapidly changing needs of our markets, we place considerable emphasis on research and development projects designed to improve our existing product lines, develop new product lines and customize our products to meet our customers’ needs. As of December 31, 2025, we had 406 employees and 68 subcontractors engaged primarily in research and development activities, compared to 378 employees and 71 subcontractors at the end of 2024, and 408 employees and 71 subcontractors at the end of 2023. For a further discussion of research and development, see Item 5.A “Operating Results.” For a discussion regarding the benefits provided under programs of the IIA, see Item 4.B “Business Overview—Israeli Innovation Authority.” D. Trend Information We have identified the following key trends and uncertainties that we believe will materially influence our market, financial condition and the demand for our solutions: • Applications are migrating to the public cloud. The migration to public cloud exposes organizations to new threats that require consistent security across all cloud environments. Organizations also prefer to purchase security services as a subscription, to match the subscription-based consumption of hosting services. • Datacenter architecture is changing. Datacenter architecture is changing to include various models such as a physical datacenter, a virtual datacenter, a software defined datacenter, and private or public cloud. New emerging edge clouds, new AI-datacenters processing AI-enabled applications with connectivity to AI Providers, coupled with the 5G breakouts and SD-WAN, will enable enterprises to effectively leverage cloud-native services and edge computing services. Many organizations use a mixed infrastructure that includes a combination of one or more of the above and therefore require broader overarching protection that encompasses both the datacenter and multi-cloud-based applications. In addition, this mixed environment often involves multiple vendors and creates challenges in IT staffing and operational costs, which increase the needs for hybrid cloud services, managed “single pane of glass” style security services and modern automated data center technologies. • Application modernization requires new security tools. Application infrastructure is changing, from monolithic applications to modern applications and websites in which deployment workflows, front-end built-tools and API-centric architectures are used. The rise of cloud-native ecosystems, increasingly adapting cloud-direct and micro-services architecture packaged as containers, is providing a built-in “on-demand” elasticity and availability application infrastructure. This enables introducing and running the new generation of cloud-native applications, in a fast, adaptive and more efficient way by interacting with DevOps CICD tools and methods. As such, the AppSec blast radius is expanded and requires injection of security controls within the application lifecycle at early stages, to avoid slowdown in development, to sanitize, for example, usage of opensource software used by developers and might leak in malicious code (recent Log4J library). Various “shift-right” and “shift-left” methods are used and specifically adapted for various target deployment environments. 78 • The above-mentioned cloud-native application delivery opens the door for leakage through the open cloud interface. A new family of attack surfaces manifested by the fact that the cloud APIs are publicly published, and DevOps processes are done from the outside of the cloud “perimeter” (the insider becomes the outsider). “Cloud-native” infiltrations are enabled by the usage of cloud-IAM (identify and access) misconfigurations or account take over techniques and by various vulnerabilities of publicly exposed web and API interfaces. This creates a need for a new protection posture for compliance, permissions hardening, vulnerabilities detection as well as cloud-native detection (infiltrations and exfiltration) and response tools under new industry categories: CIEM (Cloud Infrastructure Entitlement Management), CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protector Platform), and CTDR (Cloud Threat Detection and Response). • Organizations’ attack surfaces are increasing due to a changing economy. This was caused by a combination of two forces. First, working from home, primarily due to the restraints associated with COVID-19, required organizations to enable remote access to applications and services that were previously not exposed. The second wave of remote and automated trade is boosted mainly by the “API economy” (a term used to describe that all of the enterprise communication is built on top of the APIs and all platforms expose the APIs to exchange data, thereby exposing them to cyber attacks) where both B2B and B2C transactions are using machines for trade automations. This eliminated the traditional network perimeter, and now, even after The World Health Organization determined that COVID-19 no longer fit the definition of a public health emergency, every home computer or mobile device has become the new perimeter. Second, an increase in the online consumption of goods has accelerated organizations’ digital transformation and migration to the cloud. The result is more opportunities for attackers to leverage the increased attack surface. • Increasing complexity and intensity of security threats, including new AI-weaponized attacks. The collapsed boundaries between data and instructions, between agents and employees creates new silent exit blind spots, opening the door for the new ‘zero-click’ attack surfaces. The increasing complexity and intensity of the security threats landscape requires expertise in identifying the attacks and state-of-the-art security to mitigate the attacks and safeguard the assets. Attack delivery is aided by the growing presence of connected devices (IoT), which increases the threat surface against any kind of infrastructure, as well as traffic encryption (dark data) assisting in hiding attacks. We have also observed a new generation of availability attacks against application infrastructure utilizing new generation of Web/L7 DDoS tools that aim to evade all network DDoS/L3-4 protections. Furthermore, attack tools are increasingly available to all through the dark net and becoming more sophisticated as hackers use automation and weaponize AI. Increasing focus is currently centered around the new opportunities of weaponizing AI enabled by foundation models as well as customized weaponized SLMs . This leads to ever morphing and scalable attack vectors at all levels, from volumetric botnets through web and API-centric attacks, as well as new attack surfaces that utilize Kubernetes-platforms (container orchestration platform of choice). The mass amount of uncontrolled IoT devices and cloud hosting opens the door for a new generation of botnets and automated bots that are hard to classify and block. Most organizations are not able to keep up with these developments with their internal cybersecurity resources and seek managed security services. 79 • Increasing expectations for applications availability and frictionless performance, due to the increasing dependence on applications in today’s business world. Businesses are sensitive to the resilience and availability of their applications, given their customers’ expectations of flawless experience and optimal performance. As such, exposed web and API based applications and shortly also Agentic applications and Agentic commerce, are the target for attackers that utilize both the server side as well as the client/browser side platforms for spreading their malicious code. New security controls utilize the power of AI and machine learning to control the delivery of AppSec services (control false positives) as well as detection of zero-days and the new zero-click attacks for Agentic-centric applications. See also the discussion under Item 4.B “Business Overview–Our Growth Strategy” and “Business Overview–Competition” above and the risks and uncertainties described under Item 3.D “Risk Factors.” E. Critical Accounting Estimates In many cases, the accounting treatment of a particular transaction is specifically dictated in U.S. GAAP and does not require management’s judgment in its application. There are also areas in which management’s judgment in selecting among available alternatives would produce a materially different result. Our management has reviewed these critical accounting policies, estimates and related disclosures with the Audit Committee of our Board of Directors. See Note 2 to our consolidated financial statements included elsewhere in this annual report, which contains additional information regarding our accounting policies, estimates and other disclosures required by U.S. GAAP. Our management believes that the significant accounting policies that affect its more significant judgments and estimates used in the preparation of its consolidated financial statements and that are the most critical to aid in fully understanding and evaluating our reported financial results include the following: • Revenue recognition; • Investment in marketable securities; • Goodwill and impairment of long-lived assets; • Share-based compensation; and • Income taxes. Revenue Recognition. We recognize revenues in accordance with Accounting Standards Codification (ASC) No. 606, “Revenue from Contracts with Customers.” As such, we identify a contract with a customer, identify the performance obligations in the contract, determine the transaction price, allocate the transaction price to each performance obligation in the contract and recognize revenues when (or as) we satisfy a performance obligation. The transaction price is determined based on the consideration which we expect to be entitled to in exchange for transferring the promised goods or services to our customer. This transaction price is exclusive of amounts collected on behalf of third parties, such as sales tax and value-added tax. Payment terms and conditions vary by contract type, although terms generally include a requirement to pay within less than a year. 80 Our solutions are sold primarily through distributors and resellers, all of which are considered end-users. Our arrangements typically contain various combinations of our products, subscriptions and PCS, which are distinct and are accounted for as separate performance obligations. We allocate the transaction price to each performance obligation based on its relative standalone selling price (“SSP”). If the SSP is not observable, we estimate the SSP taking into account available information such as geographic specific factors, customer grouping and internally approved historical pricing guidelines related to the performance obligation. For PCS and subscriptions, we determine the standalone selling price based on observable renewals prices or standalone subscription transactions. For products, the SSP is not observable, and therefore, we estimate the product SSP taking into account available information such as geographic specific factors, customer grouping and internally approved historical pricing guidelines. Deferred revenues represent mainly the unrecognized revenue collected for subscriptions and for PCS. Such revenues are recognized ratably over the term of the related agreement and are classified as short- and long-term based on their contractual term. We record a provision for estimated sale returns, credits and stock rotation granted to customers on our products in the same period that the related revenues are recorded in accordance with ASC 606. Those estimates are based on historical sales returns and other factors known to us. Such provisions amounted to $12.5 million and $5.3 million as of December 31, 2025 and 2024, respectively. Investment in Marketable Securities. We account for investments in marketable securities in accordance with Accounting Standards Codification (“ASC 320”), “Investments – Debt Securities.” Management determines the appropriate classification of our investments at the time of purchase and reevaluates such determinations at each balance sheet date. We classified all our debt securities as available-for-sale marketable securities. Debt securities are carried at fair value, with the unrealized gains and losses reported in “accumulated other comprehensive income (loss)” in shareholders’ equity, except for changes in allowance for expected credit losses, which is recorded in financial income, net. Realized gains and losses on sales of investments are included in financial income, net and are derived using the specific identification method for determining the cost of securities. The amortized cost of debt securities is adjusted for amortization of premiums and accretion of discounts to maturity. Such amortization together with interest on securities are included in financial income, net. We periodically evaluate our available-for-sale debt securities for impairment. If the amortized cost of an individual security exceeds its fair value, we consider our intent to sell the security or whether it is more likely than not that we will be required to sell the security before recovery of its amortized basis. If either of these criteria are met, we write down the security to its fair value and record the impairment charge in financial income, net in our consolidated statements of income (loss). If neither of these criteria are met, we determine whether credit loss exists. Credit loss is estimated by considering changes to the rating of the security by a rating agency and any adverse conditions specifically related to the security, as well as other factors. Credit loss impairments for both the years ended December 31, 2025 and 2024 were immaterial. 81 Goodwill and impairment of long-lived assets. Goodwill represents the excess of the purchase price in a business combination over the fair value of the net tangible and intangible assets acquired. Under ASC 350 “Intangibles – Goodwill and Other” (ASC 350), goodwill is not amortized, but rather is subject to an annual impairment test. ASC 350 requires goodwill to be tested for impairment at least annually or between annual tests in certain circumstances and written down when impaired. Goodwill is tested for impairment by comparing the fair value of each reporting unit with its carrying value. ASC 350 allows an entity to first assess qualitative factors to determine whether it is necessary to perform a quantitative goodwill impairment test. If the qualitative assessment does not result in a more likely than not indication of impairment, no further impairment testing is required. If the entity elects not to use this option, or if the entity determines that it is more likely than not that the fair value of a reporting unit is less than its carrying value, then the entity prepares a quantitative analysis to determine whether the carrying value of a reporting unit exceeds its estimated fair value. If the carrying value of a reporting unit exceeds its estimated fair value, the entity recognizes an impairment of goodwill for the amount of this excess. We conduct our annual test of impairment for goodwill on December 31 of each year, or more frequently if impairment indicators are present. No impairment loss was recorded during each of 2025, 2024, and 2023. Share-based compensation. We account for share-based compensation in accordance with ASC 718, “Compensation-Stock Compensation” (ASC 718). ASC 718 requires companies to estimate the fair value of equity-based payment awards on the date of grant using an option-pricing model. The value of the portion of the award that is ultimately expected to vest is recognized as an expense over the requisite service periods in our consolidated statements of income (loss). Some of our subsidiaries have share option plans pursuant to which qualified directors and employees may be granted options for the purchase of securities of the subsidiaries. Share-based compensation expenses recorded on the subsidiaries' level are presented in non-controlling interests. We recognize compensation expenses for the value of our awards based on the accelerated attribution method over the requisite service period of each of the awards, net of estimated forfeitures. Forfeitures are estimated at the time of grant and revised, if necessary, in subsequent periods if actual forfeitures differ from those estimates. Estimated forfeitures are based on actual historical pre-vesting forfeitures. We selected the Black-Scholes-Merton option pricing model to account for the fair value of our share-options awards with only service conditions and whereas the fair value of the RSUs awards is based on the market value of the underlying shares at the date of grant. On July 28, 2022, our shareholders approved an equity grant to the Chief Executive Officer of the Company, which is comprised of RSUs, market-condition based RSUs and market-condition based share options. The equity grant includes grants for the years 2022, 2023, and 2024 and are fixed monetary amounts ($7.725 million, $5.0 million and $5.0 million, respectively). Market-condition based RSUs’ vesting is dependent upon the fulfillment of certain market conditions and will vest, or partially vest, depending on the Company's share performance compared to other companies that are listed on the NASDAQ CTA Cybersecurity Index over the requisite service period, which is up to three years. Market-based condition share options’ vesting is dependent upon the fulfillment of certain market conditions and will vest depending on the Company's share performance over the requisite service period, which is up to three years. 82 The fair value of the market-condition based awards was determined using a Monte Carlo simulation methodology. The option-pricing model requires a number of assumptions, of which the most significant are the expected stock price volatility and the expected option term. Expected volatility was calculated based upon actual historical stock price movements over a historical period equivalent to the option’s expected term. The expected option term represents the period of time that options are expected to be outstanding. Expected term of options is based on historical experience. The risk-free interest rate is based on the yield from U.S. treasury bonds with an equivalent term. We have historically not paid dividends and have no foreseeable plans to pay dividends. Income Taxes. We account for income taxes in accordance with ASC 740, “Income Taxes.” This statement prescribes the use of the liability method whereby deferred tax assets and liability account balances are determined based on differences between financial reporting and tax bases of assets and liabilities and are measured using the enacted tax rates and laws that will be in effect when the differences are expected to reverse. We provide a valuation allowance, if necessary, to reduce deferred tax assets to their estimated realizable value if it is more likely than not that a portion or all of the deferred tax assets will not be realized. ASC 740 contains a two-step approach to recognizing and measuring a liability for uncertain tax positions. The first step is to evaluate the tax position taken or expected to be taken in a tax return by determining if the weight of available evidence indicates that it is more likely than not that, on an evaluation of the technical merits, the tax position will be sustained on audit, including resolution of any related appeals or litigation processes. The second step is only addressed if the first step has been satisfied (i.e., the position is more likely than not to be sustained), otherwise a full liability in respect of a tax position not meeting the more likely than not criteria is recognized. The second step is to measure the tax benefit as the largest amount that is more than 50% likely to be realized upon ultimate settlement. We accrue interest and penalty, if any, that are related to unrecognized tax benefits in taxes on income. Although we believe we have adequately reserved for our uncertain tax positions, no assurance can be given that the final tax outcome of these matters will not be different. We adjust these reserves in light of changing facts and circumstances, such as the closing of a tax audit, the refinement of an estimate or changes in tax laws. To the extent that the final tax outcome of these matters is different than the amounts recorded, such differences will impact the provision for income taxes in the period in which such determination is made. The provision for income taxes includes the impact of reserve provisions and changes to reserves that are considered appropriate, as well as the related interest and penalties. In 2025, Radware Ltd. was subject to an examination by the Israel Tax Authority with respect to its tax returns for the 2019–2022 tax years. In December 2025, Radware Ltd. entered into a settlement agreement with the Israel Tax Authority, thereby concluding the examination. We have previously recorded adequate tax provisions to fully cover the obligations arising from the settlement. Accordingly, the audit findings and related agreement did not have a material impact on our consolidated statements of operations or overall tax expense. Accounting for tax positions requires judgments, including estimating reserves for potential uncertainties. We also assess our ability to utilize tax attributes, including those in the form of carryforwards for which the benefits have already been reflected in the financial statements. We do not record valuation allowances for deferred tax assets that we believe are more likely than not to be realized in future periods. While we believe the resulting tax balances as of December 31, 2025 and 2024 are appropriately accounted for, the ultimate outcome of such matters could result in favorable or unfavorable adjustments to our consolidated financial statements and such adjustments could be material. See Note 14 to our consolidated financial statements included elsewhere in this annual report for further information regarding income taxes. We have filed or are in the process of filing local and foreign tax returns that are subject to audit by the respective tax authorities. The amount of income tax we pay is subject to ongoing audits by the tax authorities, which often result in proposed assessments. See “Results of Operations—Income Taxes” above. 83 While we believe that we have adequately provided for any reasonably foreseeable outcomes related to tax audits and settlement, our future results may include favorable or unfavorable adjustments to our estimated tax liabilities in the period the assessments are made or resolved, audits are closed or when statutes of limitation on potential assessments expire.