← Back to ALLT filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
A. History and Development of Allot
Our History
Our legal and commercial name is Allot Ltd. We were incorporated on November 12, 1996.
We are a company limited by shares organized under the laws of the State of Israel. Our principal executive offices are located at 22
Hanagar Street, Neve Ne’eman Industrial Zone B, Hod-Hasharon 4501317, Israel, and our telephone number is +972 (9) 761-9200. We
have irrevocably appointed Allot Communications Inc. as our agent to receive service of process in any action against us in any United
States federal or state court. The address of Allot Communications Inc. is 1500 District Avenue, Burlington, MA 01803.
32
Our website address is www.allot.com. Information contained on, or that can be accessed
through, our website does not constitute a part of this annual report and is not incorporated by reference herein. We have included our
website address in this annual report solely for informational purposes. Our SEC filings are available to you on the SEC’s website
at http://www.sec.gov, which contains reports, proxy and information statements, and other information regarding issuers that file electronically
with the SEC. The information on that website is not part of this annual report and is not incorporated by reference herein.
B. Business Overview
Overview
We are a provider of leading innovative security solutions and network intelligence
solutions for mobile, fixed and cloud service providers as well as enterprises worldwide. For over 25 years, our solutions have been deployed
globally for network-based security, including mobile security, distributed denial of service (“DDoS”) protection and Internet
of Things (“IoT”) security, network and application analytics, traffic control and shaping, and more. More recently, we have
cultivated a strategic focus on the expansion and advancement of our SECaaS product offerings.
The Company delivers a unified security service for individual consumers and small
and medium-sized businesses (“SMBs”), at home, at work and on the go, with the Allot Secure product family. Our Allot Security
Management product is, to our knowledge, the only platform that unifies security services for mobile, fixed and 5G converged networks.
Our industry-leading network-based SECaaS solution has previously achieved high double-digit
percentage of penetration with some service providers and is used by approximately 20 million subscribers globally. Our multi-service
platforms (AllotSmart) are deployed by over 500 mobile, fixed and cloud service providers and over 1,000 enterprises.
We have a global and diverse customer base composed of mobile and fixed broadband
service providers, cable operators, satellite service providers, private networks, data centers, governments, and enterprises such as
financial and educational institutions. We have a strong backlog representing customers’ orders for products and services not yet
recognized as revenues. Backlog is subject to delivery delays or program cancellations, which are beyond our control.
With over 20 years of experience empowering service providers and enterprises to get
more out of their networks and to manage them better, we enable network operators and enterprises to detect security breaches, to protect
their own networks and their users from attacks, to clearly see and understand their networks from within, to optimize, innovate and capitalize
on every opportunity, to learn about users and network behaviors, and to improve Quality of Service (“QoS”) and reduce costs,
all while increasing value to customers and deploying new services faster.
Through our combination of innovative technology, proven know-how and collaborative
approach to industry standards and partnerships, we deliver solutions that equip service providers with the capabilities to elevate their
role as premier digital services providers and to expand into new business opportunities. We offer our customers market leading, proprietary
technologies that are powerful, diverse and scalable. In addition, we have developed significant industry know-how and expertise through
our experience in designing and implementing use cases with our large customer base.
During 2024, we defined a new strategy for the company. As part of the strategy process
Allot is becoming a cyber security-first company, operating under a single, unified business unit. Our foundations are our deep expertise
and proven capabilities combining two key areas: cybersecurity and network intelligence.
33
We have been working to leverage synergies between our existing network intelligence
assets and our security offerings including integrated cloud-based solutions focused on network visibility, traffic management, and cybersecurity
for the 5G era.
The combination creates a compelling value proposition, enabling us to deliver a highly
differentiated, fully integrated solution.
We generated total revenues of $102 million in the year ended December 31, 2025, an
increase of 11% over the prior year. In 2025, 37% of our revenues were attributable to security solutions, and 63% of our revenues were
attributable to network intelligence solutions.
Industry Overview
Security Solutions
As the number of networks, applications and network-connected devices has increased,
consumers, enterprises and SMBs have become increasingly vulnerable to cyber threats and crime, and communication service providers (“CSPs”)
have begun to encounter complex operational challenges requiring nuanced solutions.
• Network Security Threats: As reliance on the Internet has grown, service providers and enterprise networks have become increasingly vulnerable to a wide range of security threats, including DDoS attacks, spambots, malware and other threats. These attacks are designed to flood the network with traffic that consumes all available bandwidth, impeding operators’ ability to provide high quality broadband access to subscribers or preventing enterprises from using mission-critical applications. These threats also compromise network and data integrity. We believe service providers and enterprises can better protect against such attacks by detecting and neutralizing malicious traffic at very early stages, before such threats can compromise network integrity and services. In addition, there is a monetization opportunity for the service provider to monetize the network infrastructure by providing additional protection services to SMB and enterprises.
• End-User Security Threats: Broadband devices and mobile devices have also become increasingly vulnerable to online threats, such as malware, ransomware and phishing. Broadband and mobile device users have limited cyber-security expertise and therefore present easy targets for cybercriminals. In recent years, we have seen a growing demand from large and mid-size operators to offer such security services to their customers-both individual consumers and small and mid-size businesses. We believe few consumers download security applications to all of their personal devices, but CSPs are well positioned to provide security services because they are the sole providers of access to the network for their consumers, are capable of blocking attacks before they reach the consumer and have multiple touch points with consumers as trusted brands, through ongoing customer support and frequent communication.
• Emerging AI-powered cyber threats are fundamentally changing the risk landscape for communication service providers (CSPs) and their customers. Attackers now leverage generative AI to automate malware creation, craft highly adaptive phishing attacks, accelerate reconnaissance, and orchestrate multi-vector attacks that evolve in real time. This dramatically increases both the scale and sophistication of threats targeting consumers, SMBs, and critical network infrastructure. As CSPs struggle to keep pace with this escalation, the need for robust, network-based security becomes more urgent. This evolution creates a significant strategic opportunity for Allot: our AI-enhanced, network-native security architecture is uniquely positioned to detect and mitigate these dynamic, machine-driven threats at scale, enabling CSPs to protect their subscribers while driving new recurring revenue models through differentiated security offerings.
• A recent global consumer cybersecurity survey conducted by Dynata in September 2025, covering more than 3,100 mobile subscribers across the US, UK, Germany, France, Italy and Sweden, reveals a widening gap between rising concern and low protection adoption. According to the October dataset in the Consumers Survey Dynata - Oct. 25, over 61% of users were concerned about their mobile device’s security in the past 12 months, and nearly 50% report feeling more worried than a year ago—yet only approximately 36% use any protection, while approximately 50% admit they have none. This anxiety‑action gap creates a major opportunity for telcos, reinforced by the findings of the accompanying Mind the Gap - A Telco Revenue Growth Opportunity - Q4 2025, which shows that 84% of consumers trust their mobile provider to offer cybersecurity, and 67% are willing to pay monthly, especially for zero‑touch, network‑based protection. With willingness concentrated around an accessible $5/€5/£5 per month, the data points to a clear and credible conclusion: consumer worry is high, protection is low, telcos are uniquely positioned to close the gap and capture recurring revenue at scale, and we are well-positioned to help with our zero-touch, network-based protection solutions.
34
Network Visibility and Traffic Management Solutions
The rapid proliferation of broadband networks in recent years has been driven largely
by demand from users for faster and more reliable access to the Internet and by the increased number and complexity of broadband applications,
as well as the proliferation of mobile smartphones, tablets and other Internet-connected devices. As a result of this rapid proliferation,
service providers have been forced to invest heavily in network infrastructure upgrades and customer support services to maintain the
quality of experience for subscribers. Further, the cost of increasing the bandwidth in mobile networks is significantly higher than that
in wireline networks, and mobile operators require intelligent bandwidth management solutions to handle increased data traffic and the
requirement for continuous low-latency transmission. Moreover, to offset the increased investment and operational costs, CSPs need to
be able to offer premium services to consumers. To offer premium services, to guarantee high-quality delivery of content and user experience,
to optimize bandwidth utilization and to reduce operational costs, CSPs need enhanced visibility into and control of network traffic,
including visibility into the type of applications used on the network and levels of traffic generated by different subscribers.
Our Security Solutions
Our Security-as-a-Service Market Opportunity
For CSPs offering the Allot solutions as security services to their subscribers, the
Allot SECaaS solutions are offered to the CSPs on a recurring revenue basis, in which both Allot and the operator share the revenue generated
from the operator’s subscribers for the use of Allot security services, or offered for a fixed yearly fee or a fixed fee up to an
agreed number of subscribers.
Our Products
Allot provides a comprehensive security solution, referred to as Allot Secure 360,
to protect network customers, network service integrity and brand reputation. Allot’s SECaaS solutions enable operators to secure
subscribers against online threats and harmful content by providing network-based SECaaS to their customers. Allot Secure 360 provides
consumers and SMBs with a 360-degree security architecture-complete, end-to-end protection anywhere, against any cyber threat, and on
any device.
Protection for Consumers and SMBs - 360-Degree Security
• Allot Secure Management (ASM): The Allot Secure Management platform creates a unified security experience for Allot security consumers by providing an end-to-end security management infrastructure that seamlessly communicates with and integrates each enforcement point-NetworkSecure, HomeSecure, DNSecure, IoTSecure, OffnetSecure, BusinessSecure and DDoSBusinessSecure. On-net coverage is provided through NetworkSecure, HomeSecure, DNSecure, DDoS BusinessSecure and IoTSecure, and off-net coverage through OffnetSecure, and the ASM solution creates a flexible security architecture of advanced threat detection technologies in-network, at the consumer-premises equipment and at the endpoint device with network intelligence solutions, machine learning and comprehensive personalization capabilities. The ASM solution delivers a scalable platform that simplifies security service activation, system awareness, new enforcement point integration, threat event reporting and handling, operation and management by the consumer regardless of which enforcement point is active.
35
• Allot NetworkSecure: A multi-tenant solution that allows the service provider to offer opt-in security services that allow subscribers to define and enforce safe-browsing limits (Parental Control) and to prevent incoming malware from infecting their devices (Anti-Malware). Services are enforced at the network level, requiring no device involvement or battery consumption.
• Allot HomeSecure: A multi-tenant solution that allows the service provider to offer opt-in security services that allow subscribers to define and enforce safe-browsing limits (Parental Control) and to prevent incoming malware from infecting their devices (Anti-Malware). Services are enforced at the home router & network level.
• Allot DNSecure: A multi-tenant solution that allows the service provider to offer opt-in security services that allow subscribers to define and enforce safe-browsing limits (Parental Control) and to prevent incoming malware from infecting their devices (Anti-Malware). Services are enforced at the network DNS requests level, requiring no device involvement or battery consumption.
• Allot IoTSecure: A multi-tenant solution that enables CSPs to grant each of its enterprise customers a dedicated management console for monitoring and securing their mobile IoT deployments on the CSP network.
• Allot BusinessSecure: A multi-tenant solution that provides a simple, reliable and secure network for the connected business achieved through a small firmware agent installed on the business router, supported by the Allot Secure cloud, and a mobile application. These elements, working in concert, provide visibility into the network and block both external and internal attacks.
• OffnetSecure: A multi-tenant solution that functions as an extension of NetworkSecure, securing the subscribers’ devices while off the Internet, producing seamless customer protection using market leading malware protection and controls.
• Allot Secure Cloud: The Allot Secure cloud provides to each enforcement point in the security architecture up-to-date threat intelligence, web categorization and device fingerprint data. The Allot Secure cloud uses machine learning and Artificial Intelligence technologies to identify connected devices, create device-specific profiles and provide anti-virus screening.
• AllotDDoS BusinessSecure - A multi-tenant solution that allows the service provider to offer opt-in network protection services to SMB and Enterprise customers to protect their connectivity lines from DDoS attacks, to prevent traffic saturation, and to ensure uninterrupted service.
Protection for the Carriers
• DDoS Secure: A solution that provides attack detection and mitigation services that protect commercial networks against inbound and outbound Denial of Service (“DoS”) and DDoS attacks, Zero Day attacks, worms, zombie and spambot behavior.
• Smart NetProtect: Allot’s multi-layer approach provides protection from multi-vector attacks against network infrastructure, subscribers, and applications. It is composed of multiple protection capabilities: Anti-DDoS, Anti-Botnet, Firewall and QoE protection, and provides protection for legacy and modern fixed and mobile architectures, including 5GSA.
Integrated Network Visibility and Traffic Management Solutions
In addition to our comprehensive and sophisticated security offerings, our integrated
network visibility and traffic management solutions, together called AllotSmart, provide network visibility and control and allow mobile,
fixed and enterprise operators to elevate their role in the digital lifestyle ecosystem and expand into new business opportunities. AllotSmart
provides our customers with the potential to increase their revenues by monetizing network usage through value-added products and services,
implementing value-based charging and reducing costs by optimizing the delivery and performance of OTT content and cloud computing services.
AllotSmart also promotes improved customer loyalty by enabling service providers to offer a selection of service tiers and digital lifestyle
options, empowering customers to personalize their network experience. In addition, AllotSmart enables telecommunication providers to
comply with a wide range of regulatory requirements aimed to assist governments with securing the public. Our products enable both CSPs
and our governmental and law enforcement customers to monitor the content of internet traffic in order to oversee compliance with legal
and law enforcement requirements.
36
Allot Smart offering includes the following solutions:
• Smart5G: Deliver granular visibility and control of 5G network and application performance to help CSPs meet customer expectations from eMBB, mMTC, and URLLC.
• SmartVisibility: Access accurate usage data and analytics to improve network performance and deliver the services subscribers want. Make informed business decisions based on granular insights.
• SmartTraffic QoE: Leverage SmartVisibility to reap the benefits of automated congestion management and QoE optimization. Get the most out of deployed infrastructure and defer expansion.
• SmartPCC: Innovate and grow revenue by rolling out personalized service plans that cater to the unique and dynamic needs of prepaid, postpaid, and business customers.
• SmartSentinel: Navigate the regulatory landscape with flexibility and precision. Comply with URL filtering, data retention and GDPR regulations efficiently and cost effectively.
Centralized Management
The Allot NetXplorer is the management umbrella for our devices, platforms and solutions,
providing a central access point for network-wide monitoring, reporting, analytics, troubleshooting, accounting and Quality of Service
policy provisioning. Its user-friendly interface provides our customers with a comprehensive overview of the application, user, device
and network topology traffic, while its wide variety of reports provide accessible, detailed analyses of granular traffic data.
Customers
We derive a significant and growing portion of our revenue from direct sales to large
mobile and fixed-line service providers, as well as government and law enforcement entities. We generate the remainder of our revenue
through a select and well-developed network of channel partners, generally consisting of distributors, resellers, OEMs and system integrators.
In 2025, we derived 43% of our revenues from Europe, 19% from the Americas, 19% from Asia and Oceania and 19% from the Middle East and
Africa. A breakdown of total revenues by geographic location for 2023, 2024 and 2025 is set forth in the following table.
Revenues by Location
($ in thousands)
2025 % Revenues 2024 % Revenues 2023 % Revenues
Revenues
Europe $ 44,014 43 % $ 35,140 38 % $ 39,945 43 %
Asia and Oceania $ 19,236 19 % $ 24,010 26 % $ 20,547 22 %
Middle East and Africa $ 19,651 19 % $ 18,882 21 % $ 16,116 17 %
Americas $ 19,092 19 % $ 14,163 15 % $ 16,542 18 %
Total Revenues $ 101,993 100 % $ 92,195 100 % $ 93,150 100 %
37
Channel Partners
We market and sell our products to end-customers both by direct sales and through
channel partners, which include distributors, resellers, OEMs and system integrators. A significant portion of our sales occur through
our channel partners. In 2025, approximately 43% of our revenues were derived from channel partners. In some cases, our channel partners
are also responsible for installing and providing initial customer support for our products, with our continuous technical assistance.
In the majority of the cases, the partners are responsible for the initial customer support (Tier 1 support), while we act as the escalation
level. Our channel partners are located around the world and address most major markets. Our channel partners target a range of end-users,
including carriers, alternative carriers, cable operators, private networks, data centers and enterprises in a wide range of industries,
including government, financial institutions and education. Our agreements with channel partners that are distributors or resellers are
generally non-exclusive, for an initial term of one year and automatically renew for successive one-year terms unless terminated. After
the first year, such agreements may typically be terminated by either party upon ninety days prior notice.
We offer support to our channel partners. This support includes the generation of
leads through marketing events, seminars and web-based leads and incentive programs as well as technical and sales training.
Sales and Marketing
Our product sales cycle varies based on the intended use by the end-customer. The
sales cycle for initial network deployment may generally last between twelve and twenty-four months for large and medium service providers,
six to twelve months for small service providers, and one to six months for enterprises. Follow-on orders and additional deployment of
our products usually require shorter cycles. Large and medium service providers generally take longer to plan the integration of our solutions
into their existing networks and to set goals for the implementation of the technology.
Our SECaaS sales strategy is to target strategic accounts that have high revenue potential,
while ensuring small to medium sized deals have customer assurances or minimum revenue threshold. Moving forward, the number of our SECaaS
deals will likely drop, but we anticipate the total sales potential will remain the same as was expected under the prior SECaaS sales
strategy, and we believe the emphasis on larger customers with a minimum guaranteed revenues will help us achieve profitability sooner.
We focus our marketing efforts on product positioning, increasing brand awareness,
communicating product advantages and generating qualified leads for our sales organization. We rely on a variety of marketing communications
channels, including our website, trade shows, industry research and professional publications, the press and special events to gain wider
market exposure, as well as an internal cyber marketing team.
We have organized our worldwide sales efforts into the following regions: North America,
South America, Europe, the Middle East and Africa; and Asia and Oceania. We have regional offices in Spain, Italy, France, Singapore,
India, Kazakhstan, Japan, Colombia and Israel. As of December 31, 2025, our sales and marketing staff, including product management and
business development functions, consisted of 97 employees.
Service and Technical Support
We believe our technical support and professional services capabilities are a key
element of our sales strategy. Our technical staff provides project management, delivery, training, support and professional services,
as well as assists in presale activities and advises channel partners on the integration of our solutions into end-customer networks.
Our basic warranty to end-customers (directly or through our partners) is three months for software and twelve months for hardware. Generally,
end-customers are also offered a choice of one year or multi-year customer support programs when they purchase our products. These customer
support programs can be renewed at the end of their terms. Our end-customer support plans generally offer the following features:
38
• unlimited 24/7 access to our global support organization, via phone, email and online support system, provided by regional support centers;
• expedited replacement units in the event of a warranty claim;
• software updates and upgrades offering new features and protocols and addressing new and changing network applications; and
• periodic updates of solution documentation, technical information and training.
Our support plans are designed to maximize network up-time and minimize operating
costs. Our customers, including partners and their end-customers, are entitled to take advantage of our around-the-clock technical support,
which we provide through our seven support centers located in France, Israel, Singapore, India, Colombia, Spain and the United States.
We also offer our customers 24-hour access to an external web-based technical knowledge base, which provides technical support information
and, in the case of our channel partners, enables them to support their customers independently and obtain follow up and support from
us.
We also offer particular professional services, such as network audit, solution design,
project management, business intelligence reports, customer project documentation, integration services, interoperability testing and
training.
The expenditures associated with the technical support staff are allocated in our
statements of comprehensive loss between sale and marketing expenses and cost of goods sold, based on the roles of and tasks performed
by personnel.
As of December 31, 2025, our technical staff consisted of 143 employees, including 64 technical support
persons, 69 deployment and professional services engineers, 9 documentation and training persons, and 1 Management position.
Research and Development
Our research and development activities take place primarily in Israel. We also have
research and development activities in Spain and India. In addition, we use subcontractors in Israel and Poland to source research and
development engineers. We devote a significant amount of our resources towards research and development in order to introduce new products
and continuously enhance existing products and to support our growth strategy. We have assembled a core team of experienced engineers,
many of whom are leaders in their particular field or discipline and have technical degrees from top universities and have experience
working for leading Israeli or international networking companies. These engineers are involved in advancing our core technologies, as
well as in applying these core technologies to our product development activities. In previous years, our research and development efforts
have benefited from non-royalty-bearing grants from the Israel Innovation Authority. As of December 31, 2025, there are no outstanding
royalties due from us to the Israel Innovation Authority. In 2025, we received additional grants from the Israel Innovation Authority;
however, these grants do not bear royalties. Under the terms of those grants, we are required to perform our manufacturing activities
for products arising from the research and development funded by such grants within the state of Israel. The State of Israel does not
own any proprietary rights in technology developed with the Innovation Authority funding and there is no restriction related to the Israel
Innovation Authority on the export of products manufactured using technology developed with the Israel Innovation Authority funding (other
limitations on export apply under applicable law). In addition, we have received during 2025 grants from the Spain Tax Authority. For
a description of restrictions on the transfer of the technology and with respect to manufacturing rights, please see “ITEM 3: Key
Information-Risk Factors-The government grants we have received for research and development expenditures require us to satisfy specified
conditions and restrict our ability to manufacture products and transfer technologies outside of Israel. If we fail to comply with these
conditions or such restrictions, we may be required to refund grants previously received together with interest and penalties and may
be subject to criminal charges.”
39
Subcontracting
We subcontract the integration of our software products with off-the-shelf hardware
platforms provided mainly by Lenovo and Hewlett Packard Enterprise (HPE). Based on verbal understandings, Arrow ocs (Israel) performs
the integration of the software product with HPE servers, while Malam-Team (Israel) performs the integration of such software with Lenovo
Servers. Such hardware components are manufactured in accordance with the design of our products.
Some of the hardware components of our products are obtained from single or limited
sources.
The global AI industry has generated increased demand for off-the-shelf hardware components
across multiple industries, including components necessary for the production of our solutions. We carry approximately three to nine months
of inventory of key components, however this new demand has resulted in and may continue to result in shortages of components necessary
for our solutions, substantial increases in prices for such components and suppliers requiring us to increase lead times and adjust purchase
quantities of such components in advance in order to secure sufficient supply. Such shortages of components, as well as the increases
in pricing, order requirements and lead times, has and may continue to impact our cost of goods and products and our ability to supply
solutions to our customers on time.
In addition, since our products have been designed to incorporate these specific components,
any change in these components due to an interruption in supply or our inability to obtain such components on a timely basis may require
engineering changes to our products before we could incorporate substitute components. Global semiconductor shortages could increase
the possibility of making such engineering changes, or taking other remedial measures, as many of our suppliers use semiconductors in
the products we require.
Competition
We compete against large companies in a rapidly evolving and highly competitive sector
of the networking technology market, which offer, or may offer in the future, competing technologies, including partial or alternative
solutions to operators’ and enterprises’ challenges, and which, similarly to us, intensely pursue the largest service providers
(referred to as Tier 1 operators) as well as large enterprises. Our DNI technology enabled offerings face significant competition from
router and switch infrastructure companies that integrate functionalities into their platforms addressing some of the same types of issues
that our products are designed to address. This competition is expected to intensify as expansion of 5G networks progresses. The DNI market
has lower long-term visibility; therefore there is less visibility for growth in our DNI segment for 2026.
Our security products, which are offered to operators and are deployed in their networks
for the purpose of enabling them to provide security services to their end customers, are subject to competition from companies which
offer security products, based on different technology and marketing and sales approaches. Primarily we compete by providing a network
native architecture that allows zero touch operation by the end-user. Additionally, we compete on the basis of product performance, ease
of use and installation, customer support, ability to integrate multiple solutions over our management system and price.
Our security product offerings face significant competition from companies that directly
approach end customers and offer them security applications to be installed on their devices; companies that approach the business enterprise
sector through distribution channels and offer cloud security products; and companies that offer security products bundled with other
products. In addition, the emergence of new market entrants leveraging advanced AI technologies may disrupt certain use cases and customer
segments, potentially challenge our competitive position and impacting demand for our solutions. By offering our security products to
operators that provide security services to both small and medium size business and individual end customers, we aim to expand the reach
of our products.
40
See “ITEM 3: Key Information-Risk Factors-Our revenues and business may be adversely
affected if we do not effectively compete in the markets in which we operate.”
Intellectual Property
Our intellectual property rights are very important to our business. We believe that
the complexity of our products and the know-how incorporated into them makes it difficult to copy them or replicate their features. We
rely on a combination of confidentiality and other protective clauses in our agreements, copyright and trade secrets to protect our know-how.
We also restrict access to our servers physically and through closed networks since our product designs and software are stored electronically
and thus are highly portable.
We customarily require our employees, subcontractors, customers, distributors, resellers,
software testers, technology partners and contractors to execute confidentiality agreements or agree to confidentiality undertakings when
their relationship with us begins. Typically, our employment contracts also include assignment of intellectual property rights for all
inventions developed by employees, non-disclosure of all confidential information, and non-compete clauses, which generally restrict the
employee for six months following termination of employment. The enforceability of non-compete clauses in certain jurisdictions in which
we operate may be limited. See “ITEM 3: Key Information-Risk Factors-If we are unable to successfully protect the intellectual property
embodied in our technology, our business could be harmed significantly.”
The communications equipment industry is characterized by constant product changes
resulting from new technological developments, performance improvements and lower hardware costs. We believe that our future growth depends
to a large extent on our ability to be an innovator in the development and application of hardware and software technology. As we develop
the next generation products, we initiated and continuously pursue patent protection for our core technologies in the telecommunications
market. We have and plan to continue to seek patent protection in our largest markets and our competitors’ markets, for example
in the United States and Europe. As we continue to spread our business into additional markets, such as Japan and Australia, we will evaluate
how best to protect our technologies in those markets. We intend to vigorously prosecute and defend the rights of our intellectual property.
As of December 31, 2025, we had 28 in-force U.S. patents. We expect to formalize our
evaluation process for determining which inventions to protect by patents or other means.
Government Regulation
Due to the industry and geographic diversity of our operations and services, our operations are subject
to a variety of rules and regulations, including import and export controls, sanctions, privacy and data protection, and several government
agencies in the United States, the E.U. and other countries regulate various aspects of our business.
Export Controls
The export of some of our products and solutions is subject to Israeli export control
laws which are administered by the Israeli Defense Export Controls Agency (“DECA”) within the Israeli Ministry of Defense.
A license from DECA is required to develop, manufacture, integrate and export encryption products or products that incorporate encryption,
including the encryption embedded in substantially all of our products. In general, such a license is valid for one year and is granted
and renewed as a matter of course for such products. The failure to possess the necessary license can lead to sanctions, including the
denial of licenses in the future, fines, and criminal penalties. We currently operate under an export license issued pursuant to the Israeli
encryption control regime. Israeli export control laws and regulations as well as the licenses granted to us by DECA prohibit us from
exporting some of our products to customers in certain countries and require us to obtain the consent of DECA to export some of our products
to customers in certain other countries. The encryption export control regulation has been repealed and will no longer be in effect as
of March 21, 2026.
41
In addition, we are subject to U.S. export control laws and regulations, including
the Export Administration Regulations (the “EAR”) administered by the U.S. Bureau of Industry and Security (“BIS”),
and the International Traffic in Arms Regulations administered by the U.S. State Department’s Directorate of Defense Trade Controls.
In June 2025, we submitted an initial voluntary self-disclosure to the BIS related to possible export control violations in connection
with the provision of software upgrades and one expansion card to a small number of customers in Russia and our use of subcontractor software
engineers in Belarus who accessed certain of our software and technology. We have undertaken remedial steps, and we made a final submission
to BIS in March 2026. We cannot provide any assurance as to the response of BIS to our submission, including the effectiveness of our
remedial steps, and we may be subject to investigations and/or penalties.
Sanctions
Our activities are subject to certain economic sanctions laws including the laws of
the State of Israel and the United States, and our policies require us to comply with such applicable regimes, laws and regulations. In
addition, we have adopted internal policies and procedures restricting sales to certain additional countries, designated entities and
individuals.
Data Privacy
Given the global nature of our operations, we are subject to a variety of local, state,
national, and international laws and directives and regulations related to privacy and data protection, data security, data storage and
retention, data transfer and deletion, and technology protection.
Virtually every jurisdiction in which we operate has established its own legal framework
relating to privacy, data protection, and information security matters with which we and/or our customers must comply. Laws and regulations
in these jurisdictions apply broadly to the collection, use, storage, retention, disclosure, security, transfer, and other processing
of data that identifies or may be used to identify or locate an individual. Some countries and regions have passed legislation that imposes
significant obligations in connection with privacy, data protection, and information security.
United States
The United States has federal and state laws and regulations regarding privacy and
information security, including consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), data breach notification
laws, and personal data privacy laws. States continue to revise and pass new privacy-related legislation. For example, the California
Consumer Privacy Act (CCPA) and follow-on legislation in the California Privacy Rights Act (CPRA), grants California residents certain
rights to access, correct and request deletion of personal information and opt out of the sale and sharing of personal information. Similar
laws passed in various other states such as Virginia, Colorado, Connecticut, New Jersey and Texas, with effective dates through 2026.
A broad range of legislative measures also have been introduced at the federal level. Some state laws also minimize what data can be collected
from consumers and how businesses may use and disclose it.
Europe and UK
We are required to comply with the GDPR and, following the exit of the UK from the
EU, the UK equivalent. Implementation of the GDPR and the UK equivalent exposes us to two parallel data protection regimes, each of which
impose several stringent requirements for controllers and processors of personal information and could make it more difficult to and/or
more costly for us to collect, store, use, transmit and process personal information and sensitive data. Non-compliance with the GDPR
and the UK equivalent legislation may result in administrative fines or monetary penalties of up to 4% of worldwide annual revenue in
the preceding financial year or EUR20 million (or GBP 17.5 million under the UK legislation), whichever is higher for the most serious
infringements, and could result in proceedings against us by governmental entities or other related parties.
42
Israel
The Israeli Privacy Protection Law, 1981 (“PPL”), along with its regulations
such as the Israeli Privacy Protection Regulations (Data Security) 2017 (“Security Regulations”), mandates strict requirements
for processing, transferring and securing personal data. A significant amendment to the PPL, known as Amendment 13, was approved by the
Israeli Parliament in August 2024 and became effective on August 14, 2025. This amendment notably enhances the investigative powers of
the Privacy Protection Authority and increases the potential monetary sanctions for violations, which could reach millions of NIS in certain
cases. Compliance with Amendment 13 may necessitate substantial changes to our data processing practices and could involve significant
costs. Non-compliance with the PPL may lead to enforcement actions, litigation, including class actions, and substantial fines and penalties.
AI
As we continue to innovate and improve our offerings by leveraging AI, jurisdictions
are turning increasing attention to the regulation and governance of the use of AI and machine learning technologies. As these legal requirements
evolve, we may face additional scrutiny and regulation and bear increased compliance costs and other exposures associated with the regulation
of our use of such technologies. In addition, we may become subject to new or heightened legal, ethical or other challenges arising out
of the perceived or actual impact of AI on human rights, intellectual property, privacy and employment, among other issues, and we may
experience brand or reputational harm, legal liability or increased costs associated with those issues. For more information, see Item
3.D “Risk Factors—Issues in the use of AI (including machine learning) in our solutions may result in reputational harm, liability
or impact our financial results.”
Internal Cybersecurity
As a provider of innovative network intelligence and security solutions for mobile
and fixed service providers, we are particularly sensitive about the possibility of cyber-attacks and data theft. A breach of our system
could provide data information about us and the customers that our solutions protect. Further, we may be targeted by cyber-terrorists
because we are an Israeli company. We are also aware of the material impact that an actual or perceived breach of our network may have
on the market perception of our products and services and on our potential liability.
We are focused on instituting new technologies and solutions to assist in the prevention
of potential and attempted cyber-attacks, as well as protective measures and contingency plans in the event of an existing attack. For
instance, in our internal IT systems, we employ identity and access controls, next-gen endpoint protection and other security measures
that we believe make our infrastructure less susceptible to cyber-attacks. We also continuously monitor our IT networks and systems for
intrusions and regularly maintain our backup and protective systems. We have made certain updates to our IT infrastructure to enhance
our ability to prevent and respond to such threats and we routinely test the infrastructure for vulnerabilities.
We conduct periodic trainings for our employees in this respect on phishing, malware
and other cybersecurity risks to the Company. We also have mechanisms in place designed to ensure prompt internal reporting of potential
or actual cybersecurity breaches, and maintain compliance programs to address the potential applicability of restrictions on trading while
in possession of material, nonpublic information generally and in connection with a cybersecurity breach. Finally, our agreements with
third parties also typically contain provisions that reduce or limit our exposure to liability.
43
C. Organizational Structure
As of December 31, 2025, we held directly and indirectly the percentage indicated of the outstanding
capital of the following subsidiaries:
Company Jurisdiction of Incorporation Percentage Ownership
Allot Communications Inc. United States 100 %
Allot Communications Europe SARL France 100 %
Allot Communications (Asia Pacific) Pte. Limited Singapore 100 %
Allot Communications (UK) Limited (with branches in Italy and Germany) United Kingdom 100 %
Allot Communications Japan K.K. Japan 100 %
Allot Communications Africa (PTY) Ltd South Africa 100 %
Allot Communications India Private Ltd India 100 %
Allot Communications Spain, S.L. Sociedad Unipersonal Spain 100 %
Allot Communications (Colombia) S.A.S Colombia 100 %
Allot MexSub Mexico 100 %
Allot Turkey Komunikasion Hizmeleri limited Turkey 100 %
Allot Australia (PTY) LTD Australia 100 %
* Allot Ltd also holds a branch in Colombia.
D. Property, Plant and Equipment
Our principal administrative and research and development activities are located in
our approximately 43,000 square foot (4,000 square meter) facilities in Hod-Hasharon, Israel. The leases for our facilities vary in dates
and terms, with the main facility’s non-stabilized lease expiring in March 2030.
We recently closed a small office in Spain and currently lease a single 6,668.46 square
feet (619.53 square meters) facility in Spain, mainly for our sales and research and development operations, pursuant to lease agreements.
The lease agreement of this site was renewed for three years in 2023 till 2026.