Item 1. Business
Item 1. Business
Overview
We are a leading provider of networking solutions that enable next-generation networks focused on reliability, availability, scalability and cybersecurity. Our portfolio supports customers operating in the cloud, on-premise or in hybrid environments providing rapid return on their investment as well as investment protection with best-in-class technical performance. As cyber-attacks increase in volume and complexity, we integrate security as a key attribute in essentially all our solutions that further enable our customers to continue to adapt to market trends in the cloud, internet of things and the ever-increasing need for more data, building upon our strong global footprint and leadership in application and network infrastructure. Our customers include leading service providers (cloud, telecommunications, multiple system operators, cable), government organizations, and enterprises.
Industry Trends & Market Drivers
The digitization of business has made applications a critical ingredient in virtually every aspect of operations. The safety and efficiency of applications can directly impact business and financial performance, and security shortfalls can impact brand value and customer retention. The application networking and security industry is experiencing dynamic shifts in the way applications are developed, delivered, monetized and protected. Our corporate strategy and technology address these evolving needs of our customers and industry, including:
Increased Adoption of Cloud Applications . For decades, businesses operated with applications based in physical, appliance-based data centers. While these traditional applications remain central to businesses around the world, a new genre of cloud-based applications is emerging, presenting new opportunities and challenges that require organizations to reassess the visibility, performance and security of their applications. Some of these challenges relate to how a business effectively manages secure application services across various data centers and cloud types, whether private, public or hybrid clouds. Over time, more and more applications may be born in the cloud, while some applications that existed in traditional data centers may migrate to clouds as well. To address this shift, businesses will need solutions that bridge both traditional and cloud-based application environments and centrally manage all secure application services holistically in this multi-cloud world.
Increased Network Complexity and New Infrastructure Paradigms. Traditional IT vendors may need to shift from hardware-centric models to software-defined approaches across several operating environments to improve agility for critical applications, and subsequently, their business operations. Ensuring product portfolios adapt and diversify to include newer virtualized software, container-based software and cloud-based offerings are key factors determining future market leadership and competitive landscapes.
Growing Importance of Automation and Orchestration. As applications increasingly move to a multi-cloud environment, the deployment of orchestration and automation tools has become essential to efficiently automating the deployment and operations of security and application services. There is a need for increased operational efficiency and agility, improved detection and reporting of security anomalies, enhanced end-user experiences and reduced total cost of ownership (“TCO”), simplified management of distributed application services, improved capacity planning and optimized multi-cloud software lifecycle management. By deploying newly developed secure application delivery automation and predictive analytics tools, enterprises are able to visualize their application performance, detect anomalous trends and fully automate their application delivery and network security.
The Rise of DDoS Attacks. The cyberthreat landscape continues to intensify and grow. Malicious actors and cybercriminals such as hacktivists, amateur hackers, and foreign military and intelligence organizations target data centers of every type. Distributed Denial of Service (“DDoS”) attacks are increasing in size, frequency, complexity and notoriety. IT defenders are faced with the increasing sophistication of adversaries who are responsible for the size and frequency of these attacks.
A DDoS attack seeks to render a target network or website unavailable by orchestrating coordinated attacks from massive worldwide networks of compromised endpoints, called botnets. Compromised endpoints can be computing devices or “Internet of Things” driven devices like video cameras. Any internet-connected device can be vulnerable to hackers and utilized as part of a botnet.
7
Rapid growth of TLS, SSL, Encrypted Applications and Hidden Threats . Many applications use Transport Layer Security (“TLS”) and Secure Sockets Layer (“SSL”) protocols. Cyber criminals exploit the protocol to hide malicious malware within encrypted channels and carry out attacks against businesses and users. This malicious trend drives demand for greater visibility within SSL-encrypted channels. Businesses need a way to decrypt traffic and apply outbound security policies efficiently, and require an effective way to inspect, identify, and remediate malicious traffic, then re-encrypt traffic and deliver it quickly to its destination. Conducting this process efficiently without placing a “security performance tax” on the user experience is a critical requirement.
The Advent of 5G Networks and a Smart World . The growing deployment of commercial 5G networks will bring massive increases in network throughput and significant new business opportunities for mobile carriers. It will also require a new generation of security infrastructure capable of handling the growing capacity requirements and complex management needs of 5G networks. Capacity requirements increase dramatically in 5G networks due to substantial increases in concurrent sessions, lower packet size and higher connections per second. Operators must dramatically lower latency, reduce total cost of ownership, and improve efficiency which may require advanced consolidation of network functions at the core. Meanwhile, the scope and size of DDoS attacks may also increase dramatically with the proliferation of connected devices and traffic, due in large part to the expansion of Internet of Things (“IoT”)/Machine-to-Machine traffic coming from new 5G-delivered Smart World applications. To address these requirements, mobile operators will need new solutions that provide hyperscale and increased performance, richer feature sets, and rich automation, analytics and threat intelligence.
Need for Advanced Multi-Cloud Secure Application Service Solutions. To address these challenges, advanced and integrated solutions for managing secure application services across businesses’ application environments are needed. Of the many solution requirements, some of the more critical include:
• Ability to Centrally Manage Traditional and Cloud Environments. As more applications are born in the cloud, and they operate alongside traditional applications supported by on-premise and appliance-based data centers, application delivery and security solutions will be called upon to span traditional and cloud-based environments. In doing so, solutions must centrally control and manage secure application services across any combination of traditional data centers and a myriad of different clouds. To support data centers and different cloud types, solutions require a variety of form factors: hardware, software (i.e., virtual, bare metal and containers) and cloud-based offerings.
• Clear Visibility and Sophisticated Analytics. The effectiveness of application performance and security depends greatly on the level of visibility a business has into its application traffic. That visibility must be able to span any number of data centers and cloud types to ensure a holistic view of security threats and performance issues affecting applications. The deeper and clearer the visibility, the better the analytics and actionable information that can be applied to enhancing application performance and protection. Secure application service solutions must be driven by solid visibility and per-app analytics.
• Ability to Scale. Performance and security at scale are paramount in today’s dynamic application environments. Solutions need to analyze application traffic quickly and enhance performance and security in traditional and cloud-based application environments in a centrally managed manner. With the rapid adoption of IoT devices, and the advent of 5G, we believe a solution’s ability to perform at scale will be increasingly imperative.
• Sophisticated Security Functionality. Secure application service solutions must detect and mitigate sophisticated cybersecurity threats, such as malicious threats hiding in encrypted traffic and DDoS attacks. To defend against the rising volume of sophisticated cyber-attacks, solutions require exceptional performance and scale without dramatically increasing footprint and total cost of ownership.
Product Portfolio
Our product portfolio seeks to address many of the aforementioned challenges and solution requirements. The portfolio consists of six secure application solutions and two intelligent management and automation tools.
Our software solutions are available to be delivered in a variety of form factors, such as embedded in optimized hardware appliances, as bare metal software, containerized software, virtual appliances and cloud-native software. While our revenue to date has predominantly derived from delivery of our proprietary software on a perpetual license basis embedded in
8
optimized hardware, this model has begun to evolve in various ways, including among others, term licenses, subscriptions, and software-only models. Our comprehensive and flexible application solutions portfolio, combined with our Harmony Controller, positions us to address the growing need for shifting workloads to a mix of private clouds and public clouds. A10 Harmony Controller is built on microservices and container technologies and offers a multi-tenant, highly scalable controller architecture that incorporates real-time and predictive analytics at the application level and central management and orchestration of secure application services across hybrid environments, from physical data centers to public, private and hybrid clouds.
The following is an overview of our portfolio:
Secure application solutions:
1. Thunder Application Delivery Controller (“ADC”)
2. Lightning Application Delivery Controller (“Lightning ADC”)
3. Thunder Carrier Grade Networking (“CGN”)
4. Thunder Threat Protection System (“TPS”)
5. Thunder SSL Insight (“SSLi”)
6. Thunder Convergent Firewall (“CFW”)
Intelligent management and automation tools:
1. Harmony Controller
2. aGalaxy TPS
The following is a further overview of our portfolio:
Secure Application Solutions
1. Thunder Application Delivery Controller. Thunder ADC provides advanced server load balancing, including global server load balancing, high availability, aFleX scripting, aVCS, ADP multi-tenancy, SSL, offload, acceleration, caching and compression, web application firewall (“WAF”), domain name server (“DNS”) application firewall (“DAF”) and others. ADCs are typically deployed in front of a server farm within a data center, including web, application and database servers.
2. Lightning Application Delivery Controller. Lightning ADC services ADC functionality in the cloud, increasing the agility and reducing costs for customers. Introduced after the acquisition of Appcito, Inc. (“Appcito”) in 2016, Lightning ADC is a cloud-native software-as-a-service (“SaaS”) platform designed to boost the delivery and security of applications and microservices across public, private and hybrid clouds, enabling ADC-as-a-service. Central to the Lightning ADC is the SaaS-based A10 Harmony Controller, which provides central management, policy configuration, and a big data repository and analytics engine.
3. Thunder Carrier Grade Networking . Thunder CGN extends the life of increasingly scarce IPv4 address blocks and their associated infrastructure using Carrier-Grade network address translation (“CGNAT”), and also provides translation solutions to the IPv6 addressing standard. Our CGN solution is typically deployed in service provider networks to provide standards-compliant address and protocol translation services between varying types of IP addresses. It has been successfully implemented by many large service providers around the world.
4. Thunder Threat Protection System . Thunder TPS solution provides high-volume, large-scale protection for customers’ networks and server resources against massive DDoS attacks. TPS is typically deployed at the perimeter of the networks to protect internal network resources from large-scale, volumetric and multi-vector attacks. In 2017, we enhanced the TPS solution with the launch of a dedicated detector function, improved workflow and automation in aGalaxy TPS. In 2018, we enhanced our TPS detection capabilities with the One-DDoS solution, which enables Thunder ADC, CGN, and CFW solutions to act as in-line detectors to enhance application and infrastructure detection. We also added TPS Dynamic Attack Pattern Recognition (DAPR) for automatic attack learning, to identify and thwart zero-day attacks, and enhanced machine learning (ML) with always-on adaptive learning. TPS is augmented by the A10 Threat Intelligence Service which can block known
9
bad connections (i.e., IP addresses) from entering protected networks. This service is based on software licensed from ThreatSTOP, Inc. and A10 threat research.
5. Thunder SSL Insight. Thunder SSLi eliminates the inherent blind spots created by SSL encryption by offloading CPU-intensive SSL decryption functions that enable security devices to inspect and remove malware within encrypted traffic. Thunder SSLi decrypts SSL-encrypted traffic and forwards it to a third-party security device, such as a firewall, for deep packet inspection (“DPI”). Once the traffic has been analyzed and scrubbed, Thunder SSLi re-encrypts the traffic and forwards it to its intended destination.
6. Thunder Convergent Firewall. Thunder CFW addresses multiple critical security capabilities in one package by consolidating multiple security and networking functions in a single appliance, helping customers significantly lower capital and operating expenses. Its performance and scale deliver superior value to customers, all within a small form factor, and streamlines customer operations with a cloud-ready programmable platform.
Thunder CFW includes:
• A high-performance Secure Web Gateway with integrated explicit proxy, URL filtering and SSL visibility, enabling security policy enforcement for outbound HTTP/HTTPS client traffic. Our solution includes a Cloud Access Proxy to provide scalability, performance, and security to overcome deployment and operational challenges.
• A high-performance data center firewall with integrated network denial-of-service protection and server load balancing, which provides a Layer 4 stateful firewall and Layer 7 application-level gateway functionality for protecting data center applications from emerging network and DDoS threats.
• A high-performance Gi/SGi firewall with integrated network DDoS, CGNAT, ADC and application visibility. The Gi/SGi firewall protects the mobile operator infrastructures from Internet-based DDoS and other security threats.
• A high-performance IPsec VPN, a security product designed to strengthen security postures and protect application data.
Intelligent Management and Automation Tools
1. Harmony Controller. Harmony Controller provides intelligent management, automation and analytics for secure application delivery in multi-cloud environments to help simplify operations. Infrastructure and application operations teams can centrally manage and automate configuration and application policies for our Thunder and Lightning application and security services, such as load balancing, application delivery, web application firewall, SSL decryption, Gi/SGi firewall, Carrier Grade NAT and Cloud Access Proxy solutions. Configuration and control can also be automated via application program interface (“API”) and integrated with orchestration systems used within organizations. In addition, the Harmony Controller provides comprehensive infrastructure and per-application metrics and analytics for performance and security monitoring, anomaly detection and faster troubleshooting. The container-based, microservices architecture allows controller capacity to be scaled without interrupting operations. Our Harmony Controller is available in two deployment models: A10 managed software-as-a-service (“SaaS”), or as a self-managed, on-premise deployment.
2. aGalaxy TPS. a Galaxy TPS multi-device network management solution enables a network administrator to manage multiple Thunder TPS devices. aGalaxy TPS is designed to help lower operational costs by freeing up staff from repetitive tasks while increasing precision and accuracy with centralized and automated tasks, reducing the potential for human error. aGalaxy TPS is available as a hardware appliance or a software-only virtual machine. aGalaxy TPS highlights included advanced workflow and automated defense capabilities.
Product Form Factors
Our products are offered in a variety of form factors and payment models, including physical appliances and perpetual and subscription-based software licenses, as well as pay-as-you-go licensing models and FlexPool, a flexible consumption-based software model. FlexPool allows businesses to flexibly allocate and re-distribute capacity across applications, multiple clouds and data centers.
10
Thunder Series: ADC, CGN, TPS, SSLi, and CFW products are available on the Thunder Series family of physical appliances. The Thunder Series products support throughput ranges from 200 Mbps to 300 Gbps. The appliance family provides a variety of other security and performance options.
vThunder virtual appliances operate on all major hypervisor platforms, including VMware, Microsoft Hyper-V and Linux KVM. vThunder is also available from cloud providers like Amazon Web Services (“AWS”), Microsoft Azure, and service providers. The vThunder Series products support throughput ranges from 200 Mbps to 100 Gbps.
Thunder for Bare Metal is a software version of our ADC and CGN solutions that is designed to run on a variety of Intel x86 servers, allowing the customer to design and select their own hardware platform.
Lightning is a cloud-native SaaS ADC product designed to boost the delivery and security of applications and microservices across public, private and hybrid clouds. Our Lightning ADC and the A10 Harmony Controller’s multi-cloud management capabilities allow flexible application deployment across multiple clouds with the ability to maintain and manage diverse workloads. Our Lightning ADC will run natively on public cloud environments, such as Amazon Web Services, Microsoft Azure, and Google Cloud Platforms.
AX Series : Our ADC and CGN solutions are available on select older models from the AX Series line.
Underlying Technology
Since our inception, our solutions have been known for their high performance and scalability in some of the largest and most demanding networks. The value and significance of our high-performance offerings reside in our portfolio’s underlying software operating system. With the exception of Lightning ADC, our products are built on the Advanced Core Operating System (“ACOS”) platform and leverage its performance optimization and security features.
The ACOS platform is optimized for modern 64-bit central processing units (“CPUs”), which increasingly have multiple parallel processing cores that operate within a single CPU for higher efficiency and performance scalability. To maximize the capabilities of these increasingly dense multi-core CPUs, ACOS implements a proprietary shared memory architecture that provides all cores with simultaneous access to common memory. This shared memory software architecture enables our products to utilize these multi-core CPUs efficiently and scale performance with increasing CPU cores. As a result, ACOS provides customers with products that can deliver superior price performance benefits over products that lack these capabilities.
ACOS’ high-performance design enables our products to address a wide range of performance-driven networking challenges. The flexible software design of ACOS allows us to apply our portfolio to a variety of markets for a variety of needs. Some notable details about ACOS include:
High Performance and Intelligent Network Input/Output (“I/O”) Processing. In order to maximize the efficiency of high density, multi-core processors, we have developed a high-performance intelligent network I/O technology that can balance application traffic flows equitably across processor cores. Our Flexible Traffic Accelerator logic can be implemented either as software running within a standard x86 processor or a Field Programmable Gate Array (“FPGA”) semiconductor. Our Flexible Traffic Accelerator (“FTA”) also performs certain hardware-based security checks for each packet and can isolate suspicious traffic before it can impact system performance.
Scalable and Efficient Memory Usage. To improve the performance of the multi-core processor architecture, we have developed a shared memory technology to allow all processors to share common memory and the state of the system simultaneously. This avoids the overhead associated with Inter-Processor Communication architectures deployed in first-generation approaches. We optimize memory to be visible to all cores simultaneously, while minimizing communication overhead and contention among processors for allocated memory space. All processors share a common memory pool, which dynamically allocates memory space based on application processing requirements without constraints. Customers can achieve greater performance and scalability from memory and processor resources because configurations, policies and network databases are efficiently stored within a shared memory architecture.
Optimized Application Networking and Security. Once data is processed and placed into a shared memory, a processor can begin to apply ACOS common services and function-specific logic. To ensure that every processor is utilized to perform every function and thereby achieve greater system utilization, ACOS uses all processor cores
11
symmetrically for all functions and services. The ACOS common services perform a set of key operational functions, including configuration management, network I/O, aFleX scripting, Virtual Chassis System (“aVCS”), aXAPI for management integration, Application Delivery Partitions (“ADPs”), virtualization to enable multi-tenancy, and common resource management such as buffer, system memory, timer management and other internal system management tasks. ACOS features a modular software design, which improves reliability by ensuring that modifications made to one module will not have unwanted side effects on other system functions.
Other noteworthy ACOS Technologies . ACOS incorporates a number of other technologies to provide a rich environment for developing Layer 4-7 application networking solutions, including:
• aFleX Scripting. aFleX scripting technology is based on industry-standard tool command language and enables customers to write custom scripts to augment the application processing.
• ADP. ADP enables multi-tenancy in the ACOS common services so that multiple departments of an organization or multiple customers can share a physical/virtual appliance.
• aVCS. aVCS enables multiple physical/virtual appliances to be managed as a single chassis.
• aXAPI . aXAPI is an industry standard representational state transfer (“RESTful”) program interface to enable management integration for automated management.
Support & Services
One of our founding principles is to provide excellent customer support. Our global support team, with deep technical domain expertise, is part of our engineering organization and is trained across all products and solutions, and takes complete ownership of customer issues from the beginning to the end to achieve rapid response and resolution. Our consistent, high-quality customer service and technical support is a key factor in attracting and retaining customers of all sizes, as well as support services that include installation, phone support, repair and replacement, software updates, online tools, consulting and training services.
All customers receive standard warranty support for 90 days with the purchase of our products. We offer four maintenance options - Basic, Basic Plus, Gold and Platinum support programs (Platinum available in select countries). Maintenance contracts may be purchased in 12-month increments up to five years. The average maintenance contract term is approximately 18 months. We invoice channel partners or customers directly for maintenance contracts at the time of hardware purchase, and all maintenance contracts are non-cancellable and are generally renewed through the same channel as originally purchased. Software updates are provided to all customers with a current maintenance contract on a when-and-if-available basis. We maintain technical support centers in the United States, Japan, India and the Netherlands.
Thunder TPS features an enhanced support offering that includes access to the A10 DDoS Security Incident Response Team (“SIRT”). Augmenting the standard support, the offering includes access to a dedicated team of DDoS mitigation experts specializing in DDoS prevention, offering immediate assistance for mitigating attacks, and a subscription to the A10 Threat Intelligence Service, leveraging collective intelligence to block known threats.
Our professional services team provides a full range of fee-based consulting services, including pre-sale network assessment, comprehensive network analysis and capacity planning, post-sale migration and implementation services, on-site installation and ongoing support.
Customers
Our customers operate in a variety of industries, including telecommunications, technology, industrial, government, retail, financial, gaming, and education. As of December 31, 2022, we had sold our products to over 8,000 customers worldwide since our inception. Our customers include the top two United States wireless carriers, four of the top 10 United States cable providers, and the top four service providers in Japan, in addition to other global enterprises, gaming companies and governmental organizations. During the years ended December 31, 2022, 2021 and 2020, purchases from our 10 largest end-customers accounted for approximately 41%, 39% and 41% of our total revenue, respectively.
12
In 2022, two distribution channel partners accounted for 15% and 13% of our total revenue. In 2021, one distribution channel partner accounted for 12% of our total revenue. In 2020, one distribution channel partner accounted for 10% of our total revenue.
Competition
As security, 5G and cloud trends continue to gain prominence, changes in application delivery needs, cyber security threats, and the technology landscape result in evolving customer requirements. These evolving demands have expanded our addressable market into cybersecurity including DDoS protection, 5G /5G-readiness and hybrid networking, where we compete with a number of companies not included among our traditional competitors of the past. The agility and flexibility of a common management platform enables us to offer multiple product categories that are easier to manage for our customers. Our portfolio also includes container and microservices-based versions of certain of our comprehensive set of hardware, software and cloud offerings.
We do not consider any of these markets to include a single dominant company, nor do we consider the markets to be fragmented. Our main competitors fall into the following categories:
• Companies that sell network security solutions and services including DDoS protection, such as Arbor Networks Inc., a subsidiary of Netscout Systems, Symantec Corporation (through its acquisition of Blue Coat Systems, Inc. in 2016), F5 Networks, Inc. (“F5 Networks”) and Radware, Ltd;
• Companies that sell network security products, including Secure Web Gateways, SSL Insight/SSL Intercept, data center firewalls and Office 365 proxy solutions;
• Companies that sell Gi/SGi firewall and CGN products, which were originally designed for other networking purposes, such as edge routers and security appliances from vendors like Cisco Systems, Inc. (“Cisco Systems”), Juniper Networks, Inc. (“Juniper Networks”) and Fortinet, Inc. (“Fortinet”); and
• Companies that sell products in the traditional application delivery market, such as F5 Networks, Citrix Systems, Inc. (“Citrix Systems”), Avi Networks Inc. (“Avi Networks”) as well as many startups.
The key competitive factors in our markets include:
• Ability to innovate and respond to customer needs rapidly;
• Ability to detect and mitigate large-scale cyber security threats;
• Ability for products to scale with high-speed network traffic;
• Ability to address on-premise and cloud application environments in a secure, centrally managed manner;
• Ability to accommodate any IT delivery model or combination of models, regardless of form factor and customer consumption model;
• Level of customer intimacy and application know-how;
• Total cost of ownership including ease-of-use and a common platform approach for multiple products;
• Brand awareness and reputation; and
• Ability to attract and retain talented employees.
Sales and Marketing
Sales
Our high-touch sales force engages customers directly and through distribution channels. Our sales team is comprised of inside sales and field sales personnel who are organized by geography and maintain sales presence in 28 countries as of
13
December 31, 2022, including in the following countries and regions: United States, Western Europe, the Middle East, Japan, Taiwan, South Korea, Southeast Asia and Latin America. Our sales organization includes sales engineers with deep technical domain expertise who are responsible for pre-sales technical support, solutions engineering, proof-of-concept work and technical training for our distribution channel partners. Our sales team is also comprised of a channel sales organization that is expanding our market reach through partners. We may continue to grow our sales headcount, including in geographies where we currently do not have a sales presence.
Some customer sales are originated and completed by our Original Equipment Manufacturer (“OEM”) and distribution channel partners with little or no direct engagement with our sales personnel. We fulfill nearly all orders globally through our distribution channel partners, which include distributors, value added resellers and system integrators. Revenue fulfilled through our distribution channel partners accounted for 83%, 89% and 91% of our total revenue for the years ended December 31, 2022, 2021 and 2020, respectively.
Marketing
Our strategy is focused on driving greater demand for our products and services, and enabling sales to win as that demand broadens. Our marketing drives global demand generation campaigns, as well as additional awareness and demand via joint marketing campaigns with channel partners and strategic alliance partners worldwide. Our marketing also drives global awareness through industry analyst engagement, media outreach, blogs, social media and events.
Manufacturing
We outsource the manufacturing of our hardware products to original design manufacturers. This approach allows us to benefit from the scale and experience of our manufacturing partners to reduce our costs, overhead and inventory while allowing us to adjust more quickly to changing customer demand. Our manufacturers are Lanner Electronics Inc. (“Lanner”), AEWIN Technologies Co., Ltd. (“AEWIN”) and iBase. These companies manufacture and assemble our hardware products using design specifications, quality assurance programs and standards established by us. Our manufacturers procure components and assemble our products based on our demand forecasts and purchase orders. These forecasts represent our estimates of future demand for our products based on historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
We have agreements with Lanner with an initial term of one year and AEWIN with an initial term of six years pursuant to which they manufacture, assemble, and test our products. Each agreement automatically renews for successive one-year terms unless either party gives notice that they do not want to renew. We do not have any long-term manufacturing contracts that guarantee fixed capacity or pricing. Quality assurance and testing is performed at our San Jose, Taiwan and Japan distribution centers, as well as at our manufacturers’ locations. We warehouse and deliver our products out of our San Jose warehouse for the Americas and direct from Taiwan for APAC and EMEA. We outsource delivery to a third-party logistics provider for deliveries in Japan.
Backlog
As of December 31, 2022 and 2021, we had product backlog of approximately $8.1 million and $10.9 million, respectively. Backlog represents orders confirmed with a purchase order for products to be shipped generally within 90 days to customers with approved credit status. Orders may be subject to cancellation, rescheduling by customers and product specification changes by customers. Although we believe that the backlog orders are firm, purchase orders may be canceled by the customer prior to shipment without significant penalty. For this reason, we believe that our product backlog at any given date is not a reliable indicator of future revenues.
For the years ended December 31, 2022, 2021 and 2020, our total revenue was $280.3 million, $250.0 million, and $225.5 million, respectively, and our gross margin was 79.7%, 78.6%, and 77.8%, respectively. We had net income of $46.9 million, $94.9 million and $17.8 million for the years ended December 31, 2022, 2021 and 2020, respectively.
Intellectual Property
We rely on a combination of patent, copyright, trademark and trade secret laws, and restrictions on disclosure to protect our intellectual property rights. As of December 31, 2022, we had 212 United States (“U.S.”) patents issued and 4 U.S. patent applications pending, and 77 overseas patents issued and 12 overseas patent applications pending. Our issued U.S. patents, excluding 17 patents that we acquired, expire between 2025 and 2039. Our issued overseas patents, excluding 5 patents
14
that we acquired, expire between 2027 and 2037. Our future success depends in part on our ability to protect our proprietary rights to the technologies used in our principal products. Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our products or to obtain and use trade secrets or other information that we regard as proprietary. In addition, the laws of some foreign countries do not protect our proprietary rights as fully as do the laws of the United States. Any issued patent may not preserve our proprietary position, and competitors or others may develop technologies similar to or superior to our technology. Our failure to enforce and protect our intellectual property rights could harm our business, operating results and financial condition.
We license software from third parties for development of, or integration into, our products, including proprietary and open source software. We pursue registration of our trademarks and domain names in the United States and other jurisdictions. See Part I, Item 1A. Risk Factors included in this Annual Report on Form 10-K for additional information regarding the risks associated with protecting our intellectual property.
Human Capital
As of December 31, 2022, we had 575 full-time employees, including 252 engaged in research and development and customer support, 269 in sales and marketing and 54 in general and administrative and other activities. None of our employees is represented by a labor union or is a party to any collective bargaining arrangement in connection with his or her employment with us. We have never experienced any work stoppages, and we consider our relations with our employees to be good.
Corporate Responsibility
A10 Networks’ mission is to enable business-critical networks that are secure, available and efficient. In our rapidly expanding digital economy, this has never been more relevant and critical. Our customers rely on us to help them drive better business outcomes now and into the future.
With our mission in mind, we are committed to maintaining the highest standards of ethics and corporate governance, and to fostering a diverse and inclusive workforce and customer and partner ecosystem. We believe these practices will deliver the highest value for our employees, customers, partners and shareholders. Our global footprint provides an additional level of sustainability for business performance, and we ensure that we are driving this responsibility across all our global locations.
We use as a guide the code of conduct policies set forth by the Responsible Business Alliance, the world’s largest industry coalition dedicated to corporate social responsibility in global supply chains, and we expect all of our suppliers to do so as well. The alliance sets standards and practices for a social, environmentally sustainable, and ethical supply chains. Our supply chain has sustained audits based on the Validated Assessment Program.
Further, we have established standards and practices to which our Board of Directors, executives and employees are obligated to adhere, as outlined on our website under Corporate Responsibility.
Environmental, Social and Governance (“ESG”)
Environmental
We are committed to business practices that preserve the environment upon which our society and economy depend. We are committed to meeting or exceeding all legal and compliance guidelines for our people, products and operations. In addition, we strive to deliver products and services that minimize the impact to the environment throughout our value chain. Our environmental initiatives are aligned with the 1.5°C ambition as outlined in the Paris Agreement, and we have corporate goals to support the initiative.
We work with our contract manufacturers and suppliers to maintain compliance with, for example, RoHS, REACH and WEEE in the EU and elsewhere across the globe for other such environmental requirements. The Company’s Conflict Minerals Supply Chain Policy as well as our Code of Business Conduct and Ethics outlines our practices and procedures with respect to human rights to ensure participants in our supply chain do not knowingly contribute to local conflict or human rights abuses. We expect our suppliers to comply with our policy on responsible sourcing of minerals from conflict-affected and high-risk areas and to cooperate with our diligence inquiries and requests for information and certification as may be required by us to comply with reporting and disclosure obligations to which we are subject from time to time.
15
Our corporate headquarters in San Jose, California, is compliant with the California Building Energy Efficiency Standards - Title 24 to reduce wasteful and unnecessary energy consumption. The Company has planned for greater use of renewable energy in partnership with the local utility, PG&E. At our headquarters, we offer EV charging stations to our employees and visitors, and where applicable according to local requirements, we offer recycling and we properly dispose of e-waste.
Social
Diversity, Inclusion & Equal Opportunity
We are committed to providing a work environment that is free of discrimination and harassment. We are an equal-opportunity employer. We make employment decisions on the basis of a person’s qualifications, and our business needs. We believe in the richness and quality of a working environment that is informed by people from all walks of life and strive to create a genuinely inclusive environment. We have implemented Diversity, Equal Opportunity, and Inclusion action planning teams focused on analysis from diversity surveys and focus groups. We have ongoing outreach efforts to recruit a diverse candidate pool and are building questions into our engagement survey to promote a diverse and inclusive environment.
We are committed to ensuring our team members are treated with fairness and respect. We believe that a cooperative work environment, based on trust and mutual respect, is essential to our success. We embrace the diversity of our workforce and celebrate the creative value added by individuals with differing backgrounds. We expressly prohibit intimidation, hostility, harassment, discrimination and other inappropriate behavior. Furthermore, we expect employees to conduct themselves in a professional and dignified manner at all times; in doing so, we seek to avoid making employees feel uncomfortable at work.
As new employees join us, they learn more about our policies and culture through orientation and onboarding, our Employee Handbook, Code of Business Conduct and Ethics, and compliance trainings. These all provide guidance on how we expect to operate in order to foster diversity, equity and inclusion across our company.
We are an equal opportunity employer and a Vietnam Era Veterans' Readjustment Assistance Act (“VEVRAA”) federal subcontractor. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. We also comply with all applicable state and local laws governing nondiscrimination in employment.
Total Rewards
We offer an attractive mix of compensation and benefit plans to support our employees and their families’ physical, mental, and financial well-being. We believe that we employ a fair and merit-based total compensation system for our employees and offer a variable bonus plan for eligible employees. Employees are generally eligible for medical, dental, vision and other comprehensive benefits, most of which become effective on their start date. Below are some of the types of health and wellness related benefits offered to employees:
• Medical, dental and vision insurance;
• Retirement plan with Company matching contribution feature;
• Flexible Spending Accounts for medical expenses, childcare, parking and transit;
• Health Savings Account (with employer contribution);
• Life insurance;
• Short & long-term disability;
• Paid time off and leave of absences; and
• Employee assistance program
Employees have an opportunity for financial inclusion at A10 Networks with an ownership interest in our company. There are several programs that provide employees with the ability to own our stock. Generally, more than 75% of our employees participates in at least one of our stock programs. During their tenure with our company, most employees have an opportunity to receive an equity award, either upon hire and/or during an annual review process to recognize those with significant impact on achieving our goals. Most employees, whether part or full time, also have the ability to participate in our Employee Stock Purchase Plan (“ESPP”). Participants in the ESPP may purchase our stock at a 15% discount to market price. We believe our discounted stock purchase program helps to build an ownership mentality amongst participating employees.
16
Health, Safety and Wellness
We are committed to maintaining a healthy, safe, and secure work environment that protects our employees and the public from harm. At the outset of the pandemic, we immediately followed all local shelter-in-place orders in each of the locations where we do business. As stated below, we permit remote working as conditions of the pandemic continue to fluctuate around the world. We are aligned with the guidance from the Centers for Disease Control in the U.S. and all other local requirements where we do business across the globe.
We use a multi-faceted approach to ensure the health and safety of our employees, from our Code of Conduct to our policies governing the way we act within and outside of our company. We comply with applicable health, safety, and environmental laws as well as related company policies and procedures. We have a zero-tolerance policy against aggressive behavior, violence, direct and indirect threats, harassment, intimidation, and possession of weapons on company property. Moreover, we strive to conduct our everyday business activities in an environmentally sustainable way through wellness programs and webinars through our health insurance providers.
Our Response to COVID-19
The health and well-being of our employees has always been and continues to be a top priority. To ensure the health and well-being of all of our employees during the COVID-19 pandemic, we have taken the following measures:
• Implemented work-from-home and social distancing policies for our organization;
• Taken steps to ensure employee’s ability to remotely work-from-home when feasible;
• From time to time, placed restrictions on travel by our employees and in-person meetings; and
• Prepared our San Jose, CA headquarters facility to be compliant with all local and statewide COVID-19 requirements for those essential workers that are unable to work-from-home.
We will continue to monitor progress in managing the pandemic and will revise our measures in accordance with national and local public health guidance.
Governance
Our Board of Directors believes that our board should be a diverse body, and our Nominating and Corporate Governance Committee considers a broad range of backgrounds and experiences when selecting nominees for our board. Sixty percent of our directors currently self-identify as being from one or multiple diverse groups, including gender.
We continuously review and improve our corporate governance guidelines in response to changing requirements and feedback from employees, customers, partners, vendors and shareholders. The Nominating and Corporate Governance Committees of the Board of Directors, consisting entirely of independent directors, evaluates the appropriate governance practices as defined by law and industry best practice and takes those recommendations to the Board of Directors. Currently, four of five Board members are independent and three of five have less than five years of tenure.
A10 engages with an independent audit firm to ensure the company complies with relevant requirements such as the 2002 Sarbanes-Oxley Act.
The company’s governance and code of conduct policies are outlined in the Code of Business Conduct and Ethics, Corporate Governance Guidelines, Whistleblower Policy and the Employee Handbook. Employees many submit concerns to generalcounsel@a10networks.com or via the company’s third-party hotline as noted the Employee Handbook.
Corporate Information
A10 Networks, Inc. was incorporated in the State of California in 2004 and subsequently reincorporated in the State of Delaware in March 2014. Our website is located at www.A10networks.com, and our investor relations website is located at https://investors.A10networks.com. The following filings are available through our investor relations website after we file them with the SEC: Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, as well as any amendments to such reports and all other filings pursuant to Section 13(a) or 15(d) of the Securities Act. These filings are also
17
available for download free of charge on our investor relations website. Additionally, copies of materials filed by us with the SEC may be accessed at the SEC’s website at www.sec.gov.
We announce material information to the public about A10, our products and services and other matters through a variety of means, including our website ( www.A10networks.com ), the investor relations section of our website (https:// investors.A10networks.com ), press releases, filings with the Securities and Exchange Commission, public conference calls, and social media, including our corporate Twitter account ( @A10Networks) and our corporate Facebook page (https://www.facebook.com/a10networks). Information provided includes press releases and other information about financial performance, information on environmental, social and governance and details related to the Company’s annual meeting of shareholders. The contents of our website and social media contents are not intended to be incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. We encourage investors and others to review the information we make public in these locations, as such information could be deemed to be material information. Please note that this list may be updated from time to time.
18
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.