20-F: CyberArk Software Ltd. 20-F Filing: Details Share Structure, Governance, and Risk Factors

Sentiment:

Annual Report


CyberArk's 20-F filing outlines the company's share structure, corporate governance practices, and key risk factors impacting its business and industry.

Capital raiseTo support our operations, growth, and liquidity needs, we may issue additional ordinary shares, convertible securities, or debt instruments, including drawing on or expanding our revolving credit facility.

Summary

  • CyberArk Software Ltd.'s 20-F filing details the company's ordinary shares, par value, and trading history on Nasdaq under the symbol CYBR.
  • The document outlines the authorized share capital, consisting of 250,000,000 ordinary shares, par value NIS 0.01 per share.
  • It summarizes the terms of CyberArk's ordinary shares based on its articles of association and Israeli law, including transfer rights, election of directors, and dividend/liquidation rights.
  • The filing addresses potential acquisitions under Israeli law, including full tender offers and special tender offers.
  • It highlights anti-takeover measures under Israeli law and CyberArk's articles of association, such as the classification of directors and voting requirements.
  • The document discusses the company's exclusive forum provisions for legal proceedings, specifying U.S. federal district courts for Securities Act claims and Tel Aviv courts for other corporate matters.
  • It identifies American Stock Transfer & Trust Company, LLC as the transfer agent and registrar for CyberArk's ordinary shares.
  • The filing includes a special note regarding forward-looking statements, cautioning about risks and uncertainties that could affect actual results.
  • It details various risk factors related to CyberArk's business and industry, including competition, security vulnerabilities, economic uncertainties, and regulatory compliance.
  • The document mentions the acquisition of Venafi Holdings, Inc. on October 1, 2024, and Zilla Security Inc. on February 12, 2025, and discusses potential integration challenges.
  • It highlights the company's reliance on third-party cloud providers and the potential impact of cyberattacks on its IT network systems.
  • The filing addresses risks related to AI technology, privacy, data protection, and the ability to attract and retain qualified personnel.
  • It discusses the potential impact of economic uncertainties, global sales operations, and intellectual property claims on CyberArk's financial condition.
  • The document outlines the company's exposure to fluctuations in currency exchange rates and the ability of its solutions to help customers achieve regulatory compliance.
  • It mentions the potential for adverse tax consequences if CyberArk is classified as a passive foreign investment company (PFIC).
  • The filing addresses risks related to CyberArk's incorporation and location in Israel, including regional conflicts and political instability.

Sentiment

Score: 6

Explanation: The document is largely factual and descriptive, but the inclusion of numerous risk factors tempers the overall sentiment. While the company highlights its strengths and growth strategies, the extensive list of potential challenges creates a sense of caution.

Positives

  • Ownership or voting of ordinary shares by non-residents of Israel is not restricted.
  • Fully paid ordinary shares are freely transferable unless restricted by another instrument or applicable law.
  • The company is permitted to follow certain home country corporate governance practices instead of certain rules of Nasdaq.
  • The company has a $250 million committed revolving credit line facility, which is fully available for utilization, as needed.

Negatives

  • The company has incurred net losses and may not be able to generate sufficient revenue to achieve and sustain profitability.
  • The company's share price may be volatile, and shareholders may lose all or part of their investment.
  • The company may lose its foreign private issuer status, which would then require it to comply with the rules and regulations applicable to U.S. domestic issuers.
  • The company may be classified as a passive foreign investment company, which could have adverse tax consequences for U.S. shareholders.
  • The company does not intend to pay dividends on its ordinary shares for the foreseeable future, so any returns will be limited to changes in the value of its ordinary shares.

Risks

  • The information security market is rapidly evolving, and CyberArk's solutions may fail to adapt to market changes and demands.
  • The company may be unable to acquire new customers or sell additional solutions to existing customers.
  • Real or perceived security vulnerabilities and gaps in CyberArk's solutions may result in significant reputational, financial, and legal adverse impact.
  • Cyberattacks on CyberArk's IT network systems or those of its third-party providers could materially adversely affect its reputation, financial condition, and operating results.
  • The company faces intense competition from a wide variety of information security vendors.
  • The company may fail to fully execute, integrate, or realize the benefits expected from strategic alliances, partnerships, and acquisitions.
  • The company may not effectively execute its sales and marketing strategies, and expand, train and retain its sales personnel.
  • The dynamic regulatory environment around privacy, data protection, and AI may limit CyberArk's offerings or require modification of its solutions.
  • The company may be unable to hire, retain, motivate and upskill qualified personnel.
  • The company increasingly relies on third-party providers of cloud infrastructure services, and any disruption of or interference with its use of these services could adversely affect its business.
  • The company's quarterly results of operations could fluctuate due to a number of factors, including sales execution from quarter to quarter, seasonality, or other factors.
  • A portion of the company's revenues is generated by sales to government entities, which are subject to a number of challenges and risks.
  • Economic uncertainties or downturns, globally or in certain regions or industries, could materially adversely affect the company's business.
  • The company is subject to a number of regulatory and geopolitical risks associated with global sales and operations.
  • Intellectual property claims may increase the company's costs or require it to cease selling certain solutions.
  • The company is exposed to fluctuations in currency exchange rates, which could negatively affect its financial condition and results of operations.
  • If the company's solutions fail to help its customers achieve and maintain compliance with certain government regulations and industry standards, its business and results of operations could be materially and adversely affected.
  • The company may be subject to claims for remuneration or royalties for assigned service invention rights by its employees.
  • As a public company incorporated in Israel, the company may become subject to further compliance obligations and market trends or restrictions, which may strain its resources and divert management's attention.
  • Provisions of Israeli law and the company's articles of association may delay, prevent, or otherwise impede a merger with or an acquisition of the company.
  • It may be difficult to enforce a judgment of a U.S. court against the company, its officers and directors or the Israeli auditors named in this annual report in Israel or the United States.
  • The rights and responsibilities of the company's shareholders are, and will continue to be, governed by Israeli law which differs in some material respects from the rights and responsibilities of shareholders of U.S. corporations.
  • Conditions in Israel, including conflicts with Hamas and other conflicts in the region, as well as political and economic instability in Israel, may adversely affect the company's operations and limit its ability to market its solutions.

Future Outlook

The company expects to continue to invest in its sales and marketing teams, with a particular focus on expanding its channel partnerships including managed service providers, targeting new customers, expanding its relationships with existing customers, creating technology partnerships and further building out its customer success operations for existing customers.

Management Comments

  • By securing every identity with the right level of privilege controls, we enable secure access for all human and machine identities to help organizations secure critical business assets and applications, protect their distributed workforce and customers, minimize risk and increase resiliency, and accelerate business across cloud, hybrid and self-hosted environments.
  • With the increase in identity-related incidents over the past year, it is imperative for organizations to secure every identity with the right level of privilege controls.
  • We believe that a siloed approach is inefficient and does not provide adequate security.
  • We believe an Identity Security Platform must do far more than manage one group of identities; it must provide solutions to secure and govern all identities, across all environments.
  • Our goal is to reinvent and modernize capabilities across the established silos while inventing new ways to secure modern identities.
  • By further expanding the CyberArk Identity Security Platform to include a modern IGA offering based on the innovative and transformative capabilities from our acquisition of Zilla Security Inc., we will offer the most complete identity security platform for securing all identities, including human and machine.
  • We believe the CyberArk Identity Security Platform powered by CORA AI will provide the most comprehensive capabilities to discover and onboard identities with context and risk mapping, apply the right level of privilege controls across entitlement management, session management, credential management and authentication management while providing automated lifecycle management, policy, governance and compliance.
  • Since 2024, CyberArk has taken steps to focus its GTM strategy on a solution-based framework that will enable CyberArk to evolve from product-focused sales to solution selling, which is expected to better align with our customers problems.
  • We expect that this change will move us from a more fragmented market positioning to messaging our core differentiators holistically to stand out in the market and continue to drive our Identity Security leadership.
  • Our new secured identity framework and solutions are expected to help our GTM teams to take full advantage of the market opportunity while delivering value-based solutions for customers.
  • These solutions are expected to make it easier for our customers to buy the capabilities they need to secure every identity across their organization.

Industry Context

The announcement highlights the increasing importance of identity security in the face of evolving cyber threats and the growing complexity of IT environments. CyberArk is positioning itself as a leader in this space, aiming to provide a comprehensive platform for securing all identities, both human and machine.

Comparison to Industry Standards

  • CyberArk competes with companies like Delinea and BeyondTrust in Privileged Access Management (PAM), Okta and Microsoft in Access Management, Hashi Corporation in Secrets Management, KeyFactor in Machine Identity, and SailPoint and Saviynt in Identity Governance and Administration.
  • The company's approach to identity security, which emphasizes securing every identity with the right level of privilege controls, aligns with the zero trust security model.
  • CyberArk's focus on securing both human and machine identities reflects a growing industry trend, as the number of machine identities continues to increase.
  • The company's efforts to consolidate IAM silos and provide a unified platform for identity security are consistent with the industry's move towards more integrated and comprehensive solutions.

Management Changes

RolePrevious PersonNew PersonEffective DateReason
Chief Financial OfficerJoshua SiegelErica Smith2025-01-01Joshua Siegel stepped down as CFO on January 1, 2025, and Erica Smith became CFO, effective January 1, 2025.

Corporate Governance

Change TypeDescriptionEffective DateImpact Assessment
Board of DirectorsThe Board of Directors shall consist of such number of Directors (not less than four (4) nor more than 9 (nine), including the External Directors, to the extent required by law) as may be fixed from time to time by the Board of Directors.N/AThis provides flexibility in determining the size of the board.
Election and Removal of DirectorsThe Directors, excluding the External Directors, shall be classified, with respect to the term for which they each severally hold office, into three classes, as nearly equal in number as practicable, hereby designated as Class I, Class II and Class III.N/AThis creates a staggered board, making it more difficult to replace the entire board at once.
Shareholder Proposal RequestAny Shareholder or Shareholders of the Company holding at least the required percentage under the Companies Law of the voting rights of the Company which entitles such Shareholder(s) to require the Company to include a matter on the agenda of a General Meeting (the Proposing Shareholder(s)) may request, subject to the Companies Law, that the Board of Directors include a matter on the agenda of a General Meeting to be held in the future, provided that the Board determines that the matter is appropriate to be considered in a General Meeting (a Proposal Request).N/AThis outlines the process for shareholders to propose matters for consideration at general meetings.
Forum for Adjudication of DisputesUnless the Company consents in writing to the selection of an alternative forum, the federal district courts of the United States, shall be the exclusive forum for the resolution of any complaint asserting a cause or causes of action arising under the U.S. Securities Act of 1933, as amended, including all causes of action asserted against any defendant to such complaint.N/AThis specifies the exclusive forum for certain legal disputes.

Legal Proceedings

  • The company is currently not a party to any material litigation, and it is not aware of any pending or threatened material legal or administrative proceedings against the company.

Related Party Transactions

  • The company's policy is to enter into transactions with related parties on terms that, on the whole, are no more favorable, or no less favorable, than those available from unaffiliated third parties.
  • The company has entered into written employment agreements with each of its officers, which contain provisions regarding non-competition and confidentiality of information.
  • The company has granted options to purchase, and restricted share units underlying its ordinary shares to its officers and certain of its directors.
  • The company has entered into indemnification agreements with its office holders to exculpate, indemnify, and insure its office holders to the fullest extent permitted by Israeli law.

Stakeholder Impact

  • The company's performance and risk factors can impact shareholders through share price volatility and potential losses.
  • Employees are affected by the company's ability to attract, retain, and motivate qualified personnel.
  • Customers are impacted by the company's ability to provide effective and reliable security solutions and maintain regulatory compliance.
  • Suppliers and creditors are affected by the company's financial stability and ability to meet its obligations.

Next Steps

  • The company intends to extend its leadership position by enhancing its solutions, including utilization of AI, introducing new functionality and developing new offerings to address additional human and machine identity security use cases.
  • The company intends to build deeper relationships across the C-suite and in the board room.
  • The company plans to expand its sales reach by adding new direct sales capacity, expanding its indirect channels by deepening its relationships with existing partners and by adding new partners.
  • The company plans to pursue new customers in the enterprise and corporate segments of the market with its sales and partner teams, as well as through its brand awareness and lead generation campaigns.
  • The company will focus on expanding relationships with existing customers by growing the number of users who access its solutions and cross-selling additional solutions.
  • The company will continue to deliver high levels of customer service and support and invest in its Customer Success team to help ensure that its customers are up and running quickly and derive benefit from its software.
  • The company will continue to build on its momentum and operate as a subscription company.

Key Dates

DateDescription
2014-09-24CyberArk's ordinary shares began trading on Nasdaq under the symbol CYBR.
2014-09-24CyberArk's IPO was priced at $16.00 per share.
2024-10-01CyberArk acquired Venafi Holdings, Inc.
2025-02-12CyberArk acquired Zilla Security Inc.

Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.