Company Description
Radware Ltd. (NASDAQ: RDWR) is a cybersecurity and application delivery company focused on protecting digital services in multi-cloud environments. According to the company’s public disclosures, Radware offers cloud application, infrastructure, and API security solutions that use AI-driven algorithms to provide real-time protection against sophisticated web and application attacks, distributed denial-of-service (DDoS) campaigns, API abuse, and malicious bot activity. Enterprises and carriers worldwide rely on these solutions to address evolving cybersecurity challenges, safeguard their brands and business operations, and help reduce costs.
Core business focus
Radware describes itself as a global leader in application security and delivery solutions for multi-cloud environments. Its portfolio centers on securing the digital experience by providing protection and availability services for infrastructure, applications, corporate IT, and APIs. The company’s solutions are designed to operate across physical, cloud, and software-defined data centers, reflecting the shift of enterprise workloads into distributed and hybrid architectures.
Public information indicates that Radware’s operations are organized around Radware’s core business and a segment referred to as The Hawks’ Business, with the majority of revenue derived from the core business. The company has also stated that it generates a significant portion of its revenue from the United States, while serving enterprises and carriers globally.
AI-driven security capabilities
A consistent theme in Radware’s communications is the use of AI-driven algorithms to enable precise, hands-free, real-time protection. The company highlights AI-powered web DDoS protection that can detect and mitigate highly disruptive HTTPS flood attacks without blocking legitimate traffic. Its AI-based systems generate defense signatures within seconds, automatically adjust thresholds as attacks evolve, and optimize security policies to reduce operational burden for security teams.
Radware has also introduced AI SOC Xpert, powered by its EPIC-AI™ technology, to embed AI into Security Operations Center (SOC) workflows. AI SOC Xpert provides root cause analysis, incident timelines, and context across DDoS and bot attacks, along with dashboards for application protection and on-premise DDoS protection. It is designed to accelerate investigation, streamline remediation, and lower mean time to resolution by offering agentic AI guidance and automated recommendations.
DDoS mitigation and cloud security network
Radware places particular emphasis on DDoS mitigation. The company offers cloud-based and hardware-based DDoS protection platforms, including its DefensePro® X mitigation platform. Public announcements state that Radware has doubled the mitigation capacity of its global cloud security service network to 30 Tbps of total attack mitigation power. Its cloud security centers are equipped to counter large, complex, multi-vector DDoS campaigns and high–requests-per-second assaults such as HTTPS floods.
Radware’s global network of cloud security centers mitigates attacks close to their point of origin. This model is intended to improve application response times for in-region traffic, accelerate mitigation response, and help organizations address a broad range of threats, including DDoS attacks, web application attacks, malicious bot activity, and API abuse, while supporting data residency requirements. The company reports that its cloud security network spans dozens of centers worldwide, including locations such as Bogotá, Lima, Mumbai, Singapore, and Tel Aviv.
Cloud application protection and API security
Radware offers a Cloud Application Protection Service, described as a cloud-based solution specialized in application and DDoS protection. The service is designed to detect zero-day web DDoS attacks that target applications and APIs, including encrypted traffic. AI-based algorithms generate defense signatures within seconds and automatically adapt as attacks morph, distinguishing between normal and abnormal traffic to avoid blocking legitimate users.
In collaboration with partners such as Hitachi Solutions, Radware’s Cloud Application Protection Service is positioned to support organizations facing surges in impactful DDoS attacks. The service supports various DDoS attack types, including network, web application, volumetric, zero-day, and encrypted traffic attacks, and incorporates regular policy review support to further reduce operational overhead for customers.
Generative AI and LLM security
Radware has expanded its focus into generative AI and large language model (LLM) security. The company introduced an LLM Firewall as an add-on to all tiers of its Cloud Application Protection Services. This solution is designed to secure generative AI use at the prompt level, stopping threats before they reach the LLM model. It aims to guard against prompt injection, jailbreaks, resource abuse, and attempts to exfiltrate personally identifiable information, and is described as model-agnostic and easy to integrate across platforms.
Radware states that LLM Firewall is aligned with the 2025 OWASP Top 10 Risks and Mitigations for LLMs and Gen AI applications and is part of a broader agentic AI protection strategy. This reflects the company’s view that AI security must be enforced at the prompt layer to address risks specific to LLM behavior and integrations.
Threat research and agentic AI vulnerabilities
Radware conducts threat intelligence research on behalf of the cybersecurity community. Its research team has disclosed vulnerabilities such as ShadowLeak and, more recently, a zero-click indirect prompt injection vulnerability called ZombieAgent targeting OpenAI’s Deep Research agent. According to Radware’s disclosures, ZombieAgent can implant malicious rules into an AI agent’s long-term memory or working notes, enabling persistent hijacking and silent data exfiltration from cloud infrastructure without user interaction.
The company emphasizes that such vulnerabilities highlight a growing “agentic threat surface,” where AI agents read emails, interact with corporate systems, initiate workflows, and make autonomous decisions. Radware’s research and responsible disclosure practices are intended to give security professionals insights into how attackers may exploit these platforms and to inform defenses for enterprises adopting agentic AI.
Global operations and customer base
Radware’s public statements describe a global enterprise and carrier customer base. The company notes that enterprises and carriers worldwide use its solutions to protect business operations, maintain continuity, and manage costs amid rising cyber threats. Radware’s cloud security centers operate in multiple regions, and partnerships, such as with Hitachi Solutions in Japan, extend its reach into specific markets where DDoS attacks and application-layer threats have intensified.
Radware has also highlighted major customer wins, including a multi-year, multimillion-dollar agreement with a top-ten SaaS and IT service management leader. In that case, the customer deployed Radware’s DefensePro DDoS mitigation solution to protect critical applications and infrastructure after experiencing repeated large-scale DDoS attacks. The customer sought a service-provider-class DDoS solution with strong scalability, and Radware’s architecture, automation capabilities, and deployment flexibility were cited as key factors in the selection.
Regulatory reporting and public company status
Radware is a foreign private issuer that files with the U.S. Securities and Exchange Commission (SEC), including reports on Form 20-F and current reports on Form 6-K. Recent Form 6-K filings have covered items such as quarterly financial results, earnings conference call schedules, and notices for the company’s annual general meetings of shareholders. These filings provide details on revenue by region, profitability metrics, cash and investment balances, and governance matters such as director elections, compensation policies, and auditor appointments.
The company’s disclosures also discuss risk factors affecting its business, including global economic conditions, geopolitical instability, competition in the cybersecurity and application delivery markets, reliance on independent distributors, dependence on hardware vendors, use of AI technologies, and risks associated with global operations and regulatory compliance. Investors can refer to Radware’s annual report on Form 20-F and subsequent SEC filings for a more detailed discussion of these risks.
Industry recognition
Radware reports that it has earned numerous awards for its DDoS mitigation capabilities. Industry analysts and review platforms such as G2, PeerSpot, and QKS Group are cited by the company as recognizing Radware as a market leader in DDoS protection based on customer reviews, satisfaction scores, and market presence. This external feedback is used by Radware to underscore the perceived effectiveness and adoption of its DDoS and application security offerings.
Business segments and revenue characteristics
Based on available information, Radware operates through at least two business segments: Radware’s core business and The Hawks’ Business. The company has stated that it derives maximum revenue from its core business. It also reports recurring revenue metrics such as annual recurring revenue (ARR) for term-based cloud services, subscription licenses, and maintenance contracts, reflecting the importance of subscription and cloud-based models in its overall revenue mix.
Radware explains that ARR is a key performance indicator representing the annualized value of booked orders for recurring services in effect at the end of a reporting period. While ARR is distinct from revenue and deferred revenue, it is used internally and presented to investors as a measure of the value of the recurring components of the business.
Use cases and problem domains
Across its communications, Radware positions its solutions as addressing several specific problem domains:
- DDoS protection for network, application, volumetric, zero-day, and encrypted traffic attacks.
- Web application and API security to counter web DDoS, malicious bots, and API abuse.
- Multi-cloud application delivery and security to support applications deployed across physical, cloud, and software-defined data centers.
- Generative AI and LLM security through prompt-level protection and LLM Firewall capabilities.
- AI-assisted SOC operations via AI SOC Xpert for investigation, remediation, and policy optimization.
These use cases reflect Radware’s focus on helping organizations maintain availability, protect sensitive data, and manage operational complexity as threats grow in scale and sophistication.