MoatLedger Wonderful companies at fair prices. A ledger, kept patiently.
watch

F5, Inc.: A Real Moat Priced as If It Were Larger

Some companies fail on quality and pass on price. F5, Inc. is the more interesting — and more frustrating — case: a business that passes three of our four gates cleanly, then fails the fourth so decisively that the first three become academic. Here is the walk through the gates, in order.

Gate 1: Circle of Competence

F5 sells the infrastructure that manages and protects application traffic for large enterprises and government agencies. Its core products — BIG-IP (hardware appliances plus software), NGINX (software), and Distributed Cloud (SaaS) — provide load balancing, access control, and application security. Revenue arrives on three axes: systems (hardware) sales, software subscriptions and perpetual licenses, and global services (maintenance and support).

FY2025 revenue was $3.09 billion, up 10%, with operating profit crossing $1 billion for the first time. Growth was driven by large customers reinvesting in their data centers and by hybrid cloud and AI infrastructure demand.

Is this knowable? On the first level — can the information be obtained — yes, comfortably. SEC filings, earnings calls, market share data, and even the CISA emergency directive following the company’s security incident are all public. On the second level — can the future be predicted with reasonable confidence — conditionally. The demand itself is sticky: ten years from now, large organizations will still need to manage and secure application traffic. The open question is whether that demand stays in F5’s form factor or migrates to cloud-native alternatives — hyperscaler-built load balancers, Cloudflare-type services. That is a question of transition speed, not of existence. A pass, but not the kind that permits “certain growth” narratives.

Gate 2: Moat

The moat is switching costs, and they are substantial. BIG-IP sits in the middle of enterprise and government traffic paths, customized with configurations like iRules; replacing it is expensive and risky. F5 holds roughly 45% share of the enterprise ADC market, and Citrix’s retreat from the business pushed hundreds of customers into F5’s arms. Hundreds of thousands of internet-exposed BIG-IP hosts have been counted — the installed base is itself the evidence of the moat.

Pricing power shows up in the numbers rather than in announced price increases. A gross margin of 81.4% and a net margin of 22.4%, sustained long-term in a hardware-mixed business and preserved through the software subscription transition, indicate margin defense built on lock-in. This is not the annual-increase, See’s-Candies variety; it is the quieter, structural kind.

The direction, however, is stagnation to gentle erosion. The core ADC market is mature and shrinking; in cloud-native and edge, Cloudflare and hyperscaler-native services are structurally better positioned. Citrix customer absorption and the long residency of hybrid cloud are defensive factors; cloud migration is the erosive one.

Two further considerations. First, AI: data center buildouts and traffic surges are a picks-and-shovels tailwind — the real driver of FY2025 growth — but as AI workloads concentrate in hyperscalers, the long-term footing of self-hosted ADCs narrows. Net effect: short-term reinforcement, long-term neutral to erosive. Second, and more seriously: in October 2025, F5 disclosed that a nation-state-backed attacker had exfiltrated BIG-IP source code and undisclosed vulnerabilities after more than twelve months of infiltration, prompting a CISA emergency directive. For a security vendor, that is a direct wound to the trust asset underlying the moat. No customer attrition has appeared in FY2025 results yet, but the renewal cycle needs one to two years of observation.

Gate 3: Management

Capital allocation has been disciplined. CEO François Locoh-Donou (since 2017) pays no dividend and focuses on buybacks — $1.1 billion repurchased across 2024–2025, shrinking the share count. Acquisitions — NGINX in 2019 for $670 million, Shape Security in 2020 for $1 billion — fit the software transition; there are no signs of empire-building or repeated large bets at peaks. The balance sheet is unlevered: zero long-term debt, $1.34 billion in cash, and ROE of 15.7% achieved without leverage.

The retained-earnings test appears to pass. FY2025 free cash flow was $906 million, up 18.9%, with record revenue and profit; the stagnant 2019–2023 hardware-to-software transition is being recouped through 22% software revenue growth.

Candor is the blemish. The security incident was disclosed via 8-K with a detailed response — but the disclosure was delayed at the DOJ’s request (discovered in August, disclosed in October), and a securities class action is proceeding on that delay. We record it as a deduction and watch the litigation. Alignment is otherwise fine: 96% performance-linked CEO compensation, 0.33% ownership, routine small insider sales.

Gate 4: Price

Owner earnings for FY2025 come to roughly $741.5 million — consistent with the $906 million free cash flow and the light-capex reality that net income approximates cash flow. We use a conservative $740 million.

At a 12x multiple reflecting low growth, intrinsic value is about $8.9 billion; a generous 15x for continued software and SaaS growth gives $11.1 billion; adding roughly $1.1 billion of net cash, the upper bound is about $12.2 billion.

The market, at a $23.8 billion market cap, was pricing the company at roughly twice that upper bound. Owner-earnings yield of 3.1% sat below the ~4.3% ten-year Treasury, and a P/E of 35.45 is hard to justify for a mid-teens-ROE, low-growth infrastructure company — the price had already recovered the dip that followed the security incident. A 30% discount to the $11 billion central estimate implies a market cap of roughly $7.7 billion — about a third of the then-current price. Even at a full 15x with no discount, discussion only becomes possible below $12 billion.

A postscript from late July 2026: Q3 FY2026 delivered non-GAAP EPS of $4.73 against $4.00 consensus, revenue of $865 million (+11% YoY), and product revenue up 19% — the eighth consecutive quarter of double-digit product growth — with raised FY2026 guidance (revenue $3.4 billion, EPS $17.21–17.33). The stock still fell 8.6% that day, from near its 52-week high ($408) to $372.91 — a valuation reset after a beat-and-raise, not moat damage. At a ~$21.0 billion market cap, the owner-earnings yield improved to 3.53% on the conservative FY2025 figure, or ~3.9% on a generous FY2026 run-rate — still below the risk-free rate. The decline moved the stock from overvalued to slightly less overvalued. A 30%-discount entry would now sit near $150–172 a share, roughly 40–46% below the current price.

Verdict

Watch. The business quality is real — a switching-cost moat, no leverage, consistent ROE (15.7%, standard deviation 2.8 percentage points), disciplined capital allocation, and eight straight quarters of double-digit product growth. But the absence of any margin of safety is disqualifying, and the 2025 breach leaves an unresolved question about whether a security vendor’s trust asset is dented or broken. Until the price approaches the intrinsic-value range and the renewal cycle speaks, this is an observation, not an ownership candidate.

What would change the verdict: a sustained fall in price toward the $8.5–12 billion intrinsic-value band (or years of sideways trading while earnings grow into the multiple) — or, in the other direction, evidence that the breach is hollowing the moat: software growth fading below 10%, renewal or services revenue declines, federal procurement exclusions, adverse litigation outcomes, or a break of the 81% gross margin line.


This analysis is AI-generated, educational, and not investment advice. Figures may contain errors or be delayed. Disclaimer