1 of 53

OWASP Foundation

Board Summary

August 2024

2 of 53

Initiatives & Operations

Andrew van der Stock

OWASP Foundation Staff

3 of 53

Executive Director

  • Moving back to Australia
    • How to best contact me and make time with me
  • Policy review of Board election materials is underway
    • Code of Conduct and Elections policy are in public review
  • Microsoft Intune being rolled out to manage devices
    • Enforced device encryption, automatic updates, MFA login for Windows devices, security baseline settings (PIN complexity, password requirement, etc)
    • Compliance audit
    • Remote wipe

4 of 53

Executive Director

  • Audit
    • Single entity (OWASP Foundation, Inc.), single year
    • Audit field work has commenced
    • Need to sort out EU entity (discussion later in this meeting)
    • IT general controls:Need to enroll staff in Insperity training in securely handling data, phishing attacks, privacy, etc.
  • New presentation templates
  • Leaders as Members update

5 of 53

New templates are here

Now 100% compliant with the brand guidelines

6 of 53

OWASP Blue Theme

Your name here

7 of 53

OWASP Light Theme

Your name here

© 2024 Author Name. Licensed under CC-BY-SA 4.0

8 of 53

OWASP Dark Theme

Your name here

© 2024 Author Name. Licensed under CC-BY-SA 4.0

9 of 53

Leaders as members

10 of 53

Leaders As Members

1071 total leaders

293 Members

778 Non-Members

A few anomalies so far

  • No single source of truth
  • Pseudonym
  • Not an email address
  • Missing emails (i.e. name only)
  • Email in leaders.md doesn’t match their Stripe customer record
  • No Stripe owasp.org metadata
  • Stripe is non-owasp.org email
  • No leader tag for most leaders in Copper
  • Duplicate Copper records fools our membership check tools

11 of 53

Timeline

GSuite Suspended

leaders.md will be updated to be their secondary email

Oct 30

GitHub admin role revoked�Leader discounts suspended

GitHub role changed to member

Nov 30

August

Campaign to become members

Weekly mail outs to non-member leaders, Slack and social media announcements

September 30

Not able to manage chapters in AMS�Expenses suspended for non-members

Leaders must be in the AMS to manage their chapter. Only member Leaders will only be able to claim expenses.

Dec 30

Leadership is terminated

Removed as a user from GitHub�Removed from leaders.md�GSuite will be deleted March 30, 2025

12 of 53

Leader benefits

Benefit

Non-member leader

Complimentary

Individual Member

Vote

No

No

Yes

Member benefits

No

Yes

Yes

Manage chapters

Ends Sept 30

Yes

Yes

Claim expenses

Ends Sept 30

Yes

Yes

Leader Discounts

Ends Oct 30

Yes

Yes

GitHub admin role

Ends Oct 30

Yes

Yes

Manage projects, events, or committees

Ends Oct 30

Yes

Yes

GSuite

Ends Nov 30

Yes

Yes

Removed as leader

Terminated Dec 31

N/A

N/A

13 of 53

Operations

  • The Board Election process has started. The call for candidates is open until 8-31-24.

14 of 53

Corporate Relations

Kelly Santalucia

15 of 53

Corporate Supporter New Member Benefits

Testimonials from Corporate Supporters

Checkmarx:

“Checkmarx places high value on our sponsorship with OWASP, which we see as a partnership. The goals of OWASP and Checkmarx are aligned, aiming to bring the practice of application security to a higher standard everywhere in the world. One significant factor in the choice to become a Gold Sponsor was the ability it gave us to provide a benefit to OWASP members, which in our case was to give all members access to our Codebashing secure training platform at no additional cost. Presenting at OWASP gatherings and having our VP of Security Research co-lead the API Security Project are all part of a sponsorship that benefits everyone.”

Ubiq:

“The OWASP individual member benefit program has led to increased adoption and sign-ups of our free, community version, enabling us to work more closely with security-minded developers and engineers across the globe and educate them on how identity-driven, data-level security controls can more effectively safeguard sensitive data and help them avoid cryptographic failures.”

Appdome:

“Appdome chose the gold level for two reasons

  1. We believe in the OWASP mission and want to fund the mission as much as we can afford
  2. The ability to provide a member benefit that is only available at this level and above”

Root:

Root qualifies as a start-up (est 36-months or less) and could have joined with the $2k package, however, they joined as a Platinum ($25k). She found the member benefit very interesting and hopefully soon, will be submitting a member benefit proposal for approval.

16 of 53

Corporate Supporter Pipeline

17 of 53

Conference Sponsor Pipeline

18 of 53

2024 Global AppSec San Francisco Exhibitor/Sponsorship Pipeline

Exhibitors

Budgeted

53

Sold

63

% sold to budget

119%

Sponsors

Budgeted

7

Sold

10

% sold to budget

142%

Budgeted Exhibit & Sponsor Revenue

$965,000

Currently

$1,179,025

Exceeding Budget

$214,025

19 of 53

Finance

The Charity CFO

20 of 53

Membership

Andrew van der Stock

21 of 53

Individual Members

Membership up 97 for August, for a total of 8286 members, an all time high.�

One Year 4239 +60

Two Year 1074 -7

Lifetime 1266 17

Complimentary 1707 27�

All forms of complimentary membership will be reaffirmed once we are on a new AMS.

In September, let’s discuss sunsetting force majeure complimentary membership.

22 of 53

Chapters

Dawn Aitken

23 of 53

New Chapters

24 of 53

Meetup Membership Data

143,416 Total members

  • 220 Groups - (276 active chapters)
  • 48 meetings in the last 30 days
  • 1,519 new members joined in the last 30 days

25 of 53

Projects and Grants

Starr Brown

26 of 53

Projects

Project status always available at Project Website Status | OWASP Foundation

  • Ongoing Leader Feedback
    • Open call for feedback related to contributor license agreements, project funding, and in-kind funding. The attempt to notify via the #leaders channel in Slack garnered two responses - in total.
    • Redistributing via email and Slack
      • Please share amongst other Project leaders if you communicate via private channels on our behalf
    • Link: https://owasp.wufoo.com/forms/z1nwhgkb12p34cu/
    • Will promote again at Global AppSec San Francisco and Project Summit
  • Ongoing Project Budgets & Financial Transparency
    • Financial clarity is lacking for projects in terms of budget vs. spend
    • Transparency is lacking because of the current process does not allow for easy means of showing budget vs. inflow / outflow
    • Transparency between the foundation and its project leaders needs to be better to ensure we can clearly account for cash flow and resolve requests for payment in a timely manner
    • Andrew has requested additional ledger coding with Charity CFO that will assist in the effort of making project accounting clear and easy to understand

27 of 53

Projects

  • AMS
    • Data cleanup and workflow confirmation is our current stage; this is the majority of the project’s implementation
    • Go live likely early October due to dates related to elections / member status and because an extension was given for the Cloudflare member portal use
  • Blend-ed
    • Go Live planned for Q4 2024
    • RFC: Donated materials for OWASP Top 10 beginner friendly free certification course need review by community members
    • Planning: Train the Trainer courses as means to support current OWASP community trainers and leaders with a way to not detract financially from existing trainers and to add to the inflow of revenue supporting projects, developers and leaders as well as to increase operational revenue by creating training packages for other organizations who wish to utilize the OWASP portfolio of projects as part of their offering
    • Planning: Leader, Member & Chapter training

28 of 53

Projects @ Events

Planning

    • Project Summit
      • We need travel assistance with the goal of bringing lab and incubator project developers as well as those more junior in their career to the event
      • Working with Fastly, major airlines & other grant providers to apply for travel funding
      • Seeking Summit Sponsors, prospectus forthcoming by early September

29 of 53

Events

Lauren Thomas

30 of 53

Global AppSec Lisbon Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 840 Budgeted: 600

Sold: 1045 Sold: 782

% sold to budget: 124% % sold to budget: 130%

% increase from 2023: 198% % increase from 2023: 177%

Training

Budgeted: 130

Sold: 182

% sold to budget: 140%

% increase from 2023: 152%

Analysis: Global AppSec Lisbon far exceeded expectations in regards to YOY growth and anticipated budgeted numbers. Sponsorship and conference growth could be due to finally exiting the times of COVID as well as the location. Training growth attributed to added training courses. The only area where ticket sales did not meet the expected attendance is the WIA Reception which budgeted 35 tickets and sold 16 as well as the Newcomers reception which budgeted for 75 tickets and sold slightly under at 65 tickets.

31 of 53

Global AppSec San Francisco Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 1155 Budgeted: 900

Sold: 566 Sold: 441

% sold to budget: 49% % sold to budget: 49%

Note: At this time (4 weeks before the event) for SF 2022,

we had 263 Tickets sold. At this time for DC 2023, we had

507 tickets sold

Training

Budgeted: 115

Sold: 54

% sold to budget: 47%

BOD Call to Action: Please reach out to your contacts and promote on social media. If you have a company looking for bulk ticket purchases, even better. Please direct them to the events team.

32 of 53

Global AppSec Developer Day SF Update

Due to low registration numbers, Developer Day on September 25th has been cancelled. We will be reviewing our efforts to determine what steps should be taken in order to build the conference in the future.

Tentative plans for a virtual Developer Day in early 2025.

BOD Call to Action: Please assist the foundation with outreach to Developers. Once a date has been secured for virtual Developer Day 2025, we would appreciate any assistance in reaching out to potential developers.

33 of 53

2024 and Beyond Global AppSec Events at a Glance

Event

Date

Attendees

Trainees

Est. Profit

Status

2024 Global AppSec Lisbon

June 24-28, 2024

650 goal

70 goal

$130,000 goal Actuals: TBD

Completed

2024 Global AppSec SF

September 23-27

1000 goal

70 goal

$500,000

On Track

2025 Global AppSec NZ (New)

September 1-5, 2025

550 goal

100 goal

Dates confirmed

2025 Global AppSec DC

November 3-7

1000 goal

TBD

$325,000

Dates confirmed

2026 Global AppSec SF

November 2-6

1000 goal

TBD

TBD

Dates confirmed

34 of 53

2024 AppSec Days at a Glance

Event

Date

Attendees

Trainees

Profit

Status

OWASP SnowFROC

March 7, 2024

350

TBD

$18,000 est profit (actual profit TBD)

Completed

AppSec Days BASC

April 6, 2024

200

TBD

$4,000 est profit

Completed

AppSec Days PNW

June 15-16, 2024

150

TBD

$9,500 est profit

Completed

OWASP Italy Day

June 20, 2024

100

0

€3,500 est profit

Completed

OWASP AppSec Days Panama

September 11-12

100

40

Break even

On Track

OWASP AppSec Days Singapore

October 1-2, 2024

100

30

Break even

On Track

OWASP AppSec Days Spain

October 26, 2024

200

0

Break even

On Track

OWASP LASCON

October 22-25, 2024

350 goal

20 goal

$31,000 est profit

On Track

35 of 53

2024 AppSec Days at a Glance… Continued

Event

Date

Attendees

Trainees

Profit

Status

German OWASP Day

November 12-13

200

36

€2,700.00

On track

OWASP AppSec Days India (Virtual)

November 14-15

400 goal

0

4,000

On Track

OWASP BeNeLux

November 28-29, 2024

345 goal

80 goal

€5,110

On Track

AppSec Cali

January 2025

TBD

TBD

TBD

TBD - working on finding new leader

AppSec Days France

September 2025

100

0

€10,911

On track - just applied

BOD Call to Action: in Q4 of 2024 we have a handful of new Regional Events. If you would kindly assist in spreading the word on AppSec Days Panama, Singapore, Spain, and India.

36 of 53

2024 Global AppSec SF Status On Track

September 23-27

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

430

900

$300,000

0

$300,00

On Track

Trainees

54

100

$200,000

0

$200,000

On Track

Trainers

6

6

0

$100,000

0

On Track

Speakers

4

44

0

$4,000

0

On Track

Venue

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

On Track

Catering

$450,000

$450,000

0

$450,000

0

On Track

37 of 53

2024 AppSec Days Panama Status On Track

September 11-12

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

130

100

0

0

0

On Track

Trainees

120

40

0

0

0

On Track

Trainers

4

4

0

0

0

On Track

Speakers

12

12

0

0

0

On Track

Venue

Complimentary

Complimentary

0

Complimentary

0

On Track

Catering

$10,000

$10,000

0

$10,000

0

On Track

38 of 53

2024 AppSec Days Singapore Status On Track

October 1-2,2024

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

25

100

0

0

0

Low attendance

Trainees

0

30

0

0

0

On Track

Trainers

2

3

0

0

0

On Track

Speakers

12

12

0

0

0

On Track

Venue

$25,632 SGD

$25,632 SGD

0

$25,632 SGD

0

Completed - contract signed

Catering

$31,920 SGD

$31,920 SGD

0

$31,920 SGD

0

On Track

39 of 53

2024 AppSec Days Spain Status On Track

October 26,2024

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

0

200

0

0

0

On Track - still in approval process

Trainees

N/A

N/A

N/A

N/A

N/A

N/A

Trainers

N/A

N/A

N/A

N/A

N/A

N/A

Speakers

0

10

0

0

0

On Track - still in approval process

Venue

Complimentary

Complimentary

0

0

0

On Track - still in approval process

Catering

$4,000

$4,000

0

$4,000

0

On Track - still in approval process

40 of 53

2024 LASCON Status On Track

October 22-25

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

106

350

$71,720

0

$71,720

On Track

Trainees

0

20

$11,000

$11,000

On Track

Trainers

3

3

0

$19,800

0

On Track

Speakers

0

50

0

$3,750

0

On Track

Venue

$81,000

$81,000

0

$81,000

0

On Track

Catering

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

41 of 53

2024 AppSec Days India Status On Track

November 14-15

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

2

500

25,000 INR

0

25,000 INR

On track

Trainees

N/A

N/A

N/A

N/A

N/A

N/A

Trainers

N/A

N/A

N/A

N/A

N/A

N/A

Speakers

0

24

0

0

0

On track

Venue (Virtual - Streamyard)

TBD

TBD

TBD

TBD

TBD

Vandana to confirm

Catering

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

42 of 53

Completed events

43 of 53

2024 SnowFROC Status Completed

March 7

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

329 paid

78 free

407 total

400

$30,000.00

0

$30,000.00

Completed

Net Payout: $22,747.16

Trainees

59

100

$5,000.00

0

$5,000.00

Completed

Trainers

4

4

0

$1,000.00

0

Completed

Sponsors

21

10

$30,000.00

0

$30,000.00

Completed $74,500

Speakers

15

17

0

0

0

Completed

Venue

$14,875.00

$14,875.00

0

$14,875.00

0

Completed

Catering

$25,000.00

$25,000.00

0

$25,000.00

0

Completed

44 of 53

2024 BASC Status Completed

April 6

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

247

220

0

0

0

Completed

Trainees

n/a

n/a

n/a

n/a

n/a

Completed

Trainers

n/a

n/a

n/a

n/a

n/a

Completed

Sponsors

17

13

$37,000

0

$37,000

Completed $40,000

Speakers

10

10

0

0

0

Completed

Venue

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

Completed

Catering

Completed

45 of 53

2024 AppSec Days PNW Status Completed

June 15-16

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

286

310

$15,750

0

0

Completed

Trainees

N/A

N/A

N/A

N/A

N/A

N/A

Trainers

N/A

N/A

N/A

N/A

N/A

N/A

Speakers

15

15

0

0

0

Completed

Venue

$13,513

$13,513

0

$13,513

0

Completed

Catering

$14,000

$14,000

0

$14,000

0

Completed

46 of 53

2024 Global AppSec Lisbon Status: Completed

June 24-28

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

782

600

€350,000

0

€350,000

Completed�

Trainees

182

130

€150,000

0

€150,000

Completed

Trainers

10

5

0

€100,000

0

Completed

Speakers

40

40

0

€7,000

0

Completed

Venue

€75,000

€88,000

0

€88,000

0

Completed

Catering

€300,000

€300,000

0

€300,000

0

Completed

47 of 53

Community Development

Christian Capellan

48 of 53

Force Majeure Accounts

  • No address or other identifying information was requested from force majeure complimentary accounts (Israel, Ukraine). Over 1000 accounts with no info, most appear to be fraudulent.
  • Auditing 50 top users by Google Drive usage are being audited (address requested).
    • 30 day deadline given before account deletion.
    • Only two responses so far, both giving well-known non-residential addresses (a nightclub and a warehouse).
    • One account was storing significant adult content, possible CSAM.
  • Short-term: will be requiring address for new force majeure accounts (soon).
  • Long-term: no force majeure accounts will be automatically ported to new AMS. Individuals will be contacted and asked to resubmit, providing address in new workflow.

49 of 53

Google Drive

  • Google Workspace usage at 50% (down from 100% in May).
  • Continuing to audit and clean up shared drives.
  • OWASP accepted invite to apply to directly report suspected and/or confirmed CSAM to Centers for Missing and Exploited Children. Waiting on reporting infrastructure to be provided to us.

50 of 53

DEV Content

Date

Article

Views

Likes

15 Apr 2024

SQL Injection Isn’t Dead Yet

5783

37

13 May 2024

Threat Modeling for Developers

4278

24

07 May 2024

Security for Citizen Developers

2717

10

10 Jun 2024

OWASP Cornucopia 2.0

1862

21

01 Apr 2024

Memory Safe or Bust?

904

12

51 of 53

YouTube Content

Date

Video

Views

Likes

Subscribers

08 Apr 2024

AI and API Security Panel

1,022

33

+35

10 Jun 2024

How to play OWASP Cornucopia

904

16

+2

07 May 2024

Security for Citizen Developers

548

18

+10

17 Jun 2024

Threat Modeling for Developers (Panel)

521

30

+11

52 of 53

Analytics: LinkedIn

261,606 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

155,252

460,888

351,684

203,320

Reactions

815

3,801

2,837

1,967

Comments

20

152

64

51

Reposts

13

84

65

45

New Followers

5,875

5,841

3,959

3,512

53 of 53

Analytics: X (Twitter)

207,966 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

120K

249K

204K

112K

Likes

130

387

415

194

Mentions

84

126

141

72

Reposts + Quotes

48

162

147

77

Followers

206,587

207,132

207,680

207,966