1 of 57

OWASP Foundation

Board Summary

February 2025

2 of 57

Initiatives & Operations

Andrew van der Stock

OWASP Foundation Staff

3 of 57

Executive Director

  • Stripe auto-renewal subscriptions will be ended Feb 28, 2025
    • Communications will take place with the community
    • Affects approximately 1483 members +/- 500 (due to CC renewal)
  • Staff Summit - lots of initiatives that need to be prioritized
  • Non Profit Cyber Meeting in London
  • Website Redesign Status
  • Monday CRM Migration - single source of truth, finally

4 of 57

Operations

  • Finalizing hotel for Global Board Meeting in Amsterdam
  • Working on A/R collectibles
  • Worked on Chapter tickets

5 of 57

Finance

The Charity CFO

6 of 57

Corporate Relations

Kelly Santalucia

7 of 57

Corporate Support

February 2025

(Budget $600,000 on track)

  • Pending quotes: $27,000
  • Invoiced: $34,000
  • Payments received: $22,000

  • The EAR Project team continues to meet weekly. We are in Phase II and working on the training deliverables. Organized closed door sessions will begin in early March.

8 of 57

Event Exhibitor and Sponsorship Sales

Event

Budgeted

Sold

Difference

Amount in Pending Contracts

Status

SnowFROC

(March)

$75,500

$99,900

$24,400

0

Expo floor sold out

BASC

(April)

$38,500

$35,420

($3,080)

$1,500

Platinum and Gold sold out

AppSec Days Israel (June)

$130,000

$34,500

($95,500)

$13,850

Space available

AppSec Days France

(September)

$15,000

$12,499

($2,501)

$5,485

Gold sold out

LASCON�(October)

$113,000

$23,390

($89,610)

$12,500

Space available

Global AppSec EU

(May)

$449,068

$254,050

($195,018)

$58,946

Diamond and Gold sold out

Global AppSec US

(November)

$919,900

On “sale” Feb 21

9 of 57

Corporate Supporter Pipeline

10 of 57

Conference Exhibit/Sponsor Pipeline

11 of 57

Membership

Hayden Corry

12 of 57

Individual Members

We are still learning about the new platform, but it is proving far more accurate than the old platform, which over inflated numbers.

One Year 3686 -135

Two Year 1,085 -5

Lifetime 1,309 +12

Complimentary 212 -25

Lower figures are due to the AMS being accurate. Many fraudulent complimentary memberships were not renewed.

Force Majeure has become renewal only and subject to ID verification

If substantial abuse continues after the ID audit, strongly recommend complimentary memberships of all types be sunsetted.

13 of 57

Multifactor Authentication

Approaching 100% of active users

Enabled November 12

Then: 1259 / 8323 (15%)

Now: 2727 / 8675 (31%)

New enforcement date March 31, 2025

14 of 57

Membership Tickets Last 30 days

15 of 57

Chapters

Hayden Corry

16 of 57

Chapter Procedures

Hayden Corry will collaborate with Starr and Christian to automate the chapter creation process.

A new process is being documented

Hayden is reviewing the Chapter Policy for rewrites.��

17 of 57

Chapter Tickets

18 of 57

New Chapters

19 of 57

Meetup Membership Data

152,249 Total members

  • 212 Groups - (286 active chapters)
  • 54 meetings in the last 30 days
  • 2,100 new members joined in the last 30 days
  • 37,808 members visited a group within the last year

20 of 57

Projects and Grants

Starr Brown

21 of 57

Projects

22 of 57

Projects

23 of 57

Projects @ Events

Developer Week report available here

Key takeaways:

  • Developer engagement requires specialized content
    • Laptops out for a lab or simple examples with code on screen of best practices
    • Cheat Sheets #1 most referred OWASP Project
    • Short presentations work best for audience
    • Virtual had more than 2x the attendance & could deliver content more affordably OWASP can best represent itself on both
  • Volunteers are helpful for wider coverage but staff should support to ensure that post-event reporting and on-site engagement is meaningful to the Foundation & community
  • The event itself was approximately 2000 in-person attendees
  • Required 120 humans to run, a mix of staff, freelancers, and volunteers
  • Audience receptive to learning to code more securely and to become contributors as a learning path

Additional Developer Conference:

  • QCon should be considered for Senior dev attention
    • Suggestion from OWASP Developer Week speaker, Q-Con scheduled speaker and long time London chapter co-leader, Andra Lezza
    • November 17-19, 2025 in San Francisco

24 of 57

GSoC 2025

  • GSoC 2025
    • Met with mentors & long-time community contributors to increase impact through better engagement & planning
    • Highly recommend interviews as pool of students is increasing as well as their submissions utilizing more GPT than ability
    • Increased social media presence to solicit community & contributor engagement
    • Highlight Student & Project contributions in live stream at end of term as showcase
      • Potentially as Global AppSec US DC stream event

25 of 57

Events

Lauren Thomas

26 of 57

General Events Updates

  • 2024 Global AppSec SF videos have been sent to OWASP members and can be accessed here. Videos will be open to the General Public March 23, 2025.
  • 2025 Global AppSec US (Washington, D.C) Super Early Bird Tickets, Call for Training, and Sponsorship documents are up.
  • Sourcing for future Global AppSec US and EU Conferences are well underway.
  • Heather is working with the Events Committee to address Events in a Box
  • Working with Edmond Momartin to bring AppSec Cali back in 2026

27 of 57

Industry Trends

  • Last-minute registrations remain major pain point
  • Finding meeting space remains a challenge. Clients are booking space further out to get the locations and dates they want. It behooves planners to secure not just hotels early, but transportation, venues and excursions.
  • “Rising costs are the harsh reality everyone’s living in today so it’s all about revenue growth for our clients – exhibitor engagement, pricing models and sponsorships.
  • Acceleration of event technology, innovation, and data insights are a critical focus
  • Authorities are trying to address overtourism during certain times of the year in hot spots like Barcelona, Rome, London, Paris and Amsterdam that cause hassles, like crowded venues and high costs.
  • South Africa and Dubai are seeing interest among a segment of clients looking for a high-end, unique experience.
  • The APAC region has seen some softening among clients. Reduced air lift, higher fares and travel time from the U.S. are factors.
  • Space is still at a premium in Japan, Singapore and elsewhere thanks to booming tourism
  • South Korea and India are seeing emerging interest.
  • As companies shift operations to Latin America, places like Bogota, Buenos Aires and Panama are seeing increased investment and infrastructure.

28 of 57

Global AppSec EU (Barcelona) Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 865 Budgeted: 700

Sold: 174 Sold: 146

% sold to budget: 20% % sold to budget: 23%

Training

Budgeted: 130

Sold: 13

% sold to budget: 10%

Note: After review of previous Global AppSec Ticket Sales, it appeared as though we were not capturing many Early Bird ticket sales. In an attempt to gain more EB ticket sales and appeal to an audience requiring lower ticket costs (and therefore increasing overall conference attendance), we opened a Super Early Bird ticket and open sales earlier to accommodate. This has resulted in a 205% increase in early bird ticket sales when compared to 2024 Global AppSec SF (43 tickets) and a 107% increase in early bird ticket sales for 2024 Global AppSec Lisbon (82 tickets).

29 of 57

2025 and Beyond Global AppSec Events at a Glance

Event

Date

Attendees

Trainees

Est. Profit

Status

2025 Global Appsec EU (Barcelona)

May 26-30, 2025

700 goal

130 goal

$100,000

Planning in progress

2025 Global AppSec US (DC)

November 3-7

900 goal

TBD

$325,000

Planning in progress

2026 Global AppSec US (SF)

November 2-6

900 goal

TBD

TBD

Dates confirmed

Sourcing for future EU and US Global conferences are currently ongoing

30 of 57

2025 AppSec Days at a Glance

Event

Date

Attendees

Trainees

Profit

Status

OWASP SnowFROC

March 14, 2024

300 goal

100 goal

$17,020 goal

On Track

AppSec Days BASC

April 5, 2025

200 goal

0

$10,000 goal

On Track

AppSec Israel

June 5, 2025

887 goal

0

$37,968 goal

On Track

AppSec Days Italy

June 19, 2025

120 goal

0

€2,000 goal

Just applied - event not formally approved yet

OWASP AppSec Days India

September 19, 2025

400 goal

0

TBD - just applied

Just applied - event not formally approved yet

AppSec Days France

September 23, 2025

100 goal

0

€10,911 goal

On Track

OWASP AppSec Days Singapore

TBD - Likely Sept./Oct.

100

30

Break even

Conducting Site tours before formally applying

31 of 57

2025 AppSec Days at a Glance… Continued

Event

Date

Attendees

Trainees

Profit

Status

OWASP LASCON

October 21-24, 2025

350 goal

20 goal

$36,716 goal

On Track

German OWASP Day

November

TBD

TBD

TBD

Has not applied but will

OWASP AppSec Days Uruguay

November 19-20, 2025

700 paid

20 goal

Break even

On Track

OWASP BeNeLux

December

TBD

TBD

TBD

Just applied - reviewing documents

32 of 57

2025 SnowFROC Status On Track

March 14

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

160

300

$30,000.00

0

$30,000.00

On Track

Trainees

8

100

$5,000.00

0

$5,000.00

Low attendance

Trainers

4

4

0

$1,000.00

0

On Track

Speakers

15

17

0

0

0

On Track

Venue

$14,875.00

$14,875.00

0

$14,875.00

0

On Track

Catering

$25,000.00

$25,000.00

0

$25,000.00

0

On Track

33 of 57

2025 BASC Status On Track

April 5

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

0

220

0

0

0

On Track

Trainees

n/a

n/a

n/a

n/a

n/a

On Track

Trainers

n/a

n/a

n/a

n/a

n/a

On Track

Speakers

10

10

0

0

0

On Track

Venue

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

On Track

Catering

On Track

34 of 57

2025 AppSec Israel Status On Track

June 5, 2025

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

0

887

0

0

0

On Track

Trainees

n/a

n/a

n/a

n/a

n/a

On Track

Trainers

n/a

n/a

n/a

n/a

n/a

On Track

Speakers

10

10

0

0

0

On Track

Venue

$24,714.00

$24,714.00

N/A

$24,714.00

N/A

On Track

Catering

$51,149.00

$51,149.00

N/A

$51,149.00

N/A

On Track

35 of 57

Completed events

36 of 57

2024 SnowFROC Status Completed

March 7

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

329 paid

78 free

407 total

400

$30,000.00

0

$30,000.00

Completed

Net Payout: $22,747.16

Trainees

59

100

$5,000.00

0

$5,000.00

Completed

Trainers

4

4

0

$1,000.00

0

Completed

Sponsors

21

10

$30,000.00

0

$30,000.00

Completed $74,500

Speakers

15

17

0

0

0

Completed

Venue

$14,875.00

$14,875.00

0

$14,875.00

0

Completed

Catering

$25,000.00

$25,000.00

0

$25,000.00

0

Completed

37 of 57

2024 BASC Status Completed

April 6

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

247

220

0

0

0

Completed

Trainees

n/a

n/a

n/a

n/a

n/a

Completed

Trainers

n/a

n/a

n/a

n/a

n/a

Completed

Sponsors

17

13

$37,000

0

$37,000

Completed $40,000

Speakers

10

10

0

0

0

Completed

Venue

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

Completed

Catering

Completed

38 of 57

2024 AppSec Days PNW Status Completed

June 15-16

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

286

310

$15,750

0

0

Completed

Trainees

N/A

N/A

N/A

N/A

N/A

N/A

Trainers

N/A

N/A

N/A

N/A

N/A

N/A

Speakers

15

15

0

0

0

Completed

Venue

$13,513

$13,513

0

$13,513

0

Completed

Catering

$14,000

$14,000

0

$14,000

0

Completed

39 of 57

2024 Global AppSec Lisbon Status: Completed

June 24-28

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

782

600

€350,000

0

€350,000

Completed�

Trainees

182

130

€150,000

0

€150,000

Completed

Trainers

10

5

0

€100,000

0

Completed

Speakers

40

40

0

€7,000

0

Completed

Venue

€75,000

€88,000

0

€88,000

0

Completed

Catering

€300,000

€300,000

0

€300,000

0

Completed

40 of 57

Global AppSec San Francisco Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 1155 Budgeted: 900

Sold: 1093 Sold: 851

% sold to budget: 95% % sold to budget: 95%

Training

Budgeted: 115

Sold: 242

% sold to budget: 210%

41 of 57

2024 AppSec Days Panama Status Completed

September 11-12 (waiting on final report from organizers)

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

209

100

0

0

0

Completed

Trainees

190

40

0

0

0

Completed

Trainers

4

4

0

0

0

Completed

Speakers

12

12

0

0

0

Completed

Venue

Complimentary

Complimentary

0

Complimentary

0

Completed

Catering

$10,000

$10,000

0

$10,000

0

Completed

42 of 57

2024 AppSec Days Singapore Status Completed

October 1-2,2024

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

137

100

0

0

0

Completed

Trainees

21

30

0

0

0

Completed

Trainers

2

3

0

0

0

Completed

Speakers

12

12

0

0

0

Completed

Venue

$25,632 SGD

$25,632 SGD

0

$25,632 SGD

0

Completed

Catering

$31,920 SGD

$31,920 SGD

0

$31,920 SGD

0

Completed

43 of 57

2024 LASCON Status Completed

October 22-25

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

384

350

$71,720

0

$71,720

Completed

Trainees

48

20

$11,000

$11,000

Completed

Trainers

3

3

0

$19,800

0

Completed

Speakers

0

50

0

$3,750

0

Completed

Venue

$81,000

$81,000

0

$81,000

0

Completed

Catering

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

44 of 57

2024 German OWASP Day Status Completed

November 12-13

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

113

200

€40,907.00

0

€40,907.00

Completed

Trainees

37

36

€3,437.00

€1,050.00

€2,387.00

Completed

Trainers

3

2

0

€1,050.00

0

Completed

Speakers

13

13

0

€2,080.00

0

Completed

Venue

€4,445.00

€4,445.00

0

€4,445.00

0

Completed

Catering

€10,600.00

€10,600.00

0

€10,600.00

0

Completed

45 of 57

2024 AppSec Days India Status Completed

November 14-15

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

599

500

25,000 INR

0

25,000 INR

Completed

Trainees

N/A

N/A

N/A

N/A

N/A

Completed

Trainers

N/A

N/A

N/A

N/A

N/A

Completed

Speakers

0

24

0

0

0

Completed

Venue (Virtual - Streamyard)

TBD

TBD

TBD

TBD

TBD

Completed

Catering

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

Completed

46 of 57

2024 AppSec Days BeNeLux Status Completed

November 28

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

354

300

0

0

0

Completed

Trainees

88

80

€4,000.00

0

€4,000.00

Completed

Trainers

2

2

0

€600.00

0

Completed

Speakers

8

8

0

€960.00

0

Completed

Venue

€11,990.00

€11,990.00

0

€11,990.00

0

Completed

Catering

€21,060.00

€21,060.00

0

€21,060.00

0

Completed

47 of 57

2024 Global AppSec SF Status completed

September 23-27

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

851

900

$530,000

0

$530,00

Completed

Trainees

242

115

$200,000

0

$200,000

Completed

Trainers

6

6

0

$100,000

0

Completed

Speakers

4

44

0

$4,000

0

Completed

Venue

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

Completed

Catering

$450,000

$450,000

0

$450,000

0

Completed

48 of 57

Community Development

Christian Capellan

49 of 57

Force Majeure Accounts

  • No address or other identifying information was requested from force majeure complimentary accounts (Israel, Ukraine). Over 1000 accounts with no info, most appear to be fraudulent.
  • Auditing 50 top users by Google Drive usage are being audited (address requested).
    • 30 day deadline given before account deletion.
    • Only two responses so far, both giving well-known non-residential addresses (a nightclub and a warehouse).
    • One account was storing significant adult content, possible CSAM.
  • Short-term: will be requiring address for new force majeure accounts (soon).
  • Long-term: no force majeure accounts will be automatically ported to new AMS. Individuals will be contacted and asked to resubmit, providing address in new workflow.

50 of 57

Google Drive

  • Google Workspace usage at 50% (down from 100% in May).
  • Continuing to audit and clean up shared drives.
  • OWASP accepted invite to apply to directly report suspected and/or confirmed CSAM to Centers for Missing and Exploited Children. Waiting on reporting infrastructure to be provided to us.

51 of 57

DEV Content

Date

Article

Views

Likes

15 Apr 2024

SQL Injection Isn’t Dead Yet

5783

37

13 May 2024

Threat Modeling for Developers

4278

24

07 May 2024

Security for Citizen Developers

2717

10

10 Jun 2024

OWASP Cornucopia 2.0

1862

21

01 Apr 2024

Memory Safe or Bust?

904

12

52 of 57

YouTube Content

Date

Video

Views

Likes

Subscribers

08 Apr 2024

AI and API Security Panel

1,022

33

+35

10 Jun 2024

How to play OWASP Cornucopia

904

16

+2

07 May 2024

Security for Citizen Developers

548

18

+10

17 Jun 2024

Threat Modeling for Developers (Panel)

521

30

+11

53 of 57

Analytics: LinkedIn

261,606 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

155,252

460,888

351,684

203,320

Reactions

815

3,801

2,837

1,967

Comments

20

152

64

51

Reposts

13

84

65

45

New Followers

5,875

5,841

3,959

3,512

54 of 57

Analytics: X (Twitter)

207,966 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

120K

249K

204K

112K

Likes

130

387

415

194

Mentions

84

126

141

72

Reposts + Quotes

48

162

147

77

Followers

206,587

207,132

207,680

207,966

55 of 57

2024 Global AppSec San Francisco Exhibitor & Sponsorship Pipeline

Exhibitors

Budgeted

53

Sold

64

% sold to budget

120%

Sponsors

Budgeted

7

Sold

10

% sold to budget

142%

Budgeted Exhibit & Sponsor Revenue

$965,000

Current based on my tracking

$1,206,125

Exceeded $965k budget by 24.98%

$241,125 additional profit

56 of 57

OWASP Executive Advisory Report (EAR) Project

Summary of Outreach Efforts to Non-Security Companies

Industries Engaged:

  • Finance
  • Crypto Exchange
  • Video Game Development
  • Software Development
  • Airlines
  • Electronics & Entertainment

Objective:�To gather suggestions on how OWASP can attract greater corporate support from non-security companies.

Methodology:�Conducted interviews with security thought leaders from various non-security companies to gain insights and recommendations.

Key Question Posed:�"What could OWASP do to attract your corporate support?"

Next Steps:Findings have been compiled and will be presented to the Board of Directors for review.

57 of 57

Corporate Supporters

Budget Goal $425k - projected to exceed by 24.4%

I am projected to exceed the $425k goal set by Andrew by 24.4%. I am continuing to drive sales and aiming to achieve an even higher percentage by year-end.

November:

Total dollar amount of quotes sent: $87k

Invoiced (quotes signed): $37k

Payments Received: $64k

December (to date):

Total dollar amount of quotes sent: $17k

Invoiced (quotes signed): $44k

Payments Received: $14k