1 of 56

OWASP Foundation

Board Summary

March 2025

2 of 56

Initiatives & Operations

Andrew van der Stock

OWASP Foundation Staff

3 of 56

Executive Director

  • High level update on family health situation
  • London trip report
  • D&O Insurance is up for renewal - $4m for D&O, $2m for others
  • Update on status of new EU entity
  • Update on status of Barcelona VAT registration
  • Update on status of old EU entity
  • Chapter Committee has sent through updated Charter for approval

4 of 56

Operations

  • Hotel is finalized for Global Board Meeting in Amsterdam. Food menu options will be provided 7 days before event.
  • Are we moving forward with WASPY Awards this year?
  • Working on co-marketing events
    • NDC Oslo - Norway
    • Techarama - Belgium
    • Apidays - New York

5 of 56

Finance

The Charity CFO

6 of 56

Corporate Relations

Kelly Santalucia

7 of 56

Corporate Support

March 2025

(Budget $600,000 on track)

  • Pending quotes from March: $25,000
  • Invoiced in March: $40,000
  • Payments received in March: $2,000

8 of 56

Event Exhibitor and Sponsorship

Event

Budgeted

Sold

Difference

Pending Contracts

Status

SnowFROC

(March)

$75,500

$102,900

$27,400

0

Completed

Expo floor sold out

BASC

(April)

$38,500

$38,420

($80)

0

Platinum and Gold sold out

AppSec Days Israel (June)

$130,000

$57,000

($73,000)

$4,050

Space available

AppSec Days France

(September)

$15,000

$12,499

($2,501)

$1,097

Gold and Silver sold out

LASCON�(October)

$113,000

$23,390

($89,610)

$8,500

Space available

Global AppSec EU

(May)

$449,068

$335,012

($114,056)

$47,565

Diamond, Gold, and Silver sold out

Global AppSec US

(November)

$919,900

$283,175

($636,725)

$126,360

Silver sold out

9 of 56

Corporate Supporter Pipeline

10 of 56

Conference Exhibit/Sponsor Pipeline

11 of 56

Membership

Hayden Corry

12 of 56

Individual Members

We are still learning about the new platform, but it is proving far more accurate than the old platform, which over inflated numbers.

One Year 3,604 -245

Two Year 1,058 -27

Lifetime 1,333 +36

Complimentary 217 +5

Lower figures are due to the AMS being accurate. Many fraudulent complimentary memberships were not renewed.

Force Majeure has become renewal only and subject to ID verification

If substantial abuse continues after the ID audit, strongly recommend complimentary memberships of all types be sunsetted.

13 of 56

Multifactor Authentication

Approaching 100% of active users

Enabled November 12

Then: 1259 / 8323 (15%)

Now: 2913 (+186)/ 8817 (+142, or 33%, up 2%)

New enforcement date April 30, 2025

14 of 56

Membership Tickets Last 30 days

15 of 56

Chapters

Hayden Corry

16 of 56

Chapter Procedures

Hayden Corry will collaborate with Starr and Christian to automate the chapter creation process.

A new process is being documented

Hayden is reviewing the Chapter Policy for rewrites.��

17 of 56

Chapter Tickets

18 of 56

New Chapters Last 60 Days

  • 2025-02-07, OWASP Juiz de Fora
  • 2025-02-07, OWASP Salvador
  • 2025-02-17, OWASP Bartlesville
  • 2025-02-13, OWASP Chapter Heilbronn
  • 2025-02-14, OWASP Hermosillo
  • 2025-01-16, OWASP Leiria
  • 2025-02-14, OWASP Londrina
  • 2025-02-14, OWASP Luxembourg City
  • 2025-02-07, OWASP Oshawa
  • 2025-02-14, OWASP Ruhrpott
  • 2025-02-16, OWASP Sri Sairam Engineering College
  • 2025-02-08, OWASP Yaounde
  • 2025-02-25, OWASP Cebu
  • 2025-02-24, OWASP Cologne
  • 2025-02-13, OWASP Heilbronn
  • 2025-03-18, OWASP Bharati Vidyapeeth (Deemed to be University) College of Engineering
  • 2025-03-13, OWASP JIS University

19 of 56

Meetup Membership Data

155,162 Total members

  • 221 Groups - (298 active chapters)
  • 70 meetings in the last 30 days
  • 3,081 new members joined in the last 30 days
  • 38,092 members visited a group within the last year

20 of 56

Projects and Grants

Starr Brown

21 of 56

Project Housekeeping

GitHub

  • Archiving GitHub repos that haven’t updated since 2023 or older
    • Notified the community via email & Slack on March 3rd
  • Stats will be shared once complete
    • Estimated conclusion April 2025

Email Lists

22 of 56

Project Housekeeping

Shared Resources

Added Liblab

  • SDKs for API
  • Free access for open-source projects
  • Request access via Jira and will be shared during first Town Hall

Increased DockerHub seats

  • Auditing to remove disused accounts
  • 5 > 50 seats

Working on AWS credits

  • Consolodating all AWS accounts that OWASP projects depend on to a single Foundation account
  • Surveying leaders to compile list of all accounts to resource correctly with Amazon

23 of 56

Projects & Community

Town Hall Community Sessions

  • Monthly (Last Friday of the month)
  • Two meetings in one day to cover dual time zones (8 CEST / 8 ET)
  • Goal to enhance service to the Project community by being more responsive to their goals and concerns
  • Listed on OWASP events calendar
  • Kicks off March 28th

Office Hours

  • Open Zoom call every other Thursday
  • Listed on OWASP events calendar
  • Kicks off April 3rd

24 of 56

Events

Lauren Thomas

25 of 56

General Events Updates

  • 2024 Global AppSec SF videos have been released to the General Public.
  • 2025 Global AppSec US (Washington, D.C) Super Early Bird Tickets, Call for Training, and Sponsorship documents are up.
  • Short list of 2026/2027 and possibly 2028 Global AppSec EU locations have been made.
  • Heather is working with the Events Committee to address Events in a Box
  • Working with Edmond Momartin to bring AppSec Cali back in 2026

26 of 56

Industry Trends

  • Last-minute registrations remain major pain point
  • Finding meeting space remains a challenge. Clients are booking space further out to get the locations and dates they want. It behooves planners to secure not just hotels early, but transportation, venues and excursions.
  • “Rising costs are the harsh reality everyone’s living in today so it’s all about revenue growth for our clients – exhibitor engagement, pricing models and sponsorships.
  • Acceleration of event technology, innovation, and data insights are a critical focus
  • Authorities are trying to address overtourism during certain times of the year in hot spots like Barcelona, Rome, London, Paris and Amsterdam that cause hassles, like crowded venues and high costs.
  • South Africa and Dubai are seeing interest among a segment of clients looking for a high-end, unique experience.
  • The APAC region has seen some softening among clients. Reduced air lift, higher fares and travel time from the U.S. are factors.
  • Space is still at a premium in Japan, Singapore and elsewhere thanks to booming tourism
  • South Korea and India are seeing emerging interest.
  • As companies shift operations to Latin America, places like Bogota, Buenos Aires and Panama are seeing increased investment and infrastructure.

27 of 56

Global AppSec EU (Barcelona) Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 865 Budgeted: 700

Sold: 386 Sold: 331

% sold to budget: 44.6% % sold to budget: 47.3%

Training

Budgeted: 130

Sold: 48

% sold to budget: 36.9%

Note: After review of previous Global AppSec Ticket Sales, it appeared as though we were not capturing many Early Bird ticket sales. In an attempt to gain more EB ticket sales and appeal to an audience requiring lower ticket costs (and therefore increasing overall conference attendance), we opened a Super Early Bird ticket and open sales earlier to accommodate. This has resulted in a 205% increase in early bird ticket sales when compared to 2024 Global AppSec SF (43 tickets) and a 107% increase in early bird ticket sales for 2024 Global AppSec Lisbon (82 tickets).

28 of 56

2025 and Beyond Global AppSec Events at a Glance

Event

Date

Attendees

Trainees

Est. Profit

Status

2025 Global Appsec EU (Barcelona)

May 26-30, 2025

700 goal

130 goal

$100,000

Planning in progress

2025 Global AppSec US (DC)

November 3-7

900 goal

TBD

$325,000

Planning in progress

2026 Global AppSec US (SF)

November 2-6

900 goal

TBD

TBD

Dates confirmed

Sourcing for future EU and US Global conferences are currently ongoing

29 of 56

2025 AppSec Days at a Glance

Event

Date

Attendees

Trainees

Profit

Status

OWASP SnowFROC

March 14, 2024

300 goal

100 goal

$17,020 goal

Completed

AppSec Days BASC

April 5, 2025

200 goal

0

$10,000 goal

On Track

AppSec Israel

June 5, 2025

887 goal

0

$37,968 goal

On Track

AppSec Days Italy

June 19, 2025

120 goal

0

€2,000 goal

On Track

OWASP AppSec Days India

September 19, 2025

400 goal

0

TBD - just applied

On Track

AppSec Days France

September 23, 2025

100 goal

0

€10,911 goal

On Track

OWASP AppSec Days Singapore

September 2025

100

30

Break even

On Track

30 of 56

2025 AppSec Days at a Glance… Continued

Event

Date

Attendees

Trainees

Profit

Status

OWASP LASCON

October 21-24, 2025

350

20

$36,716 goal

On Track

German OWASP Day

November

TBD

TBD

TBD

Has not applied but will

OWASP AppSec Days Uruguay

November 19-20, 2025

700

20

Break even

On Track

OWASP BeNeLux

December 2-3, 2025

150

40

Break even

On Track

31 of 56

2025 SnowFROC Status Completed

March 14

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

322

300

$30,000.00

0

$30,000.00

Completed

Trainees

78

100

$5,000.00

0

$5,000.00

Completed

Trainers

4

4

0

$1,000.00

0

Completed

Speakers

15

17

0

0

0

Completed

Venue

$14,875.00

$14,875.00

0

$14,875.00

0

Completed

Catering

$25,000.00

$25,000.00

0

$25,000.00

0

Completed

32 of 56

2025 BASC Status On Track

April 5

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

37

220

0

0

0

Low Attendance

Trainees

n/a

n/a

n/a

n/a

n/a

On Track

Trainers

n/a

n/a

n/a

n/a

n/a

On Track

Speakers

10

10

0

0

0

On Track

Venue

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

On Track

Catering

On Track

33 of 56

2025 AppSec Israel Status On Track

June 5, 2025

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

0

887

0

0

0

On Track

Trainees

n/a

n/a

n/a

n/a

n/a

On Track

Trainers

n/a

n/a

n/a

n/a

n/a

On Track

Speakers

10

10

0

0

0

On Track

Venue

$24,714.00

$24,714.00

N/A

$24,714.00

N/A

On Track

Catering

$51,149.00

$51,149.00

N/A

$51,149.00

N/A

On Track

34 of 56

Completed events

35 of 56

2024 SnowFROC Status Completed

March 7

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

329 paid

78 free

407 total

400

$30,000.00

0

$30,000.00

Completed

Net Payout: $22,747.16

Trainees

59

100

$5,000.00

0

$5,000.00

Completed

Trainers

4

4

0

$1,000.00

0

Completed

Sponsors

21

10

$30,000.00

0

$30,000.00

Completed $74,500

Speakers

15

17

0

0

0

Completed

Venue

$14,875.00

$14,875.00

0

$14,875.00

0

Completed

Catering

$25,000.00

$25,000.00

0

$25,000.00

0

Completed

36 of 56

2024 BASC Status Completed

April 6

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

247

220

0

0

0

Completed

Trainees

n/a

n/a

n/a

n/a

n/a

Completed

Trainers

n/a

n/a

n/a

n/a

n/a

Completed

Sponsors

17

13

$37,000

0

$37,000

Completed $40,000

Speakers

10

10

0

0

0

Completed

Venue

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

$0 - Microsoft is providing Venue as a sponsor

Completed

Catering

Completed

37 of 56

2024 AppSec Days PNW Status Completed

June 15-16

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

286

310

$15,750

0

0

Completed

Trainees

N/A

N/A

N/A

N/A

N/A

N/A

Trainers

N/A

N/A

N/A

N/A

N/A

N/A

Speakers

15

15

0

0

0

Completed

Venue

$13,513

$13,513

0

$13,513

0

Completed

Catering

$14,000

$14,000

0

$14,000

0

Completed

38 of 56

2024 Global AppSec Lisbon Status: Completed

June 24-28

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

782

600

€350,000

0

€350,000

Completed�

Trainees

182

130

€150,000

0

€150,000

Completed

Trainers

10

5

0

€100,000

0

Completed

Speakers

40

40

0

€7,000

0

Completed

Venue

€75,000

€88,000

0

€88,000

0

Completed

Catering

€300,000

€300,000

0

€300,000

0

Completed

39 of 56

Global AppSec San Francisco Summary

Overall Conference Tickets (Receptions, conference, training) Conference Tickets

Budgeted: 1155 Budgeted: 900

Sold: 1093 Sold: 851

% sold to budget: 95% % sold to budget: 95%

Training

Budgeted: 115

Sold: 242

% sold to budget: 210%

40 of 56

2024 AppSec Days Panama Status Completed

September 11-12 (waiting on final report from organizers)

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

209

100

0

0

0

Completed

Trainees

190

40

0

0

0

Completed

Trainers

4

4

0

0

0

Completed

Speakers

12

12

0

0

0

Completed

Venue

Complimentary

Complimentary

0

Complimentary

0

Completed

Catering

$10,000

$10,000

0

$10,000

0

Completed

41 of 56

2024 AppSec Days Singapore Status Completed

October 1-2,2024

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

137

100

0

0

0

Completed

Trainees

21

30

0

0

0

Completed

Trainers

2

3

0

0

0

Completed

Speakers

12

12

0

0

0

Completed

Venue

$25,632 SGD

$25,632 SGD

0

$25,632 SGD

0

Completed

Catering

$31,920 SGD

$31,920 SGD

0

$31,920 SGD

0

Completed

42 of 56

2024 LASCON Status Completed

October 22-25

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

384

350

$71,720

0

$71,720

Completed

Trainees

48

20

$11,000

$11,000

Completed

Trainers

3

3

0

$19,800

0

Completed

Speakers

0

50

0

$3,750

0

Completed

Venue

$81,000

$81,000

0

$81,000

0

Completed

Catering

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

Incl in venue

43 of 56

2024 German OWASP Day Status Completed

November 12-13

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

113

200

€40,907.00

0

€40,907.00

Completed

Trainees

37

36

€3,437.00

€1,050.00

€2,387.00

Completed

Trainers

3

2

0

€1,050.00

0

Completed

Speakers

13

13

0

€2,080.00

0

Completed

Venue

€4,445.00

€4,445.00

0

€4,445.00

0

Completed

Catering

€10,600.00

€10,600.00

0

€10,600.00

0

Completed

44 of 56

2024 AppSec Days India Status Completed

November 14-15

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

599

500

25,000 INR

0

25,000 INR

Completed

Trainees

N/A

N/A

N/A

N/A

N/A

Completed

Trainers

N/A

N/A

N/A

N/A

N/A

Completed

Speakers

0

24

0

0

0

Completed

Venue (Virtual - Streamyard)

TBD

TBD

TBD

TBD

TBD

Completed

Catering

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

N/A - virtual

Completed

45 of 56

2024 AppSec Days BeNeLux Status Completed

November 28

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

354

300

0

0

0

Completed

Trainees

88

80

€4,000.00

0

€4,000.00

Completed

Trainers

2

2

0

€600.00

0

Completed

Speakers

8

8

0

€960.00

0

Completed

Venue

€11,990.00

€11,990.00

0

€11,990.00

0

Completed

Catering

€21,060.00

€21,060.00

0

€21,060.00

0

Completed

46 of 56

2024 Global AppSec SF Status completed

September 23-27

Current / Submitted

Projected / Budgeted

Budgeted Income

Budgeted Expense

Budgeted Profit

Status

Attendees

851

900

$530,000

0

$530,00

Completed

Trainees

242

115

$200,000

0

$200,000

Completed

Trainers

6

6

0

$100,000

0

Completed

Speakers

4

44

0

$4,000

0

Completed

Venue

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

Incl. in f&b

Completed

Catering

$450,000

$450,000

0

$450,000

0

Completed

47 of 56

Community Development

Christian Capellan

48 of 56

Force Majeure Accounts

  • No address or other identifying information was requested from force majeure complimentary accounts (Israel, Ukraine). Over 1000 accounts with no info, most appear to be fraudulent.
  • Auditing 50 top users by Google Drive usage are being audited (address requested).
    • 30 day deadline given before account deletion.
    • Only two responses so far, both giving well-known non-residential addresses (a nightclub and a warehouse).
    • One account was storing significant adult content, possible CSAM.
  • Short-term: will be requiring address for new force majeure accounts (soon).
  • Long-term: no force majeure accounts will be automatically ported to new AMS. Individuals will be contacted and asked to resubmit, providing address in new workflow.

49 of 56

Google Drive

  • Google Workspace usage at 50% (down from 100% in May).
  • Continuing to audit and clean up shared drives.
  • OWASP accepted invite to apply to directly report suspected and/or confirmed CSAM to Centers for Missing and Exploited Children. Waiting on reporting infrastructure to be provided to us.

50 of 56

DEV Content

Date

Article

Views

Likes

15 Apr 2024

SQL Injection Isn’t Dead Yet

5783

37

13 May 2024

Threat Modeling for Developers

4278

24

07 May 2024

Security for Citizen Developers

2717

10

10 Jun 2024

OWASP Cornucopia 2.0

1862

21

01 Apr 2024

Memory Safe or Bust?

904

12

51 of 56

YouTube Content

Date

Video

Views

Likes

Subscribers

08 Apr 2024

AI and API Security Panel

1,022

33

+35

10 Jun 2024

How to play OWASP Cornucopia

904

16

+2

07 May 2024

Security for Citizen Developers

548

18

+10

17 Jun 2024

Threat Modeling for Developers (Panel)

521

30

+11

52 of 56

Analytics: LinkedIn

261,606 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

155,252

460,888

351,684

203,320

Reactions

815

3,801

2,837

1,967

Comments

20

152

64

51

Reposts

13

84

65

45

New Followers

5,875

5,841

3,959

3,512

53 of 56

Analytics: X (Twitter)

207,966 followers

Mar 2024

Apr 2024

May 2024

Jun 2024 (so far)

Organic Impressions

120K

249K

204K

112K

Likes

130

387

415

194

Mentions

84

126

141

72

Reposts + Quotes

48

162

147

77

Followers

206,587

207,132

207,680

207,966

54 of 56

2024 Global AppSec San Francisco Exhibitor & Sponsorship Pipeline

Exhibitors

Budgeted

53

Sold

64

% sold to budget

120%

Sponsors

Budgeted

7

Sold

10

% sold to budget

142%

Budgeted Exhibit & Sponsor Revenue

$965,000

Current based on my tracking

$1,206,125

Exceeded $965k budget by 24.98%

$241,125 additional profit

55 of 56

OWASP Executive Advisory Report (EAR) Project

Summary of Outreach Efforts to Non-Security Companies

Industries Engaged:

  • Finance
  • Crypto Exchange
  • Video Game Development
  • Software Development
  • Airlines
  • Electronics & Entertainment

Objective:�To gather suggestions on how OWASP can attract greater corporate support from non-security companies.

Methodology:�Conducted interviews with security thought leaders from various non-security companies to gain insights and recommendations.

Key Question Posed:�"What could OWASP do to attract your corporate support?"

Next Steps:Findings have been compiled and will be presented to the Board of Directors for review.

56 of 56

Corporate Supporters

Budget Goal $425k - projected to exceed by 24.4%

I am projected to exceed the $425k goal set by Andrew by 24.4%. I am continuing to drive sales and aiming to achieve an even higher percentage by year-end.

November:

Total dollar amount of quotes sent: $87k

Invoiced (quotes signed): $37k

Payments Received: $64k

December (to date):

Total dollar amount of quotes sent: $17k

Invoiced (quotes signed): $44k

Payments Received: $14k