OWASP 2026 Global Board Elections

Bio
Hi OWASP Community, I’m Michael Koppmann.
OWASP has been part of my life in Application Security for over a decade. It began when I was still a young student preparing for my first job interview. Someone gave me one piece of advice: “You should know about the OWASP Top 10.” So I studied it. During the interview, the recruiter actually asked me about several of the risks covered by the Top 10. I could answer the questions, and that was how I started my career as a penetration tester.
Looking back, OWASP did much more than help me through that first interview. Its projects and eventually its community have shaped much of the career that followed. Today, I work as a Senior Information Security Consultant at SBA Research in Austria. Throughout this career, I have worked as a penetration tester, auditor, trainer, speaker, and developer.
For years, OWASP was simply there whenever I needed it. The Top 10 helped me understand common problems, ASVS helped me think about requirements, and Juice Shop supported my training sessions. Projects like SAMM and CycloneDX became valuable parts of my work. At Global AppSec EU in Barcelona in 2025, I met the community behind these projects. People eagerly shared their knowledge, and our conversations led to new ideas and opportunities. The conference had an energy that is hard to describe unless you have experienced it.
It was time to give something back. Together with four other community members, I helped establish the OWASP Vienna Chapter in its current form, and it is becoming an important meeting place for the local security community. I also joined the team developing the OWASP Certified Secure Developer curriculum. Developer education matters deeply to me. I have spent much of my career working with developers, and I want them to understand real security, not compliance theater.
In 2026, I became the lead volunteer at Global AppSec EU Vienna, working alongside more than 30 volunteers. We did whatever it took to keep the event running. It was hard work, but it showed me why I care so much about this community. People from different backgrounds and with different levels of experience came together to make it one of the most successful OWASP events yet.
That is the OWASP I want to support.
Questions
What would you change about the way the OWASP Foundation communicates with its community?
I would focus on making communication about major changes more predictable for volunteers.
When decisions affect chapters or projects, their leaders should be involved early, with realistic timelines and clear explanations of what is changing, why, and what is expected of them.
Important decisions should also come with a short summary of who is responsible and what outcome is expected, followed by a review of whether that outcome was achieved.
The board should set these expectations and review progress, while leaving implementation to staff.
For me, volunteer time is a real organizational resource. The board should treat it with the same respect as financial resources.
Does OWASP’s reliance on proprietary SaaS conflict with its global open-source mission? If so, what should change?
To some extent, yes. OWASP doesn’t need to run everything itself, but we should avoid becoming dependent on a provider we cannot easily replace. The ongoing move away from Meetup after a sharp price increase is a good example of the risks.
I would prefer open-source solutions for core community infrastructure where practical. More importantly, I would prioritize open standards, data portability, and realistic exit plans for critical services.
Self-hosting also brings costs and responsibilities of its own. Changing infrastructure can affect many volunteers, whose time we also need to account for.
The board can set the principles, but any migration should be judged not only by software licensing, but also by security, reliability, cost, usability, and the burden it places on staff and volunteers.
How would you make paid OWASP membership more valuable and attract new members?
One of OWASP’s greatest strengths is that its knowledge and chapter meetings are free. This is a core value we must preserve. But we can do more to show people why becoming a member is worthwhile.
We should promote membership at chapter events and on project pages, and introduce the OWASP Foundation and its membership program at developer and security conferences. We should make existing benefits easier to discover and explain how dues support our mission.
The OWASP Certified Secure Developer certification could also bring developers into OWASP. Membership is currently planned as a certification requirement, but the certification must be valuable in its own right, not simply a way to sell memberships.
But I think the most important part is the community itself. Everyone can be part of OWASP, whether they pay for membership or not. Paid membership gives people something additional: a vote in the organization’s future and a way to support the work that benefits the entire community. We should make both the value of that vote and the impact of their financial support more visible.
How would you improve and diversify OWASP’s fundraising?
Over 75% of OWASP’s income comes from events. Our conferences are great, but depending so heavily on them is a risk.
I would build on existing fundraising efforts by seeking more recurring corporate support, helping projects apply for suitable grants, and making it easier for project leaders to find sponsors.
Many companies use OWASP’s standards and tools every day. They should be encouraged to give something back. Board members can help by representing OWASP, making introductions, and opening doors.
But sponsors must never be able to influence our standards, conclusions, or project decisions. Our vendor neutrality is more important than any sponsorship.
The board should set clear fundraising goals and regularly review whether we’re becoming less dependent on a single revenue source.
Why should OWASP members vote for you?
Because I care. I care about OWASP, and when I see something that I believe is worth doing, I get involved and do the work.
I won’t pretend to have an answer to every problem. But I will listen, ask questions, and take responsibility for my decisions.
Sometimes I think of OWASP as a kind of guild. People come to learn their craft, ask for help, share what they know, and create tools and knowledge together. Eventually, some of the people who once came looking for help become the ones helping the next person.
I want to help ensure that the next student, developer, or security professional can find that same knowledge, meet the same kind of people, and discover that they, too, can become part of this community.
If that is the kind of board member you want, I would be grateful for your vote.