Past Meetings

April 2020 Minutes

Official minutes of this Board meeting.

Meeting Details

  • Date: Tuesday, April 28, 2020
  • Time: 1:00 PM EDT – 2:30 PM
  • Location: Remote

Call to Order

Board Members

Directors will be recorded when the meeting is called to order.

Guests

No guests listed.

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

None listed.

Reports

COVID-19 Response

Attached to this month's New Business is the Executive Director's report/plan for the remainder of 2020 considering the worldwide coronavirus pandemic. The economic plan is build with the most conservative event revenue forecast assuming ALL gatherings more than 50 people would be prohibited for the remainder of the year. The original ask from the Board was to only model SF, but if SF were to be cancelled many other events on our calendar would share the same fate.

We modeled several different outcomes and have presented three new, and our original approved plan for a total of four options. We are recommendation a hybrid of budget caps and new revenue activities to best mitigate the finanical impact of cancelling 2020 events.

Two other related activites were to (1) apply for the US Payroll Protection Plan and (2) quickly identify other revenue streams for the Foundation. #1 was completed but OWASP Foundation was not included in the first round of funding of this program. It should be noted that the forumlas provided by the Federal Government cap our loan amount at $41,552 meaning that while it would help; it is not a transformative impact. #2 resulted in the Virtual AppSec Days (more details below) which have already resulted in over $125,000 revenue to the Foundation.

Conferences

As directed by the Board to design and implement quick revenue opportunities to backfill 2020 revenue lost from the postponement of Global AppSec Dublin, the staff launched Virtual AppSec Days registration on 7-April. Given the urgency of the Board’s request, staff elected to select from previously accepted CfT submissions instead of the longer process to open a fresh CfT.

As of 25-April, the conference has 1,165 Conference attendee registrants, 242 Training registrations, and 85 CtF registrations. Our marketing has led to over 17K visitors to the registration site. The event is expected to gross over $125,000 with a forecasted profit of at least $75K. Our custom-build registration tool has been reliably processing registrations and will save the Foundation at least $4,250 compared to having used our previous provider or Eventbrite.

Needless to say, standing up, launching and preparing for an event like with so many unfamiliar tools on such an aggressive timeline has been extremely stressful for staff. Emily, Sibah, and Harold deserve a great deal of thanks for making this event happen - incredibly so successfully, on an absurd timeline. Following the close of this event, staff is already brainstorming ways we could add this concept to our evergreen programming.

San Francisco CfT and CfP closed with 53 and 172 submissions respectively. Kelly has already been actively selling the event and has $398K contracted revenue with $120K in the sales pipeline. Over the past three weeks, selling results have been soft due to COVID-19 and general market uncertainty. We are tracking to plan on key milestones which can be found, along with contracted sponsors at https://owasp.org/www-staff/projects/202010-Global-AppSec-SF

As part of our COVID-19 plan we have secured (but have not signed) a contract with the same venue in SF for 2021. We requested, and were given concessions, if we still need to cancel the 2020 event without force maejour. We have also received our contract for Berlin 2022. Both of these items are on the April 2020 Board agenda for approval.

Lisa submitted an updated DEFCON application for a larger booth. Staff will be coordinating with the Outreach Committee on this Global Partnership effort. Plans for BlackHat US are underway for August 1-6 and BlackHat Asia has been rescheduled to September 29 - October 2, 2020. OWASP will be participating in both events.

Website

SEO engagement will end the first week of May. Search visibility since site launch in January is down only 0.63% which would be considered a best in class metric for a site with such a complicated content remapping need. In addition to ensuring our URLs were remapped the firm with Harold’s help also performed keyword research & mapping, 301 redirect mapping, xml and html sitemap creation, schema markup design, title tag & meta description optimizations, 404 page recommendations, duplicate content analysis, broken link analysis, on-site competitive analysis, branded search audit, and Cloudflare and server migration support.

Work is proceeding with our DNS/VM migration. DNS is now serving from Cloudflare which also gives better caching leading to a 10% increase in site response time down from an average 330ms to less than 300ms. The wiki is in the process of being moved to a new, more affordable hosting VM. There was an effort to static-fy the wiki to remove MySQL dependencies but that effort requires more research. More details can be found https://owasp.org/www-staff/projects/202003-DNS-VM-migration.html

Content migration by Chapters and Projects has slowed with 156 of 271 Chapters (57.5%) and 88 of 151 (58.3%) Projects yet to migrate. Chapter page migration, along with new chapter activity can be monitored at https://owasp.org/chapters/status/

Community Review Process

Tricia (Virtual resource) has been assisting me in developing the Community Review Process. I would expect this item to be ready for Board review at our May meeting. Rather than just tossing up a tool to collect feedback, I have instead chosen to develop a process that not just collects feedback, but also defines roles, participants, a methodology to process conflicting data, reporting, and then delivers a final work product.

Staffing

Following last month’s Board discussion, we closed on a final Sr. Events Manager candidate. We are in the compensation negotiation phase with our preferred candidate.

We have been reassigning roles between Dawn and Lisa. The substantive change is Dawn will no longer have primary responsibility for Community and Chapters allowing her to solely focus on operations and as our internal accounting interface to Virtual. Lisa has very willingly accepted several new responsibilities as part of this transition. There are some additional alterations yet to complete on workflows but no issues are expected.

IT Retooling

Copper migration continues. We have migrated Chapter, Project, and Committee information into the system. Kelly has been updating Opportunities so we can more transparently monitor pipeline and invoicing. Hopefully before 1-June the CRM will be ingesting Membership, Donation, and Event transactions. Some early testing has verified the functionality, it is now just a matter of defining requirements and building some light tools to animate this effort. We do not anticipate any major issues with this migration.

Finally, Harold and I have been brainstorming integrations between our website and Meetup. We have also been discussing a backup plan for replacing Meetup if their business model continues to change. It is also notable that Meetup currently costs ~$32K per year so even today it is not trivial.

New Business

No items.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.