Past Meetings

May 2020 Minutes

Official minutes of this Board meeting.

Meeting Details

  • Date: Tuesday, May 26, 2020
  • Time: 1:00 PM EDT – 2:30 PM
  • Location: Remote

Call to Order

Board Members

Directors will be recorded when the meeting is called to order.

Guests

No guests listed.

Conflict of Interest and Anti-Trust Statement

As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.

Changes to the Agenda

Changes to the agenda — unless otherwise prohibited by anti-trust or competition laws — including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.

Approval of Minutes

None listed.

Pre-reading Material

None listed.

Reports

Conferences

Virtual AppSec Days was a very big success. The conference had 1,248 Conference attendee registrants, 371 Training registrations, and 161 CtF registrations. Our marketing has led to over 19K visitors to the registration site. The event grossed $164,530 using the custom-build registration tool that reliably processed registrations and saved the Foundation $5,594 compared to having used our previous provider or Eventbrite.

Staff is working with the Tiger Team to plan the Virtual AppSec Summer of Security repeating the training format in June, July, and August. We have yet to make a decision on the Conference and Capture the Flag activities. The Call for Trainers is now closed with 73 submissions.

The Global AppSec SF program is coming together and staff is preparing to launch the Registration website on June 1. Two of our Keynote speakers have already been confirmed and have signed the speaker agreement. We have executed the Global AppSec SF 2021 event contract and expect the contract for Berlin 2022 to be received shortly.

DEFCON and BlackHat have been cancelled by the organizers.

Staffing

Alonna Stock, Sr. Events Manager will be starting on June 1. She will be working with Emily on our event planning and execution. Initially she will be the lead on Regional and Local events while heavily assisting Emily on Global Events. The Foundation elected to not renew Sibah Poede’s contract.

Website

SEO engagement ended the first week of May. Final changes to our broken link analysis has further reduced our offsite traffic (going to wiki) to only 5.3% of site traffic.

Content migration by Chapters and Projects is ongoing with 133 of 283 Chapters (46.9%) and 91 of 152 (59.9%) Projects yet to migrate. Chapter page migration, along with new chapter activity can be monitored at https://owasp.org/chapters/status/

Responding to community feedback, we have implemented alternate footers that can be selected per page of the website. The issue was a few members of the community didn’t like the size of the footer that recognized our Corporate Supporters. The new design uses less vertical space and an alternate design removes the spotlight company.

Event P&Ls

Dawn has been given the task to close all 2019 Event P&Ls. This has been a longtime outstanding item and I’m grateful Dawn has stepped up to work with Virtual on resolving this matter.

GDPR

This project is ongoing and we had hoped to launch this effort at the beginning of the month. As you may know, our primary email address has nearly 50,000 names on it. While this is impressive, unfortunately there is no record of subscriber opt-in to the list. This is a very big risk for the Foundation. We intend to have run a two-week campaign to that list requesting the opt-in for future emails from the Foundation.

IT Retooling

We continue to find automation opportunities with Copper and our workflows. The team has implemented several new processes for handling sales that are increasing efficiency and reducing our costs. The Foundation has started processing invoices through Stripe. This change will offer greater flexibility for our partners when paying the Foundation including secure credit card payment.

Harold and I have been brainstorming integrations between our website and Meetup. We have also been discussing a backup plan for replacing Meetup if their business model continues to change. It is also notable that Meetup currently costs ~$32K per year so even today it is not trivial.

Virtual Events

  • Summer of Security
    • June 23 - 24
    • July 28 - 29
    • August 25 - 26
  • 5 sponsorships sold so far (goal is 10)
  • Call for trainers closed Friday (over 50 submissions)
  • Website will launch Monday June 1
  • Goal is to have at least 10 training per month
  • Schedule will be announced the week of June 1
  • The team is still exploring other possible talks and contests to hold during these weeks

San Francisco Global AppSec

  • Trainer acceptance letters went out on Friday
    • 8 trainings were accepted
    • Program team has list of other highly graded trainings that we can add of we go virtual
  • Presenter acceptances will go out this Friday
  • All presenters and trainers were alerted that the conference may go virtual and they were asked to confirm they are comfortable with that format.
  • Keynotes have been selected
    • John Steven,
    • Masha Sedova
    • Andrew Clay Schafer
    • Colleen Coolidge
    • We are in the process of collecting their info and the website should be updated by the end of the month
  • Registration will open the second week of June in or order to not overlap the Summer of Security registration launch
  • We have contracted with an AV company that has a virtual solution should we decide to go that route
  • I have been researching price points for a virtual conference as well as viewing demos for virtual trade-show floors
  • Kelly, MIke, and I have been researching how to deliver sponsors value in a virtual environment.

Dublin Global AppSec

  • The new timeline for CfP/CfT is as follows:
    • Reopen call for papers August 1
    • Reclose CfP September 20
  • Announce full schedule October 19 (during the Global AppSec)
  • Recommending we revisit the feasibility of an in-person conference in November (Nov 20th?) which will give us plenty of time to cancel our hotel contract penalty-free and explore options with CCD.
  • Force majeure penalty-free cancelation
  • Potential deferment to 2023

Future Global AppSec 2021

  • San Francisco: October 18-22, 2021
  • Dublin: February 15-19, 2021

Global AppSecs 2022

  • Berlin: May 2-6 2022
  • North America: TBD
  • Full 18 month project will be presented at the June board meeting, this will apply to events in 2022 and beyond as the next 18 months are still too uncertain to and we must remain agile during these times.

New Business

No items.

Comments, Announcements, and Other Business

Adjournment

OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.