With regard to Operating cash, the Liabilities (AP, accrued expenses, accrued Payroll, deferred revenue for events such as AppSec EU, Lascon, AppSec US etc that may not happen) of $615K added to the $1,069K of Ch/Proj balances is $1,684K , as compared to the $1,431.9K of cash, leaves us a Negative Oper. Cash balance of $252.1K, if all the Chapters and Projects spent all their funds ( I have held out the $113K of PPP federal funding as the chance of it being forgiven is fairly high). This Oper cash deficit is $29K MORE than it was at the end of June. Also Open AR is $177K which is down $56K from the June balance of $233K, which when collected would “Almost” balance out the Oper cash deficit. While we are not currently in a “cash” deficit position, we do need to be cognizant that with the continued travel and meeting restrictions on gatherings which has severely affected our events, if we do not make some of this up with our on line offerings ( SF needs to meet or exceed the current estimates) our cash position will worsen as we move through the rest of the fiscal year. I did see the email noting that AppSec Cali has been cancelled as an “in person” event. It would greatly benefit the Foundation if we were to put on a significant “online event” in its place, not only to help with our Cash flow, but being the first event coming out of the Holidays, could be a significant opportunity for us.
At this point in the year with all that is going on while we are still ahead of budget for Net Income we do need to start to focus on next year as the effects of the Pandemic are not estimated to ease, allowing travel and in person meetings until the fall of 2021. To that end we need to make sure we are providing value in our “online” events not only for the registrants but for our sponsors as well.
I have the next board call as Tues Aug 25th 2020 and I will be attending along with Marissa Oakley who has begun to work on the OWASP financials with me. Be safe everyone
Executive Director Report
The operational plan is slowly coming together, based around three themes: "Survive, Refocus on Mission, and Thrive". I will be making a draft available in the weeks coming. As part of "Survive", I will be ending or discouraging Foundation activities that have limited mission focus, excessive costs for return on investment, or otherwise is not an essential activity that is either not highly visible nor used by our members. We must concentrate our efforts on executing the "Refocus on mission" - doing new things and getting our message out to developers and our industry, and "Thrive", where grants, fundraising, and donations are a key goal.
I've asked the Board to schedule a virtual face to face Board meeting. I propose this to be 2 x 4 hour sessions held over consecutive days. Hopefully, by the time of the Board meeting, this will be scheduled. I look forward to seeing you all there.
I humbly request the Board focus on strategies for the survival of OWASP and our mission. During our prep call, Sherif proposed the formation of a Board sub-committee or similar to allow the ad hoc participation of the Board, myself, and our community on strategic topics essential for OWASP's survival. I strongly urge this takes place. I would dearly love the Board to actively discuss their vision for the future of OWASP with myself and the community, so that we can emerge from the pandemic a stronger Foundation, with deep and integrated links with developers and our industry, and a stronger brand.
The Community needs the Board to move on from all of the internally focused drama. We have a number of challenges, including community disquiet regarding Board issues, resistance to reform, push back on the policy review process, and the contents of the draft policies. I would encourage the Board to put the past behind us, and consider if they wish to slow down or pause the policy review process, completely refactor it, or alternatively, come up with a more open source mechanism for policy development. My preference is the latter. We cannot ignore our longest and most productive members and contributors are getting prepared to walk away if we get this wrong. I think it's time to put a pause, gather community feedback, and not just from those who are the loudest talkers, and re-establish a policy revision mechanism that both achieves reform, but also satisifies our community that they had a real (and not sham) method of developing and approving it.
Regarding policy development, I am writing updated or replacement policies that can give an indication of where the Operating Plan for 2021 will go. The current set revised policies that are causing much distress now are not meeting community expectations, and for root and branch reform of how we fund our mission, I am encouraging devolution to the Community through the Committees 2.0 process to allow the Foundation to focus entirely on survival and being the best Foundation it can for our members, projects, chapters, and committees. However, the Community 2.0 process is flawed, has no guardrails against creating shadow boards, and provides no funding mechanism for Committees. I ask that the Board work with me to reform Committees 2.0 to allow our Community run many of the key programs at OWASP, including a global grant program to replace the expensive and highly contentious "fake balances" that we've been saddled with. This will allow OWASP to scale, and for the Community decide how and why the funds the Board makes available each year should be spent. The Foundation must be in the business of enabling more active mission, more active events, more active chapters, more active projects, and far greater outreach, rather than trying to do all of this themselves. This requires automation, which cannot be baked in if the Community fundamentally disagrees with the policies being reviewed.
- Funding NG - root and branch reform of our finances to promote new activity on a global scale, hold those granted funds to account, including scholarships, awards, and travel, and ensure that the Community approves of and participates in the funding and fundraising. For too long, the Community has wanted to expense things that should never have been expensed, but they had no other avenue. We need a much simpler process for expenses that simply trusts but verifies with a lower limit, and a much more open grants process to allow any Leader, Member, Committee or similar apply for mission related funds and get it done. The grants process demands visible, time boxed outcomes, which we can show donors, grant sources, partners, and government agencies, something the current process does not. There are many nuances, including how to permit very large chapters who need > $3k per month to run their chapters, and how sponsorship and donations will work. Some level of relaxing our vendor neutrality principles to avoid having to put in extremely onerous restrictions that are holding back funding.
- Membership NG - root and branch reform of our membership model. I want to introduce OWASP Reward Points, that through actively doing automatically measurable KPIs, members and leaders can earn complimentary membership and other rewards by doing the things that advance our mission, and to demonstrate value in being a member - even if you earned it through volunteering for us. I would like to see that active project, chapter and committee leaders are able to be rewarded for their hard work, but in return, we can measure their success. This will replace Honorary Membership and meet community expectations regarding "free" leader membership, which has been a huge source of contention. Just like a coffee card, we will need to balance this approach to ensure that the activities contain a wide variety of methods to earning points that also brings activity, positivity, and funds to the Foundation, by gamifying membership.
I do ask that the Board - per the Board of Directors Code of Conduct - after discussing a motion with passion and independence for the benefit of the Foundation you lead rather than any other interests, that once a vote passes the Board comes together as one and supports the vote.
By the time of the Board meeting, I will have investigated access to ongoing Board education. I hope to make this available to all existing Directors, Candidates, and after the election, our new Directors. I would encourage the Board to review your induction materials, our bylaws, the OWASP Board Member Code of Conduct, and Robert's Rules of Order. If you are missing either of your induction books, please contact Dawn for a new copy, or please expense a e-book purchase. Dawn can send you the book details if you wish to have it in electronic format. Once the new version of the Robert's Rules of Order comes out in September, I will get a physical copy sent to all Board members for their reference.
The minutes of the Special Board meeting held on August 11, 2020, had to be modified to take into account the lack of proxy voting. This did not affect the outcome of any vote. The major change is that Martin Knobloch is to be marked Absent (with apologies), and to strike his votes from the record. I will be investigating if we could introduce proxy voting, but for now, this means the minutes.
Recently, a milestone payment of $60k was needing to be approved. As this was a budgeted expense in Budget Forecast Z, this was approved by the ED / Chair co-approving the payment under the Signatory Policy 2.0. These amounts were agreed with the original contract signed with the AV company, CEAVCO, back in May. This milestone downpayment allows us to open the registrations and to start the process of speaker recording. The conference budget proposes a potential income of $742,875.00, and potential expenses of $276,868.08, for a budgeted profit of $466,006.92 for AppSec Virtual. A key portion of this profit is due to the AV platform, which covers the recording and editing of speakers' sessions, registrations, expo, training, keynotes, and the event itself.
In terms of financial risk, we have seen a number of sponsors pull out of AppSec Virtual after a poor Black Hat expo experience for many vendors. I believe our vendor expo platform is better than what I personally experienced at Black Hat. Our events team are working on ways to raise the attractiveness of visiting sponsor booths, especially as all the talks will be available to watch for a 21 day period. We are working on strategies to retain sponsors, including offering a monthly payment model to soften the blow of a huge upfront cost. I will continue to keep you informed.