The 20th Anniversary has been all consuming, and so I apologize for the late staff reports, including my own. I beg forgiveness, because we are really kicking community and financial goals.
I wish to thank Kelly Santalucia, Dawn Aitken, and RMK Productions for putting on a really successful 20th Anniversary Celebration. We had around 5000 registrations, and heavy viewing throughout the 24 hours of the event. We will be doing content marketing of the videos to our members as a member benefit shortly once the videos have been edited and uploaded, and released publicly by the end of the year. I watched many of the sessions, and I was particularly affected by Mark Curphey's keynote. I will share that video with the Board, because it marks exactly the course I've been navigating for OWASP, and I think he has some solid "inside but outside" counsel for the Board and the community I wish to discuss sooner than later.
In events finance news, I have signed RMK Productions for AppSec Global November 2021. The cost is similar to the 20th Anniversary is within the budget that the Board approved last year. The signing authority changes means that the invoices will need to be co-approved by either Grant or Sherif.
We held a Lifetime Membership drive, which has been very successful, with 118 new Lifetime Memberships, for a revenue of $45k that we have ten years to make up with new one, two and lifetime members. I think this is achievable if we stay on course with our policy and community reform, getting back to our community being deeply centered in everything we do. We have blown through our 4000 member goal set out in the September 2020 Operating Plan, with 4,936 members as of 27th September 2021. This is an increase of 1,778 new members, or an increase of 56.3% since I joined on June 29, 2020. This is without a doubt, a high water mark for OWASP membership at any point in our history.
Our finances are doing significantly better than budgeted due to the incredible support of our community, our Corporate Members and Event Sponsors, and of course our members. I wish to thank everyone deeply for their continued support of OWASP.
I think this demonstrates that getting the Foundation's community spirit back, setting the right policies, involving the community deeply in everything we do, and stamping down hard on toxic behavior and very occasionally on specific individuals has really helped OWASP thrive. I make zero apologies for coming down hard on toxic behavior or on individuals who wish us harm, because they were killing OWASP before and actively harming our mission. Let's be positive, let's move forward, and build our impact for our mission. A well engaged and positive community, with leadership that doesn't bow to the loudest negative voices, demonstrably leads to fantastic outcomes for everyone.
Lastly, it's that time of the year again where we need to put together the 2022 budget. I will be reaching out to candidates to find out if they have any measures that will require funding, and invite successful candidates to finesse a draft so that the new Board can approve the 2022 budget as their first piece of business in the January 2022 Board meeting.
Some of the bigger issues that I would like the new Operating Plan and budget to address are:
- An end to end customer experience review. We MUST review our business processes and fully embed our new policies in our operating procedures and automation to improve customer experience, reduce costs, improve self-service, and free up staff for high value activities. For example, wherever there is friction with our community, and it's not a guardrail to protect the community, our core values, the OWASP Foundation or its finances, or our ability to do our mission, the friction must be removed with great vigor as it is a vampiric negative drain on community spirit, takes resources and emotional energy away from actually important activities, and diminishes the execution of our mission, which relies on the goodwill of volunteers. Unnecessary friction is the enemy of volunteerism and it must be eradicated unless there's a very good reason for it
- Documenting our business requirements, evaluating, and migrating to an off the shelf association management platform to improve customer experience, reduce our costs and improve productivity
- Documenting our event business requirements, evaluating, and adopting an integrated events platform to reduce our costs and improve the productivity and customer experience of events, and to reduce the number of systems we need users to register and use
- Formal marketing budget. We need to start planning a return to in person events, even though it doesn't feel that way right now. As such, we need to start figuring out bulk swag, a swag policy (chapters don't need swag to operate, but when approved, how do they get it locally, where do they get the artwork, and what will be the limits?). I want to start a retention marketing plan to ensure that we use our massive increase in membership numbers to grow the organization for organic growth, and use a marketing push for inorganic growth in the developer and AppSec Leadership personas.