The 2022 Budget process has started. I am meeting with each of the 2022 Board members to obtain their priorities to make sure that we have captured any desired programs that may incur costs or income. A key part of this process is a far greater focus on fundraising. Fundraising is critical to every non-profit Board, and it's not just referring corporate members, but actually planning and undertaking fundraising.
Talking of fundraising, we have slowly reclaimed our Amazon Smile and other charity accounts, like Facebook and so on. I have been adding the 20th Anniversary Fundraiser to the 20th Anniversary videos that are going up. So far, these efforts have brought in only a small amount of funds. During the Board's initial 2022 strategy day, we need to think about how we can fundraise the next $250k to $1m, not the next $1k. Everything helps, but some things help more than others. We will be promoting these fundraisers in our monthly membership benefits email to all members.
Many firms are now approaching us for partnerships for member benefits. These have been tremendously successful in driving up our overall membership numbers, as well as the take up seen by our partners. Our members definitely like and value these partnerships. But it should not be a free for all.
I believe that we will need to publicly publish our current guidelines to achieve vendor neutrality. Right now, we don't require partners to be corporate members, and yet if this pace continues, we should consider a discussion between stakeholders and the Board on defining a partnership policy.
My current partnership settings are:
- of benefit and relevance to OWASP members
- no cost to OWASP members for at least an initial trial version
- provide some benefit and low costs to the partner, such as ensuring that the offer uses Google SSO so that the offer cannot be used or redeemed by non-OWASP members
- partners do not need to be corporate members, but it would be nice as this is a great way to get in front of the OWASP membership with less costs in some cases than being a corporate member
- not a benefit that would hurt OWASP Foundation income elsewhere (i.e. training that would normally raise funds for OWASP and the trainer)
We have tried and so far succeeded at ensuring that none of the benefits are the same thing, but to allow vendor neutrality and equality of access to our members under the same rules, we must permit this sooner or later. I would not recommend this be made into a permanent policy or inflexible guidelines.
The Marketing Plan has moved forward. I've had several meetings with Matt Landry and Jim Cudahy, and the plan is to conduct a survey of members, the Board, and non-members to work out a priority plan that is strategically aligned. Preliminary results will be presented at December's board meeting, with the final report will be presented to the Board Meeting in January 2022.
I've sent through a discussion on the OWASP Global Board mail list regarding a trial of StreamYards. A number of chapters have been using it with good success, so it is important to think about how to provide these services to all chapters rather than a select few. We will be running a trial. This would normally be an operational matter, and as it's unbudgeted and quite close to my signing limit, and likely to continue at least for a few years, I seek Board feedback before signing the first contract, which will provide 10 shared seats of StreamYard's Business Plan for 12 months.
November saw us run our AppSec Global Virtual in the US time zone and run a training event in the Australian Western Standard Timezone. We are close to our budget figures for AppSec Global through no small part of all the efforts of the Events team and everyone who helped them put the events on. I thank Kelly and Lauren, who have worked so very hard at putting these events on. I don't want us to fall back into being an events company, but I deeply thank our community, the speakers, our trainers, and of course our event sponsors for supporting us by attending or sponsoring these events.