June 2026 Videoconference
Meeting Details
- Date: 24 June 2026
- Time: 17:30 - 19:00 Central European Summer Time, UTC 15:30 convert
- Location: In person at OWASP Global AppSec Vienna 2026, Room TBD
- Recording
Agenda
CALL TO ORDER
Board Members
- Ricardo Griffith - PRESENT
- Steve Springett - PRESENT
- Harold Blankenship - PRESENT
- Sam Stepanyan - PRESENT
- Ashwini Siddhi - PRESENT
- Kelly Santalucia - PRESENT
- Marisa Fagan - PRESENT
Guests
- Andrew van der Stock
- Missie Lindsey
- Starr Brown
- Stacey Ebbs
- Chris Barbeau (via pre-recorded video)
- Shruti Kulkani
- and other guests in the audience
CONFLICT OF INTEREST AND ANTI-TRUST STATEMENT
As the Board consists of individuals from many competing organizations, OWASP and its Board shall abide by all applicable anti-trust and competition laws. To avoid any perceived or actual conflict of interest, or anti-trust concerns under US federal, state, or regulations, only the published agenda shall be discussed or voted upon, or amended as below. If there are any conflicts of interest, Board members are expected to disclose the conflict of interest and must recuse themselves from discussion and voting.
No conflicts of interest were disclosed at the start of the meeting.
CHANGES TO THE AGENDA
Changes to the agenda - unless otherwise prohibited by anti-trust or competition laws - including adding, altering, or tabling of motions is permitted by following Roberts Rules of Order (RONR 12th Ed) 41:63, which requires an affirmative two-thirds vote.
A change to the agenda was proposed to add a discussion by Shruti Kulkani regarding the OWASP Certified Secure-Software Developer certification program, a regional training event, and Teach-AppSec. The motion was seconded and passed unanimously.
APPROVAL OF MINUTES
The minutes of the previous meeting were approved unanimously.
PRE-READING MATERIAL
- OWASP Foundation Board Summary
- Finance Board Summary
- Finance Board Summary Video
- Finance Board Slide Deck
- Finance Board Slide Deck Video
- Finance Board Cash Flow Forecast
- Finance Board Aged Receivables
Foundation Summary update from Andrew van der Stock
Andrew van der Stock delivered the management report. He reported significant progress on hiring, especially for the Associate Executive Director role. OWASP had identified 13 finalist candidates and interviewed 12. An offer had been extended, with other strong candidates available if the offer was not accepted. Andrew also noted plans to seek additional candidates for a community support role, emphasizing that community understanding was important for the role.
Andrew reported a payment dispute with Salesforce. OWASP believed it was current on billing, but Salesforce had engaged a debt collector. Andrew planned to resolve the matter through the Salesforce account team.
Audit fieldwork was reported as on schedule. OWASP had completed management interviews, supplied requested materials, and expected fieldwork to close in July. A draft audit was expected in August or September, earlier than the previous year. Andrew also expected OWASP to be well positioned to file its Form 990 by the November 15 deadline.
The board also discussed Google Workspace notifications related to Google Takeout. Andrew explained that OWASP’s education plan produces graduation-style notices, and disabling Google Takeout would create GDPR concerns. He recommended accepting the minor inconvenience rather than disabling users’ ability to export their data.
Andrew reported that two of OWASP’s three certificates of deposit had been rolled into longer-term instruments maturing in November, with stronger yields than the prior option. He noted this could affect the timing of OWASP Corporation investment, with November likely the earliest practical point for a substantial investment.
Other operational updates included:
- Barcelona VAT remained to be paid, but OWASP had the required information.
- Certificate of residency requests had been submitted, including one with the IRS.
- A foreign liability insurance policy was still pending from the broker.
- Additional insurance needs for OWASP EU directors had been identified.
- OWASP had filed a trademark dispute concerning misuse of OWASP trademarks, with no response yet from LinkedIn.
- Andrew was exploring an AI dashboard to give the board more real-time operational visibility, though he was not yet sure it provided enough value.
Finance Summary update from Chris Barbeau
A finance summary prepared by Charity CFO was presented. The May financials showed strong liquidity and positive year-to-date results:
- Cash at the end of May was approximately $2.335 million, up about $182,000 from April.
- The current ratio improved to nearly 11:1.
- Accounts receivable exceeded $1m with about $295,000 over 90 days old.
- Cash on hand exceeded six months.
- Total net assets increased to about $3.8 million.
- Year-to-date revenue was approximately $2.78 million.
- Year-to-date expenses were approximately $1.46 million.
- Year-to-date net gain was approximately $1.32 million.
- May net income was approximately $645,000, largely driven by conference revenue.
Andrew emphasized that accounts receivable was too high, especially the approximately $295,000 over 90 days old. He distinguished between small fees that may be written down and larger receivables tied to services or sponsorships that OWASP should pursue. He said reducing aged receivables would be a priority.
Cash flow projections suggested OWASP could finish the year with around $1.95 million in cash. The main financial headwind identified was the high cost of San Francisco, particularly for future conference-related costs. Andrew noted the organization would focus spending on programming and event quality rather than extras. He also reported that OWASP had secured AV and session recording support for AppSecEU for the next three years.
Additional Foundation updates from Andrew van der Stock
Andrew praised Missie Lindsey’s sponsorship work, noting that she had reengaged past corporate supporters, upgraded some sponsors to platinum, and was helping develop the proposed Industry Advisory Council as both a value-add and revenue opportunity.
Marketing was reported as strong under Stacey’s work. Andrew noted improved reach after a prior decline attributed to AI-driven changes in web traffic. He said storytelling-style content appeared to be performing better than repetitive event announcements. He also observed that AI systems were heavily scraping OWASP materials and suggested OWASP should consider how to engage with AI companies or derive value from that use. OWASP planned a new impact report later in the year.
Membership support was described as under control, with ticket creation and resolution in balance. Chapter support, however, had a backlog. Andrew reported 44 chapter-related tickets awaiting action, including add/remove leader requests, student chapter requests, and reactivation requests. He expected the new website to help address those issues. Meetup activity had improved despite reducing the number of groups. Andrew said leaders would be asked to begin transitioning communities away from Meetup over the next six months, using the new OWASP website as the central place to find meeting information.
Global AppSec Europe 2026 was described as very successful, with record attendance and strong ticket sales. OWASP had expanded its Glue Up licensing multiple times due to demand. The 25th anniversary events were also progressing, with chapters selecting birthday party events. Andrew reminded the board that lifetime membership had previously been approved to increase to $750 in 2027, and the 25th anniversary year was an opportunity to encourage signups before that increase.
Change of agenda: Discussion of OWASP Certified Secure-Software Developer certification program, regional training event, and Teach-AppSec
Shruti Kulkani presented the following updates:
-
OWASP Certified Secure-Software Developer certification program: is ready for review and will be presented as project demo on Friday
-
Regional training event: the pilot event was held in London in Feb 2026, which received good feedback from the attendees
-
Teach-AppSec: This is an application security project which has curriculum including teaching hours and references for the modules.
For full details, please review the video recording, starting at approximately 50 minutes into the recording.
NEW BUSINESS
Summary of private Board meeting and outcomes
Marisa Fagan summarized the previous private board meeting. The board had a full schedule and discussed several operational and governance topics of public interest.
Key topics included:
- Completion of the community policy review policy, which would unlock broader policy review work.
- Membership trends, retention risks, and growth opportunities.
- Committee operations and alignment with committee policy.
- Student chapters, including standards for opening and maintaining chapters and a renewed commitment to supporting them.
- The proposed Industry Advisory Council and next steps.
- An AI impact assessment covering OWASP’s mission, events, projects, education, funding, governance, and partnership opportunities.
- Board travel cost reductions, in response to rising travel expenses.
THe public version of minutes of this meeting can be found associated minutes from the private Board meeting.
Discussion on website update
Andrew gave an update on the new OWASP website. He said the project had taken much longer than expected but was close to launch. Remaining issues included bugs affecting board member display, content readiness, events, news, finance and governance pages, board and OWASP EU content, and policy listings.
Security review had been completed, including penetration testing by a CREST-certified firm, source-code review, and API testing. Andrew said known issues such as SQL injection and token exposure had been resolved and retested.
The main remaining work was content readiness and final DNS or routing changes, which required Christian’s involvement after returning from leave. Andrew emphasized that chapters and projects would remain responsible for updating their own content, but marketing support would be offered to help improve landing pages and messaging. OWASP would prioritize flagship and production projects, upcoming events, and board meeting information before launch.
A discussion followed about Meetup migration and data export. Andrew explained that email addresses had been exported for archived chapters, but GDPR constraints limited how OWASP could use them. Some previously deleted Meetup groups had been restored, though some leaders had not yet been restored as organizers. Ricardo asked whether chapter communities should be periodically reminded to move to the new system. Andrew agreed communication was needed but warned against excessive messaging that could lead to unsubscribes.
Discussion on when Chapter creation will be back online
Andrew said city chapter creation would resume shortly after the new website goes live, assuming no major launch issues. Student chapters would require interviews with students and faculty to validate legitimacy. Because of the northern hemisphere summer, some student chapter approvals may wait until August or September. The immediate goal was to clear the city chapter backlog first, then process student chapters as universities return from break.
Student chapter discussion
The board then discussed student chapters more broadly. Marisa summarized the board’s conclusion: OWASP has a renewed commitment to student chapters, but supporting students also requires consistently enforcing policies. Inactive groups should be treated according to policy so expectations are clear.
Ashwini suggested connecting student chapters with local city chapters through points of contact, so city chapters can help rejuvenate inactive student chapters. She also proposed mentorship programs and invited creative ideas for supporting students.
Andrew emphasized the need to restart the Chapter Committee, which can help inactive chapters recover. Sam noted that the committee was one chapter leader short of reforming and invited interested leaders to volunteer through the OWASP Slack chapter committee channel.
Chapter and broader policy discussion
Sam explained that the chapter policy needs updates because it was created during the pandemic and is now out of date. Specific issues included:
- The policy incorrectly stating that chapter leaders do not need to be members, despite later changes requiring membership.
- Contradictory language about student chapters and city chapters.
- Outdated references to Meetup Pro and operational instructions no longer relevant to OWASP’s future direction.
- Need to update chapter leader responsibilities and shared services available to leaders.
- Need to better reference the Code of Conduct.
Policy review discussion (merged with Chapter policy discussion)
Ricardo then summarized the broader policy review work. The community review policy had been outdated and required substantial attention. A policy review team had been formed, with Marisa helping identify participants. The team reviewed the policy through several sessions and returned it for further review during the Vienna meeting. Ricardo said about a dozen additional policies were expected to be reviewed and updated in priority order during the year.
Marisa and Sam also discussed a forthcoming Code of Ethics policy. Marisa explained that the Code of Ethics would complement the Code of Conduct: the Code of Conduct governs community behavior, while the Code of Ethics would apply more directly to membership and professional standards. Sam said this would align OWASP with similar organizations and create a clearer ethical commitment for members.
COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS
ADJOURNMENT
Adjournment motion
The next general Board meeting is on July 28, 2026, at 12 pm US Eastern Time.
“It is moved, and seconded to adjourn. Those in favor, say “aye””
Sponsor: Chair Second: TBA