OWASP and the summits
What the public record establishes
| Claim | Source |
|---|---|
| Former OWASP Board member | Founder biography, repeated across several documents, with the evidence column reading "Public record, founder biography" |
| "OWASP Leader — Contributed to multiple OWASP projects and organized global security summits" | docs.diniscruz.ai/about — his own published bio, and therefore self-stated |
Email of record is dinis.cruz@owasp.org | The pyproject.toml authors field. A hard artefact. |
The entire Issues-FS estate lives under the owasp-sbot GitHub organisation | Repository location. A hard artefact. |
MGraph-DB publicly credited to OWASP — "an open source, serverless graph database… published by the OWASP community… available in the OWASP SBot GitHub repositories" | Published article |
The summits — four, and the format is the argument
2008 · OWASP European Summit · Algarve, Portugal · 4–7 November
Around 80 attendees. Theme: "Setting the Web Application Security Agenda for 2009." And one striking detail: "the OWASP Foundation covered travel and accommodation costs for all participants (~80 people) using OWASP funds."
The outcomes were structural rather than technical: OWASP's core principles and a formal code of ethics, and the creation of six new global committees. A foundation spent its money flying people to a room to decide how it would govern itself.
2009 · Washington D.C. · 11 November
One day, leadership only: "review 2009 & decide directions for 2010."
2011 · OWASP Global Summit · Lisbon · 8–11 February
"Over 150–180 attendees from more than 20 countries and 120 companies." Named as an organiser: "A dedicated organizing team (led by OWASP volunteers including Dinis Cruz and others) spent months preparing working session topics."
The format is the part that matters: "designed in a working session style format", with "no vendor booths, no purely lecture-style talks to a passive audience." Attendees came from Google, Mozilla, Microsoft, PayPal, Facebook, Apache, Verizon and Dell.
Outcomes: board elections by membership, the first full-time Executive Director, the Browser Security Report 2011, OpenSAMM v1.1, and the seeds of the OWASP Mobile Top Ten. Plus a detail worth pausing on — "reportedly 'thousands' joined some sessions remotely via live streams or IRC, a forward-thinking move in 2011."
2017 · Woburn Forest, UK · 12–16 June
Five days. 173 sessions in total across the week, with attendance in the low hundreds. Named as primary organiser: "organized by OWASP community leaders (with Dinis Cruz, a long-time OWASP contributor, acting as a primary organizer and evangelist)."
Open planning: "proposed working sessions were gathered on a public wiki and interested participants could sign up." Tracks covered Threat Modeling, SAMM, DevSecOps, Education, Mobile, CISO and Research. And the ethos, stated as a rule: "no spectators, only participants."
2018 onward · the Open Security Summit
"the concept of an open, working-session-based security summit was embraced outside the strict OWASP umbrella… The Open Security Summit series explicitly built on the OWASP Summit 2017 model, using the same 5-day intensive format for broader security topics."
The lesson the summits taught, stated in the third person
"the format became more purely collaborative over time… OWASP learned that maximal value came from letting experts 'roll up their sleeves' together rather than having people passively watch slide decks."
"even in an era of constant virtual communication, face-to-face collaboration can significantly accelerate progress on complex security problems."
"OWASP maintained its stance that sponsor involvement should not compromise the neutrality of the content — sponsors contributed to logistical costs but did not get speaking slots or marketing displays at summits, preserving the collaborative, vendor-neutral atmosphere."
The connection nobody has made
The current agentic-team operating model — briefs with named outcomes, cross-team reviews, day-indexes, acceptance criteria on every brief, and "no spectators" as an implicit rule for agents — is the OWASP working-session format applied to a company, and then to a set of AI agents.
That is a real, traceable line from a room in the Algarve in 2008 to an agent team in 2026, and it is one page. It is also the most interesting thing on this site for a reader who came for open source and did not expect a governance argument: the summit format was a solution to the problem of getting expert attention onto hard problems without a vendor capturing the agenda — which is, restated, the funding problem and the neutrality problem at the same time.
The OWASP monetisation thread — a live, unclaimed argument
"say you are an OWASP leader or member with a good reputation for a certain set of application-security skills… One of the challenges today is that you do not have good revenue streams easily, apart from working for companies or doing consulting. That is where skills come into play, because you should be selling those skills."
And the sharper diagnosis: organisations "either use the broad standards as-is… or fork them into static custom guides, losing the benefit of OWASP's ongoing improvements." The proposal — a knowledge-graph working group, an ontology, machine-readable releases — is a finished argument that has never been executed.
This is the funding problem in the same shape, applied to a specific community the author belongs to. That matters: it is a proposal made from inside rather than a critique from outside, which is the only position from which it lands.
What is needed, stated as questions
These are published rather than held privately, because the gap is the point. Thirteen questions, ready:
On OWASP. What years on the board, and what did the role actually involve? Which projects were led or contributed to, and which mattered most? Why is the current estate under owasp-sbot rather than a personal or company org — was that a deliberate statement? What did OWASP get right that other foundations got wrong, and what did it get wrong? And, applying this site's own stress test to OWASP: who holds the trademark, what is the copyright structure, would it survive a hostile change of control?
On the summits. Why did 2017 leave the OWASP umbrella and become the Open Security Summit? Does it still run? Where did "no spectators, only participants" come from, and did it work? The 2008 summit paid travel and accommodation for ~80 people — would that be possible now, and what did it buy? What did running four summits teach you that shows up in how the agent team is run today?
On the projects. O2 Platform, MGraph-DB, OSBot, memory_fs, sgit-ai, Issues-FS — why was each one open-sourced? Did anyone ever contribute? What happened when they did? What would you do differently?