<!-- generated from owasp/index.html by admin/build/gen_markdown.py — do not edit by hand -->

*[open-source.sgit.ai](/index.md) · site v0.2.2 · canonical: https://open-source.sgit.ai/owasp/index.html*

> Four summits from 2008 Algarve to 2017 Woburn's 173 sessions, the working-session format and no spectators only participants — written from the public record, with the first-person account planned and its questions published.

---

# OWASP and the summits

> **How this page is written.** Everything below is **sourced and checkable**, and it is written from the public record rather than from memory — the summits as they were reported, with the author's role in them as the record states it. The first-person account — board tenure, the projects led, the founding of the Open Security Summit — is [planned, and its questions are published below](#interview), so that when it is written it answers what a reader would actually ask.

## What the public record establishes

| Claim | Source |
|---|---|
| **Former OWASP Board member** | Founder biography, repeated across several documents, with the evidence column reading *"Public record, founder biography"* |
| *"OWASP Leader — Contributed to multiple OWASP projects and **organized global security summits**"* | `docs.diniscruz.ai/about` — his own published bio, and therefore self-stated |
| Email of record is **`dinis.cruz@owasp.org`** | The `pyproject.toml` authors field. A hard artefact. |
| The entire Issues-FS estate lives under the **`owasp-sbot`** GitHub organisation | Repository location. A hard artefact. |
| **`MGraph-DB` publicly credited to OWASP** — *"an open source, serverless graph database… published by the OWASP community… available in the OWASP SBot GitHub repositories"* | Published article |

> **Note what the last three mean.** This is not a historical affiliation being cited for credibility. **The current work ships under the OWASP organisation, under an OWASP email address, with at least one project publicly credited to the OWASP community.** The thread is live, and this page presents it in the present tense.

## The summits — four, and the format is the argument

### 2008 · OWASP European Summit · Algarve, Portugal · 4–7 November

Around 80 attendees. Theme: *"Setting the Web Application Security Agenda for 2009."* And one striking detail: *"the OWASP Foundation **covered travel and accommodation costs for all participants (~80 people)** using OWASP funds."*

The outcomes were structural rather than technical: **OWASP's core principles and a formal code of ethics**, and the creation of **six new global committees**. A foundation spent its money flying people to a room to decide how it would govern itself.

### 2009 · Washington D.C. · 11 November

One day, leadership only: *"review 2009 & decide directions for 2010."*

### 2011 · OWASP Global Summit · Lisbon · 8–11 February

*"Over 150–180 attendees from more than 20 countries and 120 companies."***Named as an organiser:***"A dedicated organizing team (led by OWASP volunteers **including Dinis Cruz** and others) spent months preparing working session topics."*

The format is the part that matters: *"**designed in a working session style format**"*, with *"**no vendor booths, no purely lecture-style talks to a passive audience**."* Attendees came from Google, Mozilla, Microsoft, PayPal, Facebook, Apache, Verizon and Dell.

Outcomes: board elections by membership, the first full-time Executive Director, the Browser Security Report 2011, OpenSAMM v1.1, and the seeds of the OWASP Mobile Top Ten. Plus a detail worth pausing on — *"reportedly 'thousands' joined some sessions remotely via live streams or IRC, **a forward-thinking move in 2011**."*

### 2017 · Woburn Forest, UK · 12–16 June

Five days. **173 sessions in total across the week**, with attendance in the low hundreds. **Named as primary organiser:***"organized by OWASP community leaders (with **Dinis Cruz, a long-time OWASP contributor, acting as a primary organizer and evangelist**)."*

Open planning: *"proposed working sessions were gathered on a public wiki and interested participants could sign up."* Tracks covered Threat Modeling, SAMM, DevSecOps, Education, Mobile, CISO and Research. And the ethos, stated as a rule: ***"no spectators, only participants."***

### 2018 onward · the Open Security Summit

*"the concept of an open, working-session-based security summit was embraced outside the strict OWASP umbrella… **The Open Security Summit series explicitly built on the OWASP Summit 2017 model**, using the same 5-day intensive format for broader security topics."*

> **And this is where the public record stops.** Why the series moved outside the OWASP umbrella, what changed, and its current state are part of the first-person account. [The questions are published below →](#interview)

## The lesson the summits taught, stated in the third person

> "the **format became more purely collaborative over time**… OWASP learned that maximal value came from letting experts 'roll up their sleeves' together rather than having people passively watch slide decks."

> "even in an era of constant virtual communication, **face-to-face collaboration can significantly accelerate progress on complex security problems**."

> "OWASP maintained its stance that sponsor involvement should not compromise the neutrality of the content — sponsors contributed to logistical costs but did not get speaking slots or marketing displays at summits, preserving the collaborative, **vendor-neutral** atmosphere."

## The connection nobody has made

The current agentic-team operating model — briefs with named outcomes, cross-team reviews, day-indexes, acceptance criteria on every brief, and *"no spectators"* as an implicit rule for agents — **is the OWASP working-session format applied to a company, and then to a set of AI agents.**

That is a real, traceable line from a room in the Algarve in 2008 to an agent team in 2026, and it is one page. It is also the most interesting thing on this site for a reader who came for open source and did not expect a governance argument: **the summit format was a solution to the problem of getting expert attention onto hard problems without a vendor capturing the agenda** — which is, restated, [the funding problem](../funding/index.md) and [the neutrality problem](../survivability/index.md) at the same time.

## The OWASP monetisation thread — a live, unclaimed argument

> "say you are an OWASP leader or member with a good reputation for a certain set of application-security skills… **One of the challenges today is that you do not have good revenue streams easily, apart from working for companies or doing consulting.** That is where skills come into play, because you should be selling those skills."

And the sharper diagnosis: organisations *"either use the broad standards as-is… or **fork them into static custom guides, losing the benefit of OWASP's ongoing improvements**."* The proposal — a knowledge-graph working group, an ontology, machine-readable releases — is a finished argument that has never been executed.

This is [the funding problem](../funding/index.md) in the same shape, applied to a specific community the author belongs to. That matters: it is **a proposal made from inside rather than a critique from outside**, which is the only position from which it lands.

## What is needed, stated as questions

These are published rather than held privately, because the gap is the point. Thirteen questions, ready:

**On OWASP.** What years on the board, and what did the role actually involve? Which projects were led or contributed to, and which mattered most? **Why is the current estate under `owasp-sbot` rather than a personal or company org — was that a deliberate statement?** What did OWASP get right that other foundations got wrong, and what did it get wrong? And, applying [this site's own stress test](../survivability/stress-test.md) to OWASP: who holds the trademark, what is the copyright structure, would it survive a hostile change of control?

**On the summits.** Why did 2017 leave the OWASP umbrella and become the Open Security Summit? Does it still run? Where did *"no spectators, only participants"* come from, and did it work? The 2008 summit paid travel and accommodation for ~80 people — would that be possible now, and what did it buy? What did running four summits teach you that shows up in how the agent team is run today?

**On the projects.****O2 Platform, MGraph-DB, OSBot, memory_fs, sgit-ai, Issues-FS — why was each one open-sourced?** Did anyone ever contribute? What happened when they did? What would you do differently?

> **The model already exists.** The O2 Platform article — a real retrospective on the 2010–2012 OWASP SAST engine — shows what these accounts look like when written. It was written about the author rather than by him; the six retrospectives on [the build order](../roadmap/index.md#interview) are the first-person versions.

[← cURL](../funding/curl.md)[What's next →](../roadmap/index.md)

---

*This page is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).*
