Global Initiatives/Cyber Security Startup Initiative
OWASP Cyber Security Startup Initiative
The aim of the OWASP Cyber Security Startup Initiative (CSSI) is to catalyse opportunities for innovation in application security by promoting the creation of prototypes of open source tools produced by entrepreneur-lead teams seeking to form cyber-security start-ups. OWASP will be piloting this initiative by running the cyber security incubator with sponsors. The ideal sponsors of this initiative are academic institutions, government entities and corporate sponsors/private investors. OWASP will manage the initiative end to end: from the initial planning and documentation of the cyber-security start-up process to the running and the piloting the initiative to the final documentation of the process and incorporation of the lessons learned. OWASP will be managing the logistical aspects of the program and OWASP leaders will mentor prospective cyber-security start-ups teams in the creation of the prototypes using free open source tools and APIs. OWASP will work together with the sponsors of this initiative by preparing the prospective cyber-security start-up(s) to seek funding by investor(s) at a later acceleration stage of the creation of the start-up.
The main goal of the pre-accelerator is to create opportunities for prospective entrepreneur-lead teams to transform ideas into open source community-validated concepts. The pursuit of innovative ideas can lead to the development of prototypes and (PoCs) Proof of Concept(s). Prospective start-ups can leverage no-cost OWASP resources that includes open source tools, documents/guides and training modules. The OWASP security incubator will offer to the selected entrepreneur-lead teams a structured place to work to experiment with the creation of working prototypes. The program, the workplace and the funding for the creation of the prototypes will be funded by OWASP corporate sponsorship(s). The initiative manuals and the prototypes developed by the start-ups will be released as open source to the application security community. The validation of the ideas with proof of concepts will help the start-up to participate to the next phase that is the cyber-security start-up acceleration program. The experience gained will help prospective start-ups to develop a Minimum Viable Product (MVP) and seek funding from prospective investors for further development.
This initiative will focus on the pre-incubator/pre-acceleration phase that is the preliminary phase that leads to the incubation of a possible start-up. This is the phase where talent is nurtured and ideas are developed, concepts are validated and prototypes are tested. The goal of the pre-acceleration phase is to create Proof of Concepts (PoCs) of prototypes of application security products. This phase leads to the next phase that is the acceleration phase. Entrepreneur-lead teams participating to the OWASP pre-acceleration program can possibly use these POCs/prototypes to develop Minimum Viable Product (MVPs) in the acceleration stage. These MVPs might be used to present to Angel investors/VCs to seek funding for the creation of their start-ups using these products.
Beneficiaries of this Initiative
The OWASP pre-incubator security start-up initiative helps the collaborative effort of academic institutions, government entities as well as corporate sponsors in the creation their cyber-security innovation campus/acceleration programs for cyber-security start-ups. The role of OWASP in this initiative is to provide the tools, the training modules, the documentation guides that help start-ups teams selected to participate into the pre-acceleation program to design, implement and test secure software. The ideal candidates for the participation to this initiative are teams of young graduates from universities with curriculum in cyber-security that are interested in experimenting with application security tools and create innovative ways to test and to develop secure software. By spearheading the creation of cyber-security pre-acceleator programs OWASP will also create the opportunity for these teams of young college graduates to experiment with software security concepts, develop working prototypes of secure software. The experience gained by participating to the program will help young graduates to seek a career in software security as well as to become self-employed in a new cyber-security start-up that can leverage OWASP tools and prototypes developed (e.g. by using them in the start-up software security consulting services). The experience gained will help start-ups to develop their business plans and MVPs. These business plans and MVPs could be presented to prospective investors for funding. By participating to this initiative, prospective start-ups will be better positioned to move up to the next phase and seek funds such as seed capital investment from prospective investors/VCs/Angels.
Initiative Participation Requirements
Participants to the OWASP pre-acceleration security start-up program are required to respect the open source licenses for the use of OWASP tools and for the prototypes/PoCs being developed. OWASP prototypes/PoCs should be released as open source and subjected to the Creative Commons 3.0 License (see OWASP licenses for details).
The role of OWASP in this Initiative
OWASP will provide funding for running of the initiative using OWASP corporate sponsorship. The funding will be used to run the initiative and to manage the logistical aspects of the program that includes providing office space for prospective start-up teams, conduct the "hackatons" to experiment with OWASP tools and resources and organize training sessions with application security mentors. The artefacts produced by the start-ups will also funded by the initiative: these will be released as open source at the end of the program. Part of the funding will be also allocated for documenting the process such as creation of guidelines for managing the pre-accelerator for security start-ups. The lessons learned by running the pre-accelerator program will be documented and distributed to the various sponsors of the initiative (e.g. academic institutions, corporate sponsors, government institutions) as well as released as free resource to be used by the application security community as a whole.
Since OWASP is a non for profit organisation is not involved in any commercialisation aspects of the tools and products/MVPs that will be developed in the future by the start-ups that participated to the pre-acceleration program. OWASP will be only involved in running the start-up incubator program and in the funding of OWASP open source projects created by the start-ups that participate to this initiative. OWASP will not invest into the start-ups and will not take any commercial interests in the development of products that the start-up will develop outside this program. This includes also products/MVPs that are used to seek funds such as seed capital for the start-up.
The OWASP organization, through the global foundation and his local chapters and the leaders of this initiative will ONLY run and manage the security start-up pre-accelerator program and fund the development of prototypes/PoCs that will be released as open source. OWASP will provide in-person mentoring in application security to the start-up teams participating to the program and mentoring to help teams to take their ideas into working prototypes/tools. OWASP will also collect data while running this program that will be useful for the documentation of the program manuals as lesson learnt. A the end of the pre-incubation phase, OWASP mentors will also teach the start-ups on how to create business plans and will advise in the technical aspects related to the proposal of new products and services.
Initiative Collaboration Effort
OWASP will be managing and run this initiative in collaboration with the sponsors. The likely sponsor(s) of this initiative are academic institutions that already have cyber-security curriculum and graduate programs in cyber-security as well as government organisations, corporate sponsors that would like to partner with academic institutions for the creation of cyber-security incubators for start-ups. Examples of these academic-government-private partnerships are the Cyber Labs incubator in Israel, the Cyber-security start-up accelerators in VA USA the Cyber [email protected] in MD USA and the CyberHive in CA-USA San Diego
Participation and Sponsorship Appeal
Corporate sponsors, academic institutions and government organisations interested in participating in the OWASP cyber-security pre-acceleration initiative can contact the initiative leaders (ref to the leaders info of this page) as well as OWASP foundation board directly. OWASP has different corporate sponsorship options available and all provide benefits. More information on OWASP corporate sponsorship can be found here
If you are interested to directly contribute to the Cyber Security Pre Startup Accelerator Initiative please fill in the following sponsorship form
Ron Moritz, CISSP Managing Director, MTC OWASP:, 1 October 2013, Why Investors are excited about cyber-security start-ups, again?
Trusted Software Alliance, May 26, 2014, Security start-ups with Michael Coates podcast
Financial Times: Investors flock to Cyber Security Startups
Note: this initiative proposal is released to OWASP for the purpose of seeking OWASP corporate funding only and should considered propriety of the authors and OWASP. This material cannot distributed and used for commercial purposes and without consent of the authors
Starting point/To date Neill Gernon and Marco Morana have worked up to this point on: -Startup community engagement> Meetings with London startup hubs including Level39 (Europes largest accelerator space), IDEALondon and universitys like Kings University where Marco spoke about the programme with thier security leaders. Also had meetings inside Google Campus London, Tech Hub and Central Working. -Programme planning> Designing the programme which has taken inspiration from lean prototyping workshops that Neill Gernon runs in London and Dublin startup clusters. Planning stages also included engaging with owasp staff including Samantha Groves, Kelly Santalucia and GK Southwick to conclude that this should be submitted and structured as an initiative. -Coordinating owasp meetings: Meetings with owasp chapter leaders including Tobias Gondrom, Justin Clarke and Marco Morana.
Thursday, 24th April - Meeting. Meeting (conference call) between Neill Gernon & Marco Morana concluded the following: -Speakers/Mentors> (a) Will will be looking to confirm speakers for the first kick off event (mid May). At this kick off event Neill Gernon & Marco Morana will talk on the programme format and the benifits to participants - this is an overview of the programme and a chance for all interested to come together and connect pre- initiative launch. Also to answer any questions attendees have before beginning. (b) Will be looking to confirm mentors for the pre-accelerator programme. These mentors will commit to specific calander dates to give team advisory, product validation, people mentorship and guidance through out the initiative. -Calander> Now we have a chosen starting point (kick off event by the 22nd May in London), we will be outlining the calander timeline of events, workshops and hackathon dates/times. *This initiative schedule will be updated to the wiki soon* -Sponsor details: Waiting to get confirmation from sponsors on how they wish to support initiative and owasp -How to continuously update the wiki for future updates and initiative news.
Kick off event date, sponsor details, speakers and mentor confirmation will be following this meeting.
Friday 9th May - Update on sponsor signup Created a quick "google form" along with a new presentation to get sponsors signed up to the initiative. Confirmation of dates and venue pending and subject to sponsor commitment due to venue expenses. Potential sponsors have been two options: 1. join owasp membership and a % goes toward the initiative 2. sponsor initiative direct Google form found [here> https://docs.google.com/forms/d/1hg3xqM3fHKDda0WshTEC7UTzK4nwcr1j6H79mHXSBoQ/viewform .]
Additional updates> 1. Wednesday meeting with Marco Moran confirmed to discuss initiative progress, venue, dates and sponsor confirmation. 2. Monday - Meeting with IDEALondon to discuss venue and initiative start dates 3. Monday - Meeting with a London university to propose initiative sponsorship
'Friday 23rd May - Update on sponsor/meeting progress' Coordinating venue, sponsor and dates has taking longer than expected but continuing to progress with target engagements. Continued email discussions with Neill Gernon and Marco Morana on the progress of initiative to this date.
Academic Sponsors/meeting. Securing dates to meet with UCL Meeting with researchers from the Research Institute in Science of Cybersecurity  for the week of the 2nd of June. Meeting will be Neill Gernon and Marco Morana presenting initiative to Professor M. Angela Sasse  and to Professor David Pym  as well as other additional professors from the Institute. The goal is to present the initiative as potential r&d research for UCL and as a career route for UCL students to create cyber security startups to drive cyber security innovation.
Progress with Kings University Marco Morana will also be engaging with contacts at Kings University London to arrange meeting to present the initiative for the university/students.
Securing dates to meet with Royal Holloway Currently coordinating meetings with Royal Holloway with Lorenzo Cavallaro (through Marco Morana) and also to Justin O'Brian (through Samantha Groves) to help us present the initiative to Royal Holloway as an initiative that their students can participate in.
Confirming a round table session at AppSec UK. We are currently confirming a roundtable session to be held at AppSec UK  in Cambridge to present the initiative to owasp members/sponsors - both academic/corporate. Coordinating this roundtable session with Samantha Groves, Adrian Winckles and Tobias Gondrom which will be held at the AppSec Project Summitt  and presented by Neill Gernon on June 23rd/24th at Angelia Ruskin University Cambridge.
Update: Tuesday 27th May
Meeting with Justin O'Brian (MBA Director & entrepreneurship at Royal Holloway) went well and he is recommending our initiative to professors leading the computer science, info security and IT institutes.
Update: Monday 2nd June
Meeting confirmed for 20th June to present initiative with UCL professors Angela Sasse, David Pym and team at the Research institute in the Science of Cyber Security at UCL.
Roundtable event confirmed. Neill Gernon will be presenting (joined by Marco Morana via Call) a roundtable talk at AppSecEU in Cambridge on the 24th June 2pm-6pm. Attendees will be able to join in person or attend online and all will be asked to register on our event page We aim to inform the appsec community of our initiative and gain advocates, help and initiative sponsors.
Update: Tuesday 10th June
Conference call meeting led by Samantha Groves on the project summit at Cambridge, this is where we host our roundtable event presenting the cyber startup initiative. Logistics and setup discussed including live web call for those unable to attend. All preparation ahead of the live event on the 24th June.
Update: Meeting at UCL Cyber Institute Meeting at UCL with their Cyber Security research institute which included> Angela Sasse, David Pym (Dialed in), George Danezis, Simon Parkin. Presented the initiative to UCL as a potential sponsor, they like it and would like to commit resources (mentors, facilitates and students/researchers) to the programme to create cyber startups and will inspect a separate department to see if it can be financially sponsored as they dont think there budget can be . Follow up meeting to conclude exactly how they will participate is to be confirmed. 2nd meeting is awaiting confirmation.
Update: AppSec EU in Cambridge. Initiative presentation Neill Gernon presented the initiative to a small gathering at the project summit in AppSec Cambridge. It was an engaging session that seemed to benefit both the initiative leaders (Neill & Marco) and also the attending crowd. We discussed the overall programme and where it leads to, where it can be adopted in various university/startup hubs like cambridge, London etc. We we please to hear that both Anglia Ruskin University and Royal Holloway University London who had both attended the session were interested in the programme. We will be continuing discussions with them on how it could be adopted inside a university to leverage students to build cyber startups. Follow on meetings will be confirmed and updated.
Additional AppSec news The response from attendees, facilitators, sponsors regarding the initiative was very positive and I myself (neill) was very surprised how many people wanted to get involved - whether at idea/prototype or early product stage.
New presentation We have updated the presentation with clear opening slides which should clearly articulate and present the initiatives focus and purpose to both and community and potential sponsors.
Follow up meetings Neill and Marco will be discussing the initiative and its next steps with partnering university's like, UCL,Kings University, Royal Holloway and Anglia Ruskin University. Meetings/conference calls will take place over the coming couple of weeks with the same target outcome - we are looking for sponsor support for this first stage of the initiative.
RE-Framing this Inititaive To make this more engaging, appealing and to initially create more buzz, we have re-framed this initiative as "cyber security startup week" - A week long series of events and workshops with an end of week hackathon. This will still bring together the startup, academic and corporate communitys focused on innovation within cyber security. Note: *The key elements essential for a pre-accelerator are still there, our goal is still to create teams that will develope POC/MVP open source prototypes*.
CONFIRMED: Date/Venue/Sponsor Sponsor - Pleased to announce that Sonatype have been confirmed as a sponsor for this program. Date - The week of the 26th of December has been confirmed to run this program. Dates: 26th/27th/28th/29th/30th of Dec 2015.ave Venues - Both IDEALondon and Google Campus have been confirmed to host this program. Workshops and events will take place at IDEALondon and the end of week hackathon takes place at Google Campus.
Next News 09/11/14 - Next news is due to be the launch of the website, confirmation of panel speakers and workshop hosts and promotion of the program to the academic, startup and corporate community's.
Milestones and Goals
The OWASP pre-incubator security start-up project includes the following milestones;
1) OWASP Security start-up pre-incubator process guide that document the process the WHAT that is a guide that can be followed by a non-profit entity such as OWASP, University, and Government Agency to run a security start-up pre-incubator program. We will document all steps of the process that can be followed to create pre seed funding security start-ups which can be replicated by following this program including the different stages that lead from opportunity to idea concept to creation of the open source prototype to the start-ups itself. The guide provide guidance on the goals of the various activities such as events, prototyping workshops and hackathons (e.g. goal is to experiment with OWASP open source tools, templates for the development of working prototypes) create and sign legal contract agreements, creation and validation of PoCs Proof of Concepts.
2) OWASP Security start-up pre-incubator process manual that teaches the HOW that is how to engage with the start-up community locally (start), organize events, workshops, hackathons, mentoring and prepare business plans for participation to security incubators start-ups (end);
3) OWASP Security start-up pre-incubator wiki site to manage the steps of the startup security pre accelerator process and document the proof of concept prototypes that can go on to be fully incubated start-ups; This wiki site will be created as OWASP pre-accelerator web site and will help it to be taken forward and used by OWASP chapters in different areas/countries.
4) Documented results of piloting with a start-up pre-incubator real case that includes using the process guide the manual the wiki site to run a real case of pre-incubator program by running it at one of the established start up campuses in London pending on availability and agreements.
5) OWASP open source working software prototype/PoCof an open source application security software/technology. This prototype/PoC is produced by following the￼￼￼￼￼￼several steps of the pre-accelerator security incubator program and is produced by the initiative participants as residents in the pre-accelerator working space and validated by the open source community. The scope of the prototype is to validate a proof of concept of a new idea that makes either web or mobile applications more secure. This prototype is released as open source to the community.
Signup to our mailing list, updates coming soon! Mail list> https://lists.owasp.org/mailman/listinfo/owasp_cyber_security_pre-accelerator_initiative