Global Initiatives/Cyber Security Pre-accelerator Initiative

=Main=



{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 * valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |

OWASP Cyber Security Startup Initiative
This initiative seeks to catalyze opportunities for innovation in application security by promoting the use of open source security tools within the start-up community.

The main outcome of this OWASP initiative is the creation of a process that can be used by running a pre-accelerator (also referred as company accelerator, innovation campus) for application security start-ups by both private and public sectors. As part of this initiative a process for pre-incubation of security start-ups will be created and documented. In addition valuable data will be provided based upon the lesson learnt to run a pre-accelerator program funded by OWASP.

This initiative will focus on the pre-incubator/pre-acceleration phase that is the preliminary phase that leads to the incubation of a possible start-up. This is the phase where talent is nurtured and ideas are developed, tools are validated and tested. The goal of the pre-acceleration phase is to create Proof of Concepts (PoCs) of software security tool prototypes. This phase leads to the next phase that is the acceleration phase. Entrepreneur-lead teams participating to the OWASP pre-acceleration program can possibly use these POCs/prototypes to develop Minimum Viable Product (MVPs) in the acceleration stage. These MVPs might be used to present to Angel investors/VCs to seek funding for the creation of their start-ups using these products.

Initiative Goals
The main goal of the pre-incubator is to create opportunities for entrepreneur-lead teams to transform their ideas of software security tools/services into open source community-validated concepts such as PoCs/prototypes. The pursuit of innovative ideas and the development of these (PoCs) Proof of Concept(s) can leverage OWASP free resources such as open source tools/documents/trainings. The OWASP security incubator will offer to the selected entrepreneur-lead teams a structured place to work to transform their ideas into working prototypes. This will be done with the support of OWASP and OWASP corporate sponsorship(s). Any artifact developed by the start-ups participating into the program including the PoCs and prototypes being developed will be released as open source to the application security community.

Participation and Sponsorship Appeal
Interested corporate sponsors, academic institutions and government organisations can contact OWASP to become a sponsor of the Cyber Security Pre Startup Accelerator Initiative by filling in the following sponsorship form

Benefits for Sponsors of this Initiative
The OWASP pre-incubator security start-up initiative helps academic institutions, government entities as well as corporate sponsors to promote the creation of application security start-ups. OWASP will provide the tools, the training modules, the documentation guides and help teams to design, to implement and to test secure software. The likely targets of this initiative are young graduates from Universities with curriculum in cyber- security interested in experimenting with application security tools to create innovative ways to test and develop secure software. By spearheading the incubation of security start-ups OWASP will also create the opportunity for young college graduates to experience with software security and seek a career in software security as well as to become employed in self created security start-up that can leverage OWASP tools for their software security consulting services, application security training and secure software development services. The possible investment that the start-up might obtain from investors during the acceleration phase might be used to fund MVPs and the creation of consulting services. These MVPs can be developed based upon the experience gained participating to the OWASP pre-acceleration security program and the lessons learnt by developing the software/prototypes/PoWs within the pre-acceleration program. MVPs could be presented to prospective investors for funding.

For Non-Profit Use Limitations and Open Source Licensing Requirements
Participants to the OWASP pre-acceleration security start-up program have a legal requirement to respect the open source licenses for the use of OWASP tools in the prototypes/PoCs being developed such as the Creative Commons 3.0 License (see OWASP Copyrights for details). These licensing agreements legally bind the prospective start-up to respect these license agreements when signing into the program.

OWASP won’t be involved in the creation and commercialization aspects of the tools and MVPs that can be further be developed by the start-ups that participated to the pre-acceleration program. OWASP will be involved only in the mentoring and funding support of the activities of the pre-accelerator program and in the funding of OWASP open source projects. OWASP won't invest into the start-ups being created during the acceleration phase and won't participate in the development of any commercial products. OWASP won't participate in the start-up since OWASP is a non-profit organization. OWASP won't take any commercial interests in the development of MVPs or be part as organization in the business plan/proposal of the start-up.

The OWASP organization, through his local chapters and the leaders of this initiative will ONLY run and manage the security start-up pre-accelerator program. OWASP will provide in-person mentoring in application security to the teams participating to the program, mentoring to help teams to take their ideas into working prototypes/tools. OWASP will also collect data while running this program that will be useful for the documentation of the program manuals as lesson learnt.

A the end of the pre-incubation phase, OWASP mentors will also teach the start-ups on how to create business plans and will advise in the technical aspects related to the proposal of new products and services.


 * valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |

Presentation Materials
OWASP Start-up initiative proposal documentation

Atrovate proposal to OWASP presentation deck

Note: this initiative proposal is released to OWASP for the purpose of seeking OWASP corporate funding only and should considered propriety of the authors and OWASP and cannot distributed and used for commercial purposes and without consent of the authors

Initiative Leader(s)
Neill Gernon Marco Morana

Mailing List

 * Mailing List


 * }

= News and Events =

Starting point/To date Neill Gernon and Marco Morana have worked up to this point on: -Startup community engagement> Meetings with London startup hubs including Level39 (Europes largest accelerator space), IDEALondon and universitys like Kings University where Marco spoke about the programme with thier security leaders. Also had meetings inside Google Campus London, Tech Hub and Central Working. -Programme planning> Designing the programme which has taken inspiration from lean prototyping workshops that Neill Gernon runs in London and Dublin startup clusters. Planning stages also included engaging with owasp staff including Samantha Groves, Kelly Santalucia and GK Southwick to conclude that this should be submitted and structured as an initiative. -Coordinating owasp meetings: Meetings with owasp chapter leaders including Tobias Gondrom, Justin Clarke and Marco Morana.

Thursday, 24th April - Meeting. Meeting (conference call) between Neill Gernon & Marco Morana concluded the following: -Speakers/Mentors> (a) Will will be looking to confirm speakers for the first kick off event (mid May). At this kick off event Neill Gernon & Marco Morana will talk on the programme format and the benifits to participants - this is an overview of the programme and a chance for all interested to come together and connect pre- initiative launch. Also to answer any questions attendees have before beginning. (b) Will be looking to confirm mentors for the pre-accelerator programme. These mentors will commit to specific calander dates to give team advisory, product validation, people mentorship and guidance through out the initiative. -Calander> Now we have a chosen starting point (kick off event by the 22nd May in London), we will be outlining the calander timeline of events, workshops and hackathon dates/times. *This initiative schedule will be updated to the wiki soon* -Sponsor details: Waiting to get confirmation from sponsors on how they wish to support initiative and owasp -How to continuously update the wiki for future updates and initiative news.

Kick off event date, sponsor details, speakers and mentor confirmation will be following this meeting.

Friday 9th May - Update on sponsor signup Created a quick "google form" along with a new presentation to get sponsors signed up to the initiative. Confirmation of dates and venue pending and subject to sponsor commitment due to venue expenses. Potential sponsors have been two options: 1. join owasp membership and a % goes toward the initiative 2. sponsor initiative direct Google form found [here> https://docs.google.com/forms/d/1hg3xqM3fHKDda0WshTEC7UTzK4nwcr1j6H79mHXSBoQ/viewform .]

Additional updates> 1. Wednesday meeting with Marco Moran confirmed to discuss initiative progress, venue, dates and sponsor confirmation. 2. Monday - Meeting with IDEALondon to discuss venue and initiative start dates 3. Monday - Meeting with a London university to propose initiative sponsorship

= Milestones =

Milestones and Goals

The OWASP pre-incubator security start-up project includes the following milestones;

1) OWASP Security start-up pre-incubator process guide that document the process the WHAT that is a guide that can be followed by a non-profit entity such as OWASP, University, and Government Agency to run a security start-up pre-incubator program. We will document all steps of the process that can be followed to create pre seed funding security start-ups which can be replicated by following this program including the different stages that lead from opportunity to idea concept to creation of the open source prototype to the start-ups itself. The guide provide guidance on the goals of the various activities such as events, prototyping workshops and hackathons (e.g. goal is to experiment with OWASP open source tools, templates for the development of working prototypes) create and sign legal contract agreements, creation and validation of PoCs Proof of Concepts.

2) OWASP Security start-up pre-incubator process manual that teaches the HOW that is how to engage with the start-up community locally (start), organize events, workshops, hackathons, mentoring and prepare business plans for participation to security incubators start-ups (end);

3) OWASP Security start-up pre-incubator wiki site to manage the steps of the startup security pre accelerator process and document the proof of concept prototypes that can go on to be fully incubated start-ups; This wiki site will be created as OWASP pre-accelerator web site and will help it to be taken forward and used by OWASP chapters in different areas/countries.

4) Documented results of piloting with a start-up pre-incubator real case that includes using the process guide the manual the wiki site to run a real case of pre-incubator program by running it at one of the established start up campuses in London pending on availability and agreements.

5) OWASP open source working software prototype/PoCof an open source application security software/technology. This prototype/PoC is produced by following the￼￼￼￼￼￼several steps of the pre-accelerator security incubator program and is produced by the initiative participants as residents in the pre-accelerator working space and validated by the open source community. The scope of the prototype is to validate a proof of concept of a new idea that makes either web or mobile applications more secure. This prototype is released as open source to the community.

=How to Get involved=

Signup to our mailing list, updates coming soon! Mail list> https://lists.owasp.org/mailman/listinfo/owasp_cyber_security_pre-accelerator_initiative