

About us
The OWASP Hamburg Stammtisch meetings are FREE and OPEN to anyone interested in learning more about application security.
We encourage individuals to provide knowledge transfer via presentations, sometimes hands-on training, of projects and research topics. People come here who care as a hobby or in their job about IT security: developers, managers, pen testers and everybody else who's interested. The atmosphere is open and relaxed. Who intends to come to sell products or services: Please move on, this is not the right place. OWASP is about education and sharing (mostly) technical information.
We try to conduct approximately bimonthly meetings. When depends on the availability of speakers and rooms. So if you have an interesting topic to talk about, please let us know!
Most of the time talks are in German, but sometimes they are in English.
Openness: The participation is free and open to every person on this planet. A membership is not required.
Upcoming events
2
![Sicherheit aus CISO-Perspektive [EN/DE]](https://secure.meetupstatic.com/photos/event/e/7/5/9/highres_471599225.jpeg)
Sicherheit aus CISO-Perspektive [EN/DE]
NewWork SE, Baumwall 6, Hamburg, DEMoin Hamburg et al.,
in September we have another meeting. Presentation language is TDB. Please answer the language question when you RSVP.
This presentation builds on the CISO roundtable we hosted last year. *) Since many people were interested in the topic but few really understood what a CISO or ISB actually does, we came up with the idea to explore this in more detail.
I’m especially pleased having Tim Sattler for this presentation! He played a key role in shaping the CISO roundtable.
Not only does Tim have decades of experience as a CISO, but he also served on the German ISACA Board for many years before being appointed to the ISACA Foundation’s Global Board of Directors a year ago.*) To be continued
Thanks again for New Work for hosting this!
Eckdaten:
- Lokation: New Work SE, Baumwall **6** (danke dafür und danke, Gerrit)
- Presentation Language: depending on RSVP
- Sprecher: Dr. Tim Sattler
- Title: The Evolution of the CISO Role
- Date: 15.9.2026
- Start: 18:30, doors open: 18:00
Afterwards we plan to go to the Portuguese Quarter to continue the conversation over some food and drinks.
# Abstract
Ten years ago the CISO was often a technical, reactive role inside IT; today it operates at board level, and increasingly shapes decisions at the top. Tim traces the shift from technical security lead to strategic trusted advisor, the forces behind it, and where the role is heading by 2030 – with plenty of room for discussion.
# Sonstiges
Falls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!
# Generelles zum OWASP-Stammtisch
Bei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder #Infosec allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um Lernen, den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne #OWASP-Mitgliedschaft.
Schönen Gruß, Dirk
https://www.meetup.com/owasp-hamburg-stammtisch/
https://infosec.exchange/@owasp_hamburg
https://www.linkedin.com/company/owasp-meeting-hamburg
https://owasp.org/www-chapter-germany/stammtische/hamburg/48 attendees
Blocker: Why Secure Software Begins Before the First Line of Code
Kauai, Kauai, Hawaii, USA, Kauai County, HI, USMoin Hamburg et al.,
we're thrilled to have Jim Manico from the US @ our OWASP meeting in Hamburg! Jim is since a long time engaged in software security. (IIRC I met him first 13 years ago @ OWASP's Global AppSec conference)
Since then he became one of the most influential volunteers in the OWASP community, who founded and maintains OWASP's Cheat Sheets. He also led the Application Security Verification Program which have shaped how developers everywhere write secure code. He is a Java Champion and a JavaOne "rockstar" speaker, and is a regular keynote/trainer at AppSec conferences globally. Being on the cutting edge he co-led the new OWASP AISVS , a community-driven catalogue of testable security requirements for AI-enabled systems.
Eckdaten:
- Location: TBA (will be updated when room is confirmed. Software problem 🤷♂️: can not set the map to Null)
- Title:* ORDNUNG! PRÄZISION! SPEZIFIKATION! Why Secure Software Begins Before the First Line of Code
- Speaker: Jim Manico
- Date: 12.10.2026
- Start: ~18:00
Abstract:
Developers spend enormous effort fixing defects that should never have existed. The root cause is often not poor coding. It is poor requirements. This presentation introduces Spec-Driven Development, a disciplined engineering approach where precise, security-aware specifications become the foundation for implementation, testing, code review, and AI-assisted development. You'll learn practical techniques for writing requirements that are measurable, verifiable, and resistant to ambiguity, allowing both humans and AI to consistently produce secure software.Because secure code starts with secure specifications and engineering discipline.
# Misc
If you'd like to give a talk yourself, or if you can generally provide an ad-free venue for talks, please feel free to get in touch!
# General remarks to our OWASP Meeting
Our meetings are open to everyone, focus on software and its security on the Internet and/or #Infosec in general. This is where people who deal with IT security, professionally or personally, come together: developers, managers, penetration testers, and anyone interested in (application) security. The atmosphere is open and relaxed. We’re all about sharing experiences, discussing technical topics, and last but not least: networking. If you’re looking to sell or advertise products or services: sorry, this isn’t the place for you. You’re more than welcome to let your colleagues or friends know about our meetups. All meetups are free, open to everyone, and free of charge, with or without an OWASP membership.
Schönen Gruß, Dirk
https://www.meetup.com/owasp-hamburg-stammtisch/
https://infosec.exchange/@owasp_hamburg
https://www.linkedin.com/company/owasp-meeting-hamburg
https://owasp.org/www-chapter-germany/stammtische/hamburg/25 attendees
Past events
62