<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.EmailStyle23
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle24
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
 /* List Definitions */
 @list l0
        {mso-list-id:450561522;
        mso-list-template-ids:1943965626;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level3
        {mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level4
        {mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level5
        {mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level6
        {mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level7
        {mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level8
        {mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level9
        {mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1
        {mso-list-id:1651056073;
        mso-list-type:hybrid;
        mso-list-template-ids:-651121980 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level2
        {mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level3
        {mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level4
        {mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level5
        {mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level6
        {mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level7
        {mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level8
        {mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level9
        {mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l2
        {mso-list-id:1942299056;
        mso-list-template-ids:1004175610;}
@list l2:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="3074" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=EN-US link=blue vlink=purple>

<div class=WordSection1>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Had an idea for how to better market OWASP but first a few
mini-stories.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Ever heard of James Governor and Redmonk? He is a noted industry
analyst who brought on the concept of open source analysis. His first open
source research was entitled: Compliance Oriented Architectures. I had a
twitter dialog with him over the weekend regarding future open source
publications in the security space.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Several months I ago, I had a conversation with another noted
industry analyst who covers the information security space who made me a lot
smarter regarding analyst pay-for-play and got enlightened as to why I had it
100% wrong. The thesis is that it doesn&#8217;t benefit an analyst firm to say
anything nice about a company, but rather something negative but otherwise
correctable. Since the best way to influence an analyst is to pay them for
their time, the value proposition of being good isn&#8217;t always good.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I remember attending the OWASP 2008 NYC conference where I got
into a conversation with Rohyt Belani and how he discussed it was futile to
expect outsourcing firms to write secure software without paying extra for it.
Of course, I took it as a personal challenge to prove him wrong. I had a very,
very small success working with Cognizant in this regard.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I currently share frequent thoughts on maturity as part of the
SAMM list based on my observations of my past and current employer.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>So, combining these thoughts, I believe we could do well to
participate/champion/contribute to the creation of an open source research
report that measures the ability of outsourcing firms to deliver software. If
we can inject into the outsourcing conversation something other than rate
arbitrage and CMMI, we may be able to move the industry. It is OWASP that is
best positioned to provide analyst guidance in this regard and to acknowledge
that with the exception of governments, the vast majority of software
development is shifting towards countries with less overall software
development experience.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I would use my internet socialization skills to rally up a few
analysts to write and publish research in this space in a 100% open manner.
Thoughts?<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div>

<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'>James McGovern<br>
</span></b><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'>Insurance SBU <o:p></o:p></span></p>

<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'>Virtusa </span></b><b><span style='font-size:10.0pt;font-family:
"Calibri","sans-serif";color:#7F7F7F'>Corporation</span></b><b><span
style='font-size:10.0pt;font-family:"Calibri","sans-serif";color:gray'><o:p></o:p></span></b></p>

<p class=MsoNormal><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'>100 Northfield Drive, Suite 305 | Windsor, CT | 06095<o:p></o:p></span></p>

<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:#7F7F7F'>Phone:&nbsp; </span></b><span style='font-size:10.0pt;
font-family:"Calibri","sans-serif";color:gray'>860 688 9900</span><span
style='font-size:10.0pt;font-family:"Calibri","sans-serif";color:#7F7F7F'> <b>Ext:&nbsp;
</b></span><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'>1037</span><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:#7F7F7F'> | <b>Facsimile:&nbsp; </b></span><span style='font-size:10.0pt;
font-family:"Calibri","sans-serif";color:gray'>860 688 2890</span><span
style='font-size:10.0pt;font-family:"Calibri","sans-serif";color:#7F7F7F'>
&nbsp;</span><span style='font-size:10.0pt;font-family:"Calibri","sans-serif";
color:gray'><o:p></o:p></span></p>

<p class=MsoNormal><a href="http://www.virtusa.com/"><span style='font-size:
10.0pt;font-family:"Calibri","sans-serif";color:#7F7F7F;text-decoration:none'><img
border=0 width=81 height=21 id="Picture_x0020_52"
src="cid:image001.jpg@01CB6EA1.3C9E04D0"
alt="cid:image011.jpg@01CB08A4.F95CFA30"></span></a><span style='font-size:
10.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><a
href="http://www.virtusa.com/blog/"><span style='font-size:11.0pt;font-family:
"Calibri","sans-serif";color:#1F497D;text-decoration:none'><img border=0
width=22 height=22 id="Picture_x0020_53"
src="cid:image002.gif@01CB6EA1.3C9E04D0"
alt="cid:image012.gif@01CB08A4.F95CFA30"></span></a><span style='font-size:
11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'> </span><a
href="https://twitter.com/VirtusaCorp" target="_blank"><span style='text-decoration:
none'><img border=0 width=22 height=22 id="Picture_x0020_54"
src="cid:image003.gif@01CB6EA1.3C9E04D0"
alt="cid:image004.gif@01CB08A4.F95CFA30"></span></a><span style='font-size:
11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><a
href="http://www.linkedin.com/companies/virtusa" target="_blank"><span
style='text-decoration:none'><img border=0 width=22 height=22
id="Picture_x0020_55" src="cid:image004.gif@01CB6EA1.3C9E04D0"
alt="cid:image005.gif@01CB08A4.F95CFA30"></span></a><span style='font-size:
11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><a
href="http://www.facebook.com/VirtusaCorp" target="_blank"><span
style='text-decoration:none'><img border=0 width=22 height=22
id="Picture_x0020_56" src="cid:image005.gif@01CB6EA1.3C9E04D0"
alt="cid:image006.gif@01CB08A4.F95CFA30"></span></a><span style='font-size:
11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p>

</div>

</div>

</body>

</html>

<table><tr><td bgcolor=#ffffff><font color=#000000><pre>Virtusa was recently ranked and featured in 2010 Global Services 100, IAOP's 2010 Global Outsourcing 100 sub-list, 2009 Deloitte Technology Fast 500 and 2009 Dataquest-IDC Best Employers Survey among others.

---------------------------------------------------------------------------------------------

This message, including any attachments, contains confidential information intended for a specific individual and purpose, and is intended for the addressee only. Any unauthorized disclosure, use, dissemination, copying, or distribution of this message or any of its attachments or the information contained in this e-mail, or the taking of any action based on it, is strictly prohibited. If you are not the intended recipient, please notify the sender immediately by return e-mail and delete this message.

---------------------------------------------------------------------------------------------</pre></font></td></tr></table>