OWASP may be a shambolic volunteer project, but it's interesting that, in many areas, it's still the best thing available for the last 18 years...
Security vulnerabilities in Web applications have been a major cause of big losses at a large number of these companies.
Despite that, the most authoritative, best funded, Web application security group is OWASP. A group with a full-time staff of < 10, and an annual budget of well under $10M.
It's interesting to me anyway, that the wider IT industry doesn't see value in trying to establish security practices and tooling which could be used to reduce some of these losses. Even if they don't like OWASP itself for any reason, that they don't look to establish something else to achieve the same goal.