Independent reference. Not affiliated with any vendor on this site.
Business case

WAF ROI: business case framework

The WAF business case is straightforward when it is grounded in a named dataset. Apply ROSI - Return on Security Investment - using the IBM 2026 Cost of a Data Breach Report's global average and the WAF's reduction in web-application-attack incident frequency. This page walks the framework.

Last verified August 2026

$4.99M
Global avg breach cost (IBM 2026)
$6.64M
Healthcare avg breach (IBM 2026)
$5.29M
Phishing-vector avg (IBM 2026)
$11.5M
US avg breach cost (IBM 2026)

The ROSI formula

Return on Security Investment is the standard framework for security spend that is preventative rather than revenue-generating. Conceptually:

ROSI
ROSI = ((ALE x Mitigation %) - Cost of control) / Cost of control

ALE = Annualised Loss Expectancy (probability of a breach x cost of a breach).
Mitigation % = the fraction of that ALE the control removes.
Cost of control = the all-in WAF cost (subscription + implementation + tuning labour).

Anchor 1: cost of a breach

Use a named dataset. IBM's 2026 Cost of a Data Breach Report (the canonical industry reference, published annually since 2005) puts global average breach cost at $4.99 million, a record high and up 12% from $4.44 million the year prior. Healthcare-sector breaches average $6.64 million, the costliest sector for the thirteenth consecutive year. Phishing (including its voice and SMS variants) was the most common initial attack vector and averaged $5.29 million, the highest of any vector. In the United States the average is $11.5 million, more than double the global figure. These are the figures we cite; we do not invent ranges.

The global average cost of a data breach rose to a record USD 4.99 million in 2026, a 12% increase over the prior year.
IBM Cost of a Data Breach Report 2026, in collaboration with Ponemon Institute

Anchor 2: WAF impact on web-application-attack frequency

WAFs measurably reduce the frequency of successful web-application attacks. The honest position: we do not publish a fixed mitigation percentage because (a) it varies sharply by attack vector and rule tuning maturity, and (b) anyone claiming a clean “X percent of breaches prevented” figure is over-claiming. Use a band you can defend in front of a CFO; we recommend 10-30% reduction in web-application-attack-vector ALE for a properly tuned WAF, with the wider band for less-mature tuning.

Anchor 3: cost of control

Use the all-in number from the hidden costs page: subscription plus implementation plus year-one tuning labour. For a mid-market property using AWS WAF with Bot Control, this is roughly the $185/mo subscription + ~$15-50K year-one implementation + ~0.2 FTE tuning labour. For an enterprise property on Imperva or Akamai, it is a quote-only annual contract plus professional services plus internal labour.

Worked example (illustrative, not a real company)

Mid-market SaaS, illustrative ROSI
  1. 1.Annualised Loss Expectancy (ALE)$499,000
  2. 2. (10% probability of a breach in any year)
  3. 3. (x $4.99M IBM global average)
  4. 4.Mitigation fraction attributable to WAF (mid)20%
  5. 5.Loss avoided per year$99,800
  6. 6.All-in WAF cost per year (AWS WAF + Bot Control + tuning)$25,000
  7. 7.Net benefit per year$74,800
ROSI (illustrative)~299%
(illustrative example, not a real company). Inputs - probability, mitigation fraction, all-in cost - are scenario-dependent. The point is the framework, not the percentage.
Honesty rule
ROSI calculations are model-driven, not measured. They are useful for framing the spend, not for justifying a number to the dollar. Anyone presenting a ROSI calculation should be ready to talk about which inputs they chose and why, and what happens to the answer when the probability or mitigation assumption moves by half.

Related reading

See the PCI DSS WAF page for the compliance-mandated WAF case (where ROSI is irrelevant; the WAF is mandatory), and the sister sites below for adjacent security-stack budget context.

Last verified June 2026