A card skimmer costs what it steals. Your visitors' browsers can already see it happen — a script running that you never put there, card details going somewhere you never approved — and every one of them will tell you the moment it does, or refuse to let it happen at all, if you ask them to. Most sites never ask, so the browser notices and says nothing.
Without Report URI
57,534 cards exposed. Nobody is told, so it keeps taking cards until something else gives it away.
Monitoring
1,370 cards exposed, $842,466 saved. You are alerted the first time it runs, and you take it down.
Monitoring and prevention
Nothing taken. The browser refuses it outright. $860,959 saved
Three years of Report URI
Break-even
Enforcement prevents; reporting is how you get there and what catches the rest. A policy that names the origins your scripts load from and the destinations your page may talk to blocks an injected skimmer outright — it never executes, or its exfiltration never leaves the browser. That is prevention, and unlike an alert it does not depend on anyone being awake.
What enforcement cannot stop is an attacker who both runs inside an origin your policy already allows and sends data to a destination it already allows — a compromised script you were loading on purpose. That residual is why the enforced row above is not zero, and why the reports still matter once you are enforcing.
Reporting is also the route to enforcement. Turning on a policy you have not measured breaks the site; report-only mode tells you what would have been blocked so you can enforce without taking the checkout down. That is the sequence this model is really pricing.
It also does not tell you your breach probability. Every vendor model that asserts one picks a number that suits the vendor. This one gives you a break-even instead: the likelihood at which the monitoring has paid for itself. Whether your own risk is above or below that line is your judgement, not ours.
The figures left out all point the same way. Forensic investigation, card-brand assessments, chargebacks, notification, litigation and customer loss are real and none of them are counted here. IBM put the 2026 global average cost of a data breach at $4.99 million, and a drive-by browser compromise at the same figure.
Report URI collects the violation reports your visitors' browsers are generating right now, and tells you the moment something new appears on a payment page.