Which of the following would be MOST effective when justifying the cost of adding security controls to an existing web application?