nofun wrote:
my question is how important is mod_security?
Impossible to guess.
Are you protecting Fort Knox or your kid's tee-ball league fan site?
Security is always a trade off between resource allocation, convenience, and security.
Personally, I keep detailed (and up to date) documentation on how my sites/systems are setup, current (and frequent) backups, and reasonable security (mostly via patched system/apps, simple light footprint monitoring, and iptables).
If my site goes down (from a hardware/software error or from nefarious activity) I can rebuild my site from scratch in about an hour.
For me, that's good enough.