To put it another way - there is no security risk that fail2ban helps with that can't be resolved in another, better, more robust and less risky way.
Particularly on my small server, fail2ban is the difference between "usable" and "on the edge of falling over".
Everyone makes mistakes. That’s the whole point of the Swiss cheese model and of layers of security in general.
I look at the imap login attempts on my server sometimes. The passwords they try are usually pathetic. Nothing close to the 15+ character actual passwords we have in use.
I disagree with this, 404 queries still use resources and someone trying URLs in a matter of seconds should be blocked nonetheless.
Only if you can get business/users/management buy-in or approval for implementing those ways and changing workflows.