A forensics investigation is usually required by insurers. It's not an arbitrary amount of money, it's just an amount you're not happy with. I understand why you feel that way, but it's not the way the law works.
Services can negotiate the terms of their insurance contract or even choose whether or not to carry insurance. They agree to these terms and know the implications, and again, if the need for the investigation is legitimate then they should be conducting it regardless of how the vulnerability is uncovered.