Just out of curiosity, will you be able to allow specific IP's from these banned chunks if/when the need arises?
I actually check which registry owns the IP space in question before doing bans. If it belongs to a RIR that isn't ARIN, generally speaking, the entire large block gets banned. If it belongs to ARIN or a portion of RIPE that isn't a pit of scum and villainy, I'll do smaller ban blocks.
If the host machine in question is on DHCP and part of a botnet, I have to ban the whole subnet...if the user in question has his own static IP, I can work around it, but if he's on DHCP as well as the botnet...not a whole hell of a lot I can do there