It's budget season. Somewhere in your organization, someone is building a 2027 deck right now, and there's a decent chance it quotes a number that expired eight weeks ago.
That's this week's lead. Below it: three decisions that land on the same budget, and one date that passed while most teams weren't looking.
THE DECODE
Breach costs just reversed
Last year's story was comforting. IBM's Cost of a Data Breach report showed the global average falling 9% to $4.44 million, the first decline in five years. A lot of decks quoted it.
The 2026 edition, published July 29, takes it back.
Global average: $4.99 million, up 12%, a new record
US average: $11.5 million, more than twice the global figure (it was $10.22 million)
Time to identify and contain: 247 days, up from last year's nine-year low of 241
One in four malicious breaches was AI-driven, up 56%, and those add about $1 million to the bill
Why it matters: the headline number isn't the useful part. The spread is. Breaches contained in under 200 days averaged $4.32 million. Over 200 days, $5.65 million. That's a $1.33 million gap you can set next to a detection-and-response line item, which is a far easier conversation with a CFO than "security is important."
What to do: replace the old figures anywhere they're quoted, and lead your security ask with the containment-speed gap instead of the average. Usual caveat: this is a survey-derived average, not an actuarial table, so treat it as a planning benchmark. Our benchmarks brief walks through turning these numbers into defensible line items, and it now carries the 2026 figures up top.
Three decisions on the same budget
Kubernetes: you're probably paying for eight cores to use one
Average cluster CPU utilization sits near 10-13% of what's been requested. Teams with no cost discipline waste an estimated 32-40% of their cloud bill; mature teams, 15-20%. The target is 40-60% of requested CPU actually used, measured over a week. While you're in there, check whether several autoscalers are quietly fighting each other in the same cluster. That's the newest failure mode, and it's more common than it should be.
Bedrock vs. Vertex AI vs. Azure AI Foundry: stop comparing features
The three have copied each other's homework. What's left is harder to copy: which frontier models each cloud is allowed to serve you, and which compliance authorizations it has actually cleared. Need OpenAI's frontier models under an enterprise agreement? That's Azure. Need FedRAMP High or DoD impact levels? Check authorization status before anything else, because it cut the field when we ran the comparison in July. Want the deepest catalog and compliance isn't a gate? Vertex. One billing trap to model first: Gemini's reasoning models bill hidden "thinking" tokens as output, so estimate from measured usage, not response length.
Retiring the VPN: plan for 80%, not 100%
About 65% of enterprises say they plan to replace their VPN with zero trust network access. The part every vendor leaves out is the 12 to 24 months when both run side by side, you pay for both, and the help desk takes tickets for both. Migrate app by app, not user by user. Decommission at roughly 80% coverage, because some legacy apps will never broker cleanly. And model the cost over three years, not one.
One date you may have missed
August 2, 2026. That's when the European Commission's enforcement powers over general-purpose AI obligations began. Penalties under the EU AI Act run up to €15 million or 3% of global turnover for most violations. Like GDPR, it's extraterritorial: a US SaaS product with EU customers is in scope even with zero EU infrastructure. Most of the Annex III high-risk obligations were pushed to December 2027, which is a reprieve, not a cancellation.
The mistake I keep seeing is three separate compliance programs for the EU AI Act, ISO 42001 and NIST AI RMF, each with its own spreadsheet and steering committee. Run one governance stack anchored on a single AI system register, and let each framework pull the evidence it needs. Here's the sequencing.
One ask: hit reply and tell me which of these is in your 2027 budget fight. I read every reply, and it decides what I decode next.
See you next week,
- David

