There is much discussion about Australia’s mandatory data breach notification legislation, to take effect in early 2018. Which organisations are in scope and how prepared are they? What takeaways are there for Australia learn from other jurisdictions, including the United States? What does the new regime mean for those who are not in scope? In future, will business competitive advantage be dependent upon trust in the cyber domain?