The federal government’s new cybersecurity framework is “a good start,” but lawyers say the real test will be whether companies voluntarily adopt it, especially without compelling incentives like liability protection.

Experts also fear that plaintiffs lawyers could seize on the framework as a way to show that a hacked company failed to exercise the proper standard of care.