Most Australian IT buyers put significant energy into comparing processors, RAM configurations, and display specs before signing a laptop fleet order. Fewer spend meaningful time on the firmware layer underneath. That's a mistake. The BIOS and firmware stack on a business laptop shapes everything from how quickly you can respond to a supply chain vulnerability to whether remote management works reliably in the field.
What BIOS and UEFI actually control
The terms BIOS and UEFI are often used interchangeably, but UEFI (Unified Extensible Firmware Interface) replaced the legacy BIOS on virtually every device manufactured after 2012. What it does hasn't changed in principle: it initialises hardware, verifies the boot chain, and hands control to the operating system. What has changed is the attack surface and the management capability it exposes.
Modern UEFI firmware controls Secure Boot enforcement, Thunderbolt security levels, virtualisation extensions (Intel VT-x, AMD-V), pre-boot authentication, and USB access restrictions. Each of those settings matters for a business deployment. Secure Boot prevents unsigned bootloaders from executing. Disabling it, as some IT teams do to accommodate Linux dual-boot or older imaging tools, removes a critical layer of protection that Microsoft's Windows 11 assumes is present.
Thunderbolt is a particular concern. The default Thunderbolt security level on many laptops shipped direct from distributors is set to "No Security," which allows DMA (direct memory access) attacks via any connected device. Setting it to "User" or "Secure Connect" level at deployment is a five-minute task. Leaving it at the default is the kind of gap a forensic investigation will find later. This connects directly to the broader problem covered in our piece on cyber security logging gaps and what forensic investigations actually find: silent configuration exposures that only surface after an incident.
Fleet management and the BIOS password problem
For most fleet deployments, the bigger operational headache isn't security settings per se. It's BIOS password management. Vendors including HP, Dell, and Lenovo ship enterprise-class laptops with support for BIOS password management via their fleet tools: HP Sure Admin, Dell Command | Configure, Lenovo Think Shield. These tools let IT teams set, rotate, and audit supervisor passwords without touching each device physically. Most organisations don't use them.
The typical pattern: an IT team images a batch of laptops, sets a standard supervisor password manually across the batch, and documents it in a shared spreadsheet. That spreadsheet doesn't rotate. When a staff member leaves, the password stays the same. When the fleet grows to 400 units, physical access to change it is no longer practical. The result is a fleet of devices where anyone who knows a years-old password can disable Secure Boot, clear the TPM, or disable the hard drive encryption requirement at boot.
Enterprise BIOS management tools solve this, but they require an upfront integration step with your MDM or endpoint management platform. If you're evaluating fleet management tools, the firmware management capability is worth checking before you commit. This is the kind of detail that also appears in discussions about business laptop security features and what actually matters in Australian enterprise environments.
Firmware update cadence: slower than you think
Operating system patches ship weekly. Firmware updates ship far less often, and IT teams apply them even less often than that. A 2024 Eclypsium study found that the average enterprise device ran firmware that was 18 months behind the vendor's current release. That gap matters because firmware vulnerabilities are real and actively exploited. Intel Management Engine, AMD Platform Security Processor, and NIC firmware have all been targets in documented attacks.
The patch management discipline most Australian organisations apply to Windows doesn't extend to firmware. There are two reasons. First, firmware updates historically required physical access or a manual reboot with update media. Second, IT teams worry about failed updates bricking devices. Both concerns are legitimate, but vendor tooling has improved substantially. HP's BIOS Update tool, Dell's Command Update, and Lenovo's System Update all support silent firmware deployment via SCCM or Intune. The risk of a failed update on a modern enterprise laptop is low when the vendor's recommended deployment method is followed.
The practical recommendation: include firmware update testing in your standard patch cycle. Pick a representative subset of device models, test new firmware releases in a staging ring, and deploy to the full fleet after a two-week observation period. It's no different from how OS patch rings work.
Secure Boot, TPM 2.0, and Windows 11 compliance
Windows 11 requires both Secure Boot and TPM 2.0 to be enabled. Most fleet laptops ship with both available, but not always both active. TPM 2.0 is sometimes present as a chip but disabled in firmware, which means Windows 11 installation fails, and the default Windows upgrade diagnostic gives an unhelpful error message pointing at the CPU compatibility table instead of the firmware setting.
Before you image a new batch, verify three things in the UEFI settings. First, TPM 2.0 is enabled and set to active rather than hidden. Second, Secure Boot is on and set to Standard (not Custom, which bypasses signature enforcement). Third, the boot mode is UEFI only, not UEFI with Legacy BIOS Compatibility Support Module (CSM) enabled. CSM enabled and Secure Boot active is a contradictory state that some firmware implementations allow but that reduces the security guarantees Secure Boot is supposed to provide.
What to check when specifying a fleet
Before finalising a fleet purchase, ask vendors three specific questions beyond the standard datasheet. Does the device support remote BIOS configuration via the vendor's fleet management tool, and does that tool integrate with your MDM? What is the vendor's committed firmware support window, and does it cover the full device lifecycle you're planning (three years is common; five years is increasingly the standard for enterprise deployments)? Does the device include a hardware-isolated security chip for firmware integrity measurement, such as HP Sure Start, Dell SafeBIOS, or Lenovo ThinkShield Firmware Resiliency?
That last point matters more than most procurement guides acknowledge. HP's Sure Start technology, for example, stores a golden copy of the BIOS in a separate read-only memory region and can restore a corrupted or tampered firmware image automatically at boot without IT intervention. Dell and Lenovo offer equivalent capabilities under different branding. These features don't appear in most comparison tables, but they represent a genuine difference in resilience between enterprise-class and commercial-grade devices.
Firmware is not glamorous. It doesn't show up in benchmark comparisons or marketing one-pagers. But it's the first code that runs when a device powers on, and it's the layer attackers target when they want persistence that survives an OS reinstall. Getting the settings right at deployment, managing passwords systematically, and treating firmware updates as part of your patch programme are unglamorous tasks. They're also the ones most likely to save you from an expensive incident later.

