Microsoft announces Secured-core PCs, which will come from many vendors like Dell and adhere to security best practices for better firmware attack protection
Microsoft today announced a new initiative to combat threats specifically targeted at the firmware level and data stored in memory: Secured-core PCs.
Context & Ripple Effects
Secured-core PCs cap a multi-year arc of Microsoft pushing security deeper into the PC stack. It began with Project Evo in 2016, when Microsoft and Intel agreed to bring advanced security features to new machines, and gained urgency after Dell and other vendors began shipping systems that could disable Intel's Management Engine following critical vulnerability disclosures — proof that firmware was an attack surface vendors had to let customers switch off.
The initiative matters because it makes firmware hardening a certification requirement across many OEMs rather than one vendor's feature, and because it set up the next step: a year later Microsoft announced Pluton with AMD, Intel, and Qualcomm, moving the same protection into the CPU itself.
First-order effects
- Vendors like Dell must adhere to Microsoft's security best practices to ship Secured-core machines, making firmware configuration a compliance checklist item rather than an optional differentiator.
- Enterprise buyers gain a recognizable label for machines hardened against firmware and memory-resident attacks, shifting purchase criteria toward certified configurations.
Second-order effects
- Chipmakers are pulled into the program on Microsoft's terms — the follow-on Pluton project with AMD, Intel, and Qualcomm shows silicon vendors building dedicated security components to meet the standard.
- Security software vendors face pressure at the edges of the stack: five years later Microsoft moved to help CrowdStrike, Broadcom, Sophos, and Trend Micro operate outside the Windows kernel, reducing the privileged access such tools traditionally required.
Third-order effects
- If the pattern holds, Microsoft becomes the de facto spec-writer for PC trust — defining what counts as secure from firmware through silicon — while third-party security software is progressively pushed out of the most privileged layers of Windows.
- Firmware attacks becoming a named threat category pushes the industry toward security anchored in hardware roots of trust, narrowing the space where off-spec or unpatched firmware can ship.
The trend: PC security is migrating down the stack from software add-ons to firmware and silicon, with Microsoft setting the specification that OEMs and chipmakers must follow.