Revolutionary technologies such as agentic AI, local AI, and distributed computing are fundamentally changing the way many organizations compose, manage, and protect their PC fleets. While those tools offer the potential for unprecedented levels of speed, efficiency, and operational capacity, the same technological progress inevitably equips threat developers with the many of the same advantages. These bad actors are learning how to avoid traditional OS-level antivirus software through increasingly sophisticated AI-empowered firmware and hardware-level attacks, automated vulnerability exploitation, and the targeting of decentralized endpoints. Even quantum-level intrusion and encryption, while still in their early days, are emerging as likely security battlegrounds of the future.
Because of the dynamism of the modern security environment, IT leaders and technical professionals responsible for equipping and protecting enterprise PC fleets must pay close attention to the security features manufacturers build in beneath the OS. When it comes to firmware verification, credential protection, and telemetry that reaches enterprise management platforms, the capabilities that original equipment manufacturers (OEMs) enable can vary considerably, and those differences are worth understanding before you commit to your next deployment.
We researched the extent to which three Windows PC OEMs—Dell, HP, and Lenovo—supported 10 below-the-OS security and system management features on systems based on Intel Core Ultra processors with Intel vPro. We reviewed publicly available marketing claims and feature documentation, grouping the features into two categories: 1) prevention, detection, and remediation solutions; and 2) integrated hardware and software security solutions. In the first group, we investigated signed factory configuration manifests, quantum-resistant firmware signing, quantum-resistant BIOS verification, off-host Intel Management Engine verification, BIOS image capture, early attack sequence detection, CVE detection and remediation, and dedicated-hardware credential storage. In the second group, we examined hardware-assisted security through Dell, Intel, and CrowdStrike partnership and below-the-OS telemetry integration.
Based on what we found in each OEM’s publicly available documentation, Dell supports all 10 of the below-the-OS security features we evaluated. HP fully supports one feature and partially supports three, while Lenovo fully supports two and partially supports one. Notably, Dell was the only OEM of the group to validate BIOS integrity against an external, off-host reference, to capture compromised BIOS images for forensic analysis, and to surface its own firmware verification results natively within CrowdStrike Falcon. For companies that want to equip their workforce with capable, feature-rich PCs while remaining confident that their fleets are well-protected against an evolving threat environment, Dell systems may be a strong choice for their next deployment.
To dig into the details of our below-the-OS security feature comparison study, check out the report below.
Principled Technologies is more than a name: Those two words power all we do. Our principles are our north star, determining the way we work with you, treat our staff, and run our business. And in every area, technologies drive our business, inspire us to innovate, and remind us that new approaches are always possible.