HP has released a new report highlighting the far-reaching cybersecurity implications of failing to secure devices at every stage of their lifecycle.
The findings show that platform security – securing the hardware and firmware of PCs, laptops and printers – is often overlooked, weakening cybersecurity posture for years to come.
The report, based on a global study of 800+ IT and security decision-makers (ITSDMs) and 6,000+ work-from-anywhere (WFA) employees, shows that platform security is a growing concern with 81% of ITSDMs agreeing that hardware and firmware security must become a priority to ensure attackers cannot exploit vulnerable devices.
However, 68% report that investment in hardware and firmware security is often overlooked in the total cost of ownership (TCO) for devices. This is leading to costly security headaches, management overheads and inefficiencies further down the line.
Key findings from across the five stages of the device lifecycle include:
- Supplier Selection – In addition, 34% say a PC, laptop or printer supplier has failed a cybersecurity audit in the last five years, with 18% saying the failure was so serious that they terminated their contract. 60% of ITSDMs say the lack of IT and security involvement in device procurement puts the organisation at risk.
- Onboarding and Configuration – More than half (53%) of ITSDMs say BIOS passwords are shared, used too broadly, or are not strong enough. Moreover, 53% admit they rarely change BIOS passwords over the lifetime of a device.
- Ongoing Management – Over 60% of ITSDMs do not make firmware updates as soon as they’re available for laptops or printers. A further 57% of ITSDMs say they get FOMU (Fear Of Making Updates) in relation to firmware. Yet 80% believe the rise of AI means attackers will develop exploits faster, making it vital to update quickly.
- Monitoring and Remediation – Every year, lost and stolen devices cost organisations an estimated $8.6bn. One in five WFA employees have lost a PC or had one stolen, taking an average 25 hours before notifying IT.
- Second Life and Decommissioning – Nearly half (47%) of ITSDMs say data security concerns are a major obstacle when it comes to reusing, reselling, or recycling PCs or laptops, while 39% say it’s a major obstacle for printers.
A New Approach to the Device Lifecycle is Needed to Improve Platform Security
Oversights in supplier selection, onboarding, and configuration significantly impact device security throughout its lifecycle.
Findings reveal a pressing need for IT and security teams to play a more active role in the procurement process to set requirements and verify vendor security claims. However, collaboration between procurement and IT teams is often lacking, with 52% of IT decision-makers (ITSDMs) stating that procurement rarely consults IT and security when verifying hardware and firmware claims.
Nearly half (45%) admit they simply trust suppliers’ claims due to a lack of tools to validate them, and 48% describe procurement teams as overly credulous, likening them to “lambs to the slaughter.”
Onboarding and configuration also present significant challenges.
A majority (78%) of ITSDMs desire zero-touch cloud-based onboarding that includes hardware and firmware security configurations, yet 57% express frustration at not being able to achieve this. Work-from-anywhere (WFA) models exacerbate these issues, with almost half of remote workers reporting disruptions during device onboarding.
Additionally, WFA models complicate platform security management, with 71% of ITSDMs citing increased difficulty, leading to risky employee behaviours such as using personal laptops for work or relying on unauthorised repair services, which can compromise device integrity. Hardware and firmware security remains a blind spot for many organisations.
While monitoring and remediation of threats to these layers are critical, 79% of ITSDMs admit their knowledge of hardware and firmware security lags behind software security. Moreover, 63% face blind spots in detecting vulnerabilities, 57% cannot analyse past security events, and 60% believe hardware and firmware attack mitigation is impossible, leaving post-breach remediation as their only option.
“You will always need to choose technology providers you can trust. But when it comes to the security of devices that serve as entry points into your IT infrastructure, this should not be blind trust,” comments Michael Heywood, business information security officer, Supply Chain Cybersecurity at HP Inc.
Recommended reading
- How Much E-waste is Generated in the UK?
- New Study: A Third of Scots Don’t Know How to Recycle E-waste
- International E-waste Day: Is FastTech the New Fast Fashion?
“Organisations need hard evidence – technical briefings, detailed documentation, regular audits and a rigorous validation process to ensure security demands are being met, and devices can be securely and efficiently onboarded.”
Concerns about platform security are also driving an e-waste epidemic, as organisations struggle to reuse or recycle devices securely. More than half (59%) of ITSDMs admit they often destroy devices due to data security fears, while 69% acknowledge sitting on large numbers of devices that could be repurposed if sanitisation were easier.
Compounding the issue, 70% of WFA employees retain old work devices, and 12% admit leaving jobs without returning them, creating additional risks from orphaned devices still holding sensitive corporate data.
More than two thirds (69%) of organisations say their approach to managing device hardware and firmware security only addresses a small part of their lifecycle. This leaves devices exposed, and teams unable to monitor and control platform security from supplier selection to decommissioning.
To manage platform security across the entire lifecycle, HP Wolf Security’s recommendations include:
- Supplier selection: Ensure IT, security and procurement teams work together to establish security and resilience requirements for new devices, validate vendor security claims and audit supplier manufacturing security governance.
- Onboarding and configuration: Investigate solutions that enable secure zero-touch onboarding of devices and users, and secure management of firmware settings that don’t rely on weak authentication like BIOS passwords.
- Ongoing management: Identify the tools that will help IT monitor and update device configuration remotely and deploy firmware updates quickly to reduce your fleet’s attack surface.
- Monitoring and Remediation: Ensure IT and security teams can find, lock and erase data from devices remotely – even those that are powered down – to reduce the risk of lost and stolen devices. Improve resilience by monitoring device audit logs to identify platform security risks, such as detecting unauthorised hardware and firmware changes and signs of exploitation.
- Second life and decommissioning: Prioritise devices that can securely erase sensitive hardware and firmware data to enable safe decommissioning. Before redeploying devices, seek to audit their lifetime service history to verify chain of custody, and hardware and firmware integrity.
“Post-breach remediation is a losing strategy when it comes to hardware and firmware attacks,” warns Alex Holland, principal threat researcher in the HP Security Lab.
“These attacks can grant adversaries full control over devices, embedding deep within systems. Traditional security tools are blind to these threats as they tend to focus on the OS and software layers, making detection nearly impossible. Preventing or containing these attacks in the first place is critical to stay ahead, or else organizations risk a threat they cannot see – and cannot remove.”





