About HP Sure Click
HP Sure Click is the isolation layer inside HP Wolf Security. Rather than trying to decide whether a file or a web page is safe, it treats the question as unanswerable and opens the risky thing inside a disposable virtual machine that can reach almost nothing else on the PC. When the tab or the document is closed, the container is deleted, and anything hostile that was running inside it goes with it. No user action is needed and nothing has to be quarantined afterwards.
The engine is not HP's own invention. It came from Bromium, a company founded in 2010 by Gaurav Banga, Simon Crosby and Ian Pratt, whose micro-virtualization product vSentry shipped from September 2012. HP licensed the technology for Sure Click first and then bought Bromium outright in September 2019. Sure Click is that engine, folded into HP's business PC line and sold under HP's name.
How the isolation actually works
Bromium's design puts a late-load hypervisor, which it called a microvisor, underneath the running copy of Windows. It is built on the open source Xen platform and uses the virtualization extensions already present in the processor. Instead of one heavy virtual machine holding a whole second operating system, it spins up a lightweight micro-VM for each individual task: this tab, this attachment, this download. Each one is given access only to the resources that specific task needs, which keeps the attack surface narrow and enforces least privilege by construction.
The practical consequence is that malicious code is allowed to run. It simply runs somewhere it cannot do damage, with no view of the file system, the corporate network or the credentials sitting in memory. When the task ends, the micro-VM is destroyed along with whatever it was hosting. This is containment done locally, on the user's own processor, rather than a cloud service the machine has to reach.
What it opens in a container, and what it leaves alone
Three things go into micro-VMs: web pages, opened through the HP Sure Click Secure Browser, Microsoft Word documents, and PDF files. Files arriving as email attachments or downloads open inside a container automatically rather than waiting for the user to choose. HP states the software requires Windows 10 or Windows 11 and works with Edge, Chrome, Firefox and Chromium based browsers.
There is an advanced protection setting that isolates every web page rather than only the untrusted ones. HP warns in its own documentation that turning it on can stop some sites working properly, which is a fair trade to offer and an unusually honest one to publish.
What falls outside those handlers is not covered. Sure Click is a containment tool, not a detection tool, and HP does not position it as a replacement for endpoint detection. On HP machines it is paired with HP Sure Sense for detection, HP Sure Start for firmware integrity and HP Sure View for the physical privacy screen.
Which PCs get it and how it is sold
HP Wolf Security for Business requires Windows 10 or 11 Pro or higher and is available on HP Pro, Elite, RPOS and Workstation products. That is the honest answer to the common question of whether a given HP laptop has it: the consumer lines are not the target.
HP Sure Click Pro is not sold as a standalone product. It requires either HP Wolf Pro Security Edition or the HP Wolf Pro Security Service. Those can arrive preloaded on a Wolf Pro Security Edition PC or be installed as standalone software, and the standalone route covers non-HP PCs as well as HP ones, which is the only supported way to run this on another vendor's hardware.
HP Sure Click Enterprise is the separate offering aimed at large organisations and government buyers, adding threat intelligence collected from the containers themselves and protection against phishing pages that harvest credentials.
How it compares with the alternatives
There are two other ways to solve the same problem. Remote browser isolation, sold by vendors such as Menlo Security, Cloudflare and Zscaler, does the containment in a data centre and streams a safe rendering to the user. That approach does not care what the endpoint runs, and it reaches unmanaged devices, but it introduces a network dependency and an ongoing per-seat cost. Endpoint detection and response watches behaviour and can catch things containment never sees, but it still has to be right about what it is looking at.
Sure Click's argument is that it does not need to be right. The container holds whether or not anyone recognised the threat. The price of that argument is narrow reach: Windows only, dependent on processor virtualization support, strongest on HP business hardware, and limited to the file types and browsers it knows how to wrap.
Who should buy something else
Fleets that are mostly Mac or Linux should not start here, because there is nothing to install. Organisations running no HP hardware at all can license the standalone software, but should first ask whether they are paying for an approach that is cheaper to obtain elsewhere.
Teams whose real problem is contractors and personal devices they do not manage will get further with remote browser isolation, which does not require anything to be installed on a machine the organisation does not own.
Buyers whose first gap is visibility rather than containment, meaning they cannot currently tell what happened on an endpoint after the fact, should buy detection and response before they buy isolation. Sure Click deliberately produces less noise, and a quiet tool is not what a team with no telemetry needs first.
Individuals should note that Sure Click Pro is not sold to them separately. A home user on Windows Pro who wants to open a suspicious file once has Windows Sandbox built into the operating system already.
Reviews
No reviews yet
Nobody has reviewed HP Sure Click here yet.