About HP Sure Start
HP Sure Start is not something a buyer adds to a PC. It is built into HP business machines, and the part that matters is a separate piece of silicon called the HP Endpoint Security Controller. That controller runs before the main processor is allowed to do anything. It validates its own firmware using 2048-bit RSA, then cryptographically checks the BIOS boot block. If a single bit is wrong, it overwrites the system flash with its own copy of the boot block, held in isolated non-volatile memory the operating system cannot reach.
The repair usually finishes in under a minute and nobody is asked to approve it. HP first shipped Sure Start in 2014, which makes it one of the older hardware roots of trust in the PC industry rather than a recent addition.
Why firmware is worth attacking
Firmware sits below the operating system. Code that runs there starts before Windows, before any security agent, and before anything that might report on it. It survives a reinstall, and it survives swapping the disk, because it does not live on the disk. That combination is what makes it attractive: an attacker who gets there gets persistence that ordinary remediation does not touch.
The standards world reached the same conclusion. NIST Special Publication 800-193, Platform Firmware Resiliency Guidelines, sets out three things a resilient platform needs: protection of the firmware, detection of unauthorised change, and recovery to a known good state. Most vendors do the first two. Sure Start is HP's attempt at all three, with the recovery step done in hardware rather than by sending a technician.
How the check and the repair actually work
The order matters more than the cryptography. The Endpoint Security Controller executes first, before the host CPU is released. It verifies itself, then verifies the BIOS boot block, and only then lets the machine continue. A component that checks the BIOS after the BIOS has already run is checking something that has had the opportunity to lie.
When verification fails, the controller does not simply refuse to boot and leave the user with a dead machine and a support call. It writes its protected copy of the boot block back into the system flash and continues. The design goal is that a firmware attack becomes an event the user notices as a slightly slow start, not as a week without a laptop.
What Runtime Intrusion Detection adds
Boot-time verification only covers boot time. Sure Start also includes Runtime Intrusion Detection, which watches System Management Mode code in memory while the operating system is running. System Management Mode is a highly privileged execution mode that the operating system cannot inspect, which is exactly why it is a target.
Chipset hardware detects anomalies there and reports them to the Endpoint Security Controller, which acts on policy: log the event, tell the user, or power the machine down. That last option is a real choice an administrator has to make, and it is worth deciding deliberately rather than discovering the default during an incident.
Which HP PCs have it, and which generation
Sure Start has moved through generations. The 2014 release did firmware authentication. The third generation, in 2017, added runtime detection and protection of BIOS settings. The fourth, in 2018, added protected storage using AES-256, protection of secure boot keys, and third party security certification. HP's own technical white paper documents that history, and the generation on a given machine follows its age.
On availability, HP states that HP Wolf Security for Business requires Windows 10 or 11 Pro or higher and is available on HP Pro, Elite, RPOS and Workstation products, while noting that included features vary by product. The white paper covering the 2018 range lists Elite notebooks, desktops, tablets and all-in-ones plus the Pro 600 series with 8th generation Intel or AMD processors.
The practical advice is unglamorous: read the datasheet for the exact model being purchased. Sure Start is not uniformly present across everything with an HP badge, and the consumer lines are not where to look for it.
How it compares with what other PC makers do
Dell covers this ground with Dell Trusted Device and its below-the-operating-system BIOS verification work, and Lenovo with ThinkShield. All three vendors are building against the same NIST guidance, so the categories match even where the marketing names do not.
The difference worth asking a vendor about is what happens after a problem is found. Detection that produces an alert in a console still needs a human and a rebuild. Sure Start's argument is that the good copy is already on the machine, in a place the running system cannot write to, and the repair happens without anyone being told first. The independent analyst firm Quocirca described HP's hardware-based root of trust as protecting against firmware replacement attacks and called it a strong step in maintaining hardware security across a device's life.
Who should be looking at something else
Anyone hoping to buy Sure Start on its own is in the wrong place. It ships inside HP business hardware, so the decision is a hardware decision, and it cannot be added to a fleet that has already been bought.
Organisations running mostly Mac or Linux have nothing to install and should look at what their own platform vendor does at the firmware layer instead.
Security teams whose requirement is fleet-wide firmware attestation reported into a SIEM, across mixed hardware from several manufacturers, need a dedicated firmware security platform rather than any one maker's built-in feature. Sure Start protects the machine it is in and reports locally.
And anyone reaching for this as an answer to ransomware or phishing has the wrong layer. Sure Start does nothing about a user opening a hostile attachment. That is what HP Sure Click and endpoint detection are for, and firmware resilience is the floor beneath them rather than a replacement.
Reviews
No reviews yet
Nobody has reviewed HP Sure Start here yet.