July 1, 2026

There's a quiet certificate expiration happening across Windows 11 machines that most small business owners haven't heard about. The Secure Boot certificates that were baked into PCs back in 2011 are hitting end of life. If those certificates aren't replaced, your machines become more vulnerable to a specific class of attack called a bootkit, which is malware that loads before Windows even starts. Antivirus won't catch it. You won't see it. It just sits there.
This isn't theoretical. Bootkits have been used in real attacks against businesses. The updated 2023 certificates close that door.
Secure Boot is a firmware-level feature that checks whether the software loading at startup is trusted and hasn't been tampered with. Think of it as a bouncer checking IDs before anything gets into the building. The problem is that the "approved ID list" from 2011 is outdated. Microsoft and the PC manufacturers have issued updated lists, but someone has to apply them.
That someone is usually you, or whoever manages your IT.
If your business runs Windows 11 on hardware from HP, Dell, Lenovo, ASUS, Acer, MSI, Samsung, LG, or Microsoft Surface, you're in scope. That covers most of the business laptops and desktops I see in NJ offices. The update process varies by manufacturer. Some have a BIOS update that handles it automatically. Others require a manual firmware update followed by specific steps inside Windows. A handful of older models aren't supported at all, which means those machines need a harder conversation about replacement.
If you're running a mix of hardware across five or ten employees, you could easily have three different update procedures in your environment at the same time.
Larger companies have dedicated security teams watching for exactly this kind of advisory. Most small businesses don't. The update gets missed, the machine keeps working fine, and nobody knows there's an exposure until something goes wrong.
Bootkit attacks tend to show up in targeted scenarios, but they're also sold as tools in cybercriminal markets. If someone wants persistent, hard-to-detect access to a machine on your network, an outdated Secure Boot configuration is a useful entry point. For a business handling client data, financial records, or anything under HIPAA or similar compliance requirements, that's a serious problem.
First, find out what hardware you have. If you don't have an inventory, start one. Even a simple spreadsheet with make, model, and serial number is enough to get started.
Second, check whether your machines have received recent firmware updates. Windows Update doesn't always push BIOS or UEFI firmware changes automatically. You may need to go directly to the manufacturer's support site for each model, or use a management tool. If your business uses Microsoft Intune or Windows Update for Business, those platforms can help you track patch compliance across your fleet, including firmware where supported.
Third, identify any machines that are too old to receive the updated certificates. If a PC can't get the new Secure Boot certificate and it's sitting on your network with access to shared drives or email, that's a risk you should document and address. Sometimes the answer is a firewall policy. Sometimes it's a retirement conversation.
If you're a one-person IT team managing 20 or 30 endpoints across two locations, this kind of audit takes time you probably don't have. I get it.
Firmware and certificate updates are the kind of maintenance that looks invisible when it's done right and becomes a crisis when it's skipped. The Secure Boot situation is a good reminder that keeping Windows updated isn't the whole job. The layer underneath Windows matters too.
If you want help auditing your Windows fleet or setting up a patch management process that actually covers firmware, Exine works with small and mid-size businesses across New Jersey and New York City to make sure this stuff gets handled before it becomes a problem.