Skip to main content

Secure Boot explained

Secure Boot is a setting in your PC's firmware that stops malicious software loading before Windows even starts. That kind of malware is very hard to detect once it's running, so Secure Boot is an important early line of defence.

Reading is great. Tracking makes it stick. Sign up for a free Dashboard to tick off tasks and see your Security Score.

Get my free Dashboard →
CE: Secure Configuration
A phone screen showing a security app

Cyber Nova AI helps you prepare for Cyber Essentials. It doesn't award or certify it. Follow the steps here to get ready, then apply for certification through an accredited Cyber Essentials body when you're set.

Check whether it's on

Press the Windows key and R together, type msinfo32, and press Enter. In the System Information window, look for Secure Boot State. If it says On, you're done.

If it says Off or Unsupported

Off usually means it was turned off at some point, often for gaming or a dual-boot setup, and never turned back on. Turning it on again happens in the BIOS or UEFI settings, which vary by PC, so check your manufacturer's guidance before changing anything there. Unsupported generally means older hardware that predates the feature. That's not a fault, it just means this particular protection isn't available on that PC.

Don't rush the firmware

BIOS and UEFI settings are powerful, so only change what you understand. If you're unsure, it's fine to note the result and move on to the other tasks, which give plenty of protection on their own.

Track your Windows security progress. Free.

Create a free account to tick off tasks, see your Security Score improve, and know exactly what you've done and what's still to do.

Start your free security check