About Gerard Moore
In an October 2024 interview, Gerard Moore, CEO of Phoenix Technologies, promoted the company’s FirmGuard product and discussed the importance of BIOS security. Moore stated that Phoenix provides firmware for Lenovo, LG, and Vio laptops and collaborates with chip makers including Intel, AMD, and ARM. He described firmware as a “critical attack surface” and cited a warning from CISA that firmware is increasingly targeted by hackers, adding that “if you get control of the firmware you have control of the entire device.”
Moore offered free, cloud-based firmware audits through FirmGuard, noting that “up to 10% of their inventory to their surprise was in legacy mode which is not secure.” He positioned the audits as a way for managed service providers to identify and fix vulnerabilities in client devices, including for compliance purposes such as HIPAA. Moore also described Phoenix as a “40-year startup” and emphasized that the company’s firmware development focuses on security.
Source: AI-verified profile updated from Gerard Moore's recent appearances.
Browse all interviews →
Transcript (24 segments)
R
Robin Robins0:05
Hey folks, Robin Robins here, founder of TMT and MSP Success magazine. I'm here with Jared Moore, who is CEO of Phoenix Technologies, and we are here to talk about an area of security and protection for your clients that I can practically guarantee that you're not thinking about, that you're not protecting your clients about. And I know you've heard that from a million vendors like, oh, you know, there's another cyber security protection that you need, but I really do think this time is one that you are not thinking about this and not protecting your clients about. And because of that, it is now the new gateway, the new back door, the new way hackers are now getting into your client's networks, and you're going to start seeing more of this when it comes to compliance, obviously in security. So Jared, very excited to have you here and talk about this.
G
Gerard Moore1:04
Good to be here. Yeah, so it's kind of exciting, like you were saying, you're a 40-year startup, so I guess talk to us a little bit about Phoenix Technologies and what you do. Yeah, Phoenix has been around quite a while. We do the firmware for all the Lenovo laptops, ThinkPads, LG laptops, VAIO laptops. We work with the silicon makers Intel, AMD, ARM in terms of developing secure, robust, and efficient firmware, but obviously secure is key. And the most secure firmware is UEFI, which is the open source standard for firmware. We're a co-founder of the UEFI Forum, we're on the UEFI board, we chair the UEFI security response team, so we feel we're pretty expert in firmware and firmware security. And Firmu, which is the product we're talking about, is focused on MSPs, their use cases to give them a tool not only to provide security but also efficiency and compliance.
R
Robin Robins1:57
So, it's a remote tool to go in and fix firmware on their client's device. I mean, that's essentially one component of it, correct?
G
Gerard Moore2:09
Correct, no, that's correct. So it is completely remote. You can access your customers' endpoints, you can check the security level of the firmware that it's intact, monitor that firmware, and then use Firmu Guard to manage those endpoints in terms of erasing disks to a secure level and changing the firmware settings of the endpoint, all remotely.
R
Robin Robins2:33
Okay, so when we're talking to the MSPs out here that are watching you, and they hear security, they hear compliance, so like, why do MSPs need this product?
G
Gerard Moore2:41
So I've had one, I've been on one call with somebody who had hundreds of thousands of endpoints, and they joked of the fact that they focus on application security, they focus on operating system security, and they kind of look at firmware security through fingers like this because that's not something that there's a great deal of awareness of. So really, it is a real threat, it's an attack surface, and that's why we produce Firmu Guard, because it allows you to monitor and track what your firmware is doing, but it's got other benefits as well.
R
Robin Robins3:17
Okay, so from a security standpoint, I mean, are attacks happening on that level?
G
Gerard Moore3:24
Attacks are happening, and in fact, the best source for that is the fact that CISA, the Federal Cyber Security Agency, last year issued a bulletin basically warning about the risk to firmware from attacks that they are increasing in prevalence. They're dangerous because if you get control of the firmware, you have control of the entire device, operating system, the hard disk, and you're below the operating system, so they persist. So even if you reboot the machine or even reinstall the operating system, the firmware malware is still there.
R
Robin Robins4:01
So, but aren't other security tools protecting that device from that attack? Or are they getting through in some way?
G
Gerard Moore4:09
I mean, one of the best protections is to just keep your firmware up to date. So part of one of the features of Firmu Guard is secure update to make sure that your firmware is up to date and making sure that you've got firmware, the endpoints are running in the correct and most secure mode. So Firmu Guard does provide that. Whether it's unique or not, I think we believe it is unique in not only in that aspect but also in the tools like secure wipe where, as I mentioned, you can securely erase a hard disk to a military standard.
R
Robin Robins4:40
Okay, so it's just another layer. Then again, like, I think everybody, I have not heard of anybody talking about firmware security in any, you know, we get a lot of vendors, we have hundreds of vendors come to our events, I haven't heard anyone talking about this, so that it is unique, I think.
G
Gerard Moore4:55
Yeah, no, and the issue is that firmware is a harder layer to hack. The operating system, the applications in some ways are easier, which is why CISA gave that warning that firmware is a critical attack surface and it is being increasingly used. But you are correct, five years ago this probably wasn't as much of an issue or a concern as it is now as it's becoming out, and that's the timeliness of us introducing Firmu Guard.
R
Robin Robins5:23
Okay, so because I know when I asked you like, why do MSPs need this, you mentioned security which we're talking about now, compliance which you kind of touched on a little bit, so talk about that a little bit because I believe like, if companies have to be HIPAA compliant, they have to shred the hard disk if they're getting rid of a machine or deploying it to something else. So I think, is this a tool that people are now using, your Firmu Guard, are they using that now to become HIPAA compliant with the devices that they're trying to?
G
Gerard Moore5:34
Yes, in order to, for example, confidential patient data you would normally dispose of that in a physical way by crushing the device or securely erasing the disk, but it was something you had to do on site, you had to go collect the device. With Firmu Guard you can actually do that remotely, and it'll even print a certificate of erasure for compliance purposes. And because we're operating at a firmware level, the disk is completely erased from the operating system including the operating system. So from a compliance perspective that's a big benefit. If you had a bad lever, for example, and you were concerned about information on the endpoint, you can erase that endpoint totally before the endpoint is shipped back to you or if you don't see it again. So those are ways where from a compliance perspective you can benefit from it and charge for it as an MSP.
R
Robin Robins6:47
Okay, so there's the security part of it, there's that compliance piece about wiping devices, there's the convenience part of it. I know one of our mutual clients, I won't say his name, I don't know if we're supposed to say, but had a client had a firmware problem and was able to just remote in and fix it where normally would had to go on site.
G
Gerard Moore7:10
Yeah, we put this out on a testimonial. We had one client who had two based actually in the west coast, they had two laptops in Hong Kong. They needed to make some changes to run Windows 11, they needed firmware changes. Clearly they're not going to get on site in Hong Kong. They were going to with a 15-hour time difference going to have to get somebody to walk them through the steps. With Firmu Guard they fixed the problem in 15 minutes because they could use our configuration utility to change the firmware settings, reboot into Windows 11, and the problem was resolved in 15 minutes. So it was a huge efficiency benefit for them.
R
Robin Robins7:47
Right, right, okay, sounds good. All right, so it sounds like security, compliance, efficiency, awareness, all these things that this is, I think we're going to start hearing more about this I think as whether it's HIPAA compliance or CMMC, you know having those devices secure from the bottom up like you know is super super important. So I think you have a scan or something like or an offer so that if people want to learn more and
G
Gerard Moore8:14
Yeah, talk about that. So what we have is you just go to firmguard.com/tmt. It's called SEC, it's a free audit for all of your inventory. It will, there's no strings attached, no cost, but will tell you if for example some endpoints are in legacy mode which is a major security vulnerability, if you've got secure boot enabled, if you've got BitLocker enabled. And we have found with people who have done these audits that maybe up to 10% of their inventory to their surprise was in legacy mode which is not secure. So as I said, it's free, no strings attached, firmguard.com/tmt and just sign up.
R
Robin Robins8:54
Yeah, and because you had mentioned so not only is that but there's other, it'll tell them if it's in like, reboot, secure boot has been turned off, secure boot, BitLocker, any of those things you can check using that scan. Okay, so they go there, is this a tool they download and run on their clients or how does it like so they go and download or are they signing up for a demo right there?
G
Gerard Moore9:07
It's all cloud-based. They're signing up for the audit. It's free of charge, as I said, no strings, and the team will take them through it all and then they can see for themselves the benefits. So they can take their clients and look at the firmware and see if there's any vulnerabilities there and then the tool will let them fix many of those vulnerabilities as well.
R
Robin Robins9:40
Well, they have to pay for that part right? No, no, no, that's part of the audit they can do that as well. Okay, excellent. We're confident they'll like us and then want to keep it and want to keep us. Okay, excellent. All right, well that sounds like a pretty good offer guys so again go give the URL one more time at firmguard.com/tmt so go there and check it out and sign up. I'll make sure my MSP does that on us, he'll definitely find something wrong with mine for sure. I'm sure my firmware is all messed up anyway. Okay great seeing you guys, thanks for being here.
G
Gerard Moore10:11
So much thanks, very much thanks for Rob.