What Is Firmware in Computer Systems?

Dec 17, 2019 | Data, Security

manageengine

Featured article by Adam Edmond, Independent Technology Author

Most people have heard of software or hardware, but if you are simply an average tech user who knows how to navigate a smartphone and not much else, you are likely unfamiliar with the word “firmware.” Yet firmware is essential to the operation of any computerized system, so it is important to understand what it means as well as how you can use it to your advantage.

Firmware is a permanent part of a hardware device, such as a keyboard, hard drive, or video card. It is what is programmed into a specific device to allow it to communicate with other devices. In the case of the keyboard, for example, a blue tooth keyboard contains certain firmware that signals to the computer that the keyboard needs to connect with it—without you touching a button.

These instructions, which are embedded into software stored on a small memory chip on the motherboard, are called BIOS (pronounced by-oss), or Basic Input Output System, and they control both the input and output functions of a device. BIOS firmware, for example, is responsible for the Power-On Self-Test (POST) that occurs when you first start your computer.

In layman’s terms, pre-installed BIOS firmware makes it possible to operate your computer. It is the first software that begins to run the moment you physically boot up your computer. It also provides start-up services to operating systems and programs. On top of that, its settings are non-volatile, meaning that even if a device loses power for some reason, its settings will still be saved.

Firmware is not only critically important for turning on your computer, but it is also instrumental in creating potentially life-saving research tools. Firmware development companies are routinely involved in the creation of medical devices for the healthcare industry as well as those used for educational purposes, industrial automation, and consumer electronics.

In one instance, firmware development services played a key role in a University of London study that examined the effect of exposure to noise on the cardiovascular systems of children and adults. Firmware was created so that the portable electrocardiogram device researchers developed, which was used to track participants’ heart rates along with individual noise levels, could record the data and send it to mobile phones via Bluetooth.

Another project involved improving existing software for robots, which were used as part of a learning program for 9-14-year-old students to learn to code. Part of the project also involved creating a portal where students could interact with the robots. While specific processes were involved, firmware development was essential in the successful execution of the project.

So, in a nutshell, that’s firmware. Summed up, it is the software embedded into a device (or piece of hardware) that makes your electronics function without you even thinking about it. This could include but is not limited to the software that maintains the clock settings on your computer or the software inside of televisions and other appliances.

Now that you understand firmware, you can officially add one more word to your technical vocabulary!

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more