Firmware is the low level software stored on a hardware device that tells that device how to be itself. It sits below the operating system, ships with the product, and is written by the manufacturer rather than by you.
Every firewall, switch, access point, printer, SSD, NAS and PC motherboard in an office runs firmware, and each one is a separate update stream that nothing else patches for you.
- Firmware is software that lives on the device, not on your system disk
- It runs below any operating system, which is why security tools rarely see it
- A firmware update means flashing a manufacturer image onto the device itself
- Most offices patch Windows carefully and never touch the switch or the printer
- A failed flash can leave hardware dead, so the routine matters more than the speed
On this page
DefinitionWhat is firmware, and where does it live
The firmware definition that survives contact with real hardware is short. Firmware is the set of instructions a device runs to operate its own hardware, held in memory on the device, loaded at power on, and replaced only by deliberately writing a new image over the old one.
That is the firmware meaning in every product category. A switch boots its own image before it forwards a frame. A storage device runs controller instructions that decide where data blocks physically land. A printer runs the code that drives the motors and the network stack. None of that lives on your computer.
Engineers call these embedded systems: a computer inside a product that is not sold as a computer. Firmware is the software layer of an embedded system, which is why IoT devices such as a camera, a label printer or a badge reader behave like small computers on your network.
Older devices held these instructions in read only memory, and the page on what ROM is covers why the name stuck. A mask ROM chip could not be rewritten at all. EEPROM and then flash memory changed that, and firmware became updatable, which made it fixable and also made it a target.
Firmware also comes in types that sit at different depths. Platform firmware such as UEFI brings a computer up. Device firmware runs one component, such as a storage controller or a network card. Subsystem firmware runs management hardware, like the out of band controller on a server.
On a PC the firmware users meet by name is the BIOS or UEFI on the motherboard. It runs at power on, tests the hardware, and starts the operating system.
The motherboard is only one of the devices in that computer with firmware of its own. The storage drive, the network card and the embedded controller each run their own.
Three layersFirmware is not software, and it is not a driver
People use the three words interchangeably and then download the wrong file. The distinction is about where the code runs.
Software runs on top of an operating system. Applications are installed, updated and removed through the operating system, and cannot run without one. Deleting an application changes nothing about the hardware.
A driver runs inside the operating system and speaks to a device. It translates between Windows and that piece of hardware, so there is a Windows driver and a Linux driver for the same card.
Firmware is low level code that runs on the device and needs no operating system. A switch with no computer attached still boots and runs. The firmware vs driver question answers itself once you ask which side of the cable the code sits on.
The confusing case is a vendor package that installs both at once. A network card download often contains a Windows driver and a firmware image for the card, and the installer applies both. The release notes say which is which, and they carry separate version numbers.
Your inventoryThe firmware a business actually owns
This is the part the glossary pages leave out. In a 30 person office, the list of devices carrying firmware you are responsible for is longer than the list of servers.
The firewall or edge router. The one that matters most, because it faces the internet and vendors publish security fixes for it. Treat its release notes the way you treat patch management for servers.
Switches and access points. Usually neglected for years. Cloud managed devices apply updates on a schedule you set. On locally managed systems, nobody is coming.
Printers and multifunction devices. Full network stacks with web interfaces, scan to email credentials and stored data. They are computers that staple.
PCs and servers. UEFI plus storage, controller and management firmware. A BIOS update is the one most people mean, and it is no longer the rare emergency it once was, because processor level security fixes arrive that way.
NAS storage, IP cameras, UPS units, VoIP phones, door controllers. Each of these devices has its own image, its own portal and its own end of support date.
Write that list down once, with the current version and where the download lives. It takes an afternoon, and it is the highest value hour in this topic, because you cannot patch an inventory you do not have.
SecurityWhy firmware is the forgotten attack surface
Firmware sits below everything your security spend covers. Endpoint protection runs inside the operating system, so it sees what happens above the firmware, not what the firmware does. Reinstalling Windows replaces the operating system and leaves the platform firmware exactly as it was.
NIST published SP 800-193, Platform Firmware Resiliency Guidelines, for this reason. Its abstract covers the resiliency of platform firmware and data against destructive attacks, and states that a successful attack could render a system inoperable, perhaps permanently, or requiring reprogramming by the manufacturer. The three mechanisms are protection, detection and recovery.
Three practical exposures follow, and none of them need an exotic attacker.
Edge devices running old images. Firewall and VPN appliance vulnerabilities are published, indexed and scanned for within days. An unpatched edge device is the most direct route into a small network there is.
Devices past end of support. When a vendor stops publishing firmware updates for a model, that model stops being fixable. That date, not a hardware failure, is the real replacement trigger for a firewall or an access point.
Default credentials on the management interface. A printer or a camera with a factory password is a foothold that no firmware update fixes, because the update is not the problem.
On PCs the firmware defenses are ones you switch on rather than install. Secure Boot checks signatures on what loads at boot, and a setup password stops users changing boot order at the desk.
UpdatingWhat a firmware update is, and how to run one safely
A firmware update replaces the whole program on a device with a new image. It is not a patch applied to parts of a file.
That is why the answer to what is a firmware update is also the answer to why these updates carry risk. For a moment during the write, the device holds neither the old image nor a complete new one.
On Windows computers much of this is handled for you. Microsoft's documentation on the Windows UEFI firmware update platform describes system and device firmware updates shipping as driver packages that contain an INF and a firmware image.
Windows then hands that payload to the platform through the UEFI UpdateCapsule function. The same documentation says UEFI should not be used to update peripheral devices, because a removable device cannot be guaranteed to be present at the reboot that applies the update.
For everything else, the routine is the same every time.
Match the model exactly, including the hardware revision. Two devices with the same name on the front can take different images. Vendors publish per revision for a reason.
Read the release notes first. They say whether the fix applies to you, what breaks, whether the change is a security fix or a performance tweak, and whether you must pass through an intermediate version.
Save the configuration. On a firewall or switch, export the config and keep it off the device. Some upgrades reset settings, and a few will not import an older config back.
Do one device at a time. If two firewalls run as a high availability pair, taking both out together turns a maintenance window into an outage.
Protect the power and the path. A desktop on a UPS, a laptop on mains, and the flash run over a wired connection rather than Wi-Fi or a VPN that can drop.
Know the recovery route before you start. Dual firmware banks, a recovery partition, a TFTP or USB recovery mode, or vendor support. If there is none, the update needs a stronger reason.
Verify afterward. Read the running version back from the device. On a Windows computer, Get-CimInstance Win32_BIOS returns Manufacturer, SMBIOSBIOSVersion and ReleaseDate, which is what goes in the inventory.
PitfallsWhere people go wrong
Asking what is firmware instead of asking which firmware you own. The definition takes a minute. The inventory is the work, and it decides whether anything gets updated.
Treating no news as up to date. Almost no network device tells you a fix exists. Subscribe to vendor security advisories for the firewall at minimum, and check the rest on a calendar.
Updating the firewall on a Friday afternoon. Firmware updates need a window where someone can drive to the site. Reboots take longer than expected and config conversions occasionally go sideways.
Flashing hardware over Wi-Fi or a VPN. A dropped link during the write is the classic way to turn a working access point into a paperweight. Use a wired connection on the same network.
Updating a PC's BIOS because a scanner flagged it, on a computer that works. Match the update to a real problem, a security fix or a documented performance issue. That judgment is different from the desktop patching habit.
Forgetting the printer and the cameras. They are the devices nobody owns, on default credentials, running images from the year they were bought.
ComparisonFirmware, drivers and software, and what changes for each one
| Criterion | Firmware | Driver | Application software |
|---|---|---|---|
| Where the code runs | On the device itself | Inside the operating system | On top of the operating system |
| Works with no operating system | Yes | No | No |
| Written by | The hardware maker | The hardware maker or OS vendor | A software vendor |
| Stored in | Flash memory in the device | The system disk | The system disk |
| Survives an operating system reinstall | Yes | No | No |
| Normal way to update it | Flashing a vendor image | Windows Update or a vendor package | The application's own updater |
| What a failed update costs | The device, sometimes permanently | A rollback | A reinstall |
| Seen by endpoint security tools | Rarely | Yes | Yes |
Two rows decide how you treat each one. Because firmware survives an operating system reinstall, rebuilding a machine has never been a fix for a firmware problem. Because a failed flash can cost the device itself, firmware is the one category where installing everything immediately is the wrong policy, and a short checklist is the right one.
The middle rows explain the download page confusion: the driver is for the computer, the firmware is for the device, and installing one does not apply the other.
FAQFrequently asked questions
What is firmware in simple terms?
It is the built in program that makes a piece of hardware work. It lives on the device rather than on your computer, starts as soon as the device gets power, and came from the manufacturer. Without it the hardware does nothing at all.
What is the firmware meaning in everyday use?
Most people say firmware when they mean a device's own operating code: the software inside a router, a printer, a storage drive or a motherboard. It is the layer between physical hardware and anything users install on top.
What is the difference between firmware and software?
Firmware runs on a device and needs no operating system. Software runs on top of an operating system and cannot work without one. Firmware vs software is a question of where the code sits and who ships it, the hardware maker or a software vendor.
What is the difference between firmware and a driver?
The driver is installed in Windows and lets the operating system talk to a device. The firmware runs inside that device. Firmware vs driver matters on download pages, where the same product often has both, with separate version numbers.
What is a firmware update?
It replaces the whole program on a device with a newer image from the manufacturer. It fixes bugs, closes security holes, or adds support for newer hardware. It is applied from the device's own interface, a vendor tool or, on PCs, Windows Update.
Is a firmware update safe?
Usually, if you match the exact model, read the release notes, keep power and network stable, and do not interrupt it. The risk is real but small. The larger risk in most offices is a firewall running an image that is three years old.
How do I know if my firmware needs updating?
Compare the running version against the vendor's current release, which means reading the version from the device and checking the download page. Vendor security advisories are the signal that matters most for anything facing the internet.
Does Windows Update install firmware?
It can. Manufacturers publish system and device firmware as driver packages that Windows applies through the UEFI capsule mechanism, so many business computers get UEFI updates automatically. Network gear, printers and NAS boxes are never covered by it.
Where is firmware stored?
In a flash memory chip on the device, separate from any storage you can see in the operating system. That is why formatting a drive or reinstalling Windows does not change it, and why a corrupt image can stop a device from starting.
Which firmware should a small business keep updated?
The firewall first, then switches and access points, then servers and PCs, then printers, NAS boxes and cameras. Anything reachable from the internet moves to the top of that list regardless of what it is.
What happens if a firmware update fails?
Often nothing, because the device rolls back to its previous image. Where there is no second bank, the device may not start, and recovery means a USB or TFTP procedure, vendor support, or replacement. That is the reason for the checklist.
Is BIOS firmware?
Yes. The BIOS, or UEFI on any recent machine, is the motherboard's firmware. It runs at power on, initializes the hardware and starts the operating system, and the manufacturer publishes updates for it per board model.
Do phones and IoT devices have firmware?
Yes, and the pattern is the same. Cameras, thermostats, badge readers and label printers all run vendor firmware, and many stop receiving updates long before they stop working. Support lifetime is worth asking about before purchase.
Keep readingRelated concepts
Read next · Firmware and boot What a BIOS Update Does, and Why the Old Advice Changed When a BIOS update is worth the risk on a working machine, and how the old advice changed. Open this next10 min- Firmware and boot · 10 min UEFI vs BIOS The motherboard firmware in detail: what UEFI changed, and how to tell which mode a machine is in.
- Firmware and boot · 9 min What Is ROM, and Why Read Only Is No Longer Accurate Why firmware used to be unchangeable, and what read only memory means on hardware built today.