Protect devices against debug-port abuse, firmware extraction, counterfeit components, side channels, and malicious peripherals. Apply secure boot, hardware roots of trust, authenticated updates, key storage, and supply-chain controls.