Breaking the threat model HP Wolf Security puts suspicious clicks in disposable micro-VMs • 14% of observed email threats had bypassed a gateway scanner • The printer is an endpoint, too •

Company profile / Endpoint security

The Safest Click Is the One That Never Escapes

HP spent years trying to recognize every dangerous file. Then it bought a company built on a stranger premise: let the file run - just give it nowhere dangerous to go.

The case in five clicks

  • HP Wolf Security is an HP portfolio, not a standalone startup.
  • Its signature trick is isolation: risky files and pages open inside disposable micro-virtual machines.
  • Its reach runs lower than antivirus, through firmware and hardware, and wider than PCs, into printers.
  • Some protections come with eligible HP devices; Pro and enterprise layers add subscriptions and services.
  • The idea works best in HP-heavy Windows fleets where IT can manage policy, compatibility and endpoint agents.

There is a peculiar moment in the life of a suspicious email attachment. You double-click it. The icon twitches. Somewhere, a security product has perhaps already judged the file clean, or dangerous, or merely unfamiliar. HP Wolf Security makes a more mischievous calculation. It allows the file to open, but inside a tiny, hardware-enforced computer that has been created for this encounter alone. If the attachment behaves, nobody notices. If it detonates, it wrecks a room with no useful doors. Close the document and the room disappears.

This is the difference between recognizing a burglar and building a vestibule the burglar cannot leave. The first job gets harder every time criminals change their clothes. The second depends on architecture.

“The leading technology of the future will be secure by design and intelligent enough to not simply detect threats, but to contain and mitigate their impact.”Ian Pratt, HP, at the 2021 Wolf Security launch

A wolf assembled from older animals

The name HP Wolf Security arrived in May 2021, during the great corporate migration from offices to spare bedrooms and kitchen tables. The technology had a longer childhood. HP had built Sure Start, its self-healing BIOS defense, years earlier. It had added Sure Sense, which uses deep learning and behavior analysis to spot malware. And it had licensed isolation technology from a startup called Bromium for a product named Sure Click.

Bromium was founded in 2010 by Gaurav Banga, Simon Crosby and Ian Pratt, people steeped in virtualization. Its founding observation was awkward for the antivirus industry: patches lag, signatures lag, and workers keep clicking. Bromium's answer was the micro-VM. Each risky task received a minimal virtual machine backed by the processor's own virtualization features. In 2012 the company shipped vSentry. Investors eventually put roughly $116 million into Bromium. HP first became a customer and licensor, then acquired the company in 2019 for an undisclosed price.

That sequence matters. HP did not buy a slide deck and hope for chemistry. It used the technology inside Sure Click before absorbing the company. Two years later, Wolf Security collected HP's scattered defenses under one marketable animal: home, business, Pro, and enterprise; PCs and printers; silicon, firmware, software, cloud console and services.

HP Wolf Security branding alongside an HP business laptop
The wolf travels with the laptop. HP's commercial advantage is also its constraint: the deepest tricks are easiest when the security company makes the endpoint.

The gateway said yes

Wolf's strongest argument is not that detection is useless. Wolf Pro includes malware detection. The argument is that detection will sometimes be late. In HP's March 2026 threat report, 14 percent of email threats observed by Sure Click had bypassed at least one gateway scanner. The first layer had made its decision, and the dangerous thing was already at the employee's desk.

Attackers now hide scripts in images, borrow legitimate administration tools and buy prebuilt malware parts. A file may look like an invoice, use familiar Windows utilities and change just enough to avoid yesterday's signature. HP's quarterly threat research exists because isolated malware can still be watched after it slips past other filters. The micro-VM is both bin and laboratory.

14%Email threats seen in Q4 2025 that had passed at least one gateway scanner.
55B+Attachments, pages and files HP says customers opened in isolation with no reported breaches.
4Commercial layers: Business, Pro, Enterprise, plus consumer protections.

The 55-billion figure is HP's own and “no reported breaches” is not the same thing as an independent audit. Still, it captures the company's wager neatly. Clicking is not a behavior that security training will abolish. The useful intervention is to reduce what a click can reach.

A portfolio disguised as one product

The customer changes as you move up the menu. An owner of an eligible HP business laptop receives a base layer of built-in features. A small company can buy Wolf Pro for threat containment, malware prevention, credential protection and cloud management without staffing a full security operations team. Large enterprises and governments can add Sure Click Enterprise, Sure Access for privileged work, fleet controls and services. Published users range from Masonicare and the insurer Visana to German public agencies and the Northern Alberta Institute of Technology.

BuyerWhat they are really buyingCommercial shape
HP device ownerFirmware, hardware and basic endpoint defenses tied to the machineIncluded on eligible models
Small or midsize IT teamManaged isolation, malware and credential protectionTerm license or device bundle
Enterprise or governmentIsolation, privileged access, centralized policy, telemetry and servicesContract and quote

There is no honest single price. Public regional listings show the shape of it: a one-year Wolf Pro license was listed at £35.99 including VAT in Britain and €42.29 including VAT in France. Some PC configurations bundle multi-year terms. Enterprise pricing is negotiated. After an initial term, some standard Sure Click and Sure Sense functionality may continue without charge, but without future software updates or HP support. That footnote is more informative than a starting-price badge.

The model braids two businesses. Security helps HP sell and differentiate hardware; subscriptions and services create recurring revenue after the machine ships. It also explains why Microsoft Defender, CrowdStrike, SentinelOne, Sophos and other endpoint platforms are alternatives but not perfect twins. They are built to span mixed fleets. HP can reach into its own BIOS, controller silicon and printers.

The office appliance with a memory

A printer is easy to regard as furniture until one remembers that it has firmware, storage, memory, a network connection and documents people would rather not publish. Wolf extends to HP printers with secure boot, run-time intrusion detection, self-healing firmware, fleet policy and secure lifecycle controls. In 2026 HP announced broader quantum-resistant protection in new LaserJet lines. The phrase sounds futuristic; the practical point is prosaic. Printers live for years, so cryptographic choices made today must survive tomorrow's attacks.

The same expansion is happening on laptops. Protect and Trace can locate, lock or erase supported machines, including through a cellular connection on configured hardware. Enterprise Security Edition addresses physical tampering. TPM Guard, announced for selected 2026 commercial PCs at no extra charge, protects communication between the trusted platform module and CPU against certain probing attacks. Wolf began with the risky click and kept moving downward, toward the screws.

What another team can copy

  1. Design the blast radius first. Assume one control will miss and limit what the missed event can touch.
  2. Make recovery automatic. A protection that requires a midnight technician is only partly a product.
  3. Integrate before acquiring. HP licensed and shipped Bromium's technology before buying the company.
  4. Turn telemetry into research. Contained attacks can teach defenders without being allowed to roam.

Architecture still needs a compatible machine

Isolation is not magic dust. Wolf Pro's published requirements include supported 64-bit Windows editions, modern Intel or AMD processors, at least 8GB of RAM and substantial free disk space. The richest firmware and hardware features depend on particular HP models. Browser and document support varies. Administrators can weaken outcomes through policy choices, and any extra endpoint software can introduce performance, compatibility or support work.

Where the fit becomes awkward

A heterogeneous fleet may prefer one cross-vendor EDR. Unsupported operating systems do not gain the full stack. Resource-constrained machines may resent local virtualization. Organizations that already run overlapping endpoint agents need to test conflicts, user experience and incident workflows rather than assume that more controls automatically mean more protection.

This is where HP's difference becomes precise. The company is not merely selling an antivirus with a wolf logo. It is selling coordination between the maker of the computer and the people defending it. That coordination is hardest for a pure software vendor to reproduce and hardest for HP to deliver on somebody else's laptop.

The essential idea remains pleasantly small. A person will click. A scanner will occasionally shrug. A clever file will wear a familiar costume. Instead of demanding perfect judgment from all three, give the mistake a room of its own, then throw away the room.