So....
Does BitLocker assist here?
Assuming you've turned on the PCRs which check the BIOS and/or option ROMs haven't changed checksum, and you've got boot protection enabled (i.e. key/passphrase required) then the O/S should have a hissy fit on boot up, which should ring alarm bells?