315
Secure Boot is completely broken on 200+ models from 5 big device makers
(arstechnica.com)
This is a most excellent place for technology news and articles.
Speaking from my background, it prevents someone from trying to boot using an external device to access your system, assuming you have a BIOS password in place.
Of course encrypting your drive works just as well, but security in depth demands a “why not both?” Approach