When packaging an application requiring an exception within the XP firewall, you can automate the exception using netsh.
BIOS updates can be automated along with your standard deployment routines. A single job can be used regardless of the model being deployed.