Enable Grub2 file signature verifications
The ultimate path is to ensure that GRUB2 has integrity checking, especially using file signature to check authenticity. Otherwise, the kernel and the initrd images are still open for modifications and attack.