I ran the official Razer BIOS Updater.
After the update it displayed "invalid signature detected, check Secure Boot policy in setup." The updater then reported the update completed successfully.
To get the machine to boot, I disabled Secure Boot in BIOS. The laptop now boots normally and I can log in with my Microsoft account password.
Disabling Secure Boot invalidated my Windows Hello PIN, which no longer works (expected, but I want to restore it).
When I try to re-enable Secure Boot, the same "invalid signature detected. Check Secure Boot policy in setup" error returns and the machine will not boot until I disable it again.
My BIOS does not appear to show a "Restore Factory Keys" / "Restore Default Secure Boot Keys" / "Install default keys" option where I have looked.
I have also noticed device initialisation issues since the update (Bluetooth pairings dropping on every reboot), which may or may not be related.

