Yes, in that case things are a serious pain to get working. I assume they'd quite widely ship a live USB image (perhaps even a Windows executable) to update the bootloader.
The option you always have is disabling secure boot, which means that in its very very worst case it's no better than not doing anything at all. In its best (and presumably overwhelmingly dominant) case then it's infinitely better.