To be clear, my understanding isn't necessarily that Secure Boot auto-stops cheats from working, but creates a permanent hardware ID for the machine and OS, which makes permanent bans signficantly more difficult (and/or at least expensive) to go around as it requires new hardware. Unfortunately, this comes at the expense of many legitimate folks needing to change settings in their BIOS, and many (not saying you, OP) which are not technically inclined end up breaking their OS install due to needing to switch from Legacy/BIOS to UEFI in the process (which will not let Windows boot)