I ran fwupdmgr security, and the only thing that's holding back my wonderful T480 from having HSI:2 is an outdated CSME version.
So, I went to the Lenovo site, and downloaded the CSME update from there.
I got the .EXE file, extracted it with 7z, and got the following files:
[0]CERTIFICATE
What am I supposed to do with them???
