This is mitigated by a Trusted Computing Group feature - at boot, the OS sets a non-volatile flag, and clears it again on clean shutdown after wiping any sensitive material from RAM. If the system boots with the flag set then the firmware wipes the RAM before booting anything. This doesn't protect you against someone pulling the RAM out of the system and dumping it there, but that's a much harder attack.