Windows 10 reached end of support on October 14, 2025. Nearly a year later, a surprising number of business PCs are still running it. Quietly, reliably, and completely unpatched.
That last word is the problem. The machines still boot. Applications still open. Nothing looks broken, which is exactly why this risk is so easy to defer. But every month that passes adds to a growing pile of vulnerabilities that Microsoft has documented, attackers have studied, and nobody is fixing.
If you still have Windows 10 in your environment, here is what actually changed, what your realistic options are, and how to work through it without a disruptive all-at-once replacement project.
What End of Support Actually Means
End of support is not a kill switch. Microsoft did not disable anything, and your Windows 10 machines will keep running indefinitely. What stopped is the flow of security updates.
Concretely, that means:
- No more security patches. Newly discovered vulnerabilities in Windows 10 will not be fixed on unenrolled machines.
- No technical support from Microsoft for issues on the platform.
- Gradually thinning software support. Vendors test against supported operating systems. Over time, new versions of the tools you rely on stop being validated on Windows 10, and eventually stop installing.
- Hardware and driver drift. New peripherals increasingly ship without Windows 10 drivers.
The compounding problem
An unpatched operating system does not become dangerous gradually and evenly. It becomes dangerous in steps, each time a new vulnerability is published. Attackers actively study patches released for Windows 11 to find the same flaws in the version that will never receive a fix. The gap between "unsupported" and "actively targeted" narrows every month.
Why This Is a Compliance Problem, Not Just a Security One
For many businesses, the sharper deadline is not technical but contractual. Running unsupported software can put you offside with obligations you have already signed up to:
- Cyber insurance. Policies increasingly ask whether you run supported, patched operating systems. An inaccurate answer can jeopardise a claim at the worst possible moment.
- Regulatory frameworks. Regimes covering healthcare, financial services and payment card data generally expect security patches to be applied. An OS that cannot receive patches is difficult to defend in an audit.
- Client contracts. If you handle customer data, your agreements may already commit you to maintaining supported systems.
These obligations do not care that the machine still works. They care whether it can be patched.
Your Four Realistic Options
Every Windows 10 device in your environment ends up in one of four buckets. The work is deciding which, and being honest about the cost of each.
1. Upgrade in place to Windows 11
The cheapest path when it is available. If the hardware meets Windows 11 requirements (broadly, a recent enough processor, TPM 2.0 and Secure Boot), the upgrade is free and preserves applications and data. Most business machines bought in the last several years qualify.
2. Replace the hardware
Machines that fail the Windows 11 requirements are, almost by definition, old enough that replacement is defensible on its own merits. A device that cannot run a current OS is also a device nearing the end of its useful life for performance, battery and warranty reasons.
3. Extended Security Updates (ESU)
Microsoft offers paid Extended Security Updates as a bridge, delivering critical and important security fixes to enrolled Windows 10 machines. It is deliberately priced to encourage migration rather than indefinite delay, with the cost rising each year you stay. Treat it as a way to buy scheduling room for a genuinely difficult migration, not as a strategy.
4. Isolate and contain
Occasionally a machine genuinely cannot move: a workstation bolted to a piece of production equipment, or a system running software the vendor abandoned. These can sometimes be kept, but only if they are properly contained: segmented off the main network, stripped of internet access and email, locked down with application allow-listing, and explicitly documented as accepted risk.
Working Through It Without a Crisis
Start with an accurate inventory
You cannot plan around machines you do not know about. Before anything else, establish how many Windows 10 devices you actually have, who uses them, what runs on them, and which ones meet the Windows 11 hardware requirements. This step routinely surprises people, both in the count and in how many turn out to be upgradeable at no hardware cost.
Sort by exposure, not by age
The natural instinct is to start with the oldest machines. Risk is the better sort order. A laptop that travels, handles email and browses the web is far more exposed than a fixed workstation on a segmented network. Prioritise the devices that touch the internet, handle sensitive data, or belong to users with elevated access.
Pilot before you commit
Upgrade a small, representative group first, ideally including your most demanding line-of-business application. Windows 11 is not a dramatic departure, but driver issues and application compatibility surprises are easier to absorb across five machines than fifty.
Budget replacements across quarters
For the machines that genuinely need replacing, spreading purchases across quarters is far easier to absorb than a single capital request. It also lets you standardise on fewer models over time, which pays back in support and imaging effort for years.
The businesses that handled this well did not move faster than everyone else. They simply started with an accurate inventory, so they knew how much of the problem was a free in-place upgrade and how much was a real purchase.
What to Do This Quarter
If Windows 10 is still in your environment, the useful next steps are small and concrete:
- Count them. Get a definitive list of Windows 10 devices and their hardware eligibility.
- Check your insurance application. Confirm what you told your carrier about supported operating systems, and whether it is still true.
- Upgrade the easy ones now. Eligible machines are a free fix; there is no reason to leave them exposed while you plan the rest.
- Price the remainder. Turn the leftover devices into a real number so it can be scheduled and budgeted rather than deferred.
- Document anything that must stay. If a machine cannot move, write down why, what compensating controls are in place, and who accepted the risk.
None of this needs to happen in a single weekend. What it does need is to stop being invisible, because the one thing an unpatched operating system will not do is tell you when its luck runs out.
Not Sure What's Still Running Windows 10?
We can inventory your environment, identify which machines upgrade for free, and turn the rest into a costed plan you can schedule.
Request an Assessment