Windows 10 reached end of support on 14 October 2025. The machines did not stop working, nothing dramatic happened on the day, and for a lot of businesses that was the end of the conversation.
Which is exactly the problem. The risk from running an unsupported operating system does not arrive as an event. It accumulates quietly, and it has been accumulating for a while now.
What “end of support” actually means
It does not mean the computer stops. It means Microsoft no longer issues security updates for it.
Every month, vulnerabilities are found in Windows. On supported versions they get patched. On Windows 10 they now simply remain open, permanently, and the list only grows.
There is a second-order effect that catches people out too. When a vulnerability is patched on a supported version, the details become public — which effectively signposts the same weakness on the unsupported one. Each patch cycle makes an unsupported machine slightly easier to attack, not just no safer than last month.
The knock-on effects
Software support drops away. Vendors gradually stop testing against an unsupported OS. At some point your line-of-business application, accounting package or browser stops receiving fixes on that machine.
Compliance gets awkward. Cyber Essentials requires that software be supported and receiving security updates. Unsupported machines in scope are a problem at assessment. Cyber insurers ask similar questions, and the honest answer affects your position at renewal or after a claim.
One weak machine is enough. A single unpatched device on your network is a foothold. From there, an attacker moves sideways to everything else. The rest of your estate being well maintained does not neutralise it.
Working out where you actually stand
Before deciding anything, find out what you have. Most businesses are surprised — there is usually a machine in reception, one in the warehouse, or a laptop belonging to someone who works two days a week.
For each one, three questions settle it. Can it run Windows 11? Many machines from the last several years can. What is it actually used for? And is it exposed to email and the web, or does it sit isolated driving one piece of equipment?
Your realistic options
Upgrade the ones that qualify. Usually the cheapest route. The hardware requirements are stricter than previous versions, so some capable-feeling machines will not qualify.
Replace the ones that do not. If a machine is five or six years old, spending on it rarely makes sense. Budget the replacement rather than nursing it.
Isolate genuine exceptions. Sometimes a machine cannot move because it drives a specific piece of equipment with no supported alternative. That can be managed — but managed means properly segmented from the rest of the network and off the internet, not simply left alone.
Extended security updates. Available, and a reasonable bridge if a replacement is genuinely scheduled. A poor long-term answer, because you are paying annually to stand still.
Doing it without disruption
Move in small batches rather than all at once, starting with the least critical users so any surprises surface early. Check your key applications on Windows 11 before the machine that runs your business is the one you are testing on. And use the moment sensibly — it is a natural point to tidy up who has local admin rights and what is set to start automatically.
The bottom line
Every month a Windows 10 machine stays in service, it gets a little more exposed. Find out what you still have, upgrade what can be upgraded, budget for what cannot, and properly isolate anything that genuinely has to stay. This is a planning problem, and planning problems get more expensive the longer they are left.
FAQ
Can we just keep using Windows 10 carefully? Careful use does not patch a vulnerability. Antivirus and good habits help, but they do not substitute for security updates that are no longer being written.
How do we know if a machine can run Windows 11? It comes down to processor generation, memory, and whether TPM 2.0 is present and enabled. It is worth checking properly rather than assuming — TPM is sometimes present but switched off in firmware.
Does this affect Cyber Essentials? Yes. Unsupported software in scope is a common reason for failing assessment, so it is worth resolving before you certify or renew.


