Skip to content

Resource

Windows 10 end of support and hardware refresh

End of support is the easiest risk in IT to defer, because nothing breaks on the day. The machines carry on working and the exposure accumulates invisibly, which is why businesses tend to address it only when an insurer, an auditor or an incident forces the issue.

What it actually affects

The security consequence is the obvious one. The contractual and insurance consequences are the ones that tend to force the decision.

Consequences of running an unsupported operating system
AreaWhen it bites
Security updates stopNewly discovered vulnerabilities are never patched. Exposure compounds over timeImmediate
Cyber insuranceUnsupported operating systems increasingly trigger questions or exclusionsAt renewal
Compliance frameworksSeveral require supported, patchable systems. An unsupported one is a findingAt assessment
Managed agreementsMost providers exclude unsupported systems from coverage, including oursContractual
Software vendorsApplication vendors withdraw support for unsupported platforms on their own timelineGradually
Extended security updatesBuys time at a cost that rises annually. A bridge, not a planPaid option

Building the plan

Six steps, and the first one is the one most businesses cannot complete because the information has never been collected.

  • Inventory every device with its operating system version, age and warranty status
  • Split the list into upgradeable in place, needs replacing, and cannot move because of an application dependency
  • Cost the replacements across two budget years rather than one, if the timeline allows
  • Identify the application dependencies early, because those take longest to resolve and involve a vendor
  • Plan the awkward machines separately, since equipment tied to a device or a legacy application needs a containment answer rather than an upgrade
  • Schedule replacements in batches, so support absorbs them alongside normal work

The machines that cannot move

Every business has one or two: a workstation driving a piece of equipment, a machine running an application the vendor abandoned, a system nobody wants to touch because it works and nobody remembers how it was configured.

These are not upgrade problems, they are containment problems. The answer is a restricted network segment limiting what the machine can reach and what can reach it, no internet access unless genuinely required, and the compensating control written down so it can be shown to an auditor or an insurer.

Treating them as exceptions to be documented rather than as upgrades to be deferred is the difference between a managed risk and an unmanaged one, and the documentation is what makes it the former.

Common questions

Answered before you ask.

What actually happens on the end of support date?

Nothing visible. The machines keep working exactly as before, which is precisely what makes this risk easy to defer. What stops is the supply of security updates, so every vulnerability discovered after that date remains permanently open on those machines. The exposure does not appear as a failure, it accumulates quietly until something exploits it.

Can we just buy extended security updates?

It is available and it is a bridge rather than a destination. The cost typically rises each year deliberately, to make continuing more expensive than moving. It is a reasonable choice for a specific machine with a genuine application dependency that needs another year to resolve. It is an expensive choice for a fleet of ordinary office laptops that could simply be replaced.

Our machines cannot run the newer version. What now?

That is common, because the hardware requirements exclude a lot of otherwise serviceable equipment. The realistic answer for general office machines is replacement, planned across budget cycles rather than executed in a panic. For a specific machine tied to equipment or a legacy application, the answer is containment: isolate it on a restricted network segment, limit what it can reach, and document the compensating control.

How far ahead should we plan a refresh?

End of support dates are published years in advance, which makes being surprised by one a planning failure rather than bad luck. A rolling asset list with ages, warranty status and operating system versions turns this from an event into a line in the annual budget. That list is also the single most useful document to have during any provider transition, and most businesses have never had one.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment