Microsoft stopped supporting Windows 10 on October 14, 2025. If your business is still running it, and plenty are, those computers aren’t getting security updates anymore. Everything still turns on and works normally, which is exactly why it’s easy to put off doing anything about it. The problem is that every day you stay on Windows 10, more security holes pile up that nobody is ever going to fix.
What “End of Support” Actually Means
When Microsoft ends support for a version of Windows, the updates stop, including the monthly security patches that fix newly discovered flaws.
Your PCs don’t stop working the day support ends. Nothing switches off. What’s different is that Microsoft has stopped fixing Windows 10’s security problems. Attackers and researchers keep finding new ones, and now nobody is patching them. Every new flaw that surfaces is a permanent way in.
Why This Is a Real Risk, Not Just an Old Computer Problem
Unsupported systems are an easy target specifically because attackers know the flaws will sit there indefinitely. The UK’s National Cyber Security Centre has noted that holes in unsupported products stay exploitable, often by fairly low-skilled attackers, because there’s no race against a patch.
If you handle card payments, health records, or personal data, standards like PCI DSS and HIPAA generally expect supported, patched software. Windows 10 no longer qualifies, which can put you out of compliance without anyone realizing it happened.
It can also hit your cyber insurance. Insurers increasingly ask whether your systems are supported and patched. Running an unsupported operating system can raise your premium, shrink your coverage, or give an insurer grounds to contest a claim after the fact.
And it’s not just Microsoft. Over time, browsers, accounting software, and other tools you depend on daily will drop Windows 10 support too, so the apps you rely on start failing quietly, one at a time.
Law firms and medical practices tend to feel this first. Both handle the kind of client data that draws closer scrutiny at insurance renewal and, for firms in Florida, ties back to the Bar’s competence standard around technology. An outdated OS sitting on a paralegal’s desktop is exactly the kind of gap an auditor or a claims adjuster is trained to look for.
Your Three Real Options
Most businesses end up mixing all three across their fleet.
Upgrade to Windows 11 for free, if the hardware qualifies. If the PC is a few years old, this is usually the right move. The catch is hardware: Windows 11 requires a supported processor, TPM 2.0, and Secure Boot, which rules out a fair number of older machines. Microsoft’s free PC Health Check app tells you whether a specific machine qualifies.
Buy Extended Security Updates (ESU) as a bridge. For businesses, that’s $61 per device the first year, doubling annually for up to three years, roughly $427 per device total if you ride it out the whole time. ESU buys you security patches only, no new features, no real support. It’s a stopgap while you plan the actual move.
Replace machines that are too old to upgrade. Some hardware just isn’t worth the ESU fees year after year. Once you add up what you’d pay to keep an old machine patched, a new PC that ships with Windows 11 is often the cheaper path.
How to Plan the Move Without It Becoming a Fire Drill
Start with an inventory: every computer still on Windows 10. Then check which ones qualify for Windows 11 using the PC Health Check tool. Upgrade the ones that qualify first; it’s free and keeps files and programs in place. For the rest, decide between ESU and replacement based on age and how critical the machine is.
We run this kind of inventory for clients regularly, and it usually takes less time than people expect to get a clear picture of what’s actually at risk. If you’re not sure how many machines in your environment are still on Windows 10, that’s worth finding out before it becomes a compliance question or an insurance one.