Microsoft ended support for Windows 10 on October 14, 2025. On October 15, nothing happened. The machines booted, email opened, the label printer printed. That is exactly why so many small businesses still have Windows 10 in the building almost a year later — the deadline came with no visible consequence, and the urgent thing that week was something else.

I still find Windows 10 on a lot of site visits, and I do not think the people running it are careless. I think they were told “this is a serious deadline” and then watched nothing break, which is a reasonable reason to stop worrying. So let us skip the countdown-clock treatment and talk about what actually changed, what your realistic options are, and how to deal with it without an emergency purchase order.

What “No More Security Updates” Actually Means

The operating system did not lose any features. What it lost was the monthly repair service.

Every month, Microsoft publishes fixes for newly discovered flaws in Windows. Those flaws mostly existed in Windows 10 too — the two systems share an enormous amount of code. Windows 11 gets the fix. Windows 10 does not, unless you have paid for Extended Security Updates — more on that below.

The part people miss is that the monthly update is also a public disclosure. Security researchers and attackers alike compare the patched code with the unpatched code to work out precisely what was wrong and how to exploit it. So each Patch Tuesday effectively hands out a map of freshly confirmed weaknesses that will never be repaired on your Windows 10 machines. The gap does not stay the same size. It widens every month, and it has been widening since October 2025.

There is a second, slower problem: the rest of the software ecosystem follows. Browsers, security tools, VPN clients, accounting packages, and hardware drivers all eventually stop testing against an unsupported operating system. You will not get a warning. You will get a vendor support ticket that ends with “we no longer support that OS,” usually on the day you most need help.

None of this means a Windows 10 machine is compromised today. It means the odds move against you steadily, and the machines that matter most — the ones with email, banking, patient records, or administrative rights — are where that math gets uncomfortable first.

Extended Security Updates: The Paid Stopgap

Microsoft offers Extended Security Updates, usually shortened to ESU. It is worth understanding precisely, because it is frequently oversold in both directions.

What it is. Paid delivery of security fixes rated critical and important for Windows 10, for a limited number of years after end of support. There are separate tracks for consumers and for businesses, each with its own duration and enrollment process.

What it is not. It is not general support. No new features, no non-security bug fixes, no help desk coverage for the operating system itself, and no obligation on third-party vendors to keep supporting you. Business licensing is per device, renewed annually, and priced to escalate each year on purpose. Microsoft designed it as an exit ramp, not a parking space.

Check Microsoft’s current lifecycle and licensing pages for exact end dates and terms rather than trusting a number in a blog post, including ours — those dates and the enrollment mechanics have shifted more than once. The same goes for how long Microsoft 365 Apps will keep receiving security updates on Windows 10, which is a separate lifecycle from the operating system.

When it makes sense. ESU is the right answer for a specific, documented set of machines: a workstation attached to a piece of equipment whose vendor has not certified Windows 11, a line-of-business application in the middle of a replacement project, a device with a long procurement lead time. Buy it for those, with a replacement date written down. It is the wrong answer as a company-wide decision to stay put, because you will pay a rising annual fee for a shrinking benefit and still have the migration in front of you.

Why Compliance and Insurance Care

No regulation says “you must run Windows 11.” They say things that amount to the same thing.

In every one of those cases, the difference between a finding and a footnote is documentation. “We have four machines on Windows 10, here is why, here is the compensating control, here is the replacement date” is a defensible position. “We are not sure how many we have” is not.

Step One: Find Out What You Actually Have

Almost every business I ask underestimates this count, because the forgotten machines are exactly the ones nobody uses daily — the computer running the time clock, the one in the back that drives a scanner, the spare in the conference room, the laptop a former employee returned.

If you have a managed IT provider, this is a report they can produce in an afternoon; continuous device inventory is part of what real 24/7 monitoring is for. If you are doing it yourself, walk the building and record, for every Windows device:

That last column is the one that sets your order of operations.

Step Two: Sort Into Four Piles

Upgrade in place. Machines that meet the Windows 11 requirements and have enough life left. Frequently larger than expected: on a lot of business-class hardware the TPM is present but disabled in firmware, or Secure Boot was never turned on, and both are quick fixes. Take a backup first, do a handful before you do the fleet, and expect a couple of hours of user grumbling about the new Start menu.

Replace. Machines that cannot meet the processor requirement, or that are old enough that spending money on them is throwing good after bad. Replace, do not upgrade, anything with a mechanical hard drive or under 8 GB of memory.

Isolate. The genuine special cases — a workstation controlling equipment whose vendor will not certify Windows 11, a medical or lab device with an embedded Windows build, a machine running software that no longer has a publisher. These do not need to be replaced this quarter, but they should not sit on the same flat network as everything else either. Put them on a separate VLAN, cut off internet access if they do not need it, block them from browsing and email, restrict which systems they can talk to, and monitor them closely. Compensating controls are a legitimate answer when they are real and documented.

Retire. The ones nobody could name a user for. Wipe them properly and get them out of the building. Every machine you retire is a machine you do not have to license, patch, or explain to an underwriter.

Step Three: Buy Deliberately, Not All at Once

The panic buy is the expensive mistake. Replacing thirty computers in one month means paying whatever is on the shelf, disrupting everyone at once, and repeating the same crunch in five years when they all age out together.

Spread it. Group the replacements by risk and by budget cycle, take the highest-exposure machines first — finance, administrators, anything handling protected data — and fold the rest into a rolling refresh so roughly a fifth to a quarter of your fleet turns over each year. That converts an occasional crisis into a predictable line item, which is the entire argument in IT budgeting for small business.

A few practical notes for the buying itself. Standardize on one or two models so imaging, spare parts, and support stay simple. Buy business-class rather than consumer hardware for the warranty and the manageability. Check your line-of-business applications and attached peripherals against Windows 11 before you order, not after — scanners, label printers, and older signature pads are the usual surprises. And confirm lead times, because “in stock” and “in stock in the configuration you need” are different things.

Meanwhile, do not let the migration become an excuse to neglect the machines still running. Keep them fully patched with whatever updates are still available, make sure they are covered by a monitored EDR platform rather than plain antivirus, and confirm they are included in your backups. An unsupported machine with strong surrounding controls is in far better shape than a supported one with none.

The Short Version

Windows 10 works, and it will keep working. It is also accumulating unfixed security flaws every month, and that fact now shows up in compliance findings and insurance terms as well as in risk. You do not need to panic, and you do not need to replace everything by Friday. You need an accurate list, a sorted plan with dates, ESU only where there is a documented reason, and a budget that spreads the work over the next few quarters. That is a manageable project. Not knowing what you have is what turns it into an emergency.

Related Questions

Is it illegal or unsafe to keep using Windows 10 after end of support?

It is not illegal, and the computer keeps working. What changes is that Microsoft stopped shipping security updates for Windows 10 on October 14, 2025, so newly discovered flaws in the operating system stay open unless you pay for Extended Security Updates. The risk is cumulative rather than immediate. Nothing happened on October 15, but every month since has added another set of vulnerabilities that get fixed in Windows 11 and not in Windows 10. Attackers compare the two and work out what to target. A machine that is unsupported and also handles email, banking, or patient records is the combination worth acting on first.

What are Extended Security Updates and should we buy them?

Extended Security Updates, or ESU, is Microsoft continuing to ship security fixes for Windows 10 for a limited period to customers who enroll. The business track is paid and per device; the consumer track has different terms. It delivers security fixes rated critical and important, and nothing else. No new features, no non-security bug fixes, and no general technical support for the operating system. That licensing is renewed annually, and the price is designed to increase each year so the program pushes you toward migration rather than becoming a permanent home. Buy it as a bridge for machines with a documented reason and a replacement date, not as a decision to stay put. Check the current Microsoft lifecycle and licensing pages for the exact end dates and terms, because both the consumer and business tracks have their own timelines.

Why will my computer not upgrade to Windows 11?

Windows 11 has hardware requirements that many otherwise healthy machines do not meet. The common blockers are a missing or disabled TPM 2.0 security chip, firmware not set to UEFI with Secure Boot enabled, or a processor that is not on the Microsoft supported processor list. Memory and storage minimums catch a few older machines as well. Some of these are fixable in about ten minutes: on plenty of business machines the TPM exists but is turned off in firmware, or the disk is still partitioned in the older style and can be converted. The processor requirement is the one with no supported workaround — unsupported installs exist, but Microsoft does not commit to updating them, which is not a position to put a business machine in. In practice it is machines from roughly 2017 and earlier that fail this check, so the eight-to-ten-year-old computers get replaced rather than upgraded.

How does running Windows 10 affect HIPAA compliance and cyber insurance?

Neither names a specific Windows version, and both effectively assume supported software. The HIPAA Security Rule requires ongoing risk analysis and reasonable safeguards, so an unsupported operating system handling protected health information is something your risk analysis has to identify, document, and either remediate or mitigate with compensating controls. PCI DSS expects system components to be patched against known vulnerabilities and requires a documented plan for technology that has reached end of life. Cyber insurance questionnaires now ask directly whether you run unsupported operating systems, and a yes can draw a higher rate, an exclusion, or a declination. In all three cases the workable answer is the same: know exactly which machines they are, have a dated plan, and keep the evidence.

Not Sure How Many Windows 10 Machines You Still Have?

We will inventory every Windows device in your environment, tell you which can be upgraded in place, which need replacing, and which need to be isolated — and give you a dated plan you can budget against instead of a sales pitch.

Request a Device Inventory (888) 735-7701