Windows 10 reached end of support on 14 October 2025. Nearly a year on, plenty of UK businesses still have machines running it, usually for one of three reasons: the hardware will not take Windows 11, an application will not run on it, or nobody got round to it.
Here is what that actually means and what the realistic options are.
What end of support means in practice
The machine keeps working. Nothing switches off. That is precisely why this gets deprioritised.
What stops is security updates. Vulnerabilities discovered from that date onward are not fixed, and they accumulate. Attackers pay close attention to unsupported operating systems for exactly this reason — the window never closes, so an exploit written today still works next year.
The consequences beyond security
Three that businesses meet before they meet an attacker.
Cyber Essentials. Unsupported software is an automatic failure. One Windows 10 machine fails the whole certification, which increasingly matters commercially as covered in this article on supply chain requirements.
Client security requirements. Security questionnaires ask whether all systems are supported. Answering honestly loses work; answering otherwise is a misrepresentation in a contractual document.
Cyber insurance. Many policies require systems to be supported and patched. A claim arising from an unsupported machine is exactly the claim an insurer will examine closely, and businesses have found their cover was not what they assumed.
The risk that actually materialises first is rarely the breach. It is a client questionnaire you cannot answer or an insurance claim that is queried.
Option 1: upgrade the machines that can take it
Windows 11 requires TPM 2.0, Secure Boot and a supported processor generation. Machines bought from roughly 2018 onwards generally qualify; earlier ones generally do not.
Check properly rather than assuming — some machines have TPM available but disabled in firmware, which is a setting rather than a limitation and that alone rescues a proportion of an estate.
Workarounds exist to install Windows 11 on unsupported hardware. Do not use them in a business. They leave you in an unsupported state, they may not receive updates and they fail certification exactly as before.
Option 2: Extended Security Updates
Microsoft's paid programme provides critical security updates beyond end of support, sold annually with the price increasing each year to discourage indefinite use.
It is a legitimate bridge for machines that genuinely cannot be replaced this quarter. It is not a strategy — the cost rises deliberately, and it does not restore the machine to a supported state for certification purposes.
Use it to buy time for a planned replacement, with the replacement actually planned.
Option 3: replace
For most business machines this is the right answer, and it is worth being honest about the arithmetic. A machine from 2017 is at the end of its useful life regardless of the operating system. It is slower, its battery is finished, its drive is aging, and it is generating support calls.
The replacement cost is real and the alternative is an unsupported machine that costs you a certification, a questionnaire answer and an unknown amount of support time.
Option 4: isolate
For the genuinely stuck case — a machine tied to software that will not run on Windows 11, controlling equipment that cannot be replaced.
Isolate it properly:
- Separate network segment with no route to the internet
- No email, no browsing, no access to shared file storage
- Restricted physical access and a documented exception
- A dated plan for replacing the application it exists to run
Isolation is a legitimate control and assessors accept it when it is genuine. It has to be actual isolation rather than an intention.
What to do this month
- Inventory every machine and its operating system version. You cannot plan without this and most businesses do not have it.
- Check Windows 11 eligibility for each, including whether TPM is merely disabled rather than absent.
- Sort into three groups: upgrade, replace, isolate.
- Budget the replacements over two or three quarters rather than all at once.
- Document the exceptions with the control applied and the planned end date.
Do not repeat it
The reason this became urgent is that nobody was tracking machine age against support dates. Keep an asset register with purchase date, warranty end and operating system support end and review it quarterly.
A three or four year replacement cycle, budgeted as an ongoing cost rather than an occasional crisis, is both cheaper and considerably less stressful than a scramble every few years. That register is part of what a proper system maintenance service should be giving you.
If you would like your estate audited and a costed replacement plan, get in touch — the audit itself usually takes a day and gives you something you can actually budget against.








