Still on Windows 10? The Real Cost of Running Past End of Support
Windows 10 reached end of support in October 2025. Here is what that means for compliance, cyber insurance, and your budget, and how to plan the move sensibly.
Windows 10 reached end of support on October 14, 2025. If some of your machines are still running it, they are not broken and they have not stopped working. That is exactly why the risk is easy to ignore. The problem is quieter than a failure. It is the slow accumulation of exposure that shows up when a regulator, an auditor, or a cyber insurer starts asking questions.
For businesses in healthcare, finance, legal, and defense supply chains, an unsupported operating system is not a minor line item. It is a governance issue that touches compliance, insurability, and budget all at once. Here is how to think about it clearly.
What end of support actually changes
After the end-of-support date, Microsoft no longer ships routine security updates for Windows 10 through the normal channel. The software keeps running, but newly discovered vulnerabilities stop getting patched. Extended Security Updates, or ESU, are available for a limited time at added cost, and that cost is designed to rise over time to encourage migration rather than indefinite delay.
In other words, staying put is a paid decision now, not a free one. The question is whether you are paying deliberately to buy migration time, or paying by accident because no one has scheduled the work.
Why auditors and insurers care
Running an unsupported operating system is one of the most common findings in a security review, and it is one of the easiest to document against you. Regulators increasingly expect organizations to run supported, patchable software as a baseline expectation of reasonable care.
- Compliance frameworks generally treat unsupported software as a control gap that must be remediated or formally risk-accepted.
- Cyber insurance applications frequently ask whether all systems are supported and patched, and an inaccurate answer can jeopardize a future claim.
- An unpatched endpoint is a realistic entry point, and incident responders will note it in any post-breach analysis.
The true cost of standing still
When teams compare the cost of new hardware against the cost of doing nothing, they often forget that doing nothing is not actually free. ESU fees are real and climb over time. The staff hours spent nursing aging machines are real. And the potential cost of a denied insurance claim or a compliance finding dwarfs the price of a planned refresh.
The honest comparison is not new laptops versus zero. It is a planned, budgeted transition versus a growing, open-ended liability.
Refresh the hardware or upgrade in place
For each device, there are really two paths. You either upgrade the existing machine to a supported version of Windows, or you replace the hardware. The right choice depends on whether the device meets current hardware requirements and how much useful life it has left.
- Upgrade in place when the hardware is eligible, recent, and still fits the role it serves.
- Refresh the hardware when a machine cannot meet requirements, is near end of life, or has become slow enough to cost you productivity.
- Treat any device that holds or accesses regulated data as a priority, regardless of its age.
A practical plan for this quarter
Start with an inventory. You cannot plan a migration you have not measured. Identify every machine still on Windows 10, note whether it is upgrade-eligible, and flag the ones that touch sensitive data. That list becomes your migration schedule and your budget request in a single document.
From there, sequence the work in waves rather than all at once, use ESU only as a deliberate bridge for the machines you cannot move immediately, and set a firm target date to be fully off Windows 10. A managed services partner can help you sequence this work so the migration lands on your timeline instead of an attacker's. The goal is simple: turn an open-ended risk into a finite, funded project.