Microsoft ended support for Windows 10 in October 2025. If your business is still running it — and many are — every day that passes is one more day your systems are exposed. Here's what that actually means and what your real options are.
Let's be direct: Windows 10 reached end of life on October 14, 2025. That date came and went, and Microsoft stopped issuing security patches for it. If you're still running Windows 10 machines in your business — and based on what we see in the field, a lot of small businesses are — you now have an unpatched operating system handling your business data.
We're not here to scare you. But we are here to be honest with you, because there's a lot of "it's probably fine" thinking happening right now, and it's going to cause real pain for some businesses over the next year or two. Running an unpatched OS is a known, measurable risk — not a theoretical one.
The good news is that you have options. Some are cheaper than you think. Some aren't cheap at all. And one of them — just leaving it alone — is the option that gets businesses into serious trouble. Let's walk through all of them so you can make an informed decision for your situation.
Every month, Microsoft releases security patches for supported versions of Windows. These patches fix vulnerabilities — holes in the operating system that attackers can use to get in. When Windows 10 went end-of-life, those monthly patches stopped. The known vulnerabilities from before October 2025 don't go away; they just never get fixed. And new vulnerabilities that get discovered going forward will never be patched either.
Here's the part that gets missed in a lot of the "end of life" coverage: attackers pay close attention to end-of-life dates. When a major OS goes out of support, they study the patches that Microsoft releases for still-supported systems, figure out which of those vulnerabilities also exist in the older OS, and start exploiting them. It's called "patch Tuesday, exploit Wednesday" — and it's a well-documented pattern.
This is exactly what happened with Windows XP after its 2014 end-of-life, and with Windows 7 after its 2020 end-of-life. Businesses that held on found themselves dealing with ransomware and breaches at higher rates than businesses that had upgraded. The same dynamic is now playing out with Windows 10.
Beyond the security risk, there's a compliance angle too. If your business is subject to any data security requirements — PCI-DSS if you process card payments, HIPAA if you handle health information, state privacy regulations — running unsupported software can create a compliance problem. Insurance companies are also starting to ask about patch status and supported OS versions when assessing cyber insurance applications. Running end-of-life software can affect your coverage. (More on that in our cybersecurity guide.)
Before you can make a plan, you need to know how many Windows 10 machines you have and what hardware they're running on. This sounds basic, but we've walked into businesses where nobody had a complete list of their computers. If that's you, no judgment — let's fix that first.
On any Windows machine, you can check the OS version by going to Settings → System → About. The "Edition" and "Version" fields tell you what you're on. Windows 10 is still Windows 10 regardless of the version number (like 22H2, which was the last feature release).
More importantly, check the hardware specs on each machine — specifically the processor and TPM (Trusted Platform Module) version. Windows 11 has strict hardware requirements that Windows 10 didn't have, and that's the thing that's forcing a lot of businesses into hardware replacement conversations they weren't expecting.
Windows 11 requires:
A lot of machines from 2017 and earlier fail the processor or TPM requirement. Microsoft created a free tool called the PC Health Check app that tells you definitively whether a specific machine can run Windows 11. Running it on every machine in your office is the right first step.
For machines that meet the hardware requirements, upgrading to Windows 11 is the cleanest path forward. It's supported through at least 2031. The upgrade itself is free — Microsoft still allows free upgrades from Windows 10 to Windows 11 as of this writing. Your applications, files, and settings come along for the ride.
That said, "free upgrade" doesn't mean "no cost." There's still time involved in doing it right. You want to make sure you have a working backup before you upgrade (always). You want to test that your line-of-business applications work correctly on Windows 11 before you roll it out company-wide. And you want to give employees a heads-up so they're not surprised by the interface changes.
The upgrade process itself is relatively painless on qualifying hardware. It typically takes an hour or so and you end up with a clean, supported operating system. For businesses with a mix of qualifying and non-qualifying machines, this is usually the best approach for the machines that can take it — upgrade those now and plan for the others separately.
One thing worth knowing: Windows 11 has different hardware requirements partly because Microsoft built in stronger security at the hardware level. TPM 2.0 is required because Windows 11 uses it for features like Secure Boot and BitLocker encryption in ways that Windows 10 didn't enforce as strictly. So machines that run Windows 11 are genuinely more secure by default — not just nominally "supported."
If your machines don't qualify for Windows 11, you're looking at replacing them. For a lot of business owners, this triggers immediate sticker shock. But let's put some numbers on it before you panic.
A solid business-class desktop PC from Lenovo, HP, or Dell — not a consumer machine, a real business machine with a warranty and driver support — runs anywhere from $600 to $1,000 depending on specs. Laptops are typically $800 to $1,400 for something genuinely business-grade. These aren't glamorous numbers, but they're not catastrophic either for machines you'll use for five to seven years.
Here's the thing to keep in mind: if your machine can't run Windows 11, it's almost certainly old enough that it's a liability in other ways too. Hard drives fail more often as they age. Batteries degrade. Motherboards develop intermittent issues. You're probably already spending time and money nursing it along. Replacing it with a machine that comes with a hardware warranty and a supported OS is often the financially smarter move when you factor in the real total cost of ownership.
We talk about the real math on hardware aging in our post about the most expensive IT mistakes small businesses make. Running hardware past its useful life almost always costs more than replacing it on a sensible schedule.
If budget is tight, there's also a middle path: certified refurbished business-class hardware. You can often find recent-generation Lenovo ThinkCentres or HP EliteDesks for $300–$500 with Windows 11 already installed and a 90-day to one-year warranty. Not as glamorous as new, but it gets you off Windows 10 without a four-figure outlay per seat.
Microsoft offers something called Extended Security Updates (ESU) for Windows 10, which extends security patching through October 2028 — three additional years. This isn't free: it costs $61 per device for the first year, $122 per device for the second year, and $244 per device for the third year. (Business pricing as of this writing — verify current pricing with Microsoft or your IT provider.)
So for a business with 20 machines, you're looking at $1,220 for year one, $2,440 for year two, and $4,880 for year three — just to stay patched. By year three, you've spent nearly $8,500 in ESU fees alone on 20 machines. You could have bought a lot of replacement hardware for that.
ESU makes sense in specific situations: you have a piece of software that's business-critical and genuinely cannot run on Windows 11 (legacy line-of-business applications are a real thing), or you have a machine that controls specialized equipment and needs to stay on the current OS configuration. In those cases, ESU buys you time to solve the underlying problem without leaving you completely exposed.
What ESU is not is a long-term strategy. It's an expensive bridge that keeps you patched for a few years while you work on a real solution. If you find yourself considering ESU for your entire fleet, that's a signal that your hardware refresh planning needs some attention. We can help you build a technology roadmap that spreads hardware costs over time so you're not facing a big wall of replacement all at once.
There's one more option, and we want to address it directly: doing nothing. Just running Windows 10 without patches, without ESU, and hoping for the best.
Some businesses will do this. The machines will keep working fine for a while — Windows doesn't stop running just because it's out of support. Day to day, nothing obvious changes. And that normalcy makes it easy to keep putting off the decision.
Here's what's actually happening in the background: the attack surface on those machines is growing over time. Every newly discovered vulnerability that gets patched on Windows 11 is a vulnerability that exists — unpatched — on your Windows 10 machines. Attackers keep a running list. They prioritize targets they know are vulnerable. And they're not in a hurry — they wait.
The businesses that get hit with ransomware and data breaches aren't usually doing something dramatically wrong. They're often doing what feels reasonable in the moment: prioritizing today's work over tomorrow's risks. But the consequences when it goes wrong are severe — downtime, data loss, remediation costs that dwarf what the upgrade would have cost. We've seen this play out enough times that we feel obligated to be blunt about it.
Don't do nothing. Make a plan, even if you can't execute it all at once. A plan to upgrade in stages over the next six months beats no plan at all.
Here's a practical framework for working through this:
Run the PC Health Check app on every machine. Divide your inventory into "can upgrade to Windows 11" and "cannot upgrade." That gives you your starting point.
For machines that can upgrade: Schedule the upgrades. Do them in batches. Test your key applications first on a non-critical machine before rolling out to everyone. This should be your near-term focus — there's no reason to delay these.
For machines that can't upgrade: Look at the age and condition of each one. A machine from 2016 that's been running hard for a decade and can't run Windows 11 is probably due for replacement. A machine from 2018 that's been lightly used and is otherwise in great shape might be a candidate for ESU as a bridge while you plan the replacement.
Budget for replacements over time. If you have ten machines that need to be replaced, you don't necessarily have to do them all at once. Replace the oldest and most critical ones first, then work through the rest over the next year or two. Just make sure everything is either on Windows 11 or covered by ESU by the time you get there.
Check your cyber insurance policy. Some policies now have language about running supported software. Confirm that your current setup doesn't create a coverage gap — you don't want to find out at claim time that a breach on an unsupported OS wasn't covered.
If you're not sure where to start, a straightforward IT audit of your environment will tell you exactly what you're dealing with. We offer that as a starting point for new clients — no obligation, just clarity. Check out our IT Buyer's Guide if you're evaluating IT providers and want to know what to look for.
Windows 10 is end-of-life. No more security patches. The risk goes up over time, not all at once.
Your three real options: upgrade to Windows 11 (free if hardware qualifies), replace hardware that can't run Windows 11 ($600–$1,000 per desktop for business-grade), or buy Extended Security Updates ($61+/device/year) as a bridge while you plan.
The option to avoid: doing nothing and running unpatched. That's not a risk worth taking with machines that handle your business data, your customer information, or your financial records.
Start by knowing what you have. Run the PC Health Check app. Make a plan. Execute it in stages if you need to. And if you'd like help thinking through the specifics for your business, that's exactly the kind of thing we help with.