Cybersecurity

Still running Windows 10? Here's what end of support actually means

Windows 10 end of support: what changes, ESU pricing, and whether your hardware can run Windows 11

The date on the calendar was 14 October 2025. That's when Microsoft switched off free security updates for Windows 10, and if your office still has machines running it, nothing broke that day. The desktop looked the same. Outlook opened, the printer worked, nobody got a pop-up saying “everything's fine.” That's exactly what makes this dangerous: the risk is invisible until something finds it.

This is what “end of support” actually means, what your realistic options are now, and why the honest answer for most small businesses is “you need a plan this quarter, not this decade.”

What "end of support" actually changes

Microsoft still lets Windows 10 run. It just stops fixing it. No more monthly security patches, no more fixes for newly discovered flaws, no feature updates, and if you ring Microsoft with a Windows 10 problem, official support won't touch it. Every week that passes after 14 October 2025, researchers and attackers keep finding new holes in Windows 10's code. Microsoft already knows about them from patching Windows 11. It just isn't fixing the Windows 10 side any more.

Your antivirus still runs. Your firewall still works. Neither of those patches the operating system underneath them, and an unpatched OS is the one thing that lets malware get from "email attachment someone clicked" to "everything on the network encrypted." The lock on the front door still turns. Nobody's replacing the frame around it when it rots.

StatCounter's browser-share data put Windows 10 at roughly a quarter of the world's desktops as of June 2026, eight months after end of support. You are nowhere near the only business still working through this.

The paid bridge: Extended Security Updates

Microsoft does offer a way to buy time, called ESU (Extended Security Updates). For businesses, it's $61 per device for the first year (via volume licensing, running from November 2025), doubling to $122 for year two and $244 for year three, and you can't buy year two without having paid for year one. It's cumulative, not optional per year. Three years is the maximum. After that, ESU stops too, no matter what you pay.

For home users it's cheaper and shorter: one year of consumer ESU only, covering through October 2027, either free if you're syncing PC settings to a Microsoft account, free for 1,000 Microsoft Rewards points, or a one-off payment of $30 USD (or the local equivalent) plus tax. There's no three-year consumer option. It buys twelve months, not three years.

ESU only covers critical and important security patches. No new features, no general technical support, no fixes for anything Microsoft decides isn't a security issue. It's scaffolding around a condemned building, not a renovation. Useful if you need six months to plan a proper rollout. Not a strategy on its own.

Why this matters for compliance, not just security

If your business holds Cyber Essentials certification, or is working toward it, this bites hard. Under the current Cyber Essentials scheme, running an unsupported operating system is treated as an automatic fail if even one in-scope device is found running it. It isn't a point deduction. It just fails the assessment outright. Some assessors are willing to treat ESU as a temporary bridge while a genuine upgrade plan is underway. Nobody treats it as a permanent fix. We should say plainly here: Alpha IT does not hold Cyber Essentials certification ourselves. If you need it for a specific tender or client requirement, that's worth raising with an accredited certification body directly, not assuming ESU quietly solves it.

UK GDPR requires "appropriate technical measures" to protect personal data, and an operating system with known, unpatched vulnerabilities is a hard thing to defend as appropriate. This isn't theoretical. The ICO fined DSG Retail Limited (the company behind Currys PC World and Dixons Travel) £500,000 after malware sat on thousands of point-of-sale terminals running out-of-date software for nine months before anyone noticed. In February 2026, the Court of Appeal upheld that fine, rejecting DSG's argument that the ICO had overstepped. Unsupported software was one of the specific failings named in the ruling. That's not a small business, obviously. The principle the ICO applied doesn't have a size threshold.

Cyber insurance is the other one that catches people out

Read your policy wording, not the marketing page. A growing number of UK cyber insurance policies now require that software on covered systems be currently supported by its manufacturer, as a condition of the policy rather than a suggestion. If an insurer can show the breach came in through an unsupported, unpatched Windows 10 machine, that's grounds to reduce a payout or refuse the claim entirely. You find this out during a claim, which is the worst possible time to find it out. If you're not certain what your policy says on this, it's worth a five-minute call to your broker this week rather than after something's happened.

Can your existing hardware even run Windows 11?

This is where a lot of businesses get stuck, and it's a fair complaint: plenty of perfectly good three or four-year-old machines fail the Windows 11 compatibility check. The two requirements that trip people up are TPM 2.0 and Secure Boot.

TPM stands for Trusted Platform Module, a small security chip (or a firmware equivalent built into the CPU, which Intel calls PTT and AMD calls fTPM) that handles encryption keys and secure boot verification. Windows 11 requires TPM version 2.0 specifically, and Microsoft has been explicit and repeated about this being non-negotiable for future Windows versions, not a preference they might soften. Most PCs built since around 2016-2017 have a TPM 2.0 chip on the motherboard, but it's very often shipped disabled in the BIOS/UEFI settings by default. Worth checking before you assume a machine is a write-off. Press Windows key + R, type tpm.msc, and see what it reports. Sometimes the fix is a five-minute BIOS setting, not a new PC.

Beyond TPM, Windows 11 also wants a supported CPU from Microsoft's approved list (broadly, 8th-generation Intel Core or newer, AMD Ryzen 2000-series or newer), UEFI firmware with Secure Boot capability, and 4GB of RAM minimum, though we'd want to see considerably more than that in practice for anything beyond the lightest use. If a machine fails on CPU generation and not just a disabled TPM setting, no BIOS toggle fixes that. That one's a genuine hardware decision, not a software one.

Realistic migration paths, in order of how much they cost

Check compatibility first, always. Settings > Update & Security > Windows Update on a Windows 10 machine will usually offer a PC Health Check tool, or you can download it directly from Microsoft, and it tells you plainly whether a given machine passes or fails and, often, exactly why.

If it passes: an in-place upgrade to Windows 11 is free, and for most standard business machines it takes an afternoon per device, done in the background while people keep working, with a restart at the end. This is the cheapest route by a distance, and it's the first thing worth checking before spending anything.

If a BIOS setting is the only blocker: enable TPM 2.0 and Secure Boot in firmware settings, confirm the PC Health Check tool now passes, then upgrade. Slightly more fiddly than a straight upgrade. Still free.

If the hardware genuinely fails: budget for replacement. This is the expensive option and there's no way round that honestly, but staggering it machine-by-machine over two or three quarters, oldest first, spreads the cost a lot better than one panicked bulk order in September. If you've got machines that are five-plus years old anyway, this is probably due regardless of Windows 10.

If you need more runway before any of the above: ESU buys time, at the pricing above, while you plan the rest properly. Treat it as a deadline extension you're paying for, not a solution.

What to actually do this month

Get an inventory. If you don't already know exactly how many machines in your business are still on Windows 10, that's the first job, not the last one. A spreadsheet with each device, its age, and a pass/fail against the Windows 11 compatibility check tells you the real size of the problem in under an hour for most small offices.

Then triage: which machines pass today, which pass with a BIOS change, and which need replacing. That split usually turns what feels like an overwhelming project into three separate, much smaller ones.

Where we come in

This is exactly the kind of audit our health check covers: a full inventory of what's running Windows 10, which machines pass the Windows 11 check as-is, which need a BIOS setting changed, and which genuinely need replacing, with a straight answer on each rather than a sales pitch dressed up as one. The Professional plan on our pricing page includes managed patching, so once you're on Windows 11 the "did October's updates actually install" question stops being something anyone in your office has to remember to check. If ransomware getting in through an unpatched machine is the scenario you're actually worried about, our first-hour ransomware guide covers what happens if it does.

We don't hold Cyber Essentials ourselves, so if compliance for a specific tender is what's driving this, we'll say so plainly and point you toward an accredited certification body rather than imply our plans cover that box on their own. Our plain-English Cyber Essentials guide is a reasonable place to start if you haven't looked at the five controls before. What we can do is get the technical side sorted so that box is easier to tick when you do go for it.

The short version

Windows 10 stopped getting security patches on 14 October 2025. It still runs, it just isn't protected any more, and neither Cyber Essentials nor most cyber insurance policies treat "still runs" as good enough. ESU buys limited time at a rising price, not a permanent fix. Check whether your machines pass the Windows 11 compatibility test before assuming you need new hardware; a lot of "failures" are just a disabled TPM setting. If you don't know where your business stands on this, that's worth finding out this month rather than after something goes wrong.

Frequently asked questions

Is Windows 10 going to stop working now that support has ended?+

No. That's the confusing part. Nothing switches off, no banner forces the issue, and most people notice nothing different day to day. What's changed is invisible: Microsoft stopped releasing the monthly patches that close newly found holes in the code.

What do we actually lose without security updates?+

Mainly the fixes for vulnerabilities discovered after 14 October 2025. Security researchers and criminal groups both keep looking for weaknesses in Windows code, and Microsoft keeps finding and patching them in Windows 11. Those same weaknesses often exist in Windows 10 too, but nobody's fixing that side any more. Over time the gap between “what's been found” and “what's been patched” only grows, and an unpatched operating system is one of the most common ways ransomware and other malware get a foothold in a network.

Can we just buy Extended Security Updates and carry on as we are?+

For a limited period, yes. Business ESU costs $61 per device for year one, rising to $122 for year two and $244 for year three, and you have to buy the years in order; you can't skip straight to year three without paying for the earlier ones. It only covers critical and important security patches, not new features or general support, and after three years it stops regardless of what you're willing to pay. Treat it as bought time to plan a proper move, not a long-term answer.

Will our existing computers even run Windows 11?+

Some will, some won't, and you often can't tell without checking. The two requirements that catch people out are TPM 2.0 (a security chip, sometimes present but switched off in BIOS settings) and a supported processor generation. Microsoft's free PC Health Check tool tells you plainly, per machine, whether it passes and roughly why if it doesn't. Quite a few “failures” turn out to be a disabled TPM setting rather than genuinely incompatible hardware, and that's worth ruling out before assuming you need new kit.

Does this affect our Cyber Essentials certification?+

It can, seriously. Cyber Essentials treats an unsupported operating system as an automatic fail for any in-scope device, not a minor deduction. ESU can bridge the gap while you're actively upgrading. Assessors don't treat it as a permanent fix, though. We should be upfront that Alpha IT doesn't hold Cyber Essentials certification ourselves, so if this is for a specific tender or client requirement, speak to an accredited certification body about exactly what they'll accept.

Would running Windows 10 actually affect a cyber insurance claim?+

It could, and it's worth checking your policy wording rather than assuming. A growing number of UK cyber insurance policies now require covered systems to run software that's still supported by its manufacturer. If a breach can be traced to an unsupported, unpatched machine, insurers have grounds to reduce or refuse a payout. That's a conversation worth having with your broker before there's a claim to make, not during one.

What's the cheapest realistic way to sort this for a small office?+

Start by checking which machines pass the Windows 11 compatibility test as they are. Those upgrades are free and usually take an afternoon each. For machines that fail only because TPM is switched off in the BIOS, that's also a free fix once you've found it. Genuine hardware failures need replacing, and staggering that over two or three quarters, oldest machines first, spreads the cost far better than replacing everything in one go before a deadline.

Can Alpha IT help us work out where we stand?+

Yes. Our health check gives you a straight inventory: what's running Windows 10, what passes the Windows 11 check today, what needs a BIOS change, and what genuinely needs new hardware. No upsell attached to the answer. If patching and updates are the bit you'd rather not track yourselves once you're on Windows 11, that's what the managed plans on the pricing page are for.

Call usFree consultation