
Windows 10 stopped receiving free security updates in October 2025. Most of the businesses we talk to did not finish their refresh before the deadline — they replaced the obvious machines, bought a year of Extended Security Updates (ESU) for the rest, and moved on. That clock is now running out.
The good news: this is a solvable, budgetable problem. The bad news: "it still works fine" is not a security control.
Why an unsupported endpoint is different
- No patches means permanent exposure. Every new Windows vulnerability disclosed from here forward stays open on that device.
- Your insurer may care more than you do. Unsupported operating systems are showing up as explicit exclusions and questionnaire items on cyber policies.
- Compliance frameworks fail you on it. CMMC, HIPAA and SOC 2 all expect supported, patchable systems.
- Software vendors drop you next. Microsoft 365 apps, browsers, and EDR agents progressively stop supporting the old OS.
Step 1: Get an actual inventory
Not a spreadsheet from 2023. Pull a live report from your RMM tool showing OS version, build, CPU generation, RAM, TPM status, and last-seen date. In almost every audit we run, 10–20% of the "fleet" turns out to be machines nobody uses, and a few turn out to be critical devices nobody knew existed.
Step 2: Sort every device into one of four buckets
- Upgrade in place. 8th-gen Intel or newer with TPM 2.0 and 8GB+ RAM will usually take Windows 11 cleanly. This is your cheapest win — a RAM and SSD bump plus an in-place upgrade often buys two more good years.
- Replace now. Anything used daily by revenue-generating staff that can't run Windows 11. Don't stretch these.
- Isolate and retire on a schedule. The lab PC bolted to a $200,000 instrument, the shop-floor terminal, the machine running the one app the vendor never updated. These get network segmentation, no internet access, no email, and a documented retirement date.
- Decommission today. Anything not logged in for 60+ days. Wipe it, document it, remove it from your license count. This is where you find budget.
Step 3: Stop buying a fleet at once
Buying 40 laptops in one quarter is how you end up with 40 machines aging out in the same quarter four years from now. Move to a rolling replacement — roughly a quarter of the fleet per year — so hardware becomes a predictable operating expense instead of a periodic capital shock. This is the entire premise behind our Laptops-Now lifecycle program.
Step 4: Fix the migration friction before you scale it
The technical upgrade is rarely the painful part. The painful part is local files nobody backed up, printers, line-of-business apps with license keys taped inside a drawer, and the two hours of lost productivity per user. Standardize now: OneDrive Known Folder Move, documented app packages, Autopilot enrollment so a new machine ships straight to the user's desk.
What a realistic timeline looks like
For a 50-person company: two weeks to inventory and bucket, two weeks to pilot the upgrade path on 5 machines, then 6–10 weeks of scheduled batches. Roughly a quarter, done calmly, with no weekend heroics.
Where BITS fits
We do this fleet triage constantly, and we don't push a refresh you don't need — if half your machines can be upgraded in place, we'll tell you that. If you'd like a straight read on where your fleet stands, get in touch and we'll run the inventory with you.


