
Windows 10 support has ended. Every unpatched fleet is now an insurance and compliance problem.
Start With Facts
The first question isn't "when do we upgrade" - it's "what can actually be upgraded." TPM 2.0, Secure Boot and CPU generation requirements mean a meaningful share of otherwise healthy machines can't run Windows 11 in place.
We inventory the fleet and split it three ways: upgrade in place, needs a firmware or setting change first, and replace. You get a per-machine list with age, user and cost so the budget conversation is grounded in real numbers instead of a vendor's refresh cycle.
Rollout
We pilot with a small representative group first - including anyone using older line-of-business or lab software - and verify printing, VPN, MFA, drivers and peripherals before touching the wider company.
Then we roll out in waves during off-hours, with a documented rollback for each phase and a support window staffed to catch the small annoyances that follow any OS change. Users get a short heads-up on what visibly changes, so the help desk isn't flooded with "where did the Start menu go."
Risk
Unsupported operating systems stop receiving security patches, which is exactly the gap ransomware operators shop for. Cyber insurance renewals and enterprise security questionnaires increasingly ask directly about supported-OS percentage, and a bad answer costs money or deals.
If replacement hardware is required, our laptop provisioning service handles imaging, encryption, enrollment and direct-to-employee shipping - so the refresh doesn't turn into a logistics project for your office manager.