Why end-of-support software is a real risk, and what to do after Windows 10
When software reaches end of life, vulnerabilities keep being discovered in it. The only thing that changes is that fixes stop arriving. Windows 10 went out of support on October 14, 2025. Exchange Server 2016 and 2019, along with Office 2016 and 2019, fell off the list the same day. SQL Server 2016 ran out on July 14, 2026, and Windows Server 2016 has January 12, 2027 waiting for it. None of those machines shut down on the day. They all kept running, and that is exactly the problem. Patch management cannot fix this class of risk, because there is no patch to apply. What you have instead is either a paid extension you bought some time with, a written migration plan, or an open door that widens a little every month.
The scale is not small. StatCounter's July 2026 figures put Windows 10 at 29.83% of desktop Windows installs worldwide, with Windows 11 at 68.93%. Twenty months after support ended, roughly one machine in three is still on an operating system that no longer receives updates by default. Some of those are covered by a paid ESU subscription. Most are not.
Governments now treat this as its own threat category
On February 5, 2026, CISA, the FBI and the UK's NCSC published a joint fact sheet called "Reducing the Attack Surface for End-of-Support Edge Devices". It describes nation-state actors deliberately targeting end-of-support edge devices (load balancers, firewalls, routers, VPN gateways) to gain initial access, keep a foothold, and reach sensitive data. The same day, CISA issued Binding Operational Directive 26-02 to US federal agencies: identify unsupported edge devices within three months, start removing them within twelve, finish within eighteen. The reasoning in the text is blunt. Unsupported devices should not remain on enterprise networks.
That directive binds federal agencies, not you. What it tells you is where threat intelligence is currently pointing, and attackers pick targets by version number rather than by organisation type.
What is actually on the calendar
In a typical SME environment, these are the items that have already expired or are about to:
- Windows 10: October 14, 2025. Extendable through ESU.
- Exchange Server 2016 and 2019: October 14, 2025. Replaced by Exchange Server SE or cloud mail.
- Office 2016 and Office 2019: October 14, 2025. No ESU program at all for these two. There is no extension to buy.
- SQL Server 2016: July 14, 2026. ESU runs for a maximum of three years.
- Windows Server 2016: January 12, 2027. Less than a year left to plan.
- Windows Server 2012 and 2012 R2: expired back in 2023, and still very much in the field.
When you build this list for your own environment, don't stop at operating systems. The PHP or Node.js version under your web application, the database client your ERP depends on, the Android build on the warehouse barcode terminals, the firmware on the NAS in the meeting room: they all belong on the same sheet.
Why "it still works" is a bad measure
Nothing happens on the end-of-support date itself. The risk accumulates over the following months, and it accumulates at an accelerating rate. The mechanism is straightforward. A vulnerability gets found, the vendor ships a patch for the supported version, and researchers and attackers alike reverse-engineer that patch to locate the exact flaw. If the same code sits in the version that no longer gets updates, you now have a hole everyone knows about and only one side can close. For an unsupported release, a published patch works as a set of instructions.
The second problem is compatibility. A server past end of support gradually stops accepting new EDR agents, new backup clients, new TLS libraries. So an ageing system doesn't only collect vulnerabilities. The defensive options you could layer on top of it close off one by one.
What ESU is, and what it is not
Extended Security Updates for Windows 10 are sold to organisations through volume licensing at $61 per device for year one, and the price doubles every consecutive year, for a maximum of three years. The program is cumulative: if you decide to join in year two, you pay for year one as well. Technical support is not included. You receive critical and important security updates only. No new features, no non-security bug fixes.
Three years works out to 61 + 122 + 244 = $427 per device. Put that number next to the price of a new business workstation and the decision usually makes itself. ESU is a bridge, not a destination.
Consumers get a different deal: the consumer ESU program runs through October 12, 2027, and you can enrol free by syncing your PC settings, by redeeming 1,000 Microsoft Rewards points, or with a one-time $30 payment. That route does not apply to company-managed devices.
One more point causes regular confusion. Microsoft 365 apps on Windows 10 keep receiving security updates until October 10, 2028, and Defender security intelligence updates continue at least that long. Those keep Office and your malware definitions current. They do nothing about a flaw in the operating system kernel. "Defender is still updating, so Windows must be fine" is not a valid conclusion.
The hardware barrier is real
Windows 11 requires TPM 2.0 and a supported processor, in practice Intel's 8th generation or newer. Microsoft has repeated more than once that it will not relax this. Two situations show up in the field. On some machines the TPM chip is physically present but disabled in BIOS, and those are recoverable in a few minutes. On others it genuinely isn't there, and replacement is the only path.
Installing Windows 11 by bypassing the requirements is technically possible, but Microsoft does not guarantee those installations will receive updates. On a machine that handles personal data or will face an audit, that shortcut creates a bigger problem than the one it solves.
The dangerous part isn't the desktop
A Windows 10 client is at least visible. It sits in the inventory, it has an EDR agent, somebody uses it every day. The real exposure is where nobody looks: an old firewall facing the internet, a VPN appliance the vendor stopped supporting, a NAS whose firmware is stuck in 2019, a camera recorder, a print server with its management interface reachable from outside. CISA's directive targets precisely this category, because these devices share three properties. They are reachable from outside, you cannot install a security agent on them, and most companies have never listed them as assets at all.
Add embedded systems in production environments to that: the control PC driving a production line, POS terminals, the workstation wired to a lab instrument. These usually cannot be upgraded, because the software on top is certified against one specific OS version.
Compliance and contracts
Article 12 of Türkiye's KVKK requires data controllers to take "all necessary technical and organisational measures to ensure an appropriate level of security." The Authority's own personal data security guide lists patch management and software currency among those technical measures explicitly. In an audit, or in the review that follows a breach, "that server stopped receiving updates in 2025" has no defensible answer. ISO 27001 leads to the same place: control A.8.8 in the 2022 version covers management of technical vulnerabilities directly, and an out-of-support component gets written up against it.
Cyber insurance questionnaires have tightened in the same direction. Whether you run unsupported operating systems is now a standard line on application forms, and the answer moves both your premium and your exclusions.
When you genuinely cannot upgrade
Some systems really can't be moved. The risk doesn't go to zero, but it can be narrowed:
- Separate it on the network. Give it its own VLAN, cut internet access entirely, and allow it to talk only to the one destination it actually needs.
- Separate the identity. The account that reaches this machine should not be a domain admin. Access should go through a jump host and be recorded.
- Increase visibility. If no agent can be installed, watch it from the network side and make sure its logs reach central monitoring.
- Keep the backup apart. Its backup should not live on a share in the same network, and one copy should be immutable. In a ransomware scenario, backups are the first thing attacked.
- Write down an end date. A compensating control is a temporary answer. Without a line in the decision log saying "this system is removed by this date, owner is this person," temporary becomes permanent.
A concrete plan for the next 90 days
Build an asset inventory and put the vendor's end-of-support date on every row: servers, clients, network devices, applications, databases, runtimes. Until it all sits in one table, no priority order you produce will be correct. Then sort that table by three questions: is it reachable from the internet, does it process personal data, is it part of the identity or backup infrastructure. Make one decision per row (upgrade, replace, buy ESU, isolate, decommission) and write a date and a name next to it. When you cost the options, calculate ESU across three years with the doubling applied, and set that total beside the replacement price. Finally, add a clause to your procurement process: from now on, every piece of hardware and software you buy has its end-of-support date in the contract and goes into the inventory on day one. That single habit is what stops you reading this same article again in three years.
Building the inventory, separating the systems that truly cannot be upgraded from the ones nobody has gotten around to, and turning the ESU-versus-replacement question into actual numbers usually moves faster with an outside pair of eyes. We do this work at Wedevit without selling you a product: we find the out-of-support assets, rank them by risk, design compensating controls for whatever cannot move, and fit the migration plan to your budget calendar.
Need help with this topic?