
Microsoft has officially set the end-of-support date for Windows 10: October 14, 2025. After this date, Windows 10 devices will no longer receive critical security patches, bug fixes, or feature updates. For businesses, this is more than just a technical deadline—it’s a major risk factor for operations, security, and compliance.
Windows 10 officially reached end of support on October 14, 2025. Microsoft no longer provides security updates, bug fixes, or technical assistance for any device running Windows 10. As of December 2025, Statcounter data showed that 44.64 percent of Windows desktop computers globally were still running Windows 10, meaning nearly half the market was operating a system that Microsoft had stopped patching. For businesses in regulated industries or those with cyber insurance policies, that status has direct compliance and financial consequences that extend well beyond an operating system preference.
This article explains what the end of Windows 10 support means in practice, what the Extended Security Updates program does and does not provide, what the security and operational risks are for businesses that remain on Windows 10, why Windows 11 represents a genuinely more secure foundation, and how Ferrara IT manages the Windows 11 upgrade and hardware replacement process for businesses through its Managed IT Services program.
End of support does not mean Windows 10 stops working. Devices running Windows 10 continue to function. Files open, applications run, and users can continue working. What ends is Microsoft's obligation to identify and patch the security vulnerabilities that are discovered in the operating system after October 14, 2025.
In practical terms, this means the following is no longer provided for Windows 10 devices:
The distinction that matters for business risk assessment is the security patch gap. Every vulnerability that security researchers and attackers discover in Windows 10 after October 14, 2025 remains permanently unpatched on any device that is not enrolled in the Extended Security Updates program or upgraded to Windows 11. Over time, the list of publicly known, exploitable vulnerabilities in Windows 10 grows without any corresponding remediation.
Attackers specifically target end-of-life operating systems for this reason. When a vulnerability is disclosed and no patch is available, the exploitation window is permanent rather than temporary.
The IBM 2025 Cost of a Data Breach Report recorded the average global cost of a data breach at $4.88 million, the highest figure ever documented. For small and mid-sized businesses, a six-figure breach can be operationally devastating. Running Windows 10 without Extended Security Updates past October 2025 is the equivalent of leaving a building's emergency exit permanently propped open: the risk increases every month as more vulnerabilities accumulate without patches. Ferrara IT's managed cybersecurity services team regularly identifies organizations operating under the assumption that their perimeter security tools protect Windows 10 devices adequately after end of support. They do not.
The specific risks that accumulate for unpatched Windows 10 devices include:
When a security researcher or threat intelligence organization publicly discloses a Windows 10 vulnerability after the end of support date, Microsoft does not release a patch. Attackers immediately incorporate the disclosed vulnerability into their toolkits. Organizations running unpatched Windows 10 devices face an ever-expanding catalog of known, unmitigated attack vectors that no firewall or endpoint tool can fully compensate for at the operating system layer.
Ransomware operators specifically profile target organizations for unsupported operating systems. Legacy systems are attractive targets because attackers know that exploitation toolkits built against disclosed vulnerabilities will work reliably. A single successful ransomware deployment can halt business operations for days or weeks, triggering recovery costs, data loss, and regulatory notification obligations that far exceed the cost of a timely operating system upgrade.
Organizations subject to HIPAA, PCI DSS, CMMC, NIST, or SOC 2 have explicit requirements that systems handling sensitive or regulated data remain in a supported and patched state. Running Windows 10 without Extended Security Updates after October 2025 creates a documented compliance gap. In the event of a breach, regulators and auditors will identify the unsupported operating system as a contributing factor, which can amplify penalties and trigger additional scrutiny across the organization's full security program.
Cyber insurance underwriters have become significantly more rigorous in assessing the security posture of organizations at the time of a claim. Most carriers now include operating system currency as an underwriting requirement, and several explicitly exclude breach claims where the breached system was running an unsupported operating system at the time of the incident. Businesses that experience a breach on a Windows 10 device running without Extended Security Updates after October 2025 risk having their claim denied entirely, leaving the full breach cost uninsured.
Microsoft offers Extended Security Updates (ESU) as a paid subscription that extends critical security patch delivery for Windows 10 devices beyond the October 14, 2025 end of support date. For consumer devices, Year 1 ESU coverage runs through October 13, 2026, at a cost of $30 per device. For commercial customers, ESU pricing is per device and increases each year for up to three years of coverage, with enterprise customers able to extend through October 2028 at escalating cost.
ESU is a legitimate risk management tool in specific circumstances. It is not an upgrade alternative and should not be treated as one.
ESU provides:
ESU does not provide:
The most significant operational risk of ESU as a strategy is vendor support attrition. Software vendors update their compatibility and support matrices based on the operating system lifecycle. As Windows 10 ages further into its unsupported period, vendors progressively drop it from their supported configurations. When a vendor removes Windows 10 from its support matrix, calling their helpdesk produces a single answer: they cannot support your configuration. ESU does not change that.
Windows 11 is not Windows 10 with a reskinned interface. The hardware requirements that prevented some older devices from upgrading to Windows 11 exist precisely because Windows 11 is built on a fundamentally different security architecture. The minimum hardware requirements for Windows 11, specifically TPM 2.0, Secure Boot, and a compatible processor, are prerequisites for security features that cannot be retrofitted onto older hardware running Windows 10.
A dedicated security chip that stores cryptographic keys, protects BitLocker encryption keys at the hardware level, and enables secure boot verification. Windows 10 did not require TPM 2.0. Windows 11 requires it because hardware-stored keys are significantly harder for attackers to extract than software-stored equivalents.
Verifies that the operating system loader and boot components have not been tampered with before the system starts. Prevents bootkit and rootkit malware from loading before security software can detect them. Secure Boot is enforced at the UEFI firmware level, not the software level.
Virtualization-Based Security (VBS) creates an isolated environment for critical Windows processes that cannot be accessed by standard code running on the main operating system. HVCI uses this environment to verify the integrity of kernel code, blocking driver-based attacks that have been used in major ransomware deployments.
Enables passwordless authentication using facial recognition or fingerprint scanning tied to the device's TPM chip. Credentials never leave the device, eliminating the network transmission attack vector that affects password-based authentication. Works as a phishing-resistant login method without requiring a separate hardware security key.
Full-disk encryption is enabled and TPM-backed by default in Windows 11 Pro and Enterprise. Protects data on lost or stolen devices from unauthorized access. The TPM 2.0 requirement ensures that BitLocker keys are stored in hardware rather than software, making offline attacks significantly more difficult.
An integrated security chip on newer Windows 11 certified hardware that runs firmware updates through Windows Update, closing the firmware attack gap that exists when firmware and operating system security are maintained through separate channels.
Beyond security, Windows 11 delivers measurable operational improvements. Snap Layouts and Snap Groups enable more efficient multitasking on single and multi-monitor setups. Integration with Microsoft 365 and Microsoft Copilot is deeper and more consistent than on Windows 10. Performance under memory-intensive workloads has improved, and battery life on compatible portable devices is longer due to better power management at the hardware abstraction layer.
Not every Windows 10 device is eligible for a Windows 11 upgrade. The Windows 11 minimum hardware requirements exclude older processors and any device without a TPM 2.0 chip. Before making any upgrade or replacement decision, a complete device inventory and compatibility assessment is required. Ferrara IT provides this assessment as part of its IT assessments service, delivering a device-by-device recommendation that accounts for hardware age, application compatibility, and budget timeline.
The decision framework for each device follows a clear logic:
A common planning error is treating the October 2026 ESU expiry as the upgrade deadline. By the time that date approaches, device procurement timelines, IT staff scheduling, and budget planning cycles make it very difficult to execute a clean hardware refresh across an entire organization without rushed purchases and operational disruption. Organizations that begin their assessment and planning now have substantially more flexibility in how they stage the transition.
The Technical Safeguards standard requires that systems handling electronic protected health information (ePHI) remain in a state where security vulnerabilities are mitigated through patches or equivalent controls. Running Windows 10 without ESU after October 2025 creates a documented gap. Upgrading to Windows 11 with BitLocker and Windows Hello addresses the access control and encryption requirements directly.
Requirement 6.3.3 mandates that all system components are protected from known vulnerabilities by installing applicable security patches. An unpatched Windows 10 device in a cardholder data environment fails this requirement. Windows 11 with current patches satisfies the requirement and its hardware security features support the strong authentication and encryption controls required elsewhere in PCI DSS.
Configuration Management (CM) domain requires that authorized software is installed and that vulnerabilities are identified and remediated. Running an unsupported operating system without patches is a direct finding under CM.2.061. Organizations subject to CMMC for federal contracts cannot pass an assessment with unpatched Windows 10 devices in scope.
Most cyber insurance underwriters include operating system patching status as a standard underwriting question. Some carriers have begun requiring evidence that all endpoint operating systems are supported and currently patched as a condition of coverage. A breach claim involving an unpatched Windows 10 device after October 2025, outside of an active ESU subscription, creates grounds for claim denial on the basis of material misrepresentation or failure to maintain reasonable security controls.
Ferrara IT manages Windows 11 upgrades and hardware refreshes for businesses across the Philadelphia and Mid-Atlantic region as part of its Managed IT Services program. The process is designed to minimize operational disruption while ensuring every device in the organization is either running a supported operating system or on a documented, time-bound replacement plan.
The Windows 11 upgrade process includes:
Yes, Windows 10 devices continue to function after October 14, 2025. The operating system itself does not stop working. What ends is Microsoft's security patching. Without the Extended Security Updates subscription, any vulnerability discovered in Windows 10 after that date will remain permanently unpatched on your device. Over time, the number of publicly known, unmitigated vulnerabilities accumulates, increasing the risk of exploitation with each passing month.
Extended Security Updates (ESU) is a paid annual subscription that delivers only critical security patches for Windows 10 through October 2026. It does not provide new features, bug fixes, software vendor support, or any guarantee that your applications will continue to work on Windows 10. Upgrading to Windows 11 is a one-time transition to a fully supported, actively developed operating system with substantially stronger security architecture, complete application support, and a four to six year productive lifespan ahead of it. ESU is appropriate when a specific application is not yet compatible with Windows 11. For all other cases, upgrading is the more cost-effective and secure path.
Windows 11 requires a compatible processor, 4 GB of RAM, 64 GB of storage, UEFI firmware with Secure Boot capability, and a TPM 2.0 chip. Many devices manufactured after 2017 have TPM 2.0 hardware installed but with the feature disabled in the firmware by default. Running Microsoft's PC Health Check tool will identify whether a device is eligible for the free Windows 11 upgrade. Devices that fail the compatibility check, particularly on the processor or TPM requirements, cannot run Windows 11 and require hardware replacement.
Windows 11 is built on the same foundation as Windows 10, and Microsoft 365 applications including Outlook, Word, Excel, Teams, and OneDrive are fully supported and optimized for Windows 11. In fact, Microsoft has aligned its Microsoft 365 support lifecycle with Windows 11, meaning that Office 2021 and Office LTSC 2021 on Windows 11 devices are supported through October 2026, while the same applications on Windows 10 no longer receive support following the Windows 10 end of support date.
The timeline depends on the number of devices, the proportion of devices that require hardware replacement rather than software upgrade, and the complexity of the application environment. For a small organization with 10 to 25 devices, a properly managed upgrade and replacement process typically completes within two to four weeks including assessment, procurement lead time, and phased deployment. Larger organizations with 50 or more devices or complex application environments typically require six to twelve weeks for a full phased rollout. Beginning the assessment now ensures sufficient lead time for hardware procurement and a staged deployment that minimizes operational disruption.
Windows 10 end of support is not a future deadline. It passed in October 2025. Every month that a business continues running Windows 10 without Extended Security Updates, or without a defined transition plan, adds to the documented security and compliance exposure that auditors, insurers, and attackers will all eventually address in their own ways.
Ferrara IT assesses every device in your organization, identifies which can be upgraded and which need replacement, manages the procurement and deployment process, and ensures your environment is fully compliant and properly configured on Windows 11 before we close the project.
Schedule your Windows 11 Readiness Assessment today. Contact our team to get started.
Learn more about Ferrara IT Managed Security Services
or visit ferrarait.com to explore the full range of managed IT and cybersecurity services.
