
Short answer: Windows 10's free security updates have ended. Machines still running it accumulate unpatched vulnerabilities with every disclosure — and attackers specifically hunt end-of-life systems because they stay broken. The move is an inventory today, then upgrade, replace, or bridge each machine deliberately. Doing nothing is the one wrong answer.
What "end of support" actually means
The computers keep working — that's the trap. What stops is the patching: new vulnerabilities get discovered, published, and weaponized, and your machines never receive the fix. The risk compounds monthly, quietly, until an automated scan finds you. Compliance and cyber insurance are affected too: unsupported operating systems are exactly what insurers ask about and auditors flag.
Your three real options, per machine
1. Upgrade in place to Windows 11
Free where hardware qualifies — Windows 11 has firm requirements (TPM 2.0, supported CPUs), so a chunk of older fleets won't pass the check. For machines that do: schedule, update, verify apps, done.
2. Replace the hardware
Machines that can't upgrade are usually old enough that replacement is the honest economics: slow hardware taxes payroll daily, and a modern device is faster, supported, and secure out of the box. Stagger purchases by role priority.
3. Buy time with Extended Security Updates (ESU)
Microsoft sells continued security patches per device, per year, with pricing designed to escalate — a bridge for machines tied to legacy software, not a plan. Anything on ESU should have a retirement date attached.
| Option | When it fits | Watch out for |
|---|---|---|
| Upgrade to Windows 11 | Hardware passes the checks (TPM 2.0, supported CPU) — free | Verify apps after updating |
| Replace the hardware | Machines that fail the check and are old enough that slow hardware taxes payroll | Stagger purchases by role priority |
| Extended Security Updates (ESU) | Machines tied to legacy software that need a bridge | Per-device, per-year pricing designed to escalate — attach a retirement date |
The sequence that keeps this painless
- Inventory: every Windows 10 machine, its hardware eligibility, and what it runs.
- Triage: upgrade-eligible now; replace-list with dates; ESU only where a line-of-business app forces it.
- Verify apps against Windows 11 before each wave — the occasional legacy application is the real blocker, and better found in testing than on Monday morning.
- Recycle securely: retired drives get wiped or destroyed, documented.
This is standard lifecycle work inside a managed IT agreement — inventory, scheduling, overnight migrations, and nobody losing a workday. If you'd like the inventory done for you, book a 15-minute engineer call.
Frequently asked questions
Can I keep using Windows 10 after end of support?
The computers keep working — that is the trap. What stops is the patching: new vulnerabilities get discovered, published, and weaponized while your machines never receive the fix, and the risk compounds monthly. Unsupported systems also affect compliance and cyber insurance, since they are exactly what insurers ask about and auditors flag.
What are Extended Security Updates (ESU)?
ESU is Microsoft's paid program of continued security patches, sold per device, per year, with pricing designed to escalate. It is a bridge for machines tied to legacy software, not a plan — anything staying on ESU should have a retirement date attached.
Which PCs can upgrade to Windows 11 for free?
The upgrade is free where hardware qualifies. Windows 11 has firm requirements, including TPM 2.0 and a supported CPU, so a chunk of older fleets won't pass the check. For machines that do qualify, the process is straightforward: schedule the update, run it, and verify your applications afterward.
Sources and further reading
- Microsoft's Windows 10 lifecycle page — the official end-of-support record.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



