Back to insights

Windows End-of-Support: What It Actually Costs Your Business

When Microsoft stops patching an OS, the risk and the bill both go up — here's how to run the numbers before something forces your hand.

Windows End-of-Support: What It Actually Costs Your Business

What 'end of support' actually means

Microsoft ships security patches on the second Tuesday of every month — most people in IT call it Patch Tuesday. When an operating system reaches end of support, those patches stop coming. That means any vulnerability discovered after that date stays open forever on your machine. Windows 10 hits its end-of-support date on October 14, 2025. After that day, it joins Windows 7, Windows 8.1, and Windows Server 2012 in the 'permanently unpatched' category. The machine keeps working. Your staff can still log in, open files, and print things. But every week that passes, the list of known, exploitable holes in that OS gets a little longer — and none of them will ever be fixed by Microsoft again. Attackers know these timelines as well as IT folks do. They often hold newly discovered exploits and release them publicly after end-of-support dates, precisely because they know a large installed base will never be patched.

The real-world risk in plain terms

Think of an unpatched OS the way you'd think of a door lock that the manufacturer admitted is broken but won't fix. You can still lock it. It might hold. But a burglar with the right tool opens it in seconds. In practice, the most common threats hitting unpatched machines right now are ransomware delivered through phishing emails, remote-access exploits that let attackers into your network without any employee clicking anything, and credential-harvesting malware that quietly collects passwords over weeks. A small retail or professional-services shop in the DC area is not too small to be a target — in fact, automated scanning tools don't care about your size. They scan IP ranges looking for known vulnerabilities, and an exposed Windows 10 machine after October 2025 will have a growing list of those. One compromised workstation on your network is often enough to move laterally to a file server, accounting software, or a shared drive.

Upgrade vs. replace: running the actual numbers

Before you decide anything, check whether your current hardware can run Windows 11. Microsoft's minimum requirements include a 1 GHz processor with at least two cores, 4 GB of RAM, 64 GB of storage, and — this is the one that catches most small businesses — a TPM 2.0 chip (a small security chip on the motherboard). Many machines bought before 2018 either don't have TPM 2.0 or have it disabled in firmware. If your hardware clears all those hurdles, a Windows 11 upgrade costs you nothing beyond staff time — Microsoft offers it as a free upgrade from Windows 10. Figure two to three hours of disruption per workstation for a careful upgrade including driver checks. If the hardware doesn't qualify, you're looking at replacement. A solid business-class desktop runs $600–$900 right now. A business laptop that will last five or more years is $800–$1,200. Spread that over a five-year life and you're paying $12–$18 per month per machine — less than most software subscriptions. Contrast that with the cost of a ransomware incident: the Ransomware Task Force's 2023 report put average recovery costs for small businesses in the $50,000–$200,000 range when you count downtime, data recovery, and outside help. The math is not close.

Compliance implications for regulated businesses

If your business handles health information, payment card data, or certain government contracts, running an unsupported OS isn't just a security risk — it's a compliance violation. HIPAA requires covered entities and business associates to apply security patches in a reasonable timeframe; running an OS the vendor has explicitly abandoned is very difficult to defend in an audit. PCI DSS 4.0, which governs businesses that process credit cards, requires that all system components be protected from known vulnerabilities. An unpatched, unsupported OS fails that requirement on its face. For firms that hold federal contracts, CMMC (Cybersecurity Maturity Model Certification) requirements explicitly cover patch management, and auditors are asking about OS support status. At HashWhales we see this regularly with small professional-services firms in the DC area that didn't realize their IT setup created a compliance gap. Fines for HIPAA violations start at $100 per violation and can reach much higher for willful neglect. PCI non-compliance can result in card processors revoking your ability to accept cards. These aren't hypothetical. Getting your OS off the unsupported list is often the fastest way to close a compliance finding before it becomes an enforcement action.

What to do before October 2025

Start with an inventory. Pull a list of every Windows machine in your office — you need the make, model, year of purchase, and current OS version. If you don't have a way to do this automatically, you can check an individual machine by pressing the Windows key, typing 'winver,' and hitting Enter. Once you have the list, run Microsoft's PC Health Check tool (free download from Microsoft's site) on each machine to find out whether it qualifies for Windows 11. Sort your results into three buckets: machines that can be upgraded for free, machines that need to be replaced, and machines that are already on Windows 11. For the free-upgrade machines, schedule the upgrades now rather than waiting until September. Doing five machines in a single frantic week in October is how things break. For replacement machines, budget now. If you're replacing more than three or four workstations, stagger the purchases across this fiscal year and next if that helps cash flow. For any machine that handles patient data, card data, or contract work, replacement should jump to the front of the line regardless of cost. If you're not sure where to start or you'd rather not spend your Saturday running PC Health Check on a dozen machines, this is exactly the kind of assessment we handle for local businesses — a few hours of work that gives you a clear, prioritized action list.

Want the same review applied to your systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp