We warned about the deadline back in September; this is the piece for organisations reading it in hindsight. Windows 10's free support ended in October 2025, the first paid year of Extended Security Updates has now lapsed with October 2026, and consumer ESU is finished entirely. Plenty of multi-site fleets still have a Windows 10 tail: the regional sites the migration never reached, the devices too old for Windows 11, the POS lanes nobody wanted to touch before peak trading. The tail is now the risk register.
An unpatched operating system in one office is a vulnerability. Across a distributed estate it is a standing invitation, replicated at every site, reachable through every network the estate touches, and increasingly visible to cyber insurers, auditors and enterprise customers who ask pointed questions about supported software. The cost of the tail is not hypothetical breach headlines; it is the compounding operational drag of running a two-standard estate, where every process, image and support call forks into "Windows 11 sites" and "the others".
The realistic answer for most estates is all four in proportion: a thin ESU bridge, aggressive migration of the capable, a disciplined replacement wave for the rest, and an honest retirement list.
The uncomfortable lesson of the ESU cycle is that it will repeat; operating systems now come with published funerals. Estates that maintain a live view of hardware capability against the next requirement set, and refresh in planned annual waves rather than deadline surges, never meet this problem again. That is the program worth budgeting now, while the current one is still teaching the lesson.
Still carrying a Windows 10 tail? Speak to an expert.

3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read
3 Min Read