CIO Brief: The Security Cost of Delaying Windows 11
Retrospective: this article looks back at events from October 2025, written in 2026 with the benefit of hindsight.
The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended updates gets more vulnerable each month. Delaying the move to Windows 11 is a security decision, not just an IT budget one.
Why unsupported systems matter
When Microsoft stops patching an operating system, new vulnerabilities stay open forever. Attackers specifically target organizations with older systems because they're easier to break into.
The options
- Upgrade compatible devices to Windows 11.
- Replace devices that can't upgrade.
- Pay for Extended Security Updates for devices that need more time (costs rise each year).
- Isolate devices that can't be upgraded or patched, limiting what they can access.
The business impact
- Increased breach risk from unpatched devices.
- Compliance and insurance issues — many frameworks and insurers require supported operating systems.
- Rising ESU costs if migration drags on.
Questions to ask your team
- How many of our devices still run Windows 10?
- Which are covered by Extended Security Updates, and until when?
- Are unsupported devices blocked from accessing company data?
- What's the timeline and budget to finish the migration?
What good looks like
All devices on Windows 11 or enrolled in ESU with a firm migration date, unsupported devices blocked from company data, and leadership tracking progress monthly.
The decision
Set a hard deadline for removing unsupported Windows 10 devices from access to company data. Deadlines turn a perpetual project into a finished one.
- Windows 10 End of Support (Oct 2025): Unpatched Endpoints in Your Microsoft 365 Estate Platform Changes
- How to Use Intune Compliance Policies to Block Unsupported Devices How-To & Hardening
- Windows 11 Migration Security Checklist How-To & Hardening