Windows 10 stopped receiving free security updates in 2025, and government warnings about actively exploited software kept arriving through September 2026. Both point to the same problem: equipment nobody is watching becomes the easiest way into a small business.
A deadline most offices already passed
Microsoft stopped providing free support for Windows 10 on October 14, 2025. According to Microsoft's own documentation, versions of Windows 10 that reached that date no longer receive technical support, feature updates, or quality updates, the category that includes security and reliability fixes. The operating system keeps running. It simply stops being defended.
Do not assume you already know the answer for every machine in your office. Point of sale terminals, a back office desktop, an older laptop kept running for one specific piece of software: these are the devices that get skipped when everything else is upgraded, and they are exactly the devices this deadline already applies to.
For some of these machines, the obstacle is not willingness. Microsoft's own guidance is to upgrade eligible computers to Windows 11 or move to a new Windows 11 computer, which means some machines can only be replaced, not upgraded. That is a budget decision, not a five-minute task, and it is why Microsoft offers a paid bridge for organizations that need more time.
None of this is unique to Windows. It is simply the version of the problem most offices run into first, because a Windows machine sits on nearly every desk.
Paying for more time does not restore full support
That bridge is called Extended Security Updates (ESU). It lets organizations keep receiving critical and important security updates on Windows 10 after the end of support date, through an annual subscription. For organizations, Microsoft's documentation prices the first year at $61 per device and states that the price doubles every consecutive year, for a maximum of three years.
That structure is worth reading twice. The bridge is temporary by design, it grows more expensive every year you stay on it, and it ends on a fixed schedule no matter how much you are willing to pay. A business that pays every year still reaches a hard stop within three years of the original end of support date. Extended Security Updates exist to buy time to finish a migration. They are not a long-term substitute for running a supported operating system.
What losing support really means
The Cybersecurity and Infrastructure Security Agency (CISA) puts it plainly on its guidance page, Update Business Software: "Outdated software is one of the most significant security risks to your business." The same page explains the mechanism: once software or hardware is no longer supported, it stops receiving security updates. Flaws found in that product after the support date are never fixed on the version still running in your office, and the gap between what is known and what is patched only widens with time.
The warnings did not stop this month
CISA maintains a running list called the Known Exploited Vulnerabilities (KEV) Catalog. On September 2, 2026, the agency added seven entries to it, "based on evidence of active exploitation." The list was not limited to obscure enterprise platforms. It included SonicWall SMA1000 remote access appliances, the kind of device a business installs so staff can connect securely from home or the field, and Sangoma Switchvox, a business phone system.
That was not an isolated update. On September 27, 2026, CISA added two more entries to the same catalog, again "based on evidence of active exploitation," this time in Citrix NetScaler products. Twenty-five days apart, same catalog, same reason, and ordinary business infrastructure rather than software nobody outside a data center has heard of.
Why small businesses take the hit
A large enterprise usually has someone whose job includes tracking end of support dates and patch cycles across every device on the network. Many smaller businesses do not have that role, and equipment tends to stay in service as long as it still turns on and does the job it was bought for. CISA tells organizations to prioritize public-facing and legacy systems for a reason: attackers scan for known flaws automatically, so an exposed, unpatched device does not need to be singled out to be found.
Replacing hardware is a budget line. It competes for the same dollars as payroll, rent, and inventory, which is why the decision so often becomes "not yet" instead of "never." Nobody chooses to run unsupported software. It accumulates one postponed decision at a time.
A single unsupported device can also put more than itself at risk. On a flat network, a compromise on one forgotten machine can reach the same systems as everything else in the building. If a device cannot be replaced right away, isolating it is not optional.
It is also worth confirming, in writing, who on your information technology (IT) support team is responsible for watching these dates. Patch responsibility is one of the details that an IT support contract often leaves unstated, which means it defaults to nobody until something goes wrong.
Fix the front door first
None of this means replacing every aging computer in the building this month. CISA's patching guidance is specific about where to start: "Work with your IT team to establish regular patching procedures and tests. Prioritize critical vulnerabilities especially for public-facing or legacy systems." For a small business, that means the remote access appliance, the public website, the email platform, and anything else reachable from outside your building go first. The desktop in the back office that never talks to the internet directly is a lower priority, though not a permanent exception.
The same logic applies to line-of-business software, such as accounting platforms and phone systems, not only the computers that run them. If a vendor has stopped issuing updates for the version your business uses, that product belongs on the same list.
Budget for replacement in stages if that is what it takes. What matters is that the stages follow exposure, not whichever machine happens to break first.
What to do this week
- List every computer, server, and network appliance your business runs, and record the exact operating system version on each one. Do not rely on memory or purchase date.
- Check each item against the manufacturer's own end-of-support page, not an impression of how old it looks.
- For anything already past its end-of-support date, choose one of three actions: upgrade it, replace it, or remove it from the network. Leaving it unchanged is not one of the three.
- If an unsupported device must stay in service for a short period, isolate it on its own network segment so a compromise there cannot reach the rest of your systems.
- Turn on automatic updates everywhere the option exists, including operating systems, business applications, and browser extensions.
- Put the patching question to your IT support provider in writing, and get a clear answer on who tracks end-of-support dates on your behalf.
- Ask your cyber insurance carrier whether unsupported software affects your coverage or your renewal questionnaire. Cyber insurance is not a substitute for keeping systems supported.
Replacing an old computer or renewing a support contract costs money today, on a schedule you control. An incident on a machine nobody was watching does not wait for a convenient month. Treat every end-of-support date on your equipment list as a deadline, because to whatever is scanning the internet for exactly that gap, it already is one.
Sources
- Extended Security Updates (ESU) program for Windows 10 - Microsoft Learn
- Update Business Software - Cybersecurity and Infrastructure Security Agency
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog, September 2, 2026 - Cybersecurity and Infrastructure Security Agency
- CISA Adds Two Known Exploited Vulnerabilities to Catalog, September 27, 2026 - Cybersecurity and Infrastructure Security Agency
Know which devices in your office are past their support date
Adams Cloud & Cybersecurity helps small businesses inventory their equipment, identify what has passed end of support, and sequence upgrades so the most exposed systems are handled first.
Book a free consultation