The desktops and servers that quietly stopped being safe

Windows is so familiar that it is easy to forget it has an expiry date. Every version Microsoft releases is supported for a defined period, and when that period ends, the security updates stop. The machine keeps working — which is exactly why this gets ignored — but it stops being protected. For a great many businesses, that line has already been crossed, on desktops and on servers, often without anyone making a conscious decision to let it happen.

This is not a niche technical concern. An unsupported Windows machine sitting on your network, or running your line-of-business application, is a business risk with consequences in security, compliance and even your insurance. Here is what has actually happened, and what to do about it.

The dates that have already passed

On the desktop, the big one is recent: Windows 10 reached end of support on 14 October 2025. The version that ran most business PCs for a decade no longer receives security updates. The two versions before it went earlier — Windows 7 in January 2020 and Windows 8.1 in January 2023 — and any machine still on those has been exposed for years.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

On the server, the picture is staggered. Windows Server 2008 and 2008 R2 went out of support in January 2020. Windows Server 2012 and 2012 R2 followed in October 2023, with paid Extended Security Updates as a temporary measure that themselves run out in October 2026. The next dates are already on the horizon: Windows Server 2016 reaches end of support in January 2027 and Windows Server 2019 in January 2029. If your servers are on 2016 or 2019, the clock is running, and server migrations take longer to plan than the dates suggest.

One more worth naming, because so many smaller businesses still self-host email: on-premises Exchange Server 2016 and 2019 also reached end of support in October 2025. A mail server running unsupported is a particularly exposed thing to leave on the internet.

“It still works” is not the same as “it is still safe”

The reason end of support gets deferred is that nothing visibly changes on the day. The desktop still boots. The server still serves. But from that date, every new security vulnerability discovered in the operating system stays unpatched on your machines. Attackers know these dates as well as Microsoft does, and unsupported systems become preferred targets precisely because the holes never get fixed. The risk does not arrive as a single event; it accumulates quietly until something exploits it.

The desktop problem: a fleet you cannot simply update

For Windows 10, the obvious answer is to move to Windows 11. The complication is hardware. Windows 11 has stricter requirements than its predecessor, and a large number of working, perfectly serviceable PCs cannot run it. So the “upgrade” is, for many businesses, a fleet replacement — a capital cost that lands all at once and is easy to keep postponing.

Microsoft offers a consumer Extended Security Updates option and continues to patch its Office applications on Windows 10 for a limited window, which buys a little time. But these are bridges, not destinations. A business running a roomful of Windows 10 machines that cannot take Windows 11 has a planning problem to solve now, not a decision to defer until something forces it.

The server problem: the application that pins the OS

Servers are where end of support gets genuinely hard, because a server rarely runs alone. It runs an application, a database, and the connections between them. Very often the reason a business is stranded on Windows Server 2012 R2 is not inertia — it is that a critical application will not run on anything newer, or depends on an old version of the .NET Framework, or talks to a database that is itself out of support.

When that is the case, you do not have a Windows problem. You have a chain in which each layer holds the next in place — the dependency lock described in the compound problem. The operating system cannot move until the application does, the application is bound to its runtime, and the runtime is bound to the old Windows. If your blocker is an old .NET application specifically, the route through it is the one covered in migrating off .NET Framework; if it is the database, see the SQL Server and MySQL end-of-life problem. Either way, updating Windows in isolation is not possible, which is exactly why these servers stay frozen for years.

The fallout

The consequences of running unsupported Windows reach well beyond the IT department.

Security is the first and most direct. Unpatched operating systems are among the most common routes into a business, and a single compromised machine can be the foothold for an attack on everything it can reach.

Compliance is the one that converts the risk into a liability. Running unsupported software undermines any claim to have appropriate technical measures in place, which data-protection law expects. Payment-card rules require supported, patched systems. Regulated firms face direct questions about end-of-life technology. An auditor will treat an out-of-support server underneath a critical system as a finding, not a detail.

Cyber insurance has sharpened this considerably. Insurers now ask whether you run unsupported operating systems, and the answer affects your premium, your cover and — at the worst possible moment — whether a claim is paid. The money saved by deferring the upgrade can quietly be the reason the policy does not respond.

And the practical erosion familiar from any frozen technology: third-party software keeps dropping support for old Windows regardless of whether you are paying for extended updates, so you progressively lose the ability to install or integrate anything new, while the skills to maintain the old environment grow scarcer. Extended Security Updates, where offered, are a rising annual rent — a way of paying to stand still, which is a particular form of technical debt.

What to do

Start with an inventory — a clear list of every Windows version running in the business, on desktops and servers, and its support status. Most organisations do not have this, and you cannot manage a risk you cannot see.

For the desktops, that turns into a refresh plan: which machines can take Windows 11, which need replacing, and over what timescale and budget. For the servers, the critical extra step is to map the dependencies — what each server runs, what those applications need, and which of them is the real reason the operating system is stuck. That map is what turns “we can’t update the server” into a defined plan with an order to it.

Extended Security Updates have a legitimate role as a bridge — buying twelve to twenty-four months to execute a proper migration without rushing. They become a trap only when treated as a destination. The goal is to use the bridge to get across, not to keep paying to stand on it.

If you have Windows machines or servers past their support date — or 2016 and 2019 servers heading towards it — the safest path is to plan the move before it becomes an emergency. We will establish where you stand and what to move first.

Start a Conversation

Build and rescue work

Hands-on delivery of this kind is handled by Sixteen Pillars Studio.

Looking at an acquisition, supplier, or major project?

The greatest risks are rarely visible in the executive summary. The Sixteen Pillars framework surfaces the technology risks that diligence usually misses.