Why a working computer can still be a business risk
An unsupported computer may look and behave normally. The problem is that newly discovered operating-system weaknesses are no longer fixed through the standard Windows 10 update channel. Over time, that creates a growing security and compliance concern.
The risk is higher when the device handles email, customer data, finance systems, remote access or administrator credentials. It can also affect cyber insurance conditions, customer security questionnaires and certification work.
Build an accurate device list first
Include office desktops, laptops used at home, reception or workshop computers, spare devices, training machines and PCs attached to specialist equipment. It is common for the last unsupported device to be one that is rarely visible to management but still connected to the network.
- Record the user, location, Windows edition and current version.
- Check processor, memory, storage, TPM and Secure Boot compatibility.
- List any specialist software, peripherals or machinery the device controls.
- Confirm where its data is stored and whether a tested backup exists.
Choose the right route for each device
A compatible and healthy computer may be suitable for an in-place move to Windows 11 after application and driver checks. Older or unreliable hardware is often better replaced rather than spending time forcing it through an upgrade it was not designed to support.
Microsoft's Extended Security Updates programme can provide a temporary bridge for eligible business devices that cannot move immediately. It should sit inside a dated migration plan, not become a reason to leave the device unchanged indefinitely.
Avoid a disruptive last-minute migration
Test critical applications and peripherals before changing a whole department. Schedule user communication, data transfer and post-upgrade checks, and keep an agreed rollback or replacement option for systems that fail testing.
Where a Windows 10 computer controls manufacturing, access control or another specialist system, involve the software or equipment vendor. Isolating the device and restricting its access may reduce risk while a supported replacement is planned, but that decision should be documented and reviewed.
Official sources and further reading
These primary sources were checked when this article was last reviewed.
