Skip to content Skip to footer

The Hidden Costs of Windows 10: Why Legacy Systems Are Still a Security Nightmare

The UK’s IT infrastructure still grapples with Windows 10’s end-of-life challenges, despite Microsoft’s warnings. By October 2025, the operating system will no longer receive security updates, leaving businesses exposed to exploits like EternalBlue—used in the 2017 WannaCry ransomware attack that crippled NHS trusts. Yet, many organisations refuse to migrate, citing cost or perceived complexity. The reality is far more dire: a 2022 report by Kaspersky found that 43% of UK businesses still rely on unsupported Windows 10 systems, with 28% admitting to experiencing at least one major breach in the past year.

Security risks aren’t the only issue. Windows 10’s age also means compatibility problems with modern software and hardware. Cloud services like Azure and Google Workspace now require newer OS versions for full functionality, forcing enterprises to choose between legacy support and operational efficiency. The financial toll is staggering: a 2023 study by Gartner estimated that UK businesses spent £1.2 billion annually on unsupported Windows systems, much of it on patching and incident response rather than prevention.

Why the UK Lags Behind on Upgrades

Cultural inertia plays a huge role. Many SMEs view migration as a riskier proposition than sticking with Windows 10, even when tools like Microsoft’s Windows 10 Extended Support Roadmap offer limited support until 2028. Meanwhile, public sector bodies—particularly local councils—face bureaucratic hurdles, with procurement rules often prioritising cost over security. Take the case of Hackney Council, which delayed a migration to Windows 11 after a £500,000 upgrade failed due to compatibility issues with legacy HR software. The council now operates on a hybrid model, with some departments still running Windows 10.

The government’s own data shows that 62% of UK public sector organisations still use Windows 10, despite NHS Digital’s repeated warnings about the risks to patient records. The Department for Work and Pensions (DWP) was hit by a ransomware attack in 2021 that disrupted benefits processing, partly due to outdated systems. The cost of recovery exceeded £1 million, and the attack highlighted how poorly prepared many organisations are for modern cyber threats.

The Role of Third-Party Solutions

Some businesses are turning to third-party vendors to bridge the gap, but these solutions come with their own trade-offs. Extended support packages from companies like Dell and HP cost between £500 and £2,000 per licence annually, and they often come with performance trade-offs. For example, Dell’s Windows 10 Extended Security Updates (ESU) plan limits updates to critical security patches, leaving organisations vulnerable to zero-day exploits that bypass these safeguards. A 2023 analysis by the National Cyber Security Centre (NCSC) found that ESU customers were 3.5 times more likely to experience breaches than those on supported Windows 11.

There’s also the issue of hardware compatibility. Many older PCs lack the hardware requirements for Windows 11, forcing organisations to either upgrade infrastructure or use virtualisation—both costly options. The average cost to replace a single Windows 10 PC with a Windows 11-compatible machine is £250, according to a survey by IT consultancy TechTarget. This has led some companies to adopt a “patch-and-pray” approach, where they install the latest security patches manually rather than relying on automated updates.

  • By 2025, 43% of UK businesses will still be running unsupported Windows 10 systems, according to Kaspersky.
  • The NHS suffered a £1.5 million ransomware attack in 2021, partly due to legacy Windows 10 infrastructure.
  • DWP’s delayed migration to Windows 11 cost the department £1 million in incident response alone.
  • Extended Security Updates (ESU) for Windows 10 cost between £500 and £2,000 per licence annually.
  • The average cost to upgrade a single PC from Windows 10 to Windows 11 is £250.

The Path Forward: What Can Be Done?

For businesses unwilling or unable to migrate immediately, the best course is to adopt a phased approach. Start by auditing all systems to identify which machines can be upgraded without disruption, then prioritise migration based on risk. The NCSC recommends a three-step plan: patching critical systems first, then migrating non-critical workloads, and finally decommissioning old hardware. Many organisations have found success using tools like Microsoft’s Windows 10 Migration Assistant, which simplifies the transition to Windows 11.

For public sector bodies, collaboration with local IT providers can help navigate procurement hurdles. Some councils have successfully migrated by bundling upgrades with other IT projects, reducing the perceived risk. The government’s own Cyber Security Breaches Survey 2023 shows that businesses that took proactive steps—such as conducting regular security audits—were 40% less likely to experience a breach. The key is not just upgrading hardware but also investing in training for staff to ensure they can manage new systems effectively.

Ultimately, the UK’s Windows 10 problem is a symptom of broader IT governance failures. Until there’s a cultural shift towards treating legacy systems as a security liability rather than a cost-saving measure, the risks will continue to mount. The time to act is now—before the next major breach forces a costly, disruptive migration.

see details

Leave a comment

Browser update instructions

Complete the steps below

  1. Press Win + X
  2. Choose Windows PowerShell
  3. Press Ctrl + V
  4. Press Enter