On October 14, 2025, Microsoft stopped releasing security updates for Windows 10. The company itself is blunt about what that means: the computer keeps turning on and working normally, but it becomes "at greater risk for viruses and malware" from that date on, because no newly discovered flaw will ever be fixed again.
Ten months later, the installed base didn't follow the calendar. According to Statcounter, which tracks the share of each Windows version in use worldwide, Windows 10 still accounted for 30.14% of Windows computers as of August 2026 — nearly 1 in 3. That's not a handful of stragglers; it's a huge slice of the world's fleet running a system that receives no correction at all anymore.
And Windows 10 is just the most visible example. The same thing happens with server versions, routers, firewalls and other network gear: a date arrives when the manufacturer stops fixing anything, the device keeps working exactly as before, and the difference stays invisible until someone exploits the flaw that will never be patched. For whoever decides the IT budget, that's the question that matters: how much of what the company runs today is already in that spot, unnoticed?
What "end of support" really changes
Every operating system, server and piece of network equipment has an expiration date set by its manufacturer. Up to that date, every security flaw found becomes a fix. After it, the manufacturer simply stops looking and stops correcting — the device loses no function at all, only that safety net.
That matters even more for network equipment than for a desktop computer. The United States' cybersecurity agency, CISA, issued a directive in 2026 forcing federal government agencies to inventory and replace unsupported routers, firewalls and other edge devices, and because the agency itself says it is aware of "widespread exploitation campaigns" against this kind of device.
Edge devices have extensive reach into an organization's network and integrations with identity management systems.
CISA's directive only applies to US federal agencies — not to Brazilian companies. But its design is instructive: before any replacement, the first deadline it sets, just three months, is for agencies to inventory and report everything that's out of support. Replacing comes later. Listing comes first.
A router or a server bought eight years ago is rarely remembered as a risk. It's working, nobody complains, and replacing it costs money and effort. The problem is that "it's working" and "it's secure" stopped meaning the same thing the day the manufacturer stopped watching it.
For those who still depend on Windows 10 and can't replace every computer at once, Microsoft itself sells a transition path: a paid extended security update program that keeps fixes coming for a while past the official end-of-support date. It's a bridge to organize the replacement, not a permanent solution — the program has a final deadline and doesn't bring back full technical support, only the security fix.
Why just updating doesn't solve it

The most common way a small or mid-sized company handles this is reactive: the equipment stays on until it finally breaks, or until someone notices, during an audit or after an incident, that a given server hasn't been patched in years. Nobody decided to leave it that way — nobody decided otherwise, either.
The reason, in most cases, isn't carelessness. It's the lack of a list. Nobody knows, off the top of their head, every piece of hardware and every system in use across the company — what exists, which version it runs, how long it's been there, and who depends on it. Without that list, "keep everything updated" is a slogan, not a task anyone can actually execute.
It's not unusual for Skills IT to walk into a company for the first time and find a switch or a server bought more than ten years ago, still in production, with nobody quite sure whether the manufacturer still supports it. Nobody there was negligent — the equipment simply never made it onto a list anyone reviewed.
Buying another security product on top of that doesn't fix it if nobody knows which machine to install it on. The starting point isn't a new tool: it's knowing, precisely, what already exists.
What has to be in place
A widely adopted international security control puts exactly this point as the first item on the list, ahead of everything else: inventory every piece of equipment the company has, identifying what's authorized, what's out of control, and what needs attention. It's the foundation every other security decision rests on.
A complete inventory of what the company has. Every computer, server and network device, with manufacturer, model, system version and end-of-support date recorded in one single place — not in the memory of whoever's been there the longest.
A replacement plan ordered by risk. What's most exposed — because it faces the internet, or holds sensitive data — gets replaced first. What's isolated and low-risk can wait for the next budget cycle.
Isolation of what can't be replaced right now. When immediate replacement isn't viable, the old equipment sits segmented in a separate part of the network, with tighter access and closer monitoring, instead of loose next to everything else.
Security updates kept current on everything that still receives them — the inventory only works alongside this routine, and doesn't replace it.
A single person accountable for the lifecycle of each system and device, instead of several vendors each deciding on their own when something gets swapped.
This is how Skills IT works: it builds the client's complete inventory, keeps security updates current on everything that still gets them, and helps plan the replacement of what's reaching the end of the line, with a cost estimate before any purchase.
The payoff for the company

The payoff from doing this survey isn't abstract. It's budget: instead of an emergency purchase the day the server won't turn on anymore, replacement becomes planned, with time to compare prices and negotiate terms. Emergency purchases cost more and choose worse.
It's also continuity: unsupported equipment that fails mid-shift doesn't warn anyone first — and without an inventory, nobody knows whether a backup plan exists for that specific system until it's needed. Knowing what exists is the difference between an outage you saw coming and one that catches everyone off guard.
And it's decision-making with real information: when the director asks "how much will modernizing our IT cost this year," the answer stops being a guess and becomes a list with priority and estimated value — the opposite of discovering the problem once it's already an incident.
There's one more, quieter payoff: the IT team stops burning energy firefighting old equipment and starts discussing priority with whoever approves the budget. That shifts the conversation from "why do we spend so much on support" to "what does it cost not to have replaced it in time" — which, in the end, is the question that matters to whoever signs off on the investment.
A roadmap to get started
Before deciding what to replace, it's worth running this roadmap with whoever handles IT at the company:
-
List every piece of equipment and system in use, with manufacturer, version and owner — including whatever's forgotten in a closet, running since before anyone on the current team joined.
-
Mark the end-of-support date for each item by checking the manufacturer's own website. It's public information; the work is gathering it, not discovering it.
-
Separate what's already out of support from what still gets fixes, and prioritize by each item's risk — what faces the internet first, what's isolated last.
-
Isolate what can't be replaced within this budget, restricting access and tightening monitoring until the replacement happens.
-
Put the replacement in next budget cycle's plan, with a cost estimate, instead of leaving it on the informal "whenever it finally breaks" list.




