Windows 10 stopped receiving security updates on October 14, 2025, according to Microsoft's official schedule for the system. Past that date, any new flaw found in the system stays unfixed — the door that opens no longer closes.
That changes the math on replacing, or not replacing, a company's computer fleet. A seven-year-old machine that "still works" and runs that same Windows 10 isn't just slow: it's a computer with no security update, connected to the company network, every single day.
The catch is that many of these computers can't even move up to Windows 11. Microsoft requires a specific security chip and a recent-generation processor to install the new system — a requirement that machines older than five or six years generally don't meet. That leaves three paths: pay for a temporary extended-update program, keep running without a fix, or replace the equipment. None of the three is free; what changes is who picks the moment — the company, or the breakdown.
The paid extended-update program, according to Microsoft itself, is designed as a temporary bridge, not a solution: it covers only the most critical security fix, doesn't include general technical support, and has a deadline of its own. Paying for it year after year, on a computer that should have been replaced already, is just postponing the same decision — with a monthly fee added on top.
The bill nobody puts in the spreadsheet
Every day, the seven-year-old machine charges a quiet toll. Five minutes for the system to boot in the morning isn't an exaggeration — it's routine on a machine that has piled up years of updates on top of an increasingly full drive. Multiply that dead time by every employee, every day of the month, and the total hours lost surprise anyone who never added it up.
The second cost is the ticket that keeps coming back. When the same computer calls the technician for the third time over the same reason — freezing, a blue screen, a program that won't open — the company isn't solving the problem, it's applying a bandage. Every ticket has a cost, even inside an unlimited support contract: the technician's time, the employee's time waiting, the rework of redoing what crashed halfway through.
The third cost is invisible until the day it shows up. A system with no security update piles up known flaws that already have a fix available — nobody applied it. According to the State of Ransomware 2026 survey, from security vendor Sophos, a security gap — known or still unknown — was named as a factor by companies hit by ransomware worldwide (the scam where a program scrambles a company's files and demands payment to unlock them): 62% of them named this cause, topping the list for the second year running. An outdated computer fleet is, in practice, a list of open doors waiting for someone to try the handle.
The size of the bill, when the worst happens, helps explain why it's worth avoiding. The same Sophos survey put the average cost of recovering a company after a ransomware attack at US$1.7 million, up 11% from the year before — and, looking only at companies with revenue under US$50 million, the range closest to most small and mid-size businesses, the median ransom demand from attackers landed around US$140,000. These are numbers from outside Brazil, but they point at the same thing: the cost of neglecting a computer fleet isn't abstract, it's a bill that grows.
Waiting for it to break costs more
The common way to handle an old computer is to wait for it to die for good. Except "dying for good" almost never happens on schedule: it happens in the middle of month-end closing, on the day of the most important delivery, right when the most demanding client calls. The emergency swap costs more — the new machine arrives with no time for a calm setup, no organized migration of what was saved on the old one, and the employee stuck waiting during the install.
Another version of the same habit is buying a spare part to squeeze out one more year: more memory, a faster drive. It helps a little, but it doesn't fix the system with no security update running underneath — the computer just opens an exposed system a bit faster.
And there's the most expensive version of all: leaving the matter with no owner. Without someone responsible for knowing how many computers the company has, how old each one is, and which system each one runs, replacement never turns into a decision — it just keeps getting pushed back, until the day it stops being a choice.
What has to be in place
A well-kept computer fleet rests on routine, not luck.
A planned replacement cycle, not a reactive one. Knowing the age and the planned replacement date for each machine turns a surprise expense into an expected budget line, reviewed well ahead of time.
Security updates current, on every computer. It isn't about having a new system for fashion's sake — it's about still receiving the fix as soon as a flaw is found.
An inventory of what the company owns. Without knowing how many computers exist, how old they are, and which system each one runs, nobody decides — they just react to each breakdown, one at a time.
Tickets logged with cause and fix. A third ticket for the same reason, on the same machine, is the sign that the real fix is no longer a technician's visit: it's replacement.
Cost estimated before the purchase, not after the breakdown. Replacing a batch of computers once a year, with an estimate agreed on ahead of time, works out cheaper and more predictable than replacing one at a time, always in an emergency.
This is how Skills IT works: with an inventory of the equipment fleet, tickets logged with cause and fix, and a cost estimate agreed on before any replacement.
What the company gains
The gain from replacing a computer isn't a nicer machine on the desk. It's work time back: the employee who doesn't wait five minutes every morning, the ticket that doesn't come back a fourth time, the afternoon that isn't lost to a breakdown that had been announced for months.
There's also the gain of predictability. A company that knows how many computers it has, and when each one is due, can plan the replacement inside the year's budget — instead of pulling money from somewhere else, with no warning, on the day the equipment decides to quit for good.
And there's the gain that only shows up when the problem doesn't happen: no breach that got in through a flaw with a fix that had been sitting there for months. A managed service provider, like Skills IT, keeps that inventory and that replacement calendar current without the client needing to ask. That never shows up in a results report — it's exactly the incident that never happened.
A roadmap to get started
- List the company's computers by age. Without that list, any replacement decision is a guess.
- Flag which ones still run a system with no security update. Those are first in line, not last.
- Pull the ticket history by machine. A machine with repeat tickets for the same reason has already cost more in lost time than it would cost to replace it.
- Ask whether the year's budget has a line for equipment replacement. If the answer is "we buy when it breaks," the breakdown is making the decision, not the company.
- Ask for an estimate beforehand, not after. Knowing the cost of the replacement batch in advance is what turns a surprise expense into a predictable budget line.



