In 2022, a small law firm called Tuckers Solicitors LLP received a £98,000 fine from the Information Commissioner’s Office following a ransomware attack. The reason was not that they were running ancient systems or had ignored every warning. The reason was that a critical patch had been released in February 2020 and not applied until June 2020.
Four months. One patch. £98,000.
That is the world we are now in.
Windows 10 reached end of support on 14 October 2025. Since that date Microsoft has issued no free security updates for it. A significant number of UK small businesses are still running it, usually for a perfectly reasonable sounding reason. The machines work. Staff know them. There is no budget line waiting to replace them.
The conversation you have probably had goes something like this: “Windows 10 is unsupported, you need new computers.” That is true, but it is not the whole picture. The part that gets left out is the part that actually costs money.
First, work out what you are actually dealing with
Before anything else, check whether your machines can upgrade at all. Plenty of perfectly serviceable computers cannot run Windows 11. The blocker is usually the processor. Windows 11 requires an 8th generation Intel chip or AMD Zen 2 as a minimum, alongside TPM 2.0 and Secure Boot.
TPM and Secure Boot are worth checking properly, because they are frequently present but switched off in the BIOS, and turning them on takes about five minutes. The processor is different. That is a hard floor. No amount of extra memory or a faster SSD will change it.
If your machines fail on the processor, that tells you something useful about their age. Anything below that threshold was built around 2017 or 2018 at the very newest. Eight or nine years old now. That matters when you are deciding how much to spend keeping them alive.
One thing to avoid: there are well known methods of forcing Windows 11 onto unsupported hardware. Microsoft is explicit that unsupported installations receive no updates. You would end up in a worse position than today and lose the option we are about to describe.
Option one: replace the machines
The clean answer. A business grade laptop or desktop sits around £850. Add a monitor if you are replacing an all in one, so call it roughly £1,000 per user before installation and data migration.
That solves the problem permanently and puts you on an operating system supported into the mid 2030s.
For most small businesses, though, that is a five figure sum arriving with no notice. Which is exactly why the machines are still running Windows 10.
Option two: Extended Security Updates
This is the option that often does not get mentioned. It should.
Microsoft sells Extended Security Updates, known as ESU, to business customers. It delivers critical and important security patches through the normal update channels, which means your IT provider deploys them with standard tooling, exactly as they would on a fully supported machine. The machines are patched. They are not “unsupported with a plaster on.”
There are some rules worth understanding before you rely on it.
The price doubles every year, deliberately. Expect around £65 per device excluding VAT for year one, around £130 for year two and around £265 for year three. Microsoft has designed the curve to stop anyone treating this as a permanent arrangement.
It is cumulative. You cannot buy year two without paying for year one. If you have been holding off, you have not saved anything. You have simply lost cover.
It is never sold pro rata. A year is a year, whenever you buy it. There is no financial benefit in waiting. Delaying means paying the same amount for fewer months of protection.
It ends permanently in October 2028. There is no year four. This is a bridge, not a destination.
It covers security patches only. No new features, no bug fixes, no Microsoft support for the machines.
Run the numbers across the full three years and ESU comes to roughly half the cost of replacing the hardware. Over the next twelve months it is a fraction of it. Used properly, that is the point. ESU buys time to replace hardware in a planned, budgeted way rather than in a panic.
One practical note. Buying ESU directly from Microsoft normally requires a Volume Licensing Agreement, which most small businesses do not have. A Microsoft partner can purchase the licences on your behalf through their own agreement. Nothing for you to set up.
Do not let Microsoft 365 lull you into a false sense of security
Word, Outlook and Teams will continue to receive security updates on Windows 10 until October 2028. Everything feels like it works. And it does. That is the problem.
Think of it like a new lock on a rotten door frame. The lock is fine. The wood it is screwed into is the issue.
Your Microsoft 365 applications sit on top of the operating system. They do not protect it. The OS is what handles authentication, manages network connections, controls file access and runs every process on the machine. When someone exploits an unpatched Windows vulnerability, they do not go through Outlook. They go underneath it.
The applications work. The ground they are standing on is what is exposed.
Why “we will risk it” is a worse decision than it looks
An unpatched operating system is not a fixed risk you can weigh once and accept. It is a risk that grows every single month.
Every Windows 10 vulnerability discovered from October 2025 onwards stays open on those machines permanently. The list of published, documented, unfixable weaknesses gets longer with every patch cycle, and automated scanning for exactly this kind of target is cheap and constant. The machine that was a tolerable risk last autumn is materially worse today. It will be worse again in six months.
Antivirus does not close that gap. Endpoint detection and response is genuinely valuable and you should have it, but it looks for suspicious behaviour after something has happened. It cannot patch a hole in the operating system. And if those machines have access to your file storage, whether that is SharePoint, a server or a network drive, one compromised PC puts your entire company’s data within reach.
The data protection exposure is the real cost
This is where an IT decision becomes a board level one.
Under UK GDPR you are required to implement security measures appropriate to the risk, taking account of the current state of the art. Running an operating system the vendor no longer patches, when a patching route is commercially available and you know about it, is very difficult to argue is appropriate.
Back to Tuckers. The firm was not doing nothing. They had systems in place. The ICO’s conclusion was still that a known critical vulnerability should not have existed in their infrastructure at all. A four month lag on one patch. £98,000.
Windows 10 without ESU is not a four month lag. It is an indefinite gap on every vulnerability from here on.
At the larger end, Advanced Computer Software Group was fined £3.07 million in March 2025 following a ransomware attack, with inadequate patch management among the failings identified.
Two things worth understanding clearly.
Penalties under UK GDPR can reach £8.7 million or 2 per cent of turnover. Nothing like that would land on a small business, and the ICO is proportionate. But Tuckers shows what proportionate looks like at the smaller end. It is not a rounding error.
The ICO also considers whether a failing was negligent or deliberate. This is the point that stops most people when they hear it properly.
A documented decision to continue running unpatched machines, made after the risk and the available fix were both explained to you, sits in a materially different category to an oversight you were not aware of. The more clearly the risk has been put to you, the less defensible inaction becomes.
Reading this and doing nothing is a worse legal position than not having read it.
What a bad week actually looks like
The fines and the percentages can feel abstract. Here is what actually happens.
A machine gets compromised. You might not know for days, or longer. When you do find out, the clock starts immediately. UK GDPR requires you to notify the ICO within 72 hours of becoming aware of a breach. Not 72 hours from when you have worked out exactly what happened. 72 hours from when you knew something had gone wrong.
In those 72 hours you are trying to contain the incident, work out what data was affected, get a lawyer involved and draft a notification to the regulator. If the risk to individuals is high, you also need to write to every affected person individually. Your staff are fielding calls. Your operations may be partially or completely down. Your email may be compromised. Your backups may be affected too.
Legal and forensic costs for a small business in this situation typically run from £15,000 to £50,000 before any fine is considered. The downtime and the reputational damage sit on top of that. A client who receives a breach notification letter from you may not remain a client.
None of that is in the headline fine figure. All of it is real.
Insurance and certification
Two more places this surfaces, both typically discovered at exactly the wrong moment.
Cyber insurance policies generally require software to be supported and patched. A claim can be reduced or refused if unpatched systems are found to be a contributing factor. Read your policy wording now, or ask your broker directly, before you decide to sit on this.
Cyber Essentials requires supported and updated systems. Accepting the risk is explicitly not sufficient on its own. Unsupported machines normally need to be replaced, migrated or segregated out of scope. ESU keeps devices receiving security updates, which is what an assessor is looking for, but confirm the position with your certifying body rather than assuming.
What to do now
Get an accurate inventory. How many machines are on Windows 10, and which of them genuinely cannot upgrade? Check TPM and Secure Boot in the BIOS before writing anything off as incompatible.
Confirm they are on Windows 10 version 22H2. ESU requires it, and older builds need bringing up to date first.
Price both routes. Replacement and ESU as a bridge. Not one or the other in isolation.
Read your cyber insurance wording. Not at renewal. Now.
Decide, and write the decision down. Whichever route you take, record it with the reasoning. If you are accepting risk, do so consciously and in writing. That document matters if things go wrong later.
Put dates against replacements. Even if nothing is being bought this financial year. Phasing a few machines a year is a budget line. Replacing everything the week after one dies is an emergency.
The short version
You are almost certainly not stuck with unpatched computers, and you almost certainly do not have to replace everything at once. What you cannot do is nothing. The risk grows every month, the cheapest fix gets more expensive every year by design, and the regulator has already shown that patching failures cost money.
If you would like a straight answer, we can audit your estate, identify which machines qualify for Windows 11, handle ESU procurement on your behalf and build a phased replacement plan that fits your budget. No sales pitch, no obligation.
James