Skip to main content
MicroNet Global

Managed IT

Windows 10 end of support: the estate you cannot see

Windows 10 support ended in October 2025 and ESU Year 1 expires this October. A practical refresh plan for back-office, EPOS-adjacent and AV control PCs.

7 min readBy the MicroNet Global team

Windows 10 mainstream support ended on 14 October 2025, and the first year of commercial Extended Security Updates expires in October 2026, weeks from now. MicroNet Global, a hospitality IT specialist supporting 745+ sites across 15+ countries, treats this as an inventory problem before it is a procurement one, because most operators cannot yet count the machines affected.

That is not a criticism. A hospitality estate is not a tidy fleet of corporate laptops in a spreadsheet. It is machines that arrived with a fit-out, a vendor or a previous operations director, and many have never been touched since.

Where the deadline actually stands

Windows 10 stopped receiving mainstream support on 14 October 2025. Extended Security Updates then bought time in yearly instalments, with Year 1 ending in October 2026 and each subsequent year costing more, because ESU is a bridge rather than a destination.

Windows 11 requires TPM 2.0 and Secure Boot, which turns this into a hardware programme rather than a software one: a large share of venue back-office and EPOS-adjacent PCs predates it and cannot be upgraded in place at any price. So the position in September 2026 is simple. If you bought ESU Year 1, you have weeks left. If you did not, those machines have had no security updates for nearly a year.

What is Extended Security Updates?

Extended Security Updates is a paid Microsoft programme that continues to deliver security patches for Windows 10 after mainstream support ended, sold in yearly instalments with the price rising each year. It provides security fixes only: no new features, and no guarantee that third-party software vendors will keep supporting their applications on the platform.

Why a hospitality estate is harder than an office

An office refresh is a logistics exercise. A venue estate is an archaeology exercise: scattered machines, often unlogged, frequently doing something nobody has documented.

There is the back-office PC in the cellar running the rota, the stock system and the safe software. There are EPOS-adjacent terminals: the manager's reporting PC, the cash-up station, the back-office server the till software talks to. There are kitchen display PCs in a hot, greasy environment, signage players above ceiling tiles, and BMS and AV control PCs installed by a contractor with their own remote access.

And there is the machine nobody has logged into for two years, running the only copy of something important: a licence server, a legacy reporting tool, a monthly export finance depends on.

The compliance angle is not a judgement call

An unsupported operating system inside the card data environment is a PCI DSS problem, not a matter of risk appetite. The standard requires system components to be protected from known vulnerabilities, and an operating system receiving no patches cannot meet that. PCI DSS v4.0.1 is current, and all its requirements are in force following the 31 March 2025 deadline.

Requirement 12.5.2 expects annual confirmation of PCI scope, so "which machines are in scope?" has to be answered in writing, and an unsupported in-scope machine will surface in a self-assessment questionnaire or a report on compliance. The [[PCI DSS checklist for hospitality]{.underline}](about:blank) is the place to confirm what sits inside your cardholder data environment. Unsupported endpoints are also among the most reliable footholds an attacker can find, which is why they feature in real [[hospitality cyber security attack paths]{.underline}](about:blank).

You cannot plan a refresh you cannot count

Start with an inventory from more than one source: what the management and antivirus tools already know, a network discovery scan per site to catch unmanaged machines, and GMs walking their sites with a checklist, because signage players and AV control PCs often sit on switches nobody has documented.

Record for each device: site, location, operating system, hardware model and age, TPM and Secure Boot status, what it does, who owns the application, whether it touches card data, and whether anyone would notice if it were switched off. That last column resolves the most machines.

Triage: upgrade, replace, isolate, retire

Device typeTypical constraintRecommended route
Back-office PC under four years oldUsually has TPM 2.0 and Secure BootUpgrade in place, after checking its applications
Back-office PC over five years oldNo TPM 2.0, often out of warrantyReplace, and standardise the model across the estate
Manager's reporting and cash-up stationendor software may lag Windows 11 certificationonfirm vendor support, then upgrade or replace
EPOS back-office serverVendor-owned and vendor-certifiedVendor-led migration; do not upgrade unilaterally
Kitchen display PCHarsh environment, low spec, bespoke buildReplace with fit-for-purpose hardware or a vendor appliance
Digital signage playerCheap, numerous, awkward to reachRetire in favour of a modern player or built-in display app
BMS and AV control PCVendor-locked, legacy control softwareIsolate if the vendor has no Windows 11 path, with a replacement date
Machine nobody usesUnknown purpose, still powered onIdentify its function, migrate it, retire the machine

The vendor-locked machines

Every estate has a PC that an EPOS, AV or BMS vendor has not certified for Windows 11. Upgrading it breaks the support agreement; leaving it breaks the security position.

Handle that as a formal conversation, not an email. Ask the vendor in writing for their certification roadmap and a date, and record the answer: it becomes part of your compensating-control story and of the commercial discussion at renewal. A vendor with no roadmap is telling you something useful.

Budgeting and scheduling around trading

A refresh across a multi-site group is a capital programme and rarely fits one financial year. Split it by risk: the card data environment first, internet-facing machines second, anything that stops a site trading third, everything else next year. That survives a finance review better than a site-by-site rollout.

Scheduling is underestimated. A venue cannot lose its back office on a Friday. Work happens on the quietest morning, before deliveries, with the machine imaged in advance so the visit is a swap rather than a build. Data, printer mappings, saved reports and six years of bookmarks have to come across, or the refresh is remembered as the week IT broke everything. That planning is ordinary [[IT consultancy]{.underline}](about:blank) work.

Isolation, done properly

For a genuinely immovable machine, isolation is a legitimate last resort. But it means more than putting the device on a different VLAN.

It means its own segment with default-deny rules in both directions, permitting only the traffic its function requires. No internet access unless a named vendor destination is allowed. Removal from the card data environment, documented. No shared credentials and no local admin used elsewhere. Logging and alerting on denied traffic. And a review date with a named owner, so a temporary arrangement does not become permanent.

Operators running large numbers of [[restaurant and bar sites]{.underline}](about:blank) find a handful of these per estate, not hundreds. Handle them deliberately and the rest is ordinary procurement, best run with a [[managed IT support]{.underline}](about:blank) partner who holds the asset register.

Frequently asked questions

Not without paid Extended Security Updates, and not in the card data environment even with them. After ESU Year 1 ends in October 2026, unenrolled machines receive no patches, so new vulnerabilities stay open permanently. A machine that cannot be replaced yet needs strict isolation and a date.

Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.

Keep reading

Related insights

All insights
New openings6 min read

The technology checklist for a new hospitality opening

The questions operators should answer before the opening team arrives on site, from connectivity and suppliers to handover and live support.

Read article
Managed IT5 min read

Why hospitality needs a different IT support model

Hospitality does not operate in office hours. A useful support model is built around service, sites and the commercial cost of disruption.

Read article
Cyber security7 min read

A practical guide to hospitality cyber security

A plain-English starting point for protecting guest data, payment systems and the people who keep venues running.

Read article
Managed IT7 min read

What hotel IT support actually covers, and what it doesn't

What hotel IT support covers: systems in scope, who owns the PMS and door locks, contract tiers, exclusions and how response targets really work.

Read article
Managed IT7 min read

Why PMS and EPOS integrations break, and how to catch it early

Why PMS and EPOS integrations fail: stopped interface services, expired certificates, room status and API changes, and the checks that catch silent errors.

Read article
Managed IT7 min read

In-house IT team or hospitality IT partner: an honest comparison

In-house IT team or outsourced hospitality IT partner? An even-handed comparison of cover, cost, breadth, openings and the co-managed middle ground.

Read article
Networks & Wi-Fi7 min read

Why guest Wi-Fi generates complaints, and how to design it out

Why guest Wi-Fi draws complaints in hotels and restaurants, and how to design it out --- surveys, AP placement, captive portals, segmentation and peak load.

Read article
Networks & Wi-Fi7 min read

Wi-Fi 7 and the 6 GHz band: what actually changed for venues in 2026

Ofcom opened the full 6 GHz band in July 2026. What Wi-Fi 7 changes for hotels, restaurants and clubs, what it costs, and when waiting is the better call.

Read article
Managed IT7 min read

Disaster recovery when there are 180 covers booked tonight

Business continuity for hotels and restaurants with covers booked tonight. RTO and RPO explained, the failure scenarios that happen and what restores service.

Read article
Compliance7 min read

PCI DSS for restaurants and hotel groups: the practical checklist

A practical PCI DSS checklist for multi-site restaurants and hotels: who enforces it, scope reduction, segmentation, phone orders and v4.x deadlines.

Read article
Cyber Security7 min read

Hospitality cyber security: the attack paths that actually get used

The attack paths actually used against hotel and restaurant groups, the defences that work, and what to do in the first hour of a suspected incident.

Read article
Compliance7 min read

Martyn's Law for venues: what it requires, and where technology helps

What Martyn's Law means for hospitality operators: the standard and enhanced tiers, the SIA's role, and where technology genuinely supports the duties.

Read article
Openings & Rollouts7 min read

The IT critical path for opening a restaurant, hotel or club

A week-by-week IT timeline for opening a restaurant, hotel or club, from circuit lead times and cabling first fix to soft launch and day-one support.

Read article
Managed IT7 min read

Microsoft 365 when most of your workforce never sits at a desk

How to licence Microsoft 365 across hotel and restaurant teams, covering frontline worker tiers, shared device sign-in, identity, offboarding and backup.

Read article

Put this into practice

Services and sectors this touches

Secure, scalable and seamless IT wherever hospitality takes you.