Software vendors set end-of-support dates for a reason: after that date, no more security patches are issued, no matter what vulnerabilities are discovered. Continuing to run unsupported software is an unmanaged, growing exposure.
What actually happens after end of support
- New vulnerabilities remain permanently unpatched.
- Third-party security tools (EDR, browsers, MFA agents) begin dropping compatibility.
- Cyber-insurance carriers exclude coverage for incidents traced to unsupported systems.
- Auditors and enterprise customers flag it in questionnaires.
Why organizations keep running it anyway
Usually one of three reasons: a critical line-of-business application that only runs on the old platform, a piece of specialized hardware with no updated driver, or a lack of budget and time to plan the replacement. None of these make the risk go away.
Building a migration plan
- Inventory every asset with its OS and application versions and their support dates.
- Rank by exposure — internet-facing and sensitive-data systems first.
- For each unsupported system, choose one: upgrade, replace, isolate on a segmented network, or retire.
- For anything that must remain unsupported, document the compensating controls and revisit them quarterly.
The one path to avoid
Doing nothing and hoping insurance covers it. Increasingly, it does not.