Security needs visibility: The defence value of ITAM
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
- ITAM
- Governance
- Security
Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.
Support for Windows 10 ended on 14 October 2025. For organisations that finished migrating ahead of that date, the job is done. For a great many others it is not — machines are still being replaced, budgets are still being argued over, and some fleets are running on Extended Security Updates while the rest of the programme catches up.
Either way, a Windows 11 migration was never just a desktop refresh. It is the one moment in a decade when you are forced to look at every device you own, what it costs, what it runs and how long it has left. That makes it the natural point to review your asset lifecycle management, your software licence position and your Microsoft licensing.
Done properly, the migration maintains compliance and audit readiness, reduces licensing risk, and keeps disruption low across hybrid environments. Done as a scramble, it does the opposite of all three.
14 October 2025. After that date there are no free security updates, no bug fixes and no technical support from Microsoft.
Running Windows 10 without cover means:
Yes. Microsoft’s Extended Security Update programme covers enrolled devices for a maximum of three years past end of support — to October 2028 for commercial and educational organisations. Microsoft 365 apps on Windows 10 receive security updates on a similar timeline, ending 10 October 2028.
ESU is charged per device, and the cost escalates each year of the programme. It is also cumulative: enrolling in year two means paying for year one as well. It is a bridge, not a destination, and the economics are deliberately designed to make it one.
A full inventory assessment is the first step, and it needs to cover more than a compatibility flag. You want to identify:
TPM 2.0 is the requirement that catches out the most machines, and it is the one least visible in a typical asset register.
Three options:
Assign financial values to replacement devices, calculate the total refresh expense, and forecast IT spending from actual hardware and lifecycle data rather than a per-head average. The difference between those two approaches is usually the difference between a budget that survives contact with reality and one that does not.
Warranty data identifies devices approaching end of life, which makes them the obvious replacement candidates — especially where they also fail the Windows 11 requirements. Using it lets you sequence upgrades intelligently, avoid repair costs on machines you are about to retire, and keep security and compliance intact while the programme runs.
A phased strategy lets you prioritise critical departments first, minimise business disruption, and provide support and training as each group moves.
The hardware requirements people resent are the security improvements they wanted.
Yes, and you should. Assess application dependencies, driver support for legacy hardware, and compatibility risks before you move. Usage data helps here too — there is no value in testing an application nobody has opened in six months, and plenty in retiring it instead.
It depends on size, hardware readiness and complexity. The single largest variable is how early the planning started, which is also the only one you control.
Seven questions. Score 1, 0.5 or 0 for each.
Do you have a complete inventory of every device still running Windows 10?
Do you know which devices meet the Windows 11 hardware requirements?
Do you have a cost estimate for upgrading or replacing incompatible devices?
Have you factored warranty status into replacement priority?
Do you have a structured migration plan with timelines?
Have you tested applications for Windows 11 compatibility?
Have you secured budget approval?
6–7 — On track. You are well prepared. The remaining risk is execution slipping, not planning.
3.5–5.5 — Moderate risk. You are making progress but gaps remain. Prioritise completing the inventory, then budgeting, then sequencing.
0–3 — High risk. You are exposed to disruption, security vulnerabilities and compliance findings, and every month on ESU costs more than the last. Start with the inventory.
The reason a migration stalls is almost never the upgrade itself. It is that nobody can produce a trustworthy list of what needs upgrading, what it will cost and what breaks if it moves.
Discovery first. Ten discovery methods land in one schema — native agent, agentless, command-line, standalone, Active Directory import, network scan, third-party ITAM import, cloud connectors, browser monitoring and file metering. Network Discovery sweeps a class-C subnet in under five seconds. You get the whole list, including the machines that were never enrolled anywhere.
Readiness, not guesswork. Hardware inventory carries the attributes the Windows 11 requirements actually turn on, so device readiness is a query rather than a survey. Dynamic groups built in the query builder let you carve the fleet into ready, upgradeable and replace — and keep those groups current as work proceeds.
Warranty and cost, in the same record. Hardware warranty retrieval and expiry tracking sit next to cost tabs with manual and automatic costing rules, so the replacement schedule and the budget come out of one place instead of two spreadsheets that disagree.
Then actually do the upgrade. CerteroX ITAM ships Windows 11 upgrade orchestration, software distribution for MSI, EXE and Click-to-Run packages, WSUS-integrated patch management with downstream server support, and an SCCM interface that can import and drive SCCM applications, packages and jobs. The console that found the machines is the console that moves them.
Prove it as you go. Governance Policies work as compliance-as-code — BitLocker enabled, Defender running — so post-migration security posture is evidenced continuously rather than sampled at the end. Trend charts, KPIs and threshold alerts on role-shared dashboards give programme reporting without anyone building a weekly deck, and a read-only API with a documented Power BI data source covers the board pack.
Retire what you were about to migrate for no reason. AppsMonitor meters file-based software usage with first-used and last-used tracking and a % Used metric over a rolling 90-day window. Migration is the cheapest moment you will ever get to stop paying for applications nobody opens.
Windows 10 end of support has already happened. What is left is a lifecycle programme with a security deadline attached and a meter running on every device still uncovered.
The organisations handling it well are not the ones with the biggest budget. They are the ones that could answer “what do we own, what does it cost, and what runs on it” on the first day.
Book a demo, or read more about CerteroX ITAM.
Other posts covering the same ground.
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.
When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.