Site navigation

NCSC Urges Orgs to Upgrade Windows 11

Elizabeth Greenberg

,

windows 11 upgrade
Organisations could risk significant cybersecurity vulnerabilities if they do not upgrade. 

The National Cyber Security Centre has put out a warning to organisations to upgrade their Windows systems ahead of Windows 10 nearing end-of-life date.

Windows 10 will become a legacy technology on 14 October 2025, but is still used by many organisations despite it being released over a decade ago.

The NCSC says that there are “significant” security risks to not upgrading, with out-of-date systems often being a prime target from cyber-criminals.

While many Windows 10 users have already updated their systems, many are unable to upgrade to Windows 11 due to hardware limitations. Windows 11 hardware requirements, such as TPM 2.0, UEFI, and support for secure boot were introduced, meaning that in order to upgrade, organisations may have to purchase new hardware.

Upgrading will improve security, the NCSC assures, as Windows 11 has improved secure-by-default design, with newer hardware required to use some existing security features that required manual activation in Windows 10.

Windows 11 also offers other security features like Native passkey management, as well as improvements to default behaviour features and Windows Hello.

“Devices that don’t meet Windows 11 hardware requirements – and are therefore unable to use the features that are needed to secure Windows – remain fundamentally vulnerable to attack,” device security researcher at NCSC, Josh D, wrote.


Recommended reading


The NCSC cited two examples of out-of-date operating systems falling victim to cyber-criminals.

“We saw this when a vulnerability in IE 6-11 was exploited after Windows XP support ended on 8 April 2014, and before it was patched on 1 May 2014.

“And again in 2017, a vulnerability in unpatched versions of XP was exploited extensively by the WannaCry ransomware – an attack which resulted in huge costs and damage globally.”

This underscores the need to upgrade, even if it means purchasing new hardware.

Organisations can “consider it an opportunity to address security vulnerabilities in your devices rather than simply the nuisance of replacing old hardware,” the NCSC suggested.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data