Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityHospitals & Medical Centers

The (Microsoft) Windows Are Wide Open for Bad Actors

By Jason Stewart
Laptop with desktop screen showing
Sunrise King via Unsplash
August 26, 2025

On October 14, Microsoft will officially end its support for the Windows 10 operating system. Most healthcare organizations won’t be able to fully transition to Windows 11 by then because they have so many legacy applications to run. That means that bad actors will soon be launching malware that takes advantage of known openings and vulnerabilities during the Windows transition period.

Even for the biggest organizations with large model IT staffing, the transition to Windows 11 is at minimum a six-to-nine month process. First, you have to build an image and test it against all your applications. Then you have to re-image devices, train your entire staff and formally roll out the new operating system.

Microsoft will offer an Extended Security Updates (ESU) program for up to three years following Windows 10 end-of-service. It’s an annual subscription that provides critical patches but no new features or general support.

One complicating factor is that many healthcare organizations don’t consistently maintain a Microsoft Enterprise Agreement (EA) due to cost considerations. The first phase of the agreement covers the licenses and initial support, then the organization pays 85% of that amount for ongoing support and maintenance (which includes the right to upgrade to new versions of Windows).

To reduce operating costs, many hospitals and healthcare organizations will go three years on EA followed by three years off before signing a new agreement. Bear in mind that these organizations have to maintain roughly 150 to 300 applications in a delicate balance of state-of-the-art and legacy programs that may not function in the new environment. These organizations may have to lean on compensating technologies like Citrix to keep the legacy applications running in a secure manner, which further drives up costs.

Because so many legacy applications need to be supported, healthcare organizations are always a target for cybercriminals. But the threat exposure is even greater when an operating system like Windows 10 is no longer supported and maintained.

At some point, continuing to run Windows 10 will be a HIPAA violation. The Department of Health & Human Services (HHS) has yet to clarify when it will start declaring hospitals noncompliant if they’re still relying on Windows 10.

The Impact On Cyber Insurance

Many cyber insurance providers require lengthy technology and security questionnaires upon execution of a cyber-risk policy. Insurance providers may deny claims if a data breach stems from an unsupported operating system. That means that a healthcare organization relying on Windows 10 could be left holding the bag for the staggering cost of ransomware payments, data recovery, lost revenue due to downtime and legal/compliance fees.

At a bare minimum, cybersecurity insurance premiums are bound to increase for healthcare organizations that are significantly behind in their transition to Windows 11.

Will Windows 11 Be More Secure?

Microsoft’s new operating system incorporates many security and privacy enhancements. Windows 11 will require organizations to use Trusted Platform Module (TPM) 2.0, a hardware-based security layer that allows encrypted credentials and tamper protection at the point of system startup.

Windows 11 will also incorporate a Diagnostic Data Viewer that lets an organization instantly see what data is being collected and how it’s deployed.

Attackers Are Ready To Pounce

When we reach mid-October, cybercriminals will be poised to strike Windows 10 users because Microsoft will no longer provide security patches for newly discovered vulnerabilities. Without those security updates, your organization becomes a prime target for malware and ransomware.

For most healthcare organizations, it’s simply not possible to make an instant upgrade to Windows 11. But you need to demonstrate due diligence by at least formalizing the process of transitioning to the new operating system. It’s important to start planning your upgrade immediately. Failure to do so will make you vulnerable — not just to cyberattacks, but to increased insurance premiums and possible compliance violations.

KEYWORDS: healthcare cybersecurity legacy security systems vulnerability

Share This Story

Jason stewart headshot

Jason Stewart is Manager, vCISO Services at Fortified Health Security in Brentwood, Tennessee.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

Popular Stories

Red and blue pawns with thought bubbles

Implementing Meaningful De-Escalation Training in Your Security Program

Fingerprint on computer board

Enhancing Incident Response with Integrated Access Control and Video Verification

Iran on map

Iran Conflict and Cybersecurity: What to Expect in the Next 30 Days

World Cup trophy beside goal

World Cup Safety and Security Is About More than Just Crime

Woman in suit

Can the Industry Do More for Women in Security?

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 8, 2026

The Future of Executive Protection: Layering Technology, Intelligence, and Response

Digital threats to executives and other high-profile employees are evolving faster than most corporate protection programs. Learn why modern executive protection programs require data-driven, intelligence-led strategies to keep pace with the magnitude of today’s threats.

April 15, 2026

How AI is Closing the Decision Gap in Leading GSOCs

Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing