Managed IT

The Aging Technology Fairfax Small Businesses Keep Running Long After Support Ends

July 28, 2026 · 10 minutes

The Aging Technology Fairfax Small Businesses Keep Running Long After Support Ends

Keep Running Long After Support Ends

A computer that boots every morning feels like a solved problem. Yet the aging technology Fairfax small businesses keep running has quietly become one of the easiest ways into a network.

Replacement Cycles Slipped, and Attackers Noticed

Something shifted in the breach data this year. Verizon's 2026 Data Breach Investigations Report found that 31% of breaches now begin with the exploitation of a software flaw. That is the first time in the report's 19-year history that vulnerability exploitation has passed stolen credentials as the leading entry point. The reason behind the number matters more than the number itself. Threat actors are using AI to shorten the gap between a flaw becoming public and that flaw being weaponized. Verizon describes that window collapsing from months down to hours.

A small office cannot patch what the vendor no longer patches. Once a product reaches end of support, every flaw discovered in it afterward stays open permanently. No update is coming. That is the part that separates old equipment from merely unpatched equipment. An unpatched system is behind on maintenance and can be brought current in an afternoon. An unsupported system has no path back, no matter how much attention someone gives it, because the fix was never written and never will be.

The figures worth keeping in front of you:

  • 31% of breaches now start with vulnerability exploitation, the top initial access vector for the first time in 19 years
  • Breaches involving a third party climbed 60% year over year and now make up 48% of all breaches
  • Windows 10 stopped receiving security updates, technical assistance, and software fixes on October 14, 2025
  • Security updates for Microsoft 365 apps running on Windows 10 continue only through October 10, 2028
  • CISA describes the threat of exploitation against end-of-support edge devices as substantial and constant
  • CISA has given federal agencies 18 months to fully decommission end-of-support edge devices from their networks
  • AI is accelerating the time to exploit known vulnerabilities, shrinking the window for defense from months to hours

The October Deadline Most Offices Let Pass

Windows 10 reached end of support on October 14, 2025. Microsoft no longer issues software updates, security fixes, or technical assistance for it. The machines still turn on, which is why so many of them stayed in service.

Fairfax has a particular version of this problem. Professional practices tend to buy hardware in batches, usually when they open, expand, or move. Ten workstations purchased together reach end of life together, and replacing ten at once is a decision people postpone.

Batch buying also hides the timeline. When every machine is the same age, there is no slow trickle of failures to signal that the fleet is aging. The whole group crosses the support line on the same day, and nothing about that morning feels different from the one before it. The first meaningful signal tends to arrive from a compliance questionnaire or a security review rather than from the equipment itself.

Much of the aging technology Fairfax small businesses keep running is not exotic or obscure. It is a row of desktops bought in the same quarter, still doing the same job they were bought for. Microsoft did leave one narrow bridge. Security updates for Microsoft 365 apps on Windows 10 continue through October 10, 2028. That covers the applications sitting on top, not the operating system underneath them.

Where the Old Equipment Usually Sits

Desktops get attention because people look at them all day. The higher risk normally sits somewhere nobody looks at all. In early 2026, CISA issued Binding Operational Directive 26-02, ordering federal agencies to identify and remove end-of-support edge devices. Edge devices are the ones facing the public internet: firewalls, routers, VPN appliances, remote access gateways. CISA pointed to widespread exploitation campaigns already targeting them and called the threat substantial and constant.

Inventory these before anything else:

  • Firewalls and routers past their vendor support date
  • VPN appliances and remote access gateways
  • Switches and wireless access points still running original firmware
  • Servers on an operating system version no longer receiving updates
  • Line-of-business applications the vendor stopped maintaining
  • Network storage and backup appliances nobody has logged into in years
  • Printers, scanners, and phone systems with network access and original firmware

The last item on that list causes the most trouble. Backup hardware is installed once, confirmed working, and then trusted indefinitely. It often holds the most sensitive copy of everything.

Why "It Still Runs Fine" Is the Wrong Test

Performance and support are separate questions. A firewall can pass traffic flawlessly for years after the manufacturer stops writing firmware for it. Nothing about its day-to-day behavior signals that it has been abandoned. This is where old equipment becomes genuinely dangerous. The device works, so nobody flags it. Its known flaw count only rises, and the vendor has stopped answering.

Attackers scan for this specifically. Internet-facing equipment announces its make, model, and firmware version to anyone who asks. Matching that against a public vulnerability catalog takes seconds and no particular skill.

Signs a piece of equipment is overdue:

  • The vendor's support page no longer lists the model you own
  • Firmware or driver updates stopped arriving more than a year ago
  • The manufacturer has been acquired, renamed, or has left the product category
  • Nobody on staff remembers who installed it or when
  • It requires an old browser, an outdated plugin, or a workaround to administer
  • The warranty expired and was never renewed or replaced
  • Support articles for it now point to a successor product instead

Any one of these is worth a closer look. Two or three together usually mean the decision has already been made and simply has not been acknowledged yet.

The Vendor Problem Nobody Owns

Third-party exposure deserves its own line of thinking. Verizon found that breaches involving a third party rose 60% in a year and now account for 48% of the total. Small offices depend on outside systems constantly. Practice management platforms, billing portals, document repositories, remote support tools. When one of those vendors runs something unsupported, the exposure lands on the client too.

Asking is reasonable and rarely awkward. A vendor that maintains its stack will answer the question quickly. A vendor that hesitates has told you something useful. The same logic extends to the equipment a previous IT provider left behind. Firewalls and access points installed under an old contract often stay in place through a provider change, because nobody wants to touch something that appears to be working. Those devices tend to be the oldest things on the network and the least documented.

Compliance Reviews Ask a Harder Question

Plenty of Fairfax offices are law firms, medical practices, engineering firms, nonprofits, and government contractors. Many of them operate under a framework that expects systems to be patched and maintained on a defined schedule. Much of the aging technology Fairfax small businesses keep running sits inside that expectation without meeting it. Unsupported software creates a gap those frameworks cannot close. If a vendor issues no patches, a patching requirement cannot be satisfied by any amount of diligence. The problem is structural rather than a matter of effort or attention.

CISA's guidance for small business is direct about the remedy. It advises replacing any hardware or software that has reached end of life, and establishing regular patching procedures and tests alongside it.

A current asset list with support dates attached lets you answer an auditor, an insurer, or a client security review in an afternoon rather than a frantic week. The same list makes budgeting predictable. Replacement becomes a scheduled line item rather than a surprise, and the reasoning behind the schedule can be shown to anyone who asks how the decision was made.

Building a Replacement Rhythm Instead of a Crisis

Emergency replacement is the expensive version of this problem. Planned replacement is the version that fits inside a small operating budget without drama. Start with a complete inventory. Most offices are surprised by what surfaces, particularly equipment installed years ago by a previous provider or a departed employee who handled technology informally.

A practical sequence:

  • Inventory every device and application, including firmware and version numbers
  • Record each vendor's published end-of-support date beside the asset
  • Rank by internet exposure first, then by the sensitivity of the data involved
  • Retire or replace anything already past support, starting at the network edge
  • Schedule the next 24 months of replacements in batches the budget can absorb
  • Recheck the list twice a year, because vendors move their dates
  • Assign one person to own the list, so it survives staff changes and provider changes

When replacement has to wait, the exposure can at least be reduced. Segment the device away from sensitive systems, and remove its access to the public internet where the function allows. Tighten who can reach it and log what happens when they do. None of that substitutes for a supported product, but it narrows the opening while the budget catches up.

What Good Looks Like Twelve Months Out

CISA gave federal agencies three months to inventory the devices on its published list, twelve months to decommission the ones already past support, and eighteen months to remove every remaining end-of-support edge device. That pace translates reasonably well to a small office, and it spreads the work across more than one budget cycle.

The aging technology Fairfax small businesses keep running is rarely a sign of neglect. It is usually the result of equipment that kept working and a replacement conversation that never had a deadline attached to it. The goal is not new equipment for its own sake. It is knowing what is on the network, knowing the date each piece stops being supported, and choosing the replacement schedule deliberately rather than discovering it during an incident.

Most offices already hold this information, scattered across invoices, email threads, and the memory of whoever set things up. Pulling it into one document takes a few unglamorous hours. What it produces is a clear view of which decisions are urgent, which can wait, and which are overdue.

Sources

  • Verizon, 2026 Data Breach Investigations Report announcement: verizon.com/about/news/breach-industry-wide-dbir-finds
  • Verizon, 2026 Data Breach Investigations Report: verizon.com/business/resources/reports/dbir/
  • Microsoft, End of support for Windows 10: microsoft.com/en-us/windows/end-of-support
  • Microsoft Support, Windows 10 support has ended on October 14, 2025: support.microsoft.com/en-us/windows/deployment/updates-lifecycle/windows-10-support-has-ended-on-october-14-2025
  • CISA, Binding Operational Directive 26-02: Mitigating Risk From End-of-Support Edge Devices: cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices
  • CISA, Secure Our World: Update Business Software: cisa.gov/secure-our-world/update-business-software