What do you do about production equipment running old Windows?
Isolate it so it can reach almost nothing, document exactly what it does and what depends on it, take a full recoverable image, and start the replacement conversation with the equipment vendor. What you should not do is treat it as a laptop that someone has neglected to update.
Almost every manufacturer has at least one, and the situation is usually reasonable rather than negligent. A machine was commissioned a decade or more ago with a computer attached running whatever was current. The machine still works and has years of life left. The control software is certified only against that platform, the vendor has no migration path, and replacing the computer might mean replacing equipment worth a great deal of money. So it stays, and everyone quietly hopes.
The risk is real and worth naming precisely rather than dramatising. An unsupported operating system stops receiving fixes, so every vulnerability discovered after end of support remains open permanently. Attackers know this and know that manufacturing is full of such machines. The exposure is not that someone targets your particular controller; it is that ransomware reaching your network will find and encrypt it along with everything else, and this is the machine you can least afford to lose and least easily rebuild.
Start with the vendor conversation, because it determines everything downstream. Ask specifically: is there a supported path to a current platform, what does it cost, does it require equipment downtime, and does an unsupported upgrade void anything. Get the answer in writing. Vendors sometimes have a path nobody asked about, and sometimes the honest answer is that this generation of equipment ends with that operating system. Either answer is useful; the assumption is not.
Where replacement is not available or not yet affordable, containment is the answer and it can be genuinely effective. Put the machine in a segmented network zone where it can reach only the specific systems it must and nothing else, and where almost nothing can reach it. Remove internet access unless something genuinely requires it. Control removable media, since a USB drive is the classic route into an otherwise isolated machine. Restrict who can physically use it. None of that patches the vulnerabilities and all of it removes the paths by which they would be exploited.
Then image it, and treat that as production capability rather than IT housekeeping. Take a full image of the machine so it can be restored to identical hardware or rebuilt if the hardware dies. Industrial computers fail, replacement parts for decade-old hardware are difficult to source, and reinstalling control software that shipped on a CD in 2011 with a licence key nobody can find is a bad afternoon during a stoppage. Store the image with your other backups, verify it can be restored, and note what hardware it belongs to.
Document it properly while you are there, because the knowledge usually lives with one person. What the machine does, what software it runs, which vendor supports it, what it connects to, who to call, and what happens to production if it stops. That page is worth writing once and it is what makes the machine manageable by someone other than the person who has always dealt with it.
Then plan the replacement rather than deferring it indefinitely. Put the equipment on your capital plan with a date, even a distant one, and revisit it annually. The point is not to force a premature purchase but to stop the decision being made for you by a hardware failure at the worst moment, which is how these situations usually resolve. Businesses that plan replace on their schedule; businesses that do not replace in an emergency at a worse price.
One further consideration is increasingly common: supply chain questions. Larger customers now ask manufacturers about their security posture, and an unsupported machine on a flat network is a poor answer. Being able to say that legacy equipment exists, is segmented, is documented and has a replacement plan with dates is a considerably better one, and it is true rather than reassuring.
The honest caveats. Containment reduces risk rather than eliminating it, and a business relying on a machine that cannot be patched should know that clearly rather than comfortably. Vendors are sometimes unhelpful and that constraint is theirs rather than something a provider can resolve. And imaging old hardware is occasionally awkward and worth the effort anyway. If you want your legacy machines assessed, isolated and imaged, call 1800 456 567.
Deal with the machine nobody wants to touch
We isolate and document legacy production computers, take recoverable images, and plan replacement with your equipment vendors.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business