All insights

What do you do about production equipment running old Windows?

6 min readBy Brendon Whiting, Founder · 2 June 2026

Isolate it so it can reach almost nothing, document exactly what it does and what depends on it, take a full recoverable image, and start the replacement conversation with the equipment vendor. What you should not do is treat it as a laptop that someone has neglected to update.

Almost every manufacturer has at least one, and the situation is usually reasonable rather than negligent. A machine was commissioned a decade or more ago with a computer attached running whatever was current. The machine still works and has years of life left. The control software is certified only against that platform, the vendor has no migration path, and replacing the computer might mean replacing equipment worth a great deal of money. So it stays, and everyone quietly hopes.

The risk is real and worth naming precisely rather than dramatising. An unsupported operating system stops receiving fixes, so every vulnerability discovered after end of support remains open permanently. Attackers know this and know that manufacturing is full of such machines. The exposure is not that someone targets your particular controller; it is that ransomware reaching your network will find and encrypt it along with everything else, and this is the machine you can least afford to lose and least easily rebuild.

Start with the vendor conversation, because it determines everything downstream. Ask specifically: is there a supported path to a current platform, what does it cost, does it require equipment downtime, and does an unsupported upgrade void anything. Get the answer in writing. Vendors sometimes have a path nobody asked about, and sometimes the honest answer is that this generation of equipment ends with that operating system. Either answer is useful; the assumption is not.

Where replacement is not available or not yet affordable, containment is the answer and it can be genuinely effective. Put the machine in a segmented network zone where it can reach only the specific systems it must and nothing else, and where almost nothing can reach it. Remove internet access unless something genuinely requires it. Control removable media, since a USB drive is the classic route into an otherwise isolated machine. Restrict who can physically use it. None of that patches the vulnerabilities and all of it removes the paths by which they would be exploited.

Then image it, and treat that as production capability rather than IT housekeeping. Take a full image of the machine so it can be restored to identical hardware or rebuilt if the hardware dies. Industrial computers fail, replacement parts for decade-old hardware are difficult to source, and reinstalling control software that shipped on a CD in 2011 with a licence key nobody can find is a bad afternoon during a stoppage. Store the image with your other backups, verify it can be restored, and note what hardware it belongs to.

Document it properly while you are there, because the knowledge usually lives with one person. What the machine does, what software it runs, which vendor supports it, what it connects to, who to call, and what happens to production if it stops. That page is worth writing once and it is what makes the machine manageable by someone other than the person who has always dealt with it.

Then plan the replacement rather than deferring it indefinitely. Put the equipment on your capital plan with a date, even a distant one, and revisit it annually. The point is not to force a premature purchase but to stop the decision being made for you by a hardware failure at the worst moment, which is how these situations usually resolve. Businesses that plan replace on their schedule; businesses that do not replace in an emergency at a worse price.

One further consideration is increasingly common: supply chain questions. Larger customers now ask manufacturers about their security posture, and an unsupported machine on a flat network is a poor answer. Being able to say that legacy equipment exists, is segmented, is documented and has a replacement plan with dates is a considerably better one, and it is true rather than reassuring.

The honest caveats. Containment reduces risk rather than eliminating it, and a business relying on a machine that cannot be patched should know that clearly rather than comfortably. Vendors are sometimes unhelpful and that constraint is theirs rather than something a provider can resolve. And imaging old hardware is occasionally awkward and worth the effort anyway. If you want your legacy machines assessed, isolated and imaged, call 1800 456 567.

Deal with the machine nobody wants to touch

We isolate and document legacy production computers, take recoverable images, and plan replacement with your equipment vendors.

Frequently asked questions

Ask the equipment vendor first, because the software controlling the machine may only be certified against the original platform and an unsupported upgrade can void support arrangements. Some vendors have a migration path and some do not. Their answer, in writing, determines whether this is an upgrade or a containment problem.

No, and on some it cannot even be installed without affecting the control software. Containment does the work instead: the machine reaches almost nothing, almost nothing reaches it, removable media is controlled, and it is documented. Detection is a poor substitute for a device that cannot be patched against known holes.

Then containment becomes permanent and imaging becomes urgent. Take a full image of the machine so it can be rebuilt if the hardware dies, since sourcing a replacement for decade-old industrial hardware is difficult and the software may not reinstall. That image is effectively part of your production capability.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.