Windows XP turns 20: Why it’s time to say goodbye

Windows XP main wallpaper
(Image credit: TechRadar)

Monday October 25th marks the 20th anniversary of Windows XP, the first operating system launched by Microsoft in the 21st century. Codenamed “Neptune” during development, Windows XP was originally just intended for the consumer market. However, an update to Windows 2000 for the business market was scrapped and the two projects merged. Windows XP was launched to great acclaim and received positive reviews for its performance and stability, a more intuitive user interface, improved hardware support, and its expanded multimedia capabilities. It was famed for its green start button and blue task bar.

About the author

Jake Moore, Cybersecurity Specialist at ESET.

Whilst Microsoft recently launched Windows 11 (codenamed “Sun Valley”) to much fanfare, several critical PCs still run on Windows XP. In fact, it is thought that 0.6% of the 1.3 billion Windows PCs worldwide still rely on the aging operating system. This is despite Microsoft ending mainstream support for Windows XP back in 2009 followed by extended support in 2014. That means 8 million PCs around the globe are currently out-of-date and unprotected to the latest breed of cyberattacks. 

Legacy critical infrastructure deployments

What makes it worse is that these unprotected Windows XP PCs are often in critical infrastructure deployments. For example, a significant number of ATMs still use versions of Windows XP. In fact, at the time of extended support ending in 2014 it was estimated that more than 95% of the three million ATMs in use worldwide were still running on Windows XP.

There are several high-profile examples of legacy systems being hacked since support ended. In 2017, the dangers of running unsupported out-of-date IT systems were illustrated when the notorious WannaCry ransomware tore through the NHS’s outdated systems in a matter of hours. The highly publicized attack caused £92m worth of damage and disrupted a third of all NHS trusts in England. Whilst Microsoft released a posthumous patch to address the vulnerability, it was too late. A year before, the Royal Melbourne Hospital in Australia’s Windows XP network was struck down with the QBot virus. The virus infiltrated major hospital systems, forcing staff to resort to fax or phone to communicate. It took the hospital over two weeks to contain the virus, which mutated up to six times a day.

The need to patch over the cracks

The stark reality is that when it comes to being hit with an attempted cyberattack it is not a question of if, but when. Four in ten businesses (39%) and a quarter of charities (26%) report having cyber security breaches or attacks in the last 12 months. It is particularly prevalent in medium sized businesses (65%), large businesses (64%) and high-income charities (51%). This has meant that the need to fully patch business critical systems has never been higher. 

Important patches to newly found security holes continue to be released at unerring regularity. Microsoft releases patches on the second Tuesday of each month, jam packed with security updates. In its most recent “Patch Tuesday” update, the company rolled out security patches to no fewer than 86 loopholes it found in operating systems much more technically advanced than XP. 

While antivirus and other endpoint security measures are an important line of defense, effectively applying software updates and patches removes many of the vulnerabilities that cybercriminals target today. However, in these days of remote working, applying such updates can sometimes be difficult. Luckily, help is at hand. By using a multi-platform patch management solution, IT admins can get complete visibility over the patch status of their systems and provide guidance to staff so that they know what to patch and how.

You can’t patch what isn’t there

Effective patching is a critical security precaution for businesses of all sizes. The benefits are numerous. It provides a more secure environment for your staff and helps protect your business from potential security breaches. But more than that, it allows the business to continue to innovate, avoid unnecessary fines and promotes system uptime which leads to happy customers. The last point is particularly important. We all saw the furor that the recent Facebook downtime caused, where businesses which use social media to connect with consumers were faced with irate customers and a significant financial hit.

However, the struggle for businesses is that you can’t patch what isn’t there. And in the eyes of Microsoft, Windows XP is no longer there. With every additional year after the end of extended support, the likelihood of security issues and incidents increases. Therefore, now is the time to say goodbye to Windows XP and move to a supported operating system. A vulnerable server could expose hundreds or thousands of passwords and be used to access and steal files from mapped drives. Unfortunately, 20 years on and businesses still use Windows XP in great numbers. Until they update, the industry must remember the left behind.

TOPICS
Jake Moore

Jake Moore is a cyber security specialist at ESET UK. He is also a well respected industry expert who regularly comments on a range of cyber stories in publications such as The Guardian, The BBC, The Independent and Forbes. He is usually asked to give his opinion, advice and analysis on stories featuring a security or technology angle.

Read more
Microsoft
10 tech anniversaries you shouldn't miss in 2025
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
A Windows 11 laptop sitting on a desk in front of a window
Microsoft really wants you to update to Windows 11 in 2025
A finger touching a screen showing the Windows 11 logo
5 reasons why I’m finally upgrading to Windows 11 in January
Windows 11 forced onto old hardware
Windows 11 is still my favorite OS, ads and all
Latest in Pro
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
A young man working on laptop in office writing notes
Ending the fix/break cycle of End User Computing support
OpenAI
OpenAI wants to help your business build its next generation of AI agents
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
A hand reaching out to touch a futuristic rendering of an AI processor.
Business investors are positive about AI’s impact on the economy
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Latest in News
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
An Nvidia GeForce RTX 4060 on a table with its retail packaging
Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – and that it’ll run with only 8GB of video RAM
Indiana Jones talking to a friend in a university setting with a jaunty smile on his face
New leak claims Indiana Jones and the Great Circle PS5 release will come in April
A close up of the limited edition vinyl turntable wrist watch from AndoAndoAndo
This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want one