Windows 10 PCs out of updates, passwords people who left still use, admin accounts nobody remembers making. A Halloween walk through what should be dead on your network but keeps walking.
Halloween is a good excuse to talk about the things on a network that should be dead but keep walking around anyway. Almost every small-business network we look at has a few. Nothing dramatic happens when they show up. They just sit there, quietly working, until someone else finds them first.
Here are the three we run into most, and what to do about each before October is over.
Microsoft ended free support for Windows 10 on October 14, 2025. Businesses that weren't ready could buy a year of Extended Security Updates, and that first year runs out on October 13, 2026. Year two costs $122 per device, double the $61 of year one, and year three is $244.
You may have seen that home users got an extra year of free updates. That doesn't cover most business PCs: computers joined to Active Directory or Microsoft Entra, or managed through device management, aren't eligible for the consumer program.
A PC that stops getting security updates still turns on, still opens Outlook, still prints. That's exactly what makes it a zombie. Nobody notices anything is wrong until an attacker uses a flaw that will never be patched.
What to do: list every machine still on Windows 10. Upgrade the ones that can run Windows 11, pay for another year only for the few that truly can't move yet (and write down the date each one will be replaced), and retire the rest.
In a July 2025 survey of 1,200 full-time U.S. workers by PasswordManager.com, 40% said they had used a former employer's password after leaving, and 15% said they were still doing it. Six in ten said they could because the password had never been changed. Another 28% got it from someone who still worked there.
Most of them were after things like streaming and software subscriptions, not your files. But it's the same door. A shared login that a former employee still knows is a login you can't account for.
What to do: treat offboarding as a same-day checklist. Disable the Microsoft 365 account and sign the person out of every session, change any shared passwords they knew (Wi-Fi, vendor portals, social media, the alarm code), remove their phone from MFA, and hand their mailbox and files to a manager instead of leaving the account active "just in case."
The temporary admin account from a project three years ago. The login the last IT person used. A remote access tool a vendor installed once and nobody remembers. These are the accounts that tend to have the most power and the least attention.
In Sophos's 2026 ransomware report, 97% of organizations whose attack started with stolen credentials had MFA deployed in some form. Attackers go for the gaps: the accounts left out of the rollout, or the kind of MFA a phishing page can still get past. Forgotten admin accounts are usually in that first group.
What to do: list every admin account in Microsoft 365, your firewall and your servers. Each one should belong to a named person, use MFA, and have been used recently. Anything else gets disabled. Uninstall remote access tools you don't actively use.
None of this needs new software. It needs someone to look, write down what they find, and make a decision about each item. That's most of what keeps a small business from becoming the easy target.
If you'd rather have us run this check for you, that's what a tech consultation is for. We'll tell you plainly what we found, including if you're already in good shape.