Skip to main content

Getting your organisation ready for Windows 11 upgrade before Autumn 2025

Why you should act now to ensure you meet the new hardware standards, and prioritise security.
Tavrius via Getty Images

At the NCSC we maintain recommended configurations for the main operating systems which help organisations to quickly deploy our recommended baselines, rather than needing to evaluate all the settings themselves. Today, we have released our updated configuration packs for Microsoft Windows and - as ever - we've selected the smallest group of settings for you to deploy which are both usable and deliver real world security benefits.


The security risks of delaying upgrade

It goes without saying that the security risks of not upgrading are significant. In addition to the difficulties associated with being out of support, an out-of-date operating system is a prime target for cyber criminals. We saw this when a vulnerability in IE 6-11 was exploited after Windows XP support ended on 8 April 2014, and before it was patched on 1 May 2014. And again in 2017, a vulnerability in unpatched versions of XP was exploited extensively by the WannaCry ransomware – an attack which resulted in huge costs and damage globally.




Written by

Josh D Device Security Researcher, NCSC