Windows 10 stopped receiving free security updates on 14 October 2025. Nearly ten months later, roughly three in ten Windows desktops are still running it. Most of those machines still boot, still open email, and still pass the only test many organisations ever applied to them, which is whether anyone has complained. That is the exact shape of an accumulating risk: nothing visibly breaks, the exposure compounds quietly, and the bill arrives as an incident rather than as an invoice.

This article is about closing that gap deliberately rather than waiting for the incident to close it for you. The argument is not that everyone should rush out and buy hardware. It is that the decision you are actually making — extend, refresh, or move the desktop into the cloud — has a cost, a risk profile, and a deadline attached to each option, and that most organisations have never written those three things down side by side. The Surface 5G option in particular tends to be evaluated as a premium device purchase when the honest comparison is against three years of Extended Security Updates plus the operational cost of a fleet that cannot be patched, cannot be attested, and increasingly cannot be insured.

Two things make August 2026 a genuine decision point rather than a convenient hook. The first is that Year One of the commercial Extended Security Updates programme ends on 13 October 2026, and Year Two costs double. The second is that the hardware question has changed shape: the current Surface for Business generation ships as a Secured-core PC with an integrated 5G option, which turns a Surface 5G refresh from a like-for-like replacement into a change in how endpoints connect, attest, and recover. A Surface 5G device is not simply a faster laptop with a SIM slot. It removes an entire class of network assumption from your threat model, and that is worth more than the specification sheet suggests.

What follows is a practitioner’s guide rather than a product pitch. It covers what actually changed at end of support, what the Extended Security Updates meter really costs, which Windows 11 protections cannot be retrofitted onto Windows 10 at any price, what Surface 5G hardware exists today and what it genuinely does, where the Surface 5G business case is weakest, how to sequence the migration waves, what to measure, and the failure patterns common enough to name in advance. Prices quoted are indicative United States list prices at the time of writing and vary by region, configuration, and agreement.

Surface 5G and Windows 11 After Windows 10: The Quick Answer

If you want the compressed version: there are only three defensible endpoint positions after Windows 10, Surface 5G is the strongest expression of one of them, the cheapest-looking one gets more expensive every year, and the one most organisations have actually adopted — doing nothing and hoping — is not on the list.

Position one is paid extension. You enrol eligible Windows 10 22H2 devices in Extended Security Updates and buy time. It is legitimate as a bridge and indefensible as a destination, because the price doubles annually, the programme ends after three years, and it delivers critical and important security fixes only. Position two is refresh to Windows 11 hardware, of which Surface 5G is the most capable and most expensive expression, and which is the only option that improves your security posture rather than merely preserving it. Position three is to move the desktop itself into a Cloud PC and let the endpoint become a thin, replaceable access device, which changes the cost model from capital to consumption and shifts the resilience problem to your network.

Most real fleets end up running all three at once, which is fine as long as it is a designed outcome rather than the residue of three years of deferral. The table below is the shape of the decision.

Option What it actually buys Hard end date Security posture The number that decides it
Extended Security Updates Critical and important patches only, no features, no general support 12 October 2028 maximum Frozen, then abandoned Cumulative per-device ESU spend over the remaining runway
Windows 11 refresh, standard hardware Supported servicing, hardware-backed protections Version-dependent, rolling Improved, retrofit-proof Cost per device including deployment labour and app remediation
Windows 11 refresh, Surface 5G The above plus cellular-first connectivity and Secured-core baseline Version-dependent, rolling Improved, plus one class of network risk removed Cost per device plus data plan, against untrusted-network incident exposure
Windows 365 Cloud PC Windows 11 desktop delivered to any endpoint, ESU entitlement included Subscription-bound Centralised, network-dependent Monthly per-user cost against refresh amortised over four years
Do nothing An unpatched endpoint estate Already passed Deteriorating monthly The excess on the cyber policy you may no longer be able to claim against

Read that table by its final column. Every row has a number that settles the argument, and in most organisations not one of the five has been calculated. That is the actual problem, and pricing the Surface 5G row honestly alongside the other four takes about a week of finance and IT time.

What Actually Changed on 14 October 2025

It is worth being precise about end of support, because the vagueness around it is what allows the Surface 5G decision to be deferred.

On 14 October 2025, Microsoft stopped providing technical support, feature updates, and quality updates — including security and reliability fixes — for the affected versions of Windows 10. The machines did not stop working, no telemetry switch was thrown, and no licence expired. What ended was the supply of fixes for vulnerabilities discovered from that date onward, which is a different and slower kind of failure than the one people brace for.

The practical consequence is that every Patch Tuesday since has widened the gap. Vulnerabilities disclosed and fixed in Windows 11 exist in shared code paths in Windows 10, and the fix itself is a specification for the attack. This is the ordinary dynamic of post-end-of-support platforms and it is well documented across two decades of Windows lifecycle transitions. Nothing about it is speculative, and nothing about it is visible on a device that seems to be working perfectly, which is why a Surface 5G case has to be argued from evidence rather than from symptoms.

The distributional picture matters too. Windows 11 passed a clear majority of the Windows desktop base during 2026, but StatCounter’s Windows version data still put Windows 10 at roughly thirty percent of desktop Windows share in July 2026, against just under sixty-nine percent for Windows 11. Those figures are sampled from web traffic rather than taken from a device census, so treat them as direction rather than as an installed-base count. Whatever the exact figure, the residual is not a rounding error. It is a very large installed base of machines that are, in security terms, standing still while the threat environment does not — and it is the reason the Surface 5G and Windows 11 conversation is still live rather than historical.

The Windows 10 ESU Meter Is Now the Expensive Option

The Extended Security Updates programme is the most misunderstood line item in this entire decision, usually because it is quoted as a single small number rather than as a schedule, and it is the schedule that makes a Surface 5G refresh look inexpensive.

For commercial and educational organisations, Microsoft’s published ESU terms set Year One at 61 US dollars per device through volume licensing, and state plainly that the price doubles every consecutive year, for a maximum of three years. The arithmetic that follows is not a forecast: Year Two is 122 dollars per device and Year Three is 244 dollars, giving a cumulative 427 dollars per device for the full three-year runway. Year One coverage runs from 15 October 2025 to 13 October 2026; Year Two from 14 October 2026 to 12 October 2027; Year Three from 13 October 2027 to 12 October 2028.

Two mechanics inside that programme cost organisations real money because they are discovered late. The first is that ESU is cumulative and cannot be bought in partial periods. An organisation that skipped Year One and decides in November 2026 that it needs coverage must buy Year One retroactively as well, at a combined 183 dollars per device before it receives a single Year Two patch. Deferral is not free here; it is pre-paid at full price, and every deferred month shortens the runway available to a Surface 5G programme.

The second is what the money does not buy. ESU excludes new features, customer-requested non-security updates, and design change requests, and it explicitly does not include general technical support for Windows. Support under ESU covers licence activation, installation of the ESU itself, and regressions caused by it — and even that requires an active support plan. A Windows 10 device under ESU that develops an unrelated fault is, from a vendor support perspective, a device you are on your own with, which is a materially different proposition from an in-warranty Surface 5G machine under remote firmware management.

There are genuine exceptions worth knowing. ESU is included at no additional cost for Windows 10 virtual machines running in Windows 365, Azure Virtual Desktop, Azure virtual machines, Azure Local, Azure Stack, Nutanix Cloud Clusters on Azure, and Azure VMware Solution. Windows 10 endpoints connecting to a Windows 365 Cloud PC are also entitled to ESU for up to three years with an active Windows 365 licence. If a meaningful share of your Windows 10 estate is virtual or is acting purely as a Cloud PC client, your real ESU bill is smaller than the device count suggests, and you should establish that before comparing it against a Surface 5G refresh.

Why “It Still Boots” Is Not a Security Position

The most common objection to a Surface 5G and Windows 11 programme is not technical or financial. It is that the current machines are fine, and the person saying it is describing an observation rather than a control.

The threat data does not support the observation, and it is the strongest evidence available for a Surface 5G and Windows 11 case. Microsoft’s 2025 Digital Defense Report found that more than half of cyberattacks with a known motive were driven by extortion or ransomware, and — more directly relevant here — that the overwhelming majority of ransomware attacks it observed reaching the encryption stage involved unmanaged or under-managed devices somewhere in the chain. Microsoft’s incident response findings in the same body of work attribute a substantial share of intrusions to unpatched internet-facing assets and exposed remote services, which is precisely the category an out-of-support endpoint drifts into as its management agents age out of support alongside it.

That last mechanism deserves emphasis because it is the one that surprises people. An unsupported operating system does not fail alone. Endpoint detection agents, VPN clients, browsers, management agents, and cryptographic libraries all publish their own support matrices, and they drop the retired platform on their own schedules. An organisation that budgeted for three years of ESU frequently discovers in year two that its detection coverage on those devices has quietly degraded, which converts a patched-but-old endpoint into an unmonitored one, and which is precisely the failure a Surface 5G refresh forecloses. This is the distinction between security and resilience that we have covered in detail elsewhere: the difference between cyber resilience and cyber security is the difference between preventing an incident and still functioning during one, and an unsupported endpoint fleet erodes both at once.

A Surface 5G refresh is not the only answer to that. It is, however, the only answer that also resets the hardware root of trust, and that matters for the protections discussed next.

The Windows 11 Security Baseline You Cannot Retrofit onto Windows 10

The single strongest technical argument for a Surface 5G and Windows 11 migration has nothing to do with the user interface. It is that a specific set of Windows 11 protections are on by default and depend on hardware that most Windows 10 fleets do not have — and no amount of ESU spending changes that.

Windows 11 requires a compatible 64-bit processor from a supported list, UEFI firmware with Secure Boot capability, and TPM 2.0, as set out in Microsoft’s published system requirements. Those requirements were unpopular precisely because they are load-bearing. Secure Boot constrains what can execute before the operating system loads. TPM 2.0 provides a hardware-anchored place to seal keys and to measure boot state so that something other than the machine itself can attest to its integrity. Neither is a feature you enable in a policy; both are properties of the silicon and firmware underneath.

The practical outcome is a default posture rather than a hardened one. On a compliant Windows 11 device, virtualization-based security, hypervisor-protected code integrity, and credential isolation are available as defaults on supported hardware rather than as a project. On a typical Windows 10 machine that predates the requirements, some of those features can be switched on and will run poorly, some will run in software with a performance cost, and some cannot run at all. The gap is not a licensing gap that a Surface 5G purchase order happens to close. It is a hardware gap, and the purchase order is simply the mechanism.

This is why framing the decision as “Windows 11 versus ESU” understates it. ESU keeps the old floor swept. Windows 11 on Surface 5G-class hardware raises the floor. Only one of those two changes what an attacker has to do.

Three solid blocks in a row, each exactly twice the height of the one before it and casting a longer shadow, with the platform ending in a sheer drop beyond the tallest, the Extended Security Updates price doubling annually before the programme stops

TPM 2.0, Secure Boot and Why the Hardware Floor Exists

It is worth spending a paragraph on what the hardware floor actually does, because “TPM 2.0 required” has been repeated so often that its purpose has been flattened into a compatibility annoyance.

Secure Boot’s job is narrow and important: it ensures the firmware only hands control to code signed by a trusted authority, which closes off the class of attack that installs itself before any operating system defence is running. A bootkit that loads ahead of the kernel is invisible to everything that loads after it, and it survives a reinstall. That is the failure mode Secure Boot exists to prevent, and it is why every Surface 5G configuration ships with it rather than treating it as an option.

TPM 2.0’s job is to be a small piece of hardware that cannot be lied to. It holds keys that never leave it in usable form, and it records measurements of the boot sequence that can be reported to a remote party. The second half of that is the underrated half. Health attestation — the ability for a conditional access policy to require evidence that a device booted in a known-good state before it is given a token — is only credible with a hardware root of trust. Without it, “device compliance” is a claim made by software running on the device that might already be compromised.

Put those together and the argument for the Surface 5G hardware floor stops being about performance. You are buying the ability to make and verify a statement about the machine, which is the foundation that everything in a zero trust architecture stands on. Our discussion of identity-aware proxies as the new network perimeter assumes exactly this: that the device signal feeding the access decision is trustworthy. On unattestable hardware it is not, and the whole model degrades to identity alone, which is the strongest non-financial argument for a Surface 5G hardware floor.

Virtualization-Based Security, HVCI and Credential Guard in Practice

The Windows 11 protections that matter most in a real incident on a Surface 5G fleet are the ones that make stolen credentials useless and injected drivers unloadable, and they are worth understanding at the level of what they stop.

Virtualization-based security uses the hypervisor to carve out a memory region that the normal kernel cannot read, even with full administrative rights on the machine. Credential Guard puts derived domain credentials in that region, which breaks the standard pass-the-hash and pass-the-ticket workflow that turns one compromised laptop into lateral movement across a domain. Hypervisor-protected code integrity moves the decision about which kernel-mode code may execute into the same protected region, which blocks vulnerable-driver loading — the technique that has underpinned a long series of endpoint defence bypasses.

None of that is exotic and none of it is new. What is new is that it is the default on a compliant Windows 11 device such as a Surface 5G configuration, rather than a hardening project competing for attention. On a Surface 5G device the relevant features are enabled out of the box under Windows 11 Pro with Secured-core configuration, which removes the most common reason these controls are absent in practice, which is that nobody got round to it.

The honest caveat is that virtualization-based security carries a measurable performance cost on older silicon and can conflict with legacy drivers, which is exactly why so many Windows 10 fleets never turned it on. Surface 5G-generation hardware absorbs the cost. This is one of the few places in enterprise IT where a hardware refresh genuinely removes a trade-off rather than moving it, and it is a large part of why a Surface 5G refresh is a security programme with a device purchase attached rather than the reverse.

Microsoft Pluton and the Secured-Core Surface 5G Baseline

Secured-core is a specification rather than a marketing tier, and every current Surface 5G configuration ships to it.

In Microsoft’s May 2026 announcement of the current Surface for Business devices, the line-up is described as Secured-core PCs with chip-to-cloud protection, memory-safe firmware built on Project Mu and Open Device Partnership UEFI, Rust-based drivers, and a secure embedded controller. Those are not consumer-facing features and they will never appear in a review. They are supply-chain and firmware-integrity claims, and firmware is the layer where the ordinary endpoint security stack has the least visibility.

The Microsoft Pluton security processor is the component most relevant to a Surface 5G deployment. Pluton integrates the root of trust into the processor die rather than leaving it as a discrete chip communicating over a bus, which closes the physical-interception path against a discrete TPM. Microsoft’s Surface for Business material describes Pluton as securing identities and encryption keys in hardware, alongside Windows Hello and BitLocker. For a fleet of Surface 5G devices that leave the building — which is the entire premise of buying cellular hardware — the threat model includes physical possession, and a die-integrated root of trust is a meaningfully better answer than a socketed one.

The point for planning purposes is that Secured-core is not something you configure onto a Surface 5G device after the fact. It is a property of the device you ordered, which means the specification decision at procurement time is a security decision. Organisations that let purchasing default to the cheapest configuration on the catalogue frequently discover that they bought the right brand and the wrong posture. A Surface 5G order is a security specification, not a stationery requisition.

What the 58 Percent Figure Does and Does Not Prove

Any article recommending Windows 11 will eventually meet Microsoft’s headline security statistic, and it deserves a paragraph of scepticism rather than a citation and a nod.

The figure that circulates is a 58 percent drop in security incidents, including a 3.1 times reduction in firmware attacks, and it appears in Microsoft’s own security communications about Windows 11. The footnote matters more than the number: it originates in a Techaisle survey commissioned by Microsoft in February 2022. That is self-reported data, gathered by a vendor-commissioned survey, about the vendor’s own product, at a point when Windows 11 adopters were a self-selecting early cohort likely to be better resourced and better managed than average.

None of that makes the figure dishonest, and the direction of the effect is entirely plausible given what virtualization-based security and a hardware root of trust actually do. It does mean the number should not appear on a slide to your board as though it were an independently measured outcome, because someone will eventually check the footnote and the correction will cost you more credibility than the statistic bought.

The defensible version of the Surface 5G claim is mechanical rather than statistical. Windows 11 on Surface 5G hardware makes specific documented attack techniques harder — pre-boot code execution, credential theft from LSASS, vulnerable-driver loading, and firmware persistence — and you can name each one and explain what blocks it. That argument survives scrutiny. The percentage does not need to carry any weight, and it should not be asked to.

Windows 11 Resiliency: Quick Machine Recovery, Hotpatching and the Reboot Budget

The word “resilience” in the title of this article is not decoration, and the Windows 11 features that earn it are operational rather than defensive.

The Windows Resiliency Initiative is Microsoft’s response to a specific, well-remembered class of failure: a fleet of machines that will not boot, in offices the IT team cannot reach, with no remote channel available because remote channels require a booted machine. Quick machine recovery, now generally available in Windows 11 version 24H2, allows a device that fails to boot to reach Windows Update from the recovery environment and receive a targeted remediation. That converts a desk-side visit into a policy, and for a distributed Surface 5G fleet it is the difference between a bad afternoon and a bad fortnight.

Hotpatching is the other half. On Windows 11 Enterprise 24H2 and Windows 365, hotpatching applies certain security updates to in-memory code without a restart, which reduces the number of forced reboots per year on covered devices. That sounds like a convenience feature and is not. The reboot budget is the real constraint on patch latency in most organisations — patches are deferred because restarting a user mid-task has a cost — and reducing the number of restarts required directly reduces the window in which a known vulnerability sits unpatched on a live endpoint.

Neither capability exists on Windows 10 under ESU, and this is the cleanest way to express what the ESU decision really is. ESU buys you the fixes. It does not buy you the machinery that gets the fixes applied faster or recovers the device when something goes wrong. A Surface 5G fleet on Windows 11 gets both, and the second one is what turns a security programme into a resilience programme.

One large solid block with a small extremely dense glowing core sealed at its centre behind unbroken walls, threads of light running out to five smaller blocks around it, a hardware root of trust anchoring the protections built on it

Why Surface 5G Changes the Network Assumption

Here is where the Surface 5G argument becomes distinct from a generic Windows 11 refresh, and it is the part most business cases leave out entirely.

Every mobile endpoint in a conventional, non-Surface 5G fleet carries an implicit assumption: that when the user is away from the office, they will find a network, and that network will be somebody else’s. Hotel Wi-Fi, airport Wi-Fi, a client’s guest network, a conference SSID, a café. The security response to that assumption is a stack of compensating controls — always-on VPN, DNS filtering, certificate pinning, user training — each of which works most of the time and none of which works when the user is in a hurry and the captive portal is misbehaving.

A Surface 5G device removes the assumption instead of compensating for it. With an integrated modem and a provisioned profile, the device has its own carrier connection the moment it is opened, and the untrusted intermediate network simply is not in the path. This is not a claim that cellular is cryptographically perfect; it is a claim that the specific, common, cheap attack against a laptop on a hostile local network requires the laptop to be on that network. Take the laptop off it and the attack class goes away rather than being detected.

The corresponding operational gain is at least as large. Users who do not have to hunt for a network do not tether to personal phones, do not disable the VPN to make a captive portal work, and do not defer a Windows update because the connection is poor. Patch compliance on a Surface 5G fleet is structurally better than on a Wi-Fi-dependent one, for reasons that have nothing to do with user discipline. That is a resilience argument, and it is the one that justifies the Surface 5G premium more convincingly than any speed figure.

The Public Wi-Fi Problem Surface 5G Removes

It is worth naming the attack precisely, because “public Wi-Fi is risky” has been repeated into meaninglessness.

The technique is catalogued by MITRE as adversary-in-the-middle via an evil twin. An attacker stands up an access point advertising an SSID that a target device either recognises or will plausibly accept, the device associates, and the attacker now occupies the network path. From there the available moves include captive-portal credential harvesting, downgrade attempts against poorly configured clients, DNS manipulation, and traffic analysis that reveals which internal services a device reaches for even when payloads are encrypted. The equipment costs less than a keyboard and the skill floor is low. Nothing in that description requires the target to be interesting; it requires the target to be on the network, which is the assumption Surface 5G deletes.

Modern defences blunt most of this. Certificate validation, HTTP Strict Transport Security, and always-on VPN tunnels mean an evil twin usually yields metadata rather than credentials. But “usually” is carrying weight there, and the residual is a function of every client on the device being correctly configured, every certificate being validated, and the VPN actually being connected at the moment it matters. A Surface 5G endpoint that never associates with the rogue access point does not depend on any of that being true.

There is a second-order benefit for the security team. Every Wi-Fi-borne alert that a cellular-first fleet does not generate is analyst time returned to work that matters, which is the same argument we made about consolidating tooling to avoid security tool sprawl. Removing a source of noise is worth more than adding a detection for it, and Surface 5G removes a source of noise at the network layer rather than filtering it downstream.

The honest limit is that this only applies to devices that actually have and use the cellular connection. A Surface 5G device with an unprovisioned modem, or one whose users default to hotel Wi-Fi because the data allowance is stingy, delivers none of this. The control is the provisioned, funded, policy-enforced connection, not the hardware.

Surface 5G, eSIM and Zero-Touch Provisioning

The reason cellular endpoints failed to catch on a decade ago was logistics, and the reason a Surface 5G standard is viable now is eSIM.

Physical SIM management at fleet scale was genuinely awful: cards ordered per carrier, shipped to a depot, inserted by hand, tracked in a spreadsheet, and reconciled against a carrier bill that never matched. eSIM replaces that with a profile that can be downloaded to the device. Microsoft’s guidance on eSIM deployment for Surface devices describes provisioning cellular profiles through Intune alongside other device policy, which means Surface 5G connectivity configuration travels the same path as everything else you manage.

Combine that with Windows Autopilot and the Surface 5G deployment story becomes genuinely zero-touch. A device ships from the manufacturer to a home address, the user signs in, and the device enrols, applies policy, downloads its cellular profile, and becomes a managed corporate endpoint without a technician ever touching it and without depending on the user’s home network being present or trustworthy. For distributed organisations, that last clause is the whole point: the provisioning path itself no longer runs over an unknown network.

Current Surface 5G hardware also retains a physical nano-SIM alongside eSIM. That matters more than it appears to, because it is the escape hatch for regions where your primary carrier has no agreement, for short international deployments, and for the specific customer sites where a local SIM is the only workable answer. Design your Surface 5G standard around eSIM and keep the nano-SIM slot as the exception path rather than pretending it will not be needed.

Which Surface 5G Devices Actually Exist Right Now

Precision here saves a Surface 5G procurement a fortnight, because “Surface has 5G” is true of some models and not others, and the pattern is not intuitive.

The dedicated cellular device that opened the current generation was Surface Laptop 5G, announced in July 2025 and shipping from 26 August 2025. It is a 13.8-inch Intel Core Ultra Series 2 machine weighing under three pounds, with a 40-plus TOPS neural processing unit, six antennas positioned around the chassis with dynamic switching, support for both nano-SIM and eSIM, and a custom multi-layer laminate enclosure engineered to let signal through an otherwise metal body. It can also act as a mobile hotspot, which quietly makes it the connectivity fallback for whatever else the user is carrying.

The current business line-up, announced in May 2026, moved to Intel Core Ultra Series 3 across Surface Laptop for Business at 13, 13.8, and 15 inches, and Surface Pro for Business at 13 inches, with Snapdragon X2 configurations following later in 2026. Wi-Fi 7 is standard and Surface 5G is an option on selected configurations rather than across the range. Microsoft’s Surface Pro for Business model comparison currently shows optional 5G on the 13-inch Intel Core Ultra Series 3 configuration and on the earlier 13-inch Snapdragon configuration, while the 12-inch Snapdragon model and the 11th Edition Intel model are Wi-Fi only.

Indicative United States list pricing at the time of writing starts around 1,499 dollars for the 13-inch Surface Laptop for Business, around 1,949 dollars for the 13.8 and 15-inch models and for the Surface Pro for Business 13-inch Intel configuration, and around 1,649 dollars for the Snapdragon Surface Pro for Business. The Surface 5G option adds cost on top of those figures. Treat all of it as a starting point for a quotation rather than as a price, and confirm the exact SKU carries 5G before the purchase order goes out, because that is the single most common procurement error in a Surface 5G rollout.

Surface 5G Is Not Universal: Coverage, Carrier and Region Caveats

Microsoft’s own materials carry the qualification and it should be carried into your business case rather than dropped from it: 5G availability varies by carrier, by region, and by specific configuration, and it is not offered everywhere.

That has three planning consequences. The first is that a Surface 5G standard cannot be applied uniformly across a multinational fleet without a coverage and carrier check per country. The device will work; the connectivity model may not, and discovering that after shipping two hundred units to a region your carrier does not serve is an expensive way to learn it. The second is that Surface 5G data plan economics vary enormously by market, and a per-device monthly cost that is trivial in one country can be the largest line in the total cost of ownership in another.

The third is subtler and more often missed. Cellular performance in a specific building is not a national statistic. Basements, older commercial buildings with heavy structure, and hospital or industrial sites frequently have poor indoor cellular coverage and excellent managed Wi-Fi, which inverts the entire Surface 5G argument for those users. A sensible Surface 5G programme surveys the places its users actually work rather than assuming national coverage maps apply indoors, and it accepts that some cohorts are better served by Wi-Fi 7 on a well-designed corporate network — which is a different investment, addressed in our piece on smart office infrastructure and Wi-Fi 7.

None of these caveats invalidate the Surface 5G case. They determine which portion of your fleet it applies to, which is a question worth answering with data rather than with enthusiasm. In most organisations the genuinely cellular-first cohort is somewhere between ten and forty percent of users, and the business case is far stronger when it is scoped to them than when it is spread across everyone.

Two identical upright slabs, the left one fed by a channel that passes through a dark angular block where the light dims and scatters, the right one fed by a clean unbroken beam descending from above, an intercepted network path beside a direct cellular one

Copilot+ PCs, NPUs and Whether the AI Story Should Drive the Refresh

Every current Surface 5G configuration is also an AI PC, and this is where refresh business cases most often go wrong.

The Copilot+ PC classification requires a neural processing unit capable of more than 40 trillion operations per second. Current Surface for Business hardware clears that comfortably — Microsoft cites around 50 TOPS on the Intel Core Ultra Series 3 Surface Pro for Business and around 80 TOPS on the Snapdragon X2 configuration. Those are real capabilities and they enable genuinely useful local inference: on-device transcription, background processing, and a class of assistive feature that does not send content to a service.

The problem is using that as the justification for a Surface 5G refresh. An NPU is a capability, not an outcome, and an organisation that has not redesigned any workflow around local inference will realise nothing from it beyond a slightly better video call. We looked at this arithmetic directly when asking whether an NPU fleet upgrade is actually worth it, and the conclusion holds here: the AI capability should be treated as a free option that arrives with a device you were replacing anyway, not as the reason to replace it.

There is a related governance point. Local inference does not remove your data governance obligations, and a fleet of Copilot-capable endpoints attached to a poorly permissioned tenant will surface content faster than your access model can defend — which is the argument we made at length about securing and governing Microsoft 365 Copilot with Purview. Buy the Surface 5G hardware for the security floor, the servicing, and the connectivity. Treat the NPU as upside, and do the permission work separately.

Building the Windows 11 Migration Wave Plan

The Surface 5G migration itself is a logistics exercise, and the organisations that do it badly are almost always the ones that treated it as a single event.

The unit of planning is the wave, and the wave is defined by application risk rather than by department or geography. Wave zero is IT and the migration team, which sounds self-serving and is not: the team that will handle the exceptions needs to have lived through them. Wave one is the population with the smallest and best-understood application surface — typically frontline, sales, or field roles running a browser and the productivity suite, which is also frequently the cohort with the strongest Surface 5G case. Wave two is general knowledge work. Wave three is the specialist estate: engineering workstations, finance close tooling, clinical or laboratory systems, and anything with a hardware dongle or a vendor who has not published a Windows 11 statement.

Two rules make the difference between a wave plan and a wish. First, every wave has an entry gate and an exit gate, and the exit gate includes decommissioning the device that was replaced. Second, the specialist estate gets its remediation work started at the same time as wave one, not after wave two completes, because that work is bounded by third-party vendor timelines you do not control.

Run the waves against a live inventory rather than the asset register. In most organisations the asset register overstates coverage by a double-digit percentage, and the machines it misses are disproportionately the ones nobody owns — which are, per the ransomware data quoted earlier, exactly the machines that matter. If your estate is genuinely scattered across corporate and personal hardware, the discovery problem is the first problem, and we have written separately about restoring control over fragmented corporate and BYOD fleets.

The Application Compatibility Work Nobody Budgets

Compatibility is the most common cause of a stalled Windows 11 programme, and it is rarely the operating system’s fault.

The applications that break are predictable: anything with a kernel-mode driver, anything depending on a specific TLS or cryptographic behaviour, anything with a hardware licensing dongle, anything last built against a framework that has since reached end of life, and anything supplied by a vendor whose support statement stops at Windows 10. In practice the Windows 11 application compatibility rate for ordinary line-of-business software is high, and the residual few percent absorb most of the programme’s effort and nearly all of its delay.

The mechanism that works is unglamorous. Inventory the installed application estate from telemetry rather than from memory, rank by user count multiplied by business criticality, and start vendor conversations with the top of that list immediately. For each application, record one of four states: confirmed supported, supported after upgrade, unsupported with a replacement identified, or unsupported with no path. The last category is where the programme’s real risk sits, and it needs an owner and a date rather than a note.

Budget explicitly for remediation alongside the Surface 5G hardware line. A migration business case that funds devices and deployment labour but not application remediation will be re-opened in month four, and re-opening a business case costs more political capital than the original approval did. As a rough planning heuristic, treat application work as a material fraction of programme cost rather than a rounding error, and treat any estimate produced without a telemetry-based inventory as a guess.

Where an application genuinely has no Windows 11 path and cannot be replaced, the answer is isolation rather than delay: run it on a small, segmented, well-monitored estate — ideally virtualised, where the ESU entitlements described earlier may apply — and let the rest of the fleet move to Surface 5G and Windows 11. Holding an entire migration hostage to one unsupported application is a choice, and it should be made explicitly by someone senior rather than by default.

Windows 11 Servicing: The Version You Standardise On

Choosing a target version sounds like a detail and is actually the decision that determines how often you do this again.

The current servicing picture is worth stating plainly because it has become genuinely confusing. Windows 11 version 24H2 reaches end of servicing for Home and Pro on 13 October 2026 — which is to say, within weeks of this article. Version 25H2 runs to 12 October 2027 for Home and Pro and to 10 October 2028 for Enterprise and Education. Version 26H1, which began servicing on 10 February 2026, runs to 14 March 2028 for Home and Pro and 13 March 2029 for Enterprise and Education, and it is the version most likely to be preinstalled on newly purchased Surface 5G hardware.

The critical detail about 26H1 is that Microsoft scoped it to new devices coming to market rather than as a general feature update, and it is not offered as an in-place update from 24H2 or 25H2 on existing devices. That produces a real operational hazard during a Surface 5G rollout: newly delivered hardware may arrive on a version that your existing fleet cannot be moved to, and your image, driver, and policy baselines have to accommodate both. Verify current dates against Microsoft’s release information before you commit a plan, because this schedule has moved before.

The pragmatic answer for most organisations is to standardise the existing fleet on the Enterprise or Education servicing of the latest broadly deployable version, accept that new Surface 5G deliveries will land on whatever ships with them, and use Windows Autopatch to converge the estate over the following servicing cycle rather than attempting to force uniformity on day one. Uniformity is a nice-to-have. Being inside a supported servicing window on every device is the actual requirement.

A row of plain unlit slabs travelling along a glowing channel through a single sealed arch and emerging on the far side lit and each encircled by its own ring of light, zero-touch provisioning turning bare hardware into a governed endpoint

Autopilot, Intune and Autopatch Under a Surface 5G Fleet

A Surface 5G refresh that lands on an immature management plane produces a modern fleet you cannot see, which is a worse position than an old fleet you can.

The minimum viable management plane under a Surface 5G fleet has four parts. Autopilot handles provisioning so that devices go from carton to compliant without a build room. Intune carries configuration, compliance policy, application delivery, and — for cellular devices — the eSIM profile. Autopatch handles update rings so that patch deployment is a schedule rather than a monthly negotiation. And the Surface Management Portal gives device-level firmware and health visibility that generic tooling does not surface, which matters specifically because firmware is where Secured-core does its work.

Device Firmware Configuration Interface deserves a specific mention. DFCI allows firmware settings on Surface hardware — boot order, integrated peripherals such as cameras and radios, and firmware-level security options — to be managed from Intune rather than by a technician at the device. On a Surface 5G fleet that may never be physically handled by IT, remote firmware control is not a convenience feature; it is the only way to change a firmware setting at all.

If your Intune practice is immature, fix that before the Surface 5G hardware arrives rather than during. The sequencing failure — buy devices, then discover the management plane is not ready, then hand-configure the first three hundred units — is the single most expensive mistake in a refresh programme, and it is entirely avoidable. Organisations starting from a standing start should look at the baseline setup work first; our Intune setup guide for smaller organisations covers the order of operations that avoids most of it.

Identity and Conditional Access in a Cellular-First Fleet

A Surface 5G fleet quietly breaks one assumption that many access policies still rest on, and it is better to find that in design than in production.

Plenty of conditional access configurations include network location as a signal — trusted IP ranges corresponding to offices, or the corporate VPN egress. A Surface 5G device connecting over a carrier network is, from the policy’s perspective, coming from an arbitrary consumer IP address every time. If your policies grant reduced friction on trusted networks, your most mobile and best-secured devices will encounter the most friction, and users will find their way around it.

The correct response is to move the weight of the access decision onto device state and identity strength rather than network position, which is the direction zero trust architecture has pointed for a decade anyway. A Surface 5G device is unusually well equipped for this: it can attest its boot state through a hardware root of trust, report compliance through Intune, and carry a phishing-resistant credential in hardware. Those are stronger signals than an IP range has ever been, and building the policy on them makes the Surface 5G transition a simplification rather than an exception.

The transitional risk is real, though. During a migration you will be operating mixed policy for months, and the most common failure is a policy that was written for the old assumption silently blocking or silently permitting the new devices. Test conditional access explicitly against a Surface 5G device on cellular, off VPN, in the configuration a real user will have, before wave one and not after it.

What a Surface 5G Fleet Actually Costs

The Surface 5G business case fails most often because it compares the wrong two numbers: a device price against an ESU price, with everything else left out of both sides.

On the Surface 5G side, the honest total includes the device at its configured price rather than its starting price, the cellular option, deployment and enrolment labour, application remediation attributable to the migration, accessories and docks, a data plan per device per month for the life of the device, and the residual value or disposal cost of the machine being replaced. The data plan is the line most often forgotten and it compounds: at even a modest monthly rate across a four-year device life, connectivity can approach a meaningful fraction of the hardware cost, and in high-tariff markets it can exceed it.

On the Windows 10 side, the honest total includes the cumulative ESU licence at 61, 122, and 244 dollars per device across the three years, the labour of enrolling and maintaining the ESU keys, the growing cost of compensating controls for an unsupported platform, the support cost of ageing hardware with rising failure rates, and — the item nobody quantifies — the cost of the third-party agents that will drop support for the platform before you do. Neither total is the sticker price on either side, and a Surface 5G business case built on sticker prices will not survive its first review.

There is also a disposal and compliance cost at the end of the old fleet’s life that belongs in the model rather than in a later surprise, and it is not small once data sanitisation obligations are handled properly. We have covered the penalties attached to getting that wrong in our piece on hardware decommissioning and data sanitisation compliance, and the sustainability reporting consequences of a large refresh belong in the same conversation, as set out in our guide to ESG metrics across the IT asset lifecycle.

The Cost Comparison That Decides It

Once both totals are honest, the Surface 5G comparison usually resolves faster than people expect, and the table below is the frame that resolves it.

Cost element Stay on Windows 10 with ESU Refresh to Surface 5G How to source the number
Licence or device 61, then 122, then 244 US dollars per device per year, cumulative Configured device price, not the starting price Volume licensing quote; hardware quotation for the exact SKU
Connectivity Existing Wi-Fi and VPN estate Carrier data plan per device per month Carrier proposal per region, multiplied by device life
Deployment labour Enrolment and key management per device Autopilot provisioning, near zero-touch at steady state Time-and-motion from your wave zero pilot
Application work Deferred, then incurred anyway at migration Incurred once, during the programme Telemetry-based application inventory
Support burden Rising with hardware age and agent attrition Falling; in-warranty, remotely manageable Service desk ticket rates by device age
Security posture Frozen; compensating controls only Secured-core, attestable, hotpatchable Named techniques blocked, not a percentage
Terminal date 12 October 2028, no extension available Rolling servicing, no cliff Microsoft lifecycle documentation

The pattern that emerges in most models is that ESU is genuinely cheaper for one year, roughly a wash over two once agent attrition and support burden are included, and clearly more expensive over three once the cumulative 427 dollars per device is set against a device that would otherwise have been replaced on a normal refresh cycle anyway. The Surface 5G premium over a commodity Windows 11 laptop is real and should be justified on the connectivity and Secured-core arguments for the cohort that needs them, not applied to the whole fleet by default.

Where the Surface 5G Business Case Is Weakest

An honest guide names the cases where its own Surface 5G recommendation is wrong, and there are several.

The weakest case is the desk-bound user. Someone who works in one building on a well-managed corporate network gains nothing from cellular, and the Surface 5G premium plus a data plan is money spent on a risk they do not carry. For that cohort the correct answer is a supported Windows 11 device at commodity pricing, and the security argument is fully satisfied without the cellular option.

The second weak case is the short-runway estate. If a meaningful block of devices is already scheduled for replacement inside twelve months on the normal refresh cycle, ESU for exactly that block is the cheaper and simpler bridge, and forcing an early refresh to avoid a single year of ESU destroys value. Use ESU as designed — as a bridge for a defined population with a defined end date — rather than as a policy for the whole estate.

The third is the virtualised or Cloud PC estate, where the ESU entitlements described earlier may already cover you at no additional cost, and where the endpoint’s specification matters far less because the desktop is not running on it.

The fourth is regional coverage failure, which was covered above and is worth repeating because it is a hard blocker rather than a soft one. And the fifth is an immature management plane: an organisation that cannot currently provision, patch, and attest its existing devices will not be rescued by better hardware, and should spend the first quarter of its budget on the management plane instead. A Surface 5G fleet amplifies whatever operational maturity you already have, in both directions.

Two platforms joined by four parallel glowing bridges with blocks crossing in four distinct ranks, the far platform filling while the vacated sections of the near one break away and fall, migration waves with decommissioning as the exit gate

Windows 365 and Cloud PCs: The Third Option

The option most often omitted from the comparison is not to fix the endpoint at all, and it deserves a fair hearing rather than a footnote.

A Windows 365 Cloud PC delivers a Windows 11 desktop from Microsoft’s infrastructure to whatever the user happens to be holding. The endpoint becomes an access device, and its specification, operating system version, and even its ownership matter far less. For organisations with a large population of Windows 10 machines that cannot meet the Windows 11 hardware floor and are not due for replacement, this is a genuinely strong answer, and it carries the ESU entitlement described earlier for the connecting endpoint for up to three years.

The trade-off is that it converts a hardware problem into a connectivity and consumption problem. A Cloud PC is unusable without a connection, its monthly cost is permanent rather than amortising, and its performance is bounded by the worst network the user encounters. That last point is where the two options in this article turn out to be complementary rather than competing: the failure mode of a Cloud PC strategy is bad connectivity, and a Surface 5G endpoint is precisely the device that does not suffer from it. A Surface 5G endpoint running a Cloud PC is arguably the most resilient configuration available today, and also one of the most expensive per user.

Most organisations should model all three positions for each user cohort rather than choosing one globally. The right answer for a field engineer, a contact-centre agent, a contractor on a personal machine, and a finance analyst running a heavy local model are four different answers, and pretending otherwise is how fleets end up standardised on the wrong thing for eighty percent of their users.

Decommissioning: The Step That Realises the Saving

The saving in a Surface 5G programme is not realised when the new device arrives. It is realised when the old one is switched off, wiped, and removed from every system that still thinks it exists.

This is the step organisations reliably skip, and skipping it has three costs. The obvious one is that the ESU licence, the management licence, and the support contract on the retired device keep billing. The second is that the device stays in the asset register and in the compliance scope, and an unsupported, unpatched machine sitting in a drawer with a valid domain-joined identity is exactly the unmanaged endpoint the ransomware statistics describe. The third is that the programme cannot demonstrate its own benefit, because the cost line it promised to remove never falls.

Make decommissioning a gate rather than a task. A Surface 5G wave is not complete when the new devices are deployed; it is complete when the replaced devices have been collected, sanitised to a documented standard, removed from directory and management, deregistered from conditional access, and either disposed of through an accredited route or redeployed with a recorded destination. Every one of those steps produces evidence, and the evidence is what turns a claimed saving into a booked one.

The residual value question is worth a moment too. A four-year-old Windows 10 machine that cannot run Windows 11 has close to no resale value and a real disposal cost, whereas retiring a fleet before it is fully depreciated may leave book value that finance has to write off. Neither fact changes the security argument, but both belong in the model, and finding them in month one is considerably better than finding them in the year-end review.

Compliance, Cyber Insurance and Unsupported Endpoints

The argument that finally moves budget in many organisations is neither security nor cost. It is contractual.

Cyber insurance applications and renewals increasingly ask direct questions about patch currency, endpoint detection coverage, multi-factor authentication, and whether unsupported operating systems are in use. Answering those questions accurately with a substantial Windows 10 population and no ESU enrolment is difficult, and answering them inaccurately is considerably worse than difficult, because a material misstatement on an application is exactly the ground on which a claim is contested. The same questions appear in customer security questionnaires, in supplier assurance reviews, and in the due diligence attached to any significant contract.

Regulated sectors face a sharper version. Where a framework requires that systems processing regulated data receive security updates, an out-of-support endpoint without ESU is a finding, and ESU enrolment is the evidence that answers it — which is a legitimate reason to buy ESU for a defined population while a Surface 5G refresh runs in parallel. The two are not in opposition; they are a bridge and a destination.

The practical instruction is to get the current position documented before the next renewal rather than after it. Count the unsupported devices, count the ESU-covered ones, count the ones with current endpoint detection, and be able to state the migration schedule with dates. An organisation that can produce that in a meeting is in a materially better negotiating position than one that cannot, regardless of what the numbers say. Where an incident does occur, the quality of the response plan matters more than the device estate, and our ransomware defence playbook covers what that plan needs to contain.

Surface 5G and Windows 11 Deployment Roadmap

The following sequence is what a competent programme runs, in order. It assumes a mixed estate and an imperfect starting position, because that is what everyone has.

Step 1: Establish a telemetry-based inventory

Build a device inventory from what the network and the management plane actually observe, not from the asset register, and reconcile the difference explicitly. Record operating system version, hardware eligibility against the Windows 11 requirements, warranty status, primary user, physical location, and installed applications. The reconciliation gap is your first finding, and in most organisations it is between five and twenty percent of devices.

Step 2: Segment users into connectivity cohorts

Classify every user as desk-bound, hybrid, or genuinely mobile, using building access data or Wi-Fi association history rather than job title. Only the third cohort has a strong Surface 5G case, and sizing it honestly at this stage is what keeps the business case credible later. Expect the genuinely mobile population to be smaller than the organisation believes and larger than facilities data suggests.

Step 3: Decide the ESU bridge population and buy it deliberately

Identify the devices that will still be on Windows 10 after 13 October 2026 and enrol exactly those in Year Two of ESU, with a named owner and a scheduled exit date per device. Buying ESU for a defined, shrinking population is competent bridging. Buying it estate-wide because the migration is undecided is how organisations end up paying 244 dollars per device in 2027.

Step 4: Fix the management plane before the hardware lands

Confirm Autopilot enrolment, Intune configuration and compliance baselines, Autopatch update rings, the Surface Management Portal, and DFCI policy are all working against a pilot group. If any of the five is not ready, delay the hardware order rather than the readiness work. Surface 5G hardware arriving ahead of the management plane is the most expensive sequencing error available.

Step 5: Run the application inventory and start vendor conversations

Rank applications by user count multiplied by criticality, assign each a compatibility state, and open vendor conversations for everything unresolved in the top decile immediately. Vendor timelines are the longest pole in the programme and the only one you cannot compress, so start them before you need the answers rather than when you do.

Step 6: Pilot wave zero, including a real Surface 5G cellular test

Deploy to IT and the migration team, and test a Surface 5G device on cellular with the VPN disconnected, against production conditional access, from outside every trusted network range. Measure provisioning time, eSIM activation success, patch delivery over cellular, and data consumption per user per week. Those four measurements are the inputs to every estimate that follows.

Step 7: Run waves with decommissioning as the exit gate

Execute the waves in the order established earlier, and treat a wave as incomplete until the replaced devices are collected, sanitised, removed from directory and management, and disposed of or redeployed with recorded evidence. Report the decommissioning count alongside the deployment count in every status update, because the gap between the two is where the promised saving disappears.

Step 8: Converge servicing and publish the standing position

Once the waves complete, converge the estate onto a supported servicing branch through Autopatch, and publish a standing statement of the position: devices by operating system version, servicing end dates, ESU coverage, and the next refresh window. That document is what answers the insurer, the auditor, and the customer questionnaire without a fire drill, and maintaining it costs an hour a month.

Surface 5G and Windows 11 Metrics That Matter

The following set is what a defensible Surface 5G and Windows 11 programme reports, with the qualification each one needs. Anything not on this list is supporting colour rather than evidence.

Metric Definition Target direction Principal caveat
Unsupported endpoint count Devices on an operating system past end of support without ESU Zero Must come from observed telemetry, not the asset register
ESU coverage ratio Enrolled devices over Windows 10 devices still in service 100 percent of the bridge population A high ratio on a large population signals a stalled migration, not success
Windows 11 eligible but not migrated Devices that meet the hardware floor and have not moved Falling to zero The cheapest migration wins available; usually under-reported
Patch latency, ninetieth percentile Days from release to installation on the slowest tenth of devices Lower Averages hide the tail, and the tail is what gets exploited
Cellular activation rate Surface 5G devices with an active provisioned profile over those shipped Toward 100 percent Devices with dormant modems deliver none of the security benefit
Untrusted network association rate Share of sessions on non-corporate Wi-Fi Lower on the Surface 5G cohort Only meaningful with a pre-deployment baseline
Data consumption per device Monthly cellular data per Surface 5G user Stable and forecastable Drives the largest recurring cost line; watch the outliers, not the mean
Zero-touch provisioning rate Devices deployed without technician intervention Higher Falls sharply if the management plane was not ready first
Attestable device share Devices reporting hardware-backed health attestation Toward 100 percent The signal every conditional access policy should be leaning on
Reboot count per device per quarter Forced restarts for updates Lower The direct measure of what hotpatching bought you
Decommissioning lag Days from new device deployed to old device sanitised and removed Lower Where the promised saving is realised or lost
Application remediation backlog Applications with no confirmed Windows 11 path Zero The programme’s real critical path
Cost per migrated device, fully loaded Device, connectivity, labour, and remediation divided by devices migrated Falling across waves If it is not falling, the wave structure is not working

The caveat column carries the weight, as always. A programme that reports the deployment count without the decommissioning lag is reporting activity rather than outcome, and someone in finance will eventually notice.

A long row of upright glowing slabs with one fallen dark slab in the middle being lifted back upright and relit by a narrow beam descending from above while the rest of the row stands undisturbed, remote recovery of a single failed device

Common Mistakes in a Post-Windows 10 Refresh

The failure patterns are consistent enough to enumerate, and nearly all of them are organisational rather than technical.

The first is treating ESU as a decision rather than a bridge. Buying Year One without a dated migration plan attached simply relocates the same conversation twelve months later at double the price, and the second conversation is harder because the runway is shorter.

The second is comparing sticker prices. A device price against an ESU price is not a comparison, because it omits data plans, deployment labour, application remediation, agent attrition, and disposal on one side or the other. Both totals have to be honest or neither number means anything.

The third is buying Surface 5G hardware for users who never leave the building. The cellular premium is justified by a risk profile, and paying it for a desk-bound population is the fastest way to make the whole programme look like an indulgence when it is scrutinised.

The fourth is ordering Surface 5G hardware before the management plane is ready. This produces hand-built devices, inconsistent baselines, and a deployment cost per device several times the modelled figure, and it is entirely a sequencing failure rather than a technology one.

The fifth is skipping the cellular reality check. A Surface 5G programme designed from national coverage maps rather than from the buildings and regions users actually occupy will deliver excellent connectivity to some users and a very expensive Wi-Fi laptop to others.

The sixth is leaving conditional access policies built on network location untouched. Cellular devices arrive from arbitrary addresses, and a policy that rewards trusted networks will punish exactly the devices you spent the most to secure.

The seventh is never decommissioning. Running the old fleet alongside the new one indefinitely is the default outcome of a successful deployment, and it guarantees that costs rise while the promised savings stay theoretical.

The eighth is letting the AI capability write the Surface 5G business case. An NPU that no workflow uses is a specification, not a benefit, and a case built on it will not survive its first review by anyone who asks what changed.

Where Surface 5G and Windows 11 Still Fall Short

An honest assessment includes what a Surface 5G and Windows 11 programme does not solve, because overselling is how programmes lose the credibility they need later.

Surface 5G is not a security guarantee. It removes a specific and common attack surface — the hostile local network — and it does not encrypt your application traffic, authenticate your users, or protect you from a compromised credential. Carrier networks have their own documented weaknesses, roaming introduces intermediaries, and a device on cellular is still one phishing email away from the same outcome as a device on Wi-Fi. The Surface 5G benefit is real and narrow, and describing it as broad is the fastest way to have it dismissed entirely.

The hardware premium is genuine and it is not small. A Surface 5G configuration costs materially more than a commodity Windows 11 business laptop, before the data plan, and the security delta over a well-managed non-cellular Windows 11 device is smaller than the delta over Windows 10. If budget is the binding constraint, moving everyone to supported Windows 11 hardware beats moving a subset to Surface 5G, and that ordering should be stated plainly rather than fudged.

Secured-core and attestation raise the cost of attack rather than eliminating it. Firmware attacks are harder against memory-safe firmware and a die-integrated root of trust; they are not impossible. Credential Guard defeats a family of credential theft techniques; it does not defeat a user who approves a malicious authentication prompt. Every control in this article is probabilistic, and a programme that presents them as absolutes will be embarrassed by the first incident that gets through.

The vendor evidence base is thin and self-interested. The headline security percentages come from vendor-commissioned surveys, the device performance claims are vendor benchmarks against selected comparators, and the connectivity claims carry regional qualifications that rarely survive into a slide. All of it is directionally reasonable and none of it is independent, including the parts that support the recommendation this article makes. For the avoidance of doubt, no vendor or product is endorsed here, and Progressive Robot has no commercial relationship with any party named in this article.

Finally, this is a migration and migrations have their own risk. A large fleet change concentrates operational risk into a defined window, and organisations have caused themselves more disruption through a badly sequenced Surface 5G refresh than the unpatched estate would have caused in the same period. The wave structure, the pilot, and the decommissioning gate exist to manage that, and they are not optional decoration.

Frequently Asked Questions

Is Windows 10 unsafe to use right now?

It is unsupported rather than instantly unsafe, which is a slower and more dangerous condition. Without ESU, no security fixes have been issued for it since 14 October 2025, so the exposure grows with every disclosed vulnerability in shared code. The practical risk is compounded by third-party agents progressively dropping support, which erodes the detection coverage on those devices. Treat it as a risk that accumulates monthly rather than a switch that flips.

Can we just keep paying for Extended Security Updates indefinitely?

No. Commercial ESU is capped at three years and ends on 12 October 2028, the price doubles annually from 61 to 122 to 244 US dollars per device, and it is cumulative — enrolling late means paying for the years you skipped. It also excludes new features, non-security updates, and general technical support. It is a competent bridge for a defined population with a dated exit and an expensive way to defer a decision otherwise.

Do we need Surface 5G specifically, or will any Windows 11 laptop do?

For the security floor, any device meeting the Windows 11 hardware requirements delivers the hardware-backed protections, and that is the majority of the benefit. Surface 5G adds the Secured-core baseline and, more importantly, cellular connectivity that removes the untrusted-network attack surface. Buy it for the genuinely mobile cohort, and buy supported commodity Windows 11 hardware for everyone else.

How much does a Surface 5G device actually cost?

Indicative United States list pricing for current Surface for Business hardware starts around 1,499 dollars for the 13-inch Surface Laptop for Business and around 1,949 dollars for the larger models and the Intel Surface Pro for Business, with the 5G option and higher memory and storage configurations adding to that. Add a carrier data plan per device per month for the device’s life. Treat published figures as a starting point for a quotation rather than as a price.

Which current Surface models actually offer 5G?

Not all of them, and the Surface 5G pattern is not intuitive. Surface Laptop 5G is the dedicated cellular model. Within Surface Pro for Business, 5G is currently an option on the 13-inch Intel Core Ultra Series 3 configuration and on the 13-inch Snapdragon configuration, while the 12-inch Snapdragon and 11th Edition Intel models are Wi-Fi only. Availability also varies by carrier and region, so confirm the exact SKU and the local carrier agreement before ordering.

Is cellular really more secure than corporate Wi-Fi?

Against a well-managed corporate wireless network, no — that network is under your control and can be more tightly governed than a carrier link. The comparison that matters is against the networks users actually connect to when they are away: hotel, airport, café, and client guest Wi-Fi. Against those, a provisioned Surface 5G connection removes the adversary-in-the-middle position entirely rather than compensating for it, which is a structurally stronger control than detection.

What about Windows 365 instead of new hardware?

It is a legitimate third option, particularly for populations whose hardware cannot meet the Windows 11 floor and is not due for replacement, and Windows 10 endpoints connecting to a Cloud PC carry an ESU entitlement for up to three years with an active licence. The trade-off is a permanent per-user monthly cost and total dependence on connectivity, which is why Cloud PCs and Surface 5G endpoints work better together than either does alone.

How long should a Surface 5G and Windows 11 migration take?

For a mid-sized estate with a functioning management plane, plan roughly one to two quarters of preparation — inventory, application work, and management readiness — followed by waves at whatever rate your logistics and service desk can absorb, commonly a few hundred devices per week. The variable that determines the schedule is almost never the operating system. It is application remediation and vendor response times, and those should be started first.

What is the single most common mistake in these programmes?

Ordering Surface 5G hardware before the management plane is ready. It converts a near-zero-touch deployment into hand-building devices, multiplies the cost per device, produces inconsistent baselines that generate support tickets for years, and destroys the business case that justified the purchase. Fix Autopilot, Intune, Autopatch, and firmware management against a pilot group first, then order at volume.

Final Verdict

The organisations that will handle the next three years well are not the ones that bought the newest hardware. They are the ones that wrote down all five endpoint positions, calculated the number that settles each, and then made a deliberate, dated choice for each user cohort rather than letting deferral make the choice for them.

The structural point is that the cheapest-looking option gets more expensive every year while delivering strictly less. Extended Security Updates at 61 dollars looked like prudence in 2025. At 122 dollars from October 2026, on hardware another year older, with third-party agents beginning to drop the platform, it looks like what it is — a bridge being used as a building. The decision does not improve by being postponed, and it is the only decision in this article with a published price for waiting.

On the other side, the case for Windows 11 on modern hardware is mechanical rather than promotional. Secure Boot and TPM 2.0 enable protections that cannot be retrofitted at any price; virtualization-based security and credential isolation break specific documented attack techniques; quick machine recovery and hotpatching change what happens when things go wrong and how fast fixes actually land. Those are nameable, checkable claims, and they do not need a vendor percentage to carry them.

The Surface 5G argument sits on top of that and is narrower than the marketing suggests, which is precisely why it holds. For the population that genuinely works away from your network, a cellular-first endpoint removes an entire attack class from the threat model rather than detecting it, improves patch compliance for structural rather than behavioural reasons, and makes zero-touch provisioning independent of whatever network the user happens to find. For everyone else, it is a premium without a matching risk. Scope Surface 5G to the cohort that earns it, fund the data plan properly, fix the management plane before the boxes arrive, and gate every wave on decommissioning the device it replaced.

Do that and the phrase in the title stops being rhetoric. Risk is an unpatched estate you cannot see, cannot attest, and cannot insure. Resilience is a Surface 5G fleet you can provision remotely, verify cryptographically, patch without a reboot, recover when it will not boot, and connect without borrowing somebody else’s network. The distance between those two positions is one programme, and it is considerably more achievable than the budget conversation suggests — provided it starts before the price doubles again.

References