Every office has one, even if almost nobody who works there has ever seen it. It’s usually a plain looking computer, tucked in a cupboard or a back room, that nobody touches from one year to the next. What it does is hold your files, run software like your case management or accounts system, and let everyone else’s computer connect to it. That’s a server, and the software it runs on is called an operating system, the same idea as Windows on your laptop, just built for that job instead.
A lot of business servers are running a version of that software called Windows Server 2016. On 12 January 2027, Microsoft stops supporting it.
Nothing will look any different that day. The server will switch on exactly as it always has. The files will open. The software will run. That’s exactly what makes this deadline easy to miss, and expensive to ignore.
What “end of support” actually means
Think of it a bit like a car the manufacturer has stopped making. The car doesn’t vanish from the driveway the day the factory closes. It still starts, it still drives. What stops is the manufacturer making new parts for it. If something breaks after that, there’s nobody making the part that fixes it.
That’s what happens to a server. While Windows Server 2016 is supported, whenever a weakness is found in it, usually by a security researcher, Microsoft builds a fix and sends it out. After 12 January 2027, that stops. Any weakness found in it from that point on has no fix coming. Ever.
Why that’s more dangerous than it sounds
Weaknesses like that get found in software for years after it’s released. That’s completely normal, and it’s already happening to Windows Server 2016 now. The difference is what happens next. Right now, when one’s found, Microsoft fixes it, usually before most people even hear about it. After January 2027, it just stays open.
That makes an old server a specific kind of target, not just a neglected one. Whoever finds a weakness in it knows it will never be closed, so there’s no rush. They can take their time working out where to use it and when. It’s the difference between a lock that occasionally gets a new key cut, and one where everybody, including anyone who might want to get in, knows no new key is ever coming.
The moment it actually bites usually isn’t a break in
For most businesses, the first sign of trouble isn’t a hack. It’s a form.
If you have cyber insurance, you’ll likely be asked at some point, often at renewal, whether your systems are patched and supported. Cyber Essentials asks the same thing outright. So does a client checking your business over before signing a contract, or a bigger company checking your IT security before renewing one with you.
“Yes, patched and supported” is the answer that keeps things moving. “No, but it still works fine” isn’t, and it’s a far worse conversation to have after you’ve sent that form back than before.
What actually catches businesses out isn’t knowing the deadline exists. It’s not realising a specific server in the building is still running Windows Server 2016 in the first place, often because it was bought years ago and has simply carried on running through a hardware upgrade or two since, with nobody thinking to check.
Why it’s worth sorting sooner rather than later
January 2027 feels a long way off. It’s closer than it looks once you account for what has to happen before it.
Moving whatever runs on that old server onto something newer takes planning: checking the software will actually work on the new setup, picking a quiet time to make the switch, and testing it properly rather than rushing it the week before the deadline. That matters even more if what’s on the server is something the business can’t do without for a day, like case management or accounts. Sorted early, it’s a calm, straightforward piece of work. Left to the last minute, it’s a panic.
Three ways to deal with it
Microsoft has set out three routes, and which one makes sense depends on what that server is actually running and how old it is.
Replace the software with the newer Windows Server 2025, if the hardware underneath can take it. Like swapping in a new engine rather than the whole car: everything the server does gets moved across and tested on something current, and the clock resets for years.
Pay for a limited extension, called Extended Security Updates, if replacing it properly isn’t possible straight away. Microsoft keeps sending fixes for a fixed period while you get ready to move, delivered through a system called Azure Arc. Microsoft is upfront that this is a stopgap, not a long term fix.
Move what the server does into Microsoft’s cloud, called Azure, rather than replacing the physical machine at all. Useful if the computer the server runs on is also getting old and due for replacing anyway.
None of that needs deciding today. What’s worth doing today is finding out whether any of this actually applies to you, by asking whoever looks after your IT which operating system your server is running.





