Jump to content

Recommended Posts

Posted
8 minutes ago, Fazza said:

 

Please correct me if I am wrong, they dont turn up and inspect all your hardware and software, they simply ask you if to fill in a form where you make a declaration saying you are using supported hardware?

If you install Windows 11 on a Gen7 CPU (i.e. unsupported hardware) and then make a declaration on the form saying all the software you have is installed on supported hardware then you will pass because you have not been correct in your answer?

 

Isn't the wording though "supported operating system" or "supported software"? I don't recall a question about "supported hardware", but iirc a list of hardware is being asked for.
"Supported operating system" then becomes something that can be argued either way, so I'm just wondering if anyone, after submitting their declarations and list of hardware, has encountered a problem.

 

I'd rather run Win 11 than LTSC 2019, so would only go about deploying LTSC if it were needed for CE accreditation (or obviously if Win 11 were to get broken in some way).

Posted
3 minutes ago, jthompson said:

 

Isn't the wording though "supported operating system" or "supported software"? I don't recall a question about "supported hardware", but iirc a list of hardware is being asked for.
"Supported operating system" then becomes something that can be argued either way, so I'm just wondering if anyone, after submitting their declarations and list of hardware, has encountered a problem.

 

I'd rather run Win 11 than LTSC 2019, so would only go about deploying LTSC if it were needed for CE accreditation (or obviously if Win 11 were to get broken in some way).

 

If you install Windows 11 on unsupported hardware then it is not supported by Microsoft therefore when asked if all your software is supported then you will have to answer No.  If you lie and say yes, then you will pass as they rely on you telling the truth in the form you fill in.

 

As with any insurance, you are most likely to get caught lying when you make a claim and it wont matter if the lie has anything to do with how the attack happened, it will most likely void the insurance.

  • Thanks 1
Posted

They will only pay out for cyber security insurance if you have backups anyway, and if you have backups why do you need insurance?

Posted
25 minutes ago, mavhc said:

They will only pay out for cyber security insurance if you have backups anyway, and if you have backups why do you need insurance?

 

We only have backups of our Servers so when we had a cyber attack (server wise) we were back up and running quite quickly but we dont have backups of any of our endpoints so we had to re-image all of them as a precautionety matter (both the Metropolitan Police and the FBI agreed with us that this was the best cause of action) and that took months as we could only afford one extra temp so we ended up working evenings and part of the weekend for quite a few weeks to get it all done!  Now we have insurance we'd have money to spend hiring the correct amount of people to do whatever needs doing.

  • Thanks 1
Posted (edited)
13 hours ago, jthompson said:

I'd rather run Win 11 than LTSC 2019, so would only go about deploying LTSC if it were needed for CE accreditation (or obviously if Win 11 were to get broken in some way).

 

ok, but.. why? I'm confused why people are desperate to put Windows 11 on unsupported hardware. I would do it for say... my home PC but at scale in the workplace it (to me at least) just doesn't seem worth the headaches. What are you getting out of it?

You have to manually reimage/deploy feature updates (They won't auto upgrade) & you run the risk of Microsoft randomly killing a whole bunch of machines during normal monthly updates.

 

The last thing I would want is to walk into a mountain of BSOD's and have to reimage back to Windows 10 anyway.

Can say it's unlikely, but we tried this with a few Dell machines that didn't support Windows 11, only to end up reverting when they hit random BSOD's

 

Likewise, I ran ChromeOS Flex on some hardware Google had no support lifecycle for, only for it to die during a normal update. Reinstalling didn't matter, it would crash if you went past a certain version.

The MacOS equivalent would be pushing OpenCore Legacy patcher out & I would say that's playing with fire also.

 

I used to be super blase about this stuff, but as I've been burnt over the years I tend to stick to vendor-supported OSs now.

 

Edited by DrCheese
  • Like 2
  • Thanks 1
Posted
On 13/03/2025 at 10:10, supportman said:

I'm quite surprised how aggressive Microsoft have been with this and why it hasn't kicked up more fuss?

Microsoft announced quite clearly when Windows 11 was newly launched that this would be a requirement. And people did kick up a fuss.

 

Microsoft rightly get a lot of stick for some of their decisions but people complain when they refuse to update things because of legacy commitments and people moan when they do force an upgrade that won't support 8 or 9 year old CPUs.

 

I think Dr Cheese has the right answer - buy Windows 10 extended support and use that time frame to transition to supported hardware. Frankly that price for edu extended support is a bargain, you probably don't want to know what we were quoted when we asked.

Posted

I'm with DrCheese, running Windows 11 on unsupported hardware just doesn't make any sense to me, especially given there are viable options like LTSC and Windows 10 extended support.  And if neither of those are palatable, then it's off to SLT/Governors to let them know that the devices will die in October!  You have to remember, if you're working in a school, you're responsible for maintaining what is essentially a corporate network, which hundreds of people rely on, not dabbling about with kit like you might do at home.

Posted

We use LTSC, have been doing for years, and support stops January 2027. This still isn't long enough for some schools who just say they have no budget. I've done my part, I can't control people who set a  budget that doesn't include investing in IT even though they've known this was coming for some time. It's always the same story. Five members of SLT managed to afford themselves the highest spec MacBook Airs though at one site (that they don't need). Funny eh.

Posted
2 minutes ago, SPM99 said:

We use LTSC, have been doing for years, and support stops January 2027. This still isn't long enough for some schools who just say they have no budget. I've done my part, I can't control people who set a  budget that doesn't include investing in IT even though they've known this was coming for some time. It's always the same story. Five members of SLT managed to afford themselves the highest spec MacBook Airs though at one site (that they don't need). Funny eh.

LTSC 2019 support runs until 2029, so that would give another 2 years.  

 

Try and get one or more SLT members to tag along with you to one of the cyber security seminars/conferences that companies hold, so they can see first hand the importance of endpoint security and the fallout should you get hacked.  I did this, in an attempt to scare them as much as it scares me.  One I went to recently said the average recovery cost from a cyber attack, to a secondary school, is around £250k.........

Posted
3 minutes ago, colly72 said:

LTSC 2019 support runs until 2029, so that would give another 2 years.  

 

Try and get one or more SLT members to tag along with you to one of the cyber security seminars/conferences that companies hold, so they can see first hand the importance of endpoint security and the fallout should you get hacked.  I did this, in an attempt to scare them as much as it scares me.  One I went to recently said the average recovery cost from a cyber attack, to a secondary school, is around £250k.........

Most are on LTSC 2021 as we updated everything from 1809 a while back! Looks like I will have to go back to it. Schools eh?

Posted
Just now, SPM99 said:

Most are on LTSC 2021 as we updated everything from 1809 a while back! Looks like I will have to go back to it. Schools eh?

I know, they are a unique challenge!

Posted
37 minutes ago, colly72 said:

Try and get one or more SLT members to tag along with you to one of the cyber security seminars/conferences that companies hold, so they can see first hand the importance of endpoint security and the fallout should you get hacked.  I did this, in an attempt to scare them as much as it scares me.  One I went to recently said the average recovery cost from a cyber attack, to a secondary school, is around £250k.........

 

This is quite interesting /  scary 

 

Schools under attack: The latest numbers and facts from the UK Government

Of those included in a cyber survey carried out in winter 2023/24 and the qualitative element in early 2024.

  • 52 per cent of primary schools identified a breach or attack in the past year
  • 71 per cent of secondary schools identified a breach or attack in the past year
  • 86 per cent of further education colleges identified a breach or attack in the past year
  • All other education institutions were more likely to have identified cyber security breaches or attacks in the last 12 months than the average UK business.
  • Further education and higher education institutions are more likely to experience breaches and attacks than schools, and to experience a wider range of attack types, such as impersonation, viruses or other malware, and unauthorised access of files or networks by outsiders 
  • Higher education institutions are more likely to be affected by cyber-attacks – 97 per cent identified a breach or attack in the past year. Just under six in 10 of the HE institutions identified that they’d been negatively impacted by a breach.

An honest question - if you're one of the 48% of primary schools that has not identified a breach, for example,  how confident are you that means there is no breach, rather than one you have not yet detected. 

 

If you're lucky enough not to be breached yet, do you really think you're smarter than all your counterparts at 52%, 71% or 86% in your sector, or just luckier? 

Posted
3 minutes ago, Roberto said:

 

This is quite interesting /  scary 

 

Schools under attack: The latest numbers and facts from the UK Government

Of those included in a cyber survey carried out in winter 2023/24 and the qualitative element in early 2024.

  • 52 per cent of primary schools identified a breach or attack in the past year
  • 71 per cent of secondary schools identified a breach or attack in the past year
  • 86 per cent of further education colleges identified a breach or attack in the past year
  • All other education institutions were more likely to have identified cyber security breaches or attacks in the last 12 months than the average UK business.
  • Further education and higher education institutions are more likely to experience breaches and attacks than schools, and to experience a wider range of attack types, such as impersonation, viruses or other malware, and unauthorised access of files or networks by outsiders 
  • Higher education institutions are more likely to be affected by cyber-attacks – 97 per cent identified a breach or attack in the past year. Just under six in 10 of the HE institutions identified that they’d been negatively impacted by a breach.

An honest question - if you're one of the 48% of primary schools that has not identified a breach, for example,  how confident are you that means there is no breach, rather than one you have not yet detected. 

 

If you're lucky enough not to be breached yet, do you really think you're smarter than all your counterparts at 52%, 71% or 86% in your sector, or just luckier? 

 

Schools are a easy target:

 

  • They (commonly) don't have the budget to invest in top-tier security solutions
  • They don't have dedicated cyber security specialists
  • They have holidays, or periods of time, where there are limited or no staff on site, so early detection (and by default, early remediation) may be an issue
  • They do have lots of personal data, that may be of value to criminals
Posted
38 minutes ago, Roberto said:

 

This is quite interesting /  scary 

 

Schools under attack: The latest numbers and facts from the UK Government

Of those included in a cyber survey carried out in winter 2023/24 and the qualitative element in early 2024.

  • 52 per cent of primary schools identified a breach or attack in the past year
  • 71 per cent of secondary schools identified a breach or attack in the past year
  • 86 per cent of further education colleges identified a breach or attack in the past year
  • All other education institutions were more likely to have identified cyber security breaches or attacks in the last 12 months than the average UK business.
  • Further education and higher education institutions are more likely to experience breaches and attacks than schools, and to experience a wider range of attack types, such as impersonation, viruses or other malware, and unauthorised access of files or networks by outsiders 
  • Higher education institutions are more likely to be affected by cyber-attacks – 97 per cent identified a breach or attack in the past year. Just under six in 10 of the HE institutions identified that they’d been negatively impacted by a breach.

An honest question - if you're one of the 48% of primary schools that has not identified a breach, for example,  how confident are you that means there is no breach, rather than one you have not yet detected. 

 

If you're lucky enough not to be breached yet, do you really think you're smarter than all your counterparts at 52%, 71% or 86% in your sector, or just luckier? 

I guess scale of incident is going to skew these stats quite a lot. Are these complete break downs of IT, or just an email gone to the wrong sender? How many schools wouldn't report a small data leak or phishing email as an cyber incident? What about the stuff that was caught by filters and firewalls? I suspect attempted attacks are much higher than what has been reported. Not saying that a minor incident is acceptable, just that its probably not always going to be reported the same.

Posted (edited)
55 minutes ago, Chris_Cook said:

I guess scale of incident is going to skew these stats quite a lot. Are these complete break downs of IT, or just an email gone to the wrong sender? How many schools wouldn't report a small data leak or phishing email as an cyber incident? What about the stuff that was caught by filters and firewalls? I suspect attempted attacks are much higher than what has been reported. Not saying that a minor incident is acceptable, just that its probably not always going to be reported the same.

If these are government figures then I guess whatever else these incidents were, they were ones people thought were worth reporting for whatever reason. So it's probably not something getting blocked at the firewall or mail filter with no issues, or an email going to Mr Miggins when it should have gone to Mrs Miggins but effectively no harm done (or at least, no complaint made), if I had to guess.

 

Actually if you read the summary on the govt. website they're fairly complimentary to the education sector in general on this matter.

Edited by Roberto
Posted
4 hours ago, colly72 said:

LTSC 2019 support runs until 2029, so that would give another 2 years.  

 

Try and get one or more SLT members to tag along with you to one of the cyber security seminars/conferences that companies hold, so they can see first hand the importance of endpoint security and the fallout should you get hacked.  I did this, in an attempt to scare them as much as it scares me.  One I went to recently said the average recovery cost from a cyber attack, to a secondary school, is around £250k.........

2 months later: Can I have new computers? -- No, we spent all the money on cyber security consultants without asking you

  • Haha 1
Posted
On 24/03/2025 at 22:46, DrCheese said:

 

ok, but.. why? I'm confused why people are desperate to put Windows 11 on unsupported hardware. I would do it for say... my home PC but at scale in the workplace it (to me at least) just doesn't seem worth the headaches. What are you getting out of it?

 

I take your point: it all makes sense, particularly thinking through the reality of what "it suddenly isn't stable on this model any more" would actually mean in a school day.

I guess my preference for the more recent OS is that if we're running that as broadly as possible, then we're more easily able to keep all of the app deployments, tweaks and various end user support idiosyncrasies current. There may also be some inherant security advantages, even if the hardware is below spec (idk). That comes from sticking with Win 7 way too long in the past, and having to reinvent a tonne of stuff to make a jump to Win 10.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...