Tens of thousands of ATMs will be running Windows XP long after Microsoft’s deadline to abandon the operating system ahead of a potential hacker storm.
Just a third of the UK’s 60,000 ATMs will be upgraded from Windows XP before the end of this year, according to the biggest supplier of those machines - NCR.
But it will be 8 April when Microsoft actually stops releasing security patches for Windows XP and when systems still running the OS will be open to hackers writing new malware and devising fresh attacks.
NCR – which supplies 60 per cent of the UK’s cash points – believes 95 per cent of Britain’s ATMs are today still running Windows XP with less than a month to go.
NCR told The Reg it has been working with Microsoft for nearly three years through workshops and sales camps to persuade banks to upgrade their ATMs.
NCR is selling a version of its ATM software that runs on Windows 7.
But the banks are dragging their feet because of the cost and are only moving as part of an overall business strategy because of the substantial cost involved in buying the new cash machines needed.
The price of an ATM runs to $40,000 per machine for the latest fully specified touchscreen machines with an average start price of $8,000.
The banks are reluctant to move over until they’ve realised the capital cost of paying for the existing ATMs that are running Windows XP, according to NCR.
That differs to the pace of Windows XP upgrades on the PC.
There, many in financial services are understood to have already migrated their corporate desktops and laptops off Windows XP in advance of the April cut-off.
But then, a PC can be bought for as little as a few hundred pounds.
“We’ve done a lot of work trying to educate banks to move early,” enterprise software global marketing director Robert Johnson told The Reg in an interview, “but the majority are going at the pace that suits their business.”
We'll move when we're ready...
Institutions are working to their own timetable and not Microsoft’s, he said.
“The interesting dynamic is getting customers to be ready to do an upgrade. Most customers are looking at this with some reluctance because they don’t appreciate being driven to a decision by Microsoft. They want to work to their own dates.”
“What we will probably see is one third of the install base move off Windows XP by the end of 2014,” he said.
The cost comes from paying for the Windows licence, upgrading the software stack, testing and configuring the new software and in deployment. The software stack consists of a basic platform that connects Windows to the application modules that provide different services.
Modules vary by bank, but include security and the ability to insert and recognise the ATM card and withdraw money. Options on top of that include the ability to recognise the customer by name to promote advertising, goods and services, mobile phone top-ups and bill payments. Touchscreen also being offered instead of keyboard input.
Johnson predicts there will patchy upgrades across the sector and within companies’ ATM networks.
“Lots of companies will take time to migrate and some will not migrate in one go because they have thousands of ATMs,” he said.