Cybersecurity Guide

How can a business protect itself from ransomware?

Ransomware is not just an antivirus problem. An attack can start with an email, a password, an unpatched device or privileged access and end with unavailable systems, encrypted data and compromised backups.

RANSOMWAREPCENTER GUIDE
PREVENTMake initial access harderPCenter
LIMITReduce the blast radiusPCenter
RECOVERRestore operations without depending on the attackerPCenter
Updated 27 September 2026PCenter
Reading time: ~8 minPractical guide
SMBs · Teams · InfrastructureCibersegurança
Ransomware · Backup · IdentityProteção por camadas

Protection starts by assuming that one defensive layer can fail.

Ransomware operations can combine phishing, credential theft, vulnerability exploitation, lateral movement and abuse of privileged accounts. In human-operated attacks, the objective is often to gain enough control to reach critical systems, valuable data and even backups.

Defence therefore needs layers. Microsoft frames the problem around recovery, limiting damage and making initial access harder. CISA also emphasises protected, regularly tested backups because ransomware actors often try to destroy accessible copies.

Core principle

A ransomware-ready business can continue operating even when one protection fails. That requires tested recovery, protected identities, controlled endpoints and a clear response plan.

01

Recover

Keep protected, tested backups sufficiently isolated from production credentials and attack paths.

03

Prevent entry

Patch systems, protect email, require MFA and use endpoint protection to block or detect common techniques.

Eight layers that materially reduce risk.

01
Isolated or immutable backupsCritical backups should not remain permanently writable using the same credentials as production, and restoration should be tested.
02
Multi-factor authenticationMFA makes a stolen password less likely to become immediate access to cloud services, VPNs and systems.
03
Patching & vulnerabilitiesOperating systems, applications, appliances, VPNs and exposed services need regular updates, with priority for critical vulnerabilities.
04
Endpoint protectionAntivirus/antimalware, firewall and detection help block malware and techniques used before encryption.
05
Email & collaborationFiltering, protection against malicious links/attachments and user awareness reduce a common initial-access route.
06
Least privilegeAdministrative accounts should be separate, protected and used only when required.
07
Segmentation & access controlA compromised endpoint should not automatically reach servers, backups and every critical resource.
08
Response planDefine who decides, communicates, isolates systems, preserves evidence and restores services in priority order.
Norton 360

Where does Norton 360 fit into PCenter's approach?

PCenter works with Norton 360 as one layer of endpoint protection. Norton 360 provides malware/ransomware protection and firewall capabilities, while selected plans also include cloud backup and additional features. It should be treated as one layer rather than a replacement for MFA, patching, isolated backups and access controls.

Real-time protectionHelps detect and block malware and ransomware on the endpoint.
Smart FirewallHelps monitor communications and block unauthorised traffic on the device.
Cloud BackupAvailable in selected plans; useful as an additional layer, not a substitute for a business recovery architecture.

Backup only protects you if it can survive the attacker.

A backup that is permanently reachable from the same environment can itself be encrypted or deleted. CISA recommends offline, encrypted backups and regular restore testing.

A successful backup job is not enough. The business needs to know whether it can actually restore the data, how long recovery takes and which systems must come back first.

MFA and least privilege block a dangerous route.

Compromised credentials are a common access vector. MFA, separate administrator accounts and least-privilege policies reduce the chance that one stolen credential becomes broad control of the environment.

Patching closes known doors.

Operating systems, VPNs, applications, browsers, appliances and internet-facing services need regular patching. Known exploited vulnerabilities should be prioritised.

INCIDENTE

If you suspect ransomware

The first goal is to stop spread, preserve evidence and keep recovery options available.

01Isolate affected systems from the network without unnecessarily destroying evidence.
02Prevent lateral movement and protect privileged accounts and credentials.
03Determine scope across endpoints, servers, cloud services, backups and potentially exfiltrated data.
04Activate the response and communications plan, including legal and data-protection obligations where applicable.
05Restore priority services from verified copies into a clean environment.
FAQ

Ransomware

Is antivirus enough to stop ransomware?

No. Endpoint protection matters, but it should be combined with MFA, patching, least privilege, email security, segmentation, tested backups and an incident-response plan.

Does PCenter work with Norton 360?

Yes. PCenter uses Norton 360 as one endpoint-protection layer within a broader security and continuity approach.

Does Norton cloud backup replace business backup?

Not necessarily. Business backup should consider scope, retention, isolation, restore capability, servers, applications and recovery objectives.

Does MFA help against ransomware?

Yes. It reduces the risk that stolen credentials alone provide access to email, VPNs, cloud services and other critical systems.

Should backups always remain online?

Critical copies need protection from attacker modification or deletion using an architecture appropriate to the environment.

Should a business pay the ransom?

Payment does not guarantee recovery and does not remove risks such as data theft. Response should be coordinated with specialists, management and relevant legal or law-enforcement advice.

Technical references

This guide combines PCenter's approach with public recommendations from CISA, Microsoft and official Norton product information.

Ransomware cannot be solved with one tool.

PCenter can assess endpoints, identities, backups, servers, Microsoft 365, access paths and recovery processes to build layered protection.