Why might a device need to be isolated?¶
A device may need to be isolated when continued connectivity creates a credible risk to evidence, safety or ongoing operations.
Evidential caution: that every connected device should be isolated immediately. Isolation can help, but it can also remove useful live evidence, interrupt synchronisation or affect other systems.
What this means¶
Reasons for isolation may include reducing the risk of remote wiping, preventing another user from changing data, stopping malware communication, limiting ongoing fraud or containing an active compromise.
Isolation may also help preserve a current device state where continued network activity would otherwise overwrite or alter records.
Before acting, identify the actual risk. Is there evidence of remote access, account compromise, active deletion, malicious traffic or continued harm? Avoid acting on vague concern alone.
Consider the effect of isolation. A messaging device may stop synchronising. A cloud application may close. A server may lose contact with dependent systems. A managed device may react to the loss of connectivity.
Where the device supports critical services or is part of a wider incident, obtain specialist advice before changing connectivity.
What to check or do next¶
- Record the connection state first. Capture Wi-Fi, mobile signal, VPN, Ethernet, Bluetooth, remote sessions and any visible network alerts.
- If urgent action is required, document why isolation was necessary, what method was used and what changed.
Evidential limits¶
Use the least disruptive method that addresses the specific risk. Full isolation may not always be necessary.
Operational takeaway
Isolate only when a specific connectivity risk justifies it, after recording the live state and considering what evidence or services the isolation may interrupt.