Could isolation cause evidence loss?¶
Yes. Isolation can protect evidence from remote change, but it can also remove or alter evidence that depends on an active connection.
Evidential caution: that disconnecting a device is always evidentially neutral. Live sessions may close, cloud data may stop loading, remote desktops may terminate and synchronisation records may change.
What this means¶
A messaging application may stop receiving data or fail to preserve disappearing content. A cloud service may lose an authenticated session. A business system may cease logging central activity.
Isolation may also cause a managed device to react, trigger alerts or alter security state.
Where the device is part of an active cyber incident, disconnection may remove visibility of an attacker or prevent collection of live network evidence.
Before isolating, record what is currently visible and connected. Capture open applications, session state, network indicators, active users and any alerts.
Consider whether the same risk can be managed more narrowly. One connection route may be disabled without removing all communications.
Also consider whether the device relies on a remote server for the content currently displayed. Once isolated, that content may disappear, become incomplete or be replaced by cached information.
Where the system is complex, business-critical or unfamiliar, seek specialist advice before isolation.
What to check or do next¶
- If isolation is necessary, document the reason, method, time and any immediate change in behaviour.
- Do not overstate what was preserved. If a session ended, cloud content disappeared or monitoring stopped, record that openly.
Operational takeaway
Recognise that isolation may protect against remote change while simultaneously destroying live, cloud or session evidence, so record the state first and isolate proportionately.