Should I disconnect a network cable?¶
Disconnecting a network cable may reduce remote access or ongoing harmful activity, but it can also alter evidence and affect other systems.
Evidential caution: that unplugging a cable is a simple and reversible isolation step. It may terminate live sessions, interrupt logging, remove access to remote data or disrupt services.
What this means¶
Before disconnecting, photograph the cable, port, device, network indicators and any active applications or alerts.
Consider whether the connection supports evidence that exists only while the session remains active, such as remote desktops, cloud applications or live monitoring.
A disconnected device may also stop sending logs to a central system or lose access to authentication and time services.
In a business or critical environment, one cable may support many users or services.
Document the time, person, cable and visible result of the disconnection.
What to check or do next¶
- Identify what the cable connects to. It may link a desktop, server, router, storage system, camera, phone or industrial device.
- If active harm is occurring, disconnection may be necessary. Use the narrowest effective action and record why delay was not reasonable.
- Where possible, obtain network or incident-response advice before acting.
- Do not reconnect the cable casually. Reconnection may trigger synchronisation, pending commands or renewed malicious activity.
- Record whether the device retained another connection route after the cable was removed, including Wi-Fi, mobile data or a second network interface.
Operational takeaway
Disconnect a network cable only after recording the live state and weighing containment against the risk of losing sessions, logs, services or wider evidence.