Skip to content
FRP-145 Fraud & Financial Crime

When should network isolation be considered?

Network isolation should be considered when continued connectivity creates a credible risk of ongoing harm, evidence destruction or wider compromise.

Avoid this assumption: Isolation is always the correct response to suspicious activity. Disconnection may stop malware, remote control, exfiltration or lateral movement, but it can also terminate useful sessions and remove visibility of the attacker.

Start by identifying the specific risk. Is data leaving the network? Are systems being encrypted, deleted or remotely controlled? Is the compromise spreading?

Record the live state before action where this can be done without unacceptable delay. Capture alerts, active sessions, affected devices, current connections, services and time.

Consider the scope of isolation. The proportionate action may involve one device, one account, one network segment, one interface or one service rather than the entire site.

Identify what will be affected, including logging, cameras, communications, authentication, safety systems, cloud access and business operations.

Seek network and incident-response advice quickly where the environment is complex or critical.

Where immediate safety or serious harm requires action, use the narrowest effective measure and record why waiting was not reasonable.

Document the authorisation, exact method, time and every resulting change.

Record what remained connected and any alternative route that may still exist.

Do not assume isolation has removed the attacker or preserved all evidence.

Record who will verify whether isolation achieved its intended effect.

Operational takeaway

Use network isolation only against a defined active risk, preserving the live state and selecting the narrowest measure that balances containment, evidence and operational continuity.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.