What is device isolation?¶
Device isolation means deliberately reducing or removing communication routes so a device cannot keep exchanging data in ways that create risk.
It is about connectivity. It is not the same thing as switching the device off.
A device can stay powered while becoming less connected¶
Possible routes include:
- mobile data;
- Wi-Fi;
- Ethernet;
- Bluetooth;
- USB data;
- tethering;
- docks; and
- remote-access paths.
Switching off one route does not prove the device is isolated.
Why isolate at all?¶
A device may need isolation to reduce a specific risk such as:
- remote wipe or lock;
- continuing unauthorised access;
- malware communicating;
- synchronisation changing data;
- ongoing fraud or abuse; or
- compromise spreading to other systems.
Why might a device need to be isolated? develops those decision points.
Isolation changes evidence too¶
Disconnecting a device may:
- close a remote session;
- stop cloud content loading;
- interrupt messaging;
- end live network visibility;
- trigger security or management events; or
- affect connected business systems.
That means isolation is not automatically “safer for the evidence”.
Against remote change, continuing malicious traffic or unwanted communication.
Live sessions, network state, remote content and monitoring that could otherwise help explain what was happening.
Record the route and the result¶
Before intervention, note the visible connection state.
After intervention, record:
- which control was used;
- exact time;
- operator;
- which indicators changed;
- which routes remained; and
- any immediate effect on applications or sessions.
The practical point is: isolation is a measured communication control, not a ritual. Know which route you are changing and what evidence that change may cost.