Skip to content
Skip to main content
First Response & Preservation Operational Explainer

Why might a device need to be isolated?

Isolate a device when continued connectivity creates a specific, credible risk that outweighs the evidential or operational cost of disconnecting it.

Do not isolate simply because the device is digital or because “that is what we always do”.

The decision test
Name the risk first. Remote wipe, continuing hostile access, malware traffic or ongoing harm are reasons. Vague discomfort about a connected device is not.

Start from the live risk

Examples include:

Observed situation Why isolation may help
Remote-management console is active Reduces the chance of remote alteration
Device is communicating with suspected malicious infrastructure Limits continuing network activity
Fraudulent account activity is still occurring May interrupt the device's active route
Malware appears to be spreading Can reduce exposure to other systems
A wipe/lock instruction is credible May reduce the chance of the command arriving

The stronger the observed behaviour, the stronger the case for intervention.

Preserve the starting state first where you can

Record:

  • mobile signal;
  • Wi-Fi network;
  • Ethernet;
  • VPN;
  • Bluetooth;
  • remote sessions;
  • connected devices;
  • active applications; and
  • visible alerts or warnings.
Example pre-isolation note
Wi-Fi: Northmere-StaffVPN: connectedRemote session: activeEthernet: noneBluetooth: on

That lets you explain what communication routes existed before the change.

Consider what the connection is preserving

Connectivity may also be supporting:

  • a live cloud session;
  • remote content;
  • central logging;
  • security monitoring;
  • business operations; or
  • another system that depends on the device.

Could isolation cause evidence loss? covers that cost in more detail.

Use the narrowest effective control

If one route creates the risk, removing every route may be unnecessary.

For example, disabling one network path may contain a defined threat while retaining other useful monitoring or state.

For complex, shared or business-critical systems, coordinate with technical owners or specialists.

The practical point is: isolate for a named connectivity risk, preserve the starting state, and use the least disruptive control that actually addresses that risk.

Reference: FRP-044First Response & Preservation