Skip to content
Skip to main content
First Response & Preservation Operational Explainer

Should I disconnect a network cable?

Disconnect it only when reducing a defined network risk is worth the loss of whatever that connection is currently supporting.

A cable can carry hostile traffic, but it can also carry useful sessions, logging and business services.

The decision test
Work out what the cable supports and what risk it creates before pulling it.

Identify both the device and the network role

A network cable may connect:

  • workstation;
  • server;
  • router;
  • NAS;
  • camera;
  • industrial controller; or
  • another networked appliance.

Record:

  • both ends;
  • port labels;
  • link lights;
  • visible applications;
  • alerts;
  • current remote sessions; and
  • any known service dependency.
Reason to disconnectContinuing hostile communicationActive attacker route, malware traffic or ongoing harmful access.
Reason to hesitateUseful live service or evidenceRemote session, logging, authentication or critical operations.

One cable may affect more than one person

A server or shared appliance may support many users.

Disconnecting it may stop:

  • central logging;
  • authentication;
  • transactions;
  • remote access;
  • databases; or
  • security monitoring.

Could disconnecting a server affect other users or evidence? covers that wider dependency risk.

Use the narrowest effective action

Where possible, control the specific risk rather than the entire system.

That might mean one interface, one account, one service or one virtual machine rather than the whole host.

If immediate harm requires disconnection, record:

  • why it could not wait;
  • exact cable/port;
  • operator;
  • time;
  • visible result; and
  • remaining connectivity.

The practical point is: disconnect a network cable as a containment decision, not an instinctive preservation step.

Reference: FRP-054First Response & Preservation