Skip to content
Skip to main content
First Response & Preservation Operational Explainer

When should a computer be isolated from the network?

Isolate when a defined credible connectivity risk - such as exfiltration, remote control, destructive activity or lateral movement - outweighs the evidence and services lost by disconnection.

Record the live network role

Capture screens, interfaces, cables, sessions, users and alerts. Identify cloud applications, remote storage, authentication, central logging and monitoring that depend on the connection.

One computer may have Ethernet, Wi-Fi and mobile routes. Removing one does not prove isolation.

Use the narrowest effective containment

An interface, account or session may be controlled without disconnecting the whole device or network. Coordinate with incident, network and forensic specialists where possible.

If harm requires immediate action, record why delay was unacceptable, the exact method, time, operator and every resulting change. Disconnection can protect systems while ending visibility and volatile sessions.

Key takeaway

Isolate for a specific evidenced network risk and preserve the sessions, logging and service context the control may remove.

Reference: FRP-091First Response & Preservation