When should a computer be isolated from the network?¶
Isolate when a defined credible connectivity risk - such as exfiltration, remote control, destructive activity or lateral movement - outweighs the evidence and services lost by disconnection.
Record the live network role¶
Capture screens, interfaces, cables, sessions, users and alerts. Identify cloud applications, remote storage, authentication, central logging and monitoring that depend on the connection.
One computer may have Ethernet, Wi-Fi and mobile routes. Removing one does not prove isolation.
Use the narrowest effective containment¶
An interface, account or session may be controlled without disconnecting the whole device or network. Coordinate with incident, network and forensic specialists where possible.
If harm requires immediate action, record why delay was unacceptable, the exact method, time, operator and every resulting change. Disconnection can protect systems while ending visibility and volatile sessions.
Key takeaway
Isolate for a specific evidenced network risk and preserve the sessions, logging and service context the control may remove.