Should compromised systems be disconnected immediately?¶
Not automatically. Disconnect when a defined active risk justifies the loss of connectivity and live evidence, using the narrowest effective measure available.
Compare continued harm with evidential loss¶
Connectivity may enable exfiltration, remote control, encryption or spread. It may also carry central logs and the only observable session with an attacker. Record the screen, alerts, users, applications, network state and time before action where that delay is tolerable.
Identify dependencies such as authentication, cloud services, communications, safety functions and monitoring. Do not keep a system online merely to watch activity when serious harm continues, but do not unplug it simply to create an appearance of control.
Isolate with a clear objective¶
One account, interface, device or segment may be sufficient. Active or complex incidents require incident-response and network coordination to understand alternative routes and operational effects. If immediate action is necessary, record why and what evidence could not first be preserved.
Document authority, method, exact time, affected systems and resulting changes. Disconnection does not prove every route is closed or that the relevant records have been preserved; both require verification.
Key takeaway
Disconnect only against a stated continuing risk, after balancing dependencies and volatile evidence and selecting a containment boundary whose effect can be checked.