Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could immediate disconnection prevent further harm?

Yes. If network access is enabling serious ongoing harm, prompt disconnection can interrupt that route and protect other systems or people.

Identify what connectivity enables

Disconnection may stop remote control, command traffic, exfiltration, malware spread or destructive actions. Define the observed harm and the route carrying it rather than assuming every network connection is causal. Capture alerts, sessions, affected devices, current connections and time when that can be done without unacceptable delay.

Consider what the action will also interrupt: central logging, attacker visibility, cloud access, unsaved work and essential services. That cost does not prevent urgent action, but it determines what should be preserved and who must be involved.

Verify the containment outcome

Use the smallest effective boundary - an identity, interface, host or segment - where practicable. Record authority, method, time and why specialist coordination could or could not be obtained first.

Afterwards, check whether the harmful activity stopped and whether Wi-Fi, mobile, VPN, cloud sessions or management channels provide another route. One cable removal is an action, not proof that the incident is contained.

Key takeaway

Immediate disconnection is justified when it interrupts a demonstrated route of serious harm, but its scope, collateral effects and actual containment result must be recorded and verified.

Reference: FRP-190First Response & Preservation