MYTHOSAI

Incident recovery / PRACTICAL GUIDE

Plan device isolation during a suspected incident

Reduce further connectivity while documenting what isolation can interrupt or change.

Before you start

Authority to act on the device and the organisation's incident-response process.

Balance containment and continuity

Isolation limits a device's network communication. It can reduce spread or further access, but it can also interrupt patient care, payment processing, remote administration or access to evidence. The right action depends on the system and the incident. Follow the responsible organisation's response procedure rather than treating every suspicious notification as permission to shut down all equipment.

For a personal computer with active suspicious behaviour, disconnecting its network can be a practical containment step while you obtain help. Business-critical systems need their designated owner involved promptly.

Choose an authorised method

  1. Record the symptom, affected device and time before taking action when the situation allows. Identify any critical business function that disconnection will interrupt.
  2. Use an existing approved endpoint-isolation feature if the organisation has one and you are authorised to use it. Otherwise, disconnect the relevant wired or wireless connection using supported controls.
  3. Confirm which connections remain: a second network adapter, mobile tethering or another wireless link can keep the device connected. Do not assume unplugging one cable isolates every path.
  4. Tell the incident owner what you changed and how authorised access can be restored. Keep the device unavailable for ordinary work until the response process determines the next step.

Verify the boundary carefully

Check connection status and, where safe, the expected loss of a harmless network service. Document what was tested. Some endpoint isolation methods intentionally retain a management channel, so their visible behaviour can differ from physically disconnecting the network.

Avoid evidence destruction

Do not immediately factory-reset, wipe logs or run a collection of downloaded cleanup tools. A shutdown or reboot can remove volatile information, while leaving a device running may have its own risks. Let the responsible responder decide how to balance those factors for the observed incident.

Use a separate trusted device for sensitive account recovery when the affected computer may be compromised. Do not enter fresh administrator credentials into it merely to see whether the problem has stopped.

Reconnect through a decision

Reconnection should follow assessment, remediation and a verification plan. Record the authorised decision and monitor the relevant behaviour afterwards. A disconnected computer looking quiet is not proof that it is clean; it may simply be unable to communicate while the original issue remains.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.