NETWORK ISOLATION
When To Disconnect From the Internet in an Emergency — and When Not To

Disconnecting a device or network can be a sensible containment step when you have credible signs of compromise, but indiscriminate isolation can also destroy communications, interrupt medical or business systems and make recovery harder. The decision should match the problem you actually have.
This guide is about verification, protection, continuity and recovery. It does not provide instructions for committing fraud or cyber intrusion.
The immediate answer
If one device appears compromised, isolate that device first rather than automatically shutting down every connection in the household or business. Preserve a separate trusted route for official information and recovery, and follow provider or incident-response guidance when critical systems are involved.
Know what isolation is trying to achieve
Disconnecting can stop a compromised device from communicating with an attacker, spreading to nearby systems or continuing unwanted network activity. It does not magically clean the device or prove the threat is contained. Think of isolation as buying time while you determine what happened. If the problem is a stolen online password rather than infected hardware, disconnecting your entire home network may do little while also removing the services you need to recover the account.
Start with the smallest safe boundary
If a laptop is behaving suspiciously, disconnect that laptop from Wi-Fi or Ethernet and leave unaffected devices available for trusted communications. In a small business, follow the incident plan and identify systems that can be isolated without creating safety risks. Avoid improvising with industrial, medical or other critical equipment. Some systems have consequences far beyond data loss and should be handled by qualified operators.
Keep one clean communications path
Recovery often requires contacting providers, banks, colleagues or cyber support. Use a device you have reason to trust and a network path separate from the suspected compromise where possible. Do not use a device you believe is infected to change all your passwords, because that can expose the new credentials as well. If a major public cyber incident is underway, maintain access to official service-status and emergency information rather than cutting yourself off from every channel.
Do not destroy evidence in the rush to act
Factory-resetting devices, wiping logs or repeatedly rebooting systems can make diagnosis and recovery harder, particularly for organisations. For households, the priority is still safety and account protection, but preserving screenshots, suspicious messages and basic timing can help support teams or fraud reporting. If an organisation faces a serious incident, use its response process and appropriate professional or NCSC reporting routes rather than experimenting on the compromised network.
Reconnect only when you understand the recovery state
Before reconnecting a device, apply trusted recovery guidance: update or rebuild where appropriate, change exposed credentials from a clean system, revoke unknown sessions and verify backups before restoring data. If you cannot determine whether the device is safe, seek competent support. Reconnection should be a deliberate step after containment and recovery, not something done automatically because the internet is inconvenient to live without.
Prepare an offline fallback before you ever need isolation
Keep key contacts, recovery instructions and essential documents available without cloud access. Know which household or business functions fail if the internet disappears: payments, alarms, heating controls, work systems, communications and entertainment may all depend on it. A small offline fallback means you can isolate a suspicious system without immediately losing the ability to function. That is the difference between controlled containment and self-inflicted chaos.
Continue from here
Build this topic into a wider plan, then see how the same dependency could fail in an AI-collapse scenario.
Evidence desk
These guides use current UK cyber and fraud-prevention guidance. AI-enabled voice cloning and deepfakes are treated as real fraud techniques, while any wider collapse consequences are labelled as scenario analysis.
OFFLINE FALLBACK
If identity, payments and communications fail together, paper and offline systems matter.
The 72-hour field manual covers power, communications, money, food, water and the practical information your household needs when digital systems stop cooperating.
Continue
More Cyber & Digital Resilience guides → · Communications survival →