System Isolation
System isolation is a cybersecurity practice of separating a compromised device or network segment from the rest of an organization's infrastructure to stop a threat from spreading. It often keeps the affected system partly operational or reachable for investigation rather than shutting it down completely. It is a security and incident response measure, not an insurance coverage term.
System isolation is a containment technique used during incident response in which a compromised system or network segment is separated from the broader environment to limit lateral movement and further compromise. In endpoint contexts it may involve cutting or restricting a device's network connectivity while preserving the device for forensic analysis rather than powering it off. As a security control it supports risk mitigation by reducing the impact of an active incident; it does not by itself transfer risk or constitute insurance coverage, and whether costs associated with isolation and remediation are covered depends on the specific policy wording, endorsements, exclusions, and conditions of any applicable cyber policy. This entry addresses the cybersecurity meaning; unrelated uses of 'isolation' in electrical, physical-science, or medical/environmental contexts are out of scope.
Why it matters
System isolation is one of the first practical steps an organization takes once an active compromise is detected, because it directly limits how far an attacker or malware can spread. By separating a compromised device or network segment from the rest of the infrastructure, responders can halt lateral movement while an investigation is still underway. This makes isolation a core containment measure within incident response rather than a passive defense.
A key characteristic that distinguishes isolation from simply powering off a machine is that it often keeps the affected system partly operational or reachable. This preserves the device for forensic analysis, which can be important for understanding the scope of an incident, supporting later notification and regulatory decisions, and informing remediation. Shutting a system down entirely can destroy volatile evidence, so isolation is frequently the preferred approach where investigation matters.
From an insurance perspective, it is important to be precise about what isolation does and does not do. System isolation is a risk mitigation control: it reduces the impact of an active incident but does not transfer risk and does not by itself constitute cyber insurance coverage. Whether costs tied to isolation, investigation, and remediation are recoverable depends entirely on the specific policy wording, endorsements, exclusions, and conditions of any applicable cyber policy. Having strong isolation capability may support an organization's insurability and its response, but it should not be mistaken for a coverage guarantee.
Who it's relevant to
Inside System Isolation
Common questions
Answers to the questions practitioners most commonly ask about System Isolation.
