Isolating a device — and getting it back
Isolation cuts a compromised device off the network while keeping it remotely recoverable.
- 1Isolate from a device row on Devices or from any detection page. The command reaches the device within about a minute.
- 2What it does: blocks ALL network traffic except Cybermatic's own endpoints, DNS, and DHCP — so the portal connection survives and you stay in control.
- 3The device shows an ISOLATED badge. Isolation survives reboots: the agent re-applies it until you release.
- 4Un-isolate from the same places; normal firewall policy is restored within a minute.
- 5Every isolate/un-isolate is recorded on the Response page with who requested it and when.