Skip to content
All guidesCybermatic Endpoint Protection

Isolating a device — and getting it back

Isolation cuts a compromised device off the network while keeping it remotely recoverable.

  1. 1Isolate from a device row on Devices or from any detection page. The command reaches the device within about a minute.
  2. 2What it does: blocks ALL network traffic except Cybermatic's own endpoints, DNS, and DHCP — so the portal connection survives and you stay in control.
  3. 3The device shows an ISOLATED badge. Isolation survives reboots: the agent re-applies it until you release.
  4. 4Un-isolate from the same places; normal firewall policy is restored within a minute.
  5. 5Every isolate/un-isolate is recorded on the Response page with who requested it and when.

More in Cybermatic Endpoint Protection