Lesson 4 of 4 · 8 min
Responding: isolating a machine
What to do in the first minutes after you suspect a Mac is compromised: cutting its network access, preserving what happened, and who to call.
Detection only matters if it leads to action. This lesson is about the first minutes after you notice something wrong: an app connecting somewhere it should not, a Mac behaving strangely, or a warning from someone you trust that you may have been targeted. The goal here is not to fix the underlying problem yourself; it is to stop it from getting worse and to keep what you will need to get real help.
Isolate first, investigate second
NIST’s Computer Security Incident Handling Guide (SP 800-61) frames containment as a choice that has to be made quickly, and warns that “an attacker could escalate unauthorized access or compromise other systems” for as long as containment is delayed. On one Mac, containment means cutting its network access: turning off Wi-Fi, unplugging an Ethernet cable, or turning on Airplane Mode if available, rather than continuing to use it normally while you think. This does not fix anything by itself, but it stops an ongoing connection to an attacker, and stops the Mac from being used to reach anything else, such as another device on the same network or an account you are still logged into.
- Disconnect from the network: Wi-Fi off, Ethernet unplugged. This is the single most useful first action, since it cuts off both incoming instructions and outgoing data at once.
- Do not shut down or restart the Mac unless you have been told to by someone helping you. Powering off can lose information in memory that would otherwise help explain what happened, and can trigger harmful software designed to notice a shutdown and cover its tracks.
- Do not uninstall the suspicious app, delete files, or “clean up” before getting help. It is tempting, but it destroys the evidence a helper would need to understand what happened.
- If the Mac is used for work, or the incident might involve someone else’s data, tell whoever is responsible for that (an employer’s IT or security contact, an organization’s security lead) immediately, rather than after you have looked into it yourself.
Preserving what you can, briefly
NIST’s guide recommends documenting “every step taken from the time the incident was detected to its final resolution,” timestamped, ideally by someone other than the person doing the technical work. On one Mac, without a formal team, this can be simple: write down or photograph what you saw and when (the app, the destination, the time), note anything you changed (did you disconnect the network? did you close an app?), and keep any screenshots you already took. This is exactly the kind of detail the tools in the previous lesson, such as a per-app connection log, are useful for capturing before you disconnect.
Getting help
Who to contact depends on who you are and what is at stake. For most people, this starts with whoever manages the device if it is not personal (an employer, an organization’s IT), or a trusted, technically capable person if it is. For journalists, activists, human rights defenders and others who may be targeted because of their work, two organizations specifically offer this kind of support at no cost:
- Access Now’s Digital Security Helpline offers rapid-response help, in multiple languages, for civil society groups and individuals who believe they are at risk or already under attack, after a vetting process to confirm they fall within its mandate.
- Freedom of the Press Foundation offers digital security training and personalized advice for journalists and newsrooms, including guidance on device security and source protection.
Neither organization, nor this lesson, can promise that any set of steps makes a targeted person safe; the honest goal is reducing risk and getting a knowledgeable person involved quickly, not eliminating it.
Key takeaways
- Disconnect the Mac from the network (Wi-Fi off, Ethernet unplugged) as the first response to a suspected compromise; this alone stops it exchanging data with an attacker.
- Do not shut down, restart, or “clean up” a suspected compromised machine before getting help: doing so can destroy the information a helper needs.
- Write down or photograph what you observed and when, as close to the time it happened as possible.
- Access Now’s Digital Security Helpline and Freedom of the Press Foundation both offer free, specialized help for journalists, activists and civil society at risk.
- Isolating and documenting reduces risk and preserves evidence; it does not by itself make a compromised machine safe again.
Check yourself
1. What is usually the most useful first action if you suspect a Mac is compromised?
- Restart the Mac immediately
- Disconnect it from the network (Wi-Fi off or Ethernet unplugged) — Right.
- Uninstall all recently installed apps
- Run a full backup to an external drive
Cutting network access stops both outgoing data and incoming instructions immediately, without needing to first understand what is wrong.
2. Why does NIST’s incident handling guidance caution against powering off a suspected compromised system right away?
- It takes too long to restart
- Powering off can lose information held in memory that would help explain what happened — Right.
- It voids the warranty
- It has no effect either way
Volatile data such as running processes, open connections and memory contents is lost on shutdown, and some harmful software is designed to react to a shutdown by covering its tracks.
3. Who does the Access Now Digital Security Helpline primarily serve?
- Any business that pays for a subscription
- Government agencies only
- Civil society groups and individuals at risk because of their activism, journalism or human rights work — Right.
- Software developers reporting bugs
The helpline is a free resource specifically for at-risk activists, journalists and human rights defenders, after a vetting process.
Do it with FireAI
Put this lesson into practice on your own Mac.
- Rules: app, website, domain, IP or a range, forever or until you restart — Write a rule as precise as one address or as broad as an entire domain.
- The kill switch — Cut your Mac off the internet in one click when something feels wrong.
- Investigate a connection — Decide with the facts in front of you, not a vague warning.
- Activity: every app that went online, and a plain-words history search — See every app that went online today, and act on any of them in one click.
Sources
- NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide
- Access Now: Digital Security Helpline
- Freedom of the Press Foundation: Digital Security
Put it into practice on your Mac
Try every feature free for 17 days, no card needed.