In this SANS Ransomware Summit panel, Michael Rogers, Senior Director at MOXFIVE, and other experts discuss whether to cut off internet access during a ransomware investigation. It's a complex choice based on business operations, security posture, and compromise. Real cases show keeping internet open can lead to more problems such as continued exfiltration or actions on objective, while disconnecting, though business impacting, reduces potential risk.