Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Quarantine
Cyber Security

Quarantine

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Cyber Security

Quarantine is a DLP response that pauses delivery of a message until it can be reviewed or released under policy. It is typically used for medium to high risk content when organisations want control without immediate outright denial. Quarantine also creates an audit trail for investigation and tuning.

Expanded Definition

In DLP and secure messaging workflows, quarantine is a controlled holding state that interrupts normal delivery until a human or automated policy decision is made. It is distinct from blocking, which denies delivery outright, and from simple alerting, which reports an event without changing disposition. NHI Management Group uses quarantine as a governance term for risk-managed suspension, especially where content inspection, sender reputation, data classification, or policy confidence is incomplete. In practice, quarantine may apply to email, file transfer, collaboration messages, or outbound content containing regulated data, suspicious links, or policy violations. Its purpose is to preserve operational continuity while reducing exposure, and it often feeds case management, review queues, and audit logging. Definitions vary across vendors because some tools use quarantine as a delivery state while others treat it as a user-visible mailbox folder or administrative review queue. The most common misapplication is treating quarantine as equivalent to rejection, which occurs when teams assume no action is needed after content is isolated.

Examples and Use Cases

Implementing quarantine rigorously often introduces review latency and operational overhead, requiring organisations to weigh faster user delivery against stronger policy control.

Common uses include:

  • Email with sensitive data patterns is held for security review before release or deletion, rather than being blocked automatically.
  • A file-sharing platform quarantines a document that matches a policy for regulated identifiers, allowing an analyst to confirm whether the match is legitimate.
  • Outbound messages containing suspicious URLs are paused so defenders can check for phishing indicators and determine whether the sender account is compromised.
  • A collaboration message is quarantined after an automated classifier raises low-confidence concern, reflecting the NIST Cybersecurity Framework 2.0 emphasis on detection, response, and governance-aligned handling.
  • In an identity-adjacent workflow, a message tied to account recovery or privileged access is quarantined when it could expose secrets, tokens, or verification data.

Quarantine is most useful when the organisation needs a reversible action that can be reviewed, escalated, or tuned without creating unnecessary business disruption.

Why It Matters for Security Teams

Quarantine matters because it gives security teams a defensible middle path between permissive delivery and hard denial. Used well, it reduces the chance that sensitive data, malicious content, or policy violations reach recipients before a judgment can be made. Used poorly, it creates hidden operational friction, delayed communications, and missed incidents if queues are not staffed or review thresholds are not tuned. Security and governance teams need clear rules for who can release, discard, or escalate quarantined items, along with logging that preserves the reason for intervention. This is especially important where quarantine touches identity recovery, privileged workflows, or NHI-related exchanges, because delayed or misreleased content can expose credentials, tokens, or approval paths. Quarantine also supports incident response by preserving evidence and showing how the control behaved over time, which helps refine policy and reduce false positives. Organisations typically encounter the real cost of quarantine only after a high-volume incident or a misrelease event, at which point disciplined review, queue ownership, and policy tuning become operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DSQuarantine supports protecting data by holding risky content before release.
NIST SP 800-53 Rev 5SI-4Monitoring and analysis controls cover detection-driven content holding and review.
ISO/IEC 27001:2022A.8.12Supports data leakage prevention handling for content flagged by policy.
NIST SP 800-63Identity workflows may require holding recovery or verification messages.
OWASP Non-Human Identity Top 10NHI workflows can be affected when quarantined content contains credentials or tokens.

Use quarantine to prevent unvetted content from reaching recipients until policy review completes.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org