Incident Playbook
Internet Shutdowns
Summary
Internet access or specific platforms are deliberately blocked or slowed, cutting staff and communities off.
- Category
- Infrastructure and connectivity
- Typical severity
- High
- Response led by
- Incident lead, with programme and field leads
First 15 minutes
- Switch to the plan you agreed in advance.
- Use only tools you installed before. Don't install VPN files shared in group chats, which are a common way to spread malware.
- Keep sensitive details off plain SMS and calls, which aren't encrypted.
1. Overview
An internet shutdown is a deliberate disruption of internet access or specific services, often ordered during elections, protests or unrest. It cuts people off from news, help and each other, and makes it harder to document what's happening.
2. How it happens
- A full shutdown of mobile data or all internet access in an area or country.
- Throttling, where connections become too slow to use.
- Blocks on specific platforms, such as social media or messaging apps.
- Blocks on specific websites, including news and civil society sites.
3. Indicators
Signs that this incident may be happening:
- Apps and websites stop loading for everyone at the same time.
- Some services work while others don't.
- Disruption begins around elections, protests or other sensitive events.
4. Triage questions
Answer these first to understand scope and severity:
- Is it a full shutdown, throttling, or blocking of specific platforms?
- Which areas, networks and services are affected?
- Where are staff and partners, and can you reach them?
- Which critical work depends on connectivity?
- Is it linked to an election, protest or other event, and how long might it last?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | Brief disruption of a single platform; alternatives work. |
| Medium | Specific platforms blocked for days; work slowed. |
| High | Mobile data or internet shut down in areas where staff work. |
| Critical | Full shutdown during unrest, with staff in the field and no way to confirm their safety. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- Switch to the plan you agreed in advance.
- Use only tools you installed before. Don't install VPN files shared in group chats, which are a common way to spread malware.
- Keep sensitive details off plain SMS and calls, which aren't encrypted.
- Keep regular safety check-ins with everyone in the field.
- Record when the disruption started, what it affected and where.
7. Communication
Who to inform, and when:
- Field staff, through pre-agreed offline channels and check-ins.
- Leadership and incident lead, to make safety decisions.
- Partners and funders, about delays to work and reporting.
- Communities you serve, through offline channels where possible.
- Groups that document shutdowns, once it is safe to share records.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- When the disruption started and ended, and which networks and services were affected.
- Screenshots and test results showing what was blocked.
- Locations affected.
- Impact on work and on communities.
- Any official statements about the disruption.
9. Recovery and review
- Upload evidence securely once connections return.
- Share your records with groups that document and challenge shutdowns.
- Check in on staff and partners.
- Review your plan and fix what didn't work.
10. Prevention checklist
- Agree an offline communication plan: phone trees, simple SMS codes and meeting points.
- Install trusted circumvention tools, such as a reputable VPN, before you need them.
- Download offline maps, key contacts and important documents.
- Agree how evidence will be stored securely offline until it can be shared.
- Keep devices charged, with power banks ready.
- Plan how you'll keep in touch with staff in the field.