3-minute read DataRoad
In summary
- The first hour determines the outcome. Most definitely lost data is lost during recovery attempts, not the incident.
- Switch off the equipment and do not install recovery software on the affected disk.
- Data recovery is expensive, slow and without guarantee — therefore it is always the worst option available.
- A backup that has never been restored it doesn't count as a backup.
In this article
There is an inconvenient statistic in data recovery: a significant proportion of unrecoverable cases arrive that way because of what was done after of the incident. The disk had a chance; it was the attempts to resolve the issue that eliminated them.
This article is about the first few hours — and what to do to ensure you never need it.
What to do in the first hour
Stop using the equipment. If a drive is failing, every minute it is powered on can worsen the physical damage. If files have been deleted, every new write operation could overwrite the space where they still reside. Switch it off.
Do not restart repeatedly. It is a natural consequence – and one of the worst. On a disc with a mechanical fault, every time the drive starts up, the read head is forced to pass over an already damaged surface.
Isolate the equipment from the network if there is any suspicion of malicious software, to prevent it from spreading to shared drives.
Check your backups before anything else. It seems obvious, yet it’s often overlooked. If a recent, complete copy exists, the problem is no longer one of recovery but of restoration — which is quicker, cheaper and guarantees a successful outcome.
Write down what happened. What noise was heard, what message appeared, what was happening at the time, what steps have already been tried. This information is very useful for anyone who might need to intervene.
If you hear clicking or repeated mechanical noises, switch it off immediately. It is a sign of physical damage. Any attempt by software in this state tends to turn a recoverable case into permanent loss.

What never to do
- Do not install recovery software on the affected drive. The installation writes data — potentially overwriting what you want to recover.
- Do not run check and repair utilities on disks with suspected physical failure. They are made to fix file systems, not to deal with dying hardware, and can consolidate the damage.
- Do not format or reinstall “to see if it sorts it out.
- Do not open the disc. Physical recovery is carried out in a cleanroom; opening them in a normal environment irreversibly contaminates the platters.
- Don’t rely on recipes from the internet. Freezers, knocks and board swaps are stories that have been circulating for twenty years and destroy recoverable cases.
Types of loss and what changes
Accidental deletion. The best-case scenario. As long as the space is not reused, the data remains there. The rule is to stop writing to the volume immediately.
Logical flaw. Corrupted file system structure, missing partition, disk asking to be formatted. The hardware is fine; it's the map that's been lost. It usually has good recovery rates with appropriate tools used by someone who knows what they're doing.
Physical fault. Noises, unrecognised disc, intermittent operation. Requires a laboratory and a clean room. This is the most expensive scenario and the one most vulnerable to amateur attempts.
RAID failure. A multi-disk system is not immune — it is common for one disk to have failed months ago without anyone noticing, and only the failure of the second makes the problem visible. Here, the order of rebuilding matters a great deal, and a poorly executed rebuild destroys the array.
If it is ransomware
Everything changes. It's not a matter of support recovery — it's incident response.
Immediately isolate the affected equipment from the network, without disconnecting it from the power supply if there is an intention to investigate. Check whether the backups have been compromised — backup systems permanently connected to the network are a primary target. Preserve evidence before wiping anything.
And there is a decision that is not technical: paying doesn't guarantee anything and funds the following activity. It is a conversation to be had with management and, depending on the case, with legal advice and the authorities. If personal data is involved, there are notification obligations with tight deadlines.
How not to come back here
Data recovery is always the worst option available: expensive, time-consuming and with no guarantee of a result. Anything that avoids it is worth more than it is.
The rule of thumb that continues to work is that of the three copies: the production data, a local copy for quick restoration, and an off-site or air-gapped copy — the latter being the one that survives ransomware.
But the part that fails the most isn't having copies. It's test them. A backup that has never been restored is a hypothesis, not a guarantee. The restoration test should be a scheduled event, with a set date, like a fire drill.
And monitoring: knowing that the backup failed on the day it fails, and not on the day it is needed.
DataRoad implements and manages backup and recovery solutions for businesses, with restoration tests and continuous monitoring, within managed IT services.
A chat before making a decision
Whether you’re tackling a specific problem, planning a move or simply looking for a second opinion, we always start in the same way: by understanding your situation before making any suggestions. No obligation, no jargon and no catalogues.




































































































