Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Milestone · Preservation Is Not Recovery

The Enquiry That Asked for Imaging Before Access

The nine hundred and fiftieth case in this archive is the only one that arrived already knowing the answer. A son writing about his late father's computer — a retired academic — held in his possession and believed encrypted, with no access to any passwords or recovery keys. The machine likely held a significant body of academic work including unpublished material, and colleagues and institutions had expressed interest in preserving it. He then asked for three things, in this order: safely image and preserve the contents of the drives; assess whether any data can be accessed, with or without decryption; advise on realistic recovery scenarios given the encryption. Almost every enquiry in this archive asks can you get my data back. He asked to preserve it first and find out second — and that ordering is a doctrine this archive has practised for nine hundred and fifty cases without ever stating plainly.

MediaDesktop computer belonging to a deceased academic — storage believed encrypted with no credentials or recovery keys available; substantial body of scholarly work including unpublished material understood to be held
Reported situationMachine held by the family following a bereavement · encryption believed present · no passwords or recovery keys accessible · scholarly and institutional interest in preservation · forensic, non-destructive approach requested explicitly
Fault classNo device fault — an authority, preservation and credentials case; encrypted content preservable in full regardless of whether access is currently possible
Equipment usedAuthority verified by documentation before examination · every drive imaged write-blocked and verified by hash (Atola TaskForce 2) · images stored as the preserved asset · encryption state established and key sources searched · position and realistic scenarios issued in writing

The decode: why imaging comes first, and what it buys

The distinction almost nobody draws: preservation and recovery are different operations with different requirements, and only one of them depends on access. A forensic image of an encrypted drive is a complete, faithful copy of the encrypted data. It can be taken today, in full, whether or not anyone alive can read a byte of it. The image contains everything the drive contains — including the encrypted volume, its headers, and any unencrypted regions — and it can be verified by hash so that its fidelity is provable years later.

Why that matters more than it sounds: because the two objects age completely differently. A hard drive is a mechanism with bearings, a motor, a head assembly and a circuit board, and it is failing slowly whether or not it is used — and if it is left in a cupboard for five years, its next spin-up is the most demanding moment of its life. An image is a file. It does not spin, does not seize, does not develop bad sectors, and can be copied indefinitely. Imaging converts a decaying asset into a stable one, and in doing so it converts a deadline into no deadline.

Why that is exactly right for his situation: because his obstacle is a credential rather than a fault, and credentials surface. A password manager on another machine. A note in a filing cabinet or a notebook. A recovery key printed at setup and filed with the paperwork nobody has been through yet. A colleague who knew his practice. An old unencrypted backup on a drive in a drawer. An institution that later acquires both the authority and the means. None of those may appear this year. Any of them may appear in five — but only if the encrypted data still exists in five years, and a drive in a cupboard is a poor bet where an image is a safe one.

The honest technical position, stated plainly: encryption without a lawful key is a wall. It is not a lock to be picked, and this bench turns lawfully-held keys only. If no key is ever found, the plaintext is unreachable — permanently, for anyone. That answer does not change. But it is an answer about access, and he did not ask only about access. The wall stands between the family and the plaintext; it does not stand between them and the preservation.

Authority, as always: possession is not authority, and where an owner has died the person entitled to deal with their property is the executor or administrator, evidenced by the death certificate together with the grant of probate or letters of administration. That requirement protects this estate and every other, and it comes before examination rather than after.

The dimension that makes this a milestone rather than a case: the work is scholarly, some of it unpublished, and other people want it. The loss would not be confined to a family — it would remove something from a field. That is an argument for preservation specifically, because an archive or an institution may in time have both the standing to pursue access and the resources to do it, and their opportunity depends entirely on whether the data still exists when they arrive.

The outcome — and the volume closes

Authority was verified by documentation before any device was examined. Every drive was then imaged write-blocked on the Atola TaskForce 2 and verified by hash, so that the fidelity of the copy is provable rather than asserted — the images stored as the preserved asset in their own right, independently of whether anything can currently be read. Only then were the access questions addressed: the encryption state established, the unencrypted regions examined for material outside the protected volume, and the plausible key sources searched with the family — other machines, password managers, printed keys, backups predating encryption, and accounts that may hold an escrowed copy. The realistic scenarios were issued in writing, including the honest one. Free assessment, one fixed written figure including VAT; imaging and preservation quoted separately from any access work, because they are separate things.

And with case 950 this volume closes, and site four passes two hundred. The milestones behind it have circled a single argument. At 550, a shop that knew not to touch a failing drive. At 600, two shops that met their ceiling and pointed onward. At 650, institutions each doing their job while the data question belonged to nobody. At 700, an executor with every right and no key. At 750, the honest no. At 800, the customer who did everything right. At 850, the backup that covered everything except the file that mattered. At 900, the laptop that booted once and died in the two minutes it took to fetch a cable. And here, at 950, the enquiry that needed none of it explained — because he had worked out the order of operations for himself, from first principles, while grieving.

So the doctrine, stated plainly at last, because it is the one thing this archive would keep if it could keep only one sentence. When you cannot decide, preserve. An image costs a fraction of a recovery, requires no access, and buys unlimited time. If the answer today is no — no key, no budget, no certainty about what is even on it, no idea whether it matters — take the image anyway and decide afterwards. Because the drive will not wait for the answer to change, and the image will wait as long as you need.

When you cannot decide what to do with a drive

Preserve it, and decide afterwards. Imaging and recovery are different things: a forensic image is a complete, faithful copy that can be taken whether or not anyone can currently read the contents — including from an encrypted drive, where the image captures the encrypted data in full. That matters because the two objects age differently. A drive is a mechanism that degrades whether or not you use it, and one left in a cupboard for years faces its hardest moment at the next spin-up. An image is a file that doesn't spin, seize or develop faults, and can be verified and copied indefinitely. So if you're facing a locked drive, an estate you haven't finished going through, a budget you don't have yet, or simply no idea whether the contents matter — take the image now and answer the questions later. Keys and answers surface; drives don't wait.

A drive you can't yet decide about?
Preserve it first — call Glasgow Data Recovery on 0141 404 0294; authority verified, every drive imaged write-blocked and hash-verified, and access questions answered separately and honestly.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294