Data Recovery Case File · Trust, Practice & Honest Limits · Knowing When to Stop
Two Failed Drives and the Instinct to Stop
His enquiry contained a sentence that this archive would put on a wall if it could. Two consumer devices had failed — "one external USB and one a networked RAID unit, and neither are working. In the case of the first, I suspect it's the enclosure; in the second, I think one of the drives has gone, though that's a complete guess. However, to avoid potentially making things worse with me messing around, I wondered if you could help get the data off them." He has two reasonable hypotheses, he has labelled one of them honestly as a guess, and he has stopped before acting on either. After many hundreds of these cases, that instinct is worth more than any amount of technical knowledge — because most of the damage this archive documents was inflicted by capable people trying to help.
| Media | Two consumer storage devices — a USB external drive and a network storage unit — both non-functional; owner's hypotheses recorded but untested |
| Reported situation | Both devices failed · enclosure suspected on the first, a member disk on the second · owner explicitly declining to experiment · assistance requested before any intervention |
| Fault class | Two independent faults requiring separate assessment — hypotheses testable non-destructively; array state to be established rather than assumed |
| Equipment used | Each device assessed and quoted independently · enclosure hypothesis tested by substitution before anything invasive · array state established before any member was touched · both imaged write-blocked; contents verified by opening |
The decode: what he can safely do, and what he was right to avoid
Why stopping was the right call: because the actions that seem most reasonable are the ones that cost most. On the network unit, the obvious next steps are to let it rebuild, to reinsert a suspect disk, or to initialise the array so it comes back — and all three can overwrite the layout a reconstruction depends on. On the USB drive, the obvious step is to run a repair utility or accept a format prompt, both of which write to the structures that matter. None of those is a foolish thing to try; they are what the devices themselves suggest. That is exactly why the instinct to stop is so valuable: the danger is not ignorance, it is a helpful interface.
What he can safely do: a short list, all non-destructive. On the USB drive, his enclosure hypothesis is genuinely testable — an external is two products in one, a bare drive plus an enclosure with its own bridge board, and the bridge fails more often than the drive. Putting the drive in a different enclosure, or the same drive on a different known-good caddy, tests his theory without writing anything. If it appears, he has his answer and can copy the data off immediately. On the network unit, he can note what its status lights report, whether it powers at all, and whether it appears on the network — all observation rather than intervention.
What he must not do: the same short list inverted. No rebuild, no resync, no initialising the array, no inserting a replacement disk, and no accepting an offer to repair or format on either device. And specifically: NAS disks use a Linux filesystem, so connecting one to a Windows machine produces an offer to initialise it — which on a member disk destroys the layout or a complete copy depending on the configuration.
Why his "complete guess" is fine: he apologises for not knowing which disk has failed, and there is nothing to apologise for. An array's real state is established by examination rather than accepted from a customer, and a guess offered honestly is more useful than a confident assertion that turns out to be wrong. What matters is that he has not acted on the guess.
Two devices, two jobs: each is assessed and quoted independently, because one may be an enclosure fault resolved in an afternoon and the other a genuine array reconstruction. A single blended figure would hide which is which, and that is precisely the information he needs in order to decide what is worth doing.
On the bench
The two devices were treated as two patients and quoted separately. The USB drive's enclosure hypothesis was tested first by substitution, since it is the cheapest possible answer and non-destructive — and where the drive appeared in a different caddy, the contents were secured immediately. The network unit's array state was established rather than assumed: its members removed, labelled by bay, and each imaged write-blocked before any interpretation, so that no rebuild or resync could occur and no hypothesis had to be right first time. The array was then reconstructed offline from the copies, and both devices' contents were verified by opening before delivery.
The outcome
Both devices assessed and quoted separately, the enclosure hypothesis tested non-destructively, and the array reconstructed offline from write-blocked images. Free assessment, one fixed written figure including VAT per device; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone with a failed device and a hypothesis: stopping before you act on it is worth more than being right about it, because the interventions that seem most reasonable — rebuilding, initialising, repairing, formatting — are the ones that overwrite what a recovery needs; test only what can be tested without writing, which for an external drive means swapping the enclosure; label your disks by bay; and ask for separate figures on separate devices, because one may be cheap and the other not.
Failed device and a theory you are tempted to test
Separate the tests that write from the tests that don't. Safe: swapping an external drive into a different enclosure, trying another cable or port, noting what status lights report, checking whether a device appears at all. Those cost nothing and can only tell you more. Unsafe, however reasonable they look: letting a NAS rebuild or resync, initialising or re-creating an array, reinserting a suspect disk, running repair utilities, and accepting any prompt to format or initialise — all of which overwrite exactly what a recovery rebuilds from. Be especially careful connecting NAS disks to a Windows machine, which will offer to initialise them because it can't read their Linux filesystem. If you have more than one failed device, ask for them to be assessed and quoted separately; one may be a cheap enclosure fault and the other a real reconstruction, and you need to know which.
That instinct is the valuable part — call Glasgow Data Recovery on 0141 404 0294; each device assessed and quoted separately, hypotheses tested without writing, everything imaged before interpretation.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.