Diagnostic assessment for data recovery in Canterbury

For Canterbury, a business data recovery case is defined by service impact and dependencies, not only by the number of terabytes.

  • Case intake Gather the storage details, failure chronology, prior actions, encryption information and priority files.
  • Technical diagnosis Determine the physical and logical risks and select an acquisition approach suited to the medium.
  • Source protection Use protected images where possible to rebuild arrays, volumes and file structures outside the source.
  • Result validation Test representative priority data, describe incomplete results and prepare readable files on healthy storage.
data recovery laboratory — data recovery

Assess the fault before acting

A noisy hard drive, an SSD that is not recognised and a degraded RAID volume do not call for the same actions. The diagnostic assessment separates physical failure, logical corruption, encryption and combined incidents.

The timeline also helps assess the effect of a knock, power issue, deletion or rebuild that has already been started.

The timeline connects the last healthy use, first warning, regional transport and every later restart before the fault layers are classified.

Very slow hard drive with unstable sectors

A very slow drive should remain powered off during regional or inter-island transport.

Unstable heads and unreadable sectors can worsen each time a normal backup retries.

Document the first delay and any power event, then capture responsive areas with bounded retries. Analyse volume structures and essential folders on the image.

Clicking, scraping, or recurring recalibration means power should remain off. Mechanical stability needs evaluation before another region of the disk is read.

  • Stop a copy if the computer freezes or the drive repeatedly disconnects
  • Record SMART warnings and the location of observed read errors
  • Do not run a surface scan or repair tool that writes to the drive

Acquire evidence before reconstructing data

Where the medium remains stable enough, a controlled image provides a repeatable source for file-system work. RAID metadata, encryption keys, VM descriptors and recorder time settings are retained with it.

Reconstruction is performed on working material so a mistaken hypothesis does not rewrite the only remaining source.

Unstable ranges are read by priority, capturing structural metadata and essential folders first while gaps are logged rather than repeatedly forced.

External drive with a failed USB socket or enclosure

An external drive fault may sit in the cable, power adaptor, bridge board, or disk.

One controlled cable check is different from repeatedly starting a unit that clicks, heats, or disconnects.

Separate interface testing from media acquisition. Keep the original enclosure and identifiers because its bridge may control encryption or sector translation.

Once the disk is judged stable, a protected direct connection can isolate bridge failure without initialization, formatting, or an operating-system repair prompt.

  • Keep the original enclosure, power supply and cable together
  • Stop powering the unit if there is noise, smell or abnormal heat
  • Do not fit an unrelated controller board without checking firmware and ROM data

Make file checks reflect the case requirements

Describe required accounts, work folders, image dates, database tables or camera window. Priorities guide reads when a disk is unstable.

Keep enclosures, chargers, card adaptors, array logs and recovery keys. Decline resets, formats and in-place repairs.

Recovered documents, media and application data are sampled for opening, dates and consistency. Handover identifies gaps and partial content.

The stages of a defensible data recovery

A NAS rebuild can combine incompatible member states when disk order or warning history is incomplete.

Stripe layout, parity rotation, controller metadata, and the failure sequence define the likely coherent state.

Label bays before transport, image members separately, and test layouts virtually. Do not let the appliance initialise a pool or write replacement parity.

Keep firmware details, alert history, and replaced disks with the case. A candidate layout must expose the newest coherent shares and selected files.

  • Label every drive in the position in which it was found
  • Stop rebuild, initialisation and member-replacement attempts
  • Preserve controller logs and the timing of each warning
  • Image safely and rebuild on protected working copies.

A practical brief for the diagnostic assessment

Visible database files may still contain broken pages or a transaction chain that no longer closes.

A power event or interrupted replica can leave data, logs, and secondary files at different times.

Safeguard the source set, examine headers and log relationships on copies, and verify selected records. Report usable exports separately from unresolved inconsistencies.

Identify the database engine, version, local time range, and important tables. Successful startup is not enough if transactions or application records remain incomplete.

  • Stop the database service and automatic repair jobs
  • Keep data files, logs and configuration together
  • Identify critical tables, tenants and the required recovery point
  • Last healthy use and incident sequence.
  • Earlier restarts, scans, repairs or rebuilds.
  • Essential folders, formats and date ranges.

Data recovery laboratory — Hard Drive Recovery in an ISO 5 Clean Room

For a case sent from Canterbury, the diagnostic assessment first identifies the storage technology and the affected layer. That evidence selects the suitable mechanical, electronic, logical or system-level laboratory process.

A donor head assembly is matched by technical family, revision and preamplifier compatibility, not just the model label. It is used to create a temporary reading window for controlled sector imaging.

Compare generations before selecting the reference copy

For Canterbury, the original, external disk, NAS, cloud and synchronised copies remain isolated. Dates, versions, deletions and conflicts form a timeline, and generations are compared on working copies before any merge.

The source is not repaired in place. A sector-level or device-appropriate acquisition is created where condition permits, and every read limitation remains logged for later reconstruction.

File systems, containers, arrays or application layers are analysed on a separate working copy. This prevents an incorrect assumption from changing the only available source.

The result is checked by opening priority documents, media, archives or application data and comparing them with known dates and structures.

FAQ

Frequently asked questions

Can media from Canterbury be sent between islands for assessment?

Transport can be coordinated after review. Use confirmed case details, pack against movement and keep labelled array members together.

What should happen after moisture or earthquake shock?

Disconnect power safely, leave the device closed and record the event. Avoid heat, rice, hard-drive opening or another test startup.

Should an extremely slow hard drive be copied with a normal backup program?

No. Uncontrolled retries can worsen the condition. A limited, logged sector image provides a safer basis for recovery work.

Can an external hard drive simply be moved into another enclosure?

Not always. A bridge may change sector presentation or encrypt data. Preserve the original enclosure and identify the failed layer first. Keep adaptor, cable and serial labels with the unit.

Can the original RAID disk order be found by trial and error?

It can often be tested, but not by writing to the original members. Metadata and disk images provide the safer evidence for reconstruction.

Is locating the missing database file enough to declare recovery successful?

No. The file must be opened with the appropriate engine and checked for structural and business-level consistency.

Diagnostic assessment

Unsure about a storage device or fault?

Datastrophe assesses the risk before any recovery attempt and points you towards the safest next step.

Request a diagnostic assessment