'IT data recovery' gets used for two jobs that share almost nothing. The first is continuity: documented systems, tested restores, failover, an agreed order in which things come back and an agreed person who decides. That is planning work, it is done in advance, and it is what keeps a firm trading through an incident. The second is salvage: a specific piece of storage has failed or been destroyed, and somebody has to get the data off it. That is bench work, it is done afterwards, and no amount of planning removes the need for it.
The trades get confused because they are sold together and they overlap at exactly one point — the moment a restore fails. Up to that moment the plan is doing its job. After it, the plan has nothing further to offer and the question becomes physical: what is on that disk, and can it be read. A firm with a good plan still ends up on the phone to a recovery bench occasionally; a firm without one ends up there in a much worse mood.
The pattern here has a local shape. Mid-Norfolk's agricultural and food businesses run production, traceability and cold-chain records on systems that were specified years ago and have quietly become load-bearing — a line PC in a room nobody visits, a camera recorder logging a process that an auditor will one day want to see. When one of those fails, the loss is regulatory as much as commercial. Out at Great Yarmouth, the offshore-wind supply chain generates survey data, inspection records and project archives on kit that spends its life being carried, and portable drives that live in bags fail for reasons that are entirely physical.
Then there is the research end. Norwich Research Park and UEA between them produce a great deal of data that exists in exactly one place for longer than anybody admits — a postdoc's external drive, an instrument PC with a local capture folder, a laptop that goes home at night. None of that is negligence; it is what happens when the person generating the data is also the person responsible for it and has a grant deadline. The failures are the ordinary ones: dropped externals, dead laptop drives, a NAS that ran for six years on discs bought on the same day and then failed two of them within a fortnight.
First, keep one copy that is not attached to anything. Not a second drive on the same desk, not a share on the same network, not a sync folder that faithfully mirrors a deletion. Offline or genuinely off site, rotated, and boring. Second, test a restore. An untested backup is a belief, not a backup, and the moment it fails is a poor time to discover the difference. Restore something real, quarterly, and time how long it takes.
Third, write down what matters and in what order — which system has to be up first, who decides, who can be told. Half the cost of an incident is people standing about waiting to be given permission. Fourth, and this is the one that actually saves the data: stop touching failing hardware. A drive that has started clicking, a NAS that is halfway through a rebuild it will not finish, a server that reboots every few minutes — every additional attempt to make them work reduces what comes back. Paint it on the wall if that helps: an array is not an archive. RAID is there so a single dead disc does not halt trading this afternoon, and it defends you against nothing else — not a deletion, not an encryption run, not a burst pipe, not a rebuild that turns out badly.
Power the affected system down rather than letting it keep trying, and do not start or continue a rebuild. Label every disc with the bay it came out of before anything moves — that mapping is worth real money later, and it is lost the instant somebody tidies the discs into a box. Ring 0800 689 0668 and say what it is stopping; the job is flagged on that call so it goes to an engineer as soon as it lands rather than joining the queue.
Then send the storage, not the furniture. Tracked and insured post reaches the bench the next working day from anywhere in Norfolk; your own courier is fine if your firm already runs an account, on your booking and your cost; or somebody drives it to the Cambridge desk. There is no collection service, so no part of your recovery depends on a van turning up. Every disc is imaged individually before anything is reconstructed, so nothing is ever risked on a live rebuild, the free diagnostic is finished inside 2 working days of arrival, and the fixed written quote arrives before any chargeable work begins. We are perfectly happy to work alongside your own IT people, and generally the job goes better when we do.
An array is not an archive. RAID is there so one dead disc does not stop you trading this afternoon. It preserves nothing against a deletion, a ransomware run, a burst pipe or a rebuild that goes wrong tomorrow — only a copy that is not attached to the system does that.
Free diagnostic inside 2 working days of arrival, one fixed quote, no fix no fee on logical faults. Start online or ring the freephone.