Taking work now — the first look is freeSpinning disks in a machine Quicker still, give us a ring:0203 0868633
ADR Advanced Data Recovery 0203 0868633 Price my job
ADR / Sorted by symptom / Data after a disaster

The part that follows

Disaster recovery, London. Not sold by the month. The job is lifting data back off the hardware afterwards.

Two trades answer to that phrase and only the second is ours. The first sells what you arrange beforehand — copies held elsewhere, a contract, hardware sitting spare. None of it is sold here, so if that is what you came for, your IT department or a managed provider is the right call. The second trade begins the morning those arrangements were not enough: a server or a RAID set that will not start, a NAS reporting no volume, disks pulled out after water or heat damage, a machine that met a spike when the electricity returned, shares enciphered during a ransomware incident. Hackney sends a good deal of that, the council's own economic plan counting some 98% of businesses there as micro or small and the founder as IT department too; Canary Wharf sends the other sort, where the media is encrypted and the first question is whether recovery breaches a compliance obligation. Multi-disk work is published at £500 + VAT and upwards, the look that sizes it is free, and on most jobs the invoice follows the data or does not arrive. The files come back to you; putting them onto replacement hardware is your systems people's half.

On most jobs: no data, no bill A free look first, then one figure in writing Media posted in from Croydon, Ealing and Camden

Put it to an engineer — the first look costs nothing
0203 0868633

What the symptom usually means.

Different fault? Try the finder →
How it shows itselfThe usual reason for itWhere that leaves you
A server that never comes upThe controller has put a second member out, or the set never returned after a power eventLeave the power off and mark the bays
The NAS starts, but the share has gone or comes up read-onlyThe disks no longer agree on how the array was laid out, so the unit declines to guessDo not let it initialise
A rebuild was begun and stopped part way throughA second member stopped under the read load, and parity only ever covered oneStop, and send every one
Disks recovered after water damage or heat damageConnectors and boards take the damage; behind the seal the platters generally do notBag them as found, and post today
Folders renamed and unreadable, with a note left beside each oneSomething reached the shares long enough to encipher them and empty the snapshotsUnplug the network lead; leave power on
Nothing since the power returnedA spike through the board — and on one supply it reaches every disk hanging off itLeave the whole set switched off
Packing it and posting it:cushion it so nothing can shift about, insure the parcel at the value of the files and not the price of the hardware, and post it tracked. We meet the cost of the leg home. Prefer to walk the packing through with an engineer first, before the box is sealed? Ring us. Every bit of it is written down on theguide to packing and posting.

What decides a job of this size.

The load a rebuild puts on themEvery remaining member gets read across its whole surface, with parity recomputed and written as the pass travels. For a set that has already dropped a member, no harder demand has been made of those disks in years — and it is being made at the worst possible hour.
Where the array is describedNot in the enclosure. Every drive carries a description of its own in a superblock, so a box that will not start is rarely where matters finish — the disks are lifted out, and the volume is reassembled here instead.
Water, heat, mains electricityThe gentle version is a pipe splitting above a comms cupboard. Heat is worse, since solder and plastics surrender long before an alloy casing does, and the board then becomes a part to be sourced. Hardest to plan around is the mains: electricity returns more roughly than it departs, and a single spike travels along a shared supply and into every disk on it.
Once ransomware has been throughShares get enciphered fast, and fast work is careless work. A snapshot the unit itself kept, volume shadow copies the software never reached, originals unlinked rather than overwritten, long files enciphered only in stretches — a recoverable file list is assembled out of leavings like those. No payment is made from here, and no approach is made to anybody.

From the box arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on it the day the parcel lands, and an engineer settles what has truly failed before anything else happens — free of charge, and first in the order of work. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNothing owed at this stage
02

Disks arrive bay-numbered

A server or a RAID set travels as bare drives, each carrying its bay number in marker before it leaves the chassis; a NAS may come whole, power supply included. Nothing is switched on here and no controller is invited to interpret anything. Bay order, and whatever has already been tried, is written down before a disk is touched.

Bay order noted firstNo disk is switched on here
03

Each member cloned on its own

Every disk goes onto an imager of its own, the weakest one first, with the read rate dropped right back wherever a head is labouring. As soon as the clones exist your own disks are shelved and left alone.

Weakest member firstReads slowed where a head labours
04

Assembled over the clones

The order of the members, the size of the stripe and the way parity rotates are all derived from the clones rather than believed from the card. The volume goes back together over those clones, the file tree is read off it, and not one write reaches a disk of yours.

Volume built over the copiesYour media is read, and only read
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge whatever. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have read those files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the jobThe post home is ours

What arrives most often

  • It is the second failure that shows — a set can run a member short for months without the front panel mentioning it once. The next disk to stop is the one that takes the volume with it.
  • A deleted share and a share that is simply gone are different problems — deleting a folder from a NAS or a server generally leaves the metadata that described it in place, and a database refusing to attach is far more often a matter of its header or its log than of the pages themselves. Look at both before the volume beneath them is rebuilt.
  • Nearly always it is the one machine nobody copied — a workstation beneath somebody's desk holding all the drawings, a server in a cupboard, the NAS everybody mapped and nobody ever opened. Where that is the job, the disks in front of us are the entirety of it, which is why nothing here is switched on to find out.
  • The seal is where it stops — pins, connector and board all sit outside it and are what take the damage, whereas the chamber the platters turn in is sealed against precisely this and generally reads afterwards as it read before. Dry nothing, and switch nothing on to check.

Almost none of this is dramatic work. The hardware behind it is ordinary: a practice server in Clerkenwell carrying the model files for a live project, a NAS in a Harley Street basement with the imaging on it, a studio's desk-side array out of an arch at Hackney Wick, the single workstation in a Whitechapel family firm that nobody ever copied anything off. Ordinary hardware, and most of these finish as ordinary jobs. What tips one the other way is almost always what got done between the failure and the postbox: the number of rebuild attempts, and the number of days a wet disk spent in a cupboard before somebody bagged it.

One job, followed all the way through.

LDN · ADR-2025-2891JOB LOGGED ✓

Nine months between the two failures, and the volume still came back whole

A joinery works outside Barnet ran a four-bay Synology DS418 over the bench, RAID 5 across four 4TB members, its fan pulling sawdust off a mitre saw for years. One member had been logging bad sectors from January onwards; instead of answering the warning emails, somebody switched the emails off. Nine months on a second member stopped and the box reported the volume failed. An intention was already written in marker pen across the lid — new disk in, let it rebuild — and that was the single instruction we declined, in writing. Head stacks were replaced on both failed members, all four imaged, and the volume went back together over the images.

All 4 members imaged first2 head stacks replaced

What helps, and what harms.

Do this much first

  • Switch the set off and keep it off — no further rebuild attempts, and nothing initialised
  • Write the bay number onto each disk
  • Say what the controller is, the level, and what was tried
  • Post the bare drives; a NAS is welcome whole

What sets us back

  • Setting the rebuild going again on the chance this pass finishes, the commonest single reason a set stops being recoverable
  • Shuffling disks between bays to identify the bad one
  • Allowing the card to initialise the set
  • Reinstalling or restoring back onto those same disks

Questions answered before you commit.

Do you sell a disaster recovery plan?

No, nor anything near one: no backup product, no continuity contract, no hardware held spare, no out-of-hours rota. A plan is worth owning and somebody ought to sell you one — your own IT department, or any managed provider. This is the number for afterwards, when the only surviving copy is sitting on hardware that refuses to hand it over.

Shall we let it rebuild again?

No. Switch it off, and keep it off. A rebuild reads every surviving member end to end and writes parity as it travels, which is the heaviest work those disks have been asked for in years, requested at the precise moment the set is one member short. Mark the bays, lift the disks out, send them exactly as they are.

What does work of this size cost, and how long?

This page sits in the multi-disk band, which opens at £500 + VAT. For comparison, a card or a stick comes to £250 + VAT and a single drive to £300 + VAT. One figure goes to you in writing; chargeable work begins only once you have agreed to it. Three to six working days after the parcel lands is normal. On most jobs, nothing is billed when the data does not come back.

What survives a ransomware incident?

Usually more than the note on the screen implies. Enciphering a network overnight is hurried, and hurry is careless: a snapshot the unit itself kept, volume shadow copies the software never got round to, originals unlinked instead of overwritten. Leavings of that kind are what a file list is assembled from. No payment is made from here.

Nothing gets worse while the power is off.

Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. On most jobs an invoice only follows the data. Until that list reaches you, leave the drive switched off.

0203 0868633