Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Second Fixes & Trade Handoffs · Protect What You Have

Most of It Is Off, and the Rest Is the Hard Part

His enquiry reported a partial success and asked a reasonable follow-up question. A failed 2TB drive: "I have managed to get approximately 70% of the data from it — just wondering how much it would cost to try and completely recover the data from the drive." That is a genuinely good outcome achieved alone, and the question deserves a straight answer. But there is something to say first, because it is more urgent than the pricing. The 70% he already has is now the most valuable thing in this case, and the way most people in his position lose it is by continuing.

MediaFailed 2TB hard drive — approximately 70% of contents already extracted by the owner; remaining portion inaccessible
Reported situationDrive failed in service · owner extracting approximately 70% of contents · remaining data not obtainable by the owner's means · full recovery of the remainder sought
Fault classPartial read failure — bulk of surface readable with a residue of failing regions; remaining data concentrated where reads fail
Equipment usedExisting recovered data verified and secured before any further work · Atola Insight Forensic error-rate assessment · PC-3000 Express with Data Extractor imaging under per-sector timeouts, weak regions revisited · losses mapped per file

The decode: secure what you have, then the honest arithmetic

Why the existing 70% needs protecting first: because it is finished and safe, and nothing about further attempts can improve it while several things can jeopardise it. If that data sits on the same machine that has been doing the copying, or on a drive that is itself elderly, it should be copied somewhere else today — and the copy verified by opening files rather than by checking a count. People in this position frequently keep working on the remaining 30% for weeks and then lose the 70% to an unrelated failure, having never made a second copy of it.

The second thing to check about that 70%: whether it is actually good. Files copied from a failing drive can arrive incomplete or with unreadable sections silently padded, depending on how they were copied — so a file can exist at the right size and not open. Spot-checking a sample by opening them is worth an hour, because a recovery that turns out to have delivered broken files is a different problem from a recovery that is 30% short.

Why the remaining 30% is disproportionately hard: the honest arithmetic. He got 70% because 70% of the surface reads. What is left is precisely the material sitting where reads fail — so the remainder is not simply more of the same work, it is the difficult part by definition. That is why straightforward copying stopped where it did.

What actually retrieves it: a different technique rather than more persistence. Imaging under per-sector timeouts gives each failing sector a strict budget and defers it rather than waiting for the drive's internal retries to exhaust — then returns on later passes, where sectors that failed several attempts frequently succeed. Ordinary copying cannot do this; it asks once, waits, and moves on or stalls. That difference is where most of the remaining 30% comes from.

The honest expectation: not all of it. Some regions will be genuinely unrecoverable, and the useful deliverable is a map of losses per file — knowing exactly which files are incomplete is worth more than a percentage, because it lets him decide what still matters.

Why he should stop copying now: every further attempt is sustained reading of the weakest regions with no timeout control, which is the operating condition most likely to make things worse.

On the bench

The existing recovered data was verified and secured before any further work — copied to separate media and spot-checked by opening files, since a partial recovery that turns out to contain silently padded files is a different problem from one that is merely incomplete, and nothing on the drive could improve what was already safe. The Atola Insight Forensic then assessed error rates to establish how the failing regions were distributed. Imaging ran on the PC-3000 Express under Data Extractor with per-sector timeouts, weak regions revisited on later passes, and every unreadable area resolved to the individual files it affected.

The outcome

The existing data secured and verified first, the remainder imaged under timeout control and the losses reported per file. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who has recovered part of a failing drive themselves: what you already have is the asset — copy it somewhere else today and spot-check it by opening files, because copies from a failing drive can arrive silently padded and the right size; then understand that the remaining portion is the hard part by definition, since you got what you got because that part reads. Stop copying, because the technique that retrieves the rest is timeout control rather than persistence.

Recovered part of a failing drive yourself

Secure what you already have before you do anything else — copy it to separate media today, and spot-check it by actually opening a sample of files. Two things catch people here. Files copied from a failing drive can arrive at the right size with unreadable sections silently padded, so a file can exist and not open; finding that out now is much better than finding out later. And people commonly keep working on the missing portion for weeks, then lose the part they'd already saved to an unrelated failure, having never made a second copy. Then be realistic about the rest: you got what you got because that part of the surface reads, so what's left is the difficult part by definition. More copying won't reach it — the technique that does is giving each failing sector a strict time budget and returning to it on later passes.

Got most of it off and stuck on the rest?
Secure what you have first — then call Newcastle Data Recovery on 0191 406 1051; error rates measured, remainder imaged under per-sector timeouts with weak regions revisited, losses named file by file.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.