Disaster recovery describes two trades. One writes the plan and sells the replication; this is the other, the bench that gets the data back when the plan turns out to have a hole in it. Here are the six failures that actually arrive from this county, what the first hour should look like, where three copies on two media with one off site usually breaks down in practice, and what each band costs.
Servers and arrays begin at £500 + VAT; one drive is £300 + VAT. The examination that produces the figure is free and closes on the second working day after your media is logged in. Ransomware is priced as ordinary media rather than as investigation.
The disaster in a disaster recovery plan is hardly ever a fire. Six situations account for very nearly every business emergency that reaches this bench from Coventry and Warwickshire, and four of them happen on a completely unremarkable Tuesday.
A drive failed in February, the alert went to a mailbox that closed when its owner left, and the array carried on one short until the next one went. The volume disappears, the server is still humming to itself, and the last restore anybody proved is older than anyone wants to say out loud. This is the most common business disaster there is.
It nearly always arrives over a weekend. Disconnect the affected machines straight away, reinstall over nothing, and reformat nothing. Recovery works on what the malware never reached, on originals it unlinked rather than overwrote, and on older versions held elsewhere. Charged as ordinary media, never quoted as investigation.
A volume dropped during a migration, a share deleted at twenty past four, a LUN detached from a host it did not belong to, an array made again by an optimist. Nearly all of that reverses cleanly, provided the machine went off promptly and nothing has written to the storage since.
A pipe above a comms cupboard, a basement office after heavy rain, a fire that the extinguishers dealt with thoroughly. Power nothing up to check and dry no electronics. Storage that arrives sealed and still damp recovers far more often than storage somebody switched on to see whether it survived.
Found at the worst imaginable moment. A job failing silently since the spring. A box backing itself up onto itself. A sync client that faithfully copied the encryption to every machine in the building within the hour. A copy nobody has ever restored from is not yet a backup, and this is the week that gets proved.
The building is fine and the storage is not. A power cut leaves a database inconsistent, a controller dies, a guest will not boot, a disk starts clicking under a desk. Undramatic, business-stopping, and the bulk of what comes through here. Ordinary recovery rather than an insurance claim, and quoted before a thing is touched.
Worth settling at the top, because the phrase covers two different trades. One of them writes your continuity plan, sizes your recovery objectives, sells replication and tests the failover on a Saturday. That is a worthwhile service and it is not the one on offer here. This is the other half: the storage has already failed, the plan has turned out to have a hole in it, and the disks come to a laboratory so the data can be got back off them.
Nothing on this site is backup software, hosted replication or managed IT, and nobody here will ring you about a service contract afterwards. If the question is how to stop this happening again, the answer costs nothing and appears further down the page. If the question is what to do about the server that stopped at half past eight this morning, the rest of this page is about that.
Stop writing to the affected storage. That means shutting the machine down properly where it is safe to do so, rather than leaving it running while people carry on working, and certainly rather than restoring a backup on top of it before anybody knows whether the backup is sound.
Establish which layer failed, because each one has a different right answer. A machine that will not power up has a hardware fault and the storage inside it is usually untouched. A machine that runs and cannot find its storage has a controller or an array problem. A machine that presents a volume nothing will mount has a file system or application problem sitting on hardware that is working. Ten minutes spent on that question is cheaper than any of the wrong moves it prevents.
Rebuild nothing, initialise nothing, reformat nothing and re-create nothing while the only copy of the data is on the storage in question. Every one of those verbs writes.
Write down the sequence while it is fresh — what stopped, when, what was tried, in which order, by whom. Two accurate paragraphs regularly save a day of laboratory time on a multi-disk job, and nobody is being audited by the exercise.
Then ring. The freephone is answered during working hours, and a job can be marked before the parcel arrives, which puts it at the head of the queue the moment it is logged in.
The old rule survives because it keeps being right: three copies of anything that matters, held on at least two different kinds of storage, with one of them somewhere the same event cannot reach. Almost every business that loses data has one or two of those three and believes it has all three. The failures repeat themselves so exactly that they are worth listing individually.
The backup that was mapped as a drive letter. If the destination appears in Windows as a letter, anything running on that machine can write to it — and ransomware is something running on that machine. A share that stays permanently mounted is a second copy of your data sitting inside the blast radius. The copies that survive an encryption run are the ones nothing could reach: removable media taken out of the building, or a destination that only accepts writes initiated from somewhere else.
The box that backed itself up. A four-bay unit copying one of its own shares onto another of its own shares protects you against a deleted file and against nothing else whatever. Chassis, power supply, controller, cupboard and burst pipe are all common to both copies.
The sync mistaken for a backup. Cloud sync is extremely good at making every machine agree with every other machine, which is precisely what you do not want on the morning one of them is wrong. A deletion, a corruption or an encryption run propagates in minutes. What actually protects you is version history and the web recycle bin, and both have a time limit worth learning before you need it rather than during.
The restore nobody has ever performed. A backup is only a claim until somebody has pulled a real file off it onto real hardware and opened it. A striking share of the emergencies here involve a job that ran perfectly every night and restored nothing, and that discovery is always made on the worst possible morning.
Nobody can quote a recovery time from a description down a telephone, and a firm that offers to is gambling with your week. What is fixed is this: the examination is free, it closes on the second working day after your media is logged in, and it produces a written price beside a realistic date. A single drive usually finishes two to four working days after you authorise. A set runs longer, because every member is imaged separately before anything can be assembled.
Where the business genuinely cannot wait, plan around the media rather than around the laboratory. Move people onto other hardware, restore whatever partial backup exists onto something new, and treat the recovery as the way of closing the gap rather than the way of restoring everything. The firms that come out of a bad week in reasonable shape are the ones that separated those two jobs on the first morning instead of the third.
Insurers, auditors and solicitors occasionally want more than the files. A forensic investigation reported in full is £800 + VAT, and what it produces is a document written to be read by people who were not in the room and are being paid to disagree with it. Take the written report away and what remains is a verified image with its deleted material extracted, at £400 + VAT — the same rung the recorder and encrypted-media band already occupies, rather than a tier invented for the purpose. Say at the outset if a document will be needed, because it decides how the work is recorded from the first hour instead of the last.
Most incidents need none of that. A failed array, a deleted volume, an encryption run through the shares: ordinary recovery, quoted in the ordinary bands. Malware-encrypted media in particular is charged as media, from £500 + VAT for an array and £300 + VAT for a single drive, and applying investigation rates to it would be indefensible.
Servers, RAID sets, NAS boxes and SAN volumes begin from £500 + VAT and climb with the number of member disks. One hard drive or SSD is £300 + VAT. Cards and USB sticks are £250 + VAT. A CCTV or DVR recorder disk is £400 + VAT, as is an encrypted volume where the key can be produced. Every figure is confirmed in writing after the free examination and nothing starts before you have agreed to it. The whole table appears together on the cost page.
Logical recoveries run under no fix, no fee: failed arrays with sound members inside them, deleted volumes, damaged file systems, ransomware. Standing outside that guarantee are chip-level work, DVR jobs, forensic jobs and any failure that is mechanical or electronic, and invasive work takes half the agreed figure upfront before anything is opened.
Arrays and servers send member disks only, marked with the bay order, with the front panel photographed before anything is withdrawn — chassis, card and power supplies stay in your rack. A network box travels complete with its disks in their bays. An external drive stays sealed in its own case. A laptop, desktop or recorder sends its bare drive and keeps the machine. Storage soldered onto a mainboard cannot be removed and therefore cannot be sent, and no phones or tablets are handled here.
Post it tracked and covered, or bring it in during working hours: Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford OX4 4GP, weekdays 9:00am to 5:30pm. From Coventry it is roughly fifty-five miles down the M40, about an hour. Nobody collects and there is no Coventry office to visit.
The businesses that ring from this county have more in common than their trades suggest. A manufacturer near Nuneaton whose production records live on one server. A logistics operation off the M6 with a warehouse system nobody dares reboot during shift hours. An accountancy practice in the city centre in the fortnight before a filing deadline. A design studio near the cathedral quarter with fifteen years of artwork on a four-bay box in a cupboard. A hotel in Stratford whose booking system doubles as its ledger. A school running everything from one file server behind the office. Not one of them considered itself to have a disaster recovery problem until the morning it did.
Where the emergency is happening right now rather than being planned for, emergency data recovery covers the first ten minutes symptom by symptom, and the backup that was not a backup takes the commonest failure apart at length.
Businesses that come through one of these intact are the ones that shut the storage down and picked up a telephone, rather than the ones that kept trying ideas.
Something rigid, some padding and a tracked label treat an ailing device far better than a week of being carried about in a bag while its owner decides what to do next. Handed in at a Coventry counter during the afternoon, it generally reaches the Oxford bench the following working morning, which beats what most people manage by clearing a day for the M40.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.