Data Recovery Case File · Portable Drives · Somebody Wrote It Down
He Recorded the Progression, Which Almost Nobody Does
His enquiry arrives as a dated log. "Day 1: I connected my external drive and the file browser recognised it. However, when I tried to access any files, it took some time to load. I noticed in the task manager that the drive was showing 100% usage. Day 2: I realised there was an issue when I tried copying files to another drive. The process was slow." Two days of observations, in order, with a measurement in them — and that measurement is the diagnosis.
| Media | External hard drive — progressive read degradation documented over consecutive days; sustained 100% device utilisation reported without corresponding throughput |
| Reported situation | Drive recognised by the host and accessible on the first day · file access notably slow · device utilisation reported at 100% by the host task manager · copying to another drive attempted the following day · transfer proceeding very slowly · degradation continuing across days |
| Fault class | Progressive read failure with utilisation reflecting retry time rather than transfer · degradation documented and ongoing |
| Equipment used | Owner's timeline accepted as a degradation record · utilisation distinguished from throughput before any conclusion · Atola Insight Forensic error-rate assessment · imaged write-blocked under strict per-sector timeouts with retries capped · losses mapped per file |
The decode: what 100% usage means when nothing is moving
What that figure actually measures: the proportion of time the device spent busy with a request. It does not measure how much data moved. A drive transferring at full speed shows 100%, and so does a drive that has accepted one request and spent the entire period failing to complete it.
Why the combination is the diagnosis: 100% utilisation with almost no throughput means the drive is occupied and achieving nothing. It is retrying — repositioning and escalating through an internal recovery sequence taking seconds per sector, during which it is entirely busy and entirely unproductive.
Why that is such a good early indicator: it appears before anything fails outright. Files still open, the drive is still recognised, and nothing announces a problem — but the ratio between how busy the drive is and how much it delivers has already collapsed. Anybody who looks can see it, and almost nobody looks.
What his second day added: confirmation under load. Ordinary browsing touches a small fraction of a drive; copying visits everything. The transfer being slow rather than failing means most regions still read and some do not, with time going into the ones that do not.
Why the log itself is unusually valuable: it establishes direction. A single observation says what the drive is doing; a series says which way it is going — and a drive that was slow on Monday and slower on Tuesday is deteriorating rather than sitting at a stable fault. That changes the urgency and it cannot be established from one look.
What follows from the direction: the position gets worse while decisions are made, so every day of deliberation costs something. It also means whatever reads today may not read next week, which argues for capture rather than further investigation.
What must stop: the copying. Each attempt is sustained reading across a degrading surface, and a file-by-file copy through the operating system inherits its timeouts — so every failure consumes the full retry sequence before moving on.
Why imaging differs: per-sector timeouts are capped deliberately, difficult regions are deferred rather than allowed to consume the session, and the healthy expanse is taken at speed first.
On the bench
The owner's timeline was accepted as a degradation record, a series of observations establishing direction where a single one establishes only state. Utilisation was distinguished from throughput before any conclusion — device utilisation measuring time spent busy rather than data moved, so 100% with negligible transfer indicates a drive fully occupied by retries and achieving nothing. The Atola Insight Forensic assessed error rates, with imaging write-blocked under strict per-sector timeouts with retries capped.
The outcome
The timeline read as a degradation record, utilisation separated from throughput, and the drive imaged under capped timeouts. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: 100% usage measures time spent busy, not data moved — so a drive showing full utilisation while transferring almost nothing is occupied entirely by retries. That signal appears before anything fails outright, and your log shows it getting worse.
Drive that is slow rather than broken
Look at the device utilisation figure in your task manager and compare it with the transfer rate — that pairing is one of the best early warnings available. Utilisation measures the proportion of time the drive spent busy with a request, not how much data moved, so a drive running at 100% while transferring almost nothing is entirely occupied and achieving nothing. That's retrying: repositioning and escalating through an internal recovery sequence taking seconds per sector. It shows up while everything still works, which is exactly when acting is cheap. If you noted dates, keep them — a series tells you the direction, and direction decides urgency.
Stop copying — call Oxford Data Recovery on 01865 593000; your timeline read as a degradation record, error rates measured, imaged under capped per-sector timeouts with losses reported per file.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.