Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Case 1500 · What Protection Covers

He Built the Redundancy and the Box Around It Failed

This archive is fifteen hundred cases long and most of the people in it had one copy. He had two. "I have two drives which were part of a two-bay external mirrored enclosure. A couple of years ago the enclosure failed, and without the funds to replace it I recovered what I could from one of the disks. However, there's a great deal that was not successfully recovered, and I would now like to see if there is anything that can" still be done. He did the thing everybody is told to do — and the thing that failed was neither of the disks he was protecting.

MediaTwo 3TB drives from a two-bay mirrored external enclosure — enclosure electronics failed; one member previously read by the owner with partial results; second member status not established
Reported situationTwo drives configured as a mirrored pair in an external enclosure · enclosure failing approximately two years previously · replacement not affordable at the time · one member read directly by the owner · partial recovery achieved · substantial content not recovered · second member status not stated · both drives retained
Fault classEnclosure failure with both members intact — mirror redundancy addressing member failure only; prior partial recovery method and untried second member both determinative
Equipment usedSecond member assessed independently before any conclusion about the first · prior recovery method established · enclosure-specific volume layout identified from member metadata · both members imaged individually write-blocked · volume interpreted from images rather than carved

The decode: what he protected against, and what he added

What a mirror is: two disks holding identical content, either of which can fail without any loss. It is real protection, correctly chosen, and it works exactly as advertised. More people should have one.

What it protects against: a disk failing. That is the specific event it was designed for, and had either drive died, he would have replaced it and never written this enquiry.

What failed instead: the enclosure. Not a disk — the box. The controller that presented the pair, the power supply that ran them, the interface that connected them to a computer. The thing he bought in order to have the protection.

The doctrine of case 1500: every arrangement adds a component

Here is the shape of it. To protect two disks from failing, he had to buy something that holds two disks. That something has electronics, a power supply and a single connection to the outside world — and none of it is protected by the redundancy it provides. The mirror guards the disks. Nothing guards the mirror.

Which generalises, and this is the thing worth carrying away from fifteen hundred cases. A network unit protects against a disk failing and adds a controller, a network stack and an operating system that can be attacked. A backup drive protects against a machine failing and adds a device that lives in the same room and shares the same flood, fire and burglary. Cloud synchronisation protects against a device failing and adds an account that can be locked. Every protective arrangement is a trade: it covers one failure and introduces another.

Why that is not an argument against any of them. Redundancy works, backups work, and mirrors are worth having. It is an argument for one question, asked of any arrangement before you rely on it: what failure does this cover, and what did I add in order to get it? The second half of that question is almost never asked, and the answer to it is what turns up here two years later.

What he did after the enclosure died, and it was right: he read one disk directly. That works, and it is the single most useful thing to know about a mirror — each member holds a complete ordinary volume, readable on its own on any machine, without the enclosure and without the other disk. Most people do not know it, and it is why a failed mirror enclosure is rarely a disaster.

Why he did not get everything, and all three possibilities are worth checking. First, the software he used may have carved rather than reading the filesystem — which returns files stripped of names and folders and misses anything fragmented, and is the commonest reason a self-recovery comes back partial. Second, some enclosures write their own layout, offsetting the volume or adding a header, so the disk is not quite a plain volume and needs interpreting rather than reading. Third — and this is the one to act on — he may have read the wrong disk.

Why that last one is genuinely likely: the two members of a mirror are not always in the same condition. One can be quietly failing for months while the enclosure serves reads from the other, and nobody is told, because that is precisely what the arrangement exists to do. He has a second disk, and there is a real chance he has never tried it.

What the two years cost: less than it might have. Nothing has been written to either disk, so nothing has been overwritten — the only cost is mechanical, in lubricant that has thickened and heads that have rested, which argues for acting now rather than waiting further.

Why this is case 1500. Almost everybody in this archive had a single copy and lost it. He had two copies, chose well, and lost access to both through a component that was neither of them. The lesson is not that protection fails. It is that protection is always a claim about one particular failure — and the only useful question, every time, is which one.

On the bench

The second member was assessed independently before any conclusion about the first — mirror members frequently differing in condition, since an enclosure serving reads from the healthier disk conceals the degradation of the other for as long as it operates, which makes an untried second member the most likely source of what was missed. The prior recovery method was established, carving returning files without names or folder structure and missing fragmented content. Enclosure-specific volume layout was identified from member metadata, some units offsetting the volume or writing a header, and both members were imaged individually write-blocked with the volume interpreted from images rather than carved.

The outcome

The untried second member assessed first, the previous method established, the enclosure's own layout identified, and the volume interpreted rather than carved. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, and the doctrine of case 1500: every protective arrangement adds a component, and the component you add is not protected by the thing it protects. Your mirror guarded two disks behind one enclosure, one supply and one connection. Ask of anything you rely on: what failure does this cover, and what did I add to get it? And try the other disk — mirror members are not always in the same condition, and yours may never have been read.

Mirrored pair whose enclosure has failed

Try the other disk — that is the practical thing, and it may be the whole answer. Each member of a mirror holds a complete ordinary volume readable on its own, on any machine, without the enclosure and without its partner, which is the most useful fact about mirrors and one most people never learn. But the two members are not always in the same condition: an enclosure serving reads from the healthier disk hides the other's decline for as long as it runs, so the one you read may have been the failing one. Two other things explain a partial self-recovery — software that carved rather than reading the filesystem, which loses names and folders and misses fragmented files, and enclosures that write their own layout so the disk isn't quite a plain volume. And afterwards, ask of anything you rely on: what failure does this protect against, and what did I add in order to get it?

Mirrored drives stranded by a dead enclosure?
Try the disk you never read — then call Oxford Data Recovery on 01865 593000; both members assessed independently, enclosure layout identified from metadata, volume interpreted from images rather than carved.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.