Recovery · Blog · 05/20/2026

When information is lost: what to do in the first minutes

Technical guidance for the first decisions after data loss: preservation, overwrite risk, evidence and initial actions.

When information is lost: what to do in the first minutes
Cover image · Xabier Durruti

When information is lost, the first reaction is often to try things: restart, install recovery programs, connect the drive to several computers, format it, accept system repair messages or keep using the device in the hope that the data comes back. Technically, many of those actions can make the situation worse.

Information recovery does not start by recovering. It starts by preserving. Before trying any solution, the affected medium should change as little as possible. A deleted file, damaged system or lost partition may still contain recoverable data, but every new write can overwrite part of that information.

In cyberintelligence and digital forensic analysis, the principle is clear: first preserve, then analyze and only then act. This is especially important when the information has personal, professional, economic or evidential value.

  • Do not install recovery software on the affected device.
  • Do not save new files on the disk, USB drive, memory card or phone.
  • Do not format or accept repair messages without understanding their effect.
  • Do not keep testing if the device makes abnormal noises or repeatedly disconnects.

The type of loss matters. Accidentally deleting a folder is not the same as a system failure, a missing partition, a drive that will not mount, a locked phone, a damaged memory card or possible malware encryption. Each case needs a different strategy.

If the device is still working, it is often best to stop using it as soon as possible. The operating system may continue writing temporary files, logs, updates or cache data. On mobile devices, applications may synchronize or modify internal databases.

Initial documentation is more important than it seems. Knowing whether there was a fall, deletion, update, infection, power failure, formatting or later manipulation helps assess real possibilities. It also helps distinguish ordinary data recovery from a case where forensic analysis may be needed.

When information may have evidential value, care must be greater. It is not enough to recover files; it may be necessary to preserve the state of the medium, maintain traceability, avoid modifications and document the process. A poorly planned intervention can reduce the technical value of the recovered information.

  • If the disk has physical symptoms, disconnect it and avoid repeated attempts.
  • If the loss was caused by deletion, avoid using the device.
  • If there is possible ransomware, preserve the encrypted files and any ransom notes.
  • If malware is suspected, do not mix recovery and cleanup without preserving data first.

In a professional analysis, the first step is usually to assess the medium, the file system, the symptoms, the volume of later writes and the real objective: recover everything, recover specific files, preserve evidence or understand what happened.

Not everything can always be recovered. Being honest about that possibility is part of technical work. But the probability of success can be increased by avoiding initial mistakes.

In data recovery, the first correct step is often to stop, document what happened and request a technical assessment before improvising.