After data loss, the safest first move is often to stop changing the device or account.
Repeated restarts, repair utilities, operating-system reinstalls, new file copies, account cleanup, and improvised recovery attempts can overwrite evidence or data that a qualified recovery process might have used. The right response depends on what happened: accidental deletion, hardware failure, cloud synchronization, account compromise, ransomware, or physical damage are different cases.
Stop and describe the event
Write down what the person saw, what happened immediately before it, and what has been tried since. Include the device, account, folders, approximate data size, last known good date, error messages, unusual sounds, liquid or impact damage, and whether other devices show the same problem.
Do not clean up the story. A failed repair attempt or forgotten password is important context for the next person.
If the device is making new clicking, grinding, or repeated spin-up sounds, has physical or liquid damage, smells overheated, or is disappearing intermittently, stop powering it on. Continued operation can worsen a mechanical or electrical failure.
Distinguish local, cloud, and account loss
A missing folder may still exist in another place:
- The Mac or PC recycle bin or Trash
- A cloud service recycle bin or version history
- Another synchronized device
- Time Machine, Windows backup, or a business backup platform
- A NAS snapshot or prior file-server backup
- An email attachment or approved collaborator’s copy
Check status without creating a large volume of new writes to the affected storage. For cloud services, use the web interface to determine whether files were deleted, moved, renamed, or made inaccessible by permissions.
Synchronization is not the same as an independent backup. A deletion or unwanted encrypted change may synchronize across devices. Conversely, disconnecting every device blindly can prevent a useful unsynchronized copy from being identified. Preserve the state and decide deliberately.
Treat suspected compromise differently
If files have unfamiliar extensions, a ransom note appears, multiple systems change together, or an account shows unknown sign-ins, assume the incident may extend beyond one disk.
Disconnect affected devices from wired and wireless networks when it is safe to do so. Do not delete messages, logs, or suspicious files. Use a known-clean device and communication path to contact the authorized response team. Business incidents may involve cyber insurance, legal counsel, law enforcement, customers, or regulators; those decisions belong to the organization’s approved incident process.
Do not reconnect a restored system until the entry path and account risk have been addressed.
Verify backups before modifying the source
Look for actual recovery points and open representative files when possible. A backup application installed on the computer is not proof that recent backups exist.
For a Mac, Time Machine can restore files or an entire system from its backup destination. For Windows, backup and recovery options depend on whether the device uses a personal Microsoft account, OneDrive, business management, File History, an image, or another platform. Business users should not assume the consumer Windows Backup application covers an Entra ID or Active Directory device.
Record the newest verified recovery point, where it lives, and whether it appears independent of the failed source.
Choose the recovery path by value and failure type
Logical recovery from accidental deletion may be appropriate for a healthy disk. A damaged drive may need a specialist clean-room or hardware lab. A locked cloud account may need identity recovery and administrator help rather than disk software. A failed NAS may require the exact array, filesystem, encryption, and device history.
Before authorizing recovery, ask:
- Is the original media preserved unchanged?
- Will diagnostics write to the source?
- Is an image or clone created first where appropriate?
- How are privacy and chain of custody handled?
- What happens if the initial attempt fails?
- What costs require approval?
- Which files matter most if only partial recovery is possible?
No honest provider can guarantee recovery before evaluating the failure. Be cautious with absolute promises.
Build the next backup after the incident is stable
Recovery is not complete when files reappear. Place recovered data on verified storage, scan it where appropriate, confirm key files open, and establish a new protection plan before retiring the original media.
Tyler’s Tech Company provides backup and data recovery triage for Greater Boston homes and small businesses and coordinates with specialist recovery providers when the media requires capabilities outside normal IT support. For a current incident, describe the device and what happened without sending credentials.