Mechanical, electronic, flash wear, logical, human — and the first response to each.

01Every drive dies one of five ways. Know which one you're looking at before you touch anything.

The instinct, when data goes missing, is to act immediately — click, poke, retry, reformat. That instinct costs recoveries. The failure mode in front of you determines everything: what you can safely do next, how urgent the clock is, and whether this is a £100 job you can handle yourself or a cleanroom situation where the next keystroke is the one you'll regret. Here are the five ways storage fails, what each one looks like from the outside, and the correct first move for each.

Five modes, and the honest first response to each
ModeWhat you seeFirst response
MechanicalClicking, ticking, buzzing, failure to spin up.Power down. Do not retry repeatedly. Image on the next good spin-up, or send it away.
ElectronicCompletely dead, not detected, no spin at all.Check power and cable first, then stop. Board-level work is a specialist job.
Flash wearAn SSD that has gone read-only, or throws uncorrectable errors.Read everything off it now. Read-only is the drive's last cooperative state.
Logical / file systemDetected but wrong capacity, or garbage where data should be.Change nothing. Do not reformat to 'fix' it. Image the raw device.
HumanDeleted, overwritten, or synced away.Stop using the volume immediately, then restore from a version rather than undelete.

021. Mechanical Failure

The traditional hard drive is an extraordinary piece of precision engineering running inside a sealed chamber at tolerances measured in nanometres. The read/write heads float a few nanometres above platters spinning at several thousand revolutions per minute. When something in that system breaks — a head crash, a seized spindle motor, a snapped actuator arm — the damage is physical and immediate.

The signature is sound. A rhythmic clicking or ticking almost always means the heads are failing to find their home position and resetting, over and over. A grinding noise suggests head-to-platter contact, which is destroying the magnetic surface with every revolution. A drive that spins up, spins down, and retries is often a motor struggling against stiction — the platters have stuck to the heads after resting — or a bearing about to give out entirely. Any of these sounds means one thing: power off immediately. Every additional second the drive runs is more physical damage.

First move: Stop. Do not attempt to image a mechanically failing drive yourself if it is making grinding or continuous clicking sounds — you will accelerate the destruction of the platter surface. This is the clearest case for a professional data recovery lab. A reputable lab works in an ISO-certified cleanroom, because even a single dust particle can be catastrophic between a head and a platter. The cost is real, but it is the only way to recover data from a drive with head damage.

If the drive is clicking intermittently but still mounts, and you have reason to think it is early-stage, the calculus changes slightly — but the answer is still to image it immediately, letting a tool like ddrescue map the readable sectors and skip the bad ones without hammering the same spot repeatedly. The moment it starts clicking consistently: stop.

032. Electronic Failure

The drive's printed circuit board — the PCB on the underside of a conventional hard drive — contains the controller chip, the firmware memory, motor driver circuits and a cache chip. Any of these can fail. A power surge or transient is a common cause; so is simple component aging.

Electronic failure looks different from mechanical failure. The drive is often completely silent. It doesn't spin up at all, or it powers on and is simply not recognised by the operating system — no mount, no device enumeration, nothing in Disk Management or Disk Utility. No noise, no obvious motion, just absence.

The temptation is to swap the PCB from a matching donor drive bought online. This can work, but the window is narrower than most guides suggest: modern drives store drive-specific calibration data (sometimes called the adaptive data or the ROM) on a small chip on the board, and if you simply swap the whole PCB, you will almost certainly get a drive that spins up and remains unreadable, because the heads are being driven by calibration data that belongs to a different set of platters. The correct approach — transplanting only the ROM chip, or reading and writing it — requires equipment and skills that go beyond most home setups.

First move: Do nothing destructive while the drive still has a chance. If the drive is simply not recognised, document what you see, check another cable and another port to rule out the trivial causes, and if it remains unresponsive, hand it to a professional. An electronic failure that hasn't cascaded into mechanical damage is a good recovery prospect — the platters and heads are often intact. Don't reduce that prospect by experimenting.

043. Flash Wear and Firmware

SSDs, USB flash drives, SD cards and eMMC storage all fail by a different mechanism. NAND flash cells can only sustain a finite number of program/erase cycles. Consumer drives mitigate this with wear levelling — spreading writes across all available cells rather than hammering the same ones — but the cells age regardless. When enough cells reach end-of-life, the drive's controller may put it into read-only mode to protect remaining data, or it may simply stop responding.

The harder problem is firmware and controller failure on flash devices. Unlike a mechanical drive, which tends to degrade visibly, an SSD can go from apparently healthy to completely unresponsive without a meaningful warning period. The drive vanishes from the system, or it enumerates but returns errors on every read. SMART data on SSDs is less reliable as a predictor than on spinning drives — the attributes exist, but the failure curve is steeper and shorter.

USB flash drives and SD cards have minimal or no wear levelling, minimal error correction, and no SMART interface at all. They are the least recoverable storage medium in common use, not the most. Treat them as temporary transport, not archive.

First move: If an SSD stops responding, power it off and leave it powered off. Do not repeatedly power-cycle it. Some flash controllers enter a locked state that can be exacerbated by additional power cycles. If it still mounts, image it immediately — imaging a failing drive before it goes completely silent is the single most important action. If it has gone completely unresponsive, a professional with NAND-level recovery tools may be able to read the chips directly, but this is expensive and not always successful.

054. Logical and File System Failure

The physical hardware is fine. The data is there, magnetically or electronically intact. But the structures that tell the operating system where the files are — the partition table, the file system metadata, the journal, the directory tree — are damaged or missing. This is logical failure.

Causes are varied: a partial format, a failed resize operation, a corrupted journal after an unclean shutdown, a botched firmware update on an external drive, or even a drive that was formatted for one operating system and then misread by another. The drive is recognised; it is not readable. Or it is readable, but some or all of the files are missing or inaccessible.

This is the failure mode where the intervention order matters most. The file system structures that describe where files live are often still partially present — and every write to the disk, including writes made by recovery tools or the OS trying to remount the volume, can overwrite exactly the data needed to reconstruct them. File system repair tools like fsck on Linux, chkdsk on Windows, and First Aid in macOS Disk Utility are designed for minor corruption on an otherwise healthy volume. Running them on a seriously corrupted volume can make the situation worse and is never the first step.

First move: Image the volume before doing anything else. Work from the image. If the hardware is healthy, this is a task you can handle: make a sector-by-sector copy, verify it, then work from that copy — your original drive remains untouched as a fallback.

065. Human Error

Accidental deletion, an unintended format, a rm -rf that went one directory too high, a bulk rename that destroyed meaningful filenames — human error accounts for a substantial proportion of real data loss. It is also, counterintuitively, often the most recoverable failure mode, and the one people most reliably make worse by panicking.

When a file is deleted, most operating systems do not immediately erase the underlying data — they remove the directory entry and mark the space as available for reuse. The file's content sits on the disk, recoverable, until something new is written over it. The critical factor is time and activity: every new file written, every application opened, every operating system swap write is potentially landing on top of the data you need.

This is also the failure mode where sync is not backup becomes painfully concrete: a deletion propagates to every synced device within seconds, and a mirror that was refreshed moments before you noticed offers nothing. Versioned backups — the kind that keep snapshots across days or weeks — are the correct defence.

First move: Stop using the device. If it is a laptop or desktop, shut it down — OS activity writes constantly in the background. If it is an external drive, unmount it cleanly and leave it alone. The more of the original data that remains unoverwritten, the better the outcome.

USB flash drives and SD cards have minimal or no wear levelling, minimal error correction, and no SMART interface at all.

07The Common Thread

Every failure mode has one thing in common: the first action should not be another read or write against the affected storage. Stop the activity, understand what you are looking at, and make an image before you attempt anything else. Which specific tool you use and how you proceed from there depends on which of the five modes you are dealing with. But that first discipline — pause, identify, preserve — applies to all of them equally.