// THREAT DETECTION AND DATA PRIVACY TERM

Data Recovery

Data recovery is the process of restoring data that has been lost, accidentally deleted, corrupted, or made inaccessible. It involves salvaging data from damaged or failed storage media like hard drives, servers, or tapes.

Data Recovery — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Data recovery is a core incident response and disaster recovery (DR) process involving the restoration of lost, corrupted, or inaccessible data from primary or backup storage media such as hard disk drives (HDDs), solid-state drives (SSDs), RAID arrays, or cloud backups. This process is triggered by events like hardware failure, software corruption, cyberattacks (e.g., ransomware), or human error to ensure business continuity.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • data restoration
  • file recovery
  • disaster recovery
  • data salvage
  • information retrieval
  • file undeletion

USAGE NOTE

In incident response, data recovery is typically performed after containment and eradication to restore systems to a clean, operational state using trusted backups.

DEVELOPERS

Organizations developing technology related to Data Recovery.

  • Ontrack

    A global leader in data recovery services and software, recovering data from all types of storage media and systems after data loss events, including hardware failure, human error, and cyberattacks.

  • Cellebrite

    Specializes in digital intelligence solutions, including tools for law enforcement, military, and intelligence agencies to extract, decode, and analyze data from mobile devices, drones, and computers for investigative purposes.

  • DriveSavers

    A prominent provider of data recovery services for physically damaged and logically corrupted storage devices, including hard drives, SSDs, and mobile phones. They operate in high-security environments for corporate and government clients.

  • Acronis

    Develops integrated cyber protection solutions that combine data backup and recovery with cybersecurity features like anti-malware and anti-ransomware to protect against and recover from data loss incidents.

  • Veeam

    Provides backup, recovery, and data management solutions for virtual, physical, and cloud environments. Their technology is critical for organizations to recover data and operations swiftly following a cyberattack like ransomware.

  • Magnet Forensics

    Develops digital investigation software that helps forensic examiners recover and analyze digital evidence from computers, mobile devices, and cloud services, often recovering deleted or hidden data.

  • Kroll

    A corporate investigation and risk consulting firm with a major cybersecurity practice. Their Digital Forensics and Incident Response (DFIR) teams use advanced data recovery techniques to investigate breaches and restore compromised systems.

  • Zerto

    A Hewlett Packard Enterprise company that provides disaster recovery and data protection solutions. Its continuous data protection (CDP) technology enables recovery to a point in time just seconds before a cyberattack, minimizing data loss.

RELATED TERMS IN INCIDENT RESPONSE