What to do if…
The NAS is not responding
An unreachable NAS is diagnosed like a server: network first, disks next, external copy in parallel. The internal RAID is not repaired by pulling out disks at random: as long as a copy outside the NAS exists, that copy is the path to restoration, and tinkering with the disks is the path to permanent loss.
Updated October 20263 min read5 sources cited
Key points
- Network first: another workstation, the admin interface, another cable, another switch. Many “dead NAS” cases are dead switches.
- Several disks showing alerts, or unreadable files: stop all writes, do not rebuild blindly.
- Volume still readable: copy the critical folders off the NAS first, repair afterwards.
- Internal snapshots die with the NAS: only the external copy counts.
- The NAS is a source to be backed up, not a backup.
1. Find out how far the problem goes
| Symptom | Likely cause | First step |
|---|---|---|
| Only one workstation can no longer see it | The workstation: network drive, password, VPN | Test from another workstation |
| No workstation can see it, nor the admin interface | Network, power supply or device frozen | Ping, status lights, another cable, another switch |
| The interface reports a failed disk | Degraded volume, still healthy if the RAID has some margin | Replace the disk indicated by the manufacturer, not another one |
| Several disks showing alerts, volume degraded beyond the RAID, unreadable files | Loss of redundancy or corruption | Stop all writes, do not rebuild blindly |
| Files renamed or encrypted en masse | Attack | Disconnect the NAS from the network and follow the ransomware guide |
Many “dead NAS” cases are dead switches.
If the files on the NAS have changed extension or display a ransom demand, this is not a failure: disconnect it from the network without shutting it down and go to Ransomware has just struck.
2. Protect what is still responding
If the volume is still readable, immediately copy the most critical folders to a disk that is not in this NAS, in addition to the backup already held off-site. Then run the repair recommended by the NAS manufacturer.
A RAID rebuild puts heavy load on all the remaining disks. On a second failing disk, it can destroy the volume: if two disks are suspect and an external backup is good, restoring from the external copy is often safer than rebuilding.
3. Restore from the copy outside the NAS
If the volume is dead:
- restore the shares from the off-site backup to a new volume, another NAS or a server;
- reapply the permissions, or recover them if the NAS configuration was itself backed up;
- recreate the tasks and accounts. Without a configuration export, this part has to be redone by hand: it often takes longer than copying the files.
Snapshots internal to the lost NAS are no longer available. NIST puts it this way in its storage security guidelines: if the source data is unavailable, the snapshots can no longer be used either. Only the copy that left the device is of any use.
RAID, snapshots, external backup: what protects against what
| Risk | RAID | Internal snapshots | Backup outside the NAS |
|---|---|---|---|
| Single disk failure | Yes | No | Yes |
| File deleted by mistake | No | Yes, as long as the NAS is working | Yes |
| Failure of the NAS itself | No | No | Yes |
| Ransomware with administrator access | No | Often not | Yes, if the copy is isolated or immutable |
| Fire, theft, water damage | No | No | Yes, if it is on another site |
CERT-MU, in its guideline on backup plans, recommends keeping an off-site copy and regularly testing restoration. The French cybersecurity agency (ANSSI) recommends the “3-2-1” rule: three separate copies of the data, two backups on different media, one of them offline.
4. Afterwards
Put an external backup back in place on the day the NAS returns to service. Check the overnight alert. If the NAS was the only copy of the workstations’ data (“we save to the NAS, so it’s backed up”), the scope was wrong: the NAS is a source, not a backup. See How do you back up a NAS? and Why make an off-site backup?.
At WeDoBack
NAS devices are among the sources WeDoBack includes in its off-site backup: data is encrypted on the machine before it is sent, with a key held by the customer, then stored on servers dedicated to backup, separate from production. Restoration covers the copied data, to a healthy location, not the repair of the RAID. If the NAS hosted the company’s only file server and downtime is intolerable, the critical content should live on a server covered by a DRP, not only on a NAS restored file by file. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), i.e. from 11:00 to 15:00 and from 16:00 to 19:30 Mauritius time during European summer time, and one hour later in winter.
Frequently asked questions
Isn’t RAID enough to protect the data on the NAS?
No. RAID lets you survive the failure of one disk, sometimes two. It does not protect against deletion, ransomware, controller failure, fire or theft: all the copies are in the same box. ANSSI, France’s cybersecurity agency, recommends three copies, on two different media, one of them offline.
Are NAS snapshots a backup?
They let you quickly go back to a previous version of a file, as long as the NAS is working. NIST points out that if the source data becomes unavailable, the snapshots can no longer be used either. They complement an external backup; they do not replace it.
Should the disks be sent to a data recovery specialist?
Only if no clean external copy exists and the data is valuable. In that case, shut the NAS down properly, number the disks in their original order and do not attempt anything. Every rebuild attempt reduces the chances of recovery.
Sources
Documents consulted in October 2026.
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI (French cybersecurity agency)
- SP 800-209, Security Guidelines for Storage Infrastructure (October 2020) — NIST
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- Guideline on Ransomware Removal — CERT-MU
- DRP offer (Disaster Recovery Plan) — WeDoBack
Need help now?
Do not restore anything until you have identified a clean copy. We can guide you.
Call +33 9 72 50 78 28or write to usDealing with an incident right now?
Our teams help you identify the right copy and restore it, Monday to Friday, 9 am to 1 pm and 2 pm to 5:30 pm (Paris time).
