UX Writes

DNS Change May Cause Internet Outages

 ·  By Imogen Cavendish
DNS Change May Cause Internet Outages - dns change
DNS Change May Cause Internet Outages

CIOs are being warned of a potential wave of mysterious outages due to a DNS KSK rollover, which is set to take place from October 11, 2026, to January 11, 2027. This update has the potential to create real downstream destruction when unresolved failures sit underneath important business functions, according to Sai Joshitha Kathari, senior site reliability engineer at Visa.

The danger lies in the many dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps, which can keep working quietly for years and then fail during a DNS or certificate-related change. These issues are often unknown to IT or handled by a third-party vendor, and no one in IT has had reason to ask those vendors about DNS updates.

The DNSSEC update itself is straightforward, but it is also the first significant DNSSEC change since 2018. The rollout statement noted that the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). Independent technology analyst Carmi Levy says that CIOs need to take this event very seriously, as failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.

Kim Davies, vice president of IANA Services and president of public technical identifiers at ICANN, says that the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. However, based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees.

Justin Greis, CEO of consulting firm Acceligence, says that CIOs are being distracted by AI and this issue can catch people off-guard, resulting in a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover.

Related: Mophie Roam reaches 25W with cooling tech

Greis adds that many enterprises will discover in January problems created by their own automation, as older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.

Cricket Liu, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries, which can disrupt critical business operations. Geoff Huston, chief scientist at the Asia Pacific Network Information Centre (APNIC), says that it is difficult to project what will happen in January until it happens, as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers.

Acceligence’s Greis says that any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs, as it may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks.

Enterprises that treat the rollover as a routine infrastructure task will likely complete the update and move on, but those that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage. As the updates propagate, hiccups will materialize, and CIOs must be prepared to address them in a timely and effective manner, ensuring their travel tech and other critical systems remain operational.

CIOs should take proactive steps to prepare for the potential impact of the DNS KSK rollover.

Leave a Comment

Your email address will not be published.